Safety Power Handshake Architecture for Independent Failure Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional power management architectures in automotive and industrial systems face challenges in ensuring safety integrity, including logic independence, scalability, and cost-effectiveness, particularly in detecting and responding to failures that could cause damage or injury.
Innovation Solution
A safety power management system utilizing a handshake procedure between a main digital control unit and a digital machine supervisor, with independent clocking and power supplies, to ensure system integrity and generate fail-safe notifications, thereby eliminating the need for a full-featured fail-safe state machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated full-featured state machine with physical isolation is used for safety power management, then system safety and reliability are improved, but device complexity and cost increase
Solution Approach 1:
The safety power management system is segmented into two independent parts: a main digital control unit for normal power management operations and a digital machine supervisor for safety monitoring. This segmentation allows each component to be optimized for its specific function, reducing overall complexity while maintaining safety through the specialized supervisor unit that independently verifies control unit operations.
Solution Approach 2:
The digital machine supervisor acts as an intermediary between the main control unit and the safety output. It receives control signals from the main unit, verifies their integrity through handshake procedures, and only allows safe signals to pass through to control power management components. This intermediary layer provides safety without requiring a full-featured redundant state machine.
2Reliability
If a dedicated full-featured state machine with physical isolation is used for safety power management, then system safety and reliability are improved, but manufacturing cost increases
Solution Approach 1:
By segmenting the safety function into a lightweight digital machine supervisor rather than implementing a complete redundant state machine, the manufacturing cost is reduced. The supervisor unit requires fewer resources and can be implemented with simpler circuitry while still providing ASIL-D level safety through its verification mechanisms.
Solution Approach 2:
The digital machine supervisor uses a verification approach that does not require expensive redundant hardware for every control function. Instead, it uses cost-effective handshake procedures and verification logic that can detect and respond to failures without duplicating the entire control unit, thereby reducing manufacturing costs while maintaining safety integrity.
3Reliability
If independent clock signals and power supplies are used for the digital machine supervisor and main control unit, then logic independence and safety integrity are improved, but device complexity increases
Solution Approach 1:
The system segments the clocking and power supply into independent domains for the main control unit and the digital machine supervisor. This segmentation ensures that a failure in one unit's clock or power supply cannot affect the other, maintaining logic independence. The complexity increase is minimized by using separate but simple clock and power interfaces rather than complex isolation mechanisms.
Solution Approach 2:
The independent clock and power supply arrangements create natural isolation boundaries between the main control unit and supervisor. These intermediary power and clock domains act as barriers that prevent failure propagation, ensuring that the supervisor can always operate independently to verify control unit outputs even if the main unit fails.
4Measurement precision
If a handshake procedure with verification process is implemented, then detection precision for logic integrity failures is improved, but processing time increases
Solution Approach 1:
The handshake procedure uses preliminary verification where the digital machine supervisor checks control signals before they are executed. By performing verification in advance through the handshake mechanism, the system ensures high detection precision for logic integrity failures without adding significant processing time during critical power management operations, as the verification is done proactively rather than reactively.
Data Source
Figure 1~2
Figure 3
Figure 4~6
AI summary
Provided is a safety power management system that includes a main digital control unit configured to control one or more system power supplies. In addition, a digital machine supervisor is configured to execute a handshake procedure in which it: (a) sends handshake requests to the main digital control unit at predetermined times, (b) waits for a response signal from the main digital control unit to each of the handshake requests, (c) performs a verification process on the response signal if the response signal is received within an expected timeframe, and (d) outputs a DMS safety signal if the response signal is not received within the expected timeframe or if the verification process fails. The main digital control unit also is configured to output a DCU safety signal if one of the handshake requests is not received at any one of the predetermined times.