Electronic control device and program

The electronic control device addresses system main relay issues and diagnostic storage concerns by suppressing parked services during data rewriting, ensuring seamless operation and convenience.

JP2025136023AActive Publication Date: 2025-09-19TOYOTA JIDOSHA KK
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2024034178
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-06
Publication Date
2025-09-19
Estimated Expiration
2044-03-06

AI Technical Summary

Technical Problem

Existing vehicle control systems face challenges in ensuring the convenience of parked services while performing over-the-air data rewriting operations, as they may result in system main relay issues and diagnostic information storage concerns.

Method used

An electronic control device that executes parking services using a specific function of the vehicle while the ignition is off, and can receive activation information indicating that another electronic control device is ready to perform an activation process, suppressing the execution of parking services during data rewriting operations.

Benefits of technology

Ensures the convenience of parked services by eliminating concerns about diagnostic data storage during over-the-air data rewriting operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025136023000001_ABST
    Figure 2025136023000001_ABST
Patent Text Reader

Abstract

To ensure the convenience of services during parking while eliminating concerns about diagnostic memory in the case that data rewriting operation by an OTA and execution of services during parking coexist.SOLUTION: An electronic control device for executing services during parking by using a specific function of a vehicle while ignition of a vehicle is off can receive activate information showing the completion of processing preparation of another electronic control device which performs activate processing for writing update object information including a program or data acquired from an external device in a nonvolatile memory mounted on the vehicle to validate the update object information due to refusal to use the specific function, and suppresses execution of the services during parking in the case of receiving the activate information.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an electronic control device and a program. [Background technology]

[0002] In recent years, with the diversification of vehicle control, such as driving assistance functions and autonomous driving functions, the scale of programs for vehicle control, diagnosis, and the like installed in vehicle electronic control units (hereinafter also referred to as ECUs (Electronic Control Units)) is increasing. Furthermore, with version upgrades for functional improvements and the like, opportunities to reprogram (reprogram) ECUs are also increasing. Meanwhile, with the advancement of communication networks, connected car technology is also becoming widespread. Given these circumstances, for example, Patent Document 1 proposes a technology for over-the-air (OTA) reprogramming of ECUs by providing a vehicle master device as a relay device on the vehicle side, distributing update data received wirelessly from a center device to the ECUs to be reprogrammed, and instructing the ECUs to write the update data. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-27640 Summary of the Invention [Problem to be solved by the invention]

[0004] Patent Document 1 describes an ECU with multiple data storage surfaces as a rewrite target ECU. For example, in a rewrite target ECU with two surfaces, surface A and surface B, update data for a new program is written to surface B, surface B with the updated data for the new program written thereto is switched from a non-operational surface to an operational surface, and surface B, which has been switched from the non-operational surface to the operational surface, is started, and the new program is executed.

[0005] The purpose of Patent Document 1 is to properly complete program rewriting in a configuration having multiple data storage surfaces. The invention described in Patent Document 1 is configured to install the software while the vehicle is in motion or parked, and activate it while the vehicle is parked. This configuration makes it possible to properly complete program rewriting in a configuration having multiple data storage surfaces.

[0006] In addition to data rewriting via OTA, there may also be a need to execute parking services that require system operation while the vehicle is parked. However, with the technology described in Patent Document 1, under certain conditions, it may be necessary to refuse to hold the system main relay when the ignition is switched from off to on. For example, if the ECU to be reprogrammed is a battery ECU and an OTA reprogramming process is performed to switch the vehicle's phase, the system main relay is forcibly shut off, raising concerns about the system main relay becoming stuck. To resolve this concern, the battery ECU is forced to refuse to hold the system main relay. If the ECU to be reprogrammed is forced to refuse to hold the system main relay, attempting to execute a parking service under such circumstances would result in the system main relay's request to hold the system main relay being rejected, raising concerns about diagnostic information being stored. If the concern about diagnostic information being stored were to be resolved by unconditionally refusing to execute parking services when data reprogramming via OTA is performed, the system operation request from the parking service would not be met at all, resulting in a loss of convenience.

[0007] The present disclosure aims to ensure the convenience of parked services while eliminating concerns about diagnostic storage when OTA data rewriting operations and execution of parked services coexist. [Means for solving the problem]

[0008] The present disclosure relates to an electronic control device that executes a parking service using a specific function of the vehicle while the vehicle ignition is off, and that can receive activation information indicating that another electronic control device that performs an activation process, which writes update target information including a program or data acquired from an external device into a non-volatile memory mounted on the vehicle and activates the update target information, while refusing to use the specific function, is ready to process the activation process, and when the activation information is received, the execution of the parking service is suppressed. The present disclosure also applies to a program that causes the electronic control device to realize a similar function. [Effects of the Invention]

[0009] According to the present disclosure, when an OTA data rewriting operation and the execution of a parked service coexist, it is possible to ensure the convenience of the parked service while eliminating concerns about diagnostic data storage. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram for explaining the configuration of an electronic control system including an electronic control device according to this embodiment. [Figure 2] FIG. 2 is a timing chart for explaining the operation of the electronic control system shown in FIG. [Figure 3] FIG. 3 is a timing chart for explaining the operation of the electronic control system shown in FIG. [Figure 4] FIG. 4 is a timing chart for explaining the operation of the electronic control system shown in FIG. [Figure 5] FIG. 5 is a flowchart for explaining the operation of the electronic control system shown in FIG. [Figure 6] FIG. 6 is a timing chart for explaining the operation of the electronic control system shown in FIG. [Figure 7] FIG. 7 is a timing chart for explaining the operation of the electronic control system shown in FIG. [Figure 8]FIG. 8 is a timing chart for explaining the operation of the electronic control system shown in FIG. [Figure 9] FIG. 9 is a flowchart for explaining the operation of the electronic control system shown in FIG. [Figure 10] FIG. 10 is a block diagram of the electronic control system shown in FIG. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, the present embodiment will be described with reference to the accompanying drawings. To facilitate understanding of the description, the same components in the drawings will be denoted by the same reference numerals as much as possible, and duplicated descriptions will be omitted.

[0012] The electronic control system 2 will be described with reference to Fig. 1. The electronic control system 2 is a system installed in a vehicle. The vehicle on which the electronic control system 2 is installed is a well-known vehicle equipped with a drive power source and a drive motor, such as an EHV (Electric Hybrid Vehicle), a BEV (Battery Electric Vehicle), or a PHEV (Plug-in Hybrid Electric Vehicle).

[0013] The electronic control system 2 is a system that can rewrite programs for vehicle control, diagnosis, etc., installed in an electronic control unit (hereinafter also referred to as ECU (Electronic Control Unit)) via OTA (Over The Air). In this embodiment, a case where a program is rewritten using wireless communication will be described, but the present invention can also be applied to a case where data used in various applications, such as map data used in a map application or control parameters used in the ECU, is rewritten using wireless communication.

[0014] Rewriting a program using wireless communication includes not only obtaining a program from outside the vehicle via wireless communication and rewriting it, but also obtaining various data used when the program is executed from outside the vehicle via wireless communication and rewriting it.

[0015] As shown in FIG. 1, the electronic control system 2 includes a CGW 21, a DCM 22, an in-vehicle display 23, a power-driven ECU 24, an execution target ECU 25, a parking service request ECU 26, a vehicle power management ECU 27, an SMR 28, an auxiliary battery 31, a power supply relay 32, buses 41, 43, 46, and signal lines 42, 44, 45.

[0016] The CGW (Central Gate Way) 21 is a vehicle gateway device. The DCM (Data Communication Module) 22 is an in-vehicle communication device. The DCM 22 and the CGW 22 are configured to be able to communicate data with each other via a bus 46.

[0017] The DCM 22 performs data communication with an external device (not shown) via a communication network. When the DCM 22 downloads update target information including programs or data from the external device, the DCM 22 transfers the downloaded update target information to the CGW 22.

[0018] The CGW 21 has a data relay function, and when it acquires update target information from the DCM 22, it instructs the rewrite target ECU, which is the target of rewriting, to write the acquired update target information and distributes the update target information to the rewrite target ECU. Furthermore, when the writing of the update target information in the rewrite target ECU is completed and rewriting is completed, the CGW 21 instructs the rewrite target ECU to activate the program etc. after the rewriting is completed.

[0019] An in-vehicle display 23 is also connected to the bus 46 so as to be capable of data communication. The in-vehicle display 23 has a function of receiving operation inputs from the user and a function of displaying various screens, and also serves as a navigation function. The functions of the in-vehicle display 23 may be performed by a mobile terminal such as a smartphone or tablet that the user can carry with them. While inside the vehicle, the user can perform operation inputs while checking various screens related to the rewriting of the application program on the in-vehicle display 23, and can perform procedures related to the rewriting of the application program.

[0020] The CGW 21 and DCM 22 constitute a master device in the electronic control system 2 and function as an OTA master. The functions of the master device may be divided between the CGW 21 and DCM 22 in any manner. In addition to the bus 46, the CGW 21 is connected to the bus 41 and the bus 43.

[0021] The CGW21 has, as its electrical functional blocks, a microcomputer (hereinafter referred to as the "MCU"), a data transfer circuit, a power supply circuit, and a power supply detection circuit. The MCU has a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), and a flash memory. The flash memory includes a secure area in which information cannot be read from outside the CGW21. The MCU executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the CGW21.

[0022] The data transfer circuit controls data communication between buses 41, 43, and 46 in accordance with the CAN (Controller Area Network, registered trademark) data communication standard and diagnostic communication standard. The power supply circuit receives inputs from the battery power supply, accessory power supply, and ignition power supply. The power supply detection circuit detects the voltage values ​​of the battery power supply, accessory power supply, and ignition power supply input by the power supply circuit, compares these detected voltage values ​​with predetermined voltage thresholds, and outputs the comparison results to the microcontroller. Based on the comparison results input from the power supply detection circuit, the microcontroller determines whether the battery power supply, accessory power supply, and ignition power supply supplied from the outside to CGW 21 are normal or abnormal.

[0023] The DCM 22 has, as its electrical functional blocks, a microcomputer, a wireless circuit, a data transfer circuit, a power supply circuit, and a power supply detection circuit. The microcomputer has a CPU, a ROM, a RAM, and a flash memory. The flash memory includes a secure area in which information cannot be read from outside the DCM 22. The microcomputer executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the DCM 22.

[0024] The wireless circuit controls data communication with external devices via a communication network. The data transfer circuit controls data communication with the bus 46 in accordance with the CAN data communication standard. The power supply circuit inputs battery power, accessory power, and ignition power. The power supply detection circuit detects the voltage values ​​of the battery power, accessory power, and ignition power input by the power supply circuit, compares these detected voltage values ​​with predetermined voltage thresholds, and outputs the comparison results to the microcontroller. Based on the comparison results input from the power supply detection circuit, the microcontroller determines whether the battery power, accessory power, and ignition power supplied from the outside to the DCM 22 are normal or abnormal.

[0025] The bus 41 is connected to the power supply ECU 24, the execution target ECU 25, and the parking service request ECU 26 so as to be able to communicate data with each other. The bus 43 is connected to the vehicle power supply management ECU 27 so as to be able to communicate data with each other.

[0026] The power supply drive ECU 24 is an ECU that controls the drive power supply. For example, if the vehicle is an EHV, it is a hybrid ECU that outputs control signals to the engine ECU, motor ECU, and battery ECU.

[0027] The execution target ECU 25 is an ECU whose program or data is to be rewritten by OTA in the description of this embodiment, and is an ECU that is to be subjected to OTA reprogramming. In the description of this embodiment, the execution target ECU 25 is a battery ECU.

[0028] The parking service request ECU 26 is an ECU for executing a parking service. The parking service is a service that is executed by holding the system main relay while the vehicle ignition is off. In this embodiment, the parking service request ECU 26 is neither an OTA starter nor an ECU that executes OTA.

[0029] The vehicle power supply management ECU 27 is an ECU that manages the entire vehicle power supply. For example, when a special power supply ON request is sent from the parking service request ECU 26, the vehicle power supply management ECU 27 outputs a special power supply ON signal to the power supply drive ECU 24. In the following explanation and the explanations in the figures, the special power supply and the flag related to the special power supply are also referred to as "IGB." The vehicle power supply management ECU 27 sends the special power supply ON signal to the power supply drive ECU 24 using the signal line 42, which is a direct line. Upon receiving the special power supply ON signal, the power supply drive ECU 24 turns ON the power supply relay 32. The power supply relay 32 is driven by the power supply drive ECU 24 and is a relay that turns ON / OFF the power supplies of other ECUs. When the power supply relay 32 is turned ON, power is supplied from the auxiliary battery 31, and the execution target ECU 25 is started up.

[0030] The powered ECU 24 and the execution target ECU 25, which is a battery ECU, output an SMR hold request signal to an SMR (System Main Relay) 28. The powered ECU 24 transmits the SMR hold request signal using, for example, a signal line 44. The execution target ECU 25 transmits the SMR hold request signal using, for example, a signal line 45.

[0031] The SMR 28 is a system main relay. The SMR 28, which is a system main relay, is provided between a drive battery (not shown) and a power control unit (not shown) and switches between a conductive state and a non-conductive state between the drive battery and the power control unit. The SMR 28 enters a conductive state when it receives an SMR hold request signal, and enters a non-conductive state when it no longer receives the SMR hold request signal.

[0032] Each of the above-mentioned ECUs has, as electrical functional blocks, a microcomputer, a data transfer circuit, a power supply circuit, and a power supply detection circuit. The microcomputer has a CPU, a ROM, a RAM, and a flash memory. The flash memory includes a secure area in which information cannot be read from outside the ECU. The microcomputer executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the ECU.

[0033] Each of the above-mentioned ECUs includes a so-called dual-ROM microcomputer. For example, the microcomputer has a first data storage surface and a second data storage surface, each storing at least one of programs and parameter data. Based on this premise, when the vehicle is in a driving or parked state, the microcomputer executes at least one of the programs and data stored in the first data storage surface, which is the operational surface (old surface), and executes a process of writing at least one of update programs or update data acquired from an external device to the second data storage surface, which is the non-operational surface. When the vehicle is in a parked state, the microcomputer executes an activation process that switches the operational surface from the first data storage surface to the second data storage surface.

[0034] The data transfer circuit controls data communication between buses 41 and 43 in accordance with the CAN data communication standard. The power supply circuit inputs battery power, accessory power, and ignition power. The power supply detection circuit detects the voltage values ​​of the battery power, accessory power, and ignition power input by the power supply circuit, compares these detected voltage values ​​with predetermined voltage thresholds, and outputs the comparison results to the microcontroller. Based on the comparison results input from the power supply detection circuit, the microcontroller determines whether the battery power, accessory power, and ignition power supplied from the outside to the ECU are normal or abnormal. Note that core ECUs are basically configured the same, although the loads they connect to, such as sensors and actuators, differ.

[0035] Next, a description will be given of the operation of the electronic control system 2. First, the operation of the electronic control system 2 when the processing specific to this embodiment is not performed will be described with reference to Fig. 2. The timing chart shown in Fig. 2 shows the operations of the OTA master (CGW 21 and DCM 22), the parking service request ECU 26, the vehicle power management ECU 27, the powered ECU 24, and the execution target ECU 25 along their respective time axes.

[0036] In the initial state of FIG. 2, the ignition is ON. By time t1, the OTA master performs status checks, etc. Status checks include checking whether the writing of the programs and data received via OTA has been completed. If the writing of the programs and data received via OTA has been completed at time t1, a request for activation approval from the user is displayed on the in-vehicle display 23. In this embodiment, it is assumed that the activation has been approved by the user at time t1.

[0037] Between time t1 and time t2, the OTA master outputs a setting request for plane switching. At time t2, the user turns the ignition off. When the user ignition is turned off, the power of the OTA master switches from Hi to Lo.

[0038] At time t5, the user switches the ignition ON. When the user ignition is turned ON, the power supply of the OTA master switches from Lo to Hi. From time t2 to time t5, the power supply is Lo, so the OTA master stops functioning. At time t5, the power supply becomes Hi, so the OTA master starts up. At time t6, the startup of the OTA master is completed. At time t6, the user confirms activation (Teady-ON) via the in-vehicle display 23. From time t6 to time t7, the OTA master performs a version consistency check for programs and data.

[0039] At time t3, the parking service request ECU 26 sets a flag (IGB-ON) for turning on the special power supply, thereby requesting the start of the parking service.

[0040] The vehicle power supply management ECU 27 switches the direct line signal and CAN signal of the user's ignition ON / OFF in accordance with the user's ignition operation. In the following explanation and the explanations in the figures, the user's ignition and the flag related to the user's ignition are also referred to as "IGP." The vehicle power supply management ECU 27 switches the direct line signal and CAN signal of the special power supply (IGB) ON / OFF in accordance with the special power supply flag (IGB-ON) of the parking service request ECU 26. Therefore, at time t3, the special power supply (IGB) is turned ON.

[0041] The power-driven ECU 24 executes the system shutdown process from time t2 when the user turns off the ignition (IGP). In this embodiment, the system shutdown process is scheduled to continue until time t4 unless there is another request.

[0042] When the parking service request ECU 26 sets a flag (IGB-ON) for turning on the special power supply at time t3 to request the start of the parking service, the special power supply (IGB) is turned on. At time t3, the power-driven ECU 24 is performing system shutdown processing, but because the special power supply (IGB) is turned on, the system shutdown processing is terminated and the process transitions to system startup processing. At time t3 when the process transitions to system startup processing, the power-driven ECU 24 outputs a hold request to the SMR 28.

[0043] The power supply ECU 24 keeps the power supply relay 32 ON until the system shutdown process is completed. In Fig. 2, the system startup process is performed before the system shutdown process is completed, so the power supply relay 32 does not turn OFF and remains ON.

[0044] The execution target ECU 25, which is a battery ECU, executes the power-on process on the old side of the microcomputer. When the user turns on the ignition (IGP), the execution target ECU 25 switches to execution on the new side of the microcomputer. The execution target ECU 25 has functions essential for the parking service provided by the parking service request ECU 26, such as the retention process of the SMR 28.

[0045] The execution target ECU 25 performs a process to shut off the SMR 28, which is a control that inhibits ECU sleep, during the system shutdown process of the power-driven ECU 24. In this embodiment, the process to shut off the SMR 28 is completed between time t2 and time t3, and the execution target ECU 25 enters a state of waiting for the power relay 32 to be turned off. At this timing, the execution target ECU 25 turns off the drive of the SMR 28 and rejects the request to hold the SMR 28.

[0046] As explained above, the parking service request ECU 26 outputs a request to hold the SMR 28 at time t3, while the execution target ECU 25 rejects the request to hold the SMR 28. This raises the concern that a discrepancy may arise between the two requests, resulting in a diagnostic record being stored.

[0047] Next, a processing example for resolving the above-mentioned concerns about diagnostic storage will be described with reference to Fig. 3. The timing chart shown in Fig. 3 also shows the operations along the time axis of the OTA master (CGW 21 and DCM 22), parking service request ECU 26, vehicle power management ECU 27, power drive ECU 24, and execution target ECU 25. The underlying operations are the same as those described in Fig. 2, so differences will be mainly described.

[0048] The OTA master outputs OTA phase information and OTA activation interval information. The OTA phase information is information that indicates the status of the OTA process. For example, if the OTA phase information is "3", it indicates that the program or data is being installed. For example, if the OTA phase information is "4", it indicates that the activation is in progress and version matching is being checked. For example, if the OTA phase information is "0", it indicates that the device is waiting. The OTA activation interval information is information that indicates that the OTA process is in the activation state and version matching is being checked.

[0049] 3, at time t1, the OTA phase information switches from "3" to "4," and the OTA activation period information switches from OFF to ON. At time t7, the OTA phase information switches from "4" to "0," and the OTA activation period information switches from ON to OFF.

[0050] The parking-time service request ECU 26 is configured to receive the OTA phase information and the OTA activation section information. Therefore, the parking-time service request ECU 26 can recognize that the OTA process is being performed from time t1 to time t7. Therefore, in this embodiment, this section is set as a suppression period in which the parking-time service request ECU 26 does not request the parking-time service. Therefore, unlike the example described with reference to FIG. 2, the parking-time service request ECU 26 does not set a flag to turn on the special power supply (IGB) at time t3, and does not request the start of the parking-time service. Note that although the parking-time service request ECU 26 can determine which phase the OTA is in based on the OTA phase information and the OTA activation section information, it cannot obtain information about which ECUs are the target of the OTA.

[0051] Since the parking service is suppressed, the vehicle power management ECU 27 does not turn on the special power supply (IGB). The system shutdown process by the power drive ECU 24 continues without interruption until the originally scheduled time t4, as shown in Figure 2, and is then completed.

[0052] At time t4, the system shutdown process is completed, and the power-driven ECU 24 turns off the power relay 32. The execution target ECU 25 waits for the power relay 32 to turn off, and turns off the power at time t4.

[0053] The execution target ECU 25 completes the SMR 28 shutoff process between time t2 and time t3, and enters a state in which it rejects the request to retain the SMR 28. However, because the parking service is suppressed, the discrepancy described with reference to Figure 2 does not occur, and concerns about diagnostic memory are eliminated.

[0054] At time t7, the OTA phase information switches from "4" to "0" and the OTA activation section information switches from ON to OFF, and at this point the restriction on parking services is lifted.

[0055] Next, a processing example for resolving the above-mentioned concerns about diagnostic storage will be described with reference to Fig. 4. The timing chart shown in Fig. 4 also shows the operations along the time axis of the OTA master (CGW 21 and DCM 22), parking service request ECU 26, vehicle power management ECU 27, power drive ECU 24, and execution target ECU 25. The underlying operations are the same as those described in Fig. 2 and Fig. 3, so differences will be mainly described.

[0056] In the explanation given with reference to Fig. 3, it is assumed that the OTA master outputs the OTA phase information and the OTA activation section information. Since the execution target ECU 25 can also output the OTA activation section information, an example in which the execution target ECU 25 outputs the OTA activation section information will be explained with reference to Fig. 4.

[0057] 4, the OTA activation period information is switched from OFF to ON at time t1, and from ON to OFF at time t7.

[0058] The execution target ECU 25 outputs OTA activation section information, and the parking-time service request ECU 26 receives the information. Therefore, the parking-time service request ECU 26 can recognize that OTA processing is being performed from time t1 to time t7. As explained with reference to FIG. 3, this section is a suppression period during which the parking-time service request ECU 26 does not request parking services.

[0059] As explained with reference to Figure 3, the discrepancy explained with reference to Figure 2 does not occur, and concerns about diagnostic storage are resolved. Also, at time t7, the OTA activation section information switches from ON to OFF, and at this timing the restriction on parking services is released.

[0060] Next, the operation of the electronic control system 2 will be described with reference to the flowchart shown in Fig. 5. In step S11, OTA flag processing is executed. The OTA flag processing is executed by the OTA master or the execution target ECU 25, and is a process of switching the OTA activation section information to ON or OFF and transmitting the information to the parking service request ECU 26.

[0061] In step S12 following step S11, the parking service request ECU 26 determines whether the OTA activation section information, which is an OTA flag, is ON. If the OTA activation section information is ON (step S12: YES), the process proceeds to step S13. If the OTA activation section information is not ON (step S12: NO), the parking service request ECU 26 ends the determination of the OTA activation section information and continues normal control.

[0062] In step S13, the parking service request ECU 26 executes the parking service suppression process, which continues until a predetermined condition is met, as described with reference to FIGS.

[0063] Next, with reference to Figure 6, a processing example for resolving the above-mentioned concerns about diagnostic storage will be described. In the explanation given with reference to Figures 3 and 4, parking services were suppressed while the OTA activation section information was ON. Even if parking services are suppressed in this way, there is an advantage that it is easy for the user to understand that the control is after a program or data update, because the parking services are resumed after the ignition is turned ON again and version consistency is confirmed. On the other hand, the OTA activation section information remains ON until the user turns ON the ignition (IGP), and parking services are suppressed during that time. Figure 6 describes a processing for further improving convenience.

[0064] The timing chart shown in Fig. 6 also shows the operations along the time axis of the OTA master (CGW 21 and DCM 22), the parking service request ECU 26, the vehicle power management ECU 27, the power drive ECU 24, and the execution target ECU 25. The underlying operations are the same as those described in Fig. 2, so differences will be mainly described.

[0065] The OTA master outputs OTA activation period information, which indicates that the OTA process is currently being activated and that version consistency is being checked.

[0066] In the example shown in FIG. 6, the OTA activation period information switches from OFF to ON at time t1, and switches from ON to OFF at time t7.

[0067] The OTA activation section information is set to be received by the parking service request ECU 26. Therefore, the parking service request ECU 26 can recognize that the OTA processing is being performed from time t1 to time t7.

[0068] The diagnostic concern described with reference to Figure 2 arises when the execution target ECU 25 continues to reject the request to hold the SMR 28. The execution target ECU 25 performs a process to shut off the SMR 28, which is a control that inhibits ECU sleep, during the system shutdown process of the powered ECU 24. In this embodiment, the process to shut off the SMR 28 is completed between time t2 and time t3, and the system is in a state waiting for the power relay 32 to be turned off.

[0069] Therefore, after the power supply relay 32 is turned off, the power supply of the execution target ECU 25 is also turned off, so there is no need to continue to reject the request to hold the SMR 28 by the execution target ECU 25.

[0070] Therefore, in the example shown in Fig. 6, the period from when the OTA activation section information is turned ON until after the system shutdown process is completed by the powered ECU 24 is set as the parking service suppression period. In the example shown in Fig. 6, the parking service request ECU 26 is set to set the parking service suppression period as a predetermined time from time t1 when the OTA activation section information is turned ON until after the system shutdown process is completed by the powered ECU 24. The predetermined time is the time until the system shutdown process is expected to be completed by the powered ECU 24, and is set between time t4 and time t5 in Fig. 6.

[0071] The parking service request ECU 26 enters the parking service start request period when the parking service suppression period ends. Between time t4 and time t5, the parking service request ECU 26 sets a flag (IGB-ON) that turns on the special power supply, requesting the start of the parking service.

[0072] The vehicle power supply management ECU 27 switches the direct line signal and CAN signal of the special power supply (IGB) between ON and OFF in accordance with the special power supply flag (IGB-ON) of the parking service request ECU 26. Therefore, the special power supply (IGB) is turned ON between time t4 and time t5.

[0073] The power-driven ECU 24 executes system shutdown processing from time t2 when the user turns off the ignition (IGP) until time t4. The power-driven ECU 24 keeps the power relay 32 ON until time t4 when the system shutdown processing is completed. Since the system shutdown processing is completed at time t4, the power relay 32 is turned OFF at time t4.

[0074] The execution target ECU 25 performs a process to shut off the SMR 28, which is a control that inhibits ECU sleep, during the system shutdown process of the power-driven ECU 24. In this embodiment, the process to shut off the SMR 28 is completed between time t2 and time t3, and the execution target ECU 25 enters a state of waiting for the power relay 32 to be turned off. At this timing, the execution target ECU 25 turns off the drive of the SMR 28 and rejects the request to hold the SMR 28.

[0075] At time t4, the power supply relay 32 is turned off, and the execution target ECU 25 releases the state of waiting for the power supply relay 32 to turn off. After the system shutdown process is completed by the power-driven ECU 24, the execution target ECU 25 releases the state of refusing to accept the request to hold the SMR 28.

[0076] The execution target ECU 25 completes the SMR 28 shutoff process between time t2 and time t3, and enters a state in which it rejects the request to hold the SMR 28. However, the rejection state is released after time t4. Therefore, even if the parking service request ECU 26 requests a parking service and a request to hold the SMR 28 occurs, no discrepancy occurs and there is no concern about diagnostic data storage.

[0077] Next, a processing example for eliminating the above-mentioned concern about the diagnosis storage will be described with reference to Fig. 7. The description with reference to Fig. 7 corresponds to another example of the description with reference to Fig. 6.

[0078] The timing chart shown in Fig. 7 also shows the operations along the time axis of the OTA master (CGW 21 and DCM 22), the parking service request ECU 26, the vehicle power management ECU 27, the power drive ECU 24, and the execution target ECU 25. The underlying operations are the same as those explained in Fig. 2 and Fig. 6, so differences will be mainly explained.

[0079] 7, the power supply drive ECU 24 outputs the hold information of the power supply relay 32. The hold information of the power supply relay 32 is ON if the power supply relay 32 is in the ON state, and is OFF if the power supply relay 32 is in the OFF state. The hold information of the power supply relay 32 is transmitted to the parking service request ECU 26.

[0080] At time t4, the power supply ECU 24 completes the system shutdown process, and the power supply relay 32 turns OFF. At this timing, the information held in the power supply relay 32 turns OFF, and the parking service request ECU 26 cancels the suppression of parking services.

[0081] At time t4, as explained with reference to Figure 6, the state in which the execution target ECU 25 rejects the request to retain the SMR 28 is released, so the parking service request ECU 26 requests a parking service, and even if a request to retain the SMR 28 occurs, no discrepancy occurs and there is no concern about diagnostic memory.

[0082] Next, a processing example for eliminating the above-mentioned concern about the diagnosis storage will be described with reference to Fig. 8. The description with reference to Fig. 8 corresponds to another example of the description with reference to Fig. 6.

[0083] The timing chart shown in Fig. 8 also shows the operations along the time axis of the OTA master (CGW 21 and DCM 22), the parking service request ECU 26, the vehicle power management ECU 27, the power drive ECU 24, and the execution target ECU 25. The underlying operations are the same as those explained in Fig. 2 and Fig. 6, so differences will be mainly explained.

[0084] In the example shown in Fig. 8, the power-driven ECU 24 outputs CAN data. The CAN data is data that continues to be transmitted if the power relay 32 is in an ON state, and stops being transmitted if the power relay 32 is in an OFF state. The CNA data is transmitted to the parking service request ECU 26. The CNA data is a frame with a relatively short transmission period, although it may not be related to the OTA processing.

[0085] At time t4, the power ECU 24 completes the system shutdown process, and the power relay 32 is turned off. At this time, the transmission of CAN data is stopped, and the parking service request ECU 26 releases the restriction on parking services.

[0086] At time t4, as explained with reference to Figure 6, the state in which the execution target ECU 25 rejects the request to retain the SMR 28 is released, so the parking service request ECU 26 requests a parking service, and even if a request to retain the SMR 28 occurs, no discrepancy occurs and there is no concern about diagnostic memory.

[0087] Next, the operation of the electronic control system 2 described with reference to Figures 6, 7, and 8 will be described with reference to the flowchart shown in Figure 9. In step S11, OTA flag processing is executed. The OTA flag processing is executed by the OTA master or the execution target ECU 25, and is processing for switching the OTA activation section information to ON or OFF and transmitting the information to the parking service request ECU 26.

[0088] In step S12 following step S11, the parking service request ECU 26 determines whether the OTA activation section information, which is an OTA flag, is ON. If the OTA activation section information is ON (step S12: YES), the process proceeds to step S13. If the OTA activation section information is not ON (step S12: NO), the parking service request ECU 26 ends the determination of the OTA activation section information and continues normal control.

[0089] In step S13, the parking service request ECU 26 executes the parking service suppression process.

[0090] In step S14 following step S13, the parking service request ECU 26 determines whether the parking service suppression period has elapsed. The elapse of the parking service suppression period is determined based on the elapse of a predetermined time period or information transmitted to the power-driven ECU 24, as described with reference to FIGS.

[0091] If the parking service suppression period has elapsed (step S14: YES), the process proceeds to step S 15. If the parking service suppression period has not elapsed (step S14: NO), the process continues with step S14.

[0092] In step S15, the parking service request ECU 26 cancels the parking service suppression period and executes normal control.

[0093] The electronic control system (components such as an ECU including a microcomputer that executes control, a CGW, and a DCM) and the method thereof described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to execute one or more functions embodied in a computer program. Alternatively, the electronic control system (components such as an ECU including a microcomputer that executes control, a CGW, and a DCM) and the method thereof described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the electronic control system (components such as an ECU including a microcomputer that executes control, a CGW, and a DCM) and the method thereof described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to execute one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible storage medium.

[0094] The present embodiment has been described above with reference to specific examples. However, the present disclosure is not limited to these specific examples. Design modifications to these specific examples made by a person skilled in the art as appropriate are also included within the scope of the present disclosure as long as they comprise the features of the present disclosure. The elements of the above-described specific examples, as well as their arrangement, conditions, shape, etc., are not limited to those exemplified and can be modified as appropriate. The elements of the above-described specific examples can be combined in various ways as appropriate, as long as no technical contradictions arise.

[0095] [Note] Notes 1 to 7 below can be combined in any way as long as there is no technical contradiction.

[0096] [Appendix 1] An electronic control device that executes parking services using a specific function of a vehicle while the ignition of the vehicle is off, The activation process involves writing update target information, including programs or data acquired from an external device, into a non-volatile memory mounted on the vehicle to activate the update target information. The activation process involves refusing to use a specific function. The activation process can receive activation information indicating that the other electronic control unit has completed its preparations for the activation process. When activation information is received, execution of the parking service is suppressed.

[0097] In the above embodiment, the parking service request ECU 26 is exemplified as the electronic control device of Supplementary Note 1. The electronic control device of Supplementary Note 1 is not limited to the parking service request ECU 26, but can be realized as an ECU involved in executing a parking service that is executed using a specific vehicle function while the vehicle ignition is off. In the above embodiment, the system main relay is exemplified as the specific vehicle function, but any function used for the parking service that is executed while the vehicle ignition is off may be used. The ECU that performs the activation process is an electronic control device different from the electronic control device of Supplementary Note 1. In the above embodiment, the execution target ECU 25 is exemplified as the ECU that performs the activation process, and specifically, the battery ECU is described. The ECU that performs the activation process is not limited to this, and can be applied to an ECU that has a mode that rejects a request to use a specific function, such as the system main relay, after preparation for the activation process.

[0098] According to Appendix 1, activation information indicating that preparation for activation processing is complete is received and the execution of the parking service is suppressed while the vehicle ignition is off. This eliminates discrepancies with ECU processing that may reject a request to hold the system main relay when the conditions for preparation for activation processing is complete and the vehicle ignition is off are met, and eliminates concerns about diagnostic memory when data rewriting operations via OTA and execution of the parking service coexist.

[0099] [Appendix 2] 2. The electronic control device according to claim 1, wherein the electronic control device cancels the suppression of the execution of the parking service after the denial of use of the specific function by another electronic control device that performs the activation process is canceled.

[0100] According to Appendix 2, the suppression of the execution of the parking service is lifted after the denial of use of a specific function by another electronic control device is lifted, so the suppression of the execution of the parking service does not remain permanent, and the parking service can be executed while eliminating concerns about diagnostic memory.

[0101] [Appendix 3] The activation information includes information that the activation process is in progress and information that the activation process has been completed; 3. The electronic control device according to claim 2, wherein the suppression of the parking service is lifted after the activation information has transitioned from indicating that the activation process is in progress to indicating that the activation process has been completed.

[0102] According to Appendix 3, the suppression of the execution of the parked service is released after the activation process is completed, so the suppression of the execution of the parked service does not remain permanent, and the parked service can be executed while eliminating concerns about diagnostic memory.

[0103] [Appendix 4] An electronic control device as described in Appendix 2, which, after receiving activation information and recognizing that preparation for activation processing has been completed, cancels the suppression of execution of parking services after a predetermined time has elapsed since the vehicle ignition was turned off.

[0104] According to Appendix 4, the suppression of the parking service execution is lifted after a predetermined time has elapsed since the vehicle ignition was turned off, so that the parking service can be executed at a more appropriate timing while eliminating concerns about diagnostic data storage.

[0105] [Appendix 5] An electronic control device as described in Appendix 2, which cancels the suppression of the execution of parked services after receiving activation information and recognizing that preparation for activation processing has been completed and after the vehicle's drive power retention state is released.

[0106] According to Appendix 5, the suppression of the execution of the parking service is released after the vehicle's drive power retention state is released, so that an ECU that is associated with the vehicle's drive power retention state and may reject a request to retain the system main relay will have the suppression of the execution of the parking service released after being released from that rejection mode, thereby eliminating concerns about diagnostic memory and allowing the parking service to be executed early.

[0107] [Appendix 6] 5. The electronic control device according to claim 4, which recognizes that the vehicle's drive power supply holding state has been released when reception of a signal indicating the vehicle's drive power supply holding state is interrupted.

[0108] According to Supplementary Note 6, the release of the vehicle's drive power supply holding state is recognized based on the reception status of a signal indicating the vehicle's drive power supply holding state, so that parking services can be executed at more appropriate timing.

[0109] [Appendix 7] The electronic control device Use certain vehicle features to run parked services while the vehicle ignition is off, Activation information indicating that another electronic control unit has completed preparations for an activation process that writes update target information, including a program or data acquired from an external device, into a nonvolatile memory mounted on the vehicle and activates the information, along with denial of use of a specific function, is received; A program that suppresses execution of a parking service when activation information is received.

[0110] According to Supplementary Note 7, it is possible to provide a program that achieves the same effects as Supplementary Note 1. Supplementary Notes 2 to 6 can also be realized as a program, similar to Supplementary Note 7.

[0111] The electronic control devices described in Supplementary Notes 1 to 6 are included in an electronic control system 2. The electronic control system 2 is a collection of ECUs including a flash memory as a non-volatile memory having a first data storage surface and a second data storage surface, each of which stores at least one of a program and data. As shown in Fig. 10, the electronic control system 2 includes, as functional components, an installation execution unit 201, an activation execution unit 202, an activation information output unit 203, an activation information receiving unit 204, and a parking service management unit 205.

[0112] When the vehicle equipped with the electronic control system 2 is in a driving or parked state, the installation execution unit 201 operates at least one of the programs or data stored in the first data storage surface, which is the operational surface, and writes at least one of the update programs or update data obtained from an external device to the second data storage surface, which is the non-operational surface.

[0113] The activation execution unit 202 switches the operation surface from the first data storage surface to the second data storage surface when the vehicle is in a parked state.

[0114] The activation information output unit 203 outputs activation information indicating that the installation execution unit 201 or the activation execution unit 202 is running. In the above embodiment, the activation information is described as OTA phase information or OTA activation section information. The activation information includes information indicating that update target information including a program or data acquired from an external device is written to a non-volatile memory mounted on the vehicle and preparations for activation processing to activate the written area are complete. The activation information includes information indicating that the activation processing is running and that the activation processing has been completed.

[0115] The activation information output unit 203 can be provided in the CGW 21 and the DCM 22 as the OTA master, as described with reference to Figures 1 to 3 and 6 to 8. The activation information output unit 203 can also be provided in the execution target ECU 25, as described with reference to Figure 4.

[0116] The activation information receiving unit 204 receives the activation information output by the activation information output unit 203. When the activation information is received, the parking during service management unit 205 suppresses the execution of the parking during service that uses the vehicle's driving power source. In the above embodiment, the activation information receiving unit 204 and the parking during service management unit 205 are described as being provided in the parking during service request ECU 26. [Explanation of symbols]

[0117] 2: Electronic control system 21: CGW (Central Gate Way) 22:DCM(Data Communication Module) 23: In-car display 24: Powered ECU 25: Target ECU 26: Parking service request ECU 27: Vehicle power management ECU 28:SMR(System Main Relay) 31: Auxiliary battery 32: Power relay 41: Bus 42: Signal line 43: Bus 44: Signal line 45: Signal line 46: Bus

Claims

1. An electronic control device that executes parking services using a specific function of a vehicle while the ignition of the vehicle is off, The activation information indicating that the other electronic control unit has completed preparations for processing an activation process that writes update target information, including a program or data acquired from an external device, into a non-volatile memory mounted on the vehicle and activates the update target information, along with refusal to use the specific function, can be received; an electronic control device that, when receiving the activation information, inhibits execution of the parking service;

2. The electronic control unit according to claim 1 , wherein the suppression of execution of the parking service is lifted after the denial of use of the specific function by the other electronic control unit is lifted.

3. the activation information includes information that the activation process is being executed and information that the activation process has been completed; The electronic control unit according to claim 2 , wherein the suppression of the parking service is released after the activation information has transitioned from an activation process in progress to an activation process completed.

4. 3. The electronic control device according to claim 2, wherein after receiving the activation information and recognizing that preparation for the activation process is complete, the electronic control device cancels the suppression of execution of the parked service after a predetermined time has elapsed since the vehicle ignition was turned off.

5. 3. The electronic control device according to claim 2, wherein the activation information is received and the activation process is recognized as being ready, and the execution of the parking service is cancelled after the vehicle's drive power retention state is cancelled.

6. 6. The electronic control device according to claim 5, wherein the electronic control device recognizes that the vehicle's drive power supply holding state has been released when reception of the signal indicating the vehicle's drive power supply holding state is interrupted.

7. The electronic control device Use certain vehicle features to run parked services while the vehicle ignition is off, receiving activation information indicating that the other electronic control unit has completed preparations for an activation process that writes update target information, including a program or data acquired from an external device, into a nonvolatile memory mounted on the vehicle and activates the update target information, along with refusal to use the specific function; a program that, when activation information is received, inhibits execution of the parking service;

Citation Information

Patent Citations

  • In-vehicle software updating method and in-vehicle system

    EP4071603A1

  • Center device, specifications data generation method, and program for specifications data generation

    JP2020027620A

  • On-vehicle apparatus, information generation method, information generation program, and vehicle

    JP2022041194A

  • In-vehicle software updating method and in-vehicle system

    JP2022160928A

  • Program management apparatus, program management method, and recording medium

    JP2023118652A