In-vehicle network system and method for controlling in-vehicle network system

By introducing a power/startup management ECU into the vehicle network system, and utilizing relay circuits and anomaly detection units, the problem of intermediate ECUs being unable to identify anomalies in lower-level ECUs is solved, thereby improving anomaly identification efficiency and maintenance efficiency.

CN121625985APending Publication Date: 2026-03-10DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In existing vehicle network systems, the intermediate ECU cannot effectively identify the cause of abnormalities in the lower-level ECUs, resulting in low maintenance efficiency.

Method used

An upper-level control device (power/startup management ECU) is introduced to control the power supply of the lower-level control device through a relay circuit, and to detect the power and communication status. The abnormal part determination unit is used to determine the location of the abnormality.

Benefits of technology

It enables rapid identification of abnormal locations in lower-level control devices, improving maintenance efficiency and reducing maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121625985A_ABST
    Figure CN121625985A_ABST
Patent Text Reader

Abstract

The invention provides an in-vehicle network system and a method for controlling the in-vehicle network system. The power source / start management ECU (10) receives, in place of the plurality of lower ECUs (20, 30), an NM message that selectively instructs the plurality of lower ECUs (20, 30) to start, transmitted via the communication bus (8). Furthermore, the power source / start management ECU (10) turns on relay circuits (15, 16) provided on the power supply lines (6) of the lower ECUs (20, 30), which have been instructed to start by the NM message, thereby bringing the lower ECUs (15, 16), which have been instructed to start, into a start state. Furthermore, for the lower ECUs (20, 30) in which the relay circuits (15, 16) have been turned on, the power source / start management ECU (10) detects the state of power supply to the lower ECUs (20, 30) and the state of communication with the lower ECUs (20, 30), and determines the location where an abnormality occurs on the basis of the detection results.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to an in-vehicle network system having a plurality of control devices connected to a communication bus and capable of communicating with each other in a vehicle and a control method of the in-vehicle network system. BACKGROUND

[0002] For example, an in-vehicle network system provided with a higher-level ECU, an intermediate ECU, and a lower-level ECU is disclosed in Patent Literature 1. In the in-vehicle network system of Patent Literature 1, the intermediate ECU is supplied with electric power from a power supply, and supplies the lower-level ECU with the electric power from the power supply in accordance with a message received from the higher-level ECU. That is, the intermediate ECU maintains the lower-level ECU in a power-off state until the message is received from the higher-level ECU. In correspondence with the reception of the message from the higher-level ECU by the intermediate ECU, the lower-level ECU is supplied with the electric power from the power supply. The lower-level ECU transitions from the power-off state to a standby state in which an instruction is awaited by the electric power supply.

[0003] PRIOR ART DOCUMENTS

[0004] PATENT LITERATURE

[0005] Patent Literature 1: Japanese Patent No. 7238650 SUMMARY

[0006] In the in-vehicle network system described in Patent Literature 1, it is conceivable that some abnormality occurs so that the intermediate ECU becomes in a state in which communication with the lower-level ECU is interrupted despite the supply of the electric power to the lower-level ECU. In this case, it is possible to detect by the intermediate ECU that the communication with the lower-level ECU has become abnormal. However, if it is not clear what kind of bad condition has caused the abnormality in the communication with the lower-level ECU, the treatment for eliminating the bad condition becomes very troublesome, and the efficiency of the maintenance can possibly be deteriorated.

[0007] The present disclosure is achieved in view of the above-described points, and aims to provide an in-vehicle network system capable of estimating a site of abnormality occurrence when an abnormality occurs in a lower-level control device and a control method of the in-vehicle network system.

[0008] To achieve the above-described object, the in-vehicle network system of the present disclosure is an in-vehicle network system having a plurality of control devices connected to a communication bus and capable of communicating with each other in a vehicle, in which

[0009] the plurality of control devices include at least one higher-level control device and a plurality of lower-level control devices,

[0010] the higher-level control device is provided with:

[0011] a power supply management section that turns on and off a plurality of relay circuits provided on power supply lines of the plurality of lower control devices;

[0012] a start management section that receives, instead of the plurality of lower control devices, a network management message (hereinafter referred to as an NM message) that selectively instructs the plurality of lower control devices to start, which is transmitted via the communication bus, and instructs the power supply management section to turn on a relay circuit provided on a power supply line of a lower control device for which start is instructed by the NM message, thereby setting the lower control device for which start is instructed to a started state; and

[0013] an abnormality site determination section that detects a power supply state to the lower control device and a communication state with the lower control device, and determines an abnormality occurrence site based on the detection result.

[0014] In addition, a control method of an in-vehicle network system of the present disclosure is a control method of an in-vehicle network system having a plurality of control devices connected with a communication bus and capable of communicating with each other in a vehicle, in which

[0015] the plurality of control devices include at least one upper control device and a plurality of lower control devices,

[0016] the upper control device has a power supply management section that turns on and off a plurality of relay circuits provided on power supply lines of the plurality of lower control devices,

[0017] the control method of the in-vehicle network system includes the following:

[0018] receiving, instead of the plurality of lower control devices, a network management message (hereinafter referred to as an NM message) that selectively instructs the plurality of lower control devices to start, which is transmitted via the communication bus, by the upper control device;

[0019] turning on a relay circuit provided on a power supply line of a lower control device for which start is instructed by the NM message by the upper control device, thereby setting the lower control device for which start is instructed to a started state; and

[0020] detecting, by the upper control device, a power supply state to the lower control device and a communication state with the lower control device, and determining an abnormality occurrence site based on the detection result.

[0021] According to the in-vehicle network system and the control method of the in-vehicle network system of the present disclosure, the upper control device receives, instead of the plurality of lower control devices, the NM message selectively indicating the start of the plurality of lower control devices, which is transmitted via the communication bus. Also, the upper control device sets the lower control device indicated to start in the start state by turning on the relay circuit provided on the power supply line of the lower control device indicated to start by the NM message. Also, the upper control device detects the power supply state to the lower control device and the communication state with the lower control device, and determines the abnormality occurrence site based on the detection result.

[0022] Thus, according to the in-vehicle network system and the control method of the in-vehicle network system of the present disclosure, the abnormality occurrence site can be presumed, so that when an abnormality occurs, the efficiency of the maintenance for eliminating the abnormality can be suppressed from deteriorating. BRIEF DESCRIPTION OF DRAWINGS

[0023] Figure 1 is a configuration diagram showing an example of the configuration of the in-vehicle network system of the embodiment.

[0024] Figure 2 is an explanatory diagram for explaining an example of the NM message, the PN request information, and the PNC setting information.

[0025] Figure 3 is a diagram showing an example of the PNC setting table stored in the storage section of the power supply / start management ECU.

[0026] Figure 4 is a diagram showing an example of the relay connection information stored in the storage section of the power supply / start management ECU.

[0027] Figure 5 is a configuration diagram showing an example of the configuration of the current detection section provided in the abnormality site determination section for detecting the power supply state to the lower ECU.

[0028] Figure 6 is a diagram showing the first threshold value and the second threshold value compared with the detected current amount in the abnormality site determination section.

[0029] Figure 7 is a flowchart showing an example of the processing executed in the power supply / start management ECU.

[0030] Figure 8 is a flowchart showing the details of the start ECU determination processing of the flowchart of Figure 7 .

[0031] Figure 9 is a flowchart showing the details of the abnormality site determination processing of the flowchart of Figure 7 . DETAILED DESCRIPTION

[0032] Hereinafter, embodiments of the in-vehicle network system and the control method of the in-vehicle network system of the present disclosure will be described with reference to the accompanying drawings. However, the present disclosure is not limited to the following embodiments, and various modifications described later are also included in the technical scope of the present disclosure.

[0033] Furthermore, various modifications can be made in addition to the following description without departing from the scope of the gist of the present disclosure. The embodiments and various modifications can be appropriately combined and implemented within a range where no technical contradiction occurs.

[0034] In the following description, for the same or similar structures, cases where the same reference numerals are given in multiple drawings are omitted from the description. In addition, in cases where only a part of the structure is mentioned, the description of the other parts can be applied with respect to the other parts.

[0035] (First Embodiment)

[0036] Figure 1 is a configuration diagram showing an example of the configuration of the in-vehicle network system 100 of the present embodiment. As shown in Figure 1 , the in-vehicle network system 100 is provided with a power / start management ECU 10 as a higher-level control device, first and second lower-level ECUs 20, 30 as lower-level control devices, and first and second normal ECUs 40, 50. ECU is an abbreviation of Electronic Control Unit. The first and second lower-level ECUs 20, 30 are connected to the power / start management ECU 10 via first and second relay circuits 15, 16, respectively.

[0037] Further, the number of the first and second lower-level ECUs 20, 30 connected to the power / start management ECU 10 via the relay circuits such as the first and second relay circuits 15, 16 can not be two but three or more. In addition, the number of the first and second lower-level ECUs 20, 30 connected to the first and second relay circuits 15, 16, respectively, can not be one but two or more. Furthermore, in the in-vehicle network system 100, the combination of the power / start management ECU 10 and the first and second lower-level ECUs 20, 30 can not be one set but a plurality of sets can be provided. In the case where a plurality of sets of the combination of the power / start management ECU 10 and the first and second lower-level ECUs 20, 30 are provided in the in-vehicle network system 100, each of the power / start management ECUs 10 and the first and second lower-level ECUs 20, 30 can be connected in a manner capable of communicating with each other via the communication bus 8.

[0038] The power / startup management ECU 10, the first and second subordinate ECUs 20 and 30, and the first and second normal ECUs 40 and 50 can each be configured as a computer equipped with a processor, memory, and storage devices. The power / startup management ECU 10, the first and second subordinate ECUs 20 and 30, and the first and second normal ECUs 40 and 50 also have communication interfaces (communication IFs) 11, 21, 31, 41, and 51 for communicating with other ECUs.

[0039] Processors, such as CPUs, MPUs, GPUs, and DFPs, execute prescribed processes according to a program. Memory is a volatile storage medium that temporarily stores the results of the processor's operations, such as RAM. Storage devices are non-volatile storage media such as flash memory and ROM. Various programs and data executed by the processor are stored in the storage device. Some or all of the functions possessed by the power / startup management ECU10, the first and second lower-level ECUs 20 and 30, and the first and second general ECUs 40 and 50 can also be implemented in hardware, such as ASICs (Application Specific Integrated Circuits) and FPGAs (Field-Programmable Gate Arrays), without software programs.

[0040] The power / starting management ECU 10 may, for example, function as a domain controller to uniformly coordinate the control of the first and second subordinate ECUs 20 and 30. A domain refers to a functional unit when the vehicle's functions are broadly divided according to domains such as powertrain, chassis, advanced driver assistance, body, and cabin. The above is an example of domain division; however, domain division may differ from the example described above. Furthermore, the power / starting management ECU 10 may also function as a region controller to uniformly coordinate the control of subordinate ECUs 20 and 30 configured in each region of the vehicle.

[0041] The vehicle network system 100 can use CAN (registered trademark, hereinafter the same) as the communication protocol for communication between the various ECUs 10, 20, 30, 40, and 50. However, the communication protocol is not limited to CAN; the vehicle network system 100 can also employ other communication protocols such as CAN-FD. However, in the vehicle network system 100 of this embodiment, the first and second lower-level ECUs 20 and 30 and the first and second normal ECUs 40 and 50 are divided into multiple groups (referred to as clusters) according to each ECU that needs to be simultaneously activated to achieve at least one desired function. Furthermore, network management messages (hereinafter referred to as NM messages) described later are used to switch between normal operating mode (start-up state) and power-saving mode (e.g., sleep state) according to each cluster. In addition, the power-saving mode includes a power-off state for the first and second lower-level ECUs 20 and 30. Therefore, the communication protocol adopted by the vehicle network system 100 needs to be a communication protocol capable of transmitting and receiving NM messages.

[0042] The first and second lower-level ECUs 20 and 30, and the first and second normal ECUs 40 and 50, are, for example, control ECUs used in a vehicle to control a specified controlled object, and sensor ECUs that calculate a specified physical quantity based on detection signals detected by sensors. When it is necessary to control the controlled object or to calculate a specified physical quantity based on sensor detection signals, the first and second lower-level ECUs 20 and 30, and the first and second normal ECUs 40 and 50, in normal operating mode, become active and perform normal operations. On the other hand, when it is not necessary to control the controlled object or calculate the specified physical quantity, the first and second lower-level ECUs 20 and 30, and the first and second normal ECUs 40 and 50, in power-saving mode, become power-off or sleep states.

[0043] To facilitate the switching between the startup state (normal operating mode) and the power-off state or sleep state (power-saving mode), the first and second lower-level ECUs 20 and 30, and the first and second normal ECUs 40 and 50, are each assigned to a cluster within a plurality of clusters. Furthermore, the assigned cluster is also stored by each ECU as cluster setting information (also known as PNC setting information). As described later, the PNC setting information of the first and second lower-level ECUs 20 and 30 is stored in the storage unit 14 of the power / startup management ECU 10. Moreover, the configuration is such that, in response to a request for startup of the cluster to which each ECU belongs via startup cluster information (also known as PN request information) contained in an NM message, the first and second lower-level ECUs 20 and 30, and the first and second normal ECUs 40 and 50, switch from the power-off state or sleep state to the startup state.

[0044] If the first and second lower-level ECUs 20 and 30 and the first and second normal ECUs 40 and 50 respectively become active and switch to normal operating mode, they periodically send NM messages to other ECUs during their normal operation. Furthermore, if the first and second lower-level ECUs 20 and 30 and the first and second normal ECUs 40 and 50, after performing necessary processing, become in a state where normal operation is no longer required, they stop periodically sending NM messages. If a predetermined standby time is reached when no NM messages are received from other ECUs belonging to the same cluster, the first and second normal ECUs 40 and 50 switch from normal operating mode to power-saving mode, changing from active to sleep mode. Regarding the first and second lower-level ECUs 20 and 30, the power / startup management ECU 10 monitors the NM messages sent to them. Furthermore, if the time for which the NM message to the first and second lower-level ECUs 20 and 30 is not received reaches the specified standby time, the power / startup management ECU 10 will disconnect the first and second relay circuits 15 and 16, and stop supplying power to the first and second lower-level ECUs 20 and 30.

[0045] The first and second normal ECUs 40 and 50 have communication IFs 41 and 51, which are capable of receiving NM messages in sleep mode and switching the first and second normal ECUs 40 and 50 from sleep mode to start mode accordingly upon receiving an NM message. If the communication IFs 41 and 51 are set to start mode, the first and second normal ECUs 40 and 50 determine whether they have requested their own start based on the PN request information in the NM message and their own PNC setting information. If it is determined that they have requested their own start, the first and second normal ECUs 40 and 50 continue to be in start mode. On the other hand, if it is determined that they have not requested their own start, the first and second normal ECUs 40 and 50 return to sleep mode. Alternatively, the communication IFs 41 and 51 may be configured to perform the determination based on the PN request information and PNC setting information in the NM message. In this case, if the communication IFs 41 and 51 determine that they have requested start based on the PN request information and PNC setting information, the corresponding first and second normal ECUs 40 and 50 are switched from sleep mode to start mode. The following is a detailed explanation of an example of NM messages, PN request information, and PNC configuration information.

[0046] For example, such as Figure 2As shown, the NM message contains data in bytes 0 through 7. Byte 0 contains the Node ID (NID). The Node ID is an identifier inherent to the power / startup management ECU 10, the first and second subordinate ECUs 20 and 30, and the first and second general ECUs 40 and 50. The Node ID identifies the source of the NM message. Byte 1 contains the Control Bit Vector (CBV). The Control Bit Vector indicates whether local networking is used. When the Control Bit Vector indicates that local networking is used, the user data area in bytes 2 through 7 contains startup cluster information, i.e., PN request information, representing the corresponding startup cluster. Furthermore, local networking means setting only ECUs belonging to a portion of the clusters to the startup state, while setting ECUs belonging to the remaining clusters to the power-off state or sleep state. In this way, by only enabling the ECUs that need to operate to the startup state, the power consumption of each ECU installed in the vehicle can be reduced.

[0047] exist Figure 2 In the example shown, the control bit vector indicates the use of local networking, and PN request information is stored in bytes 6 and 7 of the user data area. The user data area, bytes 2 through 5, can be used to transmit any information, such as ECU starting factors and information related to normal or abnormal conditions. Furthermore, Figure 2 This is just one example of the form of an NM message. NM messages can also take other forms, as long as they include information about the availability of the local network and PN request information.

[0048] The PN request information is organized according to each of the multiple clusters, indicating which clusters should be started and which do not. More specifically, in Figure 2 In the example shown, the clusters are pre-divided into 16. Furthermore, the PN request information contains 16 bits of data corresponding to each of the 16 pre-divided clusters. That is, the 16 bits of the PN request information correspond to the 16 pre-divided clusters. When each of the 16 bits of the PN request information is "0", it indicates that the corresponding cluster does not need to be started. On the other hand, when each of the 16 bits of the PN request information is "1", it indicates that the corresponding cluster needs to be started.

[0049] As described above, the first and second lower-level ECUs 20 and 30 and the first and second general-purpose ECUs 40 and 50 have PNC configuration information that represents the cluster to which they belong in a group of multiple clusters. One example of this PNC configuration information is... Figure 2 As shown. Figure 2 An example of PNC setting information for any one of the first and second lower-level ECUs 20 and 30 and the first and second normal ECUs 40 and 50 is shown. Figure 2In the PNC configuration information shown, when the corresponding clusters are classified as A to P from left to right in the diagram, Figure 2 The PNC setting information indicates that the ECU holding this PNC setting information belongs to clusters D, H, and J. The first and second lower-level ECUs 20 and 30 and the first and second normal ECUs 40 and 50 can belong to more than one cluster because they can perform various functions through program execution.

[0050] If the first and second normal ECUs 40 and 50 receive an NM message containing PN request information via their respective communication IFs 41 and 51, then... Figure 2 As shown, the PN request information and PNC setting information are compared bit by bit, and a logical AND operation is performed, for example. That is, if the first and second normal ECUs 40 and 50 receive an NM message through their respective communication IFs 41 and 51, they temporarily enter a startup state. Furthermore, the first and second normal ECUs 40 and 50 determine whether the cluster requested for startup via the PN request information contained in the NM message matches the cluster of PNC setting information allocated to the first and second normal ECUs 40 and 50 respectively. For example, in Figure 2 In the example shown, the clusters requested to be started via the PN request information are clusters D, G, I, M, N, and O. The clusters to which the ECU belongs, as indicated by the PNC configuration information, are clusters D, H, and J. In this case, within cluster D, the cluster requested to be started via the PN request information contained in the NM message is consistent with the cluster in the PNC configuration information. Therefore, as... Figure 2 As shown, the result of the logical AND operation is "1" in cluster D.

[0051] When the result of a logical AND operation is a "1" in a certain bit, it has the following properties: Figure 2 The ECU shown in the PNC setting information has been determined to have requested the start of this ECU. Based on this determination, the ECU with… Figure 2 The ECU, as shown in the PNC setting information, transitions from sleep mode to start mode; if already in start mode, it remains so. On the other hand, if the result of the logical AND operation is all zeros and no single bit is "1", then... Figure 2 The ECU shown in the PNC setting information is determined to have not requested its own startup. In this case, the ECU with... Figure 1 The ECU, displaying the PNC setting information, discards the received NM message and returns to sleep mode.

[0052] Thus, the first and second normally functioning ECUs 40 and 50 have the function of identifying whether an NM message is a request to start the ECU based on PNC setting information. Through this NM message identification function, only the first and second normally functioning ECUs 40 and 50 of the cluster that have PNC setting information and whose PNC setting information includes a request to start via PN request information are switched to the start state via an NM message. Hereinafter, the communication IF that has the function of receiving NM messages in the sleep state of the ECU and switching the ECU from the sleep state to the start state will be referred to as the NM response communication IF.

[0053] In the vehicle network system 100 of this embodiment, the first and second lower-level ECUs 20 and 30 do not have NM communication IFs. In other words, the communication IFs 21 and 31 of the first and second lower-level ECUs 20 and 30 are non-NM communication IFs. As described above, NM communication IFs have the function of receiving NM messages in the sleep state of the ECU and switching the ECU from the sleep state to the start state. Therefore, NM communication IFs are more expensive than non-NM communication IFs. As described above, the communication IFs 21 and 31 of the first and second lower-level ECUs 20 and 30 are non-NM communication IFs. Therefore, by using the combination of the power / startup management ECU 10 and the lower-level ECUs 20 and 30, the overall cost of the vehicle network system 100 can be reduced.

[0054] In the vehicle network system 100 of this embodiment, the power / start management ECU 10 is configured such that, although the communication IFs 21 and 31 of the first and second lower-level ECUs 20 and 30 are not NM communication IFs, the first and second lower-level ECUs 20 and 30 are also objects of local networking corresponding to NM messages. Furthermore, the power / start management ECU 10 is configured to determine the location of the abnormality when at least one of the first and second lower-level ECUs 20 and 30 experiences some abnormality and becomes unable to operate normally. Hereinafter, the power / start management ECU 10 of this embodiment will be described in detail with reference to the accompanying drawings.

[0055] like Figure 1 As shown, the power / start management ECU 10 includes a communication IF 11, a start management unit 12, a power management unit 13, a storage unit 14, first and second relay circuits 15 and 16, an abnormality determination unit 17, an abnormality transmission unit 18, and an abnormality storage unit 19. The start management unit 12, power management unit 13, abnormality determination unit 17, and abnormality transmission unit 18 are functional units constructed within the power / start management ECU 10 via software and / or hardware. The storage unit 14 and the abnormality storage unit 19 can be configured using the storage device of the power / start management ECU 10. The storage unit 14 and the abnormality storage unit 19 can be located in different storage devices or in the same storage device.

[0056] The first and second relay circuits 15 and 16 of the power / starting management ECU 10 are respectively connected to the power supply line 6 for supplying power to the first and second lower-level ECUs 20 and 30. The power supply circuit 4 can convert the power supply voltage of the vehicle's battery 2 into the operating voltage of the power / starting management ECU 10, the first and second lower-level ECUs 20 and 30, and the first and second normal ECUs 40 and 50 as needed. Voltage from the power supply circuit 4 is supplied to the power supply line 6.

[0057] exist Figure 1 In the example shown, the power line of the first lower-level ECU 20 is connected to the first power port 15a, which is connected to the first relay circuit 15. Additionally, the power line of the second lower-level ECU 30 is connected to the second power port 16a, which is connected to the second relay circuit 16. The first and second lower-level ECUs 20 and 30 are powered via the first and second relay circuits 15 and 16 and their respective power lines. That is, the first and second relay circuits and their respective power lines are equivalent to power supply lines.

[0058] The first and second relay circuits 15 and 16 can be constructed, for example, using semiconductor switches such as MOSFETs and IGBTs. However, the first and second relay circuits 15 and 16 can also be constructed using conventional mechanical relays instead of semiconductor switches. Furthermore, as... Figure 3 As shown, the first and second relay circuits 15 and 16 can be located inside the power / start management ECU 10 or outside the power / start management ECU 10.

[0059] The communication IF 11 of the power / startup management ECU 10 is an NM-response communication IF capable of receiving NM messages. As described above, the communication IFs 21 and 31 of the multiple lower-level ECUs 20 and 30 are non-NM-response communication IFs. In this embodiment, the multiple lower-level ECUs 20 and 30 are in a power-saving mode with their power cut off when no operation is required. Therefore, the communication IFs 21 and 31 of the multiple lower-level ECUs 20 and 30 cannot receive NM messages when the corresponding lower-level ECUs 20 and 30 are in power-saving mode. Therefore, the communication IF 11 of the power / startup management ECU 10 receives NM messages that selectively instruct the multiple lower-level ECUs 20 and 30 to start, instead of the communication IFs 21 and 31 of the multiple lower-level ECUs 20 and 30. The NM messages received by the communication IF 11 are provided to the startup management unit 12.

[0060] Here, the storage unit 14 of the power / startup management ECU 10 stores, in addition to the programs executed by the processor of the power / startup management ECU 10, PNC setting information representing the clusters to which the first and second lower-level ECUs 20 and 30 belong, respectively. Furthermore, the storage unit 14 stores relay connection information representing the correspondence between the first and second relay circuits 15 and 16 and the first and second lower-level ECUs 20 and 30.

[0061] For example, storage unit 14 can use such as Figure 3 The PNC configuration table shown stores the PNC configuration information representing the cluster, which is respectively assigned to the first and second lower-level ECUs 20 and 30. Furthermore, Figure 4 The illustrated PNC settings represent the correspondence between the inherent identifiers (node ​​IDs) of multiple lower-level ECUs, including the first and second lower-level ECUs 20 and 30, and the PNC setting information assigned to these lower-level ECUs. Additionally, relay connection information indicating the correspondence between the first and second relay circuits 15 and 16 and the first and second lower-level ECUs 20 and 30 is provided, such as... Figure 3 As illustrated, the storage unit 14 stores the correspondence between the numbers of multiple relay circuits, including the first and second relay circuits 15 and 16, or the numbers of power ports, and the node IDs that represent the unique identifiers of multiple lower-level ECUs, including the first and second lower-level ECUs 20 and 30.

[0062] The start management unit 12 of the power / start management ECU10 is referenced Figure 5The illustrated PNC setting table can obtain the PNC setting information of the first and second lower-level ECUs 20 and 30 respectively. Furthermore, based on the obtained PNC setting information of each lower-level ECU 20 and 30 and the PN request information of the NM message, the startup management unit 12 can determine which lower-level ECU 20 or 30 was instructed to start via the NM message. Specifically, the startup management unit 12 compares the PN request information of the NM message with the PNC setting information of each of the multiple lower-level ECUs 20 and 30 bit by bit. If the startup management unit 12 determines, based on the comparison results, that there is PNC setting information containing a cluster that requested startup via the PN request information, it determines that the startup of the lower-level ECU 20 or 30 corresponding to that PNC setting information was instructed. In this case, the startup management unit 12 provides the node ID of the lower-level ECU 20 or 30 indicating that startup was instructed via the NM message to the power management unit 13. On the other hand, if the startup management unit 12 determines that there is no PNC setting information for a cluster that has requested startup via PN request information, it discards the NM message because the received NM message does not indicate the startup of any lower ECU 20 or 30.

[0063] When the power management unit 13 of the power / startup management ECU 10 receives the node ID of the lower-level ECU 20 or 30 that is instructed to be started from the startup management unit 12, it refers to the relay connection information stored in the storage unit 14, which indicates the correspondence between each relay circuit 15 or 16 and each lower-level ECU 20 or 30. Furthermore, the power management unit 13 determines the relay circuit 15 or 16 corresponding to the node ID of the lower-level ECU 20 or 30 that is instructed to be started, and outputs a drive signal to turn on the determined relay circuit 15 or 16. As a result, power is supplied via the relay circuit 15 or 16 corresponding to the lower-level ECU 20 or 30 that is instructed to be started, and the corresponding lower-level ECU 20 or 30 enters the startup state.

[0064] The first and second lower-level ECUs 20 and 30 control various control devices installed in the vehicle that are controlled only when specific conditions are met or only in specific environments (e.g., door lock mechanisms, power window drive motors, headlight light sources, wiper motors, AV equipment, etc.), or calculate the prescribed physical quantities required for control based on sensor detection signals. For example, the door lock mechanism is controlled by the ECU for controlling the door lock mechanism when the vehicle user wants to get in or out of the vehicle. The power window drive motor is controlled by the ECU for controlling the power window when the user operates the window lift switch.

[0065] In this way, the first and second lower-level ECUs 20 and 30 control the controlled devices that operate only under specific conditions or in specific environments, or calculate the prescribed physical quantities required for such control. Therefore, when the power / startup management ECU 10 instructs the first and second lower-level ECUs 20 and 30 to start via an NM message, it connects the first and second relay circuits 15 and 16 corresponding to the first and second lower-level ECUs 20 and 30, supplying power to them. On the other hand, when the power / startup management ECU 10 does not instruct the first and second lower-level ECUs 20 and 30 to start via an NM message, it disconnects the first and second relay circuits 15 and 16 corresponding to the first and second lower-level ECUs 20 and 30, stopping the power supply to them. This cuts off the dark current when the lower-level ECUs 20 and 30 do not need to operate, further improving energy efficiency for the entire vehicle system.

[0066] The NM message can be generated by the power / startup management ECU 10 as a function of a domain controller or area controller. In this case, the power / startup management ECU 10 determines the function to be performed in the vehicle. Furthermore, when the desired function needs to be performed, the power / startup management ECU 10 determines that a cluster needs to be in a startup state simultaneously when performing the corresponding function, and generates an NM message containing PN request information specified as a startup cluster. The generated NM message is sent via the communication bus 8 to the first and second normal ECUs 40 and 50, other power / startup management ECUs 10, etc. Moreover, the generated NM message is also used to determine whether the lower-level ECUs 20 and 30 of the power / startup management ECU 10 itself need to switch to a startup state. However, the function of determining the function to be performed in the vehicle and sending an NM message containing PN request information can also be possessed by other ECUs such as the first and second normal ECUs 40 and 50, and not by the power / startup management ECU 10.

[0067] In addition, the power / startup management ECU10 can also go into sleep mode when all ECUs belonging to the vehicle network system 100 have gone into sleep mode or power-off mode and have not received NM messages for a specified period of time.

[0068] The abnormal location determination unit 17 of the power / startup management ECU 10 detects the power supply status and communication status with the lower-level ECUs 20 and 30, which have relay circuits 15 and 16 connected, and determines the location of the abnormality based on the detection results. To detect the power supply status of the lower-level ECUs 20 and 30, the abnormal location determination unit 17 has, for example, the following features: Figure 6The current detection unit 70 is shown. A separate current detection unit 70 is provided for each of the multiple relay circuits 15 and 16. The current detection unit 70 includes a shunt resistor 71, a differential amplifier 72, and an A / D converter 73.

[0069] Shunt resistor 71 is connected to the upstream and downstream sides of each relay circuit 15 and 16 in the power supply lines 6 branching from the common power supply line 6 to the respective lower ECUs 20 and 30. Alternatively, shunt resistor 71 can also be connected to the power supply line 6 within each relay circuit 15 and 16. In shunt resistor 71, when the corresponding relay circuit 15 and 16 are turned on to supply power to the lower ECUs 20 and 30, a current corresponding to the power supplied to the lower ECUs 20 and 30 flows. As a result, a potential difference corresponding to the magnitude of the current flowing through shunt resistor 71 is generated across shunt resistor 71.

[0070] Differential amplifier 72 amplifies and outputs the potential difference across shunt resistor 71. A / D converter 73 converts the amplified potential difference from analog to digital. The converted digital potential difference represents the amount of current flowing through the power supply line 6 of the lower ECUs 20 and 30. Therefore, current detection unit 70 can detect the amount of current flowing through the power supply line 6 of the lower ECUs 20 and 30 when relay circuits 15 and 16 are turned on to supply power to the lower ECUs 20 and 30, and use this as a measure of the power supply status to the lower ECUs 20 and 30.

[0071] Furthermore, the abnormal location determination unit 17 will detect the current quantity and... Figure 1 The first threshold for determining a short circuit anomaly and the second threshold for determining a disconnection anomaly are compared. If the detected current is greater than the first threshold, the anomaly determination unit 17 can determine that a short circuit anomaly has occurred in the power supply line 6 of the lower-level ECUs 20 and 30. Conversely, if the detected current is less than the second threshold, the anomaly determination unit 17 can determine that a disconnection anomaly has occurred in the power supply line 6 of the lower-level ECUs 20 and 30.

[0072] Furthermore, if the detected current is less than the second threshold, the anomaly determination unit 17 can determine that the detected current is less than the second threshold based on multiple determination results rather than a single determination result. This is because, if the detected current is small, the relationship with the second threshold may be incorrectly determined. In this case, the anomaly determination unit 17 repeats the comparison between the detected current and the second threshold a predetermined number of times. Furthermore, if the anomaly determination unit 17 determines that the power supply line 6 of the lower ECUs 20 and 30 has experienced a disconnection anomaly when it obtains the result that the detected current is less than the second threshold after multiple comparisons, then the anomaly determination unit 17 determines that the power supply line 6 of the lower ECUs 20 and 30 has experienced a disconnection anomaly. Additionally, to ensure the accuracy of the determination, the comparison with the detected current can also be performed multiple times for the first threshold. In this case, the anomaly determination unit 17 repeats the comparison between the detected current and the first threshold a predetermined number of times. The predetermined number of times the comparison with the first threshold is repeated and the predetermined number of times the comparison with the second threshold is repeated can be the same or different.

[0073] Based on a comparison of the detected current quantity with the second threshold, or alternatively, the anomaly determination unit 17 may also compare the detected current quantity with the minimum current consumption value of the lower-level ECUs 20 and 30 during normal operation when they are set to the start state. In this case, the anomaly determination unit 17 may also determine that the power supply line 6 of the lower-level ECUs 20 and 30 and / or the lower-level ECUs 20 and 30 have malfunctioned if the detected current quantity is less than the minimum current consumption value.

[0074] When the detected current is compared with the first threshold, the second threshold, and / or the minimum current consumption value, and it is determined that an abnormality has occurred in the power supply line 6 of the lower-level ECUs 20 and 30, the abnormality determination unit 17 outputs a drive signal to disconnect the corresponding relay circuits 15 and 16. As a result, the relay circuits 15 and 16 installed on the abnormal power supply line 6 switch from being on to being off. Consequently, the power supply to the lower-level ECUs 20 and 30, which are abnormal and cannot be expected to operate normally, can be cut off.

[0075] Furthermore, the anomaly determination unit 17 sends messages to the lower-level ECUs 20 and 30, which are connected to the relay circuits 15 and 16 via the communication IF11 and communication bus 8, in order to detect the communication status with the lower-level ECUs 20 and 30. The anomaly determination unit 17 also detects whether there is a response from the lower-level ECUs 20 and 30 to the sent messages. In other words, the anomaly determination unit 17 uses the presence or absence of a response to the messages sent to the lower-level ECUs 20 and 30 as a measure of the communication status with them. Moreover, for multiple lower-level ECUs 20 and 30, message sending and response detection are performed individually.

[0076] If there is a response from the lower-level ECUs 20 and 30, the anomaly determination unit 17 can consider the communication status with the lower-level ECUs 20 and 30 to be normal. Conversely, if there is no response from the lower-level ECUs 20 and 30, the anomaly determination unit 17 can consider the communication status with the lower-level ECUs 20 and 30 to be abnormal. More specifically, if the power supply status to the lower-level ECUs 20 and 30 is normal, but no response to messages is received from the lower-level ECUs 20 and 30, the anomaly determination unit 17 can determine that the communication bus 8 between the lower-level ECUs 20 and 30, the communication IF21 and 31 between the lower-level ECUs 20 and 30, and / or the lower-level ECUs 20 and 30 have malfunctioned.

[0077] In the event of an anomaly in the communication bus 8 between the lower-level ECUs 20 and 30, the communication IFs 21 and 31 between the lower-level ECUs 20 and 30, and / or in the case of an anomaly in the lower-level ECUs 20 and 30, the anomaly determination unit 17 may disconnect the corresponding relay circuits 15 and 16, and then reconnect the relay circuits 15 and 16. This restarts the corresponding lower-level ECUs 20 and 30. Through restarting, the lower-level ECUs 20 and 30 may return to their normal state. Furthermore, the anomaly determination unit 17 may also determine that an anomaly has occurred in the communication bus 8 between the lower-level ECUs 20 and 30, the communication IFs 21 and 31 between the lower-level ECUs 20 and 30, and / or in the case of an anomaly in the lower-level ECUs 20 and 30 if a message response cannot be obtained from the lower-level ECUs 20 and 30 even after attempting a predetermined number of recovery attempts. Additionally, an anomaly in the communication IFs 21 and 31 between the lower-level ECUs 20 and 30 can be considered an anomaly in the lower-level ECUs 20 and 30.

[0078] When an anomaly is detected in the communication bus 8 between the lower-level ECUs 20 and 30, the communication IF21 and 31 between the lower-level ECUs 20 and 30, and / or in the lower-level ECUs 20 and 30, the anomaly determination unit 17 outputs a drive signal to disconnect the corresponding relay circuits 15 and 16. As a result, the relay circuits 15 and 16 corresponding to the anomaly-affected lower-level ECUs 20 and 30 switch from being on to being off. Consequently, the power supply to the lower-level ECUs 20 and 30 that are experiencing an anomaly and cannot be expected to operate normally can be cut off.

[0079] When the anomaly location determination unit 17 determines the location of an anomaly, the anomaly sending unit 18 of the power / startup management ECU 10 generates an anomaly notification message. This anomaly notification message includes the node ID of the corresponding lower-level ECUs 20 and 30 and / or information about the cluster to which the corresponding lower-level ECUs 20 and 30 belong. Furthermore, the anomaly sending unit 18 sends the generated anomaly notification message to other ECUs (e.g., the first and second normal ECUs 40 and 50) of the vehicle network system 100 via the communication IF 11 and the communication bus 8. Thus, when other ECUs of the vehicle network system 100 lose communication with their lower-level ECUs 20 and 30, they can determine the cause of the interruption.

[0080] When the anomaly determination unit 17 determines that an anomaly has occurred, the anomaly storage unit 19 of the power / startup management ECU 10 stores information indicating the location of the anomaly. For example, if the anomaly determination unit 17 determines that the power supply line 6 of the first lower-level ECU 20 has an anomaly, the anomaly storage unit 19 stores the power supply line 6 of the first lower-level ECU 20 as the location of the anomaly. The location of the anomaly stored in the anomaly storage unit 19 can be read by a diagnostic tool connected to the communication bus 8 via a data link coupler or by a data center 60 that functions as a diagnostic tool. As a result, the maintenance manager can obtain information related to the location of the anomaly and can smoothly perform actions to eliminate the anomaly.

[0081] Furthermore, the power / startup management ECU 10 may not have an anomaly storage unit 19. For example, the anomaly location determination unit 17 may be configured to send information indicating the anomaly location to an external server such as a data center 60 whenever an anomaly location is determined. In this case, the maintenance manager can obtain information related to the anomaly location from the data center 60.

[0082] In the vehicle network system 100 of this embodiment, a PNC setting information modification unit 42 that modifies the PNC setting information stored in each ECU 10, 40, 50 may also be installed in any of the ECUs belonging to the vehicle network system 100, such as the power / startup management ECU 10, the first and second normal ECUs 40, 50, etc. Figures 7 to 9 The image shows an example where the PNC setting information change unit 42 is installed in the first general ECU 40.

[0083] The first normal ECU 40, equipped with the PNC setting information change unit 42, has an external communicator capable of wirelessly communicating with an external server such as a data center 60. Furthermore, the first normal ECU 40 is configured to download applications for implementing new functions in the vehicle, and update programs for upgrading programs already installed in any of the ECUs 10, 20, 30, 40, and 50, from the data center 60 via the external communicator. The downloaded programs are provided to the corresponding ECUs 10, 20, 30, 40, and 50 via the communication bus 8, performing the installation of new applications and the rewriting of update programs. Moreover, the ECU communicating with the external server via the external communicator and the ECU equipped with the PNC setting information change unit 42 can be different ECUs.

[0084] Regarding ECUs 10, 20, 30, 40, and 50 with newly installed applications or updates, it is generally considered that the corresponding ECU's startup conditions need to be added or changed, depending on the function of the application or update. Therefore, in cases where it is necessary to add or change the startup conditions of an ECU with an installed application or update, the data center 60 will download the new PNC setting information corresponding to the addition or change of startup conditions along with the application or update to the first normal ECU 40.

[0085] When the PNC setting information modification unit 42 receives new PNC setting information from the data center 60, it modifies (rewrites) the PNC setting information stored in ECUs 10, 20, 30, 40, and 50 that have installed the application or update program. As a result, ECUs 10, 20, 30, 40, and 50 that have installed the application or update program switch from sleep state (including power-off state) to start state according to the cluster represented by the modified PNC setting information. The PNC setting information modification can be performed in the corresponding ECU when a modification instruction is received from the PNC setting information modification unit 42 along with the new PNC setting information. Alternatively, the PNC setting information modification can be performed by having the PNC setting information modification unit 42 access the memory of the corresponding ECU.

[0086] Furthermore, the PNC setting information modification unit 42 can also be located outside the vehicle network system 100, such as the data center 60, instead of being located within the ECU belonging to the vehicle network system 100. However, if the PNC setting information modification unit 42 is installed within the ECU belonging to the vehicle network system 100, the PNC setting information modification unit 42 can terminate communication with the outside once it obtains the data for modifying the PNC setting information of the ECU from the outside. On the other hand, if the PNC setting information modification unit 42 is located on a server outside the vehicle network system 100, the ECU that needs to modify the PNC setting information needs to communicate with the external server separately via an ECU equipped with an external communicator. Therefore, this may result in a potential drawback of increased communication volume with the external server.

[0087] Next, refer to Figures 7 to 9 The flowchart illustrates an example of the processing performed in the power / startup management ECU 10. The processing performed in the power / startup management ECU 10 includes setting the first and second lower-level ECUs 20 and 30 as objects of the local network corresponding to the NM message. Additionally, the processing performed in the power / startup management ECU 10 includes determining the location of an anomaly based on the power supply status of the first and second lower-level ECUs 20 and 30 and the communication status with the lower-level ECUs 20 and 30, and taking appropriate action if an anomaly is found. The power / startup management ECU 10 performs... Figure 8 The process shown in the flowchart is equivalent to executing the control method of the in-vehicle network system 100 of this disclosure.

[0088] In step S100, the power / startup management ECU 10 receives an NM message. In step S110, the power / startup management ECU 10 performs a startup ECU determination process to determine the lower-level ECUs 20 and 30 that have indicated startup via the NM message. Details of this startup ECU determination process are as follows: Figure 8 The flowchart is shown below. Refer to the following... Figure 7 The flowchart illustrates the ECU startup determination process.

[0089] In step S300, the power / startup management ECU 10 determines the cluster to be started based on the PN request information in the NM message. In step S310, the power / startup management ECU 10 reads the PNC setting information of multiple lower-level ECUs 20 and 30 from the storage unit 14. Then, in step S320, the power / startup management ECU 10 determines the PNC setting information of the cluster that is consistent with the cluster that requested start via the PN request information (startup request cluster).

[0090] In step S330, the power / startup management ECU 10 determines whether, in step S320, at least one PNC setting information from the plurality of lower-level ECUs 20, 30 was determined to contain a cluster consistent with the start request cluster. If at least one PNC setting information is determined, the power / startup management ECU 10 proceeds to step S340. On the other hand, if no determined PNC setting information is found, the power / startup management ECU 10 proceeds to step S350.

[0091] In step S340, the power / startup management ECU 10 sets the lower-level ECUs 20 and 30 corresponding to the determined PNC setting information as start ECUs, and sets all other lower-level ECUs 20 and 30 as non-start ECUs. In step S350, the power / startup management ECU 10 sets all lower-level ECUs 20 and 30 as non-start ECUs. Afterwards, the power / startup management ECU 10 returns to... Figure 7 The process is shown in the flowchart.

[0092] exist Figure 7 In step S120 of the flowchart, the power / startup management ECU 10 determines whether there are any subordinate ECUs 20 and 30 that are set as start ECUs. If there are subordinate ECUs 20 and 30 that are set as start ECUs, the power / startup management ECU 10 proceeds to step S130. On the other hand, if there are no subordinate ECUs 20 and 30 that are set as start ECUs, the power / startup management ECU 10 terminates. Figure 7 The process is illustrated in the flowchart. In this case, the NM message is discarded.

[0093] In step S130, the power / startup management ECU 10 connects the relay circuits 15 and 16 connected to the lower-level ECUs 20 and 30 that are set as start ECUs, based on the relay connection information stored in the storage unit 14 indicating the correspondence between each relay circuit 15 and 16 and each lower-level ECU 20 and 30. Conversely, the power / startup management ECU 10 disconnects the relay circuits 15 and 16 connected to the lower-level ECUs 20 and 30 that are set as non-start ECUs.

[0094] like Figure 9 As shown in step S200 of the flowchart, the lower-level ECUs 20 and 30, whose relay circuits 15 and 16 are turned on, begin to receive power. Thus, the lower-level ECUs 20 and 30, whose relay circuits 15 and 16 are turned on, undergo the prescribed starting process in step S210 and enter the startup state.

[0095] In step S140, the power / startup management ECU10 performs an anomaly determination process on the lower-level ECUs 20 and 30 that have activated relay circuits 15 and 16, based on the power supply status and communication status with the lower-level ECUs 20 and 30 to determine the location of the anomaly. Details of this anomaly determination process are as follows... Figure 9 The flowchart is shown below. Refer to the following... Figure 7 The flowchart illustrates the ECU startup determination process.

[0096] In step S400, the power / startup management ECU10 detects the amount of current flowing through the power supply line 6 of the lower ECUs 20 and 30 that have the relay circuits 15 and 16 connected, and uses this as the power supply status of the lower ECUs 20 and 30.

[0097] In step S410, the power / startup management ECU 10 determines whether the detected current is greater than a first threshold used to determine a short-circuit fault. If the detected current is greater than the first threshold, the power / startup management ECU 10 proceeds to step S420. In step S420, the power / startup management ECU 10 determines that a fault has occurred in the power supply line 6 of the lower-level ECUs 20 and 30, which are connected to relay circuits 15 and 16, as the location of the fault. On the other hand, if the detected current is less than the first threshold, the power / startup management ECU 10 proceeds to step S430.

[0098] In step S430, the power / startup management ECU 10 determines whether the detected current is less than a second threshold used to determine a disconnection abnormality. If the detected current is determined to be less than the second threshold, the power / startup management ECU 10 proceeds to step S440. On the other hand, if the detected current is determined to be greater than or equal to the second threshold, the power / startup management ECU 10 proceeds to step S460.

[0099] In step S440, the power / startup management ECU 10 compares the detected current with the second threshold a predetermined number of times. Then, in step S450, if the power / startup management ECU 10 determines that the detected current is less than the second threshold after a predetermined number of comparisons, it proceeds to step S420. In step S420, the power / startup management ECU 10 determines that an abnormality has occurred in the power supply line 6 of the lower-level ECUs 20 and 30, which are connected to the relay circuits 15 and 16. On the other hand, if the detected current is not less than the second threshold after a predetermined number of comparisons, the power / startup management ECU 10 proceeds to step S460.

[0100] In step S460, the power / startup management ECU 10 sends a message to the lower-level ECUs 20 and 30 that have activated the relay circuits 15 and 16 to detect the communication status with the lower-level ECUs 20 and 30. Then, in step S470, the power / startup management ECU 10 determines whether a response to the sent message has been detected from the lower-level ECUs 20 and 30. If a response is detected, the power / startup management ECU 10 proceeds to step S510. On the other hand, if no response is detected, the power / startup management ECU 10 proceeds to step S480.

[0101] In step S480, the power / startup management ECU 10 performs an abnormal recovery process up to a predetermined number of times, disconnecting relay circuits 15 and 16 corresponding to the lower-level ECUs 20 and 30 that did not detect a response, and then reconnecting relay circuits 15 and 16 to restart the lower-level ECUs 20 and 30. Then, in step S490, the power / startup management ECU 10 determines whether a response to the message was detected from the restarted lower-level ECUs 20 and 30 before the predetermined number of abnormal recovery processes were completed; in other words, whether the lower-level ECUs 20 and 30 have returned to normal. If it is determined that the lower-level ECUs 20 and 30 have not returned to normal, the power / startup management ECU 10 proceeds to step S500. On the other hand, if it is determined that the lower-level ECUs 20 and 30 have returned to normal, the power / startup management ECU 10 proceeds to step S510.

[0102] In step S500, as the location of the abnormality, the power / startup management ECU 10 determines that an abnormality has occurred in the communication bus 8 of the lower-level ECUs 20 and 30 where no response to the message was detected. In step S510, the power / startup management ECU 10 determines that no abnormality has occurred in the power supply line 6 and the communication bus 8 of the lower-level ECUs 20 and 30.

[0103] exist Figure 7 In step S150 of the flowchart, the power / startup management ECU 10 determines whether an abnormal location has been identified in the abnormal location identification process of step S140. If an abnormal location has been identified, the power / startup management ECU 10 proceeds to step S160. Conversely, if no abnormal location has been identified, the power / startup management ECU 10 terminates the process. Figure 9 The process is shown in the flowchart.

[0104] In step S160, the relay circuits 15 and 16 corresponding to the location where the abnormality occurred are disconnected. This cuts off the power supply to the power supply line 6, the communication bus 8, and / or the lower-level ECUs 20 and 30 that are malfunctioning and cannot be expected to operate normally.

[0105] In step S170, the power / startup management ECU 10 generates an anomaly notification message. This message includes the node ID of the lower-level ECUs 20 and 30 corresponding to the location of the anomaly and / or information about the cluster to which the lower-level ECUs 20 and 30 belong. Furthermore, the power / startup management ECU 10 sends the generated anomaly notification message to other ECUs in the vehicle network system 100. Thus, other ECUs in the vehicle network system 100 can determine the cause of communication interruption when communication with lower-level ECUs 20 and 30 is lost.

[0106] In step S180, the power / startup management ECU 10 stores information indicating the location of the malfunction. The stored location of the malfunction can be read by a diagnostic tool connected to the communication bus 8 via a data link coupler or by the data center 60, which acts as a diagnostic tool.

[0107] As described above, in the vehicle network system 100 according to this embodiment, the power / startup management ECU 10 receives NM messages sent via the communication bus 8, selectively instructing the startup of multiple lower-level ECUs 20 and 30, instead of the multiple lower-level ECUs 20 and 30. Furthermore, the power / startup management ECU 10 connects to relay circuits 15 and 16 connected to the lower-level ECUs 20 and 30 that have been instructed to start via the NM messages. Thus, the lower-level ECUs 20 and 30 that have been instructed to start are in a startup state. Therefore, the vehicle network system 100 according to this embodiment is configured to switch the power supply of the lower-level ECUs 20 and 30 from a stopped state to a supplied state based on the NM messages instructing startup, and can perform detailed management of the power supply and shutdown of the lower-level ECUs 20 and 30.

[0108] Furthermore, according to the vehicle network system 100 of this embodiment, for the lower-level ECUs 20 and 30 that have their relay circuits 15 and 16 connected, the system detects the power supply status to the lower-level ECUs 20 and 30 and the communication status with the lower-level ECUs 20 and 30, and determines the location of the abnormality based on the detection results. Therefore, according to the vehicle network system 100 of this embodiment, the location of the abnormality can be determined, and thus, when an abnormality occurs, the efficiency of maintenance used to eliminate the abnormality can be suppressed.

[0109] (Modified Example)

[0110] The preferred embodiments of this disclosure have been described above, but this disclosure is not limited to any of the above embodiments and can be implemented in various modifications without departing from the spirit of this disclosure.

[0111] For example, in the above embodiment, an example was described where, for lower-level ECUs 20 and 30 with relay circuits 15 and 16 connected, the power supply status and communication status with lower-level ECUs 20 and 30 were detected, and the location of the abnormality was determined based on the detection results. Alternatively, for lower-level ECUs 20 and 30 with relay circuits 15 and 16 disconnected, the power supply status and communication status with lower-level ECUs 20 and 30 could be detected, and the location of the abnormality could be determined based on the detection results. Thus, it is also possible to detect the occurrence of an abnormality where a short circuit in relay circuits 15 and 16 unexpectedly supplies power to lower-level ECUs 20 and 30.

[0112] In addition, ​ The flowchart illustrates an example of detecting the communication status with lower-level ECUs 20 and 30 when they are being normally powered. However, it is also possible to detect the communication status with lower-level ECUs 20 and 30 regardless of whether they are being normally powered.

[0113] The systems and methods described in this disclosure can also be implemented using a dedicated computer configured to perform one or more functions embodied in a computer program. The systems and methods described in this disclosure can also be implemented using dedicated hardware logic circuits. Alternatively, the systems and methods described in this disclosure can be implemented using one or more dedicated computers configured to perform a computer program and a combination of one or more hardware logic circuits. For example, some or all of the functions of the power / startup management ECU 10 can be implemented in hardware. Implementing a function in hardware includes using one or more ICs. Some or all of the functions of the power / startup management ECU 10 can also be implemented using a system-on-chip (SoC), an integrated circuit (IC), or a field-programmable gate array (FPGA). The concept of an IC also includes an application-specific integrated circuit (ASIC). Furthermore, the computer program can be stored as instructions executable by a computer on a computer-readable non-transitory tangible storage medium. The recording medium for the program can be an HDD (Hard-disk Drive), an SSD (Solid State Drive), flash memory, or the like. Additionally, the scope of this disclosure also includes non-transitional physical recording media such as the program used to enable the computer to function as the power / startup management ECU 10 and a semiconductor memory storing that program.

Claims

1. An in-vehicle network system having a plurality of control devices connected to a communication bus and capable of communicating with each other in a vehicle, characterized by the plurality of control devices including at least one upper control device and a plurality of lower control devices, the upper control device having a power management section that turns on and off a plurality of relay circuits provided on power supply lines of the respective lower control devices, a startup management section that receives, instead of the plurality of lower control devices, a network management message (NM message) selectively indicating startup of the plurality of lower control devices, which is transmitted via the communication bus, and instructs the power management section to turn on the relay circuit provided on the power supply line of the lower control device indicated to start by the NM message, thereby setting the lower control device indicated to start to a startup state, and an abnormality site determination section that detects a power supply state to the lower control device and a communication state with the lower control device, and determines an abnormality occurrence site based on the detection result.

2. The in-vehicle network system according to claim 1, characterized in that the abnormality site determination section detects a power supply state to the lower control device and a communication state with the lower control device for the lower control device whose relay circuit is turned on, and determines an abnormality occurrence site based on the detection result.

3. The in-vehicle network system according to claim 1 or 2, characterized in that the NM message includes startup cluster information that specifies a startup cluster indicating a group of the control devices that should be started, the upper control device has a storage section that stores cluster setting information indicating a cluster to which the lower control device belongs for each of the plurality of lower control devices, the startup management section determines that startup of the lower control device corresponding to the respective cluster setting information is instructed by the NM message when a startup cluster specified by the startup cluster information of the NM message coincides with the cluster of the cluster setting information stored in the storage section.

4. The in-vehicle network system according to claim 3, characterized in that the in-vehicle network system further has a change section capable of performing a change to the cluster setting information of the respective lower control devices stored by the upper control device.

5. The in-vehicle network system according to claim 4, characterized in that the change section is installed in any one of the plurality of control devices connected to the communication bus.

6. The in-vehicle network system according to claim 3, characterized in that the upper control device has a storage section that stores the cluster setting information of the respective lower control devices and relay connection information indicating a correspondence relationship between the plurality of lower control devices and the plurality of relay circuits.

7. The in-vehicle network system according to claim 6, characterized in that The upper control device turns on the relay circuit corresponding to the lower control device in which the cluster specified by the start cluster information included in the NM message coincides with the cluster of the cluster setting information, and turns off the relay circuit corresponding to the lower control device in which the cluster specified by the start cluster information included in the NM message does not coincide with the cluster of the cluster setting information, based on the cluster setting information and the relay connection information.

8. The in-vehicle network system according to claim 1, wherein The abnormality site determination section detects an amount of current flowing through the power supply line of the lower control device as a power supply state to the lower control device.

9. The in-vehicle network system according to claim 8, wherein The abnormality site determination section determines that an abnormality has occurred in the power supply line of the lower control device when the detected amount of current is greater than a first threshold value for determining a short-circuit abnormality or when the detected amount of current is less than a second threshold value for determining a disconnection abnormality.

10. The in-vehicle network system according to claim 8, wherein The abnormality site determination section repeatedly compares the detected amount of current with the magnitude of the first threshold value or the second threshold value a predetermined number of times when the detected amount of current is greater than the first threshold value or less than the second threshold value, and determines that an abnormality has occurred in the power supply line of the lower control device when a result of the detected amount of current being greater than the first threshold value or less than the second threshold value is obtained in the comparison results.

11. The in-vehicle network system according to claim 8, wherein The abnormality site determination section determines that an abnormality has occurred in the power supply line of the lower control device and / or the lower control device when the detected amount of current is less than a minimum consumption current of the lower control device in an activated state.

12. The in-vehicle network system according to any one of claims 9 to 11, wherein The abnormality site determination section switches the relay circuit from on to off in correspondence with a determination that an abnormality has occurred in the power supply line of the lower control device.

13. The in-vehicle network system according to claim 1, wherein The abnormality site determination section transmits a message to the lower control device via the communication bus and detects a response to the message as a communication state with the lower control device.

14. The in-vehicle network system according to claim 13, wherein The abnormality site determination section determines that an abnormality has occurred in the communication bus with the lower control device and / or the lower control device when a response to the message is not obtained from the lower control device although the power supply state to the lower control device is normal.

15. The in-vehicle network system according to claim 13, wherein The abnormality site determination section attempts recovery from the abnormality by turning on the relay circuit after turning off the relay circuit in correspondence with a determination that the communication bus between the lower control device or the lower control device has an abnormality, and determines that the communication bus between the lower control device and / or the lower control device has an abnormality in a case where a response to the message cannot be obtained from the lower control device even after recovery has been attempted a prescribed number of times.

16. The in-vehicle network system according to claim 14 or 15, characterized in that, The abnormality site determination section turns off the relay circuit in correspondence with a determination that the communication bus between the lower control device and / or the lower control device has an abnormality.

17. The in-vehicle network system according to claim 1, characterized in that, The upper control device further includes an abnormality transmission section that creates an abnormality notification message and transmits the abnormality notification message to other control devices in a case where the abnormality site determination section determines that an abnormality site, the abnormality notification message including an identifier indicating the corresponding lower control device and / or information indicating a cluster to which the corresponding lower control device belongs.

18. The in-vehicle network system according to claim 1, characterized in that, The upper control device further includes an abnormality storage section that stores information indicating an abnormality site in a case where the abnormality site determination section determines that an abnormality site.

19. A control method of an in-vehicle network system, the control method of an in-vehicle network system being a control method of an in-vehicle network system having a plurality of control devices connected to a communication bus and capable of communicating with each other in a vehicle, characterized by, The plurality of control devices including at least one upper control device and a plurality of lower control devices, The upper control device having a power supply management section that turns on and off a plurality of relay circuits provided on power supply lines of the plurality of lower control devices, The control method of an in-vehicle network system includes: The upper control device receives a network management message (NM message) that selectively instructs startup of the plurality of lower control devices, which is transmitted via the communication bus, in place of the plurality of lower control devices; The upper control device turns on the relay circuit provided on the power supply line of the lower control device for which startup has been instructed by the NM message, thereby setting the lower control device for which startup has been instructed to a startup state; and The upper control device detects a power supply state to the lower control device and a communication state with the lower control device, and determines an abnormality site based on the detection result.