STORAGE ABNORMALITY DETECTION DEVICE, STORAGE ABNORMALITY DETECTION METHOD, AND STORAGE ABNORMALITY DETECTION PROGRAM
The storage abnormality detection device addresses premature memory lifespan judgments by checking uncorrectable errors and warranty conditions, ensuring effective memory use by accurately detecting abnormalities.
Patent Information
- Application Number
- JP2022161973
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-06
- Publication Date
- 2025-08-20
- Estimated Expiration
- 2042-10-06
AI Technical Summary
Existing memory detection methods determine abnormality based on the total amount of data written, leading to premature judgment of memory lifespan expiration, even when the memory is still usable.
A storage abnormality detection device that checks for uncorrectable errors and predetermined conditions, such as product warranty period or distance, to accurately determine memory abnormalities beyond the total write amount.
This approach allows for more effective use of memory by accurately detecting abnormalities based on uncorrectable errors and warranty conditions, preventing premature memory degradation determination.
Smart Images

Figure 0007726171000001 
Figure 0007726171000002 
Figure 0007726171000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a storage abnormality detection device, a storage abnormality detection method, and a storage abnormality detection program. [Background technology]
[0002] Patent document 1 proposes an electronic control device that includes a processing unit that writes data for which a write execution condition is met into a data storage area of a memory, a means that counts the number of writes to memory for each piece of data written to memory for each operating period of the processing unit, a means that, when an operation stop condition is met, adds the maximum number of writes counted during the current operating period to the value stored in the memory's count storage area before the processing unit stops operating, updates the value obtained by adding the maximum number of writes counted during the current operating period to the value stored in the memory's count storage area, and writes this value into the count storage area as the maximum number of writes, and a means that determines whether the memory's lifespan has expired based on the maximum number of writes stored in the count storage area. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-170604 Summary of the Invention [Problem to be solved by the invention]
[0004] A memory with a limit on the total amount of data written can be written to without any problems even if data is written to the memory up to a preset limit such as TBW (Total Bytes Written). The limit on the total amount of data written is set for safety reasons, so if the memory is judged to have reached the end of its life when the limit is reached, as in Patent Document 1, it will be judged to have an abnormality in the memory due to its lifespan even though it is still usable.
[0005] The present invention has been made in consideration of the above facts, and aims to provide a storage abnormality detection device, a storage abnormality detection method, and a storage abnormality detection program that can make more effective use of memory than when determining abnormalities based on the total amount of writing. [Means for solving the problem]
[0006] A storage abnormality detection device according to a first aspect includes a memory having a limit on the total amount of data written, and a correction unit that detects and corrects errors that occur in the memory and detects uncorrectable errors a predetermined number of times or more within a predetermined period. and satisfying a predetermined condition related to the memory or the vehicle in which the memory is installed. and a determination unit that determines that the memory is abnormal when the error occurs.
[0007] According to the first aspect, the correction unit detects and corrects an error that occurs in a memory that has a limit on the total amount of data that can be written.
[0008] The determination unit detects an error that cannot be corrected by the correction unit a predetermined number of times or more within a predetermined period. and satisfying a predetermined condition related to the memory or the vehicle in which the memory is installed. In this way, by checking for uncorrectable errors, it is possible to determine whether writing is actually possible and then determine whether there is an abnormality, which allows for more effective use of the memory than when determining an abnormality based on the total amount of writing.
[0009] The storage abnormality detection device of the second aspect is the storage abnormality detection device of the first aspect, in which the judgment unit judges that there is an abnormality in the memory when the judgment unit detects an error that cannot be corrected by the correction unit a predetermined number of times or more within a predetermined period and the total amount of writing to the memory is equal to or greater than a predetermined upper limit value.
[0010] According to the second aspect, since the total write amount is checked in addition to checking for uncorrectable errors, it is possible to accurately determine whether a memory is abnormal compared to when determining an abnormality by checking only one of the two.
[0011] A storage abnormality detection device according to a third aspect is a storage abnormality detection device according to the first aspect, wherein the judgment unit judges that an abnormality has occurred in the memory when an error that cannot be corrected by the correction unit is detected a predetermined number of times or more within a predetermined period and the predetermined product warranty period or a predetermined product warranty distance is exceeded.
[0012] According to the third aspect, in addition to checking for uncorrectable errors, the product warranty period or product warranty distance is checked, making it possible to accurately determine memory abnormalities compared to when determining abnormalities by checking only one of the two.
[0013] The storage abnormality detection device according to the fourth aspect is the storage abnormality detection device according to any one of the first to third aspects, and further includes a notification unit that notifies of an abnormality in the memory when the determination unit determines that there is an abnormality in the memory, when the memory is used for a function related to vehicle operation, a function related to regulations, or a function related to security.
[0014] According to the fourth aspect, when the memory is used for a function related to vehicle operation, a function related to regulations, or a function related to security, if an abnormality is detected, replacement of the memory can be immediately recommended.
[0015] A storage abnormality detection device according to a fifth aspect is a storage abnormality detection device according to the second aspect, wherein the judgment unit checks the total amount of writing to the memory before performing a write operation to the memory, and if the total amount of writing to the memory is less than a predetermined upper limit and the correction unit detects an uncorrectable error a predetermined number of times or more within a predetermined period, the judgment unit judges that the abnormality is due to a factor other than the limit.
[0016] According to the fifth aspect, it is possible to detect abnormalities caused by factors other than abnormalities in writing to the memory.
[0017] A storage abnormality detection device according to a sixth aspect includes a computer, a correction unit that detects and corrects errors that occur in a memory having a limit on the total amount of data written, and detects an uncorrectable error by detecting the uncorrectable error a predetermined number of times or more within a predetermined period. and satisfying a predetermined condition related to the memory or the vehicle in which the memory is installed. If this occurs, the process determines that the memory is abnormal.
[0018] According to the sixth aspect, it is possible to provide a storage abnormality detection method that can make more effective use of memory than when determining an abnormality based on the total amount of writing.
[0019] A storage abnormality detection program according to a seventh aspect includes a program for causing a computer to detect an uncorrectable error by a correction unit that detects and corrects errors that occur in a memory having a limit on the total write amount, and detecting the uncorrectable error a predetermined number of times or more within a predetermined period. and satisfying a predetermined condition related to the memory or the vehicle in which the memory is installed. If this occurs, a process is executed to determine that the memory is abnormal.
[0020] According to the seventh aspect, it is possible to provide a storage abnormality detection program that can use memory more effectively than when determining an abnormality based on the total amount of writing. [Effects of the Invention]
[0021] As described above, according to the present invention, it is possible to provide a storage abnormality detection device, a storage abnormality detection method, and a storage abnormality detection program that can make more effective use of memory than when determining an abnormality based on the total amount of writing. [Brief explanation of the drawings]
[0022] [Figure 1] 1 is a diagram showing a schematic configuration of a vehicle control system according to an embodiment of the present invention; [Figure 2] FIG. 1 is a block diagram showing an example of the configuration of a microcomputer. [Figure 3] FIG. 2 is a block diagram showing a storage controller and a flash memory included in the central ECU. [Figure 4]5 is a flowchart showing an example of the flow of processing performed by a storage controller of a central ECU in the vehicle control system according to the first embodiment. [Figure 5] 10 is a flowchart showing an example of the flow of processing performed by a storage controller of a central ECU in a vehicle control system according to a second embodiment. [Figure 6] 11 is a flowchart showing an example of the flow of processing performed by a storage controller of a central ECU in a vehicle control system according to a third embodiment. [Figure 7] 10 is a flowchart showing an example of the flow of processing performed by a storage controller of a central ECU in a vehicle control system according to a fourth embodiment. [Figure 8] 10 is a flowchart showing the process flow of the connection point A. DETAILED DESCRIPTION OF THE INVENTION
[0023] An example of an embodiment of the present invention will be described in detail below with reference to the drawings. In this embodiment, a vehicle control system mounted on a vehicle will be described as an example. Fig. 1 is a diagram showing a schematic configuration of the vehicle control system according to this embodiment.
[0024] A vehicle control system 10 according to this embodiment includes a central ECU (Electronic Control Unit) 12 that controls the entire vehicle, as shown in Fig. 1. The central ECU 12 functions as an example of a storage abnormality detection device.
[0025] A plurality of ECUs and a DCM (Data Communication Module) 20 are connected to the central ECU 12. Examples of the plurality of ECUs connected include a multimedia ECU 14, a meter ECU 16, and an advanced driving assistance ECU 18.
[0026] The multimedia ECU 14 controls a plurality of media such as text, audio, still images, and video. The multimedia ECU 14 performs processing to acquire images captured by a camera or the like, process the acquired images, and display them on a display, meter, etc. Specifically, during parking, the multimedia ECU 14 processes the images captured by the camera into images viewed from above the vehicle, and displays them on a display.
[0027] The meter ECU 16 performs processing to display multiple meters on a meter display installed on the instrument panel and to display various vehicle information. Furthermore, if an abnormality or the like occurs in the vehicle, the meter ECU 16 notifies the occupant by displaying the occurrence of the abnormality on the meter display.
[0028] The advanced driving assistance ECU 18 has the function of acquiring surrounding information detected by various sensors such as cameras and radars that monitor the surroundings, providing the surrounding information to other ECUs, and controlling the steering and braking if necessary.
[0029] The DCM 20 is a module that communicates with external devices via public line networks and wireless communication, and communicates according to a communication standard such as that for mobile phones.
[0030] 2, the central ECU 12, the multiple ECUs, and the DCM 20 are configured to include a general microcomputer 11 including a CPU (Central Processing Unit) 11A, a ROM (Read Only Memory) 11B, a RAM (Random Access Memory) 11C, a storage 11D, an interface (I / F) 11E, and a bus 11F. That is, the CPU 11A loads various programs stored in the ROM 11B, the storage 11D, etc. into the RAM 11C and executes them to control the vehicle and perform control such as detecting an abnormality in the storage 11D.
[0031] 3, the central ECU 12 includes a storage controller 32 as an example of a determination unit and a flash memory 30 as an example of a memory. The flash memory 30 is provided as an example of the storage 11D, and reading and writing are controlled by the storage controller 32. As an example, a NAND flash memory is applied to the flash memory 30.
[0032] The storage controller 32 includes an ECC (Error Checking and Correcting) 34 as an example of a correction unit, which has the function of detecting and automatically correcting errors that occur in the flash memory 30. The ECC 34 detects and corrects data errors by adding and verifying error correction codes during data transfer.
[0033] Incidentally, memory with a limit on the total amount of data that can be written, such as NAND flash memory, has a lifespan that is also determined by the limit on the total amount of data that can be written. When the lifespan is reached, writing becomes impossible, so when the lifespan is completely reached, it becomes necessary to detect failures and abnormalities and notify the application that uses the memory.
[0034] The conventional method for detecting end of life involves setting a TBW (Total Bytes Written) as an upper limit for writing in advance, and determining that the end of life has been reached when the total amount of writing reaches the TBW.
[0035] However, even if the memory is written up to the TBW, writing can still be performed without any problems. The TBW value is determined taking into account variations between memory cells, the worst-case usage environment, and a safety factor, so the end of life is detected much earlier than when the memory cells actually deteriorate and become unable to be written, making it impossible to use the memory effectively.
[0036] Therefore, the storage controller 32 of the central ECU 12 is configured to determine that the flash memory 30 is abnormal if an error that cannot be corrected by the ECC 34 is detected a predetermined number of times or more within a predetermined period.
[0037] (First embodiment) In this embodiment, if an error that cannot be corrected by the ECC 34 is detected a predetermined number of times or more within a predetermined period (for example, every predetermined amount of writing), and the total amount of writing exceeds the TBW, it is determined that the memory is abnormal. This allows for more effective use of the memory than when determining whether the flash memory 30 is abnormal based on the TBW.
[0038] Next, a description will be given of processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 according to this embodiment configured as described above. Fig. 4 is a flowchart showing an example of the flow of processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 according to this embodiment. The processing in Fig. 4 starts when an instruction to write to the flash memory 30 is issued using, for example, a file operation API (Application Programming Interface) or the like.
[0039] In step 100, the storage controller 32 performs a storage write operation, and then proceeds to step 102. That is, a write operation to the flash memory 30 is performed.
[0040] In step 102, the storage controller 32 determines whether or not a bit error (so-called bit flip) that can be corrected by the ECC 34 has been detected. If the determination is negative, the process proceeds to step 104, and if the determination is affirmative, the process proceeds to step 106.
[0041] In step 104, the storage controller 32 completes the write to the flash memory 30 and ends the series of processes.
[0042] On the other hand, in step 106, the storage controller 32 determines whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined amount of write. This determination may be, for example, whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined number of writes. If the determination is negative, the process proceeds to step 108, and if the determination is positive, the process proceeds to step 110.
[0043] In step 108, the storage controller 32 performs a storage rewrite operation and returns to step 102 to repeat the process described above.
[0044] In step 110, the storage controller 32 determines whether or not it has confirmed that the amount of writing is equal to or greater than the TBW. This determination may be made, for example, by checking driver information to determine whether or not the amount of writing is equal to or greater than the TBW, or by checking information other than the driver information. If the determination is negative, the process proceeds to step 112, and if the determination is positive, the process proceeds to step 114.
[0045] In step 112, the storage controller 32 stores the ECC error (for example, stores a diagnostic trouble code (DTC)) or resets it, and then ends the series of processes.
[0046] In step 114, the storage controller 32 stores the write disable status due to memory cell degradation in the vehicle (RoB: Record of behavior), and then ends the series of processes.
[0047] By performing this processing, if an error that cannot be corrected by ECC 34 is detected a predetermined number of times or more within a predetermined period, it is determined that the flash memory 30 is abnormal. This makes it possible to use the memory more effectively than when determining an abnormality using TBW. Furthermore, by checking the TBW in addition to checking the ECC 34, it is possible to reliably detect an abnormality in the flash memory 30.
[0048] 4, the TBW is checked in addition to the ECC 34, but it is also possible to check only the ECC 34. That is, an abnormality in the flash memory 30 may be determined only by determining whether an error uncorrectable by the ECC 34 has been detected a predetermined number of times or more for each predetermined write amount. In this case, the process omits steps 110 and 112 in FIG. 4.
[0049] Furthermore, in this embodiment, if degradation of a memory cell is determined by checking ECC34 and TBW, the information is stored in the vehicle without directly notifying the occupants, so this is applicable to cases where "driving," "turning," and "stopping" are not affected even if writing to storage is not possible.
[0050] (Second embodiment) Next, as a second embodiment, another example of the processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 configured as described above will be described.
[0051] In the first embodiment, the TBW is checked in addition to checking the ECC34, but in this embodiment, instead of checking the TBW as in the first embodiment, the product warranty period or the product warranty distance is checked.
[0052] In this embodiment, by combining with other logic, it is applied to suppress storage writes exceeding the TBW during the product warranty period and product warranty distance. Note that the product warranty period and product warranty distance differ depending on the vehicle, such as passenger cars, taxis, and commercial vehicles.
[0053] 5 is a flowchart showing an example of the flow of processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 according to this embodiment. The processing in FIG. 5 starts when an instruction to write to the flash memory 30 is issued using, for example, a file operation API. The same processes as those in FIG. 4 will be described with the same reference numerals.
[0054] In step 100, the storage controller 32 performs a storage write operation, and then proceeds to step 102. That is, a write operation to the flash memory 30 is performed.
[0055] In step 102, the storage controller 32 determines whether or not a bit error (so-called bit flip) that can be corrected by the ECC 34 has been detected. If the determination is negative, the process proceeds to step 104, and if the determination is affirmative, the process proceeds to step 106.
[0056] In step 104, the storage controller 32 completes the write to the flash memory 30 and ends the series of processes.
[0057] On the other hand, in step 106, the storage controller 32 determines whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined amount of write. This determination may be, for example, whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined number of writes. If the determination is negative, the process proceeds to step 108, and if the determination is positive, the process proceeds to step 107.
[0058] In step 108, the storage controller 32 performs a storage rewrite operation and returns to step 102 to repeat the process described above.
[0059] In step 107, the storage controller 32 determines whether a predetermined product warranty period has elapsed or whether the vehicle has traveled a predetermined product warranty distance or more. If the determination is negative, the process proceeds to step 112, and if the determination is positive, the process proceeds to step 114.
[0060] In step 112, the storage controller 32 stores the ECC error (for example, stores a diagnostic trouble code (DTC)) or resets it, and then ends the series of processes.
[0061] In step 114, the storage controller 32 stores the write disable status due to memory cell degradation in the vehicle (RoB: Record of behavior), and then ends the series of processes.
[0062] Even if processing is performed in this manner, as in the above embodiment, it is possible to use the memory more effectively than when determining an abnormality based on TBW. Also, by checking the product warranty period or product warranty distance in addition to checking the ECC 34, it is possible to reliably detect an abnormality in the flash memory 30.
[0063] (Third embodiment) Next, as a third embodiment, another example of the processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 configured as described above will be described.
[0064] In this embodiment, the application will be described for functions related to vehicle driving, such as "running," "turning," and "stopping," functions related to regulations, or functions related to security, such as important security measures. That is, in each of the above embodiments, when degradation of a memory cell is determined, the information is stored in the vehicle without notification, but in this embodiment, the storage controller 32 functions as a notification unit and notifies the occupant of an abnormality in the flash memory 30.
[0065] 6 is a flowchart showing an example of the flow of processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 according to this embodiment. The processing in FIG. 6 starts when an instruction to write to the flash memory 30 is issued using, for example, a file operation API. The same processes as those in FIG. 4 will be described with the same reference numerals.
[0066] In step 100, the storage controller 32 performs a storage write operation, and then proceeds to step 102. That is, a write operation to the flash memory 30 is performed.
[0067] In step 102, the storage controller 32 determines whether or not a bit error (so-called bit flip) that can be corrected by the ECC 34 has been detected. If the determination is negative, the process proceeds to step 104, and if the determination is affirmative, the process proceeds to step 106.
[0068] In step 104, the storage controller 32 completes the write to the flash memory 30 and ends the series of processes.
[0069] On the other hand, in step 106, the storage controller 32 determines whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined amount of write. This determination may be, for example, whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined number of writes. If the determination is negative, the process proceeds to step 108, and if the determination is positive, the process proceeds to step 110.
[0070] In step 108, the storage controller 32 performs a storage rewrite operation and returns to step 102 to repeat the process described above.
[0071] In step 110, the storage controller 32 determines whether or not it has confirmed that the amount of writing is equal to or greater than the TBW. This determination may be made, for example, by checking driver information to determine whether or not the amount of writing is equal to or greater than the TBW, or by checking information other than the driver information. If the determination is negative, the process proceeds to step 112, and if the determination is positive, the process proceeds to step 113.
[0072] In step 112, the storage controller 32 stores the ECC error (for example, stores a diagnostic trouble code (DTC)) or resets it, and then ends the series of processes.
[0073] In step 113, the storage controller 32 notifies the driver that writing is disabled due to memory cell degradation, and then the series of processes ends. In this embodiment, the notification is sent to the meter ECU 16, which then notifies the driver of the memory abnormality by displaying a warning indicating the memory abnormality, thereby prompting the driver to immediately replace the memory.
[0074] In this embodiment, as in the first embodiment, degradation of a memory cell is determined by checking the TBW in addition to checking the ECC34, but as in the second embodiment, degradation of a memory cell may also be determined by checking the product warranty period or product warranty distance in addition to checking the ECC34.
[0075] (Fourth embodiment) Next, as a third embodiment, another example of the processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 configured as described above will be described.
[0076] In this embodiment, the TBW is checked before a write operation is performed. Note that, although the following describes a case where the processing of the third embodiment is modified so that the TBW is checked before a write operation is performed, the other embodiments may also be modified so that the TBW is checked before a write operation is performed, similar to the processing described below.
[0077] 7 is a flowchart showing an example of the flow of processing performed by the storage controller 32 of the central ECU 12 in the vehicle control system 10 according to this embodiment. The processing in FIG. 7 starts when an instruction to write to the flash memory 30 is issued using a file operation API, for example. The same processes as those in FIG. 6 will be described with the same reference numerals.
[0078] In step 98, the storage controller 32 determines whether or not it has confirmed that writing has been performed in excess of the TBW. This determination may be made, for example, by checking driver information to determine whether or not the amount of writing is greater than the TBW, or by checking something other than the driver information. If the determination is affirmative, the process proceeds to step 100; if negative, the process proceeds to connection point A. The processing of connection point A will be described in detail later.
[0079] In step 100, the storage controller 32 performs a storage write operation, and then proceeds to step 102. That is, a write operation to the flash memory 30 is performed.
[0080] In step 102, the storage controller 32 determines whether or not a bit error (so-called bit flip) that can be corrected by the ECC 34 has been detected. If the determination is negative, the process proceeds to step 104, and if the determination is affirmative, the process proceeds to step 106.
[0081] In step 104, the storage controller 32 completes the write to the flash memory 30 and ends the series of processes.
[0082] On the other hand, in step 106, the storage controller 32 determines whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined amount of write. This determination may be, for example, whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined number of writes. If the determination is negative, the process proceeds to step 108, and if the determination is positive, the process proceeds to step 113.
[0083] In step 108, the storage controller 32 performs a storage rewrite operation and returns to step 102 to repeat the process described above.
[0084] In step 113, the storage controller 32 notifies the meter ECU 16 that writing is not possible due to memory cell degradation, and ends the series of processes. In this embodiment, the notification is sent to the meter ECU 16, and the meter ECU 16 notifies the occupant of the memory abnormality by displaying a warning indicating the memory abnormality.
[0085] On the other hand, if the determination in step 98 is positive and the process proceeds to node A, the process proceeds to step 116 shown in Fig. 8. Fig. 8 is a flowchart showing the process flow of node A.
[0086] In step 116, the storage controller 32 performs a storage write operation and then proceeds to step 118. That is, a write operation to the flash memory 30 is performed.
[0087] In step 118, the storage controller 32 determines whether or not a bit error (so-called bit flip) that can be corrected by the ECC 34 has been detected. If the determination is negative, the process proceeds to step 120, and if the determination is affirmative, the process proceeds to step 122.
[0088] In step 120, the storage controller 32 completes the write to the flash memory 30 and ends the series of processes.
[0089] On the other hand, in step 122, the storage controller 32 determines whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined amount of write. This determination may be, for example, whether uncorrectable garbled bits have occurred a predetermined number of times or more for each predetermined number of writes. If the determination is negative, the process proceeds to step 124, and if the determination is positive, the process proceeds to step 126.
[0090] In step 124, the storage controller 32 performs a storage rewrite operation to node B and returns to step 98 of FIG. 7 to repeat the process described above.
[0091] In step 126, the storage controller 32 returns an error notification to the application and ends the series of processes. That is, if writing of more than the TBW is not confirmed and bit corruption that cannot be corrected by ECC occurs a predetermined number of times or more for each predetermined amount of writing, it is determined that the abnormality is due to a factor other than memory, and an error is notified to the application.
[0092] Even when processing is performed in this manner, as in the above embodiment, it is possible to use the memory more effectively than when determining an abnormality based on TBW. Also, by checking the product warranty period or product warranty distance in addition to checking the ECC 34, it is possible to reliably detect an abnormality in the flash memory 30. Furthermore, in this embodiment, it is possible to detect abnormalities caused by factors other than abnormalities in writing to the memory.
[0093] In the above embodiment, a NAND flash memory is used as an example of the flash memory, but the present invention is not limited to the NAND flash memory. For example, a NOR flash memory or other memory with a limit on the total write capacity may be used.
[0094] Furthermore, in the above embodiment, the ECC 34 has been described as being provided in the storage controller 32, but this is not limiting. For example, the ECC 34 may be provided outside the storage controller 32, or may be realized by software.
[0095] Furthermore, the processing performed by the storage controller 32 in each of the above embodiments has been described as software processing performed by executing a program, but this is not limited to this. For example, the processing may be performed by hardware such as a GPU (Graphics Processing Unit), an ASIC (Application Specific Integrated Circuit), or an FPGA (Field-Programmable Gate Array). Alternatively, the processing may be a combination of both software and hardware. Furthermore, if the processing is software, the program may be stored in various storage media and distributed.
[0096] Furthermore, the present invention is not limited to the above, and it goes without saying that various modifications can be made without departing from the spirit of the present invention. [Explanation of symbols]
[0097] 10 Vehicle Control System 11 Microcomputer 12 Central ECU 30 Flash memory (memory) 32 Storage controller (judgment unit and notification unit) 34 ECC (Correction Department)
Claims
1. Memory with a limit on the total amount of data written, a determination unit that determines that the memory is abnormal when a correction unit that detects and corrects errors that have occurred in the memory detects an uncorrectable error a predetermined number of times or more within a predetermined period and a predetermined condition related to the memory or a vehicle in which the memory is installed is satisfied; and A storage abnormality detection device comprising:
2. 2. The storage abnormality detection device of claim 1, wherein the determination unit determines that the memory is abnormal when the determination unit detects an error that cannot be corrected by the correction unit a predetermined number of times or more within a predetermined period and the total amount of writing to the memory is greater than or equal to a predetermined upper limit value.
3. 2. The storage abnormality detection device of claim 1, wherein the judgment unit judges that the memory is abnormal when an error that cannot be corrected by the correction unit is detected a predetermined number of times or more within a predetermined period and the error exceeds a predetermined product warranty period or a predetermined product warranty distance.
4. The storage abnormality detection device of claim 1, further comprising a notification unit that notifies of an abnormality in the memory when the determination unit determines that an abnormality in the memory exists, when the memory is used for a function related to vehicle operation, a function related to regulations, or a function related to security.
5. 2. The storage abnormality detection device of claim 1, wherein the determination unit checks the total amount of data written to the memory before performing a write operation to the memory, and if the total amount of data written to the memory is less than a predetermined upper limit, and if the correction unit detects an error that cannot be corrected a predetermined number of times or more within a predetermined period, determines that the abnormality is due to a factor other than the limit.
6. The computer A correction unit detects and corrects errors that occur in memory that has a limit on the total amount of data that can be written, and detects uncorrectable errors. A storage abnormality detection method that performs processing to determine that the memory is abnormal if the uncorrectable error is detected a predetermined number of times or more within a predetermined period and predetermined conditions related to the memory or the vehicle in which the memory is installed are met.
7. On the computer, A correction unit detects and corrects errors that occur in memory that has a limit on the total amount of data that can be written, and detects uncorrectable errors. A storage abnormality detection program for executing a process to determine that the memory is abnormal when the uncorrectable error is detected a predetermined number of times or more within a predetermined period and predetermined conditions related to the memory or the vehicle in which the memory is installed are met.
Citation Information
Patent Citations
On-vehicle machine
JP2015022403A
Electronic controller
JP2016170604A
Memory device and storage unit
WO2016030992A1