Files
NeoECU-Hardware/Architecture/IO_MODULES/DIGITAL_OUTPUTS.md
T
h3cx 0de94168f7 Initial function IO and power architecture
This commit contains the inital functional IO (engine controls and
general digital and analog IO excluding digital IO) and the initial
power architecture for the project
2026-08-29 21:18:45 +02:00

8.1 KiB

General-Purpose Digital Output Module

Purpose

This module defines the generic harness-connected digital-output classes for NeoECU V1. It does not cover the dedicated ignition and injector power stages. Connector positions, channel count, and the assignment of vehicle functions remain open until packaging and connector design.

Two non-interchangeable output classes are provided:

  • protected 5 V high-side logic outputs for external electronic-control inputs;
  • protected battery-domain low-side outputs for relays, solenoids, and other inductive loads.

Firmware assigns a compatible vehicle role and reported polarity to a channel; it cannot turn one electrical class into the other. A starter-enable function may use either class only when the external starter interface accepts it.

Protected 5 V logic outputs

Use the automotive-qualified TI TPS4H000-Q1 quad smart high-side switch. It is supplied from +5V_AUX, not directly from +5V_MAIN.

+5V_MAIN --> +5V_AUX eFuse / load switch --> TPS4H000-Q1 VBB
                                                |
MCU GPIO --> TPS4H000-Q1 INx                   OUTx --> LOGIC_OUTx --> connector
                 |                                      |
               R_IN_PD                                  R_OUT_PD
                 |                                      |
                GND                                    GND
  • +5V_AUX isolates an external logic-output fault from +5V_MAIN, the MCU, and the sensor-excitation rail.
  • Each channel is active high: when commanded on, it sources +5V_AUX. R_OUT_PD holds the connector output low when the channel is off or the ECU is unpowered. This is a protected high-side output with a passive low state, not a true push-pull stage.
  • R_IN_PD is an external pull-down at the IC input. It holds the output off while the MCU is reset, booting, unpowered, or has not deliberately taken control. MCU internal pulls are not a substitute.
  • Set each channel's current limit to the TPS4H000-Q1 minimum configured value of 100 mA. This is the intended maximum output current for this logic-output class; the +5V_AUX eFuse limit must be selected consistently with the populated channel count and simultaneous-fault policy.
  • Use the IC's diagnostic/current-sense variant as appropriate for the MCU interface. Per-channel fault reporting is useful but open-load reporting is optional for generic logic commands.

Logic-output connector protection

Place TVS_LOGIC_OUTx at the connector side of each output, with a short, low-inductance return to the protected output-ground reference. Select its working standoff above the maximum +5V_AUX voltage and its worst-case dynamic clamp below the TPS4H000-Q1 output-pin limit with margin.

The TVS absorbs transient events. It is not sized to dissipate a sustained misconnection to VBAT_PROT; the TPS4H000-Q1's off-state short-to-battery detection and fault behaviour must handle that case. Confirm its unpowered output behaviour and the completed TVS network against the actual connector fault and transient specification before schematic freeze.

Protected low-side outputs

Use the automotive-qualified Infineon TLE9104SH smart quad low-side switch. It drives battery-domain loads supplied from VBAT_PROT.

VBAT_PROT --> external load --> SINK_OUTx --> TLE9104SH OUTx
                                                  |
                                           internal low-side MOSFET
                                                  |
                                           OUT_PGND --> power-entry ground star

VBAT_PROT --> TLE9104SH VS       +5V_MAIN --> TLE9104SH VDD
                                  +3V3_MAIN --> TLE9104SH VIO

MCU GPIO --> TLE9104SH INx       MCU SPI <--> TLE9104SH SPI
                 |                              |
               R_IN_PD                         diagnostics
                 |
          TLE9104SH local ground reference

MCU enable --> TLE9104SH EN
                 |
               R_EN_PD
                 |
          TLE9104SH local ground reference
  • The TLE9104SH supplies active inductive-load clamping, configurable overcurrent protection, short-circuit and thermal protection, direct channel inputs, and SPI diagnostics.
  • VS is supplied from VBAT_PROT; use the documented logic supplies so the MCU-facing interface is referenced to +3V3_MAIN while the driver itself is supplied from the internal 5 V rail. Decouple both supply domains locally at the IC.
  • R_EN_PD holds EN inactive through power-up and MCU reset. R_IN_PD on every direct input holds its channel off. Firmware may enable outputs only after the required reset, SPI configuration, and diagnostic checks have completed.
  • Use the diagnostic interface to identify overcurrent, overtemperature, short-to-battery, short-to-ground, and—where useful—open-load faults. The final retry, latching, reporting, and output-inhibit policy is firmware work and remains open.
  • Define OUT_PGND as a high-current return domain. It must remain separate from DGND, sensor return, injector return, and ignition return until the deliberate power-entry star connection.

Sink-output connector protection

The TLE9104SH's internal active clamp is the primary turn-off path for inductive loads. Provide a connector-side transient-protection footprint for each sink output, but select and place any external TVS only after calculating the load energy, harness transient environment, and desired release time. An incorrect low-voltage clamp can bypass the driver's intended inductive clamp, increase TVS dissipation, or slow a relay/solenoid release.

The final protection network shall keep the output pin within its validated limit for connector transients and for an externally powered load while the ECU is off. It shall not back-power the TLE9104SH logic supply, +3V3_MAIN, or +5V_AUX.

Default state and fault behaviour

Condition Logic output (TPS4H000-Q1) Sink output (TLE9104SH)
MCU reset or boot R_IN_PD holds the channel off; R_OUT_PD holds the connector low. R_EN_PD and R_IN_PD keep every channel open.
ECU unpowered Output is not actively driven; connector protection and the IC must tolerate the assigned external-fault case without rail back-power. Output is open; externally powered loads and connector faults must not back-power ECU logic.
Output short/overload Per-channel current limit and thermal protection act; +5V_AUX eFuse limits the aggregate branch. Per-channel overcurrent/thermal protection acts and status is reported through SPI.
Inductive turn-off Not an intended load class. Internal active clamp controls load-current decay; any external TVS is coordinated with it.

Validation and open items before schematic freeze

  1. Confirm the output connector transient/ESD and sustained miswiring cases, including externally applied battery voltage while the ECU is off.
  2. Select TVS_LOGIC_OUTx by worst-case dynamic clamp and pulse rating, not nominal voltage marking. Confirm it does not conduct at the maximum +5V_AUX voltage.
  3. Select R_OUT_PD from the external logic-input leakage, required low level, and permitted static current when the output is high.
  4. Select the +5V_AUX eFuse threshold and TPS4H000-Q1 channel-limit setting together; 100 mA per active channel is the maximum intended logic-output current.
  5. For each sink load, establish steady current, inrush, inductance, stored energy, required release time, PWM requirement, and thermal/copper limits.
  6. Calculate whether an external sink-output TVS is required and verify that it complements rather than overrides the TLE9104SH active clamp.
  7. Define the firmware diagnostic and recovery policy, and identify any output assignment that needs an additional hardware permit gate.

References