In-vehicle network system and control procedures

The in-vehicle network system addresses communication disruptions by using a power management and abnormality detection mechanism to efficiently locate and correct issues in lower control units, enhancing maintenance efficiency.

DE102025134683A1Pending Publication Date: 2026-03-05DENSO CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102025134683
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing in-vehicle network systems face inefficiencies in diagnosing communication disruptions in lower control units due to unknown malfunctions, which can hinder maintenance efficiency.

Method used

An in-vehicle network system with a power management unit and abnormality position determination unit that monitors power supply and communication states of lower control devices, using relay circuits and network management messages to identify and locate abnormalities.

Benefits of technology

Enables efficient identification and localization of abnormalities, preventing maintenance inefficiencies and ensuring timely correction of issues in the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An in-vehicle network system (100) includes a plurality of control devices (10, 20, 30, 40, 50) connected to a communication bus (8) and configured to communicate with each other. The plurality of control devices includes at least one upper control device (10) and a plurality of lower control devices (20, 30).The upper control device includes a power management unit (13) configured to turn on and off a plurality of relay circuits (15, 16) provided in a power supply line (6); a start management unit (12) configured to receive a network management message, instruct the power management unit to turn on the relay circuit, and set the lower control device; and an abnormality location determination unit (17) configured to detect a power supply state and a communication state and to determine an abnormality occurrence location.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present disclosure relates to an in-vehicle network system comprising several control devices capable of mutual communication and connected via a communication bus, and a control method for the in-vehicle network system.

[0002] For example, JP 7238650B discloses an in-vehicle network system comprising an upper control device, an intermediate control device, and a lower control device. In the in-vehicle network system of JP 7238650B, the intermediate control device receives power from a power supply and supplies power to the lower control device from the power supply in response to a message received from the upper control device. In other words, the intermediate control device keeps the lower control device in an off state until a message is received from the upper control device. Upon receiving a message from the upper control device at the intermediate control device, the lower control device is supplied with power. Due to this power supply, the lower control device transitions from the off state to a ready state and awaits instructions.

[0003] In an in-vehicle network system, as described in JP 7238650B, it is conceivable that some irregularity could occur, leading to a communication disruption with the lower control unit, even though the intermediate control unit is supplying power to the lower control unit. In such cases, the intermediate control unit can detect that a communication disruption with the lower control unit has occurred. However, if the specific malfunction causing the communication disruption is unknown, addressing the problem can be cumbersome, potentially reducing maintenance efficiency.

[0004] In view of the foregoing, the present disclosure aims to provide an in-vehicle network system and a control method for the in-vehicle network system that estimate the abnormality occurrence position when an irregularity occurs in the lower control device.

[0005] According to one aspect of the present disclosure, an in-vehicle network system is provided, comprising a plurality of control devices connected to a communication bus and configured to communicate with each other within a vehicle. The plurality of control devices includes at least one upper control device and a plurality of lower control devices. The at least one upper control device includes a power management unit configured to switch on and off a plurality of relay circuits provided in a power supply line to each of the plurality of lower control devices, and a start management unit configured to receive a network management message on behalf of a plurality of lower control devices.wherein the network management message is transmitted over the communication bus and selectively directs a start of the plurality of lower control devices to instruct the power management unit to turn on the relay circuit provided in the power supply line of the lower control device for which a start is instructed by the network management message, and to place the lower control device for which the start is instructed into a start state, and an abnormality position determination unit configured to detect a power supply state to the lower control devices and a communication state with the lower control devices and to determine an abnormality occurrence position based on a detection result.

[0006] According to one aspect of the present disclosure, a method for controlling an in-vehicle network system is provided, comprising a plurality of control devices connected to a communication bus and configured to communicate with each other within a vehicle. The plurality of control devices includes at least one upper control device and a plurality of lower control devices. The at least one upper control device includes a power management unit configured to switch on and off a plurality of relay circuits provided in a power supply line to each of the plurality of lower control devices.The procedure includes: receiving, on behalf of the plurality of lower control devices, a network management message transmitted over the communication bus by at least one upper control device, selectively instructing a start of the plurality of lower control devices; energizing the relay circuit provided in the power supply line of the lower control device for which a start is instructed by the network management message; placing the lower control device for which a start is instructed into a start state; detecting a power supply state to the lower control devices and a communication state with the lower control devices; and determining an abnormality occurrence position based on a detection result.

[0007] According to the vehicle's internal network system and the method for controlling the vehicle's internal network system described in this disclosure, the upper control unit receives the network management message, transmitted over the communication bus, which selectively instructs the start of several lower control units on behalf of those units. The upper control unit then activates the relay circuit provided in the power supply line of the lower control unit for which the network management message indicates a start, thereby activating the instructed lower control unit. The upper control unit monitors the power supply status to the lower control units and the communication status with the lower control units and determines the abnormality occurrence location based on these monitoring results.

[0008] Therefore, according to the vehicle's internal network system and the control procedure for the vehicle's internal network system described in this disclosure, it is possible to estimate the location of the abnormality. Therefore, if an abnormality occurs, it is possible to prevent a decrease in the efficiency of the maintenance required to correct the abnormality.

[0009] The functions, features, and advantages of this disclosure will become clearer from the following detailed description with reference to the accompanying drawings. These show: Fig. 1 a configuration diagram showing an example of the configuration of the vehicle's in-vehicle network system according to the embodiment; Fig. 2. An explanatory diagram to illustrate an example of the NM message, PN request information, and PNC configuration information; Fig. 3 a diagram showing an example of the PNC configuration table stored in the data storage unit of the power / start management ECU; Fig. 4 a diagram showing an example of the relay connection information stored in the data storage unit of the power / start management ECU; Fig. 5 a configuration diagram showing an example of the configuration of the current sensing unit provided in the abnormality position determination unit for sensing the power supply status to the lower ECU; Fig. 6 a diagram showing the first threshold and the second threshold, which are compared with the amount of current detected in the abnormality position determination unit; Fig. 7 a flowchart illustrating an example of the process performed in the power / start management ECU; Fig. 8. A flowchart detailing the start-up ECU identification process in the flowchart of Fig. 7 shows; and Fig. 9. A flowchart detailing the abnormality position determination process in the flowchart of Fig. 7 shows.

[0010] The following describes embodiments of the vehicle's in-vehicle network system and the control method for the vehicle's in-vehicle network system according to the present disclosure with reference to the drawings. However, the present disclosure is not limited to the following embodiments, and various modifications described later are also included within the technical scope of the present disclosure. Furthermore, various changes may be made without departing from the spirit of the present disclosure. The embodiments and various modifications may be combined appropriately, provided that no technical contradictions arise. In the following description, identical or similar configurations may be assigned the same reference numerals across multiple drawings, and explanatory notes may be omitted.If only part of a configuration is mentioned, the description of other parts from other sections can be applied. (First embodiment)

[0011] Fig. Figure 1 is a configuration diagram illustrating an example of the configuration of the vehicle's in-vehicle network system 100 according to this embodiment. As shown in Fig. As shown in Figure 1, the vehicle's internal network system 100 includes an energy / start management ECU 10 as an upper control unit, first and second lower ECUs 20, 30, and first and second normal ECUs 40, 50 as lower control units. ECU stands for Electronic Control Unit. The first and second lower ECUs 20, 30 are each connected to the energy / start management ECU 10 via a first and second relay circuit 15, 16.

[0012] The number of first and second lower ECUs 20, 30 connected to the power / start management ECU 10 via relay circuits, such as the first and second relay circuits 15, 16, is not limited to two and can be three or more. Additionally, the number of first and second lower ECUs 20, 30 connected to each of the first and second relay circuits 15, 16 is not limited to one and can be two or more. Furthermore, in the vehicle's internal network system 100, the combination of the power / start management ECU 10 and the first and second lower ECUs 20, 30 is not limited to one set and can be provided in multiple sets.If multiple sets of combinations of the power / start management ECU 10 and the first and second lower ECUs 20, 30 are provided in the vehicle's internal network system 100, each power / start management ECU 10 and the first and second lower ECUs 20, 30 can be connected to each other for communication via the communication bus 8.

[0013] The power / start management ECU 10, the first and second lower ECUs 20, 30, and the first and second normal ECUs 40, 50 can each be configured by a computer containing a processor, memory, and data storage. The power / start management ECU 10, the first and second lower ECUs 20, 30, and the first and second normal ECUs 40, 50 also include communication interfaces (IFs) 11, 21, 31, 41, 51 for communicating with other ECUs.

[0014] The processor can be, for example, a CPU, MPU, GPU, DFP, or similar device that performs predetermined processing according to a program. Memory is a volatile storage medium, such as RAM, that temporarily stores the processor's calculation results. Data storage is a non-volatile storage medium, such as flash memory or ROM. Various programs and data executed by the processor are stored in the data storage. Some or all of the functions provided by the power / start management ECU 10, the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50 can be implemented by hardware, such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field-Programmable Gate Array), instead of software, such as a program.

[0015] The power / start management ECU 10 can function as a domain controller, monitoring the control of the first and second lower ECUs 20 and 30. A domain refers to a functional unit when the vehicle's functions are broadly subdivided, such as into powertrain domain, chassis domain, advanced driver assistance domain, body domain, and cockpit domain. The above is an example of domain subdivision, and the domain subdivision may differ from the examples mentioned above. Additionally, the power / start management ECU 10 can function as a region controller, monitoring the control of the lower ECUs 20 and 30 located in each region of the vehicle.

[0016] The vehicle's internal network system 100 can use CAN (registered trademark) as the communication protocol for mutual communication between the ECUs 10, 20, 30, 40, and 50. The communication protocol is not limited to CAN, and the vehicle's internal network system 100 can adopt another communication protocol, such as CAN-FD. However, in this embodiment of the vehicle's internal network system 100, the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50 are divided into several groups (referred to as clusters) for each ECU, which must be activated simultaneously to perform at least one desired function. Using a network management message (referred to as an NM message), the normal operating mode (start-up state) and the power-saving mode (e.g., sleep state) are switched for each cluster. The power-saving mode involves the first and second lower ECUs 20 and 30 being switched off.Therefore, the communication protocol adopted from the vehicle's internal network system 100 must support the transmission and reception of NM messages.

[0017] The first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50, are, for example, control ECUs for controlling a predetermined control target in the vehicle or sensor ECUs for calculating a predetermined physical quantity based on signals acquired by sensors. In normal operating mode, the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50 enter the startup state and perform normal operations when it is necessary to control the control target or calculate a predetermined physical quantity based on the sensor signal. Conversely, when it is not necessary to control the control target or calculate a predetermined physical quantity, the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50 enter a power-saving state, i.e., a switched-off or sleep state.

[0018] To switch between such a startup state (in normal operating mode) and a powered-off state or a sleep state (in a power-saving mode), the first and second lower ECUs 20, 30 and the first and second normal ECUs 40, 50 are each assigned to a cluster within the multiple shared clusters. The assigned cluster is maintained by each ECU as cluster configuration information (also referred to as PNC configuration information). However, the PNC configuration information of the first and second lower ECUs 20, 30 is stored in the data storage unit 14 of the power / start management ECU 10, as described later.Then, in response to the start cluster information (also known as PN request information) included in the NM message, the first and second lower ECU 20, 30 and the first and second normal ECU 40, 50 are configured to switch from the off or sleep state to the start state.

[0019] When the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50 enter the startup state and normal operating mode, they periodically transmit NM messages to other ECUs while performing their normal operations. Once these ECUs have completed the necessary processing and no longer need to perform normal operations, they cease the periodic transmission of NM messages. The first and second normal ECUs 40 and 50 transition from normal operating mode to power-saving mode and switch from the startup state to sleep mode if they do not receive any NM messages from other ECUs belonging to the same cluster for a predetermined standby period. With respect to the first and second lower ECUs 20 and 30, the power / start management ECU 10 monitors for an NM message addressed to the first and second lower ECUs 20 and 30.If the predetermined standby time is reached without receiving the NM message addressed to the first and second lower ECU 20, 30, the power / start management ECU 10 switches off the first and second relay circuit 15, 16 and stops the power supply to the first and second lower ECU 20, 30.

[0020] The first and second normal ECUs 40 and 50 have communication interfaces 41 and 51 that are capable of receiving NM messages in sleep mode and switching from sleep to startup mode in response to receiving NM messages. When switched to startup mode by communication interfaces 41 and 51, the first and second normal ECUs 40 and 50 determine, based on the PN request information in the NM message and their PNC configuration information, whether a startup request is being made. If it is determined that a startup request is being made, the first and second normal ECUs 40 and 50 proceed to startup mode. Conversely, if it is determined that a startup request is not being made, the first and second normal ECUs 40 and 50 return to sleep mode. This determination based on the PN request information and the PNC configuration information can be performed by communication interfaces 41 and 51.In this case, if communication interfaces 41 and 51 determine, based on the PN request information and the PNC configuration information, that a start is requested, communication interfaces 41 and 51 transition the corresponding first and second normal ECUs 40 and 50 from sleep to start states. An example of NM messages, PN request information, and PNC configuration information is explained in detail below.

[0021] As in Fig. As shown in Figure 2, NM messages contain data from byte 0 to byte 7. Byte 0 contains the node ID (NID). The node ID is a unique identifier for each of the power / start management ECU 10, the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50. The node ID allows identification of the sender of the NM message. Byte 1 contains the control bit vector (CBV). The control bit vector indicates whether partial networking (PN) is used. If the control bit vector indicates the use of partial networking, the user data area from byte 2 to byte 7 contains PN request information, which is start cluster information indicating that the cluster should be activated. Partial networking means that only the ECUs belonging to certain clusters are activated, while the ECUs belonging to other clusters are kept in the off or sleep state.By activating only the ECUs necessary for operation, the energy consumption of each ECU installed in the vehicle can be reduced.

[0022] In the Fig. In the example shown, the control bit vector indicates the use of a partial network, and PN request information is stored in bytes 6 and 7 of the user data area. The user data area from byte 2 to byte 5 can be used to transmit any information, such as ECU start factors or information regarding normal or abnormal conditions. Fig. Figure 2 merely shows an example of the format of NM messages, and NM messages can take other formats as long as they include the use of partial networking and PN request information.

[0023] The PN request information specifies the startup cluster to be activated and the cluster that does not require startup for each of the multiple shared clusters. More precisely, it is contained in the Fig. In example 2, the clusters are pre-divided into 16. The PN request information contains 16-bit data corresponding to the 16 divided clusters. That is, the 16-bit data of the PN request information is pre-assigned to the 16 divided clusters. Each data bit of the 16-bit PN request information indicates that starting the assigned cluster is unnecessary if it is "0" and necessary if it is "1".

[0024] As described above, the first and second lower ECUs 20 and 30, and the first and second normal ECUs 40 and 50, contain PNC configuration information indicating the cluster to which they belong among the multiple shared clusters. An example of this PNC configuration information is shown in Fig. 2 shown. Fig. Figure 2 illustrates an example of the PNC configuration information for any one of the first and second lower ECUs 20, 30 and the first and second normal ECUs 40, 50. In the Fig. In Figure 2, the PNC configuration information, where the clusters in the figure are classified from left to right as A to P, indicates that the ECU holding this PNC configuration information belongs to clusters D, H, and J. Since the first and second lower ECUs (20, 30) and the first and second normal ECUs (40, 50) can have different functions through program execution, they can belong to one or more clusters.

[0025] When the first and second normal ECUs 40 and 50 receive the NM message containing the PN request information via communication interfaces 41 and 51, the first and second normal ECUs 40 and 50 compare the PN request information and the PNC configuration information bit-by-bit, as shown in Fig. 2 shown, and calculate, for example, a logical AND (a logical product). In other words, when NM messages are received at their communication IFs 41, 51, the first and second normal ECUs 40, 50 temporarily enter the startup state. Then, the first and second normal ECUs 40, 50 determine whether the cluster requested to start by the PN request information in the NM message matches the cluster assigned in their PNC configuration information. For example, in the Fig. In example 2, the clusters requested to start by the PN request information are clusters D, G, I, M, N, and O. The clusters specified by the PNC configuration information to which the ECU belongs are clusters D, H, and J. In this case, the cluster requested to start by the PN request information in the NM message matches the cluster in the PNC configuration information in cluster D. Therefore, as shown in Fig. 2 shows the result of the logical AND in cluster D “1”.

[0026] If one bit of the logical AND result is "1", the ECU uses the values ​​in Fig. The PNC configuration information shown in section 2 indicates that its startup is being requested. Based on this determination, the ECU proceeds with the configuration shown in the following: Fig. The PNC configuration information shown in section 2 transitions from the idle state to the start state and maintains the start state if it is already enabled. Conversely, if none of the bits of the logical AND result are "1" and all are "0", the ECU determines the state using the information shown in section 2. Fig. The PNC configuration information shown in section 2 indicates that its startup is not requested. In this case, the ECU discards the information contained in the data. Fig. The PNC configuration information shown in section 2 displays the received NM message and returns to sleep mode.

[0027] Thus, the first and second normal ECUs 40 and 50 have the function of identifying, based on the PNC configuration information, whether the NM message requests their startup. This NM message identification function ensures that only the first and second normal ECUs 40 and 50, with PNC configuration information containing the clusters requested to start by the PN request information, enter the startup state due to the NM message. A communication interface equipped with the function to receive NM messages and switch the ECU from sleep to startup is subsequently referred to as an NM-compatible communication interface.

[0028] In the vehicle's internal network system 100 according to this embodiment, the first and second lower ECUs 20, 30 do not have NM-compatible communication interfaces. In other words, the communication interfaces 21, 31 of the first and second lower ECUs 20, 30 are both NM-incompatible communication interfaces. As described above, NM-compatible communication interfaces have the function of receiving NM messages and switching the ECU from sleep to start mode. Therefore, NM-compatible communication interfaces are more expensive than NM-incompatible communication interfaces. The communication interfaces 21, 31 of the first and second lower ECUs 20, 30 are, as described above, NM-incompatible communication interfaces. Consequently, by using the combination of the power / start management ECU 10 and the lower ECUs 20, 30, the overall cost of the vehicle's internal network system 100 can be reduced.

[0029] In the vehicle-internal network system 100 according to this embodiment, although the communication IFs 21, 31 of the first and second lower ECUs 20, 30 are NM-incompatible communication IFs, the power / start management ECU 10 is configured to subject the first and second lower ECUs 20, 30 to partial networking according to NM messages. Furthermore, the power / start management ECU 10 is configured to determine the location where the abnormality occurred if a certain abnormality occurs in at least one of the first and second lower ECUs 20, 30, preventing them from operating normally. The power / start management ECU 10 according to this embodiment is described in detail below with reference to the drawings.

[0030] As in Fig. As shown in Figure 1, the power / start management ECU 10 includes a communication interface 11, a start management unit 12, a power management unit 13, a data storage unit 14, first and second relay circuits 15 and 16, an abnormality position determination unit 17, an abnormality transmission unit 18, and an abnormality data storage unit 19. The start management unit 12, the power management unit 13, the abnormality position determination unit 17, and the abnormality transmission unit 18 are functional units formed within the power / start management ECU 10 by software and / or hardware. The data storage unit 14 and the abnormality data storage unit 19 can be formed by the data storage of the power / start management ECU 10. The data storage unit 14 and the abnormality data storage unit 19 can be provided in a separate data storage unit or in the same data storage unit.

[0031] The first and second relay circuits 15, 16 of the power / start management ECU 10 are provided in the power supply line 6 to supply power to the first and second lower ECUs 20, 30, respectively. The power circuit 4 can convert the power supply voltage from the vehicle-mounted battery 2 into the operating voltage of the power / start management ECU 10, the first and second lower ECUs 20, 30, and the first and second normal ECUs 40, 50, as needed. The voltage from the power circuit 4 is supplied to the power supply line 6.

[0032] In the Fig. In the example shown, the power line of the first lower ECU 20 is connected to the first power terminal 15a, which is connected to the first relay circuit 15. Similarly, the power line of the second lower ECU 30 is connected to the second power terminal 16a, which is connected to the second relay circuit 16. The first and second lower ECUs 20 and 30 are powered via the first and second relay circuits 15 and 16 and their respective power lines. Thus, the first and second relay circuits and their respective power lines constitute the power supply line.

[0033] The first and second relay circuits 15, 16 can be configured using semiconductor switches, such as MOSFETs or IGBTs. However, the first and second relay circuits 15, 16 can also be configured using conventional mechanical relays. Additionally, as shown in Fig. As shown in Figure 1, the first and second relay circuits 15, 16 may be provided inside or outside the power / start management ECU 10.

[0034] The communication IF 11 of the power / start management ECU 10 is an NM-compatible communication IF capable of receiving NM messages. The communication IFs 21 and 31 of the multiple lower ECUs 20 and 30 are NM-incompatible communication IFs, as described above. In this embodiment, the multiple lower ECUs 20 and 30 enter a powered-off state in power-saving mode when operation is unnecessary. Therefore, the communication IFs 21 and 31 of the multiple lower ECUs 20 and 30 cannot receive NM messages when the corresponding lower ECUs 20 and 30 are in power-saving mode. Consequently, the communication IF 11 of the power / start management ECU 10 receives NM messages that selectively instruct the start of the multiple lower ECUs 20, 30, on behalf of the communication IFs 21, 31 of the multiple lower ECUs 20, 30. The NM messages received by the communication IF 11 are provided to the start management unit 12.

[0035] In addition to programs executed by the processor of the power / start management ECU 10, the data storage unit 14 of the power / start management ECU 10 stores the PNC configuration information assigned to each of the first and second lower ECUs 20, 30, specifying the clusters to which each belongs. Furthermore, the data storage unit 14 stores relay connection information specifying the correspondence between the first and second relay circuits 15, 16 and the first and second lower ECUs 20, 30.

[0036] For example, data storage unit 14 can store the PNC configuration information specifying the clusters assigned to each of the first and second lower ECUs 20 and 30, as shown in Fig. As shown in section 3, using a PNC configuration table for saving. The in Fig. Figure 3 illustrates the PNC configuration table, showing the correspondence between the node IDs, which are unique identifiers of several lower ECUs including the first and second lower ECUs 20 and 30, and the PNC configuration information assigned to these lower ECUs. Additionally, data storage unit 14 stores relay connection information, specifying the correspondence between the first and second relay circuits 15 and 16 and the first and second lower ECUs 20 and 30. As shown in Fig. As shown in Figure 4, the data storage unit 14 stores the correspondence between the numbers of several relay circuits that include the first and second relay circuit 15, 16, or the numbers of power connections and the node IDs that are unique identifiers of several lower ECUs that include the first and second lower ECU 20, 30.

[0037] The start management unit 12 of the power / start management ECU 10 can retrieve the PNC configuration information of each of the first and second lower ECUs 20, 30 by referencing the information in Fig. The boot management unit 12 obtains the PNC configuration table shown in Figure 3. Based on the obtained PNC configuration information for each lower ECU 20, 30 and the PN request information from the NM message, the boot management unit 12 can then determine which of the lower ECUs 20, 30 were instructed to activate by the NM message. Specifically, the boot management unit 12 compares the PN request information from the NM message bit-by-bit with the PNC configuration information of each of the multiple lower ECUs 20, 30. If, based on the comparison result, the boot management unit 12 determines that there is PNC configuration information that includes the cluster requested to start by the PN request information, it determines that the boot of the lower ECU 20, 30 corresponding to this PNC configuration information has been instructed.In this case, the startup management unit 12 provides the node ID of the lower ECU 20, 30, which was instructed to activate by the NM message, to the power management unit 13. Conversely, if the startup management unit 12 determines that there is no PNC configuration information containing the cluster requested to start by the PN request information, the received NM message does not instruct any lower ECU 20, 30 to start, and the NM message is discarded.

[0038] Upon receiving the node ID of the lower ECU 20, 30 instructed to activate from the start management unit 12, the power management unit 13 of the power / start management ECU 10 refers to the relay connection information stored in the data storage unit 14, which specifies the correspondence between each relay circuit 15, 16 and each lower ECU 20, 30. The power management unit 13 then identifies the relay circuits 15, 16 according to the node ID of the lower ECU 20, 30 instructed to activate and outputs a control signal to turn on the identified relay circuits 15, 16. As a result, power is supplied through the relay circuits 15, 16 corresponding to the lower ECUs 20, 30 instructed to activate, and the corresponding lower ECUs 20, 30 enter the start state.

[0039] The first and second lower ECUs 20 and 30 control various control devices mounted on the vehicle. These devices are only controlled when specific conditions are met or in specific environments (e.g., door locking mechanisms, power window motors, headlights, wiper motors, AV equipment) or calculate predetermined physical quantities necessary for control based on sensor signals. For example, the door locking mechanism is controlled by the door locking control ECU when the vehicle user attempts to enter or exit the vehicle. The power window motor is controlled by the power window control ECU when the user operates the window switch.

[0040] Thus, the first and second lower ECUs 20 and 30 control target devices that only operate when specific conditions are met or in specific environments, or calculate predetermined physical quantities necessary for control. Therefore, when the start of the first and second lower ECUs 20 and 30 is instructed by the NM message, the power / start management ECU 10 switches on the first and second relay circuits 15 and 16, corresponding to the first and second lower ECUs 20 and 30, and supplies power to them. Conversely, if the start of the first and second lower ECU 20, 30 is not instructed by the NM message, the power / start management ECU 10 switches off the first and second relay circuit 15, 16 corresponding to the first and second lower ECU 20, 30 and stops the power supply to the first and second lower ECU 20, 30.This allows the quiescent current to be switched off when the operation of each lower ECU 20, 30 is unnecessary, enabling further energy savings for the entire in-vehicle system.

[0041] NM messages can be generated by the Power / Start Management ECU 10 as a function of domain control or area control. In this case, the Power / Start Management ECU 10 determines the functions to be executed in the vehicle. When the execution of a desired function is necessary, the Power / Start Management ECU 10 identifies the cluster that must be activated simultaneously to execute the corresponding function and generates an NM message containing PN request information that identifies the start cluster. The generated NM message is transmitted via communication bus 8 to the first and second normal ECUs 40, 50, and other Power / Start Management ECUs 10. Furthermore, the generated NM message is also used to determine whether it is necessary to switch the lower ECUs 20, 30 of the Power / Start Management ECU 10 itself to a start state.However, the function to determine the functions to be performed in the vehicle and to transmit NM messages containing PN request information can be provided by other ECUs, such as the first and second normal ECU 40, 50, instead of the power / start management ECU 10.

[0042] Furthermore, the energy / start management ECU 10 can enter sleep mode if all ECUs belonging to the vehicle's in-vehicle network system 100 are in sleep or off mode and a predetermined duration has been reached without receiving NM messages.

[0043] The abnormality position determination unit 17 of the power / start management ECU 10 detects the power supply status to the lower ECUs 20, 30 and the communication status with the lower ECUs 20, 30 for the lower ECUs 20, 30 whose relay circuits 15, 16 have been switched on, and determines the abnormality occurrence position based on the detection results. The abnormality position determination unit 17 includes, as shown in Fig. Figure 5 shows a current sensing unit 70 for sensing the power supply status to the lower ECUs 20, 30. The current sensing unit 70 is provided individually for each of the multiple relay circuits 15, 16. The current sensing unit 70 includes a shunt resistor 71, a differential amplifier 72, and an analog-to-digital converter (ADC) 73.

[0044] The shunt resistor 71 is connected upstream and downstream of each relay circuit 15, 16 in the power supply line 6, which branches off from the common power supply line 6 to each lower ECU 20, 30. Alternatively, the shunt resistor 71 can be connected to the power supply line 6 within each relay circuit 15, 16. When the corresponding relay circuit 15, 16 is activated and power is supplied to the lower ECUs 20, 30, a current equal to the power supplied to the lower ECUs 20, 30 flows through the shunt resistor 71. As a result, a potential difference arises across the shunt resistor 71 corresponding to the magnitude of the current flowing through it.

[0045] The differential amplifier 72 amplifies the potential difference across the shunt resistor 71 and outputs it. The A / D converter 73 converts the amplified potential difference from an analog value to a digital value. The digital value represents the amount of current flowing through the power supply line 6 to the lower ECUs 20 and 30. Therefore, the current sensing unit 70 can detect the amount of current flowing through the power supply line 6 to the lower ECUs 20 and 30 as the power supply state when the relay circuits 15 and 16 are switched on and power is supplied to the lower ECUs 20 and 30.

[0046] The abnormality position determination unit 17 compares, as in Fig. Figure 6 shows the detected current quantity with the first threshold for determining a short-circuit fault and the second threshold for determining an open-circuit fault. If the detected current quantity is greater than the first threshold, the abnormality position determination unit 17 can determine that a short-circuit fault has occurred in the power supply line 6 to the lower ECUs 20 and 30. If the detected current quantity is less than the second threshold, the abnormality position determination unit 17 can determine that an open-circuit fault has occurred in the power supply line 6 to the lower ECUs 20 and 30.

[0047] The abnormality position determination unit 17 can determine that the detected current is below the second threshold based on multiple determination results, rather than a single result. This is because it is possible to incorrectly determine the relationship with the second threshold when the detected current is small. In this case, the abnormality position determination unit 17 repeats the comparison between the detected current and the second threshold a predetermined number of times. If the result that the detected current is below the second threshold is obtained in several comparisons, the abnormality position determination unit 17 can determine that an idle fault has occurred in the power supply line 6 to the lower ECUs 20 and 30.To ensure accuracy, multiple comparisons with the detected current quantity can also be performed for the first threshold value. In this case, the abnormality position determination unit 17 repeats the comparison between the detected current quantity and the first threshold value a predetermined number of times. The predetermined number of times for repeating the comparison with the first and second threshold values ​​can be the same or different.

[0048] In addition to or instead of comparing the detected current with the second threshold, the abnormality position determination unit 17 can compare the detected current with the minimum consumption current value during normal operation of the lower ECUs 20, 30 in the start-up state. In this case, if the detected current is less than the minimum consumption current value, the abnormality position determination unit 17 can determine that an abnormality has occurred in the power supply line 6 to the lower ECUs 20, 30 and / or the lower ECUs 20, 30.

[0049] If the comparison results between the measured current and the first threshold, the second threshold, and / or the minimum consumption current indicate that an abnormality has occurred in the power supply line 6 to the lower ECUs 20 and 30, the abnormality position determination unit 17 outputs a control signal to switch off the corresponding relay circuits 15 and 16. As a result, the relay circuits 15 and 16 located in the power supply line 6 where the abnormality occurred are switched from on to off. Consequently, the power supply to the lower ECUs 20 and 30, which are expected to malfunction due to the abnormality, can be shut off.

[0050] Additionally, to detect the communication status with the lower ECUs 20 and 30, the abnormal position detection unit 17 sends messages to the lower ECUs 20 and 30, whose relay circuits 15 and 16 have been activated via the communication interface 11 and the communication bus 8. The abnormal position detection unit 17 then detects the presence or absence of responses from the lower ECUs 20 and 30 to the sent messages. In other words, the abnormal position detection unit 17 detects the presence or absence of responses to the messages sent to the lower ECUs 20 and 30 as the communication status with them. The transmission of messages and the detection of responses are performed individually for each of the lower ECUs 20 and 30.

[0051] If there is a response from the lower ECUs 20 and 30, the abnormality position determination unit 17 can assume the communication state with the lower ECUs 20 and 30 to be normal. Conversely, if there is no response from the lower ECUs 20 and 30, the abnormality position determination unit 17 can assume the communication state with the lower ECUs 20 and 30 to be abnormal. More precisely, if the power supply state to the lower ECUs 20 and 30 is normal, but no response to the messages is received from the lower ECUs 20 and 30, the abnormality position determination unit 17 can determine that an abnormality has occurred in the communication bus 8, the communication interfaces 21 and 31, and / or the lower ECUs 20 and 30.

[0052] If an abnormality occurs in communication bus 8, communication interfaces 21, 31, and / or lower ECUs 20, 30, the abnormality position determination unit 17 can switch off and then on the corresponding relay circuits 15, 16. This allows the corresponding lower ECUs 20, 30 to restart. The restart can return the lower ECUs 20, 30 to a normal state. If the abnormality position determination unit 17 attempts to return from the abnormal state a predetermined number of times but still does not receive a response from the lower ECUs 20, 30 to the messages, it can determine that an abnormality has occurred in communication bus 8, communication interfaces 21, 31, and / or the lower ECUs 20, 30. The abnormality in the communication IFs 21, 31 of the lower ECUs 20, 30 can be considered an abnormality of the lower ECUs 20, 30.

[0053] If an abnormality is determined to have occurred in the communication bus 8, the communication interfaces 21, 31 and / or the lower ECUs 20, 30, the abnormality position determination unit 17 outputs a control signal to switch off the corresponding relay circuits 15, 16. This switches the relay circuits 15, 16 corresponding to the lower ECUs 20, 30 where the abnormality occurred from on to off, thereby cutting off the power supply to the lower ECUs 20, 30, which are expected to malfunction due to the abnormality.

[0054] The abnormality transmission unit 18 of the power / start management ECU 10 generates an abnormality notification message containing the node ID of the affected lower ECUs 20, 30 and / or information indicating the cluster to which the corresponding lower ECUs 20, 30 belong, when the abnormality location determination unit 17 determines the abnormality occurrence location. The abnormality transmission unit 18 sends the generated abnormality notification message to other ECUs in the vehicle's internal network system 100 (e.g., the first and second normal ECUs 40, 50) via the communication interface 11 and the communication bus 8. This allows other ECUs in the vehicle's internal network system 100 to understand the cause of the communication disruption with the lower ECUs 20, 30.

[0055] The abnormality data storage unit 19 of the power / start management ECU 10 stores information indicating the abnormality occurrence location when the abnormality location determination unit 17 determines the abnormality occurrence location. For example, if the abnormality location determination unit 17 determines that an abnormality has occurred in power supply line 6 of the first lower ECU 20, the abnormality data storage unit 19 stores power supply line 6 of the first lower ECU 20 as the abnormality occurrence location. The abnormality occurrence location stored in the abnormality data storage unit 19 can be read by a diagnostic tool connected to the communication bus 8 via a data link coupler, or by a data center 60 acting as a diagnostic tool.This allows maintenance personnel to obtain information about the abnormality occurrence location (corresponding to the location where the abnormality occurred) and to smoothly implement measures to correct the abnormality.

[0056] The power / start management ECU 10 may not have the abnormality data storage unit 19. For example, the abnormality location determination unit 17 may be configured to send information indicating the abnormality occurrence location to an external server, such as a data center 60, each time it determines the abnormality occurrence location. In this case, maintenance personnel can obtain information about the abnormality occurrence location from the data center 60.

[0057] In the vehicle-internal network system 100 according to this embodiment, each ECU belonging to the vehicle-internal network system 100, such as the power / start management ECU 10, the first and second normal ECU 40, 50, can implement a PNC configuration information modification unit 42 to modify the PNC configuration information held by each ECU 10, 40, 50. Fig. Figure 1 shows an example where the PNC configuration information modification unit 42 is implemented in the first normal ECU 40.

[0058] The first standard ECU 40, in which the PNC configuration information modification unit 42 is implemented, includes an external communication device capable of wireless communication with external servers, such as the data center 60. The first standard ECU 40 is configured to download application programs for implementing new functions in the vehicle or update programs for updating the version of programs already implemented in any ECU 10, 20, 30, 40, or 50 via the external communication device. The downloaded programs are made available to the relevant ECUs 10, 20, 30, 40, or 50 via the communication bus 8, and the installation of new application programs or their conversion into update programs is performed.The ECU that communicates with external servers via the external communication device and the ECU that implements the PNC configuration information modification unit 42 can be separate ECUs.

[0059] With regard to ECUs 10, 20, 30, 40, and 50, in which new application programs or update programs are implemented, it may be necessary to add or modify the startup conditions of the relevant ECUs depending on the functions of the application programs or update programs. Therefore, if it is necessary to add or modify the startup conditions of the ECU in which the application program or update program is implemented, Data Center 60 downloads new PNC configuration information corresponding to the addition or modification of startup conditions, along with the application program or update program, to the first standard ECU 40.

[0060] When the PNC Configuration Information Modification Unit 42 obtains new PNC configuration information from the Data Center 60, it modifies (overwrites) the PNC configuration information held by ECUs 10, 20, 30, 40, and 50, in which the application program or update program is implemented, with the new PNC configuration information. This allows ECUs 10, 20, 30, 40, and 50, in which the application program or update program is implemented, to switch from the sleep state (including the powered-off state) to the boot state, according to the cluster specified by the modified PNC configuration information. The overwriting of PNC configuration information can be performed by the relevant ECU upon receiving a rewrite instruction along with the new PNC configuration information from the PNC Configuration Information Modification Unit 42.Alternatively, overwriting PNC configuration information can be performed by the PNC configuration information modification unit 42 by accessing the memory of the relevant ECU.

[0061] The PNC configuration information modification unit 42 can be located outside the vehicle's internal network system 100, such as in a data center 60, instead of being part of an ECU belonging to the vehicle's internal network system 100. However, if the PNC configuration information modification unit 42 is implemented in an ECU belonging to the vehicle's internal network system 100, communication with external entities can be terminated once the data for modifying the ECU's PNC configuration information has been obtained from the outside. On the other hand, if the PNC configuration information modification unit 42 is located on an external server outside the vehicle's internal network system 100, the ECU requiring PNC configuration information modification must communicate individually with the external server via an ECU equipped with an external communication device.This can lead to the disadvantage of increased communication volume with external servers.

[0062] An example of the processing performed by the power / start management ECU 10 is given with reference to the flowcharts in Fig. 7 to Fig. 9 described. The processing performed by the power / start management ECU 10 includes processing to subject the first and second lower ECUs 20, 30 to partial networking according to NM messages. Additionally, the processing performed by the power / start management ECU 10 includes determining the abnormal occurrence position based on the power supply state to the first and second lower ECUs 20, 30 and the communication state with the lower ECUs 20, 30, and addressing the abnormal occurrence position, if any. The execution of the processing, as described in the flowcharts of Fig. 7 to Fig. Figure 9 shows that the energy / start management ECU 10 corresponds to an execution of the control procedure of the vehicle's internal network system 100 disclosed herein.

[0063] In step S100, the power / start management ECU 10 receives an NM message. In step S110, the power / start management ECU 10 performs a start ECU identification process to identify the lower ECUs 20 and 30 that were instructed to activate by the NM message. The details of this start ECU identification process are shown in the flowchart of Fig. Figure 8 shows the process. The following describes the start-up ECU identification process with reference to the flowchart in [reference missing]. Fig. 8 described.

[0064] In step S300, the power / start management ECU 10 identifies the cluster that was requested to start based on the PN request information in the NM message. In step S310, the power / start management ECU 10 reads the PNC configuration information of the several lower ECUs 20 and 30 from the data storage unit 14. Then, in step S320, the power / start management ECU 10 identifies the PNC configuration information containing the cluster that matches the cluster (start request cluster) for which a start is requested by the PN request information.

[0065] In step S330, the power / start management ECU 10 determines whether at least one PNC configuration piece has been identified among the PNC configuration pieces of the several lower ECUs 20 and 30 that contain a cluster matching the start request cluster. If at least one PNC configuration piece is identified, the power / start management ECU 10 proceeds to processing step S340. Conversely, if no PNC configuration pieces are identified, the power / start management ECU 10 proceeds to processing step S350.

[0066] In step S340, the power / start management ECU 10 sets the lower ECUs 20 and 30, which correspond to the identified PNC configuration information, as start ECUs and sets the other lower ECUs 20 and 30 as non-start ECUs. In step S350, the power / start management ECU 10 sets all lower ECUs 20 and 30 as non-start ECUs. Afterward, the power / start management ECU 10 returns to processing as shown in the flowchart of Fig. 7 is shown.

[0067] In step S120 of the flowchart in Fig. Step 7 determines whether the power / start management ECU 10 has lower ECUs 20 and 30 set as start ECUs. If lower ECUs 20 and 30 are set as start ECUs, the power / start management ECU 10 proceeds to process step S130. Conversely, if there are no lower ECUs 20 and 30 set as start ECUs, the power / start management ECU 10 terminates the processing shown in the flowchart. Fig. 7 is shown. In this case, the NM message is discarded.

[0068] In step S130, the power / start management ECU 10 activates relay circuits 15 and 16 connected to lower ECUs 20 and 30, which are set as start ECUs, based on the relay connection information stored in data storage unit 14. This information specifies the correspondence between each relay circuit 15 and 16 and each lower ECU 20 and 30. Additionally, the power / start management ECU 10 deactivates relay circuits 15 and 16 connected to lower ECUs 20 and 30, which are set as non-start ECUs.

[0069] As in step S200 of the flowchart in Fig. As shown in Figure 7, the power supply for the lower ECUs 20 and 30, whose relay circuits 15 and 16 have been switched on, is started. Consequently, in step S210, the lower ECUs 20 and 30, whose relay circuits 15 and 16 have been switched on, undergo a predetermined starting process and enter the starting state.

[0070] In step S140, the power / start management ECU 10 performs an abnormality position determination process to determine the abnormality occurrence position based on the power supply status to the lower ECUs 20 and 30, whose relay circuits 15 and 16 have been activated, and the communication status with the lower ECUs 20 and 30. The details of this abnormality position determination process are shown in the flowchart of Fig. Figure 9 shows the initial ECU identification process. The following section describes the process with reference to the flowchart in Figure 9. Fig. 9 described.

[0071] In step S400, the power / start management ECU 10 detects the amount of current flowing through the power supply line 6 to the lower ECUs 20, 30, whose relay circuit 15, 16 has been switched on, as the power supply state to the lower ECUs 20, 30.

[0072] In step S410, the power / start management ECU 10 determines whether the detected current is greater than the first threshold to identify a short-circuit fault. If it is determined that the detected current is greater than the first threshold, the power / start management ECU 10 proceeds to process step S420. In step S420, the power / start management ECU 10 determines that an abnormality has occurred in the power supply line 6 to the lower ECUs 20 and 30, whose relay circuit 15 and 16 was activated, as the abnormality occurrence position. Conversely, if it is determined that the detected current is less than or equal to the first threshold, the power / start management ECU 10 proceeds to process step S430.

[0073] In step S430, the power / start management ECU 10 determines whether the detected current is less than the second threshold for determining an idle fault. If it is determined that the detected current is less than the second threshold, the power / start management ECU 10 proceeds to processing step S440. Conversely, if it is determined that the detected current is equal to or greater than the second threshold, the power / start management ECU 10 proceeds to processing step S460.

[0074] In step S440, the power / start management ECU 10 repeats the comparison between the detected current and the second threshold a predetermined number of times. In step S450, if the result that the detected current is less than the second threshold is obtained after the predetermined number of comparisons, the power / start management ECU 10 proceeds to process step S420. In step S420, the power / start management ECU 10 determines that an abnormality has occurred in the power supply line 6 to the lower ECUs 20 and 30, whose relay circuit 15 and 16 has been activated. Conversely, if the result that the detected current is less than the second threshold is not obtained after the predetermined number of comparisons, the power / start management ECU 10 proceeds to process step S460.

[0075] In step S460, the power / start management ECU 10 sends a message to the lower ECUs 20 and 30, whose relay circuits 15 and 16 have been activated, to determine the communication status with the lower ECUs 20 and 30. In step S470, the power / start management ECU 10 determines whether a response to the sent message is received from the lower ECUs 20 and 30. If a response is received, the power / start management ECU 10 proceeds to processing step S510. Conversely, if no response is received, the power / start management ECU 10 proceeds to processing step S480.

[0076] In step S480, the power / start management ECU 10 executes a recovery from abnormality process by switching off relay circuits 15 and 16, corresponding to lower ECUs 20 and 30, from which no response is detected, up to a predetermined number of times. It then switches relay circuits 15 and 16 on to restart the lower ECUs 20 and 30. In step S490, the power / start management ECU 10 determines whether a response to the message from the restarted lower ECUs 20 and 30 is detected a predetermined number of times during the recovery from abnormality process; in other words, whether the lower ECUs 20 and 30 have normalized. If it is determined that the lower ECUs 20 and 30 have not normalized, the power / start management ECU 10 proceeds to processing step S500.Conversely, if it is determined that the lower ECUs 20, 30 have been normalized, the power / start management ECU 10 proceeds to process step S510.

[0077] In step S500, the power / start management ECU 10 determines that an abnormality has occurred in communication bus 8 and / or lower ECUs 20 and 30 if no response to the message is detected as the abnormality occurrence position. In step S510, the power / start management ECU 10 determines that no abnormality has occurred in power supply line 6 and communication bus 8 to lower ECUs 20 and 30.

[0078] In step S150 of the flowchart in Fig. 7. The Power / Start Management ECU 10 determines whether the abnormality occurrence position has been identified in the abnormality location determination process of step S140. If it is determined that the abnormality occurrence position has been identified, the Power / Start Management ECU 10 proceeds to processing step S160. Conversely, if it is determined that no abnormality occurrence position has been identified, the Power / Start Management ECU 10 terminates the processing described in the flowchart of Fig. 7 is shown.

[0079] In step S160, relay circuits 15 and 16, corresponding to the abnormality occurrence position, are switched off. This allows the power supply to the lower ECUs 20 and 30, which are expected to malfunction and for which an abnormality has occurred in the power supply line 6, the communication bus 8, and / or the lower ECUs 20 and 30, to be shut off.

[0080] In step S170, the power / start management ECU 10 generates an abnormality notification message containing information that specifies the node ID of the lower ECUs 20 and 30 corresponding to the abnormality occurrence location and / or the cluster to which these lower ECUs belong. The power / start management ECU 10 then transmits the generated abnormality notification message to other ECUs in the vehicle's internal network system 100. This allows other ECUs in the vehicle's internal network system 100 to understand the cause of the communication disruption with the lower ECUs 20 and 30.

[0081] In step S180, the power / start management ECU 10 stores information indicating the abnormality occurrence position. The stored abnormality occurrence position can be read by a diagnostic tool connected to communication bus 8 via a data link coupler, or by a data center 60 acting as a diagnostic tool.

[0082] As described above, according to the vehicle's internal network system 100 of this embodiment, the power / start management ECU 10 receives NM messages that selectively instruct the start of several lower ECUs 20, 30, transmitted via the communication bus 8, on behalf of the several lower ECUs 20, 30. The power / start management ECU 10 then switches on the relay circuits 15, 16 connected to the lower ECUs 20, 30 instructed to activate by the NM messages. This allows the lower ECUs 20, 30 instructed to activate to enter the start state.Therefore, according to the vehicle-internal network system 100 of this embodiment, it is possible to manage the supply and stopping of energy to the lower ECUs 20, 30 in detail, while the system is configured to switch the energy to the lower ECUs 20, 30 from a stopped state to a supply state in response to NM messages instructing the start.

[0083] Furthermore, according to the vehicle's internal network system 100 of this embodiment, the power supply status to the lower ECUs 20, 30, whose relay circuits 15, 16 have been switched on, and the communication status with the lower ECUs 20, 30 are detected, and the location of the abnormality is determined based on the detection results. Therefore, according to the vehicle's internal network system 100 of this embodiment, it is possible to suppress the deterioration in maintenance efficiency when an abnormality occurs, since it is possible to determine the location of the abnormality, thus facilitating the rectification of the abnormality. (Modifications)

[0084] Although the preferred embodiment of the present disclosure has been described above, the present disclosure is not limited to the embodiment mentioned above and can be modified and implemented in various ways without departing from the spirit of the present disclosure.

[0085] For example, in the embodiment described above, an example is provided in which the power supply state to the lower ECUs 20, 30, whose relay circuits 15, 16 are switched on, and the communication state with the lower ECUs 20, 30 are detected, and the abnormality occurrence position is determined based on the detection results. Additionally, it is also possible to detect the power supply state to the lower ECUs 20, 30, whose relay circuits 15, 16 are switched off, and the communication state with the lower ECUs 20, 30, and to determine the abnormality occurrence position based on the detection results. This enables the detection of abnormalities where a short-circuit fault occurs in the relay circuits 15, 16, leading to an unintended power supply to the lower ECUs 20, 30.

[0086] Additionally, the flowchart of Fig.Figure 9 describes an example where the communication status with the lower ECUs 20 and 30 is detected when the lower ECUs 20 and 30 are normally supplied with power. However, the communication status with the lower ECUs 20 and 30 can be detected regardless of whether the lower ECUs 20 and 30 are normally supplied with power.

[0087] The systems and methods described in this disclosure can be implemented by a dedicated computer configured with a processor programmed to perform one or more functions embodied in a computer program. The systems and methods described in this disclosure can also be implemented using dedicated hardware logic circuits. Furthermore, the systems and methods described in this disclosure can be implemented by one or more dedicated computers configured with a combination of a processor executing a computer program and one or more hardware logic circuits. For example, some or all of the functions provided by the Power / Start Management ECU 10 can be implemented as hardware. The implementation of certain functions as hardware may involve the use of one or more integrated circuits.Some or all of the functions provided by the Power / Boot Management ECU 10 can be implemented using a system-on-a-chip (SoC), an integrated circuit (IC), or a field-programmable gate array (FPGA). The concept of ICs includes application-specific integrated circuits (ASICs). Additionally, the computer program can be stored as instructions executable by a computer on a non-volatile physical storage medium. Possible recording media for the program include HDDs (hard disk drives), SSDs (solid-state drives), flash memory, and the like. Furthermore, a program to cause a computer to function as the Power / Boot Management ECU 10, and non-volatile physical storage media such as semiconductor memory to record this program, are also within the scope of this disclosure. QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] JP 7238650B [0002, 0003]

Claims

[1] In-vehicle network system (100), comprising: a large number of control devices (10, 20, 30, 40, 50) connected to a communication bus (8) and configured to communicate with each other in a vehicle, where: the plurality of control devices includes at least one upper control device (10) and a plurality of lower control devices (20, 30); which includes at least one upper control device a power management unit (13) configured to switch on and off a plurality of relay circuits (15, 16) provided in a power supply line (6) of each of the plurality of lower control devices, and a start management unit (12) configured to receive a network management message on behalf of a plurality of lower control devices, the network management message being transmitted over the communication bus and selectively instructing a start of the plurality of lower control devices to instruct the power management unit to turn on the relay circuit provided in the power supply line of the lower control device for which a start is instructed by the network management message, and to place the lower control device for which the start is instructed into a start state; and an abnormality position determination unit (17) configured to detect a power supply state to the lower control devices and a communication state with the lower control devices and to determine an abnormality occurrence position based on a detection result. [2] In-vehicle network system according to claim 1, wherein the abnormality position determination unit for the lower control device for which the relay circuit has been switched on detects the power supply state to the lower control device and the communication state with the lower control device and determines the abnormality occurrence position based on the detection result. [3] In-vehicle network system according to claim 1 or 2, wherein The network management message contains start cluster information that specifies a start cluster, indicating a group of control devices to be started. which includes at least one upper control device and further includes a data storage unit (14) configured to store cluster configuration information specifying a cluster to which the lower control devices belong, for each of the plurality of lower control devices, and The boot management unit determines that the booting of the lower control devices corresponding to the cluster configuration information is instructed by the network management message if the boot cluster specified by the boot cluster information in the network management message matches the cluster in the cluster configuration information stored in the data storage unit. [4] In-vehicle network system according to claim 3, further comprising a modification unit (42) configured to modify the cluster configuration information of each of the plurality of lower control devices stored by the at least one upper control device. [5] In-vehicle network system according to claim 4, wherein the modification unit is implemented in any of the plurality of control devices connected to the communication bus. [6] In-vehicle network system according to one of claims 3 to 5, wherein the at least one upper control device includes a data storage unit (14) which stores the cluster configuration information of each of the plurality of lower control devices and relay connection information which specifies a correspondence between the plurality of lower control devices and the plurality of relay circuits. [7] In-vehicle network system according to claim 6, wherein the at least one upper control device, based on the cluster configuration information and the relay connection information, switches on the relay circuit corresponding to the lower control device whose cluster of the cluster configuration information matches the start cluster specified by the start cluster information included in the network management message, and switches off the relay circuit corresponding to the lower control device whose cluster does not match. [8] In-vehicle network system according to any one of claims 1 to 7, wherein the abnormality position determination unit detects a current flowing through the power supply line of the lower control device as the power supply state to the lower control device. [9] In-vehicle network system according to claim 8, wherein the abnormality position determination unit determines that an abnormality has occurred in the power supply line of the lower control device when the detected current is greater than a first threshold to determine a short-circuit fault, or when the detected current is less than a second threshold to determine an open-circuit fault. [10] In-vehicle network system according to claim 8 or claim 9, wherein The abnormality position determination unit repeatedly compares the detected current quantity with a first threshold or a second threshold a predetermined number of times if the detected current quantity is greater than the first threshold or if the detected current quantity is less than the second threshold, and The abnormality position determination unit determines that the abnormality has occurred in the power supply line of the lower control device when, in the results of a multitude of comparisons, it is determined that the current quantity is greater than the first threshold or less than the second threshold. [11] In-vehicle network system according to one of claims 8 to 10, wherein the abnormality position determination unit determines that an abnormality has occurred in the power supply line of the lower control device and / or the lower control device when the detected current quantity is less than a minimum consumption current during normal operation of the lower control device which is in a start state. [12] In-vehicle network system according to one of claims 9 to 11, wherein the abnormality position determination unit switches the relay circuit from on to off in response to a determination that the abnormality has occurred in the power supply line of the lower control device. [13] In-vehicle network system according to one of claims 1 to 12, wherein the abnormality position determination unit transmits a message to the lower control device via the communication bus as the communication state with the lower control device and detects the presence or absence of a response to the message. [14] In-vehicle network system according to claim 13, wherein the abnormality position determination unit determines that an abnormality has occurred in the communication bus with the lower control device and / or in the lower control device when the response to the message is not received from the lower control device, even though the power supply state to the lower control device is normal. [15] In-vehicle network system according to claim 13, wherein the abnormality position determination unit attempts to return from an abnormality by switching off the relay circuit and then switching on the relay circuit upon determining that the abnormality has occurred in the communication bus with the lower control device or in the lower control device, and determines that the abnormality has occurred in the communication bus with the lower control device and / or in the lower control device if the response to the message is not received after a predetermined number of return attempts. [16] In-vehicle network system according to claim 14 or 15, wherein the abnormality position determination unit switches off the relay circuit in response to a determination that the abnormality has occurred in the communication bus with the lower control device and / or in the lower control device. [17] In-vehicle network system according to any one of claims 1 to 16, wherein the at least one upper control device further comprises an abnormality transmission unit (18) configured to generate and send to another control device an abnormality notification message containing information specifying an identifier of the lower control device corresponding to the abnormality occurrence position and / or a cluster to which the corresponding lower control device belongs, when the abnormality position determination unit determines the position of the abnormality. [18] In-vehicle network system according to any one of claims 1 to 17, wherein the at least one upper control device further includes an abnormality data storage unit (19) configured to store information indicating an abnormality occurrence position when the abnormality position determination unit determines the abnormality occurrence position. [19] Method for controlling an in-vehicle network system (100) comprising a plurality of control devices (10, 20, 30, 40, 50) connected to a communication bus (8) and configured to communicate with each other in a vehicle, wherein the plurality of control devices includes at least one upper control device (10) and a plurality of lower control devices (20, 30), the upper control device comprising a power management unit (13) configured to switch on and off a plurality of relay circuits (15, 16) provided in a power supply line (6) of each of the plurality of lower control devices, the method comprising: by at least one upper control device, Receiving, on behalf of the plurality of lower control devices, a network management message transmitted over the communication bus that selectively directs a start of the plurality of lower control devices; Switching on the relay circuit provided in the power supply line of the lower control device, for which the start is instructed by the network management message; Setting the lower control device, for which the start is instructed, into a start state; Detecting the power supply status to the lower control devices and the communication status with the lower control devices; and Determining an abnormality occurrence position based on a data collection result.

Citation Information

Patent Citations

  • Communication system

    US20130326255A1

  • Communication system

    US20210258186A1