Program verification device
The program verification device in the in-vehicle electronic control units checks the monitoring function of the third-level program, addressing the lack of verification in existing techniques and ensuring the functional safety of the control units.
Patent Information
- Application Number
- JP2023189472
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-05-19
AI Technical Summary
Existing techniques do not adequately verify whether a third-level program stored in in-vehicle electronic control units is functioning correctly to execute its monitoring functions.
A program verification device is configured with a control unit, first and second monitoring units, and a storage device, which includes a program storage unit, an abnormality setting unit, and a function verification unit. This device checks if the second monitoring function determines the first monitoring function to be normal or abnormal, thereby verifying the monitoring function of the third-level program.
The solution effectively checks the normal execution of the monitoring function of the third-level program, ensuring the functional safety of the electronic control unit by confirming the correctness of the monitoring processes.
Smart Images

Figure 2025077352000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a technique for checking the functions of programs stored in in-vehicle electronic control units.
Background Art
[0002] In in-vehicle electronic control units, as described in Patent Document 1 below, a technique is known in which a second-level program monitors the functions of a first-level program that controls an in-vehicle control target, and a third-level program monitors the functions of the second-level program. With this technique, the functional safety of the electronic control unit is realized with a three-level configuration.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When the third-level program is stored and updated by version update or the like, a technique for determining whether the program is normally stored by data check or the like has been conventionally known.
[0005] However, as a result of the inventors' detailed examination, it has been found that there is a problem that determining whether a normally stored third-level program normally executes a monitoring function has not been conventionally performed, including the technique described in Patent Document 1.
[0006] One aspect of the present disclosure is to provide a technique for checking whether a stored third-level program normally executes a monitoring function.
Means for Solving the Problems
[0007] A program verification device according to one aspect of the present disclosure includes a control unit (22) configured to control a control target of a vehicle by executing a program at a first level (50), and a program at a second level (52). A first monitoring unit (24) configured to execute a first monitoring function for determining whether the control function for the control unit to control the control target is normal or abnormal, and a program at a third level (54). A second monitoring unit (26) configured to execute a second monitoring function for determining whether the first monitoring function by the first monitoring unit is normal or abnormal, and a third level stored in a storage device (30) of an in-vehicle electronic control device (10) including: A vehicle-mounted program verification device (60) for verifying whether the second monitoring function by the program (32, 34) is normal or abnormal, comprising a program storage unit (62), an abnormality setting unit (64, S2), and a function verification unit (66, S4 to S7).
[0008] The program storage unit stores the third-level program in the current target storage area among the first storage area and the second storage area of the electronic control device. When the program storage unit stores the third-level program in the current target storage area, the abnormality setting unit sets abnormal data for which the monitoring result of the first monitoring function by the first monitoring unit becomes abnormal in the electronic control device.
[0009] The function verification unit checks whether the second monitoring unit determines that the monitoring result of the first monitoring function by the first monitoring unit is abnormal with respect to the abnormal data set by the abnormality setting unit. According to such a configuration, it is possible to check whether the monitoring function of the third-level program stored in the electronic control device is normal.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Mode for Carrying Out the Invention
[0011] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. [1. Configuration] The in-vehicle system 2 shown in FIG. 1 includes an actuator drive IC 4, an electronic control unit 10, and a program verification device 60. Hereinafter, the electronic control unit is also referred to as an ECU. The in-vehicle system 2 may be mounted on a vehicle having any one of an internal combustion engine, a motor, or an internal combustion engine and a motor as a drive source for driving the vehicle. Hereinafter, the internal combustion engine is also referred to as an engine.
[0012] When the vehicle includes an engine and a motor, the engine may be for charging a battery that supplies power to the motor. Further, the drive system may be configured to supply power generated by a fuel cell to the motor.
[0013] The ECU 10 controls, for example, the operation of a throttle device (not shown) that adjusts the intake air amount to the engine of the vehicle. Note that even when the start switch for starting the drive system of the vehicle is turned off and the power supply to other in-vehicle devices is cut off, power is supplied from the battery to the ECU 10 and the program verification device 60.
[0014] The ECU 10 adjusts, for example, the opening degree of a throttle valve of the throttle device, which is a control target, by outputting a control signal to an actuator drive IC 4 that drives a motor of the throttle device.
[0015] The ECU 10 includes a microcomputer 20 for controlling the throttle device and a monitoring IC 40 for monitoring the operation of the microcomputer 20. The microcomputer is an abbreviation for a microcomputer. In FIG. 1, one microcomputer 20 is shown, but there may be a plurality of microcomputers 20.
[0016] The microcomputer 20 includes a CPU (not shown), storage devices such as a ROM, a RAM, and a flash memory, an input / output interface, and the like. The microcomputer 20 inputs various data from sensors and the like, for example, the opening degree of the throttle valve of the throttle device, the operation position of the vehicle's accelerator pedal, the fuel injection amount, and the like.
[0017] The microcomputer 20 includes a torque control unit 22, a torque monitor unit 24, and a monitoring unit 26. The torque control unit 22 executes a program at the first level 50, the torque monitor unit 24 executes a program at the second level 52, and the monitoring unit 26 executes a program at the third level 54.
[0018] By executing the program at the first level 50, the torque control unit 22 calculates the target throttle opening degree of the throttle valve from the accelerator operation amount. Then, the torque control unit 22 executes a control function of outputting a control signal to the actuator drive IC4 so that the actual throttle opening degree becomes the target throttle opening degree.
[0019] The torque monitor unit 24 executes the first monitoring function shown in the following (1) to (3) according to the program at the second level 52. (1) Calculate the allowable torque, which is the maximum value of the engine's output torque, from the accelerator operation amount.
[0020] (2) Calculate the estimated torque, which is an estimated value of the torque currently generated by the engine, from the throttle opening degree. (3) Compare the calculated allowable torque and the estimated torque, and determine, for example, whether the estimated torque is greater than the allowable torque by a predetermined value or more. When the estimated torque is greater than the allowable torque by a predetermined value or more, the torque monitor unit 24 determines that the control function of the throttle valve by the torque control unit 22 is abnormal. In this case, the torque monitor unit 24 outputs to the monitoring unit 26 that the control function of the torque control unit 22 is abnormal.
[0021] The monitoring unit 26 executes a second monitoring function to determine whether the first monitoring function by the torque monitoring unit 24 is normal or abnormal by executing a program at the third level 54. When the monitoring unit 26 is notified from the torque monitoring unit 24 that the control function of the torque control unit 22 is abnormal, the monitoring unit 26 outputs a cutoff signal for cutting off the drive of the throttle device to the actuator drive IC 4.
[0022] Also, the monitoring unit 26 sets test data for function monitoring in the torque monitoring unit 24 at each predetermined test timing during vehicle travel, and determines whether the first monitoring function by the torque monitoring unit 24 is normal or abnormal.
[0023] Normally, sensor data such as the accelerator operation amount and throttle opening detected by a sensor is input to the torque monitoring unit 24 as input data used for calculating the aforementioned allowable torque and estimated torque.
[0024] At the test timing, the monitoring unit 26 switches the input data so that the torque monitoring unit 24 inputs test data instead of sensor data. Then, the monitoring unit 26 compares the calculation result by the torque monitoring unit 24 when the torque monitoring unit 24 inputs test data with the expected value of the calculation result. The test data and the corresponding expected value are stored in advance in a ROM or the like, and corresponding ones are selected.
[0025] As test data, normal data for which it is normal that the comparison result between the calculation result by the torque monitoring unit 24 and its expected value matches, and abnormal data for which it is normal that they do not match are input to the torque monitoring unit 24, respectively.
[0026] The monitoring unit 26 outputs the respective comparison results to the monitoring IC 40 when the torque monitoring unit 24 inputs normal data and abnormal data at the test timing. In this way, the torque monitor unit 24 at the second level 52 monitors the control function of the torque control unit 22 at the first level 50 that controls the in-vehicle control target, and the monitoring unit 26 that is part of the third level 54 monitors the monitoring function of the torque monitor unit 24 at the second level 52. With such a three-level configuration, the functional safety of the ECU 10 is realized.
[0027] The monitoring IC 40 realizes the functional safety of the third level 54 together with the monitoring unit 26 in the ECU 10. The monitoring IC 40 determines the respective comparison results by the monitoring unit 26 when the torque monitor unit 24 inputs normal data and abnormal data as test data. When there is a comparison result that is not expected in the respective comparison results by the monitoring unit 26, the monitoring IC 40 determines that it is an abnormality of the microcomputer 20. In this case, the monitoring IC 40 outputs a cutoff signal to the actuator drive IC 4.
[0028] For example, when the torque monitor unit 24 inputs normal data as test data and the monitoring unit 26 outputs a mismatch as the comparison result, the monitoring IC 40 determines that it is an abnormality of the microcomputer 20 and outputs a cutoff signal to the actuator drive IC 4.
[0029] Alternatively, when the torque monitor unit 24 inputs abnormal data as test data and the monitoring unit 26 outputs a match as the comparison result, the monitoring IC 40 determines that it is an abnormality of the microcomputer 20 and outputs a cutoff signal to the actuator drive IC 4.
[0030] In addition, when the count value of a watchdog timer (not shown) provided in the microcomputer 20 exceeds a predetermined value without being initialized due to an abnormality of the microcomputer 20, the monitoring IC 40 outputs a cutoff signal to the actuator drive IC 4.
[0031] The program verification device 60 is configured mainly by one or more microcomputers including a CPU, a RAM, a ROM, an input / output interface, and the like. The program verification device 60 includes a program storage unit 62, an abnormality setting unit 64, and a function verification unit 66. By the CPU of the program verification device 60 executing a program stored in a non-transitory tangible recording medium such as a ROM, the respective functions of the program storage unit 62, the abnormality setting unit 64, and the function verification unit 66 are realized.
[0032] As shown in FIG. 2, the program storage unit 62 stores and updates a program 34 of the third level 54 of the new version that upgrades the program 32 of the third level 54 of the old version currently in use in the storage device 30 of the microcomputer 20. The storage device 30 is a rewritable non-volatile storage device such as a flash memory.
[0033] The program 34 of the third level 54 of the new version is stored in the current target storage area, which is not the storage area where the program 32 of the third level 54 of the old version is stored, among the first storage area and the second storage area of the storage device 30.
[0034] Hereinafter, the program 32 of the third level 54 of the old version is also simply referred to as the old third program 32, and the program 34 of the third level 54 of the new version is also simply referred to as the new third program 34.
[0035] The program storage unit 62 downloads and acquires the new third program 34 from the server during the running of the vehicle by OTA (Over the Air for example), and stores it in the storage device 30.
[0036] In addition, when a new third program 34 that upgrades the newly stored new third program 34 is stored, the storage area where the current old third program 32 is stored becomes the storage area where the new third program 34 is to be stored next.
[0037] The storage device 30 is composed of two sides, a storage area for storing the currently used old third program 32 and a storage area for storing the new third program 34. The abnormality setting unit 64 instructs the monitoring unit 26 to set, for example, abnormal data indicating that the monitoring result by the first monitoring function of the torque monitoring unit 24 is abnormal in the torque monitoring unit 24 at the second level 52.
[0038] For example, the abnormality setting unit 64 sets, as abnormal data, data for which it is normal that the comparison result between the calculation result by the torque monitoring unit 24 and its expected value does not match, like the above-described test data, in the torque monitoring unit 24.
[0039] The function determination unit 56 checks whether the version of the new third program 34 is the version to be updated this time until the stored new third program 34 is executed next time. Further, the function determination unit 56 determines whether the second monitoring function by the new third program 34 is normal or abnormal until the stored new third program 34 is executed next time.
[0040] The function determination unit 56 determines whether the new third program 34 functions properly based on whether the monitoring unit 26 determines that the first monitoring function of the torque monitoring unit 24 is abnormal with respect to the above-described abnormal data set in the torque monitoring unit 24.
[0041] For example, when the monitoring unit 26 determines that the torque monitoring unit 24 is abnormal with respect to the abnormal data set in the torque monitoring unit 24 and outputs a cutoff signal to the actuator drive IC 4, the function determination unit 56 determines that the new third program 34 functions properly.
[0042] On the other hand, when the monitoring unit 26 does not output a cutoff signal with respect to the abnormal data set in the torque monitoring unit 24, the function determination unit 56 determines that the new third program 34 does not function properly.
[0043] [2. Processing] Next, the monitoring process executed by the program verification device 60 will be described with reference to the sequence diagram of FIG. 3. The monitoring process shown in FIG. 3 is executed by the ECU 10 and the program verification device 60, for example, after the start switch of the drive system is turned off and power is no longer supplied to other in-vehicle devices, until the start switch is turned on next.
[0044] In S1, the function verification unit 66 checks the version of the stored new third program 34. In S2, the function verification unit 66 instructs the monitoring unit 26 to set the above-described abnormal data in the torque monitor unit 24 so that the monitoring result by the torque monitor unit 24 becomes abnormal.
[0045] In S3, the monitoring unit 26 executes the monitoring function for the torque monitor unit 24 according to the new third program 34. In S4, the function verification unit 66 monitors the monitoring function of the monitoring unit 26 for the torque monitor unit 24 according to the new third program 34.
[0046] If the monitoring result of the monitoring unit 26 for the torque monitor unit 24 is abnormal, it is determined that the new third program 34 is functioning normally. In S5, as shown in FIG. 2, the function verification unit 66 activates the new third program 34 and causes the new third program 34 to be executed.
[0047] If the monitoring result by the monitoring function of the monitoring unit 26 is normal, it is determined that the new third program 34 is not functioning normally. In S6, as shown in FIG. 2, the function verification unit 66 activates the old third program 32 and causes the old third program 32 to be executed.
[0048] Then, in S7, since the function verification unit 66 determines that the new third program 34 is not functioning normally, it notifies, via a display or voice, etc., that the new third program 34 is to be acquired from the server again and stored.
[0049] In the present embodiment described above, the torque control unit 22 corresponds to the control unit, the torque monitor unit 24 corresponds to the first monitoring unit, and the monitoring unit 26 corresponds to the second monitoring unit. Also, S2 corresponds to the process of the abnormality setting unit 64, and S4 to S7 correspond to the processes of the function confirmation unit.
[0050] [3. Effects] According to the present embodiment described above, the following effects can be obtained. (3a) When the stored new third program 34 functions normally, activate the new third program 34. On the contrary, when the stored new third program 34 does not function normally, activate the old third program 32. Thereby, the functional safety of the ECU 10 is realized by the new third program 34 or the old third program 32 that functions normally.
[0051] (3b) When the new third program 34 does not function normally, reinstall the new third program 34, so that the functional safety of the ECU 10 is realized using the new third program 34 as much as possible.
[0052] [4. Other Embodiments] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the foregoing embodiments and can be implemented with various modifications.
[0053] (4a) In the foregoing embodiment, the monitoring process in FIG. 3 is executed while the start switch of the drive system is off and then on again, but it is not limited thereto.
[0054] For example, the monitoring process in FIG. 3 may be executed while the start switch of the drive system is off and power supply to other in-vehicle devices is cut off. Also, the monitoring process in FIG. 3 may be executed after the start switch of the drive system is turned on and before the processing by other in-vehicle devices is executed.
[0055] (4b) In the above-described embodiment, the new third program 34 is stored in the storage device 30 of the ECU 10 by OTA during the running of the vehicle, but it is not limited thereto. For example, the new third program 34 may be stored in the storage device 30 of the ECU 10 by an external tool connected to the vehicle at a dealer or the like. Then, at the dealer, it is determined whether the monitoring function by the new third program 34 is normal or abnormal.
[0056] Alternatively, the new third program 34 may be stored in the storage device 30 of the ECU 10 by the vehicle manufacturer at the time of vehicle shipment. Then, at the vehicle manufacturer, it is determined whether the monitoring function by the new third program 34 is normal or abnormal.
[0057] (4c) In the above-described embodiment, an example in which the ECU 10 controls the intake air amount of the throttle device in a drive system including an engine has been described. In contrast, the ECU 10 may control a drive system that supplies power from a battery or a fuel cell to a motor.
[0058] (4d) The program confirmation device 60 and its method described in the present disclosure may be realized by a dedicated computer provided by configuring a processor and a memory programmed to execute one or more functions embodied by a computer program.
[0059] Alternatively, the program confirmation device 60 and its method described in the present disclosure may be realized by a dedicated computer provided by configuring a processor by one or more dedicated hardware logic circuits.
[0060] Or, the program confirmation device 60 and its method described in the present disclosure may be realized by one or more dedicated computers configured by a combination of a processor and a memory programmed to execute one or more functions and a processor configured by one or more hardware logic circuits.
[0061] In addition, the computer program may be stored in a non-transitory tangible recording medium readable by a computer as instructions executed by the computer. The method for realizing the functions of each part included in the program verification device 60 does not necessarily require the inclusion of a program, and all of its functions may be realized using one or more pieces of hardware.
[0062] (4e) A plurality of functions of one component in the above-described embodiments may be realized by a plurality of components, or one function of one component may be realized by a plurality of components. Further, a plurality of functions of a plurality of components may be realized by one component, or one function realized by a plurality of components may be realized by one component. Also, a part of the configuration of the above-described embodiments may be omitted. Further, at least a part of the configuration of the above-described embodiments may be added to or replaced with the configuration of other above-described embodiments.
[0063] (4f) In addition to the above-described program verification device 60, the present disclosure can also be realized in various forms such as a system including the program verification device 60 as a component, a program for causing a computer to function as the program verification device 60, a non-transitory tangible recording medium such as a semiconductor memory storing this program, and a program verification method.
Description of Reference Numerals
[0064] 10: ECU (Electronic Control Unit), 22: Torque Control Unit (Control Unit), 24: Torque Determination Unit (First Monitoring Unit), 26: Monitoring Unit (Second Monitoring Unit), 30: Storage Device, 60: Program Verification Device, 62: Program Storage Unit, 64: Abnormality Setting Unit, 66: Function Verification Unit
Claims
1. A control unit (22) configured to control a control target of a vehicle by executing a program of a first level (50); a first monitoring unit (24) configured to execute a first monitoring function of determining whether a control function of the control unit to control the controlled object is normal or abnormal by executing a program of a second level (52); a second monitoring unit (26) configured to execute a second monitoring function of determining whether the first monitoring function by the first monitoring unit is normal or abnormal by executing a third level (54) program; An on-board program confirmation device (60) for confirming whether the second monitoring function by the third level program (32, 34) stored in a storage device (30) of an on-board electronic control device (10) is normal or abnormal, the storage device comprises a first storage area and a second storage area; a program storage unit (62) configured to store the third level program in a current target storage area out of the first storage area and the second storage area; an abnormality setting unit (64, S2) configured to set, in the electronic control device, abnormality data that indicates an abnormality in the monitoring result of the first monitoring function by the first monitoring unit when the program storage unit stores the third level program in the current target storage area; a function confirmation unit (66, S4 to S7) configured to confirm whether or not the second monitoring unit determines that the monitoring result of the first monitoring function by the first monitoring unit is abnormal with respect to the abnormality data set by the abnormality setting unit; A program verification device comprising:
2. 2. The program confirmation device according to claim 1, The program storage unit is configured to acquire the third level program to be stored in the current target memory area by OTA. Program verification device.
3. 2. The program confirmation device according to claim 1, The function confirmation unit (S7) is configured to notify that the program storage unit will store the third level program again in the current target storage area when the second monitoring unit determines that the monitoring result of the first monitoring function by the first monitoring unit is normal for the abnormal data set by the abnormality setting unit. Program verification device.
4. 2. The program confirmation device according to claim 1, the function confirmation unit is configured to confirm whether or not the second monitoring unit determines that the monitoring result of the first monitoring function by the first monitoring unit is abnormal for the abnormal data set by the abnormality setting unit during the period from when the program storage unit stores the third level program in the current target storage area until when the third level program stored in the current target storage area is executed. Program verification device.
5. 5. A program confirmation device according to claim 4, The function confirmation unit is configured to confirm whether or not the second monitoring unit determines that the monitoring result of the first monitoring function by the first monitoring unit is abnormal based on the abnormality data set by the abnormality setting unit during the period from when the program storage unit stores the third level program in the current target memory area until a start switch for starting a drive system of the vehicle is turned off and the start switch is next turned on to execute the third level program stored in the current target memory area. Program verification device.
Citation Information
Patent Citations
Vehicular electronic controller
JP2015108944A