Vehicle control device and memory protection method
The multicore microcomputer system with dual memory and data switching/recovery mechanisms addresses memory protection issues in vehicle control systems, ensuring stable operation and reliable data recovery.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2026-03-19
AI Technical Summary
Existing memory protection methods in vehicle control systems can lead to repeated system restarts and instability due to unauthorized access, especially when backup data is corrupted, potentially causing the control system to malfunction.
A vehicle control device with a multicore microcomputer that includes a first memory for reference data and a second memory for backup data, equipped with a determination function to identify unauthorized access and a reference data switching function to switch to backup data upon detection, along with a data repair mechanism to restore corrupted data.
Ensures stable operation by providing normal data and reliably repairing memory anomalies caused by unauthorized access, preventing system instability and malfunctions.
Smart Images

Figure 2026049841000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a vehicle control device equipped with a multi-core microcomputer having a plurality of control cores, and a memory protection method in the multi-core microcomputer.
Background Art
[0002] Recently, functional safety standards have been established, and vehicles such as automobiles are being produced in accordance with these standards. Therefore, a vehicle control device used in an automobile or the like is provided with a failure diagnosis function for diagnosing the occurrence of an abnormality and the location of the abnormality in the vehicle. Further, the abnormal information (or normal information) diagnosed by this failure diagnosis function is stored in a memory area such as a RAM (Random Access Memory) as an error code, for example. Furthermore, not only the above-described error code but also various other types of information (for example, a program used for control and control information used for calculation) are stored in the memory area such as the RAM.
[0003] For this reason, a microcomputer is provided with a memory protection function for preventing unauthorized access (for example, control operations such as writing, reference, and update) to the above-described memory area. Hereinafter, access will be described including control operations such as writing, reference, and update.
[0004] However, there is a concern that this memory protection function may affect the stability of the vehicle control system. For example, when an unauthorized access to an unintended memory area is detected, a restart is performed as a recovery. Then, when multiple unauthorized accesses are detected due to a software program abnormality such as memory destruction or an unauthorized access from the outside, the restart is repeated, so there is a high possibility that the stability of the system will be impaired.
[0005] To avoid situations that compromise system stability, Japanese Patent Publication No. 2018-22333 (Patent Document 1) proposes a method to easily restore the system by repairing abnormal data when an abnormality occurs in the memory area.
[0006] Patent Document 1 shows that when a diagnosis of the first memory area is performed during the startup process, which is carried out by executing the first startup program, and an abnormality is detected in the first memory area, the first memory area is repaired by overwriting and updating the location of the detected abnormality in the data storage area of the first startup program stored in the first memory area using data read from the second startup program stored in the second memory area. [Prior art documents] [Patent Documents]
[0007] [Patent Document 1] Japanese Patent Publication No. 2018-22333 [Overview of the project] [Problems that the invention aims to solve]
[0008] The memory data repair method described in Patent Document 1 makes it possible to stabilize the control system by using backup data to repair the abnormal data when a memory abnormality occurs due to unintended unauthorized access, upon detecting the occurrence of the abnormality.
[0009] However, even if the memory data corruption is repaired and the control system stabilizes, if the memory data corruption repair fails, the system may repeatedly restart, potentially leading to an unstable state of the control system.
[0010] Furthermore, if memory abnormalities occur due to unintended unauthorized access to backup data, it may become impossible to repair the memory with correct data because the backup data is corrupted, potentially causing the control system to malfunction.
[0011] The object of the present invention is to provide a vehicle control device and a memory protection method that can provide normal data even if an anomaly occurs in the memory data due to unauthorized access, and can more reliably repair the data based on this anomaly. [Means for solving the problem]
[0012] The present invention relates to a vehicle control device equipped with a multicore microcomputer having multiple control cores for controlling a vehicle, wherein the multicore microcomputer includes a first memory storing first reference data referenced by the implemented software, and a second memory storing second reference data having the same content as the first reference data, and further includes a determination function that determines whether the access to the first and second reference data has been received from a legitimate control core authorized to access it, or from a control core other than a legitimate control core, and a reference data switching function that, if the determination function determines that the access to the first reference data has been received from a control core other than a legitimate control core, switches the reference data referenced by the software from the first reference data to the second reference data.
[0013] Furthermore, the present invention relates to a memory protection method for a vehicle control device equipped with a multicore microcomputer having multiple control cores for controlling a vehicle, wherein the multicore microcomputer includes a first memory storing first reference data referenced by the implemented software, and a second memory storing second reference data having the same content as the first reference data, and the multicore microcomputer is characterized by performing a determination step of determining whether the first reference data and the second reference data have been accessed from a legitimate control core that is authorized to access them, or from a control core other than a legitimate control core; a reference data switching step of switching the reference data referenced by the software from the first reference data to the second reference data if it is determined that the access to the first reference data has been accessed from a control core other than a legitimate control core; and a data repair step of repairing the first reference data using the second reference data if it is determined that the first reference data has been accessed from a control core other than a legitimate control core. [Effects of the Invention]
[0014] According to the present invention, even if an anomaly occurs in the memory data due to unauthorized access, normal data can be provided, and furthermore, data based on this anomaly can be repaired more reliably. [Brief explanation of the drawing]
[0015] [Figure 1] This is a configuration diagram showing the configuration of a vehicle control device, which is an example of an embodiment of the present invention. [Figure 2] This is a control block diagram showing the functional blocks of the microcomputer in the vehicle control device according to this embodiment. [Figure 3] This is an explanatory diagram illustrating the memory areas allocated to each core in RAM and the permission status of access. [Figure 4] This flowchart illustrates the operation of the unauthorized access error handling process performed by the memory protection unit. [Modes for carrying out the invention]
[0016] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. However, the present invention is not limited to the following embodiments, and various modifications and application examples within the technical concept of the present invention are also included in its scope.
[0017] First, the configuration of the vehicle control device according to an embodiment of the present invention will be briefly described based on FIG. 1. As an example of the vehicle control device, a control device INV for an electric motor includes a power converter unit 10 Then, the control device INV operates to drive and control a three-phase motor MTR. The three-phase brushless motor, which is the three-phase motor MTR, has a stator 12 provided with coils of U-phase, V-phase, and W-phase, and a rotor 13 provided with magnets, which is rotatably supported with respect to the stator 12.
[0018] The control device IVT includes the power converter unit 10 and the control unit 11 as described above. The power converter unit 10 includes a U-phase arm in which the switching element 14u on the upper arm side and the switching element 15u on the lower arm side are connected in series, a V-phase arm in which the switching element 14v on the upper arm side and the switching element 15v on the lower arm side are connected in series, and a W-phase arm in which the switching element 14w on the upper arm side and the switching element 15w on the lower arm side are connected in series.
[0019] Each arm included in the power converter unit 10 is connected in parallel between the positive electrode line LP of the in-vehicle DC power supply 16 and the negative electrode line LN of the DC power supply 16, forming a three-phase bridge circuit. Also, a capacitor 17 is connected in parallel with each arm between the positive electrode line LP and the non-polar line LN. The switching elements 14u to 15w each include an antiparallel diode and are composed of power semiconductor elements such as, for example, a FET (Field Effect Transistor) or an IGBT (Insulated Gate Bipolar Transistor).
[0020] In addition, the power converter unit 10 includes an AC current sensor 18 for detecting an AC current value. The AC current detection value IA from the AC current sensor 18 is input to the control unit 11. The AC current detection value from the AC current sensor 18 is multiplied by the pulse duty value of the power converter unit 10 to obtain a DC current estimated value.
[0021] The control unit 11 includes at least a power converter control unit 19, a control core 20, and a gate driver 21. As is well known, these have a microcomputer as the main component.
[0022] The power converter control unit 19 has a function of generating a command signal for a gate driver 22 that generates gate pulses for the switching elements 14u to 15w of the upper arm and the lower arm.
[0023] The control core 20 has a control information generation function of generating control information corresponding to a diagnostic function and the load of the motor. Of course, it also has other functions. These functions are executed by a plurality of individual control cores that make up the control core 20.
[0024] Also, the gate driver 22 generates gate pulses that control the gates of the respective switching elements of the power converter unit 10 based on a control signal from the power converter control unit 19. The gate pulses are duty-controlled.
[0025] Here, the control unit 11 is configured to communicate with an external control device via CAN (Controller Area Network) or the like, and has a microcomputer having a processor such as an A / D converter and a CPU (Central Processing Unit), a rewritable storage memory such as a RAM (Random Access Memory), a read-only storage memory such as a ROM (Read Only Memory), etc. as the main component.
[0026] Next, embodiments of the present invention will be described with reference to Figures 2 to 4. In this embodiment, the memory protection function is assumed to utilize the access protection function of the microcomputer so that authorized control cores can access only specific memory areas.
[0027] Figure 2 shows the main components of a functional block related to this embodiment in a vehicle control device using a multi-core microcomputer. This functional block includes at least a plurality of individual control cores 30-0, 30-1 to 30-N and a core-shared RAM 40. Each of the control cores 30-0, 30-1 to 30-N is equipped with an arithmetic function unit, a timer management function unit, etc., for executing program instructions stored in memory (not shown), and each performs processing related to a specific function.
[0028] For example, control core (0) 30-0 performs a fault diagnosis function (executed by software) to diagnose the occurrence and location of abnormalities in the vehicle. Control core (1) 30-1 performs a power converter control function (executed by software) to control the power converter unit 10. Furthermore, the other control cores (N) 30-N perform other control functions (executed by software) for controlling the vehicle. The number of these control cores used is the number required to control the vehicle.
[0029] Each control core (0)30-0, control core (1)30-1 to control core (N)30-N functions by executing program instructions. In addition, control core (0)30-0, control core (1)30-1 to control core (N)30-N are equipped with management functions as defined by functional safety standards.
[0030] In this embodiment, control core (0) 30-0 includes a memory protection execution unit 31 and an ASIL (Automotive Safety Integrity Level) function execution unit 32 that ensures the safety of the control system. Control cores (1) 30-1 to control cores (N) 30-N also include QM (Quality Management) function execution units 33-1 to 33-N other than the ASIL function. The memory protection execution unit 31, the ASIL function execution unit 32, and the QM function execution units 33-1 to 33-N are also basically operated by software.
[0031] In functional safety standards, ASIL-D is assigned to automotive components that are used specifically to ensure safety. Examples of such functions include airbags, brakes, and power steering.
[0032] Other ranks include ASIL-C for engines, transmissions, and functions such as cruise control; ASIL-B for headlights and brake lights; and ASIL-A for taillights and body parts. Furthermore, parts that do not require an ASIL rating are assigned a rank called QM (Quality Management).
[0033] The memory protection execution unit 31 of control core (0) 30-0 performs access protection settings (shown in Figure 3) for each control core (0) 30-0, control core (1) 30-1 to control core (N) 30-N when the microcomputer starts up.
[0034] Therefore, after access protection is configured, if unauthorized access by a control core (hereinafter sometimes referred to as unauthorized access) is detected, an unauthorized access error handling process is executed. The details of this unauthorized access error handling process are shown in the flowchart in Figure 4.
[0035] The core-shared RAM 40 is configured with separate memory areas allocated to each control core, for storing data used by each control core (0) 30-0, control core (1) 30-1 to control core (N) 30-N.
[0036] Control core (0) 30-0 is allocated a reference area 41 and a backup area 42 for control core (0). The reference data in the reference area 41 and the backup data in the backup area 42 for control core (0) have the same data content and are overwritten or updated simultaneously. These storage areas basically store data related to ASIL.
[0037] Furthermore, the reference data and backup data stored in the reference area 41 and backup area 42 for the control core (0) each contain multiple data points, and if unauthorized access occurs, there is a risk that at least some of the data points may be modified. Of course, it is also possible that no changes will be made.
[0038] Here, the claim refers to the control core (0) reference area 41 as the "first memory" and the control core (0) backup area 42 as the "second memory". Furthermore, the reference data stored in the control core (0) reference area 41 is referred to as the "first reference data", and the backup data stored in the control core (0) backup area 42 is referred to as the "second reference data".
[0039] For example, if there is unauthorized access to the reference area 41 for the control core (0), the backup area 42 for the control core (0) is inverted and defined as the reference data for the control core (0) reference area 41 and used in its place. This will be explained later.
[0040] Furthermore, control core (1) 30-1 is allocated a reference area 43-1 for control core (1), and control core (N) 30-N is allocated a reference area 43-N for core N. These memory areas basically store data related to QM.
[0041] In this embodiment, the reference area 41 for control core (0) and the backup area 42 for control core (0) are storage areas that can only be accessed by control core (0) 30-0, and the same data is stored in them. On the other hand, control cores (1) 30-1 to control cores (N) 30-N are prohibited from accessing the reference area 41 for control core (0) and the backup area 42 for control core (0) (this would be unauthorized access).
[0042] In Figure 2, permitted access to the control core (0) reference area 41 and the control core (0) backup area 42 is indicated by solid arrows, and prohibited access is indicated by dotted arrows. Furthermore, the solid arrows between the control core (0) reference area 41 and the control core (0) backup area 42 indicate that unauthorized access will reverse the memory area referenced by the control core (0) 30-0.
[0043] When the ASIL function execution unit 32 processes data to rewrite or update it, not only the reference area 41 for the control core (0) that references the data when software control is executed, but also the backup area 42 for the control core (0O) that backs up the data is simultaneously rewritten or updated. At this time, the data that is rewritten or updated is the same data and is compatible with each other.
[0044] The memory protection execution unit 31 has two functions: (1) memory protection setting processing and (2) unauthorized access error handling processing.
[0045] In the memory protection setting process, when the multicore microcomputer starts up, access protection settings are executed so that only control core (0)30-0 can access the reference area 41 for control core (0) and the backup area 42 for control core (0). On the other hand, the reference areas 43-1 for control core (1) to 43-N for control core (N) are permitted to be accessed by control core (0)30-0 and control core (1)30-1 to control core (N)30-N.
[0046] Figure 3 shows an example of access protection settings for each control core that accesses each memory area allocated to the core shared RAM 40. In the access protection settings table shown in Figure 3, the columns represent each memory area of the core shared RAM 40, and the rows represent the control cores that access each memory area.
[0047] For example, control core (0) 30-0 has access permissions to the reference area 41 for control core (0), the backup area 42 for control core (0), and the reference areas 43-1 to 43-N for control core (1) and control core (N), and can access them.
[0048] On the other hand, control cores (1) 30-1 to control cores (N) 30-N are not granted access permissions to the reference area 41 for control core (0) and the backup area 42 for control core (0), and access is prohibited. However, access permissions are granted to the reference areas 43-1 for control core (1) to the reference areas 43-N for control core (N), and access is possible.
[0049] Because access rules are defined in this way, for example, if control core (1) 30-1 attempts to access the reference area 41 for control core (0) or the backup area 42 for control core (0), access is prohibited, and therefore, unauthorized access error handling processing is executed.
[0050] Figure 4 is a flowchart showing the unauthorized access error handling process in the memory protection execution unit 31 and the ASIL function execution unit 32.
[0051] ≪Step S10≫ In step S10, unauthorized access error handling processing is executed in synchronization with a predetermined startup cycle. During the execution of this unauthorized access error handling processing, the following steps are performed.
[0052] ≪Step S11≫ In step S11, for example, if control core (1) 30-1 attempts to access the reference area 41 for control core (0), as shown by the dashed line in Figure 2, there is a risk that the reference data in the reference area 41 for control core (0) may be modified due to unauthorized access. As mentioned earlier, the reference data consists of multiple data, and there is a risk that at least some of these data may be modified.
[0053] Therefore, in step S11, it is determined whether or not there is unauthorized access to the reference area 41 for the control core (0). If it is determined that there is unauthorized access (YES), the process proceeds to step S12; if it is determined that there is no unauthorized access (NO), the process proceeds to step S16.
[0054] At this time, it is also preferable to determine whether or not there has been unauthorized access to the backup area 42 for the control core (0). This is because if there has been unauthorized access to the backup area 42 for the control core (0), there is a risk that the backup data in the backup area 42 for the control core (0) may have been altered.
[0055] Therefore, if there is no unauthorized access to the backup area 42 for the control core (0), the process can proceed to step S12. Even if unauthorized access occurs, if the data is subsequently restored, it can be treated as if no unauthorized access occurred.
[0056] On the other hand, if there is unauthorized access to the backup area 42 for the control core (0), the reference area 41 for the control core (0) will also be considered to have been accessed without authorization. Therefore, since both sets of data are unreliable, a restart can be performed to address the issue.
[0057] ≪Step S12≫ In step S11, it is determined that unauthorized access has occurred to the reference area 41 for the control core (0). Therefore, in step S12, the ASIL function execution unit 32 switches the data reference destination from the reference area 41 for the control core (0) to the backup area 42 for the control core (0). As explained in step S11, even if some of the reference data is modified due to unauthorized access, all of the reference data is switched to the backup data. Since the backup area 42 for the control core (0) has not been subjected to unauthorized access, the backup data is legitimate data.
[0058] Therefore, the ASIL function execution unit 32 can continue control by referring to the regular backup data in the backup area 42 for the control core (0). When the reference destination is changed to the backup area 42 for the control core (0), the process proceeds to step S13.
[0059] ≪Step S13≫ In step S13, the reference data in the control core (0) reference area 41 and the backup data in the control core (0) backup area 42 are compared. If there is a difference between the respective data, it is assumed that the data in the control core (0) reference area 41 has been modified due to unauthorized access, and the process proceeds to step S14.
[0060] On the other hand, if there are no differences in the respective data, even if there has been unauthorized access, it is assumed that the data has not been changed, and the process proceeds to step S15.
[0061] ≪Step S14≫ In step S13, it is determined that there is a difference in the data, so in step S14, the data with the difference in the reference area 41 for the control core (0) is repaired based on the data in the backup area 42 for the control core (0). Once the data repair is complete, the process proceeds to step S15.
[0062] ≪Step S15≫ In step S15, the identification information of the current reference area is saved. That is, information that identifies the reference area 41 for control core (0) and the backup area 42 for control core (0) is saved.
[0063] The reason for this is that if data is modified due to unauthorized access and then restored, the relationship between the control core (0) reference area 41 and the control core (0) backup area 42 is reversed, and the control core (0) reference area 41 is defined as the control core (0) backup area 42, and the control core (0) backup area 42 is defined as the control core (0) reference area 41.
[0064] Once step S15 is complete, the process exits to the end and prepares for the next activation timing.
[0065] ≪Step S16≫ Returning to step S11, since it has been determined that there is no unauthorized access (NO determination), in step S16, the reference data in the reference area 41 for the control core (0) and the backup data in the backup area 42 for the control core (0) are compared. If there is a difference between the respective data, it is assumed that the data in the reference area 41 for the control core (0) has been modified for some reason, and the process proceeds to step S17.
[0066] On the other hand, if there are no differences in the respective data, the data is considered unchanged, and the process exits to prepare for the next startup timing.
[0067] ≪Step S17≫ In step S16, it is determined that there is a difference in the data, so in step S17, the data with the difference in the backup area 42 for the control core (0) is repaired based on the data in the reference area 41 for the control core (0). Once the data repair is complete, the process exits to the end and prepares for the next startup timing.
[0068] In a control flow that performs such operations, when the ASIL function execution unit 32 rewrites or updates the reference data in the control core (0) reference area 41, the same data is simultaneously rewritten or updated not only in the control core (0) reference area 41 but also in the control core (0) backup area 42.
[0069] This makes it possible to access the backup data in the backup area 42 for the control core (0) at any time after the reference data in the reference area 41 for the control core (0) has been stored. In other words, even if there is unauthorized access to one of the storage areas and the data is changed, the data in the other storage area will be considered the legitimate data, so control can continue without the need for restarts or other processes.
[0070] Furthermore, if unauthorized access occurs to the control core (0) reference area 41 (which is the current reference area) referenced by the ASIL function execution unit 32, the data reference destination is switched from the control core (0) reference area 41 to the control core (0) backup area 42. This ensures that even if there is unauthorized access to the control core (0) reference area 41, the system can be stabilized by switching to the data in the control core (0) backup area 42. In addition, if there are changes to the reference data in the control core (0) reference area 41, the reference data in the control core (0) reference area 41 can be restored based on the backup data in the control core (0) backup area 42.
[0071] On the other hand, if unauthorized access occurs to the backup area 42 for control core (0) (which is the current backup area), and there are changes to the backup data in the backup area 42 for control core (0), the data in the backup area 42 for control core (0) will be repaired based on the data in the reference area 41 for control core (0).
[0072] This allows for repair even if there is unauthorized access to the backup area 42 for the control core (0). However, in this case, the reference destination is not changed and remains the backup area 42 for the control core (0). By not switching the reference destination, unauthorized access to data can be prevented. In other words, the reference area 41 for the control core (0), which was not subjected to unauthorized access, will be used.
[0073] Furthermore, the relationship between the control core (0) reference area 41 and the control core (0) backup area 42 is configured to be reversed each time there is unauthorized access to the control core (0) reference area 41. For example, if there is unauthorized access to the control core (0) reference area 41, the control core (0) backup area 42 becomes the control core (0) reference area 41, and the repaired control core (0) reference area 41 becomes the control core (0) backup area 42. This process is repeated thereafter.
[0074] In this way, by using the data in the backup area 42 for the control core (0) to repair the reference area 41 for the control core (0), further backup data can be created. Therefore, even if there are multiple unauthorized accesses, it is possible to protect the data by switching between the reference area 41 and the backup area 42 for the control core (0).
[0075] As described above, the present invention is a vehicle control device equipped with a multicore microcomputer having multiple control cores for controlling a vehicle, wherein the multicore microcomputer includes a first memory in which first reference data referenced by the implemented software is stored, and a second memory in which second reference data identical to the first reference data is stored, and further, the multicore microcomputer is characterized by having a determination function that determines whether access to the first reference data stored in the first memory was received from a regular control core or from a control core other than a regular control core, and a reference data switching function that, if it is determined that access to the first reference data stored in the first memory was received from a control core other than a regular control core, switches the reference data referenced by the software from the first reference data stored in the first memory to the second reference data stored in the second memory.
[0076] Furthermore, in a memory protection method for a vehicle control device equipped with a multicore microcomputer having multiple control cores for controlling a vehicle, the multicore microcomputer includes a first memory where first reference data referenced by the implemented software is stored, and a second memory where second reference data identical in content to the first reference data is stored. The multicore microcomputer is characterized by performing a determination step to determine whether it has received access from a legitimate control core that is authorized to access the first and second reference data, or from a control core other than a legitimate control core that is not authorized to access the first and second reference data; a reference data switching step to switch the reference data referenced by the software from the first reference data to the second reference data if it is determined that the access to the first reference data was from a control core other than a legitimate control core; and a data repair step to repair the first reference data using the second reference data if it is determined that the first reference data was accessed from a control core other than a legitimate control core.
[0077] According to this, even if data in memory becomes abnormal due to unauthorized access, normal data can be provided, and furthermore, data based on this abnormality can be repaired more reliably.
[0078] Furthermore, the present invention is not limited to the embodiments described above, and various modifications are included. The embodiments described above are explained in detail for the purpose of clearly illustrating the present invention, and are not necessarily limited to those having all the configurations described. In addition, it is possible to replace parts of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of one embodiment. It is also possible to add, delete, or replace other configurations for the configuration of each embodiment. [Explanation of Symbols]
[0079] 10...Power converter unit, 11...Control unit, 19...Power converter control unit, 20...Control core, 21...Gate driver, 30-0, 30-1, 30-N...Control core, 31...Memory protection execution unit, 32...ASIL function execution unit, 33-1~33-N...QM function execution unit, 40...Core shared RAM, 41...Reference area for control core (0), 42...Backup area for control core (0), 43-1~43-N12...Reference area for control core (1)~Reference area for control core (N).
Claims
1. In a vehicle control system equipped with a multicore microcomputer having multiple control cores for controlling the vehicle, The aforementioned multicore microcomputer is The system comprises a first memory in which first reference data referenced by the implemented software is stored, and a second memory in which second reference data having the same content as the first reference data is stored. Furthermore, the multicore microcomputer is A determination function that determines whether the access to the first reference data and the second reference data was received from a legitimate control core authorized to access them, or from a control core other than the legitimate control core, The software also includes a reference data switching function that, if the determination function determines that access to the first reference data is from a control core other than the regular control core, switches the reference data referenced by the software from the first reference data to the second reference data. A vehicle control device characterized by the following features.
2. In the vehicle control device according to claim 1, The regular control core simultaneously rewrites or updates the first reference data in the first memory and the second reference data in the second memory. A vehicle control device characterized by the following features.
3. In the vehicle control device according to claim 1, The aforementioned reference data switching function is, If the second reference data is accessed by a control core other than the regular control core, the second reference data is not referenced. A vehicle control device characterized by the following features.
4. In the vehicle control device according to claim 1, The aforementioned multicore microcomputer is If it is determined that the first reference data has been accessed from a control core other than the designated control core, the system includes a data repair function that uses the second reference data to repair the first reference data. A vehicle control device characterized by the following features.
5. In the vehicle control device according to claim 1, The first reference data in the first memory and the second reference data in the second memory each contain multiple data, The reference data switching function, if it determines that access to the first reference data is from a control core other than the regular control core, interrupts access to all of the multiple data in the first reference data and switches to accessing all of the multiple data in the second reference data. A vehicle control device characterized by the following features.
6. In the vehicle control device according to claim 1, The aforementioned reference data switching function switches the reference data referenced by the software from the first reference data to the second reference data, provided that it is determined that there is no access to the second reference data from any control core other than the designated control core. A vehicle control device characterized by the following features.
7. In the vehicle control device according to claim 4, The aforementioned reference data switching function is, The switched second reference data is defined as the new first reference data, and the restored first reference data is defined as the new second reference data. A vehicle control device characterized by the following features.
8. A method for protecting the memory of a vehicle control device equipped with a multicore microcomputer having multiple control cores for controlling a vehicle, The aforementioned multicore microcomputer is The system comprises a first memory in which first reference data referenced by the implemented software is stored, and a second memory in which second reference data having the same content as the first reference data is stored. The aforementioned multicore microcomputer is A determination step to determine whether the access to the first reference data and the second reference data was received from a legitimate control core authorized to access them, or from a control core other than the legitimate control core, If it is determined that the access to the first reference data is from a control core other than the regular control core, the software switches the reference data it references from the first reference data to the second reference data in a reference data switching step. If it is determined that the first reference data has been accessed from a control core other than the regular control core, a data repair step is performed in which the first reference data is repaired using the second reference data. A method for protecting the memory of a vehicle control device, characterized by the features described above.
Citation Information
Patent Citations
Storage controller and storage unit management program
JP2018022333A