Electronic control device and startup control method

JP7897820B2Active Publication Date: 2026-07-30ASTEMO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
ASTEMO LTD
Filing Date
2023-05-16
Publication Date
2026-07-30

AI Technical Summary

Benefits of technology

【0007】 本発明の1つの態様によれば、電子制御装置において、ウェイクアップ回路のレジスタの故障が生じている場合においても、メインマイコンの起動制御を正常に行うことができるようになる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007897820000001
    Figure 0007897820000001
  • Figure 0007897820000002
    Figure 0007897820000002
  • Figure 0007897820000003
    Figure 0007897820000003
Patent Text Reader

Abstract

To allow a wake-up circuit to normally perform start-up control of a microcomputer in an electronic control device even when a failure occurs in a register of the wake-up circuit.SOLUTION: An electronic control device is provided, which comprises a computer that includes a processor and a memory, and a wake-up circuit that performs start-up control of the computer. The wake-up circuit operates in any one of a first mode for starting the computer provided that communication is performed on a communication line connected to the outside, and a second mode for starting the computer only when receiving an identifier matching a wake-up identifier stored in a register included in the wake-up circuit. The computer identifies whether a failure occurs in the register of the wake-up circuit, and when the failure occurs in the register, upon receiving a shut-down instruction from the outside, sets the wake-up circuit to the first mode before shutting down the wake-up circuit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an electronic control device and a startup control method.

Background Art

[0002] As an example of a technique for normally performing startup processing in an electronic control device mounted on a vehicle, a technique has been proposed in which, based on a power supply state and startup requirements, the operation requirements of each application are determined, and only the applications that satisfy the operation requirements are started.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Here, in an electronic control device, there may be a configuration in which a wake-up circuit that controls the startup of a main microcomputer performs startup control of a microcomputer (microcontroller) that performs control processing of an in-vehicle device when receiving a predetermined wake-up identifier from an external unit or the like. In such a configuration, when a failure occurs in the register of the wake-up circuit, the wake-up identifier cannot be normally authenticated, and a situation may occur where startup control cannot be performed.

[0005] Therefore, in one aspect of the present invention, an object is to enable normal startup control of a microcontroller even when a failure occurs in a register of a wake-up circuit in an electronic control device.

Means for Solving the Problems

[0006] In one aspect of the present invention, an electronic control device is provided which includes a computer having a processor and memory, and a wake-up circuit for controlling the startup of the computer, wherein the wake-up circuit operates in either a first mode, which starts the computer on the condition that communication has been performed on a communication line connected to the outside, or a second mode, which starts the computer only when it receives an identifier that matches a wake-up identifier stored in a register of the wake-up circuit, and the computer identifies whether or not a fault has occurred in the register of the wake-up circuit, and if a fault has occurred in the register, the electronic control device sets the wake-up circuit to the first mode and then shuts down the computer when it receives a shutdown command from the outside. [Effects of the Invention]

[0007] According to one aspect of the present invention, in an electronic control device, even if a register in the wake-up circuit fails, the startup control of the main microcontroller can be performed normally. [Brief explanation of the drawing]

[0008] [Figure 1] This is an explanatory diagram showing an example of a control system according to embodiment of the present invention. [Figure 2] This diagram shows the register configuration of the wake-up IC in one embodiment of the present invention. [Figure 3] This is a flowchart showing the processing that occurs when the main microcontroller in one embodiment of the present invention is first started up. [Figure 4] This is a flowchart showing the processing that occurs when the main microcontroller in one embodiment of the present invention is first started up. [Figure 5] This is a flowchart showing the processing that occurs when the main microcontroller in one embodiment of the present invention is first started up. [Figure 6] This flowchart shows the processing that occurs when the main microcontroller restarts in one embodiment of the present invention. [Figure 7] This flowchart shows the processing that occurs when the main microcontroller restarts in one embodiment of the present invention. [Figure 8] This is a sequence diagram showing the state and processing of the wake-up IC and main microcontroller in one embodiment of the present invention (when the wake-up IC's registers are normal). [Figure 9] This is a sequence diagram showing the state and processing of the wake-up IC and main microcontroller in one embodiment of the present invention (when the wake-up IC's registers fail). [Modes for carrying out the invention]

[0009] Embodiments of the present invention will be described below with reference to the drawings. However, the present invention is not limited to the embodiments described herein, and different embodiments and their variations can be combined as appropriate.

[0010] [Control system configuration] Figure 1 shows an example of a control system 1 according to this embodiment. This control system 1 is mounted on a vehicle such as an automobile and controls various devices related to the vehicle's operation. Depending on the type of in-vehicle device to be controlled, the control system 1 can be classified into, for example, a powertrain control system such as engine control, a vehicle control system such as electric power steering and brake control, a body control system such as airbags and surrounding area monitoring, and an information system such as a navigation system and GPS (Global Positioning System). The control system 1 comprises an ECU 10 (Electronic Control Unit) that controls the in-vehicle device and external units 50A to 50C.

[0011] The ECU10 includes a wake-up circuit (IC) 20 and a main microcontroller 30. The wake-up IC 20 and the main microcontroller 30 are connected via an SPI (Serial Peripheral Interface) bus and a CAN (Controller Area Network) bus. A wake-up signal is transmitted from the wake-up IC 20 to the main microcontroller 30 via an inhibitor (INH) terminal. The ECU10 is also connected to a battery 40, from which power is supplied to the wake-up IC 20 and the main microcontroller 30.

[0012] The wake-up IC 20 is an electronic circuit that has the function of starting the main microcontroller 30 when predetermined conditions are met. These predetermined conditions will be described in detail later. The wake-up IC 20 includes a control unit 21, a register 22, and communication interfaces 23A to 23D.

[0013] The control unit 21 sends a wake-up signal to the main microcontroller 30 to start it up, depending on the operating mode in which the wake-up IC 20 is operating. Register 22 is a register that stores various setting values ​​used for the operation of the control unit 21. Details of the data stored in register 22 will be described later. Communication interfaces 23A to 23D have the function of enabling communication between the wake-up IC 20 and the outside world. For example, communication interfaces 23A and 23B are composed of CAN (Controller Area Network) transceivers, etc. Communication interface 23A performs CAN communication with external units 50A to 50C, and communication interface 23B performs CAN communication with the main microcontroller 30. Communication interface 23C performs SPI communication with the main microcontroller 30. Communication interface 23D transmits a wake-up signal to the main microcontroller 30 via the INH terminal. The wake-up IC 20 has a terminal that activates the wake-up function when a wake-up signal is input from the outside, but in this embodiment, this terminal is considered open and is not shown in the figure.

[0014] The main microcomputer 30 includes a processor 31, a RAM 32, a ROM 33, and communication interfaces 34A to 34C. These are interconnected by an internal bus. The processor 31 is hardware that executes an instruction set (such as data transfer, arithmetic operation, processing, control, management, etc.) described in a program, and is composed of an arithmetic unit, registers for storing instructions and information, peripheral circuits, and the like. The function of the processor 31 is realized when the program is executed. Details of the processing executed in the processor 31 will be described later.

[0015] The RAM 32 is a volatile memory in which data is lost when the power supply is cut off, and provides a temporary storage area used while the processor is operating. The ROM 33 is a non-volatile memory (such as an EEPROM or flash memory) that can be electrically rewritten, and stores the program body that operates in the processor 31 and various data used when the program is executed. In the present embodiment, a failure flag described later is stored in the ROM 33. The communication interfaces 34A to 34C have a function of realizing communication between the main microcomputer 30 and the outside. For example, the communication interface 34A performs CAN communication with the wake-up IC 20, and the communication interface 34B performs SPI communication with the wake-up IC 20. The communication interface 34C receives the wake-up signal transmitted from the wake-up IC 20 and activates the main microcomputer 30 by a main relay.

[0016] In the present embodiment, the communication method between the wake-up IC 20 and the external units 50A to 50C is CAN. However, for example, any communication method such as LIN (Local Interconnect Network), Ethernet (registered trademark), FlexRay, etc. can be used. Similarly, the communication method between the wake-up IC 20 and the main microcomputer 30 is not necessarily limited to the above example. Also, although not shown in the figure, communication between the main microcomputer 30 and the external units 50A to 50C is also possible. Furthermore, although not shown in the figure, the ECU 10 is communicably connected to the in-vehicle devices to be controlled.

[0017] FIG. 2 shows a region related to the processing executed in the present embodiment in the storage region of the register 22 of the wake-up IC 20. The register 22 includes two types of regions: a control register and a status register. The control register includes an operation mode setting region in which information for identifying the operation mode is set, and a wake-up CAN ID setting region in which a wake-up CAN ID, which is one aspect of the wake-up identifier (details will be described later), is set. The status register includes an error setting region in which information indicating that an illegal write has been made in the wake-up IC 20 is set.

[0018] [Operation Mode and Activation Conditions of Wake-up IC] Here, the operation mode of the wake-up IC 20 and the conditions under which the wake-up IC 20 activates the main microcomputer 30 will be described. The wake-up IC 20 enters standby mode when power is supplied from the battery 40, and upon receiving a start command from the main microcontroller 30, it starts the main microcontroller 30 and transitions to normal mode. Furthermore, when the main microcontroller 30 shuts down, the wake-up IC 20 transitions from normal mode to sleep mode. Conversely, upon receiving a start command from the main microcontroller 30, it starts the main microcontroller 30 again and transitions to normal mode. This transition between normal mode and sleep mode is based on a control signal received from the main microcontroller 30 via SPI communication. Specifically, the main microcontroller 30 sends a signal to set information identifying the operating mode of the wake-up IC 20 in the operating mode setting area of ​​register 22. The wake-up IC 20 operates in the operating mode based on this information set in the operating mode setting area of ​​register 22.

[0019] Furthermore, the Wake-Up IC20 has two types of sleep modes. The first mode is a selective sleep mode in which the main microcontroller 30 is started (WUF: Wake Up Frame) when a specific CANID is received. In this selective sleep mode, the wake-up IC 20 sends a start command to the main microcontroller 30 when the wake-up CANID received from an external source matches the one set in the wake-up CANID setting area of ​​register 22. In other words, the main microcontroller 30 is not started when a CANID other than the one set in the wake-up CANID setting area of ​​register 22 is received. The CANID is set in the wake-up CANID setting area by the main microcontroller 30 when it starts up.

[0020] The second mode is a sleep-wake-up mode (WUP) in which the main microcontroller 30 is started (WUP: Wake Up Pattern) not only when a specific CANID is received, but also when the CAN bus is operational, i.e., when there is a voltage change on the CAN bus. Note that the operation of the CAN bus is one form of communication taking place on a communication line connected to the outside.

[0021] As mentioned above, in this embodiment, the pattern in which the wake-up function operates when a wake-up signal is input from an external source (LWU: Local Wake Up) is disabled because the input terminal is open. Also, if an unauthorized write is made to the wake-up CANID setting area while operating in selective sleep mode, information indicating an error is set in the error setting area of ​​register 22. In this case, the wake-up IC 20 transitions to the sleep-wake-up mode described next, regardless of the mode set in the operation mode setting area.

[0022] Here, we will explain the technical challenges related to the operating modes of these wake-up ICs 20. Normally, when the main microcontroller 30 is shut down, the wake-up IC 20 operates in selective sleep mode. However, if some kind of failure occurs in register 22, such as sticking, the main microcontroller 30 may not be able to set the wake-up CANID in the wake-up CANID setting area of ​​register 22. In this case, it is not possible to properly determine whether the wake-up CANID received from an external source matches the one set in the wake-up CANID setting area of ​​register 22. As a result, even though the wake-up IC 20 has received a startup request from the main microcontroller 30, it may be unable to start the main microcontroller 30. In the control system 1 of this embodiment, it is possible to suppress the occurrence of such a situation by executing the process described below.

[0023] [Wake-up IC and main microcontroller processing] The processes performed by the wake-up IC 20 and the main microcontroller 30 will be explained with reference to the flowcharts shown in Figures 3 to 7 and the sequence diagrams shown in Figures 8 to 9. Figures 3 to 5 show the processing of the main microcontroller 30 during the initial startup when the battery 40 is connected to the wake-up IC 20 and power is supplied. Figures 8 and 9 are sequence diagrams showing the operation of the wake-up IC 20 and the main microcontroller 30 during the initial startup. Figure 8 shows the operation when the register 22 of the wake-up IC 20 is normal, and Figure 9 shows the operation when the register 22 of the wake-up IC 20 has a fault.

[0024] In step 101 (labeled S101 in the diagram; the same applies hereafter), the main microcontroller 30 transitions to startup mode (Smode). In step 102, the main microcontroller 30 performs initial startup processing. This initial processing includes, for example, the initialization of RAM 32. In step 103, the main microcontroller 30 reads the value of a fault flag stored in the ROM 33, which is a non-volatile memory whose data can be electrically rewritten. This fault flag is a value that will be set in steps 109 and 112, which will be described later.

[0025] In step 104, the main microcontroller 30 performs SPI communication and writes a setting value to register 22 of the wake-up IC 20. For example, the main microcontroller 30 writes the wake-up CANID, which is used to determine whether or not to start the main microcontroller 30 in selective sleep mode, to the wake-up CANID setting area. In step 105, the main microcontroller 30 performs SPI communication and reads the setting value of register 22 of the wake-up IC 20 that was written in step 104.

[0026] In step 106, the main microcontroller 30 determines whether there is a previous failure history in the wake-up IC 20, based on the value of the failure flag read in step 103. If there is a failure history, proceed to step 107 (Yes); otherwise, proceed to step 110 (No). In step 107, the main microcontroller 30 identifies whether a start request has been sent to the wake-up IC 20 from other control devices of the control system 1, i.e., external units 50A to 50C. Specifically, the main microcontroller 30 identifies the presence or absence of a start request by communicating with external units 50A to 50C to confirm whether they have sent a wake-up CANID to the wake-up IC 20.

[0027] In step 108, the main microcontroller 30 determines, based on the results of the verification process in step 107, whether or not a startup request has been sent from another ECU. If a request has been sent, proceed to step 109 (Yes); otherwise, proceed to step 114 (No). In step 109, the main microcontroller 30 sets the fault flag in RAM 32 to "0 (no fault)".

[0028] In step 110, the main microcontroller 30 performs an echo-back diagnosis to determine whether or not there is a fault in the register 22 of the wake-up IC 20. Specifically, the main microcontroller 30 determines whether or not there is a fault by checking whether the setting value written to the register 22 of the wake-up IC 20 in step 104 was read out correctly in step 105. In step 111, the main microcontroller 30 determines whether the result of the echo-back diagnosis is abnormal, that is, whether the setting value written to the register 22 of the wake-up IC 20 in step 105 could not be read correctly in step 106. If the result is abnormal, that is, if there is a fault in register 22, proceed to step 112 (Yes); otherwise, proceed to step 113 (No).

[0029] In step 112, the main microcontroller 30 sets the fault flag in RAM 32 to "1 (fault detected)". If the echo-back diagnosis result is abnormal, the main microcontroller 30 may also retry writing to and reading from register 22 within a time limit.

[0030] In step 113, the main microcontroller 30 determines whether or not it has received a shutdown command. This shutdown command is received, for example, by the wake-up IC 20 from external units 50A to 50C and sent to the main microcontroller 30. If a shutdown command is received, the process proceeds to step 114 (Yes); otherwise, normal operation continues (No). In step 114, the main microcontroller 30 transitions to shutdown mode (Umode).

[0031] In step 115, the main microcontroller 30 determines whether the fault flag setting value for RAM 32 is "1 (fault detected)". If the fault flag setting value is "1", proceed to step 116 (Yes); otherwise, proceed to step 118 (No). In step 116, the main microcontroller 30 prevents the wake-up IC 20 from transitioning to selective sleep mode. In step 117, the main microcontroller 30 notifies the external units 50A to 50C that a fault has occurred in register 22 of the wake-up IC 20. This allows the external units 50A to 50C to recognize that the main microcontroller 30 of the ECU 10 may be started by an unintended CANID. At this time, the main microcontroller 30 may also notify the correct wake-up CANID in preparation for when register 22 of the wake-up IC 20 is successfully repaired.

[0032] In step 118, the main microcontroller 30 sends a command to the wake-up IC 20 to transition to sleep mode via SPI communication. At this time, if the transition to selective sleep mode is not prohibited, the main microcontroller 30 sends a control signal to transition to selective sleep mode. In other words, the main microcontroller 30 sets the wake-up IC 20 to selective sleep mode. On the other hand, if the transition to selective sleep mode is prohibited in step 116, the main microcontroller 30 sends a control signal to transition to sleep-wake-up mode, which starts the main microcontroller 30 when the CAN bus is activated. In other words, the main microcontroller 30 sets the wake-up IC 20 to sleep-wake-up mode.

[0033] In step 119, the main microcontroller 30 writes the fault flag value set in RAM 32 to ROM 33, which is a non-volatile memory that can be electrically rewritten. This ensures that the fault flag value is retained even after shutdown without being erased. In step 120, the main microcontroller 30 performs a shutdown process.

[0034] Figures 6 and 7 show the processes executed in the wake-up IC 20 when the main microcontroller 30 is restarted from a state where it was shut down by the processes in steps 113 to 117 described above. Figure 6 shows the process when the register 22 of the wake-up IC 20 is normal, that is, when the wake-up IC 20 is set to selective sleep mode.

[0035] In step 121, since the wake-up IC20 is in selective sleep mode, it performs wake-up CANID authentication. That is, the wake-up IC20 determines whether or not it has received the wake-up CANID. If it has received it, it proceeds to step 122 (Yes); otherwise, it remains in wait (No). In step 122, the wake-up IC 20 performs the same process as the initial startup process of the main microcontroller 30. That is, it sends a startup request to the main microcontroller 30, and as a result, the main microcontroller 30 executes the same process as described in steps 101 to 120, and the main microcontroller 30 starts up.

[0036] Figure 7 shows the process when a fault occurs in register 22 of the wake-up IC 20, that is, when the wake-up IC 20 is set to sleep-wake-up mode. In step 131, it is determined whether the CAN bus is operating because the wake-up IC20 is in sleep-wake mode. If it is operating, proceed to step 132 (Yes); otherwise, wait (No). In step 132, the wake-up IC 20 performs the same process as the initial startup process of the main microcontroller 30. That is, it sends a startup request to the main microcontroller 30, and as a result, the main microcontroller 30 executes the same process as described in steps 101 to 120 above, and the main microcontroller 30 starts up.

[0037] [Effects of this embodiment, etc.] According to this embodiment, if a failure occurs in register 22, the main microcontroller 30 sets the operating mode of the wake-up IC 20 to sleep-wake-up mode and then shuts down. Therefore, when a startup request for the main microcontroller 30 is received again, even if the wake-up CANID is not correctly set in register 22 due to the failure of register 22 and wake-up CANID authentication is not performed correctly, the main microcontroller 30 will start up, provided that CAN communication is working. Thus, it is possible to suppress the failure of the main microcontroller 30 to start up due to a failure of register 22 without requiring any hardware changes.

[0038] On the other hand, according to this embodiment, if there is no fault in the register 22 of the wake-up IC 20, the wake-up IC 20 is set to selective sleep mode. This allows the main microcontroller 30 to be started only when a wake-up CANID indicating a start request is received.

[0039] In this embodiment, as described above, when a failure occurs in register 22, the wake-up IC 20 is set to sleep-wake-up mode. Therefore, the main microcontroller 30 is started only when CAN communication has been performed. Consequently, it is possible that the main microcontroller 30 may be started even if communication with a CANID that is not intended to start the main microcontroller 30 is performed. In this embodiment, a failure flag is set in the wake-up IC 20 to indicate whether or not a failure has occurred in register 22, and when starting up again, the presence or absence of a failure in register 22 is checked based on this failure flag. If a failure has occurred in register 22, it is checked whether or not a start request has been sent to the external units 50A to 50C, and if no start request has been sent, a shutdown is performed again. Therefore, it is possible to suppress unnecessary processing load and power consumption that may occur when the main microcontroller 30 is started and continues to operate due to communication with a CANID that is not intended to start the main microcontroller 30.

[0040] Furthermore, in this embodiment, when a failure occurs in register 22, the external units 50A to 50C are notified of the failure. This prevents the external units 50A to 50C from unintentionally starting up the main microcontroller 30 by performing unnecessary communication.

[0041] [others] The embodiments of the present invention described above are only a part of the embodiments that can be conceivable within the technical scope of the present invention, and are disclosed as examples of the present invention, and do not limit the technical scope of the present invention. Furthermore, the functional and physical configurations in each embodiment are not limited to the above-described forms, and for example, each function and physical resource can be implemented in an integrated manner, or conversely, in a more distributed manner, or furthermore, parts of the configuration can be added, deleted, or replaced with other configurations. [Explanation of symbols]

[0042] 1…Control system, 10…ECU, 20…Wake-up IC, 21…Control unit, 22…Register, 30…Main microcontroller, 31…Processor, 32…RAM, 33…ROM, 40…Battery, 50A~50C…External unit

Claims

1. An electronic control device comprising a computer having a processor and memory, and a wake-up circuit for controlling the startup of the computer, The wake-up circuit operates in either a first mode, which starts the computer on the condition that communication has occurred on a communication line connected to the outside, or a second mode, which starts the computer only when it receives an identifier that matches a wake-up identifier stored in a register of the wake-up circuit. The computer identifies whether a fault has occurred in the register of the wake-up circuit, and if a fault has occurred in the register, it sets the wake-up circuit to the first mode and then shuts down the computer when it receives a shutdown command from an external source. Electronic control unit.

2. The electronic control device according to claim 1, wherein the computer sets the wake-up circuit to the second mode and then shuts down the computer if the register is functioning correctly.

3. The electronic control device according to claim 1 or 2, wherein the computer, when a failure occurs in the register, sets a value in the failure flag in the memory indicating that a failure has occurred in the register, and at the next startup, refers to the failure flag and, if a value indicating that a failure has occurred in the register is set, identifies whether or not a startup request has been received from an external electronic control device, and if a startup request has been received from the outside, continues the current startup state, while if no startup request has been received, shuts down.

4. The electronic control device according to claim 1 or 2, wherein the computer notifies an external party of the occurrence of a failure when it identifies that a failure has occurred in the register.

5. An electronic control device comprising a computer having a processor and memory, and a wake-up circuit for controlling the startup of the computer, wherein the wake-up circuit operates in either a first mode in which it starts the computer on the condition that communication has occurred on a communication line connected to the outside, or a second mode in which it starts the computer only when it receives an identifier that matches a wake-up identifier stored in a register of the wake-up circuit, wherein the computer Identify whether or not a fault has occurred in the register of the wake-up circuit. If a fault is detected in the register, when a shutdown command is received, the wake-up circuit is set to the first mode before the shutdown is performed. Startup control method.