Maintaining an electronic control unit identification during reprogramming events
The storage system for vehicle control modules addresses the challenge of retaining identification data during reprogramming by using a non-volatile second memory to store this data, ensuring its availability and system functionality across reprogramming operations.
Patent Information
- Application Number
- DE102006029690
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2005-06-30
- Filing Date
- 2006-06-28
- Publication Date
- 2025-06-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing vehicle control module systems face challenges in retaining identification data during reprogramming operations, leading to potential failures and inability to transition from boot mode to application mode.
A storage system that includes a non-volatile rewritable first memory for storing an application program, a non-volatile second memory for retaining identification data, and a control module that transfers identification data to the second memory before reprogramming, ensuring data retention and availability during boot mode.
The solution ensures that control module identification data is retained across reprogramming operations, allowing the system to maintain functionality and transition correctly from boot mode to application mode, even in case of reprogramming failures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The present invention relates to vehicle control modules and more particularly relates to a method of storing identification data in a memory of a control module for a motor vehicle.Control modules are used to control the operation of one or more components of a vehicle. For example, the control module may operate as an engine control module that manages a fuel control system or powertrain of the vehicle. Generally, the control module implements a control program and may include a boot program, an application program, and calibration data. The memory may be erased and / or rewritten to replace or update the control program.In FIG. 1, a control module management system 10 includes one or more control modules 12- 1, 12- 2, 12- 3,..., and 12- x, collectively referred to as control modules 12. The control modules 12 communicate with various vehicle components 14- 1, 14- 2, 14- 3,..., and 14- y, collectively referred to as vehicle components 14. The control modules 12 communicate with the other control modules 12 via a communication interface such as a vehicle communication bus 16. For example, the data rewriting device 18 may rewrite (i.e., delete or update) the control program of the control module 12- 1. Additionally, the data rewriting device 18 may communicate with the control module 12-1 to determine information about the control program currently therein. The control program may include information about itself or the control module 12-1. For example, the information may include, but is not limited to, software versions of the boot program, application program or calibration data, previous programming event data, and / or hardware information.A storage system known from US 2004 / 0122537 A1 comprises a nonvolatile, rewritable first memory for storing a control program, a volatile second memory for storing vehicle state data determined during an application mode, and a control module. For a respective reprogramming of the control program, the vehicle state data are firstly shifted from a front region of the second memory into a rear region of this second memory. Subsequently, the received new program is loaded into a portion of the second memory which includes the front portion of this second memory normally designated for the state data. The new program is then transferred from the second memory into the first memory. Finally, the vehicle state data is shifted from the rear portion of the second memory to the front portion thereof again. A non-volatile memory can also be provided as the second memory.According to a first aspect of the invention, there is provided a storage system comprising: a non-volatile rewritable first memory for storing an application program containing a control program and identification data; means for deleting, for each reprogramming operation, the application program contained in the first memory and rewriting the first memory with a new application program; a non-volatile second memory which is not rewritable; a control module (26) that transfers the identification data contained in the application program stored in the first memory from the first memory to the second memory before a respective reprogramming operation, so that the identification data transferred to the second memory in each case is retained therein and the identification data from previous reprogramming operations also remain stored in the second memory, wherein the identification data are available during a boot mode, the control module generates new identification data, which comprise reprogramming data, during the boot mode, and adds the new identification data to the already existing identification data in the second memory, and the control module then erases the first memory, rewrites the first memory with the new application program, and transfers the most up-to-date new identification data from the second memory to the first memory after erasing the first memory.Preferred embodiments of this storage system are set out in claims 2 to 13.According to another aspect of the invention, there is provided a control module comprising the storage system of claim 1.Further areas of applicability of the present invention will become apparent from the detailed description provided hereinafter. It should be understood that the detailed description and specific examples, while illustrating the preferred embodiment of the invention, are intended for purposes of explanation only and are not intended to limit the scope of the invention.The invention is described below by way of example with reference to the drawings. In this figure: FIG. 1 is a functional block diagram of a control module management system according to the prior art; FIG. 2 is a functional block diagram of a control module that includes a control module identification block in flash memory, in accordance with the present invention; FIG. 3 illustrates a control module identification block of flash memory in accordance with the present invention; and FIG. 4 is a flow chart illustrating steps of a method for storing control module identification data that can be accessed during a boot mode of a control module, in accordance with the present invention.The following description of the preferred embodiment(s) is merely exemplary in nature and is in no way intended to limit the invention, its application, or uses. For clarity, the same reference numerals are used in the drawings to identify similar elements. As used herein, the term module and / or device refers to an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or grouped), and memory that executes one or more software or firmware programs, a combinational logic circuit, and / or other suitable components that provide the described functionality.In FIG. 2, a control module ("ECU") 20 includes a volatile memory or random access memory (RAM) module 22, a non-volatile memory or flash memory module 24, a control module 26, and an input / output interface 28. The control module 26 operates in accordance with one or more programs that may be located in the RAM module 22, flash memory module 24, or other memory. In other words, the RAM module 22 and the flash memory module 24 store programs and / or data used to execute programs with the control module 26.The flash memory module 24 is a non-volatile read-only memory. Those skilled in the art will appreciate that a hard disk drive (HDD) or other suitable non-volatile memory may replace flash memory module 24. Flash memory module 24 includes rewritable and non-rewritable areas. A boot program is stored in the non-rewritable area. Generally, upon a power-on or reset of the control module 20, the boot program is executed (i.e., the control module 20 is in a "boot mode"). The control module 26 performs initial processing on the boot program while the control module 20 is in the boot mode. For example, the boot program may determine whether an appropriate application or calibration data is present. In addition, the boot program may verify the integrity of the application software or calibration data. When the boot program verifies the presence and integrity of all required software and / or data, the control module 26 executes the application program (i.e., the control module is in an "application mode"). In other implementations, the boot program may be stored in a rewritable area.The application programs and / or calibration data are stored in the rewritable area of the flash memory module 24. The data rewrite device 18 communicates with the control module 20 via the bus 16 and the input / output interface 28 to delete or rewrite the programs stored in the flash memory module 24.The RAM module 22 stores temporary data used by the control module 26. For example, the RAM module 22 may store results of computations for the application program. Generally, the RAM module 22 is volatile memory, and the contents of the RAM module 22 are lost upon a power down and / or re-initialized upon a reset of the control module 20 (i.e., zeroed). However, the RAM module 22 may include a temporary storage area 30 for maintaining permanent data. Certain data may be stored in the temporary storage area 30 during operation of the control module 20. The data is then transferred to an available area of flash memory module 24 prior to shutting down control module 20. In this manner, the data stored in the temporary storage area 30 is maintained in the flash memory module 24 before the RAM module 22 is erased.The flash memory module 24 includes a non-rewritable control module identification flash block (control module ID flash block) 32. the control module ID flash block 32 may be included in the non-rewritable area storing the boot program. Alternatively, the control module ID flash block 32 may be an independent non-rewritable area. In one implementation, the non-rewritable area is a physically rewritable area of the flash memory module 24. However, the control module 26 and / or boot program limit / limit the ability of the data rewriting device 18 to erase or rewrite the non-rewritable area. In another implementation, the non-rewritable area is a read-only memory (ROM) module.The control module ID flash block 32 stores identification information about the control module 20 and / or information about boot software, application software, and calibration data. For example, the control module ID flash block 32 may store information about the hardware components of the control module 20, such as part numbers and manufacturer data. Additionally, the control module ID flash block 32 may store software version numbers and programming data.The identification information stored in the control module ID flash block 32 may be used for diagnostic, improvement, and / or repair purposes. Software or hardware updates may be available to the control module 20. The data rewriting device 18 provides options to rewrite the control module 20 according to the identification information. For example, the data rewriting device 18 determines whether the current software is expired and allows a user to rewrite the control module 20 with current software. In other embodiments, the data rewriting device 18 is capable of determining whether the current application and the calibration software are compatible.Generally, the control module 20 begins in boot mode and enters application mode after successful verification of the application program, as described above. However, during reprogramming, the control module 20 remains in the boot mode until the flash memory module 24 is rewritten. After successful reprogramming of the flash memory module 24, the control module 20 enters the application mode for a standard operation.Data contained in the application program is not available to the data rewriting device 18 during reprogramming (i.e., boot mode). When reprogramming is initialized, the application program is deleted from the flash memory module 24 in preparation for rewriting the new application program. Conventionally, the control module identification information is stored in the application program. Therefore, the control module identification information is not available after reprogramming begins. If reprogramming fails for any reason, the control module 20 may not transition from the boot mode to the application mode until a subsequent reprogramming attempt is successful. In other words, the control module 20 remains stuck in boot mode and no information stored in the application program is available to the data rewriting device 18.The control module 20 of the present invention stores the control module identification information into the non-rewritable control module ID flash block 32 so that the control module identification information is available during the boot mode. If a reprogramming attempt fails and the application program is deleted, the data rewriting device 18 is still capable of determining the control module identification information from the control module ID flash block 32.Referring to FIG. 3, a control module ID flash block 32 is shown. The control module ID flash block 32 includes a plurality of control module IDs 1, 2, 3,..., and m respectively arranged in ID flash blocks 34- 1, 34- 2, 34- 3,..., and 34- m. Each ID represents control module identification information from previous reprogramming operations. The control module ID flash block 32 also includes empty memory blocks 36- 1, 36- 2, 36- 3,..., and 36- nto store future control module IDs. During a reprogramming event, the control module 20 determines a location 34- mof the latest control module ID to calculate a location of the first empty memory block 36- 1. The control module 20 stores a new control module ID into the first empty memory block 36- 1.Referring to FIG. 4, a control module ID method 40 starts at step 42. For example, after an initial power-on, the control module transitions from the boot mode to the application mode and begins a default operation. In step 46, the control module enters a reprogramming mode. For example, the means for rewriting data exchanges data with the control module to initialize reprogramming. In order for the means for rewriting data to reprogram the control module, the control module must be in boot mode.In the application mode, the control module uses the RAM to execute the application program. To reprogram the flash memory, the control module uses the RAM to execute data transfer subroutines. Therefore, in the application mode, the control module cannot use the RAM to write to the ID flash block (i.e., reprogram the flash memory). Instead, the control module uses the RAM to store the control module ID during the transition to boot mode. In step 48, the current control module ID is transferred from the current application program to a shared RAM location. In other implementations, the method 40 may omit step 48. For example, the control module may simultaneously use the RAM to execute the application program while executing the data transfer subroutines. In this way, the control module may transfer the current control module ID directly to the ID flash block.In step 50, the control module begins a transition from the application mode to the boot mode. In step 52, the current control module ID is transferred from the shared RAM location to an available ID flash block q during the boot mode transition. In step 54, the control module completes the transition to boot mode. After a successful transition to boot mode, the control module may inform the means for rewriting data that reprogramming may proceed.In step 56, a new control module ID is generated in the ID flash block q+1. The new control module ID includes the identification information stored in the ID flash block q plus additional information. For example, the additional information may include, but is not limited to, a repair location and / or reprogramming data. If step 56 fails for some reason, the control module ID stored in the ID flash block q is still available to the means for rewriting data. In step 58, the means for rewriting data erases the flash memory module. In other words, the data rewriting means erases all the software disposed in the rewritable areas of the flash memory module. Any data stored in the ID flash blocks is retained. If reprogramming fails or is interrupted, the control module must be reset to the boot mode and cannot enter the application mode. However, the control module ID stored in the ID flash blocks may still be accessed.In step 60, the means for rewriting data completes reprogramming. For example, the means for rewriting data completes download / programming of the control module with new application and / or calibration software. In step 62, the method 40 performs integrity and / or compatibility tests. For example, method 40 executes a checksum routine as is known in the art. Additionally, the method 40 may determine compatibility between the application software and the calibration software. In step 64, the method 40 determines whether the tests have been passed. In one implementation, the method 40 updates the control module ID stored in the ID flash block q+1 to indicate that reprogramming is complete and that integrity tests are performed. The method 40 updates the control module ID again when the tests are completed. The data rewriter then checks the control module ID to determine whether the tests have been passed. If so, the method 40 continues to step 66. If not, the method continues to step 68.In step 68, the control module remains in boot mode because one or more of the tests performed in step 64 fails. The method 40 then proceeds to step 70 and ends. Subsequently, the control module may be reset for additional reprogramming attempts. The control module begins in boot mode and the means for rewriting data may receive control module ID data from the control module ID flash block q and / or the ID flash block q+1.In step 66, the control module transitions from boot mode to application mode. In step 72, the most up-to-date control module ID (i.e., the control module ID stored in the ID flash block q+1) is transferred to the non-volatile memory. Alternatively, only specific elements of the most recent control module ID, such as the elements to be accessed during the application mode, are transferred to the non-volatile memory. In one implementation, the control module ID is transferred to the temporary storage area 30, as shown in FIG. 2. The control module continues to operate in the application mode and the method ends in step 70.
Claims
A storage system comprising: a non-volatile rewritable first memory (24) for storing an application program containing a control program and identification data; means for deleting the application program contained in the first memory (24) and rewriting the first memory (24) with a new application program for a respective reprogramming operation; and a non-volatile second memory (32) which is not rewritable, characterized a control module (26) that transfers the identification data contained in the application program stored in the first memory (24) from the first memory (24) to the second memory (32) before a respective reprogramming operation so that the identification data transferred to the second memory (32) respectively are retained therein and also the identification data of previous reprogramming operations are retained in the second memory (32), the identification data being available during a boot mode, the control module (26) generates new identification data comprising reprogramming data during the boot mode and adds the new identification data to the already existing identification data in the second memory (32), and the control module (26) subsequently erases the first memory (24), said first memory (24) being rewritten with said new application program and transferring said most up-to-date new identification data from said second memory (32) to said first memory (24) after erasing said first memory (24).The memory system of claim 1, characterized bya memory module (24) comprising the first memory and the second memory (32).The memory system of claim 2, characterized in that the memory module is a flash memory module (24).The storage system according to claim 1, characterized bya third memory (22), wherein the control module (26) transfers the identification data from the first memory (24) to the third memory (22), and then transfers the identification data from the third memory (22) to the second memory (32).The storage system according to claim 4, characterized in that the third storage (22) is volatile.The memory system according to claim 5, characterized in that the third memory is a RAM (22).The storage system of claim 1, characterized in that the first memory (24) stores a boot program.The storage system of claim 7, characterized in that the control module (26) has a first mode of operation and a second mode of operation.The storage system of claim 8, characterized in that the control module (26), after transferring the identification data to the second memory (32), transitions from the first mode to the second mode, and, after rewriting the control module (26), transitions from the second mode to the first mode.The storage system of claim 9, characterized in that the control module (26) executes the control program in the first mode and executes the boot program in the second mode.A storage system according to claim 1, characterized in that the identification data comprises a software version identifier and / or a programming date and / or a part number.The storage system according to claim 1, characterized in that the application program stored in the first memory (24) further includes a boot program, and the control module has a first mode and a second mode, executes the control program in the first mode and the boot program in the second mode, transfers the identification data from the first memory (24) to the second memory (32), transitions from the first mode to the second mode, erases the first memory (24), and rewrites the control program, transitions from the second mode to the first mode, and transfers the current identification data from the second memory (32) to the first memory (24).The storage system according to claim 1, characterized in that the application program stored in the first memory (24) further includes a boot program, a volatile third memory (22) is provided; and the control module (26) has a first mode and a second mode, executing the control program in the first mode and the boot program in the second mode, transferring the identification data from the first memory (24) to the third memory (22), transitioning from the first mode to the second mode, transferring the current identification data from the third memory to the second memory, rewriting the control program, transitioning from the second mode to the first mode, and transferring the current identification data from the second memory (32) to the first memory (24).A control module comprising the storage system of claim 1.
Citation Information
Patent Citations
Rewrite control apparatus for onboard program
US20040122537A1