1. Introduction
Electrification of road transport has renewed industrial and academic interest in electric machines that are robust, inexpensive, and free of rare-earth magnets. Switched reluctance motors (SRMs) meet these three constraints and have re-emerged as a competitive option for traction, auxiliary, and ancillary drives in electric vehicles (EVs) [
1,
2,
3,
4]. Beyond their cost and material advantages, two structural properties make SRMs particularly suited to the fault-critical operation demanded by automotive safety standards such as ISO 26262 [
5]: each stator phase is magnetically independent of the others, and the typical asymmetric H-bridge converter has two independent switches per phase, so a single switch failure does not disable the neighbouring phases. Fault-tolerant operation after the loss of one phase is therefore achievable in principle by re-routing the torque demand onto the remaining healthy phases [
6,
7,
8]. For an EV drive, this structural property translates into a safety-relevant limp-home capability—
provided the control policy running on the healthy phases preserves both torque production and per-phase thermal integrity.
In practice, the quality of the fault ride-through depends strongly on the control policy. A naive policy that continues to demand the pre-fault phase currents—the “fault-blind” baseline—leads to severe torque ripple, speed drop, and current spikes in the neighbouring phases because each healthy phase must cover a larger angular arc of the electromechanical torque profile. Classical fault-tolerant strategies address this through hard-switched compensation: torque reference re-allocation, commutation-angle shifts forced by rule-based logic, and current limits triggered by lookup tables [
6,
7,
8]. We refer to this rule-based reference design as
Hard-FT throughout the paper. Mutually coupled and multi-phase variants of the same principle have also been investigated in the literature [
9].
Finite-control-set model predictive control (FCS-MPC) has become a popular alternative for SRM current control because it handles the non-linear flux–current–angle relationship natively through a discrete-time plant model and admits arbitrary cost weights [
10,
11,
12,
13]. Recent FCS-MPC contributions for SRMs have shown improvements in torque ripple, switching effort, and average-current tracking under healthy operation [
14,
15,
16,
17], including the authors’ optimized dual-phase excitation approach for the 8/6 SRM [
18]; a broader review of predictive control for SRM drives is given in [
19]. Extensions to fault-tolerant operation are fewer and more recent: the common pattern is to retain the healthy-mode vector set and cost function and add a separate rule-based fault-handling module on top [
20,
21]. This is functional but leaves three sources of performance loss on the table: (i) the vector set, itself, is wrong after the fault because the admissible post-fault set has 26 non-trivial states rather than 8; (ii) hard turn-on/turn-off angle overrides introduce discontinuous cost-function behaviour that defeats MPC smoothness; and (iii) even with a correct vector set, the three healthy phases do not naturally distribute the missing torque uniformly, so per-phase thermal integrity is not enforced. Beyond SRMs, open-phase fault-tolerant control has advanced rapidly for multi-phase PMSM drives, where recent methods have optimized copper loss and phase-current trajectories under open-phase operation [
22,
23]; those approaches exploit the sinusoidal multi-phase structure and do not transfer directly to the doubly salient SRM addressed here. Comprehensive treatments of fault-tolerant SRM drives are collected in recent reviews [
24]. Other SRM fault modes—notably, stator interturn short circuits—are handled by dedicated diagnosis and fault-tolerant methods [
25,
26,
27], which are complementary to the single open-phase converter fault considered here.
We propose and evaluate, by simulation, a three-layer fault-tolerant FCS-MPC architecture for a four-phase 8/6 SRM under a single open-phase fault, assessed with a 30-seed Monte Carlo simulation under measurement noise and parameter mismatch. The architecture combines (i) vector-set reconfiguration with the 26 admissible post-fault vectors, (ii) soft commutation via a position-dependent cost-function penalty (replacing rule-based overrides), and (iii) asymmetry balance penalizing the variance of RMS currents across the three healthy phases. We additionally analyse an optional max-penalty thermal limiter and show it to be equivalent to layer (iii). We report two intermediate configurations as reference points: L2-MPC, which exposes only layers (i) and (ii), and L3-MPC, which adds layer (iii); the limiter is evaluated as L4-MPC. The paper’s specific contributions are summarized as follows:
We introduce a three-layer fault-tolerant FCS-MPC architecture that restores post-fault speed regulation under a single open-phase fault, which is shown to be robust to measurement noise and parameter mismatch across three critical operating points, with the largest gains at high speed, where a fault-blind controller loses regulation entirely.
An equivalence analysis of the max-penalty limiter is presented. We show both structurally and empirically that penalizing the maximum healthy-phase RMS current against a fixed threshold and penalizing the dispersion of currents both require a balanced-state minimizer, so the two coincide wherever the load can be balanced. A weight sweep and a 30-seed Monte Carlo simulation confirm that the limiter adds no measurable benefit at the studied threshold ( on all twelve paired comparisons); it is therefore reported as an analysed equivalent rather than a separate layer.
We report an ablation that isolates the contribution of each architectural layer at three operating points under nominal conditions, establishing that vector-set reconfiguration and soft commutation are the dominant contributors to tracking performance, while asymmetry balance adds a smaller but consistent improvement that is largest at low speed.
We conduct a paired-seed Monte Carlo evaluation under measurement noise and parameter mismatch with Wilcoxon signed-rank tests [
28] of the proposed controller against the fault-blind baseline and of the limiter variant against the balancing-only controller. The proposed-versus-blind speed-RMSE gain is significant at the mid- and high-speed operating points (
at 700/2 and 800/2 Nm) and only marginal at 400/2 Nm; the limiter-versus-balancing comparison is exact (
).
We report a methodological observation on the strict scorecard: a six-criteria fault-tolerance scorecard, which is typical of healthy-mode SRM control, is not passed at any operating point by any controller under Monte Carlo simulation because post-fault torque ripple intrinsically exceeds the healthy-mode bound when a quarter of the excitation is lost. We interpret this as evidence that healthy-mode SRM specifications must be explicitly relaxed when transferred to post-fault operation—an observation relevant to ISO 26262-style certification of EV drives.
The remainder of the paper is organized as follows.
Section 1.1 maps the three-layer architecture onto ISO 26262 safety concepts to make the certification relevance concrete.
Section 2 describes the 8/6 SRM plant, the asymmetric bridge converter, the Le-Huy magnetization model, and the open-phase fault.
Section 3 derives the three-layer fault-tolerant FCS-MPC architecture and its intermediate references (L2-MPC and L3-MPC), together with the analysed max-penalty limiter (L4-MPC).
Section 4 describes the simulation methodology and fault-tolerance scorecard.
Section 5 reports the results.
Section 6 discusses implications.
Section 7 concludes the paper.
1.1. ISO 26262 Context for Post-Fault SRM Drives
ISO 26262 governs the functional safety of electric and electronic systems in passenger vehicles [
5]. Traction drives, on which vehicle propulsion and stability depend, are typically classified at Automotive Safety Integrity Level (ASIL) C or D, with the highest class assigned where unintended torque could lead to severe injury at high speed. We make explicit the distinction between the application
context that motivates this work and the specific
machine used to demonstrate it. The architecture, its cost-function formulation, and the ISO 26262 mapping developed below are framed for the EV-traction context because it is in traction that post-fault per-phase thermal integrity ceases to be a quality metric and becomes a quantified technical safety requirement (TSR-2,
Section 1.1). However, the laboratory-scale four-phase 8/6 prototype used as the reference machine throughout this paper is a demonstrator whose most immediate realistic deployment is in auxiliary EV functions (Heating, Ventilation and Air Conditioning (HVAC); compressors; oil/coolant pumps; and e-axle accessories), which fall in the ASIL B–C range. The layered reasoning is identical in both cases; what changes when moving to a higher-ASIL traction drive is the tightness of the quantitative budgets (stricter thresholds), not the logical structure of the architecture.
1.1.1. Safety Goals (SGs) Addressable by the Layered Architecture
We identify three high-level safety goals to which post-fault SRM control directly contributes: (SG1) prevent unintended motor shutdown that would compromise vehicle controllability; (SG2) prevent phase-winding over-temperature that could lead to insulation failure or thermal runaway; (SG3) prevent uncontrolled torque ripple that would degrade vehicle drivability and exceed Noise, Vibration and Harshness (NVH) limits.
1.1.2. Technical Safety Requirements (TSR) Implemented per Layer
Each architectural layer implements one or more technical safety requirements derivable from the safety goals above:
1.1.3. Fault-Tolerant Time Interval (FTTI)
ISO 26262-3 defines the FTTI as the maximum interval between fault occurrence and the system reaching a safe state without violating any safety goal. For traction-class drives, the FTTI is typically in the range of 10–50 ms [
5], dominated by the safe-state transition rather than fault detection itself. The lightweight residual-based detector
Section 3.7 declares a phase faulty within two to three sampling periods (i.e., 20–30 μs at
μs), so the dominant component of the FTTI in the proposed architecture is the controller’s transient toward the re-distributed phase currents, which the Monte Carlo measurement window starts capturing 10 ms after fault onset (
Section 4.3). We emphasize that the present work does not
formally verify FTTI compliance: the 10 ms measurement-window offset is a conservative lower bound on the post-fault transient duration, not a measured time to the safe state. The post-fault metrics reported in this paper are therefore observed inside a typical traction FTTI budget, which is what makes the post-fault behaviour reported in
Section 5.2 relevant to ISO 26262 argumentation within the simulation scope of this study.
1.1.4. Mapping the Layers onto ISO 26262 Concepts
Table 1 summarizes the correspondence. Layers 1 and 2 implement the safe-state transition and degraded-mode operation associated with TSR-1 (continued torque production); Layer 3 (asymmetry balance) equalizes healthy-phase loading and is the layer most directly associated with the per-phase thermal requirement (TSR-2). The optional max-penalty limiter targets TSR-2 explicitly but, as shown in
Section 3.6, coincides with Layer 3 wherever the load can be balanced and is therefore reported as an analysed equivalent rather than a separate functional layer.
4. Simulation Methodology
All experiments were conducted in a reproducible Python3.11.15 simulation framework with checkpointed batch execution (intermediate per-seed results are persisted to disk so that interrupted batches can resume without recomputation). The plant is simulated with the Le-Huy flux-linkage model using the parameters reported in
Table 2. Sensor noise and parameter perturbations are injected between the plant and the controller through hook functions, so the controller source is never modified between runs.
4.1. Controller Variants
Four fault-mode variants and one healthy reference are compared (
Table 5). Successive rows differ in exactly one architectural element, enabling the ablation reported in
Section 5.1.
The
Fault-blind baseline is the most pessimistic reference: it keeps the healthy-mode eight-vector set and the healthy-mode cost function after the fault. The
Hard-FT variant corresponds to the Stephens-style reference [
6,
7]: the vector set is reconfigured to
, but commutation is enforced by zeroing the switch command outside the window. The three-layered variants differ in the asymmetry treatment:
L2-MPC has none,
L3-MPC adds the variance-based asymmetry balance (Layer 3), and
L4-MPC adds the optional max-penalty limiter of Equation (
10) on top of Layer 3. L3-MPC is the proposed three-layer controller; L4-MPC is used to evaluate the limiter, which
Section 3.6 shows to be equivalent to Layer 3 in the studied regime.
4.2. Operating Points, Fault Scenarios, and Perturbations
Three critical operating points (rpm, Nm), spanning low, mid, and high speed at the 2 Nm rated load, are used for both the nominal ablation and the Monte Carlo robustness campaign.
The fault is a single open circuit of phase triggered at ms. Sensor noise measurement-only: zero-mean Gaussian noise is added to the controller’s current reading at 3% of the full-scale current ( A RMS) and to the rotor-position reading at RMS, while the plant integrates the true state. For parameter mismatch, each seed draws multiplicative factors (, and ) from , applied to the plant resistance, inertia, and friction; the controller predicts using the nominal values, so the perturbation represents a mismatch between the plant and the controller’s internal model.
All Monte Carlo runs use
. The robustness campaign of
Section 5.2 evaluates the five fault-mode variants at the three critical operating points, totalling
runs.
4.3. Metrics
Six metrics are computed on a measurement window starting 10 ms after fault onset (to exclude the detection transient) and ending at : Speed RMSE [rad/s] is the RMS error of against the constant speed reference; torque RMS ripple [%] is the RMS of normalized by , times 100); torque-tracking NMSE is ), peak phase current is [A], i.e., the max of across healthy phases and time; healthy-phase RMS current is [A], i.e., the max over the three healthy phases of their RMS current in the measurement window); and mean torque is [Nm], i.e., the time-averaged torque, used as a tracking sanity check. Per-step MPC execution-time percentiles (, and ) are also logged.
4.4. Fault-Tolerance Scorecard
A drive is said to tolerate the fault at a given operating point when it meets the six criteria of
Table 6 simultaneously in the measurement window. The scorecard produces a score in the range of
per run; a run is fully compliant if its score is 6.
Threshold Derivation
The six thresholds in
Table 6 are taken from healthy-mode SRM control practice, with the following justifications. The 5%-of-reference
speed-tracking budget follows from EV drivability practice, where speed deviations of 2–5% are at the threshold of driver perception during steady cruising; above this band, drivetrain noise and longitudinal jerk become noticeable. The 0.25
NMSE cap follows from the same drivability considerations expressed as a torque-tracking ratio. The peak-current limit at
rated provides the customary
semiconductor margin used in asymmetric-bridge SRM designs [
2,
3]. The thermal limit at
rated phase RMS corresponds to the short-time over-current tolerance of insulation class F and class H windings under IEC 60034-1 [
32] and is the certification-relevant constraint mapped to TSR-2 in
Section 1.1. The 80%
ripple threshold is a healthy-mode aspiration in the SRM literature [
15,
16]; we note in
Section 5.3 that this threshold is empirically infeasible during a post-fault transient, and we explicitly recommend relaxation to a fault-mode bound as part of the paper’s contribution. The
no-runaway criterion (
) is included as an implicit composite check that screens out controllers that appear to satisfy the thermal criterion only by under-producing torque; this matters for the under-tracking artefact discussed in
Section 6.2.
4.5. Statistical Testing
Paired comparisons use the Wilcoxon signed-rank test [
28] on per-seed metric values at each OP (
scipy.stats.wilcoxon [
33]). Seeds are matched, so each pair shares the same noise realization and parameter draw. We report the
W statistic, two-sided
p-value, and significance at
. Three OPs × four primary metrics yield 12 paired tests within each comparison family (e.g., L3-MPC vs. Fault-blind, L4-MPC vs. Fault-blind, and L4-MPC vs. L3-MPC), each treated independently. The Bonferroni-corrected threshold within a family of 12 tests is
, used consistently in the significance testing of
Section 5. A less conservative alternative, the Holm step-down procedure [
34], would relax this floor at the cost of greater interpretive complexity; we report the Bonferroni threshold for transparency.
A note on terminology. We use the absence of a significant Wilcoxon result (
) as evidence
against the presence of a detectable difference at the achieved sample size, not as evidence
for statistical equivalence. Formal equivalence testing requires the Two One-Sided Tests (TOST) procedure [
35] with pre-specified equivalence margins on each metric (e.g.,
rad/s on speed RMSE,
on NMSE,
A on
, and
percentage points on torque ripple). Where the present paper reports “no detectable difference” between L4-MPC and L3-MPC, we mean this in the absence-of-evidence sense and do not claim formal equivalence.
5. Results
This section presents the simulation-based evaluation of the proposed three-layer architecture. The evaluation is organized as follows.
Section 5.1 reports the nominal ablation at three operating points (single seed, no sensor noise) to isolate the contribution of each architectural layer under ideal conditions.
Section 5.2 reports the 30-seed Monte Carlo robustness campaign at the three critical operating points under measurement noise and
parameter mismatch, with paired-seed Wilcoxon significance tests against the fault-blind baseline and the empirical confirmation that the max-penalty limiter (variant L4-MPC) is exactly equivalent to the asymmetry-balancing controller (L3-MPC) in this regime.
Section 5.3 reports the scorecard pass rate.
Section 5.4 reports algorithmic complexity and the reference Python implementation timing as a complexity indicator.
5.1. Nominal Ablation Across Three Operating Points
Table 4 reports the four fault-mode variants at three operating points with a single seed and no sensor noise. Successive columns add one architectural layer at a time, so the column-wise differences quantify the individual contributions, as shown in the (
Figure 3).
At the primary operating point (400 rpm/2 Nm), the ablation is clean. The transition from Fault-blind to Hard-FT bundles vector-set reconfiguration with a rule-based commutation override (cf.,
Table 5), so the 47% speed-RMSE reduction (1.56 → 0.83 rad/s) attributable to that transition reflects the
joint effect of these two changes rather than vector-set reconfiguration in isolation; the further reduction of Hard-FT → L2-MPC (19%, 0.83→ 0.67 rad/s) isolates the contribution of soft commutation alone. The asymmetry balance (L2-MPC → L3-MPC) adds a further 0.5% (0.671 → 0.667). The same pattern holds for NMSE (53% cumulative reduction, with asymmetry balance contributing 0.7%) and for ripple (31.8% cumulative, 0.4% from asymmetry balance).
At 700 rpm/2 Nm, a counter-intuitive feature appears: Hard-FT is worse than the Fault-blind baseline on NMSE (1.03 vs. 0.77) and on ripple (100% vs. 89%) because the hard turn-off override forces premature demagnetization in the expanded vector set. The soft-commutation layer then recovers the loss (Hard-FT → L2-MPC reduces NMSE by 33% and ripple by 21%). This is the clearest evidence in the ablation that placing the commutation logic inside the MPC cost function (rather than on top of it) is the right architectural choice at mid-to-high speeds. Asymmetry balance, again, contributes less than 1% to every metric, including a 0.5% reduction in (2.273 → 2.261 A) at this OP.
At 800 rpm/2 Nm, the Fault-blind baseline reports a speed RMSE of 10.37 rad/s—a tracking failure—but the lowest NMSE of all four variants. This is the first appearance of an artefact that recurs in the Monte Carlo results: a controller that fails to track the load reference produces an artificially low NMSE simply because
collapses toward zero, along with
. The mean torque (
) at 800/2 (omitted from
Table 4 for space) confirms partial torque collapse under Fault-blind, while the three expanded-set variants produce stronger torque and incur higher NMSE values in absolute terms. We discuss this under-tracking artefact and its consequences for thermal-metric interpretation once in
Section 6.2.
In summary, the ablation establishes three findings: (i) the dominant contributions come from the joint vector-set reconfiguration plus soft-commutation pair, not asymmetry balance; (ii) tracking metrics alone can be misleading under torque under-production; and (iii) the thermal barrier is dormant under nominal conditions (L4-MPC ≡ L3-MPC to numerical precision), as designed.
5.2. Robustness Under Measurement Noise and Parameter Mismatch
The nominal ablation isolates each layer’s contribution but uses a single noise-free seed. To assess robustness, we run a Monte Carlo campaign at the three critical operating points (400/2, 700/2, and 800/2 Nm) with independent seeds each. Two perturbations are applied per seed and held paired across variants: measurement-only sensor noise, in which the controller reads a corrupted current ( A, of ) and position () while the plant integrates the true state, and a perturbation of the plant resistance, inertia, and friction (R, J, and B), with the controller predicting using the nominal R. The fault is applied at ms, and metrics are computed over . Five variants are reported: Fault-blind; Hard-FT; and the cumulative MPC variants, i.e., L2-MPC, L3-MPC, and L4-MPC.
5.2.1. Fault Tolerance Restores Speed Regulation
Across all three operating points, the proposed controller restores speed regulation relative to the Fault-blind baseline (
Table 7). The improvement is modest at low speed (400 rpm/2 Nm:
vs.
rad/s) and pronounced at high speed, where the Fault-blind controller loses regulation entirely (800 rpm/2 Nm:
vs.
rad/s). Paired Wilcoxon signed-rank tests of L3-MPC against Fault-blind on matched seeds (
) confirm that the speed-RMSE gain is significant at the two higher-speed operating points (
at both 700/2 and 800/2 Nm), where the Fault-blind baseline loses regulation; at 400/2 Nm, where the improvement is modest, the gain is only marginal (
, significant at
but not at the
threshold used here).
5.2.2. Asymmetry Balance Helps Most at Low Speed
The asymmetry-aware layer (L3-MPC) matches or improves on the balancing-free variant (L2-MPC) and never degrades it. The clearest margin is at 400 rpm/2 Nm, where L2-MPC alone barely separates from the Fault-blind baseline on speed RMSE ( vs. rad/s) while L3-MPC reaches rad/s; at 700 and 800 rpm, the two converge (≈0.69 and ≈2.53 rad/s, respectively). L3-MPC ripple is at or below L2-MPC at every point.
5.2.3. The Max-Penalty Limiter Is Exactly Equivalent Here
With
A, the limiter never binds: the largest healthy-phase RMS current the proposed controller draws anywhere in the campaign is
A. As a result, L4-MPC reproduces L3-MPC
exactly. All twelve paired Wilcoxon comparisons (four metrics × three operating points return
, with per-seed means identical to twelve significant figures (
Table 8). This is the empirical counterpart of the structural equivalence of
Section 3.6: wherever the healthy phases can be balanced, penalizing dispersion and penalizing the maximum coincide.
5.2.4. Limitations of the Robustness Campaign
Three caveats accompany these results see (
Figure 4). First, the absolute torque ripple is high (78–
) because a single open-phase fault in a four-phase machine removes a quarter of the available excitation; this is intrinsic to the fault, not a controller artefact. At high speed, the fault-tolerant variants exhibit
higher ripple than Fault-blind (≈95% vs.
at 800/2 Nm) because the Fault-blind controller under-produces torque while the proposed controller pushes to maintain it—a trade of increased ripple for restored regulation, not a ripple reduction. Second, the Hard-FT baseline is the least favourable on both counts: it raises ripple to ≈110% and drives peak current to
A (against the 15 A peak-current limit,
rated) at 800 rpm, which motivates the soft-commutation and balancing layers rather than a rule-based override. Third, the
parameter mismatch drives peak current above the 10 A nominal thresholdat low speed (up to
A for Fault-blind and
A for L3-MPC at 400/2 Nm), entering mild magnetic saturation while operation remains stable; this is the expected consequence of predicting with a nominal model under a de-rated plant and bounds the current margin a deployment would need to allow.
5.3. Scorecard Pass Rate Under Monte Carlo
Applying the healthy-mode fault-tolerance scorecard of
Table 6 to the robustness campaign of
Section 5.2 shows that its six criteria cannot be passed simultaneously during a post-fault transient under the tested uncertainty, for any variant. The binding constraints are the speed-regulation criterion—the
-of-reference band is routinely exceeded once
current noise is injected—and, decisively, the
ripple criterion: post-fault ripple sits between
and
at every tested operating point (
Table 7), so the ripple criterion alone precludes an all-pass outcome. The healthy-phase RMS-current criterion, by contrast, is comfortably met—the largest healthy-phase RMS current the proposed controller draws across the campaign is
A, against the 8 A rated threshold.
We interpret this not as a controller failure but as evidence that the thresholds of
Table 6—typical of healthy-mode SRM control [
6,
8]—are too strict to pass simultaneously under sensor noise and parameter mismatch during a post-fault transient, when a quarter of the machine’s excitation is unavailable. post-fault-specific scorecard with relaxed ripple and speed bands is the appropriate evaluation instrument; its calibration is left to future work, alongside hardware validation. The implications for ISO 26262 post-fault certification are discussed in
Section 6.
5.4. Algorithmic Complexity and Computational Cost
5.4.1. Algorithmic Complexity (FLOP Count per MPC Step)
The post-fault MPC step evaluates
candidate vectors. Each candidate evaluation comprises four phase predictions through Equation (
5) (each requiring two multiplies and one add for the flux update, then a bilinear interpolation in the
table costing approximately eight FLOPs), one electromagnetic-torque evaluation through Equation (
2) (a four-phase summation of bilinear interpolations in the
tables ≈36 FLOPs in total), and a cost evaluation summing the six terms in Equation (
6) (≈12 FLOPs). Therefore, the per-candidate budget is
92 FLOPs, yielding
FLOPs per MPC step for the full post-fault evaluation. The healthy-mode eight-vector evaluation is proportionally smaller, at ≈740 FLOPs per step.
5.4.2. Reference Python Timing
Table 9 reports per-step MPC execution-time percentiles of the reference Python implementation on a Colab CPU runtime, aggregated across 30 seeds at each operating point. These values are not real-time measurements:
exceeds
μs by roughly a factor of 450 (i.e.,
ms, while
μs), reflecting Python interpreter overhead in Colab rather than the algorithmic cost of evaluating 26 candidate vectors. The distribution is informative as a complexity indicator:
is roughly constant at 1.8–1.9 ms across the operating points, showing that operating-point-dependent branching does not meaningfully affect the average case;
is consistent with a fixed work budget plus interpreter-level variability. A compiled implementation (e.g., the Numba JIT acceleration we used in an earlier study, which gave a ∼50× speed-up on a closely related SRM simulator [
31]) would reduce these timings by an order of magnitude or more, but compiled-runtime real-time validation is outside the scope of this simulation-based study.
7. Conclusions
This paper proposed and systematically evaluated, by simulation, a three-layer fault-tolerant FCS-MPC architecture for a four-phase 8/6 SRM under single open-phase faults, motivated by the use of SRMs in EV traction, where per-phase thermal integrity after a fault is a hard certification requirement. The architecture combines vector-set reconfiguration ( active vectors), soft commutation via a position-dependent cost-function penalty, and variance-based asymmetry balance across the three healthy phases; an explicit max-penalty thermal limiter is analysed as an equivalent alternative rather than a separate layer.
Within the simulation study, the explicit max-penalty thermal limiter was found to be equivalent to the variance-based balancing term: for a fixed healthy-phase loading, the two penalties share the balanced-state optimiser, and a noise-free sweep across the three critical operating points confirmed that the limiter reproduces the variance-based controller to within ≤0.004 A on the worst healthy-phase RMS current, with a two-order-of-magnitude change in its weight altering torque ripple by less than . Under the 30-seed Monte Carlo configurationthe two controllers were statistically identical at every operating point ( on all paired comparisons). Therefore, the limiter is reported as an analysed, equivalent alternative rather than a distinct performance layer, and the architecture comprises three functional layers. We frame the per-phase thermal bound as safety-oriented motivation only; no fault-tolerant time-interval budget or ISO 26262 compliance is claimed.
The deterministic nominal ablation confirms a monotonic improvement at the primary operating point (400 rpm/2 Nm): speed RMSE drops from 1.56 rad/s (Fault-blind) to 0.67 rad/s for the full controller. The combination of vector-set reconfiguration and the move from rule-based to in-cost commutation accounts for the majority of this gain; asymmetry-aware balancing adds a smaller but consistent improvement and evens the loading of the healthy phases. At 700 rpm/2 Nm, rule-based hard commutation is worse than the Fault-blind baseline in NMSE and ripple, while soft commutation recovers this loss, supporting the choice of placing commutation knowledge inside the MPC cost function.
Under a 30-seed Monte Carlo simulationwith measurement-only sensor noise and parameter mismatch, the proposed controller restores post-fault speed regulation at every operating point—markedly so at high speed, where the fault-blind baseline loses regulation entirely (speed RMSE vs. rad/s at 800 rpm/2 Nm; paired Wilcoxon ). A strict six-criterion scorecard is not met at any operating point, which we interpret as evidence that healthy-mode SRM specifications must be explicitly relaxed for post-fault operation. All findings are simulation-based and anchored to a laboratory-measured machine model; hardware validation of the post-fault converter behaviour is the natural next step.