Electronic circuit
Patent Information
- Application Number
- EP2024700721
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-20
- Filing Date
- 2024-01-10
- Publication Date
- 2025-11-26
AI Technical Summary
Existing electronic braking systems for motor vehicles lack a reliable fail-safe mechanism to maintain a safe state in the event of an electronic control unit failure or electrical fault, which can lead to unsafe operational conditions.
An electronic circuit with a hardware latch and delay/memory unit that maintains the last valid state of the actuator, ensuring a safe state by delaying and storing control signals, and using a safety control device to trigger the latch in case of failures, independent of the main control unit.
The solution effectively maintains a safe state of the braking system even in the event of electronic control unit failures, ensuring the actuator remains in a secure configuration until the system can reset, thereby preventing unsafe operational conditions.
Smart Images

Figure EP2024050474_25072024_PF_FP_ABST
Abstract
Description
[0001] Electronic circuit
[0002] The invention relates to an electronic circuit, in particular for controlling a braking system of a motor vehicle. Further claims are directed to a braking system comprising the electronic circuit.
[0003] DE 10 2018 104 143 A1 teaches a pressure-medium-operated braking system for a vehicle combination comprising a towing vehicle with a towing vehicle brake and a trailer vehicle with a trailer brake. The braking system further comprises a parking brake module connected to an electronic control unit. The parking brake module has a control valve, a redundancy valve, and a shuttle valve. These valves can be controlled via an electronic switching mechanism with a self-holding function such that, in the event of a malfunction or failure of the electronic control unit, the last fault-free switching position of the control valve or the redundancy valve is maintained as long as the electronic control unit does not switch to a safe idle state or the ignition system is not switched off.
[0004] One object of the present invention can be seen in ensuring a particularly reliable yet simple fail-safe function for an actuator. This object is achieved by the subject matter of the independent patent claims. Advantageous embodiments are the subject matter of the dependent claims, the following description, and the figures.
[0005] According to the invention, an electronic circuit is proposed that ensures a safe state of a function which itself does not represent a safe state in the event of an electronic failure. For this purpose, an electronic signal memory is provided as part of a system that enables a function which, in itself, does not represent a safe state in the event of a control unit failure, an electrical fault, or another fault. Certain functions do not represent a safe state in the event of an electrical fault and a lack of power. To solve this problem, the electronic circuit according to the invention can retain the last valid state of the functionalities to ensure a safe state if the main control unit of the electronic braking system fails.The electronic latch can also be referred to as an interlock unit and is a separate unit that responds to input signals from other parts of the system and can ensure a safe state in the event of a failure of other control units by using a delay unit and a memory unit to store a last valid state of the described function. The electronic latch detects such a failure (or is informed of it by other devices such as a watchdog) and puts the dangerous functionality into a safe state within a specified time. The fail-safe state is not necessarily the de-energized state, but depends on a last valid state (energized / de-energized). Therefore, the invention provides an additional circuit that maintains the last valid state in the event of a fault.
[0006] According to the present invention, in particular, an electronic hardware lock is proposed that operates in a circuit or system comprising an electronic control unit that supplies control signals to an actuator and to the hardware lock. An interface for triggering the lock in the event of a fault can be provided. Furthermore, an interface for externally resetting the lock can be provided. In the event of a fault in the electronic control unit, the actuator is controlled by the electronic hardware lock. In particular, in the event of a failure of the electronic control unit, the electronic hardware lock maintains the last valid state of a functionality (controlled by an actuator) to ensure a safe state.It is a logic unit separate from a main control unit that receives the control signal from the electronic control unit for the actuator.
[0007] The control signal from the electronic control unit to the actuator is initially delayed by a specific time by the delay unit. In the event of an error, the delayed signal is stored in the memory unit and used from there to maintain the last valid state of the actuator, in particular until the memory unit is reset by a main controller or via an external reset interface. The hardware lock requires only one delay unit and one memory block to maintain the last valid state and ensure a safe state. In this sense, according to a first aspect of the invention, an electronic circuit is provided. The electronic circuit comprises an electronic control unit, a safety control device, and an electronic locking unit with a delay unit and a memory unit.The memory unit can, in particular, be an electronic 1-bit memory unit. The locking unit can, in particular, be implemented by hardware (“hardware latch” or “HW latch”).
[0008] During normal operation, the electronic control unit is configured to control at least one actuator in a specified manner using a normal operation control signal. The feature "to be controlled in the specified manner" can be understood, for example, to mean that the actuator is energized by the electronic control unit according to a first alternative, so that the actuator is placed in a specified state, or that the actuator is de-energized by the electronic control unit according to a second alternative, so that the actuator is placed in the specified state. For example, the actuator can be a hydraulic valve or a pneumatic valve, in particular designed as a directional control valve that can be actuated electromagnetically.Such a directional control valve can, for example, be set to an open state when the directional control valve is energized and preloaded to a closed state (e.g. by a spring) when the directional control valve is not energized. Alternatively, the directional control valve can also be set to the closed state when the directional control valve is energized and to the open state when the directional control valve is not energized. This depends on the specific application of the electromagnetically actuated directional control valve. The directional control valve can, in particular, be a redundancy valve of a parking brake module of a motor vehicle. Alternatively or additionally, the redundancy valve of the parking brake module can control the parking brake function of a trailer or trailer (optionally) attached to the motor vehicle.
[0009] The safety control unit is configured to generate a trigger signal for the electronic locking unit without the electronic control unit influencing the generation of the trigger signal. The safety control unit therefore operates independently of the electronic control unit and can, in particular, monitor its functionality, e.g., using a so-called watchdog. If functionality is impaired, for example, in the event of a fault, the safety control unit can generate the trigger signal.
[0010] The delay unit is configured to receive the normal operation control signal and transmit it to the storage unit with a time delay. The storage unit thus receives a normal operation control signal that lies in the past by the time delay. The storage unit is configured to receive the trigger signal generated by the safety control device. Furthermore, the storage unit is configured to store the normal operation control signal transmitted by the delay unit with the time delay as soon as the storage unit receives the trigger signal. The electronic locking unit is configured to control the actuator based on the stored normal operation control signal as an output signal of the storage unit as soon as the storage unit has received the trigger signal and stored the normal operation control signal transmitted with the time delay.
[0011] Instead of monitoring the control signal on the low side (ground) to the at least one actuator, in particular to multiple valves, a pin on the positive side (supply) of the actuator can be monitored. The low-side connection (ground) to an actuator is often used to enable PWM (pulse width modulation) control, which prevents overheating of the actuator by reducing the dissipated heat energy. However, a PWM signal does not provide a reliable static control signal (and is therefore not a valid input for hardware interlocking) because it consists of alternating high and low phases when active. To solve this problem, it is proposed to connect the electronic hardware interlock to a high side (supply) of the actuator that is not PWM-controlled, so that a low side of the actuator can be used for PWM control.In this sense, according to a further embodiment, the electronic control unit is configured to control a high-side switch of the actuator in the specified manner using the normal operation control signal (during normal operation, in particular when no fault is present). In the event of a fault, the high-side switch of the actuator can be activated, for example, by the safety control device. The memory unit of the locking unit can be configured to control a low-side switch of the switch using the stored normal operation control signal (in the event of a fault). The electronic control unit can in turn be configured to control the low-side switch of the actuator using pulse width modulation (in particular during normal operation, when no fault is present).
[0012] A high-side switch can be understood, in particular, as a transistor which, depending on its switching position, connects or interrupts a high-voltage supply rail (typically 24 volts in an industrial application) to a load. If the actuator is a directional control valve that can be actuated electromagnetically, the high-side switch can be configured, in particular, to connect a magnetic circuit of the directional control valve to a positive pole of an electrical energy storage device when the high-side switch is in a closed switching position, and to disconnect the magnetic circuit of the directional control valve from the positive pole of the electrical energy storage device when the high-side switch is in an open switching position.Alternatively or additionally, the high-side switch can be configured, in particular, to connect the magnetic circuit of the directional control valve to an output terminal of an ignition switch arranged behind the positive pole of an electrical energy storage device when the high-side switch is in a closed switching position, and to disconnect the magnetic circuit of the directional control valve from that of the connection terminal of the ignition switch when the high-side switch is in an open switching position. A low-side switch can be understood, in particular, as a switch which, depending on its switching position, switches an electrical load on or off by switching a ground side (low side) of a load supply.If the actuator is a directional control valve that can be actuated electromagnetically, the low-side switch can be configured, in particular, to connect a magnetic circuit of the directional control valve to ground (“to ground”) when the low-side switch is in a closed switching position and to disconnect the magnetic circuit of the directional control valve from ground when the low-side switch is in an open switching position.
[0013] Regarding the generation of the trigger signal, the safety control device can be configured to generate a status signal that assumes either a normal operation value (“1”) or an error value (“0”). The normal operation value (“1”) represents that the actuator is being controlled in the specified manner. Conversely, the error value (“0”) represents that the actuator is not being controlled in the specified manner. If the value of the status signal changes from the normal operation value (“1”) to the error value (“0”), this results in a falling edge (from “1” to “0”) over time, as graphically illustrated. In this case, the memory unit can be locked to maintain a safe state of the actuator by inverting the error signal (“0”) to generate a rising edge (from “0” to “1”) over time. This inverted error signal (“1”) thus serves as the trigger signal.In this case, the memory unit remembers the logical state ("1") of the normal operation control signal, which lies in the past due to the time-delayed transmission by the delay unit, e.g., at least 25 milliseconds in the past. In this sense, according to one embodiment, the safety control device comprises an inverter, and the inverter is configured to convert the error value into the normal operation value and to transmit this normal operation value to the memory unit as the trigger signal. In general, upon triggering, the memory unit stores the output value of the delay unit present at the relevant time, which corresponds to the last valid state of the normal operation control signal before the error value ("0") occurred (so-called "Last Known Valid State").The delay time is selected appropriately so that the signal from the delay unit reliably reflects the state before the error occurred.
[0014] The locking unit can be deactivated, in particular externally. The memory unit can be reset if the memory unit receives a reset signal. Resetting the memory unit involves, in particular, the memory unit's output signal assuming a transfer value. In this case, the locking unit returns control of the actuator to the electronic control unit. In this sense, according to a further embodiment, the memory unit is configured to receive a reset signal, wherein the locking unit is configured to control the actuator using the stored normal operation control signal only until the memory unit receives the reset signal. Thereafter, the locking unit stops controlling the actuator.The electronic control unit is then configured to take over control of the actuator again as soon as the memory unit receives the reset signal.
[0015] The electronic lock can be reset via an external interface (reset unit) or, for example, by switching off the power supply. Other methods of external deactivation are also conceivable, such as using an external, hard-wired switch. According to a further embodiment, the reset signal can be generated by a reset unit separate from the locking unit. The external "reset unit" can thus act in addition to or as an alternative to the other reset methods. Furthermore, the reset unit can intervene at any point in the locking unit, for example, via a separate input on the memory unit or with a separate logic block. Inducing a reset by switching off the power supply results in the locking unit assuming a defined state (in this case, the value "0"). This also sets the redundancy logic to a defined state, for example.This represents added value or a functional extension compared to the "reset unit." The safety control unit with its inverter can, for example, be viewed as a reset unit. The memory unit, in particular embodied as a 1-bit memory, can be reset in particular when the status signal generated by the safety control unit assumes the normal operation value ("1") at any time, i.e., when the electronic control unit is again able to control the actuator in the specified manner. Inverted by the inverter, the normal operation value then becomes the error value. In this sense, according to a further embodiment, the inverter is configured to convert the normal operation value ("1") into the error value ("0") and to transmit this error value ("0") as the reset signal to the memory unit.
[0016] If the status signal generated by the safety control unit assumes the error value ("0"), then this error value ("0") can also represent that the actuator is not (yet) being controlled by the electronic control unit in the specified manner using the normal operation control signal because the electronic control unit is booting up or is in a start-up phase. In this case, the electronic control unit can read the state of the locking unit by measuring analog feedback from the high-side switch and the low-side switch of the actuator. In principle, the measurement of various signals is also conceivable in order to determine the state of the locking unit. Examples, and thus not an exhaustive list, include the first or second fail-safe control signal, the selection fail-safe control signal, or the output signal to the low-side switch.This allows the electronic control unit to detect the state of the locking unit and maintain its state after the start-up process has been completed. In this sense, according to a further embodiment, the error value ("0") represents that the actuator is not being controlled by the electronic control unit in the specified manner using the normal operation control signal because the electronic control unit is in a start-up phase. In this case, the electronic control unit is configured to measure analog feedback from the high-side switch and the low-side switch of the actuator and, based on this, to derive an operating state of the locking unit. This occurs while the electronic control unit is in the start-up phase and when the safety control device has generated the status signal in such a way that it assumes the error value ("0").Furthermore, the electronic control unit is configured to control the actuator based on the measured analog feedback signals in such a way that the locking unit maintains its operating state after the electronic control unit has completed the start-up phase. In principle, the operating state of the locking unit can change after the start-up phase due to the reset signal. From a functional perspective, it must then be ensured that the operating state of the actuator is adopted or maintained.
[0017] The safety control device can, in particular, comprise a watchdog, which is connected to the electronic control unit on the input side and to the inverter on the output side. Thus, the watchdog can, on the one hand, monitor the correct functionality of the electronic control unit and, on the other hand, generate the corresponding status signal, which is inverted by the inverter as described above.
[0018] According to a further embodiment, the delay unit is configured to transmit the normal operation control signal to the memory unit with a time delay of at least 25 milliseconds. The time delay of at least 25 milliseconds specifies, in particular, a time period that begins when the delay unit receives the normal operation signal and ends when the delay unit transmits the normal operation signal to the memory unit. The signal at an input of the delay unit is output via an output of the delay unit with a delay of at least 25 milliseconds. A logical value or other properties of the input signal are not changed. The delay can vary depending on the temperature. The implementation of the delay unit can, in particular, comprise an RC low-pass filter and two sequential Schmitt trigger inverters.According to a second aspect of the invention, a braking system for a motor vehicle is provided. The braking system comprises an electronically controllable parking brake module with a first directional control valve designed as a control valve, a second directional control valve designed as a redundancy valve, and a pressure-controlled shuttle valve. The braking system further comprises an electronic circuit according to the first aspect of the invention.
[0019] The braking system is particularly characterized by the fact that
[0020] - the electronic control unit of the electronic circuit is configured to control the redundancy valve as an actuator in a predetermined manner by means of a normal operation control signal,
[0021] - the safety control unit of the electronic circuit is designed to generate the trigger signal for the electronic locking unit without the electronic control unit influencing the generation of the trigger signal,
[0022] - the delay unit of the locking unit of the electronic circuit is designed to
[0023] - to receive the normal operation control signal,
[0024] - to transmit the normal operation control signal with the time delay to the memory unit of the electronic circuit of the locking unit,
[0025] - the storage unit is designed to
[0026] - to receive the trigger signal generated by the safety control device,
[0027] - to store the normal operation control signal transmitted by the delay unit with the time delay as soon as the storage unit receives the trigger signal, and
[0028] - the electronic locking unit of the electronic circuit is configured to control the redundancy valve using the stored normal operation control signal as an output signal of the storage unit as soon as the storage unit has received the trigger signal and stored the normal operation control signal. To increase redundancy, the electronic circuit may further comprise a further delay unit and a further storage unit, wherein
[0029] - the electronic control unit is configured to control the control valve as a further actuator in a predetermined manner by means of a further normal operation control signal,
[0030] - the further delay unit is designed to
[0031] - to receive the further normal operation control signal,
[0032] - to transmit the further normal operation control signal with the time delay to the further storage unit,
[0033] - the additional storage unit is designed to
[0034] - to receive the trigger signal generated by the safety control device,
[0035] - to store the further normal operation control signal transmitted by the further delay unit with the time delay as soon as the further storage unit receives the trigger signal, and
[0036] - the electronic locking unit is configured to control the control valve by means of the stored further normal operation control signal as an output signal of the further storage unit as soon as the further storage unit has received the trigger signal and stored the further normal operation control signal.
[0037] The embodiments described above in connection with the electronic circuit, their technical effects and associated advantages can all also be applied to the braking system according to the second aspect of the invention, which is particularly evident from the following description of the figures.
[0038] In the following, exemplary embodiments of the invention are explained in more detail with reference to the schematic drawing, in which identical or similar elements are provided with the same reference numerals.
[0039] Fig. 1 is a plan view of a part of a braking system for a motor vehicle and a trailer vehicle, Fig. 2 shows details of an embodiment of an electronic circuit according to the invention for the braking system according to Fig. 1,
[0040] Fig. 3 exemplary signal flows of the electronic circuit according to Fig. 2,
[0041] Fig. 4 is a circuit diagram of a power supply unit of an electronic control unit of the braking system according to Fig. 1,
[0042] Fig. 5 shows a power supply of a redundancy logic and an electronic locking unit of the electronic circuit according to Fig. 2 and
[0043] Fig. 6 shows a further embodiment of an electronic circuit according to the invention for the braking system according to Fig. 1.
[0044] Fig. 1 shows part of a braking system 1 for a motor vehicle 2 (not shown in detail). The motor vehicle 2 is, for example, an agricultural utility vehicle, in particular a tractor. The braking system 1 fulfills, in particular, a parking or service braking function for wheels 13 of the motor vehicle 2 and a trailer brake 3 of the trailer vehicle 4 (only indicated in Fig. 1). The functions described in more detail below are, in the exemplary embodiment shown, part of a tractor braking system platform, the so-called EBP platform. The EBP platform is intended to ensure the safe operation of the braking system 1 under various failure scenarios.
[0045] The braking system 1 comprises an electronically controllable parking brake module 5. The parking brake module 5, in turn, comprises a first directional control valve embodied as a control valve 6, a second directional control valve embodied as a redundancy valve 7, and a pressure-controlled shuttle valve 8. The parking brake module 5 is supplied with compressed air on the inlet side by a compressed air supply 9. The compressed air supply 9 comprises a first compressed air tank 10, a second compressed air tank 11, and a third compressed air tank 12. In the exemplary embodiment shown, the control valve 6 and the redundancy valve 7 are each connected on the inlet side to the third compressed air tank 12 of the compressed air supply 9, although this is purely exemplary.A valve spool of the control valve 6 and a valve spool of the redundancy valve 7 are each spring-biased in a closed switching position, according to which the pressure from the compressed air supply 9 is not directed through the control valve 6 and the redundancy valve 7 ("normally closed"). The valve spool(s) could also each be replaced by a valve seat, whereby the valve seat can be closed or opened, for example, by a plunger moved by magnetic force. Alternative actuations of the moving plunger, for example, by means of levers, are also conceivable.
[0046] On the output side, the control valve 6 and the redundancy valve 7 are each connected to the shuttle valve 8, so that the higher pressure of the two valves 6, 7 is output via the shuttle valve 8 to supply pressure to two spring-loaded parking brake valves 14, each assigned to a wheel 13, and the trailer brake 3. If the control valve 6 fails, the pressure of the redundancy valve 7 can continue to be used, provided the redundancy valve 7 has not failed. If the redundancy valve 7 fails, the pressure of the control valve 6 can continue to be used, provided the control valve 6 has not failed. A pressure sensor 15 measures the pressure output via the shuttle valve 8 and transmits the measured pressure to an electronic control unit 16 of the braking system 1.
[0047] If at least one of the valve spools of the two valves 6, 7 is in its open switching position, then a predetermined pressure can be passed through the control valve 6 and / or the redundancy valve 7 and output via the shuttle valve 8. The spring-loaded parking brake valves 14 and the trailer brake 3 are then actuated such that the parking brake is released against the spring preload. The wheels 13 of the motor vehicle 2 and / or the trailer vehicle 4 are then not locked. If, however, both valve spools of the two valves 6, 7 are in their closed switching position, then no pressure is passed through the control valve 6 and the redundancy valve 7 and output via the shuttle valve 8. The spring-loaded parking brake valves 14 and the trailer brake 3 are then not actuated as described above, but are activated instead.The wheels 13 of the motor vehicle 2 and / or the trailer vehicle 4 are then locked. In this context, one can say that the electronically controllable parking brake module 5 has an inverting switching characteristic. The parking brake of the motor vehicle 2 and the trailer brake 3 are thus applied, for example, when no pressure is output via the shuttle valve 8, and released when a sufficiently high pressure is output via the shuttle valve 8. The trailer brake can sometimes be designed without a spring brake. Accordingly, actuation then occurs via another valve, for example a so-called trailer control valve, which again inverts the signal coming from the shuttle valve 8 and thus directs pressure from the compressed air tanks to the trailer brakes 3. In other words, in the latter design, the trailer brake 3 is not actuated via a spring brake, but via the trailer's service brake.
[0048] The electronic control unit 16 of the braking system 1 is connected via a CAN bus 17 to an electronic (main) control unit 18 of the motor vehicle 2. In the illustrated embodiment, the electronic (main) control unit 18 of the motor vehicle 2 is connected in particular to a human-machine interface 19. Using the human-machine interface 19, a driver or user of the motor vehicle 2 can, in the illustrated embodiment, operate the two parking brake valves 14 of the motor vehicle 2 and / or the trailer brake 3 of the trailer vehicle 4.
[0049] In particular, the pressure supply to the parking brake valves 14 and the trailer brake 3 should be prevented from failing while the motor vehicle 2 and the trailer 4 are moving, resulting in the wheels of the motor vehicle 2 or the trailer 4 becoming locked. This pressure supply function is controlled by the electronic control unit 16 of the braking system 1 during normal operation of the braking system 1. For this purpose, the electronic control unit 16 of the braking system 1 is connected to the control valve 6 via a first electronic control line 20 and to the redundancy valve 7 via a second electronic control line 21.When the electronic control unit 16 of the braking system 1 energizes the control valve 6 and the redundancy valve 7 via the electronic control lines 20, 21, the valve spools of the control valve 6 and the redundancy valve 7 are moved from the closed switching position to the open switching position against the spring preload. In the open switching position, the pressure from the compressed air supply 9 is directed via the control valve 6 and the redundancy valve 7. The higher of the two pressures is directed via the shuttle valve 8 to the parking brake valves 14 and / or to the trailer brake 3 for pressure application, so that the wheels of the motor vehicle 2 and / or the trailer vehicle 4 are not locked.
[0050] However, if the electronic control unit 16 of the braking system 1 malfunctions during fault operation, this function is controlled by an electronic circuit 22, described in more detail below, which, in the exemplary embodiment according to Fig. 1, is housed in a common housing 23 of the electronic control unit 16 of the braking system 1. According to Fig. 2, the electronic circuit 22 comprises the electronic control unit 16 of the braking system 1, a safety control unit 24 with an inverter 25, and a watchdog 60. Furthermore, the electronic circuit 22 comprises an electronic locking unit 26 with a first electronic delay unit 27 and with a first memory unit 28, which is embodied as a 1-bit electronic memory unit. Furthermore, the electronic circuit 22 comprises a redundancy logic 29 for the redundancy valve 7.The redundancy logic 29 for the redundancy valve 7, in turn, comprises another inverter 30 and a first OR gate 31. Furthermore, a high-side switch HSS and a low-side switch LSS are connected to the redundancy valve 7.
[0051] In its normal operating state, the electronic control unit 16 of the braking system 1 generates a first normal operation control signal 32 for the high-side switch. Using the first normal operation control signal 32, the electronic control unit 16 of the braking system 1 can activate and deactivate the high-side switch HSS, so that the valve spool of the redundancy valve 7 is moved, in the manner described above, into the open switching position (with the high-side switch HSS activated or closed and the low-side switch LSS simultaneously activated) or into the closed switching position (with the high-side switch HSS deactivated or open). In this context, it can be said that the electronic control unit 16 is configured to control the redundancy valve 7 in a predetermined manner using the first normal operation control signal 32.The first normal operation control signal 32 is a direct current (DC) signal due to the nature of the FSC-AC concept applied here. In the exemplary signal waveform according to Fig. 3, the first normal operation control signal 32 assumes the value "1" when the electronic control unit 16 of the braking system 1 energizes the high-side switch HSS and thus activates or closes it. On the other hand, the first normal operation control signal 32 assumes the value "0" when the electronic control unit 16 of the braking system 1 does not energize the high-side switch HSS and thus deactivates or opens it. The electronic control unit 16 of the braking system 1 transmits the first normal operation control signal 32 as an input signal to the first OR gate 31 of the redundancy logic 29. In a similar manner, the electronic control unit 16 of the braking system 1 can also control the control valve 6 via its high-side switch (not shown in Fig. 2).
[0052] Furthermore, in its normal operating state, the electronic control unit 16 of the braking system 1 generates a second normal operation control signal 35 for the low-side switch LSS of the redundancy valve 7. Using the second normal operation control signal 35, the electronic control unit 16 of the braking system 1 can activate and deactivate the low-side switch LSS, so that the valve spool of the redundancy valve 7 is moved, in the manner described above, into the open switching position (with the low-side switch LSS activated or closed and the high-side switch HSS simultaneously closed) or into the closed switching position (with the high-low switch LSS deactivated or open). The redundancy valve 7 can be actuated by means of a direct current signal or by means of pulse width modulation (PWM), because this signal is not an input signal for the locking unit 26 described in more detail below.
[0053] The safety control unit 24 operates independently of the electronic control unit 16 of the braking system 1. The watchdog 60 of the safety control unit 24 monitors the function of the electronic control unit 16 of the braking system 1. In the exemplary embodiment shown, the safety control unit 24 can output a binary status signal 33 based on the result of the monitoring of the electronic control unit 16 of the braking system 1 by the watchdog 60. A normal operation value of "1" of the status signal represents that the electronic control unit 16 of the braking system 1 is functioning properly, so that the safety control unit 24 can conclude that the redundancy valve 7 is being controlled in the specified manner.An error value of "0" for the status signal, on the other hand, represents that at least one of the following error cases exists: that the electronic control unit 16 of the braking system 1 is not functioning properly, that the electronic control unit 16 of the braking system 1 is in a start-up phase, that the safety control unit 24 is not functioning properly, or that the safety control unit 24 is in an initialization or start-up phase. If at least one of these error cases exists, the safety control unit 24 can conclude that the redundancy valve 7 is not being controlled in the specified manner.
[0054] The safety control unit 24 transmits the generated status signal 33 to the further inverter 30 of the redundancy logic 29. The further inverter 30 of the redundancy logic 29 converts the status signal 33 transmitted from the safety control unit 24 to the further inverter 30 of the redundancy logic 29 into an inverted status signal 34. If the status signal 33 transmitted from the safety control unit 24 to the further inverter 30 of the redundancy logic 29 assumes the normal operation value "1", the further inverter 30 converts the status signal 33 such that the inverted status signal 34 assumes the error value "0" and transmits the inverted status signal 34 with the error value "0" as an input signal to the first OR gate 31 of the redundancy logic 29.If, however, the status signal 33 transmitted from the safety control unit 24 to the further inverter 30 of the redundancy logic 29 assumes the error value "0", the further inverter 30 converts the status signal 33 such that the inverted status signal 34 assumes the normal operation value "1" and transmits the inverted status signal 34 with the normal operation value "1" as an input signal to the first OR gate 31 of the redundancy logic 29. The first OR gate 31 of the redundancy logic 29 thus receives two input signals, namely the first normal operation control signal 32 (from the electronic control unit 16 of the braking system 1) and the inverted status signal 34 (from the further inverter 30 of the redundancy logic 29). The first OR gate 31 is configured to output the one of the two input values 32, 34 which assumes a value greater than or equal to 1.If none of the aforementioned error cases occurs, the status signal 33 assumes the value "1" and the inverted status signal 34 assumes the value "0." In this case, the first normal operation control signal 32 assumes the value "1" because the electronic control unit 16 of the braking system 1 energizes the high-side switch HSS and thus activates or closes it. However, it should be noted that the normal operation control signal 32 can also have the value "0" even without an error case occurring, e.g., if the actuator should not be energized. This would be the case, for example, if the parking brake is engaged or activated. Thus, in this case, the first OR gate 31 will output the first normal operation control signal 32 with the value "1" to control the high-side switch HSS of the redundancy valve 7.On the other hand, if at least one of the aforementioned error cases occurs, the status signal 33 assumes the value "0" and the inverted status signal 34 assumes the value "1." In this case, the first normal operation control signal 32 assumes the value "0" if, for example, the electronic control unit 16 of the braking system 1 experiences a malfunction and does not properly energize and activate or close the high-side switch HSS. Thus, in this case, the first OR gate 31 will output the inverted status signal 34 with the value "1" to control the high-side switch HSS of the redundancy valve 7. In this way, the redundancy logic 29 ensures that the high-side switch HSS of the redundancy valve 7 is always activated when the safety control unit 24 triggers a fail-safe state of the electronic control unit 16.
[0055] The electronic control unit 16 of the braking system 1 transmits the first normal operation control signal 32 as an input signal to the first delay unit 27. With a time delay of at least 25 milliseconds (labeled "Delay" in the corresponding signal waveforms in Fig. 3), the first delay unit 27 outputs the first normal operation control signal 32 as an output signal 36 and transmits this output signal 36 to a signal input 37 of the first memory unit 28. The logic level ("1" or "0") or other properties of the first normal operation control signal 32 are not changed. The time delay can vary depending on the temperature. The implementation of the first delay unit 27 can, in particular, comprise an RC low-pass filter and two sequential Schmitt trigger inverters (not shown).
[0056] The safety control unit 24 transmits the generated status signal 33 to the inverter 25 of the safety control unit 24. The inverter 25 of the safety control unit 24 converts the status signal 33 received from the safety control unit 24 (like the inverter 30 of the redundancy logic 29) into an inverted status signal 34. If the status signal 33 transmitted from the safety control unit 24 to its inverter 25 assumes the normal operation value "1", the inverter 25 converts the status signal 33 such that the inverted status signal 34 assumes the error value "0" and transmits the inverted status signal 34 with the error value "0" to a trigger terminal 38 and to a reset terminal 39 of the first memory unit 28.If the status signal 33 transmitted from the safety control unit 24 to its inverter 25 assumes the error value “0”, then the inverter 25 converts the status signal 33 such that the inverted status signal 34 assumes the normal operation value “1” and transmits the inverted status signal 34 with the normal operation value “1” to the trigger terminal 38 and to the reset terminal 39 of the first memory unit 28.
[0057] The inverted status signal 34 with the normal operation value "1" generated by the inverter 25 of the safety control unit 24 serves the first storage unit 28 as a trigger signal 40, which the safety control unit 24 generated without the electronic control unit 16 of the braking system 1 influencing the generation of the trigger signal 40. When the first storage unit 28 receives the trigger signal 40 generated by the safety control unit 24, the trigger signal 40 triggers the first storage unit 28 to store the normal operation control signal 36 transmitted with a time delay by the delay unit 27. This triggering occurs precisely when the inverted status signal 34 changes its value from "0" to "1". In the temporal progression according to Fig.3, this is represented by two rising edges 41 of the inverted status signal 34, whereby a failsafe state is triggered by the safety control unit 24.
[0058] The first storage unit 28 outputs the stored normal operation control signal 36, which is delayed by at least 25 milliseconds, as a first failsafe control signal 42. The first failsafe control signal 42 is a normal operation control signal 36 from the past, namely a normal operation control signal 36 that occurred at least 25 milliseconds ago. This time is always before the rising edges 41 in Fig. 3. At this time, none of the cases described above existed, and the redundancy valve 7 was controlled in the specified manner by the electronic control unit 16 of the braking system 1 using the normal operation control signal 36.
[0059] The first storage unit 28 can output the first fail-safe control signal 42 via a signal output 43 of the first storage unit 28 and transmit it as an output signal 46 to the low-side switch LSS of the redundancy valve 7 via a second OR gate 44 and a third OR gate 45 in order to control the low-side switch such that the redundancy valve 7 maintains the state prior to the occurrence of the fault on the rising edge 41. In the present case, this is the state in which the low-side switch LSS is activated or closed, so that the redundancy valve 7 is energized and its valve spool moves into the open switching position.In this way, the electronic locking unit 26 controls the redundancy valve 7 based on the stored normal operation control signal 36 as the first output signal 42 of the first storage unit 28 as soon as the first storage unit 28 has received the trigger signal 40 and stored the normal operation control signal 36 transmitted with a time delay.
[0060] Fig. 3 shows that the value of the normal operation control signal 32 drops from "1" to "0" when the error occurs. The watchdog 60 of the safety control unit 24 detects this error a few milliseconds later. As a result, the rising edge 41 of the inverted status signal 34 only occurs a few milliseconds after the error occurs, which is not critical. This period of a few milliseconds between the occurrence of the error and the rising edge 41 of the inverted status signal 34 is, on the one hand, significantly shorter than the time delay with which the normal operation control signal 32 is transmitted from the delay unit 27 to the memory unit 28.Secondly, this period of a few milliseconds between the occurrence of the error and the rising edge 41 of the inverted status signal 34 is not long enough to activate the parking brake of the motor vehicle 2 or the trailer brake. This would require a period in the range of 100 milliseconds or much longer.
[0061] The second OR gate 44 has a first input 47 and a second input 48. The first input 47 of the second OR gate 44 is connected to the output 43 of the first memory unit 28. The second input 48 of the second OR gate 44 is connected to an output 49 of a second memory unit 50 of the locking unit 26. In the illustrated embodiment, the second memory unit 50 is identical to the first memory unit 28. The second memory unit 50 cooperates with a second delay unit 51 of the locking unit 26 and the safety control unit 24 in the same way as the first delay unit 26 and the first memory unit 28. In the illustrated embodiment, the second delay unit 51 is identical to the first delay unit 27.
[0062] The functional difference lies solely in the signal inputs and outputs, in particular the input signal for the second delay unit 51, which is described in more detail below. Thus, in its normal operating state of the braking system 1—in a similar manner to the high-side switch HSS of the redundancy valve 7—the electronic control unit 16 generates a third normal operation control signal 52 for a high-side switch (not shown in Fig. 2, see Fig. 6) of the control valve 6. This third normal operation control signal 52 is transmitted by the second delay unit 51 with the time delay of at least 25 milliseconds as a time-delayed second normal operation control signal 53 to the second storage unit 50.The safety control unit 24 monitors the electronic control unit 16 of the braking system 1 and, as described above in connection with the control of the redundancy valve 7, determines based on this monitoring whether the control valve 6 is controlled in the specified manner or not, and outputs the corresponding status signal 33, which is inverted by the inverter 25. The second storage unit 50 can store the time-delayed second normal operation control signal 53 and output it as a second failsafe control signal 54, similar to what was described above in connection with the first storage unit 28.
[0063] The second failsafe control signal 54 is applied to the second input 48 of the second OR gate 44, and the first failsafe control signal 42 (as already described above) is applied to the first input 47 of the second OR gate 44. The second OR gate 44 outputs whichever of the two failsafe control signals 42, 54 is selected as the failsafe control signal 55, which assumes a value greater than or equal to 1. The third OR gate 45 has a first input 56 and a second input 57. The first input 56 of the third OR gate 45 is connected to the electronic control unit 16 of the braking system 1 and receives the second normal operation control signal 35 for the low-side switch LSS of the redundancy valve 7. The second input 57 of the third OR gate 45 is connected to an output 58 of the second OR gate 44 and receives the selection failsafe control signal 55.The third OR gate 45 outputs that of the two control signals 35, 55 as output signal 46 to the low-side switch LSS of the redundancy valve 7, which assumes a value that is greater than or equal to 1.
[0064] The two memory units 28, 50 are reset (“reset”) when the memory units 28, 50 receive a reset signal 59. In the illustrated embodiment, the reset signal 59 is generated by the safety control unit 24. The inverter 25 of the locking unit 26 converts a received normal operation value “1” into the error value “0” and transmits this error value “0” as the reset signal 59 to the memory units 28, 50. In this case, the output value of the two memory units 28, 50 is reset to a transfer value (“default”) corresponding to the value “0”. In this case, the locking unit 26 returns control of the redundancy valve 7 and the control valve 6 to the electronic control unit 16. Alternatively, the reset signal 59 can be generated by a reset unit 63 separate from the locking unit 26, which is indicated by dashed lines in Fig. 2. The external reset unit 63 can, for example,be configured to reset the memory unit 28 of the locking unit 26 by switching off the power supply. The external reset unit 63 can also be implemented by an external, hard-wired switch, by means of which the power supply, in particular of the two memory units 28, 50, can be switched off for the reset process and switched on again for restarting. Alternatively or in addition to the reset process initiated by the external reset unit 63, this can be initiated, as already described above, by the methods mentioned above.
[0065] If the status signal generated by the safety control unit 24 assumes the error value "0," then this error value "0" can represent, for example, that the redundancy valve 7 is not yet being controlled by the electronic control unit 16 in the specified manner using the first normal operation control signal 32 because the electronic control unit 16 is booting up or is in a start-up phase. In this case, the electronic control unit 16 can read the state of the locking unit 26 by measuring analog feedback from the high-side switch HSS and the low-side switch LSS of the redundancy valve 7. This allows the electronic control unit 16 to detect the state of the locking unit 26 and maintain its state after the start-up process of the electronic control unit 16 of the braking system 1 has been completed.
[0066] Fig. 4 shows a power supply unit 61 of the electronic control unit 16 of the braking system 1. The power supply unit 61 provides the electronic control unit 16 of the braking system 1 with two independent power supply terminals TRM-30A, TRM-30B, each connected to a separate ground TRM-31A-GND, TRM-31B-GNDB. Both power supplies TRM-30A, TRM-30B are combined in UB-VERS via a passive reverse polarity protection 62. Each terminal TRM-30A, TRM-30B also supplies several valves. The details of the valve power supply are not shown in Fig. 4. A wake-up signal is required to activate the computing system and all other internal circuits. The electronic control unit 16 of the braking system 1 can be activated via a vehicle ignition input TRM-15 of a vehicle ignition supply TRM-15-Supp. The corresponding input circuit TRM-15-Input provides an enable signal for a limiting unit (“limiter”).The limiting unit 64 protects the underlying circuitry from overvoltages and simultaneously functions as a gate. When the limiting unit 64 is enabled, the electronic control unit 16 of the motor vehicle 2 is activated. When the electronic control unit 16 of the motor vehicle 2 has fully started, the electronic control unit 16 of the braking system 1 can be kept activated via a self-hold signal, even if the enable signal of the input circuit TRM-15-Input has been withdrawn. This is necessary to perform a proper shutdown procedure when the vehicle ignition TRM-15 is switched off.
[0067] When the limiting unit 64 is activated, the voltage called UES is equal to UB-VERS, except in overvoltage situations.
[0068] Fig. 5 shows that the internal circuits of the redundancy logic 29 and the locking unit 26 are each powered by the UES voltage and the input voltage of the vehicle ignition supply TRM-15-SUPP. At least one of the voltages must be present for the redundant parking brake function to remain available. The redundancy valve 7 itself is powered by the independent power supply terminal TRM-30B, which is referenced to ground TRM-31B-GNDB. The redundant parking brake function is not available if both supply voltages (UES and TRM-15-SUPP) are not present. This is the case if a fault occurs in the computing system, whereby the self-hold signal is not present and the vehicle ignition supply TRM-15-SUPP is switched off. In this case, the internal circuits of the redundancy logic 29 and the locking unit 26 no longer receive power and can no longer perform any function.Safety regulations may further require that the driver of motor vehicle 2 be able to apply or engage the parking brake from their seat at all times. In the event of a fault, this is enabled by switching off the vehicle ignition TRM-15, as shown in Fig. 6. The parking brake is applied when the vehicle ignition TRM-15 is switched off in the event of a fault. The locking units 26 and 29 then no longer receive power, which means that the control or redundancy valve 6, 7 is de-energized and thus closed. As a result, the control or redundancy valve 6, 7 does not transmit any pressure, so the parking brake is applied.
[0069] Reference symbol
[0070] Delay Time delay
[0071] HSS high-side switch
[0072] Limiter limiting unit
[0073] LSS low-side switch
[0074] TRM-15 Vehicle Ignition Input
[0075] TRM-15-Input input circuit
[0076] TRM-15-Supp vehicle ignition supply
[0077] TRM-30A power supply terminal
[0078] TRM-30A-GNDB Ground
[0079] TRM-30B power supply terminal
[0080] TRM-30B-GNDB Ground
[0081] 1 braking system
[0082] 2 motor vehicles
[0083] 3 trailer brake
[0084] 4 trailer vehicle
[0085] 5 Parking brake module
[0086] 6 Control valve
[0087] 7 Redundancy valve
[0088] 8 shuttle valve
[0089] 9 Compressed air supply
[0090] 10 first compressed air tank
[0091] 11 second compressed air tank
[0092] 12 third compressed air tank
[0093] 13 wheels
[0094] 14 Parking brake valve
[0095] 15 Pressure sensor
[0096] 16 electronic control unit of the braking system
[0097] 17 CAN-BUS
[0098] 18 Electronic control unit of the motor vehicle Human-machine interface First electronic control line Second electronic control line Electronic circuit
[0099] Housing of the electronic control unit of the braking system
[0100] Safety control unit
[0101] Inverter
[0102] Locking unit first delay unit first storage unit
[0103] Redundancy logic
[0104] Inverter of the redundancy logic first OR gate first normal operation control signal
[0105] Status signal inverted status signal second normal operation control signal
[0106] Output signal of the first delay unit
[0107] Signal input of the first storage unit
[0108] Trigger connection of the first storage unit
[0109] Reset connection of the first storage unit
[0110] Trigger signal rising edge of the inverted status signal first failsafe control signal
[0111] Signal output of the first memory unit second OR gate third OR gate
[0112] Output signal to the low-side switch first input of the second OR gate second input of the second OR gate
[0113] Output of the second storage unit second storage unit second delay unit third normal operation control signal time-delayed second normal operation control signal second failsafe control signal
[0114] Selection failsafe control signal first input third OR gate second input third OR gate
[0115] Output second OR gate
[0116] Reset signal
[0117] Watchdog
[0118] Power supply unit
[0119] Reverse polarity protection
[0120] Reset unit
[0121] Limiting unit
Claims
Patent claims 1 . Electronic circuit (22) comprising - an electronic control unit (16), - a safety control device (24) and - an electronic locking unit (26) with a delay unit (27) and with a memory unit (28), wherein - the electronic control unit (16) is designed to control at least one actuator (7) in a predetermined manner by means of a normal operation control signal (32), - the safety control device (24) is designed to generate a trigger signal (40) for the electronic locking unit (26) without the electronic control unit (16) influencing the generation of the trigger signal (40), - the delay unit (27) is designed to - to receive the normal operation control signal (32), - to transmit the normal operation control signal (32) to the storage unit (28) with a time delay, - the storage unit (28) is designed to - to receive the trigger signal (40) generated by the safety control device (24), - to store the normal operation control signal (36) transmitted by the delay unit (27) with the time delay (Delay) as soon as the storage unit (28) receives the trigger signal (40), and - the electronic locking unit (26) is configured to control the actuator (7) based on the stored normal operation control signal (36) as an output signal (42) of the storage unit (28) as soon as the storage unit (28) has received the trigger signal (40) and stored the normal operation control signal (36) transmitted with the time delay.
2. Electronic circuit (22) according to claim 1, wherein - the electronic control unit (16) is configured to control a high-side switch (HSS) of the actuator (7) in the specified manner by means of the normal operation control signal (32), and - the electronic locking unit (26) is configured to control a low-side switch (LSS) of the actuator (7) by means of the stored normal operation control signal (36).
3. Electronic circuit (22) according to claim 2, wherein the electronic control unit (16) is configured to control the low-side switch (LSS) of the actuator by pulse width modulation.
4. Electronic circuit (22) according to one of the preceding claims, wherein - the safety control device (24) is designed to generate a status signal (33) which assumes either a normal operation value (“1”) or an error value (“0”), - the normal operation value (“1”) represents that the actuator (7) is controlled in the specified manner, - the error value (“0”) represents that the actuator (7) is not controlled in the specified manner, - the safety control device (24) comprises an inverter (25) and - the inverter (25) is configured to convert the error value (“0”) into the normal operation value (“1”) and to transmit this normal operation value (“1”) as the trigger signal (40) to the memory unit (28).
5. Electronic circuit (22) according to claim 4, wherein - the memory unit (28) is arranged to receive a reset signal (59), and - the locking unit (26) is designed to control the actuator (7) by means of the stored normal operation control signal (36) only until the storage unit (28) receives the reset signal (59), and - the electronic control unit (16) is configured to resume control of the actuator (7) as soon as the memory unit (28) receives the reset signal (59).
6. Electronic circuit (22) according to claim 5, wherein the reset signal (59) is generated by a reset unit (63) separate from the locking unit (26).
7. Electronic circuit (22) according to claim 6, wherein the inverter (25) is configured to convert the normal operation value ("1") into the error value ("0") and to transmit this error value ("0") as the reset signal (59) to the memory unit (28).
8. Electronic circuit (22) according to one of claims 4 to 7, wherein - the error value (“0”) represents that the actuator (7) is not controlled by the electronic control unit (16) in the specified manner by means of the normal operation control signal (32) because the electronic control unit (16) is in a start-up phase, and - the electronic control unit (16) is designed to - to measure analogue feedback from the high-side switch (HSS) and the low-side switch (LSS) of the actuator (7) and to derive an operating state of the locking unit (26) as a function thereof, while the electronic control unit (16) is in the start-up phase and the safety control unit (24) has generated the status signal (33) in such a way that it assumes the error value (“0”), and - to control the actuator (7) based on the measured analogue feedback such that the locking unit (26) maintains its operating state after the electronic control unit (16) has completed the start-up phase.
9. Electronic circuit (22) according to one of the preceding claims, wherein the safety control device (24) comprises a watchdog (60) which is connected on the input side to the electronic control unit (16) and on the output side to the inverter (25).
10. Electronic circuit (22) according to one of the preceding claims, wherein the delay unit (24) is configured to transmit the normal operation control signal (32) to the memory unit (28) with a time delay of at least 25 milliseconds.
11. Braking system (1) for a motor vehicle (2), the braking system (1) comprising - an electronically controllable parking brake module (5) with - a first directional control valve designed as a control valve (6), - a second directional control valve designed as a redundancy valve (7) and - a pressure-controlled shuttle valve (8), - an electronic circuit (22) according to one of the preceding claims, wherein - the electronic control unit (16) of the electronic circuit (22) is designed to control the redundancy valve (7) as an actuator by means of a normal operation control signal (32) in a predetermined manner, - the safety control unit (24) of the electronic circuit (22) is designed to generate the trigger signal (40) for the electronic locking unit (26) without the electronic control unit (16) influencing the generation of the trigger signal (40), - the delay unit (27) of the locking unit (26) of the electronic circuit (22) is arranged to - to receive the normal operation control signal (32), - to transmit the normal operation control signal (32) with the time delay (delay) to the memory unit (28) of the electronic circuit (22) of the electronic circuit (22), - the storage unit (28) is designed to - to receive the trigger signal (40) generated by the safety control device (24), - to store the normal operation control signal (36) transmitted by the delay unit (27) with the time delay (Delay) as soon as the storage unit (28) receives the trigger signal (40), and - the electronic locking unit (26) of the electronic circuit (22) is configured to control the redundancy valve (7) by means of the stored normal operation control signal (36) as an output signal (42) of the storage unit (28) as soon as the storage unit (28) has received the trigger signal (40) and stored the normal operation control signal (36).
12. Braking system (1) according to claim 11, the electronic circuit (22) further comprising a further delay unit (51) and a further memory unit (50), wherein - the electronic control unit (16) is configured to control the control valve (6) as a further actuator in a predetermined manner by means of a further normal operation control signal (52), - the further delay unit (51) is arranged to - to receive the further normal operation control signal (52), - to transmit the further normal operation control signal (52) with the time delay (delay) to the further storage unit (50), - the further storage unit (50) is designed to - to receive the trigger signal (40) generated by the safety control device (24), - to store the further normal operation control signal (53) transmitted by the further delay unit (51) with the time delay (Delay) as soon as the further storage unit (50) receives the trigger signal (40), and - the electronic locking unit (26) is configured to control the control valve (7) by means of the stored further normal operation control signal (53) as an output signal of the further storage unit (50) as soon as the further storage unit (50) has received the trigger signal (40) and stored the further normal operation control signal (53).