Beruflich Dokumente
Kultur Dokumente
I.
INTRODUCTION
II.
A. System definition
The basic architecture of two-motor hybrid powertrain is
shown in figure 1. At present, this hybrid system is mainly
used for commercial buses, and normally rear-wheel drive. It
includes combustion engine, integrated starter generator
(ISG), traction motor (TM) and power battery. The engine
and ISG share the common output shaft, and connects to the
traction motor via clutch. This hybrid system can achieve
multiple drive modes such as pure electric drive, series drive
and parallel drive.
The control system is composed of vehicle
controller(VCU),
engine
controller(ECU),
motor
controller(combined ISG and TM), battery management
systemBMS, and so on. The vehicle controller is mainly
responsible for coordinating the engine, ISG, TM and battery,
as well as clutch.
BMS
Power
Battery
V
C
U
Engine
ISG
Clutch
ECU
MCU
TM
Product development
system level
5 HW
6 SW
level
level
safety
4-11
Release
production
for
7-5 Production
7-6
Operation,service
and decomissioning
E1
E2
E3
Concept phase
E4
Almost
every
drive on
average
Product development
safety
E0
Less
Once a
often A few
month or
Incredib
times
than
Description
more
le
once a a year
often
year
Controllability
C0
C1
C2
C3
Simpl Norma
Difficult
lly
y
Controll
Description
contro contro to control
able
llable llable
Severity
S0
S1
S2
S3
Severe
and
LifelifeLight
threate threatenin
and
ning g injuries
moder
No
injurie (survival
Description
ate
injuries
uncertain
s
injurie
), fatal
(survi
s
injuries
val
probab
le)
production
release
Probability of
exposure
the
TABLE 1
QUANTIZATION OF RISK ASSESSMENT
amax =
iTmax
= 2.13m / s 2
Mr
Event
situation
Unintende
d vehicle
start
probability
Severity
Exposure
Entering
bus stop
At traffic
lights
of
Controll
ability
ASIL
S3
E4
C2
S1
E4
C2
(1)
1
s = amax t 2 = 2.4m
2
v = amax t = 3.2 m / s = 11.5 km / h
Hazardous
TABLE 3
HARA OF TWO-MOTOR HYBRID POWERTRAIN
Hazardous Event
Safety goal
(2)
Unintended vehicle
start
Unintended sideslip
III.
ASIL
A
Inputs
diagnosis
Inputs
Actuators
Level 2
Function monitoring
Program flow check
Level 3
Quest spec
test data Part
Question
Answer
Enable
Sub-control chip
TABLE 4
SAFETY REQUIREMENTS OF VCU
Safety functions
TABLE 5
HARDWARE ARCHITECTURE METRICS IN ACCORDANCE WITH
Answer
Monitoring mudule
Inputs
Control
unit
Link
ASIL B
ASIL C
ASIL D
>90%
>97%
>99%
>60%
>80%
>90%
TABLE 6
ERROR DETECTION AT THE SOFTWARE LEVEL IN ACCORDANCE
WITH ISO26262
ASIL
Methods
1a
1b
Plausibility checka
C
++
D
++
++
1d
++
1e
++
++
1f
++
B
++
1c
A
++
IV.
CONCLUSIONS