Method and system for determining activation of control unit function in control unit of technical device

By introducing a state variable storage area with security level allocation in the enable manager, the problem of management of different security level functions in the control unit is solved, and the security level management of the control unit functions is realized, which improves the availability and security of the system.

CN120225966APending Publication Date: 2025-06-27ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380079386.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-18
Filing Date
2023-11-09
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art is difficult to effectively manage control unit functions of different security levels in control units, resulting in reduced system availability or inability to use, and diagnostic functions of lower security levels may prevent the execution of control unit functions of higher security levels.

Method used

By introducing a security level allocation status variable storage area in the enablement manager, the status variables are adjusted according to the results of the diagnostic function and the security level, ensuring that only the control unit functions that meet a specific security level are enabled, and avoiding the diagnostic function of the lower security level affecting the control unit functions of the higher security level.

Benefits of technology

The safety level management of the control unit functions is realized, ensuring the integrity and reliability of the system, preventing the diagnostic functions of lower safety levels from preventing the execution of the control unit functions of higher safety levels, and improving the availability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120225966A_ABST
    Figure CN120225966A_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method for operating an activation manager for activating control unit functions (11) of different security levels in a control unit (1) of a technical system, comprising the following steps:-executing (S2) diagnostic functions (12) in the control unit (1), the diagnostic functions (12) each being assigned a security level; -adapting (S4, S5) the assigned state variable in a state variable store (13), which is assigned to the security level of the diagnostic function (12), as a function of an identification of an error event or a functional capability by the respective diagnostic function (12); and executing (S7, S8, S9) a control unit function (11) assigned to a specific security level as a function of one or more assigned state variables, in which only state variables stored in a state variable store (13) assigned to the security level or higher of the control unit function (11) are taken into account.
Need to check novelty before this filing date? Find Prior Art

Description

Field of the Invention

[0001] The present invention generally relates to control units in which control unit functions assigned to different safety levels are implemented. The method further relates to: performing control unit functions in a control unit based on authorizations (Freigaben) that depend on the diagnostic results of function diagnostics for the respective control unit functions. Background Art

[0002] Today, control units are used in a variety of technical devices to control these technical devices. Such control units are typically implemented by means of a microcontroller and are usually operated with functional software that typically has a plurality of functional modules, each of which may contain a plurality of control unit functions. Such control unit functions may include, for example, functions of an operating system, memory management, central functions of on-board diagnostics, error memory management functions, and working functions for implementing control unit tasks. Control unit functions are usually interrelated in order to perform control and regulation tasks.

[0003] A control unit is used to control a technical system. Depending on the application area of the technical system, a fault in one or more of the control unit functions may cause more or less critical behavior of the technical system, which may lead to a reduction in the availability of the technical system or the technical system becoming inoperable, or may damage or destroy components of the technical system.

[0004] Thus, it is stipulated that these control unit functions are monitored by one or more diagnostic functions respectively. Errors found by the diagnostic functions result in setting a corresponding error state (state variable), and this error state is retrieved for enabling the execution of the corresponding control unit function.

[0005] With the aid of a so-called authorization manager (Function Inhibition Manager, FIM), the authorization and deauthorization of individual control units can be coordinated based on the identified error events. Usually, such a function inhibition manager works with an inhibition matrix that takes into account the control unit functions identified by means of function identifiers based on the error event identifiers of the errors identified by the assigned diagnostic functions, and the inhibition matrix contains the state variables assigned to the control unit functions, by means of which the identified errors can be displayed.

[0006] For example, in the AUTOSAR "Specification of Function Inhibition Manager", AUTOSAR document identifier No. 82, version R21-11, an industry standard for such an authorization manager is described. Summary of the Invention

[0007] According to the present invention, there is provided a method for operating an enabling manager to enable control unit functions with different security levels as claimed in claim 1 and a corresponding device as claimed in the co-pending independent claims.

[0008] Other design alternatives are described in the dependent claims.

[0009] According to a first aspect, there is provided a method for operating an enabling manager to enable control unit functions with different security levels in a control unit of a technical system, the method having the following steps:

[0010] - Performing a diagnostic function in the control unit, wherein the diagnostic function is assigned a security level;

[0011] - Adjusting the assigned state variables in the state variable storage area according to the identification of an error event or functional ability by the corresponding diagnostic function, the state variable storage area being assigned to the security level of the diagnostic function;

[0012] - Performing a control unit function assigned to a specific security level according to one or more assigned state variables, wherein only the state variables stored in the following state variable storage areas are considered, these state variable storage areas being assigned to the security level of the control unit function or a higher security level.

[0013] In the enabling manager (function disabling manager), an association occurs between the error event identifier assigned to the diagnostic function and the function identifier. Here, the error event characterized by the error event identifier causes an increment or setting of a state variable, which is assigned to the function identifier and thereby assigned to a specific control unit function. In this way, when an error is identified by means of the diagnostic function, one or more control unit functions can be affected by the corresponding function identifier.

[0014] Therefore, if an error is indicated to be identified by a specific event identifier, the state variables of the function identifiers assigned according to the disabling matrix are adjusted accordingly.

[0015] However, in the above implementation, all diagnostic functions and control unit functions must have the same integrity, that is, be assigned the same security level, or for the automotive field, be assigned the same ASIL level (ISO 26262). The same integrity means that all diagnostic functions related to the control unit function can access the same state variable storage area and directly exchange information.

[0016] However, the safety level regulations state that diagnostic functions of a specific safety level cannot access the status variable storage area of a higher safety level using write access. In contrast, the control unit functions can perform read access to the storage areas of all safety levels. Here, it must be ensured that a diagnostic function with a lower safety level that has detected an error does not prevent the execution of a control unit function with a higher safety level.

[0017] To this end, the above method stipulates that, based on the results of the diagnostic functions, the enabling of the control unit functions is performed while taking into account their safety levels and the enabling manager. To this end, the enabling manager has a status variable storage area for each safety level (in advance) in order to store the status variables of these control unit functions. These status variables are each assigned to a specific control unit function, represented by a function identifier, and these status variables are adjusted in the diagnostic message provided that the corresponding assignment of the diagnostic function and the function identifier is registered. These status variables can be designed as error counters. In the latter case, when an error occurs in the assigned error function, the status variable can be incremented, and when a specific criterion is met and no error is detected, the status variable can be decremented accordingly.

[0018] Each diagnostic function is assigned a safety level. Correspondingly, each diagnostic function adjusts the status variable of the function identifier for its relevant safety level. For example, adjustment can be made if an error event is detected or if the function is found to be error-free after an error event has been detected. When an error is identified, the status variable is incremented accordingly, and when the same diagnostic function identifies that the function is normal, if the value of the status variable is greater than zero, the status variable is decremented accordingly.

[0019] When performing the control unit function, its enabling is always checked according to the safety level assigned to it. This enabling is carried out based on one or more state variables assigned through the assignment matrix. If one or more state variables of the safety level of the control unit function to be executed indicate that an error has been identified, the execution of the control unit function is disabled. Since the one or more state variables are stored at different safety levels, it is necessary to check all state variables assigned to the control unit function corresponding to the safety level of the control unit function and higher safety levels. Correspondingly, before executing the control unit function, the corresponding state variables of the same or higher safety level assigned to the control unit function are retrieved to determine the enabling of the relevant control unit function. In addition, the state variables of the corresponding lower safety level are ignored, so that even if an error is identified, the diagnostic functions of the lower safety level cannot prevent the control unit functions of the higher safety level. In this way, the integrity of the enabling of the control unit function can be ensured. Therefore, the error events of the diagnostic function can only affect the enabling of the control unit functions assigned to the same safety level or lower safety levels.

[0020] It can be stipulated that by evaluating the program code and configuration files of the diagnostic functions and control unit functions, the call context is automatically analyzed for correctly assigning these diagnostic functions and control unit functions to the corresponding safety levels, wherein in particular the program code is parsed and one or more specified configuration files are checked to determine in which call container the diagnostic function or control unit function respectively calls a specific interface for a specific safety level.

[0021] In addition, these state variable stores can be taken into account by masking the read access to the state variables assigned to the control unit function in the state variable store.

[0022] In addition, with the help of the assignment matrix, diagnostic functions can be assigned to the corresponding state variables, and state variables can be assigned to control unit functions. Thereby, the assignment of the diagnostic functions and control unit functions can be flexibly adjusted by simple calibration (even during the operation of the control unit) without having to recompile the control unit software or the software of the diagnostic functions.

[0023] Since state variables are provided at all different safety levels, the assignment of the diagnostic functions to the control unit functions can be simply adjusted by calibration. There is no need for reconfiguration and integration of the entire program. Description of the Drawings

[0024] Subsequently, the embodiments will be explained in more detail based on the accompanying drawings. Among them:

[0025] Figure 1Schematic diagram of an enabling system in a control unit having multiple diagnostic functions and multiple control unit functions; and

[0026] Figure 2 Flowchart illustrating a method for operating a control unit. Detailed Description

[0027] Figure 1 Schematic diagram of a control unit 1 for controlling a technical system 2 is shown. For example, the control unit can be provided for controlling a vehicle system or other technical devices. In the control unit 1, multiple control unit functions 11 are implemented for operating the technical device 2. These control unit functions 11 can include software algorithms and functions for reading sensors and for manipulating actuators. In particular, the control unit functions 11 can include, for example, functions of an operating system, memory management, central functions of on-board diagnostics, error memory management functions, and working functions for implementing the control unit tasks.

[0028] Technical systems are typically used in safety-critical areas, such that the functions used in the control unit 1 must be at least partially protected in a special way to avoid critical states that could pose a threat to people and / or the technical system or other systems. Thus, the functions implemented in the control unit 1 are assigned safety levels that ensure a specific degree of protection for the functions to be executed. For example, for vehicle functions implemented in the control unit 1 of a motor vehicle, there is a classification according to ASIL (ISO 26262), where the safety levels QM, ASIL-A, ASIL-B, ASIL-C, and ASIL-D are known here. The indicated safety levels represent an increasingly strict protection for the relevant functions in the indicated order.

[0029] Since control unit functions related to different functional applications can typically be implemented in the control unit 1, such as functions for a steering system, a braking system, engine control, etc., these functions can be assigned to different safety levels.

[0030] For safety-critical systems, it is also necessary to monitor the control unit functions 11 or define enabling conditions by means of diagnostic functions 12. The diagnostic functions check in a suitable way whether one or more control unit functions 11 are able to operate properly. Like the control unit functions 11, the diagnostic functions 12 are assigned corresponding safety levels with respect to their reliability and protection (integrity).

[0031] When operating a technical system, the diagnostic function 12 is periodically executed, and when an error is recognized, the corresponding status variable assigned to the diagnostic function by the disabling matrix 15 is adjusted. Generally, this status variable corresponds to an error counter, which is incremented once an error event is recognized. If specific diagnostic criteria are met and the diagnostic function 12 finds that the function is normal during subsequent diagnostics after an error event is recognized, i.e., no error is found, the error counter of the status variable can be decremented when it has not reached the zero value.

[0032] The status variables in a specific status variable storage area are fixedly assigned to the corresponding control unit functions by the disabling matrix 15 and are represented by function identifiers. Since the control unit functions are classified by safety levels, the diagnostic function describes the status variable storage areas of the same safety level by recognizing errors.

[0033] Therefore, it is stipulated that for each safety level, separate status variables are provided so that for each control unit function - depending on the supported safety level - a complete status variable storage area 13 is generated as a whole, and this status variable storage area is respectively assigned to function identifiers. Therefore, when the diagnostic function recognizes an error event, the assigned status variable is adapted to the relevant status variable storage area, which is assigned to the same safety level as the diagnostic function.

[0034] It is stipulated that the call context is automatically analyzed for the correct assignment of the diagnostic function and the control unit function to the corresponding safety levels. For this purpose, by checking the program code and the configuration file, it is evaluated with what ASIL integrity the diagnostic results are reported or the enabling query of the control unit function is performed. This analysis is based on two contributions: i) parsing the C code; and ii) processing the specified configuration file, especially the AUTOSAR configuration file. For i), function calls are searched in the C code, and the parameters passed therein are checked to determine in which software component the call is made. Then, it is analyzed in which time frame or call container the function is called ("partition"). This yields the safety level of the call container. For ii), the configuration file is analyzed. It is described therein: in which call container the diagnostic function or the control unit function calls a specific interface. Thereby, the safety level is also specified.

[0035] The control unit function 11 is coupled to the enabling function 14 such that the execution of the control unit function 11 is only permitted when enabled. The enabling function 14 is based on a disabling matrix 15 that assigns one or more state variables, possibly from different security levels, to the relevant control unit function 11. The enabling function 14 only accesses those state variables of those security levels that correspond to the security level of the control unit function 11 to be enabled and higher security levels. Thereby, it can be excluded that diagnostic functions of a lower security level can prevent the enabling of a control unit function 11 of a higher security level. According to the disabling matrix 15, the enabling function 14 checks all state variables with respect to the enabling criteria, where one or more corresponding state variables are considered at the security level of the control unit function 11 and at higher security levels. If one of the state variables does not meet the enabling criteria, the execution of the control unit function 11 is blocked.

[0036] Figure 2 The above method flow is illustrated according to the flowchart.

[0037] In step S1, it is checked whether the diagnostic function 12 is to be executed. The diagnostic function is designed to check partial aspects of the functional capabilities of the control unit. If the diagnostic function is to be executed (option: yes), the method continues with step S2, otherwise (option: no), the method continues with step S6.

[0038] In step S2, the diagnostic function is executed. The result of the diagnostic function is the identification of an error event or the identification of the functional capabilities of the function being diagnosed.

[0039] In step S3, it is checked whether an error event exists. If an error event exists (option: yes), then in step S4, the assigned state variable is incremented and the state variable is stored in the state variable storage area assigned to the state variable at the security level of the diagnostic function.

[0040] On the other hand, if it is found that the function to be diagnosed is operational (option: no), then in step S5, the corresponding state variable in the relevant state variable storage area is decremented as long as the value of the state variable is not zero. If necessary, other diagnostic criteria can be applied that must be met in order to allow the decrement of the state variable.

[0041] In step S6, it is checked whether the control unit function is to be executed. If this is the case (option: yes), the method continues with step S7, otherwise it jumps back to step S1.

[0042] The control unit function 11 to be executed is assigned to a specific safety level. Before the control unit function is executed, in step S7, an enabling function is executed, which indicates whether the execution of the control unit function is allowed or blocked. The enabling function checks the enabling or blocking of the control unit function based on the assigned state variables in the state variable storage area 13, where this assignment is specified according to a disabling matrix.

[0043] For this purpose, in step S8, a query of the state variables in the state variable storage areas 13 assigned to the safety level of the control unit 1 and all higher safety levels is executed, and it is checked whether the relevant state variables meet the enabling criteria. If these enabling criteria are met for the state variables in all considered state variable storage areas (option: yes), then in step S9, the execution of the control unit function is enabled and the control unit function is executed. Otherwise (option: no), in step S10, the execution of the control unit function is blocked.

[0044] The state variables can be retrieved from the state variable storage area 13 with the aid of a mask. The mask does not allow read access to those state variable storage areas whose safety level is lower than the safety level of the control unit function 11 to be executed.

[0045] Since the state variables must have the value 0 for all considered state variable storage areas when managed as counters, the state variables thus considered can be added in different state variable storage areas. Then, the enabling criterion stipulates that the sum of the considered state variables must be 0 in order to allow the enabling of the relevant control unit function.

Claims

1. A computer-implemented method for operating an enabling manager to enable control unit functions (11) of different safety levels in a control unit (1) of a technical system, the method having the following steps: -Execute the diagnostic function (12) in the control unit (1) described in (S2), wherein, The diagnostic functions (12) are each assigned a safety level; - Adjusting (S4, S5) the assigned state variables in a state variable storage area (13) according to the recognition of error events or functional capabilities by the respective diagnostic functions (12), the state variable storage area being assigned to the safety level of the diagnostic functions (12); - Executing (S7, S8, S9) the control unit functions (11) assigned to a specific safety level according to one or more assigned state variables, wherein only the state variables stored in a state variable storage area (13) assigned to the safety level of the control unit functions (11) or a higher safety level are considered.

2. The method according to claim 1, wherein, Automatically analyzing the call context for correctly assigning the diagnostic functions (12) and the control unit functions (11) to the respective safety levels by evaluating the program code and configuration files of the diagnostic functions and the control unit functions (11), wherein in particular the program code is parsed and one or more specified configuration files are checked to determine in which call containers the diagnostic functions (12) or the control unit functions (11) respectively call specific interfaces for a specific safety level.

3. The method according to claim 1 or 2, wherein, The diagnostic functions (12) are assigned to state variables by means of a disabling matrix (15), and one or more state variables are assigned to the control unit functions (11).

4. The method according to claim 3, wherein The disabling matrix (15) can be adjusted by calibration, especially even during operation of the control unit (1).

5. The method according to any one of claims 1 to 4, wherein The state variable storage area (13) is considered by means of a mask for read access to specific state variables in the state variable storage area (13).

6. The method according to any one of claims 1 to 5, wherein The enabling manager is executed in the control unit (1).

7. The method according to any one of claims 1 to 6, wherein, The safety levels include safety levels specified according to ASIL.

8. A device for performing one of the methods according to claims 1 to 7.

9. A computer program product comprising instructions which, when the program is executed by at least one data processing device, cause the data processing device to carry out the steps of the method according to any one of claims 1 to 7.

10. A machine-readable storage medium comprising instructions which, when executed by at least one data processing device, cause the data processing device to carry out the steps of the method according to any one of claims 1 to 7.