Controller
A dual-bank non-volatile memory system in control devices optimizes memory usage by storing the boot loader in one bank and allowing selective execution of the latest application program, addressing memory capacity issues and enhancing control accuracy and safety in vehicle control systems.
Patent Information
- Application Number
- JP2024093383
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-10
- Publication Date
- 2025-12-22
AI Technical Summary
In dual-bank microcontrollers, the area storing the boot loader cannot be used for user-created programs, reducing the non-volatile memory capacity available for control programs, which is critical for vehicle control devices that require secure storage for processing units to maintain control accuracy and prevent delays.
Implementing a control device with a dual-bank non-volatile memory system where the boot loader is stored in one bank and user programs in the other, allowing selective execution of the latest application program version through a startup process selection unit, thereby optimizing memory usage and ensuring storage for processing units.
This configuration secures storage area for processing units without additional devices, enhances memory efficiency, and improves control accuracy and safety by ensuring the latest application program is executed, thus reducing the risk of control delays and errors.
Smart Images

Figure 2025185275000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a control device for controlling equipment, and more particularly to a control device using a microcontroller unit that can switch between memory banks for use. [Background technology]
[0002] In recent years, with the development of in-vehicle communication networks, ECUs (Electronic Control Units), which are control computers (vehicle control devices) installed in vehicles such as automobiles, have begun to have their software stored in the ECUs and used to control the controlled objects rewritten.
[0003] As an example of such software rewriting technology, Patent Document 1 discloses a firmware update system in which, in a microcomputer having two banks for storing firmware, the firmware in one bank is activated to control the device, while the firmware in the other bank, which is in an inactive state, is updated. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Publication No. 2022-24904 Summary of the Invention [Problem to be solved by the invention]
[0005] Generally, in a dual-bank microcontroller (microcomputer) that can switch between two banks, the area storing the boot loader that switches between the banks, as described in Patent Document 1, cannot be used to write programs created by the microcomputer user. For this reason, the boot loader created by the user to set the operating environment of the program had to be written into each bank along with the program. In this way, when a boot loader is placed in a bank, the boot loader is stored in each of two storage areas, which reduces the capacity of non-volatile memory available for the control program by the data size of the boot loader.
[0006] Meanwhile, vehicle control devices such as engine control devices control various vehicle devices. For example, the engine control device calculates a target throttle opening based on a signal output from an accelerator sensor and controls a throttle motor so that the actual throttle opening becomes the target throttle opening. Because the control by the vehicle control device affects the running of the vehicle, it is required to secure storage space for processing units related to the control and to suppress deterioration in control accuracy and delays.
[0007] An object of the present invention is to ensure a storage area for processing units related to control in a control device using a dual-bank microcomputer. [Means for solving the problem]
[0008] In order to achieve the above-mentioned object, in a preferred embodiment, the control device of the present invention comprises an arithmetic unit, a non-volatile memory having a first bank and a second bank, a first program and a second program stored in the first bank and the second bank, respectively, and executed by the arithmetic unit to control the equipment, and a startup process selection unit stored in the first bank, which performs an initialization process to set up the execution environment of the first program and the second program, and performs a setting process to selectively start the first program and the second program. [Effects of the Invention]
[0009] According to the present invention, it is possible to provide a control device that can secure a storage area for processing units related to control without adding any devices.
[0010] Other novel features of the present invention and the technical problems solved thereby will become apparent from the description and drawings of this specification. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a schematic block diagram showing a system configuration of an embodiment of a vehicle control system to which the present invention is applied; [Figure 2] FIG. 2 is a schematic block diagram showing the configuration of a hybrid control device. [Figure 3] 4 is a flowchart showing the operation of the hybrid control device at startup. [Figure 4] FIG. 2 is a schematic diagram illustrating an example of a memory map of a nonvolatile memory. DETAILED DESCRIPTION OF THE INVENTION
[0012] Representative embodiments of the present invention will be described below with reference to the drawings.
[0013] FIG. 1 is a schematic block diagram showing the system configuration of an embodiment of a vehicle control system to which the present invention is applied.
[0014] The vehicle control system 300 of this embodiment has, as a power source for driving the vehicle, an engine 1 that generates torque by burning fuel such as gasoline, and a motor 3.
[0015] An engine control device 6 is connected to the engine 1. The engine control device 6 acquires the accelerator opening from a throttle sensor 12 to control a throttle motor 13, and also controls the rotation speed, torque, and other outputs of the engine 1 by controlling fuel injection by an injector (fuel injection device) (not shown) provided in the engine 1 and ignition timing by an ignition device.
[0016] The motor 3 is driven by an inverter 4 using electrical energy stored in a battery 5. The inverter 4 is controlled by a motor control device 8, and converts DC power supplied by the battery 5 into AC power and supplies it to the motor 3. During braking, the motor 3 also functions as a generator, and AC power generated by the motor 3 is converted into DC power and supplied to the battery 5 to charge the battery 5. A battery control device 9 is connected to the battery 5, and the charging and discharging of the battery 5 is controlled by the battery control device 9.
[0017] The output of the motor 3 is transmitted to the axle 15a via the drive shaft 14a and gear 14b, driving the wheels 15b. The output of the engine 1 is transmitted to the drive shaft of the motor via a clutch mechanism 2. The clutch mechanism 2 is controlled by a clutch control device 7, and can connect or disconnect the engine 1 and the drive shaft 14a of the motor 3. When the clutch mechanism 2 is in a disconnected state, the wheels 15b are driven by the output of the motor 3. When the engine 1 and the motor 3 are connected, the output of the motor 3 supplements the output of the engine 1 to drive the wheels 15b, or the output from the engine 1 can be used to make the motor 3 function as a generator to charge the battery 5.
[0018] The engine control device 6, clutch control device 7, motor control device 8, and battery control device 9 are connected to the hybrid control device 10 via a communication line 100. The communication line 100 forms a network capable of performing communication based on, for example, a CAN (Controller Area Network) protocol. The engine control device 6, clutch control device 7, motor control device 8, battery control device 9, and hybrid control device 10 can transmit and receive information to each other via the communication line 100. The hybrid control device 10 determines torque distribution, for example, to achieve predetermined fuel economy and drivability based on information transmitted from each control device as well as information obtained from an accelerator sensor 11, and sends commands to the engine control device 6, clutch control device 7, motor control device 8, and battery control device 9 via the communication line 100.
[0019] Each of the control devices 6 to 10 is configured with a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), etc. (not shown), and performs signal processing according to a predetermined control program.
[0020] The electric energy stored in the battery 5 is used not only as power to drive the motor 3 but also as power for auxiliary devices such as an air conditioner via a DC-DC converter (not shown).
[0021] In addition, although communication between the control devices is assumed to be performed using CAN, any protocol other than CAN can be used, such as LIN (Local Interconnect Network), Ethernet (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport), PLC (Power Line Communication), etc. Furthermore, a configuration in which communication is performed between the control devices using different protocols is also acceptable.
[0022] FIG. 2 is a schematic block diagram showing the configuration of the hybrid control device 10 in this embodiment.
[0023] The hybrid control device 10 includes a CPU 20, a nonvolatile memory 21, a RAM 22, an input interface (input I / F) 23, an output interface (output I / F) 24, and a bus 40 interconnecting these components.
[0024] The CPU 20 is a calculation device that executes a program stored in the nonvolatile memory 21 to realize the hybrid control function of the hybrid control device 10.
[0025] The nonvolatile memory 21 is composed of a writable / erasable nonvolatile storage element such as a flash memory, and stores programs executed by the CPU 20. The nonvolatile memory 21 has an area where firmware 25 is written and areas used as a first bank 26 and a second bank 27 that are used interchangeably.
[0026] The firmware 25 includes a startup process executed by the CPU 20 immediately after startup. The firmware 25 is created, for example, by a microcomputer vendor and stored in the non-volatile memory 21. The area where the firmware 25 is stored is restricted for writing by the user, and cannot be rewritten by the user.
[0027] The first bank 26 stores a boot loader 28 and a first application program 30 created by the user. The second bank 27 stores a second application program. The boot loader 28 is a program that is started up by the firmware 25, performs initial settings for the clock, cache, vector table, stack pointer, etc., and sets up an operating environment for hybrid control by the CPU 20. The boot loader includes a startup process selection unit 29 that selectively executes the first application program 30 and the second application program 31. The first application program 30 and the second application program 31 are programs for performing hybrid control.
[0028] The RAM 22 is configured with a volatile storage element that allows high-speed access, such as a DRAM (Dynamic Random Access Memory), and is used as a working area for storing various data that the CPU 20 temporarily uses when executing a program.
[0029] The input I / F 23 is an interface for processing signals sent from or acquired from outside the hybrid control device 10 and inputting the signals as data into the hybrid control device 10. The output I / F 24 is an interface for processing signals output to outside the hybrid control device 10.
[0030] The programs stored in the first bank 26 and the second bank 27 can be rewritten from outside the vehicle control system 300 by a program writing device (not shown) connected to the communication line 100. Alternatively, the programs can be rewritten by a method known as OTA (Over The Air), using wireless communication via a communication device (not shown) connected to the communication line 100.
[0031] FIG. 3 is a flowchart showing the operation of the hybrid control device 10 at startup.
[0032] When the hybrid control device 10 is powered on, the CPU 20 starts executing the firmware 25 (step S10).
[0033] After the firmware 25 has performed a predetermined process, the firmware 25 acquires bank information indicating the bank in which the process to be executed is stored, and switches the bank in accordance with the bank information. The bank information is set, for example, in a register (not shown) formed of a nonvolatile storage element in the CPU 20 or the nonvolatile memory 21 (hereinafter referred to as a bank information register). At this stage, information indicating the first bank 26 has been set in the bank information register, and the firmware 25 sets the bank so that the process stored in the first bank 26 is executed.
[0034] Next, the firmware 25 acquires the start address of the process started by the firmware 25 and sets it in the CPU 20. The start address of the process started by the firmware 25 is held in, for example, a register (not shown) formed by a nonvolatile storage element in the CPU 20 or the nonvolatile memory 21 (hereinafter referred to as a start address register), similar to the bank information register. As a result, the CPU 20 starts execution of the boot loader 28 (step S11).
[0035] The boot loader 28 executes an initialization process (step S12), and after the initialization process, the boot process selection unit 29 compares the version information of the first application program 30 and the second application program 31 to determine which application program is the newer version. The comparison of the version information is performed, for example, by reading out the version information stored inside each application program (step S13).
[0036] If the condition that the first application program 30 is newer than the second application program 31 is true, the boot loader 28 sets the start address of the first application program 30 in the CPU 20 and starts processing by the first application program 30. Thereafter, hybrid control processing by the first application program 30 is executed (step S14).
[0037] On the other hand, if the determination in step S13 is false, the boot loader 28 changes the address set in the start address register to the start address of the second application program 31 (step S15). Subsequently, the boot loader 28 changes the bank information set in the bank information setting register to the second bank 27 (step S16), and resets the CPU 20 (step S17).
[0038] After the reset, the CPU 20 executes a predetermined process to be performed after the reset by the firmware 25. After this process is completed, the firmware 25 obtains bank information from the bank information register and switches the bank to the second bank 27. The firmware 25 then obtains the start address of the second application program 31 from the start address register and sets it in the CPU 20, causing the second application program 31 to start execution (step S18).
[0039] The second application program 31 resets the settings that were initialized after the reset. The reset settings include, for example, the timer values of the registers of the CPU 20 (step S19). The second application program 31 then restores the bank information set in the bank information register to information indicating the first bank 26, and restores the address set in the start address register to the start address of the boot loader 28 (step S20). Thereafter, the second application program 31 performs hybrid control processing.
[0040] FIG. 4 is a schematic diagram showing an example of a memory map of the nonvolatile memory 21 in this embodiment.
[0041] 4 shows that the start address of the boot loader 28 is 81000000h, the start address of the first application program 30 is 80000000h, the end address is 80FFFFFFh, and the start address of the second application program 31 is 80000000h. In this embodiment, the start address of the first application program 30 and the start address of the second application program 31 are set to be the same, and the start address of the boot loader 28 is set to be after the end address of the first application program 30. In this way, the start addresses of the first application program 30 and the second application program 31 are aligned, and the boot loader can be provided only in the first bank 26. This configuration can be achieved even when the memory capacity of the second bank 27 is smaller than that of the first bank 26, improving resource efficiency. Note that the boot loader 28 can also be placed before the first application program 30, so that the start addresses of the boot loader 28 and the second application program 31 are the same. In this case, it is possible to eliminate the need to operate the start address register.
[0042] As described above, in this embodiment, the boot loader is implemented only in the first bank, and the boot loader controls the selective launch of the first application and the second application. This allows for saving the area used in the nonvolatile memory. Furthermore, in a dual-bank memory system, even if the sizes of the two banks are different, the use of a single boot loader allows for flexible program storage. In other words, even if one bank has a small memory capacity, the launch process for application programs stored in both banks can be performed. Furthermore, by selecting and setting the newer version of the first application or the second application to be launched, the newer application after an update can be selected and launched.
[0043] As described above, according to this embodiment, the data capacity of the nonvolatile memory can be reduced by the data size of one boot loader, and the reduced capacity can be used for more advanced control software, improving safety. Furthermore, by selecting the latest software, further improvements in safety can be expected.
[0044] In the embodiment described above, the startup process selection unit 29 selects a new program as the application program to be started, but the selection condition may be that no abnormality has been found. For example, in the process of step S13 in Fig. 3, it may be determined whether "any abnormality has been found in the first application program 30."
[0045] In this way, it is possible to select and start an application program in which no abnormality has been found, that is, a normal application program, thereby improving safety.
[0046] The determination of the presence or absence of an abnormality may be performed during the startup process of the boot loader 28. The presence or absence of an abnormality in the application program is determined during the startup process, and the application program to be started is determined based on that determination, so the result of the most recent abnormality determination can be used to select the application program, which is expected to further improve safety.
[0047] Furthermore, the startup process selection unit 29 may select an application program to be started that is different from the application for which the update process has not been completed. For example, the process in step S13 of FIG. 3 may determine whether the update process of the first application program 30 has been completed.
[0048] By making such a determination, it is possible to prevent an application program that has not yet completed update processing from being executed, and it is expected that safety will be improved.
[0049] These conditions for selecting an application program to be launched may be used selectively or in combination with other conditions.
[0050] In the above embodiment, the hybrid control device 10 has been described as an example, but other control devices, such as the engine control device 6, clutch control device 7, motor control device 8, and battery control device 9, can also be configured in a similar manner.
[0051] While the present invention has been described above using exemplary embodiments as examples, the present invention is not limited thereto and can be embodied in various forms without departing from the spirit of the invention as set forth in the claims. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those having all of the described configurations. Furthermore, the present invention is not limited to the type of vehicle on which it is installed and can be applied to, for example, a control device that realizes advanced functions such as an automatic driving function, an automatic parking function, or an advanced driver assistance system. [Explanation of symbols]
[0052] 1 Engine, 2 Clutch mechanism, 3 Motor, 4 Inverter (power conversion device), 5 Battery, 6 Engine control device, 7 Clutch control device, 8 Motor control device, 9 Battery control device, 10 Hybrid control device, 11 Accelerator sensor, 12 Throttle sensor, 13 Throttle motor (throttle device), 20 CPU, 21 Non-volatile memory, 22 RAM, 23 Input I / F, 24 Output I / F, 25 Firmware, 26 First bank, 27 Second bank, 28 Boot loader, 29 Startup processing selection unit, 30 First application program, 31 Second application program, 40 Bus, 100 Communication line, 300 Vehicle control system.
Claims
1. A computing device; a non-volatile memory having a first bank and a second bank; a first program and a second program stored in the first bank and the second bank, respectively, and executed by the arithmetic unit to control a device; a setting program stored in the first bank, which performs an initialization process to set up an execution environment for the first program and the second program, and which has a startup process selection unit that performs a setting process to selectively start the first program and the second program.
2. the same address is assigned to the first program start address and the second program start address, 2. The control device according to claim 1, wherein the start address of the setting program is assigned an address after the end address of the first program.
3. 3. The control device according to claim 2, wherein the memory capacity of the second bank is smaller than the sum of the memory capacity required to store the second program and the memory capacity required to store the setting program.
4. 2. The control device according to claim 1, wherein the startup process selection unit performs the setting process by selecting one of the first program and the second program so that the program that is most recently updated is started.
5. the first program and the second program each hold version information indicating an update version; 5. The control device according to claim 4, wherein the startup process selection unit makes the selection by comparing the version information of the first program and the second program.
6. 2. The control device according to claim 1, wherein the startup process selection unit selects one of the first program and the second program in which no abnormality has been found, and performs the setting process.
7. 7. The control device according to claim 6, wherein the startup process selection unit determines whether or not there is an abnormality in the first program and the second program during the initialization process.
8. 2. The control device according to claim 1, wherein the startup process selection unit selects an application, out of the first program and the second program, that is different from a program for which update processing has not been completed, and performs the setting process.
9. the control device according to claim 1 further includes firmware that switches between the first bank and the second bank based on bank information that indicates which of the first bank and the second bank is to be used; The control device wherein the startup process selection unit sets information indicating that the second bank is to be used in the bank information when the second program is selected as the program to be started.
10. The control device according to claim 9, wherein when the startup processing selection unit selects the second program as the program to be started, the startup address of the second program is set as start address information indicating the start address of the program to be started by the firmware.
11. when the startup process selection unit selects the second program as the program to be started, resets the arithmetic unit after setting the bank information and the start address information; 11. The control device according to claim 10, wherein the firmware starts execution of a selected program based on the bank information and the start address information in the post-reset process.
12. 12. The control device according to claim 11, wherein, after the second program is started, the bank information is restored to information indicating the first bank, and the start address information is restored to the start address of the setting program.
Citation Information
Patent Citations
Firmware updating system and firmware updating method
JP2022024904A