Diagnostic system

The diagnostic system addresses conflicts between reset and BIST commands by prioritizing reset operations, ensuring the second module is reset before BIST, thus preventing continued abnormal operation.

JP2026121149APending Publication Date: 2026-07-23DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
DENSO CORP
Filing Date
2025-01-10
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

In diagnostic systems where a first module requests Built In Self-Test (BIST) for a second module via a third monitoring module, conflicts between reset and BIST commands can cause the second module to continue operating in an abnormal state.

Method used

A diagnostic system with a third module that prioritizes transmitting a reset command over a BIST command when a conflict arises, ensuring the second module is reset before executing BIST.

Benefits of technology

Prevents the second module from continuing to operate in an abnormal state by prioritizing the reset command, thereby reducing the risk of further system instability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026121149000001_ABST
    Figure 2026121149000001_ABST
Patent Text Reader

Abstract

This technology provides a way to prevent circuits from continuing to operate while in an abnormal state. [Solution] The management device is connected to a first controller and a second controller, both capable of performing BIST (Built In Self-Test). The execution of BIST by the first and second controllers is controlled by the management device. The first controller is configured to send a BIST request, which is a signal requesting the second controller to perform BIST, to the management device. The management device has a function to send a reset command to the second controller upon detecting an abnormality in the second controller, and a function to send a BIST command to the second controller upon receiving a request from the first controller. The management device is configured to prioritize the transmission of the reset command in situations where the transmission of a reset command to the second controller and the transmission of a BIST command conflict.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a diagnostic technique for circuit modules.

Background Art

[0002] Patent Document 1 discloses a system including a module that issues an execution request for BIST (Built In Self-Test) and a module that receives the execution request for BIST. Here, the module may be regarded as a circuit or an apparatus.

Prior Art Documents

Patent Documents

[0003] <P

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] As a configuration of another diagnostic system different from the configuration disclosed in Patent Document 1, a system including a first module that issues an execution request for BIST, a second module that is the target of BIST, and a third module that is disposed between the first module and the second module and monitors the operation of the second module is assumed. When the third module detects an abnormality in the second module, the third module inputs a reset command to the second module and restarts the second module. Further, when the third module receives an execution request for BIST from the first module to the second module, the third module inputs a BIST command to the second module and executes BIST. Thus, the first module that requests the execution of BIST in the second module is not directly connected to the second module, but is indirectly connected via the third module.

[0005] In such a hypothetical configuration, a conflict may occur between the reset command to the second module and the BIST command in the third module. That is, the third module should reset the second module, but it may also receive a BIST execution request from the first module. In such a conflict situation, if the configuration prioritizes sending the BIST command, the second module will continue to operate in an abnormal state due to the BIST command.

[0006] This disclosure is made in accordance with the circumstances described above, and one of its purposes is to provide a technology that prevents a circuit from continuing to operate in an abnormal state. [Means for solving the problem]

[0007] One diagnostic system disclosed herein includes a first module (1) including a circuit, a second module (2) configured to perform a Built In Self-Test (BIST), and a third module (3) that is communicatively connected to the first and second modules respectively and monitors the status of the first and second modules, wherein the first module is configured to transmit a BIST request, which is a signal requesting the second module to perform a BIST, to the third module, and the third module has the function of transmitting a reset command to reset the second module upon detecting an abnormality in the second module, and the function of transmitting a BIST command, which is a signal instructing the second module to perform a BIST, based on the receipt of a BIST request from the first module, and further the third module is configured to prioritize the transmission of the reset command when there is a conflict between transmitting a reset command to the second module and transmitting a BIST command.

[0008] With the above configuration, if the transmission of a reset command to the second module and the transmission of a BIST command conflict, the third module will prioritize outputting the reset command. Therefore, the risk of the second module continuing to operate in an abnormal state due to BIST can be reduced.

[0009] The reference numerals in parentheses in the claims indicate the correspondence with the specific means described later in the embodiments, and do not limit the technical scope of this disclosure. [Brief explanation of the drawing]

[0010] [Figure 1] This is a block diagram showing the schematic configuration of an electronic control system. [Figure 2] This diagram shows the connection between the management device and the controller. [Figure 3] This is a timeline chart showing the sequence of events from when an anomaly occurs in the second controller until a reset is performed. [Figure 4] This is a time chart illustrating the operation of the control device in the comparative example. [Figure 5] This is a time chart illustrating the operation of the control device in this embodiment. [Figure 6] This is a time chart illustrating the operation of the control device in this embodiment. [Figure 7] This is a time chart illustrating the operation of the control device in this embodiment. [Modes for carrying out the invention]

[0011] Embodiments of this disclosure will be described below with reference to the drawings. This disclosure is not limited to the embodiments described below. The configurations disclosed below may be implemented with various modifications without departing from the gist of the invention. Various modifications may be combined as appropriate, without causing any technical inconsistencies. This disclosure also includes configurations that are not explicitly stated, which are combinations of multiple modifications. In the following description, components having the same function may be denoted by the same reference numeral and their specific description may be omitted. Also, components having the same function may be denoted by the same or similar names and their specific description may be omitted. If only a part of a configuration is referred to, the description of the other parts may be applied elsewhere.

[0012] Figure 1 shows an electronic control system 100 to which the diagnostic system of this disclosure is applied. As shown in Figure 1, the electronic control system 100 comprises a first controller 1, a second controller 2, and a management device 3. The electronic control system 100 may be, for example, a system for controlling a motor generator. The motor generator is a device that integrates the starting function of a starter and the power generation function of an alternator, and may be, for example, a three-phase AC rotating electric machine. The motor generator provides functions such as engine starting, engine assist during acceleration, and battery charging by energy regeneration during deceleration. Note that the diagnostic system of this disclosure is not limited to a motor generator control system, but may be applied to other devices / systems.

[0013] The first controller 1 is, for example, a device that controls the movement of the front wheels. The first controller 1 may be a microcontroller (MCU). The first controller 1 may include a processor, memory, storage, and input / output circuits. The first controller 1 performs predetermined processing by having the processor execute a program stored in memory or storage.

[0014] The first controller 1 is equipped with a watchdog function, a voltage monitoring function, and an anomaly detection function. The watchdog function periodically generates a watchdog clear signal (hereinafter referred to as the WDC signal) and outputs it to the management device 3. The watchdog function may also input the periodically generated WDC signal to itself and initiate a restart based on the absence of an abnormal WDC signal for a certain period of time. The WDC signal may be, for example, a low-level signal.

[0015] The voltage monitoring function is a function that monitors whether the voltage to be monitored (hereinafter referred to as the target voltage) is within a predetermined normal range. The target voltage may be the power supply voltage of the first controller 1, for example. The determination of whether the target voltage is within the normal range may be achieved by comparison with an internal reference voltage, and the voltage monitoring function may be configured using, for example, a voltage divider circuit or a comparator. The voltage monitoring function may output a high-level signal when the target voltage is within the normal range and a low-level signal when it is outside the normal range. The signal indicating that the target voltage is within the normal range (here, the high-level signal) may be called the normal voltage signal. The signal indicating that the target voltage is outside the normal range (here, the low-level signal) may be called the abnormal voltage signal.

[0016] The anomaly detection function outputs a signal to other devices, such as the management device 3, indicating whether or not an anomaly has been detected in the first controller 1. For example, the anomaly detection function may output a low-level signal when an anomaly is detected in the first controller 1, and a high-level signal in other cases (i.e., when normal). Anomalies may include deviations from the normal range of the target voltage as described above, or the expiration of the watchdog timer. The anomaly detection function may also be configured to detect temperature anomalies, memory sticking, overcurrents, etc., as anomaly events. The signal indicating that an anomaly has occurred (in this case, a low-level signal) may be called an error signal. In other embodiments, the first controller 1 and the management device 3 may be configured so that a high-level signal functions as an error signal.

[0017] In addition, the first controller 1 is configured to be able to execute BIST (Built In Self Test). BIST may also be referred to as a hardware self - test or the like. A test circuit is incorporated in the first controller 1. The test circuit may include a test address generation circuit, a data generation circuit, and a circuit for reading and comparing data. The first controller 1 executes BIST based on the input of a BIST command signal instructing the execution of BIST from the management device 3. BIST may be to check the watchdog function, voltage monitoring function, and abnormality detection function. The check of each functional block may be executed in a predetermined procedure. The BIST command signal may be, for example, a high - level signal.

[0018] When the first controller 1 executes BIST, it stores the result in a predetermined register within the first controller 1. The result of BIST stored in the register is appropriately referred to by the management device 3. In other embodiments, the first controller 1 may be configured to report the result of BIST to the management device 3.

[0019] In addition, the first controller 1 includes a BIST request unit 10 that controls the execution of BIST in the first controller 1 and the second controller 2. The BIST request unit 10 will be described separately later.

[0020] The second controller 2 is a device that controls a different target from the first controller 1. For example, the second controller 2 may be a device that controls the movement of the rear wheels. The second controller 2 may also be an MCU, similar to the first controller 1. The second controller 2 may include a processor, a memory, a storage, and input / output circuits. The second controller 2 executes a predetermined process by the processor executing a program stored in the memory or storage.

[0021] The second controller 2 may have substantially the same functions and configuration, differing only in the control target from the first controller 1. The second controller 2 also has a watchdog function, a voltage monitoring function, and an abnormality detection function. The second controller 2 outputs a WDC signal, a voltage abnormality signal, an error signal, etc. to the management device 3.

[0022] Of course, the second controller 2 may have functions and configurations different from those of the first controller 1. Hereinafter, when the first controller 1 and the second controller 2 are not distinguished, it is simply described as a controller.

[0023] The second controller 2 is also configured to be able to execute BIST. The second controller 2 executes BIST based on the input of a BIST command signal from the management device 3. The BIST in the second controller 2 may also check the watchdog function, the voltage monitoring function, and the abnormality detection function. When the second controller 2 executes BIST, it stores the result in a predetermined register in the second controller 2. The result of BIST stored in the register of the second controller 2 may be appropriately referred to by the management device 3. The second controller 2 may be configured to report the result of BIST to the management device 3.

[0024] The management device 3 is a device that monitors and controls the first controller 1 and the second controller 2. The management device 3 may be realized using an ASIC (Application Specific Integrated Circuit). The management device 3 may also be realized using hardware of a type other than ASIC, such as an FPGA (Field-Programmable Gate Array), an MCU, or a SoC (System on Chip). Note that the first controller 1 and the second controller 2 may also be an ASIC or an FPGA, etc.

[0025] The management device 3 includes a logic circuit 30 containing a plurality of registers 31, a memory 32, and a communication interface 33. The logic circuit 30 is a digital circuit module and includes circuits incorporated to function as the first management unit 41 and the second management unit 42, which will be described below. The registers 31 may be flip-flops, for example, and are used for storing calculation results, states, settings, etc.

[0026] Multiple registers 31 include a request management register 31a, which is used to manage the reception status of BIST requests, as described later. The request management register 31a has, for example, 8 bits, with certain bits indicating the reception status of the first BIST request and other specific bits indicating the reception status of the second BIST request. Details regarding the management of BIST requests will be described separately later.

[0027] The memory 32 may be DRAM (Dynamic Random Access Memory), flash memory, or other types of storage media. The communication interface 33 may be a circuit module for communicating with the first controller 1 and the second controller 2. The communication interface 33 includes a plurality of ports. The communication interface 33 includes GPIO (General Purpose Input / Output) ports and ports for SPI (Serial Peripheral Interface), etc.

[0028] In the following, communication using GPIO will be referred to as GPIO communication, and communication using SPI will be referred to as SPI communication. The management device 3 in this embodiment is configured to communicate with both the first controller 1 and the second controller 2 using GPIO. The management device 3 is also configured to communicate with the first controller 1 only using SPI. The management device 3 is configured not to communicate with the second controller 2 using SPI. Furthermore, the first controller 1 in this embodiment is configured not to communicate with the second controller 2. In other words, the first controller 1 is configured not to be able to directly obtain the operating status (normal / abnormal) of the second controller 2 from the second controller 2. The specific configuration of communication between the management device 3 and each controller will be described separately.

[0029] The management device 3 comprises a first management unit 41 and a second management unit 42 as functional blocks. The first management unit 41 is a functional block for managing the first controller 1. The first management unit 41 comprises a first BIST control unit 411 and a first monitoring unit 412. The second management unit 42 is a functional block for managing the second controller 2. The second management unit 42 comprises a second BIST control unit 421 and a second monitoring unit 422. The first BIST control unit 411 and the second BIST control unit 421 will be described later.

[0030] The first monitoring unit 412 monitors the operation of the first controller 1 based on signals input from the first controller 1 and detects any abnormalities in the first controller 1. When the first monitoring unit 412 detects an abnormality in the first controller 1, it sends a reset command to the first controller 1 to reset it.

[0031] For example, the first monitoring unit 412 may be equipped with a watchdog timer for the first controller 1. The watchdog timer may be a mechanism that continuously counts up based on a clock signal or the like. The watchdog timer for the first controller 1 is reset when a WDC signal is input from the first controller 1. If the watchdog timer for the first controller 1 expires without a WDC signal being input from the first controller 1, the first monitoring unit 412 determines that there is a malfunction in the first controller 1. The expiration of the watchdog timer can be understood as a state in which the count value becomes greater than or equal to a predetermined value. In addition, the first monitoring unit 412 may determine that there is a malfunction in the first controller 1 when a voltage abnormality signal (low in this case) is input from the first controller 1. The first monitoring unit 412 may determine that there is a malfunction in the first controller 1 when an error signal is input from the first controller 1.

[0032] The second monitoring unit 422 monitors the operation of the second controller 2 based on signals input from the second controller 2. When the second monitoring unit 422 detects an abnormality in the second controller 2, it sends a reset command to the second controller 2 to reset it. The second monitoring unit 422 may be equipped with a watchdog timer for the second controller 2. The watchdog timer for the second controller 2 is reset when a WDC signal is input from the second controller 2. If the watchdog timer for the second controller 2 expires without a WDC signal being input from the second controller 2, the second monitoring unit 422 determines that an abnormality has occurred in the second controller 2. The expiration of the watchdog timer can be understood as a state in which the count value exceeds a predetermined value.

[0033] Furthermore, the second monitoring unit 422 may determine that there is a malfunction in the second controller 2 when it receives a voltage abnormality signal from the second controller 2. The second monitoring unit 422 may also determine that there is a malfunction in the second controller 2 when it receives an error signal from the second controller 2.

[0034] <Regarding the configuration related to BIST> The first controller 1 is configured to be able to transmit a BIST request to the management device 3 by SPI communication. The BIST request is a signal that requests the transmission of a BIST command signal. As described above, the BIST command signal is a signal that commands (in other words, instructs) the execution of BIST.

[0035] In the present disclosure, the BIST command signal output by the management device 3 may also be described as a BIST command or a BIST instruction, etc. Also, the BIST command directed to the first controller 1 is also described as the first BIST command, and the BIST command directed to the second controller 2 is also described as the second BIST command. The BIST command is a signal transmitted by the management device 3 to the controller, and the BIST request is a signal transmitted by the first controller 1 to the management device 3. The BIST request corresponds to a signal that requests the management device 3 to cause the controller to execute BIST.

[0036] As BIST requests, there are a first BIST request that requests the management device 3 to transmit a BIST command to the first controller 1 (that is, itself), and a second BIST request that requests the management device 3 to transmit a BIST command to the second controller 2. The second BIST request corresponds to a request for executing BIST on the second module. The BIST request unit 10 of the first controller 1 is configured to transmit these BIST requests to the management device 3. The first BIST request issued by the BIST request unit 10 is received and processed by the first BIST control unit 411. Also, the second BIST request issued by the BIST request unit 10 is received and processed by the second BIST control unit 421. Note that the first BIST request and the second BIST request may be independent different frame signals or may be integrated into one frame. The BIST request unit 10 is configured to be unable to transmit a BIST request when an abnormality occurs in the first controller 1.

[0037] When the first BIST control unit 411 receives a first BIST request from the BIST request unit 10, it records this fact in the request management register 31a. For example, when the first BIST control unit 411 receives a first BIST request from the BIST request unit 10, it sets a predetermined bit in the request management register 31a, the first BIST request bit, from 0 to 1. The first BIST request bit is a bit used to manage whether or not a first BIST request exists. The first BIST request bit may be the first bit. The first BIST request bit may be the sixth bit, or the like.

[0038] A state where the first BIST request bit is 0 corresponds to a state where it is not necessary to send a BIST command to the first controller 1, that is, a state where no BIST command is sent to the first controller 1. A state where the first BIST request bit is 1 corresponds to a state where it is necessary to send a BIST command to the first controller 1. The value of the first BIST request bit is referenced by the first monitoring unit 412. The first monitoring unit 412 references the first BIST request bit at predetermined intervals or at arbitrary timings, and if the first BIST request bit is set to 1, it sends a BIST command to the first controller 1.

[0039] In this manner, the management device 3 manages whether or not to send a BIST command to the first controller 1 using a flag. This flag may be called the first BIST request flag, and is actually implemented by the first BIST request bit. When the first BIST request flag is off, the first BIST request bit is 0, and when the first BIST request flag is on, the first BIST request bit is 1. In this embodiment, BIST corresponds to checking the watchdog function, voltage monitoring function, and anomaly detection function. The first BIST request flag may also be understood as a flag for instructing the checking of the watchdog function, voltage monitoring function, and anomaly detection function.

[0040] The second BIST control unit 421 is configured for the second controller 2, corresponding to the first BIST control unit 411. When the second BIST control unit 421 receives a second BIST request from the BIST request unit 10, it records this fact in the request management register 31a. For example, when the second BIST control unit 421 receives a second BIST request from the BIST request unit 10, it sets a predetermined bit in the request management register 31a, the second BIST request bit, from 0 to 1. The second BIST request bit is a bit used to manage whether or not a second BIST request exists. The second BIST request bit is a different bit from the first BIST request bit. The second BIST request bit may be the second bit. The second BIST request bit may be the fifth bit, etc.

[0041] A state where the second BIST request bit is 0 corresponds to a state where it is not necessary to send a BIST command to the second controller 2, that is, a state where no BIST command is sent to the second controller 2. A state where the second BIST request bit is 1 corresponds to a state where it is necessary to send a BIST command to the second controller 2. The value of the second BIST request bit is referenced by the second monitoring unit 422. The second monitoring unit 422 references the second BIST request bit at predetermined intervals or at any time. If the second BIST request bit is set to 1, the second monitoring unit 422 sends a BIST command to the second controller 2.

[0042] In this way, the management device 3 uses a flag to manage whether or not to send a BIST command to the second controller 2. This flag may be called the second BIST request flag, and is actually implemented by the second BIST request bit. When the second BIST request flag is off, the second BIST request bit is 0, and when the second BIST request flag is on, the second BIST request bit is 1. The second BIST request flag can be understood as a flag that instructs the second controller 2 to check the watchdog function, voltage monitoring function, and anomaly detection function.

[0043] In this embodiment, the management device 3, acting as the second BIST control unit 421, keeps the second BIST request flag set to off if the second monitoring unit 422 detects an abnormality in the second controller 2. That is, if the second monitoring unit 422 detects an abnormality in the second controller 2, the second BIST control unit 421 will keep the second BIST request flag off even if it receives a second BIST request from the first controller, and will not switch it on. The second BIST control unit 421 releases the control that fixes the second BIST request flag to off when a predetermined prohibition release condition is met. The prohibition release condition may be, for example, that the second controller 2 has been operating normally for a certain period of time. The prohibition release condition may be the same as or different from the reset release condition. The specific content of the prohibition release condition may be designed as appropriate.

[0044] <Regarding the configuration related to communications> Figure 2 shows an example of the signals exchanged between the management device 3 and each controller, and the ports used for that purpose.

[0045] The first controller 1 and the management device 3 are equipped with four types of terminals (also called pins or ports) for SPI communication: MOSI (Master Output Slave Input), MISO (Master Input Slave Output), SCK (Serial Clock), and SS (Slave Select). MOSI is a terminal for transmitting data from the master to the slave, and MISO is a terminal for transmitting data from the slave to the master. SCK is a terminal to which a synchronization clock signal is input and output. SS is a terminal for selecting the communication partner. Here, as an example, the first controller 1 is configured to operate as the master in SPI communication. Of course, in other embodiments, the management device 3 may be configured to operate as the master in SPI communication. In the master, the number of SS terminals may correspond to the number of slaves.

[0046] The first controller 1 also includes a WDC output terminal 11 (WDC_OUT in the figure), a voltage abnormality output terminal 12 (VMON_OUT), an error output terminal 13 (ERR_OUT), an initialization input terminal 14 (INIT_IN), and a BIST input terminal 15 (BIST_IN). The WDC output terminal 11 is a terminal that outputs a WDC signal. The WDC output terminal 11 of the first controller 1 is connected to the first WDC input terminal 51 (WDC1) of the management device 3. The WDC output terminal 11 periodically outputs a low-level signal as a WDC signal. In the figure, "L" represents a low-level signal and "H" represents a high-level signal. Note that the technical significance (function / application) of the high-level signal and the low-level signal may be swapped as appropriate.

[0047] The voltage abnormality output terminal 12 is a terminal that outputs a voltage abnormality signal. When the target voltage is outside the normal range in the first controller 1, a low-level signal is output from the voltage abnormality output terminal 12 as a voltage abnormality signal. The error output terminal 13 is a terminal that outputs an error signal. When a predetermined error is detected in the first controller 1, a low-level signal is output from the error output terminal 13 as an error signal.

[0048] The initialization input terminal 14 (INIT_IN) is a terminal to which an initialization signal is input from the management device 3. The first controller 1 is reset based on the input level to the initialization input terminal 14 falling from a high level to a low level, or based on the input level being low. The initialization input terminal 14 is electrically connected to the first initialization terminal 54 of the management device 3.

[0049] The BIST input terminal 15 (BIST_IN) is a terminal to which a high-level signal as a BIST command is input from the management device 3. Based on the input level to the BIST input terminal 15 rising from a low level to a high level, or based on the input level being high, the first controller 1 executes BIST. The BIST input terminal 15 is electrically connected to the first BIST terminal 55 (BIST1) of the management device 3.

[0050] The second controller 2, like the first controller 1, is equipped with a WDC output terminal 21, a voltage abnormality output terminal 22, an error output terminal 23, an initialization input terminal 24, and a BIST input terminal 25. Since the function of each terminal is the same as that of the first controller, individual descriptions are omitted.

[0051] In addition to the terminals for SPI communication, the management device 3 is equipped with a first WDC input terminal 51, a first voltage abnormality input terminal 52, a first error input terminal 53, a first initialization terminal 54, and a first BIST terminal 55. Furthermore, the management device 3 is equipped with a second WDC input terminal 61, a second voltage abnormality input terminal 62, a second error input terminal 63, a second initialization terminal 64, and a second BIST terminal 65.

[0052] The first WDC input terminal 51, the first voltage abnormality input terminal 52, and the first error input terminal 53 are terminals for receiving WDC signals, voltage abnormality signals, error signals, etc. from the first controller 1.

[0053] The first initialization terminal 54 is a terminal for inputting a reset command to the first controller 1. If the first monitoring unit 412 does not detect any abnormality in the first controller 1, the management device 3 sets the output of the first initialization terminal 54 to a high level. If an abnormality is detected, it switches the output to a low level and restarts (i.e., resets) the first controller 1. In this embodiment, the low-level signal is configured to function as a reset command. Of course, in other embodiments, the high-level signal may be configured to function as a reset command.

[0054] After switching the output of the first initialization terminal 54 to a low level, the control device 3 keeps the output of the first initialization terminal 54 at a low level until a predetermined reset release condition is met. The reset release condition may be the elapsed time from the time the output level is switched from high to low, or it may be the reception of a predetermined number of WDC signals. The reset release condition may also be the continuation of a normal state for a certain period of time. When the reset release condition is met, the control device 3 returns the output of the first initialization terminal 54 to a high level.

[0055] The first BIST terminal 55 is a terminal for inputting a BIST instruction to the first controller 1. When the first BIST request flag is off, the management device 3 sets the output of the first BIST terminal 55 to a low level, preventing the BIST from being executed. When the first BIST request flag is on, the management device 3 switches the output of the first BIST terminal 55 to a high level. This causes the first controller 1 to execute the BIST. The result of the BIST in the first controller 1 is stored in a predetermined register within the first controller 1. The management device 3 reads the BIST result from the first controller 1 to determine whether it is normal or abnormal, and if the BIST result is normal, it returns the output of the first BIST terminal 55 to a low level.

[0056] The control device 3 is configured, by design, to set the output of the first initialization terminal 54 to a high level when the first BIST terminal 55 is set to a high level. The state in which the controller is made to execute BIST by setting the BIST terminal to a high level may be called BIST mode. The state in which the BIST terminal is set to a high level, that is, the state in which the controller is not made to execute BIST, may be called normal mode.

[0057] The second WDC input terminal 61, the second voltage abnormality input terminal 62, and the second error input terminal 63 are terminals for receiving WDC signals, voltage abnormality signals, error signals, etc. from the second controller 2.

[0058] The second initialization terminal 64 is a terminal for inputting a reset command to the second controller 2. The operation of the second initialization terminal 64 is the same as that of the first initialization terminal 54. If no abnormality is detected in the second controller 2, the management device 3 sets the output of the second initialization terminal 64 to a high level. If an abnormality is detected, the management device 3 switches the output of the second initialization terminal 64 to a low level and restarts the second controller 2. After switching the output of the second initialization terminal 64 to a low level, the management device 3 keeps the output of the second initialization terminal 64 at a low level until the reset release condition is met.

[0059] The second BIST terminal 65 is a terminal for inputting a BIST instruction to the second controller 2. When the second BIST request flag is off, the management device 3 sets the output of the second BIST terminal 65 to a low level, preventing the BIST from being executed. When the second BIST request flag is on, the management device 3 switches the output of the second BIST terminal 65 to a high level. This causes the second controller 2 to execute the BIST. The result of the BIST in the second controller 2 is stored in a predetermined register within the second controller 2. The management device 3 reads the BIST result from the second controller 2 to determine whether it is normal or abnormal, and if the BIST result is normal, it returns the output of the second BIST terminal 65 to a low level.

[0060] <Challenges> The electronic control system 100 of this embodiment has a configuration in which a first controller 1, which has a function to issue BIST requests, is connected to a second controller 2 via a management device 3, and the first controller 1 does not directly know the operating status (normal / abnormal) of the second controller 2. In such a configuration, even if an abnormality occurs in the second controller 2, the first controller 1 can issue a BIST request to the second controller 2. As a result, even if an abnormality occurs in the second controller 2, the management device 3 may cause the second controller 2 to execute BIST. In addition, while the management device 3 is causing the second controller 2 to execute BIST, it forcibly sets the level of the second initialization terminal to a normal state (high level in this case) according to the specifications. Therefore, in the event of an abnormality in the second controller 2, the output of the second initialization terminal 64, which should normally be at a low level, may be set to a high level due to the execution of BIST.

[0061] One possible solution to the above problem is for the first controller 1 to confirm with the management device 3 whether the second controller 2 is functioning correctly before sending the second BIST request to the management device 3. In other words, the first controller 1 may be configured to issue the second BIST request only if it receives a response from the management device 3 through communication that the second controller 2 is functioning correctly. Such a measure can reduce to some extent the risk that the management device 3 will cause the second controller 2 to execute BIST when there is a malfunction in the second controller 2.

[0062] However, as shown in Figure 3, there is a hardware-related delay between the time an abnormality occurs in the second controller 2 and the time when the management device 3 recognizes the abnormality in the second controller 2 and the second initialization level becomes low. Possible causes of this delay include the inductance of the signal path between the second controller 2 and the management device 3, and the response characteristics of the internal circuitry of the management device 3. In addition, a delay may occur between the time the management device 3 responds to the first controller 1 that the second controller 2 is functioning normally, and the time when it receives the second BIST request from the first controller 1 and sets the second BIST request flag to ON.

[0063] If an abnormality occurs in the second controller 2 between the time the management device 3 responds to the first controller 1 that the second controller 2 is functioning normally and the second BIST request flag is turned on, and the BIST instruction takes priority, the BIST command will be executed while the second controller 2 is still abnormal, and the second controller 2 will continue to operate in an abnormal state. Similarly, if the second BIST request flag is turned on between the time the abnormality occurs in the second controller 2 and the second initialization terminal 64 is set to a low level, and the BIST instruction takes priority, the second controller 2 will also continue to operate in an abnormal state.

[0064] Figure 4 shows the operation of an electronic control system as a comparative example when a second BIST request is received immediately after an abnormality occurs in the second controller 2. The comparative example here is a configuration in which no measures are taken to fix the second BIST request flag to off when an abnormality in the second controller 2 is detected. In the comparative example, despite an abnormality occurring in the second controller 2, the second controller 2 continues to operate for the sake of BIST. In addition, the output of the second initialization terminal 64, which should switch to a low level, remains at a high level.

[0065] <Measures and Effects> To address the above issues, in this embodiment, the management device 3 forcibly fixes the second BIST request flag to off when an abnormality in the second controller 2 is detected. Therefore, as shown in Figure 5, even if a second BIST request is received immediately after an abnormality occurs in the second controller 2, the request is invalidated and no BIST command is sent to the second controller 2. In other words, the output of the second BIST terminal 65 remains at a low level. In addition, the output of the second initialization terminal 64 is appropriately switched to a low level in response to the abnormality in the second controller 2. Thus, the management device 3 is configured to prohibit or stop the transmission of BIST commands when it detects an abnormality in the second controller 2. The management device 3 may be configured to prohibit or stop the transmission of BIST commands regardless of the reception status of the second BIST request from the first controller 1 when it detects an abnormality in the second controller 2.

[0066] Furthermore, as shown in Figure 6, even if a BIST command is sent to the second controller 2 due to a delay in detecting an anomaly in the second controller 2, the second BIST request flag is forcibly switched off when the anomaly in the second controller 2 is recognized, and the BIST command to the second controller 2 is canceled accordingly. Then, a reset command is sent to the second controller 2. In other words, even if a BIST command is output to the second controller 2 when the second controller is abnormal, the BIST command is quickly canceled, so the output of the second initialization terminal 64 does not get stuck at a high level. The management device 3 is configured to send a reset command to the second controller 2 when it detects an anomaly in the second controller 2, regardless of the reception status of the second BIST request from the first controller 1.

[0067] As described above, with the configuration of this embodiment, the output of the second initialization terminal 64 does not remain fixed at a high level when an abnormality occurs in the second controller 2. When an abnormality occurs in the second controller 2, the second initialization terminal 64 is switched to a low level corresponding to the abnormal state, thereby reducing the risk of the reset of the second controller 2 being canceled.

[0068] In Figures 3 to 6, the "VMON2" column represents the output signal of the voltage anomaly output terminal 22 of the second controller 2, the "BIST2" column represents the output signal of the second BIST terminal 65 of the management device 3, and the "INIT2" column represents the output signal of the second initialization terminal 64. Figures 3 to 6 illustrate the case where a voltage anomaly occurs in the second controller 2, but the type of anomaly may be other types, such as an anomaly in the watchdog function. "VMON2" in Figures 3 to 6 may be replaced with "WDC2" or "ERRMON2", etc.

[0069] As described above, the management device 3 of this embodiment is configured to prioritize the transmission of a reset command in situations where the transmission of a BIST command and the transmission of a reset command to the second controller 2 may conflict. This reduces the risk that the second controller 2 will continue to operate in an abnormal state.

[0070] Furthermore, the first controller 1 is configured to be unable to send BIST requests if a malfunction occurs in the first controller 1. Therefore, in the event of a malfunction in the first controller 1, the management device 3 will not receive a first BIST request immediately after the malfunction occurs in the first controller 1. When a malfunction occurs in the first controller 1, as shown in Figure 7, the first initialization terminal 54 is appropriately set to a low level without conflicting with the BIST request. In other words, when a malfunction occurs in the first controller 1, a reset release by the BIST command does not occur.

[0071] Even if an abnormality occurs in both the first controller 1 and the second controller 2, the first controller 1 is configured to be unable to send the first BIST request, so a reset release due to the BIST instruction does not occur in the first controller 1. Similarly, as mentioned above, the second controller 2 is forced to turn off the second BIST request flag in response to the detection of an abnormality, so a reset release due to the BIST instruction does not occur in the second controller 2 either.

[0072] According to the management device 3 of this embodiment, in any case where an abnormality occurs in the first controller 1, in the second controller 2, or in both controllers, a reset release by the BIST command does not occur. In any case, the management device 3 can quickly reset the controller that has experienced an abnormality.

[0073] The above describes how, in situations where the transmission of a reset instruction and a BIST instruction may conflict, the reset of the second controller 2 can be appropriately (preferentially) executed by controlling a register, specifically the second BIST request flag. However, the method of prioritizing the reset instruction is not limited to this. The management device 3 may be configured in software to output the reset instruction preferentially. Alternatively, the management device 3 may be configured using logic circuits to output the reset instruction preferentially. A configuration that prioritizes the reset instruction over the BIST instruction may be one in which the reset instruction is output without outputting the BIST instruction. Furthermore, a configuration that prioritizes the reset instruction over the BIST instruction may include one in which the output of the BIST instruction is canceled (in other words, released) and the reset instruction is output.

[0074] The case in which the transmission of a reset command to the second controller 2 and the transmission of a BIST command may conflict is when the first controller 1 outputs a second BIST request immediately after an abnormality occurs in the second controller 2. "Immediately after an abnormality occurs" may be within a predetermined time (e.g., several tens of milliseconds) from the occurrence of the abnormality. The predetermined time defined as "immediately after" here has a length corresponding to the aforementioned delay time. The case in which an abnormality occurs in the second controller 2 immediately after the first controller 1 outputs a second BIST request also falls under the category of a case in which the transmission of a reset command to the second controller 2 and the transmission of a BIST command may conflict. "Immediately after the output of the second BIST request" may be understood as within a certain time from the output of the second BIST request. In other words, the case in which the transmission of a reset command to the second controller 2 and the transmission of a BIST command may conflict may be understood as when the receipt of the BIST request and the detection of an abnormality occur almost simultaneously.

[0075] <Supplementary Note> The first controller 1 may be configured to monitor the operating state of the management device 3 and determine whether an abnormality has occurred in the management device 3. The abnormality in the management device 3 may be, for example, the expiration of a watchdog timer or a voltage abnormality. If an abnormality has occurred in the management device 3, as a result of the BIST request transmitted by the first controller 1 being put on hold, there is a possibility that a BIST command will be output at an unexpected timing. When the first controller 1 detects an abnormality in the management device 3, it is configured not to output the first BIST request and the second BIST request to the management device 3. Thereby, the possibility that a BIST command will be output at an unexpected timing can be reduced. Note that the second controller 2 may also be configured to monitor the operating state of the management device 3 and determine whether an abnormality has occurred in the management device 3. When the controller detects an abnormality in the management device 3, it may be configured to reset the management device 3.

[0076] <Regarding the Target of BIST> In the above embodiments, the configuration in which the watchdog function, the voltage monitoring function, and the abnormality detection function are targets of BIST has been described. However, the targets of BIST are not limited to these functions. Other functions or hardware corresponding to the functions may be set as BIST targets. For example, the controller may be configured to check a predetermined memory / logic circuit according to a BIST command.

[0077] <Regarding the Communication Method between the Management Device and the First Controller> The communication method between the management device and the first controller is not limited to SPI. The communication method between the management device and the first controller may be other methods such as I2C (Inter-Integrated Circuit) or UART (Universal Asynchronous Receiver / Transmitter). Furthermore, the communication method between the management device and the first controller is not limited to serial communication, but may be any parallel communication method. The second controller may also be configured to communicate data with the management device 3 using any communication method such as SPI, I2C, or UART. The first controller 1 and the second controller 2 may be connected by one or more signal lines to share a clock, power supply, or other signals.

[0078] <Regarding placement> The first controller 1, the second controller 2, and the management device 3 may be distributed in different locations within the vehicle. Alternatively, the first controller 1, the second controller 2, and the management device 3 may be housed in a common enclosure as a single device. Furthermore, either the first controller 1 or the second controller 2 may be built into the same device as the management device 3, while the second controller 2 is located in a separate location.

[0079] The number of controllers connected to the management device 3 is not limited to two, but may be three or more. Of the three or more controllers, one or more may have the function of sending BIST requests to the management device 3 for the other controllers.

[0080] The first controller 1 corresponds to the first module, the second controller 2 corresponds to the second module, and the management device 3 corresponds to the third module. The first and second modules may be circuit modules, devices, or subsystems. [Explanation of symbols]

[0081] 1. First controller (first module), 2. Second controller (second module), 3. Management device (third module), 100. Electronic control system (diagnostic system)

Claims

1. A first module (1) including a circuit, A second module (2) configured to run BIST (Built In Self-Test), The system includes a third module (3) which is communicatively connected to each of the first and second modules and monitors the status of the first and second modules, The first module is configured to transmit a BIST request, which is a signal requesting the second module to execute BIST, to the third module. The aforementioned third module is, A function that, upon detecting an abnormality in the second module, transmits a reset command to reset the second module, The system includes a function that, upon receiving the BIST request from the first module, transmits a BIST command, which is a signal instructing the execution of BIST, to the second module, Furthermore, the third module is configured to prioritize the transmission of the reset command when there is a conflict between the transmission of the reset command to the second module and the transmission of the BIST command in the diagnostic system.

2. The diagnostic system according to claim 1, wherein the third module is configured to prohibit the transmission of the BIST command when it detects an abnormality in the second module.

3. The diagnostic system according to claim 1, wherein the third module is configured to transmit the reset command to the second module if it detects an abnormality in the second module, regardless of the status of receiving BIST execution requests to the second module.

4. The diagnostic system according to claim 1, wherein the first module is configured to monitor the operating status of the third module and, if it detects an abnormality in the third module, not output the BIST request to the third module.

5. The diagnostic system according to any one of claims 1 to 3, wherein the first module is configured such that the operating state of the second module cannot be directly obtained from the second module.

6. The diagnostic system according to any one of claims 1 to 3, wherein the first module is configured to be unable to communicate with the second module.

7. The aforementioned third module is, The status of receiving execution requests for BIST to the second module is managed by the BIST request flag. Upon receiving the aforementioned execution request, the BIST request flag is set from off to on. The value of the BIST request flag is referenced at a predetermined timing, The diagnostic system according to claim 1, configured to transmit the BIST instruction to the second module in response to the BIST request flag being set to ON.

8. The diagnostic system according to claim 7, wherein the third module is configured to fix the BIST request flag to the off position until a predetermined prohibition release condition is met, in the event that an abnormality is detected in the second module.