Control system and control method of control system

By using relays that synchronously cut off or connect the power lines in the vehicle control system, the program inconsistency problem caused by residual charge in the capacitor is solved, ensuring that all control devices can reliably update the program when the ignition switch state changes, maintaining version consistency.

CN116424241BActive Publication Date: 2025-10-03TOYOTA JIDOSHA KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211475720.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-01-11
Filing Date
2022-11-23
Publication Date
2025-10-03
Estimated Expiration
2042-11-23

AI Technical Summary

Technical Problem

In a vehicle's electronic control unit, when a capacitor is connected to the power terminal, rapid switching of the ignition switch causes some control units to fail to detect program updates, resulting in inconsistent program versions.

Method used

By introducing the first and second relays into the control system, the power lines are disconnected or connected synchronously, and the length of the power supply interruption period is adjusted. This ensures that all control devices can reliably detect and send trigger signals when the ignition switch state changes, and synchronize program updates.

Benefits of technology

This prevents program inconsistencies in the vehicle's electronic control units, ensuring that all control units can reliably update their programs and maintain version consistency when the ignition switch state changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116424241B_ABST
    Figure CN116424241B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a control system and a control method for the control system. The control system of a vehicle of the present invention comprises an electric power source, a first power line, a second power line, a first relay, a second relay, at least one first control device, and at least one second control device. The first control device is configured to send a trigger signal to the second control device when the first control device detects that the first relay has been switched from disconnected to connected, and after sending the trigger signal, the first updated program that has updated the first current program is activated. The second control device is configured to activate the second updated program that has updated the second current program when the second control device receives the trigger signal from the first control device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a control system and a control method of the control system, and more particularly to a control system of a vehicle capable of updating a program for control, and a control method of the control system. Background Art

[0002] There is a technology that can update a program executed by an electronic control device of a vehicle (for example, see Japanese Patent Application Laid-Open No. 2020-27666).

[0003] In such an electronic control device, in order to achieve version consistency with the programs of other electronic control devices that coordinate their actions, each electronic control device activates (validates) the updated version of the program together, with the ignition switch being turned from off to on as an opportunity. However, when the ignition switch is turned from on to off and then immediately turned from off to on, if a capacitor is connected to the power terminal of the electronic control device, the electronic control device continues to operate with the help of the charge remaining in the capacitor. Therefore, the electronic control device connected to the part of the capacitor with residual charge cannot detect that the ignition switch is turned from off to on. That is, the electronic control device connected to the part of the capacitor with residual charge cannot activate the updated program. On the other hand, the activation of the updated program by other electronic control devices that can detect that the ignition switch is turned from off to on is possible. As a result, the consistency of the program versions of multiple electronic control devices that coordinate their actions cannot be achieved. Summary of the Invention

[0004] The present disclosure provides a control system and a control method of the control system capable of avoiding program inconsistency.

[0005] A first aspect of the present disclosure relates to a vehicle control system configured to update a control program, comprising: a power source; a first power line; a second power line; a first relay configured to disconnect or connect an electrical circuit between the power source and the first power line; a second relay configured to disconnect or connect an electrical circuit between the power source and the second power line; at least one first control device configured to be supplied with power via the first power line and to operate by executing a first current program; and at least one second control device configured to be supplied with power via the second power line and to operate by executing a second current program. The first and second relays are configured to disconnect or connect synchronously. The first period is shorter than the second period. The first period is the period from when the first relay is switched off until the power supplied to the first control device decreases, rendering it inoperable. The second period is the period from when the second relay is switched off until the power supplied to the second control device decreases, rendering it inoperable. The first control device is configured to send a trigger signal to the second control device upon detection of the first relay being switched from disconnected to connected. The first control device is configured to activate a first update program upon transmission of the trigger signal. The first update program is an update of the first current program. The second control device is configured to activate a second update program upon receipt of the trigger signal from the first control device. The second update program is an update of the second current program.

[0006] According to this structure, after the first relay and the second relay are synchronously switched to disconnection, the first control device first becomes inoperable. Thereafter, when the first relay and the second relay are synchronously switched to connection, the first control device can detect that the first relay has been switched to connection. Based on this detection, the first control device sends a trigger signal to the second control device, and then activates the first update program. After receiving the trigger signal, the second control device activates the second update program. Therefore, regardless of whether the switching of the second relay from disconnection to connection is detected, the second update program of the second control device can be correspondingly activated with the first update program of the first control device. As a result, it is possible to provide a control system that can avoid program inconsistencies.

[0007] It can also be constructed as follows: on the basis of the control system involved in the first form of the present disclosure, the above-mentioned second control device is constructed as follows: when the above-mentioned second control device detects that the second relay has been switched from disconnection to connection, regardless of whether the above-mentioned second control device receives the above-mentioned trigger signal from the above-mentioned first control device, the above-mentioned second update program is activated.

[0008] According to this configuration, the second control device can validate the second update program regardless of whether the second control device receives the trigger signal. As a result, program inconsistency can be further avoided.

[0009] The control system involved in the first form of the present disclosure can also be constructed to further include: at least one capacitor connected between the terminal of the above-mentioned first control device connected to the above-mentioned first power line and the ground line; and at least one capacitor connected between the terminal of the above-mentioned second control device connected to the above-mentioned second power line and the ground line.

[0010] With this configuration, by adjusting the capacitance of the first and second power lines, the first and second periods from when the first and second relays are switched off until the power supplied to the first and second control devices, respectively, decreases, rendering them inoperable, can be adjusted so that the first period is shorter than the second period. As a result, after the first and second relays are switched off, the first control device can be reliably rendered inoperable before the second control device.

[0011] The control system according to the first aspect of the present disclosure may further include at least one capacitor connected between a terminal of the second control device connected to the second power line and a ground line. Alternatively, no capacitor may be connected between a terminal of the first control device connected to the first power line and a ground line.

[0012] With this configuration, the first and second periods from when the first and second relays are switched off until the power supplied to the first and second control devices, respectively, decreases, rendering them inoperable, can be reliably made shorter than the second period. As a result, after the first and second relays are switched off, the first control device can be reliably rendered inoperable before the second control device.

[0013] In the control system according to the first aspect of the present disclosure, a total electrostatic capacitance between the first power line and the ground line may be smaller than a total electrostatic capacitance between the second power line and the ground line.

[0014] With this configuration, by determining the electrostatic capacitance of the first and second power lines, it is possible to compare a first period from when the first and second relays are switched off until the power supplied to the first and second control devices decreases, rendering them inoperable, with a second period. As a result, adjustment can be easily made so that the first period is shorter than the second period.

[0015] The control system according to the first aspect of the present disclosure may be configured such that the second control device determines whether the second relay has switched from disconnected to connected. The second control device may also be configured such that, if the second control device does not determine that the second relay has switched from disconnected to connected, the second control device activates the second update program conditionally upon receipt of the trigger signal.

[0016] The second aspect of the present disclosure is a control method for a vehicle control system. The control system is configured to update a control program. The control system comprises: a power source; a first power line; a second power line; a first relay configured to disconnect or connect the circuit between the power source and the first power line; a second relay configured to disconnect or connect the circuit between the power source and the second power line; at least one first control device configured to be supplied with power via the first power line and to operate by executing a first current program; and at least one second control device configured to be supplied with power via the second power line and to operate by executing a second current program. The first and second relays are configured to switch between disconnection and connection synchronously. The first period is shorter than the second period. The first period is the period from when the first relay is switched off until the power supplied to the first control device decreases, rendering it inoperable. The second period is the period from when the second relay is switched off until the power supplied to the second control device decreases, rendering it inoperable. The above-mentioned control method includes: the above-mentioned first control device sends a trigger signal to the above-mentioned second control device based on the detection that the above-mentioned first relay has been switched from disconnected to connected; the above-mentioned first control device validates the first update program after sending the above-mentioned trigger signal, and the above-mentioned first update program is a program updated from the above-mentioned first current program; and the above-mentioned second control device validates the second update program based on the receipt of the above-mentioned trigger signal from the above-mentioned first control device, and the above-mentioned second update program is a program updated from the above-mentioned second current program.

[0017] According to such a configuration, a control method for a control system that can avoid program inconsistency can be provided.

[0018] According to the present disclosure, it is possible to provide a control system and a control method of the control system that can avoid program inconsistency.

[0019] Features, advantages, and technical and industrial significance of exemplary embodiments of the present invention are described below with reference to the accompanying drawings, wherein like reference numerals denote like elements. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1This is a diagram for explaining an example of the configuration of a system including a management server and a plurality of vehicles capable of communicating with the management server in an embodiment of the present disclosure.

[0021] Figure 2 This is a diagram schematically showing an example of the structure of a vehicle according to this embodiment.

[0022] Figure 3 This is a block diagram for explaining the updating of the control program of the ECU in this embodiment.

[0023] Figure 4 This is a flowchart showing the flow of update validation processing in the first embodiment.

[0024] Figure 5 This is a timing chart showing an example of changes in applied voltage to the ECU and changes in trigger information caused by switching the ignition switch on and off in this embodiment.

[0025] Figure 6 This is a flowchart showing the flow of update validation processing in the second embodiment.

[0026] Figure 7 This is a flowchart showing the flow of update validation processing in the third embodiment. DETAILED DESCRIPTION

[0027] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The same or corresponding parts in the drawings are denoted by the same reference numerals, and their description will not be repeated.

[0028] First embodiment

[0029] Figure 1 This is a diagram for explaining an example of the configuration of a system including a management server 10 and a plurality of vehicles 1A to 1D capable of communicating with the management server 10 in the embodiment of the present disclosure.

[0030] like Figure 1As shown, the management server 10 is configured to be able to communicate with a plurality of electric vehicles including vehicles 1A to 1D via a base station 7 provided on a communication network 6. Identification information for identifying vehicles 1A to 1D is pre-stored in the management server 10. The identification information is inherent information set for each vehicle. The management server 10 also stores version information, revision information, and update history records of various control programs in each of vehicles 1A to 1D corresponding to the above-mentioned identification information. The management server 10 manages the update status of various control programs used for the actions of vehicles 1A to 1D. If a new version of at least any one of a plurality of control programs is prepared in the management server 10, the management server 10 requests an update of the control program for the target vehicle among vehicles 1A to 1D.

[0031] The management server 10 is a computer including a control device 11, a storage device 12, and a communication device 13. The control device 11, the storage device 12, and the communication device 13 are connected to each other via a communication bus 14 so as to be communicable therewith.

[0032] The storage device 12 stores a management list including the identification information of the vehicles 1A to 1D and the aforementioned update status corresponding to the identification information. The management list may also include other information corresponding to the identification information (such as update time and update status for each control program). The communication device 13 enables bidirectional communication between the control device 11 and the communication network 6.

[0033] The control device 11 is constructed to include a CPU (Central Processing Unit), memory (ROM (Read Only Memory) and RAM (Random Access Memory), etc.), and input and output ports for inputting and outputting various signals, etc., none of which are shown in the figure. The various controls performed by the control device 11 are executed by software processing, that is, by the CPU reading a program stored in a memory (non-temporary storage medium). The various controls performed by the control device 11 can also be achieved by a general-purpose server (not shown) executing a program stored in a storage medium. However, the various controls performed by the control device 11 are not limited to software processing, and can also be processed by dedicated hardware (electronic circuits).

[0034] In addition, the above description uses the case where the management server 10 manages four vehicles 1A to 1D as an example, but the number of managed vehicles is not particularly limited to 4, and may be 3 or less, or 5 or more. In the case where the vehicles 1A to 1D are not particularly distinguished, they are referred to as "vehicle 1".

[0035] Next, a specific structure of the vehicle 1 according to the present embodiment will be described. Figure 2 1 is a diagram schematically showing an example of the structure of the vehicle 1 according to this embodiment. Figure 2 The vehicle 1 includes a power storage device 20, a system main relay (SMR) 21, a power control unit (PCU) 22, a DC (Direct Current) / DC converter 40, an auxiliary battery 50, a motor generator (hereinafter referred to as MG) 62, a power transmission gear 65, drive wheels 66 and a control system 90.

[0036] The power storage device 20 is a rechargeable DC power supply. For example, the power storage device 20 is configured to include a secondary battery such as a nickel-metal hydride battery or a lithium-ion battery having a liquid or solid electrolyte. A capacitor such as an electric double-layer capacitor can also be used as the power storage device 20. The power storage device 20 supplies the PCU 22 with the power used to generate the driving force for the vehicle 1. Furthermore, the power storage device 20 is charged using power generated by the regenerative operation of the MG 62, discharged by the driving operation of the MG 62, charged using power supplied from outside the vehicle, and discharged by supplying power to the outside of the vehicle.

[0037] An SMR 21 is electrically connected between the power storage device 20 and the PCU 22 . Closing and opening of the SMR 21 are controlled by a command from an MG-ECU (Electronic Control Unit) 100 of a control system 90 .

[0038] PCU 22 converts power between power storage device 20 and MG 62 based on commands from MG-ECU 100 of control system 90. PCU 22 is configured to include an inverter that receives power from power storage device 20 to drive MG 62, and a converter (not shown) that adjusts the level of the DC voltage supplied to the inverter.

[0039] MG 62 is a three-phase AC rotating electric machine. For example, MG 62 is a permanent magnet synchronous motor having a rotor with embedded permanent magnets. MG 62 functions as both an electric motor and a generator. MG 62 is connected to power storage device 20 via PCU 22 .

[0040] For example, when vehicle 1 is traveling, MG 62 is driven by an inverter included in PCU 22. Power from MG 62 is transmitted to drive wheels 66 via power transmission gear 65. Furthermore, when vehicle 1 is braking, MG 62 is driven by drive wheels 66, operating as a generator to perform regenerative braking. Electric power generated by MG 62 is stored in power storage device 20 via PCU 22.

[0041] The vehicle 1 is further provided with a charging relay 26, a charging device 27, and an inlet 28 as a structure for charging using an AC power source 15 external to the vehicle 1 (hereinafter referred to as external charging). A connector 32 is connected to the inlet 28. The connector 32 is connected to the charging station 30 via a cable 31. Figure 2 , connector 32 is shown attached to inlet 28. However, connector 32 is configured to be attachable to and detachable from inlet 28. When external charging is performed, connector 32 is attached to inlet 28. When vehicle 1 is driven, connector 32 is removed from inlet 28. AC power from AC power source 15 is supplied to charging station 30. By attaching connector 32 to inlet 28, AC power can be supplied from charging station 30 to vehicle 1.

[0042] During external charging of power storage device 20, electric power is supplied to vehicle 1 from charging station 30 via cable 31, connector 32, and inlet 28. Charging device 27 converts the supplied electric power into electric power capable of charging power storage device 20 (hereinafter referred to as charging power), and the converted charging power is supplied to power storage device 20.

[0043] Charging relay 26 is electrically connected between power storage device 20 and charging device 27. When charging relay 26 is closed and SMR 21 is closed, electric power can be transmitted between inlet 28 and power storage device 20.

[0044] Charging device 27 is electrically connected between charging relay 26 and inlet 28. Charging device 27 converts power supplied from charging station 30 (eg, AC 100V power) into charging power (DC power) based on a command from charging ECU 110 of control system 90.

[0045] DC / DC converter 40 is electrically connected between SMR 21 and charging device 27. Therefore, when SMR 21 is closed, power can be supplied from power storage device 20 to DC / DC converter 40. In response to commands from battery ECU 130 of control system 90, DC / DC converter 40 steps down the high-voltage DC voltage of power storage device 20 to a low-voltage DC voltage. The DC / DC converter 40 then supplies the stepped-down low-voltage DC voltage to auxiliary loads (not shown) and to auxiliary battery 50. This charges auxiliary battery 50.

[0046] Auxiliary battery 50 is a secondary battery such as a lead-acid battery. Auxiliary battery 50 is capable of charging and discharging a low-voltage DC voltage (e.g., approximately 12V) sufficient to operate the auxiliary loads. A voltage sensor 59 is provided, for example, at the terminals of auxiliary battery 50 or on the power line connecting the terminals of auxiliary battery 50 and DC / DC converter 40 to detect the output voltage of auxiliary battery 50. Voltage sensor 59 transmits a signal indicating the detected output voltage of auxiliary battery 50 to battery ECU 130.

[0047] In this embodiment, control system 90 includes multiple control devices. Specifically, control system 90 includes MG-ECU 100, charging ECU 110, battery ECU 130, meter ECU 140, update ECU 150, A_ECU 160, B_ECU 170, and C_ECU 180. MG-ECU 100, charging ECU 110, battery ECU 130, meter ECU 140, update ECU 150, A_ECU 160, B_ECU 170, and C_ECU 180 are interconnected and communicable via CAN (Controller Area Network) 91. CAN is an example of a communication network.

[0048] The MG-ECU 100 is configured to include a CPU 102, memory 104, and input / output ports (not shown) for inputting and outputting various signals. The MG-ECU 100 controls the SMRs 21 and PCU 22 within the vehicle 1 so that the vehicle 1 achieves a desired driving state. Various controls executed by the MG-ECU 100 are executed through software processing, specifically, by the CPU 102 reading a control program stored in the memory 104.

[0049] A wheel speed sensor 67 is connected to the MG-ECU 100. The wheel speed sensor 67 detects the rotational speed (wheel speed) V of the drive wheels 66 and transmits a signal indicating the detected wheel speed V to the MG-ECU 100. The MG-ECU 100 uses the detected wheel speed V to calculate the speed of the vehicle 1 (hereinafter also referred to as the vehicle speed).

[0050] The charging ECU 110 is configured to include a CPU 112, memory 114, and input / output ports (not shown) for inputting and outputting various signals. The charging ECU 110 controls the charging relay 26 and charging device 27 within the vehicle 1 so that the stopped vehicle 1 can be externally charged using the charging station 30. Various controls executed by the charging ECU 110 are executed through software processing, specifically, by the CPU 112 reading a control program stored in the memory 114.

[0051] Battery ECU 130 is configured to include a CPU 132, memory 134, and input / output ports (not shown) for inputting and outputting various signals. Battery ECU 130 obtains information on the state of power storage device 20, uses this information to calculate the SOC (State of Charge) of power storage device 20, and controls DC / DC converter 40 to charge auxiliary battery 50. Various processes executed by battery ECU 130 are performed through software processing, namely, by CPU 132 reading a control program stored in memory 134.

[0052] The power storage device 20 is provided with, for example, a voltage sensor 136 , a current sensor 137 , and a temperature sensor 138 . The voltage sensor 136 , the current sensor 137 , and the temperature sensor 138 are connected to the battery ECU 130 .

[0053] Voltage sensor 136 detects voltage VB of power storage device 20 and transmits a signal indicating the detected voltage VB to battery ECU 130. Current sensor 137 detects current IB of power storage device 20 and transmits a signal indicating the detected current IB to battery ECU 130. Furthermore, temperature sensor 138 detects temperature TB of power storage device 20 and transmits a signal indicating the detected temperature TB to battery ECU 130.

[0054] Battery ECU 130 calculates the SOC, which represents the remaining capacity of power storage device 20, using detection results from, for example, voltage sensor 136, current sensor 137, and temperature sensor 138. The SOC represents the ratio of the current stored capacity to the fully charged capacity of power storage device 20 as a percentage. Various known methods can be used to calculate the SOC, such as those based on current value accumulation (coulomb counting) and those based on open circuit voltage (OCV) estimation.

[0055] Furthermore, a voltage sensor 59 for detecting the voltage of auxiliary battery 50 is connected to battery ECU 130 . Voltage sensor 59 transmits a signal indicating the voltage of auxiliary battery 50 to battery ECU 130 .

[0056] Meter ECU 140 is configured to include a CPU 142, memory 144, and input / output ports (not shown) for inputting and outputting various signals. Meter ECU 140 controls the display of specified information on display devices within the vehicle 1's cabin (e.g., various instruments such as the speedometer and distance meter, and warning lights, located in a position visible to the driver seated in the driver's seat). Various controls executed by meter ECU 140 are performed through software processing, specifically, by CPU 142 reading a control program stored in memory 144.

[0057] Update ECU 150 is configured to include a CPU 152, memory 154, a communication device 156, and input / output ports (not shown) for inputting and outputting various signals. Update ECU 150 transmits control program update information to at least one of MG-ECU 100, charging ECU 110, battery ECU 130, meter ECU 140, A_ECU 160, B_ECU 170, and C_ECU 180, thereby executing processing to request a control program update.

[0058] Communication device 156 is configured to communicate with devices external to vehicle 1. Specifically, communication device 156 is configured to communicate with management server 10 described above via communication network 6 and base station 7. Communication network 6 is comprised of, for example, the Internet. Base station 7 and communication device 156 are connected to each other via a mobile phone line (e.g., 4G, 5G) or wireless communication such as a wireless LAN (Local Area Network).

[0059] Update ECU 150 executes a request for execution of an update process, causing each ECU to execute the update process. The various processes executed by update ECU 150 are executed through software processing, i.e., by CPU 152 reading a program stored in memory 154. The various processes executed by update ECU 150 are not limited to software processing; dedicated hardware (electronic circuitry) may also be used.

[0060] A_ECU 160, B_ECU 170, and C_ECU 180 are each configured to include CPUs 162, 172, and 182, memories 164, 174, and 184, and input / output ports (not shown) for inputting and outputting various signals. A_ECU 160, B_ECU 170, and C_ECU 180 may be any of the aforementioned MG-ECU 100, charging ECU 110, battery ECU 130, meter ECU 140, and update ECU 150, or may be an ECU having other functions.

[0061] When update ECU 150 receives update differential data and information related to the ECU to be updated from management server 10 using, for example, communication device 156, update ECU 150 transmits information requesting the execution of an update process and the update differential data as update information to the ECU to be updated. Upon receiving the update information from update ECU 150, the ECU to be updated executes an update process to update the control program stored in memory using the update differential data included in the received update information.

[0062] When updating any of the control programs of the multiple ECUs installed in the vehicle 1, in addition to using data sent via a wired connection, there is also a case where the so-called OTA (Over The Air) technology is used, which uses update information received from the management server 10 via wireless communication to perform the update.

[0063] Figure 3 FIG. 1 is a block diagram for explaining the updating of the control program of the ECU in this embodiment. Figure 3 As shown, ECUs such as A_ECU 160, B_ECU 170, and C_ECU 180 operate using auxiliary battery 50 as their power source. Power line 51 is connected to the positive terminal of auxiliary battery 50. Power line 54 is connected to the power terminal of A_ECU 160. Power line 53 is connected to the power terminals of B_ECU 170 and C_ECU 180. Capacitor 56 is connected between the power terminal of A_ECU 160 and the ground. Capacitor 57 is connected between the power terminal of B_ECU 170 and the ground. Capacitor 58 is connected between the power terminal of C_ECU 180 and the ground. Capacitors 56 to 58 can be ceramic capacitors or electrolytic capacitors such as aluminum electrolytic capacitors.

[0064] Ignition switch 52A is a relay connected between power line 51 and power line 53. Ignition switch 52A switches the circuit between power line 51 and power line 53, respectively, in response to the user turning the ignition button on or off. Ignition switch 52B is a relay connected between power line 51 and power line 54. Ignition switch 52B switches the circuit between power line 51 and power line 54, respectively, in response to the user turning the ignition button on or off. In this way, ignition switches 52A and 52B switch between disconnection and connection in sync.

[0065] When using OTA technology to update the control programs of multiple ECUs operating in coordination, update information is pre-stored in the memories of each of the multiple ECUs updating the control programs. The multiple ECUs operating in coordination are at least two ECUs that exchange data and other information with each other while executing the programs and perform the processing specified by the programs. The MG-ECU 100, battery ECU 130, and meter ECU 140 are multiple ECUs operating in coordination, with the battery ECU 130 transmitting information such as the battery SOC to the MG-ECU 100 and meter ECU 140, and the MG-ECU 100 transmitting information such as power consumption to the meter ECU 140 and battery ECU 130. For example, when A_ECU 160, B_ECU 170, and C_ECU 180 operate in coordination, update information is pre-stored in these memories 164, 174, and 184. Furthermore, to ensure version consistency with the programs of the other coordinating ECUs, each ECU simultaneously activates (validates) the updated version of the program when the ignition switch is turned from OFF to ON.

[0066] However, if ignition switches 52A and 52B are turned off and then immediately turned on again, if capacitors 56, 57, and 58 are connected to the power supply terminals of A_ECU 160, B_ECU 170, and C_ECU 180, the remaining charge in capacitors 56, 57, and 58 will cause A_ECU 160, B_ECU 170, and C_ECU 180 to continue operating. Consequently, ECUs connected to capacitors with residual charge will not be able to detect the ignition switch turning on, and thus will not be able to activate the update program. Meanwhile, other ECUs that can detect the ignition switch turning on will activate the update program. Consequently, the program versions of the multiple ECUs operating in coordination cannot be consistent.

[0067] Therefore, the first period from when ignition switch 52B is turned off until the power supplied to A_ECU 160 decreases, rendering A_ECU 160 inoperable is shorter than the second period from when ignition switch 52A is turned off until the power supplied to B_ECU 170 and C_ECU 180 decreases, rendering B_ECU 170 and C_ECU 180 inoperable. A_ECU 160, upon detecting that ignition switch 52B has been turned on, sends a trigger signal to B_ECU 170 and C_ECU 180, thereby activating an update program that updates the current program of A_ECU 160. B_ECU 170 and C_ECU 180, upon receiving a trigger signal from A_ECU 160, activate an update program that updates the current program of B_ECU 170 and C_ECU 180.

[0068] Thus, after ignition switches 52A and 52B are simultaneously switched off, A_ECU 160 is initially inoperable. Subsequently, when ignition switches 52A and 52B are simultaneously switched on, A_ECU 160 can detect that ignition switch 52B has been switched on. Based on this detection, A_ECU 160 sends a trigger signal to B_ECU 170 and C_ECU 180, which then activates the updated program in A_ECU 160. After B_ECU 170 and C_ECU 180 receive the trigger signal, they activate their updated programs. Therefore, regardless of whether or not they detect the switching of ignition switch 52A from off to on, B_ECU 170 and C_ECU 180 can activate their updated programs in accordance with A_ECU 160's updated program. As a result, program inconsistencies can be avoided.

[0069] exist Figure 3 The total capacitance between power line 54 and ground (referring to the capacitance of capacitor 56) is made smaller than the total capacitance between power line 53 and ground (referring to the capacitance of capacitors 57 and 58). This allows the first period from when ignition switch 52B is turned off until the power supplied to A_ECU 160 decreases, rendering it inoperable, to be shortened compared to the second period from when ignition switch 52A is turned off until the power supplied to B_ECU 170 and C_ECU 180 decreases, rendering them inoperable.

[0070] Figure 4 This is a flowchart showing the process of update validation processing in the first embodiment. Figure 4 The process shown in the flowchart is illustrated.

[0071] Reference Figure 4 The main update validation process is executed by A_ECU 160, which has a relatively short period from power supply cessation to inoperability, as described above. The secondary update validation process is executed by B_ECU 170 and C_ECU 180, which have a relatively long period from power supply cessation to inoperability, as described above.

[0072] In the main update validation process, CPU 162 of A_ECU 160 first determines whether CPU 162 of A_ECU 160 has been notified of a control program update from update ECU 150 (step S111). If CPU 162 of A_ECU 160 determines that CPU 162 of A_ECU 160 has been notified of an update (YES in step S111), CPU 162 of A_ECU 160 receives the update information from update ECU 150 and stores the received update information in memory 164 (step S112).

[0073] In the secondary update validation process, first, CPU 172 of B_ECU 170 and CPU 182 of C_ECU 180 determine whether CPU 172 of B_ECU 170 and CPU 182 of C_ECU 180 have been notified of a control program update by update ECU 150 (step S211). If CPU 172 of B_ECU 170 and CPU 182 of C_ECU 180 determine that an update has been issued (YES in step S211), CPU 172 of B_ECU 170 and CPU 182 of C_ECU 180 receive update information from update ECU 150 and store the received update information in memory 174 and memory 184 (step S212).

[0074] After step S212 , the CPU 172 of the B_ECU 170 and the CPU 182 of the C_ECU 180 each transmit information indicating that the update information has been stored to the A_ECU 160 , which is the master ECU among the related ECUs in the coordinated operation (step S213 ).

[0075] During the main update validation process, if CPU 162 of A_ECU 160 determines that CPU 162 of A_ECU 160 has not been notified of an update (No in step S111), or after step S112, CPU 162 of A_ECU 160 determines whether CPU 162 of A_ECU 160 has received information from B_ECU 170 or C_ECU 180 indicating that the update information has been stored (step S113). If CPU 162 of A_ECU 160 determines that CPU 162 of A_ECU 160 has received information indicating that the update information has been stored (Yes in step S113), CPU 162 of A_ECU 160 causes memory 164 to store information indicating that the update information has been stored in the relevant ECU that sent the information (step S114).

[0076] If CPU 162 of A_ECU 160 determines that CPU 162 of A_ECU 160 has not received information indicating that the updated information has been stored (No in step S113), or after step S114, CPU 162 of A_ECU 160 determines whether CPU 162 of A_ECU 160 has detected that ignition switch 52B has been switched from OFF to ON (step S115). If CPU 162 of A_ECU 160 determines that CPU 162 of A_ECU 160 has detected that ignition switch 52B has been switched from OFF to ON (Yes in step S115), CPU 162 of A_ECU 160 determines whether information indicating that the updated information has been stored in all relevant ECUs has been stored in memory 164 (step S116).

[0077] When the CPU 162 of the A_ECU 160 determines that the update information has been stored in all relevant ECUs and that the memory 164 has stored the update information (YES in step S116 ), the CPU 162 of the A_ECU 160 transmits trigger information for activating the update program to the relevant ECUs (step S117 ).

[0078] In the sub-update validation processing, when the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the CPU172 of B_ECU170 and the CPU182 of C_ECU180 have not been notified of an update (No in step S211), or after step S213, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 respectively determine whether the CPU172 of B_ECU170 and the CPU182 of C_ECU180 have detected that the ignition switch 52A has been switched from off to on (step S215). When the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the CPU172 of B_ECU170 and the CPU182 of C_ECU180 detect that the ignition switch 52A has been switched from off to on (yes in step S215), the CPU172 of B_ECU170 and the CPU182 of C_ECU180 respectively determine whether the update information has been stored in the memory 174, 184 (step S216).

[0079] When the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the CPU172 of B_ECU170 and the CPU182 of C_ECU180 have not detected that the ignition switch 52A has been switched from off to on (No in step S215), the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine whether the trigger information is received from A_ECU160 (step S217).

[0080] If CPU 172 of B_ECU 170 or CPU 182 of C_ECU 180 determines that the update information has been stored (YES in step S216), or if CPU 172 of B_ECU 170 or CPU 182 of C_ECU 180 determines that the trigger information has been received (YES in step S217), CPU 172 of B_ECU 170 or CPU 182 of C_ECU 180 transmits detection confirmation information to A_ECU 160 (step S218). CPU 172 of B_ECU 170 or CPU 182 of C_ECU 180 then uses the update information stored in memory 174 or 184, respectively, to update the current program to the updated program and activate (validate) the updated program (step S219).

[0081] In the case where the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the update information is not stored (No in step S216), or when the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the CPU172 of B_ECU170 and the CPU182 of C_ECU180 do not receive the trigger information (No in step S217), or after step S219, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 return the executed processing to the upper-level processing that initially called out the update validation processing.

[0082] In the main update validation process, after step S117, CPU 162 of A_ECU 160 checks whether CPU 162 of A_ECU 160 has received detection confirmation information from B_ECU 170 and C_ECU 180 (step S118). If CPU 162 of A_ECU 160 determines that CPU 162 of A_ECU 160 has not received detection confirmation information (No in step S118), CPU 162 of A_ECU 160 repeats the process of step S118.

[0083] When CPU 162 of A_ECU 160 determines that it has received the detection confirmation information (YES in step S118 ), CPU 162 of A_ECU 160 updates the current program to the updated program using the update information stored in memory 164 and activates (validates) the updated program (step S119 ).

[0084] When the CPU162 of A_ECU160 determines that the CPU162 of A_ECU160 has not detected that the ignition switch 52B has been switched from off to on (No in step S115), or when the CPU162 of A_ECU160 determines that the update information has been stored in all relevant ECUs but the information has not been stored (No in step S116), or after step S119, the CPU162 of A_ECU160 returns the executed processing to the upper-level processing that initially called out the main update validation processing.

[0085] Figure 5 1 is a time chart showing an example of changes in applied voltage to the ECU and changes in trigger information caused by switching the ignition switches 52A and 52B on and off in this embodiment. Figure 5 As shown, at time t1, if the ignition switches 52A and 52B are switched from on to off, the voltage from the auxiliary battery 50 is no longer applied to the power terminals of A_ECU160, B_ECU170 and C_ECU180, but the voltage formed by the charge accumulated in the capacitor 56 is applied to the power terminal of A_ECU160, and the voltage formed by the charge accumulated in the capacitors 57 and 58 is applied to the power terminals of B_ECU170 and C_ECU180.

[0086] The total electrostatic capacitance between the power line 54 and the ground (mainly the electrostatic capacitance of the capacitor 56) is set to be smaller than the total electrostatic capacitance between the power line 53 and the ground (mainly the total electrostatic capacitance of the capacitor 57 and the capacitor 58). Therefore, the first period from when the ignition switch 52B is switched off to when the power supplied to A_ECU 160 decreases and becomes inoperable is shorter than the second period from when the ignition switch 52A is switched off to when the power supplied to B_ECU 170 and C_ECU 180 decreases and becomes inoperable. That is, as Figure 5 As shown, during the period from time t1 to time t2 , the voltage applied to A_ECU 160 decreases earlier than the voltages applied to B_ECU 170 and C_ECU 180 .

[0087] At time t2, when the ignition switches 52A and 52B are switched from OFF to ON, the voltage from the auxiliary battery 50 is applied to the A_ECU 160, B_ECU 170, and C_ECU 180 again. As a result, the A_ECU 160 that was previously inoperable starts to operate again. Figure 4 The main update validation process shown is as follows: A_ECU 160 executes the process of step S117 at time t3, thereby transmitting trigger information from A_ECU 160 to B_ECU 170 and C_ECU 180.

[0088] The voltage applied to B_ECU 170 and C_ECU 180 does not drop to a level where B_ECU 170 and C_ECU 180 cannot operate, and the voltage from auxiliary battery 50 is applied to B_ECU 170 and C_ECU 180 again. Therefore, B_ECU 170 and C_ECU 180 cannot detect that the ignition switch 52A has been turned on from off. However, B_ECU 170 and C_ECU 180 receive trigger information transmitted from A_ECU 160, allowing B_ECU 170 and C_ECU 180 to indirectly detect that the ignition switch 52A has been turned on from off.

[0089] Thus, regardless of whether B_ECU 170 and C_ECU 180 can directly detect that ignition switch 52A has been switched from off to on, B_ECU 170 and C_ECU 180 can indirectly detect that ignition switch 52A has been switched from off to on by receiving the trigger information. Consequently, the updated programs of B_ECU 170 and C_ECU 180 can be activated (validated) in correspondence with the updated programs of A_ECU 160. Consequently, program inconsistencies can be avoided.

[0090] Second embodiment

[0091] In the first embodiment, as Figure 4 As shown in step S215, B_ECU 170 and C_ECU 180, both of which have a relatively long period from when power supply to B_ECU 170 and C_ECU 180 is stopped until they become inoperable, directly detect that the ignition switch 52A has been switched from OFF to ON. In the second embodiment, B_ECU 170 and C_ECU 180, both of which have a relatively long period from when power supply to B_ECU 170 and C_ECU 180 is stopped until they become inoperable, do not directly detect that the ignition switch 52A has been switched from OFF to ON.

[0092] Figure 6 This is a flowchart showing the process of update validation processing in the second embodiment. Figure 6 The process is shown in the flowchart. Figure 6 As shown, Figure 6 The processing from Figure 4 The processing of step S215 and step S216 is removed from the update validation process. Figure 4 and Figure 6 It is common in China.

[0093] Even so, B_ECU 170 and C_ECU 180 cannot directly detect that the ignition switch 52A has been switched from off to on. However, B_ECU 170 and C_ECU 180 can indirectly detect that the ignition switch 52A has been switched from off to on by receiving trigger information. Therefore, the updated programs of B_ECU 170 and C_ECU 180 can be activated (validated) in correspondence with the updated programs of A_ECU 160. As a result, program inconsistencies can be avoided.

[0094] Third embodiment

[0095] In the first and second embodiments, as Figure 4 and Figure 6 As shown, different processes are executed in A_ECU 160, which has a shorter period from power supply cessation to inoperability, and in B_ECU 170 and C_ECU 180, which have a longer period. In the third embodiment, the same process is executed in A_ECU 160, which has a shorter period from power supply cessation to inoperability, and in B_ECU 170 and C_ECU 180, which have a longer period.

[0096] Figure 7 This is a flowchart showing the process of update validation processing in the third embodiment. Figure 7 The process is shown in the flowchart of Figure 7 This update validation process is performed by both A_ECU 160 , which has a shorter period from the stop of power supply to the inability to operate, and B_ECU 170 and C_ECU 180 , which have a longer period.

[0097] First, CPU 162 of A_ECU 160 , CPU 172 of B_ECU 170 , and CPU 182 of C_ECU 180 determine whether CPU 162 of A_ECU 160 , CPU 172 of B_ECU 170 , and CPU 182 of C_ECU 180 have been notified of the update of the control program from update ECU 150 (step S311 ). When the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that an update has been notified to the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 (yes in step S311), the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 respectively receive the update information from the update ECU150 and store the received update information in the memories 164, 174 and 184 (step S312).

[0098] After step S312 , the CPU 162 of the A_ECU 160 , the CPU 172 of the B_ECU 170 , and the CPU 182 of the C_ECU 180 transmit information indicating that the update information has been stored to other related ECUs operating in coordination (step S313 ).

[0099] When CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 determine that CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 have not been notified of an update (No in step S311), or after step S313, CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 determine whether CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 have received information that update information has been stored from other relevant ECUs that coordinate the action (step S314). When the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 have received information that the update information has been stored (yes in step S314), the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 respectively cause the memories 164, 174 and 184 to store this information, that is, the update information is stored in the relevant ECU that has sent the information that the update information has been recorded (step S315).

[0100] When CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 determine that CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 have not received the information that the update information has been stored (No in step S314), or after step S315, any one of CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 determines whether it is detected that the ignition switch 52A or the ignition switch 52B has been switched from off to on (step S321). When any one of the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determines that it has detected that the ignition switch 52A or the ignition switch 52B has been switched from off to on (yes in step S321), any one of the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determines whether the update information has been stored in the information of all other relevant ECUs and has been stored in the memory 164, 174, 184 (step S322).

[0101] If any of CPU 162 of A_ECU 160, CPU 172 of B_ECU 170, and CPU 182 of C_ECU 180 determines that the update information has been stored in all other relevant ECUs (YES in step S322), CPU 162 of A_ECU 160, CPU 172 of B_ECU 170, and CPU 182 of C_ECU 180 transmits trigger information for activating the update program to the other relevant ECUs (step S323). Subsequently, CPU 162 of A_ECU 160, CPU 172 of B_ECU 170, and CPU 182 of C_ECU 180 transmits detection confirmation information to the other relevant ECUs (step S324).

[0102] When any one of the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determines that it has not detected that the ignition switch 52A and the ignition switch 52B have been switched from off to on (No in step S321), the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine whether trigger information has been received from other related ECUs (step S325).

[0103] When CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 determine that CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 receive trigger information (yes in step S325), CPU162 of A_ECU160, CPU172 of B_ECU170 and CPU182 of C_ECU180 send detection confirmation information to other relevant ECUs (step S326).

[0104] When any one of the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determines that the update information has been stored in all other relevant ECUs but the information has not been stored (No in step S322), after step S324, or after step S326, the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine whether the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 have received detection confirmation information from all other relevant ECUs (step S327).

[0105] When the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that detection confirmation information has been received from all other relevant ECUs (yes in step S327), the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 respectively use the update information stored in the memory 164, 174, 184 to update the current program to the updated program and activate (validate) the updated program (step S328).

[0106] When the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 determine that the detection confirmation information has not been received (No in step S327), or after step S328, the CPU162 of A_ECU160, the CPU172 of B_ECU170 and the CPU182 of C_ECU180 return the executed processing to the upper-level processing that initially called out the update validation processing.

[0107] Thus, not only can the ECU that can directly detect that the ignition switches 52A and 52B have been switched from OFF to ON be detected, but also the ECU that can indirectly detect that the ignition switches 52A and 52B have been switched from OFF to ON can activate (validate) the update program in response to other related ECUs by receiving trigger information from the ECU that can directly detect that the ignition switches 52A and 52B have been switched from OFF to ON. As a result, program inconsistency can be avoided.

[0108] Other variations

[0109] (1) In the above embodiment, if Figure 2 As shown, vehicles 1A to 1D are BEVs (Battery Electric Vehicles). However, this is not limiting. Vehicles 1A to 1D may be any type of vehicle, including HEVs (Hybrid Electric Vehicles), PHEVs (Plug-in Hybrid Electric Vehicles), FCEVs (Fuel Cell Electric Vehicles), or vehicles equipped with an engine powered by fuel (e.g., gasoline, light oil, heavy oil, LPG (Liquefied Petroleum Gas), LNG (Liquefied Natural Gas), ethanol, or hydrogen) rather than an electric motor such as the MG62.

[0110] (2) In the above embodiment, if Figure 2 As shown, vehicles 1A to 1D are not vehicles capable of automatic driving and automatic parking. However, the present invention is not limited thereto, and vehicles 1A to 1D may be vehicles capable of automatic driving or vehicles capable of automatic parking.

[0111] (3) In the above embodiment, if Figure 3 As shown, capacitor 56 is connected between the power terminal and ground of A_ECU 160. A_ECU 160 is an ECU connected to a power line having a smaller total capacitance between the power line and the ground than other power lines. However, the present invention is not limited to this embodiment. A capacitor may not be connected between the power terminal and ground of A_ECU 160. A_ECU 160 may be an ECU connected to a power line having a smaller total capacitance between the power line and the ground than other power lines.

[0112] (4) In the above embodiment, if Figure 3As shown, one A_ECU 160 and one capacitor 56 are connected to the system of power line 54 and ignition switch 52B, where the total electrostatic capacitance between the power line and the ground line is smaller than that of other power lines. However, the present invention is not limited to this, and two or more ECUs may be connected to the system of power line 54 and ignition switch 52B, or two or more capacitors may be connected to the system of power line 54 and ignition switch 52B.

[0113] (5) In the above embodiment, if Figure 3 As shown, the system consisting of power line 54 and ignition switch 52B, which has a smaller total capacitance than the other power lines and the total capacitance between the power line and the ground line, is separated from the system consisting of power line 53 and ignition switch 52A. However, this is not limiting; the system consisting of power line 54 and ignition switch 52B, which has a smaller total capacitance than the other power lines and the total capacitance between the power line and the ground line, may be separated from two or more systems.

[0114] (6) In the above embodiment, if Figure 3 As shown, for a system in which power line 54 and ignition switch 52B have a smaller total capacitance than other power lines and between the power line and ground, capacitors 57 and 58 are connected to both B_ECU 170 and C_ECU 180, which are ECUs in a different system. However, this is not limiting. For a system in which power line 54 and ignition switch 52B have a smaller total capacitance than other power lines and between the power line and ground, capacitors may not be connected to some of the multiple ECUs in a different system.

[0115] (7) In the above embodiment, if Figure 1 and Figure 2 As shown, update information for updating the programs of the respective ECUs is transmitted from the management server 10 to the vehicles 1A to 1D via wireless communication. However, the present invention is not limited thereto, and the update information may be transmitted from the updating device to the vehicles 1A to 1D via wired communication.

[0116] (8) In the above embodiment, if Figure 3 As shown, the power source for A_ECU 160, B_ECU 170, and C_ECU 180 is the low-voltage auxiliary battery 50 of approximately 12V. However, this is not limiting, and the power source for A_ECU 160, B_ECU 170, and C_ECU 180 may also be another power storage device. For example, the power source for A_ECU 160, B_ECU 170, and C_ECU 180 may be a high-voltage battery such as power storage device 20, or a capacitor.

[0117] (9) The above-described embodiments can be understood as disclosure of the vehicle 1 or a control system including a plurality of control devices such as ECUs of the vehicle 1 , or as disclosure of a control method or a control program of the vehicle 1 or the control system.

[0118] (1) According to the control system disclosed herein, after the first relay and the second relay are synchronously switched to disconnection, the first control device first becomes inoperable. Thereafter, when the first relay and the second relay are synchronously switched to connection, the first control device is able to detect that the first relay has been switched to connection. The first control device validates the first update program after sending a trigger signal to the second control device based on the detection. The second control device validates the second update program upon receiving the trigger signal. Therefore, regardless of whether it is detected that the second relay has been switched from disconnection to connection, the second update program of the second control device can be validated correspondingly to the first update program of the first control device. As a result, program inconsistency can be avoided.

[0119] (2) According to the control system of the present disclosure, the second control device can validate the second update program regardless of whether or not a trigger signal is received. As a result, program inconsistency can be avoided more reliably.

[0120] (3) According to the control system disclosed herein, by adjusting the electrostatic capacitance of the first power line and the second power line, the first and second periods from when the first and second relays are switched off to when the power supplied to the first and second control devices, respectively, decreases and becomes inoperable can be adjusted so that the first period is shorter than the second period. As a result, after the first and second relays are switched off, the first control device can be reliably rendered inoperable before the second control device.

[0121] (4) According to the control system disclosed herein, the first and second periods from when the first and second relays are switched off to when the power supplied to the first and second control devices, respectively, decreases and becomes inoperable can be reliably made such that the first period is shorter than the second period. As a result, after the first and second relays are switched off, the first control device can be reliably rendered inoperable before the second control device.

[0122] (5) According to the control system disclosed herein, by determining the electrostatic capacitance of the first power line and the second power line, it is possible to compare the first period from when the first relay and the second relay are switched off until the power supplied to the first control device and the second control device, respectively, decreases and becomes inoperable, with the second period. As a result, it is possible to easily adjust the first period to be shorter than the second period.

[0123] The embodiments disclosed herein are to be considered in all respects as illustrative and not limiting. The scope of the present invention is not limited by the description of the embodiments described above but is indicated by the claims, and is intended to include all modifications within the scope of the claims and equivalents thereof.

Claims

1. A control system for a vehicle configured to update a program for control, characterized in that: The control system comprises: Power source; 1st power line; 2nd power line; a first relay configured to disconnect or connect a circuit between the power source and the first power line; a second relay configured to disconnect or connect a circuit between the power source and the second power line; at least one first control device configured to be supplied with power via the first power line and to operate by executing a first current program; as well as at least one second control device configured to be supplied with power via the second power line and to operate by executing a second current program, in, The first relay and the second relay are configured to switch between disconnection and connection synchronously. The first period is shorter than the second period, the first period being a period from when the first relay is switched off until the power supplied to the first control device decreases and becomes inoperable, and the second period being a period from when the second relay is switched off until the power supplied to the second control device decreases and becomes inoperable. The first control device is configured as follows: sending a trigger signal to the second control device based on the condition that the first control device detects that the first relay has been switched from disconnected to connected; activating a first update program after sending the trigger signal, wherein the first update program is a program obtained by updating the first current program; and The second control device is configured to activate a second update program under a condition that the second control device receives the trigger signal from the first control device, wherein the second update program is a program obtained by updating the second current program.

2. The control system according to claim 1, characterized in that: The second control device is configured to activate the second update program when the second control device detects that the second relay has been switched from disconnected to connected, regardless of whether the second control device receives the trigger signal from the first control device.

3. The control system according to claim 1 or 2, characterized in that: The control system also includes: at least one capacitor connected between a terminal of the first control device connected to the first power line and a ground line; and At least one capacitor is connected between a terminal of the second control device connected to the second power line and a ground line.

4. The control system according to claim 1 or 2, characterized in that: The control system further includes at least one capacitor connected between a terminal of the second control device connected to the second power line and a ground line. However, no capacitor is connected between the terminal of the first control device connected to the first power line and the ground line.

5. The control system according to claim 3, characterized in that: A total electrostatic capacitance between the first power line and the ground line is smaller than a total electrostatic capacitance between the second power line and the ground line.

6. The control system according to claim 4, characterized in that: A total electrostatic capacitance between the first power line and the ground line is smaller than a total electrostatic capacitance between the second power line and the ground line.

7. The control system according to claim 1, characterized in that: The second control device is configured as follows: Determine whether the second relay is switched from disconnection to connection, Furthermore, when the second control device does not determine that the second relay has been switched from disconnected to connected, the second control device activates the second update program on the condition that the trigger signal is received.

8. A control method for a vehicle control system, wherein the control system is configured to update a control program, wherein: The control system comprises: Power source; 1st power line; 2nd power line; a first relay configured to disconnect or connect a circuit between the power source and the first power line; a second relay configured to disconnect or connect a circuit between the power source and the second power line, wherein the first relay and the second relay are configured to switch between disconnection and connection synchronously; at least one first control device configured to be supplied with power via the first power line and to operate by executing a first current program; as well as at least one second control device configured to be supplied with power via the second power line and to operate by executing a second current program, The first period is shorter than the second period, the first period being a period from when the first relay is switched off until the power supplied to the first control device decreases and becomes inoperable, and the second period being a period from when the second relay is switched off until the power supplied to the second control device decreases and becomes inoperable. The control method includes: The first control device sends a trigger signal to the second control device based on the detection that the first relay has been switched from disconnected to connected; The first control device activates a first update program after sending the trigger signal, wherein the first update program is a program obtained by updating the first current program; as well as The second control device activates a second update program based on a condition that the trigger signal is received from the first control device. The second update program is a program obtained by updating the second current program.

Citation Information

Patent Citations

  • Electronic control device, electronic control system for vehicle, and data structure of specification data

    JP2020027666A

  • Vehicle-mounted program writing device

    CN106414178A

  • Onboard power supply system, relay box, and relay control device

    CN108602474A