Vehicle device
By dividing the system of the vehicle device into multiple levels and setting up a monitoring unit, the problem of adverse conditions affecting normal function in multi-functional vehicle devices is solved, and the protection and elimination of functions under adverse conditions are realized.
Patent Information
- Application Number
- CN202080039605.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-05-31
- Filing Date
- 2020-05-08
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2040-05-08
AI Technical Summary
In a vehicle device that operates with multiple functions, if one function malfunctions, the entire system restarts, causing other normally functioning functions to cease operation.
The system of the vehicle-mounted device is divided into multiple levels, and each level is monitored by a separate monitoring unit. When a malfunction occurs, the system is restarted and the malfunction is eliminated on a level-by-level basis.
In environments where multiple functions are operating, it can limit the impact of adverse events, ensure the continuous operation of normal functions, and effectively eliminate adverse events.
Smart Images

Figure CN113939807B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application is based on Japanese Patent Application No. 2019-102726, filed on May 31, 2019, the contents of which are incorporated herein by reference. Technical Field
[0003] This invention relates to a device for vehicles. Background Technology
[0004] Conventional vehicle devices include a recovery unit for handling malfunctions. For example, Patent Document 1 discloses a system that includes a main control unit and a sub-control unit, and eliminates the malfunction by restarting the control unit that caused it.
[0005] Patent Document 1: Japanese Patent No. 3343816
[0006] Then, in recent years, there have been vehicle devices that, in addition to providing vehicle-related information such as speed, also have multimedia information such as navigation displays. In such vehicle devices, multiple operating systems operate to realize multiple functional units. Hereinafter, the operating system will be referred to as OS.
[0007] However, in situations where multiple functions are implemented by operating multiple operating systems, and in a structure that, as in the past, involves a complete system reboot, even if one function malfunctions, the entire vehicle system will be rebooted. As a result, other functions that normally operate cannot continue to function. The same applies when applications operating on different operating systems malfunction. Summary of the Invention
[0008] The purpose of this disclosure is to provide a vehicle device that can suppress the impact on normal operation of functions and eliminate the malfunction when an adverse condition occurs in an environment where multiple functions are operating.
[0009] To achieve the above objectives, in this disclosure, the vehicle device includes a control unit that operates on a system with multiple operating systems and multiple monitoring units that monitor malfunctions of the system. The multiple monitoring units monitor each level of the system, which is divided into multiple levels, and eliminate malfunctions on a level-by-level basis when malfunctions occur.
[0010] Based on this structure, the scope of objects to be eliminated is limited to each level. In the event of an adverse situation occurring in an environment where multiple functions are operating, the impact on the normal functioning can be suppressed, and the adverse situation can be eliminated. Attached Figure Description
[0011] Figure 1 This is a diagram schematically illustrating the structure of a vehicle device according to an embodiment.
[0012] Figure 2 This is a diagram illustrating the monitoring process based on the first monitoring unit.
[0013] Figure 3 This is a diagram illustrating the monitoring process based on the second monitoring unit.
[0014] Figure 4 This is a diagram illustrating the monitoring process based on the third monitoring unit.
[0015] Figure 5 This is a schematic diagram illustrating other structures of the vehicle's equipment. Detailed Implementation
[0016] The implementation method will be described below. Figure 1 As shown, the vehicle device 1 is connected to multiple displays such as instrument display 2 and central display 3, external devices such as user-owned mobile terminals 4, other ECUs 5 mounted on the vehicle, and a power control unit 8 that controls the first power circuit 6 and the second power circuit 7 that supply power to the vehicle device 1.
[0017] As will be described later, the vehicle device 1 is a so-called vehicle infotainment device capable of providing vehicle-related information and multimedia information prompts. Furthermore, Figure 1 The structure shown is an example and is not limited to it. For example, a vehicle may have multiple ECUs 5, and the vehicle device 1 may be connected to these multiple ECUs 5 to enable communication of various information.
[0018] The instrument display 2, for example, is composed of an LCD or OLED display and is located on the instrument panel near the driver's front. This instrument display 2 shows, in full graph, information primarily related to the vehicle's status and its driving or safety, such as speed, warnings, legally required information, remaining fuel, and whether a seatbelt is being worn. Hereinafter, for convenience, this information will be referred to as vehicle information. Alternatively, the instrument display 2 can be located in, for example, the central part of the instrument panel, and the speedometer, tachometer, or warning lights can be arranged in an analog configuration.
[0019] The central display 3, for example, is composed of an LCD or OLED display and is located near the central control console. This central display 3 displays, for example, navigation screens and menu screens. In addition, the central display 3 can also display information such as television broadcasts and playing music.
[0020] These instrument displays 2 and central display 3 can be seamlessly connected to each other. Therefore, for example, a navigation screen can be displayed on the instrument display 2, or the speed can be displayed on the central display 3.
[0021] That is, the vehicle device 1 is an integrated structure that integrates multiple functional units, including the function of displaying vehicle information and the function of displaying multimedia information, and can provide the driver with various information visually or audibly.
[0022] The vehicle device 1 is controlled by a control unit 10. The control unit 10 is composed of a so-called microcomputer, which controls the vehicle device 1 by executing computer programs stored in a memory unit (not shown) on a CPU 12. Furthermore, a system for operating multiple operating systems 11 is built on the control unit 10. Hereinafter, the operating system 11 will be referred to as OS 11.
[0023] In this embodiment, OS11A and OS11B operate on the control unit 10 and each handles its own processing. These OS11s are allocated to the multiple cores of the CPU 12.
[0024] Specifically, each OS 11 operates on the management program 13. In this embodiment, the management program 13 is provided as a function of OS 11A. Alternatively, a structure can be adopted in which the management program 13 is specifically configured, and both OS 11A and OS 11B operate on the management program 13. These OS 11A and OS 11B are connected and can communicate.
[0025] OS11A is a so-called real-time OS. Compared to OS11B, it is equipped with functions that primarily perform processing requiring real-time performance, such as those related to vehicle operation or safety. Generally speaking, such a real-time OS is designed to be less prone to errors and can predict or limit application execution time, resulting in relatively higher stability compared to general-purpose OSes. Hereinafter, applications will be referred to as "applications." This OS11A is equivalent to a first-generation operating system.
[0026] OS11B is a so-called general-purpose OS. Compared to OS11A, it has relatively lower real-time performance and stability in many cases, but it has the advantage of easily performing general-purpose processing such as multimedia functions. OS11B is equivalent to a second operating system.
[0027] Each OS 11 implements various functional units in software by executing applications. Functional units included in the control unit 10 include, for example, instrument display application 14, navigation application 15, and communication application 16. Furthermore, Figure 1The number, type, or installation of functional units shown in OS11 is just one example and is not limited to this.
[0028] Instrument display application 14 is configured as a functional unit primarily for displaying information to instrument display 2. This instrument display application 14 displays information necessary for vehicle operation, such as a speedometer, and updates the display at a relatively short cycle, for example, approximately 1 / 60th of a second. Therefore, instrument display application 14 is configured in OS11A. The images displayed by this instrument display application 14 are sent to instrument display 2, for example, as drawing data in LVDS format.
[0029] The navigation application 15 is configured as a functional unit primarily for displaying information to the central display 3. This navigation application 15 performs multimedia processing, such as generating and displaying navigation screens and outputting audio for route guidance. Therefore, the navigation application 15 is installed in OS 11B. The images displayed by the navigation application 15 are sent to the central display 3, for example, as drawing data in LVDS format.
[0030] The communication application 16 is configured to communicate with an external device 4 connected to the vehicle device 1. The communication application 16 communicates with the external device 4 using known communication methods such as USB, Bluetooth (registered trademark), or Wi-Fi. The external device 4 can be a mobile terminal as described above, or it can be a tablet computer, a USB storage device, or an internet server.
[0031] The vehicle device 1 is powered by the first power circuit 6 and the second power circuit 7. The first power circuit 6 powers the control unit 10, the instrument display circuit 17, and other devices mainly used for processing or displaying control information. The first power circuit 6 receives power from a battery (not shown) and is designed to handle low voltage, so that power can be supplied to the control unit 10 and other devices even when the battery voltage is relatively low. Specifically, the minimum operating voltage that the first power circuit 6 can supply is set lower than the minimum value of the battery voltage assumed at startup, so that power can be supplied even when the voltage from the battery drops during engine cranking.
[0032] The second power supply circuit 7 primarily supplies power to devices such as the central display circuit 18 and the communication circuit 19, which are used to process or display multimedia information. Although this second power supply circuit 7 also receives power from the battery, unlike the first power supply circuit 6, it is not designed to handle low voltage. Specifically, the minimum operating voltage that the second power supply circuit 7 can supply is set higher than that of the first power supply circuit 6, and it may stop supplying power when the battery voltage drops during startup.
[0033] The power control unit 8 is composed of a microcomputer, different from the control unit 10. When a signal to start the vehicle device 1 is input from the ECU 5, the power control unit 8 starts supplying power from the first power circuit 6 and the second power circuit 7. Conversely, when a signal to stop the vehicle device 1 is input from the ECU 5, the power control unit 8 stops supplying power from the first power circuit 6 and the second power circuit 7.
[0034] Furthermore, the vehicle device 1 can be started and stopped via user input through the operation input circuit 20. This operation input circuit 20 comprises an operation unit consisting of a touch panel corresponding to the screens of the instrument display 2 and the central display 3, and operation switches (not shown).
[0035] Furthermore, in the vehicle device 1, a first monitoring unit 21, a second monitoring unit 22, and a third monitoring unit 23 are provided in relation to this embodiment. The first monitoring unit 21 is a functional unit implemented in software by a computer program executed on the power control unit 8.
[0036] As will be described later, the first monitoring unit 21 performs monitoring at the highest level of the structure that divides the vehicle device 1 into multiple levels, that is, at the first level where the control unit 10 is the object of monitoring. As shown by arrow F1, the first monitoring unit 21 monitors the control unit 10 and, in the event of a malfunction in the control unit 10, eliminates the malfunction by restarting the entire control unit 10.
[0037] As will be described later, the second monitoring unit 22 performs monitoring at the second highest level in the structure that divides the system of the vehicle device 1 into multiple levels, that is, monitoring at the second level with OS11 as the monitoring object. In this embodiment, the second monitoring unit 22 is provided at OS11A. As shown by arrow F2, this second monitoring unit 22 monitors OS11B, and if OS11B malfunctions, it eliminates the malfunction by restarting OS11B.
[0038] As will be described later, the third monitoring unit 23 performs monitoring at the lowest level of the system structure that divides the vehicle device 1 into multiple levels, that is, at the second level, which is the application operating within the OS11 that is the object of monitoring. In this embodiment, the third monitoring unit 23 is provided in each OS11.
[0039] As indicated by arrow F3, the third monitoring unit 23 monitors each application and, if an application malfunctions, eliminates the malfunction by restarting the application. Essentially, the third monitoring unit 23 restarts the application that malfunctions, but not the applications that do not malfunction.
[0040] In the vehicle device 1, the system is divided into multiple levels according to the program level, and each level is monitored. The higher the level, the wider the scope of monitoring, i.e. the scope of restart when a bad situation occurs.
[0041] Next, the function of the vehicle device 1 with the above-described structure will be explained.
[0042] In the vehicle device 1, multiple OS11s operate, among which OS11A is considered to be relatively stable and generally less prone to malfunctions. This is because the processing on the OS11A side is basically related to the internal workings of the vehicle device 1, and is also due to thorough development and debugging.
[0043] On the other hand, OS11B performs general processing, and there are also cases where it operates using data acquired from external sources, such as the vehicle device 1. Therefore, there is a difference in quality level between OS11A and OS11B. In other words, OS11B is considered to have a higher risk of malfunctions.
[0044] Furthermore, even assuming a malfunction occurs on the OS11B side, the OS11A side, which operates essentially independently, can be considered unaffected by the malfunction and continue to function. However, in the conventional structure where the entire control unit 10 is restarted upon the occurrence of a malfunction, the entire unit is restarted even if only a small portion of the applications malfunction. In other words, if a part of multiple functions malfunctions, the entire unit is restarted regardless of the extent to which the malfunction should be eliminated, thus preventing the continued operation of components such as OS11A that have not experienced malfunctions.
[0045] However, in the event of a malfunction occurring in an environment where multiple functions are operating, the vehicle device 1 suppresses the impact on normal operation and eliminates the malfunction. Furthermore, although the following processing is performed by each monitoring unit, for the sake of simplicity, the vehicle device 1 will be used as the primary focus of the explanation.
[0046] Vehicle device 1 performs Figures 2 to 4 The processing is shown. Among them, Figure 2 The processing shown is inter-CPU monitoring processing executed by the first monitoring unit 21. Additionally, Figure 3 The processing shown is the monitoring processing between OS11 executed by the second monitoring unit 22. Additionally, Figure 4 The process shown is a monitoring process between OS11 and the application executed by the third monitoring unit 23. Each process will be described independently below.
[0047] First, the monitoring of malfunctions at the first level and the methods for eliminating them will be explained. Vehicle device 1 performs... Figure 2In the process shown, in step S1, monitoring of the control unit 10 begins. At this time, the vehicle device 1 performs monitoring such as lockout monitoring, infinite loop monitoring, reset monitoring, communication interruption monitoring, and startup time monitoring. Since these monitoring contents are general, detailed explanations are omitted. However, in lockout monitoring, it monitors whether a failure occurs where the program is not executed. Additionally, in infinite loop monitoring, it monitors whether a failure occurs where the program loops. Furthermore, in reset monitoring, it monitors whether a failure occurs where the control unit 10 is in a reset state. Additionally, in communication interruption monitoring, it monitors whether a failure occurs where communication with the control unit 10 is interrupted. Finally, in startup time monitoring, it monitors whether the module starts within a preset time.
[0048] Furthermore, although the objects of these surveillance efforts differ, they will be discussed later. Figure 3 The monitoring and processing between OS11 shown, and Figure 4 The monitoring process between OS11 and applications is also shared. However, the monitored content is not limited to the examples above and can monitor other content.
[0049] When monitoring begins, the vehicle device 1 determines in step S2 whether a malfunction has been detected. If the vehicle device 1 determines that no malfunction has been detected, it proceeds to step S1 to continue monitoring since the result in step S2 was "No". On the other hand, if the vehicle device 1 determines that a malfunction has been detected, it restarts the control unit 10 in step S3 since the result in step S2 was "Yes". This eliminates the malfunction generated in the control unit 10; in other words, it eliminates malfunctions that have a wide-ranging impact on the system of the vehicle device 1.
[0050] Next, in step S4, the vehicle device 1 determines whether the restart is complete. If the restart is not complete, since step S4 shows "No," it waits for the restart to complete. On the other hand, if the vehicle device 1 determines that the restart is complete, since step S4 shows "Yes," it moves to step S1 and begins monitoring by the control unit 10. Furthermore, this... Figure 2 The process shown ends when the vehicle device 1 stops.
[0051] In this way, for adverse situations that affect the overall system of vehicle device 1, vehicle device 1 can eliminate them by restarting the control unit 10.
[0052] Next, the monitoring of adverse conditions at the second level and the methods for eliminating them will be explained. Vehicle device 1 performs... Figure 3The process shown begins in step S11 with monitoring of OS11B. At this time, the vehicle device 1 performs the aforementioned lock monitoring, infinite loop monitoring, reset monitoring, and communication interruption monitoring.
[0053] When monitoring begins, the vehicle device 1 determines in step S12 whether a malfunction has been detected. If the vehicle device 1 determines that no malfunction has been detected, it proceeds to step S11 and continues monitoring since the result in step S12 was "No". On the other hand, if the vehicle device 1 determines that a malfunction has been detected, it restarts OS11B in step S13 since the result in step S12 was "Yes".
[0054] Next, in step S14, the vehicle device 1 determines whether the malfunction has been eliminated after a restart. Furthermore, step S14 is executed after the OS11B restarts. If the vehicle device 1 determines that the malfunction of the OS11B has been eliminated by a restart, since the result in step S14 is "yes," it proceeds to step S11 and continues monitoring.
[0055] This eliminates the adverse conditions affecting OS11B. At this point, OS11A, for which no adverse conditions were detected, essentially continues its operation. That is, the adverse conditions can be eliminated while limiting their impact to the OS11B unit.
[0056] In contrast, if the vehicle device 1 determines that the malfunction has not been eliminated, since step S14 returned "No", step S15 determines whether the number of restarts is more than the prescribed M. In this embodiment, M is set to 2, but M can be set to an appropriate value such as 1, 3, or higher. If the vehicle device 1 determines that the number of restarts is not more than M, since step S15 returned "No", it proceeds to step S13 and repeats the restart.
[0057] On the other hand, if the vehicle device 1 repeatedly performs a restart and determines that the number of restarts exceeds M, it notifies the first monitoring unit 21 since "yes" is indicated in step S15. At this time, the vehicle device 1 notifies the first monitoring unit 2 that the malfunction could not be eliminated at the second level. Furthermore, in this step S15, it is also possible to configure it to directly notify the control unit 10 to restart instead of notifying the malfunction.
[0058] Furthermore, the first monitoring unit 21, upon receiving the notification, uses methods such as... Figure 2As shown, a defective condition is detected, and the control unit 10 is restarted to eliminate the defective condition. Thus, by monitoring the first monitoring unit 21 at the first level, defective conditions that could not be eliminated even if the OS11B is restarted are eliminated, i.e., defective conditions that cannot be resolved at the second level are eliminated.
[0059] In this way, the vehicle device 1 can eliminate defects that can be eliminated by restarting in units of OS11 within the second level, and in the event of a defect that cannot be eliminated at the second level, it can eliminate the defect by notifying the first monitoring unit 21, which is at a higher level and can eliminate the defect in a wider range.
[0060] Next, the monitoring of adverse conditions at the third level and the methods for eliminating them will be explained. Vehicle device 1 performs... Figure 4 The process shown begins in step S21 with monitoring of the application operating on OS11. At this time, the vehicle device 1 performs the aforementioned lock monitoring, infinite loop monitoring, reset monitoring, and communication interruption monitoring. Furthermore, this third-level monitoring is performed on both OS11A and OS11B.
[0061] When monitoring begins, the vehicle device 1 determines in step S22 whether a defect has been detected. If the vehicle device 1 determines that no defect has been detected, it proceeds to step S21 and continues monitoring since the result in step S22 is "No". On the other hand, if the vehicle device 1 determines that a defect has been detected, it restarts the application that detected the defect in step S23 since the result in step S22 is "Yes".
[0062] Next, in step S24, the vehicle device 1 determines whether the malfunction has been eliminated after restarting. Furthermore, step S24 is performed after the application restarts. If the vehicle device 1 determines that the malfunction has been eliminated by restarting, since the result in step S24 is "yes," it proceeds to step S21 and continues monitoring.
[0063] Therefore, adverse conditions arising in the application can be eliminated by restarting the application unit. Applications for which no adverse conditions were detected then essentially continue operating. In other words, adverse conditions can be eliminated by limiting their impact to the application unit level.
[0064] In contrast, if the vehicle device 1 determines that the malfunction has not been eliminated, since step S24 returned "No", step S25 determines whether the number of restarts is more than the prescribed N. In this embodiment, N is set to 2, but N can be set to an appropriate value such as 1, 3 or more. If the vehicle device 1 determines that the number of restarts is less than N, since step S25 returned "No", step S23 is skipped and the restart is repeated.
[0065] On the other hand, if the vehicle device 1 determines that the number of restarts has exceeded N due to repeated restarts, it notifies the second monitoring unit 22 since "yes" is indicated in step S25. At this time, the vehicle device 1 notifies the second monitoring unit 22 that the malfunction could not be eliminated at the third level. Furthermore, in step S25, it is also possible to configure a direct instruction to restart the OS11B of the application that detected the malfunction, instead of simply notifying of the malfunction.
[0066] Furthermore, the second monitoring unit 22, which received the notification, through methods such as... Figure 3 As shown, a malfunction is detected, and OS11 is restarted to eliminate the malfunction. If the malfunction cannot be eliminated at the second level, the first monitoring unit 21 is notified, and the control unit 10 is restarted.
[0067] Therefore, by monitoring the second monitoring unit 22 at the higher level, or by monitoring the first monitoring unit 21 at the higher level, the adverse conditions that cannot be eliminated even if the application is restarted, i.e. adverse conditions that cannot be resolved at the third level, can be eliminated.
[0068] In this way, the vehicle device 1 can eliminate defects that can be eliminated by restarting the device on an application-by-application basis within the third level, and in the event of a defect that cannot be eliminated at the third level, the defect can be eliminated by notifying the higher-level second monitoring unit 22 or the first monitoring unit 21, which can eliminate defects in a wider range.
[0069] In this way, the vehicle device 1 divides the system into multiple levels and monitors each level. For defects that can be eliminated within a level, they are eliminated by the monitoring unit of each level, and for defects that cannot be eliminated within a level, they are eliminated by the monitoring unit of the higher level.
[0070] The following effects can be obtained by implementing the methods described above.
[0071] The vehicle device 1 includes a control unit 10 that constructs a system that operates multiple OS11A and OS11B, and multiple monitoring units that monitor system malfunctions, including a first monitoring unit 21, a second monitoring unit 22, and a third monitoring unit 23. The multiple monitoring units monitor each level that divides the system into multiple levels, and eliminate malfunctions on a level-by-level basis when malfunctions occur.
[0072] Therefore, the scope of actions, such as restarting, to eliminate malfunctions can be largely limited to each level. As a result, functions that did not cause malfunctions can continue operating. Thus, in the event of malfunctions occurring in an environment where multiple functions are operating, the impact on normally functioning functions can be suppressed, and the malfunctions can be eliminated.
[0073] In addition, in the vehicle device 1, the plurality of monitoring units include a first monitoring unit 21 which is provided outside the control unit 10 and monitors the control unit 10 at a first level; a second monitoring unit 22 which is provided on the control unit 10 and monitors the OS 11 at a second level; and a third monitoring unit 23 which is provided on the OS 11 and monitors the application at a third level.
[0074] Furthermore, when the control unit 10 malfunctions, the first monitoring unit 21 eliminates the malfunction by restarting the entire control unit 10; when the OS 11 malfunctions, the second monitoring unit 22 eliminates the malfunction by restarting the OS 11 that is malfunctioning; and when the application malfunctions, the third monitoring unit 23 eliminates the malfunction by restarting the application that is malfunctioning.
[0075] Therefore, the vehicle device 1 can classify its own system into levels at the program level, in other words, by the ease of restarting. Thus, it is easy to perform hierarchical monitoring and eliminate malfunctions through restarting.
[0076] Furthermore, in the vehicle device 1, there are OS11A, which has relatively high stability, and OS11B, which has relatively low stability compared to OS11. A second monitoring unit 22 is provided on OS11A and monitors OS11B. As a result, OS11B, which has a relatively high risk of causing malfunctions, can be monitored from the side of the more stable OS11A, and malfunctions can be detected and eliminated more reliably.
[0077] In addition, in the vehicle device 1, if the third monitoring unit 23 cannot eliminate the problem by restarting the application, it instructs the second monitoring unit 22 to eliminate the problem. If the second monitoring unit 22 cannot eliminate the problem by restarting the OS11, it instructs the first monitoring unit 21 to eliminate the problem.
[0078] Therefore, in the event of a defect that cannot be eliminated at any level, the defect can be attempted to be eliminated at the nearest higher level. Furthermore, if the defect cannot be eliminated at the nearest higher level, the entire higher-level control unit 10 can be restarted. Thus, even defects that cannot be eliminated at any level can eventually be eliminated.
[0079] The embodiment illustrates a structure in which the second monitoring unit 22 is provided in OS11A, but it is also possible to configure it so that the second monitoring unit is also provided in OS11B, thereby mutually monitoring OS11. Alternatively, as... Figure 5 As shown, the system can be configured to install the second monitoring unit 22 on the management program 13 to monitor OS11A and OS11B. In this case, the system can also be configured in the same way to install the second monitoring unit 22 on OS11A, or to install the second monitoring unit 22 on each OS11, or to install the second monitoring unit 22 on the management program 13 and monitor each OS11.
[0080] The embodiment shows an example of eliminating malfunctions by restarting the program side. However, since the vehicle device 1 is connected to many devices such as multiple ECUs 5, even if the program side is restarted, inconsistencies in the operating state may occur between it and peripheral circuits and other devices, as well as the ECUs 5. Moreover, in the case of inconsistencies in the operating state, there is a concern that even if the program side is restarted, the device may not be able to recover normally. In other words, in the case of the vehicle device 1, a structure is needed that not only restarts the program side but also restores the device to normal operation in order to coordinate with peripheral circuits and other devices, as well as the ECUs 5.
[0081] Therefore, in the vehicle device 1, when multiple monitoring units eliminate malfunctions at each level, the equipment used at that level is included in the initialization object. Thus, for example, in the case where a malfunction in the navigation application 15 is caused by a malfunction in the central display circuit 18, it is possible to avoid situations where the root cause of the malfunction is not eliminated even after restarting the navigation application 15, or where further malfunctions occur after restarting because the equipment cannot achieve linkage or synchronization with the application due to intermittent operation. This also applies to the first and second levels.
[0082] At this time, as Figure 5As shown, each monitoring unit can be configured to change the initialization timing after eliminating adverse conditions between the occupied device 30 occupied by one OS11 and the shared device 31 shared among multiple OS11s.
[0083] For example, the configuration could be such that the device 30 is initialized when OS11 restarts, while the shared device 31 is temporarily suspended from service for the restarted OS11, and then restarted according to the normal boot sequence for the restarted OS11. Thus, the restarted OS11 can utilize the device as usual. Furthermore, as a service, it is possible to provide a virtual device for accessing the physical device, the initialization of that virtual device, etc.
[0084] In this case, the devices that can be considered as objects include the instrument display circuit 17, the central display circuit 18, the communication circuit 19, the operation input circuit 20 provided in the vehicle device 1, and the instrument display 2 and the central display 3 connected to the vehicle device 1. That is, devices that can be controlled by the control unit 10 can be considered as objects.
[0085] For example, suppose that device 30 is occupied by OS11A, and shared device 31 is shared by OS11A and OS11B. Moreover, it can be configured such that when OA11B experiences a malfunction and restarts at the second level, device 30 does not restart, but shared device 31 is restarted instead.
[0086] By configuring the structure in this way, unnecessary device initialization is eliminated. Therefore, for example, when restarting OS11B at the second level, concerns can be suppressed about situations where a normally functioning OS11A malfunctions due to device initialization.
[0087] Alternatively, it can be configured such that when a malfunction occurs in the control unit 10 at the first level and it restarts, both the occupying device 30 and the shared device 31 will be restarted. This prevents the operation of the control unit 10 from being affected by the devices operating midway.
[0088] Furthermore, the objects of the occupant device 30 and the shared device 31 are not limited to the so-called peripheral devices of the control unit 10, but can also include the cache memory built into the control unit 10, or virtual occupant devices such as the virtual occupant device 32 and virtual shared device 33 used when accessing peripheral devices in a virtualized environment, such as OS11. In addition, any device that can be controlled by the control unit 10 described above can be considered as an object.
[0089] Furthermore, in the embodiment, an example of eliminating malfunctions that occur during the operation of the vehicle device 1 is shown. However, it is possible, for example, to configure it to perform, based on an operation input by the user via the operation input circuit 20 for eliminating the malfunction, such as... Figures 2 to 4 The process is shown. In this case, it is possible to configure the system so that, when an application restart operation has been entered, if the adverse condition cannot be eliminated by restarting the application, an attempt can be made to eliminate the adverse condition at a higher level.
[0090] This disclosure has been described with reference to embodiments, but it should be understood that this disclosure is not limited to these embodiments or structures. This disclosure also includes various modifications and variations within the same scope. In addition, various combinations and methods, as well as other combinations and methods that include one or more of these elements, are also within the scope and spirit of this disclosure.
[0091] The control unit and method described in this disclosure can also be implemented by a special-purpose computer consisting of a processor and a memory programmed to perform one or more functions embodied in a computer program. Alternatively, the control unit and method described in this disclosure can also be implemented by a special-purpose computer consisting of a processor composed of one or more special-purpose hardware logic circuits. Alternatively, the control unit and method described in this disclosure can also be implemented by one or more special-purpose computers consisting of a processor and a memory programmed to perform one or more functions and a processor composed of one or more hardware logic circuits. Furthermore, the computer program can also be stored as instructions to be executed by the computer on a non-transient tangible recording medium that can be read by the computer.
Claims
1. A device for a vehicle, comprising: a control section configured with a system operated by a plurality of operating systems; and a plurality of monitoring sections that monitor a failure of the system, the system is divided into a plurality of levels, the plurality of monitoring sections monitor each level, and in a case where a failure occurs, the failure is eliminated in units of levels, the plurality of monitoring sections include: a first monitoring section provided outside the control section and monitoring a first level in which the control section is a monitoring target; a second monitoring section provided in the control section and monitoring a second level in which an operating system is a monitoring target; and a third monitoring section provided in the operating system and monitoring a third level in which an application program is a monitoring target, in a case where a failure occurs in the control section, the first monitoring section eliminates the failure by restarting the control section as a whole, in a case where a failure occurs in an operating system, the second monitoring section eliminates the failure by restarting the operating system in which the failure occurs, and in a case where a failure occurs in an application program, the third monitoring section eliminates the failure by restarting the application program in which the failure occurs.
2. The device for a vehicle according to claim 1, wherein the plurality of operating systems include a first operating system having relatively high stability and a second operating system having relatively low stability compared with the first operating system, and the second monitoring section is provided in the first operating system and monitors the second operating system.
3. The device for a vehicle according to claim 1, wherein in a case where the failure cannot be eliminated by restarting the application program, the third monitoring section instructs the second monitoring section to eliminate the failure, and in a case where the failure cannot be eliminated by restarting the operating system, the second monitoring section instructs the first monitoring section to eliminate the failure.
4. The device for a vehicle according to any one of claims 1 to 3, wherein the plurality of monitoring sections eliminate the failure based on an operation input for eliminating the failure.
5. A device for a vehicle, comprising: a control section configured with a system operated by a plurality of operating systems; and a plurality of monitoring sections that monitor a failure of the system, the system is divided into a plurality of levels, the plurality of monitoring sections monitor each level, and in a case where a failure occurs, the failure is eliminated in units of levels, and in eliminating the failure in each level, the plurality of monitoring sections include a device used in the level in an object of initialization.
6. The device for a vehicle according to claim 5, wherein the plurality of monitoring sections change an initialization timing after eliminating the failure between an occupied device occupied by one operating system and a shared device shared between the plurality of operating systems in the device.
7. The device for a vehicle according to claim 5 or 6, wherein the plurality of monitoring sections eliminate the failure based on an operation input for eliminating the failure.
Citation Information
Patent Citations
Semiconductor device
JP2019102726A
Data processing device
US20160011576A1
Electronic apparatus, restarting method, and non-transitory recording medium
US20180150359A1