Fail-Operational E-Powertrain Using ASIL Decomposition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current fail-operational vehicle powertrain systems, particularly those required to meet the highest Automotive Safety Integrity Level (ASIL) D standards, incur significant costs and weight due to the use of redundant hardware components, which negatively impact efficiency and range.

Innovation Solution

Implementing ASIL decomposition and functional deployment strategies to redundantly distribute functionality across existing controllers, allowing non-redundant controllers to execute multiple functions and transition tasks in case of failure, thereby achieving ASIL D compliance without redundant hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant hardware components are used to achieve fail-operational ASIL D compliance, then system reliability is improved, but device complexity and weight increase

Engineering Contradiction:
Improvefail-operational complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies multi-functionality by enabling a single controller to execute multiple different functions through software configuration. The controller is designed to perform both primary powertrain control functions and backup safety monitoring functions, eliminating the need for separate redundant hardware components while maintaining ASIL D fail-operational compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the primary control system and backup safety system into a single integrated controller. By combining multiple functions that were previously distributed across separate hardware components into one unified controller, the system reduces complexity and weight while preserving reliability through software-based redundancy.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If redundant hardware components are used to achieve fail-operational ASIL D compliance, then system reliability is improved, but vehicle weight increases

Engineering Contradiction:
Improvefail-operational complianceVSAvoidcontroller weight
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The controller is designed with multi-functionality to perform both primary control and backup safety functions, eliminating the need for additional redundant hardware components that would increase vehicle weight. This single controller handles multiple roles that previously required separate physical units.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces physical hardware redundancy with software-based functional redundancy. Instead of adding more physical controller units to provide backup functionality, the system uses software configuration and execution to achieve the same safety objectives, thereby reducing overall system weight.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If redundant hardware components are used to achieve fail-operational ASIL D compliance, then system reliability is improved, but manufacturing cost increases

Engineering Contradiction:
Improvefail-operational complianceVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The controller is designed with multi-functionality to perform both primary control and backup safety functions, eliminating the need for separate redundant hardware components. This reduces the total number of parts that need to be manufactured, assembled, and tested, thereby lowering manufacturing costs while maintaining ASIL D compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple functions into a single controller unit, reducing the bill of materials and assembly complexity. By combining primary control and backup safety functions in one device, the system reduces component count, simplifies supply chain requirements, and lowers overall manufacturing costs.

Inventive Principle:
Principle #5Merging (Combining)

4Device complexity

If multiple functions are distributed across non-redundant controllers, then device complexity is reduced, but reliability may be compromised

Engineering Contradiction:
Improvesystem complexityVSAvoidfail-operational compliance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system implements continuous monitoring and feedback mechanisms where the controller monitors its own operational status and can detect failures in real-time. This self-monitoring capability ensures that when functions are distributed across non-redundant controllers, the system can identify and respond to failures to maintain ASIL D fail-operational compliance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The controller is pre-configured with backup safety functions and monitoring capabilities before operation. This preliminary setup ensures that when the system operates with non-redundant controllers, the fail-operational compliance is already established through pre-programmed safety logic and monitoring routines that activate automatically upon failure detection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10857889B2Highly-integrated fail operational e-powertrain for autonomous driving application
Publication Date: 2020.12.08 NIO TECH ANHUI CO LTD
  • US10857889B2 patent drawing
  • US10857889B2 patent drawing
  • US10857889B2 patent drawing

AI summary

Embodiments of the present disclosure are directed to using Automotive Safety Integrity Level (ASIL) decomposition and a functional deployment strategy to redundantly distribute functionality across existing controllers. Accordingly, each of a plurality of non-redundant controllers of the vehicle can execute a plurality of functions. The controllers can comprise a vehicle controller and a controller for each of a plurality of different powertrain systems. The plurality of functions can comprise one or more functions for each of the plurality of powertrain systems and each of the functions can execute on multiple controllers. When a failure of one controller occurs, this can be detected either by a controller's build-in internal monitor or by a two-way comparison or three-way voting by external controllers. The functions executing on the failed controller can be transitioned to other controllers based on prior execution of those functions by the other controllers.