1. System Introduction
1.1. Conditions that lead to a transition to ERROR state
Logging after 20th event for errors connected related to the contactor feedback. This value is chosen to be so large because of the time delay between the request for a state and the actual physical response. It is caused by the SPI transaction to the SPS module, the rise time of the control signal and the actual opening/closing of the contactor. Only then can the feedback be read correctly, which also takes some additional time depending on the selected feedback source.
For each diagnosis entry listed below, the severity, sensitivity, and delay can be configured individually.
The severity defines the criticality level of the entry (Fatal Error, Warning, or Info). The sensitivity defines the number of fault events that must occur before the diagnosis entry is confirmed and logged. The delay configures the time before the transition to the ERROR state occurs after a fault has been confirmed. The delay is not relevant if the severity is set to Fatal Error.
Diagnosis Entry |
Description |
|---|---|
|
The system monitoring module has detected a deviation from task timing limits |
|
Low-level communication error in the AFE driver |
|
Communication integrity error in the AFE, e.g., PEC error for AFE |
|
The multiplexer connected to the AFE does not react in an expected way |
|
The AFE driver has recognized a configuration error |
|
The BMS does not receive CAN messages (a) at all or (b) not within the expected time frame |
|
The reception queue of the CAN driver is full, no new messages can be received |
|
The transmission queue of the CAN driver is full, all new messages will be lost |
|
The current counter measurements are missing or not inside expected timing constraints |
|
The energy counter measurements are missing or not inside expected timing constraints |
|
The current sensor measurements are missing or not inside expected timing constraints |
|
Redundant measurement of the cell voltages has returned implausible values |
|
The AFE driver has determined a cell voltage measurement to be implausible |
|
The AFE driver has determined a cell temperature measurement to be implausible |
|
Redundant measurement of the cell temperatures has returned implausible values |
|
The spread (difference between min and max values) of the cell voltages is implausibly high |
|
The spread (difference between min and max values) of the cell temperatures is implausibly high |
|
Cell voltage limits are violated with respect to the maximum safe limit (MSL) |
|
Cell voltage limits are violated with respect to the recommended safe limit (RSL) |
|
Cell voltage limits are violated with respect to the maximum operating limit (MOL) |
|
Cell voltage limits are violated with respect to the maximum safe limit (MSL) |
|
Cell voltage limits are violated with respect to the recommended safe limit (RSL) |
|
Cell voltage limits are violated with respect to the maximum operating limit (MOL) |
|
Temperature limits are violated with respect to the maximum safe limit (MSL) |
|
Temperature limits are violated with respect to the recommended safe limit (RSL) |
|
Temperature limits are violated with respect to the maximum operating limit (MOL) |
|
Temperature limits are violated with respect to the maximum safe limit (MSL) |
|
Temperature limits are violated with respect to the recommended safe limit (RSL) |
|
Temperature limits are violated with respect to the maximum operating limit (MOL) |
|
Temperature limits are violated with respect to the maximum safe limit (MSL) |
|
Temperature limits are violated with respect to the recommended safe limit (RSL) |
|
Temperature limits are violated with respect to the maximum operating limit (MOL) |
|
Temperature limits are violated with respect to the maximum safe limit (MSL) |
|
Temperature limits are violated with respect to the recommended safe limit (RSL) |
|
Temperature limits are violated with respect to the maximum operating limit (MOL) |
|
Overcurrent on cell-level with respect to the maximum safe limit (MSL) |
|
Overcurrent on cell-level with respect to the recommended safe limit (RSL) |
|
Overcurrent on cell-level with respect to the maximum operating limit (MOL) |
|
Overcurrent on cell-level with respect to the maximum safe limit (MSL) |
|
Overcurrent on cell-level with respect to the recommended safe limit (RSL) |
|
Overcurrent on cell-level with respect to the maximum operating limit (MOL) |
|
Overcurrent on string-level with respect to the maximum safe limit (MSL) |
|
Overcurrent on string-level with respect to the recommended safe limit (RSL) |
|
Overcurrent on string-level with respect to the maximum operating limit (MOL) |
|
Overcurrent on string-level with respect to the maximum safe limit (MSL) |
|
Overcurrent on string-level with respect to the recommended safe limit (RSL) |
|
Overcurrent on string-level with respect to the maximum operating limit (MOL) |
|
Overcurrent on pack-level with respect to the maximum safe limit (MSL) |
|
Overcurrent on pack-level with respect to the maximum safe limit (MSL) |
|
Current flowing despite the string is open |
|
The deep discharge flag has been set in persistent memory |
|
An open (broken) sense wire has been detected on the battery cell measurement |
|
The plausibility module has decided that the pack voltage is implausible |
|
The interlock feedback indicates it to be open (but it is expected to be closed) |
|
The feedback on a string minus contactor does not match the expected value |
|
The feedback on a string plus contactor does not match the expected value |
|
The feedback on a precharge contactor does not match the expected value |
|
The state of the FIN signal in the SBC is not ok |
|
An activation of the RSTB pin of the SBC has been detected |
|
The redundancy module has detected that the base cell voltage measurements are missing |
|
The redundancy module has detected that the redundancy0 cell voltage measurements are missing |
|
The redundancy module has detected that the base cell temperature measurements are missing |
|
The redundancy module has detected that the redundancy0 temperature measurements are missing |
|
Precharging aborted due to a too high voltage difference |
|
Precharging aborted because measured current was too high |
|
The redundancy module has detected that the current measurement on a string is not updated |
|
The redundancy module has detected a current measurement to be invalid |
|
The redundancy module has detected that the voltage 1 measurement of a current sensor is not updated |
|
The redundancy module has detected that the voltage 2 measurement of a current sensor is not updated |
|
The redundancy module has detected that the voltage 3 measurement of a current sensor is not updated |
|
The redundancy module has detected that the power measurement of a current sensor is not updated |
|
The redundancy module has detected a power measurement to be invalid |
|
The insulation measurement is valid or invalid |
|
A critical low insulation resistance has been measured |
|
A warnable low insulation resistance has been measured |
|
Insulation monitoring has detected a ground error |
|
General error with the port expanders |
|
I2C communication error with the RTC |
|
Clock integrity not guaranteed error in RTC IC |
|
RTC IC battery low flag set |
|
CRC does not match when reading from the FRAM |
|
Critical error while opening the contactors. Fuse has not triggered |
|
High aerosol concentration detected |
|
Supply voltage of clamp 30C lost |
|
Alarm line showed an error occurred |