汽车工程 ›› 2024, Vol. 46 ›› Issue (3): 438-447.doi: 10.19562/j.chinasae.qcgc.2024.03.007

• • 上一篇    

基于功能安全的整车控制器转矩监控策略研究

朱仲文,陆阳,王维志(),李丞,江维海   

  1. 合肥工业大学汽车工程技术研究院,合肥 230009
  • 收稿日期:2023-08-24 修回日期:2023-09-14 出版日期:2024-03-25 发布日期:2024-03-18
  • 通讯作者: 王维志 E-mail:2022840011@hfut.edu.cn
  • 基金资助:
    安徽省科技重大专项“车用大功率燃料电池系统关键技术研发及产业化”(202203a05020006);先进内燃动力全国重点实验室开放课题重点项目“重载燃料电池系统能量管理策略研究”(K2023-02)

Research on Torque Monitoring Strategy of Vehicle Control Unit Based on Functional Safety

Zhongwen Zhu,Yang Lu,Weizhi Wang(),Cheng Li,Weihai Jiang   

  1. Automotive Engineering Technology Research Institute,Hefei University of Technology,Hefei  230009
  • Received:2023-08-24 Revised:2023-09-14 Online:2024-03-25 Published:2024-03-18
  • Contact: Weizhi Wang E-mail:2022840011@hfut.edu.cn

摘要:

转矩控制作为整车控制器(VCU)的核心功能,保证其安全性至关重要。为此,本文针对VCU非预期的转矩输出异常的问题,参考ISO 26262标准开展功能安全分析,并提出一种基于EGAS架构的转矩控制3层监控策略。首先,以VCU相关项定义为基础,通过危害分析与风险评估确定汽车安全完整性等级以及安全目标。其次,采用故障树分析方法导出功能安全要求以及技术安全要求。再次,针对安全目标,设计了基于AURIX TC275三核主控芯片与TLF35584电源监控芯片的功能安全机制。此外,通过3层监控策略分配CPU资源,实现转矩控制基本功能与监控功能的分离。最后,进行处理器在环测试,包括UDE调试、UDS诊断以及TLF35584安全状态控制测试。结果表明:该3层监控策略能够实现VCU转矩控制的基本功能并在出现故障时及时进入安全状态,从而达到安全目标。

关键词: 功能安全, 整车控制器, 转矩控制, 3层监控

Abstract:

Torque control is the core function of the vehicle control unit (VCU), which is crucial to ensure its safety. Therefore, for the problem of unexpected torque output anomalies in VCU, functional safety analysis is conducted in this paper based on the ISO 26262 standards, and a torque control three-layer monitoring strategy is proposed based on the EGAS architecture. Firstly, based on the definition of VCU items, the level of automotive safety integrity and safety objectives are determined through hazard analysis and risk assessment. Secondly, the fault tree analysis method is used to derive functional safety requirements and technical safety requirements. Once again, a functional safety mechanism based on the AURIX TC275 three-core main control chip and TLF35584 power monitoring chip is designed for safety objectives. In addition, CPU resources are allocated through a three-layer monitoring strategy to achieve the separation of basic torque control functions and monitoring functions. Finally, processor in loop testing is conducted, including UDE debugging, UDS diagnosis, and TLF35584 security state control testing. The results indicate that this three-layer monitoring strategy can achieve the basic function of VCU torque control and enter a safe state in a timely manner in case of faults, thereby achieving safety goals.

Key words: functional safety, vehicle control unit, torque control, three level monitoring