The invention relates generally to integrated circuit (IC) sensors and more particularly to IC sensor self-diagnostics using multiple communication signal paths.
A recent trend in automobile drive technology, as part of developments in the automobile electronics sector, is for established passive safety systems like seatbelts and airbags to be extended by active safety systems, such as anti-lock braking systems (ABS), electronic stability programs (ESP) and electrical steering systems, to provide an increasing range of driver assistance functionalities. As has already been the case in the drive train for some time, system complexity is also continuously increasing here in order to detect hazardous driving situations and contribute to accident avoidance through active interventions by a control system. With ongoing technological advances, these trends are expected to continue and grow stronger in the future.
The resulting significant increase in the number of electronic components with a safety-related functionality has given rise to previously unprecedented requirements in terms of reliability and system availability. In order to be able to achieve this while at the same time meeting cost objectives, it is desired to develop efficient methods for functional self-monitoring through integrated test methods along with redundancies. At the same time, progress is desired in design methodologies in order to be able to identify and avoid possible weaknesses in safety systems early on. In the area of magnetic field sensors, for example, this has been done by the introduction of the Safety Integrity Level (SIL) standard.
In order to meet SIL standards in the automotive field, it is desired to implement and use corresponding self-tests, including built-in self-tests, not only at start-up but also during normal operation, as well as automatic monitoring structures or corresponding redundant functional blocks and/or signal paths. Conventional magnetic sensor systems, in particular linear Hall measuring systems, have used a single-channel analog main signal path. It is technically very difficult, or perhaps even impossible, to meet the SIL requirements in safety-critical applications with this concept. It is therefore no longer possible to cover safety requirements with just one sensor system. Thus, other conventional solutions have used two identical redundant magnetic field sensors to meet SIL requirements. Obviously, a considerable drawback of these solutions is the corresponding doubling of the cost for not one but two sensors. Still other solutions propose a defined superimposed test signal outside the signal frequency rages, such as magnetic field sensors with an additional on-chip conductor loop or pressure sensors with superimposed electrostatic coupling to the sensor.
A need remains for a reliable and cost-efficient sensor system that meets SIL and/or other applicable safety standards.
The invention may be more completely understood in consideration of the following detailed description of various embodiments of the invention in connection with the accompanying drawings, in which:
While the invention is amenable to various modifications and alternative forms, specifics thereof have been shown by way of example in the drawings and will be described in detail. It should be understood, however, that the intention is not to limit the invention to the particular embodiments described. On the contrary, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the invention as defined by the appended claims.
Embodiments relate to systems and methods for sensor self-diagnostics using multiple signal paths. In an embodiment, the sensors are magnetic field sensors, and the systems and/or methods are configured to meet or exceed relevant safety or other industry standards, such as SIL standards.
One of the sensors is a primary or main sensor. In the embodiment of
Secondary sensor 104 and its corresponding secondary signal path is generally one that, when compared with main sensor 102, is less accurate, slower and/or noisier; operates using different working principles; and/or includes additional secondary sensing tasks. Secondary sensor 104 can therefore be less expensive than main sensor 102 and may also have fewer restrictions on positioning, chip area and other factors that affect the cost and complexity of system 100. These secondary sensing tasks can include measurement of compensation signals, such as temperature, mechanical stress, internal operational or bias voltages, operational or bias currents, and/or additional, simpler target measurements. For example, sensors 102 and 104 comprise magnetic field sensors in an embodiment, and a target measurement of such sensors would be magnetic fields. In embodiments, however, secondary sensor 104 can comprise a plurality of sensors or a sensor array, such as a magnetic field sensor to mirror main sensor 102 as well as a temperature sensor and a stress sensor in one example embodiment.
In an embodiment, however, the secondary sensor and signal path can be used in a plausibility comparison with the main sensor and signal path. Further, the secondary sensor and signal path can be used for fault detection as well as verification of the main sensor and signal path. Several advantages can be provided by such a configuration. First, SIL compatibility can be achieved. Second, size and cost advantages can be realized as compared with conventional solutions, and self-testing can be carried out during normal operation without significant additional hardware. Further, additional self-testing features of the digital signal processing (DSP) and of the signal processing software can be implemented. Additionally, field failure and return rates can also be reduced, improving cost efficiencies on both sides, i.e., for the original chip manufacturer as well as the customer implementing the chip.
Referring to
System 200 also comprises one or more additional sensors 208, also considered secondary or ancillary sensors. Sensor(s) 208 can include temperature, stress, current, magnetic field or some other sensor format in various embodiments.
In an embodiment, main sensor 202 communicates with a digital signal processing (DSP) portion 220. DSP portion 220 can in turn communicate with an external ECU or other control unit (refer, for example, to
For example, in the embodiment of
In an embodiment, elements of the main signal path and elements of the secondary signal path are not identical and/or are implemented using different working principles. For example, A/D converter 212 in the main signal path can comprise a sigma-delta converter of the third order while A/D converter 218 in the secondary signal path can comprise a sigma-delta converter of the first order, or one or more the A/D converters can utilize a successive approximation register (SAR) or flash technique instead of sigma-delta. In other words, as with secondary sensor 204 being generally one that, when compared with main sensor 102, is less accurate, slower and/or noisier, operates using different working principles, and/or includes additional secondary sensing tasks, the same can be true for A/D converter 218 when compared with A/D converter 212. Further, the secondary sensor 204 when compared with main sensor 102 may have a lower sampling rate, higher latency time, lower bandwidth, smaller analog-to-digital conversion resolution, smaller signal range, different signal encodings, different mapping of sensor signals, different compensation algorithms, and/or a different processing schedule. Even further, the secondary sensor 204 may comprise fewer second sensing elements than the main sensor 102 comprises first sensing elements. The secondary sensor 204 also may comprise second sensing elements of a smaller second sensitive area than the main sensor 102 comprises first sensing elements of a first sensing area.
The different working principle may be implemented in any of a number of manners. The different working principle may be implemented for a functional portion of the first signal path as a hardware implementation, while a corresponding functional portion of the second signal path is implemented as software. Alternatively, the different working principle may be implemented using a different sensing technology for the first signal path than for the second signal path. Alternatively, the different working principle may be implemented by employing for a first functional portion of the first signal path a functional processing hardware that is at least in part different from a second functional portion of the second signal path corresponding to the first functional portion.
Outputs of cross-switch 214 are associated with both the main and secondary signal paths and are fed to a digital signal processing (DSP) portion 220. DSP 220 includes a state machine 222, a clamping algorithm 224 and a memory matrix 226 in an embodiment. Consistent with the main and secondary signal paths concept, DSP 220 also includes a first software portion associated with the main signal path and a second software portion associated with the secondary signal path. Additionally or alternatively, DSP 220 can also implement different DSP methodologies or techniques for the main signal path and the second signal path. In an embodiment, DSP 220 is coupled to I/O 210 via an interface 228, and I/O 210 is in turn coupled to an external ECU (not depicted in
The DSP 220 may be implemented as a multicore processor, or more than one DSP. Multi-core DSPs may comprise identical cores or different cores. The DSP 200 may have a DSP of one provider in the main path, and a multi-core DSP from a different provider in the secondary signal path.
The main and secondary signal paths thereby can provide two different, quasi-redundant analog signal paths that provide numerous beneficial properties. For example, transmission of the main magnetic field signal from sensor 202 in a cycle via the main signal path can provide a highly precise computational result, wherein the main signal path itself operates very precisely, such as by using chopping or other techniques, and quickly, at least with respect to the secondary signal path. The main signal path also operates as independently and freely, without being influenced by other system components.
For analytic purposes, the secondary signal path also provides the possibility of providing its data to the control unit, where the data could be processed with either a positive or a negative sign. Possible parallel outputs from DSP 220 to interface 228 and I/O 210 are shown in system 200, while sequential transmissions could also be implemented, utilizing time-division multiplex or on demand as externally requested, for example.
The outputs from DSP 220 to interface 228 may be output via only one terminal which, depending on a multiplexing scheme, will at one instance provide a first output signal associated with the main signal path and at another instant, in accordance with the multiplexing scheme, a second output signal associated with the secondary signal path.
Sensors 202 and 204 and optionally 208 can utilize different sensing principles with respect to their measured values, including processes, technological performance and specifications, size and/or placement of the sensors 202 and 204 themselves, and biasing. An embodiment of system 200 includes two bandgap biasing portions 230 and 232 and a biasing comparison 234. Biasing portion 230 is associated with the main signal path, and biasing portion 232 is associated with the secondary signal path. Biasing portions 230 and 232 provide the option of different biasing of sensors 102 and 104, respectively, while biasing comparison 234 can provide an output signal to DSP 220 for consideration.
Embodiments of system 200 can also utilize different A/D conversion and/or switching concepts, via A/D converters 212 and 218 and cross-switch 214. For example, as previously mentioned, A/D converter 212 in the main signal path can comprise a sigma-delta converter of the third order while A/D converter 218 in the secondary signal path can comprise a sigma-delta converter of the first order, or one or more the A/D converters can utilize a successive approximation register (SAR) or flash technique instead of sigma-delta. In various embodiments, these different A/D conversion and/or switching concepts can provide different fault behaviors and/or failure probabilities. Measurement ranges can also be switched in embodiments, via the noted inputs to A/D converters 212 and 218 in
Embodiments can also provide the option of switching the sensors 202 and 204 with their respective main and secondary signal paths. For example, secondary sensor 204 can be exchanged into the main signal path, and likewise with sensor 202 and the secondary signal path. This option can provide improved fault detection and/or locating by isolating a sensor from its path, for example.
Another advantage presented by embodiments of system 200 is the ability to compare, such as by forming quotients, the output signals of each of the main and secondary signal paths and evaluate the result. The result can be evaluated to determine one or more aspects related to the performance or functioning of sensors 202 and 204, the signal paths, system 200 and/or some other component. For example, comparing the output signals can detect a rapid change in the input signal. In embodiments utilizing compensation, such as temperature compensation when sensor 208 comprises a temperature sensor, the output signals can be compared as a function of the temperature compensation signal. In other embodiments, clamping or limiting of information from sensors 208 can be implemented to isolate other signals, properties or information.
Because DSP 220 utilizes software 1 for the main signal path and software 2 for the secondary signal path, output results of the signal paths can be compared in embodiments. Such a comparison can provide a check of the software algorithms themselves. Internal or external window comparisons can also be used in plausibility checks of the two signal paths or computational results of DSP 220. As part of such a plausibility check, warning and/or failure thresholds can be implemented.
The comparison of the output results of the two signal paths may comprise forming at least one of a quotient, a linear transformation of the output results of the two signal paths, and a comparison of an absolute difference between the output results of the two signal paths against a difference threshold.
Embodiments can therefore provide safety standard compatibility as well as fault self-diagnostics in a sensor system. While the handling of faults can vary according to the type and severity as well as the particular system at issue and/or relevant safety standards, embodiments can provide opportunities to alert system users of detected issues. For example, in a safety-critical automotive electronic power steering sensor application utilizing magnetic field sensors, detected faults can lead an ECU to alert a driver of a critical system issue such that appropriate action can be taken. In certain applications, an ECU can be programmed to switch to a safe mode or secure operating protocol in an error fault or deviation situation.
Further, embodiments are more space- and cost-efficient than conventional solutions utilizing redundant primary sensors. For example, the main/secondary sensor and signal path can increase chip area by less than 10% in embodiments while utilizing only a single primary sensor, rather than two, with the secondary sensor typically being a less expensive device in view of the reduced demands on its performance. In view of the less expensive secondary sensor, advantages are also achieved over conventional solutions utilizing two primary sensors on a single chip.
Various embodiments of systems, devices and methods have been described herein. These embodiments are given only by way of example and are not intended to limit the scope of the invention. It should be appreciated, moreover, that the various features of the embodiments that have been described may be combined in various ways to produce numerous additional embodiments. Moreover, while various materials, dimensions, shapes, implantation locations, etc. have been described for use with disclosed embodiments, others besides those disclosed may be utilized without exceeding the scope of the invention.
Persons of ordinary skill in the relevant arts will recognize that the invention may comprise fewer features than illustrated in any individual embodiment described above. The embodiments described herein are not meant to be an exhaustive presentation of the ways in which the various features of the invention may be combined. Accordingly, the embodiments are not mutually exclusive combinations of features; rather, the invention may comprise a combination of different individual features selected from different individual embodiments, as understood by persons of ordinary skill in the art.
Any incorporation by reference of documents above is limited such that no subject matter is incorporated that is contrary to the explicit disclosure herein. Any incorporation by reference of documents above is further limited such that no claims included in the documents are incorporated by reference herein. Any incorporation by reference of documents above is yet further limited such that any definitions provided in the documents are not incorporated by reference herein unless expressly included herein.
For purposes of interpreting the claims for the present invention, it is expressly intended that the provisions of Section 112, sixth paragraph of 35 U.S.C. are not to be invoked unless the specific terms “means for” or “step for” are recited in a claim.
This application is a continuation-in-part (CIP) of U.S. application Ser. No. 12/889,749 filed Sep. 24, 2010, which is incorporated herein by reference in its entirety.
Number | Name | Date | Kind |
---|---|---|---|
4451927 | Hershberger | May 1984 | A |
4692299 | Crew et al. | Sep 1987 | A |
4804515 | Crew et al. | Feb 1989 | A |
5343404 | Girgis | Aug 1994 | A |
5495427 | Puma et al. | Feb 1996 | A |
5589766 | Frank | Dec 1996 | A |
5965819 | Piety et al. | Oct 1999 | A |
6167547 | Senechal et al. | Dec 2000 | A |
6225802 | Ramalho et al. | May 2001 | B1 |
6340884 | Wolf et al. | Jan 2002 | B1 |
6449567 | Desai et al. | Sep 2002 | B1 |
6472897 | Shyr | Oct 2002 | B1 |
6564637 | Schalk et al. | May 2003 | B1 |
6788088 | Throngnumchai | Sep 2004 | B2 |
6891389 | Walker | May 2005 | B1 |
7046180 | Jongsma | May 2006 | B2 |
7086270 | Weinberg et al. | Aug 2006 | B2 |
7127932 | Morell et al. | Oct 2006 | B2 |
7355429 | Jenkins | Apr 2008 | B2 |
7372248 | Barthel et al. | May 2008 | B2 |
7565602 | Ausserlechner | Jul 2009 | B2 |
20020050933 | Donat et al. | May 2002 | A1 |
20020067255 | Tanizawa | Jun 2002 | A1 |
20040095218 | Wan et al. | May 2004 | A1 |
20040254711 | Zumberge et al. | Dec 2004 | A1 |
20050053005 | Cain | Mar 2005 | A1 |
20050094763 | Sherman | May 2005 | A1 |
20050124136 | Piguet et al. | Jun 2005 | A1 |
20050216134 | Katrak et al. | Sep 2005 | A1 |
20060049823 | Suzuki | Mar 2006 | A1 |
20060232284 | Condon | Oct 2006 | A1 |
20060267756 | Kates | Nov 2006 | A1 |
20070010967 | Scherr | Jan 2007 | A1 |
20070200564 | Motz et al. | Aug 2007 | A1 |
20070247141 | Pastre | Oct 2007 | A1 |
20070260383 | Sundaram et al. | Nov 2007 | A1 |
20070279044 | Rossmann et al. | Dec 2007 | A1 |
20070282459 | Schafer et al. | Dec 2007 | A1 |
20070285950 | Nakamura | Dec 2007 | A1 |
20080012557 | Hammerschmidt | Jan 2008 | A1 |
20080173518 | Klusemann | Jul 2008 | A1 |
20080245145 | Mayer et al. | Oct 2008 | A1 |
20080272797 | Pelgrom | Nov 2008 | A1 |
20090112418 | Buur et al. | Apr 2009 | A1 |
20090128160 | Chiaburu | May 2009 | A1 |
20090278711 | Lohberg et al. | Nov 2009 | A1 |
20100097088 | Uemura | Apr 2010 | A1 |
20100147124 | Seidel et al. | Jun 2010 | A1 |
20120016623 | Hayner | Jan 2012 | A1 |
20120249170 | Baumann | Oct 2012 | A1 |
20120262196 | Yokou | Oct 2012 | A1 |
20130049780 | Collins | Feb 2013 | A1 |
20130076383 | Poinstingl | Mar 2013 | A1 |
20130200909 | Rasbornig et al. | Aug 2013 | A1 |
20130314075 | Ausserlechner et al. | Nov 2013 | A1 |
Number | Date | Country |
---|---|---|
101073231 | Nov 2007 | CN |
101713673 | May 2010 | CN |
102402465 | Apr 2012 | CN |
102419403 | Apr 2012 | CN |
102695943 | Sep 2012 | CN |
2008-116339 | May 2008 | JP |
2012-68248 | Apr 2012 | JP |
WO-2005083449 | Sep 2005 | WO |
WO-2005085892 | Sep 2005 | WO |
WO-2009047812 | Apr 2009 | WO |
Entry |
---|
Office Action dated Jan. 20, 2016 for German Patent Application No. 102011083111.8. |
Office Action dated Dec. 8, 2015 for Chinese Patent Application No. 201410097855.0. |
Ramirez, Edgar, C., “Diverse Redundacy Used in SIS Technology to Achieve Higher Safety Integrity”, May 8, 2008. |
Diger, et al., “On a Redundant Diversified Steering Angel Sensor”, 2003, Proceedings of the 9th IEEE International On-Line Testing Symposium. |
Torres-Echeverria, et al., “Design Optimization of a Safety-Intrumented System Based on RAMS+C Addressing of IEC 61508 Requirements and Diverse Redundancy”, 2009, Reliability Engineering & System Safety, 94, 162-179. |
Suyama, Koichi, “Functional Safety Analysis of Reliable Control Systems Using Decision by Majority”, Jun. 1999, Proceedings of the American Control Converence, 618-21. |
Application and File History for U.S. Appl. No. 13/833,852, filed Mar. 15, 2013, inventors Rasbornig, et al. |
Endress & Hauser, FAQs About Functional Safety, © 2013, http://www.endress.com/eh/home.nsf/#products/˜product-instrument-sil-functional-safety-faq-questions, 9 pages. |
International Electrotechnical Commission, http://www.iec.ch/functionalsafety/faq-ed2, 9 pages. |
Wikipedia, ISO26262, available at http://en.wikipedia.org/wiki/ISO_26262, on Mar. 3, 2014, 6 pages. |
Infineon, “Innovative Semiconductor Solutions for Safety Applications”, © 1999-2014, 4 pages. |
National Instruments, “What is the ISO 26262 Functional Safety Standard?”, Published Feb. 23, 2012, as available at www.nni.com, 4 pages. |
Paste, et al., “A Hall Sensor Analog Front End for Current Measurement With Continuous Gain Calibration”, IEEE Sensors Journal, vol. 7, No. 5, May 2007, pp. 860-867. |
Office Action dated Mar. 5, 2018 for Japanese Patent Application No. 2017-081918 (with English translation). |
Number | Date | Country | |
---|---|---|---|
20160231371 A1 | Aug 2016 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 12889749 | Sep 2010 | US |
Child | 15132783 | US |