节点文献
符合ISO 26262功能安全标准的燃料电池ECU开发
A Fuel Cell ECU Development in Accordance with ISO 26262 Functional Safety Standard
【作者】 吴松;
【作者基本信息】 上海交通大学 , 集成电路工程(专业学位), 2019, 硕士
【摘要】 ISO 26262是从功能安全标准IEC 61508演化而来的面向汽车电子电气系统的功能安全标准。为汽车电子系统的功能安全设计提供了一套完整的指导。本研究依据ISO 26262的要求,从上而下系统性的针对燃料电池ECU(Electronic Control Unit)进行燃料电池汽车动力系统分析、安全概念分析、控制系统架构设计、硬件电路设计和测试验证工作,设计了满足ASIL(Automotive safety Integrity Level)C等级的燃料电池ECU系统和硬件,提出了功能安全的测试和验证方案。本文首先对功能安全标准ISO 26262的核心思想和关键概念进行理解和展开,并总结了各层面的工作成果。之后本文选定燃料电池发动机系统作为功能安全的研究对象,按照功能安全相关项定义的要求,设计燃料电池ECU的初步系统架构,使用HAZOP(Hazard and Operability Analysis)方法识别各功能的异常表现,进而实施危害分析和风险评估,得出燃料电池ECU的安全目标和功能安全要求。在系统开发层面,本文将功能安全要求具体展开到燃料电池ECU的功能模块,综合性的使用异常检测、故障保护和硬件冗余等手段作为安全机制,针对安全相关的功能完成详细系统架构设计。并使用FTA(Fault Tree Analysis)方法来验证燃料电池ECU的系统架构设计。在硬件开发层面,本文对硬件相关的技术安全要求进行抽出,设计了包含安全机制在内的硬件架构,包括双核锁步运行的MCU(Micro Control Unit)、带有WDT(Watchdog Timer)功能和输出监视功能的电源芯片、有输入范围检测功能的传感器接口、双重硬件冗余的喷射器输出状态监测。之后将安全机制在硬件元器件层面进行实现,完成了电气原理图及工作状态的详细设计。最终基于开发完成的燃料电池ECU,提出了对各功能模块进行功能测试方案和针对安全机制的故障注入测试方案,测试结果证明燃料电池ECU的安全机制能够有效监测各种失效模式,并迁移到安全状态。之后使用FMEDA(Failure Modes Effects and Diagnostic Analysis)方法对设计完成的燃料电池ECU电路实施安全分析,针对电阻、晶体管等硬件元器件的随机失效对安全目标的影响进行定量分析,得出燃料电池ECU的单点故障度量、潜伏故障度量和随机硬件失效违反安全目标的概率,证明燃料电池ECU的设计满足ASIL C等级。
【Abstract】 The ISO 26262 is a functional safety standard for automotive electrical and electronic systems that evolved from the functional safety standard IEC 61508.Provides a complete set of guidelines for the functional safety design of automotive electronic systems.According to the requirements of ISO 26262,this study systematically analyzes the fuel cell vehicle power system,perform safety concept analysis,control system architecture design,and hardware circuit design for the fuel cell ECU(Electronic Control Unit).A fuel cell ECU system and hardware that meets the ASIL(Automotive safety Integrity Level)C are designed,and a functional safety test and verification scheme is proposed.This paper first analyzes and extracts the main ideas and key concepts of the functional safety standard ISO 26262,and summarizes the work results at different levels.After that,this paper selected the fuel cell engine system as the research object of functional safety.According to the requirements of functional safety item definition,the preliminary system architecture of the fuel cell ECU was designed.The HAZOP(Hazard and Operability Analysis)method was used to identify the abnormal performance of each function,and then the hazard analysis and risk assessment were carried out to obtain the safety goal and functional safety requirements of the fuel cell ECU.At the system development level,this paper allocates the functional safety requirements to the functional modules of the fuel cell ECU.The comprehensive use of abnormal detection,fault protection and hardware redundancy as a safety mechanism completes the detailed system architecture design for safety-related functions.And the FTA(Fault Tree Analysis)method is used to verify the system architecture design of the fuel cell ECU.At the hardware development level,this paper extracts the hardware-related technical safety requirements,and designs the hardware architecture including the safety mechanism,such as MCU(Micro Control Unit)with lockstep dual-core operation,power supply IC with output monitoring function and WDT(Watchdog Timer),and sensor interface with input range detection,injector output control with hardware redundant and status monitoring.After that,the safety mechanism is implemented at the hardware component level,and the detailed design of the electrical schematic diagram and working state is completed.Finally,based on the developed fuel cell ECU,the function test of each functional module and the fault injection test for the safety mechanism are proposed.The test results prove that the fuel cell ECU safety mechanism can effectively monitor various failure modes and migrate to a safe state.The FMEDA(Failure Modes Effects and Diagnostic Analysis)method is used to implement the safety analysis.The bottom-up quantitative analysis of the impact for safety goal is accomplished based on the random failures of the hardware parts.The result is calculate as single point fault metrics,latent fault metrics,and probability of random hardware failure violating safety goal.Proved that the hardware design meets the requirements of the ASIL C level and clarifies the effectiveness of the safety mechanisms used.