MOTOR VEHICLE COMPRISING AN IMPROVED RESET MANAGEMENT SYSTEM, PROCESS AND PROGRAM BASED ON SUCH A VEHICLE
The motor vehicle system addresses the issue of unnecessary resets by using a safety manager to assess the state of various powertrain components before initiating a reset, thereby enhancing engine controller availability and reducing maintenance burdens.
Patent Information
- Application Number
- FR2023012171
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-09
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-11-09
AI Technical Summary
Existing motor vehicle systems often initiate unnecessary recovery actions or resets due to irrelevant failure detections, which can lead to engine controller unavailability and increased maintenance burdens.
A motor vehicle system that includes a safety manager connected to controllers determining the state of the gearbox, couplings, electric machine, and engine. This system detects failures and triggers reset requests, but only if certain critical conditions are met, such as the gearbox being coupled and the first coupling means being closed, thereby avoiding non-essential resets.
The system effectively limits unnecessary recovery actions, enhancing the availability of the engine controller by avoiding resets in situations where a dangerous event is not possible, thus reducing maintenance workload and ensuring vehicle safety.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: AUTOMOTIVE VEHICLE COMPRISING A RESET MANAGEMENT SYSTEM IMPROVED METHOD AND PROGRAM BASED ON SUCH A VEHICLE
[0001] The invention relates to the field of motor vehicles comprising internal combustion engine control systems, and more particularly to the detection of errors or failures, and the resetting of these motor vehicles.
[0002] The software components (engine controller) must meet current normative safety requirements, in particular ISO standards. These require diagnostics configured to detect random or systematic failures that could lead to a dangerous event, and the implementation of a reconfiguration / reset to avoid this risk.
[0003] In the prior art, in the event of failure detection, the signal indicating the presence of the fault and generating a request for recovery action is sent directly to a safety manager.
[0004] In some cases, the fault is detected, but due to the architecture and condition of the powertrain, the fault may not cause a dangerous event. For example, an erroneous request for high torque has no effect on a gearbox in neutral. However, this may generate a recovery action that is not necessary from a safety point of view. In this case, the engine computer is made unavailable during the recovery time.
[0005] An objective of the present invention is to remedy the defects of the prior art, and in particular to propose a solution for limiting the recovery actions generated by detections of failures that are not relevant from a security point of view.
[0006] To achieve this objective, the invention proposes a motor vehicle comprising a powertrain which comprises: - a vehicle train equipped with wheels; - a gearbox connected to the vehicle train, the gearbox being coupled to at least one first coupling means; - a heat engine connected to said first coupling means via a second coupling means; - an electrical machine connected to said first coupling means via a third coupling means; - a safety manager connected to at least one controller determining the state of the gearbox, the coupling means, the electrical machine and the motor thermal, the safety manager performing vehicle resets, characterized in that said controller detects failures and triggers reset requests, and in that: - if the gearbox is in neutral, the safety manager does not reset the motor vehicle; - if the gearbox is coupled to the train but said first coupling means is open, the safety manager does not reset the motor vehicle; - if the gearbox is coupled to the train and said first coupling means is closed, a failure of the electrical machine triggers a reset by the safety manager; - if the gearbox is coupled to the train, said first coupling means is closed, but the second coupling means is open; a failure of the thermal engine does not trigger a reset by the safety manager.
[0007] Advantageously, the invention uses as input several states of different physical elements of the powertrain to determine whether the detected fault requires implementing recovery, or whether a dangerous event cannot occur. This limits the number of recovery actions that are not necessary from a safety point of view, and increases the availability of the engine computer.
[0008] According to a variant, the motor vehicle is characterized in that if, concomitantly with a detection of failure of the thermal engine, there is no failure of the electrical machine, the second coupling means being open, and said first coupling means being closed, then the safety manager does not reset the motor vehicle.
[0009] This makes it possible not to reset the motor vehicle whereas in this circumstance, it would have been reset in the prior art.
[0010] According to a variant, the motor vehicle is characterized in that if, concomitantly with a detection of failure of the thermal engine, there is no failure of the electrical machine, the second coupling means being closed, and said first coupling means being open, then the safety manager does not reset the motor vehicle.
[0011] This makes it possible not to reset the motor vehicle whereas in this circumstance, it would have been reset in the prior art.
[0012] According to a variant, the motor vehicle is characterized in that if, concomitantly with a detection of failure of the electrical machine, there is no failure of the thermal engine, the second coupling means being closed, and said first coupling means being open, then the safety manager does not reset the motor vehicle.
[0013] This makes it possible not to reset the motor vehicle while in this circum- constancy, it would have been reset in the prior art.
[0014] According to a variant, the motor vehicle is characterized in that if, concomitantly with a detection of failure of the thermal engine, there is a failure of the electrical machine, the second coupling means being closed, and said first coupling means being open, then the safety manager does not reset the motor vehicle.
[0015] This makes it possible not to reset the motor vehicle whereas in this circumstance, it would have been reset in the prior art.
[0016] The invention also relates to a safety management method for a motor vehicle according to the invention, comprising the following steps: - a failure detection step in which failures of the thermal engine and the electric machine are detected, and reset requests are triggered, - a control step determining the state of the gearbox, the coupling means, the electric machine and the thermal engine; - a step of resetting or not resetting the vehicle, in which: - if the gearbox is in neutral, the safety manager does not reset the motor vehicle; - if the gearbox is coupled to the train but said first coupling means is open, the safety manager does not reset the motor vehicle; - if the gearbox is coupled to the train and said first coupling means is closed, a failure of the electrical machine triggers a reset by the safety manager; - if the gearbox is coupled to the train, said first coupling means is closed, but the second coupling means is open; a failure of the thermal engine does not trigger a reset by the safety manager.
[0017] According to a variant, if concomitantly with a detection of failure of the thermal engine, there is no failure of the electrical machine, said first coupling means being open, and the gearbox closed, then the motor vehicle is not reset.
[0018] According to a variant, if concomitantly with a detection of failure of the thermal engine, there is no failure of the electrical machine, said first coupling means being closed, and the gearbox open, then the motor vehicle is not reset.
[0019] According to a variant, if concomitantly with a detection of failure of the electric machine, there is no failure of the thermal engine, said first coupling means being closed, and the gearbox open, then the motor vehicle is not reset.
[0020] According to a variant, if at the same time as a failure of the thermal engine is detected, there is a failure of the electrical machine, said first coupling means being closed, and the gearbox open, then the motor vehicle is not reset.
[0021] Another object of the invention relates to a computer program comprising program code instructions for executing the steps of the security management method according to the invention, when said program operates on a computer.
[0022] The invention will be further detailed by the description of non-limiting embodiments, and on the basis of the appended figures illustrating variants of the invention, in which: - [Fig.l] schematically illustrates a powertrain of a motor vehicle according to a preferred embodiment of the invention; - [Fig.2] schematically illustrates the configurations for implementing the invention in comparison with those of the prior art.
[0023] The invention relates to a motor vehicle comprising a powertrain control system, and more particularly to the detection of errors or failures, and the resetting of these motor vehicles.
[0024] The aim of the invention is to avoid the implementation of a recovery mode or a reset in the event of a fault not causing a dangerous event, with a view to increasing the availability of the vehicle.
[0025] For this purpose, the states of several elements of the powertrain are added as a condition for triggering fault signals to the safety manager GS. These are in particular the gearbox BV, the first KO and second K1, K2 coupling means, as well as the electric machine MEL and the thermal engine ICE. This makes it possible to bypass situations that are not critical for the user.
[0026] Bypassing fault signals when the situation is not relevant from a safety point of view reduces the number of requests to enter recovery mode when it is not necessary, as well as the number of fault codes transmitted to the maintenance service. This increases overall vehicle availability.
[0027] In the event that one of the components of the powertrain is open, the fault signals concerning the upstream components are shunted: - if the gearbox BV is in neutral or the clutch is open, no front component fault signal will be sent to the GS safety manager, because the torque cannot be implemented on the front R wheels; - if the second coupling means KO is open, no fault signal from the internal combustion engine ICE will be sent to the safety manager GS, because the torque from the thermal engine ICE cannot be transmitted to the input arm of the gearbox BV; - if said first coupling means Kl, K2 is open, no fault signal from the internal combustion engine ICE will be sent to the safety manager GS, because the torque from the thermal engine ICE cannot be transmitted to the input arm of the gearbox BV.
[0028] In [Fig.2], the failures of the MEL electric machine and ICE thermal engine and the states of the coupling means are illustrated. The reference O designates an open state, and the reference NO designates a closed (non-open) state. The reference RI designates a reset request and the reference NR designates an absence of a reset request.
[0029] As illustrated by the dotted curve in [Fig.2], the prior art solution A involves triggering a reset request RI in the event of a fault detected in the thermal engine ICE and / or the electrical machine MEL without taking into account the state of the clutch and the coupling means KO, K1, K2. On the contrary, the invention I avoids this triggering in cases where the clutch or the relevant coupling means are open (sections A different from sections I in [Fig.2]).
[0030] The invention further relates to a method and a corresponding safety management program. The program can be loaded into a controller of the motor vehicle.
Claims
Claims
1. Motor vehicle comprising a powertrain which comprises: - a vehicle train equipped with wheels (R); - a gearbox (BV) connected to the vehicle train, the gearbox being coupled to at least one first coupling means (Kl, K2); - a heat engine (ICE) connected to said first coupling means (Kl, K2) via a second coupling means (KO); - an electric machine (MEL) connected to said first coupling means (Kl, K2) via a third coupling means (KE);- a safety manager (GS) connected to at least one controller determining the state of the gearbox (BV), the coupling means (KO, Kl, K2), the electric machine (MEL) and the thermal engine (ICE), the safety manager (GS) carrying out resets of the vehicle, characterized in that said controller detects failures and triggers reset requests, and in that: - if the gearbox (BV) is in neutral, the safety manager (GS) does not reset the motor vehicle; - if the gearbox (BV) is coupled to the train but said first coupling means (Kl, K2) is open, the safety manager (GS) does not reset the motor vehicle; - if the gearbox (BV) is coupled to the train and said first coupling means (Kl, K2) is closed, a failure of the electric machine (MEL) triggers a reset by the safety manager (GS);- if the gearbox (BV) is coupled to the train, said first coupling means (Kl, K2) is closed, but the second coupling means (KO) is open; a failure of the thermal engine (ICE) does not trigger a reset by the safety manager (GS).;
2. Motor vehicle according to claim 1, characterized in that if, concomitantly with a detection of failure of the thermal engine (ICE), there is no failure of the electrical machine (MEL), the second coupling means (KO) being open, and said first coupling means (Kl, K2) being closed, then the safety manager (GS) does not reset the motor vehicle.
3. Motor vehicle according to any one of claims 1 to 2, characterized in that if, concomitantly with a detection of failure of the thermal engine (ICE), there is no failure of the electrical machine (MEL), the second coupling means (KO) being closed, and said first coupling means (Kl, K2) being open, then the safety manager (GS) does not reset the motor vehicle.
4. Motor vehicle according to any one of claims 1 to 3, characterized in that if, concomitantly with a detection of failure of the electric machine (MEL), there is no failure of the thermal engine (ICE), the second coupling means (KO) being closed, and said first coupling means (Kl, K2) being open, then the safety manager (GS) does not reset the motor vehicle.
5. Motor vehicle according to any one of claims 1 to 4, characterized in that if, concomitantly with a detection of failure of the thermal engine (ICE), there is a failure of the electrical machine (MEL), the second coupling means (KO) being closed, and said first coupling means (Kl, K2) being open, then the safety manager (GS) does not reset the motor vehicle.
6. Safety management method for a motor vehicle according to any one of claims 1 to 5, comprising the following steps: - a failure detection step in which failures of the heat engine and the electric machine (MEL) are detected, and reset requests are triggered, - a control step determining the state of the gearbox (BV), the coupling means (KO, Kl, K2), the electric machine (MEL) and the heat engine (ICE); - a step of resetting or not resetting the vehicle, in which: - if the gearbox (BV) is in neutral, the safety manager (GS) does not reset the motor vehicle; - if the gearbox (BV) is coupled to the train but said first coupling means (Kl, K2) is open, the safety manager (GS) does not reset the motor vehicle;- if the gearbox (BV) is coupled to the train and said first coupling means (Kl, K2) is closed, a failure of the electrical machine (MEL) triggers a reset by the safety manager; - if the gearbox (BV) is coupled to the train, said first coupling means (Kl, K2) is closed, but the second coupling means (KO) is open; a failure of the thermal engine does not trigger a reset by the safety manager.
7. Safety management method according to claim 6, characterized in that if, concomitantly with a detection of failure of the thermal engine, there is no failure of the electrical machine (MEL), said first coupling means (KO) being open, and the gearbox (Kl, K2) closed, then the motor vehicle is not reset.
8. Safety management method according to any one of claims 5 to 7, characterized in that if, concomitantly with a detection of failure of the thermal engine, there is no failure of the electrical machine (MEL), said first coupling means (KO) being closed, and the gearbox (Kl, K2) open, then the motor vehicle is not reset.
9. Safety management method according to any one of claims 5 to 8, characterized in that if, concomitantly with a detection of failure of the electrical machine (MEL), there is no failure of the thermal engine, said first coupling means (KO) being closed, and the gearbox (Kl, K2) open, then the motor vehicle is not reset.
10. A computer program comprising program code instructions for executing the steps of the security management method according to any one of claims 5 to 9, when said program is running on a computer.
Citation Information
Patent Citations
method FOR MONITORING A FAILURE TO CONTROL THE POWERTRAIN OF A VEHICLE
FR3062357A1
METHOD FOR STARTING AN INTERNAL COMBUSTION ENGINE OF A HYBRID DRIVE CHAIN IN A MALFUNCTIONAL SITUATION
FR3131569A1
System and method of controlling reverse driving of hybrid vehicle
US20190184810A1
Driving system for vehicle
WO2016001728A1