Vehicle system and control method of vehicle system

CN122607239APending Publication Date: 2026-08-21DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202610212067.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-02-21
Filing Date
2026-02-13
Publication Date
2026-08-21

AI Technical Summary

Benefits of technology

[0013]之后,上位侧控制装置将继电器电路接通,再次开始向下位控制装置的电力供给。由此,下位控制装置被强制地再启动。因此,本公开的车辆系统以及车辆系统的控制方法能够更可靠地促进下位控制装置的正常恢复。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122607239A_ABST
    Figure CN122607239A_ABST
Patent Text Reader

Abstract

A vehicle system and a control method of the vehicle system, in the vehicle system, first and second middle ECUs have first and second relay control sections that make relay circuits of power supply lines provided to first to third lower ECUs turn on or off, the first and second middle ECUs turn off the relay circuits by the relay control sections according to a case where communication with a lower ECU whose relay circuit is turned on is interrupted for a prescribed time, and thereafter turn on the relay circuits, whereby the lower ECU whose communication is interrupted is forcibly restarted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a vehicle system having multiple control devices mounted on the vehicle, and a method for controlling the vehicle system. Background Technology

[0002] For example, Patent Document 1 describes a vehicle system in which multiple electronic control units (ECUs) detect an ECU performing abnormal actions in other ECUs and send a reset signal to that ECU.

[0003] Existing technical documents Patent documents Patent Document 1: Japanese Patent Application Publication No. 2022-138678 Summary of the Invention

[0004] In recent years, with the aim of reducing power consumption in vehicle systems, local network operation has gradually been adopted, which only sets the electronic control units (ECUs) that need to perform actions to the active state, while keeping other ECUs in a dormant state.

[0005] Local network operation can be implemented as follows: First, ECUs are classified into multiple clusters for each function. Each ECU has cluster configuration information representing its respective cluster. Each ECU receives network management (hereinafter referred to as NM) messages containing startup cluster information indicating which cluster should be started. Each ECU starts up and enters an active state when its own cluster matches the cluster in the startup cluster information. On the other hand, each ECU remains in a dormant state when its own cluster does not match the cluster in the startup cluster information. As a result, only ECUs that perform the required functions can be started, while other ECUs remain dormant.

[0006] However, for example, when the ECU's communication interface receives NM messages and performs a consistency check between the ECU's cluster and the startup cluster information, if the cluster setting information is lost or corrupted, the ECU may not be able to start based on the NM messages. Alternatively, even if the ECU is in an active state, if some anomaly occurs within the ECU, such as CPU malfunction, the ECU may fail to operate normally.

[0007] Furthermore, the technology described in Patent Document 1 involves sending a reset signal to an ECU that is performing abnormal operations. As mentioned above, in cases where the ECU cannot start or is not operating normally, the reset signal may not reach the ECU. Therefore, the technology described in Patent Document 1 may not reliably prompt the ECU to return to normal operation.

[0008] This disclosure was made in view of the above-mentioned problems, and its purpose is to provide a vehicle system that can more reliably restore the control device to normal operation in the event of certain abnormalities in the control device, as well as a control method for the vehicle system.

[0009] To achieve the above objectives, the vehicle system disclosed herein includes multiple control devices mounted on the vehicle. The multiple control devices include at least one lower-level control device and at least one upper-level control device. The upper-level control device has a relay control unit that connects or disconnects a relay circuit provided on the power supply line of the lower-level control device. At least one of the multiple control devices is communicatively connected to the lower-level control device via a communication bus. The upper-level control device is configured such that, in the event that communication between at least one of the multiple control devices and the lower-level control device whose relay circuit is connected is interrupted for a predetermined time, the relay control unit disconnects the relay circuit and then connects the relay circuit.

[0010] Furthermore, the vehicle system control method disclosed herein is a control method for a vehicle system having multiple control devices mounted on the vehicle. The multiple control devices include at least one lower-level control device and at least one upper-level control device. The upper-level control device has a relay control unit that connects or disconnects a relay circuit provided on the power supply line of the lower-level control device. At least one of the multiple control devices is communicatively connected to the lower-level control device via a communication bus. The vehicle system control method comprises: determining whether communication between at least one of the multiple control devices and the lower-level control device whose relay circuit is connected has been interrupted for a predetermined time; and, based on the determination that communication between at least one of the multiple control devices and the lower-level control device has been interrupted for a predetermined time, the upper-level control device disconnects the relay circuit through the relay control unit and then connects the relay circuit.

[0011] In the vehicle system and control method disclosed herein, the upper-level control device includes a relay control unit that connects or disconnects a relay circuit installed on the power supply line of the lower-level control device. Furthermore, the upper-level control device disconnects the relay circuit via the relay control unit and then connects it again when communication between at least one of the plurality of control devices and the lower-level control device whose relay circuit is connected is interrupted for a predetermined time.

[0012] In other words, the upper-level control device can detect abnormalities in the lower-level control device, such as the lower-level control device failing to start or the ECU malfunctioning, based on communication interruptions. The upper-level control device disconnects the relay circuit upon receiving a communication interruption from the lower-level control device, thereby temporarily halting the power supply to the lower-level control device.

[0013] Subsequently, the upper-level control device switches on the relay circuit, resuming power supply to the lower-level control device. This forces the lower-level control device to restart. Therefore, the vehicle system and control method of this disclosure can more reliably facilitate the normal recovery of the lower-level control device. Attached Figure Description

[0014] The foregoing and other objects, features, and advantages of this disclosure will become more apparent from the accompanying drawings and from the detailed description that follows.

[0015] Figure 1 This is a structural diagram illustrating an example of the structure of the vehicle system according to the first embodiment.

[0016] Figure 2 This is a diagram representing an example of an NM message and illustrating how to use NM messages to implement local network operations.

[0017] Figure 3 This is a flowchart illustrating an example of the processing performed by the upper-level ECU of the first embodiment.

[0018] Figure 4 This is a flowchart illustrating an example of the processing performed by the first and second intermediate-level ECUs of the first embodiment.

[0019] Figure 5 This is a flowchart illustrating an example of the processing performed by the first to third lower-level ECUs in the first embodiment.

[0020] Figure 6 This is a structural diagram illustrating an example of the structure of the vehicle system according to the second embodiment.

[0021] Figure 7 This indicates that the upper-level ECU in the second embodiment is... Figure 3 The flowchart shown is an example of a process performed based on the process described above.

[0022] Figure 8 This is a flowchart illustrating an example of the processing performed by the first and second intermediate-level ECUs in the second embodiment.

[0023] Figure 9 This is a flowchart illustrating an example of the processing performed by the first to third lower-level ECUs in the second embodiment.

[0024] Figure 10 This is a flowchart illustrating an example of the processing performed by the first to third lower-level ECUs in the third embodiment. Detailed Implementation

[0025] Hereinafter, embodiments of the vehicle system and vehicle system control method of the present disclosure will be described with reference to the accompanying drawings. However, the present disclosure is not limited to the following embodiments, and the various modifications described below are also included within the technical scope of the present disclosure. Furthermore, in addition to the following, various modifications can be made to implement the system without departing from the spirit of the present disclosure. The embodiments and various modifications can be appropriately combined to implement the system without creating technical contradictions. In the following description, for the same or similar structures, descriptions are sometimes omitted by using the same reference numerals in multiple drawings. In addition, when only a part of the structure is mentioned, descriptions of other parts can be applied to other parts.

[0026] (First Implementation) Figure 1 This is a structural diagram illustrating an example of the structure of the vehicle system 100 according to this embodiment. Figure 1 The vehicle system 100 shown includes an upper-level ECU 10, first and second intermediate-level ECUs 20 and 30 as upper-level control devices, and first to third lower-level ECUs 40, 50, and 60 as lower-level control devices. ECU is short for Electronic Control Unit. In this embodiment, the upper-level ECU 10, the first and second intermediate-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 are respectively mounted on a vehicle. Vehicles include passenger cars, motorcycles, transport vehicles, construction vehicles, agricultural vehicles, etc.

[0027] The vehicle system 100 operates by receiving power from the battery 2 installed in the vehicle. More specifically, power from the battery 2 is supplied to the upper ECU 10, the first and second intermediate ECUs 20 and 30, and the first to third lower ECUs 40, 50, and 60 of the vehicle system 100 via the power circuit 4. The power circuit 4 can convert the power supply voltage of the battery 2 installed in the vehicle into the operating voltage of the upper ECU 10, the first and second intermediate ECUs 20 and 30, and the first to third lower ECUs 40, 50, and 60 as needed. First to third relay circuits 26, 28, and 36 are provided on the power supply lines 6 of the first to third lower ECUs 40, 50, and 60. The first to third relay circuits 26, 28, and 36 are switched on and off states by the first and second relay control units 24 and 34 of the first and second intermediate ECUs 20 and 30, respectively.

[0028] The first to third relay circuits 26, 28, and 36 can be constructed using semiconductor switches such as MOSFETs and IGBTs. However, the first to third relay circuits 26, 28, and 36 may also be constructed using conventional mechanical relays instead of semiconductor switches. Furthermore, as... Figure 1 As shown, the first to third relay circuits 26, 28, and 36 can be located inside the first and second intermediate layer ECUs 20 and 30, or they can be located outside the first and second intermediate layer ECUs 20 and 30.

[0029] Furthermore, the structure of the vehicle system 100 is not limited to Figure 1 The example shown illustrates this. For instance, the number of upper-level ECUs 10 can be two or more, rather than one. In this case, middle-level ECUs and lower-level ECUs can be configured below each upper-level ECU. Moreover, two or more upper-level ECUs 10 can be communicatively connected to each other. Furthermore, any one of the middle-level ECUs 20 or 30 can also perform the functions of an upper-level ECU 10, thus eliminating the need for an upper-level ECU 10. The number of middle-level ECUs 20 or 30 configured below the upper-level ECU 10 can be one or more, rather than two. Regarding the lower-level ECUs 40, 50, and 60, multiple lower-level ECUs can also be connected to a single relay circuit 26, 28, or 36. Additionally, the lower-level ECUs 40, 50, and 60 can also include lower-level ECUs that are directly powered from the power supply circuit 4 without passing through relay circuits 26, 28, or 36.

[0030] The upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 can each be constructed from a computer equipped with a processor, memory, and storage. The processor can be, for example, a CPU (Central Processing Unit), MPU (Micro Processing Unit), GPU (Graphics Processing Unit), or DFP (Data Flow Processor) that executes pre-defined processes according to a program. Memory is a volatile storage medium that temporarily stores the results of the processor's operations, such as RAM (Random Access Memory). Memory can also be a non-volatile storage medium such as flash memory or ROM (Read-Only Memory). The memory stores various programs and data executed by the processor.

[0031] The upper ECU 10, the first and second middle ECUs 20 and 30, and the first to third lower ECUs 40, 50 and 60 are equipped with communication interfaces (communication IFs) 12, 22, 32, 42, 52 and 62 for communicating with other ECUs via communication buses 38, 44, 54 and 64.

[0032] The communication IF12 of the upper ECU 10 is connected to the communication IF22 and 32 of the first and second middle-layer ECUs 20 and 30 via the communication bus 38. The first and second middle-layer ECUs 20 and 30 can also communicate with each other via the communication bus 38. However, the communication bus connecting the upper ECU 10 and the first and second middle-layer ECUs 20 and 30 can be set separately from the communication bus connecting the first and second middle-layer ECUs 20 and 30 with each other.

[0033] The communication IF22 of the first middle-layer ECU 20 is connected to the communication IF42 of the first lower-layer ECU 40 via the communication bus 44. Additionally, the communication IF22 of the first middle-layer ECU 20 is connected to the communication IF52 of the second lower-layer ECU 50 via the communication bus 54. Furthermore, the communication IF42 of the first lower-layer ECU 40 and the communication IF52 of the second lower-layer ECU 50 can also be connected to the communication IF22 of the first middle-layer ECU 20 via a common communication bus. Furthermore, the communication IF32 of the second middle-layer ECU 30 is connected to the communication IF62 of the third lower-layer ECU 60 via the communication bus 64.

[0034] Vehicle system 100 can use CAN (registered trademark, hereinafter the same) as the communication protocol for communication between the upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 via their respective communication IFs 12, 22, 32, 42, 52, and 62. CAN is short for Controller Area Network. Furthermore, the communication protocol is not limited to CAN; vehicle system 100 can employ various communication protocols such as Ethernet (registered trademark), LIN (Local Interconnect Network), FlexRay (registered trademark), and CAN-FD (CAN with Flexible Data Rate). For example, different communication protocols can be used on different communication buses 38, 44, 54, and 64.

[0035] The upper-level ECU 10, for example, can function as a domain controller encompassing the control of the first to third lower-level ECUs 40, 50, and 60. A domain refers to a functional unit that broadly divides the vehicle's functions, such as the powertrain domain, chassis domain, driver support domain, body domain, and cockpit domain. For example, if the upper-level ECU 10 is the domain controller for the powertrain domain, the first to third lower-level ECUs 40, 50, and 60 include various ECUs used to control the vehicle's powertrain, such as the engine ECU, motor (inverter) ECU, battery monitoring ECU, and transmission ECU. Similarly, if the upper-level ECU 10 is the controller for the body domain, the first to third lower-level ECUs 40, 50, and 60 include various ECUs used for vehicle body control, such as the verification ECU, door ECU, window ECU, and camera ECU.

[0036] The above is an example of domain division, but the domain division can also be different from the example above. Alternatively, the upper-level ECU 10 can also function as a region controller that oversees the control of the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50 and 60 configured in each region of the vehicle (e.g., front, rear, right, left, etc.).

[0037] The upper-level ECU 10, for example, acts as a domain controller. Based on various information such as sensor signals, switch signals, and signals obtained from other ECUs, it determines whether the first to third lower-level ECUs 40, 50, and 60 should be activated and take action. Furthermore, if the upper-level ECU 10 determines that at least one lower-level ECU 40, 50, or 60 should be activated and take action, it can activate the corresponding lower-level ECU 40, 50, or 60 into an operational state by sending a network management (hereinafter referred to as NM) message. The NM message will be explained in detail later.

[0038] The function of determining whether the first to third lower-level ECUs 40, 50, and 60 should be activated and to send an NM message to activate the corresponding lower-level ECUs 40, 50, and 60 can be performed by the first and second intermediate-level ECUs 20 and 30, in addition to the upper-level ECU 10, or in place of the upper-level ECU 10. Furthermore, in vehicles equipped with multiple upper-level ECUs and at least one intermediate-level ECU below each upper-level ECU, NM messages to activate lower-level ECUs 40, 50, and 60 can also be sent from other upper-level ECUs or intermediate-level ECUs below other upper-level ECUs.

[0039] Furthermore, based on the aforementioned information, the upper-level ECU 10 determines whether each lower-level ECU 40, 50, or 60 is in a state that may require operation (e.g., the vehicle is in motion or parked). If it is determined that any lower-level ECU 40, 50, or 60 is in a state that may require operation, the upper-level ECU 10 instructs the first and second intermediate-level ECUs 20 and 30 to connect the relay circuits 26, 28, and 36 corresponding to the respective lower-level ECUs 40, 50, or 60. Alternatively, if it is determined that any lower-level ECU 40, 50, or 60 does not need to be in an operational state, the upper-level ECU 10 may instruct the first and second intermediate-level ECUs 20 and 30 to disconnect the relay circuits 26, 28, and 36 corresponding to the respective lower-level ECUs 40, 50, or 60.

[0040] For example, if at least one of the first to third lower-level ECUs 40, 50, 60 is used to unlock the vehicle door while the vehicle is parked based on the communication results with a user-held portable device (e.g., a smart key, a smartphone), the upper-level ECU 10 instructs the first and second middle-level ECUs 20, 30 to activate the relay circuits 26, 28, 36 corresponding to the respective lower-level ECUs 40, 50, 60 while the vehicle is parked.

[0041] Whether a situation requires the lower-level ECUs 40, 50, and 60 to activate can be determined not by the upper-level ECU 10, but, for example, by the first and second intermediate-level ECUs 20 and 30. In this case, the first and second intermediate-level ECUs 20 and 30 can determine whether the lower-level ECUs 40, 50, and 60 connected to the relay circuits 26, 28, and 36 that control the on / off states are in a situation that may require activation.

[0042] As described above, the first and second intermediate-level ECUs 20 and 30 each have a first and second relay control unit 24 and 34 that function to control the connection and disconnection of relay circuits 26, 28, and 36. The first and second relay control units 24 and 34 connect or disconnect the corresponding relay circuits 26, 28, and 36 based on instructions from the upper-level ECU 10 or based on the determination results in the first and second intermediate-level ECUs 20 and 30.

[0043] In addition, the first and second intermediate-level ECUs 20 and 30, besides having the function of turning on and off the various relay circuits 26, 28, and 36, also function as relay devices for enabling bidirectional communication between ECUs connected to different communication buses 38, 44, 54, and 64. For example, the first and second intermediate-level ECUs 20 and 30 gateway-forward NM messages received from one communication bus 38, 44, 54, and 64 to other communication buses 38, 44, 54, and 64. At this time, if the communication protocol of the communication bus receiving the NM message is different from that of the communication bus sending the NM message, the first and second intermediate-level ECUs 20 and 30 also perform protocol conversion. Furthermore, for example, among the first to third lower-level ECUs 40, 50, and 60, in addition to exchanging NM messages used to implement the local network, control messages containing control-related data are also exchanged. The first and second intermediate-level ECUs 20 and 30 also perform such gateway forwarding of control messages. Thus, cooperative control performed by multiple lower-level ECUs belonging to the same cluster can be executed smoothly.

[0044] The first to third lower-level ECUs 40, 50, and 60 can be, for example, control ECUs that perform control processing for controlling a specified controlled object in a vehicle, sensor ECUs that calculate specified physical quantities based on detection signals detected by sensors, or drive ECUs that output drive signals to drive actuators. The first to third lower-level ECUs 40, 50, and 60 are activated and enter an operational state when their corresponding relay circuits 26, 28, and 36 are turned on by the first and second middle-level ECUs 20 and 30. Furthermore, when in an operational state, the first to third lower-level ECUs 40, 50, and 60 perform specified processing, such as control processing for controlling the controlled object, calculation processing for calculating specified physical quantities based on sensor detection signals, and drive processing for outputting drive signals to drive the actuators.

[0045] Each of the first to third lower-level ECUs 40, 50, and 60, divided into multiple clusters, retains cluster configuration information (referred to as PNC configuration information) representing the cluster assigned to it. For example, the PNC configuration information is stored in the non-volatile storage medium of the first to third lower-level ECUs 40, 50, and 60. When in operation, during the execution of prescribed control processing, arithmetic processing, or drive processing, the first to third lower-level ECUs 40, 50, and 60 periodically send NM messages containing startup cluster information (referred to as PN request information) designating their respective cluster as the startup cluster. The clusters, PNC configuration information, and PN request information will be explained in detail later. Furthermore, upon completion of the prescribed control processing, arithmetic processing, or drive processing, the first to third lower-level ECUs 40, 50, and 60 cease sending NM messages.

[0046] The first to third lower-level ECUs 40, 50, and 60, after completing the prescribed control processing, computation processing, or drive processing, and after a specified time has elapsed since they no longer receive NM messages, including PN request information designating their respective cluster as the startup cluster, move into a sleep state. As a result, lower-level ECUs belonging to the same cluster transition from the active state to the sleep state almost simultaneously. In the sleep state, the lower-level ECUs operate in a low-power state, only capable of receiving NM messages and ceasing other functions.

[0047] In sleep mode, to receive NM messages, the first to third lower-level ECUs 40, 50, and 60 possess communication IFs 42, 52, and 62 corresponding to the operation of the local network. For example, based on PNC setting information stored in non-volatile storage media, the first to third lower-level ECUs 40, 50, and 60 set the information of the cluster to which they belong as a startup condition in communication IFs 42, 52, and 62. Therefore, each communication IF 42, 52, and 62 can determine whether the received NM message contains PN request information consistent with the cluster to which the corresponding first to third lower-level ECUs 40, 50, and 60 belong.

[0048] Furthermore, if each communication IF42, 52, and 62 determines that the received NM message contains PN request information consistent with the cluster to which the corresponding first to third lower-level ECUs 40, 50, and 60 belong, it will activate the corresponding first to third lower-level ECUs 40, 50, and 60 into an operational state. On the other hand, if each communication IF42, 52, and 62 determines that the received NM message does not contain PN request information consistent with the cluster to which the corresponding first to third lower-level ECUs 40, 50, and 60 belong, it will keep the corresponding first to third lower-level ECUs 40, 50, and 60 in a sleep state.

[0049] However, the first to third lower-level ECUs 40, 50, and 60 may not have communication IFs 42, 52, and 62 corresponding to the local network operation. In this case, if each communication IF 42, 52, and 62 receives an NM message while the first to third lower-level ECUs 40, 50, and 60 are in sleep mode, the corresponding first to third lower-level ECUs 40, 50, and 60 will be temporarily activated. Furthermore, the activated first to third lower-level ECUs 40, 50, and 60 can determine whether the NM message contains PN request information consistent with their own cluster. If the first to third lower-level ECUs 40, 50, and 60 determine that the NM message contains PN request information consistent with their own cluster, they will maintain their current operating state. On the other hand, if the first to third lower-level ECUs 40, 50, and 60 determine that the NM message does not contain PN request information consistent with their own cluster, they will return to sleep mode.

[0050] Next, we will explain the cluster, NM message, PNC configuration information, and PNC request information. In this embodiment, in order to enable local network operation through NM messages, the first to third lower-layer ECUs 40, 50, and 60 are each assigned to their respective clusters within a plurality of clusters. The NM message contains PN request information, which indicates the cluster to be started.

[0051] Figure 2 An example of an NM message is shown. Figure 2 In the example shown, the NM message contains data in bytes 0 through 7. Byte 0 includes the Node ID (NID). The Node ID is a unique identifier for each of the upper-layer ECU 10, the first and second middle-layer ECUs 20 and 30, and the first through third lower-layer ECUs 40, 50, and 60. The Node ID identifies the source of the NM message. Byte 1 includes the Control Bit Vector (CBV). The Control Bit Vector contains data indicating whether the local network is in operation. If the Control Bit Vector indicates that the local network is in operation, Bytes 2-7 contain PN request information in the user data area, which indicates the cluster that should be started.

[0052] exist Figure 2 In the example shown, the control bit vector represents the use of the local network, and PN request information is stored in bytes 6 and 7 of the user data area. The user data area, bytes 2-5, can be used to transmit any information, such as ECU starting factors, information related to normal or abnormal operation, etc. Furthermore, Figure 2 This is just one example of the format of an NM message. An NM message can take other forms as long as it contains PN request information. For example, NID and CBV can be omitted.

[0053] The PN request information is divided into multiple clusters, indicating which clusters should be started and which do not need to be started. More specifically, in Figure 2 In the example shown, the clusters are pre-divided into 16. Furthermore, the PN request information contains 16 bits of data corresponding to each of the 16 pre-divided clusters. That is, the 16 bits of the PN request information correspond to the pre-divided 16 clusters. When each of the 16 bits of the PN request information is "0", it indicates that the corresponding cluster does not need to be started. On the other hand, when each of the 16 bits of the PN request information is "1", it indicates that the corresponding cluster needs to be started. Alternatively, the PN request information may only indicate the clusters that should be started. Alternatively, the PN request information may only indicate the clusters that do not need to be started.

[0054] In addition, Figure 2 The image shows an example of PNC configuration information set for a lower-level ECU. Figure 2 In the PNC configuration information shown, when the corresponding clusters are classified as A~P from left to right in the diagram, Figure 2 The PNC setting information indicates that the lower-level ECU with this PNC setting belongs to clusters D, H, and J. Lower-level ECUs can perform various functions by executing programs, therefore a lower-level ECU can belong to more than one cluster.

[0055] The first to third lower-level ECUs 40, 50, and 60 can receive NM messages containing PN request information via their respective communication IFs 42, 52, and 62. Upon receiving an NM message, communication IFs 42, 52, and 62 determine whether the cluster requested to be started based on the PN request information in the NM message is consistent with the cluster configured in the PNC settings for the corresponding lower-level ECUs 40, 50, and 60. For example, to determine cluster consistency, communication IFs 42, 52, and 62 may... Figure 2 As shown, the PN request information of the NM message is compared with the PNC setting information of the corresponding lower-level ECUs 40, 50, and 60 bit by bit, and the logical product is calculated.

[0056] exist Figure 2 In the example shown, the clusters requested to be started based on the PN request information are clusters D, G, I, M, N, and O. The lower-level ECUs represented by the PNC configuration information belong to clusters D, H, and J. In this case, within cluster D, the cluster requested to be started based on the PN request information contained in the NM message is consistent with the cluster in the PNC configuration information. Therefore, as... Figure 2 As shown, the result of the logical product is "1" in cluster D.

[0057] As a result of the logical product, when any bit becomes "1", a setting is established. Figure 2 The communication IF of the lower-level ECU shown in the PNC setting information indicates that a request to start the corresponding lower-level ECU has been received. Upon receiving this determination, the communication IF starts the corresponding lower-level ECU into an operational state. If the lower-level ECU is already in an operational state, it maintains that state. On the other hand, as a result of logical product, if all bits are "0" and none are "1", the communication IF determines that no request to start the corresponding lower-level ECU has been received. In this case, the communication IF does not start the corresponding lower-level ECU and keeps it in a sleep state. Alternatively, if the lower-level ECU is in an operational state, it continues counting the time since it has not received an NM message requesting its start. If the lower-level ECU completes the prescribed control processing, etc., and the time since not receiving an NM message reaches a predetermined time, the lower-level ECU moves from the operational state to the sleep state.

[0058] Alternatively, PNC setting information can also be set for the upper-level ECU 10 and / or the first and second intermediate-level ECUs 20 and 30 to switch between operating and sleep states based on NM messages. Alternatively, the upper-level ECU 10 and / or the first and second intermediate-level ECUs 20 and 30 can also be configured to enter a sleep state if a predetermined time has elapsed since no NM messages have been input from other ECUs.

[0059] Next, refer to Figure 3-5 The flowchart below illustrates an example of the processes executed by the upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 in the vehicle system 100 of this embodiment. The upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 execute the processes shown in the flowchart below, which is equivalent to executing the control method of the vehicle system 100 of this disclosure.

[0060] Figure 3 This is a flowchart illustrating an example of processing performed by the upper-level ECU 10. The upper-level ECU 10 performs this process periodically. Figure 3 The process is illustrated in the flowchart. In step S100, the upper-level ECU 10 acquires various information, including various sensor signals, switch signals, and signals obtained from other ECUs. In step S110, the upper-level ECU 10 determines the lower-level ECUs 40, 50, and 60 as the processing targets.

[0061] In step S120, the upper-level ECU 10 determines, based on the information obtained in step S100, whether a situation arises where the lower-level ECU that needs to be processed may need to be activated. If it is determined that a situation arises where the lower-level ECU that needs to be processed may need to be activated, the upper-level ECU 10 proceeds to step S130. On the other hand, if it is determined that a situation does not arise where the lower-level ECU that needs to be processed may need to be activated, the upper-level ECU 10 proceeds to step S140.

[0062] In step S130, the upper-level ECU 10 instructs the first and second middle-level ECUs 20 and 30 to connect the relay circuits corresponding to the lower-level ECU being processed. Afterwards, the upper-level ECU 10 proceeds to step S140.

[0063] In step S140, the upper-level ECU 10 determines whether the relay circuit corresponding to the lower-level ECU being processed is connected. The upper-level ECU 10... Figure 3 In the current or previous processing shown in the flowchart, when it is indicated that the relay circuit corresponding to the lower-level ECU being processed will be connected, it can be determined that the relay circuit corresponding to the lower-level ECU being processed is connected. If it is determined that the relay circuit is connected, the upper-level ECU 10 proceeds to step S150. On the other hand, if it is determined that the relay circuit is not connected, the upper-level ECU 10 proceeds to step S190.

[0064] In step S150, the upper-level ECU 10 determines, based on the information obtained in step S100, whether the situation warrants activation and operation by the lower-level ECU of the processing target. If it is determined that the lower-level ECU of the processing target should activate and operate, the upper-level ECU 10 proceeds to step S160. On the other hand, if it is determined that the lower-level ECU of the processing target should not activate and operate, the upper-level ECU 10 proceeds to step S170.

[0065] In step S160, the upper-level ECU 10 initiates the processing target lower-level ECU into an operational state by sending an NM message. Afterwards, the upper-level ECU 10 proceeds to step S170.

[0066] In step S170, the upper-level ECU 10 determines whether the lower-level ECU is in an operational state due to the object not requiring processing, i.e., whether to disconnect the corresponding relay circuit. If it is determined that the relay circuit should be disconnected, the upper-level ECU 10 proceeds to step S180. On the other hand, if it is determined that the relay circuit should not be disconnected, the upper-level ECU 10 proceeds to step S190.

[0067] In step S180, the upper-level ECU 10 instructs the first and second middle-level ECUs 20 and 30 to disconnect the relay circuits corresponding to the lower-level ECUs being processed. Afterwards, the upper-level ECU 10 proceeds to step S190. In step S190, the upper-level ECU 10 determines whether the processing described in steps S120-S180 has been completed for all lower-level ECUs 40, 50, and 60. If it is determined that the processing for all lower-level ECUs 40, 50, and 60 has been completed, the upper-level ECU 10 terminates. Figure 3 The process is shown in the flowchart. On the other hand, if it is determined that the processing for all lower-level ECUs 40, 50, and 60 has not been completed, the upper-level ECU 10 proceeds to step S195.

[0068] In step S195, the upper-level ECU 10 switches to process the lower-level ECU. After that, the upper-level ECU 10 returns to step S120 and repeats the processing of steps S120-S180 until the processing of all lower-level ECUs 40, 50, and 60 is completed.

[0069] In addition, it can also be configured as follows: Figure 3 The process shown in the flowchart is not executed by the upper-level ECU10, but by the first and second middle-level ECUs20 and 30.

[0070] Next, the processes performed in the first and second intermediate ECUs 20 and 30 will be explained. Figure 4 This is a flowchart illustrating an example of the processing performed by the first and second intermediate-level ECUs 20 and 30. The first and second intermediate-level ECUs 20 and 30 perform this process periodically. Figure 4 The process is shown in the flowchart. The following describes the execution of the first intermediate-level ECU 20. Figure 4 The flowchart shows an example of the processing.

[0071] In step S200, the first intermediate-level ECU 20 determines the lower-level ECU to be processed. Furthermore, if there is only one lower-level ECU 60 whose power supply is controlled via relay circuit 36, as with the second intermediate-level ECU 30, step S200 can be omitted.

[0072] In step S210, the first intermediate-level ECU 20 determines whether the relay circuit corresponding to the lower-level ECU being processed is turned on. As described above, when the first intermediate-level ECU 20 is instructed by the upper-level ECU 10 to turn on the relay circuit, the first intermediate-level ECU 20 turns on the corresponding relay circuit via the relay control unit 24. The first intermediate-level ECU 20 can determine whether the relay circuit corresponding to the lower-level ECU being processed is turned on based on the history of relay circuit turning instructions from the upper-level ECU, the control history of the relay circuit by the relay control unit 24, etc. If it is determined that the relay circuit corresponding to the lower-level ECU being processed is turned on, the first intermediate-level ECU 20 proceeds to step S220. On the other hand, if it is determined that the relay circuit corresponding to the lower-level ECU being processed is not turned on, the first intermediate-level ECU 20 proceeds to step S260.

[0073] In step S220, the first intermediate ECU 20 determines whether the processing target lower-level ECU is in a normal control operation state. The processing of step S220 is equivalent to the determination unit of this disclosure. For example, the first intermediate ECU 20 can determine that the processing target lower-level ECU is in an operational state during the period from the time the relay circuit corresponding to the processing target lower-level ECU is turned on until a predetermined time, equivalent to the execution time of the processing target lower-level ECU completing the predetermined processing, has elapsed. In addition, the first intermediate ECU 20 holds PNC setting information indicating the cluster to which the processing target lower-level ECU belongs. The first intermediate ECU 20 can determine that the processing target lower-level ECU is in an operational state during the period of receiving an NM message including PN request information that sets the cluster to which the processing target lower-level ECU belongs as the start cluster. When it is determined that the processing target lower-level ECU is in an operational state, the first intermediate ECU 20 proceeds to step S230. On the other hand, if it is determined that the processing target lower-level ECU is not in an operational state, the first intermediate ECU 20 proceeds to step S260.

[0074] In step S230, the first middle-layer ECU 20 receives an NM message sent from the lower-layer ECU of the processing target. As described above, each lower-layer ECU 40, 50, and 60, in its operational state, periodically sends an NM message containing a PN request information indicating that its own cluster is being used as a startup cluster. The first middle-layer ECU 20 receives the NM messages periodically sent from the lower-layer ECU of the processing target. Furthermore, when control messages are periodically sent from the lower-layer ECU of the processing target, the first middle-layer ECU 20 may receive control messages instead of NM messages.

[0075] In step S240, the first intermediate-level ECU 20 determines whether a predetermined period has elapsed since it failed to receive an NM message (or control message) from the lower-level ECU being processed. This predetermined period is at least set to be longer than the periodic interval between the NM messages (or control messages) periodically sent from the lower-level ECU being processed. Therefore, the inability to receive an NM message (or control message) from the lower-level ECU being processed, which is in an operational state, for more than the predetermined period can be considered as an anomaly such as a communication interruption with the lower-level ECU being processed, resulting in CPU malfunction or other abnormalities.

[0076] Alternatively, other control devices besides the first middle-level ECU 20 (such as the upper-level ECU 10, the second middle-level ECU 30, or the second lower-level ECU 50) can determine whether NM messages (or control messages) have been periodically sent from the lower-level ECU of the target being processed, i.e., whether the period during which no NM messages (or control messages) have been received from the lower-level ECU of the target being processed has reached a predetermined period. In this case, if the other control device besides the first middle-level ECU 20 determines that the period during which no NM messages (or control messages) have been received from the lower-level ECU of the target being processed has reached a predetermined period, it can simply notify the first middle-level ECU 20 of this intention.

[0077] If the period during which no NM message is received from the lower-level ECU of the processing target reaches a predetermined period, the first intermediate-level ECU proceeds to step S250. On the other hand, if the period during which no NM message is received from the lower-level ECU of the processing target does not reach the predetermined period, the first intermediate-level ECU proceeds to step S260.

[0078] In step S250, the first intermediate-level ECU 20 disconnects the relay circuit corresponding to the lower-level ECU being processed for a certain period of time. Then, after the disconnection period, the first intermediate-level ECU 20 reconnects the relay circuit. Thus, the first intermediate-level ECU 20 can forcibly restart the lower-level ECU being processed. Therefore, the first intermediate-level ECU 20 can reliably cause the lower-level ECU being processed to return to normal operation. Afterwards, the first intermediate-level ECU 20 proceeds to step S260.

[0079] In step S260, the first intermediate-level ECU 20 determines whether the processing of steps S210-S250 has been completed for all lower-level ECUs 40 and 50 whose power supply is controlled via relay circuits 26 and 28. If it is determined that the processing for all lower-level ECUs 40 and 50 is complete, the first intermediate-level ECU 20 terminates. Figure 4 The process is shown in the flowchart. On the other hand, if it is determined that the processing for all lower-level ECUs 40 and 50 has not been completed, the first middle-level ECU 20 proceeds to step S270.

[0080] In step S270, the first intermediate-level ECU 20 switches its processing target to the lower-level ECU. Then, the first intermediate-level ECU 20 returns to step S210 and repeats the processing of steps S210-S250 until processing of all lower-level ECUs 40 and 50 is completed. Furthermore, if only one lower-level ECU's power supply is controlled via a relay circuit, steps S260 and S270 can be omitted.

[0081] Next, the processes executed in the first to third lower-level ECUs 40, 50, and 60 will be explained. Figure 5 This is a flowchart illustrating an example of the processing executed by the first to third lower-level ECUs 40, 50, and 60. The first to third lower-level ECUs 40, 50, and 60 execute [the following process] when their corresponding relay circuits are activated and powered. Figure 5 The process is shown in the flowchart. The following describes the execution of the first lower-level ECU 40. Figure 5 The flowchart shows an example of the processing.

[0082] In step S300, the first lower-level ECU 40 performs initial processing. Initial processing includes, for example, initial hardware settings and confirmation of storage medium operation. In step S310, the first lower-level ECU 40 enables communication. Thus, the first lower-level ECU 40 can send and receive various messages via communication IF 42. For example, the first lower-level ECU 40 can periodically send NM messages during normal control operations in the operational state.

[0083] In step S320, as normal control, the first lower-level ECU 40 executes prescribed control processing, arithmetic processing, or drive processing, etc. In step S330, the first lower-level ECU 40 determines whether the transition condition for transferring to a hibernation state is met. For example, if the first lower-level ECU 40 completes the execution of the prescribed control processing, arithmetic processing, or drive processing, and a predetermined time has elapsed since it last received an NM message containing a PN request message designating its own cluster as a startup cluster, then the transition condition for transferring to a hibernation state can be determined to be met. If the transition condition for transferring to a hibernation state is determined to be met, the first lower-level ECU 40 proceeds to step S340. On the other hand, if the transition condition for transferring to a hibernation state is determined not to be met, the first lower-level ECU 40 returns to the processing in step S320.

[0084] In step S340, the first lower-level ECU 40 enters a sleep state. In step S350, it is determined whether the communication IF42 of the first lower-level ECU 40 has received an NM message containing a PN request message that designates the cluster to which the first lower-level ECU 40 belongs as the startup cluster, i.e., whether the startup of the first lower-level ECU 40 has been requested. If the startup of the first lower-level ECU 40 has been requested, the processing from step S300 onwards is executed. As a result, the first lower-level ECU 40 starts up and enters an operational state. On the other hand, if the startup of the first lower-level ECU 40 has not been requested, the first lower-level ECU 40 continues to be in a sleep state.

[0085] (Second Implementation) Next, a second embodiment of the vehicle system 100A and the control method of the vehicle system 100A of this disclosure will be described. Figure 6 This is a structural diagram illustrating an example of the structure of the vehicle system 100A according to this embodiment. For example... Figure 6 As shown, the vehicle system 100A of this embodiment, compared to the vehicle system 100 of the first embodiment, has a PNC setting unit 14 provided in the upper ECU 10. The PNC setting unit 14 is equivalent to the cluster setting information setting unit of this disclosure.

[0086] The PNC setting unit 14 has the function of resetting the PNC setting information of the first to third lower-level ECUs 40, 50, and 60. Furthermore, when resetting the PNC setting information of the first to third lower-level ECUs 40, 50, and 60, the PNC setting unit 14 also resets the PNC setting information of the first to third lower-level ECUs 40, 50, and 60 held by the first and second middle-level ECUs 20 and 30. The PNC setting unit 14 has a PNC setting table that includes all PNC setting information of the first to third lower-level ECUs 40, 50, and 60. The PNC setting unit 14 can reset the PNC setting information of the first to third lower-level ECUs 40, 50, and 60 based on the PNC setting table.

[0087] Furthermore, the PNC setting unit 14 may not be located in the upper ECU 10, but may be located in any one of the first and second middle-level ECUs 20 and 30. Additionally, when the PNC setting unit 14 needs to change the PNC setting information of at least one of the first to third lower-level ECUs 40, 50, and 60 due to the addition or replacement of the first to third lower-level ECUs 40, 50, and 60, or the addition of applications to at least one lower-level ECU, it can, for example, obtain an updated PNC setting table from an external server. Moreover, the PNC setting unit 14 can also change the PNC setting information of the first to third lower-level ECUs 40, 50, and 60 to appropriate PNC setting information based on the updated PNC setting table. In this case, the PNC setting unit 14 can re-set the PNC setting information of all lower-level ECUs, or it can only re-set the PNC setting information of the lower-level ECUs whose PNC setting information has been changed.

[0088] Next, refer to Figure 7-9 The flowchart illustrates an example of the processing performed by the upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50 and 60 in the vehicle system 100A of this embodiment.

[0089] Similar to the first implementation, the upper-level ECU10 periodically executes... Figure 3 The process is shown in the flowchart. In addition, the upper-level ECU10 periodically executes... Figure 7 The process is shown in the flowchart below. The following explains... Figure 7 The process is shown in the flowchart.

[0090] In step S400, the upper-level ECU 10 determines whether it has received a resetting request for PNC setting information from the lower-level ECU. In this embodiment, as described later, if a predetermined period elapses without receiving an NM message from the lower-level ECU in operation, the first and second intermediate-level ECUs 20 and 30 send corresponding resetting requests for PNC setting information from the lower-level ECU. If it is determined that a resetting request for PNC setting information has been received, the upper-level ECU 10 proceeds to step S410. Conversely, if it is determined that no resetting request for PNC setting information has been received, the upper-level ECU 10 terminates. Figure 7 The process is shown in the flowchart.

[0091] In step S410, the upper-level ECU 10 reads the PNC setting information of the lower-level ECU that has a resetting request for PNC setting information from the PNC setting table and sends it. The sent PNC setting information is received by the corresponding lower-level ECU. Furthermore, based on the received PNC setting information, the PNC setting information of the lower-level ECU is reset. In addition, based on receiving a resetting request for PNC setting information from a lower-level ECU, the upper-level ECU 10 can reset the PNC setting information of all lower-level ECUs, or it can only reset the PNC setting information of the lower-level ECU that received the resetting request.

[0092] Next, the processes performed in the first and second intermediate ECUs 20 and 30 will be explained. Figure 8 This is a flowchart illustrating an example of the processing performed by the first and second intermediate-level ECUs 20 and 30. The first and second intermediate-level ECUs 20 and 30 perform this process periodically. Figure 8 The process is shown in the flowchart.

[0093] Figure 8 The flowchart is relative to Figure 4 Step S252 has been added to the flowchart. Other steps are... Figure 8 Flowcharts and Figure 4 There are no changes in the flowchart. Therefore, the processing of step S252 will be explained below.

[0094] When the first and second intermediate-level ECUs 20 and 30 do not receive an NM message from a lower-level ECU that should be in an operational state for a predetermined period, relay circuits 26, 28, and 36 are disconnected and then reconnected, and the process of step S252 is executed. Furthermore, the process of step S252 can be executed after the process of step S250 or before the process of step S250.

[0095] In step S252, the first and second intermediate ECUs 20 and 30 send a resetting request for the corresponding PNC setting information of the lower-level ECU to the upper-level ECU 10 when the period during which no NM message is received from the lower-level ECU in the operating state has reached a predetermined period.

[0096] Next, the processes performed in the first to third lower-level ECUs 40, 50, and 60 will be explained. Figure 9 This is a flowchart illustrating an example of the processing executed by the first to third lower-level ECUs 40, 50, and 60. The first to third lower-level ECUs 40, 50, and 60 execute [the following actions] when their corresponding relay circuits are activated and powered. Figure 9 The process is shown in the flowchart. The following describes the execution of the first lower-level ECU 40. Figure 9 The flowchart shows an example of the processing.

[0097] Figure 9 The flowchart is relative to Figure 5 Steps S316, S318, and S332 have been added to the flowchart. Other steps are... Figure 9 Flowcharts and Figure 5 There are no changes in the flowchart. Therefore, the processing of steps S316, S318, and S332 will be explained below.

[0098] After the communication function of the first lower-level ECU 40 is enabled in step S310, the processing in step S316 is executed. In step S316, the first lower-level ECU 40 determines whether it has received PNC setting information sent from the upper-level ECU 10 to the first lower-level ECU 40. If it is determined that PNC setting information has been received, the first lower-level ECU 40 proceeds to step S318. On the other hand, if it is determined that PNC setting information has not been received, the first lower-level ECU 40 proceeds to step S320.

[0099] Furthermore, whenever it is determined in step S330 that the transition condition for the first lower-level ECU 40 to transition to a sleep state is not met, the process of step S316 is repeatedly executed. That is, the process of step S316 is repeatedly executed during the period when the first lower-level ECU 40 is in the operating state.

[0100] In step S318, the first lower-level ECU 40 saves the received PNC setting information in a non-volatile storage medium. At this time, the received PNC setting information can also overwrite existing PNC setting information. Alternatively, the received PNC setting information can be written to a different storage area than the existing PNC setting information. In this case, multiple PNC setting information is saved in the non-volatile storage medium, therefore it is necessary to be able to identify which PNC setting information is the most up-to-date.

[0101] After the transition condition for the first lower-level ECU 40 to transition to a hibernation state is met, but before transitioning to the hibernation state, the processing in step S332 is executed. In step S332, the first lower-level ECU 40 sets cluster information as a start condition to the communication IF 42 based on the PNC setting information stored in the non-volatile storage medium. Thus, if the PNC setting information is reset, the cluster information as a start condition can be set in the communication IF 42 based on the reset PNC setting information. The communication IF 42 determines whether the received NM message contains PN request information consistent with the cluster information set in step S332 during the period when the first lower-level ECU 40 is in a hibernation state.

[0102] In any lower-level ECU, if an anomaly occurs such as the disappearance or corruption of PNC setting information stored in non-volatile memory, the lower-level ECU may fail to start normally based on the NM message. In this case, although the lower-level ECU should be in an active state, it remains in a dormant state.

[0103] In this embodiment, if a predetermined period has elapsed since no NM message has been received from a lower-level ECU that should be operational, the first and second intermediate-level ECUs 20 and 30 send a resetting request for the lower-level ECU's PNC setting information to the upper-level ECU 10. Based on this resetting request, the upper-level ECU 10 reads the PNC setting information of the lower-level ECU that has the resetting request from the PNC setting table and sends it. The sent PNC setting information is received by the corresponding lower-level ECU and stored in a non-volatile storage medium. Furthermore, upon receiving an NM message, the communication IF of the corresponding lower-level ECU determines whether the lower-level ECU should be started based on the start conditions of the latest PNC setting information stored in the non-volatile storage medium.

[0104] Therefore, even in the event of anomalies such as the loss or corruption of PNC setting information stored in non-volatile storage media, the PNC setting information can be repaired. As a result, the lower-level ECU can be started normally based on the NM message.

[0105] (Third Implementation) Next, a third embodiment of the vehicle system 100A and the control method for the vehicle system 100A of this disclosure will be described. The vehicle system 100A of this embodiment is configured similarly to the vehicle system 100A of the second embodiment. Therefore, the description of the structure of the vehicle system 100A of the third embodiment is omitted.

[0106] In the second embodiment, if the first and second intermediate-level ECUs 20 and 30 determine that the period during which they have not received an NM message from a lower-level ECU that is in operation has reached a predetermined period, they send a resetting request for the corresponding lower-level ECU's PNC setting information to the upper-level ECU 10. In contrast, in this embodiment, the first to third lower-level ECUs 40, 50, and 60 start up by power supply based on the activation of relay circuits 26, 28, and 36, and send a resetting request for PNC setting information to the upper-level ECU 10.

[0107] More specifically, in this embodiment, the first to third lower-level ECUs 40, 50, and 60 have a start-up factor determination function. This function determines whether the startup was initiated by power supply being activated through relay circuits 26, 28, and 36, or by receiving an NM message. Furthermore, based on the determination that the startup was initiated by power supply being activated through relay circuits 26, 28, and 36, the first to third lower-level ECUs 40, 50, and 60, and the upper-level ECU 10, send a resetting request for PNC setting information.

[0108] The start-up factor determination function of the first to third lower-level ECUs 40, 50, and 60 can be implemented, for example, by determining whether variables set to initial values ​​remain unchanged when the first to third lower-level ECUs 40, 50, and 60 are started by activating the relay circuits 26, 28, and 36 and starting power supply. For example, the values ​​of registers (e.g., program counters, address registers) and the memories of communication IFs 42, 52, and 62 within the first to third lower-level ECUs 40, 50, and 60 are initial values ​​when the relay circuits 26, 28, and 36 are activated and power supply starts. Furthermore, the values ​​of registers and memories may sometimes change from their initial values ​​as the first to third lower-level ECUs 40, 50, and 60 begin operation or send and receive messages. On the other hand, when the first to third lower-level ECUs 40, 50, and 60 are in a sleep state, power continues to be supplied to them, thus the values ​​of registers and memories that have changed from their initial values ​​are preserved. Therefore, if the values ​​in the registers and memory are the initial values, the first to third lower-level ECUs 40, 50, and 60 can determine that power supply has been initiated due to the activation of relay circuits 26, 28, and 36, thus starting the system. Conversely, if the values ​​in the registers and memory are values ​​other than the initial values, the first to third lower-level ECUs 40, 50, and 60 can determine that the system has started based on the receipt of the NM message.

[0109] Furthermore, the start-up factor determination function of the first to third lower-level ECUs 40, 50, and 60 can also be achieved by determining whether the data used in the processing during normal operation is stored in volatile memory such as main memory. That is, if the data is not stored in volatile memory, the first to third lower-level ECUs 40, 50, and 60 can determine that power supply has been started due to the connection of relay circuits 26, 28, and 36, thus starting the system. Conversely, if the data is stored in volatile memory, the first to third lower-level ECUs 40, 50, and 60 can determine that the system started based on the receipt of the NM message.

[0110] Furthermore, the start-up factor determination function of the first to third lower-level ECUs 40, 50, and 60 can be achieved by determining whether there is information indicating the reception of an NM message (e.g., a reception flag) in the communication IF. That is, if there is no information indicating the reception of an NM message in the communication IF, the first to third lower-level ECUs 40, 50, and 60 can determine that power supply has been started due to the activation of relay circuits 26, 28, and 36, thus initiating the start-up. Conversely, if there is information indicating the reception of an NM message in the communication IF, the first to third lower-level ECUs 40, 50, and 60 can determine that the start-up was based on the reception of an NM message.

[0111] Next, refer to Figure 10 The flowchart illustrates an example of the processing performed by the first to third lower-level ECUs 40, 50, and 60 in the vehicle system 100A of this embodiment. Furthermore, the processing performed by the upper-level ECU 10 is the same as in the second embodiment. Additionally, the processing performed by the first and second middle-level ECUs 20 and 30 is the same as in the first embodiment.

[0112] Figure 10 The flowchart is relative to Figure 9 Steps S311, S312, and S313 have been added to the flowchart. Other steps are... Figure 10 Flowcharts and Figure 9 There are no changes in the flowchart. Therefore, the processing of steps S311, S312, and S313 will be explained below.

[0113] In step S311, the first to third lower-level ECUs 40, 50, and 60 use the aforementioned start-up factor determination function to determine whether the start-up was initiated by the connection of relay circuits 26, 28, and 36 to begin power supply, or by receiving an NM message. Furthermore, in step S312, it is determined whether the start-up factor determined in step S311 was the connection of relay circuits 26, 28, and 36 to begin power supply. If it is determined that the start-up factor was the connection of relay circuits 26, 28, and 36, causing the start-up of power supply, the first to third lower-level ECUs 40, 50, and 60 proceed to step S313. On the other hand, if it is determined that the start-up factor was not the connection of relay circuits 26, 28, and 36, causing the start-up of power supply, the first to third lower-level ECUs 40, 50, and 60 proceed to step S320.

[0114] In step S313, the first to third lower-level ECUs 40, 50, and 60 send resetting requests for their PNC setting information to the upper-level ECU 10. If the upper-level ECU 10 receives a resetting request for PNC setting information from at least one of the first to third lower-level ECUs 40, 50, and 60, it sends PNC setting information to at least the corresponding lower-level ECU. Thus, the PNC setting information of the first to third lower-level ECUs 40, 50, and 60 can be resetting.

[0115] (Variation example) The preferred embodiments of this disclosure have been described above, but this disclosure is not limited to any of the above embodiments and can be implemented in various ways without departing from the spirit of this disclosure.

[0116] (Variation Example 1) In the second and third embodiments described above, when the PNC setting information of the first to third lower-level ECUs 40, 50, and 60 is reset, the upper-level ECU 10 reads the corresponding lower-level ECU's PNC setting information from the PNC setting table and sends it. In this case, the PNC setting information of the first to third lower-level ECUs 40, 50, and 60 is reset to the default PNC setting information.

[0117] However, when resetting the PNC settings of the first to third lower-level ECUs 40, 50, and 60, the upper-level ECU 10 can also reset PNC settings that differ from the default settings. For example, PNC settings that differ from the default settings can be reset so that the corresponding lower-level ECU belongs to at least one cluster. In this case, by resetting the PNC settings to make the corresponding lower-level ECU belong to all clusters, the chances of the lower-level ECUs starting via NM messages can be increased.

[0118] Furthermore, when the lower-level ECU reconfigures the PNC settings, which differ from the default settings, the communication between the lower-level ECU and the middle-level ECU is restored. Therefore, the anomaly in the lower-level ECU is temporary and can be considered resolved. Based on this resolution, the upper-level ECU 10 reconfigures the lower-level ECU's PNC settings back to the default settings. This allows the lower-level ECU to start at the required time.

[0119] (Variation Example 2) In the third embodiment described above, the first to third lower-level ECUs 40, 50, and 60, upon determining that they have been activated via relay circuits 26, 28, and 36, send a resetting request for PNC setting information to the upper-level ECU 10. Furthermore, the first to third lower-level ECUs 40, 50, and 60 can also determine whether their own PNC setting information is appropriate, and if deemed inappropriate, send a resetting request for PNC setting information to the upper-level ECU 10. For example, if the first to third lower-level ECUs 40, 50, and 60 have set PNC setting information that does not belong to any cluster, they can determine that the PNC setting information is inappropriate.

[0120] (Variation Example 3) The systems and methods described in this disclosure can also be implemented using a special-purpose computer configured with a processor programmed to perform one or more functions embodied in a computer program. The systems and methods described in this disclosure can also be implemented using special-purpose hardware logic circuits. The systems and methods described in this disclosure can also be implemented using one or more special-purpose computers composed of a processor executing a computer program and a combination of one or more hardware logic circuits. For example, some or all of the functions possessed by the upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 can also be implemented as hardware. Implementing a function as hardware includes using one or more ICs. Some or all of the functions possessed by the upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60 can also be implemented using any one of a system-on-a-chip (SoC), an integrated circuit (IC), and a field-programmable gate array (FPGA). The concept of IC also includes application-specific integrated circuits (ASICs). Furthermore, computer programs, as instructions executed by a computer, can be stored on a non-transitory tangible storage medium that can be read by a computer. HDDs (Hard-disk Drives), SSDs (Solid State Drives), flash memory, and the like can be used as the recording medium for the program. Additionally, methods such as using a non-transitory physical recording medium, including programs that enable the computer to function as the upper-level ECU 10, the first and second middle-level ECUs 20 and 30, and the first to third lower-level ECUs 40, 50, and 60, and semiconductor memories storing those programs, are also included within the scope of this disclosure.

Claims

1. A vehicle system comprising multiple control devices mounted on a vehicle, The plurality of control devices include at least one lower-level control device and at least one upper-level control device. The upper-level control device has a relay control unit that connects or disconnects the relay circuit located on the power supply line of the lower-level control device. At least one of the plurality of control devices is communicatively connected to the lower-level control device via a communication bus. The upper-level control device disconnects the relay circuit via the relay control unit and then reconnects the relay circuit when communication between at least one of the multiple control devices and the lower-level control device whose relay circuit is connected is interrupted for a predetermined time.

2. The vehicle system according to claim 1, The upper-level control device has a determination unit that determines whether the lower-level control device is in an active state. If the determination unit determines that the lower-level control device has entered an operational state, the upper-level control device determines whether the communication with the lower-level control device has been interrupted for a specified time.

3. The vehicle system according to claim 1, The upper-level control device is at least one of a plurality of control devices and is communicatively connected to the lower-level control device, receiving messages from the lower-level control device. If the upper-level control device fails to receive a message from the lower-level control device within a specified time, it is determined that the communication with the lower-level control device has been interrupted for the specified time.

4. The vehicle system according to claim 1, The control device other than the upper-level control device is connected to the lower-level control device in a communicative manner as at least one of the plurality of control devices, and receives messages from the lower-level control device. If the control device other than the upper-level control device fails to receive a message from the lower-level control device within a specified time, it shall notify the upper-level control device.

5. The vehicle system according to claim 1, The lower-level control device stores cluster setting information indicating the cluster assigned to it within the multiple clusters it is divided into. The lower-level control device starts from the dormant state and enters the active state upon receiving a network management message (NM message) containing cluster startup information. The cluster startup information indicates the cluster in the cluster setting information as the cluster to be started.

6. The vehicle system according to claim 5, It also includes a cluster setting information setting unit that re-sets the cluster setting information stored in the lower-level control device when the relay circuit is disconnected by the relay control unit and then reconnected.

7. The vehicle system according to claim 5, It also includes a cluster setting information setting unit that, upon receiving a resetting request for the cluster setting information from the lower-level control device, resetting the cluster setting information stored in the lower-level control device.

8. The vehicle system according to claim 7, The lower-level control device is configured to determine whether the startup was initiated based on the receipt of the NM message or by the activation of the relay circuit to start power supply. When the lower-level control device determines that it has started to start power supply, it sends a request to the cluster setting information resetting unit.

9. The vehicle system according to claim 8, The lower-level control device determines whether the startup was initiated based on the receipt of the NM message or the start of power supply based on at least one of the following: whether a variable set to an initial value when the power supply is started becomes an initial value; whether data used in the processing during normal operation is stored in volatile memory; and whether there is information indicating the receipt of the NM message.

10. The vehicle system according to any one of claims 6 to 9, When the cluster setting information setting unit re-sets the cluster setting information stored in the lower-level control device, it re-sets the cluster setting information stored in the lower-level control device in a manner that makes the lower-level control device belong to at least one cluster.

11. The vehicle system according to any one of claims 6 to 9, When the cluster setting information setting unit re-sets the cluster setting information stored by the lower-level control device, it re-sets the cluster setting information stored by the lower-level control device in a manner that makes the lower-level control device belong to all clusters.

12. The vehicle system according to claim 11, If the result of resetting the cluster setting information stored by the lower-level control device is that the communication interruption between the upper-level control device and the lower-level control device is eliminated, the cluster setting information setting unit will then reset the cluster setting information stored by the lower-level control device to the default cluster setting information.

13. A control method for a vehicle system, comprising a vehicle system having multiple control devices mounted on the vehicle. The plurality of control devices include at least one lower-level control device and at least one upper-level control device. The upper-level control device has a relay control unit that connects or disconnects the relay circuit located on the power supply line of the lower-level control device. At least one of the plurality of control devices is communicatively connected to the lower-level control device via a communication bus. The control method for the vehicle system includes: Determine whether communication between at least one of the plurality of control devices and the lower-level control device whose relay circuit is activated has been interrupted for a predetermined time; and Based on the determination that communication between at least one of the multiple control devices and the lower-level control device has been interrupted for a specified time, the upper-level control device disconnects the relay circuit through the relay control unit, and then reconnects the relay circuit.

Citation Information

Patent Citations

  • Vehicle system

    JP2022138678A