CONTROL UNIT FOR A VEHICLE
Patent Information
- Application Number
- DE502020011251
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-09-26
- Filing Date
- 2020-09-23
- Publication Date
- 2025-07-10
- Estimated Expiration
- 2040-09-23
AI Technical Summary
Existing vehicle control systems lack sufficient redundancy in communication and power networks, which can lead to sudden failures in critical functions like braking and steering, especially during automated driving.
A control system with independently redundant communication and low-voltage networks, along with a diagnostic module that selectively degrades non-critical systems to maintain minimum functionality for safety-relevant systems.
Ensures continuous electrical power supply and message transmission even in the event of network failures, supporting the vehicle's transition to a safe state and maintaining essential driving functions.
Description
[0001] The invention relates to a control device for a vehicle. The invention further relates to a control system for a vehicle. The invention further relates to a method for operating a control system for a vehicle. The invention further relates to a computer program product. State of the art
[0002] The patent DE 101 35 736 C1 discloses a method for controlling a clutch of a steer-by-wire steering system.
[0003] The patent US 7,439,634 B2 discloses a system for distributing electrical power.
[0004] Known automated driving functions require a certain bridging and handover time to the driver, particularly in cases where the driver is required to take over control of the vehicle. This enables the driver to assess the driving situation and assume proper vehicle control functions again. Possible vehicle control functions that the driver may assume after a handover period from an automated driving function may include decelerating and steering the vehicle. In other possible cases, the driver may need to correct the longitudinal and lateral movement functions of the automated driving functions, for example, to complete an overtaking maneuver or to guide the vehicle out of an intersection, construction site, tunnel, railway tracks, etc.
[0005] DE 10 2016 215 564 A1 discloses a method for operating an electrical network of a motor vehicle, in which a value of a parameter relating to a current situation of a power supply of electrical components of the electrical network is determined and only those electrical components of the network which are not necessary for a predefined emergency operation of the motor vehicle are switched off depending on the determined value.
[0006] DE 10 2015 008 005 A1 discloses a method for operating a motor vehicle, wherein a first electrical system has a first battery and a generator, a second electrical system has a second battery and the electrical systems are coupled via a DC / DC converter and electrical power from the first battery and from the generator is transmitted to the second electrical system by means of a voltage conversion of the DC / DC converter. The first electrical system should be able to supply the second electrical system even in the event of a failure of the first battery and / or a defect in the DC / DC converter. For this purpose, it is proposed that a detection device detects the failure of the first battery and / or the DC / DC converter and, upon detected failure, a switching device short-circuits the electrical systems to one another and sets a controller setpoint of the generator to a voltage of the second electrical system.
[0007] US 2018 / 257703 A1 discloses a control device for a vehicle, comprising: an interface for connecting to a communication network and interfaces for electrically supplying the control device via two independently redundant low-voltage networks, each of which is galvanically isolated from one another.
[0008] Particularly in automated driving, it is essential that safety-relevant functions are designed to be fault-tolerant, so that electronic functions are available even in the event of a fault. Here, redundancy has a dual function: fault detection and increasing function availability. This poses a particular risk while driving, particularly for longitudinal and lateral movement functions, such as those implemented using braking and steering systems, because (if relevant functions and components fail) the vehicle can suddenly no longer be braked, steered, etc. Communication and the power supply should be switchable with virtually no interruption, so that the performance of the vehicle functions is not suddenly reduced or leads to vibrations in the braking, steering, and drive functions. Disclosure of the invention
[0009] It is an object of the present invention to provide an improved control system for a vehicle.
[0010] The object is achieved according to a first aspect with a control unit for a vehicle, comprising: Interfaces for connecting to two independently redundant communication networks, each of which is galvanically isolated from one another, wherein, in the event of a failure of a first communication network, messages can be transmitted to and from the control device via a second communication network, and vice versa; wherein a fault in one of the communication networks does not affect the functionality of the other of the communication networks; and interfaces for electrically supplying the control device via two independently redundant low-voltage networks, each of which is galvanically isolated from one another, wherein, in the event of a fault in a first low-voltage network, an electrical supply to the control device can be carried out via a second low-voltage network, and vice versa;wherein, by means of the control device, electrical consumers of the vehicle can be selectively switched depending on diagnostic information relating to the networks transmitted via the interfaces, wherein a minimum functionality for safety-relevant systems of the vehicle is maintained by the selective switching of the consumers.
[0011] This creates a control system that can still be supplied with electrical power and transmit messages in the event of a fault in one of the networks. Such an independently redundant control system supports the transition of the vehicle to a safe state in the event of a fault.
[0012] According to a second aspect, the object is achieved with a control system for a vehicle, comprising: two independently redundant high-voltage networks for providing electrical energy; two independently redundant low-voltage networks for providing electrical control voltage; wherein the two low-voltage networks are each galvanically isolated from one another, and two independently redundant communication networks for transmitting messages between control devices connected to the communication networks; wherein the two communication networks are each galvanically isolated from one another and a degradation device for diagnosing errors in the networks and for selectively degrading the control devices connected to the networks, wherein the control system offers sufficient functionality for driving the vehicle, wherein the control devices are each a control device according to claim 1.
[0013] The object is achieved according to a third aspect with a method for operating a vehicle, comprising the steps:Diagnosing independently redundant and functionally interconnected high-voltage, low-voltage, and electrical communication networks of a control system of the vehicle; wherein the low-voltage networks are each galvanically isolated from one another, and wherein the communication networks are each galvanically isolated from one another; transmitting the diagnostic result to independently redundant battery management devices of the control system, wherein a fault in a first battery management device does not impair the functionality of a second battery management device, and vice versa;and selectively downgrading control devices connected to the electrical high-voltage, electrical control voltage, and electrical communication networks depending on the diagnostic result in such a way that control devices connected to the electrical power supply, electrical control voltage, and electrical communication networks are still sufficiently functional for safe driving of the vehicle; whereby the selective degradation of the control devices maintains a minimum functionality for safety-relevant systems of the vehicle.
[0014] As a result, the proposed method provides an independent, fully redundant power, supply voltage, and communication concept for a vehicle, which can partially evacuate a fault situation and provide as much functionality as required for safe vehicle operation. As a result, the proposed method provides a so-called "soft degradation" of functionalities, so that there are no abrupt functional impacts or functional losses. The proposed method is suitable for all vehicle types, but is particularly useful for purely battery-electric vehicles because these vehicles do not have an electrical power generation system coupled to an internal combustion engine and are therefore particularly affected by a complete failure of a high-voltage grid.
[0015] Advantageously, the proposed method maintains a minimum level of functionality for safety-relevant vehicle systems (sufficient functionality). As a result, electrical supply voltages for the control units and actuators, as well as electrical energy for driving, steering, or braking the vehicle, can be continuously provided.
[0016] According to a fourth aspect, the task is solved using a computer program.
[0017] Advantageous further developments of the method and the control system are the subject of dependent claims.
[0018] An advantageous development of the control system provides that the degradation device comprises a diagnostic module for performing the diagnosis and a battery management device for selectively degrading the control devices. This effectively creates a central intelligence for the control system, which performs a diagnosis and initiates and executes the relevant degradations.
[0019] A further advantageous development of the control system provides that, using the diagnostic module, a preventive and / or actual diagnosis of lines connected to the networks and a selective shutdown of control devices connected to the networks can be initiated and carried out. In this context, an "actual diagnosis" is understood to mean a diagnosis based on measured values and message information. Depending on the selected safety strategy, this allows for highly dynamic and flexible degradation of devices and networks.
[0020] A further advantageous development of the control system provides that, in the event of a fault in a high-voltage network, a DC / DC converter can be switched off and a battery can be switched on to supply power to one of the low-voltage networks. This is particularly useful if only a DC / DC converter is intended to generate the 12V control voltage for the electrical supply of electronic control units.
[0021] A further advantageous development of the control system provides for the diagnostic module and the battery management devices to be mutually monitored. This enables cross-monitoring, which advantageously increases the safety level of the control system.
[0022] A further advantageous development of the control system provides that the battery management device can determine the status of the grids, with corresponding data being transmitted via communication interfaces. This advantageously creates a kind of "central intelligence" of the control system, which supports rapid information exchange.
[0023] A further advantageous development of the method provides for a selective shutdown of electrical loads to be delayed or carried out with predetermined degradation control signals. This enables a time-delayed degradation to implement a "soft degradation."
[0024] A further advantageous development of the method provides that at least one of the control devices: brake control unit, steering control unit, control unit for driver assistance systems, control unit for engine management, is kept operational for driving the vehicle. For this purpose, at least two, even better several, and ideally all control units are interconnected to form a system that maintains basic vehicle functions. For example, a failure of an electrical control voltage in a low-voltage network does not lead to a failure of the electronic control units connected to it.
[0025] A further advantageous development of the method provides that a diagnostic-based selective shutdown of electrical consumers connected to the grid leads to smooth switchovers during which the vehicle does not perform any abrupt movements. This advantageously maintains a high level of driving comfort and safety even in the event of a vehicle malfunction.
[0026] A further advantageous development of the control system provides for one of the high-voltage networks to be connected to the other high-voltage network via a coupling switch. This can be advantageously used for mutual charging of the high-voltage batteries, series connection of the high-voltage batteries, energy balancing of the high-voltage batteries, etc.
[0027] The invention, along with further features and advantages, is described in detail below with reference to the figures. The figures are primarily intended to illustrate the principles essential to the invention.
[0028] Disclosed method features result analogously from corresponding disclosed device features, and vice versa. This means, in particular, that features, technical advantages, and embodiments relating to the control system result analogously from corresponding embodiments, features, and advantages relating to the method for operating a control system for a vehicle, and vice versa.
[0029] In the figures shows: Fig. 1 is a block diagram of an embodiment of a proposed control system for a vehicle; Fig. 2 is a basic block diagram of a proposed control device; and Fig. 3 is a basic representation of a proposed method for operating a control system for a vehicle. Description of embodiments
[0030] In the following, the term "automated vehicle" is used synonymously to mean fully automated vehicle, partially automated vehicle, fully autonomous vehicle and partially autonomous vehicle (synonym: SAE Level 2 / 3, 4 / 5).
[0031] Most errors that jeopardize the safe operation of an automated vehicle are based, among other things, on cascades. For example, a fault in a high-voltage battery leads to shutdowns, which can affect a 12V battery via a DC / DC converter. If the 12V power supply or communication to an electric motor's control electronics (inverter) is interrupted, the control electronics can open battery contactors and dissipate energy from the high-voltage network via the electric motor's windings. Various prescribed high-voltage regulations require the implementation of the following shutdown cascades, which lead to a high-voltage shutdown: Terminal 15 failure, blown fuse, high-voltage enable line, wire break, communication failure to the inverter, battery management systems, driver command control unit (VCU), etc., HV interlock (safety function to protect against high-voltage interference), inverter failure, high-voltage battery failure, failure of other consumers (e.g., cooler / fan, etc.), critical EMC influences, faulty conditions (e.g., faulty crash detection).
[0032] Essentially, all of the errors mentioned can cause massive pulsations in the vehicle's high-voltage and low-voltage networks before they lead to active shutdown, which are generally tolerated due to the inertia of the shutdown elements (e.g., fuses, software thresholds, etc.). These pulsations place an undesirable strain on the 12V battery and can massively reduce its service life. Many of the 12V consumers, such as the radiator fan motor, EPS motor, ESP motor or actuator, etc., also have the potential to feed electrical energy into the vehicle electrical system in certain situations, which can further amplify the pulsations in the vehicle electrical system. Furthermore, the vehicle can become destabilized by vibrations in the drive train and / or the driver can be massively irritated by the behavior of the pedals or steering wheel.
[0033] Since such faults can occur in all consumers and in the interconnected lines, a selective shutdown of elements or devices of a vehicle's control system is proposed. This involves identifying or preemptively diagnosing the cause of the fault and, as a consequence, selective shutdown of elements or devices of the control system in such a way that a basic driving function of the vehicle is still provided.
[0034] This is achieved by transmitting fault information diagnosed by a diagnostic module to a battery management system, which, in conjunction with the diagnostic module, shuts down the affected electrical circuits and switches the low-voltage power supply to available DC / DC power sources or other electrical power sources. This is achieved by the diagnostic module acting as a selective shutdown or switchover device.
[0035] Fig. 1 shows an electrical-electronic architecture (E / E architecture) of a proposed control system 100 for a vehicle that can provide a proposed functionality. Two independently redundant high-voltage batteries 1a, 1b (with, for example, 400V DC voltage) can be seen, each feeding a high-voltage network HN1, HN2 and being connected to or disconnected from the high-voltage network HN1, HN2 via an associated battery management device 2a, 2b. Furthermore, a switch S for defined switching (e.g. charging, balancing charge energy, connecting in series, etc.) of the high-voltage batteries 1a, 1b can be controlled by means of the battery management devices 2a, 2b. An electric motor M1, M2 of the high-voltage networks HN1, HN2 is controlled via a respective power electronics unit 11a, 11b.
[0036] Furthermore, control system 100 includes a first low-voltage network NV1 and a second low-voltage network NV2, each supplied with 12V electrical energy (electrical control voltage) by a DC / DC converter 3a, 3b. Advantageously, a 12V accumulator 4 can be connected to one of the low-voltage networks NV1 in the event of a fault. This is particularly useful, for example, if, due to a failure of the high-voltage batteries 1a, 1b, the DC / DC converters 3a, 3b subsequently no longer provide a 12V supply voltage for the low-voltage networks NN1, NN2. Furthermore, a charging device 12 can also be connected to the low-voltage network NN2 instead of the DC / DC converter 3b. The 12V accumulator 4 can be charged by means of the charging device 12.
[0037] Furthermore, a first communication network KN1 and a second communication network KN2 are provided in the control system 100, which can be designed, for example, as a CAN bus, Ethernet, etc. Central communication interfaces 9a, 9b (gateways) and a brake control unit 8 (e.g., integrated power brake, IPB) for local control of wire-controlled braking or deceleration of the vehicle are connected to the communication networks KN1, KN2. Messages for controlling electronic control units of the control system 100 are transmitted via the aforementioned communication networks KN1, KN1. A steering control unit 5, a control unit for recording a driving request 6, a control unit for automated driving 7, and a brake control unit 8 can be provided as electronic control units. Further, not described in Fig. 1 Electronic control units are shown. A so-called "degradability" of networks and consumers of the control system 100 is controlled in particular by a diagnostic module 10, which, in cooperation with the battery management systems 2a, 2b, performs a preventive diagnosis (e.g., determination of resistance changes due to line breaks, aging effects, vibrations, temperature effects, short-term critical electrical voltage requirements, etc.) of all lines of all networks, HN1, HN2, NN1, NN2, KN1, KN2, and thereby causes a selective switching of the consumers and generators or control devices connected to the control system 100 in such a way that basic driving functions (e.g., steering, braking, steering, navigation, etc.) of the vehicle are still provided even after the defect has occurred.
[0038] The proposed control system 100 for a vehicle enables the following advantageous functions, which are mentioned below only as examples: The electrical control voltage of the 12V low-voltage networks NN1, NN2 is assigned to the communication level with the communication networks KN1, KN2 and the available redundancies. This means that due to the existence of the two independently redundant low-voltage networks NN1, NN2 and the two independently redundant communication networks KN1, KN2, the electronic control units are each connected to the same line (low-voltage and communication network), because otherwise availability is reduced in the event of a failure of the 12V supply and communication. With the proposed method, for example,Although an electronic control unit may fail completely, the remaining available control units can maintain the nominal function (usually with reduced performance) of the failed control unit or provide a degraded function of the failed function. Due to the independent redundancy, it is advantageous in this way that a fault in one of the networks NN1, NN2, KN1, KN2, HN1, HN2 cannot impair the functionality of another network NN1, NN2, KN1, KN2, HN1, HN2 assigned to the respective network NN1, NN2, KN1, KN2, HN1, HN2. Essential vehicle systems for ensuring the journey to a safe standstill or state (fail-state or fail-operational state), such as brakes and steering, are each connected to the two communication networks KN1, KN2 and to the two 12V low-voltage networks NN1, NN2, which are each galvanically or "sufficiently safely" separated from each other.
[0039] All high-voltage consumers are preferably connected to the two high-voltage networks HN1 and HN2, so that high-voltage shutdowns only affect one line (including the high-voltage, low-voltage, and communication networks), and a high-voltage consumer remains functional even if one high-voltage network is completely shut down. Each line should preferably be assigned to the first and second low-voltage and communication networks to ensure that faults in the high-voltage network and high-voltage operational shutdowns do not lead to faults in other networks.
[0040] The diagnostic module 10 is intended in particular for preventive diagnostics of the lines of all networks with recording and / or simulation of electrical line resistances and electrical currents and can provide the consumers connected to the networks with corresponding information so that defined consumers can be preventively switched off or evacuated from the assigned network before a fault occurs.
[0041] Degradable consumers include, for example, a control unit 7 for driver assistance systems, which is preferably connected to a different low-voltage network NN1, NN2 than a control unit 6 for engine and thermal management. This advantageously supports the fact that a failure or shutdown of the control unit 7 for driver assistance systems can be at least partially compensated by the control unit 6 for engine and thermal management, and vice versa.
[0042] It can thus be seen that control units, energy systems, drives and networks in the proposed control system 100 are arranged and functionally connected to one another in such a way that in the event of a vehicle fault (e.g. due to an accident), all control units, energy systems, drives and networks can never be damaged or fail simultaneously.
[0043] The line diagnostics performed by diagnostic module 10 should therefore not only diagnose the high-voltage networks HV1 and HV2, but also diagnose the low-voltage networks NV1 and NV2, consolidating these into a potential degradation scenario. Diagnostic module 10 can be used to proactively switch and deactivate all devices connected to the networks (predictive maintenance).
[0044] The diagnostic information relating to the low-voltage and high-voltage networks is made available to the battery management devices 2a, 2b in real time, if possible, so that this diagnostic information can be recorded together with the battery states of the high-voltage batteries 1a, 1b. In this way, the battery management devices 2a, 2b can selectively disconnect or switch off the corresponding high-voltage networks HN1, HN2 using contactors and / or circuit breakers 12a, 12b to prevent error propagation. The battery management devices 2a, 2b are control units that are connected to other control units via various hard-wired signals and also via bus systems (e.g., CAN bus, etc.). Faults in the high-voltage networks, in the connections, in the communication, in the cooling water, etc. often require the battery management device 2a, 2b to open contactors and thus open circuits.
[0045] In addition, a so-called ''degradation manager" (not shown) may be provided to control the proposed selective degradation.
[0046] Critical consumers in the low-voltage networks NN1 and NN2 can be identified and selectively shut down by the proposed monitoring system, as long as the availability of a key vehicle control function is not compromised. Since all vehicle control functions already have redundant 12V supplies, critical circuits can be shut down using the battery management systems 2a and 2b, as required for emergency operation of the automated vehicle.
[0047] Furthermore, the battery management devices 2a, 2b can also switch off critical circuits, as is necessary for emergency operation of the control system 100. By means of the battery management devices, the 12V supply can be maintained via the DC / DC converters 3a, 3b as long as the high-voltage batteries 1a, 1b are capable of maintaining the electrical energy supply at a low level.
[0048] Furthermore, depending on the cause of the faults, the battery management devices 2a, 2b can also initiate the selective shutdown of the high-voltage networks HN1, HN2 and the low-voltage networks NN1, NN2.
[0049] With the proposed control system 100, a degradation of the networks and the devices connected to the networks can be carried out in such a way that a vehicle equipped with the control system 100 can be transferred to a safe state.
[0050] For this purpose, it is intended that messages transmitted to the control devices are checked for consistency and plausibility regarding the functionality of the vehicle's driving functions.
[0051] Fig. 2 shows a basic block diagram of a control unit or control device, in this case a steering control unit 5 of the vehicle. Two inputs 5a, 5b are visible for connecting to the two communication networks KN1, KN2 and two inputs 5c, 5d for connecting to the low-voltage networks NN1, NN2 for providing 12V power supply. The interfaces 5a, 5b and 5c, 5d are each independently redundant, which means that a failure of a connected network KN1, KN2, NN1, NN2 cannot adversely affect the operation of the control unit. A galvanic isolation of the inputs 5a, 5c from the inputs 5b, 5d, which supports functional independence of the aforementioned inputs, is provided in Fig. 2 Graphically indicated by dividing lines. This ensures that both the messages transmitted via the communication networks KN1, KN2 and the electrical supply via the low-voltage networks NN1, NN2 are guaranteed at all times, even in the event of a vehicle fault.
[0052] Fig. 3 shows a basic flow of an embodiment of the proposed method.
[0053] In a step 200, a diagnosis of independently redundant and functionally interconnected electrical high-voltage, low-voltage and electrical communication networks HN1, HN2, NN1, NN2, KN1, KN2 of a control system 100 of the vehicle is carried out.
[0054] In a step 210, the diagnostic result is transmitted to independently redundant battery management devices 2a, 2b of the control system 100, wherein a fault in a first battery management device does not impair the functionality of a second battery management device, and vice versa.
[0055] In a step 220, devices of the electrical high-voltage, electrical control voltage and electrical communication networks HN1, HN2, NN1, NN2, KN1, KN2 are selectively downgraded depending on the diagnosis result in such a way that devices connected to the electrical power supply, electrical control voltage and electrical communication networks HN1, HN2, NN1, NN2, KN1, KN2 are still sufficiently functional.
[0056] Advantageously, the proposed method can be implemented in the form of a software program with suitable program code means, which runs on the diagnostic module 10 and the battery management devices 2a, 2b. This allows for easy adaptability of the method.
[0057] As a result, a system of interconnected control units can be realized, which for a defined functionality has at least one control unit that provides associated information or data via a communication network and an associated control unit that receives the information via the communication network and converts it into actuation for the vehicle.
[0058] A typical application scenario of the invention could be an automated vehicle with functions higher than SAE Level 2, in which the driver is replaced by a machine system for a defined period of time during driving.
[0059] The person skilled in the art will combine the features of the invention in a suitable manner without deviating from the essence of the invention.
Claims
1. Control apparatus (5; 6; 7; 8; 10) for a vehicle, having: - interfaces (5a, 5b) for connecting to two independently redundant communication networks (KN1, KN2) that are each galvanically isolated from one another, wherein, in the event of a failure of a first communication network (KN1), messages are able be transmitted to and from the control apparatus (5; 6; 7; 8; 10) by way of a second communication network (KN2), and vice versa, wherein a failure of a connected communication network (KN1, KN2) is not able to adversely affect the functioning of the control apparatus (5; 6; 7; 8; 10); and - interfaces (5c, 5d) for supplying electrical power to the control apparatus (5; 6; 7; 8; 10) by way of two independently redundant low-voltage networks (NN1, NN2) that are each galvanically isolated from one another, wherein, in the event of a fault in a first low-voltage network (NN1), electrical power is able to be supplied to the control apparatus (5; 6; 7; 8; 10) by way of a second low-voltage network (NN2), and vice versa, wherein the control apparatus (5; 6; 7; 8; 10) comprises a diagnostic module (10), wherein the diagnostic module (10) performs a preventative diagnosis of all the lines of all the networks of the vehicle in cooperation with battery management systems of the vehicle and electrical loads and generators of the vehicle are consequently able to be selectively switched depending on diagnostic information, which is transmitted by way of the interfaces (5a, 5b; 6a, 6b; 7a, 7b; 8a, 8b; 10a, 10b) and concerns the networks (KN1, KN2, NN1, NN2), wherein a minimum functionality for safety-relevant systems of the vehicle is maintained by the selective switching of the loads.
2. Control system (100) for a vehicle (100), having: - two independently redundant high-voltage networks (HN1, HN2) for providing electrical energy; - two independently redundant low-voltage networks (NN1, NN2) for providing electrical control voltage, wherein the two low-voltage networks (NN1, NN2) are each galvanically isolated from one another, wherein a fault in one of the low-voltage networks (NN1, NN2) does not affect a functionality of the other of the low-voltage networks (NN1, NN2); and - two independently redundant communication networks (KN1, KN2) for transmitting messages between control apparatuses (5; 6; 7; 8; 10) connected to the communication networks (KN1, KN2), wherein the two communication networks (KN1, KN2) are each galvanically isolated from one another, wherein a fault in one of the communication networks (KN1, KN2) does not affect a functionality of the other of the communication networks (KN1, KN2); and - a degradation apparatus (10, 2a, 2b) for diagnosing faults in the networks (HN1, HN2, NN1, NN2, KN1, KN2) and for selectively degrading the control apparatuses (5; 6; 7; 8; 10) connected to the networks (HN1, HN2, NN1, NN2, KN1, KN2), wherein the control system (100) offers a sufficient functionality for a driving mode of the vehicle, - wherein the control apparatuses (5; 6; 7; 8; 10) are in each case a control apparatus (5; 6; 7; 8; 10) according to Claim 1.
3. Control system (100) according to Claim 2, characterized in that the degradation apparatus (10, 2a, 2b) comprises a diagnostic module (10) for carrying out the diagnosis and a battery management apparatus (2a, 2b) for selectively degrading the control apparatuses (5; 6; 7; 8; 10), wherein, depending on the result of the diagnosis, the control apparatuses are deactivated in such a way that the control apparatuses are still sufficiently functional for a safe driving mode of the vehicle.
4. Control system (100) according to Claim 3, characterized in that a preventative and / or actual diagnosis of lines connected to the networks (HN1, HN2, NN1, NN2, KN1, KN2) and a selective deactivation of control apparatuses connected to the networks (HN1, HN2, NN1, NN2, KN1, KN2) are able to be initiated and carried out by means of the diagnostic module (10), wherein preventative diagnosis is understood to mean a diagnosis before the occurrence of a fault from the associated network, and wherein actual diagnosis is understood to mean a diagnosis on the basis of ascertained measured values and message information.
5. Control system (100) according to one of Claims 2 to 4, characterized in that, in the event of a fault in a high-voltage network (HN1, HN2), a DC / DC converter (3a, 3b) is able to be deactivated and a rechargeable battery (4) is able to be activated in order to supply electrical power to one of the low-voltage networks (NN1, NN2).
6. Control system (100) according to one of Claims 2 to 5, characterized in that the diagnostic module (10) and the battery management apparatuses (2a, 2b) are designed to be able to be mutually monitored.
7. Control system (100) according to one of Claims 2 to 6, characterized in that a state of the networks (HN1, HN2, NN1, NN2, KN1, KN2) is able to be ascertained by means of the battery management apparatuses (2a, 2b), wherein corresponding data are able to be transmitted by way of communication interfaces (9a, 9b).
8. Method for operating a vehicle, having the steps of: - diagnosing electrical high-voltage, low-voltage and electrical communication networks (HN1, HN2, NN1, NN2, KN1, KN2) of a control system (100) of the vehicle, which are each independently redundantly designed and are functionally connected to one another, wherein the low-voltage networks (NN1, NN2) are each galvanically isolated from one another, and wherein the communication networks (KN1, KN2) are each galvanically isolated from one another; - transmitting the result of the diagnosis to independently redundant battery management apparatuses (2a, 2b) of the control system (100), wherein a fault in a first battery management apparatus does not adversely affect a functionality of a second battery management apparatus, and vice versa; and - selectively degrading control apparatuses (5; 6; 7; 8; 10), which are connected to the electrical high-voltage, electrical control voltage and electrical communication networks (HN1, HN2, NN1, NN2, KN1, KN2), depending on the result of the diagnosis in such a way that control apparatuses (5; 6; 7; 8; 10) connected to the electrical energy supply, electrical control voltage and electrical communication networks (HN1, HN2, NN1, NN2, KN1, KN2) are still sufficiently functional for a safe driving mode of the vehicle, wherein, as a result of the selective degrading of the control apparatuses (5; 6; 7; 8; 10), depending on the result of the diagnosis, the control apparatuses are deactivated in such a way that a minimum functionality for safety-relevant systems of the vehicle is maintained.
9. Method according to Claim 8, wherein a selective deactivation of electrical loads is carried out with a delay or using predetermined degradation control signals.
10. Method according to Claim 8 or 9, wherein a selective deactivation of electrical apparatuses that are not necessary for performing necessary driving functions of the vehicle is carried out.
11. Method according to Claim 10, wherein at least one of the control apparatuses: brake control unit (8), steering control unit (5), control unit (7) for driver assistance systems, control unit (8) for engine management is kept ready for operation for a driving mode of the vehicle.
12. Method according to one of the preceding claims, wherein one of the high-voltage networks (HN1, HN2) is able to be connected to the other high-voltage network (HN1, HN2) by way of a coupling switch (S).
13. Method according to one of the preceding claims, wherein a selective deactivation of electrical loads connected to the networks carried out on the basis of a diagnosis results in soft switching operations in which the vehicle does not carry out any abrupt movements.
14. Computer program comprising program code means, configured to carry out the method according to one of Claims 8 to 13 when it runs on a degradation apparatus (10, 2a, 2b) or is stored on a computer-readable data carrier.