Calibrating a battery management system
By enabling vehicle integrators to validate safety parameter changes in BMS using CRC value comparisons, the method addresses the limitations of current validation processes, enhancing flexibility and reducing costs and complexity while maintaining ISO 26262 ASIL-C compliance.
Patent Information
- Application Number
- PCT/US2024/060948
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-19
- Filing Date
- 2024-12-19
- Publication Date
- 2025-06-26
AI Technical Summary
Current methods for validating safety parameter changes in Battery Management Systems (BMS) require manufacturer involvement, limiting flexibility and increasing costs, delays, and operational complexity for integrators.
A method and system that allow vehicle integrators to modify and validate safety-critical parameters in the field by generating and comparing CRC values between a computing device and the BMS, ensuring compliance with ISO 26262 ASIL-C standards without manufacturer involvement.
This approach reduces effort, cost, and time for integrators by enabling flexible and efficient modification and validation of safety parameters, allowing for tailored BMS configurations that meet diverse safety requirements.
Smart Images

Figure US2024060948_26062025_PF_FP_ABST
Abstract
Description
CALIBRATING A BATTERY MANAGEMENT SYSTEMBACKGROUND
[0001] To minimize the risk of injury or death from vehicles operating on public roads, it is essential to implement safety measures that adhere to state-of-the-art standards. For Battery Management Systems (BMS), this translates into compliance with the ISO 26262 safety' standard at an ASIL-C level. This compliance mandates that all safety -related parameters in the BMS undergo strict validation to ensure their correctness and effectiveness, a process typically handled by the BMS manufacturer.
[0002] While ISO 26262 ASIL-C certification permits safety parameters in a BMS to be adjustable, any modifications to these parameters require thorough validation to confirm they meet safety requirements. Traditionally, this validation is performed exclusively by the BMS manufacturer, making it challenging to adapt safety-related parameters in the field. Currently, there is no known method to validate updated parameters without the direct involvement of the manufacturer, significantly limiting flexibility in parameter calibration outside controlled environments.SUMMARY OF INVENTION
[0003] Embodiments in accordance with the present disclosure are directed to methods, systems, apparatus, and computer readable storage medium for calibrating a battery management system (BMS) are disclosed. In a particular embodiment, a method of calibrating a BMS includes generating, by a computing device, a first cyclic redundancy check (CRC) value for a new system configuration file to be uploaded to the BMS. In this embodiment, the new system configuration file includes safety related parameter values defined by the computing device. The method also includes after the new system configuration file is uploaded to the BMS, receiving from the BMS, by the computing device, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS. The method also includes determining, by the computing device, whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device. In this embodiment, the method also includes in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validating, by the computing device, the safety related parameter values and intended safety function associated with the safety related parameter values.
[0004] In another embodiment, an apparatus for calibrating a battery' management system (BMS) is disclosed. The apparatus includes a computer processor and a computer memory operatively coupled to the computer processor. In this embodiment, the computer memory has disposed within it computer program instructions that, when executed by the computer processor, cause the computer processor to generate, by a computing device, a first CRC value for a new system configuration file to be uploaded to the BMS. In this embodiment, the new system configuration file includes safety related parameter values defined by the computing device. The computer memory has disposed within it computer program instructions that, when executed by the computer processor, cause the computer processor to after the new system configuration file is uploaded to the BMS, receive from the BMS, by the computing device, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS. In this embodiment, the computer memory has disposed within it computer program instructions that, when executed by the computer processor, cause the computer processor to determine, by the computing device, whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device. The computer memory also has disposed within it computer program instructions that, when executed by the computer processor, cause the computer processor to in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
[0005] In another embodiment, a non-transitory computer readable storage medium for calibrating a battery management system (BMS) is disclosed. In this embodiment, the non- transitory computer readable storage medium stores computer program instructions which, when executed, cause a computing device to generate a first CRC value for a new system configuration file to be uploaded to the BMS. In this embodiment, the new system configuration file includes safety related parameter values defined by the computing device. The non-transitory computer readable storage medium also stores computer program instructions which, when executed, cause a computing device to after the new system configuration file is uploaded to the BMS, receive from the BMS, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS. The non-transitory computer readable storage medium also stores computer program instructions which, when executed, cause a computing device to determine whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device. In this embodiment, the non-transitory computer readable storage medium also storescomputer program instructions which, when executed, cause a computing device to in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
[0006] As explained above, requiring the BMS manufacturer to validate safety parameter changes places a significant burden on the integrator responsible for installing the BMS in a vehicle, leading to increased costs, delays, and operational complexity. This invention addresses that challenge by enabling the vehicle integrator to modify and validate safety- critical parameters in the field while maintaining compliance with ISO 26262 ASIL-C. That is, according to embodiments of the present invention, the vehicle integrator, instead of the BMS manufacturer, can modify and validate the safety parameters.
[0007] This innovation represents a substantial reduction in effort, cost, and time for integrators, eliminating the need for manufacturer involvement in routine safety parameter updates. By providing a flexible and efficient modification and validation process, the invention enhances the integrator's ability to tailor BMS configurations for individual customers, meeting diverse safety requirements with ease and adaptability.
[0008] The foregoing and other objects, features and advantages of the invention will be apparent from the following more particular descriptions of exemplary embodiments of the invention as illustrated in the accompanying drawings wherein like reference numbers generally represent like parts of exemplary embodiments of the invention.BRIEF DESCRIPTION OF DRAWINGS
[0009] FIG. 1 A sets forth a block diagram illustrating a system that includes a computing device configured to calibrate a battery management system in accordance with at least one embodiment of the present disclosure.
[0010] FIG. IB sets forth a block diagram illustrating a system that includes an exemplary battery management system configured for calibration in accordance with at least one embodiment of the present disclosure.
[0011] FIG. 2 sets forth a flow chart illustrating an exemplary method of calibrating a battery management system in accordance with at least one embodiment of the present disclosure.
[0012] FIG. 3 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.
[0013] FIG. 4 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.
[0014] FIG. 5 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.
[0015] FIG. 6 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.
[0016] FIG. 7 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.
[0017] FIG. 8 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.
[0018] FIG. 9 is a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure.DESCRIPTION OF EMBODIMENTS
[0019] The terminology used herein for the purpose of describing particular examples is not intended to be limiting for further examples. Whenever a singular form such as “a”, “an” and “the” is used and using only a single element is neither explicitly nor implicitly defined as being mandatory, further examples may also use plural elements to implement the same functionality. Likewise, when a functionality is subsequently described as being implemented using multiple elements, further examples may implement the same functionality using a single element or processing entity. It will be further understood that the terms “comprises”, “comprising”, “includes” and / or “including”, when used, specify the presence of the stated features, integers, steps, operations, processes, acts, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, processes, acts, elements, components and / or any group thereof.
[0020] It will be understood that when an element is referred to as being “connected” or “coupled” to another element, the elements may be directly connected or coupled or via one or more intervening elements. If two elements A and B are combined using an “or”, this is to be understood to disclose all possible combinations, i.e., only A, only B, as well as A and B. An alternative wording for the same combinations is “at least one of A and B”. The same applies for combinations of more than two elements.
[0021] Accordingly, while further examples are capable of various modifications and alternative forms, some particular examples thereof are shown in the figures and will subsequently be described in detail. However, this detailed description does not limit further examples to the particular forms described. Further examples may cover all modifications, equivalents, and alternatives falling within the scope of the disclosure. Like numbers refer to like or similar elements throughout the description of the figures, which may be implementedidentically or in modified form when compared to one another while providing for the same or a similar functionality.
[0022] This invention allows safety critical parameters defining the safety behavior of a Battery Management System (BMS) compliant with ISO 26262 ASIL-C to be defined on PC, checked, and uploaded to the BMS in a way which is compliant with ISO 26262 ASIL-C. On a computing device, the user defines the safety parameters for the BMS using an appropriate application (configuration / tool / integrator). Following the definition of the parameters, the tool generates a binary file containing the parameters and a hash value of the file (a CRC- value).
[0023] Prior to uploading the binary file to the BMS, the tool reads back the parameters from the binary file and presents them to the user in a text file for comparison with the intended parameter values. Upon validation of the content of the binary file, it is uploaded to the BMS, which generates a hash value (CRC-value) of the received file. The CRC-value is shared with the configuration tool via a potential unsafe connection like for instance a CAN- bus (without any end-to-end validation). The tool shall now compare the CRC-value received from the BMS with the CRC-value generated by the tool. As the likelihood of a CRC-collision (identical CRC -values from different files) is low, this comparison is accepted valid within the scope of ISO 26262 ASIL-C.
[0024] The CRC-comparison allows communication over a non-safe connection on the condition that the CRC-value calculated by the BMS can be trusted, which is ensured via safe BMS design in accordance with ISO 26262 ASIL-C. This is a major saving in terms of effort, cost, and time for the integrator. This alternative modification and validation process provides an unsurpassed flexibility in the daily work of the integrator when configuring BMS for individual customers with the need of individual safety related parameters.
[0025] Exemplary methods, apparatuses, systems, and non-transitory computer program products for calibrating a battery management system in accordance with the present disclosure are described with reference to the accompanying drawings, beginning with FIG.1 A. For further explanation, FIG. 1 A sets forth a block diagram illustrating a system that includes a computing device (BMS Creator (194)) configured to calibrate a battery management system (BMS) (190) in accordance with at least one embodiment of the present disclosure. The example BMS (190) includes firmware (191), a bootloader (192), and hardware (193). The hardware (193) may include components that are configured for monitoring battery cells, analyzing data associated with the battery cells, and transmitting or reporting the data to the other systems, such as vehicle control system (VCS). Thebootloader (192) may be configured for updating a configuration file for the firmware (191) of the BMS (190).
[0026] The computing device (194) includes a controller (197) coupled to memory (195). The memory (195) includes a vehicle integrator (196) comprising computer program instructions that when executed by the controller (197) cause the controller to generate a first CRC value for a new system configuration file to be uploaded to the BMS (190). In this example, the new system configuration file includes safety related parameter values defined by the computing device (194). The integrator also includes computer program instructions that when executed by the controller (197) cause the controller to: after the new system configuration file is uploaded to the BMS, receive from the BMS (190) a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS. The integrator (196) also includes computer program instructions that when executed by the controller (197) cause the controller to determine whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device. The integrator (196) also includes computer program instructions that when executed by the controller (197) cause the controller to: in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
[0027] In a particular embodiment, the integrator (196) includes computer program instructions that when executed by the controller (197) cause the controller to define the safety related parameter values. In this example, the safety related parameter values are pertinent to the new system configuration file for the BMS. The integrator (196) may also include computer program instructions that when executed by the controller (197) cause the controller to generate the new system configuration file in a binary format for upload to the BMS.
[0028] In the example of FIG. 1A, the integrator (196) may also include computer program instructions that when executed by the controller (197) cause the controller to generate from the new system configuration file, a text file. The integrator (196) may also include computer program instructions that when executed by the controller cause the controller to: before uploading the new system configuration file to the BMS, validate the safety related parameter values for correctness by inspection of the text file including generating or calculating the first CRC value.
[0029] The integrator (196) may also be configured to upload the new system configuration file to the BMS. For example, the integrator (196) may transmit via a communication interface (198) the new system configuration file to the bootloader (192) of the BMS (190).
[0030] In another embodiment, the integrator (196) may also include computer program instructions that when executed by the controller cause the controller to: in response to determining that the second CRC value from the BMS is not identical to the first CRC value generated by the computing device, indicate that the safety related parameter values and intended safety function associated with the safety related parameter values are not validated.
[0031] For further explanation, FIG. IB sets forth a block diagram of a system that includes an example battery management system configured for calibration according to at least one embodiment of the present disclosure. The system includes a battery pack (102), such as a high voltage battery for use in an electric vehicle (101). The battery pack (102) includes a plurality of cells (104a-n), such as Lithium-ion (Li-ion) cells. The cells (104a-n) are grouped into modules (106a-n) such that each module (106a-n) comprises a corresponding subset of the cells (104a-n). The cells (104a-n) may be physically grouped into modules (106a-n) using a casing, chassis, or other enclosure. The cells (104a-n) may also be logically grouped into modules (106a-n) by virtue of distinct groupings of cells (104a-n) being monitored by a distinct module monitoring system (108a-n), as will be described below.
[0032] The system also includes a battery management system (110). In a particular embodiment, the battery management system (110) of FIG. IB is an example of the battery management system 190 of FIG. 1A. The battery management system (110) includes hardware and software for monitoring various attributes of the cells (104a-n) and providing battery sensor data indicating these attributes to a vehicle control system (112). The battery' management system (110) includes a plurality of module monitoring systems (MMS) (108a- n). Each MMS (108a-n) is configured to monitor a corresponding module (106a-n) of cells (104a-n). For example, each module (106a-n) may have a MMS (108a-n) attached to a chassis, base, tray, or other mechanism holding the cells (104a-n) of the module (106a-n). Each MMS (108a-n) includes sensors to measure various attributes of the cells (104a-n) of its corresponding module (106a-n). Such attributes may include voltage, current, temperature, and potentially other attributes. The attributes are indicated in battery sensor data generated by the MMS (108a-n).
[0033] In the example of FIG. IB, In the example of FIG. IB, the MMs are connected to a vehicle control system (VCS) via a CAN-bus and the MMSs transmit the battery sensor data via a wired connection. The VCS (112) may include a central “computer” of a vehicle. TheVCS (112) may be a central control unit or may refer collectively to one or more vehicle subsystems.
[0034] The BMS (110) may support various standard communication protocols within the Industrial, Science and Medical (ISM) frequency bands, such as IEEE 802.1 la / b / g / n (i.e., Wi-Fi and wireless local area network in the 2.4 GHz band), IEEE 802. 1 lac (Wi-Fi and wireless local area network in the 5 GHz band), 802.15.1 (Bluetooth / Bluetooth Low Energy and wireless personal area networks in the 2.4 GHz band), WAP (Wireless Access Protocol), and other protocols that will occur to those of skill in the art. In a particular embodiment, the BMS (110) uses a non-standard communication protocol in the 2.4 GHz band for communication between the MMSs (108a-n) and the WNC (114).
[0035] As with the BSM (190) of FIG. 1A, the BMS (110) of FIG. IB may be calibrated by a computing device (e.g., the computing device 194) by uploading a new configuration file.The safety parameters in this new configuration file may be validated by a BMS integrator in the field by the process described in FIG. 1A.
[0036] The arrangement of components and devices making up the exemplary system illustrated in FIG. IB are for explanation, not for limitation. Various embodiments of the present disclosure may be implemented on a variety of hardware platforms in addition to those illustrated in FIG. IB.
[0037] For further explanation, FIG. 2 sets forth a flow chart illustrating an exemplary method of calibrating a wireless battery' management system in accordance with at least one embodiment of the present disclosure. The steps may be performed by the integrator (196) of FIG. 1A on a BMS (e.g., the BMS 190 of FIG. 1A and the BMS 110 of FIG. IB).
[0038] The method of FIG. 2 includes at step 1, the integrator (e.g., the integrator (196) of FIG. 1A) defining safety related parameters pertinent to the actual system configuration considering the applied battery and the applied external safety related components. As part of the safety evaluation, it is the integrator’s responsibility to define the safety related parameters in accordance with the assumptions of use in the safety manual.
[0039] At step 2, the integrator generates a configuration file in binary format for uploading to the n3-BMS. Safety compliance is to be validated through vehicle testing by the integrator.
[0040] At step 3, the integrator shall validate the parameter values for correctness by inspection of a text file generated from the binary file before uploading the binary file to the n3-BMS (Automatically done in the BMS creator tool). A readable text file is generated from the binary file intended for upload to the n3-BMS. Due to the diverse implementation, it is considered safe, when checked by the integrator.
[0041] At step 4, the integrator calculates a CRC-value for the generated configuration file (Automatically done in the BMS Creator tool). No tool qualification needed since CRC collision when validating CRCs is very unlikely and later validation is based upon a safe CRC calculation.
[0042] At step 5, the integrator uploads the generated configuration file to the n3-BMS system via CAN. Upon process not safe, but correct upload is validated through CRC comparison.
[0043] At step 6, the integrator reads back the CRC value generated by the n3-BMS of the uploaded configuration file and validates that it is identical to the CRC value generated by the integrator. Validation to be considered safe with high coverage, since CRC collision is very unlikely. Coverage is increased through plausibility check by the base software and through vehicle testing.
[0044] At step 7, the integrator validates the intended safety functions through vehicle testing based upon the uploaded configuration file. Vehicle testing considered safe as all safety requirements shall be validated for the specific configuration file values.
[0045] For further explanation, FIG. 3 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 3 includes generating (302), by a computing device (301), a first cyclic redundancy check (CRC) value (352) for a new system configuration file (350) to be uploaded to the BMS 303. A new configuration file is a digital file containing updated or customized settings and parameters that define how a system, such as a Battery Management System (BMS), operates. This file includes data such as safety-related parameter values, thresholds, and operational limits tailored to specific requirements or use cases. It is formatted to be machine-readable, often in binary or structured formats, and is uploaded to the system to apply the new configuration.
[0046] In a particular embodiment, the new system configuration file includes safety related parameter values (351) defined by the computing device (301). A safety-related parameter value is a critical configuration setting within a system that directly impacts its ability to operate safely and mitigate potential hazards. These values are carefully defined to ensure compliance with safety standards, such as ISO 26262, and are tailored to the specific operational requirements of the system. For example, in a Battery Management System (BMS), a safety -related parameter might include the maximum allowable cell voltage to prevent overcharging, which could lead to thermal runaway. Another example is a minimum cell voltage that indicates a lower voltage threshold below which the battery should notdischarge to avoid damage or reduced lifespan. Another example is the temperature threshold for thermal shutdown, which ensures the system deactivates before overheating occurs. Additionally, the parameter values may include a maximum charging current that indicates the highest allowable cunent during charging to prevent overheating or damage to the battery cells. Another example is maximum discharging current that indicates the highest allowable current during discharge. Another example parameter value is a low-temperature charging threshold that specifies the minimum temperature at which charging is allowed to avoid damaging the battery chemistry. Readers of skill in the art will realize that the above examples of safety value parameters are non-limiting and non-exhaustive and are dependent upon the identified safety goals. Embodiments of the present invention may include a set of safety related parameter values that include some combination of the above examples as well as one or more additional safety related parameter values that are not listed or described but would occur to one of skill in the art.
[0047] These parameters collectively ensure the system operates within safe bounds and maintains functional safety. Generating the first CRC value (352) for a new system configuration file (350) by the computing device (301) involves computing a hash value that uniquely represents the binary contents of the configuration file. The computing device (301), using specialized software or an integrator tool, processes the binary file to calculate the CRC value based on a pre-defined CRC algorithm, ensuring the integrity and correctness of the file. This CRC value serves as a reference to validate the configuration file after it is uploaded to the BMS (303), enabling the detection of errors or unauthorized changes during transmission.
[0048] The method of FIG. 3 also includes after the new system configuration file 350 is uploaded to the BMS (303), receiving (304) from the BMS (303), by the computing device (301), a second CRC value (354) generated by the BMS (303) after the new system configuration file (350) is uploaded to the BMS (303). In a particular embodiment, the BMS generates the CRC value by applying a similar or same CRC algorithm that the computing device used to the binary contents of the uploaded configuration file. This process involves treating the binary file as a stream of data bits and performing a division operation on the data using a predefined polynomial divisor. The remainder of this division, typically a fixed- length binary sequence, serves as the CRC value.
[0049] After the new system configuration file (350) is uploaded to the BMS (303), the BMS calculates a second CRC value (354) based on the uploaded file using its internal algorithm. This second CRC value, which represents the integrity and correctness of the received file, isthen transmitted from the BMS (303) to the computing device (301) via a communication interface, such as a CAN bus or another protocol. The computing device (301) monitors the communication channel and retrieves the second CRC value transmitted by the BMS. Once received, the computing device compares the second CRC value with the original CRC value it generated prior to the upload to verify that the file was transmitted and stored without corruption or alteration.
[0050] In addition, the method of FIG. 3 includes determining (306), by the computing device (301), whether the second CRC value (354) from the BMS (303) is identical to the first CRC value (352) generated by the computing device (301). Determining whether the second CRC value (354) from the BMS (303) is identical to the first CRC value (352) generated by the computing device (301) involves comparing the two CRC values bit by bit. The computing device (301) first receives the second CRC value calculated and transmitted by the BMS. It then retrieves the stored first CRC value that it originally computed from the same configuration file before the upload. Using a straightforward comparison operation, the computing device checks if the two CRC values are exactly the same, which would confirm the integrity and correctness of the file as received and processed by the BMS. If the CRC values match, the computing device validates the upload; if they differ, it flags a potential error, indicating corruption or alteration of the file during transmission or processing.
[0051] The method of FIG. 3 also includes in response to determining that the second CRC value (354) from the BMS (303) is identical to the first CRC value (352) generated by the computing device (301), validating (308), by the computing device (301), the safety related parameter values (351) and intended safety function associated with the safety related parameter values (351). In response to determining that the second CRC value (354) from the BMS (303) is identical to the first CRC value (352) generated by the computing device (301), the computing device validates the safety-related parameter values (351) by confirming their integrity and correctness. Since the matching CRC values ensure that the configuration file was transmitted and stored without corruption, the computing device considers the safety -related parameter values to be reliably uploaded. Upon successful completion of these checks, the computing device records the configuration as validated and safe for use in the BMS.
[0052] For further explanation, FIG. 4 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 4 expands upon the method of FIG. 3 by including defining (402), by the computing device (301), the safety related parameter values (351). The safetyrelated parameter values (351) are pertinent to the new system configuration file for the BMS. Defining the safety -related parameter values (351) by the computing device (301) involves using a configuration tool or application to input and set specific values that ensure the system meets safety requirements. In a particular embodiment, the computing device provides a user interface where an integrator can define parameters such as voltage limits, temperature thresholds, or current limits, which are critical for safe BMS operation. In one embodiment, the tool cross-references these inputs against predefined safety guidelines, such as those outlined in a safety manual, to ensure the parameters align with the system's operational and safety constraints. Once the parameters are defined, the computing device encodes them into a configuration file in a format suitable for upload to the BMS.
[0053] For further explanation, FIG. 5 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 5 expands upon the method of FIG. 3 by including generating (502), by the computing device (301), the new system configuration file (350) in a binary format for upload to the BMS. Generating the new system configuration file (350) in binary format by the computing device (301) involves encoding the defined safety-related parameter values into a structured binary file. The computing device uses a configuration tool or integrator application that translates the user-defined parameters from a readable format, such as a text-based interface, into machine-readable binary data. During this process, the tool applies a predefined schema or format to ensure compatibility with the BMS, structuring the file to include all necessary safety-related parameters and metadata. The binary file is then saved and prepared for secure upload to the BMS, ensuring it maintains the integrity and structure required for proper operation.
[0054] For further explanation, FIG. 6 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 4 expands upon the method of FIG. 3 by including generating (602) from the new system configuration file (350), by the computing device (301), a text file (650). Generating a text file (650) from the new system configuration file (350) by the computing device (301) involves converting the binary data of the configuration file into a human-readable format. The computing device uses a configuration tool that reads the structured binary file and translates the safety-related parameter values and metadata into a textual representation, often formatted as plain text or XML. This text file is then created to allow integrators or users to verify and cross-check the parameters for correctness and compliance with safety requirements. The text file serves as an intermediary step in thevalidation process, ensuring transparency and enabling manual or automated review of the configuration before uploading it to the BMS.
[0055] For further explanation, FIG. 7 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 7 expands upon the method of FIG. 6 by including before uploading the new system configuration file (350) to the BMS (303), validating (702) the safety related parameter values (351) for correctness by inspection of the text file 650. Before uploading the new system configuration file (350) to the BMS (303), validating the safety -related parameter values (351) for correctness by inspecting the text file (650) involves reviewing the human-readable representation of the configuration. The computing device (301) generates the text file (650) from the binary configuration file, displaying each safety - related parameter and its assigned value. This file may then be reviewed manually by the integrator or through an automated tool to ensure that the parameters match the intended values and comply with predefined safety requirements or constraints. Any discrepancies, such as incorrect thresholds or missing parameters, can be identified and corrected before proceeding with the upload, ensuring that the configuration aligns with the safety standards and functional requirements.
[0056] For further explanation, FIG. 8 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 8 expands upon the method of FIG. 3 by including uploading (802), by the computing device (301), the new system configuration file (350) to the BMS (303). Uploading the new system configuration file (350) to the BMS (303) by the computing device (301) involves transmitting the binary file over a communication interface such as a CAN bus or another compatible protocol. The computing device initiates the transfer by packaging the configuration file into data packets that the BMS can interpret and process. During the upload, the computing device ensures that the data is transmitted in sequence and monitors for acknowledgments or errors from the BMS to confirm successful delivery. Once the entire file is uploaded, the BMS processes and stores the configuration data for application during its operation.
[0057] For further explanation, FIG. 9 sets forth a flowchart that illustrates another exemplary method of calibrating a battery management system in accordance with the present disclosure. The method of FIG. 9 expands upon the method of FIG. 3 by including in response to determining that the second CRC value (354) from the BMS (303) is not identical to the first CRC value (352) generated by the computing device (301), indicating (902), bythe computing device (301), that the safety related parameter values (351) and intended safety function associated with the safety related parameter values are not validated. In response to determining that the second CRC value (354) from the BMS (303) does not match the first CRC value (352) generated by the computing device (301), the computing device detects and registers the discrepancy as an error. In a particular embodiment, the computing device generates an alert or message indicating that the safety-related parameter values (351) and the associated intended safety' function have not been validated due to potential data corruption or transmission errors. This indication may be displayed on the user interface of the configuration tool, logged for further investigation, or transmitted to relevant systems for corrective action. By highlighting the mismatch, the computing device ensures that the unvalidated configuration is not used, thereby preventing unsafe operation of the BMS
[0058] Exemplary embodiments of the present disclosure are described largely in the context of a fully functional devices for calibrating a battery management system. Readers of skill in the art will recognize, however, that the present disclosure also may be embodied in a computer program product disposed upon computer readable storage media for use with any suitable data processing system. Such computer readable storage media may be any storage medium for machine-readable information, including magnetic media, optical media, or other suitable media. Examples of such media include magnetic disks in hard drives or diskettes, compact disks for optical drives, magnetic tape, and others as will occur to those of skill in the art. Persons skilled in the art will immediately recognize that any computer system having suitable programming means will be capable of executing the steps of the method of the invention as embodied in a computer program product. Persons skilled in the art will recognize also that, although some of the exemplary embodiments described in this specification are oriented to software installed and executing on computer hardware, nevertheless, alternative embodiments implemented as firmware or as hardware are well within the scope of the present disclosure.
[0059] The present disclosure may be a system, an apparatus, a method, and / or a computer program product. The computer program product may include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present disclosure.
[0060] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductorstorage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium includes the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only- memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD- ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiberoptic cable), or electrical signals transmitted through a wire.
[0061] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.
[0062] Computer readable program instructions for carrying out operations of the present disclosure may be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection maybe made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) may execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.
[0063] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.
[0064] These computer readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions may also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including instructions which implement aspects of the function / act specified in the flowchart and / or block diagram block or blocks.
[0065] The computer readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0066] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing thespecified logical function(s). In some alternative implementations, the functions noted in the block may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.
[0067] One or more embodiments may be described herein with the aid of method steps illustrating the performance of specified functions and relationships thereof. The boundaries and sequence of these functional building blocks and method steps have been arbitrarily defined herein for convenience of description. Alternate boundaries and sequences can be defined so long as the specified functions and relationships are appropriately performed. Any such alternate boundaries or sequences are thus within the scope and spirit of the claims. Further, the boundaries of these functional building blocks have been arbitrarily defined for convenience of description. Alternate boundaries could be defined as long as the certain significant functions are appropriately performed. Similarly, flow diagram blocks may also have been arbitrarily defined herein to illustrate certain significant functionality.
[0068] To the extent used, the flow diagram block boundaries and sequence could have been defined otherwise and still perform the certain significant functionality. Such alternate definitions of both functional building blocks and flow diagram blocks and sequences are thus within the scope and spirit of the claims. One of average skill in the art will also recognize that the functional building blocks, and other illustrative blocks, modules and components herein, can be implemented as illustrated or by discrete components, application specific integrated circuits, processors executing appropriate software and the like or any combination thereof.
[0069] While particular combinations of various functions and features of the one or more embodiments are expressly described herein, other combinations of these features and functions are likewise possible. The present disclosure is not limited by the particular examples disclosed herein and expressly incorporates these other combinations.
[0070] Advantages and features of the present disclosure can be further described by the following statements:
[0071] 1. A method of calibrating a battery management system (BMS), the method comprising: generating, by a computing device, a first CRC value for a new systemconfiguration file to be uploaded to the BMS, the new system configuration file including safety related parameter values defined by the computing device; after the new system configuration file is uploaded to the BMS, receiving from the BMS, by the computing device, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS; determining, by the computing device, whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device; and in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validating, by the computing device, the safety related parameter values and intended safety function associated with the safety related parameter values.
[0072] 2. The method of statement 1 further comprising: defining, by the computing device, the safety related parameter values, the safety related parameter values pertinent to the new system configuration file for the BMS.
[0073] 3. The method of statements 1 or 2 further comprising: generating, by the computing device, the new system configuration file in a binary format for upload to the BMS.
[0074] 4. The method of any of statements 1-3 further comprising: generating from the new system configuration file, by the computing device, a text file.
[0075] 5. The method of any of statements 1-4 further comprising: before uploading the new system configuration file to the BMS, validating the safety related parameter values for correctness by inspection of the text file.
[0076] 6. The method of any of statements 1-5 further comprising: uploading, by the computing device, the new system configuration file to the BMS.
[0077] 7. The method of any of statements 1-6 further comprising: in response to determining that the second CRC value from the BMS is not identical to the first CRC value generated by the computing device, indicating, by the computing device, that the safety related parameter values and intended safety function associated with the safety related parameter values are not validated.
[0078] 8. An apparatus for calibrating a battery management system (BMS), the apparatus comprising a computer processor and a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the computer processor to: generate, by a computing device, a first CRC value for a new system configuration file to be uploaded to the BMS, the new system configuration file including safety related parameter values defined by the computing device; after the new sy stem configuration file is uploadedto the BMS, receive from the BMS, by the computing device, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS; determine, by the computing device, whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device; and in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
[0079] 9. The apparatus of statement 8 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: define, by the computing device, the safety related parameter values, the safety related parameter values pertinent to the new system configuration file for the BMS.
[0080] 10. The apparatus of statements 8 or 9 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: generate, by the computing device, the new system configuration file in a binary format for upload to the BMS.
[0081] 11. The apparatus of any of statements 8-10 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: generate from the new system configuration file, by the computing device, a text file.
[0082] 12. The apparatus of any of statements 8-11 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: before uploading the new system configuration file to the BMS, validating the safety related parameter values for correctness by inspection of the text file.
[0083] 13. The apparatus of any of statements 8-12 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: upload, by the computing device, the new system configuration file to the BMS.
[0084] 14. The apparatus of any of statements 8-13 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: in response to determining that the second CRC value from the BMS is not identical to the first CRC value generated by the computing device, indicate, by the computing device, that the safety related parameter values and intended safety function associated with the safety related parameter values are not validated.
[0085] 15. A non-transitory computer readable storage medium storing computer program instructions which, when executed, cause a computing device to: generate a first CRC value for a new system configuration file to be uploaded to a battery management system (BMS),the new system configuration file including safety related parameter values defined by the computing device; after the new system configuration file is uploaded to the BMS, receive from the BMS, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS; determine whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device; and in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
[0086] 16. The non-transitory computer readable storage medium of statement 15 further comprising computer program instructions which, when executed, cause the computing device to: define, by the computing device, the safety related parameter values, the safety related parameter values pertinent to the new system configuration file for the BMS.
[0087] 17. The non-transitory computer readable storage medium of statements 15 or 16 further comprising computer program instructions which, when executed, cause the computing device to: generate, by the computing device, the new system configuration file in a binary format for upload to the BMS.
[0088] 18. The non-transitory computer readable storage medium of any of statements 15-17 further comprising computer program instructions which, when executed, cause the computing device to: generate from the new system configuration file, by the computing device, a text file.
[0089] 19. The non-transitory computer readable storage medium of any of statements 15-18 further comprising computer program instructions which, when executed, cause the computing device to: before uploading the new system configuration file to the BMS, validating the safety related parameter values for correctness by inspection of the text file.
[0090] 20. The non-transitory computer readable storage medium of any of statements 15-19 further comprising computer program instructions which, when executed, cause the computing device to: upload, by the computing device, the new system configuration file to the BMS.
[0091] It will be understood from the foregoing description that modifications and changes may be made in various embodiments of the present disclosure without departing from its true spirit. The descriptions in this specification are for purposes of illustration only and are not to be construed in a limiting sense. The scope of the present disclosure is limited only by the language of the following claims.
Claims
CLAIMSWhat is claimed is:
1. A method of calibrating a battery management system (BMS), the method comprising: generating, by a computing device, a first cyclic redundancy check (CRC) value for a new system configuration file to be uploaded to the BMS, the new system configuration file including safety related parameter values defined by the computing device; after the new system configuration file is uploaded to the BMS, receiving from the BMS, by the computing device, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS; determining, by the computing device, whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device; and in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validating, by the computing device, the safety related parameter values and intended safety function associated with the safety related parameter values.
2. The method of claim 1 further comprising: defining, by the computing device, the safety related parameter values, the safety related parameter values pertinent to the new system configuration file for the BMS.
3. The method of claim 1 further comprising: generating, by the computing device, the new system configuration file in a binary' format for upload to the BMS.
4. The method of claim 1 further comprising: generating from the new system configuration file, by the computing device, a text file.
5. The method of claim 4 further comprising: before uploading the new system configuration file to the BMS, validating the safety related parameter values for correctness by inspection of the text file.
6. The method of claim 1 further comprising: uploading, by the computing device, the new system configuration file to the BMS.
7. The method of claim 1 further comprising: in response to determining that the second CRC value from the BMS is not identical to the first CRC value generated by the computing device, indicating, by thecomputing device, that the safety related parameter values and intended safety function associated with the safety related parameter values are not validated.
8. An apparatus for calibrating a battery management system (BMS), the apparatus comprising a computer processor and a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the computer processor to: generate, by a computing device, a first cyclic redundancy check (CRC) value for a new system configuration file to be uploaded to the BMS, the new system configuration file including safety' related parameter values defined by the computing device; after the new system configuration file is uploaded to the BMS, receive from the BMS, by the computing device, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS; determine, by the computing device, whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device; and in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
9. The apparatus of claim 8 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: define, by the computing device, the safety related parameter values, the safety related parameter values pertinent to the new system configuration file for the BMS.
10. The apparatus of claim 8 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: generate, by the computing device, the new system configuration file in a binary format for upload to the BMS.
11. The apparatus of claim 8 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: generate from the new system configuration file, by the computing device, a text file.
12. The apparatus of claim 11 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to:before uploading the new system configuration file to the BMS, validating the safety related parameter values for correctness by inspection of the text file.
13. The apparatus of claim 8 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: upload, by the computing device, the new system configuration file to the BMS.
14. The apparatus of claim 8 further comprising computer program instructions that, when executed by the computer processor, cause the computer processor to: in response to determining that the second CRC value from the BMS is not identical to the first CRC value generated by the computing device, indicate, by the computing device, that the safety related parameter values and intended safety function associated with the safety related parameter values are not validated.
15. A non-transitory computer readable storage medium storing computer program instructions which, when executed, cause a computing device to: generate a first cyclic redundancy check (CRC)value for a new system configuration file to be uploaded to a battery management system (BMS), the new system configuration file including safety related parameter values defined by the computing device; after the new system configuration file is uploaded to the BMS, receive from the BMS, a second CRC value generated by the BMS after the new system configuration file is uploaded to the BMS; determine whether the second CRC value from the BMS is identical to the first CRC value generated by the computing device; and in response to determining that the second CRC value from the BMS is identical to the first CRC value generated by the computing device, validate the safety related parameter values and intended safety function associated with the safety related parameter values.
16. The non-transitory computer readable storage medium of claim 15 further comprising computer program instructions which, when executed, cause the computing device to: define, by the computing device, the safety related parameter values, the safety related parameter values pertinent to the new system configuration file for the BMS.
17. The non-transitory computer readable storage medium of claim 15 further comprising computer program instructions which, when executed, cause the computing device to: generate, by the computing device, the new system configuration file in a binary format for upload to the BMS.
18. The non- transitory computer readable storage medium of claim 15 further comprising computer program instructions which, when executed, cause the computing device to: generate from the new system configuration file, by the computing device, a text file.
19. The non-transitory computer readable storage medium of claim 18 further comprising computer program instructions which, when executed, cause the computing device to: before uploading the new system configuration file to the BMS, validating the safety related parameter values for correctness by inspection of the text file.
20. The non-transitory computer readable storage medium of claim 15 further comprising computer program instructions which, when executed, cause the computing device to: upload, by the computing device, the new system configuration file to the BMS.
Citation Information
Patent Citations
Secure electric vehicle battery management system software upgrading method
CN108334331A
Battery management unit software upgrading method and system
CN111045703A
Battery parameter adjusting method, device and system and storage medium
CN113270651A
Vehicle battery management system communication method and device, storage medium and equipment
CN116865948A
Reliable Data Transmission with Reduced Bit Error Rate
US20120226965A1