Control method of controller in electronic control unit, electronic control unit and computing device

CN120144157APending Publication Date: 2025-06-13BOSCH AUTOMOTIVE PRODUCTS (SUZHOU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510307700.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-13

Smart Images

  • Figure CN120144157A_ABST
    Figure CN120144157A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method for controlling a controller in an electronic control unit. The method comprises the following steps: monitoring whether the controller is reset or not; in response to reset of the controller, the reset type of reset of the controller is determined, the reset type comprises normal reset and abnormal reset, and the abnormal reset comprises software abnormal reset caused by software abnormity in the controller; recording the number of times of abnormal resetting of the controller after normal resetting; and controlling the controller to enter a software updating mode to update software in the controller in response to the fact that the number of times is greater than a threshold value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of vehicle control, and in particular, to a method, apparatus, electronic control unit, computing device, computer program product, and computer-readable storage medium for controlling a controller in an electronic control unit. Background Art

[0002] With the development and application promotion of artificial intelligence technology, vehicles such as cars are gradually equipped with stronger and stronger intelligent driving functions. Correspondingly, the electronic systems on vehicles usually include one or more electronic control units (ECUs). Each electronic control unit includes one or more controllers (MCUs), and corresponding software is written in the controllers. The software programs in the controllers can be responsible for implementing functions such as control algorithms, data processing, communication protocol processing, real-time monitoring and control, etc., and are key parts for the normal operation of the electronic control unit and the safe operation of the vehicle.

[0003] The software programs of the controllers in the electronic control unit usually need to be updated. The update can fix software defects, improve performance, add new functions, or enhance security. As the software programs are continuously improved, the frequency of software program updates in the controllers is also getting higher and higher. In practice, it may happen that a certain version of the software program cannot run properly, resulting in an unexpected reset (restart) of the controller and / or the electronic control unit. If the updated software program cannot run properly all the time, causing the controller and / or the electronic control unit to reset repeatedly, it will cause the electronic control unit to become "bricked" and unable to work properly. Summary of the Invention

[0004] An embodiment of this application provides a method for controlling a controller in an electronic control unit, including: monitoring whether the controller resets; in response to the controller resetting, determining the reset type of the controller reset, the reset type including normal reset and abnormal reset, and the abnormal reset including software abnormal reset caused by software abnormality in the controller; recording the number of abnormal resets that occur after the controller normally resets; and in response to the number being greater than a threshold, controlling the controller to enter a software update mode to update the software in the controller.

[0005] In some embodiments, the method further includes: in response to an abnormal voltage provided to the electronic control unit or the controller, resetting the controller so that the controller exits the software update mode.

[0006] In some embodiments, the method further includes: in response to the software in the controller being updated, the controller undergoes a normal reset.

[0007] In some embodiments, the method further includes: in response to detecting a normal reset of the controller, clearing the number of times of abnormal reset of the controller recorded.

[0008] In some embodiments, the method further includes: in response to the number being not greater than the threshold, controlling the controller to enter a software operation mode to run the software in the controller.

[0009] In some embodiments, the method further includes: in response to the controller receiving a sleep instruction, the controller enters a sleep mode, and in response to the controller being woken up, the controller undergoes a normal reset.

[0010] In some embodiments, the method further includes: in response to the controller receiving a software update instruction, the controller exits the software operation mode and undergoes a normal reset.

[0011] In some embodiments, the abnormal reset further includes a signal abnormal reset caused by the controller receiving an abnormal signal from outside the controller.

[0012] Another embodiment of the present application provides an apparatus for controlling a controller in an electronic control unit, including: a reset monitoring unit configured to monitor whether the controller undergoes a reset; a reset type determination unit configured to, in response to the controller undergoing a reset, determine the reset type of the controller undergoing a reset, the reset type including a normal reset and an abnormal reset, and the abnormal reset including a software abnormal reset caused by software abnormality in the controller; a recording unit configured to record the number of times of abnormal reset of the controller after a normal reset; and a software update unit configured to, in response to the number being greater than the threshold, control the controller to enter a software update mode to update the software in the controller.

[0013] Another embodiment of the present application provides an electronic control unit, including a controller and the apparatus for controlling the controller described in the foregoing embodiment.

[0014] Yet another embodiment of the present application provides a computing device, including: a memory configured to store computer-executable instructions; and a processor configured to execute the method according to any one of the foregoing method embodiments when the computer-executable instructions are executed by the processor.

[0015] In some embodiments, the computing device includes a vehicle domain controller.

[0016] Yet another embodiment of the present application provides a computer program product, including a computer program that implements the method according to any one of the foregoing method embodiments when executed by a processor.

[0017] Another embodiment of the present application provides a computer-readable storage medium, on which computer-readable instructions are stored, and the computer-readable instructions, when executed, implement the method according to any one of the foregoing method embodiments.

[0018] According to the embodiments described below, these and other advantages of the present application will become clear, and these and other advantages of the present application are illustrated with reference to the embodiments described below. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Embodiments of the present application will now be described in more detail and with reference to the drawings, where:

[0020] Figure 1 Illustrated are some steps involved in a method for controlling a controller in an electronic control unit according to an embodiment of the present application;

[0021] Figure 2 Illustrated is a partial flow involved in a method for controlling a controller in an electronic control unit according to some embodiments of the present application;

[0022] Figure 3 Illustrated are some steps involved in a controller in a software update mode according to some embodiments of the present application;

[0023] Figure 4 Illustrated is an example of a controller in a software running mode;

[0024] Figure 5 Illustrated is a partial flow involved in a method for controlling a controller in an electronic control unit according to another embodiment of the present application;

[0025] Figure 6 Illustrated is a block diagram of a device for controlling a controller in an electronic control unit according to another embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] The following description provides specific details of various embodiments of the present application so that those skilled in the art can fully understand and implement various embodiments of the present application. It should be understood that the technical solutions of the present application can be implemented without some of these details. In some cases, some well-known structures or functions are not shown or described in detail in the present application to avoid obscuring the description of the embodiments of the present application with unnecessary descriptions. The terms used in the present application should be understood in the broadest reasonable manner, even if they are used in conjunction with specific embodiments of the present application.

[0027] The terms used in this application should be understood in the broadest reasonable manner, even when they are used in connection with specific embodiments of this application. The "controller" herein refers to the microcontroller unit (MCU) in an electronic control unit (ECU). The controller can be regarded as a highly integrated computing and control unit that can process data, execute control logic, manage hardware resources, etc., and communicate with external devices.

[0028] Figure 1 Illustrated are some steps involved in a method for controlling a controller in an electronic control unit according to an embodiment of this application. The method includes: S101, monitoring whether the controller has a reset; S102, in response to the controller having a reset, determining the type of reset of the controller, where the type of reset includes a normal reset and an abnormal reset, and the abnormal reset includes a software abnormal reset caused by software abnormality in the controller; S103, recording the number of abnormal resets that occur after the controller has a normal reset; and S104, in response to the number being greater than a threshold, controlling the controller to enter a software update mode to update the software in the controller.

[0029] Using the method proposed in the embodiment of this application, by monitoring and recording the number of abnormal resets that occur after the controller has a normal reset, after the controller has a certain number of consecutive abnormal resets, the controller is made to enter a software update mode to update the software in the controller, thereby avoiding repeated abnormal resets of the controller and preventing the situation where the electronic control unit becomes "bricked". Another technical solution for preventing the electronic control unit from becoming "bricked" is to set a window period with a certain time length during the startup process of the electronic control unit, and monitor abnormal signals of the electronic control unit within this window period. If an abnormal signal is detected within this window period, then initiate a software update for the software in the controller. However, an overly long window period will cause a delay in the startup process of the electronic control unit, and an overly short window period may result in missed monitoring of abnormal signals, unable to effectively initiate a software update program for the software in the controller, and still unable to reliably solve the problem of the electronic control unit becoming "bricked". In contrast, the method for controlling a controller in an electronic control unit provided by the embodiment of this application can be independent of the aforementioned window period with a certain time length, and is conducive to accelerating the startup of the electronic control unit.

[0030] The normal reset of the controller mentioned in this article is in contrast to the abnormal reset. The reasons for normal reset do not include the abnormality of the software program inside the controller. Examples of normal reset include the reset that occurs when the electronic control unit and / or the controller is powered on and started, the reset that occurs when the controller is awakened from the sleep mode, and the reset that occurs when the controller completes the update of its internal software program, etc. When the controller resets, the electronic control unit usually resets as well, and vice versa. The aforementioned threshold for the number of abnormal resets of the recorded controller can be set according to the actual situation. For example, the factors to be considered for setting the threshold size may include the time required for the controller to recover from the abnormality. In some embodiments, the size of the threshold is between 25 and 30.

[0031] According to some embodiments of the present application, the method for controlling the controller in the electronic control unit further includes the following steps: in response to monitoring that the controller has a normal reset, clear the number of times of the recorded abnormal reset of the controller. That is to say, the recording and accumulation of the number of times of the controller's abnormal reset are carried out during the time period of two consecutive normal resets of the controller. Once the controller has a normal reset, clear the number of times of the controller's abnormal reset to re-count the abnormal reset.

[0032] Figure 2 The figure illustrates a partial process involved in the method for controlling the controller in the electronic control unit provided according to some embodiments of the present application. As Figure 2 shown, at step S201, it is monitored that the controller resets; at step S202, it is determined whether the controller has an abnormal reset according to the reason for the controller's reset. If it is determined that the controller has an abnormal reset, then at step S203, increment the number of times of the recorded abnormal reset of the controller by 1; at step S204, determine whether the number of times of the recorded abnormal reset of the controller exceeds the threshold. If this number exceeds the threshold, then at step S205, let the controller enter the software update mode to update the software inside the controller. Otherwise, if the number of times of the recorded abnormal reset of the controller does not exceed the threshold, the controller can enter other working modes at step S207. If at step S202, it is determined that the reset of the controller is a normal reset, then enter step S206 to clear the number of times of the recorded abnormal reset of the controller. At this time, the controller can enter other working modes at step S207. The other working modes mentioned here refer to the situation where the controller is not triggered to enter the software update mode because the number of recorded abnormal resets exceeds the threshold. Therefore, the other working modes can be the normal software running mode in which the controller runs its internal software program, or another operation mode in which the controller executes an external command input by the user.

[0033] Figure 3 The figure illustrates some of the steps involved in a controller provided according to some embodiments of the present application in a software update mode. As Figure 3 shown, at step S301, the controller enters the Flash Boot Loader, and thus is booted into the software update mode by the Flash Boot Loader. At step S302, the controller executes the Flash Boot Loader. At step S303, it is determined whether the controller receives a trigger signal for software update or a trigger signal for requesting a reset. If the trigger signal for software update or the trigger signal for requesting a reset is not received, the Flash Boot Loader continues to be executed. In the case of receiving the trigger signal for software update, at step S304, the software program is updated, new data is written into the memory of the controller, and the original software program is upgraded. If it is determined at step S303 that the controller receives the trigger signal for requesting a reset, at step S305, the controller is reset, thereby exiting the software update mode. Here, the trigger signal for requesting a reset may be caused by abnormal reasons other than the software program itself. For example, if the supply voltage provided to the controller or the electronic control unit is too high or too low, the update of the software program is no longer executed, the controller is reset, and the controller exits the software update mode. Therefore, in some embodiments, the foregoing method for controlling the controller in the electronic control unit further includes: in response to an abnormal voltage provided to the electronic control unit or the controller, resetting the controller so that the controller exits the software update mode. Additionally, after the update of the software program is completed at step S304, step S305 is also entered to reset the controller. That is, when the controller performs a reset, it is a necessary action to complete the software program update and exit the software update mode. It can be understood that Figure 3 the resets involved in the example of the controller performing software update shown are all normal resets. Therefore, in some embodiments, the foregoing method for controlling the controller in the electronic control unit further includes: in response to the software in the controller being updated, the controller undergoes a normal reset.

[0034] In some embodiments, at Figure 2 step S207 shown, if the number of times of abnormal reset of the recorded controller does not exceed the threshold, the controller can enter the software normal operation mode for running its internal software program. Therefore, in some embodiments, the method for controlling the controller in the electronic control unit further includes: in response to the number being not greater than the threshold, controlling the controller to enter the software operation mode to run the software in the controller. Figure 4Illustrated is an example where the controller is in the software running mode. At step S401, the controller enters the software running mode and starts running the software program in the controller. At step S402, the controller executes the software program. When the controller executes the software program, the vehicle where the controller is located usually has been started and is in the driving mode. Therefore, generally, the software program in the controller is in a continuous running state. However, the running state of the vehicle may change due to the user's control, and the process of the controller running the software program may also be interrupted due to problems with the software program itself. Therefore, at step S403, the controller may receive some different trigger signals to interrupt the running of the software program. For example, if an exception occurs in the software program itself and the software program cannot continue to run normally, then at step S404, the controller performs a reset, and this reset at this time is an abnormal reset of the controller. If the controller receives a reset request signal for the controller or the electronic control unit from the user or other signal sources during the process of running the software program, then at step S405, the controller performs a reset and exits the software program running mode. For example, during the process of the controller running the software program, if the user wants to start the flash bootloader to update the software program, then the controller performs a reset and exits the software program running mode. The reset that occurs at step S405 is a normal reset. Therefore, in some embodiments, the foregoing method for controlling the controller in the electronic control unit further includes: in response to the controller receiving a software update instruction, the controller exits the software running mode and performs a normal reset. At step S406, the controller may receive an instruction to enter the sleep mode and enter the sleep mode from the software program running mode. Thereafter, if the controller receives a wake-up instruction and exits the sleep mode, the controller performs a normal reset. Therefore, in some embodiments, the foregoing method for controlling the controller in the electronic control unit further includes the following steps: in response to the controller receiving a sleep instruction, the controller enters the sleep mode, and in response to the controller being woken up, the controller performs a normal reset.

[0035] Figure 5 Illustrated is a partial process involved in a method for controlling a controller in an electronic control unit according to another embodiment of the present application, to more comprehensively understand the method provided by the embodiments of the present application. As Figure 5 shown, steps S501, S502, S503, and step S504 are respectively the same as Figure 2 steps S201, S202, S203, and step S204 shown in Figure 2 and step S505 is the same asFigure 3 The steps S301, S302, S303, S304, and S305 shown are the same and will not be elaborated here. In step S506, the controller can enter the software program running mode to execute subsequent steps S512 and S513, and steps S512 and S513 are respectively the same as the previous steps S401 and S402. Alternatively, if the controller receives a software update command triggered by the user, it can also enter the software update mode at step S506. At step S514, the controller may receive some different trigger signals to interrupt the running of the software program. For example, if an exception occurs in the software program itself and the software program cannot continue to run normally, the controller performs an abnormal reset at step S515. If the controller receives a reset request signal for the controller or the electronic control unit from the user or other signal sources during the process of running the software program, the controller performs a normal reset and exits the software program running mode at step S516. At step S517, the controller may receive an instruction to enter the sleep mode and enter the sleep mode from the software program running mode. At this time, the controller will wait for a wake-up instruction. If the controller receives a wake-up instruction and exits the sleep mode, the controller performs a normal reset. As Figure 5 shown, regardless of the situation in which the controller is reset, the occurrence of the reset will be detected at step S501, and it will be determined whether an abnormal reset occurs at step S502 and the number of abnormal resets will be recorded at step S503. Thus, by monitoring and recording the number of abnormal resets that occur after the controller is normally reset, after the controller continuously experiences a certain number of abnormal resets, the controller is made to enter the software update mode to update the software in the controller, thereby avoiding multiple abnormal resets of the controller, preventing the occurrence of the situation where the electronic control unit becomes "bricked", and being beneficial to accelerating the restart of the electronic control unit.

[0036] In some embodiments, the abnormal reset further includes a signal abnormal reset caused by the controller receiving an abnormal signal from outside the controller. For example, the abnormal signal from outside the controller can come from a watchdog electrically connected to the controller. If the watchdog detects an abnormality in the operation of the controller, it can provide a reset request trigger signal to the controller, and the controller resets upon receiving this reset request trigger signal.

[0037] Another embodiment of the present application provides a device for controlling a controller in an electronic control unit, such as Figure 6As shown. The device includes: a reset monitoring unit 610 configured to monitor whether the controller is reset; a reset type determination unit 620 configured to, in response to the controller being reset, determine the reset type of the controller's reset, where the reset type includes normal reset and abnormal reset, and the abnormal reset includes software abnormal reset caused by software abnormality within the controller; a recording unit 630 configured to record the number of times of abnormal reset that occurs after the controller is normally reset; and a software update unit 640 configured to, in response to the number being greater than a threshold, control the controller to enter a software update mode to update the software within the controller. The device can be implemented in a pure software or pure hardware manner, or in a combination of software and hardware.

[0038] Another embodiment of the present application provides an electronic control unit, including a controller and the device for controlling the controller described in the foregoing embodiment.

[0039] Another embodiment of the present application provides a computing device, including: a memory configured to store computer-executable instructions; and a processor configured to execute the method according to any one of the method embodiments described in the foregoing method embodiments for controlling the controller in the electronic control unit when the computer-executable instructions are executed by the processor.

[0040] In some embodiments, the computing device can be implemented as a vehicle domain controller (VDC), or the computing device is implemented to include a vehicle domain controller, that is, the vehicle domain controller is at least a component of the computing device. The vehicle domain controller is an integrated electronic control unit that appears with the development of automotive electronics and intelligence, and improves the intelligence level of the vehicle by integrating the functions of multiple electronic control units (ECUs). According to the function or application field of the vehicle domain controller, the vehicle domain controller can be implemented as a power domain controller, a body domain controller, an autonomous driving domain controller, a cockpit domain controller, etc.

[0041] The method described above with reference to the flowchart can be implemented as a computer program. Another embodiment of the present application provides a computer program product, including a computer program that implements the method according to any one of the method embodiments described in the foregoing method embodiments for controlling the controller in the electronic control unit when executed by a processor.

[0042] Another embodiment of the present application provides a computer-readable storage medium, on which computer-readable instructions are stored, and the computer-readable instructions implement the method according to any one of the method embodiments described in the foregoing method embodiments for controlling the controller in the electronic control unit when executed.

[0043] The scope of the present application is limited only by the appended claims. Although individual features may be included in different claims, these may possibly be advantageously combined, and the order of features in a claim does not imply that the features must work in any particular order. Further, in a claim, the word "comprising" does not exclude other elements or steps.

Claims

1. A method for controlling a controller in an electronic control unit, comprising: Monitoring whether the controller is reset; In response to the controller being reset, determining a reset type of the controller being reset, the reset type including a normal reset and an abnormal reset, the abnormal reset including a software abnormal reset caused by a software abnormality in the controller; Recording the number of abnormal resets of the controller after normal reset; as well as In response to the number of times being greater than a threshold, the controller is controlled to enter a software update mode to update the software in the controller.

2. The method according to claim 1, characterized in that The method further comprises: In response to an abnormal voltage supplied to the electronic control unit or controller, the controller is reset so that the controller exits a software update mode.

3. The method according to claim 1, characterized in that The method further comprises: In response to the software in the controller completing the update, the controller is normally reset.

4. The method according to claim 1, characterized in that: The method further comprises: In response to monitoring that the controller is reset normally, the recorded number of times the controller is reset abnormally is cleared.

5. The method according to claim 1, characterized in that The method further comprises: In response to the number of times being not greater than the threshold, the controller is controlled to enter a software running mode to run the software in the controller.

6. The method according to claim 5, characterized in that The method further comprises: In response to the controller receiving a sleep instruction, the controller enters a sleep mode, and In response to the controller being awakened, a normal reset of the controller occurs.

7. The method according to claim 5, characterized in that The method further comprises: In response to the controller receiving the software update instruction, the controller exits the software running mode and performs a normal reset.

8. The method according to claim 1, characterized in that The abnormal reset also includes a signal abnormal reset caused by the controller receiving an abnormal signal from outside the controller.

9. A device for controlling a controller in an electronic control unit, comprising: A reset monitoring unit, configured to monitor whether the controller is reset; a reset type determination unit configured to determine, in response to the controller being reset, a reset type of the controller being reset, wherein the reset type includes a normal reset and an abnormal reset, and the abnormal reset includes a software abnormal reset caused by a software abnormality in the controller; a recording unit configured to record the number of abnormal resets of the controller after normal reset; as well as The software updating unit is configured to control the controller to enter a software updating mode to update the software in the controller in response to the number of times being greater than a threshold.

10. The device according to claim 9, characterized in that The abnormal reset also includes a signal abnormal reset caused by the controller receiving an abnormal signal from outside the controller.

11. An electronic control unit, comprising a controller and the device for controlling the controller according to claim 9 or 10.

12. A computing device comprising: a memory configured to store computer-executable instructions; as well as A processor configured to perform the method according to any one of claims 1-8 when the computer executable instructions are executed by the processor.

13. The computing device according to claim 12, characterized in that The computing device includes a vehicle domain controller.

14. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.

15. A computer-readable storage medium having computer-readable instructions stored thereon, which implement the method according to any one of claims 1 to 8 when executed.