Error Signal Handling Unit Delay Mechanism for Automotive ECU

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern automotive ECUs face challenges in providing uninterrupted service due to increasing complexity, where critical errors often lead to immediate fail-safe modes, potentially disrupting vehicle controllability, especially in heavy vehicles.

Innovation Solution

An error signal handling unit that receives error signals from external devices and only outputs an error condition signal if no recovery signal is received within a given delay time, preventing immediate fail-safe mode entry and allowing for error mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If immediate fail-safe mode entry is implemented upon detecting critical errors, then system safety is improved, but system availability and vehicle controllability deteriorate

Engineering Contradiction:
Improvesystem safetyVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The error signal handling unit implements a delay mechanism that waits for a predetermined time period before transitioning to fail-safe mode. This preliminary waiting action allows the system to attempt error mitigation without immediately entering fail-safe mode, thereby maintaining system availability while still ensuring safety through the timeout mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts its response to errors by introducing a time-based conditional transition. Instead of a static immediate response, the system remains in normal operation mode during the delay period and only transitions to fail-safe mode if the error persists beyond the predetermined time, creating a dynamic error handling approach that balances safety and availability.

Inventive Principle:
Principle #15Dynamics

2Speed

If immediate fail-safe mode entry is implemented upon detecting critical errors, then error response speed is improved, but error mitigation opportunity deteriorates

Engineering Contradiction:
Improveerror response speedVSAvoiderror mitigation capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs a preliminary wait action before committing to fail-safe mode. This preliminary delay provides an opportunity for error mitigation while still maintaining a relatively fast response mechanism through the timeout approach, thus preserving both error response speed and mitigation capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The predetermined time delay acts as an intermediary mechanism between immediate error detection and fail-safe mode entry. This intermediary period allows the system to evaluate whether the error can be mitigated before committing to the fail-safe state, thus preserving error mitigation opportunities while maintaining responsive error handling.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If error signals are immediately processed, then error detection responsiveness is improved, but false fail-safe mode entries increase

Engineering Contradiction:
Improveerror detection responsivenessVSAvoidfalse fail-safe mode entries
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system implements a preliminary delay period before executing fail-safe mode entry. This preliminary waiting action filters out transient or spurious error signals that may occur momentarily, thereby reducing false fail-safe mode entries while still maintaining responsive error detection through the timeout mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The predetermined time delay serves as a cushioning mechanism that protects the system from premature or false fail-safe mode entries. By providing this temporal cushion before the actual mode transition, the system can absorb transient errors without triggering unnecessary safety responses, thus reducing false positives.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS8786424B2Error signal handling unit, device and method for outputting an error condition signal
Publication Date: 2014.07.22 INFINEON TECHNOLOGIES AG
  • US8786424B2 patent drawing
  • US8786424B2 patent drawing
  • US8786424B2 patent drawing

AI summary

An Error signal handling comprises a circuitry configured to receive an error signal from an external device indicating an error condition in the external device. The circuitry is further configured to receive a recovery signal indicating a mitigation of the error condition in the external device or indicating that a mitigation of the error condition in the external device is possible. Furthermore, the circuitry is further configured to output an error condition signal based on the error signal in response to a reception of the error signal if within a given delay time from the reception of the error signal, the circuitry does not receive the recovery signal and otherwise to omit outputting the error condition signal.