Engine Start Security Control System Using Dual-Path Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional vehicle systems lack comprehensive security measures to prevent engine start failures caused by sensor, hardware, and software failures, particularly when the transmission is in power flow conditions, which can lead to unsafe engine starting.
Innovation Solution
An engine start security control system with multiple modules generating engine start flags based on internal mode switch signals, including a validation layer that uses a modified signal and a two's complement to ensure secure engine starting, and a control layer that de-bounces the signal to filter out noise, with a supervisory module to generate allow or prohibit signals based on flag settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single control module independently assesses engine start permission, then the system is simple and easy to operate, but the system is vulnerable to software failures that could lead to unsafe engine starts
Solution Approach 1:
The control module is segmented into two independent functional paths: a control layer that generates the primary engine start flag and a validation layer that generates a secondary engine start flag. Each path independently processes the IMS signal to determine transmission range, ensuring that a single software failure cannot compromise engine start security. This segmentation divides the monolithic control function into separate, verifiable components.
Solution Approach 2:
The validation layer provides feedback verification of the control layer's engine start permission decision. The validation layer independently assesses the IMS signal and compares its result with the control layer's determination. Only when both layers agree does the system permit engine start, creating a feedback mechanism that detects and prevents software failures in either path.
2Reliability
If redundant sensors are used to detect sensor failures, then sensor reliability improves, but device complexity and cost increase
Solution Approach 1:
The validation layer acts as an intermediary verification mechanism rather than adding redundant physical sensors. Instead of duplicating the IMS sensor, the system uses the same sensor input but processes it through a separate validation path that independently determines transmission range. This intermediary computational layer provides redundancy at the logic level without duplicating hardware components.
3Reliability
If a secondary calculation path is implemented for security-critical variables, then software failure protection improves, but the system complexity and development difficulty increase
Solution Approach 1:
The validation layer uses the same IMS signal input and transmission range determination logic as the control layer, making the validation path universal in its approach. Both layers perform the same fundamental function of assessing whether the transmission is in park or neutral, ensuring consistency in the security criterion while providing independent verification through separate implementation.
Data Source
AI summary
An engine start security control system for a vehicle having a transmission that is driven by an engine includes a first module that generates a first engine start flag based on an internal mode switch (IMS) signal and a second module that generates a second engine start flag based on a modified IMS signal. A third module selectively generates an engine start allow signal based on the first and second engine start flags.


