Method for monitoring a state of a control unit
The method evaluates supply voltage curves and reaction times to assess the state of control units, addressing the inefficiencies of existing monitoring methods by accurately predicting the end of life and ensuring timely maintenance.
Patent Information
- Application Number
- DE102024200542
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-22
- Publication Date
- 2025-07-24
AI Technical Summary
Existing methods for monitoring the state of control units in vehicles, particularly those with high SAE ASIL ratings, are inadequate and do not effectively predict the need for servicing or replacement, especially for L4 control units in commercial vehicles, due to the high cost of control units and the inefficiency of simple timer or counter approaches.
A method involving the evaluation of a control unit's supply voltage curve during switching, using a first monitoring module to determine reaction time differences, and comparing these with initial values to assess the unit's state, combined with additional monitoring of high-performance rails to verify power integrity.
Accurately estimates the end of life of control units by measuring and comparing startup and shutdown times, and detecting voltage fluctuations and spikes, thereby ensuring timely maintenance and preventing operational failures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The invention relates to a method for monitoring a state of a control unit and to an arrangement for carrying out the method.Prior ArtControl units are electronic modules which are used at locations where something has to be controlled or regulated. In motor vehicles, control devices are used in different fields.Monitoring of the state, in particular of the technical state, in modern control units, such as, for example, in sensor control units, in particular in systems with high SAE (Society of Automotive Engineers) ASIL (Automotive Safety Integrity Level) classifications, i.e. Level 2 or higher, is becoming increasingly important. In particular, in the case of L4 control units which are used in vehicles, such as, for example. When using commercial vehicles, it is important to know at which time the control device must be serviced or replaced.To achieve this goal, new approaches must be used to check the technical state of the control unit. Because of the very high cost of each controller, a simple timer approach is not sufficient.In L3+ systems, all supply voltages or rails are monitored with a monitoring unit which can measure the current voltage of the rail with an analog-to-digital converter (ADC) and compare this with a calculated minimum or maximum threshold value of the rail, usually within a window of + / - 3%. Furthermore, continuous monitoring with a comparator versus other threshold values can be performed. Usually, maximum classifications of a device being supplied, e.g., an SoC (System on Chip), are used. The ADC may detect slow voltage fluctuations and check whether the voltage is within a predetermined range, referred to as LF monitoring. The comparator can detect fast voltage spikes and voltage drops, referred to as RF monitoring. The monitor thresholds are individually given for both overvoltage and undervoltages.The monitoring unit also has the possibility of measuring the on-time and off-time for the associated rail in order to check whether the on-time and off-time sequence is as defined. In this connection, reference is made to FIG. 1, in which the basic diagram is shown.The publication DE 10 2019 213 654 A1 describes a method for checking the functionality of an autonomous power supply unit of a control unit for at least one passenger protection device in a vehicle. In the method, the detection of a voltage is decoupled, a time duration is detected and the functionality of the autonomous power supply unit is detected as a function of the detected voltage and / or the detected time duration.The publication DE 10 2009 047 034 A1 discloses a method for operating a controller for a starting device. The starting device has a starter motor for starting an internal combustion engine of a vehicle having an on-board power supply system. In this case, the starter motor is activated by the controller, specifically in particular for a start-stop operating mode of the vehicle. In order to reduce a load on the on-board power supply system, in particular a voltage dip, during the starting process, the controller detects at least one parameter for determining a state of the on-board power supply system, wherein the starter motor is actuated at least as a function of the parameter.Disclosure of the InventionAgainst this background, a method according to claim 1 and an arrangement having the features of claim 6 are presented. Embodiments will be apparent from the dependent claims and from the description.The method presented serves for monitoring the state of a control unit. In the method, a profile of a supply voltage of the control unit is evaluated with a first monitoring module during the switching, in particular switching on, of the control unit, wherein a current reaction time or reaction time is determined, which is compared with an initial value for the reaction time, so that a difference value is determined which carries information about the state of the control unit.In an embodiment in which a start-up of the control unit is examined, a start-up time or start-up duration is used as the reaction time. In another embodiment, in which switching off or switching off of the control unit is examined, a decay time or decay duration is examined.Thus, a method is provided that is designed to monitor the state of the power supply and some printed circuit board (PCB) parameters.The arrangement or monitoring arrangement presented serves for carrying out the described method and is implemented, for example, in hardware and / or software. The arrangement can be integrated in a control device of a motor vehicle or can be designed as such.Further advantages and embodiments of the invention will become apparent from the description and the appended drawings.It is understood that the features mentioned above and those still to be explained below can be used not only in the respectively specified combination, but also in other combinations or alone, without departing from the scope of the present invention.Brief Description of the DrawingsFIG. 1 shows a block diagram of an embodiment of the monitoring arrangement presented. FIG. 2 shows a graph of voltage curves for illustrating the presented method. FIG. 3 shows voltage curves in a graph to illustrate an embodiment of the presented method. FIG. 3 shows voltage curves in a graph to illustrate a further specific embodiment of the method presented. FIG. 4 shows a block diagram of an embodiment of the monitoring arrangement presented FIG. 5 shows further curves of voltages in a graph. FIG. 6 shows a schematic, greatly simplified illustration of a vehicle having a control unit.Embodiments of the InventionThe invention is schematically illustrated in the drawings on the basis of embodiments and is described in detail below with reference to the drawings.FIG. 1 shows, in a basic circuit diagram, an arrangement for monitoring or a monitoring arrangement, which is denoted overall by the reference numeral 10. The illustration shows a regulator 12, a voltage divider 14 with resistors R 1 16 and R 2 18, a processor 20 as load, which in this case is designed as a SoC. The illustration further shows a monitoring module 22 in which an ADC (analog-to-digital converter) 24 operating slowly and a comparator 26 operating continuously and a logic unit 28 are provided.FIG. 2 shows curves of voltages in a graph 50, on whose abscissas 52 and 54 the time is plotted and on whose ordinate 56 the voltage is plotted. The illustration shows an input signal curve 60 which shows a switch-on pulse and an examined signal curve 62 which, as illustrated by arrow 64, shifts to a curve 66.Double arrow 70 denotes a typical time during which the voltage has reached the setpoint value after switching on. This time is determined individually for each device in the new state, stored and measured at each device start and compared with the initial value determined in the new state. The double arrow 72 illustrates a delay in the voltage regulator to be switched on, namely the time that elapses until the regulator waits after the switch-on signal until it starts the regulation. Double arrow 74 illustrates the time required by the regulator until the voltage is stable, which is also referred to as soft-start time. Reference numeral 76 illustrates the profile of the regulator output voltage.In modern control units, the correct switch-on and switch-off sequence is checked using on-board monitoring units, as can be seen from FIG. 2. Therefore, the minimum and maximum operating time for each rail relative to the first rail enable signal is calculated, as indicated by dotted lines 80 in FIG. 2. It is then measured with each start-up or with each startup of the main SoC and it is checked whether the sequence is complied with. The tolerance is caused by the input parameters:Soft-start of the regulator (regulator + ext. R-C),EN (Enable) Delay in the Regulator,EN Delay in Turn-On Sequence.A first aspect of the presented method is now considered in more detail:In a new control device, the signal curve 62 shown in FIG. 2 shows the rising ramp (ramp up) of the voltage. The time measured during the first start-up, e.g. measured in the rule line at the end of the line test, should be stored in a non-volatile memory (NVM). In practice, this time is measured at each start-up of the SoC. Due to the aging of the components, the signal curve 62 will shift to the left or right, for example to the curve 66 in FIG. 2.By comparing the start-up time with the initial value, the time difference can be calculated. With this degradation, an estimate can be made about the end of operation of the controller and the external circuit. After shifting by a certain percentage, the end of operation of the control device can be well estimated.Note that during the startup sequence, the regulator and its external circuit are of particular interest.The shutdown process will be discussed below.FIG. 3 shows curves of voltages in a graph 100 on whose abscissas 102 and 104 the time and on whose ordinate 106 the voltage is plotted. The illustration shows an input signal curve 110 which comprises a switch-off pulse and an examined signal curve 112 which, as illustrated by arrow 114, shifts to a curve 116.Double arrow 120 illustrates a discharge time from the switch-off signal until the output voltage is below a defined threshold, for example. 0.2 V. Double arrow 120 shows the variance of time 120, which is given by component tolerances.The proper turn-off sequence is of great importance to modern SoCs. This is likewise checked by such an external monitoring. The decay time for each rail is calculated with all tolerances, dotted lines in FIG. 3. The input parameters are:capacitance of the buffer capacitors,discharging current,voltage on each rail,discharging current for each rail,Deactivation Delay / Order in the Energy Sequence.During shutdown, each rail typically has an active discharge to ensure rapid and defined discharge of each rail. The activation signal of the controller normally inverts the discharge signal for the associated rail.A further aspect of the presented method is discussed below.In a new control device, signal curve 112 shown in FIG. 3 shows the falling ramp of the voltage. The time measured during the first shutdown, for example measured in the controlled system at the end of the line test, should be stored in a nonvolatile memory. In practice, this time is measured with each shut-down of the SoC. Due to the aging of the components, the signal curve 112 will shift to the left, for example to the curve 116 in FIG. 3.By comparing the decay time with the initial value, the time difference can be calculated. With this degradation, an estimate can be made about the end of life of the decoupling capacitors and the external circuit. After shifting by a certain percentage, the end of operation of the control device can be well estimated.During the turn-off sequence, the capacitors and the discharge circuit are of particular interest.The dynamic decoupling check and the controllers will now be discussed:The above tests check the static behavior of the external circuit. This already gives a good indication, but this is not sufficient for core rails with high performance. Because of the very high peak currents, in the range of 100 to 200 A, and the very high requirements for performance integrity on these rails, additional monitoring becomes necessary. One goal of this monitoring is to check the performance integrity of the core rails. An influence on the integrity is given by the following parameters:capacitance of the decoupling capacitors,internal resistance of the capacitors,PCB core material (permittivity, referred to as.epsilon.0 later).A further aspect of the presented method is discussed:In order to examine the rails taking account of degradation and aging, further monitoring is necessary for all high-performance rails, for example for core rails, DDR rails (DDR corresponds to the working memory RAM) and high-performance rails in general.FIG. 4 is a circuit diagram of a further monitoring arrangement, which is denoted overall by the reference numeral 200. The illustration shows a regulator 202, a voltage divider 204 with resistors R 1 206 and R 2 208, a processor 210 as load, which in this case is designed as SoC. The diagram further shows a first monitoring module 220 in which an ADC 224 that operates slowly and a comparator 226 that operates quickly and a logic unit 228 are provided. Furthermore, a correspondingly constructed second monitoring module 250 is provided.The existing monitoring by the first monitoring module 220 cannot be used for this task, namely this first monitoring module 220 must ensure that the supply voltage is always within the maximum classification or assessment.Both monitoring modules 220 and 250 are identical, i.e. the hardware is the same, but the configuration of the threshold values is different. Each monitor has the option of measuring the average voltage with an ADC and causing a response if the given thresholds are reached. Measurement with an ADC is always done discrete-time and not continuous, which in turn means that small peaks may be lost. This is shown in Fig. 5.FIG. 5 shows different curves, namely the maximum range 310, in a graph 300 on whose abscissas 302 and 304 the time and on whose ordinate 306 the voltage is plotted. Reference numeral 312 indicates that after a certain aging of the device, the initial threshold 314 is exceeded in order to determine by what amount this threshold is increased until it is not exceeded even under high load. Reference numeral 312 indicates an initial threshold for the voltage monitoring, intentionally below the maximum permissible threshold, this is not exceeded in a new device. Reference numeral 316 shows an example of a discrete voltage waveform. Reference numeral 318 is analogous to 314, only downward. Reference numeral 320 is analogous to 312, only downward. Reference numeral 324 denotes an allowable voltage. A plot 326 indicates an error signal.Points 330 are ADC sampling points. The thresholds in the second monitoring module for the ADC are identical to those configured in the second monitoring module, namely dotted lines 340 and 342.The difference is in the high-frequency monitoring with the comparators. The threshold is decreased close to or to the 3% line, in FIG. 5, 310 and 324 is the threshold used for the first monitoring module, and 314 and 318 is the threshold for the second monitoring module.In a new controller, 314 and 318 will not achieve these because of the good state of all components. Due to aging of the decoupling capacitors, the voltage spikes will increase and reach the threshold (reference numerals 314 and 318). This is not a problem for the overall operation of the SoC.The change of the threshold value should take place stepwise until the threshold value is not reached for a long operating time, for example one hour. After a few further hours of operation, this threshold value is likewise reached by aging of the components, such as capacitors, for example, and it has to be set, for example, to the threshold value (reference numerals 312 and 320). Importantly, any change must be in the range of maximum values, threshold (reference numerals 310 and 324).With the information on the change between the threshold value (reference numerals 314 and 318) and the threshold value (reference numerals 312 and 320), i.e., operation time such as voltage change, the remaining operation time until reaching the maximum classification can be calculated.FIG. 6 shows a greatly simplified illustration of a vehicle 400 having a control unit 402, the state of which is monitored. A first monitoring module 404 and a second monitoring module 406 serve this purpose. The two monitoring modules 404, 406 are typically arranged in a monitoring arrangement or a monitoring arrangement.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedDE 10 2019,213 654 A1
[0007] DE 10 2009 047 034 A1
[0008]
Claims
Method for monitoring the state of a control unit (402), in which a profile of a supply voltage of the control unit (402) is evaluated with a first monitoring module (22, 220, 404) when the control unit (402) is switched, wherein a current reaction time is determined, which is compared with an initial value for the reaction time, such that a difference value is determined which carries information about the state of the control unit (402).Method according to Claim 1, which is carried out when the control unit (402) is started up, wherein a current start-up time as the current reaction time is compared with an initial start-up time as the initial reaction time.Method according to Claim 1, which is carried out when the control unit (402) is switched off, wherein a current decay time as the current reaction time is compared with an initial decay time as the initial reaction time.Method according to one of Claims 1 to 3, in which a second monitoring module (22, 250, 406) is used.Method according to one of Claims 1 to 4, in which a value for the initial reaction time is used, which value is stored in a nonvolatile memory.Arrangement for monitoring the state, which arrangement is configured to carry out a method according to one of Claims 1 to 5, wherein the arrangement (10) has a first monitoring module (404).The arrangement of claim 6, comprising a second monitoring module (406).Arrangement according to claim 6 or 7, wherein the first monitoring module (404) comprises an analog-to-digital converter (24, 224) for checking slow voltage changes and a comparator (26, 226) for checking fast voltage changes.Arrangement according to one of Claims 6 to 8, in which the second monitoring module (406) comprises an analog-to-digital converter (24, 224) for checking slow voltage changes and a comparator (26, 226) for checking fast voltage changes.
Citation Information
Patent Citations
Method for detection of future malfunctions in components of transport devices e.g. motor vehicles, ships and airplanes, involves capturing static voltage of component as signal before starting process or turning-off process
DE102006031710A1
Control system and method for operating the control system for a starting device
DE102009047034A1
Method and control unit for checking the functionality of an autonomous power supply unit of a control unit of a personal protective equipment for a vehicle
DE102019213654A1
Method and device for testing a memory element
DE19634320A1