background image

An extensive FMEA process led to the available safety architecture. Three key mechanisms are part of the
resulting safety concept: redundancy, diagnostic functions, monitoring functions.

Function safety specification

Identification of configurations

JS1-H Steer by Wire does not support different configurations. All functions are as specified and
described within this document and the data sheet. No configuration necessary.

Safety functions declaration

1. Safe Transmission of Joystick Angle Position
2. Safe Finger Function (Button Auto-Guidance)

Safety monitoring functions declaration

1. Monitoring of Force Feedback Direction
2. Monitoring of Operator Notification

Safe states

The following Safe States exist for each of the four processing units within JS1-H Steer by Wire:

1. Signal Safety Error

The joystick notifies the connected EHD controller about an internal error via CAN messages.
Affected functions may be abandoned. Unaffected functions remain operable, basic joystick
functionality (steering, button input) is still given.

2. Communication Stop

The affected processor interrupts the communication to the EHD controller. No messages are sent
to the CAN bus from the corresponding CAN Node. Due to the second CAN channel, the joystick
functionality is still given.

3. Force Feedback Safe Stop

The Force Feedback comfort function is disabled. Other functions remain operable, joystick
functionality is still given.

Upon entering one of the Safe States, JS1-H Steer by Wire can only be reset by performing a power
down/up.

Safety function response time

The safety response time is defined as the period of time between a failure is first observed by the
diagnostics and the time by which the corresponding safe state is entered.

Safety Function

Fault Reaction / Risk Mitigation Safety Response Time

1. Safe Transmission of Joystick Angle Position

1. Signal Safety Error
3. Force Feedback Safe Stop

80 ms

2. Provide a Safe Finger Function (ButtonAuto-Guidance) 1. Signal Safety Error

80 ms

Safety monitoring function response time

The monitoring function response time is defined as the period of time between a failure is first observed
by the monitoring and the time by which the corresponding safe state is entered.

User and Safety Manual

PLUS+1® JS1-H Steer by Wire

Functional Safety

 

©

 Danfoss | December 2022

AX436683569858en-000101 | 17

Summary of Contents for PLUS+1 JS1-H

Page 1: ...User and Safety Manual PLUS 1 JS1 H Steer by Wire www danfoss com...

Page 2: ...Revision history Table of revisions Date Changed Rev December 2022 First edition 0101 User and Safety Manual PLUS 1 JS1 H Steer by Wire 2 Danfoss December 2022 AX436683569858en 000101...

Page 3: ...14 Normal operation 14 Safe state 14 Power on self test POST 14 Out of range detection 14 Functional Safety Compatibility 15 External restrictions 15 Product limitations 15 Certification Z10 047358 0...

Page 4: ...Vehicle fault insertion and testing 22 Safety validation testing 22 Service part handling and repair instruction 22 Safety validation steps after replacing JS1 SBW with a service part or SW update 23...

Page 5: ...ct your nearest Danfoss representative Important user information Danfoss is neither responsible nor liable for indirect or consequential damages resulting from the use or application of this equipmen...

Page 6: ...19 2018 2019 Cat 2 for Monitoring Force Feedback This document covers safety functions requirements safety related parameters and application verification Additionally it provides information on insta...

Page 7: ...the opposite direction the operator moves the grip and the applied force feedback emulates the mechanical resistance to a conventional steering system The operator is notified on an error in the EHD...

Page 8: ...ors One of the joystick s finger functions is to give the machine operator control over the vehicle s direction lights Two buttons allow activating or deactivating the corresponding direction lights H...

Page 9: ...direction Operator notification The operator notification consists of a buzzer tone and a vibration feedback This is part of the redundancy concept since the joystick is designed to reliably inform th...

Page 10: ...EMS ISO 11452 2 2004 100 V m Conducted EMS ISO 11452 4 2011 200 mA Automotive transient pulses 1 2a 2b 3a 3b ISO 7637 2 2012 Automotive starting profile ISO 16750 2 2012 Note Us6 5 5V Automotive load...

Page 11: ...C power supply on page 19 CAN interface In the EHD steering system JS1 H Steer by Wire integrates dual channel CAN functionality Both CAN interfaces run simultaneously and provide steering control and...

Page 12: ...ed data page 0 Data page 0 PDU format 253 PSU specific 214 PGN supporting information Default priority 3 Parameter group number 64982 0x00FDD6 BJM1 SPN data format Start position Length Name SPN 1 1 2...

Page 13: ...2 bits Joystick 1 Button 4 Pressed Status Auto Guidance 0x00 Not pressed 0x01 Pressed 0x02 Error Indicator 0x03 Not Available 2688 6 3 2 bits Joystick 1 Button 3 Pressed Status Indicator Right 0x00 N...

Page 14: ...or affected modules are disabled but the joystick stays operational A Safe State can only be reset through a power cycle This means the one time occurrence of a single error leads to entering the Safe...

Page 15: ...y Wire relies on a load dump protected power supply by the EHD controller Those power supplies are completely independent and must not be interlinked The joystick internally connects both ground lines...

Page 16: ...functions provided by the JS1 H Steer by Wire steering joystick Approving certification and homologation of the entire system to the desired risk reduction level Installation set up safety assessment...

Page 17: ...processor interrupts the communication to the EHD controller No messages are sent to the CAN bus from the corresponding CAN Node Due to the second CAN channel the joystick functionality is still give...

Page 18: ...ring function that monitors the operator notification to ensure that the machine operator is correctly notified in case of a failures only Joystick safety perameters Safety parameter Specification Des...

Page 19: ...dback will immediately be disabled This will also send the joystick into safe state and send out Force feedback error meaning it will remain operable at limited performance until the next power down D...

Page 20: ...he two channels C1 pin Function Diagram 1 Ground common 2 Power supply A 3 Steering Bus A H 4 Steering Bus A L 5 CAN Shield A 6 FF Power 7 Horn Signal 8 Horn Power C1 pin Function Diagram 1 Ground com...

Page 21: ...ing points Calibration The joystick software uses non volatile calibration and configuration data for its steering application User and Safety Manual PLUS 1 JS1 H Steer by Wire System Set up Danfoss D...

Page 22: ...ting on the integrated system for failure modes where the system reaction to a fault cannot be predicted or simulated Please check with the EHD Safety Manual and the applicable Safety Standard which t...

Page 23: ...Service Tool can be used for checking the system status of all CAN connected Danfoss PLUS 1 Compliant devices and flashing firmware The following functions should be highlighted here Read out error c...

Page 24: ...eeds to be replaced Horn always on Hardware problem Joystick needs to be replaced GPS based Auto Drive always off Hardware problem Joystick needs to be replaced Light is always on high beam Hardware p...

Page 25: ...foss Power Solutions US Company 2800 East 13th Street Ames IA 50010 USA Phone 1 515 239 6000 Danfoss Power Solutions Trading Shanghai Co Ltd Building 22 No 1000 Jin Hai Rd Jin Qiao Pudong New District...

Reviews: