发明名称 Fault Tolerant Control System
摘要 A fault tolerant controller system includes a first controller and a second controller. One of the first and second controllers designated as a primary controller for generating control signals intended to control actuation devices on a vehicle under non-fault operating conditions, and the other of the first and second controllers designated as a secondary controller generating control signals intended to control actuation devices on the vehicle. The actuation devices are responsive only to the designated primary controller. An error is detected in the primary controller and a message is transmitted from the faulty controller to the non-faulty controller identifying the error. The non-faulty controller is subsequently designated as the primary controller. The control signals including an identifier that identifies the non-faulty controller as the designated primary controller. In response to detecting the error, the faulty controller is reset to operate in a safe operating mode as the secondary controller.
申请公布号 US2014277608(A1) 申请公布日期 2014.09.18
申请号 US201313803290 申请日期 2013.03.14
申请人 GM GLOBAL TECHNOLOGY OPERATIONS LLC 发明人 Debouk Rami I.;Baker Stephen M.;Joyce Jeffrey
分类号 G05B9/02 主分类号 G05B9/02
代理机构 代理人
主权项 1. A fault tolerant controller strategy for a fail-operational vehicle system comprising the steps of: (a) providing a first controller and a second controller both generating control signals intended to control actuation devices on a vehicle under non-fault operating conditions, the first controller initially designated as a primary controller and the second controller initially designated as a secondary controller, the actuation devices being responsive only to the designated primary controller; (b) detecting an error in one of the two controllers, wherein the respective controller detected with the error is initially identified as a faulty controller and the other controller is initially identified as a non-faulty controller; (c) if a controller error is detected in step (b), then generating control signals by the non-faulty designated primary controller for controlling actuation of the actuation devices, the control signals including an identifier that identifies the non-faulty controller as the designated primary controller; (d) in response to detecting the error in step (b), resetting the faulty controller to operate in a safe operating mode as the secondary controller.
地址 Detroit MI US