Control devices, telematics control devices and methods
The control device with a main and sub-control unit configuration, utilizing a switch mechanism for electrical isolation, addresses the challenge of updating agile parts in vehicle systems, ensuring separate certification and improved safety by isolating sub-units during critical events.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- BAYERISCHE MOTOREN WERKE AG
- Filing Date
- 2022-02-22
- Publication Date
- 2026-05-20
AI Technical Summary
Existing vehicle control devices face challenges in efficiently updating or changing agile parts without affecting safety-critical functions, leading to contradictory objectives of maintaining compatibility with rapidly evolving CE technologies and ensuring functional safety.
A control device comprising a main control unit and sub-control units, with a switch mechanism to deactivate sub-control units during critical events, ensuring electrical isolation and preventing interference with the main control unit, allowing separate certification and modification of agile and critical parts.
Enables flexible and cost-effective modification of agile parts without affecting certified critical functions, reducing the need for full recertification and enhancing system safety by isolating sub-control units during critical operations.
Smart Images

Figure 0007863113000001 
Figure 0007863113000002 
Figure 0007863113000003
Abstract
Description
Technical Field
[0001] The embodiments relate to a control device including a main control device and at least one sub-control device. Further embodiments relate to a method for operating a telematics control device and a control device.
Background Art
[0002] Modern vehicles with engines often have a number of network technologies. These network technologies enable, for example, vehicle connection to the outside via mobile communication or V2X (English: vehicle-to-X; German: Fahrzeug-zu-X-Kommunikation), vehicle connection to the user via Bluetooth or WiFi, and vehicle positioning via GNSS, for example. Here, the telematics control device (English: TCU: telematic control unit) is a central connection gateway that provides functions such as remote services and real-time traffic information. In addition, the E-Call (vehicle emergency reporting system) function is realized via the TCU, and the function is related to approval in many legal areas.
[0003] Since any change in the telematics control device can lead to additional effort in authentication, this should be avoided as much as possible after the authentication of the components has been successful. However, this means that the development of the components needs to be defined and implemented very early, and later changes may lead to additional significant effort.
[0004] For example, different categories of functions (e.g., software) in electronically controlled devices are known, which can be divided into two main categories. Here, the first category concerns parts related to safety and certification (e.g., safety-critical functions, such as eCall (vehicle emergency call system) or critical parts of control devices for performing V2X functions), and the second category concerns other applications (e.g., agile parts; for example, remote service or entertainment applications for performing functions without having an essential impact on the functional safety of the vehicle).
[0005] In many cases, the critical parts are set up early and attempted to be tested and certified. However, there is also the usual objective of continuing to develop and further modify the agile parts at a later point (for example, to enable compatibility with CE (consumer electronic) technologies that are developed more rapidly). However, these two objectives are contradictory. Therefore, updating or changing the agile parts at a later point in time is no longer possible without testing and certification of the critical parts.
[0006] To solve this problem, it is possible to use, for example, the separation of the two parts in different control devices. Currently, in control devices, the parts related to safety and authentication (e.g., critical parts) are separated from other applications (e.g., agile parts) and implemented by software or hardware solutions.
[0007] When separating at the software level, virtualization solutions such as virtual machines and hypervisors are used. While such virtualization solutions can be inexpensive, this concept can only reduce the risk of recertification or delta certification to a limited extent because both software parts (e.g., critical and agile parts) can run on the same hardware and chip.
[0008] At the hardware level, various solution possibilities exist. Therefore, it is possible to run critical components on a separate application processor. However, the cost, effort, and required component size are significant, and software changes on the external application processor could potentially continue to interfere with the functionality of critical software on the main processor. Thus, re-certification or delta certification cannot be reliably avoided.
[0009] While separation at the PCB (printed circuit board) level, either within the same or different control devices, is possible, it incurs even greater costs. Separation at the ECU level is similarly possible. This allows, for example, applications to be divided among other control devices, or simply new control devices to be developed. For instance, remote services could be implemented in a first control device (e.g., a gateway control device), and the entertainment portion in a second control device (e.g., a head unit). However, moving applications from one control device to another is not always beneficial and fundamentally contradicts the goal of high integration (reducing the number of control devices). [Overview of the project] [Problems that the invention aims to solve]
[0010] Therefore, the object of this disclosure is to provide an improved concept for vehicle control equipment, particularly telematics control equipment. [Means for solving the problem]
[0011] The problem is solved according to the embodiment of the independent claim. Another advantageous embodiment is described in the dependent claim, in the following description, and in reference to the drawings.
[0012] Accordingly, a control device is proposed that includes a main control device and at least one first sub-control device. The control device further includes a switch device for deactivating at least one sub-control device. Here, the main control device is configured to deactivate at least one sub-control device using the switch device when a predetermined event occurs.
[0013] A main control unit can be configured to execute processes for critical applications (e.g., applications requiring authorization). In contrast, a sub-control unit can be configured to execute agile applications (e.g., applications that do not require authorization from authorities). Nevertheless, in many situations, communication between the main and sub-control units can influence the main control unit.
[0014] To avoid such potential impacts in critical situations (for example, when a certain event occurs that requires the reliable execution of a critical function), the sub-controller can be deactivated as needed. This event could include, for example, the activation of the control unit's eCall (vehicle emergency call system) function. By deactivating it, it is possible to avoid, for example, the exchange of information between the main control unit and the sub-controller. With the sub-controller deactivated, the control unit can function as if it were a system with a main control unit but without a deactivated sub-controller. In other words, a switch can be used to switch between two functional systems in the control unit (for example, between a first functional system with a sub-controller and a second functional system without a sub-controller). Therefore, it may be possible to authenticate the control unit using only the main control unit, and then make changes to the sub-controller. This is because the sub-controller can be deactivated in the event of a critical event, thus not affecting the system portion authenticated by the main control unit.
[0015] For example, a switch device can be configured to electrically isolate the connection between a main control unit and at least one sub-control unit. In this case, the main control unit is configured to electrically isolate the connection to the sub-control unit by appropriately controlling the control unit to deactivate the sub-control unit. An advantage of isolation of the connection to deactivate a sub-control unit (e.g., physical isolation) is that the deactivation of the sub-control unit may be particularly reliable. For example, since no further connection can exist between the main control unit and the sub-control unit after isolation of the connection (e.g., by a switch, e.g., a semiconductor switch), when the sub-control unit is deactivated, it is impossible for a signal to flow from the sub-control unit to the main control unit. According to one embodiment, the switch device can be integrated into the main control unit. This may allow for even more reliable isolation of the electrical connection (e.g., simpler control of the switch device using the main control unit).
[0016] For example, the main control unit can be configured to stop the process running in at least one sub-control unit in order to deactivate the sub-control units. Such deactivation may have the advantage of being very easy to perform (e.g., interrupting the process running in the sub-control units). Furthermore, elements for physical isolation can be omitted, which makes it possible to configure the control unit at a lower cost.
[0017] In one embodiment, the control device is configured to include a second sub-control device. Here, the main control device is configured to deactivate only the first sub-control device, or both the first and second sub-control devices, depending on the type of predetermined event. For example, depending on the type of predetermined event that occurs, it is possible to deactivate only a predetermined sub-control device from among a plurality of sub-control devices. This makes it possible to improve the flexibility of the control device, for example. For example, when a first event occurs that affects the reliable execution of a corresponding critical function in the main control device, it may be sufficient to deactivate only the first sub-control device, whereas when a second event occurs that affects the reliable execution of a corresponding critical function in the main control device, it may be necessary to deactivate both (or more) sub-control devices. Therefore, when a predetermined event occurs, it may not be necessary to deactivate all agile functions of the control device if they are unnecessary from a safety standpoint, for example.
[0018] For example, the main control unit is a first main control unit, and the control unit can be configured to include at least one other main control unit having a lower priority level than the first main control unit. In this case, the first main control unit is configured to deactivate the other main control unit. The first main control unit can, for example, deactivate the second main control unit when a predetermined event occurs, similar to a sub-control unit. In this way, a hierarchy of critical functions of the main control unit can be formed, enabling the critical functions to operate reliably with a higher priority and greater safety.
[0019] For example, a first main control unit and another main control unit can be configured to deactivate at least one sub-control unit in different events, and / or deactivate different sub-control units of multiple sub-control units. For example, the reliable execution of a critical function of a different main control unit may require the deactivation of one sub-control unit (or different selections from multiple sub-control units). In other words, advantageously, each main control unit can be configured to deactivate a precisely selected sub-control unit that could hinder the reliable execution of a critical function of that main control unit.
[0020] For example, it is possible to configure the system so that the main control unit and at least one sub-control unit are formed on a common semiconductor chip. For example, it is possible to form multiple main control units and / or sub-control units on a common semiconductor chip. Here, the proposed system (e.g., control unit) that allows the deactivation of sub-control units and / or main control units with lower priority can simultaneously improve the system's integration density while enabling greater system flexibility (e.g., modification of the sub-control unit's function).
[0021] For example, the main control unit can be configured to be formed by a main processor on a common semiconductor chip, and the sub-control unit can be configured to be formed by sub-processors on a common semiconductor chip. Therefore, for example, in order to prevent the sub-processors from influencing the main processor, the main processor may be able to deactivate one or more sub-processors when necessary (e.g., in the event of a predetermined event). Thus, the part of the control unit related to authentication can be handled solely by the main processor.
[0022] For example, as mentioned above, a given event can be configured to include at least one of the following: an emergency function to be performed (e.g., an eCall (emergency call) function) or a V2X communication to be performed. Such critical functions of a vehicle may require particularly reliable functionality. For example, since the part of the control unit that remains active after the deactivation of a sub-control unit can be appropriately certified, it is possible to demonstrate reliable functionality in accordance with applicable regulations.
[0023] One aspect of the disclosure relates to a telematics control device for a vehicle. The telematics control device is configured to control the vehicle's wireless connectivity for critical vehicle functions. The telematics control device comprises the control devices described above or below. Such a telematics control device can offer the advantage that the critical functions of the telematics control device can be converted and configured as specified at a first point in time, while the agile functions of the telematics control device can be modified or added after the first point in time, independently of and without affecting the critical functions.
[0024] One aspect of the disclosure relates to a method for operating a control system having at least one main control unit and at least one sub-control unit. The method includes controlling the sub-control unit using the main control unit to execute a sub-process in the sub-control unit, the sub-process may have an impact on the performance of the main control unit. The method also includes receiving a request to execute a main process in the main control unit, the main process having a higher priority or safety level than the sub-process. The method also includes deactivating the sub-control unit after receiving a request to execute a main process in order to avoid the sub-control unit's influence on the main control unit while the main process is running.
[0025] Further details and aspects of the method are referred to in relation to the examples described above or below (e.g., the control device). The examples described can have additional features of one or more options corresponding to the proposed concept or one or more aspects referred to in relation to one or more of the examples described above or below.
[0026] Hereinafter, examples will be described in detail with reference to the accompanying drawings.
Brief Description of the Drawings
[0027] [Figure 1] FIG. is a schematic example of a control device having a main control device and a sub-control device. [Figure 2] FIG. is a schematic example of a control device in a telematics control device. [Figure 3] FIG. is a flowchart of a method for operating a control device.
Modes for Carrying Out the Invention
[0028] Various examples will be described in detail while referring to the accompanying drawings in which some examples are illustrated. In each figure, the thickness dimensions of lines, layers, and / or regions may be exaggerated for clarity. In the following description of the accompanying drawings showing only some exemplary examples, the same reference numerals may indicate the same or similar components.
[0029] An element represented as being "coupled" or "connected" to another element can be directly coupled or connected to the other element or elements can be present therebetween. Unless otherwise specified, all terms used herein (including technical and academic terms) have the same meaning ascribed to them by those skilled in the art to which the examples belong.
[0030] When changes are to be made to certified control equipment, complete recertification of the control equipment is often required. Various possibilities exist for separating functions, which can partially eliminate the need to recertify all functions and parts of the control equipment. In this case, software solutions cannot be partially improved in terms of efficiency, and separation to the PCB and ECU levels can incur significant costs; therefore, chip-based separation is a preferred solution. However, in this case, it may be necessary to minimize the risk of side effects from fewer critical functions (e.g., agile software parts) to critical functions (e.g., critical parts). To this end, the following concept is proposed.
[0031] Figure 1 shows a schematic example of a control device 10 having a main control device 11 and sub-control devices 12. A switch device 13 is formed to deactivate the sub-control devices 12. The main control device 11 is configured to deactivate at least one sub-control device 12 using the switch device 13 when a predetermined event occurs.
[0032] It is possible to ensure that parts of the control unit 10 no longer affect the control unit 10 by deactivating them as needed (for example, when a certain event occurs that requires the execution of a safety-related function or a critical function). For example, the sub-control unit 12 can be turned off as needed so that the remaining active parts of the control unit 10 can perform their functions without being interfered with by the functions of the sub-control unit 12.
[0033] The possibility of separation may result in situations where only the parts of the control unit that are not deactivated (e.g., not designed to be deactivated) need to function with particular reliability (e.g., require certification). In contrast, since the part can operate as an independent system, the deactivated sub-control unit 12 can be modified if necessary without requiring recertification of the entire system, i.e., the entire control unit 10 (for example, the sub-control unit 12 can be equipped with functions that are not related to safety for vehicles having the control unit 10).
[0034] Figure 2 shows a schematic example of a control device 10 in a vehicle telematics control device 20. In addition to the first main control device 11 and the first sub-control device 12, the control device 10 also shows another main control device 21 and another sub-control device 22. The first main control device can deactivate one or more of the first sub-control device 12, the other sub-control device 22, or the other main control device 21 using a switch device 13. Similarly, if necessary, the other main control device 21 may correspondingly deactivate the first and / or other sub-control devices 12, 22.
[0035] The proposed concept enhances safety and reduces hazards and risks by, for example, reducing the risk of side effects from agile parts to critical parts when separating agile and critical parts at the chip level. This can further reduce the risks of delta and recertification. The proposed concept includes a function in the main processor (e.g., main control unit) that allows for stopping, isolating, and, if necessary, turning off all other subprocessors (e.g., subcontrollers) that have non-critical functions. This ensures that the main processor guarantees all critical functionality and eliminates the impact of functions operating (progressing) in subprocessors. Consequently, all changes in those subprocessors (or generally referred to as non-critical parts of the system) are invalid and irrelevant to critical functions.
[0036] Therefore, during system execution time (e.g., normal operation), all processors and applications can initially operate (proceed) in parallel and without restriction (for example, when no predetermined event occurs). When a safety-related event occurs (e.g., a predetermined event; e.g., eCall (vehicle emergency call system) or V2X event), unrelated parts are stopped, connections are disconnected, or they are electrically switched off.
[0037] The following is an example of how the control unit operates. In normal operation, a critical application is active on the main processor, and one agile application may be active on each of the subprocessors 1 through n.
[0038] When a safety-related event is received, critical applications may continue to run on the main processor. In contrast, agile applications may be stopped on some subprocessors, and / or one or more other subprocessors may be completely shut down.
[0039] After the execution of a critical application, it is possible to restart all parts, for example (for example, the operation of control unit 10 returns to normal).
[0040] In this case, the concept can be generalized to multiple main processors (for example, a first main control unit 11 and another main control unit 21). In this case, for example, the first main processor can be configured to execute a first critical application and to deactivate a first selection of multiple subprocessors. Correspondingly, the second main processor can be configured to execute a second critical application and to deactivate a second selection of multiple subprocessors. This makes it possible to easily adapt the proposed concept to existing requirements (even for control devices other than telematics control devices).
[0041] Further details and embodiments are referenced in relation to the embodiments described above or below. The embodiment shown in Figure 2 may have one or more optional additional features corresponding to the proposed concept or one or more embodiments referenced in relation to one or more of the embodiments described above (e.g., Figure 1) or below (e.g., Figure 3).
[0042] Figure 3 shows a flowchart of method 30 for operating a control device such as those illustrated in Figures 1 and 2. Method 30 includes controlling a sub-control device using a main control device to execute a sub-process in the sub-control device 31, where the sub-process may affect the performance of the main control device. Method 30 also includes receiving a request to execute a main process in the main control device 32, where the main process has a higher priority or safety level than the sub-process. Furthermore, according to the method, in order to avoid the sub-control device affecting the main control device while the main process is running, the sub-control device is set to be deactivated after receiving a request to execute the main process 33.
[0043] According to the proposed method, if, for example, a critical process or function requires the full computing power of the main control unit, it is possible to deactivate a portion of the control unit. While the main control unit can normally control multiple subprocesses (and correspondingly transmit signals from subprocesses to the main control unit), it may be necessary to avoid interaction with subprocesses when executing system-critical functions. Therefore, according to the method, if the control unit should be used to perform a main process (e.g., a safety-critical process), such subprocesses (e.g., entertainment functions; e.g., user functions not directly related to the vehicle's driving function) can be blocked.
[0044] Further details and embodiments are referenced in relation to the embodiments described above or below. The embodiment shown in Figure 3 may have one or more optional additional features corresponding to the proposed concept or one or more embodiments referenced in relation to one or more of the embodiments described above (e.g., Figures 1-2) or below.
[0045] One aspect relates to a modular configuration for safety-related parts of highly integrated control equipment and functions. It may be possible to turn off or deactivate certain parts of the control equipment if necessary. The proposed concept allows for further modification or adaptation of agile parts of a system (e.g., control equipment) at later stages of development, without affecting critical system functions. Therefore, it is possible to avoid the need to recertify the entire system or control equipment every time a part of the system or control equipment is changed. Furthermore, the present invention may also encompass the following embodiments: 1. A vehicle control device (10) comprising a main control device (11) for executing processes of critical or safety-related applications, at least one first sub-control device (12) formed for executing agile applications, and a switch device (13) for deactivating at least one sub-control device (12), wherein the main control device (11) is configured to deactivate at least one sub-control device (12) using the switch device (13) when a predetermined safety-related event occurs. 2. The control device (10) according to 1. above, characterized in that a switch device (13) is formed to electrically isolate the connection between the main control device (11) and at least one sub-control device (12), and the main control device (11) is formed to electrically isolate the connection to the sub-control device (12) by corresponding control of the control device (10) in order to deactivate the sub-control device (12). 3. The control device (10) according to 1. or 2. above, characterized in that the main control device (11) is configured to stop a process in progress in at least one sub-control device (12) in order to deactivate the sub-control devices (12). 4. The control device (10) according to any one of 1 to 3 above, further comprising a second sub-control device (22), wherein the main control device (11) is configured to deactivate either only the first sub-control device (12) or both the first sub-control device (12) and the second sub-control device (22) depending on the type of a predetermined event. 5. A control device (10) according to any one of 1. to 4. above, characterized in that the main control device (11) is a first main control device (11), and the control device (10) includes at least one other main control device (21) having a lower priority level than the first main control device (11), and the first main control device (11) is configured to deactivate the other main control device (21). 6. The control device (10) according to 5. above, characterized in that the first main control device (11) and another main control device (21) are configured to deactivate at least one sub-control device (12) and / or deactivate different sub-control devices (12, 22) from among a plurality of sub-control devices (12, 22). 7. The control device (10) according to any one of 1. to 6. above, characterized in that the main control device (11) and at least one sub-control device (12) are formed on a common semiconductor chip. 8. The control device (10) according to 7. above, characterized in that the main control device (11) is formed by a main processor of a common semiconductor chip, and the sub-control device (12) is formed by a sub-processor of a common semiconductor chip. 9. A control device (10) according to any one of 1. to 8. above, characterized in that a predetermined event includes at least one of the following: an emergency notification function to be performed or a V2X communication to be performed. 10. A telematics control device (20) for a vehicle, wherein the telematics control device (20) is configured to control the wireless connection of the vehicle for critical vehicle functions, and the telematics control device (20) comprises a control device (10) as described in any one of 1. to 9. above. 11. A method (30) for operating a control device (10) having at least one main control device (11) and at least one sub-control device (12), wherein the method (30) Controlling the sub-controller (12) using the main control unit (11) in order to execute a sub-process in the sub-controller (12) (31), wherein the sub-process may have an impact on the performance of the main control unit; Receiving a request (32) to execute a main process in the main control unit (11), wherein the main process has a higher priority or safety level than the subprocess; In order to avoid the influence of the sub-controller (12) on the main control unit (11) while the main process is running, the sub-controller (12) is deactivated after receiving a request to run the main process (33). A method characterized by including the following.
Claims
1. A vehicle control device (10) comprising a main control device (11) for executing processes of critical or safety-related applications, at least one first sub-control device (12) formed for executing agile applications, and a switch device (13) for deactivating at least one sub-control device (12), wherein the main control device (11) is configured to deactivate at least one sub-control device (12) using the switch device (13) when a predetermined safety-related event occurs, and the control device (10) includes at least one other main control device (21) having a lower priority level than the first main control device (11), and the first main control device (11) is configured to deactivate the other main control device (21).
2. The control device (10) according to claim 1, characterized in that a switch device (13) is formed to electrically isolate the connection between the main control device (11) and at least one sub-control device (12), and the main control device (11) is formed to electrically isolate the connection to the sub-control device (12) by corresponding control of the control device (10) in order to deactivate the sub-control device (12).
3. The control device (10) according to claim 1 or 2, characterized in that the main control device (11) is configured to stop a process in progress in at least one sub-control device (12) in order to deactivate the sub-control devices (12).
4. The control device (10) according to any one of claims 1 to 3, further comprising a second sub-control device (22), wherein the main control device (11) is configured to deactivate either only the first sub-control device (12) or the second sub-control device (22) in addition to the first sub-control device (12), depending on the type of a predetermined event.
5. The control device (10) according to any one of claims 1 to 4, characterized in that the first main control device (11) and another main control device (21) are configured to deactivate at least one sub-control device (12) and / or deactivate different sub-control devices (12, 22) from among a plurality of sub-control devices (12, 22).
6. The control device (10) according to any one of claims 1 to 5, characterized in that the main control device (11) and at least one sub-control device (12) are formed on a common semiconductor chip.
7. The control device (10) according to claim 6, characterized in that the main control device (11) is formed by a main processor of a common semiconductor chip, and the sub-control device (12) is formed by a sub-processor of a common semiconductor chip.
8. The control device (10) according to any one of claims 1 to 7, characterized in that a predetermined event includes at least one of an emergency notification function to be performed or a V2X communication to be performed.
9. A telematics control device (20) for a vehicle, wherein the telematics control device (20) is configured to control the wireless connection of the vehicle for critical vehicle functions, and the telematics control device (20) comprises a control device (10) according to any one of claims 1 to 8.
10. A method (30) for operating a control device (10) having at least one main control device (11) and at least one sub-control device (12), wherein the method (30) Controlling the sub-control device (12) using the main control device (11) in order to execute a sub-process in the sub-control device (12) (31), wherein the sub-process may have an impact on the performance of the main control device; Receiving a request (32) to execute a main process in the main control unit (11), wherein the main process has a higher priority or safety level than the subprocess; In order to avoid the influence of the sub-controller (12) on the main control unit (11) while the main process is running, the sub-controller (12) is deactivated after receiving a request to run the main process (33). A method characterized by including the following.