1. System Introduction

1.1. Conditions that lead to a transition to ERROR state

Logging after 20th event for errors connected related to the contactor feedback. This value is chosen to be so large because of the time delay between the request for a state and the actual physical response. It is caused by the SPI transaction to the SPS module, the rise time of the control signal and the actual opening/closing of the contactor. Only then can the feedback be read correctly, which also takes some additional time depending on the selected feedback source.

For each diagnosis entry listed below, the severity, sensitivity, and delay can be configured individually.

The severity defines the criticality level of the entry (Fatal Error, Warning, or Info). The sensitivity defines the number of fault events that must occur before the diagnosis entry is confirmed and logged. The delay configures the time before the transition to the ERROR state occurs after a fault has been confirmed. The delay is not relevant if the severity is set to Fatal Error.

Table 1.7 Diagnosis entries

Diagnosis Entry

Description

DIAG_ID_SYSTEM_MONITORING

The system monitoring module has detected a deviation from task timing limits

DIAG_ID_AFE_SPI

Low-level communication error in the AFE driver

DIAG_ID_AFE_COMMUNICATION_INTEGRITY

Communication integrity error in the AFE, e.g., PEC error for AFE

DIAG_ID_AFE_MUX

The multiplexer connected to the AFE does not react in an expected way

DIAG_ID_AFE_CONFIG

The AFE driver has recognized a configuration error

DIAG_ID_CAN_TIMING

The BMS does not receive CAN messages (a) at all or (b) not within the expected time frame

DIAG_ID_CAN_RX_QUEUE_FULL

The reception queue of the CAN driver is full, no new messages can be received

DIAG_ID_CAN_TX_QUEUE_FULL

The transmission queue of the CAN driver is full, all new messages will be lost

DIAG_ID_CURRENT_SENSOR_CC_RESPONDING

The current counter measurements are missing or not inside expected timing constraints

DIAG_ID_CURRENT_SENSOR_EC_RESPONDING

The energy counter measurements are missing or not inside expected timing constraints

DIAG_ID_CURRENT_SENSOR_RESPONDING

The current sensor measurements are missing or not inside expected timing constraints

DIAG_ID_REDUNDANCY_CELL_VOLTAGE

Redundant measurement of the cell voltages has returned implausible values

DIAG_ID_AFE_CELL_VOLTAGE_MEAS_ERROR

The AFE driver has determined a cell voltage measurement to be implausible

DIAG_ID_AFE_CELL_TEMPERATURE_MEAS_ERROR

The AFE driver has determined a cell temperature measurement to be implausible

DIAG_ID_REDUNDANCY_CELL_TEMPERATURE

Redundant measurement of the cell temperatures has returned implausible values

DIAG_ID_BMS_VALUES_CELL_VOLTAGE_SPREAD

The spread (difference between min and max values) of the cell voltages is implausibly high

DIAG_ID_BMS_VALUES_CELL_TEMPERATURE_SPREAD

The spread (difference between min and max values) of the cell temperatures is implausibly high

DIAG_ID_CELL_VOLTAGE_OVERVOLTAGE_MSL

Cell voltage limits are violated with respect to the maximum safe limit (MSL)

DIAG_ID_CELL_VOLTAGE_OVERVOLTAGE_RSL

Cell voltage limits are violated with respect to the recommended safe limit (RSL)

DIAG_ID_CELL_VOLTAGE_OVERVOLTAGE_MOL

Cell voltage limits are violated with respect to the maximum operating limit (MOL)

DIAG_ID_CELL_VOLTAGE_UNDERVOLTAGE_MSL

Cell voltage limits are violated with respect to the maximum safe limit (MSL)

DIAG_ID_CELL_VOLTAGE_UNDERVOLTAGE_RSL

Cell voltage limits are violated with respect to the recommended safe limit (RSL)

DIAG_ID_CELL_VOLTAGE_UNDERVOLTAGE_MOL

Cell voltage limits are violated with respect to the maximum operating limit (MOL)

DIAG_ID_TEMP_OVERTEMPERATURE_CHARGE_MSL

Temperature limits are violated with respect to the maximum safe limit (MSL)

DIAG_ID_TEMP_OVERTEMPERATURE_CHARGE_RSL

Temperature limits are violated with respect to the recommended safe limit (RSL)

DIAG_ID_TEMP_OVERTEMPERATURE_CHARGE_MOL

Temperature limits are violated with respect to the maximum operating limit (MOL)

DIAG_ID_TEMP_OVERTEMPERATURE_DISCHARGE_MSL

Temperature limits are violated with respect to the maximum safe limit (MSL)

DIAG_ID_TEMP_OVERTEMPERATURE_DISCHARGE_RSL

Temperature limits are violated with respect to the recommended safe limit (RSL)

DIAG_ID_TEMP_OVERTEMPERATURE_DISCHARGE_MOL

Temperature limits are violated with respect to the maximum operating limit (MOL)

DIAG_ID_TEMP_UNDERTEMPERATURE_CHARGE_MSL

Temperature limits are violated with respect to the maximum safe limit (MSL)

DIAG_ID_TEMP_UNDERTEMPERATURE_CHARGE_RSL

Temperature limits are violated with respect to the recommended safe limit (RSL)

DIAG_ID_TEMP_UNDERTEMPERATURE_CHARGE_MOL

Temperature limits are violated with respect to the maximum operating limit (MOL)

DIAG_ID_TEMP_UNDERTEMPERATURE_DISCHARGE_MSL

Temperature limits are violated with respect to the maximum safe limit (MSL)

DIAG_ID_TEMP_UNDERTEMPERATURE_DISCHARGE_RSL

Temperature limits are violated with respect to the recommended safe limit (RSL)

DIAG_ID_TEMP_UNDERTEMPERATURE_DISCHARGE_MOL

Temperature limits are violated with respect to the maximum operating limit (MOL)

DIAG_ID_OVERCURRENT_CHARGE_CELL_MSL

Overcurrent on cell-level with respect to the maximum safe limit (MSL)

DIAG_ID_OVERCURRENT_CHARGE_CELL_RSL

Overcurrent on cell-level with respect to the recommended safe limit (RSL)

DIAG_ID_OVERCURRENT_CHARGE_CELL_MOL

Overcurrent on cell-level with respect to the maximum operating limit (MOL)

DIAG_ID_OVERCURRENT_DISCHARGE_CELL_MSL

Overcurrent on cell-level with respect to the maximum safe limit (MSL)

DIAG_ID_OVERCURRENT_DISCHARGE_CELL_RSL

Overcurrent on cell-level with respect to the recommended safe limit (RSL)

DIAG_ID_OVERCURRENT_DISCHARGE_CELL_MOL

Overcurrent on cell-level with respect to the maximum operating limit (MOL)

DIAG_ID_STRING_OVERCURRENT_CHARGE_MSL

Overcurrent on string-level with respect to the maximum safe limit (MSL)

DIAG_ID_STRING_OVERCURRENT_CHARGE_RSL

Overcurrent on string-level with respect to the recommended safe limit (RSL)

DIAG_ID_STRING_OVERCURRENT_CHARGE_MOL

Overcurrent on string-level with respect to the maximum operating limit (MOL)

DIAG_ID_STRING_OVERCURRENT_DISCHARGE_MSL

Overcurrent on string-level with respect to the maximum safe limit (MSL)

DIAG_ID_STRING_OVERCURRENT_DISCHARGE_RSL

Overcurrent on string-level with respect to the recommended safe limit (RSL)

DIAG_ID_STRING_OVERCURRENT_DISCHARGE_MOL

Overcurrent on string-level with respect to the maximum operating limit (MOL)

DIAG_ID_PACK_OVERCURRENT_CHARGE_MSL

Overcurrent on pack-level with respect to the maximum safe limit (MSL)

DIAG_ID_PACK_OVERCURRENT_DISCHARGE_MSL

Overcurrent on pack-level with respect to the maximum safe limit (MSL)

DIAG_ID_CURRENT_ON_OPEN_STRING

Current flowing despite the string is open

DIAG_ID_DEEP_DISCHARGE_DETECTED

The deep discharge flag has been set in persistent memory

DIAG_ID_AFE_OPEN_WIRE

An open (broken) sense wire has been detected on the battery cell measurement

DIAG_ID_BMS_VALUES_PACK_VOLTAGE

The plausibility module has decided that the pack voltage is implausible

DIAG_ID_INTERLOCK_FEEDBACK

The interlock feedback indicates it to be open (but it is expected to be closed)

DIAG_ID_STRING_MINUS_CONTACTOR_FEEDBACK

The feedback on a string minus contactor does not match the expected value

DIAG_ID_STRING_PLUS_CONTACTOR_FEEDBACK

The feedback on a string plus contactor does not match the expected value

DIAG_ID_PRECHARGE_CONTACTOR_FEEDBACK

The feedback on a precharge contactor does not match the expected value

DIAG_ID_SBC_FIN_ERROR

The state of the FIN signal in the SBC is not ok

DIAG_ID_SBC_RSTB_ERROR

An activation of the RSTB pin of the SBC has been detected

DIAG_ID_BASE_CELL_VOLTAGE_MEASUREMENT_TIMEOUT

The redundancy module has detected that the base cell voltage measurements are missing

DIAG_ID_REDUNDANCY0_CELL_VOLTAGE_MEASUREMENT_TIMEOUT

The redundancy module has detected that the redundancy0 cell voltage measurements are missing

DIAG_ID_BASE_CELL_TEMPERATURE_MEASUREMENT_TIMEOUT

The redundancy module has detected that the base cell temperature measurements are missing

DIAG_ID_REDUNDANCY0_CELL_TEMPERATURE_MEASUREMENT_TIMEOUT

The redundancy module has detected that the redundancy0 temperature measurements are missing

DIAG_ID_PRECHARGE_ABORT_REASON_VOLTAGE

Precharging aborted due to a too high voltage difference

DIAG_ID_PRECHARGE_ABORT_REASON_CURRENT

Precharging aborted because measured current was too high

DIAG_ID_CURRENT_MEASUREMENT_TIMEOUT

The redundancy module has detected that the current measurement on a string is not updated

DIAG_ID_CURRENT_MEASUREMENT_ERROR

The redundancy module has detected a current measurement to be invalid

DIAG_ID_CURRENT_SENSOR_V1_MEASUREMENT_TIMEOUT

The redundancy module has detected that the voltage 1 measurement of a current sensor is not updated

DIAG_ID_CURRENT_SENSOR_V2_MEASUREMENT_TIMEOUT

The redundancy module has detected that the voltage 2 measurement of a current sensor is not updated

DIAG_ID_CURRENT_SENSOR_V3_MEASUREMENT_TIMEOUT

The redundancy module has detected that the voltage 3 measurement of a current sensor is not updated

DIAG_ID_CURRENT_SENSOR_POWER_MEASUREMENT_TIMEOUT

The redundancy module has detected that the power measurement of a current sensor is not updated

DIAG_ID_POWER_MEASUREMENT_ERROR

The redundancy module has detected a power measurement to be invalid

DIAG_ID_INSULATION_MEASUREMENT_VALID

The insulation measurement is valid or invalid

DIAG_ID_LOW_INSULATION_RESISTANCE_ERROR

A critical low insulation resistance has been measured

DIAG_ID_LOW_INSULATION_RESISTANCE_WARNING

A warnable low insulation resistance has been measured

DIAG_ID_INSULATION_GROUND_ERROR

Insulation monitoring has detected a ground error

DIAG_ID_I2C_PEX_ERROR

General error with the port expanders

DIAG_ID_I2C_RTC_ERROR

I2C communication error with the RTC

DIAG_ID_RTC_CLOCK_INTEGRITY_ERROR

Clock integrity not guaranteed error in RTC IC

DIAG_ID_RTC_BATTERY_LOW_ERROR

RTC IC battery low flag set

DIAG_ID_FRAM_READ_CRC_ERROR

CRC does not match when reading from the FRAM

DIAG_ID_ALERT_MODE

Critical error while opening the contactors. Fuse has not triggered

DIAG_ID_AEROSOL_ALERT

High aerosol concentration detected

DIAG_ID_SUPPLY_VOLTAGE_CLAMP_30C_LOST

Supply voltage of clamp 30C lost

DIAG_ID_AFE_ALARM

Alarm line showed an error occurred