Safety-critical functions must be highly available during automated driving. Therefore, a stable power supply is needed, even in the case of a fault within the supply system. To design such a fail-operational system, the effects of all possible fault scenarios must be investigated during the development process. For this, simulations can be beneficial. Critical scenarios must be identified, and the system needs to be optimized to be able to handle the fault scenarios.
An exemplary critical fault scenario is depicted in Figure 1; here, a short circuit occurs at an electronic component. The responsible fuse inside one of the power distribution units (PDUs) disconnects the faulty supply system branch. However, the switching process itself creates transient disturbances that can lead to subsequent faults, e.g., an overvoltage at another component. Such critical interactions need to be prevented.
Although such faults can be simulated with existing component models, a model-based design of a highly reliable system is not trivial. Reliability has to be ensured for all possible fault scenarios in all possible system states. The system state, i.e., its operating point, depends heavily on the driving situation, specific equipment of the vehicle and other boundary conditions like battery state of charge (SoC) or ambient temperature. Therefore, the number of necessary, time-consuming simulations becomes very large and stability analysis and optimization becomes impractical.
As a solution, Figure 2 proposes a holistic design workflow that is based on an efficient stability analysis. With frequency-domain system simulation methods, individual scenarios can be more efficiently evaluated compared to time-domain simulations. Based on calculated sensitivities, the most critical operating points of the whole state space may then be identified iteratively and subsequently optimized. In the presentation, the analysis methods and the proposed design workflow are described in detail.