Redundant system ECU, program, and information processing method
Patent Information
- Application Number
- JP2023067873
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-04-18
- Publication Date
- 2025-09-11
AI Technical Summary
Existing in-vehicle ECUs do not address the process of replacing a malfunctioning ECU, leading to potential system failures.
A redundant ECU system that communicates with multiple ECUs, acquires state data, determines malfunctions, and replaces malfunctioning ECUs by executing compatible software, ensuring continuous functionality.
Efficiently replaces malfunctioning ECUs, maintaining vehicle functions without duplicating hardware connections, reducing signal line requirements, and ensuring seamless operation.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a redundant ECU, a program, and an information processing method. [Background technology]
[0002] A vehicle is equipped with a body ECU, which is an on-board ECU that controls body-related devices such as a wiper drive device, interior and exterior lighting devices, door lock devices, power windows, etc. (For example, Patent Document 1). The wiper drive device of Patent Document 1 includes an on-board ECU (body ECU) and is driven by a control program applied to the on-board ECU (electronic control unit). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2017-224926 A Summary of the Invention [Problem to be solved by the invention]
[0004] However, the on-board ECU installed in the vehicle of Patent Document 1 does not take into consideration the processing required to replace another on-board ECU when the other on-board ECU fails or ceases to operate normally.
[0005] The present disclosure aims to provide a redundant ECU etc. that can efficiently perform processing related to replacing an on-board ECU mounted in a vehicle when the on-board ECU stops operating normally. [Means for solving the problem]
[0006] A redundant ECU according to one embodiment of the present disclosure is a redundant ECU that is mounted on a vehicle and communicatively connected to a plurality of on-board ECUs, and is equipped with a control unit that performs processing related to status management of the on-board ECU, and the control unit acquires status data related to the status of the on-board ECU from the on-board ECU, and if it determines that the on-board ECU is not operating normally based on the acquired status data, it acquires software for replacing the on-board ECU that has been determined to be not operating normally, and replaces the on-board ECU that has been determined to be not operating normally by executing the acquired software. Effect of the Invention
[0007] According to one aspect of the present disclosure, it is possible to provide a redundant ECU or the like that efficiently performs processing related to replacing an in-vehicle ECU mounted on a vehicle when the in-vehicle ECU stops operating normally. [Brief description of the drawings]
[0008] [Figure 1] 1 is a schematic diagram illustrating a system configuration of an in-vehicle system according to a first embodiment. [Diagram 2] FIG. 2 is a block diagram illustrating an example of an internal configuration of a redundant ECU. [Diagram 3] FIG. 11 is an explanatory diagram illustrating an example of a management list. [Figure 4] 10 is an explanatory diagram illustrating a relay table used by the integrated ECU; [Diagram 5] FIG. 2 is an explanatory diagram illustrating a process flow (sequence) of a redundant ECU, an integrated ECU, and the like. [Figure 6] 4 is a flowchart illustrating a process of a control unit of a redundant ECU. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] [Description of the embodiment of the present invention] First, embodiments of the present disclosure will be listed and described. In addition, at least some of the embodiments described below may be arbitrarily combined.
[0010] (1) A redundant ECU according to one embodiment of the present disclosure is a redundant ECU that is mounted on a vehicle and communicatively connected to a plurality of on-board ECUs, and includes a control unit that performs processing related to status management of the on-board ECU. The control unit acquires status data related to the status of the on-board ECU from the on-board ECU, and if it determines that the on-board ECU is not operating normally based on the acquired status data, it acquires software for replacing the on-board ECU that has been determined to be not operating normally, and replaces the on-board ECU that has been determined to be not operating normally by executing the acquired software.
[0011] In this embodiment, the redundant ECU is communicably connected to a plurality of on-board ECUs via an on-board network mounted on the vehicle. The plurality of on-board ECUs perform processing for executing various services or functions provided in the vehicle. The on-board ECU may include not only an on-board ECU mounted at the time of production of the vehicle, but also an on-board ECU (backup ECU) mounted (retrofitted) after production of the vehicle. The spare ECU may acquire a message output from an on-board ECU (sensor-actuator control ECU) to which a sensor or actuator is directly connected via a signal line or the like, and perform processing for executing various services or functions using the acquired message. The redundant ECU may be configured by a spare ECU retrofitted to the vehicle in order to add a new service or function. In other words, each of the plurality of spare ECUs retrofitted may function as a redundant ECU substituting for the other spare ECUs, thereby constituting a group of redundant ECUs. The control unit of the redundant ECU may aggregate information (status information) on the status of the vehicle ECUs including these spare ECUs and the sensor / actuator control ECU, i.e., information on whether the vehicle ECUs are in an operating state (wake-up state) or a stopped state (sleep state), and perform processing related to the current status management of the vehicle ECUs. The status information of the vehicle ECUs may include management information on the functions (services) performed by each vehicle ECU and whether the vehicle ECUs are operating normally (normal or abnormal). Furthermore, the control unit of the redundant ECU periodically, periodically, or constantly performs polling communication with these vehicle ECUs to acquire status data on the status of the vehicle ECUs. The control unit of the redundant ECU may determine that the vehicle ECU is not operating normally, for example, when the status data cannot be acquired beyond the transmission cycle, when the acquired status data includes an abnormality code indicating an abnormality in the vehicle ECU that is the transmission source, or when the acquired status data is determined to be fraudulent data due to, for example, spoofing. Cases where the in-vehicle ECU is not operating normally include cases where the in-vehicle ECU is broken down or where the in-vehicle ECU has been removed from the vehicle, for example.The control unit of the redundant ECU acquires software for substituting for the vehicle ECU determined not to be operating normally. The redundant ECU is, for example, an in-vehicle ECU of the same model as the vehicle ECU determined not to be operating normally, or an in-vehicle ECU compatible with the vehicle ECU determined not to be operating normally, and by acquiring the software, the redundant ECU can substitute for the vehicle ECU determined not to be operating normally. That is, the redundant ECU can provide various services or functions that the vehicle ECU determined not to be operating normally performs by executing software that is the same as or compatible with the software executed by the vehicle ECU determined not to be operating normally. As a result, the redundant ECU starts a process (substitution process) to substitute for the vehicle ECU determined not to be operating normally, and therefore the service or function performed by the vehicle ECU can be continued. In addition, by substituting the vehicle ECU that transmits and receives to the sensor / actuator control ECU to which the sensor or the like is connected without performing duplication for the vehicle ECU (sensor / actuator control ECU), the number of signal lines such as harnesses required for connecting the sensor or the like can be reduced.
[0012] (2) In one embodiment of the redundant ECU of the present disclosure, the status data acquired from the on-board ECU includes setting information regarding the operational settings of the on-board ECU at the time the status data was transmitted, and when executing the acquired software, the control unit applies the setting information to replace an on-board ECU that is determined to be not operating normally.
[0013] In this embodiment, the status data output (transmitted) by the vehicle-mounted ECU to the redundant ECU periodically, regularly, or steadily includes setting information related to the operation settings of the vehicle-mounted ECU at the time of transmitting the status data. The vehicle-mounted ECU provides a service or function by executing software, and the setting information corresponds to, for example, various setting information for providing the service or function. The setting information may include, for example, user information related to the driver driving the vehicle, and may further include setting information (setting information for each driver) associated with each piece of user information. Furthermore, the setting information may include history information such as the operation contents performed by the driver (current user) currently driving the vehicle when using a service, etc. The control unit of the redundant ECU acquires setting information related to the operation settings of the vehicle-mounted ECU at the time of transmitting the status data from the vehicle-mounted ECU, in addition to software required to replace the vehicle-mounted ECU. By acquiring software and setting information, the control unit of the redundant ECU can execute the software by reflecting (applying) the setting information, and can inherit the operational settings of the on-board ECU to be replaced, thereby continuing to provide services or functions.
[0014] (3) In one embodiment of the redundant ECU of the present disclosure, the control unit uses the acquired software and setting information to perform a self-diagnosis process to confirm the operation of the alternative function when replacing an in-vehicle ECU that is determined to be malfunctioning.
[0015] In this aspect, the control unit of the redundant ECU performs a self-diagnosis process to confirm whether the software operates normally in a state in which the setting information is applied, when starting a process to replace an in-vehicle ECU determined not to operate normally, using the acquired software and setting information. The control unit of the redundant ECU may, for example, execute emulation software stored in the storage unit to generate an emulation environment for performing the self-diagnosis process, and determine whether the software to which the setting information is applied operates in the emulation environment. Alternatively, the control unit of the redundant ECU may, for example, input (transfer) the acquired software and setting information to a self-diagnosis program stored in the storage unit, execute the self-diagnosis program, and obtain a determination result by the self-diagnosis program to confirm whether the software operates normally. When the control unit of the redundant ECU obtains (derives) a determination result indicating normal operation as a result of the self-diagnosis process, it starts a process to replace an in-vehicle ECU determined not to operate normally. When the control unit of the redundant ECU does not obtain (derive) a result of the self-diagnosis process indicating that the ECU operates normally, the control unit may execute the software in an initialized state or with a predetermined standard setting (initial parameters) without using the obtained setting information. As a pre-processing before starting to substitute for an in-vehicle ECU determined not to operate normally, the self-diagnosis process is performed using the obtained software and setting information, so that the substitute can be started after verifying the normal operation of the software and setting information. Furthermore, when the self-diagnosis process does not obtain (derive) a result of the determination that the ECU operates normally, that is, when a result of the determination that the ECU operates incorrectly, it is assumed that there is a possibility that there is a problem with the setting information last obtained (received) from the in-vehicle ECU determined not to operate normally. Even in such a case, the software can be executed in an initialized state or with a predetermined standard setting (initial parameters), so that the software can be executed with the standard setting or the like to substitute for the in-vehicle ECU determined not to operate normally.
[0016] (4) In one embodiment of the redundant ECU of the present disclosure, a management list for identifying replaceable in-vehicle ECUs among multiple in-vehicle ECUs installed in the vehicle is stored in a memory area accessible to the control unit, and the control unit identifies the replaceable in-vehicle ECU by referring to the management list.
[0017] In this embodiment, a management list for identifying a replaceable in-vehicle ECU among a plurality of in-vehicle ECUs mounted on a vehicle is stored in a storage area accessible by a control unit of the redundant ECU, such as a storage unit of the redundant ECU. The management list includes information on the in-vehicle ECU that can be replaced by the redundant ECU, i.e., the functions (services) performed by the in-vehicle ECU. The management list may be defined by associating the ECU names (ECU-IDs) of the plurality of in-vehicle ECUs mounted on a vehicle with the names of the functions (services) performed by each of the in-vehicle ECUs. The storage unit of the redundant ECU stores the names of one or more functions (services) replaceable by the control unit of the redundant ECU, and the control unit of the redundant ECU may identify the replaceable in-vehicle ECU based on the identity or compatibility of the functions (services) by comparing the names of the functions (services) performed by each of the in-vehicle ECUs included in the management list with the names of the functions (services) replaceable by the redundant ECU (itself). By using the management list in this manner, it is possible to identify an in-vehicle ECU that performs the same or equivalent function (service) as the function (service) that the redundant ECU (itself) can replace, and if it is determined that the in-vehicle ECU in question is not operating normally, it can be smoothly substituted.
[0018] (5) In one embodiment of the redundant ECU of the present disclosure, the control unit requests the multiple on-board ECUs to transmit information regarding the services performed by the on-board ECUs, and generates or updates the management list based on the information regarding the services received from each of the multiple on-board ECUs.
[0019] In this embodiment, for example, when the redundant ECU (itself) is connected to the in-vehicle network or when the IG switch of the vehicle is turned off, the control unit of the redundant ECU requests all in-vehicle ECUs connected to the in-vehicle network to transmit information related to the services performed by the in-vehicle ECUs. Alternatively, when the control unit of the redundant ECU detects that the spare ECU or the sensor / actuator control ECU is connected to the in-vehicle network, the control unit of the redundant ECU may request the spare ECU, etc. to transmit information related to the services. Alternatively, when the control unit of the redundant ECU detects that a program update (reprogramming) has been performed on the in-vehicle ECU, the control unit of the redundant ECU may request the spare ECU, etc. to transmit information related to the services. The control unit of the redundant ECU acquires (receives) information transmitted by the in-vehicle ECU in response to the request (the name of the service or function performed by the in-vehicle ECU), and generates a management list based on each of the received information. Even after generating the management list, the control unit of the redundant system ECU may periodically, regularly, or constantly request transmission of information related to services from each of the vehicle-mounted ECUs, and may receive the information from each of the vehicle-mounted ECUs. In this case, the control unit of the redundant system ECU updates the management list based on subsequently received information (the name of the service or function performed by the vehicle-mounted ECU). When the control unit of the redundant system ECU detects that an in-vehicle ECU such as a spare ECU or a sensor / actuator control ECU has been disconnected (removed) from the in-vehicle network, the control unit of the redundant system ECU may delete the removed in-vehicle ECU from the management list. In this way, the control unit of the redundant system ECU requests transmission of information related to the services performed by the in-vehicle ECUs from the multiple in-vehicle ECUs connected to the in-vehicle network at a predetermined timing, such as when the spare ECU is connected to the in-vehicle network or when the IG switch is turned off and the vehicle transitions to a stopped state, or periodically. The control unit of the redundant ECU generates or updates the management list based on the information sent (returned) from the vehicle ECU (the name of the service or function performed by the vehicle ECU), thereby enabling the management list to be constantly kept up to date.By using this management list maintained up to date, the control unit of the redundant ECU can efficiently identify an on-board ECU that the redundant ECU (itself) can replace, i.e., identify the on-board ECU in advance before it fails (is determined to be not operating normally).
[0020] (6) In one embodiment of the redundant ECU of the present disclosure, the vehicle is equipped with an on-board device having a communication function with the outside of the vehicle, and the control unit obtains software via the on-board device to replace an on-board ECU that is determined to be malfunctioning.
[0021] In this embodiment, the vehicle is equipped with an on-board device having a communication function with the outside of the vehicle, and the on-board device is an integrated ECU that is configured with a central control device such as a vehicle computer and performs overall control of the vehicle C. The integrated ECU (on-board device) is communicatively connected to an external server, such as an OTA (Over The Air) server located outside the vehicle, via an external communication device having a wireless function. The control unit of the redundant system ECU can obtain the latest version of software from an external server such as an OTA (Over The Air) server via the integrated ECU (on-board device) to obtain software for replacing an on-board ECU determined to be not operating normally. By obtaining (downloading) software from the external server via the integrated ECU (on-board device) in this way, the redundant system ECU does not need to hold (store) the software of the on-board ECU in advance when replacing any of the on-board ECUs, and the storage area of the redundant system ECU can be prevented from becoming tight.
[0022] (7) In one embodiment of the redundant ECU of the present disclosure, the in-vehicle device has a relay function when the multiple in-vehicle ECUs communicate with each other, and the control unit sends a preparation completion notification to the in-vehicle device indicating that preparations for replacing an in-vehicle ECU determined to be abnormal are complete, and by sending the preparation completion notification to the in-vehicle device, causes the in-vehicle device to change the relay table used when performing the relay function.
[0023] In this embodiment, the integrated ECU (vehicle-mounted device) has a plurality of in-vehicle communication units, and relays communication data transmitted and received by the vehicle-mounted ECUs connected to the plurality of in-vehicle communication units. That is, the integrated ECU (vehicle-mounted device) has a relay function when the vehicle-mounted ECUs communicate with each other, and functions as, for example, an Ether switch or a CAN gateway. A relay table used (referenced) for relaying is stored in a storage unit of the integrated ECU (vehicle-mounted device). When the control unit of the redundant ECU completes preparations to replace the vehicle-mounted ECU determined not to be operating normally, the control unit transmits a preparation completion notice (function handover completion) indicating the completion of the preparations to the integrated ECU (vehicle-mounted device). The preparation completion notice (function handover completion) includes, for example, an ECU name (ECU-ID) that identifies the vehicle-mounted ECU to be replaced (the vehicle-mounted ECU determined not to be operating normally) and an ECU name (ECU-ID) of the redundant ECU that replaces the vehicle-mounted ECU to be replaced. The integrated ECU (vehicle-mounted device) receives a preparation completion notification (function takeover completion) transmitted from the redundant ECU, and changes (updates) the relay table in response to the received preparation completion notification (function takeover completion). When the preparation for substitution by the redundant ECU is completed in this way and substitution for the in-vehicle ECU to be substituted (the in-vehicle ECU determined not to be operating normally) is started, the relay table of the redundant ECU having a relay function is changed (updated) to transmit (relay) communication data to the redundant ECU, which is the destination of the in-vehicle ECU to be substituted. That is, by changing the destination of communication data that is originally the destination of the in-vehicle ECU to be substituted (the in-vehicle ECU determined not to be operating normally) to the redundant ECU, the redundant ECU can receive communication data necessary for executing substitution processing. The control unit of the redundant ECU transmits a preparation completion notification (function takeover completion) to the integrated ECU (vehicle-mounted device) as a trigger for executing processing to change (update) the relay table, and therefore the timing of the change of the relay table by the integrated ECU (vehicle-mounted device) can be controlled.This makes it possible to ensure that the change of the relay table by the ECU (on-board device) is executed after preparations (such as software installation) for substitution by the redundant ECU are completed.
[0024] (8) In one embodiment of the redundant ECU of the present disclosure, the control unit sends a request notification to the in-vehicle device indicating a request to acquire software to replace an in-vehicle ECU that has been determined to be abnormally operating, and by sending the request notification to the in-vehicle device, causes the in-vehicle device to accumulate communication data to the in-vehicle ECU to be replaced that has been received between the request notification and the preparation completion notification, and to transmit the communication data to the redundant ECU after receiving the preparation completion notification.
[0025] In this embodiment, the control unit of the redundant ECU transmits a request notification to the integrated ECU (on-board device) indicating a request to acquire software to replace the on-board ECU determined not to be operating normally. The request notification corresponds to, for example, a failure notification regarding the on-board ECU determined not to be operating normally, and is a notification requesting acquisition of an ECU name (ECU-ID) that uniquely identifies the on-board ECU and software to replace the on-board ECU. Therefore, the request notification may include the ECU name (ECU-ID) of the on-board ECU determined not to be operating normally and the name of the software (the software executed by the on-board ECU) to replace the on-board ECU. In response to the request notification from the redundant ECU, the integrated ECU (on-board device) acquires (downloads) the software to be replaced from an external server, such as an OTA (Over The Air) server located outside the vehicle, via an external communication device. The integrated ECU (on-board device) transmits the software acquired from the external server to the redundant ECU. Furthermore, during the period from when the integrated ECU (vehicle-mounted device) receives a request notification from the redundant ECU until when it receives a preparation completion notification, the integrated ECU (vehicle-mounted device) stores and holds communication data sent to the vehicle-mounted ECU determined not to be operating normally, without relaying the data. After receiving the preparation completion notification from the redundant ECU, the integrated ECU (vehicle-mounted device) relays the held communication data to the redundant ECU based on the changed relay table. During the period from when the redundant ECU determines that the vehicle-mounted ECU to be substituted is not operating normally (when the request notification is sent) to when the redundant ECU completes preparation for substitution (when the preparation completion notification is sent), the function (service) of the vehicle-mounted ECU to be substituted is not normally executed (provided). In response to this, the integrated ECU (vehicle-mounted device) stores and holds communication data received during the period (the period from when the request notification is received to when the preparation completion notification is received) to the vehicle-mounted ECU to be substituted, without relaying the data, in the memory unit of the integrated ECU (vehicle-mounted device).In addition, after receiving a preparation completion notification from the redundant ECU, the integrated ECU (vehicle-mounted device) relays the communication data it has held to the redundant ECU that has completed preparation for substitution and started substitution processing, so that it can start substitution processing while avoiding the generation of communication data that has not been processed, and continue the function (service) that the vehicle-mounted ECU to be substituted had. When receiving a request notification, the integrated ECU (vehicle-mounted device) may cut off the power supply to the ECU name (ECU-ID) included in the request notification, that is, the vehicle-mounted ECU that has been determined not to be operating normally. In this case, the integrated ECU (vehicle-mounted device) may be a PLB (Power Lan Box) that has a power distribution function for distributing power from a power supply device in addition to a relay function. The integrated ECU (vehicle-mounted device) turns off the vehicle-mounted ECU that has been determined not to be operating normally, triggered by the request notification from the redundant ECU, so that it is possible to prevent the vehicle-mounted ECU from adversely affecting the vehicle network.
[0026] (9) A program according to one embodiment of the present disclosure causes a computer communicatively connected to multiple vehicle ECUs to acquire status data regarding the status of the vehicle ECUs from the vehicle ECUs, and if it is determined based on the acquired status data that the vehicle ECU is not operating normally, acquire software for replacing the vehicle ECU determined to be not operating normally, and execute the acquired software to perform a process to replace the vehicle ECU determined to be not operating normally.
[0027] In this aspect, it is possible to provide a program that causes a computer to function as a redundant ECU that efficiently performs processing related to replacing an on-board ECU mounted in a vehicle when the on-board ECU stops operating normally.
[0028] (10) An information processing method according to one aspect of the present disclosure includes having a computer communicatively connected to multiple vehicle ECUs acquire status data regarding the status of the vehicle ECUs from the vehicle ECUs, and if it is determined based on the acquired status data that the vehicle ECU is not operating normally, acquire software for replacing the vehicle ECU determined to be not operating normally, and execute the acquired software to perform a process to replace the vehicle ECU determined to be not operating normally.
[0029] In this aspect, it is possible to provide an information processing method that causes a computer to function as a redundant ECU that efficiently performs processing related to replacing an on-board ECU mounted in a vehicle when the on-board ECU stops operating normally.
[0030] [Details of the embodiment of the present disclosure] The present disclosure will be specifically described based on the drawings showing the embodiments. A redundant ECU 32 according to an embodiment of the present disclosure will be described below with reference to the drawings. Note that the present disclosure is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.
[0031] (Embodiment 1) Hereinafter, an embodiment will be described with reference to the drawings. Fig. 1 is a schematic diagram illustrating a system configuration of an in-vehicle system S according to the first embodiment. Fig. 2 is a block diagram illustrating an internal configuration of a redundant ECU 32. The in-vehicle system S is configured with an integrated ECU 2 (in-vehicle device) and a redundant ECU 32 mounted on a vehicle C as main devices, and the redundant ECU 32 is connected to a plurality of in-vehicle ECUs 3 including a spare ECU 31 via an in-vehicle network 4 so as to be able to communicate with each other.
[0032] The integrated ECU 2 (on-board device) includes a control unit, a storage unit, and an in-vehicle communication unit, and is configured by a central control device such as a vehicle computer, similar to the redundant ECU 32 described later, and performs overall control of the vehicle C. The integrated ECU 2 may have a relay function and relay messages transmitted and received by each of the on-board ECUs 3. Alternatively, a relay device such as a CAN gateway or an Ethernet switch may be connected under the integrated ECU 2, and the relay device may relay messages transmitted and received by each of the on-board ECUs 3.
[0033] Furthermore, the integrated ECU 2 is communicatively connected to an external server S1, such as an OTA (Over The Air) server, connected to an external network such as the Internet, via the external communication device 1. The external communication device 1 includes an external communication unit and an input / output I / F (interface) for communicating with the integrated ECU 2. The external communication unit is a communication device for wireless communication using a mobile communication protocol such as LTE, 4G, 5G, or WiFi, and transmits and receives data to and from the external server S1 via an antenna 11 connected to the external communication unit. The communication between the external communication device 1 and the external server S1 is performed via an external network such as a public line network or the Internet.
[0034] The in-vehicle ECU 3 includes an in-vehicle ECU 3 mounted at the production stage of the vehicle C (installed at the time of shipment), as well as a spare ECU 31 that is retrofitted (installed after production and shipment of the vehicle C) when adding a new service or function to the vehicle C. The spare ECU 31 may include a spare ECU 31 (redundant system ECU 32) that is a redundant spare and has a function of substituting for another in-vehicle ECU 3 (spare ECU 31). The in-vehicle ECU 3 installed at the time of shipment includes an in-vehicle ECU 3 (sensor-actuator control ECU) to which a sensor 301 or an actuator 302 is directly connected by a signal line or the like, and an in-vehicle ECU 3 that is not directly connected to such a sensor 301 or the like and outputs a calculation result or the like obtained by processing information based on a message or the like obtained from the sensor-actuator control ECU.
[0035] In this way, by additionally connecting (newly installing) the spare ECU 31 to the in-vehicle network 4, it is possible to add a new service or function to the vehicle C. The spare ECU 31 to be additionally connected (newly installed) may include a redundant ECU 32 (substitute ECU) having a function of substituting (replacing) the other in-vehicle ECU 3 by executing the same software as the other in-vehicle ECU 3. By using the redundant ECU 32, even if the added spare ECU 31 or the in-vehicle ECU 3 installed at the time of shipment no longer operates normally, it is possible to substitute for the in-vehicle ECU 3 and continue or resume the provision of the service or the like that was handled by the in-vehicle ECU 3.
[0036] The redundant ECU 32 includes a control unit 321, a storage unit 322, and an in-vehicle communication unit 323, and may be configured as a redundant spare ECU 31 having a function of substituting for another in-vehicle ECU 3 (spare ECU 31) among the spare ECUs 31 that are retrofitted (attached after production and shipment of the vehicle C). The redundant ECU 32 requests the multiple in-vehicle ECUs 3 connected to the in-vehicle network 4 to transmit information on the services handled by these in-vehicle ECUs, and by acquiring the information, generates and updates a management list including information in which the in-vehicle ECUs are associated with the names of the services or functions handled by the in-vehicle ECUs. Furthermore, the redundant ECU 32 performs processing related to the status management of the in-vehicle ECUs by acquiring and aggregating status data periodically transmitted from the multiple in-vehicle ECUs 3 connected to the in-vehicle network 4.
[0037] The control unit 321 is configured with a CPU (Central Processing Unit) or an MPU (Micro Processing Unit) and performs various control processes and arithmetic processes by reading and executing a program P (program product) and data previously stored in the storage unit 322. The control unit 321 is not limited to only a software processing unit that performs software processing such as a CPU, but may also include a hardware processing unit that performs various control processes and arithmetic processes by hardware processing such as an FPGA, an ASIC, or an SOC.
[0038] The storage unit 322 is configured with a volatile memory element such as a random access memory (RAM) or a non-volatile memory element such as a read only memory (ROM), an electrically erasable programmable ROM (EEPROM), or a flash memory, and stores in advance a program P (program product) and data to be referenced during processing. The program P (program product) stored in the storage unit 322 may be a program P (program product) read from a recording medium M readable by the redundant system ECU 32. Alternatively, the program P (program product) may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 322. The storage unit 322 may further store a management list. Details of the management list will be described later.
[0039] The in-vehicle communication unit 323 is an input / output interface (CAN transceiver, Ethernet PHY) using a communication protocol such as CAN (Control Area Network), CAN-FD, or Ethernet (registered trademark). A communication line 41 such as a CAN bus or an Ethernet cable is connected to the in-vehicle communication unit 323 in accordance with the communication protocol. The control unit 321 communicates with the in-vehicle ECUs 3 such as the spare ECU 31 connected to the in-vehicle network 4 and the integrated ECU 2 via the in-vehicle communication unit 323.
[0040] The in-vehicle ECU 3 such as the standby ECU 31 includes a control unit, a storage unit, and an in-vehicle communication unit, similar to the redundant ECU 32. The in-vehicle ECU 3 and the integrated ECU 2 are connected by a power line, and the in-vehicle ECU 3 may obtain (receive) power distributed from the integrated ECU 2.
[0041] 3 is an explanatory diagram illustrating an example of the management list. The storage unit 322 of the redundant ECU 32 stores ECU management information, which is an aggregation of information about the vehicle-mounted ECUs 3 based on information about services acquired from the multiple vehicle-mounted ECUs 3 including the spare ECU 31 and the sensor / actuator control ECU, and information about the vehicle-mounted ECUs 3 based on status data, for example in a table format or list format (management list). The management list (ECU management information) includes, as management items (fields), for example, ECU name (ECU-ID), function (service), type, status, and whether or not replacement is possible. The management item of the ECU name stores, for example, an ECU number, an ECU name, an identification number (ECU-ID) that uniquely identifies the vehicle-mounted ECU 3, and the like.
[0042] The function management item stores the name (function name) of a function or service that is realized or assumed by the in-vehicle ECU 3 (ECU name) stored in the same record by executing software. The redundant ECU 32 can identify another in-vehicle ECU 3 that the redundant ECU 32 can replace (the in-vehicle ECU 3 to be replaced) based on the function name.
[0043] The type management item stores the type of the in-vehicle ECU 3 (ECU name) stored in the same record. The type includes, for example, spare, redundant spare, sensor connection, actuator connection, and installation.
[0044] The in-vehicle ECU3 of the type spare indicates a spare ECU31, and is, for example, an in-vehicle ECU3 that can be retrofitted (attached after production and shipment of the vehicle C) when adding a new service or function to the vehicle C. The in-vehicle ECU3 of the type spare redundant system indicates a redundant system ECU32, and is an in-vehicle ECU3 that can be substituted for another in-vehicle ECU3 among the spare ECUs 31 that can be retrofitted.
[0045] The in-vehicle ECU 3 of the sensor connection type is an in-vehicle ECU 3 to which a sensor 301 such as a LiDAR, an infrared sensor 301, or a CMOS camera is directly connected via a signal line, etc. The in-vehicle ECU 3 of the actuator 302 connection type is an in-vehicle ECU 3 to which an actuator 302 such as a switch, a lamp, or a drive motor is directly connected via a signal line, etc. The in-vehicle ECU 3 of the installed type is an in-vehicle ECU 3 that is installed in the vehicle C during the production stage of the vehicle C (installed at the time of shipment).
[0046] The status management item stores the operation status of the in-vehicle ECU 3 (ECU name) stored in the same record. The operation status includes, for example, "operating" indicating normal operation, "fault" indicating abnormal operation, "redundant operation" indicating replacement processing (redundant ECU 32 is replacing), and "standby" indicating a sleep state.
[0047] The management item of substitutability stores a value (yes, no) or a flag indicating whether the redundant ECU 32 can substitute for the in-vehicle ECU 3 (ECU name) stored in the same record. The storage unit 322 of the redundant ECU 32 stores the names of one or more functions (services) that can be substituted by the control unit 321 of the redundant ECU 32, and the in-vehicle ECU 3 (ECU name) that has the same function (service) as the function (service) is the in-vehicle ECU 3 that can be substituted.
[0048] For example, when the redundant ECU 32 (itself) is connected to the in-vehicle network 4 or when the IG switch of the vehicle C is turned off, the control unit 321 of the redundant ECU 32 requests all in-vehicle ECUs 3 connected to the in-vehicle network 4 to transmit information related to the services performed by the in-vehicle ECUs 3. The control unit 321 of the redundant ECU 32 acquires (receives) information (names of services or functions performed by the in-vehicle ECUs 3) transmitted by the in-vehicle ECUs 3 in response to the request, generates a management list based on each piece of received information, and thereafter appropriately updates the management list to the latest state. This makes it possible to manage the association between the in-vehicle ECUs 3 and the functions (services) performed by the in-vehicle ECUs 3.
[0049] Furthermore, the control unit 321 of the redundant system ECU 32 periodically performs polling communication (status inquiry) with all the in-vehicle ECUs 3, and updates the contents of the status management items included in the management list based on the status data acquired from these in-vehicle ECUs 3. The status data includes the operating status of the in-vehicle ECU 3 that is the source of the status data, and the operation settings that are setting information of the software being executed. Therefore, the control unit 321 of the redundant system ECU 32 can grasp the current operating status and operation settings (software setting information) of each in-vehicle ECU 3, using the transmission cycle (reception cycle) of the status data as the processing unit time.
[0050] 4 is an explanatory diagram illustrating an example of a relay table used by the integrated ECU 2. The integrated ECU 2 (on-board device) functioning as a relay device performs relay processing of messages transmitted and received between a plurality of on-board ECUs 3 by referring to the relay table stored in the storage unit of the integrated ECU 2. The relay table includes, as management items (fields), for example, a message ID and a relay destination ECU.
[0051] The management item of the message ID stores an identifier indicating the type of communication data to be relayed, such as a message, frame, or packet. For example, when the communication protocol is CAN or CAN / FD, the message ID may store a CAN-ID. When the communication protocol is TCP / IP, the message ID may store a TCP port number or a UDP port number. The management item of the destination ECU stores the ECU name of the in-vehicle ECU 3 to which the communication data (message, etc.) of the message ID stored in the same record is relayed.
[0052] When the redundant ECU 32 starts the substitution process (when the integrated ECU 2 receives a preparation completion notification from the redundant ECU 32), the integrated ECU 2 changes the relay table according to the redundant ECU 32. This makes it possible to reliably relay messages and the like required to execute a service or function to the redundant ECU 32 instead of the in-vehicle ECU 3 (the in-vehicle ECU 3 to be substituted) that has been determined not to be operating normally (to be abnormal).
[0053] 5 is an explanatory diagram illustrating a process flow (sequence) by the redundant ECU 32, the integrated ECU 2, etc. A plurality of in-vehicle ECUs 3, including the integrated ECU 2 (in-vehicle device), the spare ECU 31, the redundant ECU 32, and the sensor / actuator control ECU, included in the in-vehicle system S, are communicatively connected via an in-vehicle network 4, and perform the following processes in association with each other.
[0054] The redundant system ECU 32 requests the multiple in-vehicle ECUs 3 to transmit information related to services provided by the in-vehicle ECUs 3 (S01). For example, when the redundant system ECU 32 (itself) is connected to the in-vehicle network 4 or when the IG switch of the vehicle C is turned off or on, the redundant system ECU 32 requests all in-vehicle ECUs 3 connected to the in-vehicle network 4 to transmit information related to services provided by the in-vehicle ECUs 3.
[0055] Each of the in-vehicle ECUs 3, such as the spare ECU 31 and the sensor / actuator control ECU, transmits information relating to the service provided by that in-vehicle ECU 3 (itself) in response to a request from the redundant system ECU 32 (S02). Each of the in-vehicle ECUs 3, such as the spare ECU 31 and the sensor / actuator control ECU, transmits information relating to the service provided by that in-vehicle ECU 3 (itself) (including the name of the service or function provided by that in-vehicle ECU 3) to the redundant system ECU 32 in response to a request from the redundant system ECU 32.
[0056] The redundant ECU 32 generates a management list (S03) based on the information on the service received from each of the in-vehicle ECUs 3. The information on the service received from each of the in-vehicle ECUs 3 includes an ECU name (ECU-ID) that uniquely identifies the in-vehicle ECU 3 that is the source of the information, and the name of the service or function that the in-vehicle ECU 3 performs, in association with each other.
[0057] For example, when the redundant system ECU 32 (itself) is connected to the in-vehicle network 4, the redundant system ECU 32 generates a management list based on information about services received from each of the in-vehicle ECUs 3, and stores the management list in the memory unit 322 of the redundant system ECU 32. Even after generating the management list, the redundant system ECU 32 periodically or constantly requests the multiple in-vehicle ECUs 3 to transmit information about services, and updates the management list based on the information about services transmitted (returned) from each of the in-vehicle ECUs 3 in response to the request.
[0058] The storage unit 322 of the redundant ECU 32 stores the names of one or more functions (services) that can be substituted by the control unit 321 of the redundant ECU 32. Substitutability in the redundant ECU 32 is determined based on product specifications including, for example, the hardware configuration of the redundant ECU 32, the installed OS or class library, and functions (services) corresponding to the names or types of executable software are stored (defined) in the storage unit 322 as substitutable functions (services).
[0059] The control unit 321 of the redundant system ECU 32 compares the names of the functions (services) performed by each of the in-vehicle ECUs 3 included in the management list with the names of the functions (services) that the redundant system ECU 32 (itself) can replace, thereby identifying a replaceable in-vehicle ECU 3 based on the identity or compatibility of the functions (services). The control unit 321 of the redundant system ECU 32 may store (define) yes (replaceable) or no (not replaceable) in the replacement possibility management item of the management list based on the identification result of the replaceable in-vehicle ECU 3.
[0060] The redundant system ECU 32 detects the newly connected spare ECU 31 (S04). The redundant system ECU 32 updates the management list in response to the detection of the newly connected or disconnected spare ECU 31 (S05). When the spare ECU 31 is newly connected (newly installed) to the in-vehicle network 4, the redundant system ECU 32 can recognize that the spare ECU 31 is newly connected to the in-vehicle network 4, for example, by acquiring status data from the newly installed spare ECU 31. When a new service or function is added to the vehicle C, it is assumed that the spare ECU 31 is retrofitted (installed after the production and shipment of the vehicle C). Even for the spare ECU 31 retrofitted in response to the addition of a service in this way, the redundant system ECU 32 can timely recognize that the spare ECU 31 is newly installed. The redundant ECU 32 also requests the newly installed standby ECU 31 to transmit information regarding the service, and updates the management list based on the information regarding the service transmitted (returned) from the newly installed standby ECU 31 in response to the request.
[0061] The redundant ECU 32 performs polling communication or the like (status inquiry) with the spare ECU 31 (spare ECU 1) to obtain status data (normal response, operation setting) related to the status of the spare ECU 31 (spare ECU 1) (S06). A plurality of in-vehicle ECUs 3 including the integrated ECU 2, the spare ECU 31, and the redundant ECU 32 are connected to the in-vehicle network 4, and the redundant ECU 32 continuously performs status inquiries with the in-vehicle ECUs 3 by polling communication or the like with the plurality of in-vehicle ECUs 3.
[0062] The redundant ECU 32 can recognize whether the in-vehicle ECU 3 is operating or stopped (removed from the in-vehicle network 4) based on whether or not it has acquired status data periodically transmitted from the multiple in-vehicle ECUs 3. The status data output (transmitted) from the in-vehicle ECU 3 includes information indicating whether the in-vehicle ECU 3 is operating normally (operating normally) and information indicating that the in-vehicle ECU 3 is not operating normally and is in an abnormal state (operating abnormally). Therefore, based on the status data acquired from the in-vehicle ECU 3, the spare ECU 31 can determine the operating state of the in-vehicle ECU 3, i.e., whether or not it is operating normally (operating abnormally).
[0063] The redundant ECU 32 stores the status data acquired from the in-vehicle ECU 3 in the storage unit 322 of the redundant ECU 32. In the storing process, the redundant ECU 32 may update the management information (management list) of the in-vehicle ECU 3 to the latest state by storing the operation status (normal or abnormal) of the in-vehicle ECU 3 and the operation setting included in the status data acquired from the in-vehicle ECU 3 in a management list.
[0064] The operational settings of the in-vehicle ECU 3 correspond to various setting information (information related to the operational settings) of the software when the in-vehicle ECU 3 executes the software to provide a service or the like. The various setting information of the software may include, for example, user information related to the driver driving the vehicle C, and may further include setting information (setting information for each driver) associated with each piece of user information. Furthermore, the operational settings of the in-vehicle ECU 3 (various setting information of the software) may include history information such as the operation contents performed by the driver (current user) currently driving the vehicle C when using a service or the like.
[0065] The redundant system ECU 32 determines that the standby ECU 31 (standby ECU1) is abnormal, depending on whether or not status data has been acquired, or on the acquired abnormal response (S07). As described above, the redundant system ECU 32 performs polling communication (status inquiry) for all the in-vehicle ECUs 3 connected to the in-vehicle network 4, and acquires the latest operation settings of the standby ECU 31 (standby ECU1), for example. If any problem occurs in the standby ECU 31 (standby ECU1), the redundant system ECU 32 determines that the standby ECU 31 (standby ECU1) is abnormal, based on whether or not status data has been acquired from the standby ECU 31 (standby ECU1), or on the contents of the status data.
[0066] The redundant ECU 32 may be configured to determine that, when the status data is not acquired from the standby ECU 31 (standby ECU1) for a period exceeding the transmission period, the standby ECU 31 (standby ECU1) is not operating normally due to a failure or being removed from the in-vehicle network 4. The redundant ECU 32 may be configured to determine that the standby ECU 31 (standby ECU1) is not operating normally when the status data acquired from the standby ECU 31 (standby ECU1) indicates an abnormal response.
[0067] The redundant ECU 32 transmits a request notification (fault notification) to the integrated ECU 2, indicating a request to acquire software (S08). The redundant ECU 32 refers to the management list to identify a function (service) performed by the standby ECU 31 (standby ECU1) determined not to be operating normally. The redundant ECU 32 refers to the management list to determine whether the identified function (service) is substitutable, and if substitutable, transmits a request notification to the integrated ECU 2 requesting software for substituting (executing) the function (service). The request notification may include a name, a version, etc. of the requested software. The redundant ECU 32 may transmit a fault notification to the integrated ECU 2 indicating that it has been determined that the standby ECU 31 (standby ECU1) is not operating normally together with the request notification. Alternatively, the request notification requesting software may include a notification function as a fault notification by including the ECU name (ECU-ID) of the spare ECU 31 (spare ECU 1) that has been determined to be not operating normally.
[0068] In response to the request notification (failure notification) from the redundant system ECU 32, the integrated ECU 2 cuts off the power supply to the in-vehicle ECU 3 determined not to be operating normally and suspends (suspends) the relay of communication data to the in-vehicle ECU 3 (S09). By receiving the request notification (failure notification) from the redundant system ECU 32, the integrated ECU 2 can recognize the ECU name (ECU-ID) of the spare ECU 31 (spare ECU1) determined not to be operating normally (abnormal) and the name of software for substituting for the spare ECU 31. Furthermore, the integrated ECU 2 can recognize the ECU name (ECU-ID) of the redundant system ECU 32 that is the sender of the request notification (failure notification).
[0069] The integrated ECU2, triggered by receiving a request notification (fault notification) from the redundant ECU32, cuts off the power supply to the spare ECU31 (spare ECU1) determined to be not operating normally (abnormal). The integrated ECU2 is configured with a PLB (Power Lan Box) having a power distribution function for distributing power from a power supply device in addition to a relay function, and includes a relay for starting or cutting off the power supply to each of the multiple in-vehicle ECUs3 connected via a power line. The integrated ECU2 cuts off the power supply to the spare ECU31 (spare ECU1) by turning off the relay connected to the spare ECU31 (spare ECU1) determined to be not operating normally (abnormal). Furthermore, the integrated ECU2, triggered by receiving a request notification (fault notification) from the redundant ECU32, temporarily stops (suspends) the relay of communication data to be transmitted to the spare ECU31 (spare ECU1) determined to be not operating normally (abnormal), and stores and holds the communication data in a storage unit of the integrated ECU2.
[0070] The integrated ECU 2 acquires software for substituting for the spare ECU 31 (spare ECU 1) determined to be abnormal from the external server S1 (S10). The integrated ECU 2 acquires the software for substituting for the spare ECU 31 (spare ECU 1) determined to be abnormal from the external server S1 functioning as, for example, an OTA server. The integrated ECU 2 may acquire (download) the software from the external server S1 by transmitting a request signal including the name of the software to the external server S1.
[0071] The integrated ECU 2 outputs the software to the redundant ECU 32 (redundant standby ECU 3) (S11). The integrated ECU 2 outputs the software acquired (downloaded) from the external server S1 to the redundant ECU 32 (redundant standby ECU 3).
[0072] The redundant ECU 32 installs the software acquired from the integrated ECU 2 and applies the operation settings (S12). The redundant ECU 32 installs the software acquired from the integrated ECU 2. Furthermore, the redundant ECU 32 applies the operation settings (software setting information) included in the state data last acquired from the standby ECU 31 (standby ECU1) that has been determined not to be operating normally (abnormal), based on the state data. By using the operation settings (software setting information) included in such state data, it is possible to continue providing the service or function by inheriting the operation settings immediately before the standby ECU 31 (standby ECU1) was determined not to be operating normally.
[0073] The redundant ECU 32 uses the software and the setting information to perform a self-diagnosis process to check whether the software operates normally (S13). The redundant ECU 32 generates an emulation environment for performing the self-diagnosis process, for example, by executing emulation software, and determines whether the software to which the setting information is applied operates in the emulation environment.
[0074] The redundant ECU 32 transmits to the integrated ECU 2 a preparation completion notification (function takeover completion) indicating that preparation for substitution has been completed (S14). If the result of the self-diagnosis process is positive (determination result that the system will operate normally), the redundant ECU 32 transmits to the integrated ECU 2 a preparation completion notification (function takeover completion) indicating that preparation for substitution has been completed, and notifies the integrated ECU 2 that the takeover of the function (service) of the standby ECU 31 (standby ECU 1) to be substituted has been completed. If the result of the self-diagnosis process is negative (determination result that the system will not operate normally), the redundant ECU 32 may interrupt a series of processes related to the substitution process.
[0075] The integrated ECU 2 changes (updates) the relay table (S15). The integrated ECU 2 changes (updates) the relay table stored in the storage unit of the integrated ECU 2, triggered by receipt of a preparation completion notification (function takeover completion) from the redundant ECU 32. The integrated ECU 2 updates (changes) the relay table in accordance with the redundant ECU 32 (redundant standby ECU 3).
[0076] The integrated ECU 2 uses the relay table to relay messages (frames) transmitted and received between the in-vehicle ECUs 3. For example, the integrated ECU 2 updates the relay table to change the relay destination for a specific message (frame) from the standby ECU 31 (standby ECU 1) determined not to be operating normally to the redundant ECU 32 (redundant standby ECU 3). As a result, a message (frame) required for the redundant ECU 32 (redundant standby ECU 3) to execute software is relayed from the in-vehicle ECU 3 that sent the message via the integrated ECU 2.
[0077] The integrated ECU 2 transmits (resumes relaying) the communication data for which relaying has been stopped (put on hold) to the redundant system ECU 32 (S16). After changing (updating) the relay table, the integrated ECU 2 transmits (resumes relaying) the communication data for which relaying has been stopped (put on hold) to the redundant system ECU 32. During the period from when the integrated ECU 2 receives the request notification from the redundant system ECU 32 until when it receives the preparation completion notification, the integrated ECU 2 stores and holds the communication data transmitted to the in-vehicle ECU 3 determined not to be operating normally in the storage unit of the integrated ECU 2 without relaying the data.
[0078] The integrated ECU 2 receives the preparation completion notification from the redundant system ECU 32, changes (updates) the relay table, and then uses the changed relay table to relay (transmit) the communication data that has been held (suspended relay) to the redundant system ECU 32. Thereafter, the integrated ECU 2 continues relaying all communication data by using the changed (updated) relay table, and as a result, communication data sent to the in-vehicle ECU 3 determined to be malfunctioning is also relayed to the redundant system ECU 32 that performs alternative processing.
[0079] The redundant system ECU 32 starts a process (alternative process) to substitute for the standby ECU 31 (standby ECU 1) determined to be abnormal (S17). The redundant system ECU 32 receives communication data transmitted (relayed) from the integrated ECU 2 or the like, and starts (executes) the alternative process based on the communication data. This allows the function (service) that was being performed by the in-vehicle ECU 3 determined to be not operating normally (the in-vehicle ECU 3 to be substituted) to be continued. This ensures the availability of the in-vehicle system S including the standby ECU 31 and the redundant system ECU 32. When starting the alternative process, the redundant system ECU 32 may update the management list to the latest state by storing in the management list items indicating that the redundant system ECU 32 (standby ECU 3) is executing the alternative process and that the standby ECU 31 (standby ECU 1) determined to be not operating normally is malfunctioning.
[0080] 6 is a flowchart illustrating the processing of the control unit 321 of the redundant ECU 32. The control unit 321 of the redundant ECU 32 steadily performs the following processing, for example, when the vehicle C is in a stopped state (power switch or IG switch is off) or in a running state (power switch or IG switch is on).
[0081] The control unit 321 of the redundant system ECU 32 periodically, regularly, or steadily performs polling communication or the like with the in-vehicle ECUs 3 including the spare ECU 31 and the redundant system ECU 32 via the in-vehicle network 4, and continues processing to acquire status data from these in-vehicle ECUs 3. This enables the control unit 321 of the redundant system ECU 32 to recognize the spare ECU 31 that is newly connected (newly installed) to the in-vehicle network 4, and to recognize the in-vehicle ECUs 3 (including the spare ECU 31) that have been removed (disconnected) from the in-vehicle network 4.
[0082] The control unit 321 of the redundant ECU 32 continuously performs processing to change (update) the management list stored in the storage unit 322 in response to recognition of the installation or removal of these in-vehicle ECUs 3. Then, in response to the determination of the operating states of these in-vehicle ECUs 3, the redundant ECU 32 performs processing (substitution processing) to substitute for an in-vehicle ECU 3 determined not to be operating normally.
[0083] The control unit 321 of the redundant ECU 32 acquires status data from the in-vehicle ECU 3 via the in-vehicle network 4 (S101). The control unit 321 of the redundant ECU 32 acquires status data from all the in-vehicle ECUs 3 connected to the in-vehicle network 4 periodically, regularly, or steadily via the in-vehicle network 4. The status data includes information regarding the operating state (normal or abnormal) and operation settings (setting information of the running software, etc.) of the in-vehicle ECU 3 that is the sender.
[0084] The control unit 321 of the redundant ECU 32 may update the contents of the status management items included in the management list stored in the storage unit 322 based on the acquired status data. The control unit 321 of the redundant ECU 32 may generate screen data indicating the status of each of the in-vehicle ECUs 3 connected to the in-vehicle network 4 using the information stored in the management list updated in this manner, and output the screen data to an HMI (Human Machine Interface) device such as a display. This makes it possible to notify the operator of the vehicle C of information regarding the status of each of the in-vehicle ECUs 3.
[0085] The control unit 321 of the redundant system ECU 32 determines whether any of the in-vehicle ECUs 3 is abnormal (S102). Based on the acquired status data, the control unit 321 of the redundant system ECU 32 determines whether the in-vehicle ECU 3 that is the source of the status data is abnormal, i.e., whether the in-vehicle ECU 3 is operating normally. For example, by referring to a management list, the control unit 321 of the redundant system ECU 32 determines the operating status of the in-vehicle ECUs 3 of all ECU names included in the management list.
[0086] The control unit 321 of the redundant system ECU 32 determines that the in-vehicle ECU 3 is abnormal, for example, when the status data cannot be acquired for a period exceeding the transmission period, when the acquired status data includes an abnormality code indicating an abnormality in the in-vehicle ECU 3 that is the transmission source, or when the acquired status data is determined to be fraudulent data due to, for example, spoofing, etc. Cases when the in-vehicle ECU 3 is not operating normally (is abnormal) include, for example, a case when the in-vehicle ECU 3 has broken down or has been removed from the vehicle C.
[0087] When it is determined that none of the in-vehicle ECUs 3 is abnormal (S102: NO), the control unit 321 of the redundant system ECU 32 performs loop processing by executing S101 again. As a result, the control unit 321 of the redundant system ECU 32 continues the process of acquiring status data from all of the in-vehicle ECUs 3 connected to the in-vehicle network 4. Since the status data includes information on the operation settings and processing loads of each of the in-vehicle ECUs 3 at the current time (the time when the status data is transmitted), the control unit 321 of the redundant system ECU 32 can acquire the latest operation settings and processing loads of each of the in-vehicle ECUs 3. The control unit 321 of the redundant system ECU 32 stores these acquired operation settings in the storage unit 322, for example, by storing (updating) them in a management list.
[0088] When it is determined that any of the in-vehicle ECUs 3 is abnormal (S102: YES), the control unit 321 of the redundant ECU 32 acquires software for substituting for the in-vehicle ECU 3 determined to be abnormal (not operating normally) (S103). The control unit 321 of the redundant ECU 32 determines whether or not it is possible to substitute for the in-vehicle ECU 3 determined to be abnormal (not operating normally), for example, by referring to a management list. If it is possible to substitute, the control unit 321 of the redundant ECU 32 identifies a function (service) performed by the in-vehicle ECU 3, and transmits a request notice (fault notice) indicating a request to acquire software for executing the function (service) to the integrated ECU 2. The request notice also serves as a fault notice, and may include an ECU name (ECU-ID) of the in-vehicle ECU 3 determined to be not operating normally.
[0089] In response to a request notification (failure notification) from the redundant ECU 32, the integrated ECU 2 acquires (downloads) from the external server S1 the function to be performed or the software to be executed by the in-vehicle ECU 3 determined to be abnormal. The integrated ECU 2 outputs the acquired (downloaded) software to the redundant ECU 32. Furthermore, the integrated ECU 2, triggered by receipt of the request notification (failure notification) from the redundant ECU 32, cuts off the power supply to the in-vehicle ECU 3 determined to be abnormal and suspends (suspends) the relaying of communication data to the in-vehicle ECU 3, and stores and holds the communication data in a storage unit of the integrated ECU 2.
[0090] The control unit 321 of the redundant ECU 32 installs the software acquired from the integrated ECU 2. The redundant ECU 32 further applies operation settings (software setting information) included in the status data last acquired from the in-vehicle ECU 3 determined to be not operating normally (abnormal), based on the status data.
[0091] The control unit 321 of the redundant ECU 32 performs a self-diagnosis process using the acquired software and setting information to determine whether the alternative function operates normally (S104). The control unit 321 of the redundant ECU 32 determines whether the software to which the setting information is applied operates, for example, by executing emulation software. If it is determined that the alternative function does not operate normally (S104: NO), the control unit 321 of the redundant ECU 32 stops executing the alternative process (S1041).
[0092] When it is determined that the alternative function operates normally (S104: YES), the control unit 321 of the redundant ECU 32 transmits a preparation completion notification indicating that preparation for alternative operation is completed to the integrated ECU 2 (S105). When it is determined that the alternative function operates normally as a result of the self-diagnosis process, the control unit 321 of the redundant ECU 32 transmits a preparation completion notification indicating that preparation for alternative operation is completed to the integrated ECU 2 (function takeover completion).
[0093] The integrated ECU 2 changes (updates) the relay table when it receives a preparation completion notification (function takeover completion) from the redundant ECU 32. Furthermore, the integrated ECU 2 transmits (resumes relaying) the communication data that was stopped (put on hold). After that, the integrated ECU 2 performs relay processing for all communication data based on the changed relay table.
[0094] The control unit 321 of the redundant system ECU 32 starts the replacement process (S106). The control unit 321 of the redundant system ECU 32 receives communication data transmitted (relayed) from the integrated ECU 2, etc., and starts (executes) the replacement process based on the communication data. The control unit 321 of the redundant system ECU 32 installs software for replacing the in-vehicle ECU 3 determined to be not operating normally, and executes the software by applying the operation settings used by the in-vehicle ECU 3. This makes it possible to continue (resume) the provision of a service or function by inheriting the operation settings of the in-vehicle ECU to be replaced. When starting the replacement process, the control unit 321 of the redundant system ECU 32 may update the management list to the latest state by storing (adding) information indicating that the in-vehicle ECU 3 to be replaced is malfunctioning and that the redundant ECU 32 (itself) is performing the replacement process in the management list.
[0095] (Additional Note) An in-vehicle system S including an in-vehicle device 2 (integrated ECU) mounted on a vehicle C and communicably connected to a plurality of in-vehicle ECUs 3, and a redundant ECU 32 replacing any one of the in-vehicle ECUs 3, The in-vehicle device 2 has a function of communicating with the outside of the vehicle. The redundant ECU 32 is acquiring status data relating to a status of the in-vehicle ECU 3 from the in-vehicle ECU 3; when it is determined based on the acquired status data that the in-vehicle ECU 3 is not operating normally, a request notification is sent to the in-vehicle device 2, indicating a request for acquisition of software for replacing the in-vehicle ECU 3 determined to be not operating normally; The in-vehicle device 2 outputs the acquired software in response to the request notification to the redundant ECU 32, The redundant ECU 32 executes the software acquired via the in-vehicle device 2 to replace the in-vehicle ECU 3 that is determined to be not operating normally. In-vehicle system S.
[0096] The embodiments disclosed herein are illustrative in all respects and should not be considered as limiting. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the scope and meaning equivalent to the claims.
[0097] The claims may be combined with each other regardless of the form of reference. The claims may contain multiple dependent claims depending on multiple claims. Multiple dependent claims may be contained depending on multiple dependent claims. If multiple dependent claims are not contained depending on a multiple dependent claim, this does not limit the number of dependent claims depending on a multiple dependent claim. [Explanation of symbols]
[0098] C Vehicle S In-vehicle system S1 External Server 1. External communication device 11 Antenna 2 Integrated ECU (in-vehicle device) 3 In-vehicle ECU 31 Spare ECU 32 Redundant ECU 321 Control Unit 322 Storage section 323 In-vehicle communication unit M Recording medium P Control program (program product) 301 Sensors 302 Actuator 4. In-vehicle network 41 Communication Line
Claims
1. A redundant ECU mounted on a vehicle and communicably connected to a plurality of on-board ECUs, A control unit that performs processing related to state management of the in-vehicle ECU, The control unit is acquiring status data relating to a status of the in-vehicle ECU from the in-vehicle ECU; When it is determined that the in-vehicle ECU is not operating normally based on the acquired status data, software for replacing the in-vehicle ECU determined to be not operating normally is acquired; By executing the acquired software, the vehicle's ECU that is determined to be malfunctioning is replaced. Redundant ECU.
2. The status data acquired from the vehicle-mounted ECU includes setting information regarding operation settings of the vehicle-mounted ECU at the time of transmitting the status data, The control unit applies the setting information when executing the acquired software, thereby replacing an in-vehicle ECU that is determined to be not operating normally. The redundant ECU according to claim 1 .
3. The control unit performs a self-diagnosis process to check the operation of an alternative function when substituting for an in-vehicle ECU that is determined to be malfunctioning, using the acquired software and setting information. The redundant ECU according to claim 2 .
4. a storage area accessible by the control unit stores a management list for identifying a replaceable in-vehicle ECU among a plurality of in-vehicle ECUs mounted on the vehicle; The control unit identifies a replaceable in-vehicle ECU by referring to the management list. The redundant ECU according to claim 1 .
5. The control unit is Requesting the plurality of in-vehicle ECUs to transmit information relating to services provided by the in-vehicle ECUs; The management list is generated or updated based on information related to the service received from each of the plurality of vehicle-mounted ECUs. The redundant ECU according to claim 4.
6. The vehicle is equipped with an on-board device having a communication function with the outside of the vehicle, The control unit acquires, via the in-vehicle device, software for replacing an in-vehicle ECU that is determined to be malfunctioning. The redundant ECU according to claim 1 .
7. the in-vehicle device has a relay function when the plurality of in-vehicle ECUs communicate with each other, The control unit transmits a preparation completion notification to the in-vehicle device, the preparation completion notification indicating that the in-vehicle device is ready to replace the in-vehicle ECU determined to be malfunctioning, By transmitting the preparation completion notification to the in-vehicle device, the in-vehicle device is caused to change the relay table used when executing the relay function. The redundant ECU according to claim 6.
8. The control unit is Transmitting a request notification to the in-vehicle device, the request notification indicating a request for acquiring software to replace the in-vehicle ECU determined to be malfunctioning; By transmitting the request notification to the in-vehicle device, the in-vehicle device is caused to accumulate communication data to the in-vehicle ECU to be substituted, which is received during the period from the request notification to the preparation completion notification, and transmits the communication data to the redundant ECU after receiving the preparation completion notification. The redundant ECU according to claim 7.
9. A computer communicably connected to a plurality of vehicle-mounted ECUs, acquiring status data relating to a status of the in-vehicle ECU from the in-vehicle ECU; When it is determined that the in-vehicle ECU is not operating normally based on the acquired status data, software for replacing the in-vehicle ECU determined to be not operating normally is acquired; By executing the acquired software, the vehicle's ECU that is determined to be malfunctioning is replaced. A program that executes a process.
10. A computer communicably connected to a plurality of vehicle-mounted ECUs, acquiring status data relating to a status of the in-vehicle ECU from the in-vehicle ECU; When it is determined that the in-vehicle ECU is not operating normally based on the acquired status data, software for replacing the in-vehicle ECU determined to be not operating normally is acquired; By executing the acquired software, the vehicle's ECU that is determined to be malfunctioning is replaced. An information processing method for executing a process.