Safe State Trigger Architecture for Lower-Complexity ECU Safety
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Safety relevant applications, such as in the automotive field, require safe states in case of failure events, but ensuring all components comply with high safety integrity levels increases complexity and cost, particularly for lower hierarchy electronic control units.
Innovation Solution
An electronic control unit with a separate safe state trigger that monitors input signals and sends a safe state signal directly to the electronic device, bypassing the application controller, allowing it to comply with a lower safety integrity level.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all components in the electronic control unit comply with high safety integrity level, then safety reliability is improved, but device complexity and cost increase
Solution Approach 1:
The electronic control unit is segmented into distinct functional components: a safe state trigger dedicated to safety monitoring and a separate application controller for main control functions. This segmentation allows each component to have differentiated safety requirements, with the application controller operating at a lower safety integrity level while the safe state trigger handles safety-critical functions.
Solution Approach 2:
The safe state trigger acts as an intermediary component between the supervising controller and the application controller. It receives input signals from the supervising controller, identifies failure signals, and triggers safe states independently, thereby mediating safety-critical operations without requiring the application controller to fully comply with high safety integrity level requirements.
2Reliability
If all components in the electronic control unit comply with high safety integrity level, then safety reliability is improved, but cost increases
Solution Approach 1:
The electronic control unit is segmented into distinct functional components: a safe state trigger dedicated to safety monitoring and a separate application controller for main control functions. This segmentation allows each component to have differentiated safety requirements, with the application controller operating at a lower safety integrity level while the safe state trigger handles safety-critical functions.
Solution Approach 2:
The application controller can be implemented using less expensive components that do not need to fully comply with high safety integrity level requirements, as the critical safety functions are handled by the dedicated safe state trigger. This allows cost reduction in the application controller while maintaining overall system safety.
3Ease of operation
If the application controller processes all input signals including safety signals, then control functionality is simplified, but safety integrity is compromised
Solution Approach 1:
The electronic control unit is segmented into distinct functional components: a safe state trigger dedicated to safety monitoring and a separate application controller for main control functions. This segmentation allows each component to have differentiated safety requirements, with the application controller operating at a lower safety integrity level while the safe state trigger handles safety-critical functions.
Solution Approach 2:
The safe state trigger acts as an intermediary component between the supervising controller and the application controller. It receives input signals from the supervising controller, identifies failure signals, and triggers safe states independently, thereby mediating safety-critical operations without requiring the application controller to fully comply with high safety integrity level requirements.
Data Source
AI summary
An electronic control unit (114) is presented. The electronic control unit (114) comprises at least:an electronic device (120);an application controller (122) configured for controlling the electronic device (120); anda safe state trigger (124) configured for:monitoring input signals sent from a supervising controller (112) to the electronic control unit (114);identifying a failure signal from the input signals; andsending a safe state signal to the electronic device (120) when identifying the failure signal.Further, a method for triggering a safe state, a control system (110) and a use of the electronic control unit (114), the method or the control system (110) are presented.


