Electronic control unit and program

JP7917836B2Active Publication Date: 2026-09-09TOYOTA JIDOSHA KK
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2024034178
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-06
Publication Date
2026-09-09
Estimated Expiration
2044-03-06

AI Technical Summary

Benefits of technology

【0009】 本開示によれば、OTAによるデータ書き換え動作と駐車中サービスの実行とが併存した場合にダイアグ記憶の懸念を解消しつつ駐車中サービスの利便性を確保することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007917836000001
    Figure 0007917836000001
  • Figure 0007917836000002
    Figure 0007917836000002
  • Figure 0007917836000003
    Figure 0007917836000003
Patent Text Reader

Abstract

To ensure the convenience of services during parking while eliminating concerns about diagnostic memory in the case that data rewriting operation by an OTA and execution of services during parking coexist.SOLUTION: An electronic control device for executing services during parking by using a specific function of a vehicle while ignition of a vehicle is off can receive activate information showing the completion of processing preparation of another electronic control device which performs activate processing for writing update object information including a program or data acquired from an external device in a nonvolatile memory mounted on the vehicle to validate the update object information due to refusal to use the specific function, and suppresses execution of the services during parking in the case of receiving the activate information.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an electronic control device and a program. [Background Art]

[0002] In recent years, along with the diversification of vehicle control such as driving assistance functions and automatic driving functions, the scale of programs for vehicle control, diagnosis and the like installed in vehicle electronic control devices (hereinafter also referred to as ECUs (Electronic Control Units)) has been increasing. In addition, along with version upgrades for functional improvements and the like, opportunities for rewriting (reprogramming) ECU programs are also increasing. On the other hand, along with the development of communication networks, connected car technology has also become widespread. Under such circumstances, for example, Patent Document 1 discloses that a vehicle master device as a relay device is provided on the vehicle side, and the vehicle master device distributes update data wirelessly received from a center device to the ECU to be rewritten, and instructs the ECU to be rewritten to write the update data, whereby a technique for rewriting the program of the ECU to be rewritten by OTA (Over The Air) is proposed. [Prior Art Documents] [Patent Documents]

[0003] [Patent Document 1] Japanese Unexamined Patent Publication No. 2020-27640 [Summary of the Invention] [Problem to be Solved by the Invention]

[0004] Patent Document 1 describes an ECU having a plurality of data storage surfaces as the ECU to be rewritten. For example, in a rewrite target ECU having two surfaces, a surface A and a surface B, update data of a new program is written to the surface B, the surface B to which the update data of the new program has been written is switched from a non-operating surface to an operating surface, and the surface B switched from the non-operating surface to the operating surface is started, thereby executing the new program.

[0005] Patent Document 1 aims to properly complete program rewriting in a configuration having multiple data storage surfaces. The invention described in Patent Document 1 is configured to be installed while the vehicle is drivable or parked, and activated while parked. This configuration makes it possible to properly complete program rewriting in a configuration having multiple data storage surfaces.

[0006] While parked, there may be a need to perform parking services that require system operation, in addition to data rewriting operations via OTA. However, the technology described in Patent Document 1 may have to refuse to hold the system main relay during the transition from ignition off to ignition on under certain conditions. For example, if the ECU to be rewritten is a battery ECU and a rewriting process is performed via OTA to switch sides, the system main relay will be forcibly shut off, raising concerns about system main relay sticking. To resolve this concern about system main relay sticking, the battery ECU is forced to refuse to hold the system main relay. In this situation where the ECU to be rewritten is forced to refuse to hold the system main relay, attempting to perform parking services may result in the system main relay hold request not being accepted, raising concerns about diagnostic memory. If the concern about diagnostic memory is resolved by unconditionally not performing parking services when performing data rewriting via OTA, it will be impossible to respond to system operation requests for parking services, thus compromising convenience.

[0007] This disclosure aims to ensure the convenience of the parking service while eliminating concerns about diagnostic memory when OTA data rewriting operations and the execution of the parking service coexist. [Means for solving the problem]

[0008] This disclosure relates to an electronic control unit that performs a parking service using a specific function of a vehicle while the vehicle's ignition is off, and which can receive activation information indicating that another electronic control unit has completed preparation for processing, which involves writing update target information, including a program or data acquired from an external device, to a non-volatile memory installed in the vehicle to activate it, along with refusing to use the specific function, and suppresses the execution of the parking service when the activation information is received. This disclosure also applies to programs that enable similar functionality in an electronic control unit. [Effects of the Invention]

[0009] According to this disclosure, when OTA data rewriting operations and the execution of parking services coexist, it is possible to ensure the convenience of parking services while eliminating concerns about diagnostic memory. [Brief explanation of the drawing]

[0010] [Figure 1] Figure 1 is a diagram illustrating the configuration of an electronic control system including an electronic control device according to this embodiment. [Figure 2] Figure 2 is a timing chart illustrating the operation of the electronic control system shown in Figure 1. [Figure 3] Figure 3 is a timing chart illustrating the operation of the electronic control system shown in Figure 1. [Figure 4] Figure 4 is a timing chart illustrating the operation of the electronic control system shown in Figure 1. [Figure 5] Figure 5 is a flowchart illustrating the operation of the electronic control system shown in Figure 1. [Figure 6] Figure 6 is a timing chart illustrating the operation of the electronic control system shown in Figure 1. [Figure 7] Figure 7 is a timing chart illustrating the operation of the electronic control system shown in Figure 1. [Figure 8]Figure 8 is a timing chart illustrating the operation of the electronic control system shown in Figure 1. [Figure 9] Figure 9 is a flowchart illustrating the operation of the electronic control system shown in Figure 1. [Figure 10] Figure 10 is a block diagram of the electronic control system shown in Figure 1. [Modes for carrying out the invention]

[0011] This embodiment will be described below with reference to the attached drawings. To facilitate understanding of the explanation, the same reference numerals are used for identical components in each drawing whenever possible, and redundant explanations are omitted.

[0012] The electronic control system 2 will be described with reference to Figure 1. The electronic control system 2 is a system installed in a vehicle. Vehicles on which the electronic control system 2 is installed are well-known vehicles equipped with a drive power supply and drive motor, such as EHV (Electric Hybrid Vehicle), BEV (Battery Electric Vehicle), and PHEV (Plug-in Hybrid Electric Vehicle).

[0013] The electronic control system 2 is a system that allows the vehicle control and diagnostic programs installed in the electronic control unit (hereinafter also referred to as the ECU (Electronic Control Unit)) to be rewritten via OTA (Over The Air). In this embodiment, the case of rewriting the program using wireless communication will be described, but it can also be applied to the case of rewriting data used in various applications, such as map data used in map applications and control parameters used in the ECU, using wireless communication.

[0014] Rewriting a program using wireless communication includes, in addition to acquiring and rewriting the program from outside the vehicle via wireless communication, acquiring and rewriting various types of data used when the program is executed from outside the vehicle via wireless communication.

[0015] As shown in FIG. 1, the electronic control system 2 includes a CGW 21, a DCM 22, an in-vehicle display 23, a power supply drive ECU 24, an execution target ECU 25, a parking service request ECU 26, a vehicle power management ECU 27, an SMR 28, an auxiliary battery 31, a power relay 32, buses 41, 43, 46, and signal lines 42, 44, 45.

[0016] CGW (Central Gate Way) 21 is a vehicle gateway device. DCM (Data Communication Module) 22 is an in-vehicle communication device. The DCM 22 and the CGW 21 are configured to enable data communication via the bus 46.

[0017] The DCM 22 performs data communication with an external device (not shown) via a communication network. When the DCM 22 downloads update target information including a program or data from the external device, the DCM 22 transfers the downloaded update target information to the CGW 21.

[0018] The CGW 21 has a data relay function. When the CGW 21 acquires update target information from the DCM 22, the CGW 21 instructs a rewriting target ECU that is a rewriting target to write the acquired update target information, and distributes the update target information to the rewriting target ECU. Further, when the writing of the update target information is completed in the rewriting target ECU and the rewriting is completed, the CGW 21 instructs the rewriting target ECU to perform activation that validates the program or the like after the completion of the rewriting.

[0019] Bus 46 is also connected to an in-vehicle display 23 that is capable of data communication. The in-vehicle display 23 has the function of receiving operation input from the user and displaying various screens, and also serves as a navigation function. The functions of the in-vehicle display 23 may also be performed by a mobile device such as a smartphone or tablet that the user can carry. While inside the vehicle, the user can perform operation input while checking various screens related to rewriting the application program on the in-vehicle display 23, and perform procedures related to rewriting the application program.

[0020] CGW21 and DCM22 constitute the master device in the electronic control system 2 and function as OTA masters. The functional division between CGW21 and DCM22 as master devices may be configured as such. In addition to bus 46, buses 41 and 43 are connected to CGW21.

[0021] The CGW21 has a microcomputer (hereinafter referred to as "microcontroller"), a data transfer circuit, a power supply circuit, and a power supply detection circuit as its electrical functional blocks. The microcontroller has a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), and flash memory. The flash memory includes a secure area in which information cannot be read from outside the CGW21. The microcontroller executes various control programs stored in a non-transitional physical storage medium to perform various processes and control the operation of the CGW21.

[0022] The data transfer circuit controls data communication between buses 41, 43, and 46 in accordance with the CAN (Controller Area Network, registered trademark) data communication standard and diagnostic communication standard. The power supply circuit receives battery power, accessory power, and ignition power as input. The power supply detection circuit detects the voltage values ​​of the battery power, accessory power, and ignition power input from the power supply circuit, compares these detected voltage values ​​with predetermined voltage thresholds, and outputs the comparison result to the microcontroller. Based on the comparison result input from the power supply detection circuit, the microcontroller determines whether the battery power, accessory power, and ignition power supplied to the CGW21 from an external source are normal or abnormal.

[0023] The DCM22 has a microcontroller, a wireless circuit, a data transfer circuit, a power supply circuit, and a power supply detection circuit as its electrical functional blocks. The microcontroller has a CPU, ROM, RAM, and flash memory. The flash memory includes a secure area where information cannot be read from outside the DCM22. The microcontroller executes various control programs stored in the non-transitional physical storage medium to perform various processes and control the operation of the DCM22.

[0024] The wireless circuit controls data communication via a communication network with external devices. The data transfer circuit controls data communication compliant with the CAN data communication standard with bus 46. The power supply circuit receives battery power, accessory power, and ignition power as inputs. The power supply detection circuit detects the voltage values ​​of the battery power, accessory power, and ignition power inputs from the power supply circuit, compares these detected voltage values ​​with predetermined voltage thresholds, and outputs the comparison result to the microcontroller. Based on the comparison result input from the power supply detection circuit, the microcontroller determines whether the battery power, accessory power, and ignition power supplied to the DCM22 from an external source are normal or abnormal.

[0025] Bus 41 is connected to the power drive ECU 24, the execution target ECU 25, and the parking service request ECU 26 so that they can communicate with each other. Bus 43 is connected to the vehicle power management ECU 27 so that they can communicate with each other.

[0026] The Power Supply Drive ECU24 is an ECU that controls the power supply. For example, if the vehicle is an EHV, it is a hybrid ECU that outputs control signals to the engine ECU, motor ECU, and battery ECU.

[0027] The target ECU 25 is the ECU whose program and data are rewritten via OTA in this embodiment, and is the ECU that is subject to OTA reprogramming. In this embodiment, it is described as a battery ECU.

[0028] The Parking Service Request ECU 26 is an ECU for performing parking services. Parking services are services performed by holding the system main relay while the vehicle's ignition is off. In this embodiment, the Parking Service Request ECU 26 is neither an OTA STARTER nor an ECU that performs OTA.

[0029] The Vehicle Power Management ECU 27 is an ECU that manages the entire vehicle power supply. For example, when a special power ON request is sent from the Parking Service Request ECU 26, the Vehicle Power Management ECU 27 outputs a special power ON signal to the Power Drive ECU 24. In the following description and in the diagrams, the special power and the flag related to the special power will also be referred to as "IGB". The Vehicle Power Management ECU 27 transmits the special power ON signal to the Power Drive ECU 24 using the direct signal line 42. Upon receiving the special power ON signal, the Power Drive ECU 24 turns on the power relay 32. The power relay 32 is a relay driven by the Power Drive ECU 24 that turns the power of other ECUs ON and OFF. When the power relay 32 is turned ON, power is supplied from the auxiliary battery 31 and the execution target ECU 25 starts up.

[0030] The power-driven ECU 24 and the execution target ECU 25, which is a battery ECU, output an SMR (System Main Relay) retention request signal to the SMR 28. The power-driven ECU 24 transmits the SMR retention request signal, for example, using signal line 44. The execution target ECU 25 transmits the SMR retention request signal, for example, using signal line 45.

[0031] The SMR28 is the system's main relay. The SMR28, being the system's main relay, is installed between the drive battery (not shown) and the power control unit (not shown), and switches between a conductive state and a non-conductive state between the drive battery and the power control unit. The SMR28 becomes conductive when it receives an SMR hold request signal, and becomes non-conductive when it no longer receives an SMR hold request signal.

[0032] Each of the above-mentioned ECUs has, as an electrical functional block, a microcontroller, a data transfer circuit, a power supply circuit, and a power supply detection circuit. The microcontroller has a CPU, ROM, RAM, and flash memory. The flash memory includes a secure area in which information cannot be read from outside the ECU. The microcontroller executes various control programs stored in a non-transitional tangible storage medium to perform various processes and control the operation of the ECU.

[0033] Each of the above-mentioned ECUs includes a so-called ROM-two-surface microcontroller. For example, a microcontroller has a first data storage surface and a second data storage surface, each storing at least one of either a program or parameter data. Based on this premise, when the vehicle is in a driving state or a parked state, the microcontroller operates at least one of the programs or data stored on the first data storage surface, which is the operational surface (old surface), and writes at least one of the update program or update data obtained from an external device to the second data storage surface, which is the non-operational surface. When the vehicle is parked, the microcontroller performs an activation process to switch the operational surface from the first data storage surface to the second data storage surface.

[0034] The data transfer circuit controls data communication compliant with the CAN data communication standard between buses 41 and 43. The power supply circuit receives battery power, accessory power, and ignition power. The power supply detection circuit detects the voltage values ​​of the battery power, accessory power, and ignition power input from the power supply circuit, compares these detected voltage values ​​with predetermined voltage thresholds, and outputs the comparison result to the microcontroller. Based on the comparison result input from the power supply detection circuit, the microcontroller determines whether the battery power, accessory power, and ignition power supplied to the ECU from an external source are normal or abnormal. Note that the core ECUs have basically the same configuration, although the loads they connect to, such as sensors and actuators, may differ.

[0035] Next, the operation of the electronic control system 2 will be described. First, the operation of the electronic control system 2 when no processing specific to this embodiment is performed will be described with reference to Figure 2. The timing chart shown in Figure 2 shows the operation of the OTA master (CGW21 and DCM22), the parking service request ECU26, the vehicle power management ECU27, the power drive ECU24, and the execution target ECU25 along their respective time axes.

[0036] In the initial state shown in Figure 2, the ignition is ON. By time t1, the OTA master performs status checks, etc. Status checks include confirming whether the writing of the program and data received via OTA is complete. If the writing of the program and data received via OTA is complete at time t1, a request for user activation approval is displayed on the in-vehicle display 23. In this embodiment, it is assumed that user activation approval has been granted at time t1.

[0037] Between time t1 and time t2, the OTA master outputs a request to configure the screen switching. At time t2, the user switches the ignition to OFF. When the user ignition is turned OFF, the OTA master's power supply switches from Hi to Lo.

[0038] At time t5, the user switches the ignition ON. When the user ignition is ON, the OTA master's power switches from Lo to Hi. From time t2 to time t5, the power is Lo, so the OTA master is inactive. At time t5, the power becomes Hi, so the OTA master starts up. At time t6, the OTA master has finished starting up. At time t6, the user performs activation confirmation (Teady-ON) via the in-vehicle display 23. From time t6 to time t7, the OTA master performs program and data version consistency checks.

[0039] The parking service request ECU26 sets a flag (IGB-ON) to turn on the special power supply at time t3, requesting the start of parking service.

[0040] The vehicle power management ECU 27 switches the direct ignition signal and CAN signal ON and OFF in accordance with the user's ignition operation. In the following explanation and in the diagrams, user ignition and the flag related to user ignition will also be referred to as "IGP". The vehicle power management ECU 27 switches the direct ignition signal and CAN signal of the special power supply (IGB) ON and OFF in accordance with the special power supply flag (IGB-ON) of the parking service request ECU 26. Therefore, at time t3, the special power supply (IGB) is turned ON.

[0041] The power-driven ECU24 executes system shutdown processing from time t2 when the user turns off the ignition (IGP). In this embodiment, it is assumed that system shutdown processing will be executed until time t4 unless otherwise requested.

[0042] Incidentally, when the parking service request ECU26 sets the flag (IGB-ON) to turn on the special power supply at time t3 and requests the start of parking service, the special power supply (IGB) is turned on. At time t3, the power supply drive ECU24 is in the process of shutting down the system, but because the special power supply (IGB) is turned on, it terminates the system shutdown process and moves to the system startup process. At time t3, when it moves to the system startup process, the power supply drive ECU24 outputs a hold request to the SMR28.

[0043] The power supply drive ECU 24 keeps the power relay 32 ON until the system shutdown process is complete. In Figure 2, the system startup process is performed before the system shutdown process is complete, so the power relay 32 remains ON instead of turning OFF.

[0044] The battery ECU, the execution target ECU25, performs the power-on process on the old side of the microcontroller. When the user turns on the ignition (IGP), the execution target ECU25 switches to execution on the new side of the microcontroller. The execution target ECU25 also has essential functions for parking service requested by the parking service request ECU26, such as the holding process for the SMR28.

[0045] The execution target ECU 25 performs a shutdown process for the SMR28, which is a control that inhibits ECU sleep, during the system shutdown process of the power supply drive ECU 24. In this embodiment, the shutdown process for the SMR28 is completed between time t2 and time t3, and the system enters a state waiting for the power relay 32 to be turned OFF. At this timing, the execution target ECU 25 turns OFF the drive of the SMR28 and rejects the request to hold the SMR28.

[0046] As explained above, while the parking service request ECU26 outputs a request to retain the SMR28 at time t3, the execution target ECU25 rejects the request to retain the SMR28. This creates a discrepancy between the two requests, raising concerns that the data may be stored in the diagnostic database.

[0047] Next, referring to Figure 3, we will explain an example of a process that resolves the diagnostic memory concerns mentioned above. The timing chart shown in Figure 3 also shows the operation of the OTA master (CGW21 and DCM22), the parking service request ECU26, the vehicle power management ECU27, the power drive ECU24, and the execution target ECU25 along their respective time axes. The prerequisite operations are the same as those explained in Figure 2, so we will mainly explain the differences.

[0048] The OTA master outputs OTA phase information and OTA activation interval information. OTA phase information indicates the status of the OTA process. For example, if the OTA phase information is "3", it indicates that the program or data is being installed. For example, if the OTA phase information is "4", it indicates that activation and version compatibility checks are in progress. For example, if the OTA phase information is "0", it indicates that it is waiting. OTA activation interval information indicates that the OTA process is activating and version compatibility checks are in progress.

[0049] In the example shown in Figure 3, at time t1, the OTA phase information switches from "3" to "4," and the OTA activation interval information switches from OFF to ON. At time t7, the OTA phase information switches from "4" to "0," and the OTA activation interval information switches from ON to OFF.

[0050] The OTA phase information and OTA activation interval information are configured to be received by the Parking Service Request ECU 26. Therefore, the Parking Service Request ECU 26 can recognize that OTA processing is being performed from time t1 to time t7. In this embodiment, this interval is designated as a suppression period during which the Parking Service Request ECU 26 does not request parking services. Therefore, unlike the example explained with reference to Figure 2, the flag to turn on the special power supply (IGB) is not set at time t3, and the start of parking services is not requested. Although the Parking Service Request ECU 26 can determine which phase of OTA is in based on the OTA phase information and OTA activation interval information, it cannot obtain information on which ECU is the target of the OTA.

[0051] Since parking services are suppressed, the vehicle power management ECU 27 does not turn on the special power supply (IGB). The system shutdown process by the power drive ECU 24 continues without interruption until the originally scheduled time t4, as shown in Figure 2, and is completed.

[0052] At time t4, the system shutdown process is completed, so the power-driven ECU 24 turns off the power relay 32. The execution target ECU 25 is waiting for the power relay 32 to turn off, so it turns off its power at time t4.

[0053] The target ECU25 completes the SMR28 shutdown process between time t2 and time t3, and enters a state where it rejects the SMR28 retention request. However, since the parking service is suppressed, the discrepancy described with reference to Figure 2 does not occur, and concerns about diagnostic memory are resolved.

[0054] At time t7, the OTA phase information switches from "4" to "0," and the OTA activation section information switches from ON to OFF, so the parking service suppression is released at this time.

[0055] Next, referring to Figure 4, we will explain an example of a process that resolves the diagnostic memory concerns mentioned above. The timing chart shown in Figure 4 also shows the operation along the time axis of the OTA master (CGW21 and DCM22), the parking service request ECU26, the vehicle power management ECU27, the power drive ECU24, and the execution target ECU25. The prerequisite operations are the same as those explained in Figures 2 and 3, so we will mainly explain the differences.

[0056] In the explanation using Figure 3, it was assumed that the OTA master outputs OTA phase information and OTA activation interval information. Since the target ECU25 can also output OTA activation interval information, an example of the target ECU25 outputting OTA activation interval information will be explained using Figure 4.

[0057] In the example shown in Figure 4, the OTA activation interval information switches from OFF to ON at time t1. At time t7, the OTA activation interval information switches from ON to OFF.

[0058] The execution target ECU25 is configured to output OTA activation interval information, which is then received by the parking service request ECU26. Therefore, the parking service request ECU26 can recognize that OTA processing is taking place from time t1 to time t7. As explained with reference to Figure 3, this interval is designated as a suppression period during which the parking service request ECU26 does not request parking services.

[0059] Similar to the explanation using Figure 3, the discrepancies described using Figure 2 do not occur, and concerns about diagnostic memory are resolved. Also, at time t7, the OTA activation section information switches from ON to OFF, and at this time, the suppression of parking services is released.

[0060] Next, the operation of the electronic control system 2 will be explained with reference to the flowchart shown in Figure 5. In step S11, OTA flag processing is performed. OTA flag processing is performed by the OTA master or the target ECU 25, and involves switching the OTA activation interval information ON or OFF and sending it to the parking service request ECU 26.

[0061] In step S12, following step S11, the parking service request ECU 26 determines whether the OTA flag, which is the OTA activation interval information, is ON. If the OTA activation interval information is ON (step S12: YES), the process proceeds to step S13. If the OTA activation interval information is not ON (step S12: NO), the parking service request ECU 26 terminates its determination of the OTA activation interval information and continues normal control.

[0062] In step S13, the parking service request ECU26 executes parking service suppression processing. The parking service suppression processing continues until predetermined conditions are met, as explained with reference to Figures 3 and 4.

[0063] Next, referring to Figure 6, we will explain an example of a process that addresses the diagnostic memory concerns mentioned above. In the explanation using Figures 3 and 4, the parking service was suppressed while the OTA activation interval information was ON. Even with the parking service suppressed in this way, the user has the advantage of being able to easily understand that the control is being performed after a program or data update, as the parking service will resume after the ignition is turned ON and version consistency is confirmed. On the other hand, the OTA activation interval information remains ON until the user turns the ignition (IGP) ON, and the parking service will be suppressed during that time. Figure 6 will explain a process that further enhances convenience.

[0064] The timing chart shown in Figure 6 also illustrates the operation of the OTA master (CGW21 and DCM22), the parking service request ECU26, the vehicle power management ECU27, the power drive ECU24, and the execution target ECU25 along their respective time axes. The underlying operations are the same as those explained in Figure 2, so we will mainly explain the differences.

[0065] The OTA master outputs OTA activation interval information. This information indicates that the OTA process is in the process of activation and version compatibility verification.

[0066] In the example shown in Figure 6, the OTA activation interval information switches from OFF to ON at time t1, and then switches from ON to OFF at time t7.

[0067] The OTA activation interval information is configured to be received by the Parking Service Request ECU26. Therefore, the Parking Service Request ECU26 can recognize that OTA processing is being performed from time t1 to time t7.

[0068] The diagnostic concern described with reference to Figure 2 arises from the continued refusal of the SMR28 retention request by the execution target ECU25. The execution target ECU25 performs the SMR28 shutdown process, which is a control that inhibits ECU sleep, during the system shutdown process of the power supply drive ECU24. In this embodiment, the SMR28 shutdown process is completed between time t2 and time t3, and the system is in a waiting state for the power relay 32 to be turned OFF.

[0069] Therefore, after the power relay 32 is turned OFF, the power to the target ECU 25 is also turned OFF, eliminating the need to continue rejecting the target ECU 25's request to retain the SMR28.

[0070] In the example shown in Figure 6, the period from when the OTA activation interval information is turned ON until after the system shutdown process is completed by the power supply drive ECU 24 is defined as the parking service suppression period. In the example shown in Figure 6, the parking service request ECU 26 is set to define the parking service suppression period as a predetermined time from time t1 when the OTA activation interval information is turned ON until after the system shutdown process is completed by the power supply drive ECU 24. The predetermined time is the time until the system shutdown process is expected to be completed by the power supply drive ECU 24, and in Figure 6, it is set between time t4 and time t5.

[0071] The parking service request ECU26 enters the parking service start request period when the parking service suppression period ends. Between times t4 and t5, the parking service request ECU26 sets a flag (IGB-ON) to turn on the special power supply and requests the start of parking services.

[0072] The vehicle power management ECU27 switches the direct line signal and CAN signal of the special power supply (IGB) ON and OFF according to the special power supply flag (IGB-ON) of the parking service request ECU26. Therefore, the special power supply (IGB) is ON between time t4 and time t5.

[0073] The power supply drive ECU 24 performs system shutdown processing from time t2, when the user turns off the ignition (IGP), until time t4. The power supply drive ECU 24 turns on the power relay 32 until time t4, when the system shutdown processing is completed. Since the system shutdown processing is completed at time t4, the power relay 32 is turned off at time t4.

[0074] The execution target ECU 25 performs a shutdown process for the SMR28, which is a control that inhibits ECU sleep, during the system shutdown process of the power supply drive ECU 24. In this embodiment, the shutdown process for the SMR28 is completed between time t2 and time t3, and the system enters a state waiting for the power relay 32 to be turned OFF. At this timing, the execution target ECU 25 turns OFF the drive of the SMR28 and rejects the request to hold the SMR28.

[0075] The target ECU25 releases the OFF waiting state for the power relay 32 because the power relay 32 turns OFF at time t4. The target ECU25 also releases the state that rejects the SMR28 hold request after the system shutdown process is completed by the power drive ECU24.

[0076] The execution target ECU25 completes the SMR28 shutdown process between time t2 and time t3, and enters a state where it rejects the SMR28 retention request, but this rejection state is released after time t4. Therefore, even if a parking service request is made by the parking service request ECU26 and a SMR28 retention request occurs, no discrepancy occurs, and no concern arises regarding diagnostic memory.

[0077] Next, with reference to Figure 7, we will explain an example of a process that addresses the aforementioned concerns regarding diagnostic memory. The explanation with reference to Figure 7 is equivalent to another example of the explanation with reference to Figure 6.

[0078] The timing chart shown in Figure 7 also illustrates the operation of the OTA master (CGW21 and DCM22), the parking service request ECU26, the vehicle power management ECU27, the power drive ECU24, and the execution target ECU25 along their respective time axes. The underlying operations are the same as those explained in Figures 2 and 6, so we will mainly explain the differences.

[0079] In the example shown in Figure 7, the power drive ECU 24 outputs the hold information for the power relay 32. The hold information for the power relay 32 indicates whether the power relay 32 is ON or OFF. The hold information for the power relay 32 is transmitted to the parking service request ECU 26.

[0080] At time t4, the power drive ECU 24 completes the system shutdown process, and the power relay 32 turns OFF. At this time, the hold information of the power relay 32 is turned OFF, and the parking service request ECU 26 releases the suppression of parking services.

[0081] At time t4, as explained with reference to Figure 6, the state in which the execution target ECU25 rejects the request to retain the SMR28 is released. Therefore, even if the parking service request ECU26 requests parking service and a request to retain the SMR28 occurs, no discrepancy will occur, and no concern will arise regarding diagnostic memory.

[0082] Next, referring to Figure 8, we will explain an example of a process that addresses the aforementioned concerns regarding diagnostic memory. The explanation using Figure 8 is equivalent to another example of the explanation using Figure 6.

[0083] The timing chart shown in Figure 8 also illustrates the operation of the OTA master (CGW21 and DCM22), the parking service request ECU26, the vehicle power management ECU27, the power drive ECU24, and the execution target ECU25 along their respective time axes. The underlying operations are the same as those explained in Figures 2 and 6, so we will mainly explain the differences.

[0084] In the example shown in Figure 8, the power drive ECU 24 outputs CAN data. CAN data is transmitted continuously if the power relay 32 is ON, and stopped if it is OFF. CNA data is sent to the parking service request ECU 26. CNA data is a frame with a relatively short transmission cycle, although it does not necessarily have to be related to OTA processing.

[0085] At time t4, the power drive ECU 24 completes the system shutdown process, and the power relay 32 turns OFF. At this time, the transmission of CAN data stops, and the parking service request ECU 26 releases the suppression of parking services.

[0086] At time t4, as explained with reference to Figure 6, the state in which the execution target ECU25 rejects the request to retain the SMR28 is released. Therefore, even if the parking service request ECU26 requests parking service and a request to retain the SMR28 occurs, no discrepancy will occur, and no concern will arise regarding diagnostic memory.

[0087] Next, the operation of the electronic control system 2, as explained with reference to the flowchart shown in Figure 9 and Figures 6, 7, and 8, will be described. In step S11, OTA flag processing is performed. OTA flag processing is performed by the OTA master or the target ECU 25, and involves switching the OTA activation interval information to ON or OFF and sending it to the parking service request ECU 26.

[0088] In step S12, following step S11, the parking service request ECU 26 determines whether the OTA flag, which is the OTA activation interval information, is ON. If the OTA activation interval information is ON (step S12: YES), the process proceeds to step S13. If the OTA activation interval information is not ON (step S12: NO), the parking service request ECU 26 terminates its determination of the OTA activation interval information and continues normal control.

[0089] In step S13, the parking service request ECU26 executes the parking service suppression process.

[0090] In step S14, following step S13, the parking service request ECU 26 determines whether the parking service suppression period has elapsed. The elapsed parking service suppression period is determined based on the passage of a predetermined amount of time and information transmitted to the power drive ECU 24, as explained with reference to Figures 6, 7, and 8.

[0091] If the parking service restriction period has expired (step S14: YES), the process proceeds to step S15. If the parking service restriction period has not expired (step S14: NO), the process continues to step S14.

[0092] In step S15, the parking service request ECU26 releases the parking service suppression period and performs normal control.

[0093] The electronic control systems (components such as ECUs, CGWs, and DCMs, including a microcontroller that performs control) and methods described herein may be implemented by a dedicated computer provided by configuring a processor and memory programmed to perform one or more functions embodied by a computer program. Alternatively, the electronic control systems (components such as ECUs, CGWs, and DCMs, including a microcontroller that performs control) and methods described herein may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the electronic control systems (components such as ECUs, CGWs, and DCMs, including a microcontroller that performs control) and methods described herein may be implemented by one or more dedicated computers configured by a combination of a processor and memory programmed to perform one or more functions and a processor composed of one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium.

[0094] The embodiments have been described above with reference to specific examples. However, this disclosure is not limited to these specific examples. Modifications made to these specific examples by those skilled in the art are also included within the scope of this disclosure, as long as they retain the features of this disclosure. The elements, their arrangement, conditions, shapes, etc., of each of the aforementioned specific examples are not limited to those illustrated and can be modified as appropriate. The elements of each of the aforementioned specific examples can be combined in different ways as appropriate, as long as no technical inconsistencies arise.

[0095] [Note] Notes 1 through 7 below can be combined in any way as long as they do not contradict each other technically.

[0096] [Note 1] An electronic control unit that performs parking services using specific functions of the vehicle while the vehicle's ignition is off, The system can receive activation information indicating that another electronic control unit has completed preparation for the activation process, which involves writing update target information, including programs or data acquired from an external device, to the non-volatile memory installed in the vehicle and activating it, while simultaneously denying the use of a specific function. When activation information is received, the execution of the parking service will be suppressed.

[0097] In the above embodiment, the parking service request ECU 26 is exemplified as the electronic control device in Appendix 1. The electronic control device in Appendix 1 is not limited to the parking service request ECU 26, but can be implemented as an ECU involved in the execution of parking services performed using specific functions of the vehicle while the vehicle ignition is off. In the above embodiment, the system main relay is exemplified as the specific function of the vehicle, but any function used for parking services performed while the vehicle ignition is off is acceptable. The ECU that performs the activation process is a different electronic control device from the electronic control device in Appendix 1. In the above embodiment, the execution target ECU 25 is exemplified as the ECU that performs the activation process, and is specifically described as a battery ECU. The ECU that performs the activation process is not limited to this, and can be applied to any ECU that has a mode that rejects requests to use specific functions such as the system main relay after preparation for the activation process.

[0098] According to Appendix 1, the system receives activation information indicating that the activation process is ready and suppresses the execution of parking services while the vehicle ignition is off. This eliminates the discrepancy with the ECU's processing, which may reject the request to hold the system main relay when the conditions for the activation process being ready and the vehicle ignition being off are met. This also eliminates concerns about diagnostic memory when OTA data rewriting operations and parking services are performed simultaneously.

[0099] [Note 2] An electronic control device as described in Appendix 1, which releases the suppression of the parking service after the denial of use of a specific function by another electronic control device that performs activation processing has been released.

[0100] According to Appendix 2, the restriction on the execution of parking services is lifted after the denial of use of specific functions by other electronic control devices is released. Therefore, the restriction on the execution of parking services does not remain permanent, and concerns about diagnostic memory are resolved while enabling the execution of parking services.

[0101] [Note 3] Activation information includes that the activation process is in progress and that the activation process has been completed. An electronic control device as described in Appendix 2, which releases the suppression of the parking service after the activation information has transitioned from indicating that the activation process is in progress to indicating that it is completed.

[0102] According to Appendix 3, the suppression of parking services is released after the activation process is complete, so the suppression of parking services does not persist, and concerns about diagnostic memory are resolved while enabling the parking services to be executed.

[0103] [Note 4] The electronic control device described in Appendix 2, which, after receiving activation information and recognizing that preparation for the activation process is complete, releases the suppression of the parking service after a predetermined time has elapsed since the vehicle's ignition was turned off.

[0104] According to Appendix 4, the suppression of parking service execution is released after a predetermined time has elapsed since the vehicle ignition was turned off, allowing parking service execution at a more precise timing while eliminating concerns about diagnostic memory.

[0105] [Note 5] The electronic control device described in Appendix 2, which, after receiving activation information and recognizing that preparation for the activation process is complete, releases the suppression of the execution of the parking service after the vehicle's power supply holding state has been released.

[0106] According to Appendix 5, since the suppression of parking service execution is released after the vehicle's power supply hold state is released, the suppression of parking service execution is released after the ECU, which may reject the system main relay hold request in association with the vehicle's power supply hold state, is released from that rejection mode. This eliminates concerns about diagnostic memory and allows parking service to be executed earlier.

[0107] [Note 6] The electronic control device described in Appendix 4 recognizes that the vehicle's power supply holding state has been released when the reception of a signal indicating the vehicle's power supply holding state is interrupted.

[0108] According to Appendix 6, the system recognizes when the vehicle's power supply has been released based on the reception status of the signal indicating the vehicle's power supply retention status, allowing for the execution of parking services at a more precise timing.

[0109] [Note 7] In the electronic control unit, Use a specific function of the vehicle to perform a parking service while the vehicle's ignition is off. The activation process, which involves writing update target information including programs or data acquired from an external device to the non-volatile memory installed in the vehicle and activating it, is performed by receiving activation information indicating that the processing preparations for another electronic control unit, which performs this process with the denial of use of a specific function, are complete. A program that suppresses the execution of parking services when activation information is received.

[0110] According to Appendix 7, a program that produces the same effects as Appendix 1 can be provided. Appendices 2 through 6 can also be implemented as a program in the same way as Appendix 7.

[0111] The electronic control devices described in Appendices 1 to 6 are included in the electronic control system 2. The electronic control system 2 is an assembly of ECUs including flash memory as non-volatile memory having a first data storage surface and a second data storage surface, each storing at least one of a program or data. As shown in Figure 10, the electronic control system 2 includes, as functional components, an installation execution unit 201, an activation execution unit 202, an activation information output unit 203, an activation information receiving unit 204, and a parking service management unit 205.

[0112] The installation execution unit 201 operates at least one of the programs or data stored on the first data storage surface, which is the operational surface, when the vehicle equipped with the electronic control system 2 is in a driving state or a parked state, and writes at least one of the update program or update data obtained from an external device to the second data storage surface, which is the non-operational surface.

[0113] The activation execution unit 202 switches the operation surface from the first data storage surface to the second data storage surface when the vehicle is parked.

[0114] The activation information output unit 203 outputs activation information indicating that the installation execution unit 201 or the activation execution unit 202 is in operation. In the above embodiment, the activation information is described as OTA phase information or OTA activation interval information. The activation information includes information indicating that preparations for the activation process, which involves writing update target information, including programs or data acquired from an external device, to the non-volatile memory installed in the vehicle and activating the written area, have been completed. The activation information includes information indicating that the activation process is in operation and that the activation process has been completed.

[0115] The activation information output unit 203 can be provided on the CGW21 and DCM22, which act as OTA masters, as described with reference to Figures 1 to 3 and Figures 6 to 8. The activation information output unit 203 can also be provided on the execution target ECU25, as described with reference to Figure 4.

[0116] The activation information receiving unit 204 receives the activation information output by the activation information output unit 203. The parking service management unit 205, upon receiving the activation information, suppresses the execution of parking services that utilize the vehicle's power supply. In the above embodiment, the activation information receiving unit 204 and the parking service management unit 205 are described as being provided in the parking service request ECU 26. [Explanation of Symbols]

[0117] 2: Electronic control system 21: CGW (Central Gateway) 22:DCM(Data Communication Module) 23: In-car display 24: Power supply drive ECU 25: ECU to be executed 26: ECU service request while parked 27: Vehicle Power Management ECU 28: SMR (System Main Relay) 31: Auxiliary battery 32: Power relay 41: Bus 42: Signal line 43: Bus 44: Signal line 45: Signal line 46: Bus

Claims

1. An electronic control unit that performs parking services using specific functions of the vehicle while the vehicle's ignition is off, The system can receive activation information indicating that another electronic control unit has completed preparation for the activation process, which involves writing update target information, including programs or data acquired from an external device, to the non-volatile memory installed in the vehicle to activate it, along with the denial of use of the specified function. An electronic control device that, upon receiving the aforementioned activation information, suppresses the execution of the parking service.

2. The electronic control device according to claim 1, which releases the suppression of the parking service after the refusal to use the specific function by the other electronic control device has been released.

3. The activation information includes that the activation process is in progress and that the activation process has been completed. The electronic control device according to claim 2, wherein the suppression of the parking service is released after the activation information transitions from indicating the activation process is in progress to indicating its completion.

4. The electronic control device according to claim 2, which, after receiving the activation information and recognizing that preparation for the activation process is complete, releases the suppression of the parking service execution after a predetermined time has elapsed since the vehicle ignition was turned off.

5. The electronic control device according to claim 2, which, after receiving the activation information and recognizing that preparation for the activation process is complete, releases the suppression of the parking service after the vehicle's power supply holding state is released.

6. The electronic control device according to claim 5, which recognizes that the vehicle's power supply holding state has been released when the reception of a signal indicating the vehicle's power supply holding state is interrupted.

7. In the electronic control unit, Use a specific function of the vehicle to perform a parking service while the vehicle's ignition is off. The activation process, which involves writing update target information including programs or data acquired from an external device to the non-volatile memory installed in the vehicle and activating it, is performed by receiving activation information indicating that the processing preparations for another electronic control unit, which performs this process along with the denial of use of the specific function, are complete. A program that, upon receiving activation information, suppresses the execution of the aforementioned parking service.

Citation Information

Patent Citations

  • In-vehicle software updating method and in-vehicle system

    EP4071603A1

  • Center device, specifications data generation method, and program for specifications data generation

    JP2020027620A

  • Electronic control device, method for controlling execution of rewriting, and program for controlling execution of rewriting

    JP2020027640A

  • On-vehicle apparatus, information generation method, information generation program, and vehicle

    JP2022041194A

  • In-vehicle software updating method and in-vehicle system

    JP2022160928A