Control device and control method for a vehicle transmission

JP2026144739APending Publication Date: 2026-09-09ASTEMO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025032202
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2026-09-09

AI Technical Summary

Benefits of technology

【0009】 本発明の一態様によれば、車両用変速機の安全状態を確保し、ドライバビリティの低下を回避できる。前述した以外の課題、構成及び効果は、以下の実施例の説明によって明らかにされる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026144739000001_ABST
    Figure 2026144739000001_ABST
Patent Text Reader

Abstract

Ensure the vehicle's transmission is in a safe condition and avoid a decrease in drivability. [Solution] A control device for a vehicle transmission, comprising: a storage unit having a normal area and an alternative area separated into different areas for each control process; a fault detection unit that detects a fault in the storage unit and determines whether the detected fault is in the normal area or the alternative area; a control execution unit that selectively executes a normal control process and an alternative control process based on the fault determination results for the normal area and the alternative area; a reprogramming control unit that updates a software program stored in the storage unit; and a startup determination unit that determines the startup state based on the success or failure determination result of the reprogramming, wherein the reprogramming control unit determines that reprogramming is successful without executing reprogramming of the normal area if there is a fault in the normal area, and determines that reprogramming is failed without executing reprogramming of the area where the fault is located if there is a fault in an area other than the normal area.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a control device for a vehicle transmission. [Background Art]

[0002] IEC 61508, ISO 26262 and other international standards for functional safety have been enacted, and demands for the safety performance of automobiles are increasing. In order to meet these demands for safety performance, microprocessors that control vehicle transmissions are provided with a function that can constantly monitor a safe state, such as improving the performance of a fault detection function for a Read Only Memory (ROM). On the other hand, advances in microprocessor technology have increased the capacity of ROMs, and the failure rate of ROMs tends to increase.

[0003] As background art in the present technical field, there is the following prior art. Patent Document 1 (Japanese Unexamined Patent Publication No. 2009-41602) discloses an automatic transmission including: a plurality of friction transmission mechanisms that transmit and cut off driving force between an output shaft of a driving force generation source and a transmission output shaft of a gear-type transmission; a plurality of transmission input shafts respectively connected to the plurality of friction transmission mechanisms; and a plurality of gear trains that selectively connect the plurality of transmission input shafts and the transmission output shaft by selecting a plurality of synchronous meshing functions, wherein when a failure of each sensor, actuator, device, or mechanical mechanism constituting the transmission is detected, fail-safe control integrated and grouped in accordance with the degree of influence on a vehicle expected from a failure in a portion around or related to the failed portion regardless of the failed portion is performed. A control device for an automatic transmission characterized by the above is described. [Prior Art Documents] [Patent Documents]

[0004] [Patent Document 1] Japanese Unexamined Patent Publication No. 2009-41602 [Summary of the Invention] [Problem to be Solved by the Invention]

[0005] According to the prior art mentioned above, duplicated processes with the same content and control units are placed in ROM, and if one of the ROMs of the duplicated control fails, normal control is continued by the other duplicated control whose ROM is not faulty, thereby avoiding a decrease in drivability.

[0006] If one of the ROMs in a redundant control system fails, and the other control system continues normal operation, attempting to reprogram the system will result in a reprogramming failure because the microprocessor cannot reprogram the faulty ROM portion. The vehicle's transmission control system will then enter a reprogramming waiting state. In this state, the software stops the control of each actuator in the vehicle's transmission. In this case, the transmission's hardware controls fix the gear ratio, ensuring safety, but this significantly reduces drivability.

[0007] This invention has been made in view of the above problems, and aims to provide a method that avoids reprogramming failure when a ROM failure is detected, ensures the safe state of the vehicle's transmission without restricting the function of the vehicle's transmission, and avoids a decrease in drivability. [Means for solving the problem]

[0008] A typical example of the invention disclosed in this application is as follows: A control device for a vehicle transmission, comprising: a storage unit that has a normal area and an alternative area separated into different areas for each control process, storing a software program for normal control processing in the normal area and a software program for alternative control processing in the alternative area; a fault detection unit that detects a fault in the storage unit and determines whether the detected fault is in the normal area or the alternative area; a control execution unit that selectively executes the normal control processing and the alternative control processing based on the fault determination results for the normal area and the alternative area; a reprogramming control unit that performs reprogramming to update the software program stored in the storage unit; and a startup determination unit that determines whether to start normally or start in a reprogramming waiting state based on the success or failure determination result of the reprogramming, wherein the reprogramming control unit determines that reprogramming is successful without performing reprogramming of the normal area if there is a fault in the normal area, and determines that reprogramming is failed without performing reprogramming of the area where the fault is located if there is a fault in an area other than the normal area. [Effects of the Invention]

[0009] According to one aspect of the present invention, it is possible to ensure the safety of a vehicle transmission and avoid a decrease in drivability. Problems, configurations, and effects other than those described above will be clarified by the following description of embodiments. [Brief explanation of the drawing]

[0010] [Figure 1] This figure shows an example of a system overview related to a control device for a vehicle's transmission. [Figure 2] This figure shows the configuration of an ATCU that controls a solenoid relay according to an embodiment of the present invention. [Figure 3] This is a flowchart of the process for detecting a ROM fault location in solenoid relay control according to an embodiment of the present invention. [Figure 4]This is a flowchart of a control method for avoiding ROM failure points related to solenoid relay control according to an embodiment of the present invention. [Figure 5] This is a control flowchart for avoiding reprogramming of the ROM fault location in the solenoid relay control of an embodiment of the present invention. [Figure 6] This is a flowchart of the process executed immediately after startup by the microprocessor according to an embodiment of the present invention. [Modes for carrying out the invention]

[0011] The embodiments of the present invention will be described below with reference to the attached drawings. The attached drawings show specific embodiments in accordance with the principles of the present invention, but these are for the purpose of understanding the present invention and are not to be used in any way to limit the interpretation of the present invention.

[0012] First, an overview of the embodiments of the present invention will be described. The ROM mounted on the microprocessor 102 of the ATCU001 is composed of a storage unit for storing data and a control unit for executing software programs using the data. The control unit consists of a group of software programs that control the actuators of the vehicle's transmission based on sensor information attached to the vehicle's transmission and information acquired from other ECUs, and is arranged in the ROM in control units. The control unit also has a software program for performing reprogramming, and the software program for performing reprogramming is arranged in the ROM.

[0013] Some of the control functions in the control unit are duplicated, with identical control units and content. Depending on the ROM capacity of the duplicated controls, it is advisable to prioritize the duplication of functions that can avoid a decrease in drivability. Hereinafter, the duplicated software programs will be referred to as normal control and alternate control.

[0014] A ROM failure is monitored, for example, by the function of the microprocessor 102, and when a ROM failure occurs, address information of the failed portion is acquired. The control including the failed portion is identified based on the address information of the failed ROM portion and a data table for identifying the failed portion. The same control as in normal operation is performed by alternative control for the control including the failed ROM portion.

[0015] In reprogramming, reprogramming is not performed on the control located in the failed ROM portion, and this case is not regarded as a reprogramming failure. By avoiding reprogramming failures, the same control as normal operation is continuously performed through alternative control for the control located in the failed ROM portion. If a ROM failure occurs in both the normal control and the alternative control, a conventional fail-safe state is entered, the function of the vehicle transmission is limited, and safety is ensured.

[0016] Referring to Fig. 1, an example of the outline of a system related to a control device for a vehicle transmission will be described.

[0017] The vehicle transmission includes a primary pulley 002 that receives driving force from an engine 008, a secondary pulley 004 that outputs driving force to a final gear 009, and a belt 003 that connects the primary pulley 002 and the secondary pulley 004. The primary pulley 002 and the secondary pulley 004 can change their groove width by hydraulic pressure to change the gear ratio. Note that the vehicle transmission may be a DCT (Dual Clutch Transmission) or a stepped transmission (a so-called torque converter AT) instead of a CVT (Continuously Variable Transmission).

[0018] The transmission further includes an oil pump 005 that supplies oil to the primary pulley 002 and the secondary pulley 004, a primary solenoid valve 006 that adjusts the amount of oil supplied to the primary pulley 002, and a secondary solenoid valve 007 that adjusts the amount of oil supplied to the secondary pulley 002.

[0019] An ATCU (Automatic Transmission Control Unit) 001, which is a control device for a vehicle transmission, controls the hydraulic pressure of a primary pulley 002 and a secondary pulley 004 by opening and closing a primary solenoid valve 006 and a secondary solenoid valve 007, and consequently controls the gear ratio of the vehicle transmission.

[0020] Embodiments of the present invention will be described with reference to Figs. 2 to 6.

[0021] Fig. 2 is a diagram showing the configuration of an ATCU 001 that controls a solenoid relay according to an embodiment of the present invention. The ATCU 001 includes a microprocessor 102, a solenoid control IC 114 that receives a target current value from the microprocessor 102 and controls a solenoid 116, and a solenoid relay circuit 113 that controls power supply from a battery 115 to the solenoid control IC 114.

[0022] The microprocessor 102 includes a ROM data storage unit 105 that stores data, a ROM control unit 104 that stores software programs, a ROM failure detector 103 that detects a ROM failure address, and a reprogramming control unit 119 that reprograms a ROM. The microprocessor 102 also includes a CPU (not shown) that executes the software programs stored in the ROM control unit 104 and performs various types of control.

[0023] The ROM failure detector 103 includes a ROM failure notification register 117 that stores information on whether a ROM failure has occurred, and a ROM failure address storage register 118 that stores n addresses at which a ROM failure has occurred. The ROM failure detector 103 is a function mounted on the microprocessor 102, and monitors for ROM failures from when the microprocessor 102 starts up until it stops.

[0024] The ROM control unit 104 includes software programs for ROM failure detection control 106, ROM failure avoidance control 107, solenoid relay control 108, solenoid relay alternative control 109, ROM failure control 110, and solenoid control 111. The ROM failure detection control 106 is a software program that identifies the failure location of the control unit based on information from the ROM failure notification register 117 and the ROM failure address storage register 118 obtained from the ROM failure detector 103. The ROM failure avoidance control 107 is a software program that avoids the failure location of the control unit determined by the ROM failure detection control 106. The solenoid relay control 108 is a software program that controls the ON / OFF state of the solenoid relay circuit 113. The solenoid control 111 is a software program that supplies a target instruction current to the solenoid control IC 114. The solenoid relay alternative control 109 is a software program with the same content as the solenoid relay control 108, which is used as an alternative control when a ROM failure occurs. The ROM failure control 110 is a software program that is executed when a ROM failure occurs in both the solenoid relay control 108 and the solenoid relay substitute control 109.

[0025] The ROM data storage unit 105 has a fault location determination data table 112 for identifying the fault location in the ROM. The fault location determination data table 112 records the starting address and ending address that define the solenoid relay control region for solenoid relay control 108 and solenoid relay substitute control 109. In other words, the area between the starting address and the ending address is the solenoid relay control region.

[0026] The reprogramming control unit 119 has a ROM failure location reprogramming avoidance control 120. The ROM failure location reprogramming avoidance control 120 identifies the failure location of the control unit based on information from the ROM failure notification register 117 and the ROM failure address storage register 118 obtained from the ROM failure detector 103, and avoids reprogramming if the failure location is the solenoid relay control 108.

[0027] Figures 3, 4, 5, and 6 are flowcharts illustrating an example of software processing in this embodiment relating to the solenoid relay control 108 of the present invention. The process in Figure 6 is executed immediately after the microprocessor 102 starts up. If the result of the process in Figure 6 is normal startup, the software processing in Figures 3 and 4 is repeatedly executed at regular intervals until it finishes. If the result of the process in Figure 6 is a reprogramming waiting process, the ROM control unit 104 is not executed, and the output to the solenoid 116 stops. Also, if reprogramming is to be performed, the ROM control unit 104 is stopped, and the process in Figure 5 is repeatedly executed.

[0028] Figure 3 is a flowchart of the process performed by the ROM failure detection control 106 to detect a ROM failure related to the solenoid relay control 108. The ROM control unit 104 determines whether a ROM failure has occurred based on the ROM failure notification register 117 of the ROM failure detector 103 (201). If a ROM failure is determined, the ROM failure address information is obtained from the ROM failure address storage register 118 of the ROM failure detector 103 (202).

[0029] The ROM control unit 104 then compares the acquired fault address information with the start and end addresses of the solenoid relay control 108 (203). If the fault address information acquired in step 202 is within the solenoid relay control area, it determines that there is a ROM fault in the solenoid relay control 108 (204).

[0030] Next, the ROM control unit 104 compares the fault address information (202) with the start and end addresses of the solenoid relay alternative control 109 recorded in the fault location determination data table 112 (205). If the fault address information obtained in step 202 is within the solenoid relay alternative control area, it determines that the solenoid relay alternative control 109 has a ROM failure (206). The information regarding the presence or absence of ROM failures in the solenoid relay control 108 and the solenoid relay alternative control 109 is referenced by the ROM failure location avoidance control 107, and control is performed to avoid the ROM failure location.

[0031] Figure 4 is a flowchart of the control performed by the ROM failure location avoidance control 107 to avoid the ROM failure location related to the solenoid relay control 108. Based on the result of the solenoid relay control ROM failure determination (204) by the ROM failure location detection control 106, it is determined whether or not to avoid the solenoid relay control 108 (301). If it is not determined that there is a ROM failure in the solenoid relay control 108, the normal solenoid relay control 108 is performed (303).

[0032] On the other hand, if a ROM failure is detected in the solenoid relay control 108, the result of the solenoid relay replacement control ROM failure detection (206) of the ROM failure detection control 106 determines whether or not to avoid the solenoid relay replacement control 109 (302). If a ROM failure is not detected in the solenoid relay replacement control 109, the solenoid relay replacement control 109 is performed (304).

[0033] On the other hand, if both the solenoid relay control 108 and the solenoid relay substitute control 109 are determined to be ROM failures, the ROM failure control 110 is performed (305). For example, in the ROM failure control 110, the software control of each actuator of the vehicle's transmission is stopped, and the gear ratio is fixed by hardware control of the vehicle's transmission. Fixing the gear ratio by hardware control ensures safety, but significantly reduces drivability.

[0034] In conventional vehicle transmission control devices, if a ROM failure was detected by the solenoid relay control 108, the ROM failure control 110 was performed. However, according to this embodiment, by performing the solenoid relay alternative control 109, the ROM failure control 110 can be avoided, and as a result, a decrease in drivability can be avoided.

[0035] Figure 5 is a flowchart of the control performed by the reprogramming control unit 119 to avoid reprogramming the ROM fault location of the solenoid relay control 108.

[0036] The ROM fault address is obtained from the ROM fault address storage register 118 of the ROM fault detector 103 (401). Then, it is determined whether the ROM fault address is included in the reprogramming write area specified by the reprogramming command (402). If there is no ROM fault in the reprogramming write area, the ROM write process is performed (403). After the ROM write process, it is determined whether the ROM write was successful (404). If the ROM write is successful, the reprogramming avoidance control is terminated in order to write data to the next area. If the ROM write fails, the ROM write is interrupted (405).

[0037] If a ROM fault is determined in step 402 in the reprogramming write area, it is determined whether the ROM fault address is in the area for the solenoid relay control 108 (406). If the ROM fault address is not in the area for the solenoid relay control 108, ROM writing is interrupted (405). If the ROM fault address is in the area for the solenoid relay control 108, ROM writing to the area for the solenoid relay control 108 is skipped (407), and the reprogramming avoidance control is terminated in order to write data to the next area without determining that reprogramming has failed.

[0038] Figure 6 is a flowchart of the processes that the microprocessor 102 executes immediately after startup. It determines whether reprogramming was successful at startup (501). If reprogramming is successful, the control unit is started normally (503). On the other hand, if reprogramming fails, a re-reprogramming waiting process is executed, which allows only reprogramming to be performed, and the control unit is not started (502).

[0039] In the reprogramming waiting process (502), it is preferable to stop the software control of each actuator of the vehicle's transmission and fix the gear ratio through hardware control of the vehicle's transmission. Fixing the gear ratio through hardware control ensures safety, but significantly reduces drivability.

[0040] According to this embodiment, when a ROM failure occurs in the solenoid relay control 108, that is, when control is continued by the other alternative control that does not have a ROM failure, if reprogramming is performed, as shown in Figure 5, the control at the ROM failure location is not reprogrammed and the reprogramming is not judged as a failure. Therefore, after reprogramming, the control device is started normally (503) instead of the re-reprogramming waiting process (502) shown in Figure 6. As a result, instead of performing the ROM failure control 110 due to a reprogramming failure as in the conventional method, processing is continued with the solenoid relay alternative control 109 as shown in Figures 3 and 4, and control can be continued as with normal operation. Therefore, it is not necessary to stop the control of each actuator of the vehicle's transmission in software and fix the gear ratio by hardware control to ensure safety, and a decrease in drivability can be avoided.

[0041] It should be noted that the present invention is not limited to the embodiments described above, but includes various modifications and equivalent configurations within the spirit of the attached claims. For example, the embodiments described above are described in detail for the purpose of clearly illustrating the present invention, and the present invention is not necessarily limited to having all the described configurations. Furthermore, some of the configurations of one embodiment may be replaced with those of another embodiment. Furthermore, configurations of other embodiments may be added to the configuration of one embodiment. Furthermore, some of the configurations of each embodiment may be added, deleted, or replaced with those of other embodiments.

[0042] Furthermore, each of the aforementioned configurations, functions, processing units, and processing means may be implemented in hardware, for example, by designing them as integrated circuits, or they may be implemented in software by having a processor interpret and execute programs that realize each function.

[0043] Information such as programs, tables, and files that implement each function can be stored in memory, hard disks, SSDs (Solid State Drives), or other storage media such as IC cards, SD cards, or DVDs. Furthermore, some or all of the aforementioned control units may be implemented in hardware, for example, by designing them as integrated circuits.

[0044] Furthermore, the control lines and information lines shown are those deemed necessary for explanatory purposes and do not necessarily represent all control lines and information lines required for implementation. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]

[0045] 001 … ATCU 002… Primary pulley 003... Belt 004 ... Secondary pulley 005… Oil pump 006… Primary solenoid valve 007… Secondary solenoid valve 008... Engine 009... Final Gear 102… Microprocessor 103... ROM failure detector 104 ... ROM control unit 105 ... ROM data storage unit 106 ... ROM fault location detection control 107... ROM failure point avoidance control 108 ... Solenoid relay control 109 ... Solenoid relay alternative control 110 ... ROM failure control 111 ... Solenoid control 112 … Data table for determining fault location 113… Solenoid relay circuit 115… Battery 116 ... Solenoid 117 … ROM failure notification register 118 ... ROM fault address storage register 119 ... ROM Reprogramming Control Unit 120 ... ROM failure part reprogramming avoidance control

Claims

1. A control device for a vehicle transmission, A storage unit having a normal area and an alternative area, each separated into different areas for each control process, storing the software program for the normal control process in the normal area and the software program for the alternative control process in the alternative area, A fault detection unit that detects a fault in the memory unit and determines whether the detected fault is in the normal area or the alternative area, A control execution unit that selectively executes the normal control process and the alternative control process based on the failure determination results of the normal region and the alternative region, A reprogramming control unit that performs reprogramming to update the software program stored in the memory unit, The system includes a startup determination unit that determines whether to start normally or start in a reprogramming waiting state based on the result of determining whether the reprogramming was successful or not. The reprogramming control unit, If a failure occurs in the normal area, the reprogramming is determined to be successful without performing reprogramming of the normal area. A control device that, when a fault occurs in a region other than the normal region, determines that reprogramming has failed without performing reprogramming on the region containing the fault.

2. A control device according to claim 1, The normal control process includes a control process for a solenoid coil that controls the supply of hydraulic pressure to the vehicle transmission, The alternative control process includes a control device that includes an alternative control process for the solenoid coil.

3. A control device according to claim 1, The control execution unit is, If the normal area is not malfunctioning, the normal control process is executed. If the normal area fails and the alternative area does not fail, the alternative control process is executed. A control device that performs fault control to limit the function of the vehicle transmission when the normal area fails and the alternative area fails.

4. A control device according to claim 1, The reprogramming control unit, If there are no failures in either the normal area or the alternative area, reprogramming of the normal area or the alternative area is performed. A control device that determines whether reprogramming is successful or not based on the result of the reprogramming execution.

5. A control device according to claim 1, Each of the above-mentioned normal area and the above-mentioned alternative area is specified by a start address and an end address, The fault detection unit identifies the location of the fault by the fault address and determines whether the fault address is located between the start address and end address of either the normal area or the alternative area.

6. A method for controlling a vehicle transmission, The control method is executed by a control device having a CPU that executes a software program, and a storage unit that has a normal area and an alternative area, which are separated into different areas for each control process, and stores the software program for the normal control process in the normal area and the software program for the alternative control process in the alternative area. The control method described above is The CPU performs a fault detection procedure in which it detects a fault in the memory unit and determines whether the detected fault is in the normal area or the alternative area. The CPU includes a control execution unit that selectively executes the normal control process and the alternative control process based on the failure determination results of the normal area and the alternative area, The CPU performs a reprogramming control procedure to update the software program stored in the memory unit, The CPU includes a startup determination procedure that determines whether to start normally or start in a reprogramming waiting state based on the result of determining whether the reprogramming was successful or not. In the aforementioned reprogramming control procedure, If the CPU has a fault in the normal area, it will determine that the reprogramming was successful without performing reprogramming of the normal area. A control method in which the CPU determines that a reprogramming has failed if a fault occurs in a region other than the normal region, without performing reprogramming of the region containing the fault.

Citation Information

Patent Citations

  • Controller and control method for automatic transmission

    JP2009041602A