On-vehicle control device, control method, and control program
Patent Information
- Application Number
- JP2023091042
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-06-01
- Publication Date
- 2025-11-07
AI Technical Summary
In-vehicle devices in a sleep state cannot communicate effectively, leading to a risk of erroneous detection as abnormal.
An in-vehicle control device with an abnormality detection unit that determines the sleep state of devices based on their cluster status, disabling abnormality detection when in sleep state to prevent false alarms.
Prevents erroneous detection of abnormality in sleep-state devices, ensuring accurate system operation.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an in-vehicle control device, a control method, and a control program. [Background technology]
[0002] A vehicle is equipped with a variety of on-board devices, such as control system ECUs (Electronic Control Units) that control the engine, transmission, etc., body system ECUs that control the headlights, power windows, etc., and information system ECUs for navigation devices, multimedia devices, etc.
[0003] 2. Description of the Related Art Conventionally, in an in-vehicle system in which in-vehicle devices are connected via a network, abnormalities in the in-vehicle devices have been detected (see, for example, Patent Document 1).
[0004] In recent years, in-vehicle systems, a partial network function has been developed in which in-vehicle devices are divided into clusters called PNCs (Partial Network Clusters) for each function (service), and the in-vehicle devices of the PNCs used to execute a service are woken up and the in-vehicle devices of the other PNCs are put to sleep. The partial network function is standardized in ISO (International Organization for Standardization) 11898-6.
[0005] Between ECUs, PNC request and release information is transmitted and received using network management messages (NM messages). NM messages include PN (Partial Network) information that indicates the request or release state of each PNC. An in-vehicle device corresponding to a requested PNC wakes up, and an in-vehicle device corresponding to a released PNC goes to sleep. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] JP 2003-276527 A Summary of the Invention [Problem to be solved by the invention]
[0007] An in-vehicle device in the sleep state cannot perform communication, and therefore there is a risk that the in-vehicle device in the sleep state will be erroneously detected as having an abnormality. [Means for solving the problem]
[0008] An in-vehicle control device according to one embodiment of the present disclosure is an in-vehicle control device connected via a network to an in-vehicle device capable of switching between an operating state and a sleep state, and includes an abnormality detection unit that detects an abnormality in the in-vehicle device, a determination unit that determines whether the in-vehicle device is in a sleep state based on the state of a cluster to which the in-vehicle device belongs, and a control unit that disables detection of an abnormality by the abnormality detection unit when the in-vehicle device is in a sleep state.
[0009] The present disclosure can be realized not only as an in-vehicle control device having the above-described characteristic configuration, a control method having steps corresponding to characteristic processing in the in-vehicle control device, and a control program for causing the in-vehicle control device to execute the characteristic processing, but also as an in-vehicle system including the in-vehicle control device, or as a semiconductor integrated circuit in part or in whole. Effect of the Invention
[0010] According to the present disclosure, it is possible to avoid erroneously detecting an abnormality in an in-vehicle device that is in a sleep state. [Brief description of the drawings]
[0011] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of an in-vehicle system according to the first embodiment. [Diagram 2]FIG. 2 is a block diagram illustrating an example of a hardware configuration of the relay ECU according to the first embodiment. [Diagram 3] FIG. 3 is a block diagram showing an example of a hardware configuration of the ECU according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of the cluster table. [Diagram 5] FIG. 5 is a diagram showing an example of PN information in an NM message. [Figure 6] FIG. 6 is a diagram showing an example of transmission of an NM message in an in-vehicle system. [Figure 7] FIG. 7 is a state transition diagram of the ECU. [Figure 8] FIG. 8 is a functional block diagram illustrating an example of functions of the relay ECU according to the first embodiment. [Figure 9] FIG. 9 is a diagram for explaining disabling of the anomaly detection function. [Figure 10] FIG. 10 is a flowchart illustrating an example of an abnormality detection disabling process by the relay ECU according to the first embodiment. [Figure 11] FIG. 11 is a flowchart illustrating an example of an abnormality detection validation process by the relay ECU according to the first embodiment. [Figure 12] FIG. 12 is a sequence diagram showing a first example of a procedure for disabling abnormality detection in the in-vehicle system according to the first embodiment. [Figure 13] FIG. 13 is a sequence diagram showing a second example of the procedure for disabling abnormality detection in the in-vehicle system according to the first embodiment. [Figure 14] FIG. 14 is a block diagram showing an example of the configuration of an in-vehicle system according to the second embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] <Overview of the embodiment of the present disclosure> Below, an overview of the embodiments of the present disclosure will be listed and described.
[0013] (1) The in-vehicle control device according to the present embodiment is an in-vehicle control device connected via a network to an in-vehicle device that can switch between an operating state and a sleep state, and includes an abnormality detection unit that detects an abnormality in the in-vehicle device, a determination unit that determines whether the in-vehicle device is in a sleep state based on the state of a cluster to which the in-vehicle device belongs, and a control unit that disables detection of an abnormality by the abnormality detection unit when the in-vehicle device is in the sleep state. This makes it possible to avoid erroneously detecting an in-vehicle device in a sleep state as being abnormal.
[0014] (2) In the above (1), the determination unit may determine whether the in-vehicle device is in a sleep state based on a state of the cluster held by the in-vehicle control device when the in-vehicle control device belongs to the cluster. This makes it possible to determine whether the in-vehicle device is in an operating state or a sleep state when the in-vehicle control device belongs to the same cluster as the in-vehicle device.
[0015] (3) In the above (1), when the in-vehicle control device does not belong to the cluster, the determination unit may determine whether the in-vehicle device is in a sleep state based on a state of the cluster specified in a control message transmitted through the network to control the cluster. This makes it possible to determine whether the in-vehicle device is in an operating state or a sleep state when the in-vehicle control device does not belong to the same cluster as the in-vehicle device.
[0016] (4) In any one of (1) to (3) above, when the in-vehicle device belongs to a first cluster and a second cluster, the determination unit may determine whether the in-vehicle device is in a sleep state based on a state of the first cluster and a state of the second cluster. This makes it possible to determine whether the in-vehicle device is in an operating state or a sleep state when the in-vehicle device belongs to the first cluster and the second cluster.
[0017] (5) In any one of (1) to (4) above, the determination unit may identify a cluster to which the in-vehicle device belongs by using a table showing a correspondence between clusters and in-vehicle devices, and determine whether the in-vehicle device is in a sleep state based on a state of the identified cluster. This makes it possible to easily identify which cluster the in-vehicle device belongs to by using the table.
[0018] (6) In any one of (1) to (5) above, the state of the cluster may include an operating state and a stopped state, and the determining unit may determine that the in-vehicle device is in a sleep state when the state of the cluster is a stopped state. This makes it possible to accurately determine that the in-vehicle device is in a sleep state based on the state of the cluster.
[0019] (7) In any one of (1) to (6) above, the abnormality detection unit may detect an abnormality in the in-vehicle device based on a communication state of the in-vehicle device through the network. In this way, when the in-vehicle device is in a sleep state, erroneous detection of an abnormality in the in-vehicle device based on the communication state can be avoided by disabling the abnormality detection unit.
[0020] (8) In any one of (1) to (7) above, when the in-vehicle control device belongs to the cluster and the cluster is in the stopped state, the in-vehicle control device may maintain an operating state. This makes it possible to prevent the in-vehicle control device from going into a sleep state and becoming unable to detect an abnormality in the in-vehicle device.
[0021] (9) The control method according to the present embodiment is a control method used by an in-vehicle control device connected via a network to an in-vehicle device capable of switching between an operating state and a sleep state, and includes the steps of: determining whether the in-vehicle device is in a sleep state based on the state of a cluster to which the in-vehicle device belongs; and disabling an anomaly detection function that detects an anomaly in the in-vehicle device when the in-vehicle device is in the sleep state. This makes it possible to avoid erroneously detecting an in-vehicle device in the sleep state as having an anomaly.
[0022] (10) A control program according to the present embodiment is a control program executed by an in-vehicle control device connected via a network to an in-vehicle device capable of switching between an operating state and a sleep state, and causes a computer to execute a step of determining whether the in-vehicle device is in a sleep state based on a state of a cluster to which the in-vehicle device belongs, and a step of disabling an anomaly detection function that detects an anomaly in the in-vehicle device when the in-vehicle device is in the sleep state. This makes it possible to avoid erroneously detecting an in-vehicle device in a sleep state as being abnormal.
[0023] <Details of the embodiment of the present disclosure> Hereinafter, the details of the embodiments of the present invention will be described with reference to the drawings. Note that at least some of the embodiments described below may be combined in any desired manner.
[0024] [First embodiment] [1-1. In-vehicle systems] 1 is a block diagram showing an example of the configuration of an in-vehicle system according to the first embodiment. An in-vehicle system 10 is mounted on a vehicle.
[0025] The in-vehicle system 10 according to the first embodiment includes a relay ECU 100 and ECUs 200A, 200B, 200C, and 200D. The in-vehicle system 10 is an in-vehicle network configured with the relay ECU 100, the ECUs 200A, 200B, 200C, and 200D, and communication lines 11A, 11B, 11C, 11D, and 12 connecting them. In the following description, the communication lines 11A, 11B, 11C, and 11D may be collectively referred to as "communication lines 11."
[0026] The multiple ECUs 200A, 200B, 200C, and 200D are disposed in various parts of the vehicle. The ECUs 200A, 200B, 200C, and 200D individually control the hardware of the various parts of the vehicle and monitor the status of the hardware of the various parts of the vehicle. For example, the ECUs 200A, 200B, 200C, and 200D are ECUs for a control system, a body system, and an information system. In the following description, the ECUs 200A, 200B, 200C, and 200D may be collectively referred to as "ECU 200."
[0027] The relay ECU 100 is connected to the ECUs 200A, 200B, 200C, and 200D via communication lines 11A, 11B, 11C, and 11D, respectively. That is, the relay ECU 100 and the ECU 200A are connected via the communication line 11A. The relay ECU 100 and the ECU 200B are connected via the communication line 11B. The relay ECU 100 and the ECU 200C are connected via the communication line 11C. The relay ECU 100 and the ECU 200D are connected via the communication line 11D.
[0028] A communication line 12 extends from the relay ECU 100. The relay ECU 100 is connected via the communication line 12 to an in-vehicle device (not shown) (for example, a relay ECU or ECU).
[0029] Each of the communication lines 11A, 11B, 11C, 11D, and 12 is an Ethernet cable ("Ethernet" is a registered trademark). Each of the ECUs 200A, 200B, 200C, and 200D of the relay ECU 100 has a communication function using Ethernet.
[0030] The relay ECU 100 relays communication between the ECUs 200A, 200B, 200C, and 200D (and other ECUs). That is, the relay ECU 100 relays Ethernet frames (messages) between the ECUs 200A, 200B, 200C, and 200D. For example, the relay ECU 100 functions as at least one of an Ethernet switch, a layer 2 switch, and a layer 3 switch. This allows the ECUs 200A, 200B, 200C, and 200D to communicate with each other.
[0031] Each of the ECUs 200A, 200B, 200C, and 200D includes a communication I / F 210 connected to the communication lines 11A, 11B, 11C, and 11D. The communication I / F 210 is an I / F corresponding to a partial network function. The relay ECU 100 includes a communication I / F 110A connected to the communication line 11A, a communication I / F 110B connected to the communication line 11B, a communication I / F 110C connected to the communication line 11C, a communication I / F 110D connected to the communication line 11D, and a communication I / F 110E connected to the communication line 12. The communication I / Fs 110A, 110B, 110C, and 110D are I / Fs corresponding to a partial network function.
[0032] The relay ECU 100, the ECUs 200A, 200B, 200C, and 200D use a communication protocol compatible with the partial network function. In the first embodiment, the communication protocol is Ethernet.
[0033] The relay ECU 100, ECUs 200A, 200B, 200C, and 200D can transmit and receive NM messages for partial networks. An NM message is a message that specifies a request or release of a PNC. An NM message is a User Datagram Protocol (UDP) packet that is periodically transmitted. An ECU 200 (node) that belongs to a PNC for which a request is specified in the NM message wakes up. A node that belongs to a PNC for which release is specified in the NM message goes to sleep. Here, sleep means that the ECU 200 temporarily stops functions other than some functions and waits in a power-saving state. Wake-up means that the ECU 200 in a sleep state transitions to an operating state. An operating state means that all functions of the ECU 200 are operational.
[0034] [1-2. Relay ECU configuration] The following describes a hardware configuration of the relay ECU 100. The relay ECU 100 is an example of an "on-vehicle control device."
[0035] 2 is a block diagram showing an example of a hardware configuration of the relay ECU according to the first embodiment. The relay ECU 100 includes a microcontroller 115 and communication I / Fs 110A, 110B, 110C, and 110D.
[0036] The microcontroller 115 is, for example, a one-chip semiconductor integrated circuit, and includes a processor 101, a non-volatile memory 102, a volatile memory 103, a peripheral circuit 104, and an input / output interface (I / O) 105.
[0037] The volatile memory 103 is a semiconductor memory such as a static random access memory (SRAM), a dynamic random access memory (DRAM), etc. The non-volatile memory 102 is a semiconductor memory such as a flash memory, a read only memory (ROM), an erasable programmable read only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc.
[0038] The processor 101 is, for example, a CPU (Central Processing Unit). However, the processor 101 is not limited to a CPU. The processor 101 may be a GPU (Graphics Processing Unit). The processor 101 is configured to be able to execute a computer program. However, the processor 101 may include, for example, an ASIC (Application Specific Integrated Circuit) in part, or a programmable logic device such as an FPGA (Field Programmable Gate Array) in part.
[0039] The non-volatile memory 102 stores an abnormality detection program 106, a control program 107, which are computer programs, and data used for executing each of the abnormality detection program 106 and the control program 107. The abnormality detection program 106 and the control program 107 can be stored in a recording medium such as a flash memory, a ROM, or a CD-ROM. The abnormality detection program 106 enables the processor 101 to detect an abnormality that has occurred in the ECU 200. The control program 107 enables the processor 101 to avoid erroneous detection of an abnormality by the abnormality detection program 106.
[0040] The non-volatile memory 102 stores a cluster table 108. The cluster table 108 will be described later.
[0041] The peripheral circuit 104 is a circuit for enabling the microcontroller 115 to realize various functions. For example, the peripheral circuit 104 includes circuits such as a general-purpose input / output port (GPIO), an analog / digital converter, a timer, and serial communication. The serial communication circuit complies with standards such as Universal Asynchronous Receiver / Transmitter (UART), Inter-Integrated Circuit (I2C), and serial peripheral interface (SPI).
[0042] The I / O 105 is connected to the communication I / Fs 110A, 110B, 110C, and 110D. The I / O 105 is a port used for input / output with the communication I / Fs 110A, 110B, 110C, and 110D.
[0043] The communication I / Fs 110A, 110B, 110C, and 110D are communication interfaces that comply with Ethernet. As described above, the communication I / Fs 110A, 110B, 110C, and 110D are I / Fs that support the partial network function.
[0044] The communication I / F 110A includes a PHY 111A. The communication I / F 110B includes a PHY 111B. The communication I / F 110C includes a PHY 111C. The communication I / F 110D includes a PHY 111D.
[0045] The PHY 111A is connected to the communication line 11A. The PHY 111B is connected to the communication line 11B. The PHY 111C is connected to the communication line 11C. The PHY 111D is connected to the communication line 11D.
[0046] The PHYs 111A, 111B, 111C, and 111D convert analog signals received from the communication lines 11A, 11B, 11C, and 11D into digital signals. The PHYs 111A, 111B, 111C, and 111D convert the digital signals into analog signals and transmit the converted analog signals to the communication lines 11A, 11B, 11C, and 11D.
[0047] The PHYs 111A, 111B, 111C, and 111D support a partial network function and can interpret a PNC designated as a wakeup target and a PNC designated as a sleep target in an NM message.
[0048] The communications I / Fs 110A, 110B, 110C, and 110D each include a processing circuit (not shown) for executing processing of frames (messages) to be transmitted or received.
[0049] [1-3.ECU configuration] The following describes a hardware configuration of the ECU 200. The ECU 200 is an example of an "on-vehicle device."
[0050] 3 is a block diagram showing an example of a hardware configuration of the ECU according to the first embodiment. The ECU 200 includes a microcontroller 220 and a communication I / F 210.
[0051] The microcontroller 220 has the same configuration as the microcontroller 115 of the above-described relay ECU 100. That is, the microcontroller 220 includes a processor 201, a non-volatile memory 202, a volatile memory 203, a peripheral circuit 204, and an I / O 205.
[0052] The non-volatile memory 202 stores an application program (hereinafter also referred to as "APP") 206, which is a computer program, and data used to execute the APP 206. The APP 206 can be stored in a recording medium such as a flash memory, a ROM, or a CD-ROM. The APP 206 enables the processor 201 to execute functions for providing services as an ECU.
[0053] The peripheral circuit 204 includes a serial communication circuit conforming to a standard such as UART, I2C, or SPI. The serial communication circuit of the peripheral circuit 204 is connected to a device or sensor to be controlled by the ECU 200, and can receive a signal output from the sensor and transmit a control signal to the device or sensor.
[0054] The I / O 205 is connected to the communication I / F 210. The I / O 205 is a port used for input / output to and from the communication I / F 210.
[0055] The communication I / F 210 is a communication interface that complies with Ethernet. As described above, the communication I / F 210 is an I / F that supports the partial network function.
[0056] The communication I / F 210 includes a PHY 211 .
[0057] The PHY 211 is connected to the communication line 11. That is, the PHY 211 of the ECU 200A is connected to the communication line 11A. The PHY 211 of the ECU 200B is connected to the communication line 11B. The PHY 211 of the ECU 200C is connected to the communication line 11C. The PHY 211 of the ECU 200D is connected to the communication line 11D.
[0058] The PHY 211 converts an analog signal received from the communication line 11 into a digital signal. The PHY 211 converts the digital signal into an analog signal, and transmits the converted analog signal to the communication line 11.
[0059] The communication I / F 210 includes a processing circuit (not shown) for executing processing of frames (messages) to be transmitted and received.
[0060] The communication I / F 210 supports a partial network function. The above-mentioned processing circuit or processor 201 can interpret a PNC designated as a wake-up target and a PNC designated as a sleep target in an NM message.
[0061] [1-4.PNC] The PNC will now be described. Each of the relay ECU 100, ECUs 200A, 200B, 200C, and 200D (and other ECUs) belongs to at least one PNC. The non-volatile memory 102 of the relay ECU 100 stores a cluster table 108 that associates the relay ECU 100, ECUs 200A, 200B, 200C, and 200D with the PNCs to which the relay ECU 100, ECUs 200A, 200B, 200C, and 200D belong (see FIG. 2).
[0062] A PNC may be defined, for example, for each service provided to a user, the service being executed by one or more ECUs.
[0063] Examples of services executed by multiple ECUs include automatic high beam control of headlights, automatic cruise control, door unlocking, remote control of air conditioning, anti-theft alarm notification, charging of the driving battery (high voltage battery) in an electric vehicle, and charging of the auxiliary battery (low voltage battery) from the driving battery.
[0064] The auto high beam control of the headlights is executed by the headlight ECU that controls the headlights and the ECUs for vehicle operation (engine ECU, brake ECU, etc.). For this reason, the headlight ECU and the ECUs for vehicle operation belong to the same PNC.
[0065] Auto-cruise driving is performed by an ADAS (Advanced Driver-Assistance Systems) ECU, a radar ECU that processes the radar detection results and detects objects outside the vehicle, and an ECU for vehicle driving. Therefore, the ADAS ECU, the radar ECU, and the ECU for vehicle driving belong to the same PNC.
[0066] Door unlocking is performed, for example, by a body ECU that controls the moving parts of the vehicle body (door locks, power windows, door mirrors, etc.) and an authentication ECU that authenticates the code sent from a smart key (key fob). Therefore, the body ECU and the authentication ECU belong to the same PNC.
[0067] Remote control of an air conditioner is performed by, for example, an air conditioner ECU that controls the air conditioner and an engine ECU that controls the engine, and therefore the air conditioner ECU and the engine ECU belong to the same PNC.
[0068] The anti-theft alarm notification is executed, for example, by an alarm ECU that issues an alarm and an exterior communication ECU that communicates with a device outside the vehicle (for example, a server of a security company). For this reason, the alarm ECU and the exterior communication ECU belong to the same PNC.
[0069] Charging of the driving battery is performed by, for example, a charging ECU that controls charging of the driving battery and the auxiliary battery, and a battery management ECU that manages the driving battery. For this reason, the charging ECU and the battery management ECU belong to the same PNC.
[0070] The charging of the auxiliary battery is performed by a charging ECU, a battery management ECU, and a power conversion ECU that controls a DC / DC converter that converts the direct current voltage output from the driving battery. Therefore, the charging ECU, the battery management ECU, and the power conversion ECU belong to the same PNC.
[0071] Some services are executed by one ECU. Therefore, it is possible to configure a PNC that includes only one ECU. Examples of services executed by one ECU include windshield wiper drive, automatic steering adjustment, automatic seat adjustment, etc.
[0072] The wiper drive is performed by the wiper ECU that controls the wipers, so only the wiper ECU belongs to one PNC.
[0073] Automatic adjustment of the steering is performed by the power steering ECU, which controls the power steering. Therefore, only the power steering ECU belongs to one PNC.
[0074] Automatic seat adjustment is performed by the seat ECU that controls the power seat, so only the seat ECU belongs to one PNC.
[0075] Fig. 4 is a diagram showing an example of a cluster table. The cluster table 108 shown in Fig. 4 shows which ECUs among the relay ECU 100, ECUs 200A, 200B, 200C, and 200D belong to two PNCs, PNC1 and PNC2. The number of PNCs in Fig. 4 is an example, and three or more PNCs may be prepared. One PNC may be prepared. In the table, "1" indicates that the corresponding ECU among the relay ECU 100, ECUs 200A, 200B, 200C, and 200D belongs to the PNC in that row, and "0" indicates that the corresponding ECU among the relay ECU 100, ECUs 200A, 200B, 200C, and 200D does not belong to the PNC in that row.
[0076] For example, the relay ECU 100, ECUs 200A, 200B, and 200C belong to PNC 1. The relay ECU 100, ECUs 200A, and 200D belong to PNC 2.
[0077] The cluster table 108 is static information that is pre-stored in the non-volatile memory 102. However, the cluster table 108 may be dynamically created based on an NM message relayed by the relay ECU 100, for example.
[0078] [1-5.ECU status] The states of the ECU 200 include an operating state and a sleep state. The operating state is a state in which the ECU 200 is operating, and is capable of controlling a control target and communicating with the relay ECU 100 and other ECUs 200. The sleep state is a state in which the ECU 200 is stopped except for some functions of the communication I / F 210.
[0079] The NM message includes PN information. The PN information includes a designation of Requested or Released for each PNC. A Request corresponds to waking up a PNC. That is, a PNC for which a Request is designated in an NM message is a PNC to be woken up. A Release corresponds to putting a PNC to sleep. That is, a PNC for which Release is designated in an NM message is a PNC to be put to sleep.
[0080] Fig. 5 is a diagram showing an example of PN information in an NM message. In the example of Fig. 5, "request" is specified for PNC1, "open" is specified for PNC2, "open" is specified for PNC3, and "request" is specified for PNC4. That is, the ECU 200 belonging to PNC1 is a wake-up target, the ECU 200 belonging to PNC2 is a sleep target, the ECU 200 belonging to PNC3 is a sleep target, and the ECU 200 belonging to PNC4 is a wake-up target.
[0081] The ECU 200 that is the transmission source of the NM message broadcasts the NM message. This causes the NM message to be transmitted to all ECUs 200 connected to the network. However, the NM message may be unicast or multicast to the ECUs 200 that are the transmission destinations.
[0082] Fig. 6 is a diagram showing an example of NM message transmission in an in-vehicle system. In Fig. 6, a rectangular frame surrounding the characters "PNC1" indicates an NM message in which "request" is specified for PNC1. A rectangular frame surrounding the characters "PNC2" indicates an NM message in which "request" is specified for PNC2.
[0083] ECU 200C transmits an NM message (hereinafter also referred to as a "first message") with a specified request to PNC1. When relay ECU 100 receives the first message, it transmits the first message from each port. As a result, the first message is transmitted to ECUs 200A, 200B, and 200D. Note that here, a case is described in which the NM message is broadcast. When the NM message is unicast or multicast, the first message is transmitted only from the port connected to ECU 200A belonging to PNC1.
[0084] ECU 200D transmits an NM message (hereinafter also referred to as a "second message") with a specified request to PNC2. When relay ECU 100 receives the second message, it transmits the second message from each port. As a result, the second message is transmitted to ECUs 200A, 200B, and 200C. When the NM message is unicast or multicast, the second message is transmitted only from each port connected to ECU 200A and ECU 200B belonging to PNC2.
[0085] 7 is a state transition diagram of the ECU. The ECU 200 in the sleep state can receive an NM message. That is, the communication I / F 210 of the ECU 200 has a function of receiving an NM message even in the sleep state. When the communication I / F 210 receives an NM message, it refers to the PN information included in the NM message and determines whether a request (wake-up) is specified for the PNC to which the ECU 200 belongs.
[0086] When a PNC request is specified in the NM message, the ECU 200 wakes up, causing the state of the ECU 200 to transition from a sleep state to an operating state.
[0087] When ECU 200 in an operating state receives an NM message specifying a request of the PNC to which the ECU 200 belongs, ECU 200 maintains the operating state.
[0088] When ECU 200 in an operating state does not receive an NM message specifying a request for the PNC to which the ECU belongs for a certain period of time, ECU 200 transitions from the operating state to a sleep state. That is, when ECU 200 in an operating state receives only an NM message specifying the release of the PNC to which the ECU belongs for a certain period of time, or when ECU 200 does not receive an NM message, ECU 200 transitions from the operating state to a sleep state.
[0089] 6, it is assumed that ECUs 200A and 200B are in a sleep state, ECUs 200C and 200D that are the transmission sources of the NM message are in an operating state, and relay ECU 100 that relays the NM message is also in an operating state.
[0090] As shown in FIG. 4, it is assumed that the relay ECU 100, ECUs 200A, and 200C belong to PNC1, and the relay ECU 100, ECUs 200A, 200B, and 200D belong to PNC2.
[0091] When ECU 200A receives the first message specifying a "request" for PNC1, it wakes up. This causes the state of ECU 200A to transition from a sleep state to an operating state. When ECU 200A receives the first message, it determines that the state of PNC1 is an "operating state" and holds information indicating that PNC1 is in the operating state (for example, stores this in non-volatile memory 202). Here, ECU 200A also holds information indicating that PNC2 is in a stopped state.
[0092] On the other hand, ECU 200B, which does not belong to PNC1, maintains the sleep state even when it receives the first message.
[0093] When ECU 200A receives the second message specifying "request" for PNC 2, PNC 2 is already in an operating state and therefore maintains the operating state. When ECU 200A receives the second message, ECU 200A determines that the state of PNC 2 is "operating state" and holds information indicating that PNC 2 is in an operating state. That is, ECU 200A rewrites, for example, information stored in non-volatile memory 202 indicating that PNC 2 is in a stopped state to information indicating that PNC 2 is in an operating state.
[0094] On the other hand, when the ECU 200B belonging to the PNC 2 receives the second message, it wakes up. This causes the state of the ECU 200B to transition from a sleep state to an operating state. When the ECU 200B receives the second message, it determines that the state of the PNC 2 is "operating state" and holds information indicating that the PNC 2 is in the operating state.
[0095] For example, when ECU 200C stops transmitting the first message, ECU 200A measures the elapsed time since it stopped receiving the first message using a built-in timer, and judges whether the measured elapsed time reaches a certain period. When ECU 200A does not receive the first message for the certain period, ECU 200A judges that PNC1 is in a stopped state, and holds information indicating that PNC1 is in a stopped state. That is, ECU 200A rewrites, for example, information indicating that PNC1 is in an operating state, stored in non-volatile memory 202, to information indicating that PNC1 is in a stopped state.
[0096] On the other hand, ECU 200B, which does not belong to PNC1, maintains the operating state even if it does not receive the first message for a certain period of time.
[0097] When ECU 200D stops transmitting the second message, ECU 200A measures the elapsed time since it stopped receiving the second message using a built-in timer, and judges whether the measured elapsed time reaches a certain period. When ECU 200A does not receive the second message for the certain period, ECU 200A judges that PNC 2 is in a stopped state, and holds information indicating that PNC 2 is in a stopped state. That is, ECU 200A rewrites, for example, information indicating that PNC 2 is in an operating state, stored in non-volatile memory 202, to information indicating that PNC 2 is in a stopped state.
[0098] Since both PNC1 and PNC2 to which ECU 200A belongs are in a stopped state, ECU 200A goes to sleep.
[0099] The ECU 200B measures the elapsed time from when the second message was not received by using a built-in timer, and judges whether the measured elapsed time reaches a certain period. If the ECU 200B does not receive the second message for the certain period, the ECU 200B judges that the PNC 2 is in a stopped state, and holds information indicating that the PNC 2 is in a stopped state.
[0100] The only PNC to which ECU 200B belongs is PNC 2, and since PNC 2 is in a stopped state, ECU 200B goes to sleep.
[0101] [1-6. Functions of the relay ECU] FIG. 8 is a functional block diagram illustrating an example of functions of the relay ECU according to the first embodiment.
[0102] The relay ECU 100 has the functions of an abnormality detection unit 120, a determination unit 121, and a control unit 122. The abnormality detection unit 120 is realized by the processor 101 executing an abnormality detection program 106. The determination unit 121 and the control unit 122 are realized by the processor 101 executing a control program 107.
[0103] The abnormality detection unit 120 detects an abnormality in the ECU 200. For example, the abnormality detection unit 120 detects an abnormality in the ECU 200 based on a communication state of the ECU 200 via a network.
[0104] In a specific example, the abnormality detection unit 120 monitors the link state of each of the communication I / Fs 110A, 110B, 110C, and 110D. The abnormality detection unit 120 determines that the ECU 200 corresponding to a communication I / F in a link-up state in the communication I / Fs 110A, 110B, 110C, and 110D is normal. The abnormality detection unit 120 detects a communication I / F in a link-down state in the communication I / Fs 110A, 110B, 110C, and 110D, thereby detecting an abnormality in the ECU 200 corresponding to this communication I / F. For example, when the communication I / F 110A is in a link-down state, the abnormality detection unit 120 detects an abnormality in the ECU 200A.
[0105] In another example, the abnormality detection unit 120 transmits a specific message (hereinafter, also referred to as an "abnormality detection message") from each of the communication I / Fs 110A, 110B, 110C, and 110D. When the ECU 200 receives the abnormality detection message, the ECU 200 returns a response message (Ack). When the abnormality detection unit 120 receives the Ack, the abnormality detection unit 120 determines that the ECU 200 corresponding to the port (communication I / F) that received the Ack is normal. The abnormality detection unit 120 detects a communication I / F that does not receive an Ack among the communication I / Fs 110A, 110B, 110C, and 110D, thereby detecting an abnormality in the ECU 200 corresponding to this communication I / F. For example, when the communication I / F 110A does not receive an Ack, the abnormality detection unit 120 detects an abnormality in the ECU 200A.
[0106] The abnormality detection message may be an echo request of the Internet Control Message Protocol (ICMP), and the response message may be an echo reply.
[0107] The determination unit 121 determines whether the ECU 200 is in a sleep state based on the state of the PNC to which the ECU 200 belongs. That is, the determination unit 121 determines whether the ECU 200 is in a sleep state depending on whether the PNC is in an operating state or a stopped state. More specifically, when a specific PNC is in an operating state, the determination unit 121 determines that the ECU 200 belonging to the specific PNC is in an operating state. When a specific PNC is in a stopped state, the determination unit 121 determines that the ECU 200 belonging to the specific PNC is in a sleep state.
[0108] In a specific example, when the relay ECU 100 belongs to a specific PNC, the determination unit 121 determines whether or not the ECU 200 is in a sleep state based on state information of the PNC held by the relay ECU 100.
[0109] In the example of Fig. 4, the relay ECU 100 belongs to PNC1. Therefore, the relay ECU 100 holds state information indicating the state (operating state or stopped state) of PNC1 as described above. The determination unit 121 determines the states of the ECUs 200A, 200C belonging to PNC1 based on the state information held by the relay ECU 100. That is, when PNC1 is in the operating state, the determination unit 121 determines that the ECUs 200A, 200C are in the operating state. When PNC1 is in the stopped state, the determination unit 121 determines that the ECUs 200A, 200C are in the sleep state.
[0110] 8, in another specific example, when the relay ECU 100 does not belong to a specific PNC, the determination unit 121 determines whether the ECU 200 is in a sleep state based on the state of the PNC specified in the NM message. That is, the determination unit 121 determines whether the ECU 200 belonging to the specific PNC is in an operating state or a sleep state based on whether "request (operating state)" or "release (stopped state)" is specified for the specific PNC in the NM message.
[0111] More specifically, when a "request" is specified for a specific PNC in an NM message, the determination unit 121 determines that the ECU 200 belonging to the specific PNC is in an operating state. When an NM message specifying a "request" for a specific PNC has not been received for a certain period of time, the determination unit 121 determines that the ECU 200 belonging to the specific PNC is in a sleep state.
[0112] In the example of Fig. 4, relay ECU 100 does not belong to PNC2. Determination unit 121 refers to the state specified for PNC2 in the NM message, and determines the states of ECUs 200A, 200B, and 200D that belong to PNC2 based on this state. That is, if "request" is specified for PNC2 in the NM message, determination unit 121 determines that ECUs 200A, 200B, and 200D are in an operating state. If an NM message specifying "request" for PNC2 has not been received for a certain period of time or more, determination unit 121 determines that ECUs 200A, 200B, and 200D are in a sleep state.
[0113] 8, when ECU 200 belongs to the first PNC and the second PNC, for example, the determination unit 121 determines whether ECU 200 is in a sleep state based on the state of the first PNC and the state of the second PNC. Specifically, when at least one of the first PNC and the second PNC is in an operating state, the determination unit 121 determines that ECU 200 belonging to both the first PNC and the second PNC is in an operating state. When both the first PNC and the second PNC are in a stopped state, the determination unit 121 determines that ECU 200 belonging to both the first PNC and the second PNC is in a sleep state.
[0114] 4, the ECU 200A belongs to both PNC1 and PNC2. The determination unit 121 determines that the ECU 200A is in an operating state when at least one of PNC1 and PNC2 is in an operating state. The determination unit 121 determines that the ECU 200A is in a sleep state when both PNC1 and PNC2 are in a stopped state.
[0115] Returning to FIG. 8, for example, the determination unit 121 identifies the PNC to which the ECU 200 belongs by using the cluster table 108. The determination unit 121 determines whether the ECU 200 is in a sleep state or not based on the state of the identified PNC. Specifically, the determination unit 121 identifies that the ECU 200A belongs to PNC1 and PNC2 by referring to the cluster table 108 shown in FIG. 4. Similarly, the determination unit 121 identifies that the ECU 200B belongs to PNC2 by referring to the cluster table 108. The determination unit 121 identifies that the ECU 200C belongs to PNC1 by referring to the cluster table 108. The determination unit 121 identifies that the ECU 200D belongs to PNC2 by referring to the cluster table 108.
[0116] Here, the relay ECU 100 belongs to PNC1. The ECU 200C belonging to PNC1 is in a sleep state when PNC1 is in a stopped state, that is, when an NM message with a "request" specified for PNC1 is not received for a certain period of time or more. On the other hand, the relay ECU 100 does not go to sleep even when PNC1 is in a stopped state, but maintains an operating state. This makes it possible to avoid a situation in which the relay ECU 100 goes to sleep and is unable to detect an abnormality in the ECU 200.
[0117] When ECU 200 is in a sleep state, control unit 122 disables detection of an abnormality by abnormality detection unit 120. Specifically, when an abnormality detection function for one ECU 200 (hereinafter, an ECU of interest is also referred to as a "target ECU") is enabled, control unit 122 disables the abnormality detection function for the target ECU 200 when the target ECU 200 is in a sleep state. When the abnormality detection function for the target ECU 200 is disabled and the target ECU 200 is in an operating state, control unit 122 enables the abnormality detection function for the target ECU 200.
[0118] 9 is a diagram for explaining disabling of the abnormality detection function. For example, consider a case where the abnormality detection functions for ECUs 200A, 200B, 200C, and 200D are all valid. Here, when PNC 2 is stopped, ECUs 200B and 200D belonging to PNC 2 go to sleep. Therefore, determination unit 121 determines that ECUs 200B and 200D are in the sleep state.
[0119] The control unit 122 disables the abnormality detection function for the ECU 200B. Similarly, the control unit 122 disables the abnormality detection function for the ECU 200D. This prevents erroneous detection of abnormalities in the ECUs 200B and 200D.
[0120] Here, when PNC 2 enters an operating state, ECUs 200B and 200D belonging to PNC 2 are woken up, so that determination unit 121 determines that ECUs 200B and 200D are in an operating state.
[0121] The control unit 122 enables the abnormality detection function for the ECU 200B. Similarly, the control unit 122 enables the abnormality detection function for the ECU 200D. This restarts the abnormality detection in the ECUs 200B and 200D.
[0122] [1-7. Operation of relay ECU] Next, the operation of the relay ECU 100 according to the first embodiment will be described.
[0123] The processor 101 can execute the following anomaly detection disabling process and anomaly detection enabling process by the control program 107.
[0124] FIG. 10 is a flowchart illustrating an example of an abnormality detection disabling process by the relay ECU according to the first embodiment.
[0125] The processor 101 determines each ECU 200 as a target ECU. The abnormality detection disabling process is executed for each target ECU. More specifically, the abnormality detection disabling process is executed for each target ECU for which the abnormality detection function is enabled. That is, the abnormality detection disabling process for each target ECU for which the abnormality detection function is enabled is executed in parallel.
[0126] The processor 101 refers to the cluster table 108 and identifies the PNC to which the target ECU 200 belongs (step S101).
[0127] Next, the processor 101 determines whether the relay ECU 100 belongs to the identified PNC (step S102).
[0128] If the relay ECU 100 belongs to the identified PNC (YES in step S102), the processor 101 determines the state of the target ECU 200 based on the state of the PNC held by the relay ECU 100 (step S103). That is, if the state of the PNC held by the relay ECU 100 is an operating state, the processor 101 determines that the target ECU 200 is in an operating state. On the other hand, if the state of the PNC held by the relay ECU 100 is a stopped state, the processor 101 determines that the target ECU 200 is in a sleep state.
[0129] If the relay ECU 100 does not belong to the identified PNC (NO in step S102), the processor 101 refers to the NM message received by the relay ECU 100. The processor 101 judges the state of the target ECU 200 based on the state of the PNC specified in the NM message (step S104). That is, if "request" is specified for the identified PNC in the NM message received by the relay ECU 100, the processor 101 judges that the target ECU 200 is in an operating state. On the other hand, if the relay ECU 100 has not received an NM message in which "request" is specified for the identified PNC for a certain period of time or more, the processor 101 judges that the target ECU 200 is in a sleep state.
[0130] The processor 101 determines whether the target ECU 200 is determined to be in a sleep state or in an operating state in step S103 or S104 (step S105).
[0131] When it is determined that the target ECU 200 is in an operating state (NO in step S105), the abnormality detection disabling process ends. That is, in this case, the enabled state of the abnormality detection function for the target ECU 200 is maintained.
[0132] When it is determined that the target ECU 200 is in the sleep state (YES in step S105), the processor 101 disables the abnormality detection function for the target ECU 200 (step S106). This ends the abnormality detection disabling process.
[0133] FIG. 11 is a flowchart illustrating an example of an abnormality detection validation process by the relay ECU according to the first embodiment.
[0134] The abnormality detection enabling process is executed for each target ECU. More specifically, the abnormality detection enabling process is executed for each target ECU whose abnormality detection function is disabled. That is, the abnormality detection enabling process for each target ECU whose abnormality detection function is disabled is executed in parallel.
[0135] The processor 101 refers to the cluster table 108 and identifies the PNC to which the target ECU 200 belongs (step S201).
[0136] Next, the processor 101 determines whether the relay ECU 100 belongs to the identified PNC (step S202).
[0137] If the relay ECU 100 belongs to the identified PNC (YES in step S202), the processor 101 determines the state of the target ECU 200 based on the state of the PNC held by the relay ECU 100 (step S203). Step S203 is the same process as step S103.
[0138] If the relay ECU 100 does not belong to the identified PNC (NO in step S202), the processor 101 refers to the NM message received by the relay ECU 100. The processor 101 determines the state of the target ECU 200 based on the state of the PNC specified in the NM message (step S204). Step S204 is the same process as step S104.
[0139] The processor 101 determines whether the target ECU 200 is determined to be in a sleep state or in an operating state in step S203 or S204 (step S205).
[0140] When it is determined that the target ECU 200 is in the sleep state (NO in step S205), the abnormality detection enabling process ends. That is, in this case, the disabled state of the abnormality detection function for the target ECU 200 is maintained.
[0141] When it is determined that the target ECU 200 is in an operating state (YES in step S205), the processor 101 enables the abnormality detection function for the target ECU 200 (step S206). This ends the abnormality detection enabling process.
[0142] FIG. 12 is a sequence diagram showing a first example of a procedure for disabling abnormality detection in the in-vehicle system according to the first embodiment.
[0143] 12 shows an example in which, when ECUs 200A, 200B, 200C, and 200D are in an operating state, ECU 200D transmits an NM message specifying "request" to PNC 2. In this example, no NM message specifying "request" is transmitted from any of ECUs 200 to PNC 1.
[0144] The ECU 200D transmits an NM message specifying "request" to the PNC 2 (step S11). The NM message is a broadcast message, and is transmitted to each of the relay ECU 100, and the ECUs 200A, 200B, and 200C.
[0145] ECUs 200A and 200B belonging to PNC 2 maintain their operating state because the received NM message specifies a "request" to PNC 2. ECU 200D, which is the source of the NM message, also maintains its operating state.
[0146] In the NM message transmitted from ECU 200D, "release" is specified for PNC 1. ECU 200C belonging to PNC 1 does not receive an NM message specifying "request" for PNC 1 for a certain period of time or more. Therefore, ECU 200C goes to sleep (step S12).
[0147] The relay ECU 100 also belongs to PNC1 and should be put into sleep mode under normal circumstances. However, since the relay ECU 100 needs to execute the abnormality detection invalidation process, it maintains the operating state regardless of the PN information in the NM message.
[0148] The relay ECU 100 does not receive an NM message specifying a "request" for PNC 1 for a certain period of time or longer. Therefore, the processor 101 of the relay ECU 100 determines that the state of PNC 1 is a "stopped state" and transitions the held state information of PNC 1 from an "operating state" to a "stopped state" (step S13).
[0149] The processor 101 refers to the cluster table 108 and identifies the ECU belonging to PNC1 as the ECU 200C. The processor 101 determines that the state of the identified ECU 200C is the "sleep state" (step S14).
[0150] The processor 101 disables the abnormality detection function for the ECU 200C that is determined to be in the sleep state (step S15).
[0151] The abnormality detection function for the ECUs 200A, 200B, and 200D in the operating state is enabled. Therefore, the relay ECU 100 transmits an abnormality detection message to the ECUs 200A, 200B, and 200D (steps S16, S17, and S18). The ECUs 200A, 200B, and 200D transmit responses to the abnormality detection message to the relay ECU 100 (steps S19, S20, and S21).
[0152] On the other hand, the relay ECU 100 does not transmit an abnormality detection message to the ECU 200C whose abnormality detection function is disabled, thereby making it possible to avoid erroneous detection of an abnormality in the ECU 200C.
[0153] FIG. 13 is a sequence diagram showing a second example of the procedure for disabling abnormality detection in the in-vehicle system according to the first embodiment.
[0154] 13 shows an example in which, when ECUs 200A, 200B, 200C, and 200D are in an operating state, ECU 200C transmits an NM message specifying "request" to PNC 1. In this example, no NM message specifying "request" is transmitted from any of ECUs 200 to PNC 2.
[0155] The ECU 200C transmits an NM message specifying a "request" to the PNC 1 (step S21). The NM message is a broadcast message, and is transmitted to each of the relay ECU 100, and the ECUs 200A, 200B, and 200C.
[0156] ECU 200A belonging to PNC 1 maintains the operating state because the received NM message specifies a "request" to PNC 1. ECU 200C, the source of the NM message, also maintains the operating state.
[0157] The relay ECU 100 also belongs to PNC 1. However, since the relay ECU 100 needs to execute the abnormality detection disabling process, the relay ECU 100 maintains an operating state regardless of the PN information in the NM message.
[0158] In the NM message transmitted from ECU 200C, "release" is specified for PNC 2. ECUs 200B and 200D belonging to PNC 2 do not receive an NM message specifying "request" for PNC 2 for a certain period of time or more. Therefore, ECUs 200B and 200D go to sleep (steps S22 and S23).
[0159] The relay ECU 100 does not receive, for a certain period of time or longer, an NM message in which a "request" is specified for the PNC 2. Therefore, the processor 101 of the relay ECU 100 determines that the state of the PNC 2 is "stopped state" (step S24).
[0160] The processor 101 refers to the cluster table 108 and identifies that the ECUs belonging to PNC2 are ECUs 200B and 200D. The processor 101 determines that the states of the identified ECUs 200B and 200D are "sleep state" (step S25).
[0161] The processor 101 disables the abnormality detection functions for the ECUs 200B, 200D that are determined to be in the sleep state (step S26).
[0162] The abnormality detection function for the ECUs 200A and 200C in the operating state is valid. Therefore, the relay ECU 100 transmits an abnormality detection message to the ECUs 200A and 200C (steps S27 and S28). The ECUs 200A and 200C transmit responses to the abnormality detection message to the relay ECU 100 (steps S29 and S30).
[0163] On the other hand, the relay ECU 100 does not transmit an abnormality detection message to the ECUs 200B and 200D for which the abnormality detection function is disabled, thereby making it possible to avoid erroneous detection of an abnormality in the ECUs 200B and 200D.
[0164] [2. Second embodiment] In the first embodiment, the relay ECU 100 is an Ethernet switch. However, the relay ECU is not limited to an Ethernet switch. For example, the relay ECU may be a relay device that relays a CAN (Controller Area Network) message.
[0165] FIG. 14 is a block diagram showing an example of the configuration of an in-vehicle system according to the second embodiment.
[0166] The in-vehicle system 20 includes the relay ECU 300 and ECUs 400A, 400B, 400C, and 400D. The in-vehicle system 20 is an in-vehicle network configured by the relay ECU 300, the ECUs 400A, 400B, 400C, and 400D, and communication buses 21A and 21B connecting them. In other words, the in-vehicle system 20 is a CAN network having a bus-type network topology.
[0167] Specifically, the ECUs 400A and 400B are connected to a communication bus 21A. The ECUs 400C and 400D are connected to a communication bus 21B. The relay ECU 300 is connected to each of the communication buses 21A and 21B. A communication bus 22 extends from the relay ECU 300. The relay ECU 300 is connected to an in-vehicle device (not shown) (e.g., a relay ECU or an ECU) via the communication bus 22.
[0168] The relay ECU 300 and the ECUs 400A, 400B, 400C, and 400D each include a communication I / F that complies with CAN. The relay ECU 300 relays communications between the ECUs 400A and 400B and the ECUs 400C and 400D. That is, the relay ECU 300 relays CAN frames (messages) between the ECUs 200A and 200B and the ECUs 200C and 200D.
[0169] The relay ECU 300 and the ECUs 400A, 400B, 400C, and 400D can transmit and receive NM messages for partial networks. The NM messages are CAN frames that are periodically transmitted.
[0170] In this modification, the relay ECU 300 transmits a CAN message, which is an abnormality detection message, to each of the communication buses 21A and 21B. When the ECUs 400A, 400B, 400C, and 400D receive the abnormality detection message, they transmit a response message to the communication buses 21A and 21B. For example, the response message includes the CAN ID of the source ECU 400A, 40B, 400C, and 400D. By receiving the response message, the relay ECU 300 determines that the source ECU 400A, 40B, 400C, and 400D identified by the CAN ID is normal. When any ECU among the ECUs 400A, 40B, 400C, and 400D does not transmit a response message, the relay ECU 300 detects an abnormality in the ECU that does not transmit a response message.
[0171] The relay ECU 300 determines whether each of the ECUs 400A, 400B, 400C, and 400D is in a sleep state. The relay ECU 300 disables the abnormality detection function for the ECU determined to be in a sleep state. The disablement and enablement of the abnormality detection function are similar to those in the first embodiment described above.
[0172] [3. Modifications] In the first and second embodiments described above, the relay ECUs 100 and 300 that relay communication between ECUs have an abnormality detection function, and when an ECU is in a sleep state, the abnormality detection function for the ECU in the sleep state is disabled, but this is not limited to the above. For example, an ECU connected to one communication bus may have an abnormality detection function for an ECU connected to the same communication bus, and when an ECU connected to the same communication bus is in a sleep state, the abnormality detection function for the ECU in the sleep state may be disabled.
[0173] For example, consider a case where ECU 200B is a device (vehicle control device) having an abnormality detection function. ECU 200B can detect an abnormality in ECU 200A connected to the same communication bus 400A. Here, referring to FIG. 4, ECU 200B belongs to PNC2, but does not belong to PNC1. Similarly, ECU 200D belongs to PNC2, but does not belong to PNC1. ECU 200D is in a sleep state when PNC2 is in a stopped state, that is, when an NM message with a "request" specified for PNC2 is not received for a certain period of time or more. On the other hand, ECU 200B does not sleep even when PNC2 is in a stopped state, but maintains an operating state. This makes it possible to avoid a situation where ECU 200B goes to sleep and is unable to detect an abnormality in ECU 200A. Note that not only ECU 200B but also ECUs 200A, 200C, and 200D may be vehicle control devices having an abnormality detection function. When the ECUs 200A, 200B, 200C, and 200D are in-vehicle control devices, the relay ECU 300 may be an in-vehicle device that does not have an abnormality detection function.
[0174] In the first embodiment, the detection of an abnormality in an in-vehicle network conforming to Ethernet and the invalidation of the abnormality are described, and in the second embodiment, the detection of an abnormality in an in-vehicle network conforming to CAN are described, but the present invention is not limited to these. Any communication protocol other than Ethernet and CAN may be used as long as it is compatible with partial networks. For example, the detection of an abnormality in an ECU and the invalidation of the abnormality may be realized in an in-vehicle network conforming to FlexRay.
[0175] [4. Additional Notes] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is defined by the claims rather than the above-described embodiments, and includes the meaning equivalent to the claims and all modifications within the scope thereof. [Explanation of symbols]
[0176] 10,20 In-vehicle systems 11A,11B,11C,11D,12 Communication line 100,300 Relay ECU (on-board control device, on-board device) 101 Processor 102 Non-volatile memory 103 Volatile Memory 104 Peripheral Circuits 105 Input / Output Interface (I / O) 106 Anomaly Detection Program 107 Control Program 108 Cluster Table 110A, 110B, 110C, 110D Communication interface (communication I / F) 111A, 111B, 111C, 111D PHY 115 Microcontrollers 120 Abnormality detection unit 121 Judgment section 122 Control section 200,200A,200B,200C,200D ECU (vehicle equipment) 201 Processor 202 Non-volatile memory 203 Volatile Memory 204 Peripheral Circuits 205 Input / Output Interface (I / O) 206 Application Program (APP) 220 Microcontroller 21A, 21B, 22 Communication bus 400A, 400B, 400C, 400D ECU (on-board device, on-board control device)
Claims
1. An in-vehicle control device connected via a network to an in-vehicle device capable of switching between an operating state and a sleep state, an abnormality detection unit that detects an abnormality in the in-vehicle device; a determination unit that determines whether the in-vehicle device is in a sleep state based on a state of a cluster to which the in-vehicle device belongs; a control unit that disables detection of an abnormality by the abnormality detection unit when the in-vehicle device is in a sleep state; Equipped with In-vehicle control device.
2. the determination unit, when the in-vehicle control device belongs to the cluster, determines whether the in-vehicle device is in a sleep state based on a state of the cluster held by the in-vehicle control device; The vehicle-mounted control device according to claim 1 .
3. the determination unit, when the in-vehicle control device does not belong to the cluster, determines whether or not the in-vehicle device is in a sleep state based on a state of the cluster specified in a control message transmitted through the network to control the cluster; The vehicle-mounted control device according to claim 1 .
4. When the in-vehicle device belongs to a first cluster and a second cluster, the determination unit determines whether the in-vehicle device is in a sleep state based on a state of the first cluster and a state of the second cluster. The vehicle-mounted control device according to claim 1 .
5. the determination unit identifies a cluster to which the in-vehicle device belongs using a table showing a correspondence relationship between clusters and in-vehicle devices, and determines whether the in-vehicle device is in a sleep state based on a state of the identified cluster. The vehicle-mounted control device according to claim 1 .
6. the cluster state includes an operational state and a stopped state; the determination unit determines that the in-vehicle device is in a sleep state when the state of the cluster is a stopped state. The vehicle-mounted control device according to claim 1 .
7. The abnormality detection unit detects an abnormality in the in-vehicle device based on a communication state of the in-vehicle device through the network. The vehicle-mounted control device according to claim 1 .
8. When the in-vehicle control device belongs to the cluster and the cluster is in the stopped state, the in-vehicle control device maintains an operating state. The on-vehicle control device according to any one of claims 1 to 7.
9. A control method used by an in-vehicle control device connected via a network to an in-vehicle device capable of switching between an operating state and a sleep state, comprising: determining whether the in-vehicle device is in a sleep state based on a state of a cluster to which the in-vehicle device belongs; disabling an anomaly detection function that detects an anomaly in the in-vehicle device when the in-vehicle device is in a sleep state; Including, Control methods.
10. A control program executed by an in-vehicle control device connected via a network to an in-vehicle device capable of switching between an operating state and a sleep state, On the computer, determining whether the in-vehicle device is in a sleep state based on a state of a cluster to which the in-vehicle device belongs; disabling an anomaly detection function that detects an anomaly in the in-vehicle device when the in-vehicle device is in a sleep state; In order to execute Control program.