Control device
By detecting the abnormality of the control unit in the control device and selecting other control units whose safety status and control status meet the requirements to continue executing the software function, the problem of not considering the safety status of the control unit in the existing technology is solved, and normal operation can be continued under abnormal conditions.
Patent Information
- Application Number
- CN202080106936.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-19
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2040-11-19
AI Technical Summary
When overwriting the software of a control unit to the storage area of another control unit, the prior art does not consider the security status of the target control unit to be overwritten by the software, which may result in improper actions or the software not being executed as intended.
A control device is designed in which multiple control units are connected through a communication path. The control device can detect abnormalities in other control units. When an abnormality is detected, the management unit and the switching processing unit select other control units whose safety status and control status meet the requirements to continue executing the software functions of the abnormal control unit.
This ensures that when an abnormality occurs in the control unit, the planned actions can continue to be executed according to specifications, ensuring the safety and normal operation of the vehicle and avoiding improper output caused by security attacks.
Smart Images

Figure CN116438523B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to a control device. Background Art
[0002] Vehicles are equipped with multiple electronic control units (ECUs), interconnected via an in-vehicle network (IVI). These ECUs function as a coordinated control system. Therefore, security attacks via the IVI network can lead to unauthorized access to the IVI network, disguising control units as other devices, or tampering with their programs, potentially causing problems with vehicle driving control.
[0003] Meanwhile, conventionally, there are technologies that simplify vehicle functions or switch operations in order to continue the operation of the control device with the minimum functions required for vehicle travel even when a control unit malfunctions.
[0004] Patent Document 1 discloses a control device that, when an abnormality occurs in an arithmetic unit of a control unit, reads software for reconfiguring the functions related to the operation of the abnormal control unit from a storage unit and overwrites the software with the storage area of another control unit. According to Patent Document 1, when an abnormality occurs in a control unit, the device refers to first priority information set for the software and overwrites the software for reconfiguring the functions related to the operation of the monitored control unit with the storage area of the control unit storing other software with a lower priority level set in the first priority information.
[0005] Prior art literature
[0006] Patent Literature
[0007] Patent Document 1: Japanese Patent Application Laid-Open No. 2020-8950 Summary of the Invention
[0008] Technical problem to be solved by the invention
[0009] However, the conventional control device disclosed in Patent Document 1 does not consider the security status of the control unit that the software is overwriting when overwriting the software for reconstructing the functions related to the operation of the control unit of the monitored object into the storage area of another control unit. Therefore, if the control unit that the software is overwriting does not take into account security measures such as impersonation or tampering with other objects, it is possible that improper actions such as outputting improper output values due to security attacks may be performed. In addition, the conventional control device disclosed in Patent Document 1 does not consider the control status of the control unit that the software is overwriting. Therefore, if the software is overwritten into a control unit that does not meet the software's operational requirements, the software may not perform a predetermined action.
[0010] The present application discloses a technology for solving the above-mentioned problem, and its object is to provide a control device that enables other control units to continue to perform predetermined actions of a control unit where an abnormality occurs in accordance with specifications.
[0011] Technical means for solving technical problems
[0012] The control device disclosed in the present application includes a plurality of control units connected in a manner capable of communicating with each other via a communication path. The control device is configured to, when an abnormality is detected in any of the plurality of control units, cause at least a portion of the functions of the software of the control unit that detected the abnormality to continue to be executed by another control unit different from the control unit that detected the abnormality. The control device is characterized in that
[0013] Each of the plurality of control units comprises:
[0014] a communication unit configured to send and receive messages to and from other control units via the communication path;
[0015] a detection unit configured to detect an abnormality of the other control unit based on a message received by the communication unit from the other control unit;
[0016] A management department, which manages the security status and control status of the control unit to which it belongs;
[0017] a determination unit that, when the detection unit detects an abnormality in the other control unit, determines whether it is necessary to continue to execute at least part of the functions of the software executed by the other control unit that detected the abnormality by another control unit other than the other control unit that detected the abnormality; and
[0018] A switching processing unit that selects a control unit that continues to execute at least a part of the functions of the software based on the action requirements of the software of the other control units that detect the abnormality and at least one of the safety status and the control status of other control units other than the other control units that detect the abnormality, when the determination unit determines that there is a need to continue the execution.
[0019] Effects of the Invention
[0020] According to the control device disclosed in the present application, it is possible to obtain a control device that enables other control units to continue to execute predetermined operations of a control unit in which an abnormality has occurred in accordance with specifications. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 This is a block diagram showing the configuration of the control device according to the first embodiment.
[0022] Figure 2A This is a flowchart showing the operation of the control device according to the first embodiment.
[0023] Figure 2B This is a flowchart showing a process of selecting a control unit in the control device according to the first embodiment.
[0024] Figure 3 This is an explanatory diagram showing the structure of data in a storage unit of a storage device in the control device according to the first embodiment.
[0025] Figure 4A This is an explanatory diagram showing the structure of a data frame of a message in the control device according to the first embodiment.
[0026] Figure 4B This is an explanatory diagram showing an example of an abnormality message in the control device according to the first embodiment.
[0027] Figure 5 This is an explanatory diagram showing a data structure of a management unit of a control unit in the control device according to the first embodiment.
[0028] Figure 6 This is a block diagram showing the configuration of a control device according to the third embodiment.
[0029] Figure 7A This is a flowchart showing the operation of the control device according to the third embodiment.
[0030] Figure 7B This is a flowchart showing a software switching process in the control device according to the third embodiment.
[0031] Figure 8 This is an explanatory diagram showing an example of vehicle information indicating the state of the surrounding environment of the vehicle in the control device according to the third embodiment. DETAILED DESCRIPTION
[0032] Implementation method 1.
[0033] Next, the control device according to the first embodiment will be described with reference to the drawings. Figure 1 : is a block diagram showing the structure of the control device involved in embodiment 1. Figure 1In the embodiment, the control device mounted on the vehicle 100 includes a storage device 300, a first control unit 400, a second control unit 420, a third control unit 440, and a fourth control unit 460. The first control unit 400, the second control unit 420, the third control unit 440, and the fourth control unit 460 belong to a group of the driving system 101 of the vehicle 100, and each includes a CPU (Central Processing Unit). For example, they are configured to function as an engine control unit, a steering control unit, etc., and perform different control functions.
[0034] The storage device 300 , the first control unit 400 , the second control unit 420 , the third control unit 440 and the fourth control unit 460 are respectively connected to a communication path 200 formed by a CAN (Controller Area Network) and can communicate with each other via the communication path 200 and with other control units not shown.
[0035] A processing unit 407 is provided in the first control unit 400, and a processing unit 427 is provided in the second control unit 420. Similar processing units (not shown) are also provided in the third control unit 440 and the fourth control unit 460. Processing units 407 and 427 can control systems and various devices within vehicle 100 by executing software stored in their respective control units.
[0036] For messages containing abnormal contents of the first control unit 400, the second control unit 420, the third control unit 440, and the fourth control unit 460 (hereinafter referred to as abnormal messages), any control unit that initially receives the abnormal message sends a response message to the communication path 200, thereby preventing control units other than the control unit that initially receives the abnormal message from performing the same processing.
[0037] For example, when the first control unit 400 initially receives an exception message from the second control unit 420, the first control unit 400 sends a response message to the communication path 200 and performs the processing described later on the received exception message, while the third control unit 440 and the fourth control unit 460 that receive the response message from the first control unit 400 do not process the received exception message even if they receive the exception message from the second control unit 420.
[0038] First control unit 400 includes a communication unit 401, a detection unit 402, a determination unit 403, a storage unit 404, a management unit 405, a switching unit 406, and a calculation unit 407. Storage unit 404 of first control unit 400 stores software 1a and software 2a. Management unit 405 manages the security status 408 and control status 409 of first control unit 400 to which it belongs.
[0039] Second control unit 420 includes a communication unit 421, a detection unit 422, a determination unit 423, a storage unit 424, a management unit 425, a switching unit 426, and a calculation unit 427. Software 3a and software 4a are stored in storage unit 424 of second control unit 420. Management unit 425 manages the security status 428 and control status 429 of second control unit 420 to which it belongs.
[0040] Similarly, third control unit 440 and fourth control unit 460 include a communication unit, a detection unit, a determination unit, a storage unit, a management unit, a switching unit, and an arithmetic processing unit (none of which are shown in the figure). The storage unit stores multiple software programs. The management unit manages the security status and control status of third control unit 440 and fourth control unit 460, respectively.
[0041] The storage device 300 includes a communication unit 301 and a storage unit 302. The communication unit 301 transmits and receives data between the first control unit 400, the second control unit 420, the third control unit 440, and the fourth control unit 460 via the communication path 200. The storage unit 302 pre-stores software to be executed by the first control unit 400, the second control unit 420, the third control unit 440, and the fourth control unit 460 connected to the communication path 200, and the operating requirements of each software.
[0042] For example, storage unit 302 stores software 3b, which simplifies the functionality of software 3a in second control unit 420. Software 3b also stores control status and security status as operational requirements. The control status of software 3b might indicate, for example, that the CPU clock is 100 MHz and that 150 KB of free memory is required. The security status of software 3b might indicate, for example, that the ID (identification) stored in the HSM (Hardware Security Module) requires a key of "2000."
[0043] Furthermore, the storage unit 302 stores software 1b, which simplifies the functionality of software 1a of the first control unit 400, and software 2b, which simplifies the functionality of software 2a. Furthermore, the same control states and safety states as described above are also stored as operational requirements for each of these software 1b and 2b. Furthermore, the storage unit 302 also stores software (not shown) that simplifies the functionality of software 4a of the second control unit 420; software (not shown) that simplifies the functionality of the software of the third control unit 440 and the fourth control unit 460 (not shown); and the same control states and safety states as described above as operational requirements for these simplified software.
[0044] The communication unit 401 of the first control unit 400, the communication unit 421 of the second control unit 420, the communication unit (not shown) of the third control unit 440, the communication unit (not shown) of the fourth control unit 460, and the communication unit 301 of the storage device 300 can send and receive data to each other via the communication path 200 which is CAN.
[0045] Next, a more detailed description will be given of the control device according to Embodiment 1. First, the structure of a message transmitted to the communication path 200 which is the CAN will be described. Figure 4A 1 is an explanatory diagram showing the structure of a data frame of a message in the control device according to the first embodiment. Figure 4A As shown, the structure of the CAN frame consists of SOF (Start Of Frame), ID (Identification Key), RTR (Remote Transmission Request BIT), Control Field, CRC Sequence (Cyclic Redundancy Check Sequence), CRC Delimiter (Cyclic Redundancy Check Delimiter), ACK Time Slot (Acknowledgement Slot), ACK Delimiter (Acknowledgement Delimiter), and EOF (End Of File).
[0046] In the following description, as an example, a case where the first control unit 400 receives a message from the second control unit 420 via the communication path 200 is described. Figure 1In the embodiment of the present invention, upon receiving a message from the second control unit 420, the communication unit 401 of the first control unit 400 transmits the received message to the detection unit 402. The detection unit 402 determines whether there is an abnormality in the second control unit 420 based on the message received from the communication unit 401. If the result of the determination is that the received message is abnormal, the detection unit 402 transmits abnormality information of the second control unit 420 and information about the control device of the operation continuation target to the determination unit 403.
[0047] Here, a configuration will be described in which the message received by the first control unit 400 from the second control unit 420 is an abnormality message indicating an abnormality in the second control unit 420 . Figure 4B This diagram illustrates an example of an abnormality message in the control device according to Embodiment 1. When the CAN frame ID is "0x108," it indicates a data content abnormality and is given the highest priority. When the data field is "0xB11" for the ID "0x108," the software's operation continuation target is the group of the travel system 101, and the abnormality indicates a brake sensor voltage abnormality.
[0048] For example, when the communication unit 401 receives a message from the second control unit 420 with an ID of "0x108" indicating an abnormality and a data field of "0xB11," the detection unit 402 transmits the abnormality details and candidate information about the control unit to which the operation should be continued to be applied to the determination unit 403. If the detection unit 402 receives multiple messages with IDs indicating abnormalities from the communication unit 401, the detection unit 402 begins processing the message with the smaller ID value first, and then begins processing the message with the lower priority after processing the message with the smaller ID value is completed.
[0049] The determination unit 403 receives the abnormality details and candidate information about the control unit to which the operation should be continued from the detection unit 402, and transmits the candidate information about the control unit to which the operation should be continued, along with a software switching request signal, to the management unit 405 and the switching processing unit 406. Here, the software switching request is a signal that triggers the start of processing by the management unit 405 and the switching processing unit 406.
[0050] The storage unit 404 stores software executed by the arithmetic processing unit 407. The difference between the storage unit 302 in the storage device 300 and the storage unit 404 in the first control unit 400 is that the storage unit 302 stores a plurality of software programs executed by the arithmetic processing units of the control units 400, 420, 440, and 460, while the storage unit 404 stores only software required for control by the first control unit 400.
[0051] For example, the storage unit 404 of the first control unit 400 stores software 1a and software 2a for controlling the vehicle's steering system by the first control unit 400, and the storage unit 302 of the storage device 300 stores software 1b, 2b, 3b, 11b, and 12b, which simplify the functions of the software of the respective control units 400, 420, 440, and 460. Software 1b, 2b, and 3b belong to the group of the travel system 101 of the vehicle 100, while software 11b and 12b belong to the group of the body system (not shown) of the vehicle 100.
[0052] The management unit 405 manages the security status and control status of the first control unit 400. The second control unit 420, the third control unit 440, and the fourth control unit 460 also have their own security status and control status managed by their own management units.
[0053] Here, the structure of the data on the security status and control status of the control unit to which each control unit belongs, which is managed by the management unit of each control unit, will be described in detail. Figure 5 This is an explanatory diagram showing the data structure of the management unit of the control unit in the control device according to the first embodiment. Figure 5 In the example, the security status and control status of the first control unit 400, the third control unit 440, and the fourth control unit 460 belonging to the group of the driving system 101 are indicated. For example, the first control unit 400 is in a control state requiring a CPU clock of 120 [MHz] and free memory of 90 [KB]. As a security state, it indicates that the key ID is not held (invalid) and the HSM is invalid.
[0054] The third control unit 440 is in a control state requiring a CPU clock of 200 MHz and 200 KB of free memory. As a security state, the key ID is "2000," and the HSM is enabled. Furthermore, the fourth control unit 460 is in a control state requiring a CPU clock of 120 MHz and 80 KB of free memory. As a security state, the key ID is "2001," indicating that the HSM is enabled.
[0055] The management unit 405 of the first control unit 400 receives the software switching request signal from the determination unit 403 , and as described later, obtains the control status and security status of control units other than the first control unit 400 to which it belongs.
[0056] Next, an example will be described in detail in which the management unit 405 of the first control unit 400 acquires the safety status and control status of the third control unit 440, a control unit other than the first control unit 400 to which it belongs. For example, it is assumed that candidate information for a control unit to which the operation of the abnormal second control unit 420 should be continued includes the first control unit 400, the third control unit 440, and the fourth control unit 460, which belong to the group of the driving system 101. When the management unit 405 receives a software switching request signal and candidate information for a control unit to which the operation should be continued from the determination unit 403, it begins acquiring the control status and safety status of the third control unit 440 based on the candidate information for the control unit to which the operation should be continued.
[0057] First, management unit 405 of first control unit 400 generates a status request message and transmits it to communication path 200 via communication unit 401. Here, the status request message is the message with ID "700" in Embodiment 1. Next, the communication unit (not shown) of third control unit 440 receives the status request message transmitted by first control unit 400. The communication unit (not shown) then receives the security status and control status of third control unit 440 from the management unit (not shown) of third control unit 440 and transmits it to communication path 200.
[0058] Similar to the third control unit, the communication unit (not shown) of the fourth control unit 460 receives the status request message sent by the first control unit 400. The communication unit (not shown) then transmits the security status and control status of the fourth control unit 460 from the management unit (not shown) of the fourth control unit 460 to the receiving communication path 200. Finally, the communication unit 401 of the first control unit 400 receives the security status and control status of the third control unit 440 and the security status and control status of the fourth control unit 460 sent by the third control unit 440, and transmits them to the management unit 405.
[0059] The control state described above indicates the processing status of each control unit 400, 420, 440, and 460 connected to the communication path 200 and is used as a factor for selecting a control unit to continue the operation of the switching processing unit 406. By considering the control state when selecting a control unit, it is possible to compare the processing load of the current control unit with the operating requirements of the overlay software, thereby achieving the following effect: a control unit can be selected that can operate the overlay software according to the design specifications.
[0060] For example, the control state is represented by the control unit's CPU clock frequency and memory usage. Specifically, the switching processing unit 406 refers the control state of the third control unit 440 to the management unit 405, and can obtain the result that the CPU clock frequency of the arithmetic processing unit of the third control unit 440 is 200 [MHz] and the free memory is 200 [KB].
[0061] The security status described above indicates the setting status of the security functions of each control unit 400, 420, 440, and 460 connected to the communication path 200. Similar to the control status, it is used as a factor for selecting a control unit for the switching processing unit 406 to continue operating. By selecting a control unit in consideration of the security status, software can be executed in a control unit that has the minimum security functions required for each software. This allows the selection of a control unit with a lower risk of impersonation or tampering, as described above.
[0062] For example, as described above, the security status indicates the effective state when the control unit includes an HSM and the key ID stored in the control unit. Specifically, the switching processing unit 406 refers to the security status of the third control unit 440 in the management unit 405, and the third control unit 440 can obtain the result that the key ID stored in the HSM remains "2000".
[0063] The switching processing unit 406 receives the software switching request signal from the determination unit 403 and selects a control unit to be the target of continuing the operation of the software 3 a executed by the second control unit 420 determined to be abnormal.
[0064] Next, a description will be given of a case where, based on the control state and safety state, a control unit is selected to operate software 3b obtained by simplifying the functions of software 3a of second control unit 420. As described above, software 3b is stored in storage unit 302 of storage device 300.
[0065] Here, the structure of data stored in the storage unit 302 of the storage device 300 will be described. Figure 3 This is an explanatory diagram showing the structure of data in the storage unit of the storage device in the control device according to Embodiment 1. As described above, the storage unit 302 of the storage device 300 stores a plurality of software programs obtained by simplifying the software programs executed by the arithmetic processing units in the control units 400, 420, 440, and 460. Figure 3 In the illustrated example, the storage unit 302 stores software with software IDs 1b, 2b, and 3b as software for the travel system 101 group, and stores software with software IDs 11b and 12b as software for the body system group.
[0066] In these software, the software ID is associated with the CPU clock (MHz), free memory (KB), whether an HSM is required (valid or invalid), and whether a key is required (key ID if required) as operational requirements. When acquiring software information, the switching processing unit 406 of the first control unit 400 inputs the software ID to the storage device 300, which then outputs the software operational requirements from the storage unit 302.
[0067] For example, when the switching processing unit 406 of the first control unit 400 sends a message containing the software ID "1b" to the storage device 300, the switching processing unit 406 can obtain the software data of the software ID "1b" and the action requirements such as "CPU clock is 80 [MHz], free memory is 50 [KB], HSM is required (valid), key ID is not required (invalid)" from the storage unit 302 of the storage device 300.
[0068] Now, let's return to the description of the process of selecting a control unit to operate software 3b. First, upon receiving the software switch request signal from determination unit 403, switching processing unit 406 of first control unit 400 receives the safety status and control status of the control units in the group of driving system 101 from management unit 405, since the candidate information for the control unit to continue operation is the group of the vehicle's driving system 101. Next, switching processing unit 406 receives the operating requirements of software 3b from storage device 300.
[0069] Next, the switching processing unit 406 selects a control unit to execute the software 3b based on the control state and the safety state from the control units in the group of the driving system 101. Specifically, the control unit to execute the software 3b is selected as follows.
[0070] First, in the first selection, the switching processing unit 406 compares the action requirements of software 3b with the action status and safety status of the first control unit 400. At this time, the CPU clock is compared first. For the action requirements of software 3b, the CPU clock is 100 [MHz], while the CPU clock of the first control unit 400 is 120 [MHz], which meets the requirements. Next, the memory is compared. The action requirements of software 3b require 150 [KB] of free memory, while the free memory of the first control unit 400 is 90 [KB], which does not meet the requirements. Therefore, since the first control unit 400 has an item that does not meet the requirements of software 3b, it is excluded from the action continuation target. The switching processing unit 406 transfers to the selection of the next control unit, that is, the second selection.
[0071] In the second selection, the switching processing unit 406 compares the operational requirements of software 3b with the control state and safety status of the third control unit 440. The comparison items are the same as those for the first selection. First, when comparing the CPU clocks, software 3b's CPU clock is 100 MHz, while the third control unit 440's CPU clock is 200 MHz, meeting the requirements. Next, when comparing the memory, software 3b requires 150 KB, while the third control unit 440 has 200 KB of free space, meeting the requirements for the control unit to continue operation.
[0072] Next, when comparing the HSM information, software 3b requires the HSM information to be valid. Since third control unit 440's HSM information is valid, it meets the requirements for being the target control unit for the action to be continued. Finally, when comparing the key information, software 3b needs to store the key ID 2000 in the HSM. Since third control unit 440 maintains the key ID 2000 in the HSM, it meets the requirements for being the target control unit for the action to be continued. Therefore, since third control unit 440 meets all the operational requirements of software 3b, switching processing unit 406 selects third control unit 440 as the target control unit for the action to be continued. Since control unit 440 was determined as the target control unit for the action to be continued in the second selection, control unit 460 is also selected, but the third selection is not made.
[0073] Next, the switching processing unit 406 transmits a software update request to the communication unit 401. Here, the software update request is a message instructing the third control unit 440 to overwrite the software in the storage unit (not shown) of the third control unit 440. The switching processing unit 406 of the first control unit 400 transmits a message indicating the software update request, with an ID of "780" and a data field of "0x403," to the communication path 200 via the communication unit 401.
[0074] Communication unit 301 of storage device 300 receives the software update request via communication path 200 and transfers software 3b from storage unit 302 to communication unit 301. Communication unit 301 then transmits software 3b to communication path 200. Third control unit 440 receives the software update request sent by first control unit 400. Based on the ID, third control unit 440 determines whether it is a software update request or a request addressed to itself from the data field. It then overwrites the received software 3b in its storage unit.
[0075] The calculation processing unit 407 operates the systems and devices included in the vehicle by transmitting output values resulting from the execution of the software 1 a and the software 2 a to the communication path 200 .
[0076] Next, the operation of the control device according to the first embodiment will be collectively described using a flowchart. Figure 2A This is a flowchart showing the operation of the control device according to the first embodiment. Figure 2A In step S201, the communication unit 401 receives a message from the second control unit 420 via the communication path 200. In step S202, the communication unit 401 transfers the received message to the detection unit 402, and the process proceeds to step S203.
[0077] In step S203, the detection unit 402 determines whether there is an abnormality in the second control unit 420 based on the received message. If it is determined to be abnormal (Yes), the process proceeds to step S204, and the detection unit 402 transmits the abnormality information and the information of the control device to be continued to the determination unit 403. In step S205, the determination unit 403 transmits the software switching request and the candidate information of the control unit to be continued to the management unit 405 and the switching processing unit 406, and the process proceeds to step S206.
[0078] In step S206, the management unit 405 collects the safety status and control status from the third control unit 440 and the fourth control unit 460. Next, in step S207, the switching processing unit 406 receives the software switching request signal from the determination unit 403 and selects a control unit to be the target for continuing the operation of the software 3a executed by the second control unit 420 that has been determined to be abnormal, as described above.
[0079] Next, in step S208, the switching processing unit 406 transmits the software update request to the communication unit 401. In step S209, the communication unit 401 transmits the software update request to the communication path 200. The process proceeds to step S210, and the communication unit 301 in the storage device 300 receives the software update request. The process then proceeds to step S211, where the storage unit 302 transmits software 3b, which is obtained by simplifying the functions of the software 3a of the faulty second control unit 420. In step S212, the communication unit 301 transmits software 3b to the communication path 200.
[0080] Figure 2B This is a flowchart showing the selection process of the control unit in the control device according to the first embodiment, and collectively shows the selection operation of the control unit. Figure 2B In step S213, the first control unit 400 obtains the software 3b action requirements from the storage device 300, and then in step S214, the switching processing unit 406 of the first control unit 400 receives the control status and security status of the first control unit 400 from the management unit 405, and proceeds to step S215.
[0081] In step S215, the switching processing unit 406 determines whether the control state of the first control unit 400 to which it belongs meets the control state requirements of software 3b. If the control state of the first control unit 400 meets the control state requirements of software 3b (yes), the process proceeds to step S216 to determine whether the safety state of the first control unit 400 meets the safety state requirements of software 3b. If the result of the determination in step S216 is that the safety state of the first control unit 400 meets the safety state requirements of software 3b (yes), the process proceeds to step S217 to determine the first control unit 400 as the control unit to which the operation of the abnormal second control unit 420 shall continue.
[0082] On the other hand, if the result of determination in step S215 is that the control state of the first control unit 400 does not meet the control state requirements of the software 3b (No), the process proceeds to step S218, where the control state and security state of the third control unit 440 are received from the management unit 405. The process then returns to step S215, where the switching processing unit 406 determines whether the control state of the third control unit 440 meets the control state requirements of the software 3b. If the result of this determination is that the control state of the third control unit 440 meets the control state requirements of the software 3b (Yes), the process proceeds to step S216, where a determination is made as to whether the security state of the third control unit 440 meets the security state requirements of the software 3b.
[0083] If the result of determination in step S216 is that the safety state of the third control unit 440 satisfies the safety state requirement of the software 3b (Yes), the process proceeds to step S217 and the third control unit 440 is determined as the control unit to which the operation of the abnormal second control unit 420 is to be continued.
[0084] In addition, if the result of determination in step S216 is that the safety status of the third control unit 440 does not meet the safety status requirements of software 3b (No), then proceed to step S218, receive the control status and safety status of the fourth control unit 460 from the management unit 405, return to step S215, and the switching processing unit 406 determines whether the control status of the fourth control unit 460 meets the control status requirements of software 3b. Thereafter, by repeating the same processing as above, a candidate control unit is selected that meets the control status requirements of software 3b, and the action of the abnormal second control unit 420 is determined to be the target control unit.
[0085] In the control device involved in the first embodiment described above, as a security state, generally as a countermeasure against data tampering or impersonation, whether the key ID required for the installed message authentication can be used and whether the key ID is stored in the HSM are used in the selection of the control unit, but not limited to this. For example, whether the control unit has a memory monitoring function can also be used as a tampering detection function in the selection of the control unit.
[0086] In the control device according to Embodiment 1, if the control unit is attacked by a security attack, the vehicle cannot be properly controlled. Therefore, the setting status of the security functions of both the software and the control unit is checked. As described above, if the second control unit 420 executes software 3a and includes a function for authenticating messages between the first control unit 400 and the second control unit 420, the key ID used by the second control unit 420 for message authentication is required in order to execute software 3a or software 3b in a control unit other than the second control unit 420.
[0087] In the control device according to the first embodiment, the CPU clock rate and the memory usage rate are used as the control status. However, the present invention is not limited thereto and may also include software priority and software simplification status.
[0088] In the control device according to the first embodiment, candidates for the control unit to be continued are control units belonging to the same functional group. However, the present invention is not limited thereto and control units may be classified according to ASIL (Automotive Safety Integrity Level) and the ASIL level may be used.
[0089] Furthermore, in the control device according to the first embodiment, the storage unit 302 of the storage device 300 stores software obtained by simplifying the software held in the storage unit of each control unit, but may also store software before simplification.
[0090] Furthermore, in the control device according to the first embodiment, the storage device 300 is provided inside the vehicle 100 . However, the present invention is not limited thereto, and the storage device 300 may be provided outside the vehicle to perform wireless communication with the vehicle.
[0091] In addition, in the control device involved in embodiment 1, the communication path 200 is composed of CAN, but is not limited to this. Other networks such as CAN FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), and in-vehicle network (FlexRay) can also be used.
[0092] Implementation method 2.
[0093] Next, the control device according to the second embodiment will be described. Figure 1 The structure of the control device of Embodiment 1 is the same as that of the control device of Embodiment 1 shown in the figure. The following description focuses on the differences between the control device of Embodiment 2 and Embodiment 1. The control device of Embodiment 2 differs from the control device of Embodiment 1 in that the second control unit 420 itself performs a series of processes from detecting an abnormality in the second control unit 420 to selecting a control unit to continue the operation. In other words, the control unit itself performs a series of processes from detecting an abnormality in the control unit to selecting a control unit to continue the operation, which is different from the control device of Embodiment 1.
[0094] In the control device according to the first embodiment, for example, the first control unit 400 receives a message from the second control unit 420 to detect an abnormality in the second control unit 420. However, in the control device according to the second embodiment, for example, the second control unit 420 detects an abnormality in itself. As a method for the detection unit 422 of the second control unit 420 to detect an abnormality in the second control unit 420 itself, for example, when the output value of the software 3a deviates from a normal value, the detection unit 422 detects that an abnormality has occurred in the software 3a of the second control unit 420.
[0095] The operations after the detection unit 422 detects that the software 3a of the second control unit 420 has an abnormality, from the determination unit 423's determination of whether to continue the operation to the sending of a software update request to the third control unit 440, are the same as those of the control device according to Embodiment 1. The control device according to Embodiment 2 can achieve the same effects as those of Embodiment 1.
[0096] Implementation method 3.
[0097] Next, the control device according to Embodiment 3 will be described. The multiple control units can be grouped by functions such as steering and braking systems, as long as they are part of the vehicle's driving system. For body systems, they can be grouped by functions such as headlights and wipers. In the control device according to Embodiment 3, the multiple control units are grouped according to predetermined functions, and control is performed by managing the control units in these groups.
[0098] In the control device involved in embodiment 3, for example, the first control unit periodically obtains the safety status, control status and software execution status from multiple other control units managed by the first control unit, and the first control unit detects abnormalities in other control units under management and continues the operation of the control unit in which the abnormality is detected.
[0099] In the control device according to the third embodiment, the first control unit and Figure 1 The first embodiment shown has two structural differences. The first difference is that the control device according to the third embodiment includes a storage unit within the control unit, which serves as a memory device, unlike the storage unit provided externally in the first embodiment. The second difference is that the management unit configured as the control unit in the third embodiment also manages the vehicle status. The following description of the third embodiment will focus primarily on the differences from the first embodiment.
[0100] Figure 6 : is a block diagram showing the structure of the control device involved in the third embodiment. Figure 6 In the embodiment of the present invention, various sensors (not shown) included in vehicle 100 periodically acquire vehicle status 410 and 510, and transmit each of these to communication paths 200 and 210, which are CANs. Communication paths 200 and 210 are interconnected. All control units included in vehicle 100 periodically transmit the control status and safety status maintained by their own management units to communication paths 200 and 210.
[0101] The first control unit 400, the second control unit 420, the third control unit 440, and the fourth control unit 460 are connected to the communication path 200, which is a CAN. The fifth control unit 500, the sixth control unit 520, and the seventh control unit 540 are connected to the communication path 210, which is also a CAN. The fifth control unit 500 includes a communication unit 501, a detection unit 502, a determination unit 503, a switching unit 506, a storage unit 504, and a management unit 505. The sixth control unit 520 includes a communication unit 521, a detection unit 522, a determination unit 523, a switching unit 526, a calculation unit 527, a storage unit 524, and a management unit 525. The storage unit 504 includes software 11b and software 12b. Furthermore, the storage unit 524 includes software 11a and software 12a. Software 11b and software 12b are simplified versions of software 11a and software 12a, respectively.
[0102] Furthermore, the management unit 505 includes a control state 509, a safety state 508, and a vehicle state 510, while the management unit 525 includes a control state 529 and a safety state 528. The second control unit 420, the third control unit 440, and the fourth control unit 460 are control units for the driving system 101 of the vehicle 100, controlling the steering system, the brakes, and other functions. The sixth control unit 520 and the seventh control unit 540 are control units for the body system 102 of the vehicle 100, controlling the headlights, wipers, and other functions. The structure and function of the sixth control unit 520 and the seventh control unit 540 are similar to those of the second control unit 420, the third control unit 440, and the fourth control unit 460.
[0103] The first control unit 400 manages the control states, safety status, and software execution of the second control unit 420, third control unit 440, and fourth control unit 460, which belong to the group of the travel system 101. The vehicle 100 includes only one control unit in each functional group that has the same functions as the first control unit 400. Here, the fifth control unit 500 belongs to the group of the body system 102 and has the same functions as the first control unit 400. It manages the control states, safety status, and software execution of the sixth control unit 520 and seventh control unit 540, which belong to the body system 102.
[0104] The detection unit 402 analyzes the acquisition status and message content of the second control unit 420 message received by the communication unit 401. If the acquired message contains the normal security status 428 or normal control status 429 of the second control unit 420, the detection unit 402 transmits the message from the second control unit 420 to the management unit 405. Otherwise, the detection unit 402 detects whether an abnormality has occurred in the second control unit 420. For example, if the detection unit 402 has not received a message containing the output result of the software 2a of the second control unit 420 within 10 [ms] from the last reception, the detection unit 402 determines that an abnormality has occurred in the second control unit 420 and transmits the details of the abnormality to the determination unit 403.
[0105] Based on the abnormality details received from detection unit 402, determination unit 403 determines whether the operation of software 2a in second control unit 420 needs to be continued in a control unit different from second control unit 420. Here, if the abnormality details received from detection unit 402 by determination unit 403 are "detection unit 402 failed to receive a message containing the output result of software 2a in second control unit 420 within 10 milliseconds from the last reception," and if the abnormality details are received from detection unit 402 five times in a row, determination unit 403 determines that software 2a needs to be continued in another control unit. If determination unit 403 determines that software 2a needs to be continued in another control unit, it transmits a software switching request signal to switching processing unit 406.
[0106] The storage unit 404 stores simplified software executed by the control units 424, 440, and 460 of the group of the travel system 101 managed by the first control unit 400. Figure 6 , only software 1b and software 2b are described, which are software obtained by simplifying the software 1a and software 2a held in the storage unit 424 of the second control unit 420, respectively.
[0107] Management unit 405 manages vehicle status 410 of vehicle 100 received by communication unit 401, as well as the control and safety status of second control unit 420, third control unit 440, and fourth control unit 460. Vehicle status 410 refers to the real-time status of the vehicle 100's surroundings. For example, vehicle status 410 may indicate whether the vehicle is traveling at a high speed, traveling at a low speed, or stopped. Furthermore, surrounding status may indicate whether it is daytime or nighttime. Furthermore, traffic status may indicate whether the vehicle is congested. Specifically, vehicle status 410 can be used to determine, for example, whether the vehicle 100 is traveling at a low speed, during the day, or in traffic.
[0108] Switching processing unit 406 analyzes vehicle state 410, determines candidates for the group to which the control unit to continue operation belongs, and then selects a control unit belonging to the determined group. Specifically, upon receiving a software switching request signal, switching processing unit 406 first determines, based on vehicle state 410 stored by management unit 405, candidates for the functional group of control units to continue operation, namely, software 1b, which is a simplified version of software 1a. For example, if vehicle state 410 is "low speed, daytime, congested," control units belonging to body system 102 are selected as candidates.
[0109] Next, the switching processing unit 406 checks whether the management unit 405 holds the control status and safety status of the sixth control unit 520 and the seventh control unit 540, which are control units belonging to the group of the vehicle body system 102. If so, the process shifts to the control unit selection process. If not, the switching processing unit 406 sends a status request message to the fifth control unit 500 to collect the control status and safety status of the sixth control unit 520 and the seventh control unit 540 from the fifth control unit 500. The process related to selecting the control unit for which the software 1b is to continue operating is the same as that in the first embodiment described above.
[0110] When the seventh control unit 540 is determined as the control unit to continue the operation of the software 1b as a result of selecting the control unit to continue the operation of the software 1b, the first control unit 400 transmits a software update request and the data of the software 1b to the fifth control unit 500. Based on the software update request, the fifth control unit 500 starts overwriting (writing) the software 1b into the storage unit 524 of the seventh control unit 540.
[0111] Next, the operation of the control device according to the third embodiment will be described based on a flowchart. Figure 7A is a flowchart showing the operation of the control device according to the third embodiment. Figure 7B This is a flowchart showing a software switching process in the control device according to the third embodiment, and collectively shows an example of the operation.
[0112] exist Figure 7A In step S701, the communication unit 401 of the first control unit 400 receives a message from the second control unit 420. In step S702, the communication unit 401 transmits the message received by the communication unit 401 to the detection unit 402. Next, in step S703, the detection unit 402 determines whether the received message indicates an abnormality. If the message indicates an abnormality (Yes), the process proceeds to step S704. If the message does not indicate an abnormality (No), the process proceeds to step S710. When the process proceeds to step S710, the detection unit 402 transmits the security status and control status of the second control unit 420 to the management unit 405 and returns to step S701.
[0113] On the other hand, when proceeding from step S703 to step S704, the detection unit 402 analyzes the message, and in step S705, determines whether an abnormality of the second control unit 420 is detected from the received message. If it is determined that an abnormality is detected (yes), proceed to step S706; if no abnormality is detected (no), return to step S701.
[0114] When proceeding from step S705 to step S706, the detection unit 402 sends a message containing abnormality information of the second control unit 420 to the determination unit 403, and then proceeds to step S707. In step S707, the determination unit 403 analyzes the sent message and determines in step S708 whether the software of the second control unit 420 needs to continue to operate. If it is determined that it is not necessary to continue to operate (No), the process returns to step S701. If it is determined that it is necessary to continue to operate (Yes), the process proceeds to step S709.
[0115] When the process proceeds to step S709, determination unit 403 sends a software switching request to switching processing unit 406, and the process proceeds to step S711. In step S711, switching processing unit 406 receives the software switching request from determination unit 403, and in step S712, proceeds to the process of determining a control unit group for which the operation of software 1b should continue. For example, as described above, when vehicle state 410 is "low speed driving, daytime, congested," control units belonging to body system 102 are selected as candidates.
[0116] Next, in step S713, the switching processing unit 406 determines whether the fifth control unit 500, among the control units belonging to the vehicle body system 102, maintains the control state and safety status of the sixth control unit 520 and the seventh control unit 540. If not (No), the process proceeds to step S714, where the switching processing unit 406 sends a status request message to the fifth control unit 500. Next, in step S715, the management unit 405 obtains the control state and safety status of the sixth control unit 520 and the seventh control unit 540, and the process proceeds to step S716. On the other hand, if the result of the determination in step S713 is that the fifth control unit 500 maintains the control state and safety status of the sixth control unit 520 and the seventh control unit 540 (Yes), the process proceeds to step S716.
[0117] In step S716, the switching processing unit 406 begins executing the software switching process. In step S717, it sends a software update request to the communication unit 401. Next, in step S718, the switching processing unit 406 instructs the storage unit 404 to transmit the software 1b. In step S719, the storage unit 404 transmits the software 1b to the communication unit 401. In step S720, the communication unit 401 transmits the software 1b and the software update request to the communication path 200, overwriting the software 1b in the storage unit 504 of the fifth control unit 500.
[0118] Next, in the software switching process Figure 7BIn step S721, the switching processing unit 506 of the fifth control unit 500 reads the software 1b and the operating requirements from the storage unit 504. In step S722, the switching processing unit 506 reads the control state and security state of the sixth control unit 520 from the management unit 505. Next, in step S723, the switching processing unit 506 determines whether the control state of the sixth control unit 520 satisfies the control state requirements of the software 1b. If so (yes), the process proceeds to step S724. If not (no), the process proceeds to step S726.
[0119] When proceeding from step S723 to step S724, the switching processing unit 506 determines whether the safety status of the sixth control unit 520 meets the safety status requirements of the software 1b. If the requirements are met (yes), it proceeds to step S725 and decides to set the sixth control unit 520 as the control unit that covers the software 1b obtained by simplifying the software 1a of the abnormal second control unit 420.
[0120] On the other hand, if the result of determination in step S723 or step S724 is to proceed to step S726, the switching processing unit 506 reads the control state and safety state of the seventh control unit 540 from the management unit 505 and returns to step S723. In step S723, the switching processing unit 506 determines whether the control state of the seventh control unit 540 satisfies the control state requirements of software 1b. Thereafter, the switching processing unit 506 repeats the above-described operation. In step S725, the switching processing unit 506 determines that the seventh control unit 540 is the control unit to be overwritten with software 1b obtained by simplifying software 1a of the abnormal second control unit 420.
[0121] Figure 8 : is an explanatory diagram showing an example of vehicle information indicating the state of the surrounding environment of the vehicle in the control device according to the third embodiment. Figure 8 The example shown shows vehicle 100 traveling at a low speed and stuck in traffic on a clear day. By considering vehicle state 410 when selecting a control unit, control units can be selected based on factors that do not change rapidly, such as weather and traffic conditions. This allows the selection of control units with sufficient processing load and memory usage even after software overwriting.
[0122] In the control device involved in embodiment 3, the sixth control unit 520 or the seventh control unit 540 is shown to continue the action of the second control unit 420, but it is not limited to this. The action of the second control unit 420 can also be continued by a control unit that manages the functional group such as the first control unit 400 and the fifth control unit 500.
[0123] In the control devices according to the above-described embodiments, the switching processing unit may be configured to select another control unit from the plurality of control units to continue at least part of the functions of the software executed by the control unit to which the switching processing unit belongs.
[0124] In addition, in the control device involved in the above-mentioned embodiment 3, multiple control units are mounted on the vehicle, and the switching processing unit can also be configured to select a control unit that continues to execute at least part of the functions of the software of the control unit that detects the abnormality based on at least two of the vehicle status, safety status, and control status obtained from the vehicle.
[0125] Furthermore, in the control device according to each of the above-described embodiments, the safety status indicates whether or not at least one function related to the safety of the plurality of control units is valid.
[0126] Furthermore, in the control device according to the third embodiment, the vehicle state may be information obtained by acquiring the surrounding state of the vehicle in real time.
[0127] Furthermore, in the control device according to each of the above-described embodiments, the management unit may be configured to manage the security state and the control state of at least one of the control unit to which the management unit belongs and the control unit other than the control unit to which the management unit belongs.
[0128] Furthermore, in the control device according to the third embodiment, the management unit is configured to acquire the safety state, the control state, and the vehicle state before the switching processing unit starts processing.
[0129] This application describes a number of exemplary embodiments, but the various features, forms, and functions described in these embodiments are not limited to the application of specific embodiments and can be applied to the embodiments individually or in various combinations. Therefore, it can be considered that countless variations not illustrated are also included in the technical scope disclosed in this application. For example, it is assumed that at least one component is deformed, added, or omitted, and at least one component is extracted and combined with the components of other embodiments.
[0130] Industrial applicability
[0131] The present application can be used in a control device mounted on a vehicle, and further used in the vehicle field.
[0132] Description of labels
[0133] 100 Vehicle, 200, 210 Communication path, 300 Storage device, 400 First control unit, 420 Second control unit, 440 Third control unit, 460 Fourth control unit, 500 Fifth control unit, 520 Sixth control unit, 540 Seventh control unit, 301, 401, 421, 501, 521 Communication unit, 302, 404, 424, 504, 524 Storage unit, 402, 422, 502, 522 Detection unit, 4 03, 423, 503, 523 judgment unit, 405, 425, 505, 525 management unit, 406, 426, 506, 526 switching processing unit, 407, 427, 527 calculation processing unit, 408, 428, 508, 528 safety status, 409, 429, 509, 529 control status, 410, 510 vehicle status, 1a, 2a, 3a, 4a, 11a, 12a, 1b, 2b, 11b, 12b software.
Claims
1. A control device comprising a plurality of control units connected to each other via a communication path so as to be able to communicate with each other, wherein upon detecting an abnormality in any of the plurality of control units, the control device is configured to continue to execute at least a portion of the functions of software of the control unit that detected the abnormality by another control unit different from the control unit that detected the abnormality, wherein the control device is characterized in that: Each of the plurality of control units comprises: a communication unit configured to send and receive messages to and from other control units via the communication path; a detection unit configured to detect an abnormality of the other control unit based on a message received by the communication unit from the other control unit; a management unit that manages a security state and a control state of the control unit to which the management unit belongs, wherein the security state indicates whether at least one function related to a security countermeasure against a security threat or attack is effective, and the control state indicates a processing load; a determination unit configured to determine, when the detection unit detects an abnormality in the other control unit, whether it is necessary to continue to cause at least part of the functions of the software executed by the other control unit that detected the abnormality to be executed by another control unit other than the other control unit that detected the abnormality; as well as A switching processing unit that compares the action requirements of the software of the other control units that detected the abnormality with at least one of the safety status and the control status of other control units other than the other control units that detected the abnormality, to select a control unit that continues to execute at least part of the functions of the software when the determination unit determines that there is a need to continue the execution.
2. The control device according to claim 1, wherein The plurality of control units are mounted on the vehicle, Each of the plurality of control units belongs to any one of the plurality of functional groups of the vehicle to manage actions, The switching processing unit is configured to select a specific function group from the plurality of function groups based on a vehicle state acquired from the vehicle, and select a control unit that continues execution of at least a portion of the functions of the software from among the control units belonging to the selected function group.
3. The control device according to claim 1 or 2, characterized in that The switching processing unit is configured to be able to select another control unit from the plurality of control units so as to continue executing at least a part of the functions of the software executed by the control unit to which the switching processing unit belongs.
4. The control device according to claim 1 or 2, characterized in that: The management unit is configured to manage the security state and the control state of at least one of a control unit to which the management unit belongs and a control unit other than the control unit to which the management unit belongs.
5. The control device according to claim 1 or 2, characterized in that: The control unit selected by the switching processing unit is configured to execute software obtained by simplifying the functions of the software of the other control unit that has detected the abnormality.
6. The control device according to claim 2, wherein: The vehicle status is information obtained by acquiring the surrounding status of the vehicle in real time.
7. The control device according to claim 2, wherein: The management unit is configured to acquire the safety state and the control state of the other control units other than the other control unit that has detected the abnormality, and the vehicle state before the switching processing unit starts processing.
Citation Information
Patent Citations
Control device, control unit, control method, and program
JP2020008950A
Processing Device and Vehicle Control System
US20180281816A1
Control system for mobile body and control method for mobile body
WO2019058962A1