Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Introduction

The AMS Controller is the subsystem responsible for the supervision and management of the Prohelion BMS.

The intent of the AMS Controller is to:

  • Ensure the accumulator is engaged and providing power to the motor when required.
  • Ensure the accumulator is only engaged when it is asked too and the relevant safety requirements are met.
  • Provide feedback to the other car subsystems as to whether the accumulator is engaged.

Why not integrate this into the SCUM?

In short: Complexity and Safety.

Expanding on this, having everything handled by one monolithic system (e.g. the SCUM) is fine until it isn’t. When a finite state machine isn’t used, a system can get stuck in weird cases and lockups potentially causing a preventable incident to occur. This is especially important in safety-critical systems like the accumulator where it has the potential to maim or cause death if it isn’t adequetely respected.

From a complexity perspective, having so many moving parts inside a system can cause breakage unintentionally and makes it hard when multiple incompatible standards need to be supported. In an embedded environment, MCUs have a limited number of peripherals, GPIO power than can be drawn by other components and system clock speed. From a safety perspective, having one small system which is wholely focused on a single task is vastly easier to implement correctly, safely and auditably.

Setup

This section will guide you through how to setup the AMS Controller with the BMS and test it to ensure that it works.

Hardware Items

  • STM32 Nucleo G431KB
  • CAN Transceiver (e.g. Microchip MCP2561)
  • Prohelion D1000 Gen 2 w/ Modules

Flashing the Firmware

Important

If the Nucleo has already been flashed with the correct firmware then this step isn’t needed.

If you’re building from source then see building from source, otherwise this section is assuming you’re flashing prebuilt firmware to the board.

To flash the prebuilt firmware, you can use any tool which supports flashing ELF binaries. This tutorial will use probe-rs as the tool to flash since it can automatically hook into the logging outputs. To install probe-rs, see their website.

Once you’ve downloaded the firmware into a directory, open up a terminal and flash the board by running:

probe-rs run --chip STM32G431KB --preverify --verify [[PATH TO FIRMWARE]]

Note

To quickly explain this command:

  • The run subcommand tells probe-rs to flash the board and attach to the output.
  • The --chip flag tells probe-rs what the microcontroller is.
  • The --preverify flag tells probe-rs to not write if the firmware is identical.
  • The --verify flag tells probe-rs to read back what was written and ensure it is correct.

Once you start getting logging output from the board which will be indicated by output which has INFO, you can then Ctrl+C to exit from probe-rs and disconnect.

Setting up the Hardware

Note

This assumes you’re using a breadboard and not a perf board.

On the breadboard, add both the Nucleo board and CAN transceiver and then grab some breadboard wires to connect them up. The wiring is as follows:

Nucleo PinTransceiver PinLine Description
D2 (PA12)TXDCAN TX Line
D10 (PA11)RXDCAN RX Line
+3V3VDD3.3V Power Supply
GND (choose any one)VSSGround

Additionally, the Nucleo board is connected to the ready to drive (R2D) line, which terminates at the A0 pin. For testing purposes, connecting this line to ground will set R2D to low (preventing engagement) and connecting it to power (i.e. floating) will set R2D to high.

Important

The firmware only cares whether the R2D line is driven low or not as it assumes the line will be floating when R2D is enabled.

Now that the board is setup, it can be connected up to the BMS and used.

Caution

Neither the BMS or the AMS Board should be powered during this process as the firmware will enable the accumulator if the R2D line is not pulled low.

The BMS provides a male DB9 connection for use by the AMS or other peripherals, to connect the CAN transceiver to the BMS, the wiring is as follows:

Transceiver PinDB9 Connector
CANHPin 7 (CAN_H)
CANLPin 2 (CAN_L)
GND (From Nucleo Board)Pin 3 (GND)

Once everything is connected, connect the R2D line to ground to prevent automatic engagement of the accumulator. After this, power up the BMS and the AMS board and then connect the R2D line to the +3V3 line on the Nucleo to allow it to engage the accumulator.

Building From Source

The firmware is built on Rust with the flip-link linker.

To install Rust and flip-link.

To build:

  • Get the source code from either the repo or a tarball
  • cargo build - This will grab the nightly toolchain and build the firmware and output it to target/thumbv7em-none-eabihf/debug as ams_controller
  • Flash it as per the instructions in setup

If you’re debugging and continually testing changes to the code, replace cargo build with cargo run and it will automatically call probe-rs

Glossary

TermExpandedDefinition
AMSAccumulator Management SystemThe subsystem of the car responsible for the monitoring and safe usage of the BMS both internally and externally facing.
BMSBattery Management SystemThe subsystem of the car responsible for the management of the actual battery segments and modules themself.
SCUMShutdown, Control and Universal Monitoring UnitThe subsystem responsible for looking after the bigger picture. It has the final say in the matter and is responsible for the external safety alerts.