CONTROL UNIT FOR A TOW BAR WITH STATUS SIGNAL CHECK
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- WESTFALIA AUTOMOTIVE
- Filing Date
- 2020-08-21
- Publication Date
- 2026-05-07
AI Technical Summary
Existing control units for trailer couplings in motor vehicles are unreliable in determining the operational status of the vehicle, leading to potential accidents when the coupling arm is moved during motion, as status signals can be invalid or disconnected, compromising safety.
A control unit with a validation device that verifies the validity of status signals, such as speed and ignition signals, before allowing the coupling arm to be moved, using logical and electrical checks, plausibility tests, and redundant validation methods to ensure the vehicle is stationary and trailer socket is unoccupied.
Enhances operational reliability by preventing the coupling arm from being moved during vehicle motion, reducing the risk of accidents and ensuring safe operation by validating the integrity of status signals.
Description
[0001] The invention relates to a control unit for a trailer coupling for a motor vehicle according to the preamble of claim 1.
[0002] One such control unit is described, for example, in EP 2 862 732 A1. Another control unit, which is state of the art according to Article 54(3) EPU, is described in EP 3 594 027 A1.
[0003] The status signal indicates, for example, that the vehicle is ready for operation, such as when the ignition is switched on and the vehicle could theoretically be driven. The status signal can also be, for example, a speed signal indicating that the vehicle is in motion. If the control unit uses the status signal to determine that the vehicle could be driven or is actually driving, it prevents the coupling arm from being moved from its operating position, such as releasing the locking mechanism or driving the coupling arm into the non-operating position. This is because a trailer or load carrier might already be attached to the coupling arm while the vehicle is in motion, requiring the coupling arm to remain reliably in its operating position.Furthermore, the coupling arm regularly travels between the operating and non-operating positions, reducing the vehicle's ground clearance. This means that in intermediate positions between the operating and non-operating positions, the coupling arm can protrude further downwards in front of the vehicle's body than in the end positions. However, this safety check requires that the control unit can correctly receive the status signals. This is not guaranteed in every case.
[0004] It is therefore the object of the present invention to improve the operational reliability of a control unit of the type mentioned at the outset or to provide an improved method for operating a control unit.
[0005] To solve the problem, a control unit according to the technical teaching of claim 1 is provided.
[0006] Furthermore, a method according to the technical teaching of claim 14 is provided to solve the problem.
[0007] All process steps described below in connection with the control unit, particularly those that are advantageous, can of course also be advantageously provided in a method according to the invention. Where process steps, particularly advantageous process steps, are described below, the control unit is advantageously designed to execute them, for example, by means of program code that can be executed by a processor of the control unit.
[0008] Validation means that at least one status signal is identified as valid. For example, a status signal might be logically zero simply because the signal line providing the status signal is not connected to the control unit or is interrupted. However, logical zero can indicate to the control system that the vehicle is stationary. For instance, the status signal could be a speed signal, which, at zero speed, indicates that the vehicle is stationary. If the control system then, based on the "logical zero" information, releases the drive to adjust the clutch arm from its operating position, causing it to move from the operating position to the non-operating position or allowing adjustment by releasing the locking mechanism, there is a significant risk of an accident.However, validation ensures that the status signal is a valid status signal that can be evaluated for tax purposes.
[0009] The at least one state signal that is qualified as invalid is, for example, qualified as an invalid state signal that is unsuitable for logical evaluation by the control system.
[0010] The at least one status signal has, for example, a value or signal value that is not evaluated by the control system, for example, for a logical connection with another status signal, if the status signal as a whole has been recognized and / or qualified as invalid by the validation device.
[0011] For safety reasons, the control system blocks drive activation if a status signal is classified as invalid. The status signal may have a value that is within a valid range, for example, between an upper and a lower limit. Nevertheless, the control system blocks drive activation if the status signal is classified as either valid or invalid.
[0012] The control unit preferably has at least one status signal input for the at least one status signal forming a first status signal, and at least one second status signal input for a second status signal. The control means, in particular the logical linkage means of the control means, are configured for logically linking and / or evaluating the first status signal with the second status signal to control the drive. The control means block the control of the drive if the validation device qualifies the at least one first status signal and / or the at least one second status signal as an invalid status signal. This prevents either of the status signals from being used in a logical linkage and thus evaluated to control the drive.For example, if the first status signal indicates that the vehicle is stationary, and the second status signal indicates that a trailer socket on the tow hitch is unoccupied, the control unit will generally activate the drive upon receiving the control signal, for example, to pivot the coupling arm towards the unused or working position. However, if one of the status signals, although it has the aforementioned values, has been classified as invalid by the validation device, the control unit will block the drive activation regardless of the specific value of the status signal.Therefore, if the first and second status signals have the aforementioned values (vehicle stationary, trailer socket of the trailer hitch not occupied), but at least one of the status signals is identified as invalid, the control unit blocks the drive system from being activated. For example, the validation device can determine whether one of the status signals is invalid based on a plausibility check, such as if the first status signal indicates a stationary vehicle, even though a motion sensor in the control unit detects typical movements generated by driving.
[0013] The validation device is preferably logically and / or electrically connected upstream of the control means.
[0014] Preferably, the validation device is provided for in advance of a logical connection of at least two status signals by the control means.
[0015] The validation device can send validation information associated with a given status signal to the control system. This validation information qualifies the associated status signal as valid and / or valid, or invalid and / or invalid. Depending on the validation information, the control system either blocks or does not block the drive. For example, if the validation information qualifies the status signal as invalid, the control system blocks the drive. The validation information can be implemented, for example, as a digital signal, a transfer value from a software function, etc.
[0016] It is also possible that the validation device acts as a filter, forwarding only valid status signals to the control system and / or changing the value of a status signal to an invalid value, so that the control system can recognize that the status signal is not valid. In this case, the control system blocks the actuator from being controlled. For example, the validation device can set an invalid status signal to a value outside a limit range recognized as permissible by the control system, such as zero or above an upper threshold.
[0017] Advantageously, the control means may be designed to perform a logical linking and / or evaluation of at least two state signals for controlling the drive, of which at least one, preferably both or all state signals, is validated by the validation device, wherein the control means block the control of the drive if at least one of the at least two state signals is qualified by the validation device as a non-valid state signal.
[0018] Preferably, the status signals from or through the validation device are not, or not yet, logically linked. For example, the validation device does not perform a logical linking of the status signals to control the drive, but only validates the status signals. Status signals validated in this way, or qualified as valid or invalid, are then logically linked and / or evaluated by the control system. The validation device thus forms a preliminary stage before the logical linking or evaluation of status signals by the control system.
[0019] The validation device can also perform a logical combination of state signals to qualify a state signal as valid or invalid. However, the validation device itself does not control the drive, but rather the control means, which control the drive depending on the value of the respective state signal or the combination of values of at least two state signals. Accordingly, it may be advantageously provided that the validation device does not logically combine the state signals with each other, or that it logically combines at least one of the state signals with each other exclusively for the purpose of validation.
[0020] Preferably, the coupling arm is movably mounted relative to the holder by means of the bearing assembly, for example, pivotally and / or slidably. The coupling arm can be manually adjustable between the operating position and the non-operating position. It is also possible that the coupling arm can be driven between these two positions by the coupling arm drive.
[0021] The fixing drive can effect fixing and / or releasing the fixing. The fixing drive can, for example, drive at least one positive locking element in the direction of a position that fixes the coupling arm relative to the holder. The fixing drive can, for example, also be a release drive. The fixing device is preferably spring-loaded in the direction of the fixing position, in which the coupling arm is fixed relative to the holder. The fixing device comprises, for example, at least one positive locking element provided for fixing the coupling arm relative to the holder. The at least one positive locking element is, for example, biased in the direction of the fixing position by a spring arrangement. The at least one positive locking element can be driven by the fixing drive. The fixing drive can preferably release the fixing device against the force of the spring bias or spring.
[0022] Advantageously, the control unit or control means are designed to first actuate the locking drive to release the locking mechanism of the coupling arm, and then actuate the coupling arm drive to adjust the coupling arm towards the next operating or non-operating position. Furthermore, the control unit or control means actuate the locking drive in such a way that, once the coupling arm has reached the next operating or non-operating position, the locking device can secure the coupling arm.
[0023] It is also possible that the coupling arm can be detachably attached to the bracket and fixed in place by the locking device. When the coupling arm is attached to the bracket, for example, inserted into a mounting receptacle of the bracket, it can be secured by the locking device. The locking actuator is, in effect, blocked or enabled depending on at least one status signal. Thus, for example, when the vehicle is moving, the control unit does not activate the locking actuator to release the locking mechanism.
[0024] With regard to validation, various validation options are advantageous.
[0025] For example, the validation device may compare the status signal with at least one limit value for validation purposes. Only if the status signal exceeds or falls below a predetermined limit value is it considered a valid status signal that is evaluated by the control system. Thus, signal fluctuations that do not reflect the actual state the status signal should represent can be eliminated by the validation device.
[0026] Advantageously, the system may include at least one validation condition, or it may be formed by requiring that after at least one actuation, in particular after a predetermined or adjustable number of actuations, of the at least one drive for adjusting the clutch arm from the operating position, at least one validation, in particular at least one change, of the at least one status signal must occur so that the status signal qualifies as a valid status signal. Thus, for example, if the clutch arm has been adjusted once or several times between the operating position and the non-operating position by the clutch arm drive, a check or validation of the status signal must ensure that the status signal is valid. For example, switching the ignition of the vehicle on and / or off can each cause a change in the status signal.Therefore, if the clutch arm has been moved between the operating and non-operating positions once or several times, the vehicle's ignition must have been switched on at least once. The validation device can then determine from the change in the status signal that the status signal is not constant, for example due to a broken cable or similar issue, but rather that a valid status signal, suitable for the safety check of the control system, is present.
[0027] According to the invention, the validation device verifies changes in the status signal. It is typical for a status signal to undergo a change in state or condition under varying conditions that typically occur during the operation of a motor vehicle. For example, a speed signal changes regularly during operation. Furthermore, the motor vehicle is typically switched on and off, so a status signal indicating the vehicle's operational readiness also changes. The validation device interprets a change in the status signal as a criterion or validation condition to qualify a status signal as valid.
[0028] The change of a state signal can be an analogous change, i.e., for example, a state signal representing the speed of the motor vehicle can take on multiple values.
[0029] The status signal can also be a digital signal. For example, it can be stipulated that at least one change in the status signal includes or is formed by a change between logical "zero" and logical "one".
[0030] Preferably, the at least one validation condition includes a time period within which the at least one status signal must exhibit at least one change. For example, if the vehicle has not been put into operation for an extended period, i.e., if the ignition has not been switched on within the time period of the validation condition, the status signal indicating the vehicle's operational readiness will be classified as invalid by the validation device.
[0031] This temporal validation condition or time period can also be coupled with another validation condition. For example, the temporal validation condition can be coupled with the validation condition that a change in the status signal must occur after a predetermined number of actuator actuations in order for the validation device to identify it as a valid status signal.
[0032] A preferred concept stipulates that at least one validation condition is included or is formed by the at least one state signal exceeding and subsequently falling below a threshold, or falling below and subsequently exceeding it. This prevents, for example, a state signal from being identified as valid if it changes but does not exceed the aforementioned threshold. Thus, minor signal fluctuations, such as those induced by external factors and not representing the actual state the state signal should have, cannot lead to the security device recognizing the state signal as valid.
[0033] A status signal to be validated is preferably an analog signal, in particular a voltage signal, or a digital signal.
[0034] The status signal can also be, for example, a bus signal, in particular a bus message containing status information. The control unit receives the bus signal at a bus interface, such as a CAN bus interface and / or a LIN bus interface (CAN = Controller Area Network / LIN = Local Interconnect Network), which is connected or can be connected to a vehicle data bus. In this case, the bus interface constitutes a status signal input. The vehicle sends information such as speed and other bus messages on the data bus, which can be received by the control unit. Bus communication can also be disrupted or faulty, or the control unit can receive faulty information as status signals via the bus interface.
[0035] Advantageously, it is provided that at least one status signal comprises or is formed by one or more of the following signals: an operational readiness signal, in particular an ignition-on signal and / or a terminal 15 signal, wherein the operational readiness signal indicates that the motor vehicle is ready for driving, and / or a speed signal of the motor vehicle, which indicates a driving speed of the motor vehicle, and / or an opening signal, which indicates an open or closed position of a body locking element of the motor vehicle, in particular a door and / or tailgate of the motor vehicle.
[0036] The status signal can also be a status signal of the trailer hitch itself, for example, a signal from a trailer hitch sensor. The sensor can be designed and / or configured to determine the end position of the hitch arm, e.g., the operating or non-operating position, and / or to detect movement of the hitch arm and / or actuation of at least one drive of the trailer hitch.
[0037] It is also possible for the validation device to verify at least one status signal through a plausibility check. For example, it may be stipulated that at least one validation condition includes, or is formed by, the requirement that the at least one status signal is plausible in conjunction with at least one other state of the vehicle. Thus, if, for example, a speed signal is received, but the operational readiness signal indicates that the vehicle is not operational at all, for example, the ignition is switched off, the validation device may identify the speed signal and / or the operational readiness signal as invalid status signals.
[0038] It is advantageous that the control unit can detect or monitor the vehicle's status using a sensor signal and / or another status signal. For example, if the status signal is a speed signal, but a motion sensor in the control unit simultaneously indicates that the vehicle is stationary, the validation device will identify the speed signal as an invalid status signal.
[0039] A redundant test is preferred, in which the validation device checks a state signal using two independent methods and / or via two independent channels or inputs. A preferred concept provides that the validation device has a first state signal input and a second state signal input, different from the first, for the at least one state signal. The device evaluates the first and second state signal inputs to validate the state signal and interprets the state signal as valid only if the values detected at the first and second state signal inputs, optionally weighted, are identical or differ only by a predetermined tolerance.For example, the first status signal input may be designed and / or intended for the acquisition of an analog signal, and the second status signal input for the acquisition of a digital signal. The test inputs may, for example, be located on a processor of the control unit.
[0040] It may be provided that the control unit initially assumes a valid status signal or valid status signals, for example after commissioning of the control unit, and that control of the drive is enabled without the validation device having previously checked or validated the status signal or status signals.
[0041] The control unit is advantageously designed in such a way that, after a single actuation or a predetermined number of actuations of the drive to adjust the clutch arm from the operating position and / or the non-operating position, further actuation of the drive is only possible after prior successful validation of the status signal. Thus, for example, if the clutch arm has been adjusted once or several times between the operating position and the non-operating position, the signal indicating the vehicle's operational readiness, for example the so-called terminal 15 signal, must, as already mentioned, show a change at least once.The operator must, for example, switch the ignition of the motor vehicle on and off once so that the validation device identifies the relevant status signal as a valid signal and thus enables the control means to release the drive for further operation.
[0042] A preferred concept provides, for example, that the control unit has a validation value associated with the status signal, which is incremented or reset to an initial value each time the status signal is checked and recognized as valid, and is decremented or reset when the at least one drive is activated to adjust the clutch arm from the operating position and / or the non-operating position, and that activation of the at least one drive is only possible if the validation value is greater than a predetermined threshold, in particular greater than zero.
[0043] It is more convenient for the operator if the following measure is implemented.
[0044] Preferably, the validation device is designed to issue an error message, in particular a visual and / or audible error message, if at least one status signal is recognized as invalid. This allows, for example, verification of why the status signal was recognized as invalid. In the previously mentioned example of the status signal for the operational readiness of the vehicle, which must show at least one change after a predetermined number of actuations of the trailer hitch drive, the operator can, for example, switch the operational readiness off and then on again, i.e., switch the ignition off and on, so that the status signal is recognized as valid and further operation or control of the drive by the control unit's control means is enabled.
[0045] The term "trailer socket" in this description and the claims is used as an example of an electrical connection device for connecting electrical components, such as lights, of the trailer or load carrier. Such a connection device can have the form of a trailer socket. However, the term "trailer socket" is also intended to encompass any other contact arrangement with which the trailer or load carrier can be electrically connected.
[0046] If process steps or process features are defined in connection with the control unit or other equipment, for example, a provisioning device or test device, the method according to the invention is designed to execute this process step or process feature. The control unit inherently includes suitable means for executing process features or process steps, for example, software modules, in particular test modules, function software modules, etc., which contain program code executable by the control unit's processor, so that when the program code is executed, the control unit can perform the respective process features or process steps. If electronic or electrical means are necessary for executing process steps, for example, signal inputs or signal outputs, power electronic components, or the like, these are provided in the control unit.
[0047] The control unit's memory preferably contains rewritable working memory, e.g., so-called RAM (Random Access Memory), and advantageously non-volatile memory in which software can be permanently stored, for example, a function software module for operating the control unit. Function parameters for the at least one function software module are preferably stored in this non-volatile memory. The non-volatile memory can be rewritable, for example, so-called flash memory, an EPROM, or an EEPROM.
[0048] Exemplary embodiments of the invention are explained below with reference to the drawing. The drawing shows: Figure 1 a schematic side view of a motor vehicle with a trailer hitch, Figure 2 the trailer hitch of the motor vehicle according to Figure 1with a control unit and connected vehicle bus modules in schematic representation, Figures 3a-3h different positions of a coupling arm of the trailer coupling with respect to the holder, Figure 4 a course of a test voltage for testing the control unit according to Figure 2 Figure 5 is a schematic representation of a test routine with variable parameter values, Figure 6 is a schematic representation of a software test function, Figure 7 is a flowchart of a validation function of a validation device.
[0049] A motor vehicle 80 with a body 81 is driven by a motor 82, for example an electric motor, an internal combustion engine, or a combination thereof. The motor 82 drives wheels 83 in a manner known per se. A trailer 180 can be attached to the motor vehicle 80 by means of a trailer coupling 10.
[0050] The trailer coupling 10 comprises, for example, a support assembly 11 which is attached to the body 81 of the motor vehicle 80, for example by bolting, welding, or the like. A holder 12 of the trailer coupling 10 is attached to the support assembly 11, in particular to a cross member thereof. This holder is designed, for example, to hold a coupling arm 14 in a fixed position or, for releasable positioning of the coupling arm 14, may include, for example, a plug-in receptacle (not shown) for inserting a coupling arm 14.
[0051] However, in the present case a bearing device 13, which in particular comprises or is formed by a swivel bearing, sliding bearing or swivel-sliding bearing, is provided on the holder 12, with which the coupling arm 14 is connected between a solid line in Figure 2 The device is adjustable to the operating position G shown and to the non-operating position N shown in dashed lines.
[0052] The coupling arm 14 can be driven between the operating position G and the non-operating position N by means of a coupling arm drive 18.
[0053] The coupling arm 14 carries a coupling ball 15 at its free end, which is representative of other types of coupling bodies 15A, such as polygonal coupling elements or the like. In the operating position G, the coupling ball 15 and the section of the coupling arm 14 carrying the coupling ball 15 are pre-positioned in front of a bumper 84, so that the trailer 180 can be coupled. For example, a tow ball coupling 181 of the trailer 180, which is arranged on a drawbar 182, can be coupled to the coupling element or the coupling ball 15.
[0054] The trailer 180 has a base body 183, for example a loading trough, a caravan body, or the like, which is mounted on wheels 184 and can roll on a surface. The trailer 180 also has a connector 185 through which a lighting device 186 of the trailer 180 can be supplied with power. Lights of the lighting device 186, not shown in detail, for example rear lights, brake lights, turn signals, or the like, can be powered and controlled via a corresponding control signal or current supply to the connector 185, which preferably has individual contacts.
[0055] A trailer socket 19 is used to plug in the connector 185 of the trailer 180. This can be located, for example, on the coupling arm 14 or on a separate holder 14a.
[0056] The coupling arm 14 can be fixed in at least the operating position G by means of a fixing device 16, for example, by positive locking and / or clamping. A fixing drive 17 is advantageously provided for releasing and / or closing or locking the fixing device 16. The fixing device 16 is expediently spring-loaded in the position that locks the coupling arm 14 in the operating position G, so that the fixing drive 17 also acts as a release drive.
[0057] When the fixing drive 17 is activated, the fixing of the coupling arm 14 with respect to the holder 12 is released, so that the coupling arm 14 can be adjusted from the operating position G to the non-operating position N, for example pivoted or removed from the holder 12, if the embodiment not shown in the drawing, in which the coupling arm 14 can be detachably attached to the holder 12, is implemented.
[0058] The motor vehicle 80 has an on-board electrical system 86 with a digital data bus 85, for example, a CAN bus. Motor vehicle bus modules 90A, 90B, and 90C are connected to the data bus 85; these are hereinafter also referred to generally as "motor vehicle bus modules 90". For example, motor vehicle bus module 90C is an engine control unit for controlling the engine 82. Motor vehicle bus module 90B, in turn, is a control unit for a vehicle stability program of the motor vehicle 80. Motor vehicle bus module 90A controls, for example, a lighting system 87 of the motor vehicle 80 as well as a distance measuring device 88 for a rear area or a movement area behind the motor vehicle 80 (in the direction of travel). For example, the lighting system 87 includes brake lights, rear driving lights, reversing lights, turn signals, or the like.The distance measuring device 88, for example, includes non-contact distance sensors, in particular ultrasonic sensors. A processor 93 of a respective vehicle bus module 90A - 90C executes one or more control programs to implement the respective functionality of the vehicle bus module 90A - 90C, for example, vehicle stabilization, engine control of the engine 82, or the like.
[0059] The trailer socket 19 and the drives 17, 18 are connected to a control unit 30 via the wiring arrangement 20. Figure 2With regard to the trailer socket 19, this is only indicated by a double arrow. The control unit 30 controls the functions of the trailer coupling 10 via the wiring arrangement 20, for example, the respective connection contacts of the trailer socket 19 and / or the drive 17 and / or the drive 18. Thus, for example, the control unit 30 can be used to control the drive 17 to release the locking device 16 and the drive 18 to pivot or adjust the coupling arm 14 to move from the operating position G, preferably also from the non-operating position N.
[0060] An output suitable for operating the drives 17, 18, for example an electronic power stage and / or power electronics, is provided, for example, at a control interface 31.
[0061] Interface 32 is provided for the trailer socket 19. Interface 32 forms a coupling means for connecting the trailer socket 19.
[0062] The control unit 30 has a processor 33 that communicates with a memory 34. Memory 34 contains a function software module 38, for example, a control program, for controlling and / or monitoring the trailer hitch 10, as well as a function software module 39, for example, a communication program, whose program code can be executed by the processor 33. Advantageously, memory 34 is non-volatile memory, for example, so-called flash memory, an EPROM, or an EEPROM. The processor 33 can access volatile memory 34A, for example, RAM (random-access memory), to temporarily store data.
[0063] The control unit 30 can send or receive digital data on the data bus 85 via a bus interface 36. Further details will be explained later.
[0064] The control unit 30 communicates with the vehicle bus modules 90A–90C via the data bus 85, for example, by reporting the current operating status of the trailer hitch 10 on the data bus 85. Thus, if, for example, the trailer socket 19 is occupied and the connector 185 is plugged in, the control unit 30 reports this to the vehicle bus modules 90A–90C on the data bus 85. In this case, for example, the vehicle bus module 90B, responsible for the vehicle stabilization of the vehicle 80, will select a different operating mode than when no trailer 180 is coupled to the vehicle 80. Similarly, the engine control unit or vehicle bus module 90C reacts differently when a trailer is connected, for example, by using different load programs or control programs for the motor 82.
[0065] The function software module 38, for example, controls the functions of the trailer socket 19 in such a way that the lighting device 186 of the trailer 180 operates synchronously with the lighting device 87 of the motor vehicle 80, i.e., for example, the turn signals 87A of the motor vehicle 80 and the turn signals 186A of the trailer 180 are activated on the same side, the brake lights are activated, and so on.
[0066] The function software module 38 controls one or both of the drives 17, 18.
[0067] For example, if the vehicle is traveling at 80 km / h and a minimum speed is exceeded, the function of drive 17 and drive 18 may be deactivated. Thus, for example, the clutch arm 14 cannot be moved between the operating position G and the non-operating position N while the vehicle is in motion. The control unit 30, with its control program 38, therefore also reacts to the respective operating state of the vehicle 80.
[0068] The functional software module 38 is also connected to a sensor 21 of the trailer coupling 10. The sensor 21 includes, for example, a swivel angle of the trailer 180° relative to the motor vehicle 80. The sensor 21 is, for example, connected or connectable to the interface 32 via the wiring arrangement 20.
[0069] The drives 17, 18, the trailer socket 19 and the sensor 21 form functional components 22 with which the control unit 30 interacts and in connection with which the control unit 30 performs control functions and / or detection functions when the program code of the function software module 38 is executed.
[0070] The functional software module 38 is further designed to control output devices 44, for example optical and / or acoustic output devices. The output device(s) 44 include, for example, light sources, in particular at least one LED, a loudspeaker, or the like.
[0071] Furthermore, an interface 37 is provided for electrically connected components that are not directly part of the trailer coupling 10. For example, an operating element 45A, e.g., an operating switch, in particular a push-button switch, can be connected to interface 37 as an electrical component 45.
[0072] By actuating the control element 45, for example, the control unit 30 for controlling the drives 17, 18 is configured for actuation from the operating position G towards the non-operating position N or vice versa. Thus, an operator can, for example, issue switching commands at the component 45 or the control element 45A.
[0073] Wireless operation is also readily possible, for example using a remote control 48 which can communicate with the control unit 30 via a wireless interface 49, such as a Bluetooth interface. The control unit 30 can be controlled using the remote control 48, for example, analogous to the electrical component 45 or operating element 45A.
[0074] Furthermore, control via the bus interface 36 is also possible, for example from the cockpit of the motor vehicle 80, so that the user of the motor vehicle 80, for example sitting in the driver's seat, can control the control unit 30 to operate one or both drives 17 or 18.
[0075] Thus, interface 37, wireless interface 49 and bus interface 36 each represent a control input 57, via which a control signal SA can be sent, with which the control unit 30 can be controlled to actuate the coupling arm drive 18 and / or the fixing drive 17 in the sense of leaving the operating position G or the non-operating position N or of adjusting in the direction of the operating position G or non-operating position N.
[0076] Preferably, the control element 45A is illuminated, for example by means of the output means 44. It is advantageous if the control unit 30 normally controls a light source 44A to illuminate at a lower brightness, so that the control element 45A is easy to locate. Conversely, the control unit 30 controls the light source 44A at a higher brightness, for example, to output warning messages, status messages, or the like.
[0077] Furthermore, terminals 46 and 47 are provided for supplying power to the control unit 30. The motor vehicle 80, for example, provides a supply voltage U at terminals 46 and 47.
[0078] In principle, it would be possible for the function software modules 38, 39 to be manufactured specifically for the control unit 30, i.e., for example, minimum and maximum voltage values for the supply voltage U are permanently programmed into the function software modules 38, 39. However, this would limit the usability of the control unit 30 to limited applications, namely with trailer hitches of the same type as the trailer hitch 10 and / or with motor vehicles of the same type as the motor vehicle 80, in any case, those motor vehicles that provide the same typical supply voltages U. The invention provides a remedy for this.
[0079] Function software modules 38 and 39 are parameterizable or configurable, namely with function parameters 41 to 43. Function parameters 41 and 42, for example, belong to a parameter set 40, with which the function software module 38 can be programmed. The control unit 30 has, for example, a parameter interface 35 for receiving function parameters, such as those from parameter set 40.
[0080] Function parameters 41 to 43 are merely examples of the various types of function parameters that can be processed by function software modules and, as will become clearer below, can be provided, for example, by a provisioning device 100 for the control unit 30. The provisioning device 100 includes, for example, a personal computer, a notebook, or the like.
[0081] The provisioning unit 100 comprises a processor 103 and a memory 104. Using input devices 105, such as a keyboard, an operator can specify an input data set 107, for example, an input table, with parameter values for the function parameters 41 to 43. The processor 103 can execute the program code of an external test module 102 and, for example, output to output devices 106 of the provisioning unit 100, indicate whether the input data set 107 contains valid parameter values. The external test module 102 constitutes a test device 100 for checking the parameter values of the function parameters 41 to 43.
[0082] If the input data set 107 contains permissible parameter values for the function parameters 41 to 43, i.e., parameter values with which the function software modules 38, 39 can work properly, the provisioning device 100 generates the parameter set 40, which contains the function parameters 41 to 43 and advantageously other function parameters.
[0083] It is advantageous if the provisioning device 100 adds a verification information 108 to the parameter set 40, on the basis of which, for example, the function software modules 38, 39 or the test device 51 explained below can determine that the parameter set 40 is a verified and suitable parameter set.
[0084] Advantageously, an input-side parameter check is provided for the control unit 30. A control unit test module 50 serves as the test device 51, the program code of which is executable by the processor 33. The control unit test module 50 checks the parameter set 40 to ensure that its parameter values are permissible parameter values for the respective function parameters 41 to 43. It should also be mentioned that the parameter set 40 advantageously contains the name and parameter value of at least one, preferably each, function parameter 41 to 43.
[0085] The control unit test module 50 can be used independently of or in addition to the external test module 102. The control unit test module 50 can be a component of, for example, one or both of the function software modules 38 and 39. The control unit test module 50 checks the parameter set 40 for valid parameter values, i.e., that, for example, a parameter value for the function parameter 41 is within a predetermined and previously tested range of values.
[0086] The function software modules 38, 39 have been checked to ensure that they function properly and / or safely with permissible parameter values for the function parameters 41 to 43.
[0087] For example, function parameter 41 defines an undervoltage limit Umin for the supply voltage UV. The supply voltage UV must not fall below a parameter value Umin1 of the undervoltage limit Umin for the control unit 30 to function correctly. For example, the parameter value Umin1 for function parameter 41, i.e., the undervoltage limit Umin, is set to a value of 10 V. If a higher supply voltage UV than the undervoltage limit Umin is present at terminals 46 and 47, the control program 38 functions correctly. Otherwise, it outputs an error message at the output device 44, for example, by illuminating a light-emitting diode. However, it must be ensured that the control program 38 reliably detects the undervoltage limit, i.e., recognizes an undervoltage that is below the undervoltage limit Umin specified by function parameter 41.
[0088] For this purpose, the function software module 38 is, so to speak, tested with the parameter value Umin1 for the undervoltage limit Umin. For example, an undervoltage limit of 10 V is specified as the parameter value Umin1 of the function parameter 41.
[0089] However, it is also fundamentally possible that the test device 51 changes the parameter value of the function parameter 41 to a valid value, for example to a valid undervoltage limit of, for example, 12 V.
[0090] Furthermore, it is possible that the test device 51 checks the parameter value of function parameter 41 in conjunction with and / or in interaction with the parameter value of another function parameter, for example, function parameter 41A, which defines a maximum current for energizing one of the drives 17 or 18. If function parameter 41 defines a low minimum voltage, but the maximum current defined by function parameter 41A is too low to ensure reliable operation of the drive 17 or 18 at a low voltage according to function parameter 41, the test device 51 recognizes at least one of the function parameters 41 or 41A as invalid. This example shows that, for instance, with a larger parameter value of function parameter 41, i.e., a higher minimum voltage, the maximum current according to function parameter 41A would be sufficient.In this case, the test device 51 would qualify both functional parameters 41 and 41A as permissible.
[0091] A test device 200 is electrically connected to terminals 46 and 47 and provides different supply voltages UV at these terminals. These voltages lie above and below the undervoltage limit Umin, which is specified as function parameter 41, for example, as the test voltage Utest. The control unit 30 may only drive the actuators 17 or 18 if the undervoltage limit Umin is not undershot. If the voltages are too low, there is a risk of malfunction, meaning that the actuators 17 and 18 may no longer be operated correctly. In this case, the function software module or control program 38 must issue an error message.
[0092] The parameter value 10 V is, for example, a first parameter value Umin1, which serves as the default value for the function parameter value. To test the parameter value Umin1, the test device 200 provides a variable supply voltage Utest at its terminals connected to terminals 46 and 47. This voltage is initially 11 V, for example, and then incrementally or stepwise, for example in 0.1 V steps, decreased over time t until it falls below the parameter value Umin1. At that point, the drives 17 and 18 should no longer be operable. This test routine is a so-called hardware-in-the-loop test routine, or the test itself is referred to as a hardware-in-the-loop test.
[0093] The following test is also a hardware test of this type, but in this case, for example, the function parameter 41 is varied while the supply voltage UV is fixed at a value Utest. Therefore, if the parameter value Umin for function parameter 41 is 13 V, drives 17 and 18 must be controllable. One test method might involve initially setting the parameter value for function parameter 41 below, and especially significantly below, the supply voltage Utest, e.g., to 8 V, and then increasing it. For example, the supply unit 100 could successively specify increasingly larger function parameter values Umintest for function parameter 41, for example, initially 8 V, 10 V, or similar values, and then gradually increasing the parameter values, for example, in 0.1 V increments. This is also an incremental test or change test.
[0094] It is clear that these tests are very complex and time-consuming, but on the other hand they also ensure that the control unit 30 functions reliably.
[0095] In the aforementioned manner, permissible parameter values for the function parameters 41 and 43 are determined, which can then be specified, for example, based on the input data set 107. The test devices 101 and 51 ensure that the parameter values specified via the input data set 107 are permissible, i.e., that they are parameters verified within the scope of the aforementioned tests.
[0096] A software test, i.e., a test of the functional software modules 38, 39, is also advantageously performed for at least one parameter value of a functional parameter, preferably all parameter values permissible for a functional parameter. In this test, for example, individual functions of the control program of software module 38, such as functions for controlling drive 17, are tested separately from the functions for controlling drive 18. For example, current limits that must not be exceeded by drive 17 or 18 are specified as functional parameters.
[0097] In this process, software input variables are compared with software output variables, and only if the results are correct is the respective software component or sub-function released as tested. Such a test is called software-in-the-loop testing. It is also possible to vary parameter values for the function parameters to ensure that the respective software component is able to operate correctly with the given parameter.
[0098] Function parameter 42 can be used, for example, to specify the control of the output devices 44. Thus, if, for instance, the coupling arm 14 is driven between the operating position G and the non-operating position N by the coupling arm drive 18, the output devices 44 will output information, such as visual and / or audible information. Function parameter 42 can also be used, for example, to set the flashing frequency of an LED in the output devices 44. In this context, it is also advantageous to check the respective parameter value for function parameter 42. If, for example, the parameter value were to specify a frequency that is too low for the LED to flash, this parameter value would be recognized as invalid by the test devices 51 and / or 101.
[0099] For example, frequencies from a frequency range can be selected as parameter values for function parameter 42, for which the control unit 30 and / or the function software module 38 has been tested using a test of the type mentioned above. For example, parameter values for the respective frequency can be selected using a test of the type associated with Figure 5 The tests described above are carried out by specifying 100 different parameter values for the function parameter 42 with the corresponding frequencies from the frequency range to be tested, and checking whether the output means 44 function correctly with a respective frequency value for the function parameter, i.e., whether the optical or acoustic information is correctly output.
[0100] The function parameter 43 can, for example, influence bus communication on the data bus 85. A software test of the function software module 39, the communication program, and in particular a verification of parameter values of the function parameter 43 in connection with the function software module 39, is advantageous. For example, a parameter value for the function parameter 43 can define whether a bus message 98, containing speed information 99 of the vehicle 80, is received by the function software module 39 and transmitted to the function software module 38, or is ignored or discarded by the function software module 39.
[0101] For example, particularly in a software test environment, a test program 120 is provided which passes various parameter values for the function parameter 43 to the communication program or function software module 39, see [reference]. Figure 6. A sub-function 39A of the function software module 39 is connected to and operates the bus interface 36.
[0102] If the parameter value for function parameter 43 defines that the speed information 99 is to be read from the bus message 98 and passed to the function software module 38, the subfunction 39A passes the speed information 99 or a speed value generated therefrom to a subfunction 39B, which transmits the speed information 99 or the speed value to the function software module 38.
[0103] However, if the parameter value for function parameter 43 defines that bus message 98 or speed information 99 is to be ignored, the test checks whether subfunction 39A does not pass on the speed information 99 to subfunction 39B as expected, or whether it does pass it on to subfunction 39B, which is recognized as an error.
[0104] The aforementioned test verifies the entire function software module 39. However, it is also possible for the test program 120 to only verify sub-function 39A, which is then tested in a so-called isolated test environment. Specifically, sub-function 39A, tested in isolation, must output the speed information 99 or a speed value generated from it as either a transfer or return value, depending on the parameter value set for function parameter 43. The transfer or return value then forms the input value for sub-function 39B.
[0105] The coupling arm drive 18 is controlled by control means 59 of the function software module 38, for example a corresponding control function, whose program code can be executed by the processor 33.
[0106] When the control unit 30 receives a switching command SA at one of the control inputs 57 to adjust the coupling arm 14 between the operating position G and the non-operating position N, it controls the drives 17, 18 accordingly, and, for example, first releases a locking mechanism of the coupling arm 14 with the drive 17 and then pivots or adjusts the coupling arm 14 using the drive 18, in order to reactivate the locking device 16 to lock the coupling arm 14 in the respective operating position G or non-operating position N after the adjustment movement is completed. This sequence of movements is shown schematically in Figure 3a hinted at.
[0107] However, an obstacle H1 may be located on the movement path BB between the non-use position N and the use position G. In this case, the coupling arm 14 collides with the obstacle H1 and only reaches an intermediate position Z1, which is located before the use position G.
[0108] The control unit 30 has obstacle detection means 58 to detect when the coupling arm 14 strikes an obstacle.
[0109] The obstacle detection means 58 include, for example, a current measuring device, in particular a current sensor 56, as well as a motion signal input 55, e.g. at the interface 31, as well as a software function or sub-function of the control program 38, which evaluates information from the current sensor 56 as well as the information received at the motion signal input 55 in order to recognize whether the coupling arm 14 hits an obstacle or not.
[0110] The current sensor 56 and / or the motion signal input 55 and / or the motion sensor 23 form components of a sensor arrangement 24, which, with respect to the current sensor 56 of the motion signal input 55, form a component of the control unit 30, and with respect to the motion sensor 23, a component of the trailer coupling 10. The current sensor 56 includes, for example, a measuring resistor.
[0111] The motion signal input 55 is designed to receive a motion signal BS from a motion sensor 23, e.g., a rotary sensor, in particular a Hall sensor, of the coupling arm drive 18. The motion sensor 23 outputs, for example, a pulse signal that correlates with the rotational movement of the drive 18 and thus signals the respective position of the drive 18. Therefore, if the drive 18 can rotate and adjust the coupling arm 14 accordingly, the control unit 30 receives the motion signal BS as a pulse sequence at the motion signal input 55. However, if the coupling arm 14 can no longer move or rotate, for example, if it encounters an obstacle, the signal level of the motion signal BS no longer changes.
[0112] For example, if the coupling arm 14 hits the obstacle H1 ( Figure 3b), a current flow through the coupling arm drive 18, for example its electric motor, increases, which is detectable by the current sensor 56. In addition, the motion signal BS indicates that the drive 18 and thus the coupling arm 14 are no longer moving, i.e., that the coupling arm 14 has assumed an intermediate position Z1, for example. A corresponding software routine of the function software module 38, which forms part of the control means 59 or the obstacle detection means 58, thus detects the standstill of the coupling arm 14.
[0113] If the coupling arm 14 hits an obstacle during its movement from the operating position G to the non-operating position N or vice versa, for example according to the situation described above Figure 3b, the control means 59 regularly or in normal operation control the coupling arm drive 18 in the sense of a movement of the coupling arm 14 back to the initial position, in the present case therefore in the direction of the non-use position N, from which according to Figure 3a, 3b the coupling arm 14 has been moved out. This is in Figure 3c hinted at.
[0114] However, the situation can now be changed according to Figure 3d It occurs that the coupling arm 14 can no longer be returned to its initial position because it strikes an obstacle H2 and then assumes an intermediate position Z2. The current through the drive motor of the coupling arm drive 18 increases again, and the movement signal BS indicates that the coupling arm 14 is no longer moving, which is recognized by the obstacle detection means 58 as the coupling arm 14 striking an obstacle.
[0115] One scenario involves the control means 59 controlling the coupling arm drive 18 to stop in the intermediate position Z2. The control means essentially leave the coupling arm 14 stationary in the intermediate position Z2. The operator then has the opportunity, for example, to remove the obstacle H2.
[0116] After stopping, it is possible that a further control signal SA is required so that the control means 59 can actuate the coupling arm drive 18 to further adjust the coupling arm 14 past the location of the obstacle H2.
[0117] After stopping, it can also be provided that the control means 59, after a predetermined waiting period, then further control the clutch arm drive 18 in the sense of overcoming the obstacle H2 and / or in the direction of the initial position, here the non-use position N, without a further control signal SA being required and / or evaluated by the control means 59, similar to in Figure 3c hinted at.
[0118] Another scenario provides that the control means 59 engage the coupling arm 14 starting from the intermediate position Z2 ( Figure 3d) to reverse the movement back towards the operating position G, i.e., towards the obstacle H1. Here too, it is advantageous that no further control signal SA is required, but rather that the control means 59 automatically initiate the aforementioned movement. It is possible that after the initial contact with obstacle H1, the obstacle H1 has been removed, and the coupling arm 14 can then move past the location where obstacle H1 was in the direction of the operating position G; see, for example, [reference to relevant section]. Figures 3e and 3f .
[0119] However, it is also possible that the obstacle H1 is still in the path of movement BB from the intermediate position Z2 to the operating position G, and the coupling arm 14 strikes the obstacle H1 again. In this case, it is advantageous if the control means 59 actuate the coupling arm drive 18 to reverse its movement towards the obstacle H2 or the non-operating position N, so that the coupling arm 14 is moved away from the obstacle H1. This is because it could again be the case that the obstacle H2 is then no longer in the path of movement or the path of movement BB to the non-operating position N, for example, because an operator has meanwhile removed their foot, which formerly represented the obstacle H2, from the path of movement BB of the coupling arm 14.
[0120] Another possible scenario is that the control means 59 actuate the coupling arm drive 18 to an oscillating movement OZ of the coupling arm 14 between the obstacles H1 and H2 (indicated in Figure 3d It is possible that this oscillating movement OZ is performed multiple times, for example two or three times, so that each of these movements represents, so to speak, an attempt to remove or overcome the obstacle H1 or H2 in the way. For example, it is possible that the coupling arm 14 strikes a relatively soft obstacle H1 or H2, such as a bush, a branch, or the like, and that this obstacle gives way, so to speak, when the coupling arm 14 repeatedly attempts to move past it.
[0121] The Figures 3g-3hThe schematically illustrates comparable movement sequences during the adjustment movement of the coupling arm 14 from the operating position G to the non-operating position N. Here, too, it is possible that, for example, the obstacle H2 is in the path of movement of the coupling arm 14, and the control means 59 actuate the coupling arm drive 18 to reverse its movement back towards the operating position G. It is generally intended that the coupling arm 14 is adjusted back to the operating position G and does not remain in an intermediate position.
[0122] However, it is also possible that the tax revenue 59 in the situation according to Figure 3gThe coupling arm 14 is held in a position for a predetermined waiting period, i.e., the coupling arm drive 18 is switched off for a predetermined time, for example, a few seconds. This gives an operator the opportunity to remove the obstacle H2. The control means 59 then make another attempt to move the coupling arm 14 into the non-use position N, i.e., they continue to control the coupling arm drive 18 in the direction of the non-use position N.
[0123] Figure 3h shows a similar scenario to Figure 3dthat the coupling arm 14, on its path of movement BB from the operating position G to the non-operating position N, encounters an obstacle H4 and assumes an intermediate position Z4, which the obstacle detection means 58 recognize. The control means 59 then direct the coupling arm drive 18 to reverse its movement towards the operating position G, where, however, another obstacle, for example an obstacle H3, is present in the meantime, so that the coupling arm 14 can only move to an intermediate position Z3 and encounters the obstacle H3.
[0124] Even in this situation, it is possible for the control means 59 to reverse the movement of the coupling arm drive 18, so that, starting from the intermediate position Z3, it moves the coupling arm 14 towards the non-use position N. The coupling arm 14 reaches this non-use position N if there is no obstacle H4 in its path of travel. Otherwise, the control means 59 again reverse the movement of the coupling arm drive 18 towards the use position G. Thus, an oscillatory movement OZ is also present here.
[0125] By specifying a corresponding parameter value for a function parameter that the control means 59 evaluate, the number of such oscillation movements OZ can, for example, be set.
[0126] It is also possible to configure how the control means 59 actuate the coupling arm drive 18 in the event of an obstacle, for example, whether a waiting period is observed before an attempt to overcome the obstacle, whether the coupling arm 14 is regularly actuated to reverse its movement towards the starting position when encountering an obstacle, or only for a brief movement away from the obstacle. This list is not exhaustive.
[0127] Preferably, the obstacle detection means 58 evaluate the current values of the current sensor 56 as a function of the supply voltage UV. At a low supply voltage UV, a higher current flows to operate the coupling arm drive 18 than at a higher supply voltage UV. Therefore, it is advantageous if the obstacle detection means 58 are designed for a dynamic evaluation of the current values of the current sensor 56.
[0128] Preferably, the control means 59 should not analyze current values for a predetermined, particularly very short, period of time when the coupling arm drive 18 starts up, so that the breakaway torques necessary for starting up can be applied. For example, for a period of a few hundred milliseconds, it is irrelevant what current flows through the coupling arm drive 18 when the coupling arm 14 is moved out of the operating position G or non-operating position N.
[0129] It is also possible that different maximum current values for obstacle detection are assigned to different directions of movement of the coupling arm and / or different sections of the movement path BB of the coupling arm between the operating position and the non-operating position.
[0130] Thus, two or more movement sections BB1, BB2 of the movement path BB of the coupling arm 14 can be assigned different current limit values Imax1 and Imax2, at which the obstacle detection means 58 detect the coupling arm 14 striking an obstacle. For example, movement section BB1 lies essentially in a clear area in front of the bumper 84 (behind the vehicle 80), while movement section BB2 lies essentially in the area between the body 81 and the bumper 84. The obstacle detection means 58 are preferably more sensitive on movement section BB1, e.g., because the probability of an obstacle is greater in this clear area of the movement path BB. Accordingly, the current limit value Imax1 is lower than the current limit value Imax2.The current limit values can, for example, be stored in memory 34 as parameter values for corresponding function parameters that the obstacle detection means 58 evaluate and / or be provided by the provisioning device 100.
[0131] It is also possible that parameter values are stored that allow the calculation of the corresponding current limits, for example, depending on the distance traveled by the coupling arm 14 along the path of motion BB and / or depending on the supply voltage UV and / or depending on the direction of movement of the coupling arm 14 from the non-use position N to the use position G or vice versa. Further influencing factors include, for example, the weight of the coupling arm 14 or mechanical resistances of a drive for the coupling arm 14, such as a gearbox. A respective current limit can also be dynamically determined depending on mechanical influencing factors on the path of motion between the use position G and the non-use position N.
[0132] Upon receiving a control command SA, for example at the control element 45A, the remote control 48 or via the bus interface 36 from the control unit 30, the control means 59 regularly control the drives 17, 18 to adjust the clutch arm 14 to the respective subsequent operating position G or non-operating position N, but only after checking at least one state, preferably several states, in particular of the motor vehicle 80.
[0133] The control unit 30 has status signal inputs 52, 53, 54 and 60 for detecting the states of the motor vehicle 80.
[0134] The status signal 96 is present at the status signal inputs 52 and 53, indicating that the vehicle 80 is ready for operation, for example, whether its ignition for the engine 82 is switched on, or similar. The status signal 96 thus constitutes a readiness signal.
[0135] At status signal input 54, a status signal 97 is present, which signals the driving speed of the motor vehicle 80, and is therefore a speed signal.
[0136] A status signal 95 is present at the status signal input 60, which is an opening signal indicating an open or closed position of a body locking element of the motor vehicle 80, for example a tailgate 89 thereof.
[0137] Furthermore, the motion signal input 55 can also be a status signal input and / or be assigned to the validation device 61. Thus, if the motion signal BS at the motion signal input 55 indicates a movement of the coupling arm 14, but the signal from the current sensor 56 does not correlate with it, the validation device 61 can, for example, classify the motion signal BS as an invalid or unvalid signal.
[0138] The control unit 59 checks the status signals 95-97 for the control command SA before it is issued, and thus before the drives 17, 18 are activated. Only if, for example, the tailgate 89 is open, status signal 96 indicates that the ignition of the vehicle 80 is off or the vehicle 80 is in any case not ready for operation, and status signal 97 also indicates that the vehicle 80 is stationary or not traveling at a predetermined maximum speed, do the control unit 59 enable the activation of the drives 17 and / or 18. The control unit 59 thus performs a logical operation on, for example, the status signals 95 and 96, preferably several or all of the status signals 95-97, to enable the activation of the drives 17 and / or 18. Otherwise, the control unit 59 blocks such activation.
[0139] It is understood that the aforementioned status signals are exemplary, i.e., that a check of, for example, only status signal 96 may be sufficient, or that further states are checked by the control means 59, for example, the speed information 99 of the bus message 98 is evaluated to determine that the motor vehicle 80 is stationary.
[0140] When the motor vehicle 80 is not operational, i.e., its ignition is switched off, the status signal 96 typically has a logic zero value and / or its voltage is approximately zero volts. However, when the ignition is switched on and / or the motor vehicle 80 is basically ready to drive, the status signal 96 has a predetermined minimum value or signal level, for example, logic 1 or a corresponding analog value, in particular a voltage value.
[0141] However, the status signal 96 also has a value of logical zero, no signal level, or only a low signal level if an electrical line providing the status signal 96 and connected to the control unit 30 is interrupted. In this case, the control unit 30 mistakenly assumes that the vehicle 80 is not ready to drive. The control means 59 could, in this situation, enable the activation of drives 17 and / or 18, even if the vehicle 80 is actually operational and moving.
[0142] A validation device 61 provides a remedy here. The validation device 61 comprises, for example, program code of the function software module 38 and / or a sub-function of the function software module 38, e.g., a validation function 62.
[0143] Furthermore, the validation device 61 includes, for example, the status signal inputs 52-54 and 60. The status signal inputs 52-54 and 60 are provided, for example, on the processor 33 and / or an analog-to-digital converter (not shown) of the control unit 30, or the like. The processor 33 may also have an analog-to-digital converter, for example, at the status signal input 52. The status signal input 53, on the other hand, is a digital input of the processor 33.
[0144] The status signal 96 is redundantly connected to both status signal inputs 52 and 53. Only if the same input value or correlated input values for the status signal 96 are detected at both status signal inputs 52 and 53 is the status signal 96 generally recognized as valid.
[0145] However, for a status signal 96 to be valid, it is necessary that the status signal 96 changes within a predetermined time period and / or after one or more actuations of the drives 17 and / or 18. Typically, the motor vehicle 80 is moved at least from time to time, and certainly more frequently than the trailer coupling 10 is moved between the operating position G and the non-operating position N.
[0146] For example, processor 33 executes program code of the validation function 62 of the validation device 61.
[0147] In step 601, for example, the validation function 62 reads the respective signal values at the status signal inputs 52 and 53 and checks whether they correlate with each other. It is possible, for instance, that the validation function 62 is activated by the processor 33 or an operating system 64 of the control unit 30 whenever the status signal 96 changes and / or after a predetermined time, and then executes step 601.
[0148] In decision step 602, the validation function 62 checks whether the signal values of the state signal 96 have changed between a previous reading of the state signal inputs 52, 53 and the current reading of the same inputs, i.e., whether they have changed from logic zero to logic 1. If this is the case, the validation function 62 goes through a transition 603 to a step 604 in which a validation value VAL is incremented or set to a fixed value, for example, a value greater than 1.
[0149] Starting from step 604, the validation function 62 transitions back to step 601 in a transition 605, i.e., it reads the status signal inputs 52, 53 again or waits to be woken up again by the processor 33 or the operating system 64 of the control unit 30.
[0150] However, if in decision step 602 it is determined that the signal values at the status signal inputs 52, 53 are unchanged, a transition 606 to step 601 takes place without changing the validation value VAL.
[0151] The control means 59, however, decrement the validation value VAL each time they actuate the drives 17, 18 to adjust the coupling arm 14 from the operating position G to the non-operating position N or vice versa.
[0152] Furthermore, the control unit 59 not only checks the status signals 95-97 before each actuation of the drives 17, 18, as mentioned above, but also verifies whether the validation value VAL is greater than 0. This ensures that the status signal 96 is valid, i.e., that there is no, for example, a broken wire. However, if the validation value VAL is equal to 0 when the drives 17, 18 are to be actuated, the control unit 30 outputs a warning message, for example, to the output device 44, in particular to the light source 44A. This indicates to the operator that they must switch the vehicle 80 into operational readiness at least once, i.e., cause a change in the status signal 96, in particular by switching the ignition of the vehicle 80 on and / or off, so that the trailer hitch 10 can be actuated again.
[0153] At the same time, the above routine provides a kind of safeguard against misuse or unintentional multiple activations. Specifically, if the operator, after switching the vehicle 80 on and then off, repeatedly activates the control unit 30 to adjust the clutch arm 14, thus activating the drives 17 and 18, the validation value VAL is reduced each time. This means that the number of possible activations of the drives 17 and 18 decreases with each operation or each issuance of the switching command SA. For example, if the validation value VAL is set to 10 by the validation function 62 when the state signal 96 changes state, the operator can activate the control unit 30 to adjust the clutch arm 14 ten times.Afterwards, he must, for example, activate and deactivate the operational readiness of the motor vehicle 80 at least once by pressing the ignition button. This prevents incorrect operation, i.e., that, for example, the drives 17, 18 cannot overheat due to excessively frequent switching.
[0154] Similarly, for example, the status signal 97 for the vehicle speed 80 can also be subjected to validation. For instance, the status signal 96 is an analog signal whose voltage level and / or voltage frequency or switching frequency represents the vehicle speed 80. The status signal 97 must, for example, change within a predetermined time when the status signal 96 indicates that the vehicle is ready for operation, in order for it to be recognized as a valid signal by the validation device 61.
[0155] It is still possible that the validation unit 61 will perform a plausibility check.
[0156] It is advantageous for the control unit 30 to have, for example, a motion sensor 63. If the motion sensor 63 reports movement of the vehicle 80, but at the same time the status signal 97 indicates that the vehicle 80 is stationary, the status signal 97 is not valid.
[0157] For example, the validation device 61 can also use the speed information 99 to determine whether the status signal 96 is valid. Specifically, if the status signal 96 is logically zero, indicating that the vehicle 80 is not operational or is switched off, but at the same time the speed information 99 shows a speed significantly greater than 0, then the status signal 96 is invalid. Such a plausibility check can be performed cyclically by the validation device 61.
[0158] The invention relates to a control unit for a trailer coupling for a motor vehicle, wherein the trailer coupling has a holder mountable on the motor vehicle, on which a coupling arm is adjustable between a working position and a non-working position, wherein the coupling arm has a coupling body for attaching the trailer or coupling the load carrier, wherein the control unit has a control input for a control signal and control means which, depending on the control signal, actuate a drive for adjusting the coupling arm from the working position, wherein the drive comprises a coupling arm drive for adjusting the coupling arm between the working position and the non-working position and / or a fixing drive of a fixing device of the trailer coupling for fixing the coupling arm in the working position.and wherein the control unit has a status signal input for at least one status signal of the motor vehicle, the status signal representing at least one state of the motor vehicle relevant for controlling the trailer coupling drive, and the control means enabling or blocking the drive control depending on a respective value of the at least one status signal. The control unit has a validation device for validating the at least one status signal against at least one validation condition. The control means block the drive control regardless of the respective value of the at least one status signal if the validation device qualifies the at least one status signal as an invalid status signal.
Claims
1. Control unit (30) for a trailer coupling (10) for a motor vehicle (80), the trailer coupling (10) having a holder (12) which is mounted or can be mounted on the motor vehicle (80) so as to be fixed to the vehicle and on which a coupling arm (14) is adjustable between an in-use position (G), intended for attaching a trailer (180) or coupling a load carrier onto the motor vehicle (80), and a not-in-use position (N), intended for when the coupling arm (14) is not in use, in particular is movably mounted by means of a bearing device (13), the coupling arm (14) having at an end region remote from the bearing device (13) a coupling body (15A), in particular a coupling ball (15), for attaching the trailer (180) or coupling the load carrier, the control unit (30) having a control input (57) for a control signal (SA) and control means (59) which, depending on the control signal (SA), actuate a drive (17, 18) for adjusting the coupling arm (14) out of the in-use position (G), the drive comprising a coupling arm drive (18) for adjusting the coupling arm (14) between the in-use position (G) and the not-in-use position (N) and / or a fixing drive (17) of a fixing device (16) of the trailer coupling (10) for fixing the coupling arm (14) in the in-use position (G), the control unit having a status signal input (52-54) for at least one status signal (96, 97) of the motor vehicle (80) and / or of the trailer coupling (10), the status signal (96, 97) representing at least one status of the motor vehicle (80) and / or of the trailer coupling (10) relevant for the actuation of the drive (17, 18) of the trailer coupling (10), and the control means (59) enabling or blocking the actuation of the drive (17, 18) depending on a respective value of the at least one status signal (96, 97), and the control unit (30) having a validation device (61) for validating the at least one status signal (96, 97) on the basis of at least one validation condition and is characterized in that the control means (59) block the actuation of the drive (17, 18) independently of the respective value of the at least one status signal (96, 97) if the validation device (61) classifies the at least one status signal (96, 97) as an invalid status signal (96, 97), and in that, for validating the status signal (96, 97), the validation device (61) checks a change of the at least one status signal (96, 97).
2. Control unit according to Claim 1, characterized in that, for its validation, the validation device (61) compares the status signal (96, 97) with at least one limit value and / or in that the at least one validation condition comprises or constitutes that, after at least one actuation, in particular after a number of actuations that is predetermined or can be set, of the at least one drive (17, 18) for adjusting the coupling arm (14) out of the not-in-use position (G), at least one validation, in particular at least one change, of the at least one status signal (96, 97) must take place in order that the status signal (96, 97) is classified as a valid status signal (96, 97).
3. Control unit according to Claim 1 or 2, characterized in that the at least one change of the status signal (96, 97) comprises or constitutes a change between logical "zero" and logical "one".
4. Control unit according to one of the preceding claims, characterized in that the at least one validation condition includes a time period (10) within which the at least one status signal (96, 97) must comprise at least one change, and / or in that the at least one validation condition comprises or constitutes that the at least one status signal (96, 97) goes above and then below or goes below and then above a limit value.
5. Control unit according to one of the preceding claims, characterized in that the at least one status signal (96, 97) comprises or constitutes one or more of the following signals: - an operational readiness signal (96), in particular an ignition-on signal and / or a terminal-15 signal, the operational readiness signal signalling an operational readiness of the motor vehicle (80) for driving operation, and / or - a speed signal (97) of the motor vehicle (80), which signals a driving speed of the motor vehicle (80), and / or - an opening signal (95), which signals an open position or closed position of a body closure element of the motor vehicle (80), in particular a door and / or tailgate (89) of the motor vehicle (80), and / or - a signal (BS) of a sensor of the trailer coupling (10).
6. Control unit according to one of the preceding claims, characterized in that the at least one validation condition comprises or constitutes that the at least one status signal (96, 97) is plausible in connection with at least one further status of the motor vehicle (80), it being advantageously provided that the further status of the motor vehicle (80) can be sensed or has been sensed by the control unit (30) on the basis of a sensor signal and / or a further status signal (96, 97).
7. Control unit according to one of the preceding claims, characterized in that the at least one status signal (96, 97) comprises or is constituted by an analogue signal, in particular a voltage signal.
8. Control unit according to one of the preceding claims, characterized in that the validation device (61) has a first status signal input (52) and a second status signal input (53), different from the first status signal input (52), for the at least one status signal (96, 97) and evaluates the first status signal input (52) and the at least one second status signal input (53) for validating the status signal (96, 97) and only interprets the status signal (96, 97) as valid if values, possibly weighted values, sensed at the first status signal input (52) and the at least one second status signal input (53) are identical or only differ from one another by a predetermined tolerance, it being advantageously provided that the first status signal input (52) is designed and / or intended for sensing an analogue signal and the second status signal input (53) is designed and / or intended for sensing a digital signal.
9. Control unit according to one of the preceding claims, characterized in that it is designed in such a way that, with a single actuation or a predetermined number of actuations of the drive (17, 18) for adjusting the coupling arm (14) out of the in-use position (G) and / or the not-in-use position (N), further actuating of the drive (17, 18) is only possible after prior successful validation of the status signal (96, 97), and / or in that it has a validation value (VAL), assigned to the status signal (96, 97), which is incremented or reset to an initial value each time there is a check of the status signal (96, 97) in which the status signal (96, 97) is detected as valid and is decremented or reset when there is an actuation of the at least one drive (17, 18) for adjusting the coupling arm (14) out of the in-use position (G) and / or the not-in-use position (N), and in that an actuation of the at least one drive (17, 18) is only possible whenever the validation value (VAL) is greater than a predetermined threshold value, in particular greater than zero.
10. Control unit according to one of the preceding claims, characterized in that the validation device (61) issues an error message, in particular an optical and / or acoustic error message, if the at least one status signal (96, 97) is detected as invalid, and / or in that it has a status signal input (52) for the at least one status signal, which forms a first status signal (96), and also at least one second status signal input (54) for a second status signal (97), the control means (59) being designed for the logical interlinkage and / or evaluation of the first status signal (96) with the second status signal (97) for the actuation of the drive (17, 18), the control means (59) blocking the actuation of the drive (17, 18) if the validation device (61) classifies the at least one first status signal (96) and / or the at least one second status signal (97) as an invalid status signal.
11. Control unit according to one of the preceding claims, characterized in that the control means (59) are designed for a logical interlinkage and / or evaluation of at least two status signals (96, 97) for the actuation of the drive (17, 18), of which at least one is validated by the validation device (61), the control means (59) blocking the actuation of the drive (17, 18) if at least one status signal (96 or 97) of the at least two status signals (96, 97) is classified by the validation device (96) as an invalid status signal.
12. Control unit according to one of the preceding claims, characterized in that the validation device (61) does not logically interlink the status signals (96, 97) to one another or logically interlinks them to one another exclusively for the purpose of validating at least one of the status signals (96, 97).
13. Trailer coupling with a control unit (30) according to one of the preceding claims.
14. Method for operating a control unit (30) for a trailer coupling (10) for a motor vehicle (80), the trailer coupling (10) having a holder (12) which is mounted or can be mounted on the motor vehicle (80) so as to be fixed to the vehicle and on which a coupling arm (14) is adjustable between an in-use position (G), intended for attaching a trailer (180) or coupling a load carrier onto the motor vehicle (80), and a not-in-use position (N), intended for when the coupling arm (14) is not in use, in particular is movably mounted by means of a bearing device (13), the coupling arm (14) having at an end region remote from the bearing device (13) a coupling body (15A), in particular a coupling ball (15), for attaching the trailer (180) or coupling the load carrier, the control unit (30) having a control input (57) for a control signal (SA) and control means (59), the control means (59), depending on the control signal (SA), actuating a drive (17, 18) for adjusting the coupling arm (14) out of the in-use position (G), the drive (17, 18) comprising a coupling arm drive (18) for adjusting the coupling arm (14) between the in-use position (G) and the not-in-use position and / or a fixing drive (17) of a fixing device (16) of the trailer coupling (10) for fixing the coupling arm (14) in the in-use position (G), and the control unit having a status signal input (52-54) for at least one status signal (96, 97) of the motor vehicle (80) and / or of the trailer coupling (10), the status signal (96, 97) representing at least one status of the motor vehicle (80) and / or of the trailer coupling (10) relevant for the actuation of the drive of the trailer coupling (10), and the control means (59) enabling or blocking the actuation of the drive (17, 18) depending on a respective value of the at least one status signal (96, 97), with the following steps: - validating the at least one status signal (96, 97) on the basis of at least one validation condition by a validation device (61) and - blocking the actuation of the drive (17, 18) independently of the respective value of the at least one status signal (96, 97) by the control means if the validation device (61) classifies the at least one status signal (96, 97) as an invalid status signal (96, 97), characterized in that, for validating the status signal (96, 97), the validation device (61) checks a change of the at least one status signal (96, 97).
15. Validation device for a control unit (30) intended and / or designed for actuating a trailer coupling (10), in the form of a software module with program code which can be executed by a processor (33) of the control unit (30) and in the execution of which the control unit (30) carries out the steps of the method according to Claim 14 and / or the functions of the validation device of the method according to Claim 14.