Journal Article
A High Functional Safety Performance Level Machine Controller for a Medium Size Agricultural Tractor
2014-09-30
2014-01-2421
Functional safety requirements and solutions are more expensive when it comes to lower cost machines with less power but same functionalities with respect to big machines. The paper will show a real Electronic Control Unit (ECU) design of a machine controller, controlling both engine working point, transmission, and other utilities like PTO, 4WD, brakes and Differential Lock; the ECU was designed in accordance to ISO 25119 regulation, to meet AgPL = C or even D for some functionalities. The unit is a fully redundant electronic control unit with two CAN networks and some special safe state oriented mechanism, that allow the Performance Level C with less software analysis requirements compared with traditional solutions. All safety critical sensors are redounded and singularly diagnosable, all command effects are directly observable and most of commands are directly diagnosable.