Electronic control device

The electronic control device with independent storage units and fail-safe operations addresses the safety issue during control software switching, ensuring system stability through monitored fail-safe measures.

JP7711582B2Active Publication Date: 2025-07-23DENSO CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021204330
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-07-23
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

Existing systems fail to ensure the safety of the system during the switching process of control software between storage units in an electronic control device.

Method used

An electronic control device with independent storage units and a security unit that performs fail-safe operations to ensure system safety during software switching, using detection units to monitor the switching process and initiate safety measures as needed.

Benefits of technology

The system ensures appropriate safety during control software switching by initiating fail-safe operations when necessary, quickly releasing safety measures upon normal completion or return to a stable state, thereby preventing system failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711582000001
    Figure 0007711582000001
  • Figure 0007711582000002
    Figure 0007711582000002
  • Figure 0007711582000003
    Figure 0007711582000003
Patent Text Reader

Abstract

To properly guarantee the safety of a system in switch processing of switching control software to used.SOLUTION: An electronic controller 1 includes: a first storage unit 3a for storing control software; a second storage unit 3b for storing control software; a software switch unit 2b for performing switch processing of switching the control software to use from control software stored in one of the first storage unit and the second storage unit to control software stored in the other; a safety guarantee unit 4 for performing a safety guarantee operation of guaranteeing the safety of the system; and a software switch detection unit 2e of starting the safety guarantee operation when detecting the start of the switch processing.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an electronic control device.

Background Art

[0002] For example, in an in-vehicle electronic control device, control software (hereinafter referred to as control software) is configured to be updatable for the purpose of improving functions and eliminating defects. When updating the control software, it is required to ensure the safety of the system. For example, Patent Document 1 discloses a configuration that detects the update status of the control software and restricts the operating function based on the state of the control software.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In a two-sided configuration having a first storage unit and a second storage unit as storage areas for storing control software, while using the control software stored in either the first storage unit or the second storage unit, by writing the update data of the new control software to the other, the control software stored in the other is updated. Then, when the switching condition is satisfied, a switching process is performed to switch the control software to be used from the control software stored in one to the control software stored in the other. In this case, it is required to ensure the safety of the system even during the switching process, but with the configuration of Patent Document 1 described above, the safety of the system during the switching process cannot be ensured.

[0005] The present invention has been made in view of the above circumstances, and an object thereof is to provide an electronic control device capable of appropriately ensuring the safety of the system during a switching process of switching the control software to be used.

Means for Solving the Problem

[0006] According to the invention described in claim 1, the first storage unit (3a) can store control software. The second storage unit (3b) can store control software. The software switching unit (2b) performs a switching process of switching the control software to be used from the control software stored in either one of the first storage unit and the second storage unit to the control software stored in the other. The security unit (4) performs a security operation to ensure the security of the system as fail-safe to perform is possible . When the software switching detection unit (2e) detects the start of the switching process, it starts the security operation.

[0007] When the software switching detection unit detects the start of the switching process of switching the control software to be used from the control software stored in either one of the first storage unit and the second storage unit to the control software stored in the other, the security operation by the security unit as fail-safe is started. The security of the system can be appropriately ensured during the switching of the control software to be used.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Modes for Carrying Out the Invention

[0009] Hereinafter, a plurality of embodiments will be described with reference to the drawings. In subsequent embodiments, the description of parts overlapping with the preceding embodiments may be omitted. (First Embodiment) The first embodiment will be described with reference to FIGS. 1 to 3. The electronic control unit (ECU) 1 is, for example, an in-vehicle electronic control unit mounted on a vehicle, such as a device for controlling a drive system, a device for controlling an ADAS (Advanced Driving Assistant System), a device for controlling a multimedia system, or the like.

[0010] The electronic control device 1 includes a control unit 2, a storage unit 3, and a security unit 4. The control unit 2 is mainly composed of a microcomputer (hereinafter referred to as a microcontroller) having a CPU, a ROM, a RAM, an I / O, etc., and executes a process corresponding to a computer program by executing a computer program stored in a non-transitory tangible storage medium, thereby controlling the operation of the electronic control device 1.

[0011] The storage unit 3 includes a first storage unit 3a, a second storage unit 3b, and a third storage unit 3c. The first storage unit 3a and the second storage unit 3b can each store control software. The third storage unit 3c can store switching detection software. Each of the storage units 3a to 3c is independent, and the control software stored in the first storage unit 3a, the control software stored in the second storage unit 3b, and the switching detection software stored in the third storage unit 3c can be started without being affected by other software and without affecting other software.

[0012] The control unit 2 includes a normal control processing unit 2a, a software switching unit 2b, a microcomputer monitoring unit 2c, a microcomputer monitoring transmission unit 2d, and a software switching detection unit 2e. The normal control processing unit 2a selectively uses the control software stored in either the first storage unit 3a or the second storage unit 3b. When the normal control processing unit 2a is using the control software stored in one of the first storage unit 3a and the second storage unit 3b, it is possible to write the update data of the new control software to the other, and by writing the update data of the new control software to the other, the control software stored in the other can be updated. In this case, the update data of the control software may be acquired wirelessly from the center device by the electronic control device 1 connecting wirelessly to the center device on the communication network side, or may be acquired by wire communication from the diagnostic tool by the electronic control device 1 connecting wired to the diagnostic tool.

[0013] The software switching unit 2b monitors the establishment of the switching condition. When the switching condition is established while the software switching unit 2b is using the control software stored in either the first storage unit 3a or the second storage unit 3b, the software switching unit 2b performs a switching process of switching the control software to be used from the control software stored in one to the control software stored in the other. The switching condition is, for example, that the user has performed an approval operation for software switching, that the written update data is normal data that has not been tampered with, that the remaining amount of the battery that supplies the operating power to the electronic control device 1 is equal to or greater than a predetermined capacity, and the like.

[0014] The microcomputer monitoring unit 2c monitors the operating state of the control unit 2, and outputs a normal notification to the microcomputer monitoring transmission unit 2d while detecting that the operating state of the control unit 2 is normal. When detecting that the operating state of the control unit 2 is abnormal, the microcomputer monitoring unit 2c outputs an abnormal notification to the microcomputer monitoring transmission unit 2d. The microcomputer monitoring transmission unit 2d outputs a normal notification to the security unit 4 while detecting the input of a normal notification from the microcomputer monitoring unit 2c, and stops the output of the normal notification when detecting the input of an abnormal notification from the microcomputer monitoring unit 2c.

[0015] The safety assurance unit 4 can perform a failsafe as a safety assurance operation for ensuring the safety of a system including the electronic control unit 1 as one node. The failsafe is an operation for ensuring the safety of the system when, for example, a failure due to malfunction occurs in the system. If the electronic control unit 1 is a device that controls the drive system, for example, an actuator cut is performed to ensure the safety of the system. If the electronic control unit 1 is a device that controls the multimedia system, for example, a function limit such as reducing the amount of information displayed to the driver is performed to ensure the safety of the system. The safety assurance unit 4 waits without starting the failsafe while detecting the input of a normal notification from the microcomputer monitoring transmission unit 2d, and starts the failsafe when the input of the normal notification from the microcomputer monitoring transmission unit 2d is no longer detected. After starting the failsafe, the safety assurance unit 4 ends the failsafe when the detection of the input of the normal notification from the microcomputer monitoring transmission unit 2d is resumed.

[0016] In the present embodiment, not only when a failure due to malfunction occurs in the above-described system, but also during the execution of a switching process for switching the control software to be used, the failsafe is configured to be executed.

[0017] The software switching detection unit 2e activates the switching detection software stored in the third storage unit 3c to monitor the software switching unit 2b, and detects the start of the switching process, the normal end of the switching process, and the occurrence of an abnormality during the switching process. When the software switching detection unit 2e detects the start of the switching process, it outputs a switching start notification to the safety assurance unit 4. When the safety assurance unit 4 detects the input of the switching start notification from the software switching detection unit 2e, it starts the failsafe in the same manner as when the input of the normal notification from the above-described microcomputer monitoring transmission unit 2d is no longer detected.

[0018] When the software switch detection unit 2e detects the normal completion of the switching process, it outputs a switching normal completion notification to the security unit 4. When the security unit 4 detects the input of the switching normal completion notification from the software switch detection unit 2e, it ends the fail-safe. When the software switch detection unit 2e detects an abnormality during the switching process, it waits for a return to the state before the switching process starts. When it detects a normal return to the state before the switching process starts, it outputs a switching normal return notification to the security unit 4. When the security unit 4 detects the input of the switching normal return notification from the software switch detection unit 2e, it ends the fail-safe.

[0019] Next, the operation of the above-described configuration will be described with reference to FIGS. 2 to 3. When the control unit 2 starts the start determination process for determining the start of the switching process, it determines whether or not the switching process has been started (S1). When the control unit 2 determines that the switching condition is not satisfied and the switching process has not been started (S1: NO), it ends the start determination process and waits for the start of the next start determination process.

[0020] When the control unit 2 determines that the switching condition is satisfied and the switching process has been started (S1: YES), it outputs a switching start notification to the security unit 4 (S2) and causes the security unit 4 to start the fail-safe (S3). When the control unit 2 causes the security unit 4 to start the fail-safe, it determines whether or not the switching process has been normally completed and determines whether or not an abnormality has occurred during the switching process (S4, S5).

[0021] When the control unit 2 determines that the switching process has been normally completed without an abnormality occurring during the switching process (S4: YES), it outputs a switching normal completion notification to the security unit 4 (S6), causes the security unit 4 to end the fail-safe (S7), and ends the start determination process. On the other hand, when the control unit 2 determines that an abnormality has occurred during the switching process without the switching process being normally completed (S5: YES), it performs a return to the state before the switching process starts (S8). When the control unit 2 normally returns to the state before the switching process starts, it outputs a switching normal return notification to the security unit 4 (S9), causes the security unit 4 to end the fail-safe (S7), and ends the start determination process.

[0022] By performing the above-described processes, the control unit 2 appropriately ensures the safety of the system during the switching of the control software to be used, as shown in FIG. 3. In FIG. 3, the case is illustrated where fail-safe is implemented during the switching process of writing the update data of the control software into the second storage unit 2b and switching the control software to be used from the control software stored in the first storage unit 2a to the control software stored in the second storage unit 2b. However, the same applies to the case of writing the update data of the control software into the first storage unit 2a and switching the control software to be used from the control software stored in the second storage unit 2b to the control software stored in the first storage unit 2a.

[0023] As described above, according to the first embodiment, the following operational effects can be obtained. In the electronic control unit 1, when detecting the start of the switching process for switching the control software to be used, the fail-safe by the safety guarantee unit 4 is started. The safety of the system can be appropriately ensured during the switching of the control software to be used.

[0024] When detecting the normal end of the switching process, the fail-safe by the safety guarantee unit 4 is ended. When the switching of the control software to be used is normally ended, the fail-safe can be quickly released.

[0025] When detecting an abnormality during the switching process, it waits for a return to the state before starting the switching process. When detecting a normal return to the state before starting the switching process, the fail-safe by the safety guarantee unit 4 is ended. Even when an abnormality occurs during the switching process, if a normal return to the state before starting the switching process is achieved, the fail-safe can be quickly released.

[0026] The switching detection software stored in the third storage unit 3c is activated to detect the start of the switching process. The switching detection software can be activated without being affected by the control software and without affecting the control software, and the start of the switching process can be appropriately detected.

[0027] (Second Embodiment) The second embodiment will be described with reference to FIG. 4. In the first embodiment, the soft switching detection unit 2e outputs a switching start notification, a switching normal end notification, and a switching normal return notification to the security unit 4. However, in the second embodiment, the soft switching detection unit 2e outputs a switching start notification, a switching normal end notification, and a switching normal return notification to the microcomputer monitoring transmission unit 2d.

[0028] When the microcomputer monitoring transmission unit 2d detects the input of a switching start notification from the soft switching detection unit 2e, it stops outputting a normal notification. When the security unit 4 no longer detects the input of a normal notification from the microcomputer monitoring transmission unit 2d, it starts fail-safe. When the microcomputer monitoring transmission unit 2d detects the input of a switching normal end notification or a switching normal return notification from the soft switching detection unit 2e, it resumes outputting a normal notification. When the security unit 4 detects the input of a normal notification from the microcomputer monitoring transmission unit 2d, it ends fail-safe.

[0029] Also in the second embodiment, when the electronic control unit 1 detects the start of a switching process for switching the control software to be used, it starts fail-safe by the security unit 4. The safety of the system can be appropriately ensured during the switching of the control software to be used. Note that, instead of stopping the output of a normal notification when the microcomputer monitoring transmission unit 2d detects the input of a switching start notification from the soft switching detection unit 2e, the microcomputer monitoring transmission unit 2d may output an abnormal notification to the security unit 4, and when the security unit 4 detects the input of an abnormal notification from the microcomputer monitoring transmission unit 2d, it may start fail-safe.

[0030] (Other Embodiments) Although the present disclosure has been described based on examples, it is understood that it is not limited to the examples and structures. The present disclosure includes various modifications and modifications within an equivalent range. In addition, various combinations and forms, and further other combinations and forms including only one element, more than one element, or less than one element thereof, fall within the scope and spirit of the present disclosure.

[0031] The first embodiment and the second embodiment may be combined. That is, the soft switching detection unit 2e may be configured to output the switching start notification, the switching normal end notification, and the switching normal return notification to both the security unit 4 and the microcomputer monitoring transmission unit 2d. By adopting a redundant configuration, for example, even if an abnormality occurs in either the data transmission from the soft switching detection unit 2e to the security unit 4 or the data transmission from the soft switching detection unit 2e to the microcomputer monitoring transmission unit 2d, a fail-safe during the switching process of switching the control software to be used can be appropriately implemented.

[0032] The control unit and its method described in the present disclosure may be realized by a dedicated computer configured by a processor and a memory programmed to execute one or more functions embodied by a computer program. Alternatively, the control unit and its method described in the present disclosure may be realized by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits. Or, the control unit and its method described in the present disclosure may be realized by one or more dedicated computers configured by a combination of a processor and a memory programmed to execute one or more functions and a processor configured by one or more hardware logic circuits. Further, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by a computer.

Explanation of Reference Numerals

[0033] In the drawings, 1 is an electronic control device, 2 is a control unit, 2b is a soft switching unit, 2e is a soft switching detection unit, 3a is a first storage unit, 3b is a second storage unit, 3c is a third storage unit, and 4 is a security unit.

Claims

1. a first storage unit (3a) capable of storing control software; a second storage unit (3b) capable of storing control software; a software switching unit (2b) that performs a switching process of switching the control software to be used from the control software stored in either one of the first storage unit and the second storage unit to the control software stored in the other; a security unit (4) capable of performing a fail-safe as a security operation for ensuring the security of the system; an electronic control device comprising: a software switching detection unit (2e) that starts the security operation when detecting the start of the switching process.

2. The electronic control device according to claim 1, wherein the software switching detection unit ends the security operation when detecting normal completion of the switching process.

3. The electronic control device according to claim 1 or 2, wherein when the software switching detection unit detects an abnormality during the switching process, it waits for a return to the state before the switching process is started, and when detecting a normal return to the state before the switching process is started, it ends the security operation.

4. comprising a third storage unit (3c) different from both the first storage unit and the second storage unit; The electronic control device according to any one of claims 1 to 3, wherein the software switching detection unit activates switching detection software stored in the third storage unit and detects the start of the switching process.

Citation Information

Patent Citations

  • Software management apparatus

    JP2010125925A

  • Software update apparatus, software update system and software update method

    JP2018200510A

  • Mobility control system, method, and program

    WO2021024589A1