In-vehicle network system and method for controlling in-vehicle network system
By setting up multiple control devices in the vehicle network system, and having cluster setting information for both normal and abnormal situations, the problem of unintended ECU startup caused by ECU malfunction or communication failure is solved, and the stable and energy-saving operation of the vehicle network system is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2026-03-24
AI Technical Summary
In existing vehicle network systems, when the management ECU malfunctions or communication fails, the cluster settings of the ECU cannot be properly modified, leading to unintended ECU startup and unnecessary power consumption.
Multiple control devices are installed in the vehicle, including a start control object control device and a management control device. These devices have cluster setting information for both normal and abnormal situations. In case of an abnormal situation, the start control object control device switches to the cluster setting information for the abnormal situation to ensure proper control of the ECU's start-up.
Even if the management and control device malfunctions or communication fails, the ECU startup can be appropriately controlled to avoid unnecessary power consumption and ensure the stable operation of the vehicle network system.
Smart Images

Figure CN121716625A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to an in-vehicle network system having multiple control devices connected to a communication bus and capable of communicating with each other in a vehicle, and a control method for the in-vehicle network system. Background Technology
[0002] For example, Patent Document 1 discloses an in-vehicle network system comprising a host ECU, an intermediate ECU, and a lower-level ECU. In the in-vehicle network system of Patent Document 1, the intermediate ECU is powered by a power source and supplies power from the power source to the lower-level ECU based on a message received from the host ECU. That is, the intermediate ECU keeps the lower-level ECU in a power-off state until it receives a message from the host ECU. Corresponding to the message received from the host ECU by the intermediate ECU, the lower-level ECU is powered by the power source. The lower-level ECU transitions from a power-off state to a standby state awaiting instruction through this power supply.
[0003] Existing technical documents Patent documents Patent Document 1: Japanese Patent No. 7238650 Summary of the Invention
[0004] As described above, in the conventional vehicle network system described in Patent Document 1, the configuration is such that a specific ECU (e.g., an intermediate ECU) manages other ECUs (e.g., lower-level ECUs).
[0005] However, if the relationship between other ECUs and the specific ECU that manages the state of other ECUs is fixed, it is difficult to manage the state of other ECUs in detail. Therefore, for example, techniques such as assigning each ECU to a group, i.e., a cluster, of ECUs that are simultaneously activated to achieve the desired function, and using network management messages to set each ECU to an active or sleep state for each cluster, are also being put into practical use.
[0006] On the other hand, in recent years, after a vehicle has been sold and circulated in the market, it has become possible for vehicle owners to upgrade the software of the vehicle's ECU by downloading any application. In this case, depending on the function of the downloaded application, the upgraded ECU may require other conditions to be met in addition to starting when the conditions set before the upgrade are met, or instead of starting when the conditions set before the upgrade are met.
[0007] Therefore, when it is necessary to change the startup conditions of an ECU with upgraded software, it is advisable to have a specific management ECU of the vehicle network system receive cluster setting information corresponding to the changed startup conditions from an external source (e.g., the application's provider), thereby changing the cluster setting information representing the cluster to which the upgraded software ECU belongs.
[0008] However, in this situation, when the management ECU malfunctions or communication with it fails, the management ECU may be unable to properly modify the cluster settings of each ECU. As a result, there are concerns about the inability to properly control ECU startup, such as unintended timed startups, unnecessary power consumption, and other issues.
[0009] This disclosure was made in view of the above-mentioned problems, and its purpose is to provide an in-vehicle network system and a control method for the in-vehicle network system, which can appropriately control the startup of the startup control object control device even when the management control device, which is capable of making changes to the cluster setting information of the startup control object control device, malfunctions or communication with the management control device malfunctions.
[0010] To achieve the above objectives, the in-vehicle network system disclosed herein is an in-vehicle network system having multiple control devices in a vehicle that are connected to a communication bus and capable of communicating with each other, wherein, The multiple control devices include multiple startup control object control devices, each having cluster setting information indicating its own cluster within a plurality of clusters. When a network management message (hereinafter referred to as an NM message) sent from other control devices contains startup cluster information consistent with the cluster setting information, indicating the cluster to be started, the multiple startup control object control devices either become started or remain started. The multiple control devices also include a management control device capable of changing cluster configuration information for multiple start-up control object control devices. Multiple start-up control objects control devices have cluster setting information used during normal operation and cluster setting information used when an anomaly occurs, which serve as cluster setting information. If at least one of the following situations is detected as an abnormality in the management control device or an abnormality in communication with the management control device, the control device will switch the cluster setting information used during normal operation to the cluster setting information used when the abnormality occurs.
[0011] Furthermore, the control method for the in-vehicle network system disclosed herein is a control method for an in-vehicle network system having multiple control devices in the vehicle that are connected to a communication bus and capable of communicating with each other, wherein, The multiple control devices include multiple startup control object control devices, each having cluster setting information indicating its own cluster within a plurality of clusters. When a network management message (hereinafter referred to as an NM message) sent from other control devices contains startup cluster information consistent with the cluster setting information, indicating the cluster to be started, the multiple startup control object control devices either become started or remain started. The multiple control devices also include a management control device capable of changing cluster configuration information for multiple start-up control object control devices. Multiple start-up control objects control devices have cluster setting information used during normal operation and cluster setting information used when an anomaly occurs, which serve as cluster setting information. The control method of the vehicle network system includes: The situation where at least one control device for the initiating control object detects an abnormality in the management control device or an abnormality in communication with the management control device; and If at least one of the following situations is detected as an abnormality in the management control device or an abnormality in communication with the management control device, the control device will switch the cluster setting information used during normal operation to the cluster setting information used when the abnormality occurs.
[0012] According to the vehicle network system and control method disclosed herein, the start-up control object control device is pre-configured with cluster setting information for normal operation and cluster setting information for abnormal operation. Furthermore, in the event of an abnormality in the management control device or communication with the management control device, at least one start-up control object control device that detects the abnormality switches the cluster setting information used during normal operation to the cluster setting information used during the abnormality. As a result, at least one start-up control object control device is started according to the cluster setting information used during the abnormality. Therefore, even in the event of an abnormality in the management control device or communication with the management control device, the start-up of the start-up control object control device can be appropriately controlled. Attached Figure Description
[0013] Figure 1 This is a configuration diagram illustrating an example of the configuration of the vehicle network system according to the first embodiment.
[0014] Figure 2 This is an explanatory diagram illustrating an example of NM messages, PN request information, and PNC setting information.
[0015] Figure 3 This diagram shows an example of a PNC setting table stored in the storage section of the power / startup management ECU.
[0016] Figure 4 This diagram shows an example of relay connection information stored in the storage section of the power / startup management ECU.
[0017] Figure 5 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU and the lower-level ECU in the first embodiment.
[0018] Figure 6 It means Figure 6 The flowchart is a flowchart of the startup ECU determining the details of the processing.
[0019] Figure 7 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU of the second embodiment.
[0020] Figure 8 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU of the third embodiment.
[0021] Figure 9 This is an explanatory diagram illustrating the operation of the vehicle network system according to the third embodiment.
[0022] Figure 10 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU of the fourth embodiment.
[0023] Figure 11 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU of the fifth embodiment. Detailed Implementation
[0024] Hereinafter, embodiments of the vehicle network system and the control method of the vehicle network system of this disclosure will be described with reference to the accompanying drawings. However, this disclosure is not limited to the following embodiments, and various modifications described below are also included within the technical scope of this disclosure.
[0025] Furthermore, in addition to the description below, various modifications can be made without departing from the spirit of this disclosure. The implementation methods and various variations can be appropriately combined and implemented without creating technical inconsistencies.
[0026] In the following description, for the same or similar structures, descriptions are sometimes omitted by using the same reference numerals in multiple figures. Furthermore, where only a part of the structure is mentioned, descriptions of other parts may apply to the remaining parts.
[0027] (First Implementation) Figure 1 This is a configuration diagram illustrating an example of the configuration of the vehicle network system 200 according to this embodiment. For example... Figure 1 As shown, the vehicle network system 200 includes a power / start management ECU 10, a first upper-level ECU 40, and a second upper-level ECU 80 as upper-level control devices, and first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 as lower-level control devices. ECU is an abbreviation for Electronic Control Unit. On the power supply lines 6 of the first and second lower-level ECUs 20 and 30, first and second relay circuits 17 and 18 are provided, which are switched on and off by the power / start management ECU 10. On the other hand, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 are directly powered from the power supply circuit 4 without passing through relay circuits such as the first and second relay circuits 17 and 18. Furthermore, the power / start management ECU 10, the first upper-level ECU 40, and the second upper-level ECU 80 are also powered from the power supply circuit 4.
[0028] The power / startup management ECU 10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 can each be composed of a computer equipped with a processor, memory, and storage devices. The power / startup management ECU 10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 also have communication interfaces (communication IFs) 11, 21, 31, 41, 51, 61, 71, 81, 91, and 101 for communicating with other ECUs via communication buses 19a, 19b, 19c, 43a, 43b, 82a, and 82b.
[0029] More specifically, the communication IF11 of the power / startup management ECU 10 is connected to the communication IF41 and IF81 of the first and second upper-level ECUs 40 and 80 via communication bus 19a. Additionally, the communication IF11 of the power / startup management ECU 10 is connected to the communication IF21 of the first lower-level ECU 20 via communication bus 19b. Furthermore, the communication IF11 of the power / startup management ECU 10 is connected to the communication IF31 of the second lower-level ECU 30 via communication bus 19c. The communication IF41 of the first upper-level ECU 40 is connected to the communication IF51 and IF61 of the third and fourth lower-level ECUs 50 and 60 via communication bus 43a. Additionally, the communication IF41 of the first upper-level ECU 40 is connected to the communication IF71 of the fifth lower-level ECU 70 via communication bus 43b. The communication IF81 of the second upper-level ECU 80 is connected to the communication IF91 of the sixth lower-level ECU 90 via communication bus 82a. Furthermore, the communication IF81 of the second upper-level ECU 80 is connected to the communication IF101 of the seventh lower-level ECU 100 via the communication bus 82b. The communication IF11 of the power / startup management ECU 10 and the communication IF41 and 81 of the first and second upper-level ECUs 40 and 80 are configured, for example, to act as gateways when the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100, which are connected to different communication buses 19a, 19b, 19c, 43a, 43b, 82a, and 82b, communicate with each other.
[0030] Processors include, for example, CPUs (Central Processing Units), MPUs (Micro Processing Units), GPUs (Graphics Processing Units), and DFPs (Data Flow Processors) that execute prescribed processes according to a program. Memory is a volatile storage medium that temporarily stores the results of the processor's operations, such as RAM (Random Access Memory). Storage devices are non-volatile storage media such as flash memory and ROM (Read Only Memory). Various programs and data executed by the processor are stored in storage devices. Some or all of the functions of the power / startup management ECU10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 can also be implemented in hardware, such as using ASICs (Application Specific Integrated Circuits) or FPGAs (Field-Programmable Gate Arrays), rather than in software such as programs.
[0031] The vehicle network system 200 can use CAN (registered trademark, hereinafter the same) as the communication protocol for communication between the power / startup management ECU 10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100. CAN is an abbreviation for Controller Area Network. However, the communication protocol is not limited to CAN; the vehicle network system 200 can also use other communication protocols such as CAN-FD (CAN with Flexible Data Rate). In this embodiment of the vehicle network system 200, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 are divided into multiple groups (referred to as clusters) according to the requirement that each ECU needs to be started simultaneously to achieve at least one desired function. Furthermore, network management messages (hereinafter referred to as NM messages) are used to switch between normal operating mode (startup state) and power-saving mode (e.g., sleep state) according to each cluster. Furthermore, the power-saving mode includes the power-off state of the first and second lower-level ECUs 20 and 30. Therefore, the communication protocol used by the vehicle network system 200 needs to be a communication protocol that can handle the sending and receiving of NM messages.
[0032] The power / starting management ECU 10 and the first and second upper-level ECUs 40 and 80 can, for example, function as domain controllers that coordinate the control of the first and second lower-level ECUs 20 and 30, the third to fifth lower-level ECUs 50, 60, and 70, and the sixth and seventh lower-level ECUs 90 and 100. A domain refers to a functional unit when the vehicle's functions are broadly divided according to domains such as powertrain, chassis, advanced driver assistance, body, and cabin. The above is an example of domain division; domain division can also differ from the example above. Furthermore, the power / starting management ECU 10 and the first and second upper-level ECUs 40 and 80 can also function as area controllers that coordinate the control of the first and second lower-level ECUs 20 and 30, the third to fifth lower-level ECUs 50, 60, and 70, and the sixth and seventh lower-level ECUs 90 and 100 configured in each area of the vehicle.
[0033] The first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 are, for example, control ECUs used in vehicles to control specified objects, and sensor ECUs that calculate specified physical quantities based on detection signals detected by sensors. When controlling the object or calculating specified physical quantities based on sensor detection signals, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 are in an active state in normal operating mode, performing normal operations. On the other hand, when controlling the object or calculating specified physical quantities is not required, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 are in a power-saving state or sleep state.
[0034] To facilitate this switching between the startup state and the power-off state or sleep state, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 are each assigned to their respective clusters within a plurality of sub-clusters. Furthermore, the assigned cluster is also stored by each ECU as cluster setting information (also known as PNC setting information). PNC is short for Local Network Cluster. As described later, the PNC setting information of the first and second lower-level ECUs 20 and 30 is stored in the storage unit 14 of the power / startup management ECU 10. The configuration is such that, in response to a startup cluster information (also known as PN request information) included in an NM message requesting startup of the cluster to which each ECU 20, 30, 50, 60, 70, 90, and 100 belongs, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 switches from the power-off state or sleep state to the startup state. In addition, PNC setting information can also be set for the power / startup management ECU10 and the first and second upper-level ECUs 40 and 80.
[0035] The first to seventh lower-level ECUs (20, 30, 50, 60, 70, 90, and 100) periodically send NM messages to other ECUs during their normal operation period after transitioning from the startup state to the normal operation mode. Additionally, the power / startup management ECU 10 and the first and second upper-level ECUs (40 and 80) also periodically send NM messages when continued control is required. Furthermore, after performing necessary processing, if the first to seventh lower-level ECUs (20, 30, 50, 60, 70, 90, and 100) enter a state where normal operation is no longer required, they cease periodically sending NM messages. If the third to seventh lower-level ECUs (50, 60, 70, 90, and 100) do not receive NM messages from other ECUs belonging to the same cluster for a specified standby time, they transition from the normal operation mode to the power-saving mode, switching from the startup state to the sleep state. Regarding the first and second lower-level ECUs 20 and 30, the power / startup management ECU 10 monitors the NM messages sent to the first and second lower-level ECUs 20 and 30. Furthermore, if the time for which no NM message is received from the first and second lower-level ECUs 20 and 30 is reached reaches a predetermined standby time, the power / startup management ECU 10 disconnects the first and second relay circuits 17 and 18, stopping the power supply to the first and second lower-level ECUs 20 and 30.
[0036] The third to seventh lower-level ECUs 50, 60, 70, 90, and 100 have communication IFs 51, 61, 71, 91, and 101, respectively, capable of receiving NM messages in sleep mode and switching from sleep mode to start mode based on the received NM messages. If the ECUs are set to start mode via communication IFs 51, 61, 71, 91, and 101, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 determine whether they have requested their own start based on the PN request information and PNC setting information in the NM message. If they determine that they have requested their own start, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 remain in the start mode as is. On the other hand, if they determine that they have not requested their own start, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 return to sleep mode. Alternatively, the determination of PN request information and PNC setting information based on NM messages can be performed in communication IF51, 61, 71, 91, and 101. In this case, if communication IF51, 61, 71, 91, and 101 determines that a start request has been made based on the PN request information and PNC setting information, the corresponding ECU is switched from sleep state to start state. The following is a detailed explanation of an example of NM messages, PN request information, and PNC setting information.
[0037] For example, such as Figure 2 As shown, the NM message contains data in bytes 0 to 7. Byte 0 contains the Node ID (NID). The Node ID is a unique identifier for each of the power / startup management ECU 10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100. The Node ID identifies the source of the NM message. Byte 1 contains the Control Bit Vector (CBV). The Control Bit Vector indicates whether local networking is used. When the Control Bit Vector indicates that local networking is used, the user data area in bytes 2 to 7 contains startup cluster information, i.e., PN request information, representing the corresponding startup cluster. Furthermore, local networking means setting only ECUs belonging to a portion of the clusters to the startup state, while setting ECUs belonging to the remaining clusters to the power-off state or sleep state. In this way, by only enabling the ECUs that need to operate to the startup state, the power consumption of each ECU in the vehicle can be reduced.
[0038] exist Figure 2 In the example shown, the control bit vector indicates the use of local networking, and PN request information is stored in bytes 6 and 7 of the user data area. The user data area, bytes 2 through 5, can be used to transmit any information, such as ECU starting factors and information related to normal or abnormal conditions. Furthermore, Figure 2 This is just one example of the NM message format. NM messages can also take other forms, as long as they include information about the presence or absence of local networking and PN request information.
[0039] The PN request information is organized according to each of the multiple clusters, indicating which clusters should be started and which do not. More specifically, in Figure 2 In the example shown, the clusters are pre-divided into 16. Furthermore, the PN request information contains 16 bits of data corresponding to each of the 16 pre-divided clusters. That is, the 16 bits of the PN request information correspond to the 16 pre-divided clusters. When each of the 16 bits of the PN request information is "0", it indicates that the corresponding cluster does not need to be started. On the other hand, when each of the 16 bits of the PN request information is "1", it indicates that the corresponding cluster needs to be started.
[0040] As described above, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 have PNC configuration information indicating the cluster they belong to within a plurality of clusters. One example of this PNC configuration information is... Figure 2 As shown. More specifically, Figure 2 This example shows the PNC setting information stored by any one of the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100. Figure 2In the PNC configuration information shown, when the corresponding clusters are classified as A to P from left to right in the diagram, Figure 2 The PNC setting information indicates that the ECU holding this PNC setting information belongs to clusters D, H, and J. The first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 can belong to more than one cluster because they can perform various functions through program execution.
[0041] If the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 receive an NM message containing PN request information via their respective communication IF51, 61, 71, 91, and 101, then... Figure 2 As shown, the PN request information and PNC setting information are compared bit by bit, for example, by performing a logical AND operation. That is, if the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 receive an NM message in their respective communication IFs 51, 61, 71, 91, and 101, they temporarily enter the startup state. Then, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 determine whether the cluster requested to start via the PN request information contained in the NM message is consistent with the cluster of PNC setting information allocated to the third to seventh lower-level ECUs 50, 60, 70, 90, and 100. For example, in... Figure 2 In the example shown, the clusters requested to be started via the PN request information are clusters D, G, I, M, N, and O. The clusters to which the ECU belongs, as indicated by the PNC configuration information, are clusters D, H, and J. In this case, within cluster D, the cluster requested to be started via the PN request information contained in the NM message is consistent with the cluster in the PNC configuration information. Therefore, as... Figure 2 As shown, the result of the logical AND operation is "1" in cluster D.
[0042] When the result of a logical AND operation is a "1" in a certain bit, it has the following properties: Figure 2 The ECU shown in the PNC setting information has been determined to have requested the start of this ECU. Based on this determination, the ECU with… Figure 2 The ECU, as shown in the PNC setting information, maintains its state from sleep to start if it is already in start mode, and remains in start mode if it is already in start mode. On the other hand, if the result of the logical AND operation is all 0s and none of the bits are "1", then... Figure 2 The ECU shown in the PNC setting information is determined to have not requested its own startup. In this case, the ECU with... Figure 2 The ECU, displaying the PNC setting information, discards the received NM message and returns to sleep mode.
[0043] Thus, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 have the function of identifying whether an NM message is a request to start the ECU based on PNC setting information. Through this NM message identification function, only the third to seventh lower-level ECUs 50, 60, 70, 90, and 100, which have PNC setting information containing clusters that have requested startup via PN request information, will enter the startup state via an NM message. Hereinafter, an ECU capable of receiving NM messages in its sleep state and switching the ECU from sleep state to startup state will be referred to as an NM-responsive ECU.
[0044] In the vehicle network system 200 of this embodiment, the first and second lower-level ECUs 20 and 30 do not necessarily need to be NM-responsive ECUs. In other words, the first and second lower-level ECUs 20 and 30 can both be NM-non-responsive ECUs. As described above, an NM-responsive ECU has a communication IF that receives NM messages in the sleep state of the ECU and switches the ECU from the sleep state to the start state. Therefore, an NM-responsive ECU is more expensive than an NM-non-responsive ECU. As described above, the first and second lower-level ECUs 20 and 30 can be NM-non-responsive ECUs. Therefore, by using NM-non-responsive ECUs, i.e., the first and second lower-level ECUs 20 and 30, as lower-level control devices, the overall cost of the vehicle network system 200 can be reduced.
[0045] The vehicle network system 200 of this embodiment configures the power / start management ECU 10 such that, although the first and second lower-level ECUs 20 and 30 are NM non-responding ECUs, the first and second lower-level ECUs 20 and 30 are objects of local networking corresponding to NM messages. The power / start management ECU 10 of this embodiment will be described in detail below.
[0046] like Figure 1 As shown, the power / start management ECU 10 includes a communication IF 11, a start management unit 12, a power management unit 13, a storage unit 14, an anomaly detection unit 15, a PNC switching unit 16, and first and second relay circuits 17 and 18. The start management unit 12, power management unit 13, anomaly detection unit 15, and PNC switching unit 16 are functional units constructed within the power / start management ECU 10 via software and / or hardware. The storage unit 14 can be constructed using the storage device of the power / start management ECU 10.
[0047] The first relay circuit 17 is provided on the power supply line 6 for supplying power to the first lower-level ECU 20. In other words, the power line of the first lower-level ECU 20 is connected to the first power port 17a connected to the first relay circuit 17. The second relay circuit 18 is provided on the power supply line 6 for supplying power to the second lower-level ECU 30. In other words, the power line of the second lower-level ECU 30 is connected to the second power port 18a connected to the second relay circuit 18.
[0048] Furthermore, the number of relay circuits installed in the power / startup management ECU 10 can be three or more, instead of two. Additionally, the number of lower-level ECUs connected to each relay circuit can be two or more, instead of one. Moreover, in the vehicle network system 200, the combination of upper-level ECUs and lower-level ECUs capable of switching power supply to and from the lower-level ECUs can be multiple sets, not just one.
[0049] The power supply circuit 4 can convert the power supply voltage of the battery 2 installed in the vehicle into the operating voltage of the power / start management ECU 10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 as needed. It supplies voltage from the power supply circuit 4 to the power supply lines 6 of the power / start management ECU 10, the first and second upper-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100.
[0050] The first and second relay circuits 17 and 18 can be constructed, for example, using semiconductor switches such as MOSFETs and IGBTs. However, the first and second relay circuits 17 and 18 can also be constructed using conventional mechanical relays instead of semiconductor switches. Furthermore, as... Figure 1 As shown, the first and second relay circuits 17 and 18 can be located inside the power / start management ECU 10 or outside the power / start management ECU 10.
[0051] The power / startup management ECU 10 is an NM response ECU capable of receiving NM messages. As described above, the first and second lower-level ECUs 20 and 30 can be NM non-response ECUs. In this embodiment, the first and second lower-level ECUs 20 and 30 are in a power-saving mode with their power cut off when no operation is required. Therefore, the first and second lower-level ECUs 20 and 30 cannot receive NM messages when in power-saving mode. Therefore, the communication IF 11 of the power / startup management ECU 10 receives NM messages that selectively instruct the first and second lower-level ECUs 20 and 30 to start, instead of the first and second lower-level ECUs 20 and 30. The NM messages received by the communication IF 11 are provided to the startup management unit 12.
[0052] Here, the storage unit 14 of the power / startup management ECU 10 stores, in addition to the programs executed by the processor of the power / startup management ECU 10, PNC setting information assigned to the first and second lower-level ECUs 20 and 30, respectively, indicating the cluster to which each of the first and second lower-level ECUs 20 and 30 belongs. This PNC setting information includes PNC setting information used during normal operation and PNC setting information used when an abnormality occurs. Furthermore, the storage unit 14 stores relay connection information indicating the correspondence between the first and second relay circuits 17 and 18 and the first and second lower-level ECUs 20 and 30. For example, the storage unit 14 can use, for example... Figure 3 The PNC configuration table shown stores the PNC configuration information representing the cluster, respectively assigned to the first and second lower-level ECUs 20 and 30. Furthermore, Figure 3 The illustrated PNC settings represent an example of the correspondence between the inherent identifiers (node IDs) of multiple lower-level ECUs, including the first and second lower-level ECUs 20 and 30, and the PNC setting information assigned to these lower-level ECUs. Additionally, relay connection information indicating the correspondence between the first and second relay circuits 17 and 18 and the first and second lower-level ECUs 20 and 30 is shown below. Figure 4 As illustrated, the storage unit 14 stores the correspondence between the numbers of multiple relay circuits, including the first and second relay circuits 17 and 18, or the numbers of power ports, and the node IDs that represent the inherent identifiers of multiple lower-level ECUs, including the first and second lower-level ECUs 20 and 30.
[0053] The start management unit 12 of the power / start management ECU10 is referenced Figure 3The illustrated PNC setting table can obtain the PNC setting information of the first and second lower-level ECUs 20 and 30 respectively. Furthermore, the startup management unit 12 can determine which lower-level ECU 20 or 30 was instructed to start via the NM message based on the obtained PNC setting information of the first and second lower-level ECUs 20 and 30 and the PN request information of the NM message. Specifically, the startup management unit 12 compares the PN request information of the NM message with the PNC setting information of the first and second lower-level ECUs 20 and 30 bit by bit. If the startup management unit 12 determines, based on the comparison result, that there is PNC setting information containing a cluster that requested startup via the PN request information, it determines that the startup of the lower-level ECU 20 or 30 corresponding to that PNC setting information was instructed. In this case, the startup management unit 12 provides the node ID of the lower-level ECU 20 or 30 indicating that startup was instructed via the NM message to the power management unit 13. On the other hand, if the startup management unit 12 determines that there is no PNC setting information for a cluster that has requested startup through PN request information, it discards the NM message because the received NM message does not indicate the startup of any lower ECU 20 or 30.
[0054] When the power management unit 13 of the power / startup management ECU 10 receives the node ID of the lower-level ECU 20 or 30 that is instructed to be started from the startup management unit 12, it refers to the relay connection information stored in the storage unit 14, which indicates the correspondence between each relay circuit 17 or 18 and each lower-level ECU 20 or 30. Furthermore, the power management unit 13 determines the relay circuit 17 or 18 corresponding to the node ID of the lower-level ECU 20 or 30 that is instructed to be started, and outputs a drive signal to turn on the determined relay circuit 17 or 18. As a result, power is supplied via the relay circuit 17 or 18 corresponding to the lower-level ECU 20 or 30 that has been instructed to be started, and the corresponding lower-level ECU 20 or 30 enters the startup state.
[0055] The first and second lower-level ECUs 20 and 30 control various control devices installed in the vehicle that are controlled only when specific conditions are met or only in specific environments (e.g., door lock mechanisms, power window drive motors, headlight light sources, wiper motors, AV equipment, etc.), or calculate the specified physical quantities required for control based on sensor detection signals. For example, the door lock mechanism is controlled by the ECU for controlling the door lock mechanism when the user wants to enter or exit the vehicle. The power window drive motor is controlled by the ECU for controlling the power window when the user operates the window lift switch.
[0056] In this way, the first and second lower-level ECUs 20 and 30 control the controlled devices that operate only under specific conditions or in specific environments, or calculate the prescribed physical quantities required for such control. Therefore, when the power / startup management ECU 10 instructs the first and second lower-level ECUs 20 and 30 to start via an NM message, it connects the first and second relay circuits 17 and 18 corresponding to the first and second lower-level ECUs 20 and 30, supplying power to them. On the other hand, when the power / startup management ECU 10 does not instruct the first and second lower-level ECUs 20 and 30 to start via an NM message, it disconnects the first and second relay circuits 17 and 18, stopping the power supply to them. This cuts off the dark current when the lower-level ECUs 20 and 30 do not need to operate, further improving energy efficiency for the entire vehicle system.
[0057] NM messages can be generated by the power / startup management ECU 10, the first upper-level ECU 40, and / or the second upper-level ECU 80 as a function of a domain controller or area controller. In this case, the power / startup management ECU 10, the first upper-level ECU 40, and / or the second upper-level ECU 80 determine the function to be performed in the vehicle based on signals from various sensors and switches. Furthermore, if the power / startup management ECU 10, the first upper-level ECU 40, and / or the second upper-level ECU 80 determine that the desired function needs to be performed, they further determine the cluster to which the ECUs that need to be in a startup state simultaneously belong when performing the corresponding function, and generate an NM message containing PN request information specified as the startup cluster. The generated NM message is sent to the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, 100, etc., via communication buses 19a, 19b, 19c, 43a, 43b, 82a, 82b. Furthermore, when the NM message is generated by the power / start management ECU 10, it is also used to determine whether the lower-level ECUs 20 and 30 of the power / start management ECU 10 need to switch to the start state. However, the function of determining the function to be performed in the vehicle and sending an NM message containing PN request information can be performed by other ECUs, such as the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100, in addition to the power / start management ECU 10 and the first and second upper-level ECUs 40 and 80.
[0058] In addition, the power / startup management ECU10, the first host ECU40 and / or the second host ECU80 can also go into sleep mode when all ECUs belonging to the vehicle network system 200 are in sleep mode or power-off mode and the time without receiving NM messages reaches a specified time.
[0059] Furthermore, a PNC setting information modification unit 42, which modifies the PNC setting information allocated to each of the lower ECUs 200 (such as the power / startup management ECU 10, the first and second upper ECUs 40 and 80), can be installed in any of the ECUs belonging to the vehicle network system 200. Figure 1 The image shows an example where the PNC setting information change unit 42 is installed on the first upper ECU 40.
[0060] The first host ECU 40, equipped with the PNC setting information change unit 42, has an external communicator capable of wirelessly communicating with an external server such as a data center. Furthermore, the first host ECU 40 is configured to download applications for implementing new functions in the vehicle, and update programs for upgrading existing programs installed in any of the ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100, from the data center via the external communicator. The downloaded programs are provided to the corresponding ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 via communication buses 19a, 19b, 19c, 43a, 43b, 82a, and 82b, performing the installation of new applications and the rewriting of update programs. Moreover, the ECU communicating with the data center via the external communicator and the ECU equipped with the PNC setting information change unit 42 can be different ECUs.
[0061] For ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 that have installed new applications or updates, it is generally considered that the corresponding ECU's startup conditions need to be added or changed, depending on the function of the application or update. Therefore, in cases where it is necessary to add or change the startup conditions of an ECU with an installed application or update, the data center will download the new PNC setting information corresponding to the addition or change of startup conditions, along with the application or update, to the first host ECU 40.
[0062] When the PNC setting information modification unit 42 obtains new PNC setting information from the data center, it modifies (rewrites) the PNC setting information stored in ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 that have installed the application or update program. As a result, ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 that have installed the application or update program switch from sleep mode to start mode according to the cluster represented by the modified PNC setting information. The PNC setting information modification can be performed in the corresponding ECU when a modification instruction is received from the PNC setting information modification unit 42 along with the new PNC setting information. Alternatively, the PNC setting information modification can be performed by having the PNC setting information modification unit 42 access the memory of the corresponding ECU.
[0063] Furthermore, the PNC setting information modification unit 42 can also be installed outside the vehicle network system 200, such as in a data center, instead of within the ECU belonging to the vehicle network system 200. However, if the PNC setting information modification unit 42 is installed within the ECU belonging to the vehicle network system 200, the PNC setting information modification unit 42 can terminate communication with the outside once it obtains the data for modifying the PNC setting information of the ECU from the outside. On the other hand, if the PNC setting information modification unit 42 is installed on a server outside the vehicle network system 200, the ECU that needs to modify the PNC setting information must communicate separately with the external server via an ECU equipped with an external communicator. Therefore, this may result in a potential increase in communication volume with the external server.
[0064] If the first upper-level ECU 40, which is equivalent to the management and control device of this disclosure and is equipped with a PNC setting information modification unit 42, malfunctions or communication with the first upper-level ECU 40 malfunctions, the first upper-level ECU 40 may be unable to properly modify the PNC setting information of each lower-level ECU. As a result, there is a concern that the startup of the ECUs may not be properly controlled, for example, at least one ECU may start unintentionally at a set time based on an NM message, unnecessarily consuming power.
[0065] Therefore, in the vehicle network system 200 of this embodiment, the power / startup management ECU 10 is provided with an anomaly detection unit 15 for detecting anomalies in the first upper-level ECU 40 and / or communication anomalies with the first upper-level ECU 40. Furthermore, a PNC switching unit 16 is provided, which, when the anomaly detection unit 15 detects an anomaly in the first upper-level ECU 40 and / or communication anomalies with the first upper-level ECU 40, switches at least the PNC setting information of the first and second lower-level ECUs 20 and 30 from the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs. The anomaly detection unit 15 and the PNC switching unit 16 will be described in detail below.
[0066] The power / start management ECU 10 is configured to periodically communicate with the first host ECU 40 via the communication bus 19a. If this periodic communication is interrupted for more than a predetermined time, the anomaly detection unit 15 of the power / start management ECU 10 can detect that an anomaly has occurred in the communication with the first host ECU 40. At this time, since a communication interruption also occurs in the first host ECU 40, an anomaly in the communication with the power / start management ECU 10 can be detected.
[0067] Furthermore, when the power / startup management ECU 10 communicates with the first host ECU 40 via CAN, the anomaly detection unit 15 can detect an anomaly in the received communication data itself due to communication errors such as bit errors, format errors, ACK errors, CRC errors, or padding errors in the communication frame (communication data), thus detecting an anomaly in communication with the first host ECU 40. Moreover, the method for detecting communication errors can vary depending on the communication standard and communication method. Preferably, the power / startup management ECU 10 notifies the first host ECU 40 that an anomaly in the communication data has been detected. Therefore, the first host ECU 40 can also detect an anomaly in communication with the power / startup management ECU 10.
[0068] In addition, the power / startup management ECU 10 may have the function of monitoring whether the first upper-level ECU 40 is operating normally based on control-related data values received from the first upper-level ECU 40. For example, the power / startup management ECU 10 can receive control command values output by the first upper-level ECU 40 to the third to fifth lower-level ECUs 50, 60, and 70, sensor detection values calculated by the first upper-level ECU 40, and / or self-diagnostic results of the first upper-level ECU 40 as control-related data values.
[0069] When the power / startup management ECU 10 receives control command values and / or sensor detection values as control-related data values, its anomaly detection unit 15 can determine whether the first upper-level ECU 40 is functioning correctly based on whether each data value converges within a predetermined range that can be considered normal. In other words, the anomaly detection unit 15 can detect an anomaly in the first upper-level ECU 40 if the received data values deviate from the predetermined range. Furthermore, when the anomaly detection unit 15 receives the self-diagnostic result of the first upper-level ECU 40 as control-related data values, it can detect an anomaly in the first upper-level ECU 40 if the self-diagnostic result indicates that the first upper-level ECU 40 has experienced some kind of anomaly. Moreover, the self-diagnostic result of the first upper-level ECU 40 is included in the control-related data values because it affects the control of the first upper-level ECU 40 and other ECUs.
[0070] In the above description, an example was given of the power / startup management ECU 10's fault detection unit 15 detecting faults in the first upper-level ECU 40 and faults in communication with the first upper-level ECU 40. However, the fault detection unit for detecting faults in the first upper-level ECU 40 and the fault detection unit for detecting faults in communication with the first upper-level ECU 40 can also be provided in different ECUs. For example, the fault detection unit for detecting faults in communication with the first upper-level ECU 40 can be provided in the power / startup management ECU 10, and the fault detection units for detecting faults in the first upper-level ECU 40 can be provided in the third to fifth lower-level ECUs 50, 60, and 70, which are lower-level ECUs of the first upper-level ECU 40. In addition, in the above description, an example was given of the fault detection unit 15 being provided in the power / startup management ECU 10. However, the fault detection unit 15 can also be provided in an ECU other than the power / startup management ECU 10. Moreover, the fault detection unit 15 can also be provided in multiple ECUs, including the power / startup management ECU 10.
[0071] If the anomaly detection unit 15 detects an anomaly in the first upper-level ECU 40 and / or an anomaly in communication with the first upper-level ECU 40, then the PNC switching unit 16 of the power / start management ECU 10 will switch the PNC setting information of the first and second lower-level ECUs 20 and 30 from the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs. Furthermore, if the PNC setting information of the power / start management ECU 10 is also determined, the PNC switching unit 16 can also switch the PNC setting information of the power / start management ECU 10 to the PNC setting information used when an anomaly occurs.
[0072] To enable this switching, the storage unit 14 stores, at least for each lower-level ECU 20, 30, PNC setting information used during normal operation and PNC setting information used during abnormal operation. If no abnormality is detected in the first upper-level ECU 40 and / or communication abnormality with the first upper-level ECU 40, the PNC setting information used during normal operation is used as the PNC setting information for each lower-level ECU 20, 30. However, when an abnormality is detected in the first upper-level ECU 40 and / or communication abnormality with the first upper-level ECU 40, as described above, the PNC switching unit 16 switches the PNC setting information used during normal operation to the PNC setting information used during abnormal operation. As a result, the power / startup management ECU 10 can perform switching between the start state and power-off state of at least the lower-level ECUs 20, 30 based on NM messages, according to the PNC setting information used during abnormal operation. Furthermore, even in the event of an anomaly in the first upper ECU 40 and / or an anomaly in communication with the first upper ECU 40, the power / startup management ECU 10 is still able to receive NM messages from the second upper ECU 80, the first or second lower ECU 20, 30, and the sixth or seventh lower ECU 90, 100, etc.
[0073] In the PNC setting information used in the event of an anomaly, at least the cluster of lower-level ECUs related to the execution of controls concerning vehicle operation and occupant safety is set to be activated. Therefore, even if an anomaly occurs in the first higher-level ECU 40 and / or a communication anomaly occurs with the first higher-level ECU 40, the safety of vehicle operation and occupants can be ensured. Thus, for example, the vehicle driver can safely drive the vehicle to a safe escape location or the nearest repair shop. For example, lower-level ECUs related to the execution of controls concerning vehicle operation include ECUs related to powertrain (engine, motor) control, steering control, braking control, headlight control, etc. Additionally, lower-level ECUs related to the execution of controls concerning occupant safety include ECUs related to airbag control, advanced driver assistance system (ADAS) control, emergency reporting system control, etc.
[0074] Conversely, in the PNC settings used when an anomaly occurs, clusters to which lower-level ECUs not related to the control functions related to vehicle operation and occupant safety belong are set to be disabled. For example, lower-level ECUs not related to the control functions related to vehicle operation and occupant safety include those related to navigation control, audio control, interior lighting control, and seat control. By disabling these lower-level ECUs, energy efficiency can be achieved, and sufficient avoidance distance can be ensured. Furthermore, in the PNC settings used when an anomaly occurs, it is not necessary to disable all clusters to which lower-level ECUs not related to the control functions related to vehicle operation and occupant safety belong. For example, only at least one cluster to which lower-level ECUs not related to the control functions related to vehicle operation and occupant safety belong may be disabled.
[0075] The PNC switching unit 16 can be provided in the same manner as the anomaly detection unit 15 in multiple ECUs (upper-level ECU and lower-level ECU) that store PNC setting information. Preferably, the ECU that initially detects an anomaly in the first upper-level ECU 40 and / or an anomaly in communication with the first upper-level ECU 40 (e.g., power / start management ECU 10) sends information to the other multiple ECUs that store PNC setting information to switch the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs. Preferably, in response to receiving this information, each of the multiple ECUs that store PNC setting information switches the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs. Thus, as a whole vehicle, ECUs related to the execution of controls related to vehicle operation and occupant safety can be set to be startable, while ECUs not related to the execution of controls related to vehicle operation and occupant safety can be set to be non-startable.
[0076] In sending information to switch the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs, for example, a notification may be included indicating that an ECU that has detected an anomaly in the first upper-level ECU 40 and / or an anomaly in communication with the first upper-level ECU 40 has switched to the PNC setting information used when an anomaly occurs. Furthermore, in sending information to switch the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs, the ECU that has detected an anomaly in the first upper-level ECU 40 and / or an anomaly in communication with the first upper-level ECU 40 may send a switching instruction to multiple other ECUs to switch to the PNC setting information used when an anomaly occurs. Moreover, if the first upper-level ECU 40, for example, detects an anomaly in communication with at least one ECU, the first upper-level ECU 40 may also send information to multiple other ECUs that hold PNC setting information to switch the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs.
[0077] Thus, in the vehicle network system 200 of this embodiment, if the first upper-level ECU 40 malfunctions or communication with the first upper-level ECU 40 malfunctions, at least one ECU that detects the malfunction switches the PNC setting information used during normal operation to the PNC setting information used when the malfunction occurs. As a result, at least one ECU starts according to the PNC setting information used when the malfunction occurs. Therefore, even if the first upper-level ECU 40 malfunctions or communication with the first upper-level ECU 40 malfunctions, the startup of at least one ECU that detects the malfunction can be appropriately controlled.
[0078] Next, refer to Figure 5 and Figure 6 The flowchart illustrates an example of the processing performed in the power / startup management ECU 10 and the first and second lower-level ECUs 20 and 30. Furthermore, when other ECUs are also equipped with an anomaly detection unit 15 and a PNC switching unit 16, the same processing is performed, except for the control of connecting and disconnecting relay circuits.
[0079] In step S100, the power / startup management ECU 10 determines whether an anomaly of the first host ECU 40 and / or a communication anomaly with the first host ECU 40 has been detected. If an anomaly is detected, the power / startup management ECU 10 proceeds to step S110. On the other hand, if no anomaly is detected, the power / startup management ECU 10 proceeds to step S130.
[0080] In step S110, the power / startup management ECU 10 switches the PNC setting information of at least the first and second lower-level ECUs 20 and 30 from the PNC setting information used during normal operation to the PNC setting information used when an abnormality occurs. Then, in step S120, the power / startup management ECU 10 sends information to the other multiple ECUs that hold PNC setting information to switch the PNC setting information used during normal operation to the PNC setting information used when an abnormality occurs.
[0081] In step S130, the power / startup management ECU 10 receives or generates an NM message. In step S140, the power / startup management ECU 10 performs a startup ECU determination process to determine the lower-level ECUs 20 and 30 that have indicated startup via the NM message. Details of this startup ECU determination process are as follows: Figure 6 The flowchart is shown below. Refer to the following... Figure 6 The flowchart illustrates the ECU startup determination process.
[0082] In step S300, the power / startup management ECU 10 determines the cluster to be started based on the PN request information in the NM message. In step S310, the power / startup management ECU 10 reads the PNC setting information of multiple lower-level ECUs 20 and 30 from the storage unit 14. At this time, if the PNC setting information is switched from the PNC setting information used during normal operation to the PNC setting information used when an abnormality occurs, the power / startup management ECU 10 reads the PNC setting information used when an abnormality occurs from the storage unit 14. Then, in step S320, the power / startup management ECU 10 determines the PNC setting information of the cluster that is consistent with the cluster that requested start via the PN request information (startup request cluster).
[0083] In step S330, the power / startup management ECU 10 determines whether, in step S320, at least one PNC setting information from the plurality of lower-level ECUs 20, 30 was determined to contain a cluster consistent with the start request cluster. If at least one PNC setting information is determined, the power / startup management ECU 10 proceeds to step S340. On the other hand, if no determined PNC setting information is found, the power / startup management ECU 10 proceeds to step S350.
[0084] In step S340, the power / startup management ECU 10 sets the lower-level ECUs 20 and 30 corresponding to the determined PNC setting information as start ECUs, and sets all other lower-level ECUs 20 and 30 as non-start ECUs. Conversely, in step S350, the power / startup management ECU 10 sets all lower-level ECUs 20 and 30 as non-start ECUs. Afterwards, the power / startup management ECU 10 returns to... Figure 5 The process is shown in the flowchart.
[0085] exist Figure 5 In step S150 of the flowchart, the power / startup management ECU 10 determines whether there are any subordinate ECUs 20 and 30 that are set as start ECUs. If there are subordinate ECUs 20 and 30 that are set as start ECUs, the power / startup management ECU 10 proceeds to step S160. On the other hand, if there are no subordinate ECUs 20 and 30 that are set as start ECUs, the power / startup management ECU 10 terminates. Figure 5 The process is illustrated in the flowchart. In this case, the NM message is discarded.
[0086] In step S160, the power / startup management ECU 10 connects the relay circuits 17 and 18 connected to the lower-level ECUs 20 and 30 that are set as start ECUs, based on the relay connection information stored in the storage unit 14 indicating the correspondence between each relay circuit 17 and 18 and each lower-level ECU 20 and 30. Conversely, the power / startup management ECU 10 disconnects the relay circuits 17 and 18 connected to the lower-level ECUs 20 and 30 that are set as non-start ECUs.
[0087] like Figure 5 As shown in step S200 of the flowchart, the lower-level ECUs 20 and 30 connected by relay circuits 17 and 18 begin to receive power. Thus, the lower-level ECUs 20 and 30 connected by relay circuits 17 and 18 undergo the prescribed startup process in step S210 and enter the startup state.
[0088] As described above, in the vehicle network system 200 according to this embodiment, the power / startup management ECU 10 receives NM messages sent via the communication bus, selectively instructing the startup of multiple lower-level ECUs 20 and 30, instead of the multiple lower-level ECUs 20 and 30. Furthermore, the power / startup management ECU 10 connects to relay circuits 17 and 18 connected to the lower-level ECUs 20 and 30 that have been instructed to start via the NM messages. Thus, the lower-level ECUs 20 and 30 that have been instructed to start are in a startup state. Therefore, the vehicle network system 200 according to this embodiment is configured to switch the power supply of the lower-level ECUs 20 and 30 from a stopped state to a supplied state based on the NM messages instructing startup, and can perform detailed management of the power supply and shutdown of the lower-level ECUs 20 and 30.
[0089] (Second Implementation) Next, a second embodiment of the in-vehicle network system and the control method for the in-vehicle network system disclosed herein will be described. Furthermore, the in-vehicle network system of this embodiment is configured similarly to the in-vehicle network system 200 of the first embodiment. Therefore, descriptions related to its configuration will be omitted.
[0090] Figure 7 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU 10 of this embodiment. Furthermore, in Figure 7 In the flowchart, for execution and Figure 5 The flowchart shown illustrates the same processing steps, with explanations omitted by assigning the same step numbers.
[0091] like Figure 7 As shown in the flowchart, in step S120, the power / startup management ECU 10 of this embodiment sends information to multiple other ECUs that hold PNC setting information, indicating a switch from the PNC setting information used during normal operation to the PNC setting information used when an anomaly occurs. Next, in step S122, the power / startup management ECU 10 suspends anomaly determination based on communication interruptions with other ECUs for a predetermined period of time.
[0092] As described above, each lower-level ECU 20, 30, 50, 60, 70, 90, and 100, when in the startup state and transitioning to normal operating mode, periodically sends NM messages to other ECUs during their normal operation. Furthermore, the power / startup management ECU 10 and the first and second upper-level ECUs 40 and 80 also periodically send NM messages during periods when continued control is required. Therefore, if communication with the ECUs that are required to periodically send and receive NM messages is interrupted for a specified period, each ECU 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 can determine that the ECU has experienced some abnormality, including communication abnormalities.
[0093] However, the switching of PNC setting information between the power / startup management ECU 10 and its subordinate ECUs 20 and 30, as well as the switching of PNC setting information between multiple other ECUs based on information used to switch from PNC setting information for normal operation to PNC setting information used in case of an anomaly, do not necessarily occur simultaneously. Therefore, due to the staggered timing of the switching, the cluster of ECUs that should be switched to the start state based on the PNC setting information may differ. Consequently, in cases where anomaly determination is based on communication interruptions between ECUs, erroneous anomaly determinations may be made.
[0094] Therefore, in this embodiment, through the processing in step S122, in multiple ECUs including the power / startup management ECU 10, during a predetermined period of time corresponding to the period for completing the switching of PNC setting information, the abnormal determination based on communication interruption with other ECUs is stopped. This prevents erroneous abnormal determination based on communication interruption with other ECUs.
[0095] (Third Implementation) Next, a third embodiment of the in-vehicle network system and the control method for the in-vehicle network system disclosed herein will be described. Furthermore, the in-vehicle network system of this embodiment is configured similarly to the in-vehicle network system 200 of the first embodiment. Therefore, descriptions related to its configuration will be omitted.
[0096] Figure 8 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU 10 of this embodiment. Furthermore, in Figure 8 In the flowchart, for execution and Figure 5 The flowchart shown illustrates the same processing steps, with explanations omitted by assigning the same step numbers.
[0097] like Figure 8 As shown in the flowchart, in step S124, the power / start management ECU 10 of this embodiment determines whether the remaining capacity of the battery 2 has decreased to below a predetermined value. In this determination process, if it is determined that the remaining capacity of the battery 2 has decreased to below the predetermined value, the power / start management ECU 10 proceeds to step S126.
[0098] In step S126, the power / startup management ECU 10 switches the PNC setting information used in case of an anomaly to reduce the number of clusters that are set to be able to start. This makes it easier to ensure sufficient power for avoiding driving by changing the number of clusters started according to the PNC setting information used in case of an anomaly based on the remaining battery level of the battery 2.
[0099] In this embodiment, the storage unit 14 stores multiple types of PNC setting information, each containing a different number of clusters that are set to be activated, as PNC setting information used in case of an anomaly. These multiple types of PNC setting information may, for example, contain information that sets the number of clusters that are set to be inactive to be different from those belonging to the clusters to which the ECUs performing controls related to vehicle operation and occupant safety belong. Furthermore, these multiple types of PNC setting information may, for example, contain information that sets the number of clusters that are set to be inactive to be different from those belonging to the clusters to which the ECUs performing controls related to vehicle operation and occupant safety belong.
[0100] For example, Figure 9 This illustrates an example where the number of clusters set to be disabled for operation varies depending on the remaining capacity of battery 2, within the same cluster of ECUs responsible for controls related to vehicle operation and occupant safety. Specifically, in Figure 9 In the example shown, when the battery 2 has a relatively large remaining charge, the PNC settings information shows that the clusters of ECUs related to vehicle movement (driving, stopping, turning) and the clusters of ECUs related to occupant safety are both set to be able to start. On the other hand, when the battery 2 has a relatively small remaining charge, the PNC settings information shows that the clusters of ECUs related to vehicle movement are set to be able to start, while the clusters of ECUs related to occupant safety are set to not be able to start.
[0101] Alternatively, the cluster setting information used when an anomaly occurs can be switched to a smaller number of clusters that are set to be activated, based on the remaining battery level of battery 2, or based on whether the elapsed time since the anomaly was detected exceeds a specified time, and / or whether the travel distance since the anomaly was detected exceeds a specified distance. Furthermore, by setting multiple thresholds for the remaining battery level of battery 2, elapsed time, and / or travel distance, the switching of the cluster setting information used when an anomaly occurs can be performed multiple times, instead of just once.
[0102] (Fourth Implementation) Next, a fourth embodiment of the in-vehicle network system and the control method for the in-vehicle network system disclosed herein will be described. Furthermore, the in-vehicle network system of this embodiment is configured similarly to the in-vehicle network system 200 of the first embodiment. Therefore, descriptions related to its configuration will be omitted.
[0103] Figure 10 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU 10 of this embodiment. Furthermore, in Figure 10 In the flowchart, for execution and Figure 5The flowchart shown illustrates the same processing steps, with explanations omitted by assigning the same step numbers.
[0104] like Figure 10 As shown in the flowchart, if the power / startup management ECU 10 of this embodiment determines in step S100 that an abnormality of the first upper-level ECU 40 and / or an abnormality in communication with the first upper-level ECU 40 has been detected, then the processing in step S102 is executed. In step S102, the power / startup management ECU 10 acquires environmental information such as the time information, weather information, and / or external temperature information when the abnormality occurred. Then, in step S112, the power / startup management ECU 10 switches the PNC setting information of each lower-level ECU 20, 30 from the PNC setting information used during normal operation to the PNC setting information used when the abnormality occurs. The switched PNC setting information used when the abnormality occurs is selected based on the environmental information acquired in step S102.
[0105] In this embodiment, the storage unit 14 stores multiple types of PNC setting information, configured to suit the vehicle's environment at various times, as PNC setting information used in case of an anomaly. These multiple types of PNC setting information may include, for example, PNC setting information suitable for daytime hours and PNC setting information suitable for nighttime hours, depending on whether the cluster of ECUs controlling lighting such as headlights is activated. Additionally, these multiple types of PNC setting information may include, for example, PNC setting information for sunny days and PNC setting information for rainy days, depending on whether the cluster of ECUs controlling wipers is activated. Furthermore, these multiple types of PNC setting information may include, for example, PNC setting information for low and high temperatures and PNC setting information for normal temperatures, depending on whether the cluster of ECUs controlling the air conditioning system that regulates the air in the passenger compartment and the device that regulates the temperature of the driving battery is activated.
[0106] According to this embodiment, the PNC setting information used when an anomaly occurs can be PNC setting information that is appropriate for the vehicle's environment when an anomaly occurs.
[0107] Furthermore, this embodiment can be implemented in combination with the embodiments described above. For example, when combined with the third embodiment, multiple types of PNC setting information corresponding to the vehicle's environment when an anomaly occurs can be used to determine the number of clusters that can be started, which varies depending on the remaining battery level, elapsed time, and / or driving distance.
[0108] (Fifth implementation method) Next, a fifth embodiment of the in-vehicle network system and the control method for the in-vehicle network system disclosed herein will be described. Furthermore, the in-vehicle network system of this embodiment is configured similarly to the in-vehicle network system 200 of the first embodiment. Therefore, descriptions related to its configuration will be omitted.
[0109] Figure 11 This is a flowchart illustrating an example of the processing performed in the power / startup management ECU 10 of this embodiment. Furthermore, in Figure 11 In the flowchart, for execution and Figure 5 The flowchart shown illustrates the same processing steps, with explanations omitted by assigning the same step numbers.
[0110] like Figure 11 As shown in the flowchart, in step S128, the power / startup management ECU 10 of this embodiment connects and disconnects the first and second relay circuits 17 and 18 according to the PNC setting information used when an abnormality occurs after switching in step S110. In other words, regardless of the reception of the NM message, the power / startup management ECU 10 connects the relay circuits of the lower-level ECUs belonging to the cluster indicating startup and disconnects the relay circuits of the lower-level ECUs belonging to the cluster not indicating startup in the PNC setting information used when an abnormality occurs after switching.
[0111] According to this embodiment, when an anomaly occurs in the first upper-level ECU 40 and / or an anomaly occurs in communication with the first upper-level ECU 40, it is reliably possible to set at least the lower-level ECUs that are related to the execution of controls related to vehicle operation and occupant safety to an active state.
[0112] Furthermore, in this embodiment, even if an NM message is received in the power / startup management ECU 10, the on / off control of relay circuits 17 and 18 based on the NM message is not executed. The received NM message is discarded. Additionally, in this embodiment, an example is described where the first and second relay circuits 17 and 18 are turned on and off according to the PNC setting information used when an abnormality occurs after switching. However, it is also possible to consider the functions of each lower-level ECU 20 and 30 in advance, rather than the PNC setting information used when an abnormality occurs, to determine which relay circuits should be turned on and which should be turned off, store their on / off information, and turn the first and second relay circuits 17 and 18 on and off based on the stored on / off information.
[0113] The systems and methods described in this disclosure can also be implemented using a dedicated computer configured to perform one or more functions embodied in a computer program. The systems and methods described in this disclosure can also be implemented using dedicated hardware logic circuits. Alternatively, the systems and methods described in this disclosure can be implemented using one or more dedicated computers configured to perform a computer program and a combination of one or more hardware logic circuits. For example, some or all of the functions of the power / startup management ECU 10 can be implemented in hardware. Implementing a function in hardware includes using one or more ICs. Some or all of the functions of the power / startup management ECU 10 can also be implemented using any of a system-on-chip (SoC), an integrated circuit (IC), and a field-programmable gate array (FPGA). The concept of an IC also includes an application-specific integrated circuit (ASIC). Furthermore, the computer program can be stored as instructions to be executed by a computer on a computer-readable non-transitory tangible storage medium. The recording medium for the program can be an HDD (Hard-disk Drive), an SSD (Solid State Drive), flash memory, or the like. Additionally, the scope of this disclosure also includes non-transitional physical recording media such as the program used to enable the computer to function as the power / startup management ECU 10 and a semiconductor memory storing that program.
Claims
1. A vehicle-mounted network system, comprising multiple control devices in a vehicle connected to a communication bus and capable of communicating with each other, characterized in that, The plurality of control devices include a plurality of startup control object control devices, which have cluster setting information indicating the cluster to which they belong in a plurality of clusters. When a network management message (NM message) sent from other control devices contains startup cluster information indicating the cluster to be started that is consistent with the cluster setting information, the plurality of startup control object control devices either become started or remain started. The plurality of control devices further include a management control device capable of changing the cluster configuration information of the plurality of start control object control devices. The multiple start-up control object control devices have cluster setting information used during normal operation and cluster setting information used during abnormal operation as the cluster setting information. If at least one of the following situations is detected: an abnormality is detected in the management control device or an abnormality occurs in the communication with the management control device, the activation control object control device will switch the cluster setting information used during normal operation to the cluster setting information used when the abnormality occurs.
2. The vehicle network system according to claim 1, characterized in that, In the cluster setting information used when the anomaly occurs, at least the cluster to which the control device related to the execution of controls related to the driving of the vehicle and the safety of the occupants belongs is set to be able to start.
3. The vehicle network system according to claim 2, characterized in that, In the cluster setting information used when the anomaly occurs, clusters that do not belong to the control devices that perform controls related to the driving of the vehicle and the safety of the occupants are set as objects that cannot be started.
4. The vehicle network system according to any one of claims 1 to 3, characterized in that, At least one of the start-up control object control devices communicates periodically with the management control device, and detects an anomaly in communication with the management control device if the periodic communication is interrupted for more than a specified time, and / or if the received communication data itself is detected to be abnormal.
5. The vehicle network system according to any one of claims 1 to 3, characterized in that, At least one of the start-up control object control devices receives control-related data values from the management control device, and detects abnormalities in the management control device based on the received data values.
6. The vehicle network system according to any one of claims 1 to 3, characterized in that, If at least one of the startup control object control devices and / or the management control device detects an abnormality in the management control device or an abnormality in communication with the management control device, it sends information to other startup control object control devices to switch the cluster setting information used during normal operation to the cluster setting information used when the abnormality occurs.
7. The vehicle network system according to claim 6, characterized in that, When switching cluster setting information based on the information, the multiple startup control object control devices stop the abnormal judgment based on communication interruption with other startup control object control devices.
8. The vehicle network system according to any one of claims 1 to 3, characterized in that, Multiple cluster configuration information settings are prepared for use when an anomaly occurs. The start-up control object control device switches the cluster setting information used when an anomaly occurs based on the elapsed time since the anomaly occurred, the travel distance since the anomaly occurred, and / or the decrease in the remaining battery capacity storing the vehicle's driving power, so as to reduce the number of clusters set to be able to start.
9. The vehicle network system according to any one of claims 1 to 3, characterized in that, Multiple cluster configuration information settings are prepared for use when an anomaly occurs. The start-up control object control device selects one of the cluster setting information to be used from multiple cluster setting information used when an anomaly occurs, based on the time information, weather information and / or external temperature information when the anomaly occurs.
10. The vehicle network system according to any one of claims 1 to 3, characterized in that, The multiple start-up control objects control devices include a combination of an upper-level control device and the lower-level control device, which can use relay circuits to switch the lower-level control device on or off with power supply. The upper-level control device has a storage unit that stores cluster setting information indicating the cluster to which the lower-level control device belongs. The upper-level control device receives the NM message in place of the lower-level control device. When the cluster to be started indicated by the cluster start information in the NM message is consistent with the cluster setting information of the lower-level control device, the upper-level control device supplies power to the lower-level control device by turning on the relay circuit, thus setting the lower-level control device to the start state.
11. The vehicle network system according to claim 10, characterized in that, The storage unit stores cluster setting information used during normal operation and cluster setting information used during abnormal operation, which serves as the cluster setting information for the lower-level control device. When the upper-level control device detects an abnormality in the management control device or an abnormality in communication with the management control device, it switches the cluster setting information of the lower-level control device from the cluster setting information used during normal operation to the cluster setting information used when the abnormality occurs.
12. The vehicle network system according to claim 10, characterized in that, Multiple lower-level control devices are provided. The relay circuit is provided in multiple ways in conjunction with the multiple lower-level control devices. In addition to the cluster setting information of each of the multiple lower-level control devices, the storage unit also stores relay connection information indicating the correspondence between the multiple lower-level control devices and the multiple relay circuits.
13. The vehicle network system according to claim 12, characterized in that, Based on the cluster setting information and the relay connection information, the upper-level control device connects the relay circuit corresponding to the lower-level control device whose startup cluster specified by the startup cluster information contained in the NM message is consistent with the cluster in the cluster setting information, and disconnects the relay circuit corresponding to the lower-level control device whose startup cluster specified by the startup cluster information contained in the NM message is inconsistent with the cluster in the cluster setting information.
14. The vehicle network system according to claim 10, characterized in that, When the upper-level control device detects an abnormality in the management control device or an abnormality in communication with the management control device, it connects the relay circuit of the lower-level control device that is related to the execution of controls related to the driving of the vehicle and the safety of the occupants, and disconnects the relay circuit of the lower-level control device that is not related to the execution of controls related to the driving of the vehicle and the safety of the occupants.
15. The vehicle network system according to claim 14, characterized in that, The upper-level control device determines, based on the cluster setting information used when an anomaly occurs, whether the lower-level control device is related to performing controls related to the vehicle's operation and the safety of the occupants.
16. A control method for an in-vehicle network system, wherein the control method is for an in-vehicle network system having multiple control devices in a vehicle that are connected to a communication bus and capable of communicating with each other, characterized in that, The plurality of control devices include a plurality of startup control object control devices, which have cluster setting information indicating the cluster to which they belong in a plurality of clusters. When a network management message (NM message) sent from other control devices contains startup cluster information indicating the cluster to be started that is consistent with the cluster setting information, the plurality of startup control object control devices either become started or remain started. The plurality of control devices further include a management control device capable of changing the cluster configuration information of the plurality of start control object control devices. The multiple start-up control object control devices have cluster setting information used during normal operation and cluster setting information used during abnormal operation as the cluster setting information. The control method of the vehicle network system includes: The situation in which at least one of the start-up control object control devices detects an abnormality in the management control device or an abnormality in communication with the management control device; as well as If at least one of the following situations is detected: an abnormality is detected in the management control device or an abnormality occurs in the communication with the management control device, the start control object control device will switch the cluster setting information used during normal operation to the cluster setting information used when the abnormality occurs.