Fail-safe system for multiple control systems having at least one common sensor for monitoring common control parameter
First Claim
1. A fail-safe system for a multiple task control system for performing mutually different first and second control tasks, said multiple task control system performing said first control task on the basis of a first parameter monitored by first monitoring means and a second parameter monitored by second monitoring means and performing said second control task on the basis of said first parameter common to said first task and a third parameter monitored by third monitoring means, said fail-safe system comprising:
- first malfunction detecting means for monitoring operation of said first monitoring means to detect a faulty condition of said first monitoring means and for producing a first failure detecting signal which is indicative of failure of both of said first and second control tasks;
second malfunction detecting means for monitoring said second and third monitoring means to detect a faulty condition of one of said second and third monitoring means and for producing a second failure detecting signal which indicates failure of one of said second and third monitoring means for which said failure is detected; and
controlling means for normally performing said first and second control tasks independent of each other on the basis of said first, second and third parameters, said controlling means being responsive to said first failure detecting signal to perform a first mode fail-safe operation in both of first and second control operations and for performing said first and second tasks, and to said second failure detecting signal to perform a second mode fail-safe operation in one of said first and second control operations utilizing a faulty one of said second and third monitoring means as indicated by said second failure indicative signal.
1 Assignment
0 Petitions
Accused Products
Abstract
A fail-safe system for a multiple task control system which has a plurality of control channels for performing mutually independent and mutually distinct control functions detects failure in one of the control channels. In response, the fail-safe system discriminates between a failure which occurs at a common sensor which is commonly utilized for more than one control channels or a common control channel which are commonly used for more than one control channels, and a failure at other sensors for monitoring parameters to be used for a singular control channel or individual control channel for single control function. The fail-safe system performs mutually distinct modes of fail-safe operation depending upon the result of the discrimination.
-
Citations
27 Claims
-
1. A fail-safe system for a multiple task control system for performing mutually different first and second control tasks, said multiple task control system performing said first control task on the basis of a first parameter monitored by first monitoring means and a second parameter monitored by second monitoring means and performing said second control task on the basis of said first parameter common to said first task and a third parameter monitored by third monitoring means, said fail-safe system comprising:
-
first malfunction detecting means for monitoring operation of said first monitoring means to detect a faulty condition of said first monitoring means and for producing a first failure detecting signal which is indicative of failure of both of said first and second control tasks; second malfunction detecting means for monitoring said second and third monitoring means to detect a faulty condition of one of said second and third monitoring means and for producing a second failure detecting signal which indicates failure of one of said second and third monitoring means for which said failure is detected; and controlling means for normally performing said first and second control tasks independent of each other on the basis of said first, second and third parameters, said controlling means being responsive to said first failure detecting signal to perform a first mode fail-safe operation in both of first and second control operations and for performing said first and second tasks, and to said second failure detecting signal to perform a second mode fail-safe operation in one of said first and second control operations utilizing a faulty one of said second and third monitoring means as indicated by said second failure indicative signal. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A multi-task control system, comprising:
-
a first control channel for controlling operation of a first control load, said first control channel including first monitoring means for monitoring a first control parameter and for providing first parameter data and second monitoring means for monitoring a second control parameter different from said first control parameter, and for providing second parameter data, and said first control channel further including first signal processing means for processing said first and second control parameter data and for deriving a first command value indicative of an operational magnitude of said first control load; a second control channel for controlling operation of a second load, said second control channel including said first monitoring means which is common to said first control channel and third monitoring means for monitoring a third control parameter different from said first control parameter, and for providing third parameter data, and said second control channel further including second signal processing means for processing said first and third control parameter data and for deriving a second command value indicative of an operational magnitude of said second control load; first malfunction detecting means monitoring said first parameter data provided from said first monitoring means in order to detect abnormality of said first parameter data and produce a first failure detecting signal; second malfunction detecting means monitoring said second parameter data provided from said second monitoring means in order to detect abnormality of said second parameter data and produce a second failure detecting signal; third malfunction detecting means monitoring said third parameter data provided from said third monitoring means in order to detect abnormality of said third parameter data and produce a third failure detecting signal; first fail-safe means responsive to said first failure detecting signal for performing first mode fail-safe operation, in which fail-safe operation is commonly commanded for both of said first and second control channels for predetermined first mode fail-safe operations in each of said first and second control channels; and second fail-safe means responsive to one of said second and third failure detecting signals, for performing second mode fail-safe operation, in which fail-safe operation is selectively commanded to one of said first and second control channels corresponding to an input failure detecting signal for a predetermined second mode fail-safe operation therein. - View Dependent Claims (9, 10, 11, 12, 13)
-
-
14. A multi-task control system for an automotive vehicle for controlling a first vehicular component associated with vehicular driving operation for adjusting first vehicular behavior and a second vehicular component associated with vehicular driving operation for adjusting second vehicular behavior, comprising:
-
a first control channel for controlling operation of a first vehicular component, said first control channel including first monitoring means for monitoring a first control parameter and for providing first parameter data and second monitoring means for monitoring a second control parameter different from said first control parameter and for providing second parameter data, and said first control channel further including first signal processing means for processing said first and second control parameter data and for deriving a first command value indicative of an operational magnitude of said first vehicular component; a second control channel for controlling operation of a second vehicular component, said second control channel including said first monitoring means which is common to said first control channel and third monitoring means for monitoring a third control parameter different from said first control parameter and for providing third parameter data, and said second control channel further including second signal processing means for processing said first and third control parameter data and for deriving a second command value indicative of an operational magnitude of said second vehicular component; first malfunction detecting means monitoring said first parameter data provided from said first monitoring means in order to detect abnormality of said first parameter data and produce a first failure detecting signal; second malfunction detecting means monitoring said second parameter data provided from said second monitoring means in order to detect abnormality of said second parameter data and produce a second failure detecting signal; third malfunction detecting means monitoring said third parameter data provided from said third monitoring means in order to detect abnormality of said third parameter data and produce a third failure detecting signal; first fail-safe means responsive to said first failure detecting signal for performing first mode fail-safe operation, in which fail-safe operation is commonly commanded for both of said first and second control channels for predetermined first mode fail-safe operations in each of said first and second control channels; and second fail-safe means responsive to one of said second and third failure detecting signals, for performing second mode fail-safe operation, in which fail-safe operation is selectively commanded for one of said first and second control channels corresponding to an input failure detecting signal for a predetermined second mode fail-safe operation therein. - View Dependent Claims (15, 16, 17, 18)
-
-
19. A multi-task control system as set forth in clam 18, wherein said second fail-safe means is responsive to said first failure detecting signal to perform said first mode fail-safe operation for said second control channel, in which said second control command to be applied to said second actuator in said second control channel is modified periodically by a given rate toward a predetermined value for a predetermined position of said second actuator.
-
20. A multi-task control system for an automotive vehicle for performing anti-skid brake control for a vehicular brake system and power train control for adjusting distribution of driving torque generated by a prime mover to primary and subsidiary driving wheels, comprising:
-
a first control channel, associated with said vehicular brake system, for performing anti-skid brake control for optimizing vehicular braking performance, said first control channel processing preselected brake control parameters for deriving a magnitude of wheel acceleration and deceleration and wheel slippage for selecting an operational mode of said brake system for selectively increasing, decreasing and holding braking pressure in said brake system; a second control channel, associated with said power train for adjusting power distribution between a primary driving wheel which is constantly connnected to said prime mover to receive driving torque and a subsidiary driving wheel, for which a controlled distrubution rate of driving torque of said prime mover is supplied, said second control channel processing preselected driving torque distribution control parameters which include at least one common parameter to said first control channel; first malfunction detecting means mointoring said common parameter in order to detect abnormality thereof and produce a first failure detecting signal; second malfunction detecting means mointoring second parameter data in said first control channel other than said common parameter in order to detect abnormality thereof and produce a second failure detecting signal; third malfunction detecting means monitoring third parameter data in said second control channel other than said common parameter in order to detect abnormality thereof and produce a third failure detecting signal; first fail-safe means responsive to said first failure detecting signal for performing first mode fail-safe operation, in which fail-safe operation is commonly commanded for both of said first and second control channels for perdetermined first mode fail-safe operations in each of said first and second control channels; and second fail-safe means responsive to one of said second and third failure detecting signals, for performing second mode fail-safe operation, in which fail-safe operation is selectively commanded for one of said first and second control channels corresponding to an inputted failure detecting signal for a predetermined second mode fail-safe operation therein. - View Dependent Claims (21, 22, 23, 24, 25, 26, 27)
-
Specification