Method and apparatus for monitoring the operation of a computer-controlled operating element, particularly triggered safety apparatus for an automotive vehicle
First Claim
1. Method of monitoring a computer system wherein the system includesa computer apparatus unit (10) having an output terminal (16) anda controlled operating element (12) coupled to the output terminal (16) of the computer apparatus unit,said computer apparatus unit (10) providing a control signal at the output terminal (16) for propagation of the control signal to the operating element (12) and for controlling the operating element to carry out a predetermined operation, andwherein, additionally, the output terminal (16) of the computer apparatus unit is subject to disturbance signals which, if propagated to the operating element (12) cause undesired operation of the operating element,comprising, in accordance with the invention, the steps ofdelaying propagation of the control signal from the computer apparatus unit (10) to the operating element (12) for a predetermined time interval;
- deriving signal samples from the output terminal (16) of the computer apparatus unit (10);
evaluating said signal samples;
comparing said signal samples continuously within said predetermined time interval with check of test values and, if the comparison between said check or test values and the signal samples(a) indicates coincidence, transmitting, after said time interval, said control signal to the operating element (12) to carry out the predetermined operation;
(b) indicates a deviation, preventing, before elapse of said time interval, transmission of the control signal to the operating element and controlling the computer apparatus unit to repeat its computation.
1 Assignment
0 Petitions
Accused Products
Abstract
To prevent spurious operation of a controlled operating element (12), typically a safety element which can be irreversibly triggered, such as a trigger or firing cartridge of a passenger restraint airbag, while providing for reliable operation in case of a crash of a vehicle in which the airbag is installed, a control signal is derived from a computer (10) processing input signals. The transmission of the control signals from the computer (10) to the operating element (12) is through a time delay stage (30) which has a time delay of sufficient length to permit the computer to correct, if necessary, signals from its output (16) and to carry out tests on the output signals from the computer apparatus. An evaluation circuit (18) continuously compares the output signals with check values. The check values may be derived from, for example a second computer similar to the computer, or from stored representative values. If the comparison indicates coincidence, the operating control signal from the computer is transmitted to the operating element (12). If, however, e.g. due to extraneous disturbances, a deviation between the test samples and the signals derived from the output (16) of the computer indicates a deviation, transmission of the control signals from the computer (10) to the operating element (12) is prevented, and the computer is controlled to repeat its computation, or part of a computation cycle.
23 Citations
23 Claims
-
1. Method of monitoring a computer system wherein the system includes
a computer apparatus unit (10) having an output terminal (16) and a controlled operating element (12) coupled to the output terminal (16) of the computer apparatus unit, said computer apparatus unit (10) providing a control signal at the output terminal (16) for propagation of the control signal to the operating element (12) and for controlling the operating element to carry out a predetermined operation, and wherein, additionally, the output terminal (16) of the computer apparatus unit is subject to disturbance signals which, if propagated to the operating element (12) cause undesired operation of the operating element, comprising, in accordance with the invention, the steps of delaying propagation of the control signal from the computer apparatus unit (10) to the operating element (12) for a predetermined time interval; -
deriving signal samples from the output terminal (16) of the computer apparatus unit (10); evaluating said signal samples; comparing said signal samples continuously within said predetermined time interval with check of test values and, if the comparison between said check or test values and the signal samples (a) indicates coincidence, transmitting, after said time interval, said control signal to the operating element (12) to carry out the predetermined operation; (b) indicates a deviation, preventing, before elapse of said time interval, transmission of the control signal to the operating element and controlling the computer apparatus unit to repeat its computation. - View Dependent Claims (2, 3, 4)
-
-
5. A system to monitor disturbances in a computer system and to inhibit effects of the disturbances,
said computer system having a computer apparatus unit (10) having an output terminal (16); -
a controlled operating element (12) coupled to the output terminal, said computer apparatus unit providing an operating control signal at the output terminal (16) for preparation of the operating control signal to the controlled operating element (12) for controlling the operating element to carry out a predetermined operation, and wherein, additionally, the output terminal (16) of the computer apparatus unit is subject to disturbance signals which, if propagated to the operating element, cause undesired operation of the element (12), comprising, in accordance with the invention, an evaluation stage or circuit (18) coupled to the output terminal (16) of the computer apparatus unit (10), said evaluation stage or circuit including means (20) for providing test or check signals; a comparator (22) receiving signal samples from the output terminal (16) of the computer apparatus unit and said test or check signals and effecting comparison; and a control signal source (24) coupled to receive the output from the comparator (22) and responding to the comparator output indicative of (a) coincidence of the signal samples and the test or check signals, (b) a deviation between the signal samples and the test or check signals; said control signal source providing control signals of differing characteristics in dependence on the output from the comparator (22) in accordance with the comparison therein; a time delay stage (30) coupled between the output terminal (16) of the computer apparatus unit (10) and an input terminal (28) of the operating element (12); a correction terminal (34) on the computer apparatus unit (10) and controlling the computer apparatus unit to repeat at least one of;
a computation;
a computation cycle;
a computation step;and coupling means (32) connected to receive the control signals from the control signal source and connected to the correction terminal (34) of the computer apparatus unit (10) to cause the computer apparatus unit to correct its computation if a deviation has been detected and for providing output signals inhibiting transmission of the operating control signal from the computer apparatus unit (10) through the time delay stage (30) to the operating element (12) if such a deviation has been detected by the comparator. - View Dependent Claims (6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A method of monitoring a computer system, wherein the computer system includes
a computer apparatus unit (10) having an output terminal (16) and a controlled operating element (12), which controlled operating element comprises safety apparatus in an automotive vehicle including at least one of: -
a brake antilock system; a passenger restraint system, wherein the passenger restraint system comprises at least one of; an air bag, a safety belt tightening system, a safety belt locking system, said method including the steps of providing an operating control signal at the output terminal (16) of the computer apparatus unit (10); propagating the operating control signal to the operating element (12) for controlling the operating element to carry out a predetermined operation, and wherein, additionally, the operating terminal (16) of the computer apparatus unit is subject to disturbance signals which, if propagated to the operating element, cause undesired operation of the operating element (12), comprising, in accordance with the invention, the steps of delaying propagation of the operating control signal from the computer apparatus unit (10) to the operating element (12) for a predetermined time interval; deriving signal samples from the output terminal (16) of the computer apparatus unit (10); evaluating said signal samples; comparing said signal samples continuously within said predetermined time interval with check or test values and, if the comparison between said check or test values and the signal samples (a) indicates concidence, transmitting, after said time interval, said operating control signal to the operating element (12) to carry out the predetermined operation; (b) indicates a deviation, preventing, before elapse of said time interval, transmission of the operating control signal to the operating element and controlling the computer apparatus unit to repeat its computation. - View Dependent Claims (16, 17, 18)
-
-
19. In an automotive vehicle having a safety system including an operating element (12) comprising at least one of:
-
a brake antilock system, a passenger restraint system, wherein the passenger restraint system comprises at least one of; an air bag, a safety belt tightening system, a safety belt locking system, said safety system including a computer apparatus unit (10) having an output terminal (16); the controlled operating element (12) being coupled to the output terminal (16), said computer apparatus unit providing an operating control signal at the output terminal (16) for propagation of the operating control signal to the controlled operating element (12) for controlling the operating element to carry out a predetermined operation, and wherein, additionally, the output terminal (16) of the computer apparatus unit is subject to disturbance signals which, if propagated to the operating element, cause undesired operation of the element (12), comrising, in accordance with the invention; an evaluation stage or circuit (18) coupled to the output terminal (16) of the computer apparatus unit (10), said evaluation stage or circuit including means (20) for providing test or check signals; a comparator (22) receiving signal samples from the output terminal (16) of the computer apparatus unit and said test or check signals and effecting comparison; and a control signal source (24) coupled to receive the output from the comparator (22) and responding to the comparator output indicative of (a) coincidence of the signal samples and the test or check signals, (b) a deviation between the signal samples and the test or check signals; said control signal source providing control signals of differing characteristics in dependence on the output from the comparator (22) in accordance with the comparison therein; a time delay stage (30) coupled between the output terminal (16) of the computer apparatus unit (10) and an input terminal (28) of the operating element (12); a correction terminal (34) on the computer apparatus unit (10) and controlling the computer apparatus unit to repeat at leat one of;
a computation;
a computation cycle;
a computation step;and coupling means (32) connected to receive the control signals from the control signal source and connected to the correction terminal (34) of the computer apparatus unit (10) to cause the computer apparatus unit to correct its computation if a deviation has been detected and for providing output signals inhibiting transmission of the operating control signal from the computer apparatus unit (10) through the time delay stage (30) to the operating element (12) if such a deviation has been detected by the comparator. - View Dependent Claims (20, 21, 22, 23)
-
Specification