Electronic control device and computer program

The solution ensures coordinated data transfer between virtual machines by using control units to manage ring buffer writing and flag states, preventing data loss and maintaining communication integrity without altering the hypervisor configuration.

JP7707930B2Active Publication Date: 2025-07-15DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022001775
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-01-07
Publication Date
2025-07-15
Estimated Expiration
2042-01-07

AI Technical Summary

Technical Problem

Communication between virtual machines controlled by a hypervisor can fail when receiving virtual machines read data from a ring buffer at different timings, leading to unreceived data and potential communication disruption due to uncoordinated data writing and reading.

Method used

Implement a ring buffer with transmission and reception control units that check for normal or abnormal virtual machines before writing data, ensuring data is only written if all receiving machines have received previous data, and adjusting flags to manage abnormal states.

Benefits of technology

Prevents data loss by ensuring all normal virtual machines receive data, avoids misjudging temporary abnormalities, and maintains communication without altering the hypervisor configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007707930000001
    Figure 0007707930000001
  • Figure 0007707930000002
    Figure 0007707930000002
  • Figure 0007707930000003
    Figure 0007707930000003
Patent Text Reader

Abstract

To provide a technique for communicating by reading out communication data written in a ring buffer on the basis of whether a virtual machine on a receiving side is normal or abnormal.SOLUTION: An electronic control device 10 includes a ring buffer 42, a transmission control section 34, and a reception control section 36. The ring buffer is set for each virtual machine that transmits communication data. The reception control section reads out communication data written in the ring buffer by the transmission control section. The transmission control section does not write the communication data at the next write-in position when the communication data that has not been received by a normal virtual machine exists at the next write-in position where the communication data is written in the ring buffer, and writes the communication data at the next write-in position when all virtual machines on a receiving side have received the communication data at the next write-in position or an abnormal virtual machine has not received the communication data at the next write-in position.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an electronic control device in which a plurality of virtual machines controlled by a hypervisor communicate with each other.

Background Art

[0002] An electronic control device in which a plurality of virtual machines controlled by a hypervisor communicate with each other is known. For example, Patent Document 1 below discloses a technique in which a virtual machine that has received communication data from a transmitting virtual machine generates parameters related to communication between virtual machines from the received communication data and determines whether the generated parameters are normal values. When the generated parameters are abnormal values, the virtual machine that has received the communication data determines that the communication is abnormal.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] When communicating between virtual machines, it is conceivable to set a ring buffer for storing communication data for each transmitting virtual machine, and for a plurality of receiving virtual machines to read the communication data written to the ring buffer and communicate.

[0005] However, since the receiving virtual machines operate independently, the timing at which the receiving virtual machines read communication data from the ring buffer is different. As a result, when communication data is written to the next write position of the ring buffer, there may be an un-received virtual machine that has not read the communication data already written to the next write position.

[0006] In this case, as a result of the inventor's detailed examination, it has been found that when new communication data is written to the following write position, there is no opportunity for the virtual machine that has not received the previous communication data to read it.

[0007] On the other hand, it is conceivable not to write communication data to the following write position until the virtual machine that has not received it reads the communication data at the following write position. In this case, if the virtual machine that has not received it malfunctions and cannot read the communication data at the following write position, the virtual machine on the transmission side cannot write communication data to the following write position. As a result, according to the inventor's detailed examination, it has been found that there is a problem that communication between the virtual machines on the other receiving side and the virtual machine on the transmission side becomes impossible.

[0008] In the technique described in Patent Document 1 mentioned above, such a problem is not considered. One aspect of the present disclosure desirably provides a technique for reading and communicating communication data written in a ring buffer based on whether the virtual machine on the receiving side is normal or abnormal.

Means for Solving the Problems

[0009] An electronic control device (10, 50) according to one aspect of the present disclosure is an electronic control device in which a plurality of virtual machines (30, 80) whose operations are controlled by a hypervisor (20, 60) communicate with each other, and includes a ring buffer (42, 68), a transmission control unit (34, 64, S400 to S410, S440, S442, S450 to S454), and a reception control unit (36, 66, S420 to S424, S430 to S434, S460 to S466).

[0010] The ring buffer is set for each virtual machine that transmits communication data. The transmission control unit writes the communication data to be transmitted into the ring buffer. The reception control unit reads the communication data written in the ring buffer by the transmission control unit.

[0011] When there is unreceived communication data of a normal virtual machine at the next write position where the transmission control unit writes communication data to the ring buffer, the transmission control unit does not write the communication data to the next write position, but checks whether all virtual machines on the receiving side have received the communication data at the next write position, or whether an abnormal virtual machine has not received the communication data at the next write position. If so, the transmission control unit writes the communication data to the next write position.

[0012] A computer program according to another aspect of the present disclosure causes a computer to function as the transmission control unit and the reception control unit of the electronic control device described above. According to such a configuration, when a normal virtual machine has not received the communication data at the next write position where the communication data is written, the communication data is not written to the next write position. Thereby, it is possible to suppress the disappearance of the communication data that has not been received by the normal virtual machine.

[0013] Also, when an abnormal virtual machine has not received the communication data at the next write position where the communication data is written, the communication data is written to the next write position. Thereby, the normal virtual machine can receive the communication data written to the next write position.

Brief Description of Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Mode for Carrying Out the Invention

[0015] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. [1. First Embodiment] [1-1. Configuration] The electronic control unit 10 shown in FIG. 1 is mounted on a vehicle, for example, and includes a hypervisor 20, virtual machines 30, and a shared memory 40. The electronic control unit is also abbreviated as ECU. The virtual machine is also abbreviated as VM. The ECU 10 virtualizes each of the functions of a plurality of ECUs with a VM 30 for each function of vehicle control such as body control and engine control, or for each position where it is installed in the vehicle, and integrates the plurality of ECUs.

[0016] The hypervisor 20 includes a VM control unit 22. The VM control unit 22 manages hardware resources such as CPUs and memories assigned to each VM 30, and controls the operations of the plurality of VMs 30. Further, the VM control unit 22 responds to various requests by hypervisor calls from the VMs 30.

[0017] For example, in the case of engine control, the VM 30 is a virtualization of one ECU that realizes each function such as injection amount control and ignition control by software. In FIG. 1, four VMs 30 are illustrated, but this is an example, and the number of VMs 30 is not limited to four.

[0018] Each VM 30 includes a processing unit 32, a transmission control unit 34, and a reception control unit 36. If it is the engine control described above, the processing unit 32 virtualizes and realizes each function such as injection amount control and ignition control. Further, the processing unit 32 makes various requests necessary for processing to the hypervisor 20 by means of a hypervisor call.

[0019] The transmission control unit 34 transmits communication data to other VMs 30 via the shared memory 40. The reception control unit 36 receives communication data from other VMs 30 via the shared memory 40. The shared memory 40 stores a ring buffer 42, data reference information 44, and an error flag 46.

[0020] One ring buffer 42 is set for each VM 30 that transmits communication data to other VMs 30. Hereinafter, the VM 30 that transmits communication data is also simply referred to as the transmitting VM 30, and the VM 30 that receives communication data is also simply referred to as the receiving VM 30.

[0021] The transmission control unit 34 of the transmitting VM 30 writes the communication data to be transmitted into the ring buffer 42, and one or more other receiving VMs 30 read and receive the communication data written into the ring buffer 42, whereby the VMs 30 communicate with each other.

[0022] The data reference information 44 is set for each transmitting VM 30, and has a write pointer for the transmitting VM 30, read pointers set for each of all other receiving VMs 30 that receive the communication data of the transmitting VM 30, and the number of failures for normal receiving VMs 30. Details of the number of failures for normal receiving VMs 30 will be described later.

[0023] The write pointer indicates, in the ring buffer 42 of each transmitting VM 30, the write position where the transmitting VM 30 writes communication data next after the latest write position where the communication data has been written. That is, the write pointer indicates the next write position where the transmitting VM 30 writes communication data.

[0024] The read pointer indicates, in the ring buffer 42 of each transmitting VM30, the read position at which each receiving VM30 reads communication data next after the latest read position where the communication data has been read. That is, the read pointer indicates the next read position at which each receiving VM30 reads communication data. Hereinafter, the write pointer is also abbreviated as WP, and the read pointer is also abbreviated as RP.

[0025] The error flag 46 is set for each receiving VM30 that receives the communication data of each transmitting VM30. If the error flag 46 is off, it indicates that the receiving VM30 is normal, and if it is on, it indicates that the receiving VM30 is abnormal.

[0026] [1-2. Processing] Next, the communication process executed by the ECU 10 will be described with reference to the flowcharts of FIGS. 2 and 3 and the schematic diagrams of FIGS. 4 and 5.

[0027] (1) Communication process of the transmitting VM30 The communication process shown in FIG. 2 is executed at the timing when the transmitting VM30 transmits communication data. In S400 of FIG. 2, the transmission control unit 34 of the transmitting VM30 determines whether there is un-received communication data of a normal receiving VM30 with the error flag 46 off at the write position of the ring buffer 42.

[0028] In FIG. 4, a ring buffer 42 capable of writing four communication data is illustrated. The write positions of the four communication data are indicated by d1~d4. The write direction of the ring buffer 42 is clockwise. In FIG. 4, VM#1 corresponds to RP1, VM#2 corresponds to RP2, and VM#3 corresponds to RP3.

[0029] In the upper part of FIG. 4, the transmission control unit 34 has written communication data to d1~d4, and the latest communication data has been written to d4. Therefore, the next write position of the ring buffer 42 is d1.

[0030] Also, in the upper part of FIG. 4, VM30 corresponding to VM#1 has received communication data d1 to d4, VM30 corresponding to VM#2 has received communication data d1 to d3, and VM30 corresponding to VM#3 has received communication data d1. That is, all receiving VM30s on the receiving side have received data A at the next write position d1 indicated by WP100.

[0031] And the abnormality flags 46 of VM30 corresponding to VM#1 to VM#3 are all off. That is, VM30 corresponding to VM#1 to VM#3 is normal. Therefore, as shown in the upper part of FIG. 4, when there is no unreceived communication data in the normal receiving VM30 with the abnormality flag 46 off at the next write position d1 of the ring buffer 42 indicated by WP100, the determination in S400 is No. In this case, in S402, the transmission control unit 34 writes communication data E at the next write position d1 as shown in the lower part of FIG. 4, updates WP100 to the next write position d2 for writing communication data, and ends this process.

[0032] On the contrary, as shown in the upper part of FIG. 5, when there is unreceived communication data B in the normal VM#3 corresponding to the next write position d2 indicated by WP100 with the abnormality flag 46 off, the determination in S400 is Yes.

[0033] In this case, in S404, the transmission control unit 34 increments the failure count for the normal receiving VM30 where unreceived communication data exists at the next write position. In S406, the transmission control unit 34 determines whether the failure count is equal to or more than a predetermined number. If the determination in S406 is No, that is, if the failure count is less than the predetermined number, the transmission control unit 34 determines that the abnormality of the corresponding receiving VM30 is not confirmed. In this case, the transmission control unit 34 does not write communication data at the next write position and ends this process.

[0034] If the determination in S406 is Yes, that is, when the number of failure times is equal to or greater than a predetermined number, in S408, the transmission control unit 34 determines that the abnormality of the corresponding normal receiving VM30 has been confirmed. In this case, as shown in the lower part of FIG. 5, the transmission control unit 34 writes the communication data F to the next writing position d2, and updates the WP100 to the writing position d3 where the next communication data will be written.

[0035] In S410, as shown in the lower part of FIG. 5, the transmission control unit 34 turns on the abnormality flag 46 of the VM30 corresponding to the VM#3 for which the abnormality has been confirmed, and clears the number of failure times. In addition, the transmission control unit 34 of the transmission VM30 may notify the receiving VM30 for which the abnormality has been confirmed of the abnormality, and cause the fail processing unit or the like of the receiving VM30 to execute fail processing.

[0036] (2) Communication processing of the receiving VM30 The communication processing shown in FIG. 3 is executed at the timing when the receiving VM30 receives communication data. In S420 of FIG. 3, the reception control unit 36 of the receiving VM30 determines whether the abnormality flag 46 of its own VM30 is on.

[0037] If the determination in S420 is No, that is, when the abnormality flag 46 of its own VM30 is off and its own VM30 is normal, in S422, the reception control unit 36 reads the communication data from the next reading position indicated by RP110. Then, the reception control unit 36 updates the RP110 of its own VM30 to the reading position where the next communication data will be read.

[0038] If the determination in S420 is Yes, that is, when the abnormality flag 46 of its own VM30 is on, since the reception control unit 36 is executing this process, it is determined that its own VM30 has returned from the abnormal state to the normal state.

[0039] In this case, in S424, the reception control unit 36 matches the RP110 of its own VM30 with the position indicated by the WP100 of the transmission VM30, and turns off the abnormality flag 46 of its own VM30. The reason for aligning the RP110 of the local VM30 with the position indicated by the WP100 of the transmitting VM30 is that the transmitting VM30 ignores the abnormal receiving VM30 and writes communication data to the ring buffer 42, so that the local VM30 does not receive the communication data written during the abnormal period of itself.

[0040] In addition, the reception control unit 36 may execute the process of S424 not at the reception timing of the local VM30, but prior to the process of S422 in a separate process when the local VM30 returns from the abnormal state to the normal state.

[0041] In the first embodiment, all VM30s are respectively provided with a transmission control unit 34 and a reception control unit 36, and execute the communication processes shown in FIGS. 2 and 3 described above. Therefore, each VM30 functions as a transmitting VM30 by writing communication data to the ring buffer 42 set for the local VM30. Also, each VM30 functions as a receiving VM30 by reading the communication data written to the ring buffer 42 set for other transmitting VM30s. That is, in the first embodiment, the VM30s communicate with each other by performing two-way transmission and reception.

[0042] In the first embodiment described above, S400 to S410 correspond to the processes of the transmission control unit, and S420 to S424 correspond to the processes of the reception control unit. [1-3. Effects] According to the first embodiment described above, the following effects can be obtained.

[0043] (1a) When there is unreceived communication data of a normal receiving VM30 for which the abnormal flag 46 is off and the abnormality is not confirmed at the next writing position where the transmitting VM30 writes communication data, the transmitting VM30 does not write communication data to the next writing position. Thereby, it is possible to suppress the disappearance of the communication data received by the receiving VM30 for which the abnormality is not confirmed.

[0044] (1b) When the transmission VM 30 has the abnormality flag 46 turned on, that is, when there is un-received communication data at the next write position in the reception VM 30 where the abnormality has been confirmed, the transmission VM 30 ignores the abnormal reception VM 30 and writes the communication data to the next write position. As a result, normal reception VMs 30 other than the abnormal reception VM 30 can receive the communication data transmitted by the transmission VM 30 without being made to wait for reception.

[0045] (1c) When the number of abnormalities is less than a predetermined number, the transmission VM 30 does not confirm the abnormality of the reception VM 30. Thereby, it is possible to avoid misjudging a VM 30 that has temporarily become a temporary abnormality as an abnormality.

[0046] (1d) Since the transmission VM 30 and the reception VM 30 communicate directly via the ring buffer 42, it is not necessary to change the configuration of the hypervisor 20 for communication between the VMs 30. Thereby, the transmission VM 30 and the reception VM 30 can communicate without depending on the configuration of the hypervisor 20.

[0047] [2. Second Embodiment] [2-1. Differences from the First Embodiment] In the second embodiment, since the basic configuration is the same as that of the first embodiment, the differences will be described below. Note that the same reference numerals as those in the first embodiment indicate the same configuration, and reference is made to the previous description.

[0048] In the first embodiment described above, the VM 30 performed writing of communication data to the ring buffer 42 and reading of communication data from the ring buffer 42. In contrast, in the second embodiment, in response to a request from the VM 80 shown in FIG. 6, the hypervisor 60 performs writing of communication data to the ring buffer 68 and reading of communication data from the ring buffer 68, which is different from the first embodiment.

[0049] [2-2. Configuration] The ECU 50 shown in FIG. 6 includes a hypervisor 60 and a VM 80. The hypervisor 60 includes a VM control unit 62, a transmission control unit 64, a reception control unit 66, a ring buffer 68, data reference information 70, and an error flag 72.

[0050] The ring buffer 68, the data reference information 70, and the error flag 72 are stored in a dedicated memory area set in the hypervisor 60. Since the ring buffer 68, the data reference information 70, and the error flag 72 have substantially the same configuration as the ring buffer 42, the data reference information 44, and the error flag 46 described in the first embodiment, the detailed configuration description is omitted.

[0051] Similar to the VM control unit 22 of the first embodiment, the VM control unit 62 manages hardware resources such as CPUs and memories assigned to each VM 80 and controls the operations of the plurality of VMs 80. In addition, the VM control unit 62 responds to various requests from the VM 30 by means of a hypervisor call. The various requests from the VM 30 include a transmission request for communication data and a reception request for communication data.

[0052] The VM 80 includes a processing unit 82. Similar to the processing unit 32 of the first embodiment, if it is engine control, the processing unit 82 realizes each function such as injection amount control and ignition control. In addition, the processing unit 82 makes various requests necessary for processing to the hypervisor 60 by means of a hypervisor call. The hypervisor call includes a transmission request for communication data and a reception request for communication data.

[0053] [2-3. Processing] Next, the communication process executed by the ECU 50 of the second embodiment will be described with reference to the flowchart of FIG. 7.

[0054] (1) Communication Process of the Transmission Control Unit 64 When the transmission control unit 64 of the hypervisor 60 receives a request to transmit communication data to another VM 80 from the transmission VM 80 by a hypervisor call, it executes substantially the same processing as the flowchart of FIG. 2 in the first embodiment. Therefore, the description of the communication processing executed by the transmission control unit 64 is omitted.

[0055] (2) Communication processing of the reception control unit 66 When the reception control unit 66 of the hypervisor 60 receives a request to receive communication data transmitted by the transmission VM 80 from the reception VM 80 by a hypervisor call, it executes the communication processing shown in FIG. 7.

[0056] In S430 of FIG. 7, the reception control unit 66 determines whether or not the abnormality flag 72 of the reception VM 80 that made the reception request is on. If the determination in S430 is No, that is, if the abnormality flag 72 of the reception VM 80 is off and the reception VM 80 is normal, in S432, the reception control unit 66 reads the communication data from the next read position indicated by the RP110 of the reception VM 30. Then, the reception control unit 66 updates the RP110 of the reception VM 80 to the next read position from which the communication data is to be read.

[0057] If the determination in S430 is Yes, that is, if the abnormality flag 72 of the reception VM 80 is on, since the reception control unit 66 has made a reception request by a hypervisor call, it is determined that the reception VM 80 has returned from the abnormal state to the normal state.

[0058] In this case, in S434, the reception control unit 66 matches the RP110 of the reception VM 80 with the position indicated by the WP100 of the transmission VM 80 and turns off the abnormality flag 72 of the reception VM 80. The reason for matching the RP110 of the reception VM 80 with the position indicated by the WP100 is that since the transmission VM 80 ignores the abnormal reception VM 80 and writes the communication data to the ring buffer 68, the communication data written while the reception VM 80 is abnormal is not received.

[0059] Further, the reception control unit 66 may execute the process of S434 not at the reception request timing from the reception VM 80, but prior to the process of S432 in a separate process when notified that the reception VM 80 has returned from an abnormal state to a normal state.

[0060] In the second embodiment described above, S430 to S434 correspond to the processes of the reception control unit. [2-4. Effects] According to the second embodiment described above, in addition to the effects (1a) to (1c) of the first embodiment described above, the following effects can be obtained.

[0061] (2a) The hypervisor 60 includes a transmission control unit 64 and a reception control unit 66, and controls writing of communication data to the ring buffer 68 and reading of communication data from the ring buffer 68 in response to a hypervisor call from the VM 80. As a result, since it is not necessary for the VM 80 to include a transmission control unit and a reception control unit for communication, the configuration of the VM 80 can be simplified.

[0062] [3. Third Embodiment] [3-1. Differences from the Second Embodiment] Since the basic configuration of the third embodiment is the same as that of the second embodiment, the differences will be described below. Note that the same reference numerals as those in the second embodiment denote the same configurations, and reference is made to the previous description.

[0063] In the second embodiment described above, when the hypervisor 60 receives a transmission request by a hypervisor call from the transmission VM 80, it executes the communication process of FIG. 2 in the same manner as in the first embodiment. That is, when the number of failures in which the hypervisor 60 cannot write communication data to the next write position because there is un-received communication data at the next write position in the normal reception VM 80 is equal to or more than a predetermined number of times, the hypervisor 60 turns on the abnormal flag 72 of the reception VM 80.

[0064] In contrast, in the third embodiment, when the receiving VM 80 does not receive communication data for a predetermined time or longer, the receiving VM 80 is determined to be abnormal, and the abnormality flag 72 of the receiving VM 80 is turned on, which is different from the second embodiment.

[0065] Therefore, the data reference information 70 of the third embodiment has an unreceived time during which the receiving VM 80 does not receive communication data for the normal receiving VM 30 in which unreceived communication data exists at the next write position, instead of the number of failure times when communication data cannot be written at the next write position.

[0066] [3-2. Processing] Next, the communication process executed by the ECU 50 of the third embodiment will be described using the flowcharts of FIGS. 8 to 10.

[0067] (1) Communication Process of Transmission Control Unit 64 The communication process in FIG. 8 is executed when the transmission control unit 64 of the hypervisor 60 receives a request to transmit communication data to another VM 80 from the transmission VM 80 by a hypervisor call.

[0068] In S440 of FIG. 8, the transmission control unit 64 determines whether there is unreceived communication data in the next write position of the ring buffer 68 for a normal receiving VM 80 whose abnormality flag 72 is off.

[0069] If the determination in S440 is No, that is, when there is no unreceived communication data in the next write position for the normal receiving VM 80, in S442, the transmission control unit 64 writes the communication data at the next write position indicated by WP100. Then, the transmission control unit 64 updates WP100 to the next write position for writing communication data and ends this process.

[0070] If the determination in S440 is Yes, that is, when there is unreceived communication data in the next write position for the normal receiving VM 80, the transmission control unit 64 does not write the communication data at the next write position and ends this process.

[0071] (2) Other communication processes of the transmission control unit 64 The transmission control unit 64 executes the communication process of FIG. 9 at predetermined time intervals. In S450 of FIG. 9, the transmission control unit 64 updates by adding the current predetermined time interval to the non-reception time during which each receiving VM80 does not receive communication data.

[0072] In S452, the transmission control unit 64 determines whether there is a receiving VM80 whose non-reception time has reached a predetermined value or more. If the determination in S452 is No, that is, if there is no receiving VM80 whose non-reception time has reached a predetermined value or more, this process ends.

[0073] If the determination in S452 is Yes, that is, if there is a receiving VM80 whose non-reception time has reached a predetermined value or more, in S454, the transmission control unit 64 turns on the abnormality flag 72 of the receiving VM80 whose non-reception time has reached a predetermined value or more. That is, the transmission control unit 64 determines that the receiving VM80 whose non-reception time has reached a predetermined value or more is abnormal.

[0074] (3) Communication process of the reception control unit 66 When the reception control unit 66 of the hypervisor 60 receives a request to receive communication data transmitted by the transmission VM80 from the receiving VM80 by a hypervisor call, it executes the communication process shown in FIG. 10.

[0075] Since the processes of S462 to S466 in FIG. 10 are substantially the same as the processes of S430 to S434 in FIG. 7, the description is omitted. In S460 of FIG. 10, the reception control unit 66 clears the non-reception time of the receiving VM80 that has received the reception request. This is because it can be determined that the receiving VM80 that has received the reception request by the reception control unit 66 is normal.

[0076] In the third embodiment described above, S440, S442, S450 to S454 correspond to the processes of the transmission control unit, and S460 to S466 correspond to the processes of the reception control unit. [3-3. Effects] According to the third embodiment described above, effects similar to those of the second embodiment described above can be obtained.

[0077] [4. Other Embodiments] As described above, the embodiments of the present disclosure have been described. However, the present disclosure is not limited to the embodiments described above and can be implemented in various modifications.

[0078] (4a) In the above-described embodiments, the in-vehicle ECUs 10 and 50 have been exemplified, but the present invention is not limited thereto. Any ECU used in any field may be used as long as it is an ECU in which a plurality of virtual machines communicate with each other.

[0079] (4b) In the above-described embodiments, WP100 indicates the next write position of communication data, and RP110 indicates the next read position of communication data. In contrast, WP100 may indicate the latest write position where communication data has been written, and RP110 may indicate the latest read position where communication data has been read.

[0080] In this case, the communication data is written to the write position next to the write position indicated by WP100 and read from the read position next to the read position indicated by RP110. (4c) In the first embodiment described above, each VM30 of the ECU 10 includes both a transmission control unit 34 and a reception control unit 36, and a ring buffer 42 is set for each VM30. With this configuration, each VM30 executes transmission by writing communication data to the ring buffer 42 for its own VM30, and executes reception by reading the communication data written to the ring buffer 42 for other VM30s, and communicates bidirectionally with each other.

[0081] In contrast, at least one VM30 may include only either the transmission control unit 34 or the reception control unit 36 and execute only either transmission or reception. The ring buffer 42, data reference information 44, and error flag 46 for the transmission VM30 are not set in the VM30 including only the reception control unit 36.

[0082] (4d) In the above-described third embodiment, in the flowchart of FIG. 9, the un-received time of the receiving VM 80 was updated by software, and in the flowchart of FIG. 10, the un-received time of the receiving VM 80 that made a reception request was cleared by software. In contrast, the un-received time of the receiving VM 80 may be measured by a hardware timer.

[0083] (4e) The ECUs 10, 50 and the method described in the present disclosure may be implemented by a dedicated computer provided by configuring a processor and a memory programmed to execute one or more functions embodied by a computer program. Alternatively, the ECUs 10, 50 and the method described in the present disclosure may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits. Or, the ECUs 10, 50 and the method described in the present disclosure may be implemented by one or more dedicated computers configured by a combination of a processor and a memory programmed to execute one or more functions and a processor configured by one or more hardware logic circuits. Further, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by a computer. The method for realizing the functions of each part included in the ECUs 10, 50 does not necessarily include software, and all of its functions may be realized using one or more hardware.

[0084] (4f) The multiple functions of one component in the foregoing embodiments may be realized by a plurality of components, or one function of one component may be realized by a plurality of components. Also, the multiple functions of a plurality of components may be realized by one component, or one function realized by a plurality of components may be realized by one component. Further, a part of the configuration of the foregoing embodiments may be omitted. Still further, at least a part of the configuration of the foregoing embodiments may be added to or replaced with the configuration of other foregoing embodiments.

[0085] (4g) In addition to the foregoing ECUs 10 and 50, the present disclosure can also be realized in various forms such as a system including the ECUs 10 and 50 as components, a program for causing a computer to function as the ECUs 10 and 50, a non-transitory physical recording medium such as a semiconductor memory storing this program, and a communication method.

Explanation of Reference Numerals

[0086] 10, 50: ECU (Electronic Control Unit), 20, 60: Hypervisor, 30, 80: VM (Virtual Machine), 34, 64: Transmission Control Unit, 36, 66: Reception Control Unit, 42, 68: Ring Buffer, 46, 72: Abnormality Flag

Claims

1. An electronic control device (10, 50) in which a plurality of virtual machines (30, 80) controlled by a hypervisor (20, 60) communicate with each other, a ring buffer (42, 68) set for each of the virtual machines that transmits communication data, a transmission control unit (34, 64, S400 to S410, S440, S442, S450 to S454) configured to write the communication data to be transmitted into the ring buffer, a reception control unit (36, 66, S420 to S424, S430 to S434, S460 to S466) configured to read the communication data written into the ring buffer by the transmission control unit, comprising: when there is unreceived communication data of a normal virtual machine at the next write position to which the transmission control unit writes the communication data into the ring buffer, the transmission control unit does not write the communication data to the next write position, and whether all the virtual machines on the reception side have received the communication data at the next write position, or whether an abnormal virtual machine has not received the communication data at the next write position, the transmission control unit is configured to write the communication data to the next write position. Electronic control device.

2. The electronic control device according to claim 1, when the transmission control unit (S404 to S410) is unable to write the communication data to the next write position a predetermined number of times or more for the virtual machine in which there is unreceived communication data at the next write position, the transmission control unit is configured to determine the virtual machine in which there is unreceived communication data at the next write position as abnormal. Electronic control device.

3. The electronic control device according to claim 1, when the transmission control unit (S450 to S454) is unable to write the communication data to the next write position for a predetermined time or more for the virtual machine in which there is unreceived communication data at the next write position, the transmission control unit is configured to determine the virtual machine in which there is unreceived communication data at the next write position as abnormal. Electronic control device.

4. The electronic control device according to any one of claims 1 to 3, When the abnormal virtual machine becomes normal, the reception control unit (S424, S434, S466) is configured to match the latest read position of the ring buffer indicating that the normal virtual machine has received the communication data with the latest write position where the communication data is written in the ring buffer. Electronic control device.

5. The electronic control device according to any one of claims 1 to 4, An abnormality flag (46, 72) indicating normal or abnormal is provided for each of the virtual machines. Electronic control device.

6. The electronic control device (10) according to any one of claims 1 to 5, The virtual machine (30) that transmits the communication data includes the transmission control unit (34), and the virtual machine (30) that receives the communication data includes the reception control unit (36). Electronic control device.

7. The electronic control device (50) according to any one of claims 1 to 5, The hypervisor includes the transmission control unit (64) and the reception control unit (66). Electronic control device.

8. An electronic control device (10, 50) in which a plurality of virtual machines (30, 80) whose operations are controlled by a hypervisor (20, 60) communicate with each other, A transmission control unit (34, 64, S400 to S410, S440, S442, S450 to S454) configured to write the communication data to be transmitted into a ring buffer (42, 68) set for each virtual machine that transmits the communication data, A reception control unit (36, 66, S420 to S424, S430 to S434, S460 to S466) configured to read the communication data written in the ring buffer by the transmission control unit, Comprising, When there is unreceived communication data of a normal virtual machine at the next write position where the transmission control unit writes the communication data to the ring buffer, the transmission control unit does not write the communication data to the next write position, but whether all the virtual machines on the receiving side have received the communication data at the next write position, or whether the abnormal virtual machine has not received the communication data at the next write position. If so, the communication data is configured to be written to the next write position. A computer program that causes a computer to function as the transmission control unit and the reception control unit of the electronic control device.

Citation Information

Patent Citations

  • Method for both exchanging states and detecting failure of duplex system

    JP2002373084A

  • Method, apparatus, and system for managing data flow of processing nodes in a self-driving vehicle

    JP2018531436A

  • Information processor, abnormality detection method, and computer program

    JP2021090160A

  • On-vehicle control device, control method, and computer program

    JP2023087414A