Method and system for activating a safety-relevant function of a vehicle
Patent Information
- Application Number
- DE102024203383
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-12
- Publication Date
- 2025-10-16
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method and a system for activating a safety-relevant function of a vehicle. State of the art
[0002] In today's automotive industry, various control units play a crucial role in the safety, performance, and functionality of vehicles, such as robotic vehicles or motor vehicles, especially those with functions for automated or partially automated driving tasks. These control units implement a multitude of safety-relevant functions, which are often classified with an ASIL (Automotive Safety Integrity Level).
[0003] Control units that implement safety-relevant functions, so-called ASIL control units, are protected by a series of complex internal measures aimed at detecting and controlling potential hardware or software errors. Specific safety goals are implemented to prevent or control dangerous malfunctions in various vehicle systems, such as the ESP system, the airbag system, the radar and video ADAS systems, and the electronic power steering system. These safety goals range from preventing faulty automated braking to ensuring that airbags are only deployed in crash scenarios.
[0004] The safety and integrity of these ASIL ECUs are ensured by a variety of safety measures integrated into the software and hardware, typically as safety-relevant monitoring functions implemented in software. In particular, the correct execution of safety-relevant software functions during runtime is verified by application-agnostic measures in the base software and specialized hardware elements within the ASIL ECUs. These measures include, among others, program flow checking, redundant calculations with subsequent result comparison, the use of checksums and error correction codes, as well as the monitoring of compute resources and the runtime monitoring of individual software processes.
[0005] These ASIL control units can also be understood as a "safe" processing unit, whereby a safe processing unit is understood to be a processing unit that has a comparatively high safety requirement level (e.g. ASIL-A / B / C / D) or that has a high degree of independence from a unit to be monitored, in particular in such a way that potentially dangerous errors in the processing unit to be monitored do not simultaneously lead to dangerous malfunctions in the "safe" processing unit.
[0006] From the publication DE 10 2008 043 089 A1, a method for monitoring the functionality of an electronic component is known. In this method, a variable relating to a driving state of the motor vehicle is fed to the electronic component as an input signal, and an output signal from the electronic component is forwarded to an electronic processing unit, where this output signal is further processed using diverse software algorithms. The outputs of the diverse software algorithms are then compared in a comparator.
[0007] It is an object of the invention to provide an improved method and / or a system for monitoring and / or activating a safety-relevant function of a vehicle.
[0008] The problem is solved by a method according to the features of patent claim 1. The problem is solved by a system according to the features of patent claim 12. Disclosure of the invention
[0009] According to a first aspect, a method is proposed for monitoring and / or activating and / or non-activating a safety-relevant function of a vehicle, the vehicle comprising n ASIL control units, at least one control unit to be monitored (QM control unit) and a function control unit, where n ≥ 2, the method comprising the steps: Providing test and / or configuration data by a first of the n ASIL control units to at least one further of the n-1 ASIL control units and to the at least one control unit; Processing the provided test and / or configuration data by the at least one control unit to generate at least one diagnostic message; Providing the at least one generated diagnostic message at least to the first of the n ASIL control units and the at least one further of the n-1 ASIL control units by the at least one control unit; Checking the at least one generated diagnostic message, in particular using the provided test and / or configuration data, by the first of the n ASIL control units and the at least one further one of the n-1 ASIL control units to provide a test result; Providing at least one confirmation signal by the first of the n ASIL control units and the at least one further of the n-1 ASIL control units to the function control unit based on the test result; Verifying, by the function control unit, the receipt and status of the respective provided confirmation signal; and Transmitting user data of the at least one control unit to the function control unit and activating the safety-relevant function on the basis of the transmitted user data if all confirmation signals have been received and depending on a respective status of the respective test result, for example if the status of all provided confirmation signals is “OK”, or not activating the safety-relevant function on the basis of the transmitted user data if at least one confirmation signal has not been received or depending on the respective status of the respective test result, for example if the status of at least one of the provided confirmation signals is “not OK”.
[0010] The control unit to be monitored, also called a QM control unit, is preferably a control unit without safety guarantees regarding correct functioning. A functional control unit can also be designed as an ASIL control unit and can thus be part of a monitoring network. The functional control unit is preferably a device that uses data from the QM control unit to actively control safety-relevant functions, such as an automated driving function.
[0011] The test result can, for example, have an "OK / NOK" status. However, these are only examples of how a test result can be displayed. The test result can also exist, for example, as a "No Error / Error" status or as more complex status information, for example, with more than two status pieces, or combine multiple formats. Examples of a test result could be: "OK since period X"; "Not OK since period Y" or "Not OK regarding diagnosis 1"; or "OK regarding diagnosis 2"; or "OK regarding diagnosis 3"; or "Not OK regarding diagnosis 4"; etc.
[0012] It is understood that the steps according to the invention, as well as other optional steps, do not necessarily have to be performed in the order shown, but can also be performed in a different order. Furthermore, additional intermediate steps can be provided. The individual steps can also comprise one or more substeps without thereby departing from the scope of the method according to the invention.
[0013] According to a second aspect, it is proposed a system for monitoring and / or activating and / or non-activating a safety-relevant function of a vehicle, the system comprising n ASIL control units, at least one control unit to be monitored and a function control unit, where n ≥ 2, wherein a first of the n ASIL control units is configured to provide test and / or configuration data to at least one further of the n-1 ASIL control units and to the at least one control unit; wherein the at least one control unit is configured to process the provided test and / or configuration data to generate at least one diagnostic message; and to provide the at least one generated diagnostic message at least to the first of the n ASIL control units and the at least one further of the n-1 ASIL control units; wherein the first of the n ASIL control units (also ASIL-SG) and the at least one further of the n-1 ASIL control units are each configured to check the at least one generated diagnostic message, in particular using the provided test and / or configuration data, to provide a test result, and to each provide at least one confirmation signal to the function control unit based on the test result; wherein the function control device is configured to check receipt and status of the respective provided confirmation signal; wherein the at least one control unit (also QM-SG) is configured to transmit user data to the function control unit, and wherein the function control unit is configured to activate the safety-relevant function on the basis of the transmitted user data if all confirmation signals have been received and depending on a respective status of the respective test result, for example if a status of all provided confirmation signals is “OK”, or not to activate the safety-relevant function on the basis of the transmitted user data if at least one confirmation signal has not been received or depending on the respective status of the respective test result, for example if the status of at least one of the provided confirmation signals is “not OK”.
[0014] The statements made for the procedure apply accordingly to the system. It is understood that linguistic modifications of procedurally formulated features can be reformulated for the system according to common linguistic practice, without such formulations having to be explicitly listed here.
[0015] In a further aspect, a vehicle is claimed that has at least one such system. The vehicle can be a car (passenger car), in particular a car designed for the transport of people, such as a sedan, a station wagon, an SUV, and / or a convertible. The vehicle can be a truck (lorry). Trucks are used for the transport of goods and come in various sizes and configurations, including tractor units, curtainsider trucks, dump trucks, tank trucks, etc. The vehicle can be a bus that is used to transport passengers on public or private routes and can have different capacities, for example from a minibus to a (multi-) articulated bus. The vehicle can be a motorcycle, i.e. a two-wheeled vehicle that is operated by one or two people. The vehicle can be an e-bike. The vehicle can be a train or a rail vehicle. The vehicle can be an aircraft orAn aircraft can be designed for the transport of passengers and / or cargo by air. The vehicle can be a ship or a boat, generally a watercraft, such as sailboats, motorboats, cargo ships, cruise ships, ferries, etc., used for the transport of people and / or goods over water. These are just examples of the variety of vehicles used in various areas of transportation.
[0016] The preferred vehicle, for example a robotic vehicle or a motor vehicle, has several ASIL (Automotive Safety Integrity Level) control units that are relevant to safety. There are at least two such control units. Furthermore, the vehicle comprises at least one QM control unit, which has special features regarding computing power (e.g., in an embodiment as a particularly powerful high-performance compute control unit) and / or costs (e.g., in a particularly cost-effective embodiment). This control unit receives test and configuration data from one of the ASIL control units. The at least one control unit processes the received data and generates at least one diagnostic message. The at least one generated diagnostic message is checked by the (preferably all or at least some) ASIL control units to provide a test result.Based on the test results, the ASIL control units provide confirmation signals. The test results are preferably generated per ASIL control unit, i.e., each or at least a predetermined portion of the ASIL control units outputs a test result, for example, in the form of an "OK" or "not OK" status. The function control unit checks the receipt and status of the provided confirmation signals. Based on the transmitted payload data and / or the status of the confirmation signals, the function control unit then preferably decides whether the safety-relevant functions should be activated or deactivated.
[0017] In this case, the functional user data sent by at least one QM-SG (e.g. control command “brake”) are only used by the function control unit (e.g. ESP system) for safety-relevant functions if the monitoring ASIL-SG signals that the QM-SG is error-free by means of a corresponding bus signal (“dead man switch principle”).
[0018] In this case, a deliberate over-dimensioning of the number of ASIL-SGs required as a minimum according to safety standards may be preferred, e.g. at least 2x B(D) are required according to safety standards, whereby the ASIL-SG is designed with 3x B(D). This results in several innovative advantages and additional functions. Such safety functions consist in the fact that monitoring ASIL-SGs designed in this way can receive updates during operation, which is necessary, for example, if new QM-SGs and / or software functions to be monitored are added to the SG network. Furthermore, decomposed and / or redundant monitoring ASIL-SGs can test each other for latent errors during operation. In particular, after a software update of a monitoring ASIL-SG, the at least two other monitoring ASIL-SGs check whether (if applicable).This ensures that errors (e.g., temporarily simulated errors for testing purposes) in the QM-SG to be monitored are reliably and / or timely detected and / or signaled even after the software update. The monitoring ASIL-SG can be tested using diagnostic messages, which can be responded to by the checked monitoring ASIL-SGs, for example, with a special signature value to ensure the correctness of an update previously installed on the monitoring ASIL-SG(s). Furthermore, in the event of a failure and / or passivation and / or shutdown of one of the n ASIL-SGs, a sufficient number of monitoring ASIL-SGs still remain active so that the QM-SG to be monitored can continue to perform its safety-relevant functions.
[0019] This invention provides a method for the distributed monitoring of at least one QM-SG by a monitoring network of ASIL-SGs using special fault diagnosis messages. Several ASIL-SGs are already present in all current vehicle architectures, so that implementation of the method in existing vehicle structures is possible, preferably only on the software side or supplemented by a minor hardware change. This provides the option of retrofitting. The method offers mutual checking and / or testing of the safety-relevant monitoring functions between several ASIL-SGs during runtime. This can be particularly advantageous after configuration changes, e.g., a software update or after the integration of a new control unit. The present method thus offers improved updateability of the ASIL-SGs in the monitoring network, especially for safety-relevant functions.Furthermore, if the number and / or safety integrity levels of the ASIL-SGs involved in a monitoring system are oversized (e.g., 3x B(D)), increased operational reliability can be ensured through redundancies. Furthermore, the method can output very compact error diagnostic messages, enabling implementation of the method with few additional communication resources and / or bus signals. Resource-efficient checking of the misdiagnosis messages can also be provided in ASIL-SGs, which are comparatively limited in terms of compute resources, enabling easy integration into existing E / E architectures.
[0020] For example, QM control units can be designed as particularly powerful central and / or zone control units that do not have direct access to safety-relevant actuators (e.g., servo motors in the electronic power steering system; hydraulic pumps in the ESP system), but instead provide their control commands via network or bus messages. In another implementation, central and / or zone control units can also be configured as ASIL control units and monitor QM control units.
[0021] The cross-ECU safety concept enables more cost-effective implementation of monitoring on existing ASIL ECUs (e.g., actuator and / or sensor ECUs) in the vehicle architectures. To ensure that the monitoring of safety-relevant functions is carried out cost-effectively, a safety concept is implemented that extends beyond the individual ECUs. This allows existing ASIL ECUs, such as actuator or sensor ECUs, to be used in the vehicle architecture to perform safety monitoring.
[0022] The distributed monitoring functions are preferably implemented through additional software functions and can be used on different QM-SGs without requiring special hardware or software (e.g., operating systems or middleware). In other words, the present safety concept provides for the monitoring functions to be implemented on the QM-SGs without additional hardware or special software. This ensures that the safety concept remains valid for future changes to the QM-SGs, such as hardware upgrades or software changes, without the need for recertification.
[0023] It is particularly preferred that the monitoring ASIL control units also receive regular software updates, thereby maintaining the safety integrity of the vehicle systems. During these updates, monitoring of the QM-SG can be temporarily taken over by other ASIL control units and / or a special "monitoring network" or "monitor" network to minimize potential safety risks.
[0024] This method enables the "correct" execution of safety-relevant software functions in functional control units (FCUs) to be verified at runtime by generating diagnostic messages that are exchanged in a networked group of ASIL control units. An advantageous combination of various safety mechanisms can be used to minimize the size and number of diagnostic messages transmitted within the control unit network, while maintaining a consistently high level of fault coverage. The method enables the monitoring of high-performance QM-CUs (i.e., CUs that do not themselves meet (A)SIL requirements regarding fault diagnosis) by multiple (low-performance & low-cost) monitoring ASIL-CUs. Monitoring is based on the principle of distributed diagnostic signals for identifying, in particular, transient, permanent, and / or latent errors in the execution of application software.
[0025] The distributed integrity monitoring provided here facilitates and reduces the cost of changes to the control unit network for safety-relevant processing chains, especially during the lifetime of a vehicle, and thus facilitates the implementation of business models such as software and / or hardware-based functional upgrades and / or "function as a service" business models.
[0026] In a further aspect, the provision of the at least one generated diagnostic message further comprises a provision of functional user data, in particular in the form of bus signals, by the at least one control unit.
[0027] The control unit generates at least one diagnostic message, which preferably includes information about the state or functionality of the control unit. In addition to the at least one diagnostic message, the control unit preferably provides functional payload data. This data is information relevant to the safety-relevant function execution. The functional payload data is provided in particular in the form of bus signals. Bus signals are data transmitted via the vehicle bus and allow various components, in this case the control units, of the vehicle to communicate with each other. The control unit is preferably responsible for providing both the diagnostic messages and the functional payload data. This data is crucial for monitoring and controlling safety-relevant functions in the vehicle.
[0028] In a further aspect, the checking comprises comparing the at least one generated diagnostic message with the test and / or configuration data, wherein the checking is successful if the at least one generated diagnostic message and the test and / or configuration data satisfy at least one check criterion.
[0029] Preferably, a check of the diagnostic messages generated by the control unit is performed. The check includes comparing the generated diagnostic messages with the test and / or preferably includes configuration data. This data preferably serves as a reference for the expected state or conditions. The check is considered successful if the generated diagnostic message and / or the test and / or configuration data meet at least one test criterion. This means that the generated diagnostic message matches the expectations specified in the test and / or configuration data.
[0030] In a further aspect, if at least one confirmation signal has not been received or depending on the status of the test result, for example, if at least one of the provided confirmation signals is “not OK”, error recovery and / or error correction is initiated.
[0031] By way of example only, if at least one confirmation signal was not received or the status of at least one of the provided confirmation signals is classified as "not OK," error recovery and / or error correction is preferably initiated. The system preferably detects that an error has occurred if the expected confirmation signals are not received or if, for example, the status of one or more signals is set to "not OK." Following error detection, measures are then preferably taken to resolve or correct the error. This may include reconfiguring, rebooting, or otherwise repairing the affected system to ensure the safety and functionality of the vehicle.The error correction and / or error rectification is preferably initiated automatically by the system, semi-automatically or manually by a user as soon as the defined conditions for an error are met.
[0032] In a further aspect, at least two ASIL control units are assigned to the at least one control unit, wherein the at least two ASIL control units, in particular together with the at least one control unit, form a monitoring network in order to monitor the at least one control unit.
[0033] There is preferably at least one control unit that plays a central role in monitoring and controlling safety-relevant functions in the vehicle. At least two ASIL control units are assigned to the control unit. ASIL stands for Automotive Safety Integrity Level and characterizes the safety integrity of control units in the vehicle according to the ISO 26262 standards. The assigned ASIL control units, together with the control unit, preferably form a monitoring network. This means that these control units preferably work closely together to ensure the safety and integrity of the system. The monitoring network is preferably responsible for monitoring safety-relevant functions in the QM control unit, providing test and / or configuration data, evaluating diagnostic information derived from this, detecting errors, and initiating troubleshooting measures if necessary.Therefore, the safety load is preferably decomposed into several ASIL-SG monitors, preferably at least two ASIL-SG monitors. These together form a monitoring network and check the diagnostic messages provided by the QM-SG for potential (runtime) errors.
[0034] In a further aspect, in the case of an update of the first of the n ASIL control units, the functions of the first of the n ASIL control units are taken over by at least one other of the n-1 ASIL control units until the update is completed and / or testing of the updated or modified first of the n ASIL control units is completed.
[0035] If an update or change is carried out for the first of the n ASIL control units that monitors the safety functions in the vehicle, it is preferable if the first of the n ASIL control units is only ready for monitoring again once the update or change has been completed and / or the updated or changed first of the n ASIL control units has been successfully tested and is therefore functional again for the safety check. During the update or change process, at least one other of the n-1 ASIL control units takes over the functions of the updated or changed control unit. This ensures the continuity and safety of the functions in the vehicle, even if the first of the n ASIL control units is temporarily unavailable. The functions taken over by the updated or changed ASIL control unit are preferably taken over by the other control unit until the update or change is completed.The change has been completed and / or at least one test, which may be multi-stage, has been successfully completed on the first of the n ASIL control units. Temporarily taking over the functions of another control unit ensures that the safety and integrity of the vehicle are maintained during the update process.
[0036] In a further aspect, the testing comprises exchanging diagnostic messages between the updated or modified first of the n ASIL control units and the at least one further one of the n-1 ASIL control units for the plausibility check of the updated or modified first of the n ASIL control units and / or testing temporarily simulated errors.
[0037] After the first of the n ASIL control units has been updated or modified, a test process is carried out to ensure that the updated control unit functions correctly and fully meets the safety requirements regarding its monitoring functions in the monitoring network. During the test process, an exchange of diagnostic messages preferably takes place between the updated or modified first of the n ASIL control units and at least one other of the n-1 ASIL control units. This exchange preferably serves to check the correctness and plausibility of the information, in particular the confirmation signals, generated by the updated control unit. The exchange of diagnostic messages checks the plausibility of the information generated by the updated first of the n ASIL control units.This is a step in the testing process to ensure that the updated ASIL control unit functions properly and provides reliable information. The testing process, which involves exchanging diagnostic messages, aims to ensure that the updated control unit performs its functions properly. Specifically, it ensures that potential faults in the monitored QM control unit are reliably diagnosed and signaled by the updated ASIL control unit even after the update, and that the vehicle's safety is not compromised by the update.
[0038] The “temporarily simulated errors” can, for example, be generated by an ASIL control unit in order to provoke or cause a monitoring reaction of the most recently updated ASIL control unit in order to test this ASIL control unit.
[0039] In a further aspect, the updated or modified first of the n ASIL control units is reconfigured after successful testing into the functional position that was assigned to the first of the n ASIL control units before the update or modification.
[0040] For example, the first of the n ASIL ECUs is updated or modified, possibly to add new functions, fix bugs, or improve performance. After the update or modification, the updated ECU undergoes a testing process to ensure that it functions correctly and meets safety standards. After successful testing, the updated or modified ECU is reconfigured to the functional position assigned to the first of the n ASIL ECUs before the update or modification. This means that the ECU regains its original configuration, settings, and functions. The reconfiguration ensures that the continuity of functions in the vehicle is guaranteed. The vehicle can continue to be operated safely after the update because the updated or modified ECU retains its previous functions and settings.
[0041] In a further aspect, a computer program with program code is claimed for carrying out at least parts of the present method in one of its aspects when the computer program is executed on a computer. In other words, a computer program (product) comprising instructions that, when executed by a computer, cause the computer to carry out the method(s) of the method in one of its aspects.
[0042] In a further aspect, a computer-readable data carrier with program code of a computer program is proposed for executing at least parts of the present method in one of its aspects when the computer program is executed on a computer. In other words, the invention relates to a computer-readable (storage) medium comprising instructions that, when executed by a computer, cause the computer to execute the method(s) of the method in one of its aspects.
[0043] The described designs and further training courses can be combined as desired.
[0044] Further possible embodiments, further developments and implementations of the invention also include combinations of features of the invention described previously or below with regard to the embodiments that are not explicitly mentioned. Short description of the drawings
[0045] The accompanying drawings are intended to provide a further understanding of embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain principles and concepts of the invention.
[0046] Other embodiments and many of the aforementioned advantages will become apparent upon review of the drawings. The elements illustrated in the drawings are not necessarily drawn to scale.
[0047] They show: Fig. 1 is a schematic flow diagram of one aspect of the method; Fig. 2 a schematic flow diagram of another aspect of the method; Fig. 3 is a schematic block diagram of an aspect of the system; and Fig. 4 a schematic block diagram of another aspect of the system.
[0048] In the figures of the drawings, the same reference symbols designate the same or functionally equivalent elements, parts or components, unless otherwise stated.
[0049] Fig. 1 shows a schematic flow diagram of a method for activating a safety-relevant function of a vehicle. Fig. 1 shows a flowchart of a distributed diagnosis for an ECU, which generates user data for a function control unit and is monitored by n ASIL ECUs.
[0050] The vehicle itself, which is not shown in detail, has a number of n ASIL control units 300, at least one control unit 302 to be monitored and a function control unit 304 (see Fig. 3). The number n is preferably greater than or equal to two (n ≥ 2).
[0051] In any embodiment, the method may be performed at least in part by a system 100.
[0052] The computer-implemented method comprises at least the following steps: In a step S1, test and / or configuration data are provided by a first of the n ASIL control units to at least one further one of the n-1 ASIL control units and to the at least one control unit.
[0053] In a step S2, the provided test and / or configuration data are processed by the at least one control unit to generate at least one diagnostic message.
[0054] In a step S3, the at least one generated diagnostic message is provided at least to the first of the n ASIL control units and the at least one further one of the n-1 ASIL control units by the at least one control unit.
[0055] In a step S4, the at least one generated diagnostic message is checked by the first of the n ASIL control units and the at least one further one of the n-1 ASIL control units to provide a test result, for example an “OK” test result or a “not OK” test result.
[0056] In a step S5, at least one confirmation signal is provided by the first of the n ASIL control units and the at least one further one of the n-1 ASIL control units to the function control unit on the basis of the test result.
[0057] In a step S6, the function control unit checks the receipt and status of the respective confirmation signal provided.
[0058] In a step S7, user data of the at least one control unit is transmitted to the function control unit and the safety-relevant function is activated S8 on the basis of the transmitted user data if all confirmation signals have been received and depending on a respective status of the respective test result, for example if the status of all provided confirmation signals is “OK”, or the safety-relevant function is not activated S9 on the basis of the transmitted user data if at least one confirmation signal has not been received or depending on the status of the respective test result, for example if the status of at least one of the provided confirmation signals is “not OK”.
[0059] Fig. 2 shows an aspect of the method in a case of an update or change of the first of the n ASIL control units 300.
[0060] Before the update, S200, of the first of the n ASIL control units 300, this control unit, possibly together with at least one other of the n-1 ASIL control units 300, is assigned a functional position for monitoring a performance and / or a function of the at least one control unit 302 by exchanging and evaluating the diagnostic messages.
[0061] In preparation for the update, S202, the functions or functional status of the first of the n ASIL control units 300 are taken over by at least one other of the n-1 ASIL control units until the update or change is completed and / or testing of the updated or modified first of the n ASIL control units 300 is completed. Thus, the first of the n ASIL control units 300 is released from its functional status for the update.
[0062] The monitoring of a performance and / or a function of the at least one control unit 302 by exchanging and evaluating the diagnostic messages is then taken over by the at least one further one of the n-1 ASIL control units 300, which is indicated by S204.
[0063] The update is performed in step S206.
[0064] After the update or modification of the first of the n ASIL control units 300, testing is performed in S208 by exchanging diagnostic messages between the updated or modified first of the n ASIL control units 300 and at least one further one of the n-1 ASIL control units 300 to verify the plausibility of the correct functioning of the updated or modified first of the n ASIL control units 300.
[0065] In a second test phase, testing is carried out in S210 by exchanging diagnostic messages between the updated or modified first of the n ASIL control units 300 and the at least one control unit 302, and by checking the exchanged diagnostic messages by the at least one further one of the n-1 ASIL control units 300.
[0066] In S212, the updated or modified first of the n ASIL control units 300 is reconfigured after successful testing S208, S210 to the original functional position (see step S200) that was assigned to the first of the n ASIL control units 300 before the update or modification.
[0067] Fig. 3 shows an aspect of the system 100. The system 100 has a plurality of ASIL control units 300 (in Fig. 3 also ASIL-ECUs 1-N). The system 100 further comprises several control units 302 (in Fig. 3 also QM-ECUs 1-N) and a function control unit 304 (also Receiver ECU). The ASIL control units 300 are connected to the control units 302 and the function control unit 304 via a data bus 306 (data bus) for data exchange. Data exchange takes place via the data bus 306.
[0068] Fig. 4 shows an aspect of the method and / or system 100 in which at least two of the n ASIL control units 300 can be combined as a monitoring network 400, 402 to enable uninterrupted monitoring of the at least one control unit 302. At least two of the n ASIL control units 300 are assigned to the at least one control unit 302, which, in particular, together with the at least one control unit, form a monitoring network to monitor the at least one control unit. QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] DE 10 2008 043 089 A1
[0006]
Claims
[1] Method for activating a safety-related function of a vehicle, the vehicle comprising n ASIL control units (300), at least one control unit to be monitored (302) and a function control unit (304), wherein n ≥ 2, the method comprising the steps: - Provision (S1) of test and / or configuration data by a first of the n ASIL control units (300) to at least one further of the n-1 ASIL control units (300) and to the at least one control unit (302); - Processing (S2) the provided test and / or configuration data by the at least one control unit (302) to generate at least one diagnostic message; - Providing (S3) the at least one generated diagnostic message to at least the first of the n ASIL control units (300) and the at least one further of the n-1 ASIL control units (300) by the at least one control unit (302); - Checking (S4) the at least one generated diagnostic message, in particular using the provided test and / or configuration data, by the first of the n ASIL control units (300) and the at least one further of the n-1 ASIL control units (300) to provide a test result; - Provide (S5) at least one confirmation signal by the first of the n ASIL control units (300) and at least one further of the n-1 ASIL control units (300) to the function control unit (304) based on the test result; - Check (S6), by the function control unit (304), of the receipt and status of the respective confirmation signal provided; and - Transmitting (S7) user data from at least one control unit (302) to the function control unit (304); and - Activation (S8) of the safety-relevant function based on the transmitted user data, when all confirmation signals have been received and depending on the respective status of the respective test result, or - Non-activation (S9) of the safety-relevant function based on the transmitted user data if at least one confirmation signal has not been received or depending on the respective status of the respective test result. [2] Method according to claim 1, wherein the provision (S3) of the at least one generated diagnostic message further comprises the provision of functional user data, in particular in the form of bus signals, by the at least one control unit (302). [3] Method according to claim 1 or 2, wherein the verification (S4) comprises comparing the at least one generated diagnostic message with the test and / or configuration data, wherein the verification is successful if the at least one generated diagnostic message and the test and / or configuration data satisfy at least one test criterion. [4] Method according to one of the preceding claims, wherein, if at least one confirmation signal has not been received or depending on the respective status of the respective test result and / or the respective status of at least one of the provided confirmation signals, an error correction and / or error rectification is initiated. [5] Method according to one of the preceding claims, wherein at least two of the n ASIL control units (300) are assigned to the at least one control unit (302), wherein the at least two ASIL control units (300) in particular together with the at least one control unit (302) form a monitoring network to monitor the at least one control unit (300). [6] Method according to one of the preceding claims, wherein in the event of an update and / or a change of the first of the n ASIL control units (300), the functions of the first of the n ASIL control units (300) are taken over by at least one further of the n-1 ASIL control units until the update or change is completed and / or testing of the updated or changed first of the n ASIL control units (300) is completed. [7] Method according to claim 6, wherein the testing comprises an exchange of diagnostic messages between the updated or modified first of the n ASIL control units (300) and the at least one further of the n-1 ASIL control units (300) to validate the behavior of the updated or modified first of the n ASIL control units (300). [8] Method according to claim 6 or 7, wherein the testing comprises an exchange of diagnostic messages between the updated or modified first of the n ASIL control units (300) and the at least one control unit (302), as well as a verification of the exchanged diagnostic messages by the at least one further of the n-1 ASIL control units (300) and / or a testing of temporarily simulated faults. [9] Method according to any one of claims 6 to 8, wherein the updated or modified first of the n ASIL control units (300) is reconfigured after successful testing to the functional position that was assigned to the first of the n ASIL control units (300) before the update or modification. [10] Computer program with program code to execute at least parts of a method according to any one of claims 1 to 9 when the computer program is executed on a computer. [11] Computer-readable data carrier containing program code of a computer program for executing at least parts of a method according to any one of claims 1 to 9 when the computer program is executed on a computer. [12] System (100) for activating a safety-related function of a vehicle, the system (100) comprising n ASIL control units (300), at least one control unit to be monitored (302) and a function control unit (304), wherein n ≥ 2, - wherein a first of the n ASIL control units (300) is configured to provide test and / or configuration data to at least one further of the n-1 ASIL control units (300) and to the at least one control unit (302); - wherein the at least one control unit (302) is configured to process the provided test and / or configuration data to generate at least one diagnostic message; and to provide the at least one generated diagnostic message to at least the first of the n ASIL control units (300) and the at least one further of the n-1 ASIL control units (300); - wherein the first of the n ASIL control units (300) and the at least one further of the n-1 ASIL control units (300) are each configured to verify the at least one generated diagnostic message, in particular using the provided test and / or configuration data, to provide a test result, and each to provide at least one confirmation signal based on the test result to the function control unit (304); - wherein the function control unit (304) is configured to check the receipt and status of the respective confirmation signal provided; - wherein at least one control unit (302) is configured to transmit user data to the function control unit (304), and - wherein the function control unit (304) is configured to, to activate the security-relevant function based on the transmitted user data when all confirmation signals have been received and depending on the respective status of the respective test result, or o not to activate the security-relevant function based on the transmitted user data if at least one confirmation signal has not been received or depending on the respective status of the respective test result.
Citation Information
Patent Citations
Methods for monitoring the functionality of an electronic component
DE102008043089A1
Control unit for a motor vehicle, motor vehicle and method for safely performing a function
DE102014014858A1
updating a software scope of a means of transport
DE102017201467A1
Software installation in vehicle control units
DE102019131087A1