Ethenet-baed and -independent vehicle contol-platfom motivation, idea and technical concept fulfilling quantitative afety-equiement fom ISO26262 Andea Zikle, Michael Ambute, Ludge Fiege, Gunte Feitag, Thoma Schmid, Genot Spiegelbeg, Siemen AG Copoate Technology
Requiement fo the vehicle ICT eulting fom megatend Climate change Spend le enegy in total fo mobility Utilize utainable powe ouce fo mobility Ubanization Manage high taffic denity (commecial v. pivate tanpotation) Demogaphic change Inceae taffic afety Safely extend mobility of eldely people Deceae taffic denity Enable inte-modal taffic management Zeo Emiion by EV Intelligent mobility though, telematic and Smat Gid integation Zeo Accident by tability contol and pedictive ADAS ytem Will lead to new kind of mobility concept : Electo-vehicle educing emiion, inceaing mobility and taffic afety In-Ca Development domain Highly integated actuato Seite 1 May 2012 Infomation and communication technology A. Zikle, Siemen CT Vehicle contol and infotainment ality pojekt-ace.de
Idea: Logically centalized platfom Dive Aitance Dive Inteface Dive tain Infatuctue Paenge Management Logical data-inteface to vehicle ality Smat Seno Hadwae, Safety, Secuity Abtaction Smat Actuato New vehicle ICT: Scalable cental poceing unit Intelligent eno and actuato Middlewae decouple ality fom afety, ecuity and phyical laye Suppot of mixed-citicality application one netwok fo eveything Plug & play fo, eno and actuato Suppot fo incemental cetifiability Logically centalized platfom ealize vehicle contol- up to ASIL-D Seite 2 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Requiement fo the centalized platfom Requiement Any dive aitance (e.g. auto-pilot) X-By-Wie (without mechanical backup) ooc Hazad & Rik Scenaio Hazad..: uncontolled / miing command output ASIL.. : D Safe State....: none Fault-toleance time.: 50 m (exemplay) Random HW failue ate..: < 10-8 h -1 Smat Seno Dive Aitance Dive Inteface Dive tain Infatuctue Logical data-inteface to vehicle ality Hadwae, Safety, Secuity Abtaction Paenge Management Smat Actuato Platfom mut povide ASIL-D with failopeational behavio Fault-toleant Achitectue with aligned Communication Netwok Seite 3 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Realization of the Platfom: N-Duplex N-Duplex Platfom: Duplex Contol Compute (DCC): enue data integity Duo-Duplex ealize fail-opeational behavio N-Duplex ealize calability (e.g. availability, pefomance) moni Sende DCC 1 moni Receive DCC 2 lane b Mode of opeation: DCC ealize uniquene of contol command Aggegate (eno and actuato) need no infomation about edundancy level o within the coe platfom. Seite 4 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Platfom conitency: unique Function- and M/S- Vehicle contol-compute Platfom conitency Mate Function A Mate Slave Function BA Mate Function B DCC 1 DCC 2 DCC 3 DCC n conitent data bae DCC(1) conitent data bae DCC(2) conitent data bae DCC(3) conitent data bae DCC(n) Data exchange Seite 5 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Platfom conitency: unique Function- and M/S- Vehicle contol-compute Platfom conitency DCC 1 DCC 2 DCC 3 DCC n conitent conitent conitent conitent data bae data bae data bae data bae DCC(1) DCC(2) DCC(3) DCC(n) Safety equiement (etimated budget): P{lo of platfom conitency} < 1E-10 Data exchange Deign equiement: - Multi-path data exchange to enue availability - X-lane data exchange (fom to of one DCC) to enue integity (failue detection) Seite 6 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Reulting Requiement fo the Communication Netwok Logical view on communication elation: DCC 1 DCC 2 DCC 3 _a _b _a _b _a _b Snaphot! moni moni coding a / b conitency path a / b availability Reulting Requiement fo the Communication Netwok: No ingle failue mut lead to a lo of data conitency and thu platfom conitency, a ASIL-D with fail opeational behavio hall be implemented Multipath data exchange between DCC i equied! (To Aggegate, a ingle path i ufficient, if a edundant aggegate uing a dijoint path i available. Seite 7 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Realization of the Multipath Netwok Paallel edundant bu: Shaed medium on each bu Two phyically independent bue - High cabling effot - Slightly of pecification failue poible ed Ethenet altenative 1: edundant ta achitectue (AFDX) - High cabling effot + Phyically independent dijoint path ed Ethenet altenative 2: ing topology (induty automation) + Dijoint path + Low cabling effot - Phyical independence of path i lot additional effot Seite 8 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Conitent Communication in the Platfom DCC 1 DCC 2 DCC 3 lane b lane b Snaphot! monitoing monitoing Ethenet Ethenet Ethenet coding a / coding b cwd/acwd diection Seite 9 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Diadvantage: No phyical independence DCC 1 DCC 2 DCC 3 lane b lane b Snaphot! monitoing monitoing Ethenet Ethenet Ethenet coding a / coding b cwd/acwd diection Seite 10 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Solution: Netwok Fue DCC 1 DCC 2 DCC 3 lane b lane b Snaphot! monitoing monitoing Ethenet Ethenet Ethenet fue fue fue fue fue fue coding a / coding b cwd/acwd diection Seite 11 May 2012 A. Zikle, Siemen CT pojekt-ace.de
SbW BbW Scalability fo numbe of node and level of integity BbW blue SbW ed BbW ed optional Simplex 1 Simplex 2 DCC 1 DCC 2 Simplex 4 BbW blue SbW blue optional BbW ed Inne Ring with 2 to N DCC Banche and/o oute ing fo integation of aggegate Highe availability with low additional cabling effot Seite 12 May 2012 A. Zikle, Siemen CT pojekt-ace.de
Thank you. Andea Zikle, Michael Ambute, Ludge Fiege, Gunte Feitag, Thoma Schmid, Genot Spiegelbeg Siemen AG Copoate Technology