Communication system

The communication system addresses communication failures by using a management device with path selection and anomaly detection to switch to new paths, ensuring continuous communication and power supply in a vehicle control system.

JP2026069951APending Publication Date: 2026-04-27DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
DENSO CORP
Filing Date
2024-10-15
Publication Date
2026-04-27

AI Technical Summary

Technical Problem

In a communication system with multiple electronic control units, necessary communication may become impossible due to issues with switching the on and off states of these units, leading to potential communication failures.

Method used

A communication system with a management device and multiple managed devices that utilize a communication path selection unit to avoid abnormal parts and a notification transmission unit to switch communication paths, incorporating anomaly detection and notification units to ensure continuous communication by selecting new paths when abnormalities occur.

Benefits of technology

The system effectively establishes new communication paths to prevent the inability to perform necessary communication, ensuring that power and data transmission can continue even in the presence of abnormalities, thereby maintaining system functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026069951000001_ABST
    Figure 2026069951000001_ABST
Patent Text Reader

Abstract

This aims to prevent situations in communication systems where necessary communications cannot be performed. [Solution] In the vehicle control system, the management ECU2 is configured in S330 to select a new communication path that avoids the abnormal part when it receives an abnormality notification indicating that the abnormal part is located in the communication path used before the abnormality was detected from among multiple communication paths. The management ECU2 is configured in S360 to send a setting notification to at least multiple control ECUs 3, 4, and 5, which is a notification that communication will be performed using the newly selected communication path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a communication system including a plurality of electronic control units.

Background Art

[0002] Patent Document 1 describes an in-vehicle network system that includes a power relay for individually switching on / off the power supply of each electronic control unit, determines control content for switching on / off the power supply of a specific electronic control unit corresponding to a specific scene identified based on the vehicle situation, and switches on / off the power supply supplied to the specific electronic control unit using the power relay based on the determined control content. [[ID=I4]]

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] As a result of the inventors' detailed examination, in a communication system configured to include a plurality of electronic control units and capable of individually switching the on state and the off state for the plurality of electronic control units, there may be a problem that necessary communication cannot be performed, such as a situation where it becomes impossible to switch the on state and the off state of an electronic control unit.

[0005] One aspect of the present disclosure is to suppress the occurrence of an event where necessary communication cannot be performed in a communication system.

Means for Solving the Problems

[0006] One aspect of the present disclosure is a communication system (1) in which a management device (2), a plurality of managed devices (3, 4, 5) managed by the management device, and at least one target device (6 to 11) which is a device that is communicatively connected to at least one of the plurality of managed devices are configured to communicate with each other by selectively using one of a plurality of communication paths.

[0007] The management device comprises a communication path selection unit (S330) and a notification transmission unit (S360). The communication path selection unit is configured to select a new communication path that avoids the abnormal part when it receives an abnormality notification indicating an abnormal part among multiple communication paths where an abnormality has occurred. The notification transmission unit is configured to send a setting notification to at least multiple managed devices, which is a notification that communication will be performed using the newly selected communication path.

[0008] The management device and at least one of the multiple managed devices include an anomaly detection unit (S310, S710) and an anomaly notification unit (S325, S730). The anomaly detection unit is configured to detect an anomaly in the communication path. The anomaly notification unit is configured to notify the communication path selection unit of an anomaly regarding the detected anomaly. The multiple managed devices include a path change unit (S415) configured to set a new communication path and communicate according to a setting notification, and the setting notification includes switching information that can identify whether to turn on or off the multiple managed devices and / or target devices.

[0009] With this configuration, if an abnormality occurs in the communication path, a new communication path that avoids the abnormal part can be established, and communication can be carried out using this new communication path, thus making it less likely that necessary communication will be impossible. [Brief explanation of the drawing]

[0010] [Figure 1] This is a block diagram showing the configuration of a vehicle control system. [Figure 2] This is a flowchart showing the frame transmission process. [Figure 3] This is a flowchart showing the frame transfer process. [Figure 4] This is a flowchart showing the fault detection process. [Figure 5] This is a flowchart showing the master startup process. [Figure 6] This is a flowchart showing the slave startup process. [Figure 7] This is a flowchart showing the restart process. [Figure 8] This is a flowchart showing the master data shutdown process. [Figure 9] Figure 9A is a flowchart showing the slave termination process, and Figure 9B is a flowchart showing the terminal termination process. [Figure 10] This is a flowchart showing the slave detection process. [Modes for carrying out the invention]

[0011] [1. First Embodiment] A first embodiment of this disclosure is described below with reference to the drawings. [1-1. Structure] The vehicle control system 1 of this embodiment is mounted on a vehicle and, as shown in Figure 1, comprises a management ECU 2, control ECUs 3, 4, and 5, slave ECUs 6, 7, 8, 9, 10, and 11, and batteries 12 and 13. ECU stands for Electronic Control Unit.

[0012] The management ECU2 integrates the control ECUs 3, 4, and 5, thereby achieving coordinated control for the entire vehicle. Control ECUs 3, 4, and 5 are provided for each zone into which the vehicle is divided, and primarily perform control of the slave ECUs located within that zone.

[0013] Slave ECUs 6 and 7 belong to the same zone as control ECU 3. Slave ECUs 8 and 9 belong to the same zone as control ECU 4. Slave ECUs 10 and 11 belong to the same zone as control ECU 5.

[0014] The batteries 12 and 13 supply power to each part of the vehicle with a DC battery voltage (for example, 12V). The control ECU 3 receives power supply from the battery 12 through the power supply path 21 between the battery 12 and the control ECU 3.

[0015] The control ECU 4 receives power supply from the battery 13 through the power supply path 22 between the battery 13 and the control ECU 4. The control ECU 5 receives power supply from the battery 13 through the power supply path 23 between the battery 13 and the control ECU 5.

[0016] The slave ECUs 6 and 7 each receive power supply from the battery 12 through the power supply paths 24 and 25 between the control ECU 3 and the slave ECUs 6 and 7. The slave ECUs 8 and 9 each receive power supply from the battery 13 through the power supply paths 26 and 27 between the control ECU 4 and the slave ECUs 8 and 9.

[0017] The slave ECUs 10 and 11 each receive power supply from the battery 13 through the power supply paths 28 and 29 between the control ECU 5 and the slave ECUs 10 and 11. The management ECU 2 and the control ECU 3 are connected to each other so as to be able to perform data communication via the communication line 31.

[0018] The management ECU 2 and the control ECU 4 are connected to each other so as to be able to perform data communication via the communication line 32. The management ECU 2 and the control ECU 5 are connected to each other so as to be able to perform data communication via the communication line 33.

[0019] The control ECU 3 and the control ECU 4 are connected to each other so as to be able to perform data communication via the communication line 34. The control ECU 4 and the control ECU 5 are connected to each other so as to be able to perform data communication via the communication line 35.

[0020] The control ECU3 and slave ECUs6 and7 are connected to each other via a communication bus 36, enabling data communication between them. The control ECU 4 and the slave ECUs 8 and 9 are connected to each other via the communication bus 37, enabling data communication between them.

[0021] The control ECU 5 and the slave ECUs 10 and 11 are connected to each other via a communication bus 38, enabling data communication between them. The management ECU2 comprises a control unit 41, a communication unit 42, and a storage unit 43.

[0022] The control unit 41 is an electronic control unit centered around a microcomputer equipped with a CPU 51, ROM 52, RAM 53, etc. The various functions of the microcomputer are realized by the CPU 51 executing a program stored in a non-transitional physical recording medium. In this example, the ROM 52 corresponds to the non-transitional physical recording medium that stores the program. Furthermore, the execution of this program executes the method corresponding to the program. Note that some or all of the functions executed by the CPU 51 may be configured in hardware by one or more ICs, etc. Also, the number of microcomputers that make up the control unit 41 may be one or more.

[0023] The communication unit 42 communicates with the control ECU 3 connected to the communication line 31, with the control ECU 4 connected to the communication line 32, and with the control ECU 5 connected to the communication line 33 by sending and receiving communication frames, for example, based on the Ethernet communication protocol. Ethernet is a registered trademark.

[0024] The memory unit 43 is a storage device for storing various types of data. The memory unit 43 stores the management table 56, which will be described later. The control ECU3 comprises a control unit 61, a communication unit 62, a CAN communication unit 63, a storage unit 64, and power distribution switches 65 and 66. CAN stands for Controller Area Network.

[0025] The control unit 61 is an electronic control unit centered around a microcomputer equipped with a CPU 71, ROM 72, RAM 73, etc. The various functions of the microcomputer are realized by the CPU 71 executing a program stored in a non-transitional physical recording medium. In this example, ROM 72 corresponds to the non-transitional physical recording medium that stores the program. Furthermore, the execution of this program executes the method corresponding to the program. Note that some or all of the functions executed by the CPU 71 may be configured hardware-wise by one or more ICs, etc. Also, the number of microcomputers that make up the control unit 61 may be one or more.

[0026] The communication unit 62 communicates with the management ECU 2 connected to the communication line 31 and with the control ECU 4 connected to the communication line 34 by sending and receiving communication frames, for example, based on the Ethernet communication protocol.

[0027] The CAN communication unit 63 communicates with slave ECUs 6 and 7 connected to the communication bus 36 by sending and receiving communication frames based on the CAN communication protocol. The memory unit 64 is a memory device for storing various types of data.

[0028] The power distribution switch 65 is located on the power supply path 24, which is connected to the power supply path 21. The power distribution switch 65 is configured to open or close the power supply path 24 according to commands from the control unit 61.

[0029] The power distribution switch 66 is located on the power supply path 25, which is connected to the power supply path 21. The power distribution switch 66 is configured to open or close the power supply path 25 according to commands from the control unit 61.

[0030] The control ECU4 comprises a control unit 81, a communication unit 82, a CAN communication unit 83, a storage unit 84, and power distribution switches 85 and 86. The control unit 81 is an electronic control unit centered around a microcomputer equipped with a CPU 91, ROM 92, RAM 93, etc. The various functions of the microcomputer are realized by the CPU 91 executing a program stored in a non-transitional physical recording medium. In this example, ROM 92 corresponds to the non-transitional physical recording medium that stores the program. Furthermore, the execution of this program executes the method corresponding to the program. Note that some or all of the functions executed by the CPU 91 may be configured hardware-wise by one or more ICs, etc. Also, the number of microcomputers that make up the control unit 81 may be one or more.

[0031] The communication unit 82 communicates with the management ECU 2 connected to the communication line 32, with the control ECU 3 connected to the communication line 34, and with the control ECU 5 connected to the communication line 35 by sending and receiving communication frames, for example, based on the Ethernet communication protocol.

[0032] The CAN communication unit 83 communicates with slave ECUs 8 and 9 connected to the communication bus 37 by sending and receiving communication frames based on the CAN communication protocol. The memory unit 84 is a memory device for storing various types of data.

[0033] The power distribution switch 85 is located on the power supply path 26, which is connected to the power supply path 22. The power distribution switch 85 is configured to open or close the power supply path 26 according to commands from the control unit 81.

[0034] The power distribution switch 86 is located on the power supply path 27, which is connected to the power supply path 22. The power distribution switch 86 is configured to open or close the power supply path 27 according to commands from the control unit 81.

[0035] The control ECU 5 comprises a control unit 101, a communication unit 102, a CAN communication unit 103, a storage unit 104, and power distribution switches 105 and 106. The control unit 101 is an electronic control unit centered around a microcomputer equipped with a CPU 111, ROM 112, RAM 113, etc. The various functions of the microcomputer are realized by the CPU 111 executing a program stored in a non-transitional physical recording medium. In this example, ROM 112 corresponds to the non-transitional physical recording medium that stores the program. Furthermore, the execution of this program executes a method corresponding to the program. Note that some or all of the functions performed by the CPU 111 may be configured in hardware using one or more ICs, etc. Also, the number of microcomputers constituting the control unit 101 may be one or more.

[0036] The communication unit 102 communicates with the management ECU 2 connected to the communication line 33, and with the control ECU 4 connected to the communication line 35, by sending and receiving communication frames based on, for example, the Ethernet communication protocol.

[0037] The CAN communication unit 103 communicates with the slave ECUs 10 and 11 connected to the communication bus 38 by sending and receiving communication frames based on the CAN communication protocol. The memory unit 104 is a storage device for storing various types of data.

[0038] The power distribution switch 105 is located on the power supply path 28, which is connected to the power supply path 23. The power distribution switch 105 is configured to conduct or interrupt the power supply path 28 according to commands from the control unit 101.

[0039] The power distribution switch 106 is located on the power supply path 29, which is connected to the power supply path 23. The power distribution switch 106 is configured to open or close the power supply path 29 according to commands from the control unit 101.

[0040] The management table 56 contains the correspondence between each of the multiple events and the power distribution switches that should be turned on and turned off. Specifically, the management table 56 contains six pieces of switching information for each event, indicating whether to turn on or off each of the power distribution switches 65, 66, 85, 86, 105, and 106.

[0041] For example, for an event where the vehicle's power state switches from accessory-on to ignition-on, six switching information settings are configured, such as turning on power distribution switch 65, turning on power distribution switch 66, turning off power distribution switch 85, turning off power distribution switch 86, turning on power distribution switch 105, and turning off power distribution switch 106.

[0042] For example, in the case of a door-opening event when a vehicle door is opened, six switching information settings are configured, such as setting power distribution switch 65 to the off state, power distribution switch 66 to the off state, power distribution switch 85 to the on state, power distribution switch 86 to the on state, power distribution switch 105 to the off state, and power distribution switch 106 to the on state.

[0043] For example, if the slave ECU6 is a door control ECU, when the door switch is turned ON, the slave ECU6 sends information indicating a door open event to the management ECU2 via the control ECU4. This allows the management ECU2 to detect the occurrence of the door open event.

[0044] When the management ECU2 detects an event, it extracts six pieces of switching information corresponding to the detected event from the management table 56. The management ECU2 then generates a communication frame containing the six extracted pieces of switching information as an NM frame and transmits the generated NM frame. NM stands for Network Management.

[0045] When the control ECU 3 receives an NM frame transmitted by the management ECU 2, it extracts the switching information of the power distribution switches 65 and 66 under its control from the NM frame, and based on the extracted switching information, it sets the power distribution switches 65 and 66 to the ON state or the OFF state.

[0046] When the control ECU4 receives an NM frame transmitted by the management ECU2, it extracts the switching information of the power distribution switches 85 and 86 under its control from the NM frame, and based on the extracted switching information, it sets the power distribution switches 85 and 86 to the ON state or the OFF state.

[0047] When the control ECU 5 receives an NM frame transmitted by the management ECU 2, it extracts the switching information of the power distribution switches 105 and 106 under its control from the NM frame, and based on the extracted switching information, it sets the power distribution switches 105 and 106 to either the ON or OFF state.

[0048] [1-2. Processing] Next, the procedure for frame transmission processing performed by the control unit 41 of the management ECU2 will be described. Frame transmission processing is a process that is repeatedly performed while the management ECU2 is operating.

[0049] When the frame transmission process is executed, the CPU 51 of the control unit 41 determines in S10 whether or not an event has been detected, as shown in Figure 2. If no event has been detected, the CPU 51 terminates the frame transmission process.

[0050] On the other hand, if an event is detected, CPU 51 extracts six pieces of switching information corresponding to the detected event from management table 56 in S20 and generates an NM frame containing the six extracted pieces of switching information.

[0051] In S30, CPU 51 starts the process of sending the NM frame generated in S20 to control ECUs 3, 4, and 5 via communication lines 31, 32, and 33, respectively, and then finishes the frame transmission process. As a result, management ECU 2 periodically and repeatedly sends the NM frame generated in S20.

[0052] Next, the procedure for frame transfer processing performed by the control units 61, 81, and 101 of the control ECUs 3, 4, and 5 will be described. Frame transfer processing is a process that is repeatedly performed while the control ECUs 3, 4, and 5 are operating.

[0053] When frame transfer processing is executed, the CPUs 71, 91, and 111 of the control units 61, 81, and 101 determine in S110 whether or not an NM frame has been received, as shown in Figure 3. If an NM frame has not been received, the CPUs 71, 91, and 111 terminate the frame transfer processing.

[0054] On the other hand, when an NM frame is received, CPUs 71, 91, and 111 forward the received NM frame in S120 via the remaining communication lines, excluding the communication lines 31, 32, and 33 connected to the management ECU2 and the communication line used to receive the NM frame in S110.

[0055] For example, if the control ECU 3 receives an NM frame from the management ECU 2 via the communication line 31, it forwards the NM frame to the control ECU 4 via the communication line 34. For example, if the control ECU 3 receives an NM frame from the control ECU 4 via the communication line 34, it does not perform the forwarding of the NM frame.

[0056] For example, if the control ECU 4 receives an NM frame from the management ECU 2 via the communication line 32, it forwards the NM frame to the control ECUs 3 and 5 via the communication lines 34 and 35. For example, if the control ECU 4 receives an NM frame from the control ECU 3 via the communication line 34, it forwards the NM frame to the control ECU 5 via the communication line 35.

[0057] For example, if control ECU 4 receives an NM frame from control ECU 5 via communication line 35, it forwards the NM frame to control ECU 3 via communication line 34. For example, if the control ECU 5 receives an NM frame from the management ECU 2 via the communication line 33, it forwards the NM frame to the control ECU 4 via the communication line 35.

[0058] For example, if the control ECU 5 receives an NM frame from the control ECU 4 via the communication line 35, it does not perform the forwarding of the NM frame. CPUs 71, 91, and 111 determine in S130 whether they have already received an NM frame from the same source (i.e., management ECU2) within the period between the time S110 determines that an NM frame has been received and the time S110 determines that an NM frame has been received (hereinafter referred to as the same frame reception determination period). Note that the NM frame contains a source address indicating the source.

[0059] The same frame reception determination period is set based on the difference in the timing of receiving NM frames for each communication line when the control ECU receives NM frames via multiple communication lines.

[0060] For example, in control ECU 4, the same frame reception determination period is set based on the differences in timing when an NM frame is received from communication line 31, when an NM frame is received via communication lines 32 and 34, and when an NM frame is received via communication lines 33, 34, and 35. The same frame reception determination period may be the same for control ECUs 3, 4, and 5, or it may be different for control ECUs 3, 4, and 5.

[0061] If an NM frame from the same source has already been received within the same frame reception determination period, CPUs 71, 91, and 111 terminate the frame transfer process. On the other hand, if no NM frame from the same source has already been received within the same frame reception determination period, CPUs 71, 91, and 111 return an acknowledgment in S140 via the communication line on which the NM frame was received in S110.

[0062] For example, if the control ECU 4 receives an NM frame from the management ECU 2 via the communication line 32, it returns an acknowledgment to the management ECU 2 via the communication line 32. Also, if the control ECU 4 receives an NM frame from the control ECU 3 via the communication line 34, it returns an acknowledgment to the control ECU 3 via the communication line 34.

[0063] CPUs 71, 91, and 111, in S150, turn on or off the power distribution switches under them based on the switching information contained in the NM frame received in S110, and then terminate the frame transfer process.

[0064] Next, the procedure for fault detection processing performed by the control units 61, 81, and 101 of the control ECUs 3, 4, and 5 will be described. Fault detection processing is a process that is repeatedly performed while the control ECUs 3, 4, and 5 are operating.

[0065] When fault detection processing is executed, the CPUs 71, 91, and 111 of the control units 61, 81, and 101 determine in S210, as shown in Figure 4, whether or not there is currently a communication line that is periodically receiving NM frames. If there is no communication line currently receiving NM frames periodically, the CPUs 71, 91, and 111 terminate the fault detection processing.

[0066] On the other hand, if there is currently a communication line that is receiving NM frames periodically, CPUs 71, 91, and 111 determine in S220 whether other communication lines identified in S210 are currently receiving NM frames periodically.

[0067] If, at this point, NM frames are being received periodically on other communication lines besides the one identified in S210, CPUs 71, 91, and 111 terminate the fault detection process. On the other hand, if NM frames are not being received periodically on other communication lines besides the one identified in S210, CPUs 71, 91, and 111 determine in S230 that a communication interruption has occurred on the communication line that is not currently receiving NM frames periodically.

[0068] For example, if communication line 32 is disconnected, control ECU 4 will periodically receive NM frames from control ECUs 3 and 5 via communication lines 34 and 35, but will not be able to receive NM frames from management ECU 2 via communication line 32. Therefore, control ECU 4 will determine that a communication interruption has occurred on communication line 32.

[0069] For example, if communication line 34 is disconnected, control ECU 4 will periodically receive NM frames from management ECU 2 and control ECU 5 via communication lines 32 and 35, but will not be able to receive NM frames from control ECU 3 via communication line 34. Therefore, control ECU 4 will determine that a communication interruption has occurred on communication line 34.

[0070] For example, if communication line 31 is disconnected, control ECU 3 will periodically receive NM frames from control ECU 4 via communication line 34, but will not be able to receive NM frames from management ECU 2 via communication line 31. Therefore, control ECU 3 will determine that a communication interruption has occurred on communication line 31.

[0071] CPUs 71, 91, and 111 notify the management ECU 2 of the communication line interruption determination result in S240, indicating the communication line that has been interrupted. Upon receiving the interruption determination result, the management ECU 2 stores the diagnostic information indicating the received interruption determination result in the storage unit 43 as a fail-safe action. The management ECU 2 may also notify the vehicle occupants that a communication interruption has occurred.

[0072] CPUs 71, 91, and 111 store the diagnostic information indicating the interruption determination result notified in S240 in memory units 64, 84, and 104 in S250, and terminate the fault detection process. This fault detection process does not need to be performed if the control ECU, which is the communication partner, is in sleep mode. [1-3. Effects] The first embodiment described in detail above provides the following effects.

[0073] (1a) The vehicle control system 1 configured in this way includes ECUs 2 to 11 that are connected to send and receive communication frames. The vehicle control system 1 comprises a control ECU 3, a control ECU 4, a slave ECU 6, a slave ECU 8, a power distribution switch 65, a power distribution switch 85, a management ECU 2, a communication line 31, a communication line 32, and a communication line 34.

[0074] The control ECU 3 is configured to receive power via the power supply path 21. The control ECU 4 is configured to receive power via a power supply path 22 that is not connected to the power supply path 21.

[0075] The slave ECU 6 is configured to receive power via a power supply path 24 connected to a power supply path 21. The slave ECU8 is configured to receive power via a power supply path 26 connected to a power supply path 22.

[0076] The power distribution switch 65 is configured to switch between an ON state, which allows the power supply path 24 to conduct, and an OFF state, which disconnects the power supply path 24. The power distribution switch 85 is configured to switch between an ON state, which allows the power supply path 26 to conduct, and an OFF state, which disconnects the power supply path 26.

[0077] The management ECU2 is configured to generate an NM frame, which is a communication frame containing switching information indicating whether to turn on or off the power distribution switch 65 and the power distribution switch 85, respectively, in response to the detected event.

[0078] The communication line 31 is a communication path that connects the management ECU 2 and the control ECU 3, enabling the sending and receiving of communication frames between the management ECU 2 and the control ECU 3. The communication line 32 is a communication path that connects the management ECU 2 and the control ECU 4, enabling the sending and receiving of communication frames between the management ECU 2 and the control ECU 4.

[0079] The communication line 34 is a communication path that connects the control ECU 3 and the control ECU 4, enabling the transmission and reception of communication frames between the control ECU 3 and the control ECU 4. The management ECU2 is configured to transmit NM frames to the control ECU3 via the communication line 31.

[0080] The management ECU2 is configured to transmit NM frames to the control ECU4 via the communication line 32. The control ECU 3 is configured to control the operation of the power distribution switch 65 based on the switching information contained in the NM frame.

[0081] The control ECU 4 is configured to control the operation of the power distribution switch 85 based on the switching information contained in the NM frame. In this vehicle control system 1, the management ECU 2 generates an NM frame in response to an event and transmits the NM frame to the control ECUs 3 and 4 via communication lines 31 and 32, so that the control ECUs 3 and 4 can turn on or off the power distribution switches 65 and 85 in response to the event.

[0082] Furthermore, in the vehicle control system 1, even if the management ECU 2 is unable to transmit the NM frame to the control ECU 3 via the communication line 31, the management ECU 2 can transmit the NM frame to the control ECU 3 via the communication lines 32 and 34. Also, in the vehicle control system 1, even if the management ECU 2 is unable to transmit the NM frame to the control ECU 4 via the communication line 32, the management ECU 2 can transmit the NM frame to the control ECU 4 via the communication lines 31 and 34. Therefore, the vehicle control system 1 can prevent situations where it becomes unable to switch between allowing and denying power supply to the slave ECUs 6 and 8.

[0083] (1b) Furthermore, in the vehicle control system 1, even if the control ECU 3 is unable to control the operation of the power distribution switch 65 because it is unable to receive power through the power supply path 21, the control ECU 4, which receives power through the power supply path 22 that is not connected to the power supply path 21, can still control the operation of the power distribution switch 85. Therefore, the vehicle control system 1 can prevent the inability to simultaneously switch between allowing and denying power supply to both slave ECUs 6 and 8. Based on the above, the vehicle control system 1 can prevent the inability to switch between allowing and prohibiting power supply to the electronic control unit.

[0084] (1c) Furthermore, even when communication line 32 is available, the control ECU 3 is configured to transmit the NM frame received from the management ECU 2 to the control ECU 4 via communication line 34. Even when communication line 31 is available, the control ECU 4 is configured to transmit the NM frame received from the management ECU 2 to the control ECU 3 via communication line 34. In such a vehicle control system 1, the control ECUs 3 and 4 transmit the NM frame via communication line 34 even under normal circumstances when both communication lines 31 and 32 are available. Therefore, the vehicle control system 1 can omit the process of determining whether or not communication lines 31 and 32 are available.

[0085] (1d) The vehicle control system 1 further includes a control ECU 5, a slave ECU 10, a power distribution switch 105, a communication line 33, and a communication line 35. The control ECU 5 is configured to receive power via a power supply path 23 that is not connected to the power supply path 21 but is connected to the power supply path 22.

[0086] The slave ECU 10 is configured to receive power via a power supply path 28 connected to a power supply path 23. The power distribution switch 105 is configured to switch between an ON state, which allows the power supply path 28 to conduct, and an OFF state, which disconnects the power supply path 28.

[0087] Communication line 33 is a communication path that connects the management ECU 2 and the control ECU 5, enabling the sending and receiving of communication frames between the management ECU 2 and the control ECU 5. The communication line 35 is a communication path that connects the control ECU 4 and the control ECU 5, enabling the transmission and reception of communication frames between the control ECU 4 and the control ECU 5.

[0088] The NM frame further includes switching information indicating whether to turn the power distribution switch 105 on or off. The management ECU2 is configured to transmit NM frames to the control ECU5 via the communication line 35.

[0089] The control ECU 5 is configured to control the operation of the power distribution switch 105 based on the switching information contained in the NM frame. Even when communication lines 31 and 32 cannot be used, such a vehicle control system 1 can transmit NM frames to control ECUs 3 and 4 via communication lines 33, 34, and 35, thereby further suppressing the inability to switch between allowing and denying power supply to slave ECUs 6 and 8.

[0090] (1e) The control ECU 3 is configured to turn on or off the power distribution switch 65 based on the first NM frame received when it receives an NM frame from each of the communication lines 31 and 34 connected to the control ECU 3 within a preset same frame reception determination period. The control ECU 4 is configured to turn on or off the power distribution switch 85 based on the first NM frame received when it receives an NM frame from each of the communication lines 32, 34, and 35 connected to the control ECU 4 within a preset same frame reception determination period. The control ECU 5 is configured to turn on or off the power distribution switch 105 based on the first NM frame received when it receives an NM frame from each of the communication lines 33 and 35 connected to the control ECU 5 within a preset same frame reception determination period.

[0091] This vehicle control system 1 can prevent control ECUs 3, 4, and 5 from unnecessarily repeating the same control to power distribution switches 65, 85, and 105 when they receive multiple identical NM frames.

[0092] (1f) Furthermore, control ECUs 3, 4, and 5 are configured to determine that a communication interruption has occurred in the communication line 31 to 35 that is not receiving NM frames periodically, if each control ECU periodically receives a management frame on at least one of the communication lines 31 to 35 connected to the control ECUs 3, 4, and 5, and does not periodically receive an NM frame on at least one of the communication lines 31 to 35 connected to the control ECUs 3, 4, and 5. Such a vehicle control system 1 can identify the communication lines 31-35 where an abnormality is occurring.

[0093] (1g) Furthermore, control ECUs 3, 4, and 5 are configured to notify the management ECU 2 of the interruption detection result when they determine that a communication interruption has occurred.

[0094] Such a vehicle control system 1 can allow the management ECU 2 to recognize the communication lines 31-35 where an abnormality is occurring.

[0095] Although one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modified forms. [1-4. Modification 1 of the First Embodiment] In the above embodiment, an acknowledgment is shown when an NM frame from the same sender has not already been received within the same frame reception determination period. However, an acknowledgment may also be shown when an NM frame from the same sender has already been received within the same frame reception determination period.

[0096] [2. Second Embodiment] [2-1. Differences from the First Embodiment] The second embodiment has the same basic configuration as the first embodiment, so the differences will be explained below. Note that the same reference numerals as in the first embodiment indicate the same components, and refer to the preceding description.

[0097] In the first embodiment described above, the management ECU 2 was configured to transmit NM frames to each of the multiple communication lines 31 to 33, and the control ECUs 3, 4, and 5 were configured to relay the NM frames to each other. In contrast, in the second embodiment, a communication path to be used (for example, a normally used communication path) is predetermined for each communication partner, and the management ECU 2 transmits NM frames to only one communication line 31 to 33 that corresponds to the communication path set up in association with a predetermined communication partner. This differs from the first embodiment in that the NM frames are relayed according to that communication path.

[0098] [2-2. Correspondence with this disclosure] In the second embodiment, the vehicle control system 1 corresponds to a communication system, and the management ECU 2 corresponds to a management device. Furthermore, the control ECUs 3, 4, and 5 correspond to multiple managed devices, and slave ECUs 6 to 11 and some of the control ECUs 3, 4, and 5 correspond to target devices. In addition, among the processes performed by the vehicle control system 1, the functions of S310 and S710 correspond to an anomaly detection unit, and the function of S330 corresponds to a communication path selection unit. Furthermore, the function of S360 corresponds to a startup transmission unit and a notification transmission unit, the functions of S370 and S530 correspond to a time calculation unit, and the function of S415 corresponds to a path change unit. Furthermore, the functions of S325 and S730 correspond to an anomaly notification unit, and the functions of S450 and S550 correspond to a processing execution unit.

[0099] [2-3. Structure] As described above, in the vehicle control system 1 of the second embodiment, a communication path is set in advance for each communication partner. Specifically, the memory unit 43 of the management ECU 2 and the memory units 64, 84, and 104 of the control ECUs 3, 4, and 5 store information regarding the communication path to be used for each communication partner in a rewritable format. The information regarding the communication path is, for example, information about the ports corresponding to the communication lines 31 to 38 that should be used for each communication partner, and other information necessary when communicating along a predetermined communication path.

[0100] The communication paths between each device constituting the vehicle control system 1 (i.e., management ECU2, control ECUs 3, 4, 5, and slave ECUs 6-11) are basically configured to minimize the number of hops. For example, the communication path from management ECU2 to slave ECU6 is configured to communicate via communication line 31, control ECU3, and communication bus 36 in that order. Also, for example, the communication path from slave ECU8 to management ECU2 is configured to communicate via communication bus 37, control ECU4, and communication line 32 in that order. Also, for example, the communication path from slave ECU6 to slave ECU8 is configured to communicate via communication bus 36, control ECU3, communication line 34, control ECU4, and communication bus 37 in that order.

[0101] [2-4. Processing] In the second embodiment, assuming that a communication interruption occurs, several processes are described below to ensure that NM frames are relayed properly in this case. These processes include [A] a process to start the slave ECU and [B] a process to stop the slave ECU.

[0102] First, we will explain the process of starting up slave ECU6 as part of the process of starting up slave ECU [A]. Note that the process shown below can be applied not only to the process of starting up slave ECU6, but also to the process of identifying the communication partner and sending an NM frame.

[0103] Figure 5 is a flowchart showing the master startup process. The master startup process is a process that starts, for example, when the management ECU2 starts up, and is executed by the CPU 51 of the management ECU2.

[0104] In the master startup process, as shown in Figure 5, first, the CPU 51 of the management ECU 2 performs a disconnection check in S310. This process is the same as S230 described above. In other words, this process detects a communication interruption. Note that this process may also detect abnormalities in the communication path, such as a broken wire or excessive delay.

[0105] Next, the CPU 51 of the management ECU2 determines in S320 whether or not there is a communication interruption. If there is no communication interruption, it returns to S310. If there is a communication interruption, it proceeds to S325. Next, in S325, the CPU 51 of the management ECU2 sends an anomaly notification regarding the detected anomaly within the management ECU2. That is, the function in the management ECU2 that notifies of anomalies sends an anomaly notification, and the function in the management ECU2 that selects the communication path (for example, the function in S330 described below) receives the anomaly notification. The anomaly notification is a notification that includes information to identify the anomaly location (for example, one of the communication lines 31 to 35) where the anomaly occurred among multiple communication paths.

[0106] Next, when the CPU 51 of the management ECU2 receives an abnormality notification in S330, it selects a new communication path that avoids the abnormal part. Specifically, for example, if the communication path from the management ECU2 to the slave ECU6 shown in Figure 1 includes a communication line 31 and a communication bus 36, and a communication interruption is detected on the communication line 31, then a new communication path that avoids the communication line 31 is established.

[0107] The management ECU2 stores a routing map in the storage unit 43, which is a selection of communication paths configured based on which communication lines each device is connected to. For example, the management ECU2 selects a new communication path that avoids communication line 31, going from the management ECU2 to the slave ECU6 in the following order: communication line 32, control ECU4, communication line 34, control ECU3, and communication bus 36.

[0108] The management ECU2 stores the new communication path and the communication path used before the anomaly detection (hereinafter referred to as the old communication path) in the storage unit 43. These new and old communication paths are configured to be readable from the storage unit 43 when the management ECU2 is restarted.

[0109] Next, the CPU 51 of the management ECU2 determines in S340 whether an event exists. The event here may be the same as the event described in S10 above, or it may be a different event. In this example embodiment, it determines whether there is an event that should start the slave ECU6. If there is no event, S340 is repeated. If there is an event, the process proceeds to S350.

[0110] Next, the CPU 51 of the management ECU 2 selects the ECU to be activated in response to the event using S350. In this example, the slave ECU 6 is selected. Next, the CPU 51 of the management ECU 2 sends an NM frame to the new communication path in S360. This NM frame contains a configuration notification and a start command. The configuration notification informs the devices that make up the new communication path, including multiple control ECUs 3, 4, and 5, that communication will be conducted using the selected new communication path. The start command is a command to start the slave ECU 6.

[0111] Next, the management ECU2 is configured in S370 to calculate the diagnostic mask time. The diagnostic mask time is the time it takes for a newly joined device (e.g., control ECU3) to operate normally. The diagnostic mask time is calculated based on the known startup time of the slave ECU6. Each ECU constituting the vehicle control system 1 is configured to send a diagnostic (e.g., an error code) if communication with the target ECU is interrupted (e.g., due to a timeout). In this embodiment, each ECU ignores frames related to newly joined devices for the duration of the diagnostic mask time. Thus, a diagnostic mask temporarily ignores frames from the target ECU, so that even if one of the ECUs determines that communication has been interrupted, it is not considered an abnormality.

[0112] Furthermore, the diagnostic mask time may be set taking into account the increase in communication delay time due to the length of the communication path. This increase in communication delay time may also be considered when setting other parameters such as the SWOFF time, as described later. In the absence of a communication interruption, the diagnostic mask time for the slave ECU6 is calculated based, for example, on the startup time of the slave ECU6 and the delay time on the old communication path (e.g., communication lines 31 and 36). On the other hand, in the absence of a communication interruption, this diagnostic mask time is calculated based on the startup time of the slave ECU6 and the delay time on the new communication path (e.g., with the addition of the control ECU4, communication lines 32, 34, and 36). Furthermore, each device constituting the vehicle control system 1 may perform time synchronization to determine the timing of signal transmission and reception according to a common time. In this case, the time synchronization may be corrected according to the communication delay time. That is, the time held by each ECU may be corrected taking into account the communication delay time to ensure accurate synchronization. In addition, the control timing may be adjusted taking into account the communication delay time. For example, the control timing may be adjusted to match the timing at which the ECU that receives the frame the latest receives that frame.

[0113] When a diagnostic mask time is set for a communication partner device in each device, signals related to that communication partner device are ignored within the diagnostic mask time. More specifically, for example, within the diagnostic mask time period for slave ECU6, signals related to slave ECU6 are ignored in all devices.

[0114] Next, the CPU 51 of the management ECU 2 is configured in S380 to notify at least several control ECUs 3, 4, and 5 of diagnostic mask information. The diagnostic mask information includes the diagnostic mask time. Once this process is complete, this process terminates. The diagnostic mask time may also be notified from control ECU 3 to slave ECUs 6 and 7, from control ECU 4 to slave ECUs 8 and 9, and from control ECU 5 to slave ECUs 10 and 11.

[0115] Next, Figure 6 is a flowchart showing the slave startup process for starting slave ECUs 6-11, which is executed by the CPUs 71, 91, and 111 (hereinafter referred to as the dependent CPUs 71, etc.) of multiple control ECUs 3, 4, and 5, respectively. The slave startup process is a process that starts, for example, when the power to control ECUs 3, 4, and 5 is turned on.

[0116] In the slave startup process, as shown in Figure 6, the slave CPU 71, etc., first determines in S410 whether or not an NM frame has been received. The NM frame here may include a configuration notification and a startup command sent by the management ECU 2.

[0117] Next, in S415, the dependent CPU 71 and others configure themselves to communicate using the new communication path according to the configuration notification. The dependent CPU 71 and others store the new and old communication paths in the storage units 64, 84, and 104. These new and old communication paths are configured to be readable from the storage units 64, 84, and 104 when the dependent CPU 71 and others are restarted.

[0118] Next, the subordinate CPU 71, etc., determines in S420 whether or not to start the subordinate ECUs according to the start command included in the NM frame. The subordinate ECUs refer to slave ECUs 6 to 11 that are subordinate to control ECUs 3, 4, and 5. Slave ECUs 6 and 7 are subordinate to control ECU 3, slave ECUs 8 and 9 are subordinate to control ECU 4, and slave ECUs 10 and 11 are subordinate to control ECU 5. Note that control ECUs 3, 4, and 5 may also be considered subordinate ECUs from the perspective of management ECU 2.

[0119] In S420, for example, if the control ECU4 does not need to start the subordinate ECUs and simply relays the NM frame, it is judged negatively, and if the control ECU3 starts the slave ECU6, it is judged positively. If the subordinate ECUs are not started, the process proceeds to S450. If the subordinate ECUs are started, the process proceeds to S430.

[0120] Next, the subordinate CPU 71, etc., turns on the power distribution switch corresponding to the subordinate ECU in S430. Then, power is supplied to the subordinate ECU, and the ECU starts up. For example, when the control ECU 3 turns on the power to the slave ECU 6 (i.e., supplies power), it turns on the power distribution switch 65.

[0121] Next, the subordinate CPU 71, etc., determines in S440 whether the startup time has elapsed. The startup time is the time from when the power to the subordinate ECU is turned on until the startup is complete. The startup time is approximately the same as the diagnostic mask time. If the startup time has not elapsed, S440 is repeated. If the startup time has elapsed, the process proceeds to S450.

[0122] Next, the subordinate CPU 71, etc., sends an NM frame to the relay destination control ECU or subordinate ECU in S450. The NM frame sent here may contain configuration notifications and startup commands, similar to the NM frame received from the management ECU 2. However, when sending an NM frame to a subordinate ECU, a startup command is unnecessary because the subordinate ECU is already running. Once this process is complete, this process terminates. The NM frame may include not only a start command, but also stop information (described later), or commands to wake up or put the ECU to sleep. If the subordinate ECU is in sleep mode, the control ECUs 3, 4, and 5 may send a wake-up command to the subordinate ECU in S430. Also, if the configuration allows the subordinate ECU to recognize the NM frame while in sleep mode, the transmission of the wake-up command from the control ECUs 3, 4, and 5 may be omitted. Furthermore, the subordinate ECU may receive the NM frame transmitted in S450 and wake up itself.

[0123] Next, Figure 7 is a flowchart showing the restart process. The restart process is a process that starts when the management ECU2 goes into sleep mode or powers off due to, for example, turning off the ignition after a change in the communication path, and then starts up again. This process is executed by the CPU 51 of the management ECU2.

[0124] Next, the CPU 51 of the management ECU2 determines in S460 whether it is configured to use the new communication path. Here, the management ECU2 is pre-configured to either use the new communication path or the old communication path (the one used before the communication interruption) when it restarts after detecting a communication interruption. This setting can be changed at will, and this setting is shared with each device that makes up the network using NM frames, etc. If the new communication path is to be used, the process moves to S470; if the old communication path is to be used, the process moves to S480.

[0125] Next, the CPU 51 of the management ECU2 is configured in S470 to use the new communication path. In this case, communication resumes using the new communication path without using the old one.

[0126] Meanwhile, the CPU 51 of the management ECU2 is configured in S480 to use the old communication path. In this case, if a communication interruption is detected again during the master startup process described above, the new communication path will be used. Once these processes are completed, the restart process will end. Note that whether to use the new communication path or the old communication path is notified to each device via the NM frame setting notification.

[0127] Next, we will explain the process of stopping slave ECU6 as part of the process of stopping the slave ECU. Note that the process shown below is not limited to stopping slave ECU6, but can be applied to any process that requires consideration of waiting time, such as when putting slave ECU6 to sleep, and that identifies the communication partner and sends an NM frame.

[0128] Figure 8 is a flowchart showing the master shutdown process. The master shutdown process is a process that starts, for example, when the management ECU2 is started up, and is executed by the CPU 51 of the management ECU2.

[0129] The process from S310 to S340 in the master shutdown process is the same as the process from S310 to S340 in the master startup process. As shown in Figure 8, if an event occurs in S340, the process proceeds to S510.

[0130] Next, the CPU 51 of the management ECU 2 selects an ECU to be stopped in response to an event at S510. In this example, the slave ECU 6 is selected. Next, the CPU 51 of the management ECU2 sends an NM frame via S520 to the new communication path. This NM frame contains stop information to stop the slave ECU6, as well as the aforementioned configuration notification. The stop information is transmitted sequentially along the new communication path.

[0131] Next, the CPU 51 of the management ECU2 calculates the waiting time until SWOFF (i.e., SWOFF time, or OFF waiting time) in S530. The waiting time until SWOFF is the time until the shutdown sequence in the slave ECU6 is completed and the power distribution switch 65 can be turned OFF. This time is set taking into account the time required for the shutdown sequence by the slave ECU6 after receiving the stop information. Note that the time it takes for the slave ECU6 to shut down is known.

[0132] Next, in S540, the CPU 51 of the management ECU2 determines whether the waiting time has elapsed since it was set. If the waiting time has not elapsed, S540 is repeated. If the waiting time has elapsed, the process proceeds to S550.

[0133] Next, the CPU 51 of the management ECU 2 sends an NM frame at S550 to perform processing related to the slave ECU 6. Specifically, it sends an NM frame containing a SWOFF instruction, which is an instruction to turn off the power distribution switch 65 in order to stop the power supply to the slave ECU 6. These NM frames are transmitted sequentially along the new communication path. Once this processing is complete, the master shutdown process is finished.

[0134] Next, Figure 9A is a flowchart showing the slave stop process performed by each of the dependent CPUs 71, etc., to stop the slave ECU 6. The slave stop process is a process that starts, for example, when the power to the dependent CPU 71, etc. is turned on. The slave stop process is also a process that is performed by control ECUs 3 and 4, for example, when a communication interruption is detected on communication line 31 and communication is performed in the order of communication line 32, control ECU 4, communication line 34, control ECU 3, and communication bus 36.

[0135] In the slave shutdown process, as shown in Figure 9A, the slave CPU 71, etc., first determines in S610 whether or not an NM frame has been received. Specifically, it determines whether or not shutdown information has been received. The NM frame contains a configuration notification sent by the management ECU 2. If no NM frame has been received, S610 is repeated. If an NM frame has been received, the process proceeds to S415.

[0136] Next, the subordinate CPU 71 and others are configured in S415 to communicate using the new communication path according to the configuration notification. Next, the subordinate CPU 71 and other units relay the received NM frame containing the stop information along a new communication path in S620. For example, control ECU 4 relays the NM frame to control ECU 3, and control ECU 3 relays the NM frame to slave ECU 6. Once this process is complete, this process terminates.

[0137] Next, Figure 9B is a flowchart showing the terminal shutdown process performed by the CPUs (not shown) of each of the slave ECUs 6 to 11. The terminal shutdown process is a process that starts, for example, when the power to slave ECUs 6 to 11 is turned on.

[0138] In the terminal stop process, as shown in Figure 9B, slave ECUs 6-11 first determine in S660 whether or not they have received an NM frame. Specifically, they determine whether or not they have received stop information. If an NM frame has not been received, S660 is repeated. If an NM frame has been received, the process proceeds to S670.

[0139] Next, slave ECUs 6-11 perform the necessary steps to shut down their own devices in S670, according to the received stop information. In other words, they perform a shutdown. Once this process is complete, this process ends. Furthermore, the process for stopping the device itself is not limited to a shutdown; a sleep process may also be used. Sleep is a state in which at least frame transmission is stopped, and it consumes less power than the normal state (for example, a state in which frames can be transmitted). In addition, the NM frame containing the stop information may be transmitted by the management ECU2, or by the control ECUs 3, 4, and 5.

[0140] [2-5. Effects] The second embodiment described in detail above achieves the effect (1a) of the first embodiment described above, and further achieves the following effects.

[0141] (2a) The vehicle control system 1 is a system configured such that a management ECU 2 and a plurality of control ECUs 3, 4, and 5 managed by the management ECU 2 can communicate with each other by selectively using one of a plurality of communication paths. Each device is connected, for example, in a ring shape by communication lines 31 to 35.

[0142] In S330, the CPU 51 of the management ECU2 is configured to select a new communication path that avoids the abnormal part when it receives an anomaly notification indicating that the abnormal part is located in one of the communication paths used before the anomaly was detected. In S360, the CPU 51 of the management ECU2 is configured to send a configuration notification to at least several control ECUs 3, 4, and 5, informing them that communication will be performed using the newly selected communication path.

[0143] The CPU 51 of the management ECU2 is configured in S310 to detect abnormalities in the communication path. The CPU 51 of the management ECU2 is configured in S325 to send an abnormality notification within the management ECU2 regarding the detected abnormality.

[0144] The CPUs 71, 91, and 111 of the multiple control ECUs 3, 4, and 5 are configured in S415 to set up a new communication path and communicate according to the configuration notification. With this configuration, if an abnormality occurs in the communication path, a new communication path that avoids the abnormal part can be established, and communication can be carried out using this new communication path, thus making it less likely that necessary communication will be impossible.

[0145] (2b) The vehicle control system 1 further comprises slave ECUs 6 to 11, which are devices that are communicatively connected to at least one of the multiple control ECUs 3, 4, and 5. The management ECU 2 is configured in S370 and S530 to calculate the processing waiting time (e.g., diagnostic mask time, SWOFF time) for the management ECU 2 or the multiple control ECUs 3, 4, and 5, taking into account the required waiting time for the slave ECUs 6 to 11. The required waiting time includes, for example, the communication delay time from the synchronization time, the ECU startup time, and the power off time.

[0146] Furthermore, the management ECU2 and at least one of the multiple control ECUs 3, 4, and 5 perform processing related to the target device after waiting for a processing waiting time in S450 and S550.

[0147] Specifically, the CPU 51 of the management ECU 2 is configured in S380 to notify at least several control ECUs 3, 4, and 5 of the processing waiting time. Furthermore, the CPU 51 of the management ECU 2 is configured to wait for a processing delay period in S550, and then send control instructions (e.g., NM frames) to at least several control ECUs 3, 4, and 5.

[0148] With this configuration, the processing wait time for the management ECU2 or multiple control ECUs 3, 4, and 5 is calculated taking into account the required waiting time, and processing can be performed after waiting for the processing wait time.

[0149] (2c) In the vehicle control system 1, the management ECU 2, the multiple control ECUs 3, 4, 5, and slave ECUs 6 to 11 may be configured to synchronize their time with respect to communication. The CPU 51 of the management ECU 2 is configured in S370 and S530 to calculate the communication delay time due to the change in the communication path, which is the processing waiting time, taking into account the communication time required to reach the target device, which is the required waiting time. With this configuration, even if the communication delay time increases, it is possible to take that increase into account and correct the synchronization time, set the processing timing, etc.

[0150] (2d) In the vehicle control system 1, the management ECU 2 includes a storage unit 43 configured to store a new communication path and the old communication path before the new communication path was set. When the management ECU 2 is restarted, the management ECU 2 is configured to start communication using the old communication path.

[0151] With this configuration, when the management ECU2 is restarted, communication can be performed using the old communication path as usual. This is effective when restarting the management ECU2 restores the communication path to its normal state.

[0152] (2e) In the vehicle control system 1, the management ECU 2 may include a storage unit 43 configured to store a new communication path and the old communication path before the new communication path was set. When the management ECU 2 is restarted, the management ECU 2 may start communication using the new communication path.

[0153] With this configuration, when the management ECU2 is restarted, communication can be performed using a new communication path. This is effective when the situation does not improve even after the management ECU2 is restarted, such as when there is physical damage to the communication path.

[0154] (2f) In the vehicle control system 1, the CPU 51 of the management ECU 2 is configured in S360 to send a start command to start the target device along a new communication path. In S370 and S530, the CPU 51 of the management ECU 2 is configured to calculate the diagnostic mask time for the target device as a processing waiting time, taking into account the start time of the target device as a required waiting time.

[0155] This configuration makes it possible to prevent the target device from being mistakenly identified as abnormal during the time it is being started up and operating normally. In other words, it is possible to prevent incorrect diagnostics from being stored in each device.

[0156] [3. Other Embodiments] Although embodiments of this disclosure have been described above, this disclosure is not limited to the embodiments described above and can be implemented in various modified forms. (3a) In the second embodiment described above, the management ECU2 is configured to detect abnormalities in the communication path, but it is not limited to this. It is not limited to the management ECU2, but may be provided in, for example, at least one of the multiple control ECUs 3, 4, 5.

[0157] When control ECUs 3, 4, and 5 detect an abnormality in the communication path, the process shown in Figure 10 is performed, for example. Figure 10 is a flowchart showing the slave detection process performed by the slave CPU 71, etc. The abnormality detection process is initiated, for example, when the power to control ECUs 3, 4, and 5 is turned on.

[0158] In the anomaly detection process, as shown in Figure 10, the dependent CPU 71, etc., first performs a disconnection determination in S420. This process is the same as S230 and S310 described above. Next, the dependent CPU 71, etc., determines in S720 whether or not there is a communication interruption. This process is the same as in S320 mentioned above. If there is no communication interruption, it returns to S710. If there is a communication interruption, it proceeds to S730.

[0159] The dependent CPU 71, etc., sends an NM frame to the management ECU 2 via S730. This NM frame contains an error notification. Furthermore, if an abnormality in the communication path is detected, control ECUs 3-5 may use broadcasting, for example, to notify management ECU 2 of the abnormality. This is because control ECUs 3-5 may not be aware of the network configuration (i.e., how each device is connected). However, if control ECUs 3-5 are aware of the network configuration, they may use any available communication path to management ECU 2 to notify the abnormality. Once this process is complete, this process terminates.

[0160] If an abnormality notification is sent during this process, the management ECU2 should perform the processes from S325 onwards of the master startup process and master shutdown process, and in process S325, it should acquire the abnormality notification sent by the dependent CPU 71, etc.

[0161] (3b) In the second embodiment described above, the system is configured to immediately change the communication path when an abnormality is detected, but it is not limited to this. When an abnormality is detected, if a predetermined condition is met, such as when a pre-set event occurs, the system may not change the communication path. In this case, when the vehicle's power is cut off and then the vehicle's power is restored (for example, when the ignition is turned on), communication may be performed using the new communication path.

[0162] (3c) In the second embodiment described above, an example was given in which only the slave ECU6 is started as the target device in S360. However, if the control ECUs 3, 4, and 5 are in sleep mode, the control ECUs 3, 4, and 5 may also be started as target devices. In such cases, the CPU 51 of the management ECU2 may send start commands to the target devices in order from the starting point to the ending point of the multiple target devices, according to the connection order of the multiple target devices from the starting point to the ending point of the new communication path. For example, if the management ECU2 starts the slave ECU 10 while the control ECU 5 and slave ECUs 10 and 11 are in sleep mode, the CPU 51 of the management ECU2 may start the control ECU 5 first and then start the slave ECU 10.

[0163] With this configuration, it is possible to start up each of the multiple target devices sequentially, taking the connection order into consideration.

[0164] (3d) The control units 41, 61, 81, 101 and their methods described in this disclosure may be implemented by a dedicated computer provided by configuring a processor and memory programmed to perform one or more functions embodied by a computer program. Alternatively, the control units 41, 61, 81, 101 and their methods described in this disclosure may be implemented by a dedicated computer provided by configuring a processor by one or more dedicated hardware logic circuits. Alternatively, the control units 41, 61, 81, 101 and their methods described in this disclosure may be implemented by one or more dedicated computers configured by a combination of a processor and memory programmed to perform one or more functions and a processor configured by one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium. The methods for implementing the functions of each part included in the control units 41, 61, 81, 101 do not necessarily need to include software, and all of its functions may be implemented using one or more hardware components.

[0165] (3e) Multiple functions of one component in the above embodiment may be realized by multiple components, or one function of one component may be realized by multiple components. Also, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, some of the configurations of the above embodiment may be omitted. Furthermore, at least some of the configurations of the above embodiment may be added to or replaced with the configurations of other above embodiments.

[0166] (3f) In addition to the ECU2-5 described above, this disclosure can also be realized in various forms, such as a system comprising the ECU2-5, a program for causing the computer to function as the ECU2-5, a non-transitional physical recording medium such as semiconductor memory on which this program is recorded, and a communication control method.

[0167] [Technical Concept Disclosed in This Specified Specification] [Item 1] A communication system (1) is configured such that a management device (2), a plurality of managed devices (3, 4, 5) managed by the management device, and at least one target device (6 to 11) which is a device that is communicatively connected to at least one of the plurality of managed devices, each selectively using one of a plurality of communication paths to communicate with one another, The aforementioned control device is When an abnormality notification is received that indicates an abnormal location among the multiple communication paths where an abnormality has occurred, the communication path selection unit (S330) is configured to select a new communication path that avoids the abnormal location, A notification transmission unit (S360) is configured to send a configuration notification, which is a notification to at least the multiple managed devices that communication will be performed using the selected new communication path, Equipped with, The management device and at least one of the plurality of managed devices are: An anomaly detection unit (S310, S710) configured to detect anomalies in the aforementioned communication path, An abnormality notification unit (S325, S730) is configured to notify the communication path selection unit of the abnormality notification regarding the detected abnormality, Equipped with, The plurality of devices to be managed are, A route change unit (S415) configured to set up a new communication path and perform communication in accordance with the aforementioned setting notification, Equipped with, The setting notification includes switching information that can identify whether to turn on or off the multiple managed devices and / or the target device. Communication system. [Item 2] The communication system described in item 1, The management device further comprises a time calculation unit (S370, S530) configured to calculate the processing waiting time for the management device or the plurality of managed devices, taking into account the necessary waiting time for the target device. The management device and at least one of the plurality of managed devices are: After waiting for the aforementioned processing waiting time, the processing unit (S450, S550) performs processing related to the target device. A communication system that also includes additional features. [Item 3] The communication system described in item 1, The management device further includes a time calculation unit (S370, S530) configured to calculate the processing waiting time for the management device or the plurality of managed devices, taking into account the communication delay time due to the change in the communication path. The management device and at least one of the plurality of managed devices are: After waiting for the aforementioned processing waiting time, the processing unit (S450, S550) performs processing related to the target device. A communication system that also includes additional features. [Item 4] A communication system described in any one of items 1 through 3, The management device, the plurality of managed devices, and the target device are configured to synchronize their time with respect to communication. The management device and at least one of the plurality of managed devices correct the synchronization time with other devices, taking into account the communication delay time due to the change in the communication path. A communication system configured in such a way. [Item 5] A communication system described in any one of items 1 through 4, The aforementioned control device is A storage unit (43) configured to store the new communication path and the old communication path before the new communication path was established, When the management device restarts, it will begin communicating using the old communication path. A communication system configured in such a way. [Item 6] A communication system described in any one of items 1 through 5, The aforementioned control device is A storage unit (43) configured to store the new communication path and the old communication path before the new communication path was established, When the management device restarts, it will begin communicating using the new communication path. A communication system configured in such a way. [Item 7] A communication system as described in item 2 or item 3, The time calculation unit calculates the diagnostic mask time for the target device as the processing waiting time. A communication system configured in such a way. [Item 8] A communication system as described in item 2 or item 3, The device further comprises power distribution switches (65, 66, 85, 86, 105, 106) for transitioning the power supply of the target device between an on state and an off state, The time calculation unit calculates the off-wait time, which is the time required to transition the power distribution switch from the on state to the off state, as the processing waiting time. A communication system configured in such a way. [Item 9] A communication system described in any one of items 1 through 8, The aforementioned at least one target device comprises multiple target devices, The aforementioned control device is The system further comprises a startup transmission unit (S360) configured to transmit a startup command for starting the target device along the new communication path, The activation transmission unit transmits the activation command in order from the device closest to the starting point among the multiple target devices, according to the connection order of the multiple target devices from the starting point to the ending point in the new communication path. A communication system configured in such a way. [Explanation of symbols]

[0168] 1...Vehicle control system, 2...Management ECU, 3,4...Control ECU, 6~11...Slave ECU, 21,22,24,26...Power supply path, 31,32,34...Communication line, 65,85...Power distribution switch

Claims

1. A communication system (1) comprising a management device (2), a plurality of managed devices (3, 4, 5) managed by the management device, and at least one target device (6 to 11) which is a device that is communicatively connected to at least one of the plurality of managed devices, each configured to communicate with one another by selectively using one of a plurality of communication paths, The aforementioned control device is A communication path selection unit (S330) is configured to receive an abnormality notification indicating an abnormal location among the multiple communication paths where an abnormality has occurred, and to select a new communication path that avoids the abnormal location. A notification transmission unit (S360) is configured to send a setting notification, which is a notification to at least the multiple managed devices that communication will be performed using the selected new communication path, Equipped with, The management device and at least one of the plurality of managed devices are: An anomaly detection unit (S310, S710) configured to detect an anomaly in the aforementioned communication path, An abnormality notification unit (S325, S730) is configured to notify the communication path selection unit of the abnormality notification regarding the detected abnormality, Equipped with, The plurality of devices to be managed are, A route change unit (S415) configured to set a new communication path and perform communication in accordance with the aforementioned setting notification. Equipped with, The setting notification includes switching information that can identify whether to turn on or off the multiple managed devices and / or the target device. Communication system.

2. A communication system according to claim 1, The management device further includes a time calculation unit (S370, S530) configured to calculate the processing waiting time for the management device or the plurality of managed devices, taking into account the necessary waiting time for the target device. The management device and at least one of the plurality of managed devices are: After waiting for the aforementioned processing waiting time, the processing unit (S450, S550) performs processing related to the target device. A communication system that also includes additional features.

3. A communication system according to claim 1, The management device further includes a time calculation unit (S370, S530) configured to calculate the processing waiting time for the management device or the plurality of managed devices, taking into account the communication delay time due to the change in the communication path. The management device and at least one of the plurality of managed devices are: After waiting for the aforementioned processing waiting time, the processing unit (S450, S550) performs processing related to the target device. A communication system that also includes additional features.

4. A communication system according to claim 1 or claim 2, The management device, the plurality of managed devices, and the target device are configured to synchronize their time with respect to communication. The management device and at least one of the plurality of managed devices correct the synchronization time with other devices, taking into account the communication delay time due to the change in the communication path. A communication system configured in such a way.

5. A communication system according to claim 1 or claim 2, The aforementioned control device is A storage unit (43) configured to store the new communication path and the old communication path before the new communication path was established, When the management device restarts, it will begin communicating using the old communication path. A communication system configured in such a way.

6. A communication system according to claim 1 or claim 2, The aforementioned control device is A storage unit (43) configured to store the new communication path and the old communication path before the new communication path was established, When the management device restarts, it will begin communicating using the new communication path. A communication system configured in such a way.

7. A communication system according to claim 2 or claim 3, The time calculation unit calculates the diagnostic mask time for the target device as the processing waiting time. A communication system configured in such a way.

8. A communication system according to claim 2 or claim 3, The device further comprises power distribution switches (65, 66, 85, 86, 105, 106) for transitioning the power supply of the target device between an on state and an off state. The time calculation unit calculates the off-wait time, which is the time required to transition the power distribution switch from the on state to the off state, as the processing waiting time. A communication system configured in such a way.

9. A communication system according to claim 1 or claim 2, The aforementioned at least one target device comprises multiple target devices, The aforementioned control device is The system further comprises a startup transmission unit (S360) configured to transmit a startup command for starting the target device along the new communication path, The activation transmission unit transmits the activation command in order from the device closest to the starting point among the multiple target devices, according to the connection order of the multiple target devices from the starting point to the ending point in the new communication path. A communication system configured in such a way.

Citation Information

Patent Citations

  • On-vehicle network system and management device

    JP2015081021A