Engineered a production-grade, modular C/C++ embedded firmware platform for Battery Management Systems (BMS) with reusable Hardware Abstraction Layer (HAL) interfaces, SOC estimation, battery protection engine, deterministic state-machine fault handling, and CAN telemetry. Includes a Python-based firmware testing framework covering 20+ fault-injection scenarios across 10,000+ simulated execution cycles with 70%+ unit-test coverage.
- Languages: C (C99), C++, Python 3
- Hardware Interfaces (HAL): ADC, GPIO, I2C, UART, CAN 2.0B
- Firmware Architecture: Hardware Abstraction Layer (HAL), Deterministic Finite State Machine (FSM), Fault Manager, Battery Protection Engine, State of Charge (SOC) Estimator
- Testing & Verification: Native C Unit Testing, Python Ctypes Software-in-the-Loop (SIL), Fault Injection Framework (20+ scenarios), Accelerated 10K+ Cycle Simulator, Line Coverage Analysis
- Build & Environment: GCC / MinGW, Cross-Platform Python Automation, Git
+----------------------------------+
| System Control FSM |
| (INIT, STANDBY, PRECHARGE, |
| OPERATIONAL, FAULT, RECOVERY) |
+----------------+-----------------+
|
+-----------------------------+-----------------------------+
| | |
+------------v------------+ +------------v------------+ +------------v------------+
| Battery Protection Engine| | SOC Estimator Engine | | CAN Telemetry Module |
| - Overvoltage (OVP) | | - Coulomb Counting (Ah) | | - Pack Status (0x100) |
| - Undervoltage (UVP) | | - OCV Lookup Table | | - Cell Voltages (0x101) |
| - Overcurrent (OCCP/ODCP)| | - Complementary Filter | | - Temps & SOC (0x102) |
| - Temperature (OTP/UTP) | +-------------------------+ | - Fault Mask (0x103) |
| - Cell Imbalance | +-------------------------+
+------------+------------+
|
+------------v------------+
| Fault Manager Engine |
| - 3-Cycle Debouncing |
| - Severity Evaluation |
| - Auto-Recovery Retries |
+------------+------------+
|
=================v========================================================================
HARDWARE ABSTRACTION LAYER (HAL)
==========================================================================================
+--------------+ +--------------+ +--------------+ +--------------+ +--------------+
| HAL ADC | | HAL GPIO | | HAL I2C | | HAL UART | | HAL CAN |
| Cell Voltages| | Contactors | | EEPROM | | Serial Log | | Broadcast |
| Pack Current | | Status LEDs | | Storage | | Debug Out | | Messaging |
| Thermistors | | E-Stop Pin | | | | | | |
+--------------+ +--------------+ +--------------+ +--------------+ +--------------+
| Scenario ID | Fault Condition / Test Name | Injection Method | Expected Firmware Action |
|---|---|---|---|
| 01 | Cell Over-Voltage (OVP) | Cell 0 > 4.25V | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 02 | Cell Under-Voltage (UVP) | Cell 0 < 2.80V | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 03 | Charge Over-Current (OCCP) | Pack Current > +40A | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 04 | Discharge Over-Current (ODCP) | Pack Current < -100A | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 05 | Charge Over-Temperature (OTP) | Temp > 45°C (Charging) | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 06 | Discharge Over-Temp (OTP) | Temp > 60°C (Discharging) | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 07 | Under-Temperature (UTP) | Temp < 0°C (Charging) | Latch Fault, Open Contactors, FSM -> FAULT_ACTIVE |
| 08 | Sensor Failure / ADC Disconnect | Sensor Valid -> False | Critical Fault, FSM -> FAULT_ACTIVE |
| 09 | Auxiliary Power Rail Low | Aux Supply < 9.0V | Latch Fault, FSM -> FAULT_ACTIVE |
| 10 | Emergency Stop (E-Stop) | Active-Low E-Stop Pin | Critical Fault, Open Contactors Instantly |
| 11 | Cell Voltage Imbalance | Delta V > 100mV | Latch Fault, FSM -> FAULT_ACTIVE |
| 12 | Transient Spike Debouncing | 1-Tick Spurious Noise | Noise Filtered Out (State remains OPERATIONAL) |
| 13 | Sub-Threshold Pulse | Current @ 38A (< 40A) | Normal Operation Maintained |
| 14 | Oscillating Voltage Noise | Sine Wave Voltages | Debouncer filters noise below limit |
| 15 | I2C EEPROM Bus Timeout | Hardware Bus Hang | Communication Fault Latched |
| 16 | CAN Bus Off Recovery | CAN Transmit Error | Telemetry Engine Re-initializes |
| 17 | Contactor Stuck Open | Feedback Mismatch | Fault Active |
| 18 | Contactor Weld Detection | Feedback Mismatch | Shutdown Critical Latch |
| 19 | Recovery Retry Exhaustion | 4 Sequential Faults | Permanent Shutdown Critical Latch |
| 20 | Sensor Flapping Filter | Alternating Noise | Debouncer prevents false transitions |
| 21 | Compound Multi-Fault | OVP + OTP Triggered | Both Fault Bits Latched in CAN Telemetry |
| 22 | Telemetry Transmission Rate | 150ms Execution | Transmits CAN frames at 10 Hz rate |
python tests/python/run_all_tests.pypython build.py
./build/bms_app.exe./build/bms_unit_tests.exepython tests/python/cycle_simulator.py 10000