Motor Control Device CPU Redundancy for Safe Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional motor control devices face challenges in maintaining continuous control when a calculation unit malfunctions, especially at high speeds or with high residual charges, leading to safety concerns such as electric shocks during sudden motor stops in electric vehicles.
Innovation Solution
A motor control device with an integrated control unit that receives malfunction information from multiple microcomputers and CPUs, utilizing self-diagnosis and communication units to monitor and continue processing even if one CPU malfunctions, ensuring safe motor control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional control device uses a single microcomputer with self-diagnosis functionality, then the device can detect malfunctions, but it cannot continue control when a malfunction occurs
Solution Approach 1:
The control device is divided into multiple independent microcomputers (first microcomputer with first CPU and second CPU, second microcomputer with third CPU), each capable of independent operation. This segmentation allows the system to isolate and detect malfunctions in individual CPUs while other CPUs continue to execute control tasks, thereby maintaining control continuity even when one CPU fails.
Solution Approach 2:
The system changes the operational state parameter of the CPUs by switching between active execution and diagnostic monitoring modes. When a malfunction is detected in one CPU, the system reconfigures the operational parameters so that other CPUs take over control functions, and the malfunctioned CPU enters a diagnostic state, thus maintaining overall system functionality.
2Reliability
If the control device stops functioning when a malfunction is detected, then safety is maintained, but control continuity is lost during high-speed driving
Solution Approach 1:
The system prepares compensatory control arrangements in advance by having multiple CPUs ready to take over control functions. When a malfunction occurs, the pre-configured redundancy allows immediate transition to backup control without stopping the motor, thus cushioning the impact of the malfunction and maintaining control continuity during critical high-speed driving conditions.
Solution Approach 2:
The integrated control unit acts as an intermediary that coordinates between multiple microcomputers and CPUs. It receives diagnostic information from various CPUs, determines the system state, and manages the transition of control functions, enabling safe continuation of motor control even when individual CPUs malfunction.
3Productivity
If multiple microcomputers are used to monitor malfunctions, then control continuity can be maintained, but the device complexity increases
Solution Approach 1:
Each CPU in the system is designed with multi-functionality, capable of both executing motor control tasks and performing self-diagnosis or diagnosing other CPUs. This universal design reduces the need for dedicated separate diagnostic hardware, thereby managing system complexity while maintaining control continuity through multiple functional units.
Solution Approach 2:
The system merges the control and diagnostic functions into a unified multi-CPU architecture where the first microcomputer and second microcomputer work together. The integrated control unit combines information from multiple sources to make centralized control decisions, simplifying the overall system management despite having multiple components.
Data Source
AI summary
A motor control device avoids the difficulties associated with safely controlling a motor using a second calculation unit when a first calculation unit malfunctions. A motor control device monitors a malfunction of a first microcomputer and a malfunction of a first CPU of the first microcomputer and performs a determination based on a result of a second external communication functional unit. When the determination is normal, the process proceeds determine that the first CPU is normal and a second CPU malfunctions. Therefore, it is possible to continue processing using the first CPU in this case.


