Fault Source Identification in Automotive FCCU Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing signal processing systems in automotive safety contexts, such as those regulated by ISO 26262, face challenges in accurately routing fault information due to the complexity of fault channels, leading to potential mismanagement of faults and loss of critical information.
Innovation Solution
A method and system that enhance the quality of information provided to cores by using a data structure-based approach to identify the source of errors, allowing for faster and more accurate fault management, and enabling customized startup and scalable responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple safety mechanisms are used to cover faults in complex SoC systems, then functional safety compliance is improved, but device complexity and information loss increase
Solution Approach 1:
The patent segments the fault routing system into multiple independent components: fault detection units, fault collector and control unit (FCCU), and multiple processor cores. Each component handles specific fault types independently, reducing the complexity of overall fault management while maintaining comprehensive safety coverage.
Solution Approach 2:
The FCCU acts as an intermediary between fault detection mechanisms and processor cores. It receives fault information from multiple sources, processes it through a finite state machine, and generates appropriate reaction codes for the cores. This intermediary structure simplifies the fault routing architecture by centralizing fault management functionality.
2Reliability
If fault information is routed through multiple multiplexed channels, then safety coverage is improved, but information accuracy deteriorates
Solution Approach 1:
The patent implements feedback mechanisms where the FCCU continuously monitors fault states and adjusts its finite state machine transitions based on received fault information. The system provides feedback to processor cores through reaction codes that include information about fault status and required actions, ensuring accurate fault origin identification while maintaining comprehensive safety coverage.
3Reliability
If comprehensive fault routing is implemented, then safety mechanisms are improved, but response time increases
Solution Approach 1:
The FCCU is pre-configured with a finite state machine that defines all possible fault states and transitions. Reaction codes and fault handling protocols are pre-established, allowing the system to respond to faults immediately upon detection without requiring complex real-time decision-making. This preliminary preparation reduces response time while maintaining comprehensive fault management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method (500), comprising: coupling a set of sensing circuits to a set of electronic devices; sensing, via the sensing circuits, a set of sensing signals indicative of an operating state of the set of electronic devices; applying logic signal processing to the set of sensing signals via coupling a set of signal processing channels to the set of sensing circuits and providing a set of logically combined sensing signals as a result, wherein the logically combined sensing signals are indicative of whether the operating state of the electronic devices in the set of electronic devices is an expected operating state or an unexpected operating state; coupling the set of logically combined sensing signals to a set of input channels of a fault collection and control unit, FCCU; storing at least one data structure comprising data related to the way in which the set of input channels of the FCCU are coupled to the set of sensing circuits via the set of signal processing channels. In response to at least one combined sensing signal being indicative of an expected operating state of the set of electronic devices, the method comprises: identifying (502) the FCCU input channel from which the at least one combined sensing signal indicative of the unexpected operating state originates; accessing (504, 512, 512) the data stored in the at least one data structure; based on the accessed data, identifying (514) the electronic device producing the unexpected operating status sensing signal; providing (516) an interrupt request signal to the identified electronic device.