Vehicle communication control system and vehicle communication control device

The vehicle communication control system addresses the challenge of consistent fault information handling across ECUs by using a comprehensive determination unit to manage initialization control signals, reducing production costs and ensuring safety compliance.

JP7836212B2Active Publication Date: 2026-03-26SUBARU CORP
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Existing methods for initializing vehicle failure information in electronic control units (ECUs) require complex logic changes every time a new ECU is introduced, leading to increased production costs and reduced reusability, and may result in inconsistent handling of fault information across ECUs.

Method used

A vehicle communication control system with a comprehensive determination unit and initialization control mechanism that determines whether to prohibit fault information initialization based on vehicle state, transmitting control signals via a bus to ensure consistent handling across ECUs, regardless of individual device states.

Benefits of technology

This approach reduces the need for frequent logic changes in existing ECUs and ensures consistent handling of fault information, minimizing production costs and communication overhead while maintaining safety and regulatory compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007836212000001
    Figure 0007836212000001
  • Figure 0007836212000002
    Figure 0007836212000002
  • Figure 0007836212000003
    Figure 0007836212000003
Patent Text Reader

Abstract

To eliminate or at least reduce disadvantages of existing methods related to initializing vehicle failure information.SOLUTION: A vehicle communication control system includes a plurality of control devices and a vehicle communication control device that are interconnected via a first bus. The vehicle communication control device transmits an initialization control state signal to the first bus based on a result of determining whether initialization of failure information is prohibited, based on an initialization control signal generated by at least one control device of the plurality of control devices. Each of the plurality of control devices determines whether to initialize the failure information in response to an initialization request received from an external device, regardless of the state of the other control devices, depending on the initialization control state signal received from the vehicle communication control device via the first bus.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a vehicle communication control system and a vehicle communication control device.

Background Art

[0002] Conventionally, a vehicle is equipped with a plurality of electronic control units (ECUs: Electronic Control Unit) that control various components. These electronic control units are interconnected via a bus such as a CAN (Controller Area Network). Communication between the electronic control units is performed according to a communication protocol that is standardized or individually designed.

[0003] When each electronic control unit detects that a failure has occurred in a component under its control, it stores the failure information in a memory. The failure information is usually maintained in the memory until it is confirmed that the cause of the failure has been eliminated or that safe driving is sufficiently possible. The failure information may be transferred to other electronic control units for cooperative control between the electronic control units or for redundant storage considering the convenience of reading the information.

[0004] A so-called scan tool (also referred to as a diagnostic device) is an external device that can be connected to the bus via a connection interface provided in the vehicle. The scan tool can read the failure information possessed by the electronic control unit, and the read failure information is used, for example, for vehicle repair or analysis of the cause of the failure. The scan tool further has a function of requesting initialization of the failure information. For example, when the dealer finishes repairing the vehicle, an initialization request is sent from the scan tool to initialize (i.e., erase) the failure information stored by each electronic control unit. However, from the viewpoint of safety, it may be better not to execute the initialization of the failure information when the vehicle is in a specific state. Also, depending on the laws and regulations of each country, it may be required that the handling of the failure information does not differ between the electronic control units.

[0005] Patent documents 1 and 2 propose methods to avoid a situation where some devices perform initialization and others do not when an initialization request is sent to multiple electronic control devices. More specifically, according to the method in Patent Document 1, the scan tool on the sending side of the initialization request and the individual electronic control devices on the receiving side determine conditions related to communication possibility and the state of the ignition switch, and the fault information is initialized only if predetermined conditions are met. According to the method in Patent Document 2, particularly in cases where multiple electronic control devices hold the same fault information, each electronic control device notifies the other devices of its own state (whether or not initialization can be performed), and each electronic control device determines whether it is okay to initialize the fault information based on the state of all the devices it is involved with.

[0006] The methods disclosed in Patent Documents 1 and 2 both achieve unified operation of multiple electronic control devices regarding the initialization of fault information by relying on relatively complex logic implemented in each electronic control device (and diagnostic device). In this case, complex logic must be implemented each time a new electronic control device is introduced to the vehicle, and the introduction of a new electronic control device affects the logic already implemented in the existing device. In contrast, Patent Document 3 proposes a vehicle communication control device and a vehicle communication control system that can eliminate or at least mitigate the disadvantages of the methods in Patent Documents 1 and 2. More specifically, according to the method in Patent Document 3, a control unit has a function to comprehensively determine whether or not to prohibit the initialization of fault information stored by each of the multiple control devices based on the state of the vehicle, and based on the result of the determination, transmits an initialization control signal to the first bus that controls whether or not to prohibit the initialization of fault information. Each of the other control units then determines whether or not to initialize the fault information in response to an initialization request received from an external device, depending on the initialization control signal received via the bus. [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Japanese Patent Publication No. 2010-143404 [Patent Document 2] Japanese Patent Publication No. 2010-266279 [Patent Document 3] Japanese Patent Publication No. 2019-64300 [Overview of the project] [Problems that the invention aims to solve]

[0008] However, the method described in Patent Document 3 requires each other control unit to implement a function to determine the initialization control signals of all control units on the communication control system that have the function to transmit initialization control signals. Therefore, each time a control unit with the function to transmit initialization control signals is added, the functions of all other control units must be modified.

[0009] The technology disclosed herein aims to eliminate or at least mitigate the disadvantages of these existing methods. [Means for solving the problem]

[0010] To solve the above problems, in one view of the present disclosure, a vehicle communication control system is provided which includes a plurality of control devices and a vehicle communication control device interconnected via a first bus, wherein at least one of the plurality of control devices includes a comprehensive determination unit that comprehensively determines, based on the state of the vehicle, whether or not to prohibit the initialization of fault information stored by each of the plurality of control devices, and a first communication control unit that generates an initialization control signal to control whether or not to prohibit the initialization of fault information, so that one of the plurality of control devices does not initialize the fault information in response to an initialization request received from an external device, regardless of the state of the other control devices, based on the result of the determination by the determination unit, and the vehicle communication control device includes an initialization state determination unit that determines, based on the initialization control signal, whether or not the initialization of fault information is prohibited, and a second communication control unit that transmits an initialization control state signal to the first bus, based on the result of the determination by the initialization state determination unit, which includes information on whether or not the initialization of fault information is prohibited, and each of the plurality of control devices determines, depending on the initialization control state signal received from the vehicle communication control device via the first bus, whether or not to initialize the fault information in response to an initialization request received from an external device, regardless of the state of the other control devices.

[0011] Furthermore, in order to solve the above problems, according to another aspect of this disclosure, a vehicle communication control device is provided, which is connected to a first bus that interconnects a plurality of control devices in a vehicle, and comprises: an initialization state determination unit that determines whether or not the initialization of fault information is prohibited based on an initialization control signal that indicates the result of a comprehensive determination based on the state of the vehicle of whether or not to prohibit the initialization of fault information stored by each of the plurality of control devices, which is generated by at least one of the plurality of control devices; and a second communication control unit that transmits an initialization control state signal to the first bus, which includes information on whether or not the initialization of fault information is prohibited, based on the result of the determination by the initialization state determination unit. [Effects of the Invention]

[0012] The technology described herein can eliminate or at least mitigate the disadvantages of existing methods for initializing vehicle failure information. [Brief explanation of the drawing]

[0013] [Figure 1] This is a block diagram showing an example of a vehicle network configuration. [Figure 2] This is an explanatory diagram illustrating an example of controlling the initialization of fault information according to existing methods. [Figure 3] This is an explanatory diagram for explaining the basic principles of the technology related to this disclosure. [Figure 4] This block diagram shows an example of the configuration of a master control function according to one embodiment. [Figure 5] This is an explanatory diagram illustrating an example of the configuration of an initialization control signal according to one embodiment. [Figure 6] This block diagram shows an example of the configuration of a state management function according to one embodiment. [Figure 7] This is an explanatory diagram illustrating an example of the configuration of an initialization control state signal according to one embodiment. [Figure 8] This block diagram shows an example of the configuration of a slave control function according to one embodiment. [Figure 9] This is an explanatory diagram illustrating the relaying of initialization control signals by the gateway function. [Figure 10] This block diagram shows an example of the configuration of a gateway function according to one embodiment. [Figure 11] This flowchart shows an example of the processing flow executed by the master control function according to one embodiment. [Figure 12] This flowchart shows an example of the processing flow executed by the state management function according to one embodiment. [Figure 13] This flowchart shows an example of the processing flow executed by the slave control function according to one embodiment. [Figure 14]It is a flowchart showing an example of the flow of processing executed by the gateway function according to an embodiment.

Embodiments of the Invention

[0014] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. In the present specification and drawings, components having substantially the same functional configuration are denoted by the same reference numerals, and redundant description is omitted.

[0015] <1. Overview> [1-1. Configuration of the System] First, an example of the configuration of a vehicle communication control system will be described with reference to FIG. 1. The vehicle communication control system 10 shown in FIG. 1 includes one or more buses and one or more control devices interconnected via those buses. For example, the main bus 12 interconnects the control devices 20a, 20b, 20c, 20d, 20e, 20f, 20g,... and the body integrated device 50. The sub-bus 14 interconnects the control device 20b, the control devices 40a and 40b. The diagnostic bus 16 interconnects the body integrated device 50 and the connection interface 60. Each of the main bus 12, the sub-bus 14, and the diagnostic bus 16 may be implemented according to, for example, CAN, or may be implemented according to other types of communication protocols such as FlexRay, LIN (Local Interconnect Network), or MOST (Media Oriented Systems Transport). In the following description, when there is no need to distinguish between the control devices 20a, 20b, 20c, 20d, 20e, 20f, 20g from each other, these are collectively referred to as the control device 20 by omitting the alphabet at the end of the reference numeral. The same applies to the handling of the reference numerals of other components.

[0016] The control device 20a is an engine ECU. The engine ECU 20a is connected to one or more sensors 21a and one or more actuators 22a involved in the operation of the engine. For example, the sensors 21a include an accelerator opening sensor and an engine speed sensor. The actuators 22a include the engine's throttle valve and injectors. The engine ECU 20a works in conjunction with, for example, the control device 20b described later to control the operation of the engine so that a desired engine torque is obtained.

[0017] The control unit 20b is a HEV (Hybrid Electric Vehicle) CU (Control Unit). The HEVCU 20b communicates with other control units and integrally controls the operation of vehicle components, including the engine, motor, transmission, brakes, and battery. For example, based on data such as accelerator opening, vehicle speed, and battery power level, the HEVCU 20b calculates the torque that the engine and motor should produce and sends torque commands to control units 20a and 40b, respectively. The HEVCU 20b also determines the timing of gear changes and sends a gear change command to control unit 20c. Furthermore, the HEVCU 20b determines the timing and amount of brake application and sends a brake command to control unit 20d.

[0018] The control device 20c is a transmission ECU. The transmission ECU 20c is connected to one or more actuators 22c involved in the operation of the transmission. For example, the actuators 22c include a hydraulic control mechanism that controls the engagement and disengagement of the clutch and the gear ratio. The transmission ECU 20c engages or disengages the clutch or shifts the gear ratio in response to a gear shift instruction received from the control device 20b, for example.

[0019] The control device 20d is a brake ECU. The brake ECU 20d is connected to one or more sensors 21d and one or more actuators 22d that are involved in the operation of the brakes. For example, the sensor 21d includes a vehicle speed sensor. The actuator 22d includes a hydraulic control mechanism that controls the brake pressure of each wheel. The brake ECU 20d drives the hydraulic control mechanism to activate the brakes in response to a brake command received from, for example, the control device 20b.

[0020] The control device 40a is a battery ECU. The battery ECU 40a is connected to one or more sensors 41a involved in managing the battery state. For example, the sensors 41a include a voltage sensor, a current sensor, and a temperature sensor. The battery ECU 40a transmits data indicating the battery state (e.g., remaining power and temperature) obtained through the sensors 41a to the control device 20b.

[0021] The control device 40b is a motor ECU. The motor ECU 40b is connected to one or more sensors 41b and one or more actuators 42b involved in the operation of the motor. For example, the sensor 41b includes a motor speed sensor. The actuator 42b includes an inverter. The motor ECU 40b works in conjunction with, for example, the control device 20b to control the operation of the motor so that a desired motor torque or regenerative torque is obtained.

[0022] As shown in Figure 1, the HEVCU20b is connected to the engine ECU20a, transmission ECU20c, and brake ECU20d via the main bus 12. The HEVCU20b is also connected to the battery ECU40a and motor ECU40b via the sub-bus 14. A control device having interfaces with multiple buses, like the HEVCU20b, may also have a gateway function that relays signals received from one bus to other buses.

[0023] The Body Integration Unit (BIU) 50 functions as a communication hub for the entire vehicle, integrating various networks within the vehicle, including the main bus 12, which is the control network, as well as other networks (not shown), such as the information network and the safety network. The Body Integration Unit 50 is also connected to the connection interface 60 via the diagnostic bus 16.

[0024] The connection interface 60 is an interface that mediates the connection of external devices to the vehicle. The connection interface 60 may be a DLC (Data Link Connector or Data Link Coupler) to which a diagnostic device, such as a General Scan Tool (GST), can be connected. Figure 1 shows a diagnostic device 65 as an example of an external device.

[0025] [1-2. Description of the task] Generally, vehicles are equipped with various control devices, as illustrated in Figure 1, and these control devices communicate via a bus. Furthermore, each control device, upon detecting a failure in a component under its control (e.g., a sensor, actuator, or internal module of the ECU), stores the failure information in memory. This failure information may be standardized information, such as a DTC (Diagnostic Trouble Code), or it may be individually defined information. The failure information is usually retained in memory until the cause of the failure is resolved or it is confirmed that the vehicle can be driven safely. If the failure is not fatal to the vehicle's operation, the driver can continue driving the vehicle regardless of the presence of the failure information. However, if there is failure information that could affect driving safety, some control devices may perform control in a fail-safe mode different from the normal control mode. For example, if there is failure information associated with the accelerator pedal position sensor, it is desirable for the engine ECU or HEVCU to set the accelerator pedal position to a fail-safe value regardless of the sensor input to prevent the vehicle from running out of control.

[0026] If a vehicle malfunction occurs, the driver or dealer can connect a scan tool (e.g., diagnostic device 65) to the vehicle and display the vehicle's fault information on the scan tool. The scan tool usually also has a function to request the initialization of the fault information. For example, once the dealer has finished repairing the vehicle or analyzing the cause of the malfunction, they can send an initialization request from the scan tool to the vehicle's network to initialize (i.e., erase) the fault information stored in each control unit. However, if the existence of fault information is a condition for activating the fail-safe function as described above, the initialization of the fault information should only be performed when sufficient safety is ensured based on the vehicle's condition. Furthermore, depending on the laws and regulations of each country, it may be required that the handling of fault information be consistent across multiple control units.

[0027] In the example in Figure 1, the engine ECU 20a stores fault information 23a. The HEVCU 20b stores fault information 23b. The transmission ECU 20c stores fault information 23c. The brake ECU 20d stores fault information 23d. The battery ECU 40a stores fault information 43a. In one scenario, when the diagnostic device 65 is connected to the connection interface 60 and an initialization request is sent from the diagnostic device 65 to the diagnostic bus 16, the body integration device 50 relays the initialization request to the main bus 12. The HEVCU 20b further relays the initialization request flowing on the main bus 12 to the subbus 14. If the decision of whether or not to perform initialization of fault information in response to initialization requests flowing on the bus is left to the individual control logic of each control device, there is a risk that fault information may be erased at an unexpected time. There is also a possibility of violating the requirement for common handling of fault information. To address these problems, for example, Patent Document 2 proposes that each electronic control unit notifies other devices of its own status (whether or not initialization can be performed), and that each electronic control unit determines whether or not it is permissible to initialize fault information based on the notified status of all devices it is involved with.

[0028] However, with the existing methods described above, when a new ECU is connected to the bus, it becomes necessary to change the control logic of the controller of each ECU. This is because each controller must decide whether or not to initialize its own fault information, taking into account whether the new ECU is in a state where it can initialize fault information. In other words, with the existing methods, the implemented logic of the existing ECU must be changed every time a new ECU is introduced to the vehicle. Furthermore, the newly introduced ECU must also implement relatively complex control logic (which takes into account the state of all other controllers involved). This leads to increased production costs for the vehicle and reduces the reusability of the control device or its control logic. In addition, if a large number of controllers constantly transmit control signals for initialization control onto the bus, the communication costs will be substantial, and the bus capacity may become insufficient. Differences in the arrival timing of control signals transmitted from multiple controllers may also cause differences in the behavior of initialization control between controllers.

[0029] In contrast, Patent Document 3 introduces a function that comprehensively determines whether or not to prohibit the initialization of fault information. Figure 2 is an explanatory diagram illustrating an example of control of fault information initialization according to the technology described in Patent Document 3. In the example in Figure 2, the first ECU 20-1 and the second ECU 20-2 have a master control function 120. The third ECU 20-3 and the fourth ECU 20-4 each have a slave control function 130. Each master control function 120 comprehensively determines, based on the state of the vehicle, whether or not to prohibit the initialization of fault information stored by the multiple related ECUs (in the example in Figure 2, the first ECU 20-1, the second ECU 20-2, the third ECU 20-3, and the fourth ECU 20-4), and transmits initialization control signals 150-1 and 150-2 based on the determination result to the main bus 12. Meanwhile, the slave control functions 130 of the third ECU20-3 and the fourth ECU20-4 monitor the initialization control signals 150-1 and 150-2 flowing on the main bus 12. For example, if the slave control function 130 receives an initialization control signal (initialization prohibition signal) indicating that the initialization of fault information is prohibited, it will not initialize the fault information in response to an initialization request received from an external device (e.g., a diagnostic device 65), regardless of the status of other devices.

[0030] In this way, the master control function 120 comprehensively determines whether or not to prohibit the initialization of fault information in multiple related ECUs. As a result, even if a new ECU is introduced to the vehicle, it is sufficient to change only the control logic of the master control function 120. In other words, the slave control function 130 of the existing ECU only needs to continue monitoring the initialization control signal 150 transmitted from the master control function 120. Furthermore, the newly introduced ECU can participate in the common handling of fault information simply by implementing the same slave control function 130 as the existing ECU.

[0031] However, in the method described in Patent Document 3, if an ECU with a new master control function 120 is added to the bus, it becomes necessary to modify the slave control function 130 to implement control logic that determines the initialization control signal 150-N of the newly added ECU's master control function 120. In this case as well, this may lead to an increase in vehicle production costs and reduce the reusability of the control device or its control logic.

[0032] [1-3. Basic Principles] According to embodiments of the technology described herein, in order to eliminate or at least mitigate the disadvantages of the above-described method for initializing vehicle fault information, a function is introduced that monitors an initialization control signal transmitted from a master control function present in the bus and transmits an initialization control status signal on the bus indicating whether or not the system is in a state where initialization of fault information is prohibited (hereinafter, this function is also referred to as the "status management function").

[0033] Figure 3 is an explanatory diagram illustrating the basic principles of the technology relating to this disclosure. In the example in Figure 3, the first ECU 20-1 has a state management function 125 and a master control function 120. The second ECU 20-2 has a master control function 120. The third ECU 20-3 and the fourth ECU 20-4 each have a slave control function 130. The master control function 120 comprehensively determines, based on the state of the vehicle, whether or not to prohibit the initialization of fault information stored by the multiple related ECUs (in the example in Figure 3, the first ECU 20-1, the second ECU 20-2, the third ECU 20-3, and the fourth ECU 20-4), and transmits an initialization control signal 150 based on the determination result to the main bus 12.

[0034] The state management function 125 monitors the initialization control signal 150 flowing on the main bus 12. In the example in Figure 3, the state management function 125 also monitors the initialization control signal generated by the master control function 120 in the same first ECU 20-1. Based on the initialization control signal, the state management function 125 determines whether or not the system is in a state where the initialization of fault information is prohibited, and sends an initialization control status signal 155 to the main bus 12 based on the determination result. For example, if the state management function 125 receives an initialization control signal (initialization prohibition signal) indicating that the initialization of fault information is prohibited, it sends an initialization control status signal (initialization prohibition status signal) to the main bus 12 indicating that the system is in a state where the initialization of fault information is prohibited.

[0035] Meanwhile, the slave control functions 130 of the third ECU20-3 and the fourth ECU20-4 monitor the initialization control status signal 155 flowing on the main bus 12. If the slave control function 130 receives an initialization control status signal (initialization prohibited status signal) indicating, for example, that the initialization of fault information is prohibited, it will not initialize the fault information in response to an initialization request received from an external device (e.g., a diagnostic device 65), regardless of the status of other devices.

[0036] In this way, the master control function 120 comprehensively determines whether or not to prohibit the initialization of fault information in the multiple related ECUs, and the state management function 125 determines whether any of the master control functions 120 has determined that the initialization of fault information should be prohibited. As a result, even if a new ECU with a master control function 120 is introduced to the vehicle, only the state management function 125 needs to have its control logic changed. The master control function 120 of the existing ECU only needs to continue to comprehensively determine whether or not to prohibit the initialization of fault information in the multiple related ECUs. Furthermore, the slave control function 130 of the existing ECU only needs to continue to monitor the initialization control signal 150 transmitted from the master control function 120. In addition, the newly introduced ECU can participate in the common handling of fault information simply by implementing the same master control function 120 or slave control function 130 as the existing ECU.

[0037] The state management function 125 may be placed in any of the various control devices 20 illustrated in Figure 1. Typically, placing the state management function 125 in a device that already has a master control function 120 is advantageous from the standpoint of communication costs. The state management function 125 may also be placed in a dedicated device specifically for comprehensive handling of fault information for the entire system. The following sections will describe in more detail embodiments of such comprehensive control mechanisms for initializing fault information.

[0038] <2. Example Configuration of Each Function> [2-1. Master Control Function] Figure 4 is a block diagram showing an example of the configuration of a master control function 120 according to one embodiment. The master control function 120 is located in a device connected to a bus that interconnects control devices within a vehicle. As shown in Figure 4, the master control function 120 includes a comprehensive determination unit 122 and a first communication control unit 124.

[0039] (1) Comprehensive judgment section The comprehensive determination unit 122 comprehensively determines, based on the vehicle's state, whether or not to prohibit the initialization of fault information stored by each of the multiple control devices. The multiple control devices here may include devices on which the master control function 120 is located. For example, if the engine ECU 20a has the master control function 120, the comprehensive determination unit 122 may comprehensively determine whether or not to prohibit the initialization of fault information stored by the engine ECU 20a and HEVCU 20b (and other ECUs). In this specification, the expression "comprehensively determine" means that the conditional determination affecting the operation of multiple devices is performed collectively by a specific single device, rather than by each of the multiple devices individually or in parallel.

[0040] The conditions under which the initialization of fault information is comprehensively prohibited (hereinafter referred to as the initialization prohibition conditions) may be any conditions. Typically, the initialization prohibition conditions are related to the operational status of the failsafe function.

[0041] For example, if fault information associated with the accelerator pedal position sensor exists, the engine ECU 20a controls the throttle based on the accelerator pedal position set to a fail-safe value, regardless of the sensor input. This prevents the vehicle from running out of control, even if the sensor input indicates an abnormally high accelerator pedal position due to a fault. This fail-safe function should be maintained especially when the engine is not stopped. Therefore, the initialization prohibition condition can be expressed, for example, as follows: a) The engine is on and the throttle failsafe function is on. → Prohibit the initialization of fault information. b) The engine is off or the throttle failsafe is off. →Allow initialization of fault information In this case, the vehicle status described above includes the engine operating status and the operating status of the throttle fail-safe function. The comprehensive determination unit 122 determines that if the engine is ON and the throttle fail-safe function is ON, it will prohibit the initialization of fault information stored by each of the multiple control devices. The engine ECU 20a normally has information (engine operating status and operating status of the throttle fail-safe function) for determining the above-mentioned initialization prohibition conditions. Therefore, if the master control function 120 is located in the engine ECU 20a, no additional communication costs are incurred for collecting the information required to determine the above-mentioned initialization prohibition conditions.

[0042] As another example, the brake ECU20d may activate a fail-safe function to prevent the brakes from being released against the driver's intent if fault information associated with brake operation exists. Therefore, the initialization prohibition conditions may include (or instead of) the conditions related to the operating state of the brake fail-safe function, in addition to the conditions related to the operating state of the throttle fail-safe function described above.

[0043] (2) First Communication Control Unit Based on the comprehensive determination result by the comprehensive determination unit 122 described above, the first communication control unit 124 transmits an initialization control signal to the bus interconnecting the multiple control devices, which controls whether or not to prohibit the initialization of fault information. The initialization control signal is received by the state management function 125, which will be described later.

[0044] As an example, the initialization control signal may include an initialization prohibition signal. For instance, if the comprehensive determination unit 122 determines that the initialization of fault information should be prohibited, the first communication control unit 124 may transmit an initialization prohibition signal to the bus that comprehensively prohibits the initialization of fault information. Regardless of the state of other devices, the initialization prohibition signal prevents the control device that receives the initialization prohibition signal from initializing the fault information in response to an initialization request received from an external device.

[0045] The initialization control signal may include an initialization permission signal. For example, the first communication control unit 124 may transmit an initialization permission signal to the bus if the comprehensive determination unit 122 determines that initialization of fault information is not prohibited. The initialization permission signal allows the control device that receives the initialization permission signal to initialize the fault information in response to an initialization request received from an external device, regardless of the status of other devices.

[0046] In one embodiment, the initialization disable signal and the initialization enable signal may correspond to the first and second bit values, respectively, of predetermined bits in a control frame periodically transmitted from the master control function 120. Figure 5 is an explanatory diagram illustrating an example of the configuration of an initialization control signal according to such an embodiment. In the example of Figure 5, the initialization control signal 150 is included in a control frame 160 generated according to the CAN data frame structure. More specifically, the control frame 160 includes an SOF (Start Of Frame) field, an ID (Identifier) ​​field, an RTR (Remote Transmission Request) field, a control (CTRL) field, a data (DATA) field, and other subsequent fields (not shown).

[0047] The SOF field is used by the receiving node to recognize the start of a frame and synchronize processing timing with the frame. The ID field uniquely identifies the transmitting node and is also used for arbitration in case of frame collisions (i.e., determining which transmitting node takes precedence). Typically, the control frame 160 containing the initialization control signal 150 is given an ID that has a higher priority than the initialization request frame sent from the diagnostic device 65. The RTR field is used to distinguish data frames from remote frames that request the return of data frames. The control field carries control information indicating the length of the data field. The data field of the control frame 160 contains the initialization control signal 150 at a predefined bit position. In the example in Figure 5, the initialization control signal 150 represents initialization prohibited by a bit value of "1" and initialization permitted by a bit value of "0". In this case, the bit indicating a bit value of "1" may be interpreted as an initialization prohibition signal, and the bit indicating a bit value of "0" as an initialization permit signal. Of course, the relationship between the bit value and the prohibition and permitting of initialization may also be reversed.

[0048] The initialization control signal may have other configurations, not limited to the example in Figure 5. For example, the initialization control signal may be a control message that includes additional information along with a bit or code indicating whether initialization is prohibited or permitted. The additional information may include, for example, one or more of the following: the period during which initialization is prohibited or permitted, a code that identifies the fault information in question, and an identifier that identifies the ECU or group of ECUs in question.

[0049] [2-2. Status Management Function] Figure 6 is a block diagram showing an example of the configuration of a state management function 125 according to one embodiment. The state management function 125 is located in a device connected to a bus that interconnects control devices within a vehicle. The device on which the state management function 125 is located can function as a vehicle communication control device. As shown in Figure 6, the state management function 125 includes an initialization state determination unit 127 and a second communication control unit 129.

[0050] (1) Initialization state determination unit The initialization state determination unit 127 determines whether the initialization of fault information is prohibited based on the initialization control signals received from the master control function 120 via the bus. The initialization state determination unit 127 monitors the initialization control signals transmitted from all master control functions 120 present on the bus and determines whether at least one initialization control signal prohibits the initialization of fault information.

[0051] (2) Second Communication Control Unit Based on the result of the above-mentioned determination by the initialization state determination unit 127, the second communication control unit 129 transmits an initialization control status signal, which includes information on whether or not the initialization of fault information is prohibited, to the bus that interconnects the multiple control devices. The initialization control status signal is received by the slave control function 130, which will be described later.

[0052] As an example, the initialization control status signal may include an initialization prohibition status signal. For example, if the initialization status determination unit 127 determines that the initialization of fault information is prohibited, the second communication control unit 129 may transmit an initialization prohibition status signal to the bus indicating that the initialization of fault information is prohibited. The initialization prohibition status signal prevents the control device that receives the initialization prohibition status signal from initializing the fault information in response to an initialization request received from an external device, regardless of the status of other devices. When the slave control function 130 receives an initialization prohibition status signal from the status management function 125, it does not initialize the fault information in response to an initialization request received from an external device, without recognizing the status of other devices in the vehicle.

[0053] The initialization control status signal may include an initialization permission status signal. For example, the second communication control unit 129 may transmit an initialization permission status signal to the bus if the initialization status determination unit 127 determines that initialization of fault information is not prohibited. The initialization permission status signal allows the control device that receives the initialization permission status signal to initialize the fault information in response to an initialization request received from an external device, regardless of the status of other devices. When the slave control function 130 receives an initialization permission status signal from the master control function 120, it initializes the fault information in response to an initialization request received from an external device without recognizing the status of other devices in the vehicle.

[0054] In one embodiment, the initialization prohibition status signal and the initialization enable status signal may correspond to the first bit value and the second bit value, respectively, of a predetermined bit in a control frame periodically transmitted from the state management function 125. Figure 7 is an explanatory diagram illustrating an example of the configuration of the initialization control status signal according to such an embodiment. In the example in Figure 7, the initialization control status signal 155 is included in the control frame 165 generated according to the CAN data frame structure. The configuration of the initialization control status signal 155 in this example may be the same as the example of the initialization control signal 150 shown in Figure 5, so its explanation is omitted here.

[0055] [2-3. Slave Control Function] Figure 8 is a block diagram showing an example of the configuration of a slave control function 130 according to one embodiment. The slave control function 130 is located in each control device having a memory 131 for storing fault information. As shown in Figure 8, the slave control function 130 includes an initialization control unit 132.

[0056] The initialization control unit 132 determines whether or not to initialize fault information in response to an initialization request received from an external device (e.g., a diagnostic device 65), depending on an initialization control signal received via the bus from the state management function 125. For example, if the initialization control unit 132 receives an initialization prohibition signal indicating that initialization of fault information is prohibited, it will not initialize the fault information in response to an initialization request received from an external device, regardless of the state of other devices. Also, if the initialization control unit 132 receives an initialization permission signal indicating that initialization of fault information is permitted, it will initialize the fault information in response to an initialization request received from an external device, regardless of the state of other devices. If the initialization control unit 132 does not initialize the fault information in response to an initialization request, it may send a response signal (negative response) indicating initialization refusal back to the external device. Also, if the initialization control unit 132 initializes the fault information in response to an initialization request, it may send a response signal (acknowledgment response) indicating initialization completion back to the external device.

[0057] More specifically, for example, the initialization control unit 132 monitors control frames 165 that are periodically transmitted from the state management function 125 onto the bus. The control frame 165 has, for example, an ID assigned to the node that sent the control frame 165. The control frame 165 also includes an initialization control status signal 155 at a predefined bit position in the data field. In the example in Figure 7, if the bit value at this bit position is "1", the initialization control status signal 155 is an initialization prohibition status signal, and if the bit value at this bit position is "0", the initialization control status signal 155 is an initialization permission status signal. The initialization control unit 132 switches the status (hereinafter referred to as the initialization prohibition status) of whether the initialization of fault information is prohibited or permitted, depending on the bit value of the initialization control status signal 155. When the initialization control unit 132 receives an initialization request from an external device, it controls whether or not to initialize the fault information stored in the memory 131 based on the initialization prohibition status at that time.

[0058] [2-3. Gateway Function] As mentioned above, the network within a vehicle generally includes multiple buses. When a state management function 125 on one control unit sends an initialization control status signal to the first bus among the multiple buses, the initialization control status signal usually does not flow on buses other than the first bus. However, considering that there may be cases where a control unit connected only to other buses stores fault information, the initialization control status signal should also be relayed to buses to which the state management function 125 is not connected.

[0059] For example, in the example shown in Figure 1, the vehicle communication control system 10 includes a main bus 12, a sub-bus 14, and a diagnostic bus 16. When the engine ECU 20a has a state management function 125 and sends a control frame 165 from the engine ECU 20a to the main bus 12, the control frame 165 itself does not flow over the sub-bus 14. In such cases, it is beneficial to implement a gateway function in the HEVCU 20b interposed between the main bus 12 and the sub-bus 14 for relaying initialization control state signals.

[0060] Figure 9 is an explanatory diagram illustrating a gateway function according to one embodiment. In the example in Figure 9, the first ECU 20-1 has a state management function 125 and a master control function 120. The second ECU 20-2 has a master control function 120. The third ECU 20-3 has a slave control function 130 and a gateway function 140. The fourth ECU 20-4, fifth ECU 40-1, and sixth ECU 40-2 each have a slave control function 130. As described above, the master control function 120 comprehensively determines, based on the state of the vehicle, whether or not to prohibit the initialization of fault information stored by each of the related ECUs, and transmits a control frame including an initialization control signal 150 based on the determination result to the main bus 12. The state management function 125 monitors the initialization control signal 150 flowing on the main bus 12, determines, based on the initialization control signal 150, whether or not the system is in a state where the initialization of fault information is prohibited, and transmits an initialization control state signal 155 based on the determination result to the main bus 12.

[0061] The slave control functions 130 of the third ECU20-3 and the fourth ECU20-4 monitor control frames flowing on the main bus 12, and if an initialization prohibition status signal is received, they do not initialize fault information even if an initialization request is received from an external device. In this embodiment, the gateway function 140 of the third ECU20-3 transmits a control frame to the subbus 14 that includes a secondary initialization control status signal corresponding to the initialization control status signal 155 received from the status management function 125 via the main bus 12. In other words, the third ECU20-3 functions as a third communication control device. The control frame transmitted from the gateway function 140 may have a configuration equivalent to, for example, the control frame 165 illustrated in Figure 7, however, a different ID may be set in the ID field than that of the control frame 165. The slave control functions 130 of the fifth ECU40-1 and the sixth ECU40-2 monitor control frames flowing on the subbus 14. Furthermore, these slave control functions 130 do not initialize fault information even if an initialization request is received from an external device when an initialization prohibition signal is received, and initialize fault information in response to the reception of an initialization request when an initialization permission signal is received.

[0062] Figure 10 is a block diagram showing an example of the configuration of a gateway function 140 according to one embodiment. Here, an example is shown in which one control device has both a gateway function 140 and a slave control function 130. However, the control device is not limited to this example, and may have only the gateway function 140. The configuration of the slave control function 130 may be the same as that described using Figure 8, so its description is omitted here. As shown in Figure 10, the gateway function 140 includes a relay control unit 142.

[0063] The relay control unit 142 transmits a secondary initialization control status signal corresponding to the initialization control status signal received from the status management function 125 via the first bus (e.g., main bus 12) to a second bus (e.g., sub-bus 14) that is different from the first bus. The relay control unit 142 also outputs an initialization control signal to the initialization control unit 132 of the slave control function 130 on the same device. Furthermore, if the relay control unit 142 receives an initialization request from an external device via the first bus, it relays the initialization request to the second bus. The relay control unit 142 also outputs an initialization request to the initialization control unit 132 of the slave control function 130 on the same device. Then, if the relay control unit 142 receives a response signal to the initialization request from the slave control function 130 connected to the second bus, it relays the response signal to the first bus.

[0064] In a configuration as illustrated in Figure 10, the connection interface with an external device capable of sending initialization requests is preferably located on the first bus rather than the second bus, with reference to the gateway function 140. In this case, initialization requests sent from the external device will reach the second bus via the first bus. Furthermore, by incorporating priority control such as arbitration of collision frames based on CAN frame IDs, even if an initialization request is sent simultaneously with an initialization prohibition signal, all slave control functions 130 will be able to receive the initialization prohibition signal first, regardless of which bus each slave control function 130 is connected to.

[0065] <3. Example of processing flow> [3-1. Master Control] Figure 11 is a flowchart showing an example of the processing flow executed by the master control function 120 according to the above embodiment.

[0066] Referring to Figure 11, first, the comprehensive determination unit 122 of the master control function 120 monitors the vehicle status (step S10). For example, when protecting the throttle fail-safe function, the vehicle status may include the engine operating status and the operating status of the throttle fail-safe function. In this case, the comprehensive determination unit 122 continuously monitors whether the engine is on or off, and whether the throttle fail-safe function is on or off.

[0067] Next, the comprehensive determination unit 122 comprehensively determines whether or not to prohibit the initialization of fault information stored by each of the multiple control devices based on the state of the monitored vehicle (step S12). For example, the comprehensive determination unit 122 may determine to prohibit the initialization of fault information if the engine is on and the throttle failsafe function is on, and to permit the initialization of fault information otherwise.

[0068] The subsequent processing branches depending on whether it is determined that the initialization of fault information should be comprehensively prohibited or permitted (step S14). If the comprehensive determination unit 122 determines that the initialization of fault information should be prohibited (S14 / Yes), the first communication control unit 124 transmits an initialization prohibition signal to the bus indicating that the initialization of fault information should be comprehensively prohibited (step S16). If the comprehensive determination unit 122 determines that the initialization of fault information should be permitted (S14 / No), the first communication control unit 124 transmits an initialization permit signal to the bus indicating that the initialization of fault information should be permitted (step S18).

[0069] After an initialization control signal, which may be an initialization prohibition signal or an initialization permission signal, is transmitted, the process returns to step S10. Typically, while the vehicle communication control system 10 is in operation (i.e., during the period when initialization requests may be flowing across the network), the master control function 120 periodically repeats the processes from steps S10 to S18.

[0070] [3-2. State Management] Figure 12 is a flowchart showing an example of the processing flow executed by the master control function 120 according to the above embodiment.

[0071] Referring to Figure 12, first, the initialization state determination unit 127 of the state management function 125 receives the initialization control signal transmitted from the master control function 120 via the bus (step S20). For example, if the initialization control signal is a predetermined bit in a control frame 160 transmitted from the master control function 120, the initialization state determination unit 127 first detects a control frame 160 having a predetermined ID from among the various frames flowing on the bus. Then, the initialization state determination unit 127 extracts the bit at a predefined bit position contained in the detected control frame 160 as the initialization control signal.

[0072] Next, the initialization state determination unit 127 determines, based on the received initialization control signal, whether or not the system is in a state where initialization of fault information is prohibited (step S22). For example, if the bit extracted as the initialization control signal has a value that indicates initialization is prohibited, the initialization state determination unit 127 determines that the system is in a state where initialization of fault information is prohibited. Also, if the bit extracted as the initialization control signal has a value that indicates initialization is permitted, the initialization state determination unit 127 determines that the system is in a state where initialization of fault information is permitted.

[0073] The subsequent processing branches depending on whether it is determined that initialization of fault information is prohibited or permitted (step S24). If the initialization state determination unit 127 determines that initialization of fault information is prohibited (S24 / Yes), the second communication control unit 129 transmits an initialization prohibition status signal to the bus indicating that initialization of fault information is prohibited (step S26). If the initialization state determination unit 127 determines that initialization of fault information is permitted (S24 / No), the second communication control unit 129 transmits an initialization permission status signal to the bus indicating that initialization of fault information is permitted (step S28).

[0074] After an initialization control status signal, which may be an initialization prohibition status signal or an initialization permission status signal, is transmitted, the process returns to step S20. Typically, while the vehicle communication control system 10 is in operation (i.e., during the period when initialization requests may be flowing across the network), the state management function 125 periodically repeats the processing from steps S20 to S28.

[0075] [3-3. Slave Control] Figure 13 is a flowchart showing an example of the processing flow performed by the slave control function 130 according to the embodiment described above.

[0076] Referring to Figure 13, first, the initialization control unit 132 of the slave control function 130 receives an initialization control status signal transmitted from the state management function 125 via the bus (step S30). For example, if the initialization control status signal is a predetermined bit in a control frame 165 transmitted from the state management function 125, the initialization control unit 132 first detects a control frame 165 having a predetermined ID from among the various frames flowing on the bus. Then, the initialization control unit 132 extracts the bit at a predefined bit position contained in the detected control frame 165 as the initialization control status signal 155.

[0077] Next, the initialization control unit 132 updates the initialization prohibition status depending on the received initialization control status signal (step S32). For example, if the bit extracted as the initialization control status signal has a value that indicates the initialization prohibition state, the initialization control unit 132 sets the initialization prohibition status to "prohibited". Also, if the bit extracted as the initialization control signal has a value that indicates the initialization permit state, the initialization control unit 132 sets the initialization prohibition status to "permitted".

[0078] Next, the initialization control unit 132 determines whether or not an initialization request has been received from an external device (step S34). If no initialization request is received (S34 / No), the process returns to step S30, and the initialization control unit 132 receives the initialization control status signal again in the next cycle. If an initialization request is received (S34 / Yes), the process proceeds to step S36.

[0079] The processing from step S36 onward branches depending on the initialization prohibition status at that time. If initialization of fault information is permitted (S36 / Yes), the initialization control unit 132 initializes the fault information stored in memory 131 (step S38). Then, as a response to the initialization request, the initialization control unit 132 sends a response signal indicating that the initialization of the fault information has been completed (step S40). On the other hand, if initialization of fault information is prohibited, the initialization control unit 132 does not initialize the fault information and sends a response signal indicating that the initialization request is rejected (step S42).

[0080] The process then returns to step S30. Typically, while the vehicle communication control system 10 is operating, the slave control function 130 repeats the process from steps S30 to S42.

[0081] [3-4. Gateway] Figure 14 is a flowchart showing an example of the processing flow executed by the gateway function 140 according to the embodiment described above.

[0082] Referring to Figure 14, first, the relay control unit 142 of the gateway function 140 receives the initialization control status signal transmitted from the status management function 125 via the first bus (step S50). Then, the relay control unit 142 transmits a secondary initialization control signal corresponding to the received initialization control status signal to the second bus (step S52). The relay control unit 142 may, for example, generate a secondary control frame containing the bits of the initialization control status signal extracted from the received control frame and transmit the generated secondary control frame to the second bus. Alternatively, the relay control unit 142 may generate a secondary control frame by duplicating the data field of the received control frame without knowing which bits are the initialization control status signal, and transmit the generated secondary control frame to the second bus.

[0083] Furthermore, the relay control unit 142 determines whether or not an initialization request has been received from the first bus (step S54). If no initialization request is received (S54 / No), the process returns to step S50. If an initialization request is received (S54 / Yes), the process proceeds to step S56.

[0084] In step S56, the relay control unit 142 relays the initialization request received from the first bus to the second bus. Then, when the relay control unit 142 receives a response signal for the initialization request from the second bus (step S58), it relays that response signal to the first bus (step S60). If multiple control devices are connected to the second bus, multiple control devices may each send a response signal in response to a single relay of initialization requests.

[0085] <4. Summary> Up to this point, various embodiments of the technology relating to this disclosure have been described in detail using Figures 1 to 14. According to the embodiments described above, in a control device connected to a first bus that interconnects control devices within a vehicle, a comprehensive determination is made based on the state of the vehicle to determine whether or not to prohibit the initialization of fault information stored by each of the multiple control devices (master devices), and based on the result of the determination, an initialization control signal that controls whether or not to prohibit the initialization of the fault information is transmitted to the first bus. In addition, in a vehicle communication control device (state management device) connected to the first bus, a determination is made based on the initialization control signal received via the first bus to determine whether or not the system is in a state where the initialization of the fault information is prohibited, and based on the result of the determination, an initialization control state signal indicating whether or not the system is in a state where the initialization of the fault information is prohibited is transmitted to the first bus.

[0086] As a result, even if a control device (master device) implementing control logic for determining whether or not to prohibit the initialization of fault information is newly added to the first bus, the need to modify the control logic implemented in existing control devices (master and slave devices) other than the vehicle communication control device (state management device) is eliminated. Therefore, it is possible to achieve unified behavior of initialization control more easily than with existing methods, while suppressing the increase in production costs in proportion to the number of control devices installed in the vehicle.

[0087] Furthermore, according to the embodiment described above, if it is determined that the initialization of fault information is prohibited, an initialization prohibition status signal indicating that the initialization of fault information is prohibited is transmitted to the first bus as an initialization control status signal. Therefore, a slave device connected to the first bus can determine whether the initialization of fault information is prohibited at that time simply by monitoring whether or not an initialization prohibition status signal is received from the first bus as an initialization control status signal.

[0088] Furthermore, according to the embodiment described above, the initialization prohibition signal is a signal that prohibits a slave device that receives the initialization prohibition signal from initializing fault information in response to an initialization request received from an external device, regardless of the state of other devices. Therefore, even if a new master or slave device is introduced into the vehicle, the existing slave device does not need to consider the state of the new master device for initialization control. Moreover, it is sufficient for the new master or slave device to implement the same control logic for initialization control as the existing slave device. In this way, the embodiment described above improves the reusability of the control logic for initialization control and enhances the system's expandability.

[0089] Furthermore, according to the embodiment described above, if it is determined that the initialization of fault information is not prohibited, an initialization permission status signal indicating that the initialization of fault information is permitted is transmitted to the first bus. Therefore, the slave device can immediately determine whether the initialization of fault information is comprehensively prohibited or permitted at that time by monitoring the first bus and detecting an initialization control status signal, which is either an initialization prohibition status signal or an initialization permission status signal. In one embodiment, the initialization prohibition status signal and the initialization permission status signal may correspond to the first bit value and the second bit value, respectively, of a predetermined bit in a control frame periodically transmitted from the state management device. In this case, the slave device only needs to monitor the predetermined bit for initialization control. This means that the implementation of the initialization control function in the slave device is extremely easy.

[0090] This specification primarily describes examples in which the technology described herein is applied to hybrid vehicles. However, without limiting itself to such examples, the technology described herein is also applicable to non-hybrid vehicles (e.g., gasoline vehicles, diesel vehicles, or electric vehicles).

[0091] Furthermore, the processes performed by each of the functions described herein may be implemented using software, hardware, or a combination of software and hardware. The programs constituting the software are pre-stored, for example, in a non-temporary computer-readable storage medium provided inside or outside each control device. Then, each program is loaded into RAM (Random Access Memory) at runtime and executed by a processor such as a CPU (Central Processing Unit).

[0092] Although preferred embodiments of the present invention have been described in detail above with reference to the attached drawings, the present invention is not limited to these examples. It is clear to any person with ordinary skill in the art to which the present invention belongs that various modifications or alterations can be conceived within the scope of the technical idea described in the claims, and these are also understood to fall within the technical scope of the present invention. [Explanation of Symbols]

[0093] 10: Vehicle communication control system, 12: Main bus, 14: Sub-bus, 16: Diagnostic bus, 20-40: Control devices, 21-41: Sensors, 22-42: Actuators, 23-43: Fault information, 50: Body integration device, 60: Connection interface, 65: Diagnostic device (external device), 120: Master control function, 122: Comprehensive determination unit, 124: First communication control unit, 125: State management function, 127: Initialization state determination unit, 129: Second communication control unit, 130: Slave control function, 131: Memory, 132: Initialization control unit, 140: Gateway function, 142: Relay control unit, 150: Initialization control signal, 155: Initialization control state signal

Claims

1. A vehicle communication control system including a plurality of control devices and a vehicle communication control device, which are interconnected via a first bus, At least one of the plurality of control devices is A comprehensive determination unit that comprehensively determines whether or not to prohibit the initialization of fault information stored in each of the multiple control devices based on the vehicle's status, A first communication control unit generates an initialization control signal to control whether or not to prohibit the initialization of the fault information, in order to prevent one of the plurality of control devices from initializing the fault information in response to an initialization request received from an external device, regardless of the state of the other control devices, based on the result of the determination by the comprehensive determination unit, and transmits it to the first bus. The vehicle communication control device is: An initialization state determination unit that determines whether or not the initialization of the fault information is prohibited based on the initialization control signal received via the first bus, The system includes a second communication control unit that transmits an initialization control status signal to the first bus, which includes information on whether or not the initialization of the fault information is prohibited, based on the result of the determination by the initialization status determination unit. Each of the plurality of control devices, depending on the initialization control status signal received from the vehicle communication control device via the first bus, determines whether or not to initialize the fault information in response to the initialization request received from the external device, regardless of the status of the other control devices. Vehicle communication and control system.

2. The second communication control unit, when it determines that the initialization of the fault information is prohibited by the initialization state determination unit, transmits an initialization prohibition state signal to the first bus. The vehicle communication control system according to claim 1, wherein each of the plurality of control devices, when it receives the initialization prohibition state signal, does not initialize the fault information in response to the initialization request received from the external device, regardless of the state of the other devices.

3. The second communication control unit, when it determines that the initialization of the fault information is not prohibited by the initialization state determination unit, transmits an initialization permission state signal to the first bus. The vehicle communication control system according to claim 2, wherein each of the plurality of control devices initializes the fault information in response to the initialization request received from the external device, regardless of the state of the other devices, when the initialization permission status signal is received.

4. The vehicle communication control system according to claim 3, wherein the initialization prohibition state signal and the initialization permission state signal correspond to the first bit value and the second bit value, respectively, of a predetermined bit in a control frame periodically transmitted from the vehicle communication control device.

5. The vehicle communication control system according to any one of claims 1 to 4, wherein the vehicle communication control device is an engine control device that controls the engine.

6. The aforementioned vehicle communication control system is The vehicle communication control system according to any one of claims 1 to 5, further comprising a third communication control device that transmits a secondary initialization control state signal corresponding to the initialization control state signal received from the vehicle communication control device via the first bus to a second bus different from the first bus.

7. The vehicle communication control system according to claim 6, wherein the initialization request transmitted from the external device reaches the second bus via the first bus.

8. A vehicle communication control device connected to a first bus that interconnects multiple control devices within a vehicle, An initialization state determination unit determines whether the initialization of fault information is prohibited based on an initialization control signal received via the first bus, which is generated by at least one of the plurality of control devices and indicates the result of a comprehensive determination based on the state of the vehicle of whether or not to prohibit the initialization of fault information stored by each of the plurality of control devices, The system includes a second communication control unit that transmits an initialization control status signal to the first bus, which includes information on whether or not the initialization of the fault information is prohibited, based on the result of the determination by the initialization status determination unit. Vehicle communication control device.

Citation Information

Patent Citations

  • Vehicle controller

    JP2006051922A

  • Program rewriting system for electronic control device

    JP2008045436A

  • Vehicle communication control device

    JP2010143404A

  • Vehicle communication control apparatus

    JP2010266279A

  • Evaluation device, evaluation system, and evaluation method

    JP2017130911A