In-vehicle network system and control method for an in-vehicle network system
The in-vehicle network system with adaptive cluster configuration management ensures efficient ECU startup control by switching to abnormal operation modes when anomalies occur, addressing software update requirements and management control device malfunctions.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2026-04-02
AI Technical Summary
Conventional in-vehicle network systems face challenges in managing the startup conditions of ECUs when software updates require different startup criteria, and malfunctions in management ECUs can lead to improper ECU activation, wasting power and potentially causing system inefficiencies.
The system includes multiple control devices connected via a communication bus, with a management control device capable of switching cluster configuration information to normal or abnormal operation modes based on detected anomalies, ensuring proper ECU startup even in the presence of management control device malfunctions.
This approach allows for appropriate control of ECU startups, reducing power wastage and ensuring system efficiency by dynamically adapting to changes in startup conditions and communication anomalies.
Smart Images

Figure 2026057393000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an in-vehicle network system having a plurality of control devices connected to a communication bus and capable of communicating with each other in a vehicle, and a control method for the in-vehicle network system.
Background Art
[0002] For example, Patent Document 1 discloses an in-vehicle network system including a host ECU, an intermediate ECU, and a subordinate ECU. In the in-vehicle network system of Patent Document 1, power is supplied to the intermediate ECU from a power source, and in response to a message received from the host ECU, power from the power source is supplied to the subordinate ECU. That is, the intermediate ECU maintains the subordinate ECU in a power-off state until a message is received from the host ECU. When a message from the host ECU is received by the intermediate ECU, power from the power source is supplied to the subordinate ECU. The subordinate ECU transitions from the power-off state to a standby state in which it waits for an instruction by this power supply.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] As described above, in the conventional in-vehicle network system described in Patent Document 1, a specific ECU (for example, an intermediate ECU) is configured to manage the states of other ECUs (for example, subordinate ECUs).
[0005] However, if the relationship between other ECUs and a specific ECU that manages the state of those ECUs is fixed, it becomes difficult to finely manage the state of other ECUs. For this reason, it has been put into practice to assign each ECU to a cluster, which is a group of ECUs that are started simultaneously to achieve a desired function, and then use network management messages to start or put each ECU in a cluster into a sleep state.
[0006] On the other hand, in recent years, it has become possible for the software of the ECU installed in a vehicle to be updated after the vehicle has been sold and is on the market, for example, by the vehicle user downloading an application of their choice. In this case, depending on the function of the downloaded application, the ECU with the updated software may be required to start up not only when the conditions set before the update are met, but also when different conditions are met instead.
[0007] Therefore, if it is necessary to change the startup conditions for an ECU with updated software, a specific management ECU of the in-vehicle network system may receive cluster configuration information corresponding to the changed startup conditions from an external source (e.g., the application provider) and modify the cluster configuration information indicating the cluster to which the ECU with the updated software belongs.
[0008] However, in this case, if a malfunction occurs in the management ECU or if there is a problem with communication with the management ECU, the management ECU may not be able to properly change the cluster configuration information of each ECU. As a result, there is a risk that the startup of the ECUs may not be properly controlled, for example, by starting up at an unintended time, thus wasting power.
[0009] This disclosure has been made in view of the above-mentioned points, and aims to provide an in-vehicle network system and a control method for an in-vehicle network system that can appropriately control the startup of a control device subject to startup control, even if a malfunction occurs in the management control device capable of changing the cluster setting information of the control device subject to startup control, or if a malfunction occurs in communication with the management control device. [Means for solving the problem]
[0010] To achieve the above objective, the in-vehicle network system according to this disclosure is an in-vehicle network system having a plurality of control devices (10, 20, 30, 40, 50, 60, 70, 80, 90, 100) connected to a communication bus in a vehicle and capable of communicating with each other, Multiple control devices (10, 20, 30, 50, 60, 70, 80, 90, 100) that are subject to startup control will enter or maintain a startup state if a network management message (hereinafter referred to as NM message) transmitted from another control device contains startup cluster information that matches the cluster in the cluster configuration information and indicates the cluster to be started. The multiple control devices further include a management control device (40) capable of changing the cluster configuration information of multiple control devices subject to startup control. Multiple control devices subject to startup control have cluster configuration information, including cluster configuration information for normal operation and cluster configuration information for when an abnormality occurs. If at least one control unit targeted for startup control detects an abnormality in the management control unit or in communication with the management control unit, it switches the cluster configuration information for normal operation to the cluster configuration information for when an abnormality occurs.
[0011] Furthermore, the control method for an in-vehicle network system according to this disclosure is a control method for an in-vehicle network system having a plurality of control devices (10, 20, 30, 40, 50, 60, 70, 80, 90, 100) connected to a communication bus in a vehicle and capable of communicating with each other, Multiple control devices (10, 20, 30, 50, 60, 70, 80, 90, 100) that are subject to startup control will enter or maintain a startup state if a network management message (hereinafter referred to as NM message) transmitted from another control device contains startup cluster information that matches the cluster in the cluster configuration information and indicates the cluster to be started. The multiple control devices further include a management control device (40) capable of changing the cluster configuration information of multiple control devices subject to startup control. Multiple control devices subject to startup control have cluster configuration information, including cluster configuration information for normal operation and cluster configuration information for when an abnormality occurs. At least one control device subject to startup control detects that an abnormality has occurred in the management control device or in communication with the management control device (S100), and The system includes the following step: if at least one control unit targeted for startup control detects an abnormality in the management control unit or an abnormality in communication with the management control unit, it switches the cluster configuration information for normal operation to the cluster configuration information for when an abnormality occurs (S110).
[0012] According to the in-vehicle network system and control method for the in-vehicle network system disclosed herein, the control device subject to startup control has, in advance, cluster setting information for normal operation and cluster setting information for when an abnormality occurs. When an abnormality occurs in the management control device or when an abnormality occurs in communication with the management control device, at least one control device subject to startup control that detects the abnormality switches the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs. As a result, at least one control device subject to startup control is started up according to the cluster setting information for when an abnormality occurs. This makes it possible to appropriately control the startup of the control devices subject to startup control even when an abnormality occurs in the management control device or when an abnormality occurs in communication with the management control device.
[0013] The reference numbers in parentheses above are merely examples of correspondences with specific configurations in embodiments described later, in order to facilitate understanding of this disclosure, and are not intended to limit the scope of this disclosure in any way.
[0014] Furthermore, technical features described in each claim of the patent claims, other than those described above, will become clear from the description of the embodiments and the accompanying drawings, which will be discussed later. [Brief explanation of the drawing]
[0015] [Figure 1] This is a configuration diagram showing an example of the configuration of an in-vehicle network system according to the first embodiment. [Figure 2] This is an explanatory diagram illustrating an example of an NM message, PN request information, and PNC configuration information. [Figure 3] This figure shows an example of a PNC setting table stored in the memory unit of the power / startup management ECU. [Figure 4] This figure shows an example of relay connection information stored in the memory unit of the power / startup management ECU. [Figure 5] This flowchart shows an example of processing performed in the power / startup management ECU and subordinate ECUs of the first embodiment. [Figure 6] It is a flowchart showing details of the activation ECU identification process in the flowchart of FIG. 6. [Figure 7] It is a flowchart showing an example of a process executed in the power / activation management ECU of the second embodiment. [Figure 8] It is a flowchart showing an example of a process executed in the power / activation management ECU of the third embodiment. [Figure 9] It is an explanatory diagram for explaining the operation in the in-vehicle network system according to the third embodiment. [Figure 10] It is a flowchart showing an example of a process executed in the power / activation management ECU of the fourth embodiment. [Figure 11] It is a flowchart showing an example of a process executed in the power / activation management ECU of the fifth embodiment.
Mode for Carrying Out the Invention
[0016] Hereinafter, embodiments of an in-vehicle network system and a control method for an in-vehicle network system according to the present disclosure will be described with reference to the drawings. However, the present disclosure is not limited to the following embodiments, and various modifications described hereinafter are also included in the technical scope of the present disclosure. Furthermore, various changes can be made and implemented without departing from the gist of the present disclosure. Embodiments and various modifications can be appropriately combined and implemented as long as there is no technical contradiction. In the following description, the same or similar configurations may be given the same reference numerals in a plurality of drawings, and the description may be omitted. Also, when only a part of the configuration is mentioned, the description described elsewhere can be applied to other parts.
[0017] (First Embodiment) Figure 1 is a configuration diagram showing an example of the configuration of the in-vehicle network system 200 according to this embodiment. As shown in Figure 1, the in-vehicle network system 200 includes a power / startup management ECU 10, a first higher-level ECU 40, and a second higher-level ECU 80 as higher-level control devices, and first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 as lower-level control devices. ECU is an abbreviation for Electronic Control Unit. The power supply lines 6 of the first and second lower-level ECUs 20 and 30 are provided with first and second relay circuits 17 and 18, which are switched on and off by the power / startup management ECU 10. On the other hand, the third to seventh lower-level ECUs 50, 60, 70, 90, and 100 are supplied with power directly from the power supply circuit 4 without going through relay circuits such as the first and second relay circuits 17 and 18. In addition, power is supplied from the power supply circuit 4 to the power / startup management ECU 10, the first higher-level ECU 40, and the second higher-level ECU 80.
[0018] The power / startup management ECU 10, the first and second higher ECUs 40, 80, and the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 may each be composed of a computer equipped with a processor, memory, and storage, etc. The power / startup management ECU 10, the first and second higher ECUs 40, 80, and the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 also have communication interfaces (communication IFs) 11, 21, 31, 41, 51, 61, 71, 81, 91, and 101 for communicating with other ECUs via communication buses 19a, 19b, 19c, 43a, 43b, 82a, and 82b.
[0019] More specifically, the communication IF11 of the power / startup management ECU10 is connected to the communication IFs41 and 81 of the first and second higher ECUs40 and 80 via communication bus 19a. Furthermore, the communication IF11 of the power / startup management ECU10 is connected to the communication IF21 of the first lower ECU20 via communication bus 19b. Additionally, the communication IF11 of the power / startup management ECU10 is connected to the communication IF31 of the second lower ECU30 via communication bus 19c. The communication IF41 of the first higher ECU40 is connected to the communication IFs51 and 61 of the third and fourth lower ECUs50 and 60 via communication bus 43a. Furthermore, the communication IF41 of the first higher ECU40 is connected to the communication IF71 of the fifth lower ECU70 via communication bus 43b. The communication IF81 of the second higher ECU80 is connected to the communication IF91 of the sixth lower ECU90 via communication bus 82a. Furthermore, the communication IF81 of the second higher ECU80 is connected to the communication IF101 of the seventh lower ECU100 via the communication bus 82b. The communication IF11 of the power / startup management ECU10 and the communication IF41 and 81 of the first and second higher ECUs40 and 80 are configured to act as gateways when the first to seventh lower ECUs20,30,50,60,70,90,100, which are connected to different communication buses 19a,19b,19c,43a,43b,82a,82b, communicate with each other.
[0020] A processor is, for example, a CPU (Central Processing Unit), MPU (Micro Processing Unit), GPU (Graphics Processing Unit), or DFP (Data Flow Processor) that executes predetermined processes according to a program. Memory is a volatile storage medium that temporarily stores the results of the processor's calculations, such as RAM (Random Access Memory). Storage is a non-volatile storage medium such as flash memory or ROM (Read Only Memory). Various programs and data executed by the processor are stored in the storage. Some or all of the functions of the power / start management ECU 10, the first and second higher ECUs 40 and 80, and the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 may be implemented by hardware, such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field-Programmable Gate Array), rather than by software such as a program.
[0021] The in-vehicle network system 200 can use CAN (registered trademark, hereinafter the same) as a communication protocol for the power / startup management ECU 10, the first and second higher-level ECUs 40 and 80, and the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 to communicate with each other. CAN is an abbreviation for Controller Area Network. However, the communication protocol is not limited to CAN, and the in-vehicle network system 200 may adopt another communication protocol such as CAN-FD (CAN with Flexible Data Rate). However, in the in-vehicle network system 200 of this embodiment, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 are divided into multiple groups (these groups are called clusters) for each ECU that needs to be started simultaneously to realize at least one desired function. Then, using network management messages (hereinafter referred to as NM messages) described later, each cluster can be switched between a normal operation mode (startup state) and a power saving mode (e.g., sleep state). The power-saving mode includes the power-off state of the first and second lower ECUs 20 and 30. Therefore, the communication protocol used in the in-vehicle network system 200 must be compatible with sending and receiving NM messages.
[0022] The power / startup management ECU 10 and the first and second higher-level ECUs 40 and 80 may each function as domain controllers that oversee the control of the first and second lower-level ECUs 20 and 30, the third to fifth lower-level ECUs 50, 60 and 70, and the sixth and seventh lower-level ECUs 90 and 100, respectively. A domain refers to a functional unit when the functions of a vehicle are broadly divided, such as a vehicle powertrain domain, chassis domain, advanced driver assistance domain, body domain, and cockpit domain. The above is just one example of domain division, and the domain division may differ from the example above. In addition, the power / startup management ECU 10 and the first and second higher-level ECUs 40 and 80 may each function as area controllers that oversee the control of the first and second lower-level ECUs 20 and 30, the third to fifth lower-level ECUs 50, 60 and 70, and the sixth and seventh lower-level ECUs 90 and 100 located in each area of the vehicle.
[0023] The first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 are, for example, control ECUs for controlling a predetermined control object in a vehicle, or sensor ECUs that calculate a predetermined physical quantity based on detection signals detected by sensors. When it is necessary to control a control object or to calculate a predetermined physical quantity based on detection signals from sensors, the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 are activated in normal operation mode and perform normal operations. On the other hand, when it is not necessary to control a control object or to calculate a predetermined physical quantity, the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 are power-off or in sleep mode in power-saving mode.
[0024] To switch between this startup state and a power-off or sleep state, the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 are each assigned to a cluster within a group of divided clusters. The assigned cluster is then stored in each ECU as cluster configuration information (also referred to as PNC configuration information). PNC is an abbreviation for Partial Networking Clustering. However, the PNC configuration information for the first and second lower ECUs 20 and 30 is stored in the storage unit 14 of the power / startup management ECU 10, as will be described later. Then, in response to a request to start the cluster to which each ECU 20, 30, 50, 60, 70, 90, and 100 belongs, based on the startup cluster information (also referred to as PN request information) contained in the NM message, the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 are configured to switch from a power-off or sleep state to a startup state. Furthermore, PNC setting information may be defined for the power / startup management ECU 10 and the first and second higher-level ECUs 40 and 80.
[0025] The first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100, upon entering a startup state and transitioning to normal operation mode, periodically send NM messages to other ECUs while performing their normal operations. The power / startup management ECU 10, as well as the first and second higher ECUs 40 and 80, also periodically send NM messages while they need to continue control. After performing the necessary processing, the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 stop sending periodic NM messages when they no longer need to perform normal operations. The third to seventh lower ECUs 50, 60, 70, 90, and 100 transition from normal operation mode to power-saving mode and switch from startup state to sleep state when the time spent without receiving NM messages from other ECUs belonging to the same cluster reaches a predetermined waiting period. With respect to the first and second lower ECUs 20 and 30, the power / startup management ECU 10 monitors NM messages directed to the first and second lower ECUs 20 and 30. When the time during which no NM messages are received directed to the first and second lower ECUs 20 and 30 reaches a predetermined waiting period, the power / startup management ECU 10 turns off the first and second relay circuits 17 and 18, stopping the power supply to the first and second lower ECUs 20 and 30.
[0026] The third to seventh lower ECUs 50, 60, 70, 90, and 100 have communication IFs 51, 61, 71, 91, and 101 that can receive NM messages while in sleep mode and switch the third to seventh lower ECUs 50, 60, 70, 90, and 100 from sleep mode to wake mode in response to the reception of an NM message. When woken up by communication IFs 51, 61, 71, 91, and 101, the third to seventh lower ECUs 50, 60, 70, 90, and 100 each determine whether or not their own wake-up is requested based on the PN request information and PNC setting information of the NM message. If they determine that their own wake-up is requested, the third to seventh lower ECUs 50, 60, 70, 90, and 100 remain in the wake-up state. On the other hand, if they determine that their own wake-up is not requested, the third to seventh lower ECUs 50, 60, 70, 90, and 100 return to sleep mode. Furthermore, the determination based on the PN request information and PNC setting information of the NM message may be configured to be performed at communication IFs 51, 61, 71, 91, and 101. In this case, when communication IFs 51, 61, 71, 91, and 101 determine that a startup is requested based on the PN request information and PNC setting information, they transition the corresponding ECU from sleep state to startup state. Examples of NM messages, PN request information, and PNC setting information are described in detail below.
[0027] An NM message contains data from bytes 0 to 7, as shown in Figure 2, for example. Byte 0 contains the Node ID (NID). The Node ID is a unique identifier for each of the power / startup management ECU 10, the first and second upper ECUs 40 and 80, and the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100. The Node ID allows identification of the source of the NM message. Byte 1 contains the Control Bit Vector (CBV). The Control Bit Vector is data indicating whether or not partial networking is being used. If the Control Bit Vector indicates the use of partial networking, the user data area in bytes 2 to 7 contains PN request information, which is startup cluster information indicating the cluster to be started. Partial networking means that only the ECUs belonging to some clusters are started, while the ECUs belonging to the remaining clusters are powered off or in sleep mode. In this way, by starting only the ECUs that need to operate, the power consumption of each ECU installed in the vehicle can be reduced.
[0028] In the example shown in Figure 2, the control bit vector indicates the use of partial networking, and PN request information is stored in bytes 6 and 7 of the user data area. The user data area from bytes 2 to 5 can be used to transmit any information, such as the ECU activation factor or information regarding normal or abnormal operation. Note that Figure 2 is merely one example of the format of an NM message, and NM messages may take other formats as long as they include information on whether partial networking is being used and the PN request information.
[0029] PN request information indicates which clusters should be started and which do not need to be started for each of the multiple divided clusters. More specifically, in the example shown in Figure 2, the clusters are pre-divided into 16. The PN request information contains 16 bits of data corresponding to the 16 divided clusters. In other words, the 16 bits of data in the PN request information are pre-associated with the 16 divided clusters. When each of the 16 bits of data in the PN request information is "0", it indicates that the associated cluster does not need to be started. On the other hand, when each of the 16 bits of data in the PN request information is "1", it indicates that the associated cluster needs to be started.
[0030] As described above, the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 each possess PNC setting information that indicates the cluster to which they belong among multiple divided clusters. An example of this PNC setting information is shown in Figure 2. More specifically, Figure 2 shows an example of PNC setting information held by any one of the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100. In the PNC setting information shown in Figure 2, if the corresponding clusters are classified as A to P from left to right in the figure, the PNC setting information in Figure 2 indicates that the ECU holding this PNC setting information belongs to clusters D, H, and J. The first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, and 100 can perform various functions through program execution and other means, and therefore can belong to one or more clusters.
[0031] When the third to seventh lower ECUs 50, 60, 70, 90, and 100 receive an NM message containing PN request information via their respective communication IFs 51, 61, 71, 91, and 101, they compare the PN request information and PNC setting information bit by bit, as shown in Figure 2, and calculate, for example, a logical AND. In other words, when the third to seventh lower ECUs 50, 60, 70, 90, and 100 receive an NM message via their respective communication IFs 51, 61, 71, 91, and 101, they enter an activated state. Then, the third to seventh lower ECUs 50, 60, 70, 90, and 100 determine whether the clusters requested to be activated by the PN request information contained in the NM message match the clusters of PNC setting information assigned to the third to seventh lower ECUs 50, 60, 70, 90, and 100, respectively. For example, in the example shown in Figure 2, the clusters requested to be activated by the PN request information are clusters D, G, I, M, N, and O. The clusters to which the ECU belongs, as indicated by the PNC configuration information, are clusters D, H, and J. In this case, in cluster D, the cluster to which activation is requested by the PN request information contained in the NM message matches the cluster in the PNC configuration information. Therefore, as shown in Figure 2, the result of the logical AND is "1" in cluster D.
[0032] If the logical AND result results in any bit being "1", the ECU with the PNC configuration information shown in Figure 2 determines that it is being requested to start up. Based on this determination, the ECU with the PNC configuration information shown in Figure 2 will, for example, remain in the state transitioned from sleep to the start state, and will maintain the start state if it is already in the start state. On the other hand, if the logical AND result does not result in any bit being "1", and all bits are "0", the ECU with the PNC configuration information shown in Figure 2 determines that it is not being requested to start up. In this case, the ECU with the PNC configuration information shown in Figure 2 discards the received NM message and returns to the sleep state.
[0033] Thus, the third to seventh lower ECUs 50, 60, 70, 90, and 100 have a function to identify whether an NM message requests the activation of their own ECU, based on the PNC setting information. Due to this function to identify NM messages, only the third to seventh lower ECUs 50, 60, 70, 90, and 100, which have PNC setting information including the cluster that has been requested to be activated by the PN request information, will be activated by the NM message. Hereinafter, an ECU that has a function to receive an NM message while in sleep mode and switch the ECU from sleep mode to activation mode will be referred to as an NM-compatible ECU.
[0034] In the in-vehicle network system 200 according to this embodiment, the first and second lower ECUs 20 and 30 do not necessarily have to be NM-compatible ECUs. In other words, the first and second lower ECUs 20 and 30 may both be non-NM-compatible ECUs. As described above, an NM-compatible ECU has a communication interface that receives an NM message while the ECU is in sleep mode and switches the ECU from sleep mode to wake mode. For this reason, NM-compatible ECUs are more expensive than non-NM-compatible ECUs. As described above, the first and second lower ECUs 20 and 30 may be non-NM-compatible ECUs. Therefore, by using the first and second lower ECUs 20 and 30, which are non-NM-compatible ECUs, as lower-level control devices, the overall cost of the in-vehicle network system 200 can be reduced.
[0035] In this embodiment, the in-vehicle network system 200 is configured such that, even though the first and second lower-level ECUs 20 and 30 are both non-NM compatible ECUs, the first and second lower-level ECUs 20 and 30 are subject to partial networking in response to NM messages, and the power / startup management ECU 10 is configured accordingly. The power / startup management ECU 10 according to this embodiment will be described in detail below.
[0036] As shown in Figure 1, the power / startup management ECU 10 includes a communication IF 11, a startup management unit 12, a power management unit 13, a storage unit 14, an anomaly detection unit 15, a PNC switching unit 16, and first and second relay circuits 17 and 18. The startup management unit 12, the power management unit 13, the anomaly detection unit 15, and the PNC switching unit 16 are functional units built within the power / startup management ECU 10 by software and / or hardware. The storage unit 14 may be configured by the storage of the power / startup management ECU 10.
[0037] The first relay circuit 17 is located on the power supply line 6 for supplying power to the first lower ECU 20. In other words, the power line of the first lower ECU 20 is connected to the first power port 17a connected to the first relay circuit 17. The second relay circuit 18 is located on the power supply line 6 for supplying power to the second lower ECU 30. In other words, the power line of the second lower ECU 30 is connected to the second power port 18a connected to the second relay circuit 18.
[0038] Furthermore, the number of relay circuits provided in the power / startup management ECU 10 may be three or more, not just two. Also, the number of lower-level ECUs connected to each relay circuit may be two or more, not just one. In addition, in the in-vehicle network system 200, there may be multiple sets of combinations of upper-level ECUs and lower-level ECUs that can turn the power supply to the lower-level ECUs on and off, not just one set.
[0039] The power supply circuit 4 can, as needed, convert the power supply voltage of the vehicle's battery 2 to the operating voltage of the power / startup management ECU 10, the first and second higher ECUs 40 and 80, and the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100. The power supply lines 6 to the power / startup management ECU 10, the first and second higher ECUs 40 and 80, and the first to seventh lower ECUs 20, 30, 50, 60, 70, 90, and 100 are supplied with voltage from the power supply circuit 4.
[0040] The first and second relay circuits 17 and 18 can be composed of semiconductor switches such as MOSFETs and IGBTs. However, the first and second relay circuits 17 and 18 may be composed of ordinary mechanical relays instead of semiconductor switches. Furthermore, the first and second relay circuits 17 and 18 may be provided inside the power supply / startup management ECU 10, as shown in Figure 1, or they may be provided outside the power supply / startup management ECU 10.
[0041] The power / startup management ECU 10 is an NM-compatible ECU capable of receiving NM messages. The first and second lower ECUs 20 and 30 may be non-NM-compatible ECUs, as described above. In this embodiment, the first and second lower ECUs 20 and 30 enter a power-off state in power-saving mode when operation is not required. Therefore, the first and second lower ECUs 20 and 30 cannot receive NM messages when in power-saving mode. For this reason, the communication IF 11 of the power / startup management ECU 10 receives NM messages that selectively instruct the first and second lower ECUs 20 and 30 to start up, on their behalf. The NM messages received by the communication I / F 11 are provided to the startup management unit 12.
[0042] Here, the storage unit 14 of the power / startup management ECU 10 stores PNC setting information that indicates the cluster to which each of the first and second lower ECUs 20 and 30 belongs, in addition to the program executed by the processor of the power / startup management ECU 10. This PNC setting information includes PNC setting information for normal operation and PNC setting information for when an abnormality occurs. Furthermore, the storage unit 14 stores relay connection information that indicates the correspondence between the first and second relay circuits 17 and 18 and the first and second lower ECUs 20 and 30. For example, the storage unit 14 can store PNC setting information indicating the cluster to which each of the first and second lower ECUs 20 and 30 is assigned, using a PNC setting table as shown in Figure 3. The PNC setting table illustrated in Figure 3 shows an example of the correspondence between node IDs, which are unique identifiers for multiple subordinate ECUs including the first and second subordinate ECUs 20 and 30, and PNC setting information assigned to multiple subordinate ECUs including the first and second subordinate ECUs 20 and 30. Furthermore, the storage unit 14 stores relay connection information that shows the correspondence between the first and second relay circuits 17 and 18 and the first and second subordinate ECUs 20 and 30, as illustrated in Figure 4, which includes the correspondence between the numbers of multiple relay circuits including the first and second relay circuits 17 and 18 or the power port numbers and node IDs that indicate the unique identifiers for multiple subordinate ECUs including the first and second subordinate ECUs 20 and 30.
[0043] The startup management unit 12 of the power / startup management ECU 10 can obtain PNC setting information for the first and second lower ECUs 20 and 30 by referring to the PNC setting table illustrated in Figure 3. Based on the obtained PNC setting information for the first and second lower ECUs 20 and 30 and the PN request information of the NM message, the startup management unit 12 can determine which lower ECU 20 or 30 was instructed to start by the NM message. Specifically, the startup management unit 12 compares the PN request information of the NM message with the PNC setting information for the first and second lower ECUs 20 and 30 bit by bit. Based on the comparison result, if the startup management unit 12 determines that there is PNC setting information that includes a cluster that was requested to start by the PN request information, it determines that the startup of the lower ECU 20 or 30 corresponding to that PNC setting information has been instructed. In this case, the startup management unit 12 provides the power management unit 13 with a node ID indicating the lower ECU 20 or 30 that was instructed to start by the NM message. On the other hand, if the startup management unit 12 determines that there is no PNC configuration information including the cluster that was requested to be started by the PN request information, it discards the NM message because the received NM message does not instruct the startup of any of the lower ECUs 20 or 30.
[0044] When the power management unit 13 of the power / startup management ECU 10 receives the node IDs of the subordinate ECUs 20 and 30 that have been instructed to start up by the startup management unit 12, it refers to the relay connection information stored in the memory unit 14, which shows the correspondence between each relay circuit 17 and 18 and each subordinate ECU 20 and 30. The power management unit 13 then identifies the relay circuits 17 and 18 corresponding to the node IDs of the subordinate ECUs 20 and 30 that have been instructed to start up, and outputs a drive signal to turn on the identified relay circuits 17 and 18. As a result, power is supplied to the subordinate ECUs 20 and 30 that have been instructed to start up via the corresponding relay circuits 17 and 18, and the corresponding subordinate ECUs 20 and 30 enter the startup state.
[0045] The first and second lower ECUs 20 and 30 control various controllable devices mounted on the vehicle that are controlled only when specific conditions are met or under specific environmental conditions (e.g., door locking mechanisms, power window drive motors, headlight light sources, wiper motors, AV equipment, etc.), or calculate predetermined physical quantities necessary for such control based on sensor detection signals. For example, the door locking mechanism is controlled by the door lock control ECU when a vehicle user is about to get into or out of the vehicle. The power window drive motor is controlled by the power window control ECU when the window up / down switch is operated by the user.
[0046] Thus, the first and second lower ECUs 20 and 30 control controlled devices that operate only when specific conditions are met or under specific environments, or calculate predetermined physical quantities necessary for such control. Therefore, when the power / startup management ECU 10 receives an NM message instructing it to start the first and second lower ECUs 20 and 30, it turns on the first and second relay circuits 17 and 18 corresponding to the first and second lower ECUs 20 and 30 to supply power to them. On the other hand, when the power / startup management ECU 10 does not receive an NM message instructing it to start the first and second lower ECUs 20 and 30, it turns off the first and second relay circuits 17 and 18 to stop supplying power to the first and second lower ECUs 20 and 30. This cuts down on the dark current when the operation of each lower ECU 20 and 30 is not required, making it possible to further reduce power consumption for the entire in-vehicle system.
[0047] NM messages can be generated, for example, by the power / startup management ECU 10, the first higher-level ECU 40, and / or the second higher-level ECU 80 as a function of a domain controller or area controller. In this case, the power / startup management ECU 10, the first higher-level ECU 40, and / or the second higher-level ECU 80 determine the function to be performed in the vehicle based on signals from various sensors and switches. If the power / startup management ECU 10, the first higher-level ECU 40, and / or the second higher-level ECU 80 determine that the execution of the desired function is necessary, they further determine the cluster to which the ECUs that need to be in an activated state simultaneously when performing the relevant function belong, and generate an NM message containing PN request information designating it as the activation cluster. The generated NM message is transmitted via communication buses 19a, 19b, 19c, 43a, 43b, 82a, 82b to the first to seventh lower-level ECUs 20, 30, 50, 60, 70, 90, 100, etc. Furthermore, if an NM message is generated by, for example, the power / startup management ECU 10, it is also used to determine whether the power / startup management ECU 10 itself needs to switch to the startup state of its subordinate ECUs 20 and 30. However, the function of determining the function to be performed in the vehicle and sending an NM message containing PN request information may be possessed by other ECUs, such as the first to seventh subordinate ECUs 20, 30, 50, 60, 70, 90, and 100, in addition to or instead of the power / startup management ECU 10 and the first and second higher ECUs 40 and 80.
[0048] Furthermore, the power / startup management ECU 10, the first higher-level ECU 40, and / or the second higher-level ECU 80 may enter a sleep state if all ECUs belonging to the in-vehicle network system 200 are in a sleep state or power-off state and a predetermined time has passed during which they have not received an NM message.
[0049] Furthermore, a PNC setting information modification unit 42 that modifies the PNC setting information assigned to each of the lower ECUs 20, 30, 50, 60, 70, 90, and 100 may be implemented in any of the ECUs belonging to the in-vehicle network system 200, such as the power / start management ECU 10 or the first and second higher-level ECUs 40 and 80. Figure 1 shows an example in which the PNC setting information modification unit 42 is implemented in the first higher-level ECU 40.
[0050] The first higher-level ECU 40, on which the PNC setting information change unit 42 is implemented, has an external communication device capable of wirelessly communicating with an external server such as a data center. The first higher-level ECU 40 is configured to download application programs for realizing new functions in the vehicle, or update programs for upgrading programs already implemented in any of the ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, or 100, from the data center via the external communication device. The downloaded programs are provided to the corresponding ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, or 100 via communication buses 19a, 19b, 19c, 43a, 43b, 82a, and 82b, and the installation of new application programs or rewriting with update programs is performed. Note that the ECU that communicates with the data center via the external communication device and the ECU on which the PNC setting information change unit 42 is implemented may be separate ECUs.
[0051] For ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 that have new application programs or updates implemented, it may be necessary to add or modify the startup conditions for the corresponding ECUs depending on the functionality of the application programs or updates. Therefore, if it is necessary to add or modify the startup conditions for an ECU with an implemented application program or update, the data center will have the first higher-level ECU 40 download new PNC configuration information corresponding to the addition or modification of the startup conditions, along with the application program or update.
[0052] When the PNC configuration information change unit 42 obtains new PNC configuration information from the data center, it changes (rewrites) the PNC configuration information held in ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 on which the application program or update program is implemented to the new PNC configuration information. As a result, ECUs 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 on which the application program or update program is implemented switch from sleep state to wake state according to the cluster indicated by the changed PNC configuration information. The rewriting of the PNC configuration information may be performed in the corresponding ECU after receiving a rewrite instruction from the PNC configuration information change unit 42 along with the new PNC configuration information. Alternatively, the rewriting of the PNC configuration information may be performed by the PNC configuration information change unit 42 by accessing the memory of the corresponding ECU.
[0053] The PNC setting information change unit 42 can be located outside the in-vehicle network system 200, for example, in a data center, rather than being an ECU belonging to the in-vehicle network system 200. However, if the PNC setting information change unit 42 is implemented in an ECU belonging to the in-vehicle network system 200, the PNC setting information change unit 42 can terminate communication with the outside once it has obtained data from an external source to change the PNC setting information of the ECU. On the other hand, if the PNC setting information change unit 42 is located on a server outside the in-vehicle network system 200, each ECU that needs to change its PNC setting information will need to communicate with the external server individually via an ECU equipped with an external communication device. This may result in the disadvantage of increased communication volume with the external server.
[0054] If an abnormality occurs in the first upper-level ECU 40, which is equipped with the PNC setting information modification unit 42 corresponding to the management control device of this disclosure, or if an abnormality occurs in communication with the first upper-level ECU 40, the first upper-level ECU 40 may not be able to properly modify the PNC setting information of each lower-level ECU. As a result, there is a risk that the startup of the ECUs may not be properly controlled, for example, at least one ECU may start up at an unintended time in response to an NM message, wasting power.
[0055] Therefore, in the in-vehicle network system 200 according to this embodiment, the power / startup management ECU 10 is provided with an abnormality detection unit 15 that detects abnormalities in the first higher-level ECU 40 and / or abnormalities in communication with the first higher-level ECU 40. Furthermore, if the abnormality detection unit 15 detects an abnormality in the first higher-level ECU 40 and / or abnormalities in communication with the first higher-level ECU 40, a PNC switching unit 16 is provided that switches the PNC setting information of at least the first and second lower-level ECUs 20 and 30 from the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. The abnormality detection unit 15 and the PNC switching unit 16 will be described in detail below.
[0056] The power / startup management ECU 10 is configured to periodically communicate with the first higher-level ECU 40 via the communication bus 19a. If this periodic communication is interrupted for a predetermined period of time, the abnormality detection unit 15 of the power / startup management ECU 10 can detect that an abnormality has occurred in communication with the first higher-level ECU 40. At this time, the first higher-level ECU 40 can also detect that an abnormality has occurred in communication with the power / startup management ECU 10 because communication has been interrupted.
[0057] Furthermore, when the power / startup management ECU 10 and the first higher-level ECU 40 communicate via CAN, the abnormality detection unit 15 can detect that an abnormality has occurred in communication with the first higher-level ECU 40 if it detects an abnormality in the received communication data itself due to a communication error, such as a bit error, format error, ACK error, CRC error, or stuffing error in the communication frame (communication data). Note that the method for detecting communication errors may differ depending on the communication standard and communication method. It is preferable that the power / startup management ECU 10 notifies the first higher-level ECU 40 that it has detected an abnormality in the communication data. This allows the first higher-level ECU 40 to also detect that an abnormality has occurred in communication with the power / startup management ECU 10.
[0058] Furthermore, the power / startup management ECU 10 may have a function to monitor whether the first higher-level ECU 40 is operating normally based on control-related data values received from the first higher-level ECU 40. For example, the power / startup management ECU 10 may receive control-related data values such as control command values that the first higher-level ECU 40 outputs to the third to fifth lower-level ECUs 50, 60, and 70, sensor detection values calculated by the first higher-level ECU 40 which form the basis for calculating control command values, and / or the self-diagnosis results of the first higher-level ECU 40.
[0059] When the abnormality detection unit 15 of the power supply / startup management ECU 10 receives control command values and / or sensor detection values as data values related to control, it can determine whether the first higher-level ECU 40 is functioning normally based on whether each data value falls within a predetermined range that can be considered normal. In other words, the abnormality detection unit 15 can detect an abnormality in the first higher-level ECU 40 if the received data values deviate from the predetermined range. Furthermore, when the abnormality detection unit 15 receives the self-diagnosis result of the first higher-level ECU 40 as data values related to control, it can detect an abnormality in the first higher-level ECU 40 if the self-diagnosis result indicates that some kind of abnormality has occurred in the first higher-level ECU 40. Note that the self-diagnosis result of the first higher-level ECU 40 is included in the data values related to control because it affects the control of the first higher-level ECU 40 and other ECUs.
[0060] The above describes an example in which the abnormality detection unit 15 of the power supply / startup management ECU 10 detects an abnormality in the first higher-level ECU 40 and an abnormality in communication with the first higher-level ECU 40. However, the abnormality detection unit that detects the abnormality of the first higher-level ECU 40 and the abnormality detection unit that detects the abnormality in communication with the first higher-level ECU 40 may be provided in separate ECUs. For example, the power supply / startup management ECU 10 may be provided with an abnormality detection unit that detects the abnormality in communication with the first higher-level ECU 40, and the third to fifth lower-level ECUs 50, 60, and 70, which are subordinate ECUs of the first higher-level ECU 40, may be provided with an abnormality detection unit that detects the abnormality of the first higher-level ECU 40. Furthermore, the above describes an example in which the abnormality detection unit 15 is provided in the power supply / startup management ECU 10. However, the abnormality detection unit 15 may be provided in an ECU other than the power supply / startup management ECU 10. Moreover, the abnormality detection unit 15 may be provided in multiple ECUs, including the power supply / startup management ECU 10.
[0061] When the abnormality detection unit 15 detects an abnormality in the first higher-level ECU 40 and / or an abnormality in communication with the first higher-level ECU 40, the PNC switching unit 16 of the power / startup management ECU 10 switches the PNC setting information of at least the first and second lower-level ECUs 20 and 30 from the PNC setting information for normal operation to the PNC setting information for abnormal situations. If PNC setting information is also defined for the power / startup management ECU 10, the PNC switching unit 16 can also switch the PNC setting information of the power / startup management ECU 10 to the PNC setting information for abnormal situations.
[0062] To enable this switching, the memory unit 14 stores PNC setting information for normal operation and PNC setting information for abnormal situations for at least each of the lower ECUs 20 and 30. If no abnormality is detected in the first higher ECU 40, and / or in communication with the first higher ECU 40, the PNC setting information for normal operation is used as the PNC setting information for each of the lower ECUs 20 and 30. However, if an abnormality is detected in the first higher ECU 40, and / or in communication with the first higher ECU 40, the PNC switching unit 16 switches the PNC setting information for normal operation to the PNC setting information for abnormal situations, as described above. As a result, the power / startup management ECU 10 can switch between the startup state and the power-off state of at least the lower ECUs 20 and 30 based on NM messages, according to the PNC setting information for abnormal situations. Furthermore, even if an abnormality occurs in the first higher-level ECU 40, and / or in communication with the first higher-level ECU 40, the power / startup management ECU 10 can receive NM messages from the second higher-level ECU 80, the first or second lower-level ECUs 20 and 30, and the sixth or seventh lower-level ECUs 90 and 100, etc.
[0063] In the PNC setting information for when an anomaly occurs, the cluster to which at least the lower-level ECUs responsible for executing controls related to vehicle operation and occupant safety belong is set to be activatable. This ensures that even if an anomaly occurs in the first higher-level ECU 40, and / or an anomaly occurs in communication with the first higher-level ECU 40, the vehicle's operation and occupant safety can be ensured. Therefore, for example, the driver of the vehicle can safely drive the vehicle to a safe evacuation site or the nearest repair shop. For example, lower-level ECUs responsible for executing controls related to vehicle operation include ECUs responsible for powertrain (engine and motor) control, steering control, brake control, and headlight control. Lower-level ECUs responsible for executing controls related to occupant safety include ECUs responsible for airbag control, advanced driver-assistance systems (ADAS) control, and emergency call system control.
[0064] Conversely, in the PNC setting information for when an anomaly occurs, clusters that do not contain lower-level ECUs involved in the execution of vehicle driving and occupant safety controls are targeted for being set to be inoperable. For example, lower-level ECUs not involved in the execution of vehicle driving and occupant safety controls include ECUs involved in the execution of navigation control, audio control, interior lighting control, and seat control. By setting lower-level ECUs not involved in the execution of vehicle driving and occupant safety controls to be inoperable, power saving can be achieved, and a sufficient evacuation distance for the vehicle can be ensured. It should be noted that in the PNC setting information for when an anomaly occurs, it is not necessary to set all clusters that do not contain lower-level ECUs involved in the execution of vehicle driving and occupant safety controls to be inoperable. For example, it is sufficient to set at least one of the clusters that do not contain lower-level ECUs involved in the execution of vehicle driving and occupant safety controls to be inoperable.
[0065] The PNC switching unit 16, like the abnormality detection unit 15, can be provided in multiple ECUs (upper ECUs and lower ECUs) that hold PNC setting information. Preferably, the ECU that first detects an abnormality in the first upper ECU 40 and / or an abnormality in communication with the first upper ECU 40 (for example, the power / startup management ECU 10) transmits information to the other multiple ECUs that hold PNC setting information to switch the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. Preferably, in response to receiving this information, each PNC switching unit 16 in the multiple ECUs that hold PNC setting information switches the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. This makes it possible to set the ECUs related to the execution of vehicle driving and occupant safety control to be startable, and the ECUs not related to the execution of vehicle driving and occupant safety control to be instartable.
[0066] The transmission of information to switch the PNC setting information for normal operation to the PNC setting information for abnormal operation may include, for example, an ECU that has detected an abnormality in the first higher-level ECU 40 and / or an abnormality in communication with the first higher-level ECU 40 notifying that it has switched to the PNC setting information for abnormal operation. Furthermore, the transmission of information to switch the PNC setting information for normal operation to the PNC setting information for abnormal operation may include an ECU that has detected an abnormality in the first higher-level ECU 40 and / or an abnormality in communication with the first higher-level ECU 40 sending instructions to multiple other ECUs to switch to the PNC setting information for abnormal operation. In addition, if the first higher-level ECU 40 detects, for example, an abnormality in communication with at least one ECU, the first higher-level ECU 40 may also transmit information to multiple other ECUs that hold PNC setting information to switch the PNC setting information for normal operation to the PNC setting information for abnormal operation.
[0067] Thus, in the in-vehicle network system 200 according to this embodiment, if an abnormality occurs in the first higher-level ECU 40 or if an abnormality occurs in communication with the first higher-level ECU 40, at least one ECU that detects the abnormality switches from the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. As a result, at least one ECU is started up according to the PNC setting information for when an abnormality occurs. This makes it possible to appropriately control the startup of at least one ECU that detects the abnormality, even if an abnormality occurs in the first higher-level ECU 40 or if an abnormality occurs in communication with the first higher-level ECU 40.
[0068] Next, an example of the processing performed by the power / startup management ECU 10 and the first and second lower-level ECUs 20 and 30 will be explained with reference to the flowcharts in Figures 5 and 6. Note that if the abnormality detection unit 15 and the PNC switching unit 16 are also provided in other ECUs, similar processing will be performed, except for the control for turning the relay circuit on and off.
[0069] In step S100, the power / startup management ECU 10 determines whether it has detected an abnormality in the first higher-level ECU 40 and / or an abnormality in communication with the first higher-level ECU 40. If it determines that an abnormality has been detected, the power / startup management ECU 10 proceeds to the process in step S110. On the other hand, if it determines that no abnormality has been detected, the power / startup management ECU 10 proceeds to the process in step S130.
[0070] In step S110, the power / startup management ECU 10 switches the PNC setting information of at least the first and second lower ECUs 20 and 30 from the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. Then, in step S120, the power / startup management ECU 10 transmits information to several other ECUs that hold PNC setting information to switch the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs.
[0071] In step S130, the power / startup management ECU 10 receives or generates an NM message. In step S140, the power / startup management ECU 10 performs a startup ECU identification process to identify the subordinate ECUs 20 and 30 that have been instructed to start by the NM message. Details of this startup ECU identification process are shown in the flowchart of Figure 6. The startup ECU identification process will now be explained with reference to the flowchart in Figure 6.
[0072] In step S300, the power / startup management ECU 10 identifies the cluster for which startup is requested based on the PN request information in the NM message. In step S310, the power / startup management ECU 10 reads the PNC setting information of multiple lower ECUs 20 and 30 from the storage unit 14. At this time, if the PNC setting information has been switched from the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs, the power / startup management ECU 10 reads the PNC setting information for when an abnormality occurs from the storage unit 14. Then, in step S320, the power / startup management ECU 10 identifies the PNC setting information that includes the cluster that matches the cluster for which startup has been requested (startup request cluster) based on the PN request information.
[0073] In step S330, the power / startup management ECU 10 determines whether, in step S320, at least one PNC setting information among the PNC setting information of multiple subordinate ECUs 20 and 30 was identified as PNC setting information containing a cluster that matches the startup request cluster. If at least one PNC setting information is identified, the power / startup management ECU 10 proceeds to the process in step S340. On the other hand, if no identified PNC setting information exists, the power / startup management ECU 10 proceeds to the process in step S350.
[0074] In step S340, the power / startup management ECU 10 sets the subordinate ECUs 20 and 30 corresponding to the identified PNC setting information as start-up ECUs, and sets the other subordinate ECUs 20 and 30 as non-startup ECUs. On the other hand, in step S350, the power / startup management ECU 10 sets all subordinate ECUs 20 and 30 as non-startup ECUs. After that, the power / startup management ECU 10 returns to the process shown in the flowchart of Figure 5.
[0075] In step S150 of the flowchart in Figure 5, the power / startup management ECU 10 determines whether there are any subordinate ECUs 20 and 30 that have been set as startup ECUs. If there are any subordinate ECUs 20 and 30 that have been set as startup ECUs, the power / startup management ECU 10 proceeds to the process in step S160. On the other hand, if there are no subordinate ECUs 20 and 30 that have been set as startup ECUs, the power / startup management ECU 10 terminates the process shown in the flowchart in Figure 5. In this case, the NM message is discarded.
[0076] In step S160, the power / startup management ECU 10 turns on the relay circuits 17 and 18 connected to the lower-level ECUs 20 and 30, which are set as the startup ECUs, based on the relay connection information stored in the memory unit 14 that shows the correspondence between each relay circuit 17 and 18 and each lower-level ECU 20 and 30. The power / startup management ECU 10 also turns off the relay circuits 17 and 18 connected to the lower-level ECUs 20 and 30, which are set as the non-startup ECUs.
[0077] When relay circuits 17 and 18 are turned on, the lower ECUs 20 and 30 begin receiving power, as shown in step S200 of the flowchart in Figure 5. As a result, the lower ECUs 20 and 30, with relay circuits 17 and 18 turned on, undergo predetermined startup processes in step S210 and enter a startup state.
[0078] As described above, according to the in-vehicle network system 200 of this embodiment, the power / startup management ECU 10 receives NM messages that selectively instruct the startup of multiple lower-level ECUs 20 and 30, transmitted via the communication bus, on behalf of the multiple lower-level ECUs 20 and 30. The power / startup management ECU 10 then turns on the relay circuits 17 and 18 connected to the lower-level ECUs 20 and 30 that have been instructed to start by the NM message. As a result, the lower-level ECUs 20 and 30 that have been instructed to start enter the startup state. Therefore, according to the in-vehicle network system 200 of this embodiment, it is possible to finely manage the supply and shutdown of power to the lower-level ECUs 20 and 30 while configuring the system to switch the power supply of the lower-level ECUs 20 and 30 from a stopped state to a supplied state in response to the NM message instructing startup.
[0079] (Second Embodiment) Next, a second embodiment of the in-vehicle network system and control method for the in-vehicle network system according to this disclosure will be described. The in-vehicle network system according to this embodiment is configured similarly to the in-vehicle network system 200 according to the first embodiment. Therefore, a description of the configuration will be omitted.
[0080] Figure 7 is a flowchart showing an example of the processing performed in the power supply / startup management ECU 10 according to this embodiment. In the flowchart of Figure 7, steps that perform the same processing as shown in the flowchart of Figure 5 are assigned the same step numbers, and their explanations are omitted.
[0081] As shown in the flowchart of Figure 7, in step S120, the power supply / startup management ECU 10 in this embodiment transmits information to multiple other ECUs that hold PNC setting information to switch the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. Then, in step S122, the power supply / startup management ECU 10 stops abnormality determination based on the interruption of communication with other ECUs for a predetermined time.
[0082] As described above, each lower-level ECU 20, 30, 50, 60, 70, 90, and 100, once it enters a powered-up state and transitions to normal operation mode, periodically sends NM messages to other ECUs while it is performing its normal operation. Furthermore, the power / startup management ECU 10, as well as the first and second higher-level ECUs 40 and 80, also periodically send NM messages while they need to continue control. Therefore, if communication between each ECU 10, 20, 30, 40, 50, 60, 70, 80, 90, and 100 and the ECU with which it is supposed to periodically send and receive NM messages is interrupted for a predetermined period of time or longer, it can determine that some kind of abnormality, including a communication error, has occurred in that ECU.
[0083] However, the switching of PNC setting information in lower-level ECUs 20 and 30 by the power / startup management ECU 10, and the switching of PNC setting information in multiple other ECUs based on the information used to switch the PNC setting information for normal operation to the PNC setting information for abnormal operation, do not necessarily occur simultaneously. Therefore, due to the timing of the switching, the cluster that should be in the startup state based on the PNC setting information may differ among multiple ECUs. Consequently, if an abnormality is detected based on a communication interruption between ECUs, an incorrect abnormality detection may occur.
[0084] Therefore, in this embodiment, the process in step S122 stops the abnormality determination based on the interruption of communication with other ECUs for a predetermined period of time corresponding to the period during which the switching of PNC setting information is completed in multiple ECUs, including the power supply / startup management ECU 10. This prevents incorrect abnormality determination based on the interruption of communication with other ECUs.
[0085] (Third embodiment) Next, a third embodiment of the in-vehicle network system and control method for the in-vehicle network system according to this disclosure will be described. The in-vehicle network system according to this embodiment is configured similarly to the in-vehicle network system 200 according to the first embodiment. Therefore, a description of the configuration will be omitted.
[0086] Figure 8 is a flowchart showing an example of the processing performed in the power supply / startup management ECU 10 according to this embodiment. In the flowchart of Figure 8, steps that perform the same processing as shown in the flowchart of Figure 5 are assigned the same step numbers, and their explanations are omitted.
[0087] As shown in the flowchart of Figure 8, in step S124, the power supply / startup management ECU 10 according to this embodiment determines whether the remaining charge of the battery 2 has decreased to a predetermined value or less. If this determination process determines that the remaining charge of the battery 2 has decreased to a predetermined value or less, the power supply / startup management ECU 10 proceeds to the process in step S126.
[0088] In step S126, the power / startup management ECU 10 switches the PNC setting information for when an abnormality occurs so that the number of clusters set to be startable is reduced. In this way, by changing the number of clusters that are started by the PNC setting information for when an abnormality occurs according to the remaining charge of battery 2, it becomes easier to secure power for emergency driving.
[0089] In this embodiment, the storage unit 14 stores multiple types of PNC setting information with different numbers of clusters set to be bootable, as PNC setting information for when an abnormality occurs. The multiple types of PNC setting information may, for example, have different numbers of clusters set to be non-bootable within clusters to which ECUs related to the execution of vehicle driving and occupant safety control belong. Furthermore, the multiple types of PNC setting information may, for example, have different numbers of clusters set to be non-bootable within clusters to which ECUs related to the execution of vehicle driving and occupant safety control belong.
[0090] For example, Figure 9 shows an example where the number of clusters to be set to inoperable differs depending on the remaining charge of battery 2, within the cluster to which the ECUs responsible for executing vehicle operation and occupant safety control belong. Specifically, in the example shown in Figure 9, when the remaining charge of battery 2 is relatively high, the PNC setting information shows that both the cluster to which the ECUs responsible for executing vehicle operation (driving, stopping, turning) belong and the cluster to which the ECUs responsible for executing occupant safety control belong are set to be inoperable. On the other hand, when the remaining charge of battery 2 is relatively low, the PNC setting information shows that the cluster to which the ECUs responsible for executing vehicle operation control belong is set to be inoperable, but the cluster to which the ECUs responsible for executing occupant safety control belong is set to inoperable.
[0091] Furthermore, instead of, or in addition to, the remaining charge of battery 2, the cluster setting information for when an abnormality occurs may be switched so that the number of clusters set to be startable decreases depending on whether the elapsed time since the abnormality was detected exceeds a predetermined time, and / or whether the mileage traveled since the abnormality was detected exceeds a predetermined distance. In addition, by setting multiple thresholds for the remaining charge of battery 2, elapsed time, and / or mileage, the switching of the cluster setting information for when an abnormality occurs may be performed not just once, but multiple times.
[0092] (Fourth Embodiment) Next, a fourth embodiment of the in-vehicle network system and the control method for the in-vehicle network system according to this disclosure will be described. The in-vehicle network system according to this embodiment is configured similarly to the in-vehicle network system 200 according to the first embodiment. Therefore, a description of the configuration will be omitted.
[0093] Figure 10 is a flowchart showing an example of the processing performed in the power supply / startup management ECU 10 according to this embodiment. In the flowchart of Figure 10, steps that perform the same processing as shown in the flowchart of Figure 5 are assigned the same step numbers, and their explanations are omitted.
[0094] As shown in the flowchart of Figure 10, in step S100, the power / startup management ECU 10 of this embodiment determines that an abnormality has been detected in the first higher-level ECU 40 and / or an abnormality in communication with the first higher-level ECU 40, and then executes the process in step S102. In step S102, the power / startup management ECU 10 acquires environmental information such as time information, weather information, and / or outside temperature information at the time the abnormality occurred. Then, in step S112, the power / startup management ECU 10 switches the PNC setting information of each lower-level ECU 20, 30 from the PNC setting information for normal operation to the PNC setting information for when an abnormality occurs. The PNC setting information for when an abnormality occurs that is switched to is selected according to the environmental information acquired in step S102.
[0095] In this embodiment, the storage unit 14 stores multiple types of PNC setting information, which are set to suit the vehicle environment at any given time, as PNC setting information for when an abnormality occurs. The multiple types of PNC setting information may include, for example, PNC setting information suitable for daytime hours and PNC setting information suitable for nighttime hours, with different statuses for the activation of the cluster to which the ECU related to the control of lighting such as headlights belongs. Furthermore, the multiple types of PNC setting information may include, for example, PNC setting information for sunny days and PNC setting information for rainy days, with different statuses for the activation of the cluster to which the ECU related to the control of wipers belongs. In addition, the multiple types of PNC setting information may include, for example, PNC setting information for low temperature and high temperature and PNC setting information for normal temperature, with different statuses for the activation of the cluster to which the ECU related to the control of the air conditioner that controls the air conditioning in the vehicle interior and the equipment that controls the temperature of the traction battery belongs.
[0096] According to this embodiment, it is possible to use PNC setting information suitable for the vehicle environment at the time the abnormality occurs as PNC setting information for when an abnormality occurs.
[0097] Furthermore, this embodiment can be implemented in combination with the embodiments described above. For example, when combined with the third embodiment, multiple types of PNC setting information can be defined for multiple types of PNC setting information corresponding to the vehicle environment when an abnormality occurs, with different numbers of clusters that can be activated depending on the remaining battery level, elapsed time, and / or mileage.
[0098] (Fifth embodiment) Next, a fifth embodiment of the in-vehicle network system and control method for the in-vehicle network system according to this disclosure will be described. The in-vehicle network system according to this embodiment is configured similarly to the in-vehicle network system 200 according to the first embodiment. Therefore, a description of the configuration will be omitted.
[0099] Figure 11 is a flowchart showing an example of the processing performed in the power supply / startup management ECU 10 according to this embodiment. In the flowchart of Figure 11, steps that perform the same processing as shown in the flowchart of Figure 5 are assigned the same step numbers, and their explanations are omitted.
[0100] As shown in the flowchart of Figure 11, in step S128, the power supply / startup management ECU 10 in this embodiment turns on and off the first and second relay circuits 17 and 18 according to the PNC setting information for when an abnormality occurs, which was switched in step S110. In other words, regardless of whether an NM message is received, the power supply / startup management ECU 10 turns on the relay circuits of the lower ECUs belonging to the cluster indicating startup, and turns off the relay circuits of the lower ECUs belonging to the cluster not indicating startup, according to the PNC setting information for when an abnormality occurs that has been switched.
[0101] According to this embodiment, when an abnormality occurs in the first higher-level ECU 40, and / or an abnormality occurs in communication with the first higher-level ECU 40, the lower-level ECUs that are responsible for executing controls related to vehicle operation and occupant safety can be reliably activated.
[0102] In this embodiment, even if an NM message is received by the power / startup management ECU 10, the on / off control of the relay circuits 17 and 18 based on the NM message is not performed. The received NM message is discarded. In this embodiment, an example was described in which the first and second relay circuits 17 and 18 are turned on and off according to the PNC setting information for when an abnormality occurs. However, instead of using the PNC setting information for when an abnormality occurs, the relay circuits that should be turned on and the relay circuits that should be turned off may be determined in advance by considering the functions of each lower-level ECU 20 and 30, and the on / off information may be stored, and the first and second relay circuits 17 and 18 may be turned on and off based on the stored on / off information.
[0103] The systems and methods described in this disclosure may be implemented by a dedicated computer comprising a processor programmed to perform one or more functions embodied by a computer program. The systems and methods described in this disclosure may be implemented using dedicated hardware logic circuits. The systems and methods described in this disclosure may be implemented by one or more dedicated computers comprising a combination of a processor that executes a computer program and one or more hardware logic circuits. For example, some or all of the functions of the power / startup management ECU 10 may be implemented as hardware. Embodiments of implementing a certain function as hardware include embodiments using one or more ICs, etc. Some or all of the functions of the power / startup management ECU 10, etc., may be implemented using a system-on-chip (SoC), an integrated circuit (IC), or a field-programmable gate array (FPGA). The concept of an IC also includes an application-specific integrated circuit (ASIC). Furthermore, the computer program only needs to be stored on a computer-readable non-transitory tangible storage medium as instructions executed by the computer. Suitable storage media for the program include HDDs (Hard-disk drives), SSDs (Solid State Drives), flash memory, etc. The scope of this disclosure also includes the form of a program for causing the computer to function as a power / startup management ECU 10, and a non-transitory physical storage medium such as semiconductor memory on which this program is stored.
[0104] (Disclosure of technical ideas) Finally, this specification discloses several technical concepts described in several sections listed below. Some sections may be written in a polynomial form, selectively referencing several preceding sections. Furthermore, some sections may be written in a multiple polynomial form, referencing several sections, including other sections in a polynomial form. These sections written in polynomial and multiple polynomial forms define several technical concepts. Furthermore, the several technical concepts described in the sections listed below also apply to methods for controlling in-vehicle network systems.
[0105] (Technical thought 1) An in-vehicle network system having multiple control devices (10, 20, 30, 40, 50, 60, 70, 80, 90, 100) connected to a communication bus and capable of communicating with each other, Multiple control devices (10, 20, 30, 50, 60, 70, 80, 90, 100) have cluster configuration information indicating the cluster to which they belong among multiple divided clusters, and when a network management message (hereinafter referred to as an NM message) transmitted from another control device contains startup cluster information indicating the cluster to be started that matches the cluster in the cluster configuration information, they enter a startup state or maintain a startup state. The plurality of control devices further include a management control device (40) capable of changing the cluster setting information of the plurality of control devices targeted for startup control, Multiple of the aforementioned control devices subject to startup control have cluster setting information, including cluster setting information for normal operation and cluster setting information for when an abnormality occurs. An in-vehicle network system in which at least one of the startup-controlled control devices detects an abnormality in the management control device or an abnormality in communication with the management control device, and switches the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs.
[0106] (Technical thought 2) The in-vehicle network system according to Technical Concept 1, wherein the cluster setting information for when an abnormality occurs is configured to enable at least the cluster to which the control device related to the execution of control related to the vehicle's operation and the safety of the occupants belongs.
[0107] (Technical Thought 3) In the cluster setting information for when an abnormality occurs, the in-vehicle network system described in Technical Concept 2 is configured to disable the startup of clusters that do not include control devices related to the execution of vehicle driving and occupant safety controls.
[0108] (Technical Thought 4) An in-vehicle network system according to any one of technical concepts 1 to 3, wherein at least one of the startup control target control devices communicates periodically with the management control device, and detects an abnormality in communication with the management control device when the periodic communication is interrupted for a predetermined period of time and / or when an abnormality is detected in the received communication data itself.
[0109] (Technical Thought 5) An in-vehicle network system according to any one of technical concepts 1 to 4, wherein at least one of the startup control target control devices receives control-related data values from the management control device, and detects an abnormality in the management control device based on the received data values.
[0110] (Technical Thought 6) An in-vehicle network system according to any one of technical concepts 1 to 5, wherein at least one of the startup-controlled target control devices and / or the management control device, which has detected an abnormality in the management control device or an abnormality in communication with the management control device, transmits to other startup-controlled target control devices information for switching the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs.
[0111] (Technical Thought 7) The in-vehicle network system according to technical concept 6, wherein when a cluster setting information is switched based on the information, multiple of the aforementioned startup control target control devices stop determining abnormalities based on the interruption of communication with other startup control target control devices.
[0112] (Technical Thought 8) Multiple cluster configuration information sets are provided for when the aforementioned anomaly occurs. The in-vehicle network system according to any one of Technical Concepts 1 to 7, wherein the control device subject to startup control switches the cluster setting information for when an abnormality occurs so as to reduce the number of clusters that are set to be startable in accordance with the elapsed time since the abnormality occurred, the distance traveled since the abnormality occurred, and / or the decrease in the remaining charge of the battery that stores the power for the vehicle to run.
[0113] (Technical Thought 9) Multiple cluster configuration information sets are provided for when the aforementioned anomaly occurs. The in-vehicle network system according to any one of technical concepts 1 to 8, wherein the startup control target device selects one of the cluster setting information for use in the event of an abnormality from among a plurality of such cluster setting information, based on time information, weather information, and / or outside temperature information when an abnormality occurs.
[0114] (Technical Thought 10) Multiple control devices subject to startup control include a combination of a higher-level control device (10) and a lower-level control device that can switch the presence or absence of power supply to the lower-level control devices (20, 30) using a relay circuit. The higher-level control device has a storage unit (14) that stores cluster setting information indicating the cluster to which the lower-level control device belongs, The above-level control device receives the NM message on behalf of the lower-level control device, and when the cluster to be activated indicated by the activation cluster information of the NM message matches the cluster in the cluster setting information of the lower-level control device, it turns on the relay circuit to supply power to the lower-level control device and activate the lower-level control device, thereby bringing the lower-level control device into an activated state, according to any one of technical ideas 1 to 9.
[0115] (Technical Thought 11) The storage unit stores cluster setting information for normal operation and cluster setting information for abnormal situations as cluster setting information for the lower-level control device. The in-vehicle network system according to technical concept 10, wherein when the higher-level control unit detects an abnormality in the management control unit or an abnormality in communication with the management control unit, it switches the cluster setting information of the lower-level control unit from the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs.
[0116] (Technical Thought 12) Multiple lower-level control devices are provided, The relay circuit is provided in multiple locations according to the multiple lower-level control devices. The in-vehicle network system according to technical concept 10 or 11, wherein the storage unit stores relay connection information indicating the correspondence between the multiple lower-level control devices and the multiple relay circuits, in addition to the cluster setting information for each of the multiple lower-level control devices.
[0117] (Technical Thought 13) The above-level control unit turns on the relay circuit corresponding to the lower-level control unit whose startup cluster specified in the startup cluster information included in the NM message matches the cluster in the cluster setting information, and turns off the relay circuit corresponding to the lower-level control unit whose cluster does not match, based on the cluster setting information and the relay connection information, in the in-vehicle network system according to technical concept 12.
[0118] (Technical Thought 14) An in-vehicle network system according to any one of technical concepts 10 to 13, wherein the higher-level control device, upon detecting an abnormality in the management control device or an abnormality in communication with the management control device, turns on the relay circuit of the lower-level control device that is related to the execution of control relating to the vehicle's operation and the safety of the occupants, and turns off the relay circuit of the lower-level control device that is not related to the execution of control relating to the vehicle's operation and the safety of the occupants.
[0119] (Technical Thought 15) The above-level control device determines, based on the cluster setting information for when an abnormality occurs, whether or not the lower-level control device is involved in the execution of control related to the vehicle's operation and the safety of its occupants, in the in-vehicle network system according to technical concept 14. [Explanation of Symbols]
[0120] 2: Battery, 4: Power supply circuit, 6: Power supply line, 10: Power / startup management ECU, 11: Communication IF, 12: Startup management unit, 13: Power management unit, 14: Memory unit, 15: Anomaly detection unit, 16: PNC switching unit, 17: First relay circuit, 18: Second relay circuit, 20: First lower ECU, 21: Communication IF, 30: Second lower ECU, 40: First upper ECU, 42: PNC setting information change unit, 50: Third lower ECU, 60: Fourth lower ECU, 70: Fifth lower ECU, 80: Second upper ECU, 90: Sixth lower ECU, 100: Seventh lower ECU, 200: In-vehicle network system
Claims
1. An in-vehicle network system having multiple control devices (10, 20, 30, 40, 50, 60, 70, 80, 90, 100) connected to a communication bus and capable of communicating with each other, Multiple control devices (10, 20, 30, 50, 60, 70, 80, 90, 100) have cluster configuration information indicating the cluster to which they belong among multiple divided clusters, and when a network management message (hereinafter referred to as an NM message) transmitted from another control device contains startup cluster information indicating the cluster to be started that matches the cluster in the cluster configuration information, they enter a startup state or maintain a startup state. The plurality of control devices further include a management control device (40) capable of changing the cluster setting information of the plurality of control devices targeted for startup control, Multiple of the aforementioned control devices subject to startup control have cluster setting information, including cluster setting information for normal operation and cluster setting information for when an abnormality occurs. An in-vehicle network system in which at least one of the startup-controlled control devices detects an abnormality in the management control device or an abnormality in communication with the management control device, and switches the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs.
2. The in-vehicle network system according to claim 1, wherein the cluster setting information for when an abnormality occurs is configured to enable at least the cluster to which the control device related to the execution of control related to the driving of the vehicle and the safety of the occupants belongs.
3. The in-vehicle network system according to claim 2, wherein in the cluster setting information for when an abnormality occurs, clusters to which control devices related to the execution of control related to the driving of the vehicle and the safety of the occupants do not belong are to be set to be inoperable.
4. The in-vehicle network system according to any one of claims 1 to 3, wherein at least one of the startup control target control devices communicates periodically with the management control device, and detects an abnormality in communication with the management control device when the periodic communication is interrupted for a predetermined period of time and / or when an abnormality is detected in the received communication data itself.
5. The in-vehicle network system according to any one of claims 1 to 3, wherein at least one of the startup control target control devices receives control-related data values from the management control device, and detects an abnormality in the management control device based on the received data values.
6. An in-vehicle network system according to any one of claims 1 to 3, wherein at least one of the startup control target control devices and / or the management control device, which has detected an abnormality in the management control device or an abnormality in communication with the management control device, transmits to other startup control target control devices information for switching the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs.
7. The in-vehicle network system according to claim 6, wherein when a plurality of the startup control target control devices switch cluster setting information based on the information, they stop determining abnormalities based on communication interruption with other startup control target control devices.
8. Multiple cluster configuration information sets are provided for when the aforementioned anomaly occurs. The in-vehicle network system according to any one of claims 1 to 3, wherein the control device subject to startup control switches the cluster setting information for when an abnormality occurs so as to reduce the number of clusters that are set to be startable in accordance with the elapsed time since the abnormality occurred, the distance traveled since the abnormality occurred, and / or the decrease in the remaining charge of the battery that stores power for the vehicle's operation.
9. Multiple cluster configuration information sets are provided for when the aforementioned anomaly occurs. The in-vehicle network system according to any one of claims 1 to 3, wherein the startup control target device selects one of the cluster setting information for use in the event of an abnormality from among a plurality of such cluster setting information, based on time information, weather information, and / or outside temperature information when an abnormality occurs.
10. The multiple control devices subject to startup control include a combination of a higher-level control device (10) and a lower-level control device that can switch the presence or absence of power supply to the lower-level control devices (20, 30) using a relay circuit, The higher-level control device has a storage unit (14) that stores cluster setting information indicating the cluster to which the lower-level control device belongs, The in-vehicle network system according to any one of claims 1 to 3, wherein the higher-level control device receives the NM message on behalf of the lower-level control device, and when the cluster to be activated indicated by the activation cluster information of the NM message matches the cluster in the cluster setting information of the lower-level control device, it turns on the relay circuit to supply power to the lower-level control device and activate the lower-level control device.
11. The storage unit stores cluster setting information for normal operation and cluster setting information for abnormal situations as cluster setting information for the lower-level control device. The in-vehicle network system according to claim 10, wherein when the higher-level control device detects an abnormality in the management control device or an abnormality in communication with the management control device, it switches the cluster setting information of the lower-level control device from the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs.
12. Multiple lower-level control devices are provided, The relay circuit is provided in multiple locations according to the multiple lower-level control devices. The in-vehicle network system according to claim 10, wherein the storage unit stores relay connection information indicating the correspondence between the plurality of lower-level control devices and the plurality of relay circuits, in addition to the cluster setting information for each of the plurality of lower-level control devices.
13. The in-vehicle network system according to claim 12, wherein the higher-level control unit turns on the relay circuit corresponding to the lower-level control unit whose startup cluster specified in the startup cluster information included in the NM message matches the cluster in the cluster setting information, and turns off the relay circuit corresponding to the lower-level control unit whose cluster does not match, based on the cluster setting information and the relay connection information.
14. The in-vehicle network system according to claim 10, wherein when the higher-level control device detects an abnormality in the management control device or an abnormality in communication with the management control device, it turns on the relay circuit of the lower-level control device that is related to the execution of control relating to the driving of the vehicle and the safety of the occupants, and turns off the relay circuit of the lower-level control device that is not related to the execution of control relating to the driving of the vehicle and the safety of the occupants.
15. The in-vehicle network system according to claim 14, wherein the higher-level control device determines, based on the cluster setting information for when an abnormality occurs, whether or not the lower-level control device is involved in the execution of control related to the driving of the vehicle and the safety of the occupants.
16. A control method for an in-vehicle network system having a plurality of control devices (10, 20, 30, 40, 50, 60, 70, 80, 90, 100) connected to a communication bus and capable of communicating with each other, Multiple control devices (10, 20, 30, 50, 60, 70, 80, 90, 100) have cluster configuration information indicating the cluster to which they belong among multiple divided clusters, and when a network management message (hereinafter referred to as an NM message) transmitted from another control device contains startup cluster information indicating the cluster to be started that matches the cluster in the cluster configuration information, they enter a startup state or maintain a startup state. The plurality of control devices further include a management control device (40) capable of changing the cluster setting information of the plurality of control devices targeted for startup control, Multiple of the aforementioned control devices subject to startup control have cluster setting information, including cluster setting information for normal operation and cluster setting information for when an abnormality occurs. At least one of the startup control target control devices detects that an abnormality has occurred in the management control device or in communication with the management control device (S100), and A control method for an in-vehicle network system, comprising: at least one of the startup control target control devices, which detects an abnormality in the management control device or an abnormality in communication with the management control device, switches the cluster setting information for normal operation to the cluster setting information for when an abnormality occurs (S110).
Citation Information
Patent Citations
In-vehicle network system
JP7238650B2