Safety Layer Vehicle Control Unit

Industry solutions

Safety Layer Vehicle Control Unit

The Safety Layer Control Unit makes everyday development work easier in terms of the functional safety of electric vehicles

The Vehicle Control Unit (VCU) including Safety Layer simplifies your everyday development work. Thanks to an integrated safety level, you focus on the control of components and special applications. The necessary foundation is provided by the Safety application from Durot Electric.

Frequently asked questions

Primary functions of a VCU

  • Drive control
  • Thermal control
  • Energetic control
  • Auxiliary and secondary operations (periphery)

Secondary functions of a VCU

  • Functional safety
  • Diagnosis
The requirements for the safety of electric vehicles are increasing. For state-of-the-art developments, the coverage of security standards and mechanisms is indispensable. In this context, it is important to verify and validate systems. HIL tests, for example, serve this purpose. Vehicle distributors are liable for defects. Depending on the country and the law, this applies from senior management, to members of the development team.

The range of applications for the VCU is broad and includes, for example:

Transporter On-Highway
Safe torque path
Safe prevention of unintended acceleration

Construction machinery/excavators
Safe prevention of unintended acceleration
Safe compliance with restricted areas for personal protection

Autonomous sweepers
Secure sensor fusion
Safe detection of objects

The VCU is the brain and thus the core of every vehicle. Based on the safety concept, the safety functions are implemented and validated in the safety application. Durot Electric assumes responsibility for the correct implementation of the safety functions. In turn, your QM application contains all non-safety relevant code components.

The safety application and the QM application can be developed, compiled and flashed to the ECU completely independently. Certification according to common safety standards only takes place at the safety application level. The QM application can be further developed independently after certification of the safety application. This does not require re-certification of the safety level. This saves several man-months per iteration.

  • Initiation of the project and the Statement of Work (Item Definition).
  • Functional safety management
  • Derivation as well as elaboration of the hazard and risk analysis
  • System development and system integration
  • Technical security concepts (hardware & software)
  • Supporting processes

For the safe
Development of electric vehicles

Vehicle control with safety level

The Safety Layer Vehicle Control Unit comprises the complete hardware and software for vehicle control. The complete package offers numerous advantages.

01.

Integrated safety level

Thanks to the special architecture, the application and security levels are separated. You take care of vehicle control, we take care of safety functions.

02.

Shorter time-to-market

While your competitors are working on standards and expanding QM, you are developing functions that are crucial for the vehicle and its market success.

03.

Individual development

When developing vehicle variants or customization, no revalidation of the safety layer is necessary. You develop according to QM instead of ISO26262.

Advantages for your development department

Software architecture and specifications

  • Model-Based Embedded Software
  • Groundbreaking architecture
  • Suitability from small to large OEM
  • Developed based on the V-model
  • Based on state-of-the-art tool chain
  • Allows for further development using agile practices
  • Basis for series development up to release (release stage 4)
  • Develop up to 6x more efficiently using design flow automation
  • Automatic code generation
  • Most modern hardware available from TTControl (TTC2390)
  • For off-highway and automotive safety applications
  • Compact and robust housing for harsh environments
  • ISO 26262 ASIL C Automotive Safety Certification
  • Different variants of the TTC2300 family with different IO configurations
The QM application contains all non-safety related code components. Almost any number of tasks are executed here. Examples include HMI management, torque management, thermal management and diagnostics. Programming is done in C or in Simulink. All IO’s not used in the safety application are freely configured, read and written here. LIN, CAN and Ethernet communication is expandable and customizable.
The Safety application contains the safety functions. Scope is usually the reading and plausibility check of the relevant signals, calculation of the safety function and initiation of the safe state in case of violation of the safety function.

All data from the safety level is accessible in the QM application for diagnostic purposes or for function implementation. All IOs and memory locations and communication channels used by the safety level cannot be changed or overwritten by the QM application. This is ensured by a so-called hardware memory protection unit.

Architecture of the Safety Layer Vehicle Control Unit

Special feature of the VCU architecture

The QM application and Safety application are separated into two levels. The OEM focuses on the application level and its value creation Design and coding of the QM application is done entirely by the OEM Durot Electric provides the foundation with the safety application. The VCU basic software includes the operating system as well as the services for the application. Allows developer support and joint developments.

Would you like to find out more? Download the factsheet.

Are you planning to use our VCU including safety layer?

Count on our support. Using optional hardware-in-the-loop testing (HIL), we find errors before they become significant. Thanks to prior simulations, we thus ensure a minimum time-to-market, optimal software quality and mill-free commissioning.