On Communication Requirements for Control-by-Wire Applications

Roger Johansson, Per Johannessen, Kristina Forsberg, Håkan Sivencrona · Chalmers Research (Chalmers University of Technology) · 2003

Many control-by-wire applications are inherently safety critical. For distributed control systems, the communication subsystem as the backbone is a critical component. Thus it is vital that dependability requirements gathered from the application are well considered in the design of the communication component. However, dependability is costly and thus, it is important to carefully assess these requirements. With essential requirements from distributed control-by-wire applications in mind, we discuss the central role of the communication subsystem for system safety with focus on dependability and economy issues. Applications of particular interest today are fly-, steer-, and brake-by-wire. From these applications we identify differences and similarities in e.g. fault-tolerance, intrinsic redundancy and production volume. Requirements on fault-tolerance states how faults should be tolerated before system failure. We acknowledge case specific redundancy, and exploit how it can be utilized to accomplish sufficiently high level of system safety. Production volume influence distribution between development and recurrent costs. A common set of requirements for the communication sub-system have been established. We identify a set of features and properties that are the core requirements. This can serve as a foundation for any fault tolerant control-by-wire protocol definition. Finally, we compare this hypothetical protocol with four existing protocols intended for control-by-wire applications; FlexRay, SAFEbus, TTCAN, and TTP/C. Introduction Embedded systems are extensively used in closed-loop control systems. In particular we refer to drive-bywire control systems as an automotive class of applications where there are no physical connections (mechanical, pneumatic or hydraulic) between the steering wheel, the pedals, and the wheels. Similarly, a fly-by-wire aircraft has no physical connections between the pilot stick and the aircraft’s control surfaces. In this paper, we will refer to all such applications as control-by-wire. A drive-by-wire application may be structured according to different levels of control [Ref1], see Figure 1. The navigation function selects the paths to be used to reach the target by using knowledge about present position (localization) and information about available routes. The output of the navigation function and environment information (weather, traffic conditions etc) constitutes the input to the guidance function which will for example pilot a vehicle with instructions in angle speed in yaw and acceleration in longitude direction. Many functions are handled with different degrees of autonomy from manual, to automatic localization, route path finding, navigation and guidance. There will be a variety of options due to the set of equipment hosted by the individual vehicles and to specific traffic conditions. Either the driver manually gives the order of angle speed and acceleration via the steering wheel or pedals, or the orders are given automatically by navigation and guidance equipment. The vehicle is expected to adaptively behave the same for a given set of commands despite disturbances from road and wind, different speed, and errors in the car equipment, etc. For vehicle behavior due to maneuvering commands, we use the term vehicle dynamics and the function that executes the maneuvering commands is called vehicle dynamics control (VDC) function. PROCEEDINGS of the 21st INTERNATIONAL SYSTEM SAFETY CONFERENCE 2003

Read the paper · More papers on PaperTik