Electronic control unit
The electronic control device addresses the challenge of setting appropriate error handling times by using a variable timer and error processing units, ensuring high availability and safety with a simple configuration.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- DENSO CORP
- Filing Date
- 2025-01-17
- Publication Date
- 2026-07-30
AI Technical Summary
Existing electronic control devices face challenges in setting appropriate predetermined times for error handling due to the execution of multiple controls with multiple CPUs, leading to compromised availability and safety, and adding separate timers for each error increases complexity and cost.
An electronic control device with a variable timer device and error processing units that set error handling times based on the type of error and control requirements, implementing safety measures if handling is not completed within the timer period.
Enables appropriate error handling with high availability and safety using a simple configuration, allowing for timely transition to safe states and reducing complexity and cost.
Smart Images

Figure 2026123629000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the technology of the safety mechanism of an electronic control device.
Background Art
[0002] When an error occurs in the microcomputer in an electronic control device, it is common to perform error handling according to the control. For example, a technique is disclosed in which the passage of time from the execution of error handling is measured, and a new process is executed after a predetermined time has elapsed (see, for example, Patent Document 1).
[0003] In the example of Patent Document 1, in order to stop the error detection interrupt that is repeated due to the occurrence of a memory protection violation, the memory protection violation detection is disabled. At the same time, before the memory protection device that prevents improper writing to the memory fails and causes an unexpected situation, after a predetermined time has elapsed since the memory protection violation detection was disabled, the output of the control signal is cut off.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, as a result of the inventors' detailed examination, the following problems were found in the conventional technology. In the electronic control device of Patent Document 1, the passage of time from the execution of error handling is measured, and the control output is cut off after a predetermined time has elapsed, but only a single time can be set regardless of the control target. Therefore, for example, in an integrated electronic control device that executes a plurality of controls with a plurality of CPUs in recent years, there is a problem that an appropriate predetermined time cannot be set for each control.
[0006] For example, if an error occurs in the CPU of a microcontroller and an attempt is made to recover by restarting only that CPU, the recovery process will take a certain amount of time, so it is necessary to wait for a predetermined period of time. However, depending on the symptoms of the CPU error, recovery may not be possible. In that case, it is necessary to transition to a safe state from the moment the error occurs, before any unforeseen problems arise.
[0007] For example, if there is a mix of control systems where the time between an error occurring and an unforeseen event occurs is 50ms and 100ms, the predetermined waiting time will be set to the shorter time, which is 50ms. In this case, even if there is a 100ms grace period before an unforeseen event occurs, the system will have to abandon recovery and switch to degraded operation after 50ms, thus compromising availability (i.e., the convenience of using the device or system).
[0008] While it might be possible to have a separate timer device for each error, this would introduce another problem: a significant increase in configuration complexity and cost. One aspect of this disclosure is to provide a technology for electronic control devices that can appropriately achieve both the necessary availability and safety with a simple configuration. [Means for solving the problem]
[0009] One aspect of the present disclosure relates to an electronic control device (1) configured to perform error processing as a countermeasure corresponding to a predetermined error when such error is detected. The electronic control unit comprises an error processing unit (33), a timer setting unit (31), and a safety measures execution unit (35).
[0010] The error processing unit is configured to perform the error processing according to the type of error detected. The timer setting unit is configured to use a timer device (21) with a variable timer time and to set the error processing waiting time for the completion of the error processing as the timer time.
[0011] The safety measures execution unit is configured to perform predetermined safety measures corresponding to the error if the error processing has not been completed when the timer time has elapsed. This disclosure provides a technology that, through the above-described configuration, can appropriately achieve both the necessary availability and safety in an electronic control device with a simple configuration.
[0012] In this disclosure, when a predetermined error is detected in an object (e.g., a device or system) that is prone to errors, predetermined error processing can be performed, depending on the type of error, to resolve the error or improve the situation affected by the error (e.g., control).
[0013] Furthermore, since the time required for error processing (i.e., error processing time) may differ depending on the type of error and control, an error processing waiting time is set to wait for the completion of error processing according to the type of error and control. In this disclosure, the error processing waiting time can be set as the timer time using a timer device that can set the timer time variably.
[0014] This allows for the setting of appropriate error handling waiting times according to the type of error and control requirements, even with a simple configuration such as a single timer device. Therefore, since error handling can be performed appropriately according to the error that occurs, high availability can be achieved.
[0015] Furthermore, this disclosure states that if the timer has elapsed and error handling is not complete, predetermined safety measures corresponding to the error will be taken. For example, predetermined backup processing will be performed if the error cannot be resolved.
[0016] This ensures superior safety because, if error handling is not completed within the timer period (i.e., if the countermeasures to resolve the malfunction caused by error handling have not been completed), appropriate safety measures corresponding to the error can be implemented. In other words, even if a pre-set error handling waiting period is observed, there is a possibility that error handling may not actually be performed, but this disclosure offers the advantage of improved safety by implementing the aforementioned safety measures.
[0017] In this way, this disclosure has the remarkable effect of enabling both the necessary availability and security to be adequately achieved with a simple configuration. Here, "error" refers to an abnormality or malfunction in an object such as a microcontroller or other device or system. "Error handling" refers to the process of resolving the error itself, or the measures taken to resolve unforeseen situations such as control disruptions caused by the error. "Timer time" is the time set by a timer device (for example, the time set to determine the start or end of a predetermined operation). "Safety measures" are measures taken to improve safety if error handling is not completed when the timer time has elapsed.
[0018] Furthermore, the reference numerals in parentheses in this section and in the claims indicate a correspondence with the specific means described later in the embodiments, and do not limit the technical scope of this disclosure. [Brief explanation of the drawing]
[0019] [Figure 1] This is a block diagram showing the configuration of the electronic control device, etc., of the first embodiment. [Figure 2] This is a sequence diagram showing the control sequence implemented by the electronic control device of the first embodiment. [Figure 3] Figure 3A is a flowchart showing the error analysis process implemented in the first embodiment, and Figure 3B is a flowchart showing the time-over interrupt process implemented in the first embodiment. [Figure 4] This is a block diagram showing the configuration of the electronic control device, etc., of the second embodiment. [Figure 5] It is a sequence diagram showing a control sequence implemented by the electronic control device of the second embodiment. [Figure 6] FIG. 6A is a flowchart showing error analysis processing implemented in the second embodiment, FIG. 6B is a flowchart showing error processing implemented in the second embodiment, and FIG. 6C is a flowchart showing timeout interrupt processing implemented in the second embodiment. [Figure 7] It is a block diagram showing the configuration of an electronic control device and the like of the third embodiment. [Figure 8] It is a sequence diagram showing a control sequence implemented by the electronic control device of the third embodiment. [Figure 9] FIG. 9A is a flowchart showing error analysis processing implemented in the third embodiment, FIG. 9B is a flowchart showing timeout interrupt processing implemented in the third embodiment, and FIG. 9C is a flowchart showing watchdog output processing implemented in the third embodiment. [Figure 10] It is a block diagram showing the configuration of an electronic control device and the like of the fourth embodiment. [Figure 11] It is a sequence diagram showing a control sequence implemented by the electronic control device of the fourth embodiment. [Figure 12] FIG. 12A is a flowchart showing error analysis processing implemented in the fourth embodiment, FIG. 12B is a flowchart showing error processing implemented in the fourth embodiment, FIG. 12C is a flowchart showing timeout interrupt processing implemented in the fourth embodiment, and FIG. 12D is a flowchart showing watchdog output processing implemented in the fourth embodiment. [Figure 13] It is a block diagram showing the configuration of an electronic control device and the like of the fifth embodiment. [Figure 14] It is a sequence diagram showing a control sequence implemented by the electronic control device of the fifth embodiment. [Figure 15] FIG. 15A is a flowchart showing error analysis processing implemented in the fifth embodiment, FIG. 15B is a flowchart showing timeout interrupt processing implemented in the fifth embodiment, and FIG. 15C is a flowchart showing communication control processing implemented in the fifth embodiment. [Figure 16] This is a block diagram showing the configuration of the electronic control device, etc., according to the sixth embodiment. [Figure 17] This is a sequence diagram showing the control sequence implemented by the electronic control device of the sixth embodiment. [Figure 18] Figure 18A is a flowchart showing the error analysis process implemented in the sixth embodiment, Figure 18B is a flowchart showing the error processing implemented in the sixth embodiment, Figure 18C is a flowchart showing the time-excess interrupt processing implemented in the sixth embodiment, and Figure 18D is a flowchart showing the communication control process implemented in the sixth embodiment. [Figure 19] This is a block diagram showing the configuration of the electronic control device, etc., according to the seventh embodiment. [Figure 20] This is a sequence diagram showing the control sequence implemented by the electronic control device of the seventh embodiment. [Figure 21] Figure 21A is a flowchart showing the error analysis process implemented in the seventh embodiment, and Figure 21B is a flowchart showing the time-over interrupt process implemented in the seventh embodiment. [Figure 22] This is a block diagram showing the configuration of the electronic control device, etc., of the eighth embodiment. [Figure 23] This is a sequence diagram showing the control sequence implemented by the electronic control device of the eighth embodiment. [Figure 24] Figure 24A is a flowchart showing the error analysis process implemented in the eighth embodiment, Figure 24B is a flowchart showing the error processing implemented in the eighth embodiment, and Figure 24C is a flowchart showing the time-over interrupt processing implemented in the eighth embodiment. [Modes for carrying out the invention]
[0020] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the drawings. [1. First Embodiment] In this first embodiment, an electronic control device used in a vehicle control system such as an automobile will be used as an example. This electronic control device is, for example, a device that controls the operation of a controlled object using a single CPU, and here, the case in which the control output to the controlled object is turned off will be used as an example.
[0021] [1-1. Overall Structure] As shown in Figure 1, the electronic control unit (i.e., ECU) 1 of this first embodiment comprises a well-known microcomputer (hereinafter referred to as "microcontroller") 3 and a control output device 5.
[0022] The microcontroller 3 includes a well-known CPU 7 as its main component, and peripheral components of the CPU 7 include an error detection device 11, an error register 13, an error processing device 15, a ROM 17, a RAM 19, a timer device 21, and a control output cutoff port 23.
[0023] In Figure 1, the components within the dashed-dotted frame represent the main parts of this first embodiment. [1-2. Composition of each part] The following describes each component.
[0024] [1-2-1. CPU peripheral configuration] First, let's explain the surrounding configuration of CPU7. The error detection device 11 is a known device that detects failures (i.e., errors) in the CPU 7 and memory (for example, ROM 17 and RAM 19) mounted on the microcontroller 3.
[0025] The error detection device 11 receives various signals (i.e., error signals) from various components (e.g., devices and systems) such as the CPU 7, according to the type of error that occurred in each component. When an error signal is input to the error detection device 11, it outputs an error occurrence notification to the error processing device 15 to inform it that an error has occurred.
[0026] The error register 13 is a memory device that stores various information (i.e., error information) related to errors detected by the error detection device 11. The error information is written to the error register 13 by the error detection device 11. As is well known, the error information includes an error code indicating the type of error, an error flag, status information, a counter value, and so on.
[0027] The error processing unit 15 is a device that executes the configured response for each error, as will be described later. Examples of these responses include, for example, "do nothing" or, as will be described later, "issue an error interrupt to CPU 7".
[0028] When the error processing unit 15 receives an error notification from the error detection unit 11, it outputs a control signal to the CPU 7 (specifically, the error analysis processing unit 31) to perform an error interrupt as a reaction.
[0029] ROM17 is a well-known memory that stores data and other information. For example, ROM17 stores programs for executing various processes and various tables that are referenced when executing these programs.
[0030] Specifically, ROM17 stores a table (i.e., an error handling table) that associates various types of errors (for example, error codes indicating the type of error) with the error handling procedures set to correspond to each error code.
[0031] In the error handling table, when there are multiple types of errors, each error and its corresponding error handling action are set up in correspondence. Therefore, the error handling table can be used to determine the appropriate error handling action for the error detected.
[0032] Furthermore, ROM17 stores a table (i.e., a timer time table) that associates various types of errors (e.g., error codes) or error handling procedures (e.g., the procedures performed by the controlled object) with the error handling waiting time (i.e., timer time) set in accordance with each error code or error handling procedure. The error handling wait time is the time spent waiting for the error handling process to complete when error handling is required. Here, the error handling wait time is set as the timer time.
[0033] For example, a timer timetable can be used in which a specific error processing wait time is set for each error. Furthermore, if various types of control are possible for a given error, a timer timetable can be used in which the error processing wait time is set according to the control content. For instance, in the event of a CPU failure, different error processing wait times can be set depending on the control content; for example, 100ms when engine control is being performed and 50ms when steering control is being performed.
[0034] Thus, in the timer time table, when there are multiple types of errors and multiple control actions corresponding to each error, each error and its corresponding error processing wait time are set accordingly. Therefore, the timer time table can be used to determine the error processing wait time (i.e., the timer time) corresponding to the error detected.
[0035] Furthermore, if the ECU1 controls the vehicle's engine, the timer can be set to, for example, 100ms before the vehicle reaches excessive acceleration. Similarly, if the ECU1 controls the steering, the timer can be set to, for example, 50ms before steering becomes difficult. In other words, depending on the type of error, it's possible to determine how long it takes for the controlled system to enter an undesirable state. Therefore, the timer can be set to an appropriate time, depending on the type of error, to prevent the controlled system from reaching an undesirable state.
[0036] RAM19 is a known memory for temporarily storing data. In this first embodiment, the RAM19 stores an error handling start flag (i.e., an error handling start Flag whose value is set according to the start or completion of error handling), which will be described later. Note that in the drawings, the flag may be written as Flag.
[0037] Timer device 21 is a timer with a variable timer duration. In other words, timer device 21 is a device that allows the timer duration to be set to any desired time, such as 50ms or 100ms, in accordance with the error processing waiting time set according to the type of error and the content of the control. However, as will be described later, in reality, error processing may not be completed within the error processing waiting time due to various reasons.
[0038] An example of the timer device 21 is a Compare Match timer. The Compare Match timer is a timer device that generates an interrupt when a counter that continues to count cyclically matches the value of the Compare Match interrupt time setting register. In other words, it is a timer device in which it is possible to set whether or not to generate an interrupt by setting a register.
[0039] The control output cutoff port 23 is a port that outputs a signal to cut off the control output of the control output device 5. Here, the control output device 5 is a device that outputs a control signal to a controlled object, such as an electronic throttle valve 25 of an onboard engine, to control its operation. For example, the control output device 5 is an IC that supplies driving power to the electronic throttle valve 25.
[0040] Normally, the control quantity calculated by the CPU 7 is output to the control output device 5. However, if a signal indicating that the control output is off is output from the control output cutoff port 23, the control output of the control output device 5 is turned off (i.e., cut off). Therefore, for example, in the case of the electronic throttle valve 25, since no power is supplied, the electronic throttle valve 25 closes.
[0041] [1-2-2. CPU Configuration] The CPU 7 is a well-known arithmetic processing unit that performs various calculations. Functionally, this CPU 7 includes an error analysis processing unit 31, an error processing unit 33, a backup error processing unit 35, and a control variable calculation unit 37.
[0042] The error analysis processing unit 31 starts the error analysis process when it receives a signal from the error processing unit 15 indicating the start of the error analysis process. Specifically, first, the error information stored in the error register 13 is referenced to confirm the type of error (for example, ROM failure or RAM failure), and the timer time corresponding to the type of error and the control content is obtained from the timer time table stored in the ROM 17. In other words, an appropriate timer time is obtained as the time to perform error processing (i.e., the error processing waiting time). Then, that timer time is set in the timer device 21. That is, a signal is output to the timer device 21 to set the timer time and enable the timer interrupt.
[0043] Furthermore, the error analysis processing unit 31 outputs a signal to the error processing unit 33 to initiate error processing. The error processing method is selected according to the type of error based on the error processing table stored in the ROM 17. When error processing is started, a signal is output to the RAM 19 to set an error processing start flag indicating the start of error processing.
[0044] The error processing unit 33 performs the error processing configured according to the type of error described above in order to resolve the error and the resulting malfunction. It also outputs a signal to RAM 19 to clear the error processing start flag to indicate that the error processing has been completed.
[0045] The backup error processing unit 35 performs backup error processing as a safety measure if error processing is not completed even after the timer has elapsed. Specifically, as error handling depending on the type of error, safety measures such as turning off the control output can be implemented. For example, as error handling for errors in engine control or steering control, safety measures such as turning off the control output to the electronic throttle valve 25 or the motor that drives the steering can be implemented.
[0046] Furthermore, the backup error processing unit 35 receives a signal from the RAM 19 indicating the error processing start flag, which serves as a signal to indicate the status of error processing. Specifically, when error processing has started, the error processing start flag is ON, and when error processing is completed, the error processing start flag is OFF. In addition, the timer device 21 outputs a signal indicating the activation of backup error processing.
[0047] The control variable calculation unit 37 performs processing to calculate various control variables for controlling the controlled object controlled by the microcontroller 3. For example, it performs processing to calculate the control variable to be output to the control output device 5.
[0048] Furthermore, the various functions of the ECU1 described above are realized, for example, by the CPU7 executing a program stored in a non-transitional physical recording medium. In this example, for example, ROM17 corresponds to the non-transitional physical recording medium that stores the program. When this program is executed, the method corresponding to the program is executed.
[0049] Furthermore, the number of microcontrollers constituting ECU1 may be one or more. Also, the method for realizing the various functions of ECU1 is not limited to software; some or all of its elements may be realized using one or more hardware components. For example, if the above functions are realized by an electronic circuit which is hardware, that electronic circuit may be a digital circuit containing many logic circuits, an analog circuit, or a combination thereof.
[0050] [1-3. Control Sequence] Next, the control sequence implemented in this first embodiment will be explained based on the sequence diagram in Figure 2. Note that this shows the sequence when an error occurs, assuming there is only one CPU 7. The numbers assigned to the descriptions of each process in Figure 2 indicate the main order of each process (the same applies to each sequence diagram hereafter). As shown in Figure 2, if a malfunction (i.e., an error) occurs in the microcontroller 3, the error detection device 11 detects the occurrence of the error. When an error is detected, the type of error is stored in the error register 13.
[0051] Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1). Next, the error processing unit 15 instructs the CPU 7 to start analyzing the error (step K2). That is, it issues an error interrupt to the CPU 7.
[0052] Next, the CPU 7 refers to the timer time table in ROM 17 and obtains a timer time (i.e., error handling waiting time) corresponding to the type of error and the content of the control (step K3). Furthermore, the CPU 7 sets the timer time for the timer device 21 and enables the timer interrupt (step K4). In other words, when the timer time is reached, the backup error processing is activated by the timer interrupt.
[0053] Furthermore, the CPU 7 sends a signal to the RAM 19 to indicate that error handling is to be activated, causing it to perform the process of turning on the error handling start flag (i.e., ON) (steps K5, K6).
[0054] Simultaneously, CPU7 initiates error handling (for example, initialization) (step K7). This process executes the error handling. As mentioned above, the error handling method is selected according to the type of error.
[0055] Furthermore, once error handling is complete, the CPU 7 sends a signal to the RAM 19 to perform the process of turning off the error handling start flag (i.e., OFF) (steps K8, K9).
[0056] Subsequently, when the timer device 21 determines that the timer time has elapsed, it generates a timer interrupt to initiate backup error processing on the CPU 7 (step K10). Next, CPU7 checks the status of the error handling start flag in RAM19 (step K11). In other words, it determines whether the error handling start flag is on (i.e., error handling is not yet complete) or off (i.e., error handling is complete).
[0057] Furthermore, at this time, the timer interrupt of the timer device 21 is disabled. In other words, the timer interrupt by the timer device 21 is not activated when the backup error processing is completed.
[0058] If the error handling start flag is set to ON, it means that error handling is not yet complete, so as a safety measure, backup error handling is performed. Specifically, a signal is sent from the CPU 7 to the control output cutoff port 23 to turn off the control output from the control output device 5 (steps K12, K13).
[0059] Subsequently, the error detection device 11 clears the error information in the error register 13 based on a signal from the CPU 7 (step K14). [1-4. Control Processing] Next, the control processing performed by the CPU 7 in this first embodiment will be described.
[0060] <Error Analysis Processing> First, the error analysis process will be explained based on the flowchart in Figure 3A. The error analysis process is read from the error interrupt generated by the error processing unit 15 when an error is detected. The error analysis process is a series of processes that are performed when error processing is initiated, for example, when an error such as a memory error is detected.
[0061] In step 100 (hereinafter referred to as S) in Figure 3A, error handling is initiated, so first, the timer time (i.e., the error handling waiting time) is obtained from the timer time table in ROM 17. In the following step S110, the timer time is set in the timer device 21.
[0062] In the following step, S120, the timer interrupt is enabled. In the following step, S130, the error handling start flag is turned on. In the subsequent S140, error handling is performed according to the type of error. For example, in the case of a memory error, error handling such as memory initialization is performed.
[0063] In the subsequent S150, if error handling is complete, the error handling start flag is turned off, and this process is terminated. <Time Overload Interrupt Handling> Next, we will explain the time-over interrupt handling based on the flowchart in Figure 3B.
[0064] The time over interrupt handler is called by an interrupt that occurs when the time reaches the "current time + error handling waiting time" set in the timer device 21. In other words, the time over interrupt handler is a series of processes that are performed when the timer time has elapsed (for example, when the set timer time is reached).
[0065] In S200 of Figure 3B, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off (i.e., error handling is complete) or on (i.e., error handling is not complete). If the error handling start flag is off, error handling is complete, so the process proceeds to S220. On the other hand, if the error handling start flag is on, error handling is not complete, so the process proceeds to S210.
[0066] In S210, since error handling is not complete, backup error handling is performed as a safety measure. Specifically, the control output to the electronic throttle valve 25 is turned off. In S220, timer interrupts are disabled.
[0067] In the subsequent S230, the error information is cleared, and the process is temporarily terminated. [1-5. Effects, etc.] According to this first embodiment, the following effects can be obtained.
[0068] (1a) In this first embodiment, if an error occurs in the microcontroller 3 or the like, predetermined error processing can be performed to resolve the error or any problems caused by the error, depending on the type of error.
[0069] Furthermore, since the error processing time differs depending on the type of error and the content of the control, the error processing waiting time can be set according to the type of error and the content of the control. In this first embodiment, the error processing waiting time can be set as the timer time using a timer device 21 that can set the timer time variably.
[0070] This allows for the setting of appropriate error handling waiting times according to the type of error and the content of the control, even with a simple configuration such as a single timer device 21. Therefore, since error handling can be performed appropriately according to the type of error and the content of the control, high availability can be achieved.
[0071] Furthermore, if the timer has elapsed and error processing is not yet complete, predetermined safety measures corresponding to the error can be taken. For example, a backup error process can be implemented that turns off the control output to the electronic throttle valve 25.
[0072] This ensures superior safety because, if error handling is not completed within the timer period, appropriate safety measures can be implemented to address the error. In this way, the first embodiment achieves the remarkable effect of appropriately realizing both the necessary availability and security.
[0073] (1b) In this first embodiment, a timer time table can be used that associates the type of error and the content of the control with a timer time corresponding to the error processing wait time. By using this timer time table, an appropriate timer time (i.e., error processing wait time) can be set according to the type of error and the content of the control.
[0074] (1c) In this first embodiment, the CPU 7 can determine what processing to perform next using an error processing start flag, which is set according to the status of error processing. For example, if the error processing start flag is on after the timer has elapsed, it can be assumed that error processing is not complete and backup error processing can be performed as a safety measure. On the other hand, if the error processing start flag is off, it can be assumed that error processing is complete and backup error processing can be omitted.
[0075] [1-6. Correspondence] Next, the relationship between this disclosure and this first embodiment will be described. The electronic control unit corresponds to electronic control unit 1, the timer unit corresponds to timer unit 21, the error processing unit corresponds to error processing unit 33, the timer time setting unit corresponds to error analysis processing unit 31, and the safety measures execution unit corresponds to backup error processing unit 35.
[0076] [2. Second Embodiment] Since the basic configuration of the second embodiment is the same as that of the first embodiment, the following description will mainly focus on the differences from the first embodiment. Note that the same reference numerals as in the first embodiment indicate components with similar functions, and refer to the preceding description.
[0077] In this second embodiment, we will describe a case in which control outputs to the controlled object are turned off using multiple CPUs (for example, two). In this second embodiment, as shown in Figure 4, the microcontroller 3 of the ECU1 is equipped with two CPUs, a first CPU 7A and a second CPU 7B. Furthermore, if the second CPU 7B fails, the non-faulting first CPU 7A can perform error analysis processing and backup error processing.
[0078] [2-1. Overall Structure] First, the configuration of this second embodiment will be described. As shown in Figure 4, in this second embodiment, similar to the first embodiment, the ECU1 that controls the electronic throttle valve 25, which is the object to be controlled, comprises a microcontroller 3 and a control output device 5.
[0079] The microcontroller 3 includes a first CPU 7A and a second CPU 7B as its CPUs. In addition to the CPUs, it also includes an error detection device 11, an error register 13, an error processing device 15, a ROM 17, a RAM 19, a timer device 21, and a control output cutoff port 23, similar to the first embodiment. The RAM 19 is a shared memory that stores data used by the first CPU 7A and the second CPU 7B.
[0080] The first CPU 7A includes an error analysis processing unit 31 and a backup error processing unit 35, with a configuration similar to that of the first embodiment. When the error analysis processing is initiated by a signal from the error processing device 15, the error analysis processing unit 31 obtains the timer time from the ROM 17, sets the timer time for the timer device 21, and enables the timer interrupt.
[0081] Furthermore, a signal is output to the error processing unit 33 of the second CPU 7B to initiate error processing. In other words, the first CPU 7A sends a core interrupt request to the second CPU 2B (i.e., initiates a core interrupt on the second CPU 7B) to start error processing. In addition, as in the first embodiment, the error processing start flag in RAM 19 is set.
[0082] The backup error processing unit 35, similar to the first embodiment, performs backup error processing according to the error processing start flag and outputs a control signal (i.e., a signal to turn off the control output) to the control output cutoff port 23.
[0083] The second CPU 7B has a configuration similar to that of the first embodiment, and includes an error processing unit 33 and a control variable calculation unit 37. The error processing unit 33 performs error processing, similar to the first embodiment, and clears the error processing start flag in RAM 19 when the error processing is completed.
[0084] The control variable calculation unit 37 transmits a control signal corresponding to the calculated control variable to the control output device 5, similar to the first embodiment. [2-2. Control Sequence] Next, the control sequence of this second embodiment will be described. Here, we will explain what happens when an error occurs in the second CPU 7B.
[0085] As shown in Figure 5, if a failure (i.e., an error) occurs in the second CPU 7B, the error detection device 11 detects the occurrence of the error. Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1).
[0086] Next, the error processing unit 15 instructs the first CPU 7A to start error analysis (step K2). That is, it generates an error interrupt for the first CPU 7A. Next, the first CPU 7A refers to the timer time table in ROM 17 and obtains a timer time (i.e., error processing waiting time) corresponding to the type of error and the content of the control (step K3).
[0087] Furthermore, the first CPU 7A sets the timer time for the timer device 21 and enables the timer interrupt (step K4). Furthermore, the first CPU 7A sends a signal to the RAM 19 to initiate the process of turning on the error handling start flag (steps K5, K6).
[0088] Furthermore, the first CPU 7A sends a signal to the second CPU 7B to initiate error handling (for example, initialization) (step K7). The second CPU 7B starts (i.e., performs) error processing in response to a signal from the first CPU 7A (step K8).
[0089] Furthermore, once error handling is complete, the second CPU 7B sends a signal to RAM 19 to perform the process of turning off the error handling start flag (steps K9, K10). Subsequently, when the timer device 21 determines that the timer time has elapsed, it generates a timer interrupt in the first CPU 7A to initiate backup error processing (step K11).
[0090] Next, the first CPU 7A checks the status of the error handling start flag in RAM 19 (step K12). At this time, the timer interrupt of the timer device 21 is disabled. If the error handling start flag is on, it means that error handling is not yet complete. As a safety measure, the first CPU 7A sends a signal to the control output cutoff port 23 to turn off the control output to the control output device 5 (steps K13, K14).
[0091] Subsequently, the error detection device 11 clears the error information in the error register 13 based on a signal from the first CPU 7A (step K15). [2-3. Control Processing] Next, the control process implemented in this second embodiment will be described.
[0092] <Error Analysis Processing> First, we will explain the error analysis process performed by the first CPU 7A, based on the flowchart in Figure 6A.
[0093] In S300 of Figure 6A, the timer time is obtained from the timer time table in ROM 17, similar to the first embodiment. In the following step S310, the timer time is set in the timer device 21, similar to the first embodiment.
[0094] In the following S320, the timer interrupt is enabled, similar to the first embodiment. In the following S330, the error handling start flag is turned on, similar to the first embodiment. In the subsequent S340, an inter-core interrupt triggers an error handling call to the second CPU 7B, and the main process is temporarily terminated.
[0095] <Error handling> Next, we will explain the error handling performed by the second CPU 7B based on the flowchart in Figure 6B.
[0096] In S400 of Figure 6B, error handling is performed in the same manner as in the first embodiment. In the subsequent S410, if error handling is complete, the error handling start flag is turned off, and this process is terminated.
[0097] <Time Overload Interrupt Handling> Next, we will explain the time-excess interrupt handling performed by the first CPU 7A, based on the flowchart in Figure 6C.
[0098] In S500 of Figure 6C, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the error handling is complete and the process proceeds to S520. On the other hand, if the error handling start flag is on, the error handling is not complete and the process proceeds to S510.
[0099] In S510, since error handling is not complete, as a safety measure, the control output to the electronic throttle valve 25 is turned off, for example. In S520, timer interrupts are disabled.
[0100] In the subsequent S530, error information is cleared, and the process is temporarily terminated. [2-4. Effects, etc.] This second embodiment provides the same effects as the first embodiment.
[0101] In this second embodiment, even if an error occurs in one of the two CPUs, the other CPU can reliably implement safety measures. [3. Third Embodiment] Since the basic configuration of the third embodiment is the same as that of the first embodiment, the following description will mainly focus on the differences from the first embodiment. Note that the same reference numerals as in the first embodiment indicate components with similar functions, and refer to the preceding description.
[0102] This third embodiment describes a case where a single CPU is used and the microcontroller is reset using a watchdock. In this third embodiment, as a backup error handling process, a microcontroller reset is performed instead of the control output off process.
[0103] [3-1. Overall Structure] First, the configuration of this third embodiment will be described. As shown in Figure 7, in this third embodiment, the ECU1 comprises a microcontroller 3 and a microcontroller monitoring device 43.
[0104] The microcontroller 3 includes a CPU 7. In addition to the CPU 7, it also includes an error detection device 11, an error register 13, an error processing device 15, a ROM 17, a RAM 19, and a timer device 21, similar to the first embodiment, and further includes a microcontroller reset control device 41.
[0105] The CPU 7 has a configuration similar to that of the first embodiment, comprising an error analysis processing unit 31, an error processing unit 33, a backup error processing unit 35, and a control variable calculation unit 37. Furthermore, it includes a watchdog output processing unit 39.
[0106] In this third embodiment, with the configuration described above, under normal circumstances (i.e., when no errors occur), the watchdog output processing unit 39 periodically transmits a watchdog signal to the microcontroller monitoring device 43 located outside the microcontroller 3.
[0107] However, if the conditions for starting backup error processing are met in the backup error processing unit 35, that is, if error processing is not completed even after the timer has elapsed since the error processing started, the watchdog stop flag in the watchdog output processing unit 39 is turned on, and the output of the watchdog signal to the microcontroller monitoring device 43 is stopped.
[0108] In other words, if the error processing start flag remains on, the backup error processing unit 35 considers that error processing has not been completed within the specified time and turns on the watchdog stop flag.
[0109] The watchdog output processing unit 39 checks if the watchdog stop flag is off when outputting a watchdog signal, and does not output a watchdog signal if it is not off (i.e., it outputs a watchdog signal if it is off).
[0110] The microcontroller monitoring device 43 resets the microcontroller 3 using the microcontroller reset control device 41 if no watchdog signal is input for a certain period of time. The watchdog stop flag is initialized to off during the initialization process associated with the microcontroller reset.
[0111] [3-2. Control Sequence] Next, the control sequence of this third embodiment will be described. As shown in Figure 8, if a malfunction (i.e., an error) occurs in the microcontroller 3, the error detection device 11 detects the occurrence of the error.
[0112] Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1). Next, the error processing unit 15 instructs the CPU 7 to start analyzing the error (step K2). That is, it issues an error interrupt to the CPU 7.
[0113] Next, the CPU 7 refers to the timer time table in ROM 17 and obtains a timer time (i.e., error handling waiting time) corresponding to the type of error and the content of the control (step K3). Furthermore, the CPU 7 sets the timer time for the timer device 21 and enables timer interrupts (step K4).
[0114] Furthermore, the CPU 7 sends a signal to the RAM 19 to initiate the process of turning on the error handling start flag (steps K5, K6). At the same time, CPU7 initiates error handling (for example, initialization) (step K7).
[0115] Furthermore, once error handling is complete, CPU 7 sends a signal to RAM 19 to perform the process of turning off the error handling start flag (steps K8, K9). Subsequently, when the timer device 21 determines that the timer time has elapsed, it generates a timer interrupt to initiate backup error processing on the CPU 7 (step K10).
[0116] Next, the CPU 7 checks the status of the error handling start flag in RAM 19 (step K11). At this time, the timer interrupt of the timer device 21 is disabled. If the error handling start flag is set to ON, it means that error handling is not yet complete, so as a safety measure, backup error handling is performed.
[0117] Specifically, a signal from the backup error processing unit 35 causes the watchdog stop flag in the watchdog output processing unit 39 to be turned on (step K12). This stops the output of the watchdog signal from the watchdog output processing unit 39 to the microcontroller monitoring device 43 (step K13). Therefore, if the microcontroller monitoring device 43 does not receive a watchdog signal for a predetermined period of time, it considers that the condition for resetting the microcontroller 3 has been met and outputs a signal to the microcontroller reset control device 41 to reset the microcontroller 3 (steps K14, K15). When the microcontroller reset control device 41 receives the reset signal, it performs the well-known process of resetting the microcontroller 3 (step 16).
[0118] Subsequently, the error detection device 11 clears the error information in the error register 13 based on a signal from the CPU 7 (step K17). [3-3. Control Processing] Next, the control processing performed by the CPU 7 in this third embodiment will be described.
[0119] <Error Analysis Processing> First, the error analysis process will be explained based on the flowchart in Figure 9A. This error analysis process is the same as in the first embodiment, so it will be explained briefly.
[0120] In S600 of Figure 9A, the timer time is obtained from the timer time table in ROM17. In the following step S610, the timer time is set in the timer device 21. In the following step, S620, timer interrupts are enabled.
[0121] In the following step, S630, the error handling start flag is turned on. In the subsequent S640, error handling is performed according to the type of error. In the subsequent S650, if error handling is complete, the error handling start flag is turned off, and the process is terminated.
[0122] <Time Overload Interrupt Handling> Next, the time-over interrupt handling will be explained based on the flowchart in Figure 9B. Note that the same aspects as in the first embodiment will be briefly explained.
[0123] In S700 of Figure 9B, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the process proceeds to S720; on the other hand, if the error handling start flag is on, the process proceeds to S710.
[0124] In S710, since error handling is not complete, the watchdog stop flag is turned on as a safety measure to prevent the watchdog signal from being output. This resets microcontroller 3.
[0125] In the S720, timer interrupts are disabled. In the subsequent S730, the error information is cleared, and the process is temporarily terminated. <Watchdog output processing> Next, the watchdog output process will be explained based on the flowchart in Figure 9C.
[0126] The watchdog output process is called periodically (for example, every 10ms) by the OS scheduler, regardless of whether an error has occurred. In S800 of Figure 9C, it is determined whether the watchdog stop flag is off or not. If the watchdog stop flag is determined to be off, the process proceeds to S810. On the other hand, if the watchdog stop flag is determined to be on, this process is terminated.
[0127] In S810, since the watchdog stop flag is off, the watchdog signal is output from the watchdog output processing unit 39, just as in the normal case without errors, and this process is terminated. In this case, the microcontroller 3 is not reset.
[0128] Furthermore, if the watchdog stop flag is on, it indicates an abnormal state where the watchdog signal is not output, and therefore microcontroller 3 will be reset. [3-4. Effects, etc.] This third embodiment provides the same effects as the first embodiment.
[0129] In this third embodiment, a reset of the microcontroller 3 can be performed as a safety measure. [4. Fourth Embodiment] Since the basic configuration of the fourth embodiment is the same as that of the first to third embodiments, the following description will mainly focus on the differences from the first to third embodiments. Note that the same reference numerals as in the first to third embodiments indicate components with similar functions, and refer to the preceding descriptions.
[0130] In this fourth embodiment, when multiple CPUs (for example, two) are used as in the second embodiment, a control is implemented to reset the microcontroller as a safety measure. [4-1. Overall Structure] In this fourth embodiment, as shown in Figure 10, the ECU1 comprises a microcontroller 3 and a microcontroller monitoring device 43. The microcontroller 3 includes two CPUs, a first CPU 7A and a second CPU 7B.
[0131] In addition to the CPU, the system also includes an error detection device 11, an error register 13, an error processing device 15, a ROM 17, a RAM 19, and a timer device 21, similar to the first embodiment. Furthermore, it includes a microcontroller reset control device 41. The RAM 19 is a shared memory, similar to the second embodiment.
[0132] The first CPU 7A includes an error analysis processing unit 31, a backup error processing unit 35, and a watchdog output processing unit 39. The second CPU 7B includes an error processing unit 33 and a control variable calculation unit 37.
[0133] [3-2. Control Sequence] Next, the control sequence of this fourth embodiment will be described. As shown in Figure 11, if a failure (i.e., an error) occurs in the second CPU 7B, the error detection device 11 detects the occurrence of the error.
[0134] Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1). Next, the error processing unit 15 instructs the first CPU 7A to start error analysis (step K2). That is, it generates an error interrupt for the CPU 7.
[0135] Next, the first CPU 7A refers to the timer time table in ROM 17 and obtains the timer time corresponding to the type of error and the content of the control (step K3). Furthermore, the first CPU 7A sets the timer time for the timer device 21 and enables the timer interrupt (step K4).
[0136] Furthermore, the first CPU 7A sends a signal to the RAM 19 to initiate the process of turning on the error handling start flag (steps K5, K6). Furthermore, the first CPU 7A sends a signal to the second CPU 7B to initiate error handling (for example, initialization) (step K7).
[0137] The second CPU 7B starts (i.e., performs) error processing in response to a signal from the first CPU 7A (step K8). Furthermore, once error handling is complete, the second CPU 7B sends a signal to RAM 19 to perform the process of turning off the error handling start flag (steps K9, K10).
[0138] Subsequently, when the timer device 21 determines that the timer time has elapsed, it generates a timer interrupt in the first CPU 7A to initiate backup error processing (step K11).
[0139] Next, the first CPU 7A checks the status of the error handling start flag in RAM 19 (step K12). At this time, the timer interrupt of the timer device 21 is disabled. If the error handling start flag is set to ON, it means that error handling is not yet complete, so as a safety measure, backup error handling is performed. Specifically, the watchdog stop flag is set to ON (step K13).
[0140] As a result, the output of the watchdog signal is stopped (step K14), and the microcontroller monitoring device 43 outputs a signal to the microcontroller reset control device 41 to reset the microcontroller 3 (steps K15, K16). When the microcontroller reset control device 41 receives the reset signal, it performs the well-known process of resetting the microcontroller 3 (step 17).
[0141] Subsequently, the error detection device 11 clears the error information in the error register 13 based on a signal from the CPU 7 (step K18). [4-3. Control Processing] Next, the control process implemented in this fourth embodiment will be described.
[0142] <Error Analysis Processing> First, the error analysis process performed by the first CPU 7A will be explained based on the flowchart in Figure 12A. This error analysis process is the same as in the second embodiment, so it will be explained briefly.
[0143] In S900 in Figure 12A, the timer time is obtained from the timer time table in ROM17. In the following step, S910, the timer time is set in the timer device 21.
[0144] Next, in S920, we enable timer interrupts. In the subsequent S930, the error handling start flag is turned on. In the subsequent S940, an inter-core interrupt triggers an error handling call to the second CPU 7B, and the main process is temporarily terminated.
[0145] <Error handling> Next, error handling performed by the second CPU 7B will be described based on the flowchart in Figure 12B. This error handling is the same as in the second embodiment, so it will be explained briefly.
[0146] In S1000 of Figure 12B, error handling is performed. In the subsequent S1010, if error handling is completed, the error handling start flag is turned off, and this process is terminated.
[0147] <Time Overload Interrupt Handling> Next, based on the flowchart in Figure 12C, the time-over interrupt handling performed by the first CPU 7A will be described. This time-over interrupt handling is the same as in the third embodiment, so it will be explained briefly.
[0148] In S1100 of Figure 12C, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the process proceeds to S1120; on the other hand, if the error handling start flag is on, the process proceeds to S1110.
[0149] In S1110, since error handling is not complete, the watchdog stop flag is turned on as a safety measure to prevent the watchdog signal from being output. This resets microcontroller 3.
[0150] In S1120, timer interrupts are disabled. In the subsequent S1130, the error information is cleared, and the process is temporarily terminated. <Watchdog output processing> Next, the watchdog output processing performed by the first CPU 7A will be described based on the flowchart in Figure 12D. This watchdog output processing is the same as in the third embodiment, so it will be explained briefly.
[0151] In S1200 of Figure 12D, it is determined whether the watchdog stop flag is off or not. If the watchdog stop flag is determined to be off, the process proceeds to S1210. On the other hand, if the watchdog stop flag is determined to be on, this process is terminated.
[0152] In S1210, since the watchdog stop flag is off, the watchdog signal is output and this process is terminated. In this case, microcontroller 3 is not reset. However, if the watchdog stop flag is on, microcontroller 3 will be reset.
[0153] [4-4. Effects, etc.] In this fourth embodiment, configurations similar to those in the first to third embodiments will produce similar effects.
[0154] [5. Fifth Embodiment] Since the basic configuration of the fifth embodiment is the same as that of the first embodiment, the following description will mainly focus on the differences from the first embodiment. Note that the same reference numerals as in the first embodiment indicate components with similar functions, and refer to the preceding description.
[0155] In this fifth embodiment, when using a single CPU, a control is implemented to illuminate a warning light as a safety measure. [5-1. Overall Structure] First, the configuration of this fifth embodiment will be described.
[0156] As shown in Figure 13, in this fifth embodiment, the ECU1 is equipped with a microcontroller 3 and is configured to control the operation of the display control ECU 45. The display control ECU 45 is an electronic control device that controls the illumination of the warning lights on the display.
[0157] The microcontroller 3 includes a CPU 7. In addition to the CPU 7, the configuration includes an error detection device 11, an error register 13, an error processing device 15, a ROM 17, a RAM 19, and a timer device 21, similar to the first embodiment.
[0158] The CPU 7 has a configuration similar to that of the first embodiment, and includes an error analysis processing unit 31, an error processing unit 33, a backup error processing unit 35, and a control variable calculation unit 37. Furthermore, it includes a communication control processing unit 47. The communication control processing unit 47 outputs a signal to the display control ECU 45 to illuminate the warning light.
[0159] [5-2. Control Sequence] Next, the control sequence of this fifth embodiment will be described. As shown in Figure 14, if a malfunction (i.e., an error) occurs in the microcontroller 3, the error detection device 11 detects the occurrence of the error.
[0160] Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1). Next, the error processing unit 15 instructs the CPU 7 to start analyzing the error (step K2). That is, it issues an error interrupt to the CPU 7.
[0161] Next, the CPU 7 refers to the timer time table in ROM 17 and obtains the timer time corresponding to the type of error and the control content (step K3). Furthermore, the CPU 7 sets the timer time for the timer device 21 and enables timer interrupts (step K4).
[0162] Furthermore, the CPU 7 sends a signal to the RAM 19 to initiate the process of turning on the error handling start flag (steps K5, K6). At the same time, CPU7 initiates error handling (step K7).
[0163] Furthermore, once error handling is complete, CPU 7 sends a signal to RAM 19 to perform the process of turning off the error handling start flag (steps K8, K9). Subsequently, when the timer device 21 determines that the timer time has elapsed, it generates a timer interrupt to initiate backup error processing on the CPU 7 (step K10).
[0164] Next, the CPU 7 checks the status of the error handling start flag in RAM 19 (step K11). At this time, the timer interrupt of the timer device 21 is disabled. If the error handling start flag is set to ON, it means that error handling is not yet complete, so as a safety measure, backup error handling is performed.
[0165] Specifically, based on a signal from the backup error processing unit 35, the communication control processing unit 47 sets an instruction to illuminate the warning light in the transmission buffer (step K12). The communication control processing unit 47 periodically transmits data from the transmission buffer (step K13), so if there is an instruction to illuminate the warning light in the transmission buffer, it transmits the instruction to illuminate the warning light to the display control ECU 45 (step K14). This performs the control to illuminate the warning light (step 15).
[0166] Subsequently, the error detection device 11 clears the error information in the error register 13 based on a signal from the CPU 7 (step K16). [5-3. Control Processing] Next, the control processing performed by the CPU 7 in this fifth embodiment will be described.
[0167] <Error Analysis Processing> First, the error analysis process will be explained based on the flowchart in Figure 15A. This error analysis process is the same as in the first embodiment, so it will be explained briefly.
[0168] In S1300 of Figure 15A, the timer time is obtained from the timer time table in ROM17. In the following step S1310, the timer time is set in the timer device 21.
[0169] In the following step, S1320, the timer interrupt is enabled. In the following S1330, the error handling start flag is turned on. In the subsequent S1340, error handling is performed according to the type of error.
[0170] In the subsequent S1350, if error handling is complete, the error handling start flag is turned off, and this process is terminated. <Time Overload Interrupt Handling> Next, the time-over interrupt handling will be explained based on the flowchart in Figure 15B. Note that the same aspects as in the first embodiment will be briefly explained.
[0171] In S1400 of Figure 15B, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the process proceeds to S1420; on the other hand, if the error handling start flag is on, the process proceeds to S1410.
[0172] In S1410, since error handling is not complete, a safety measure is taken to set a signal to illuminate the warning light in the transmission buffer. In S1420, timer interrupts are disabled.
[0173] In the subsequent S1430, the error information is cleared, and the process is temporarily terminated. <Communication control processing> Next, the communication control process will be explained based on the flowchart in Figure 15C.
[0174] Furthermore, the communication control process is called periodically (for example, every 10ms) by the OS scheduler, regardless of whether or not there are errors. In S1500 of Figure 15C, the data indicating the instruction to illuminate the warning light, which is set in the transmit buffer, is output to the outside of the microcontroller 3 (i.e., the display control ECU 45), and this process is terminated. If no data for transmission is set in the transmit buffer, no data is output to the outside.
[0175] [5-4. Effects, etc.] This fifth embodiment provides the same effects as the first embodiment and the like. [6. Sixth Embodiment] Since the basic configuration of the sixth embodiment is the same as that of the first, second, and fifth embodiments, the following description will mainly focus on the differences from the first, second, and fifth embodiments. Note that the same reference numerals as those used in the first, second, and fifth embodiments indicate components with similar functions; please refer to the preceding descriptions.
[0176] In this sixth embodiment, as in the second embodiment, a control method is described in which a warning light is illuminated as a safety measure when multiple CPUs (for example, two) are used, as in the fifth embodiment.
[0177] [6-1. Overall Structure] First, the configuration of this sixth embodiment will be described. As shown in Figure 16, in this sixth embodiment, the ECU1 includes a microcontroller 3, and the microcontroller 3 controls the operation of the display control ECU45.
[0178] The microcontroller 3 includes a first CPU 7A and a second CPU 7B as its CPU. In addition to the CPU, it also includes an error detection device 11, an error register 13, an error processing device 15, a ROM 17, a RAM 19, and a timer device 21, similar to the first embodiment. The RAM 19 is a shared memory, similar to the second embodiment.
[0179] The first CPU 7A has a configuration similar to that of the first embodiment, comprising an error analysis processing unit 31 and a backup error processing unit 35, and further comprising a communication control processing unit 47 similar to that of the fifth embodiment.
[0180] The second CPU 7B has a configuration similar to that of the second embodiment, and includes an error processing unit 33 and a control variable calculation unit 37. [6-2. Control Sequence] Next, the control sequence of this sixth embodiment will be described. Here, we will explain what happens when an error occurs in the second CPU 7B.
[0181] As shown in Figure 17, if a failure (i.e., an error) occurs in the second CPU 7B, the error detection device 11 detects the occurrence of the error. Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1).
[0182] Next, the error processing unit 15 instructs the first CPU 7A to start error analysis (step K2). That is, it generates an error interrupt for the first CPU 7A. Next, the first CPU 7A refers to the timer time table in ROM 17 and obtains the timer time corresponding to the type of error and the content of the control (step K3).
[0183] Furthermore, the first CPU 7A sets the timer time for the timer device 21 and enables the timer interrupt (step K4). Furthermore, the first CPU 7A sends a signal to the RAM 19 to initiate the process of turning on the error handling start flag (steps K5, K6).
[0184] Furthermore, the first CPU 7A sends a signal to the second CPU 7B to initiate error handling (step K7). The second CPU 7B starts (i.e., performs) error processing in response to a signal from the first CPU 7A (step K8).
[0185] Furthermore, once error handling is complete, the second CPU 7B sends a signal to RAM 19 to perform the process of turning off the error handling start flag (steps K9, K10). Subsequently, when the timer device 21 determines that the timer time has elapsed, it generates a timer interrupt in the first CPU 7A to initiate backup error processing (step K11).
[0186] Next, the first CPU 7A checks the status of the error handling start flag in RAM 19 (step K12). At this time, the timer interrupt of the timer device 21 is disabled. If the error handling start flag is set to ON, it means that error handling is not yet complete, so as a safety measure, backup error handling is performed.
[0187] Specifically, the communication control processing unit 47 sets an instruction to illuminate the warning light in the transmission buffer (step K13). The communication control processing unit 47 periodically transmits data from the transmission buffer (step K14), so if there is an instruction to illuminate the warning light in the transmission buffer, it transmits the instruction to illuminate the warning light to the display control ECU 45 (step K15). This performs the control to illuminate the warning light (step 16).
[0188] Subsequently, the error detection device 11 clears the error information in the error register 13 based on a signal from the first CPU 7A (step K17). [6-3. Control Processing] Next, the control process implemented in this sixth embodiment will be described.
[0189] <Error Analysis Processing> First, the error analysis process performed by the first CPU 7A will be explained based on the flowchart in Figure 18A. This error analysis process is the same as in the second embodiment, so it will be explained briefly.
[0190] In S1600 of Figure 18A, the timer time is obtained from the timer time table in ROM17. In the following step S1610, the timer time is set in the timer device 21.
[0191] In the following step, S1620, timer interrupts are enabled. In the following S1630, the error handling start flag is turned on. In the subsequent S1640, an inter-core interrupt triggers an error handling call to the second CPU 7B, and the main process is temporarily terminated.
[0192] <Error handling> Next, error handling performed by the second CPU 7B will be described based on the flowchart in Figure 18B. This error analysis process is the same as in the second embodiment, so it will be explained briefly.
[0193] In S1700 of Figure 18B, error handling is performed. In the subsequent S1710, if error handling is completed, the error handling start flag is turned off, and this process is terminated.
[0194] <Time Overload Interrupt Handling> Next, the time-over interrupt handling performed by the first CPU 7A will be described based on the flowchart in Figure 18C. This time-over interrupt handling is the same as in the fifth embodiment, so it will be explained briefly.
[0195] In S1800 of Figure 18C, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the error handling is complete and the process proceeds to S1820. On the other hand, if the error handling start flag is on, the error handling is not complete and the process proceeds to S1810.
[0196] In S1810, since error handling is not yet complete, a safety measure is taken to set a signal to illuminate the warning light in the transmission buffer. In S1820, timer interrupts are disabled.
[0197] In the subsequent S1830, the error information is cleared, and the process is temporarily terminated. <Communication control processing> Next, the communication control process performed by the first CPU 7A will be described based on the flowchart in Figure 18D. The communication control process in this case is the same as in the fifth embodiment.
[0198] In S1900 of Figure 18D, the data indicating the instruction to illuminate the warning light, which has been set in the transmit buffer, is output to the outside of the microcontroller 3, and this process is temporarily terminated. [6-4. Effects, etc.] In this sixth embodiment, configurations similar to those in the first, second, and fifth embodiments will produce similar effects.
[0199] [7. Seventh Embodiment] Since the seventh embodiment has the same basic configuration as the first embodiment, the following description will mainly focus on the differences from the first embodiment. Note that the same reference numerals as in the first embodiment indicate components with similar functions, and refer to the preceding description.
[0200] In this seventh embodiment, when using a single CPU, an appropriate safety measure is selected from among multiple safety measures stored in the safety analysis table, and the safety measure is implemented. [7-1. Overall Structure] First, the configuration of this seventh embodiment will be described.
[0201] As shown in Figure 19, in this seventh embodiment, the ECU1 includes a microcontroller 3, a control output device 5, and a microcontroller reset control device 41, and is configured to control the operation of the electronic throttle valve 25, the display control ECU 45, and the microcontroller monitoring device 43.
[0202] The microcontroller 3 includes a CPU 7. The CPU 7 has the same configuration as in the first embodiment, and includes an error analysis processing unit 31, an error processing unit 33, a backup error processing unit 35, and a control variable calculation unit 37. Furthermore, it includes the aforementioned communication control processing unit 47 and watchdog output processing unit 39.
[0203] Furthermore, the backup error processing unit 35 outputs a control signal to one of the control output blocking port 23, the watchdog output processing unit 39, or the communication control processing unit 47 in order to implement the selected safety measure, as will be described later. Specifically, it outputs a signal to the control output blocking port 23 to turn off the control output, a signal to the watchdog output processing unit 39 to reset the microcontroller 3, and a signal to the communication control processing unit 47 to turn on the warning light.
[0204] In addition to the CPU 7, the configuration includes an error detection device 11, an error register 13, an error processing device 15, a RAM 19, and a timer device 21, similar to the first embodiment. Furthermore, it includes a first ROM 17A and a second ROM 17B as ROMs.
[0205] The first ROM 17A stores a timer time table and the like, similar to the first embodiment. The second ROM17B stores a safety analysis table so that multiple safety measures can be selected and implemented.
[0206] The safety analysis table is a table that associates various types of errors (e.g., error codes) with the safety measures set to correspond to each error code. In the safety analysis table, when there are multiple types of errors, each error is associated with a corresponding safety measure. Therefore, the safety analysis table can be used to determine the safety measures corresponding to the errors detected.
[0207] Safety measures include (1) a retreat process that shuts off the control output (see, for example, the first embodiment), (2) a recovery process that resets the microcontroller 3 (see, for example, the third embodiment), and (3) a notification process that illuminates a warning light (see, for example, the fifth embodiment).
[0208] By using this safety analysis table, for example, if there are first to third errors, it is possible to set the control output to be turned off for the first error, the microcontroller 3 to be reset for the second error, and the warning light to be turned on for the third error.
[0209] (1) Degradation processing may be performed when a failure cannot be repaired and control continues with limited functionality (e.g., CPU failure). (2) Recovery processing may be performed when a temporary error can be expected to be eliminated by resetting (e.g., memory access violation). (3) Notification processing may be performed when a failure of a safety function alone does not pose an immediate danger and only a warning is given to the driver (e.g., self-diagnostic device failure).
[0210] [7-2. Control Sequence] Next, the control sequence of this seventh embodiment will be described. As shown in Figure 20, if a malfunction (i.e., an error) occurs in the microcontroller 3, the error detection device 11 detects the occurrence of the error.
[0211] Next, the error detection device 11 notifies the error processing device 15 of the occurrence of an error (step K1). Next, the error processing unit 15 instructs the CPU 7 to start analyzing the error (step K2). That is, it issues an error interrupt to the CPU 7.
[0212] Next, the CPU 7 refers to the timer time table in ROM 17 and obtains the timer time corresponding to the type of error and the control content (step K3). Furthermore, the CPU 7 sets the timer time for the timer device 21 and enables timer interrupts (step K4).
[0213] Furthermore, the CPU 7 sends a signal to the RAM 19 to initiate the process of turning on the error handling start flag (steps K5, K6). At the same time, CPU7 initiates error handling (step K7).
[0214] Furthermore, once error handling is complete, CPU 7 sends a signal to RAM 19 to perform the process of turning off the error handling start flag (steps K8, K9). Subsequently, when the timer device 21 determines that the timer time has elapsed, it issues a timer interrupt to the CPU 7 (step K10).
[0215] CPU 7 checks the status of the error handling start flag in RAM 19 via a timer interrupt (step K11). It also disables the timer interrupt of the timer device 21. Here, when the error processing start flag is on, since the error processing has not been completed, the backup error processing unit 35 refers to the safety analysis table of the second ROM 17B and performs a process of selecting a safety measure (K12). That is, using the safety analysis table, an appropriate safety measure is selected corresponding to the type of error.
[0216] Next, the CPU 7 performs a process of implementing each selected safety measure (that is, reaction processing) based on a signal from the backup error processing unit 35 (step K13). Thereafter, the error detection device 11 clears the error information in the error register 13 (step K14).
[0217] [7-3. Control Processing] Next, the control processing performed by the CPU 7 in the seventh embodiment will be described. <Error Analysis Processing> First, the error analysis processing will be described based on the flowchart of FIG. 21A. Since this error analysis processing is the same as that of the first embodiment, it will be briefly described.
[0218] In S2000 of FIG. 21A, the timer time is acquired from the timer time table of the first ROM 17A. In the subsequent S2010, the timer time is set in the timer device 21.
[0219] In the subsequent S2020, the timer interrupt is enabled. In the subsequent S2030, the error processing start flag is turned on. In the subsequent S2040, error processing corresponding to the type of error is implemented.
[0220] In the subsequent S2050, when the error processing is completed, the error processing start flag is turned off and this process is temporarily terminated. <Time-out Interrupt Processing> Next, the time-out interrupt processing will be described based on the flowchart of FIG. 21B. The same content as that of the first embodiment will be briefly described.
[0221] In S2100 of Figure 21B, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the process proceeds to S2170; on the other hand, if the error handling start flag is on, the process proceeds to S2110.
[0222] In S2110, since error handling is not complete, the safety analysis table is referenced to obtain safety measures (i.e., safety actions). In the following S2120, it is determined whether the safety measure is a degraded process or not. If the result is positive, the process proceeds to S2130; if the result is negative, the process proceeds to S2140.
[0223] In S2130, a degraded process is performed, and the process proceeds to S2170. Meanwhile, in S2140, it is determined whether the safety measure is a recovery process or not. If the determination is positive, the process proceeds to S2150; if the determination is negative, the process proceeds to S2160.
[0224] In S2150, a recovery process is performed, and the process proceeds to S2170. Also, in S2160, a notification process is performed, and the process proceeds to S2170. In S2170, timer interrupts are disabled.
[0225] In the subsequent S2180, the error information is cleared, and the process is temporarily terminated. [7-4. Effects, etc.] This seventh embodiment provides the same effects as the first embodiment and the like.
[0226] In this seventh embodiment, since the necessary processing can be selected and executed from the safety analysis table, there is no need to implement safety measures (i.e., reaction processing) for each individual error, which has the advantage of reducing development effort and memory used for implementation.
[0227] [8. Eighth Implementation] Since the eighth embodiment has the same basic configuration as the second and seventh embodiments, the following description will mainly focus on the differences from the second and seventh embodiments. Note that the same reference numerals as those used in the second and seventh embodiments indicate components with similar functions; please refer to the preceding descriptions.
[0228] In this eighth embodiment, when using multiple CPUs (for example, two), an appropriate safety measure is selected from among multiple safety measures stored in the safety analysis table, and the safety measure is implemented.
[0229] [8-1. Overall Structure] First, the configuration of this eighth embodiment will be described. As shown in Figure 22, in this eighth embodiment, the ECU1 includes a microcontroller 3, a control output device 5, and a microcontroller reset control device 41, and is configured to control the operation of the electronic throttle valve 25, the display control ECU 45, and the microcontroller monitoring device 43.
[0230] Microcontroller 3 is equipped with a first CPU 7A and a second CPU 7B7 as its CPUs. The first CPU 7A includes an error analysis processing unit 31, a backup error processing unit 35, a watchdog output processing unit 39, and a communication control processing unit 47. The second CPU 7B includes an error processing unit 33 and a control variable calculation unit 37.
[0231] In addition to the CPU, the system also includes, as in the seventh embodiment, an error detection device 11, an error register 13, an error processing device 15, a RAM 19, a timer device 21, and a control output cutoff port 23. Furthermore, it includes a first ROM 17A and a second ROM 17B as ROMs.
[0232] Furthermore, RAM19 has the function of shared memory. In addition, the first ROM17A stores a timer time table, etc., and the second ROM17B stores a safety analysis table similar to that of the seventh embodiment.
[0233] [8-1. Control Sequence] Next, the control sequence of the eighth embodiment will be described. As shown in FIG. 23, when a failure (i.e., an error) occurs in the microcomputer 3, the error detection device 11 detects the occurrence of the error.
[0234] Next, the error detection device 11 notifies the error processing device 15 of the occurrence of the error (step K1). Next, the error processing device 15 instructs the first CPU 7A to start analyzing the error (step K2). That is, an error interrupt is applied to the first CPU 7A.
[0235] Next, the first CPU 7A refers to the timer time table in the first ROM 17A and acquires the timer time corresponding to the type of error and the content of control (step K3). Furthermore, the first CPU 7A sets the timer time for the timer device 21 and enables the timer interrupt (step K4).
[0236] Furthermore, the first CPU 7A transmits a signal to the RAM 19 to perform a process of turning on the error processing start flag (steps K5, K6). Furthermore, the first CPU 7A transmits a signal to the second CPU 7B to start error processing (step K7).
[0237] The second CPU 7B starts (i.e., performs) error processing in response to the signal from the first CPU 7A (step K8). Furthermore, when the error processing is completed, the second CPU 7B transmits a signal to the RAM 19 to perform a process of turning off the error processing start flag (steps K9, K10).
[0238] Thereafter, when it is determined that the timer time has elapsed in the timer device 21, a timer interrupt is performed on the first CPU 7A (step K11). In the first CPU 7A, the state of the error processing start flag in the RAM 19 is confirmed by the timer interrupt (step K12). Also, the timer interrupt of the timer device 21 is disabled.
[0239] If the error handling start flag is set to ON, error handling is not yet complete. Therefore, the backup error processing unit 35 refers to the safety analysis table in the second ROM 17B and performs a process to select a safety measure (K13). In other words, it uses the safety analysis table to select an appropriate safety measure corresponding to the type of error.
[0240] Next, the first CPU 7A performs a process (i.e., a reaction process) to implement each selected safety measure based on the signal from the backup error processing unit 35 (step K14). Subsequently, the error detection device 11 clears the error information in the error register 13 (step K15).
[0241] [8-3. Control Processing] Next, the control processes performed by each CPU in this eighth embodiment will be described. <Error Analysis Processing> First, the error analysis process performed by the first CPU 7A will be explained based on the flowchart in Figure 24A. This error analysis process is the same as in the sixth embodiment, so it will be explained briefly.
[0242] In S2200 of Figure 24A, the timer time is obtained from the timer time table in the first ROM 17A. In the following step S2210, the timer time is set in the timer device 21.
[0243] In the following step, S2220, timer interrupts are enabled. In the following S2230, the error handling start flag is turned on. In the subsequent S2240, an inter-core interrupt triggers an error handling call to the second CPU 7B, and the current process is terminated.
[0244] <Error handling> Next, error handling performed by the second CPU 7B will be described based on the flowchart in Figure 24B. This error analysis process is the same as in the sixth embodiment, so it will be explained briefly.
[0245] In S2300 of Figure 24B, error handling is performed. In the subsequent S2310, if error handling is complete, the error handling start flag is turned off, and this process is terminated.
[0246] <Time Overload Interrupt Handling> Next, the time-over interrupt handling performed by the first CPU 7A will be described based on the flowchart in Figure 24C. This time-over interrupt handling is the same as in the seventh embodiment, so it will be explained briefly.
[0247] In S2400 of Figure 24C, the error handling start flag is checked. That is, it is determined whether the error handling start flag is off or on. If the error handling start flag is off, the process proceeds to S2470; on the other hand, if the error handling start flag is on, the process proceeds to S2410.
[0248] In S2410, since error handling is not complete, the safety analysis table is referenced to obtain safety measures (i.e., safety actions). In the following S2420, it is determined whether the safety measure is a degraded process or not. If the result is positive, the process proceeds to S2430; if the result is negative, the process proceeds to S2440.
[0249] In S2430, a degraded process is performed, and the process proceeds to S2470. Meanwhile, in S2440, it is determined whether the safety measure is a recovery process or not. If the determination is positive, the process proceeds to S2450; if the determination is negative, the process proceeds to S2460.
[0250] In S2450, a recovery process is performed, and the process proceeds to S2470. In S2460, a notification process is performed, and the process proceeds to S2470. In S2470, timer interrupts are disabled.
[0251] In the subsequent S2480, the error information is cleared, and the process is temporarily terminated. [8-4. Effects, etc.] This eighth embodiment provides the same effects as the second and seventh embodiments, etc.
[0252] [9. Other Embodiments] While embodiments of this disclosure have been described above, it goes without saying that this disclosure is not limited to the embodiments described above and can take various forms.
[0253] (9a) In addition to the measures described in the embodiments above, various other safety measures can be considered. (9b) The operation of the electronic control unit described herein may be realized by a dedicated computer provided by configuring a processor and memory programmed to perform one or more functions embodied by a computer program.
[0254] Alternatively, the operation of the electronic control device described herein may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits.
[0255] Alternatively, the operation of the electronic control unit described herein may be realized by one or more dedicated computers comprising a combination of a processor and memory programmed to perform one or more functions and a processor comprising one or more hardware logic circuits.
[0256] Furthermore, the computer program may be stored on a computer-readable, non-transitional tangible recording medium as instructions executed by the computer. The method for realizing the functions of the electronic control device does not necessarily need to include software; all of its functions may be realized using one or more hardware components.
[0257] (9c) In addition to the electronic control device described above, the present disclosure can also be realized in various forms, such as a configuration using the electronic control device as a component, a program for making the computer of the electronic control device function, a non-transition tangible recording medium such as a semiconductor memory on which the program is recorded, and a control method.
[0258] (9d) Multiple functions of one component in each of the above embodiments may be realized by multiple components, or one function of one component may be realized by multiple components. Also, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, some of the configurations of each of the above embodiments may be omitted. Furthermore, at least some of the configurations of each of the above embodiments may be added to or replaced with the configurations of other embodiments. [Technical Concept Disclosed in This Specified Specification] [Item 1] An electronic control device (1) is configured to perform error processing as a countermeasure corresponding to a predetermined error when such an error is detected, An error processing unit (33) configured to perform the error processing according to the type of error detected, A timer setting unit (31) is configured to use a timer device (21) with a variable timer time and to set the error processing waiting time for the completion of the error processing as the timer time, If the timer time set by the timer time setting unit has elapsed and the error processing has not been completed, the safety measures execution unit (37) is configured to perform predetermined safety measures corresponding to the error, An electronic control unit equipped with the following features.
[0259] [Item 2] The electronic control device described in item 1, A timer time table is provided which associates the type of error or the content of the error processing with the timer time corresponding to the error processing waiting time. Electronic control unit.
[0260] [Item 3] An electronic control device as described in item 1 or item 2, The system is configured to set a flag according to the status of the error handling process, and to determine what next action to take based on the status of the flag. Electronic control unit.
[0261] [Item 4] An electronic control device described in any one of items 1 to 3, A safety analysis table is provided that associates the type of error with the safety measures corresponding to that type of error. Electronic control unit.
[0262] [Item 5] An electronic control device described in any one of items 1 to 4, As a safety measure, it is configured to shut down the output of the device affected by the error. Electronic control unit.
[0263] [Item 6] An electronic control device described in any one of items 1 to 4, As a safety measure, the device in which the error occurred is configured to be reset. Electronic control unit.
[0264] [Item 7] An electronic control device described in any one of items 1 to 4, As a safety measure, it is configured to output a warning regarding the error. Electronic control unit. [Explanation of Symbols]
[0265] 1…Electronic control unit, 3…Microcontroller, 7…CPU, 7A…First CPU, 7B…Second CPU, 11…Error detection device, 15…Error processing device, 17…ROM, 17A…First ROM, 17B…Second ROM, 19…RAM, 21…Timer device
Claims
1. An electronic control device (1) is configured to perform error processing as a countermeasure corresponding to a predetermined error when such an error is detected, An error processing unit (33) configured to perform the error processing according to the type of error detected, A timer setting unit (31) is configured to use a timer device (21) with a variable timer time and to set the error processing waiting time for the completion of the error processing as the timer time, A safety measure execution unit (37) is configured to perform predetermined safety measures corresponding to the error if the error processing is not completed when the timer time set by the timer time setting unit has elapsed, An electronic control unit equipped with the following features.
2. The electronic control device according to claim 1, A timer time table is provided which associates the type of error or the content of the error processing with the timer time corresponding to the error processing waiting time. Electronic control unit.
3. The electronic control device according to claim 1, The system is configured to set a flag according to the status of the error handling process, and to determine what next action to take based on the status of the flag. Electronic control unit.
4. The electronic control device according to claim 1, A safety analysis table is provided that associates the type of error with the safety measures corresponding to that type of error. Electronic control unit.
5. The electronic control device according to claim 1, As a safety measure, it is configured to shut down the output of the device affected by the error. Electronic control unit.
6. The electronic control device according to claim 1, As a safety measure, the device in which the error occurred is configured to be reset. Electronic control unit.
7. The electronic control device according to claim 1, As a safety measure, it is configured to output a warning regarding the error. Electronic control unit.