Actuator control system and steering device
Patent Information
- Application Number
- JP2026506693
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Priority Date
- 2024-03-12
- Filing Date
- 2025-01-14
- Publication Date
- 2025-09-18
AI Technical Summary
Existing actuator control systems experience communication delays and loss of controllability when communication failures occur, particularly in redundant motor drive systems, leading to reduced vehicle safety and controllability.
An actuator control system with a two-system configuration of control devices connected by a communication circuit, allowing direct transmission of control information between control devices, and utilizing CAN communication for steering operation data, with a switching device to manage communication lines in case of failures.
Reduces communication delays and ensures controllability and safety of vehicle steering even in the event of failures by enabling direct information transfer and simplifying software control, allowing actuator control to continue with reduced torque when one system is functioning normally.
Abstract
Description
Actuator control system and steering device
[0001] The present invention relates to an actuator control system for controlling an actuator mounted on a vehicle, and a steering device using this system.
[0002] Patent Document 1 describes a redundant motor drive system in which first and second actuators are each controlled by two control and calculation units. In this system, under normal conditions, the control and calculation units of the paired systems communicate with each other to drive and control the motors between the actuators. If a communication system fails, information about the failed system is obtained through communication between the control and calculation units and transmitted via the communication line of the normal system.
[0003] Japanese Patent No. 7172952
[0004] However, with the technology of Patent Document 1, when a failure occurs in the communication system, information on the failed system is acquired between the corresponding control and calculation units of the first and second systems, and communication is carried out via the communication line of the normal system, which causes delays and reduces controllability.
[0005] Furthermore, if failures occur in two locations, either in the first communication system of the first actuator and the second communication system of the second actuator, or in the second communication system of the first actuator and the first communication system of the second actuator, control signal information cannot be transmitted and control becomes impossible, even though each system of the two actuators is functioning normally.
[0006] The present invention has been made in view of the above circumstances, and an object of the present invention is to provide an actuator control system that can suppress communication delays in the event of a failure and has excellent controllability. Another object of the present invention is to provide a steering device that uses the actuator control system and can achieve both controllability and safety of the vehicle in the event of a failure.
[0007] According to one aspect of the present invention, there is provided an actuator control system that controls an actuator mounted on a vehicle using a two-system configuration of first and second control devices, the actuator control system being configured such that the first and second control devices are connected by a communication circuit, and control information is transmitted directly from the first system of the first control device to the first and second systems of the second control device, and control information is transmitted directly from the second system of the first control device to the second and first systems of the second control device.
[0008] According to another aspect of the present invention, there is provided a steering device in which a two-system steering input device and a steering device are connected by a communication circuit, the steering input device comprising a steering input section that receives steering operations from a driver, first and second microcomputers, and first and second CAN interface sections, and the steering device comprising a motor that applies a steering force to the steered wheels of the vehicle, third and fourth microcomputers, and third and fourth interface sections, and configured so that data related to the steering of the steered wheels, including a first steering operation amount signal, is transmitted from the first microcomputer to the third and fourth microcomputers via CAN communication, and data related to the steering of the steered wheels, including a second steering operation amount signal, is transmitted from the second microcomputer to the fourth and third microcomputers via CAN communication.
[0009] According to the actuator control system of the present invention, in the event of a failure, information can be sent directly from the normal system of one control device to the first and second systems of the other control device via a communication circuit, eliminating the need for communication between the control devices and reducing delays. Furthermore, as long as one of the two systems in the first and second control devices is functioning normally, control information can be transmitted between the first and second control devices via the communication circuit, allowing actuator control. Therefore, it is possible to provide an actuator control system that reduces communication delays and provides excellent controllability.
[0010] Furthermore, according to the present invention, in a steering device using the above-mentioned actuator control system, data related to the steering of the steered wheels, including the first steering operation amount signal output from the first microcomputer of the steering input device, and data related to the steering of the steered wheels, including the second steering operation amount signal output from the second microcomputer of the steering input device, can be transmitted to the third and fourth microcomputers of the steering device without causing delays due to communication between microcomputers. This makes it possible to provide a steering device that can achieve both vehicle controllability and safety even in the event of a malfunction.
[0011] 1 is a block diagram showing a schematic configuration of an actuator control system according to an embodiment of the present invention. It is a schematic configuration diagram of main parts related to steering of a vehicle equipped with a steering device according to an embodiment of the present invention. It is a block diagram showing, in an extracted form, main parts related to control of the steering input device and the turning device in the steering device shown in FIG. 2. It is a block diagram for explaining operation when a failure occurs in the communication system in FIG. 3. It is a block diagram showing another configuration example of the communication circuit shown in FIG. 3. It is a block diagram showing an example configuration of a switching device by extracting the communication circuit of FIG. 5 and its surrounding main parts. It is a circuit diagram showing a specific configuration example of the switching device in FIG. 6 and its control. It is a flowchart showing operation on the primary side of the reaction force device when the private CAN IDs transmitted from the reaction force device and the turning device are different between the primary and secondary. It is a flowchart showing operation on the primary side of the reaction force device following FIG. 8. It is a flowchart showing operation on the secondary side of the reaction force device when the private CAN IDs transmitted from the reaction force device and the turning device are different between the primary and secondary. It is a flowchart showing operation on the secondary side of the reaction force device following FIG. 10. It is a flowchart showing operation on the primary side of the turning device when the private CAN IDs transmitted from the reaction force device and the turning device are different between the primary and secondary. 13 is a flowchart showing the operation of the primary side of the steering device following FIG. 12 . FIG. 14 is a flowchart showing the operation of the primary side of the steering device following FIG. 13 . FIG. 15 is a schematic diagram for explaining the flow of data on the primary side of the steering device in the event of a failure. FIG. 16 is a flowchart showing the operation of the secondary side of the steering device in the case where the private CAN IDs transmitted from the reaction force device and the steering device are different between the primary and secondary. FIG. 17 is a flowchart showing the operation of the secondary side of the steering device in the case where the private CAN IDs transmitted from the reaction force device and the steering device are the same between the primary and secondary.20 is a flowchart showing the operation of the primary side of the reaction force device, continuing from FIG. 20. FIG. 22 is a flowchart showing the operation of the secondary side of the reaction force device, when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. FIG. 22 is a flowchart showing the operation of the secondary side of the reaction force device, continuing from FIG. 22. FIG. 22 is a flowchart showing the operation of the primary side of the steering device, when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. FIG. 24 is a flowchart showing the operation of the primary side of the steering device, continuing from FIG. 24. FIG. 24 is a schematic diagram for explaining the flow of data on the primary side of the steering device in the event of a failure. FIG. 24 is a flowchart showing the operation of the secondary side of the steering device, when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. FIG. 27 is a flowchart showing the operation of the secondary side of the steering device, continuing from FIG. 27. FIG. 27 is a schematic diagram for explaining the flow of data on the secondary side of the steering device in the event of a failure.
[0012] An embodiment of the present invention will now be described with reference to the drawings. Fig. 1 shows a schematic configuration of an actuator control system according to an embodiment of the present invention. This system controls first and second actuators 11 and 12 mounted on a vehicle using first and second control devices 13 and 14, which are configured as two systems, based on the amount of operation of a driving operation input unit 10 that accepts driving operations by the driver. These first and second control devices 13 and 14 are connected by a communication circuit 15.
[0013] The first control device 13 includes a first microcomputer (first MCU) 16 of the first system, a second microcomputer (second MCU) 17 of the second system, a first interface unit (I / F) 18 of the first system, and a second interface unit (I / F) 19 of the second system.
[0014] The first microcomputer 16 can output a first operation amount signal CS1 based on the operation amount of the driving operation input unit 10. The second microcomputer 17 can output a second operation amount signal CS2 based on the operation amount of the driving operation input unit 10. The first interface unit 18 is an interface through which the first microcomputer 16 sends and receives data via communication. The second interface unit 19 is an interface through which the second microcomputer 17 sends and receives data via communication.
[0015] Similar to the first control device 13, the second control device 14 includes a third microcomputer (third MCU) 20 of the first system, a fourth microcomputer (fourth MCU) 21 of the second system, a third interface unit (I / F) 22 of the first system, and a fourth interface unit (I / F) 23 of the second system.
[0016] The third microcomputer 20 outputs a first drive signal DS1 to the first actuator 11 based on the first operation amount signal CS1 output from the first microcomputer 16 or the second operation amount signal CS2 output from the second microcomputer 17. The fourth microcomputer 21 outputs a second drive signal DS2 to the second actuator 12 based on the second operation amount signal CS2 output from the second microcomputer 17 or the first operation amount signal CS1 output from the first microcomputer 16.
[0017] The third interface unit 22 is an interface through which the third microcomputer 20 transmits and receives data by communication. The fourth interface unit 23 is an interface through which the fourth microcomputer 21 transmits and receives data by communication.
[0018] The communication circuit 15 is for mutual communication between the first and second control devices 13, 14, and includes first and second communication lines 24, 25 and an inter-system communication line (third communication line) 26. The first communication line 24 is connected between the interface units 18, 22, and the second communication line 25 is connected between the interface units 19, 23. Furthermore, within the first control device 13, the first communication line 24 and the second communication line 25 are commonly connected by the inter-system communication line 26.
[0019] As a result, as shown by the dotted arrow AA and the dashed arrow AB, data including the first operation amount signal CS1 sent from the first interface unit 18 is transmitted to the third interface unit 22 and the fourth interface unit 23, and data including the second operation amount signal CS2 sent from the second interface unit 19 is transmitted to the fourth interface unit 23 and the third interface unit 22.
[0020] In addition, data including the first drive signal DS1 sent from the third interface unit 22 is transmitted to the first interface unit 18 and the second interface unit 19, and data including the second drive signal DS2 sent from the fourth interface unit 23 is transmitted to the second interface unit 19 and the first interface unit 18.
[0021] According to the above-described configuration, the first communication line 24 and the second communication line 25 are connected by the inter-system communication line 26, thereby enabling direct communication between the microcomputers 16, 17, 20, and 21 via the interface units 18, 19, 22, and 23. This allows information from other systems to be easily obtained via the communication circuit 15, thereby reducing communication delays. Furthermore, in the event of a failure, information can be directly transmitted from the control device of the normal system via the communication circuit 15, eliminating the need for communication between the control devices 13 and 14 and reducing communication delays. Furthermore, as long as one of the two first and second control devices 13 and 14 is functioning normally, control signal information can be transmitted between the first and second control devices 13 and 14 via the communication circuit 15 to control the actuators 11 and 12.
[0022] For example, even if failures occur in two locations, namely, the first communication system of the first control device 13 and the second communication system of the second control device 14, or the second communication system of the first control device 13 and the first communication system of the second control device 14, control signal information can be transmitted via the communication circuit 15, so control will not become impossible.
[0023] In this way, two sets of information can be obtained even if the other communication system fails. Moreover, since there is no need for communication between microcomputers, the software that controls the microcomputers can be simplified. Therefore, an actuator control system with excellent controllability can be provided.
[0024] In the above-described embodiment, the first communication line 24 and the second communication line 25 are connected by the inter-system communication line 26. However, a switching device may be interposed on the inter-system communication line 26 to selectively connect / disconnect the first communication line 24 and the second communication line 25 in the event of a fault. Such a switching device may be a switch such as a relay or a semiconductor element. This switch is controlled by, for example, one or both of the first and second microcomputers 16 and 17.
[0025] When an abnormality occurs in any one of the first to fourth interface units 18, 19, 22, and 23, the switching device connects the first communication line 24 and the second communication line 25. When an abnormality such as a ground fault or a power fault occurs in the first communication line 24 or the second communication line 25, the switching device disconnects the first communication line 24 and the second communication line 25. When an abnormality occurs in two microcomputers, such as between the first microcomputer 16 and the fourth microcomputer 21 or between the second microcomputer 17 and the third microcomputer 20, the switching device connects the first communication line 24 and the second communication line 25. Furthermore, when an abnormality occurs in a microcomputer of the first system or the second system, such as between the first microcomputer 16 and the third microcomputer 20 or between the second microcomputer 17 and the fourth microcomputer 21, the switching device disconnects the first communication line 24 and the second communication line 25.
[0026] Furthermore, although the case where the first and second actuators 11, 12 are controlled by the two-system first and second control devices 13, 14 has been described, the present invention can also be applied to a system in which the third and fourth actuators are controlled by the first control device 13. In this case, the first microcomputer 16 outputs a third drive signal for driving the third actuator from the first operation amount signal CS1 to control the third actuator, and the second microcomputer 17 outputs a fourth drive signal for driving the fourth actuator from the second operation amount signal CS2 to control the fourth actuator.
[0027] The first and second actuators 11, 12 may be configured to drive double-winding motors having first and second coils. Similarly, the third and fourth actuators may be configured to drive double-winding motors having first and second coils. Furthermore, although the first communication line 24 and the second communication line 25 are connected within the first control device 13, it goes without saying that the same effects can be obtained if they are connected within the second control device 14.
[0028] Furthermore, various in-vehicle communication networks such as CAN (Controller Area Network), Ethernet (registered trademark), and FlexRay (registered trademark) can be applied for communication. The above-described actuator control system can be applied to the control of actuators mounted on a vehicle in general, and is suitable for steering devices and brake devices that use by-wire technology such as steer-by-wire and brake-by-wire, which require high safety.
[0029] Next, the application of the above-mentioned system to a vehicle steering device will be described in detail as an example. Fig. 2 is a schematic diagram of a steering device according to an embodiment of the present invention. Steering device 101 is of a so-called steer-by-wire type, in which a steering wheel (steering input unit) 102 and a steering device 104 that steers front wheels (steered wheels) 103 are mechanically separated. In other words, steering device 104 and steering input device 105 are in steering device 101 without mechanical torque transmission to each other. Steering device 101 includes steering input device 105, steering device 104, steering input control unit 106, and steering control unit 107.
[0030] The steering input device 105 includes a steering wheel 102, a first steering angle sensor 108, a second steering angle sensor 109, a first operation torque sensor 110, a second operation torque sensor 111, and a first electric motor 112. The steering wheel 102 rotates in response to a steering operation by the driver. The first steering angle sensor 108 is a rotation angle sensor that detects the amount of rotation of a steering shaft 102a connected to the steering wheel 102 and outputs a first operation amount signal CS1 corresponding to the detected amount of rotation. The second steering angle sensor 109 is a rotation angle sensor that detects the amount of rotation of the steering wheel 102 and outputs a second operation amount signal CS2 corresponding to the detected amount of rotation. The first operation amount signal CS1 and the second operation amount signal CS2 are either analog signals corresponding to the amount of rotation of the steering wheel 102 or digital signals encoded into SENT messages based on a Single Edge Nibble Transmission (SENT)-based Short PWM Code (SPC) protocol.
[0031] The first operation torque sensor 110 and the first steering angle sensor 108 are provided in a first system of the steering input device 105, and function as a first steering operation amount sensor capable of outputting a signal related to the momentum of the steering wheel 102. The second operation torque sensor 111 and the second steering angle sensor 109 are provided in a second system of the steering input device 105, and function as a second steering operation amount sensor capable of outputting a signal related to the momentum of the steering wheel 102.
[0032] The first operation torque sensor 110 detects the steering torque input from the steering wheel 102 to the steering shaft 102a by the driver and outputs a first operation torque signal corresponding to the detected steering torque. The second operation torque sensor 111 detects the steering torque input from the steering wheel 102 to the steering shaft 102a by the driver and outputs a second operation torque signal corresponding to the detected steering torque. The first electric motor 112 is a reaction force actuator that generates a force (steering reaction force) in the steering wheel 102 that increases the steering load in response to the steering operation by the driver. The first electric motor 112 has a first rotor 112a, a first stator 112b, and a first motor rotation angle sensor 112c.
[0033] In this example, the coil of the first stator 112b is redundant and is configured as a double-winding motor having a first coil and a second coil, but two independent electric motors may also be used. The first motor rotation angle sensor 112c detects the rotation position of the first rotor 112a and outputs a motor rotation angle signal corresponding to the detected rotation position.
[0034] Although not shown, the first motor rotation angle sensor 112c is made up of two motor rotation angle sensors, which output first and second motor rotation angle signals, respectively.
[0035] The steering device 104 has a rack bar 113, a first rack position sensor 114, a second rack position sensor 115, and a second electric motor 116. The rack bar 113 is movable in the vehicle width direction and steers the front wheels 103 depending on the amount of movement. The first rack position sensor 114 detects the position of the rack bar 113 and outputs a first steering amount signal corresponding to the detected position. The rack bar 113 is connected to the front wheels 103 via a tie rod or the like, and the steering angle of the front wheels 103 is uniquely determined depending on the position of the rack bar 113, so the first steering amount signal is a signal related to the steering angle of the front wheels 103. The second rack position sensor 115 detects the position of the rack bar 113 and outputs a second steering amount signal corresponding to the detected position. The first steering amount signal and the second steering amount signal are digital signals in which an analog signal corresponding to the position of the rack bar 113 is encoded into a SENT message based on a SENT (Single Edge Nibble Transmission)-based SPC (Short PWM Code) protocol.
[0036] The second electric motor 116 is a steering actuator that generates a force to steer the front wheels 103 via a rack bar (movable member) 113 based on a steering actuator drive signal from the steering control unit 107. In this embodiment, the second electric motor 116 is a belt-driven rack-assist type steering actuator. The second electric motor 116 has a second rotor 116a, a second stator 116b, and a second motor rotation angle sensor 116c. In this example, the coil of the second stator 116b is redundant and is configured as a double-winding motor having a first coil and a second coil, but two independent electric motors may also be used. The second motor rotation angle sensor 116c detects the rotational position of the second rotor 116a and outputs a motor rotation angle signal corresponding to the detected rotational position.
[0037] Although not shown, the second motor rotation angle sensor 116c is composed of two motor rotation angle sensors, which output third and fourth motor rotation angle signals, respectively.
[0038] The first steering angle sensor 108 is directly connected to the steering control unit 107 by a dedicated communication line 117. The second steering angle sensor 109 is also directly connected to the steering control unit 107 by a dedicated communication line 118. Furthermore, the first operation torque sensor 110 is directly connected to the steering input control unit 106 by a dedicated communication line 119. The second operation torque sensor 111 is directly connected to the steering input control unit 106 by a dedicated communication line 120. Furthermore, the first rack position sensor 114 is directly connected to the steering control unit 107 by a dedicated communication line 121. The second rack position sensor 115 is directly connected to the steering control unit 107 by a dedicated communication line 122.
[0039] Steering input control unit 106 and turning control unit 107 are connected by two systems of private CAN communication lines 123, 124. Private CAN communication lines 123, 124 are dedicated communication lines separate from the vehicle's public CAN communication line (not shown). Steering input control unit 106 receives a first operation amount signal and a first steering amount signal from steering control unit 107 via first private CAN communication line 123, and receives a second operation amount signal and a second steering amount signal from turning control unit 107 via second private CAN communication line 124. Steering input control unit 106 controls the drive of first electric motor 112 based on the first operation amount signal or the second operation amount signal, the first steering amount signal or the second steering amount signal, the first operation torque signal or the second operation torque signal, and a vehicle state (vehicle speed, etc.).
[0040] In addition, if both the first steering angle sensor 108 and the second steering angle sensor 109 fail, the steering input control unit 106 calculates a first operation amount signal and a second operation amount signal based on the first motor rotation angle signal or the second motor rotation angle signal, drives and controls the first electric motor 112 based on the calculated signals, and outputs the calculated first operation amount signal and second operation amount signal to the steering control unit 107.
[0041] As a steering control device for steering device 104, steering control unit 107 controls the drive of second electric motor 116 based on the first operation amount signal or the second operation amount signal, the first steering amount signal or the second steering amount signal, and the vehicle state (vehicle speed, etc.). Note that if both first rack position sensor 114 and second rack position sensor 115 fail, steering control unit 107 controls second electric motor 116 based on the first operation amount signal and the second operation amount signal calculated by steering input control unit 106 in accordance with the first motor rotation angle signal and the second motor rotation angle signal.
[0042] The steering input control unit 106 and the turning control unit 107 operate by receiving power supplies from a first battery 125 and a second battery 126. The first electric motor 112, the first operation torque sensor 110, and the second operation torque sensor 111 receive power supplies from the steering input control unit 106. The second electric motor 116, the first steering angle sensor 108, the second steering angle sensor 109, the first rack position sensor 114, and the second rack position sensor 115 each receive power supplies from the turning control unit 107.
[0043] FIG. 3 shows the main components related to the control of the steering input device 105 and the turning device 104 in the steering system shown in FIG. 2 . The steering input device 105 is equipped with a feedback actuator (FBA), and FIG. 3 focuses on this feedback actuator. The feedback actuator applies a simulated reaction force to the driver to simulate steering system behavior equivalent to that of a conventional vehicle while driving. Each feedback actuator is equipped with a steering input control unit (first control device) 106 and torque and angle sensors (TAS) 38 and 48, each of which has a dual system, and applies electric power to first and second coils 112b1 and 112b2 of the first stator 112b to control the first electric motor 112.
[0044] Further, road wheel actuator (RWA) 104 steers front wheels 103 using the driving force of a motor, and includes a two-system steering control section (second control device) 107 and first and second pinion angle sensors (PAS), which apply electric power to first and second coils 116b1 and 116b2 of second stator 116b to control second electric motor 116. These first and second pinion angle sensors correspond to first and second rack position sensors 114 and 115 in FIG. 2, respectively, and are therefore designated by the same reference numerals.
[0045] The primary side (first system) of the steering input control unit 106 is made up of a first microcomputer (first MCU) 31, a CAN driver 32 for the vehicle CAN (VCAN-1), a CAN driver 33 for the private CAN (PCAN-1), an inverter 34 for driving the first coil 112b1 of the first electric motor 112, a motor position sensor (MPS) 35 for detecting the rotation angle of the first electric motor 112, an interface unit 36 between the first MCU 31 and a first operation torque sensor (TRQ-1) 110, and a power supply 37. The torque and angle sensor (TAS) 38 is provided corresponding to the primary side of the steering input control unit 106 and is made up of a first steering angle sensor (SAS-1) 108 and a first operation torque sensor (TRQ-1) 110. The power supply 37 supplies power to the first MCU 31, the CAN driver 33, and the first operation torque sensor 110.
[0046] The secondary side (second system) of the steering input control unit 106 is composed of a second microcomputer (second MCU) 41, a CAN driver 42 for the vehicle CAN (VCAN-2), a CAN driver 43 for the private CAN (PCAN-2), an inverter 44 for driving the second coil 112b2, a motor position sensor (MPS) 45 for detecting the rotation angle of the electric motor 112, an interface unit 46 between the second MCU 41 and a second operation torque sensor (TRQ-2) 111, and a power supply 47. The torque and angle sensor (TAS) 48 is provided corresponding to the secondary side of the steering input control unit 106 and is composed of a second steering angle sensor (SAS-2) 109 and a second operation torque sensor (TRQ-2) 111. The power supply 47 supplies power to the second MCU 41, the CAN driver 43, and the second operation torque sensor 111.
[0047] The primary side (first system) of steering control unit 107 is made up of third microcomputer (third MCU) 51, a CAN driver 52 for a private CAN (PCAN-1), a CAN driver 53, an inverter 54 for driving a first coil 116b1 of second electric motor 116, a motor position sensor (MPS) 55 for detecting the rotation angle of second electric motor 116, an interface unit 56 between third MCU 51 and first pinion angle sensor (PAS-1) 114, an interface unit 57 between third MCU 51 and first steering angle sensor (SAS-1) 108, and a power supply 58. First pinion angle sensor 114 is provided corresponding to the primary side of steering control unit 107. Power supply 58 supplies power to third MCU 51, CAN driver 52, first pinion angle sensor 114, and first steering angle sensor 108.
[0048] The secondary side (second system) of steering control unit 107 is made up of a fourth microcomputer (fourth MCU) 61, a CAN driver 62 for a private CAN (PCAN-2), a CAN driver 63, an inverter 64 for driving the second coil 116b2 of second electric motor 116, a motor position sensor (MPS) 65 for detecting the rotation angle of second electric motor 116, an interface unit 66 between the fourth MCU 61 and second pinion angle sensor (PAS-2) 115, an interface unit 67 between the fourth MCU 61 and second steering angle sensor (SAS-2) 109, and a power supply 68. The second pinion angle sensor 115 is provided corresponding to the primary side of steering control unit 107. The power supply 68 supplies power to the fourth MCU 61, the CAN driver 62, the second pinion angle sensor 115, and the second steering angle sensor 109.
[0049] Communication circuit 127 is made up of first and second private CAN communication lines 123, 124 and an inter-system communication line (third communication line) 128. First private CAN communication line 123 is connected between CAN drivers 33 and 52, and second private CAN communication line 124 is connected between CAN drivers 43 and 62. These first and second private CAN communication lines 123, 124 are commonly connected by inter-system communication line 128 within steering input control unit 106. Note that first and second private CAN communication lines 123, 124 may also be commonly connected by inter-system communication line 128 within steering control unit 107.
[0050] 4 is a block diagram for explaining the operation when a failure occurs in the communication system (here, the CAN driver 33) in FIG. 3. In this failure, data obtained by the second MCU 41 is input to the CAN driver 62 via the private CAN communication line 124. Meanwhile, data obtained by the first MCU 31 is transmitted from the second MCU 41 to the private CAN communication line 124 by the CAN driver 43 through inter-MCU communication, and is input to the CAN driver 52 via the inter-system communication line 128 and the private CAN communication line 123. The electric motor 116 is controlled by the third and fourth MCUs 51 and 61 based on the data obtained by the first and second MCUs 31 and 41.
[0051] Similarly, when an abnormality occurs in another CAN driver 43, 52, 62, the data of the system in which the CAN driver has failed is transmitted to the system in which the CAN driver has failed via inter-MCU communication, and the data is transmitted along with the data of the system in which the CAN driver is functioning via two systems using private CAN communication lines 123, 124 and inter-system communication line 128. This makes it possible to suppress communication delays due to inter-MCU communication in the system in which the failure has occurred.
[0052] Figure 5 shows another example configuration of the communication circuit shown in Figure 3. This communication circuit 127 includes a switching device 70 (represented by a switch symbol) that selectively connects / disconnects first private CAN communication line 123 and second private CAN communication line 124 within steering input control unit 106 or turning control unit 107. Since the other configuration is the same as in Figure 3, the same parts are designated by the same reference numerals and detailed description thereof will be omitted.
[0053] In the above configuration, when an abnormality occurs in any one of the interface units 36, 46, 57, 58, 66, and 67, the switching device 70 connects the first private CAN communication line 123 and the second private CAN communication line 124. This enables the operation described with reference to Fig. 4 to be performed, and communication delays due to communication between MCUs in the failed system to be suppressed.
[0054] Furthermore, when an abnormality such as a ground fault or a short to power occurs in first private CAN communication line 123 or second private CAN communication line 124, switching device 70 separates first private CAN communication line 123 from second private CAN communication line 124. By separating first and second private CAN communication lines 123, 124 in this manner, normal communication lines are separated from the communication line in which an abnormality such as a ground fault or a short to power has occurred, and communication using only the normal communication lines becomes possible.
[0055] Furthermore, when an abnormality occurs in two microcomputers in the same system, such as the first microcomputer 31 and the fourth microcomputer 61, or the second microcomputer 41 and the third microcomputer 51, the switching device 70 connects the first private CAN communication line 123 and the second private CAN communication line 124.
[0056] As a result, for example, if an abnormality occurs in the first and fourth microcomputers 31 and 61, the second microcomputer 41 can communicate with the third microcomputer 51 via the CAN driver 43, the second private CAN communication line 124, the inter-system communication line 128 (switching device 70), the first private CAN communication line 123, and the CAN driver 52, and driving (steering operation) can be continued using the second coil 112b2 of the first electric motor 112 and the first coil 116b1 of the second electric motor 116. In this case, the output torque of the first and second electric motors 112 and 116 will be reduced to about half.
[0057] On the other hand, if there is an abnormality in the second or third microcomputer 41, 51, for example, the first microcomputer 31 communicates with the fourth microcomputer 61 via the CAN driver 33, the first private CAN communication line 123, the inter-system communication line 128 (switching device 70), the second private CAN communication line 124, and the CAN driver 62, and it becomes possible to continue driving (steering operation) using the first coil 112b1 of the first electric motor 112 and the second coil 116b2 of the second electric motor 116. In this case as well, the output torque of the first and second electric motors 112, 116 will be reduced to about half.
[0058] In addition, when an abnormality occurs in the microcomputers of the first or second system, such as between the first microcomputer 31 and the third microcomputer 51, or between the second microcomputer 41 and the fourth microcomputer 61, the switching device 70 separates the first private CAN communication line 123 and the second private CAN communication line 124.
[0059] As a result, for example, if an abnormality occurs in the first or third microcomputer 31, 51, the second microcomputer 41 can communicate with the fourth microcomputer 61 via the CAN driver 43, the second private CAN communication line 124, and the CAN driver 52, and can continue driving using the second coil 112b2 of the first electric motor 112 and the second coil 116b2 of the second electric motor 116. In this case, the output torque of the first and second electric motors 112, 116 will be reduced to about half.
[0060] On the other hand, if there is an abnormality in the second or fourth microcomputer 41, 61, for example, the first microcomputer 31 communicates with the third microcomputer 51 via the CAN driver 33, the first private CAN communication line 123, and the CAN driver 52, and it becomes possible to continue driving using the first coil 112b1 of the first electric motor 112 and the first coil 116b1 of the second electric motor 116. In this case as well, the output torque of the first and second electric motors 112, 116 will be reduced to about half.
[0061] 6 shows a specific example of the configuration of the switching device 70 by extracting the communication circuit 127 and its surrounding essential parts from FIG. 5. Here, the case where communication is performed using a CAN bus line of a "two-wire differential voltage system" is shown, and two switches SW1 and SW2 such as relays or semiconductor elements are provided as the switching device 70 on the inter-system communication line 128. These switches SW1 and SW2 are selectively controlled to be turned on or off depending on the abnormality or failure status.
[0062] In the above configuration, for example, if a ground fault (represented by a ground symbol) occurs in the first private CAN communication line 123, a bus-off occurs and communication is stopped. Therefore, if a ground fault / power fault occurs in the first and second private CAN communication lines (CAN bus lines) 123 and 124, or if a bus-off occurs in the CAN driver or CAN module of the MCU, switches SW1 and SW2 are turned off. This allows communication to be performed via the normal private CAN communication line, preventing communication from being stopped due to a bus-off.
[0063] FIG. 7 is a circuit diagram showing a specific example of the configuration of the switching device 70 in FIG. 6 and its control. Here, the diagram focuses on the CAN bus lines PCAN-1H and PCAN-2H. The switching device 70 is composed of N-channel MOSFETs 71 and 72, whose source-drain current paths are connected in series between the CAN bus lines PCAN-1H and PCAN-2H. The parasitic diodes 71d and 72d of the MOSFETs 71 and 72 are arranged so that the current flows in opposite directions. The collector of a PNP bipolar transistor 73 is connected to the gates of these MOSFETs 71 and 72. The emitter of the bipolar transistor 73 is connected to a power supply VB, and the base is connected to the collector of an NPN bipolar transistor 75 via a resistor 74. The base of the bipolar transistor 75 is connected to the output terminal for the first switching signal of the first MCU 31 via a resistor 76, and the emitter is connected to the collector of an NPN bipolar transistor 78. The base of the bipolar transistor 78 is connected to the output terminal for the second switching signal of the first MCU 31 via a resistor 79, and the emitter is connected to the ground. A resistor 77 is connected between the base of the bipolar transistor 75 and the ground, and a resistor 80 is connected between the base of the bipolar transistor 78 and the ground.
[0064] Bipolar transistor 75 and resistors 76 and 77 function as a first switching signal output unit that outputs a first switching signal for switching the switching device under the control of first MCU 31. Bipolar transistor 78 and resistors 79 and 80 function as a second switching signal output unit that outputs a second switching signal for switching the switching device under the control of second MCU 41. Bipolar transistor 73 is controlled to be turned on / off based on the first switching signal and the second switching signal. When MOSFETs 71 and 72 are both turned on by turning on bipolar transistor 73, CAN bus lines PCAN-1H and PCAN-2H are connected, and when MOSFETs 71 and 72 are both turned off by turning off bipolar transistor 73, CAN bus lines PCAN-1H and PCAN-2H are separated.
[0065] When an abnormality occurs in either CAN bus line PCAN-1H or CAN bus line PCAN-2H, first MCU 31 or second MCU 41 controls switching device 70 to separate CAN bus line PCAN-1H from CAN bus line PCAN-2H. Specifically, when either the first switching signal output from first MCU 31 or the second switching signal output from second MCU 41 goes to a low level ("L" level), or when the output terminal of first MCU 31 or the output terminal of second MCU 41 goes to a high impedance (Hi-Z) state, MOSFETs 71 and 72 are turned off (switches SW1 and SW2 are open).
[0066] 8 and 9 are flowcharts showing the operation of the primary side (first MCU side) of the reaction force device (FBA) when the private CAN IDs transmitted from the reaction force device and the steering device are different between the primary and secondary. Here, it is assumed that the private CAN transmission ID = 0x030.
[0067] First, when the vehicle ignition key is turned on (step ST1), the private CAN relay is turned on (step ST2), and it is determined whether it is control timing (step ST3). If it is determined that it is control timing, vehicle CAN communication is received (step ST4). If it is determined that it is not control timing, the determination of step ST3 is continued until it is control timing.
[0068] In the following step ST5, private CAN data is received from the primary side of the RWA, and in step ST6, private CAN data is received from the secondary side of the RWA. Next, a failure determination of the private CAN is performed from the primary side of the RWA (step ST7), followed by a failure determination of the private CAN from the secondary side of the RWA (step ST8). After that, data for inter-MCU communication is received (step ST9), and a failure determination of the private CAN is performed (step ST10).
[0069] Next, a target steering reaction force is calculated (step ST11), and a signal for a target steering angle is generated (step ST12). Subsequently, a target motor torque is calculated (step ST13), and data for inter-MCU communication is generated (step ST14). After the generated data for inter-MCU communication is transmitted (step ST15), private CAN data is generated (step ST16), and it is determined whether or not a bus-off fault has occurred in the private CAN (step ST17).
[0070] If a bus-off failure is determined in step ST17, the switching device (relay) 70 connecting the private CAN is turned off (step ST18), and then the private CAN data is transmitted (step ST19), and vector control of the electric motor 112 is performed (step ST20). If a bus-off failure is not determined, the private CAN data is transmitted as is (step ST19), and vector control of the electric motor 112 is performed (step ST20). Next, a duty calculation for PWM control of the motor is performed (step ST21), and a PWM signal resulting from the calculation is output, thereby PWM controlling the electric motor 112 (step ST22).
[0071] Then, it is determined whether the vehicle ignition key is turned off (step ST23), and if it is determined that the ignition key is not turned off, the process returns to step ST3 and the operations from step ST3 to step ST22 are repeated. On the other hand, if it is determined that the ignition key is turned off, the shutdown process is executed and terminated (step ST24).
[0072] 10 and 11 are flowcharts showing the operation of the secondary side (second MCU 41 side) of the reaction force device when the private CAN IDs transmitted from the reaction force device and steering device are different between the primary and secondary. Here, it is assumed that the private CAN transmission ID = 0x032. The operation of the secondary side of the reaction force device (steps ST31 to ST54) is the same as the operation of the primary side (steps ST1 to ST24), so a detailed explanation will be omitted.
[0073] 12 to 14 are flowcharts showing the operation of the primary side (third MCU 51 side) of the steering device (RWA) when the private CAN IDs transmitted from the reaction force device and the steering device are different between the primary and secondary. Also, Fig. 15 is a schematic diagram for explaining the flow of data on the primary side of the RWA in the event of a failure. Here, it is assumed that the private CAN transmission ID is 0x040.
[0074] First, when the ignition key of the vehicle is turned on (step ST61), it is determined whether or not it is control timing (step ST62). If it is determined that it is control timing, a private CAN is received from the primary side of the FBA (step ST63). If it is determined that it is not control timing, the determination is continued until it is control timing.
[0075] Next, the private CAN is received from the secondary side of the FBA (step ST64). Next, a failure determination of the private CAN is performed from the primary side of the FBA (step ST65), and a failure determination of the private CAN is performed from the secondary side of the FBA (step ST66). After that, data from inter-MCU communication is received (step ST67), and the first and second steering angle sensors 108 and 109 detect the actual steering angle (step ST68).
[0076] Then, it is determined whether the CAN data transmitted from the primary side is normal (step ST69). That is, as indicated by the dashed arrow AL1 in Fig. 15 , CAN communication is performed between first MCU 31 and third MCU 51 via first private CAN communication line 123, and it is sequentially determined whether there are any abnormalities in CAN driver 33 and CAN driver 52. If it is determined that the data is normal, the CAN data transmitted from the primary side of FBA is set as the target steering angle calculation data (step ST70).
[0077] If it is determined that the CAN driver 43 is not normal, it is then determined whether the CAN data transmitted from the secondary side is normal (step ST71). This determination is made by executing CAN communication between the second MCU 41 and the third MCU 51 via the second private CAN communication line 124, the inter-system communication line 128 (switching device 70), and the second private CAN communication line 124, as shown by the dashed-dotted arrow AL2 in Fig. 15, and determining whether there is an abnormality in the CAN driver 43. If it is determined that the CAN driver 43 is normal, the CAN data transmitted from the secondary side of the FBA is set as the target steering angle calculation data (step ST72).
[0078] If the determination in step ST71 is that the data is not normal, the secondary-side CAN data obtained through inter-MCU communication is then determined to be normal (step ST73). This determination is made by performing CAN communication between the second MCU 41 and the fourth MCU 61 via the second private CAN communication line 124, as well as inter-MCU communication between the fourth MCU 61 and the third MCU 51, as indicated by the dashed arrow AL3 in FIG. 15, to determine whether there are any abnormalities. If the determination is normal, the CAN data transmitted from the secondary side of the FBA is set as the target steering angle calculation data (step ST74). If the determination in step ST73 is that the data is not normal, the data received from the steering angle sensor is set as the target steering angle calculation data (step ST75). This steering angle sensor reception data is obtained from the first steering angle sensor 108 on the primary side of the FBA, as indicated by the dashed arrow AL4 in FIG. 15.
[0079] In the next step ST76, the target steering angle is calculated, and steering feedback control (primary target motor torque calculation) is performed using the primary-side data (step ST77). Next, data for inter-MCU communication is generated (step ST78), and the generated inter-MCU communication data is transmitted (step ST79). Also, private CAN data is generated (step ST80), and the generated private CAN data is transmitted (step ST81). Then, vector control of electric motor 116 is performed (step ST82).
[0080] Next, a duty calculation for PWM control of the motor is performed (step ST83), and a PWM signal resulting from the calculation is output to PWM control the electric motor 116 (step ST84). It is then determined whether the vehicle ignition key is turned off (step ST85). If it is determined that the ignition is not turned off, the process returns to step ST62, and the operations from step ST62 to step ST84 described above are repeated. On the other hand, if it is determined that the ignition is turned off, the shutdown process is executed and terminated (step ST86).
[0081] 16 to 18 are flowcharts showing the operation of the secondary side (fourth MCU 61 side) of the steering device (RWA) when the private CAN IDs transmitted from the reaction force device and the steering device are different between the primary and secondary. Also, Fig. 19 is a schematic diagram for explaining the flow of data on the secondary side of the RWA in the event of a failure. Here, it is assumed that the private CAN transmission ID is 0x043.
[0082] The operation of the secondary side of the reaction force device shown in FIG. 16 (steps ST91 to ST98) is the same as the operation of the primary side shown in FIG. 12 (steps ST61 to ST68), so a detailed description will be omitted.
[0083] In step ST99 shown in Fig. 17, it is determined whether the CAN data transmitted from the primary side is normal. That is, as indicated by dashed arrow AL1 in Fig. 19, CAN communication is performed between first MCU 31 and third MCU 51 via first private CAN communication line 123, and it is sequentially determined whether there are any abnormalities in CAN driver 33 and CAN driver 52. If it is determined that the data is normal, the CAN data transmitted from the primary side of FBA is set as the target steering angle calculation data (step ST100).
[0084] If it is determined in step ST99 that the CAN data transmitted from the primary side of the FBA is not normal, it is then determined whether the CAN data transmitted from the secondary side is normal (step ST101). This determination is made by executing CAN communication between the first MCU 31 and the fourth MCU 61 via the first private CAN communication line 123, the inter-system communication line 128 (switching device 70), and the second private CAN communication line 124, as indicated by the dashed-dotted arrow AL2 in Fig. 19, to determine whether there is an abnormality in the CAN driver 33. If it is determined that the CAN data is normal, the CAN data transmitted from the secondary side of the FBA is set as the target steering angle calculation data (step ST102).
[0085] If it is determined in step ST101 that the CAN data transmitted from the secondary side of the FBA is abnormal, the secondary-side CAN data obtained through inter-MCU communication is then determined to be normal (step ST103). This determination is made by executing CAN communication between the first MCU 31 and the third MCU 51 via the first private CAN communication line 123, as indicated by the dashed arrow AL3 in FIG. 19, and inter-MCU communication between the third MCU 51 and the fourth MCU 61, to determine whether there are any abnormalities. If the CAN data is determined to be normal, the CAN data received on the primary side through the inter-MCU communication is set as the target steering angle calculation data (step ST104). On the other hand, if the CAN data is determined to be abnormal, the data received from the steering angle sensor is set as the target steering angle calculation data (step ST105). This steering angle sensor reception data is obtained from the second steering angle sensor 109 on the secondary side of the FBA, as indicated by the dashed arrow AL4 in FIG. 19.
[0086] In the following step ST106, the target steering angle is calculated, and it is determined whether the primary side is normal (step ST107). If it is determined that the primary side is normal, the primary side target torque value is set as the secondary target torque value (step ST108). If it is determined that the primary side is not normal, steering feedback control (secondary target motor torque calculation) is executed using the secondary data (step ST109). The subsequent operations shown in Figure 18 (steps ST110 to ST118) are the same as the primary side operations shown in Figure 14 (steps ST78 to ST86), and therefore detailed description thereof will be omitted.
[0087] 20 and 21 are flowcharts showing the operation of the primary side of the reaction force device when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. Here, it is assumed that the private CAN transmission ID = 0x030.
[0088] First, when the vehicle ignition key is turned on (step ST200), the private CAN relay is turned on (step ST201), and it is determined whether or not it is control timing (step ST202). If it is determined that it is control timing, vehicle CAN communication is received (step ST203). If it is determined that it is not control timing, the determination of step ST202 is repeated until it is control timing.
[0089] In the next step ST204, private CAN data is received from the RWA, and in step ST205, a failure determination is performed based on the private CAN data from the RWA. Next, data from inter-MCU communications is received (step ST206), and a failure determination is performed on the private CAN (step ST207). Next, a target steering reaction force is calculated (step ST208), and a signal for a target steering angle is generated (step ST209).
[0090] Next, a target motor torque is calculated (step ST210), and inter-MCU communication data is generated (step ST211). After the generated inter-MCU communication data is transmitted (step ST212), private CAN data is generated (step ST213), and it is determined whether or not a bus-off fault has occurred in the private CAN (step ST214).
[0091] If a bus-off fault is determined, the switching device (relay) 70 connecting the private CAN is turned off (step ST215), and the private CAN data is transmitted (step ST216). If a bus-off fault is not determined, the private CAN data is transmitted as is (step ST216), and vector control of electric motor 112 is performed (step ST217). Next, a duty calculation for PWM control of the motor is performed (step ST218), and a PWM signal resulting from the calculation is output to PWM control electric motor 112 (step ST219).
[0092] Thereafter, it is determined whether the vehicle ignition key is turned off (step ST220), and if it is determined that the ignition is not turned off, the process returns to step ST202 and the operations from step ST202 to step ST220 are repeated. On the other hand, if it is determined that the ignition is turned off, the shutdown process is executed and terminated (step ST221).
[0093] 22 and 23 are flowcharts showing the operation of the secondary side of the steering device when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. Here, it is assumed that the private CAN transmission ID is 0x030. When the vehicle ignition key is turned on (step ST231), the private CAN relay is turned on (step ST232), and a determination is made as to whether or not it is control timing (step ST233). If it is determined that it is control timing, vehicle CAN communication is received (step ST234). If it is determined that it is not control timing, the determination of step ST233 is made until it is control timing.
[0094] In the next step ST235, private CAN data is received from the primary side of the FBA, and in step ST236, private CAN data is received from the RWA. Next, a fault determination is performed based on the private CAN data from the primary side of the FBA (step ST237). Subsequently, a fault determination is performed based on the private CAN data from the RWA (step ST238).
[0095] Next, data from inter-MCU communication is received (step ST239), and a failure determination is made for the private CAN (step ST240). Subsequently, a target steering reaction force is calculated (step ST241), and a signal for a target steering angle is generated (step ST242).
[0096] Next, the target motor torque is calculated (step ST243), and inter-MCU communication data is generated (step ST244). After the generated inter-MCU communication data is transmitted (step ST245), private CAN data is generated (step ST246), and it is determined whether the private CAN data transmitted from the primary side of the FBA is normal (step ST247). If it is determined to be normal, the process proceeds to step ST251, where vector control of the electric motor 116 is performed. On the other hand, if it is determined to be abnormal, it is determined whether a bus-off fault has occurred in the private CAN (step ST248).
[0097] If it is determined in step ST248 that a bus-off failure has occurred, the switching device (relay) 70 connecting the private CAN is turned off (step ST249), and then the private CAN data is transmitted (step ST250). If it is determined that a bus-off failure has not occurred, the private CAN data is transmitted as is (step ST250), and vector control of electric motor 112 is performed (step ST251). Next, a duty calculation for PWM control of the motor is performed (step ST252), and a PWM signal resulting from the calculation is output to PWM control electric motor 112 (step ST253).
[0098] Thereafter, it is determined whether the vehicle ignition key is turned off (step ST254), and if it is determined that the ignition is not turned off, the process returns to step ST233 and the operations from step ST233 to step ST254 are repeated. On the other hand, if it is determined that the ignition is turned off, the shutdown process is executed and terminated (step ST255).
[0099] 24 and 25 are flowcharts showing the operation of the primary side of the steering device when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. Also, Fig. 26 is a schematic diagram for explaining the flow of data on the primary side of the RWA in the event of a failure. Here, it is assumed that the private CAN transmission ID is 0x040.
[0100] First, when the vehicle ignition key is turned on (step ST261), it is determined whether or not it is control timing (step ST262). If it is determined that it is control timing, private CAN data is received from the FBA (step ST263), and a fault determination is performed based on the private CAN data from the FBA (step ST264).
[0101] Next, data from inter-MCU communication is received (step ST265), and the actual steering angle is detected (step ST266). Subsequently, it is determined whether the private CAN data received from the FBA is normal (step ST267). As indicated by the dashed arrow AL1 in FIG. 26 , CAN communication is performed between the first MCU 31 and the third MCU 51 via the first private CAN communication line 123, and it is sequentially determined whether there are any abnormalities in the CAN driver 33 and the CAN driver 52. Furthermore, as indicated by the dashed arrow AL2, CAN communication is performed between the second MCU 41 and the third MCU 51 via the second private CAN communication line 124, the inter-system communication line 128 (switching device 70), and the first private CAN communication line 123, and it is sequentially determined whether there are any abnormalities in the CAN driver 43. If it is determined that the data is normal, the CAN data received on the primary side of the FBA is set as the target steering angle calculation data (step ST268).
[0102] In step ST267, for example, if the CAN driver 33 on the primary side of the FBA fails, the same CAN information is sent from the secondary side of the FBA, so the received CAN data becomes normal and the process moves to step ST268.
[0103] If the CAN data on the secondary side obtained through inter-MCU communication is determined to be abnormal, the CAN data received on the secondary side through inter-MCU communication is determined to be normal (step ST269). If the CAN data is normal, the CAN data received on the secondary side through inter-MCU communication is set as the target steering angle calculation data (step ST270). This determination is made by performing CAN communication between the second MCU 41 and the fourth MCU 61 via the second private CAN communication line 124, as indicated by the dashed arrow AL3 in FIG. 26, and inter-MCU communication between the fourth MCU 61 and the third MCU 51, to determine whether there is an abnormality. If the CAN data is determined to be abnormal, the data received from the steering angle sensor (sensor detection value) is set as the target steering angle calculation data (step ST271). The received data from the steering angle sensor is obtained from the first steering angle sensor 108 on the primary side of the FBA, as indicated by the dashed arrow AL4 in FIG. 26.
[0104] In the next step ST272, the target steering angle is calculated, and steering feedback control (primary target motor torque calculation) is performed using the primary-side data (step ST273). Next, data for inter-MCU communication is generated (step ST274), and the generated inter-MCU communication data is transmitted (step ST275). Also, private CAN data is generated (step ST276), and the generated private CAN data is transmitted (step ST277). Then, vector control of electric motor 116 is performed (step ST278).
[0105] Next, a duty calculation for PWM control of the motor is performed (step ST279), and a PWM signal resulting from the calculation is output to PWM-control the electric motor 116 (step ST280). It is then determined whether the vehicle ignition key is turned off (step ST281). If it is determined that the ignition is not turned off, the process returns to step ST262, and the operations from step ST262 to step ST281 described above are repeated. On the other hand, if it is determined that the ignition is turned off, the shutdown process is executed and terminated (step ST282).
[0106] 27 and 28 are flowcharts showing the operation of the secondary side of the steering device when the private CAN IDs transmitted from the reaction force device and the steering device are the same for the primary and secondary. Also, Fig. 29 is a schematic diagram for explaining the flow of data on the primary side of the RWA in the event of a failure. Here, it is assumed that the private CAN transmission ID is 0x040.
[0107] First, when the vehicle ignition key is turned on (step ST291), it is determined whether or not it is control timing (step ST292). If it is determined that it is control timing, private CAN data is received from the FBA (step ST293). Subsequently, private CAN data is received from the primary side of the RWA (step ST294). Next, a fault determination is performed based on the private CAN data from the FBA (step ST295). Furthermore, a fault determination is performed based on the private CAN data from the RWA (step ST296).
[0108] Next, data from inter-MCU communication is received (step ST297), and the actual steering angle is detected (step ST298). Subsequently, it is determined whether the private CAN data received from the FBA is normal (step ST299). As indicated by dashed arrow AL1 in FIG. 29 , CAN communication is performed between the first MCU 31 and the fourth MCU 61 via the first private CAN communication line 123, the inter-system communication line 128 (switching device 70), and the second private CAN communication line 124, and it is sequentially determined whether there are any abnormalities in the CAN drivers 33 and 62. Furthermore, as indicated by dashed arrow AL2, CAN communication is performed between the second MCU 41 and the fourth MCU 61 via the second private CAN communication line 124, and it is sequentially determined whether there are any abnormalities in the CAN driver 43. If it is determined that the data is normal, the CAN data received on the secondary side of the FBA is set as the target steering angle calculation data (step ST300).
[0109] In step ST299, for example, if the CAN driver 33 on the primary side of the FBA fails, the same CAN information is sent from the secondary side of the FBA, so the received CAN data becomes normal and the process moves to step ST300.
[0110] If step ST299 determines that the CAN data on the primary side obtained through inter-MCU communication is abnormal, the system determines whether the data is normal (step ST301). If the data is normal, the CAN data received on the primary side through inter-MCU communication is set as the target steering angle calculation data (step ST302). This determination is made by executing CAN communication between the second MCU 41 and the fourth MCU 61 via the second private CAN communication line 124, as indicated by the dashed arrow AL3 in FIG. 29, and inter-MCU communication between the fourth MCU 61 and the third MCU 51, to determine whether there is an abnormality. If the data is abnormal, the system sets the target steering angle calculation data to data received from the steering angle sensor (sensor detection value) (step ST303). This steering angle sensor reception data is obtained from the second steering angle sensor 109 on the secondary side of the FBA, as indicated by the dashed arrow AL4 in FIG. 29.
[0111] In the next step ST304, the target steering angle is calculated. After that, it is determined whether the primary side is normal (step ST305). If it is determined that the primary side is normal, the target torque value on the primary side is set as the secondary target torque value (step ST306). If it is determined that the primary side is not normal, steering feedback control (secondary target motor torque calculation) is performed using secondary side data (step ST307).
[0112] Next, data for inter-MCU communication is generated (step ST308) and the generated data for inter-MCU communication is transmitted (step ST309). Private CAN data is also generated (step ST310). Then, it is determined whether the CAN data transmitted from the primary side of the RWA is normal (step ST311), and if normal, the generated private CAN data is transmitted (step ST312). Then, vector control of the electric motor 116 is performed (step ST313). If not normal, the process proceeds to step ST313, where vector control of the electric motor 116 is performed.
[0113] Next, a duty calculation for PWM control of the motor is performed (step ST314), and a PWM signal resulting from the calculation is output to PWM-control the electric motor 116 (step ST315). Then, it is determined whether the vehicle ignition key is turned off (step ST316). If it is determined that the ignition is not turned off, the process returns to step ST292, and the operations from step ST292 to step ST316 described above are repeated. On the other hand, if it is determined that the ignition is turned off, the shutdown process is executed and terminated (step ST317).
[0114] As described above, according to the steering device according to the embodiment of the present invention, data related to the steering of the steered wheels, including the first steering operation amount signal output from the first microcomputer 31 of the steering input device 105, and data related to the steering of the steered wheels, including the second steering operation amount signal output from the second microcomputer 41 of the steering input device 105, can be transmitted to the third and fourth microcomputers 51, 61 of the steering device 104 without causing a delay due to communication between the microcomputers. This makes it possible to achieve both controllability and safety of the vehicle even in the event of a malfunction.
[0115] It should be noted that the configurations, methods, etc. described in the above-described embodiments are merely schematic illustrations to enable the present invention to be understood and implemented. Therefore, the present invention is not limited to the described embodiments, and can be modified in various forms without departing from the scope of the technical ideas set forth in the claims.
[0116] DESCRIPTION OF SYMBOLS 10... Driving operation input unit, 11, 12... First and second actuators, 13, 14... First and second control devices, 15... Communication circuit, 16, 17... First and second microcomputers, 18, 19... First and second interface units, 20, 21... Third and fourth microcomputers, 22, 23... Third and fourth interface units, 24, 25... First and second communication lines, 26... Inter-system communication line (third communication line), 70... Switching device, 101... Steering device, 102... Steering wheel, 103... Front wheels (steerable wheels), 104... Steering device, 105... Steering input device, 106... Steering input control unit, 107... Steering control unit, 123, 124... First and second private CAN communication lines (first and second communication lines), 127... Communication circuit, 128... Inter-system communication line (third communication line)
Claims
1. An actuator control system for controlling an actuator mounted on a vehicle, comprising: a first control device having a driving operation input unit configured to receive driving operations from a driver; a first microcomputer configured to be able to output a first operation amount signal based on the operation amount of the driving operation input unit; a second microcomputer configured to be able to output a second operation amount signal based on the operation amount of the driving operation input unit; a first interface unit that is an interface configured to send and receive communication data to the first microcomputer; and a second interface unit that is an interface configured to send and receive communication data to the second microcomputer; a second control device having a third microcomputer configured to output a first drive signal to the first actuator based on the first operation amount signal or the second operation amount signal; a fourth microcomputer configured to output a second drive signal to the second actuator based on the second operation amount signal or the first operation amount signal; a third interface unit that is an interface configured to send and receive communication data to the third microcomputer; and a fourth interface unit that is an interface configured to send and receive communication data to the fourth microcomputer; a communication circuit configured to transmit data including the first operation amount signal transmitted from the first interface unit to the third interface unit and the fourth interface unit, and to transmit data including the second operation amount signal transmitted from the second interface unit to the fourth interface unit and the third interface unit.
2. An actuator control system according to claim 1, wherein the communication circuit comprises a first communication line connected to enable communication between the first interface unit and the third interface unit, a second communication line connected to enable communication between the second interface unit and the fourth interface unit, and a switching device configured to selectively connect / disconnect the first communication line and the second communication line within the first control device or the second control device.
3. An actuator control system as claimed in claim 2, wherein the switching device is configured to connect the first communication line and the second communication line when an abnormality occurs in any one of the first to fourth interface parts, to separate the first communication line and the second communication line when an abnormality occurs in the first communication line or the second communication line, and to connect the first communication line and the second communication line when an abnormality occurs in the first microcomputer and the fourth microcomputer, or in the second microcomputer and the third microcomputer.
4. A steering device in which a steering input device and a turning device are connected by a communication circuit, wherein the steering input device comprises: a steering input section configured to receive steering operations by a driver; a first microcomputer configured to be able to output a first steering operation amount signal based on the steering operation amount of the steering input section; a second microcomputer configured to be able to output a second steering operation amount signal based on the steering operation amount of the steering input section; a first control device having a first CAN interface section which is an interface configured to send and receive data to and from the first microcomputer via CAN communication; and a second CAN interface section which is an interface configured to send and receive data to and from the second microcomputer via CAN communication; and the turning device comprises: a motor configured to apply a turning force to the steered wheels of the vehicle via a movable member; a second control device having: a third microcomputer configured to output a first drive signal to the motor based on the first steering operation amount signal or the second steering operation amount signal; a fourth microcomputer configured to output a second drive signal to the motor based on the second steering operation amount signal or the first steering operation amount signal; a third CAN interface unit which is an interface configured to send and receive data to the third microcomputer via CAN communication; and a fourth CAN interface unit which is an interface configured to send and receive data to the fourth microcomputer via CAN communication; wherein the communication circuit is configured to transmit information related to the steering of the steered wheels, including the first steering operation amount signal sent from the first CAN interface unit, to the third CAN interface unit and the fourth CAN interface unit, and to transmit information related to the steering of the steered wheels, including the second steering operation amount signal sent from the second CAN interface unit, to the fourth CAN interface unit and the third CAN interface unit.
5. A steering device according to claim 4, wherein the communication circuit has a first communication line connecting the first CAN interface unit and the third CAN interface unit, a second communication line connecting the second CAN interface unit and the fourth CAN interface unit, and a third communication line connecting the first communication line and the second communication line within the first control device or the second control device.
6. A steering device according to claim 5, further comprising a switching device provided in the third communication line and configured to be able to switch between connection and disconnection between the first and second communication lines.
7. A steering device as described in claim 6, wherein the first microcomputer is configured to determine whether or not there is an abnormality in a first system including the first CAN interface unit in the first control device, and the second microcomputer is configured to determine whether or not there is an abnormality in a second system including the second CAN interface unit in the first control device, and the first microcomputer or the second microcomputer is configured to connect the first communication line and the second communication line using the switching device when an abnormality occurs in either the first system or the second system.
8. A steering device according to claim 7, wherein the first microcomputer has a first abnormality determination unit configured to determine whether or not there is an abnormality in the first CAN interface unit, and the second microcomputer has a second abnormality determination unit configured to determine whether or not there is an abnormality in the second CAN interface unit.
9. A steering device as claimed in claim 8, wherein the third microcomputer is configured to determine whether data relating to the steering of the steered wheels, including the first steering operation amount signal, is normal, and if normal, to determine the first drive signal based on data relating to the steering of the steered wheels, including the first steering operation amount signal, and if not normal, to determine the first drive signal based on data relating to the steering of the steered wheels, including the second steering operation amount signal; and the fourth microcomputer is configured to determine whether data relating to the steering of the steered wheels, including the first steering operation amount signal, is normal, and if normal, to determine the second drive signal based on data relating to the steering of the steered wheels, including the first steering operation amount signal, and if not normal, to determine the second drive signal based on data relating to the steering of the steered wheels, including the second steering operation amount signal.
10. A steering device as claimed in claim 9, wherein the third microcomputer is further configured to determine whether data relating to the steering of the steered wheels, including the second steering operation amount signal, is normal, and if so, to determine the first drive signal based on the data relating to the steering of the steered wheels, including the second steering operation amount signal, and if not so, to determine the first drive signal based on the data relating to the steering of the steered wheels obtained from the fourth microcomputer; and the fourth microcomputer is further configured to determine whether data relating to the steering of the steered wheels, including the second steering operation amount signal, is normal, and if so, to determine the second drive signal based on the data relating to the steering of the steered wheels, including the second steering operation amount signal, and if not so, to determine the second drive signal based on the data relating to the steering of the steered wheels obtained from the third microcomputer.
11. A steering device according to claim 10, further comprising: a first steering operation amount sensor provided in a first system of the steering input device and configured to be able to output a signal related to the momentum of the steering input section; and a second steering operation amount sensor provided in a second system of the steering input device and configured to be able to output a signal related to the momentum of the steering input section; wherein the third microcomputer is further configured to determine whether the data related to the steering of the steered wheels obtained from the fourth microcomputer is normal or not, and if normal, to determine the first drive signal based on the data related to the steering of the steered wheels obtained from the fourth microcomputer, and if not normal, to determine the first drive signal based on the signal output from the first steering operation amount sensor; and the fourth microcomputer is further configured to determine whether the data related to the steering of the steered wheels obtained from the third microcomputer is normal or not, and if normal, to determine the second drive signal based on the data related to the steering of the steered wheels obtained from the third microcomputer, and if not normal, to determine the second drive signal based on the signal output from the second steering operation amount sensor. Steering device.
12. A steering device as claimed in claim 5, wherein the third microcomputer is configured to determine whether data relating to the steering of the steered wheels, including the first steering operation amount signal or the second steering operation amount signal, is normal, and if normal, to determine the first drive signal based on data relating to the steering of the steered wheels, including the first steering operation amount signal or the second steering operation amount signal, and if not normal, to determine the first drive signal based on data relating to the steering of the steered wheels obtained from the fourth microcomputer; and the fourth microcomputer is configured to determine whether data relating to the steering of the steered wheels, including the first steering operation amount signal or the second steering operation amount signal, is normal, and if normal, to determine the second drive signal based on data relating to the steering of the steered wheels, including the first steering operation amount signal or the second steering operation amount signal, and if not normal, to determine the second drive signal based on data relating to the steering of the steered wheels obtained from the third microcomputer.
13. A steering device according to claim 6, wherein the first microcomputer or the second microcomputer is configured to separate the first communication line and the second communication line using the switching device when an abnormality occurs in either the first communication line or the second communication line.
14. A steering device as described in claim 6, wherein the steering input device further comprises a first switching signal output unit configured to output a first switching signal for switching the switching device under the control of the first microcomputer, and a second switching signal output unit configured to output a second switching signal for switching the switching device under the control of the second microcomputer, and switches between connection and disconnection of the first communication line and the second communication line based on the first switching signal and the second switching signal.