Incident: Voltage Protection Device Failure in Hyundai Sonata Plug-In Hybrid.

Published Date: 2018-03-23

Postmortem Analysis
Timeline 1. The software failure incident with the voltage protection device in the Hyundai Sonata Plug-In Hybrid occurred between July 31, 2015, and August 31, 2017, as per the recall report mentioned in Article 69095. [69095]
System 1. Voltage protection device in the 2016-2018 Hyundai Sonata Plug-In Hybrid [69095]
Responsible Organization 1. The software failure incident in the Hyundai Sonata Plug-In Hybrid was caused by a part called a voltage protection device, which could activate incorrectly and render the electric motor inoperative, leading to a loss of motive power [69095].
Impacted Organization 1. Customers who own the 2016-2018 Hyundai Sonata Plug-In Hybrid vehicles were impacted by the software failure incident as they may experience a loss of motive power due to the defect in the voltage protection device [Article 69095].
Software Causes 1. The software cause of the failure incident was a defect in the part called a voltage protection device, which led to the electric motor becoming inoperative in limited instances during charging or discharging, rendering the vehicle unable to operate under electric power [69095].
Non-software Causes 1. The failure incident in the Hyundai Sonata Plug-In Hybrid was caused by a defective part called a voltage protection device, which could lead to the electric motor becoming inoperative during charging or discharging [69095].
Impacts 1. The software failure incident in the Hyundai Sonata Plug-In Hybrid resulted in the electric motor becoming inoperative, leading to the vehicle not being able to operate under electric power [69095]. 2. The defect in the voltage protection device caused the battery to swell during charging or discharging, activating the device and rendering the electric motor inoperative, potentially causing a safety issue as the vehicle may lose motive power at speed, increasing the risk of a collision [69095].
Preventions 1. Implementing thorough testing procedures during the development phase to detect any potential issues with the voltage protection device software [69095]. 2. Conducting regular software updates and maintenance checks to ensure the proper functioning of the battery management module and its components [69095]. 3. Implementing a more robust monitoring system that can detect early signs of battery swelling or abnormal behavior to prevent the activation of the voltage protection device [69095].
Fixes 1. Dealers will remove the recalled component and replace it with a new battery management module with a revised overvoltage protection switch [69095].
References 1. Recall report issued by Hyundai [69095]

Software Taxonomy of Faults

Category Option Rationale
Recurring unknown (a) The software failure incident related to the voltage protection device causing the electric motor to become inoperative in Hyundai's 2016-2018 Sonata Plug-In Hybrid is specific to Hyundai vehicles. There is no mention in the article of a similar incident happening before within the same organization. (b) The article does not mention any similar incident happening at other organizations or with their products and services.
Phase (Design/Operation) design (a) The software failure incident in the Hyundai Sonata Plug-In Hybrid recall is related to the design phase. The issue stems from a part called a voltage protection device, which is a component designed to prevent the battery from exceeding its voltage limits. However, in this case, the battery might swell during charging or discharging, activating the device and rendering the electric motor inoperative, leading to a software failure that prevents the vehicle from moving under its own power [69095]. (b) The software failure incident is not related to the operation phase or misuse of the system but rather to a design flaw in the voltage protection device that impacts the electric motor's functionality in the Hyundai Sonata Plug-In Hybrid vehicles [69095].
Boundary (Internal/External) within_system (a) The software failure incident described in the article is within_system. The issue stems from a part called a voltage protection device within the vehicle's battery management system. This component, when activated due to battery swelling during charging or discharging, renders the electric motor inoperative, leading to the vehicle not being able to operate under electric power as intended [69095].
Nature (Human/Non-human) non-human_actions, human_actions (a) The software failure incident in the Hyundai Sonata Plug-In Hybrid was due to a non-human action. The issue stemmed from a part called a voltage protection device, which could cause the battery to swell during charging or discharging, leading to the activation of the device and rendering the electric motor inoperative. This non-human factor introduced a defect that could prevent the vehicle from moving under its own power, posing a safety risk [69095]. (b) Human actions were involved in addressing the software failure incident. Hyundai issued a recall for the affected vehicles and dealers will be responsible for removing the faulty component and replacing it with a new battery management module with a revised overvoltage protection switch. Additionally, owner notifications will be sent via first-class mail to inform them about the recall and the necessary actions to remedy the issue [69095].
Dimension (Hardware/Software) hardware (a) The software failure incident in the article is related to hardware. The issue stems from a part called a voltage protection device, which is a hardware component used to prevent the battery from exceeding its voltage limits. In this case, the hardware malfunction causes the battery to swell during charging or discharging, activating the device and rendering the electric motor inoperative, leading to the software failure incident where the vehicle can't operate under electric power [69095].
Objective (Malicious/Non-malicious) non-malicious (a) The software failure incident described in the article is non-malicious. The issue stems from a part called a voltage protection device in the Hyundai Sonata Plug-In Hybrid vehicles, which is meant to prevent the battery from exceeding its voltage limits. However, in some cases, the battery might swell during charging or discharging, activating the device and rendering the electric motor inoperative. This non-malicious failure leads to a safety issue as it could prevent the vehicle from moving under its own power, potentially increasing the risk of a collision [69095].
Intent (Poor/Accidental Decisions) unknown The software failure incident described in the article does not directly point to poor decisions or accidental decisions as the intent behind the failure. Instead, the incident is attributed to a defect in a part called a voltage protection device, which leads to the electric motor becoming inoperative in certain instances, affecting the vehicle's ability to operate under electric power [69095].
Capability (Incompetence/Accidental) accidental (a) The software failure incident in the article is not related to development incompetence. The issue with the Hyundai Sonata Plug-In Hybrid was caused by a part called a voltage protection device, which could lead to the electric motor becoming inoperative during charging or discharging of the battery. This issue was identified as a safety concern due to the potential loss of motive power at speed, increasing the risk of a collision. The remedy involved replacing the faulty component with a new battery management module with a revised overvoltage protection switch [69095]. (b) The software failure incident in the article can be categorized as accidental. The problem with the voltage protection device causing the electric motor to stop working was not intentional but occurred due to the device activating during charging or discharging of the battery, leading to the inoperability of the motor. This accidental activation of the device resulted in the safety issue of potential loss of motive power while driving, prompting the recall and replacement of the faulty component [69095].
Duration temporary The software failure incident described in Article #69095 can be categorized as a temporary failure. The article mentions that the issue arises from a part called a voltage protection device, which can cause the electric motor to become inoperative in limited instances when the battery swells during charging or discharging. This specific circumstance triggers the failure, indicating that it is not a permanent issue affecting all vehicles at all times. The article also highlights that cars built after August 2017 already have the updated hardware, suggesting that the problem is not inherent in all vehicles but rather linked to a specific component or timeframe [69095].
Behaviour other (a) crash: The software failure incident described in the article is not related to a crash where the system loses state and does not perform any of its intended functions. The issue with the voltage protection device in the Hyundai Sonata Plug-In Hybrid does not result in a complete system failure but rather a specific component failure affecting the electric motor functionality [69095]. (b) omission: The software failure incident is not due to the system omitting to perform its intended functions at an instance(s). The issue with the voltage protection device causing the electric motor to become inoperative is a specific failure related to that component rather than a general omission of functions [69095]. (c) timing: The software failure incident is not due to the system performing its intended functions correctly but too late or too early. The issue with the voltage protection device affecting the electric motor's operation is not related to timing issues but rather a specific component malfunction [69095]. (d) value: The software failure incident is not due to the system performing its intended functions incorrectly. The issue with the voltage protection device causing the electric motor to stop working is a hardware-related problem rather than a software bug leading to incorrect function execution [69095]. (e) byzantine: The software failure incident is not related to the system behaving erroneously with inconsistent responses and interactions. The issue with the voltage protection device in the Hyundai Sonata Plug-In Hybrid is a specific hardware fault affecting the electric motor's operation, leading to a loss of motive power under certain conditions [69095]. (f) other: The software failure incident in the article can be categorized as a hardware-related failure rather than a software failure. The issue with the voltage protection device causing the electric motor to become inoperative is a hardware defect that requires a component replacement, specifically the battery management module with a revised overvoltage protection switch [69095].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence harm, property, non-human, theoretical_consequence The consequence of the software failure incident described in the article is related to the potential harm caused by the defect. The article mentions that if the electric motor stops working due to the software failure, it could prevent the vehicle from moving under its own power, which presents a safety issue. A loss of motive power at speed could increase the chance of a collision, indicating the potential harm that could result from the software failure [69095].
Domain transportation (a) The failed system in the article is related to the transportation industry as it involves a plug-in hybrid vehicle, specifically the 2016-2018 Hyundai Sonata Plug-In Hybrid [69095]. The software failure incident affected the electric motor of the vehicle, leading to a safety issue that could impact the vehicle's ability to move under its own power, thus directly impacting transportation.

Sources

Back to List