Communication device

The communication device with multiple control units and inter-system connection lines addresses the challenge of continuing motor control during abnormalities in existing motor control devices, achieving enhanced control continuity with a simple configuration.

WO2025135020A1PCT designated stage expired Publication Date: 2025-06-26DENSO CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/044562
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-29
Filing Date
2024-12-17
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing motor control devices with two sets of motor windings face challenges in continuing control when an abnormality occurs, leading to potential motor shutdown.

Method used

A communication device with multiple control units and electronic components, where each control unit has an arithmetic circuit and is digitally communicable with corresponding electronic components, and inter-system connection lines connect different communication lines to enhance control continuity during failures.

Benefits of technology

The proposed solution allows for continued control with a relatively simple configuration, even when abnormalities occur, by ensuring digital communication between control units and electronic components and utilizing inter-system connection lines to maintain system connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024044562_26062025_PF_FP_ABST
    Figure JP2024044562_26062025_PF_FP_ABST
Patent Text Reader

Abstract

A communication device (15) comprises a plurality of control units (21-24) and a plurality of electronic components (31, 33, 36, 38, 66-69, 701-707, 73, 801-804, 811, 812). The control units (21-24) have one or more arithmetic circuits (211, 212, 231, 232). The electronic components are provided in correspondence with the control units and are connected to the control units so as to be digitally communicable therebetween. When combinations of the control units and the electronic components provided in correspondence are defined as control systems, and communication lines connecting the control units and the electronic components corresponding to each other are defined as intra-system communication lines, inter-system connection lines (25, 251-253, 256-258) connect: between the intra-system communication lines having different control systems; between the intra-system communication lines and the electronic components of other control systems; or between the electronic components having different control systems.
Need to check novelty before this filing date? Find Prior Art

Description

communication equipment CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Patent Application No. 2023-212688 filed on December 18, 2023, and Patent Application No. 2024-029593 filed on February 29, 2024, the contents of which are incorporated herein by reference.

[0002] The present disclosure relates to a communication device.

[0003] Conventionally, motor control devices that control a motor having two sets of motor windings are known. For example, Patent Document 1 discloses a two-system configuration in which inverter circuits and control units are provided corresponding to the motor windings.

[0004] Japanese Patent Application Laid-Open No. 2018-129995

[0005] In Patent Document 1, if a further failure occurs while control is continuing after one failure has occurred, there is a risk that the motor drive may not be able to continue. An object of the present disclosure is to provide a communication device that can continue control as much as possible even when an abnormality occurs.

[0006] The communication device of the present disclosure includes multiple control units and multiple electronic components. The control units have at least one arithmetic circuit. The electronic components are provided corresponding to the control units and connected to the control units so as to be able to digitally communicate with the control units. The combination of the corresponding control units and electronic components is referred to as a control system, and the communication lines connecting the corresponding control units and electronic components are referred to as intra-system communication lines. Inter-system connection lines connect the intra-system communication lines between different control systems, between intra-system communication lines and electronic components in other control systems, or between electronic components in different control systems. This allows for a relatively simple configuration to increase the possibility of control continuity in the event of a failure.

[0007] The above and other objects, features, and advantages of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which Fig. 1 is a schematic diagram showing an electric power steering apparatus according to a first embodiment, Fig. 2 is a block diagram showing an ECU according to the first embodiment, Fig. 3 is a circuit diagram illustrating a driver circuit according to the first embodiment, Fig. 4 is a circuit diagram illustrating driver components according to the first embodiment, Fig. 5 is a circuit diagram illustrating driver components according to the first embodiment, Fig. 6 is a circuit diagram illustrating driver components according to the first embodiment, Fig. 7 is a plan view showing the driver components according to the first embodiment, and Fig. 8 is a diagram illustrating the VI of Fig. 7. 9 is a schematic diagram illustrating the board layout according to the first embodiment, FIG. 10 is a schematic diagram illustrating the board layout according to the first embodiment, FIG. 11 is a schematic diagram illustrating the board layout according to the first embodiment, FIG. 12 is an explanatory diagram illustrating the connection between microcomputers and components in two systems, FIG. 13 is an explanatory diagram illustrating the connection between microcomputers and components in three systems, FIG. 14A is an explanatory diagram illustrating the system-to-system connection lines according to the first embodiment, FIG. 14B is an explanatory diagram illustrating the system-to-system connection lines according to the first embodiment, and FIG. 15 is an explanatory diagram illustrating the system-to-system connection lines according to the first embodiment. FIG. 16 is an explanatory diagram showing an isolator according to the first embodiment, FIG. 17 is an explanatory diagram showing a communication configuration between a microcomputer and a driver component according to the first embodiment, FIG. 18 is a time chart explaining data communication according to the first embodiment, FIG. 19 is a schematic diagram showing an arrangement when the motor windings are divided into two systems, FIG. 20 is a schematic diagram showing an arrangement when the motor windings are divided into four systems, FIG. 21 is a time chart explaining communication between an arithmetic core and a pre-driver IC according to the first embodiment, FIG. 22 is a time chart explaining communication with the pre-driver IC when a part of the arithmetic cores has failed according to the first embodiment, FIG. 23 is an explanatory diagram explaining inter-system connection lines according to the first embodiment, FIG. 24 is a block diagram explaining driving of a power supply relay and a reverse connection protection relay according to the first embodiment, FIG. 25 is a block diagram explaining a redundant configuration in the microcomputer according to the first embodiment, and FIG. 26 is a flowchart explaining clock monitoring processing according to the first embodiment.FIG. 27 is a flowchart illustrating a power supply monitoring process according to the first embodiment, FIG. 28 is a block diagram illustrating driving of a power supply relay and a reverse connection protection relay according to the second embodiment, FIG. 29 is a block diagram illustrating driving of a power supply relay and a reverse connection protection relay according to the third embodiment, FIG. 30 is a block diagram illustrating an ECU according to the first embodiment, FIG. 31 is a block diagram illustrating an ECU according to the fourth embodiment, FIG. 32 is a block diagram illustrating an ECU according to the fifth embodiment, and FIG. 33 is a block diagram illustrating an ECU according to the sixth embodiment. FIG. 34 is a schematic diagram showing an arrangement in the case where the motor windings are three systems; FIG. 35 is a block diagram explaining an ECU according to the seventh embodiment; FIG. 36 is a block diagram explaining an ECU according to the eighth embodiment; FIG. 37 is a block diagram explaining an ECU according to the ninth embodiment; FIG. 38 is a block diagram explaining calculation timing according to the ninth embodiment; FIG. 39 is a block diagram explaining an ECU according to the tenth embodiment; FIG. 40 is a time chart explaining operation of the motor relay according to the tenth embodiment; FIG. 42 is a schematic diagram illustrating the board arrangement according to the 11th embodiment, FIG. 43 is a schematic diagram illustrating the board arrangement according to the 12th embodiment, FIG. 44 is a block diagram illustrating an ECU according to the 12th embodiment, FIG. 45 is a block diagram illustrating an ECU according to the 13th embodiment, FIG. 46 is a time chart illustrating the operation of a motor relay according to the 13th embodiment, FIG. 47 is a time chart illustrating the operation of a motor relay according to the 13th embodiment, and FIG. 48 is a time chart illustrating the operation of a motor relay according to the 14th embodiment. 52 is a cross-sectional view taken along line LII-LII in FIG. 50; FIG. 53 is a cross-sectional view taken along line LIV-LIV in FIG. 53; FIG. 54 is a cross-sectional view taken along line LIV-LIV in FIG. 53; FIG. 55 is a cross-sectional view taken along line LV-LV in FIG. 53; FIG. 56 is a cross-sectional view taken along line LV-LV in FIG. 53;64 is a time chart illustrating the communication processing according to the 20th embodiment; FIG. 65 is a block diagram showing a microcomputer and driver components according to the 21st embodiment; FIG. 66 is a flowchart illustrating the communication processing according to the 21st embodiment; FIG. 67 is a time chart illustrating the communication processing according to the 21st embodiment; FIG. 68 is a block diagram showing a microcomputer and driver components according to the 22nd embodiment; 76 is a time chart illustrating communication processing when one microcomputer is abnormal according to the 23rd embodiment; FIG. 77 is a block diagram showing a microcomputer and driver components according to the 24th embodiment; FIG. 78 is a time chart illustrating data transmitted and received in a microcomputer and driver components according to the 24th embodiment; FIG. 79 is a flow chart illustrating communication between a microcomputer and a driver according to the 24th embodiment;24 is a time chart illustrating communication processing according to the twenty-fourth embodiment.

[0008] A communication device according to the present disclosure will be described below with reference to the drawings. In the following, substantially identical components in multiple embodiments will be denoted by the same reference numerals, and descriptions thereof will be omitted.

[0009] (First embodiment) The first embodiment is shown in Figures 1 to 27. As shown in Figure 1, a drive device 10 includes a motor 11 and an ECU 15 as a communication device, and is applied to, for example, an electric power steering device 5, which is a steering device for assisting the steering operation of a vehicle. Figure 1 shows the overall configuration of a steering system 90 including the electric power steering device 5. The steering system 90 includes a steering wheel 91, which is a steering member, a steering shaft 92, a pinion gear 96, a rack shaft 97, wheels 98, and the electric power steering device 5.

[0010] The steering wheel 91 is connected to a steering shaft 92. A torque sensor 93 that detects steering torque is provided on the steering shaft 92. A pinion gear 96 is provided at the tip of the steering shaft 92. The pinion gear 96 meshes with a rack shaft 97. A pair of wheels 98 are connected to both ends of the rack shaft 97 via tie rods or the like.

[0011] When the driver turns the steering wheel 91, the steering shaft 92 connected to the steering wheel 91 rotates. The rotational motion of the steering shaft 92 is converted into linear motion of a rack shaft 97 by a pinion gear 96. A pair of wheels 98 are steered to an angle corresponding to the amount of displacement of the rack shaft 97.

[0012] The electric power steering device 5 includes a drive unit 10, a reduction gear 6 as a power transmission unit that reduces the rotation of the motor 11 and transmits the reduced rotation to the rack shaft 97, and the like. The electric power steering device 5 of this embodiment is a so-called "rack assist type," but may also be a so-called "column assist type" that transmits the rotation of the motor 11 to the steering shaft 92.

[0013] The drive system 10 is a so-called "mechatronically integrated" drive system, in which an ECU 15 is integrally provided on one axial side of the motor 11. The ECU 15 has a connector 16, and is connected to a vehicle power supply 7, a vehicle communication network 8, and a torque sensor 93 via the connector 16. The vehicle power supply 7 includes power supplies 501 and 502, which will be described later. The vehicle communication network 8 is, for example, a CAN (Controller Area Network), and is indicated as "CAN" in the drawing.

[0014] The ECU 15 is disposed coaxially with the motor 11, on the opposite side of the output shaft of the motor 11. Here, "coaxial" means that errors and deviations related to assembly and design, for example, are allowed. Hereinafter, the axial direction of the motor 11 is regarded as the axial direction of the drive unit 10, and will be referred to simply as the "axial direction." The same applies to "radial direction" and "circumferential direction."

[0015] 2, the motor 11 is, for example, a three-phase brushless motor, and has four motor windings 121 to 124. The motor 11 outputs part or all of the torque required for steering, and is driven by power supplied from power sources 501 and 502 to rotate the reduction gear 6 forward and reverse.

[0016] The ECU 15 includes microcomputers 21 and 23, power supply ICs 31 and 33, communication units 36 and 38, oscillators 41 and 43, driver circuits 51 to 54, pre-driver ICs 61 to 64, and position sensors 66 to 69. The subscripts "1," "2," "1A," "2A," "1B," and "2B" indicate corresponding components, and the reference numerals are omitted for components that can be identified by the subscripts. The components that make up the ECU 15 are mounted on a circuit board 75 that is disposed substantially parallel to one axial end face of the motor 11 (see FIG. 1). While one circuit board 75 is shown in FIG. 1, multiple circuit boards may be used.

[0017] The microcomputer 21 has arithmetic cores 211 and 212 with lockstep. The microcomputer 23 has arithmetic cores 231 and 232 with lockstep. The microcomputers 21 and 23 are configured to be able to send and receive information to each other through inter-microcomputer communication via an inter-microcomputer isolator 289 (see FIG. 57 ). In this embodiment, the microcomputers 21 and 23 have the same configuration, but the performance and detailed configuration may differ. Details of the microcomputers 21 and 23 will be described later.

[0018] The microcomputer 21 receives power from a power supply IC 31, and the microcomputer 23 receives power from a power supply IC 33. The power supply ICs 31 and 33 are power management ICs (PMICs). In this embodiment, power is supplied from a power supply 501 to the components above the dashed dotted line in FIG. 2, and power is supplied from a power supply 502 to the components below the dashed dotted line. In other words, the drive device 10 of this embodiment is a "two-power supply system" in which power is supplied from the two power supplies 501 and 502.

[0019] The communication units 36, 38 are used to send and receive various types of information. The communication units 36, 38 are connected to the vehicle communication network 8 and acquire vehicle signals from the vehicle communication network 8. The oscillators 41, 43 are clock sources such as crystal or ceramic oscillators.

[0020] As shown in Fig. 3, driver circuit 51 has six switching elements 511 to 516 and is provided corresponding to winding 121. Driver circuit 52 has six switching elements 521 to 526 and is provided corresponding to winding 122. Driver circuit 53 has six switching elements and is provided corresponding to winding 123. Driver circuit 54 has six switching elements and is provided corresponding to winding 124. Motor relays 131 to 134 are provided between driver circuits 51 to 54 and windings 121 to 124 (see Fig. 39).

[0021] In driver circuit 51, switching elements 511 to 513 are provided on the high potential side, and switching elements 514 to 516 are provided on the low potential side and are bridge-connected. Switching elements 511 and 514 are connected to the U phase of winding 121, switching elements 512 and 515 are connected to the V phase of winding 121, and switching elements 513 and 516 are connected to the W phase of winding 121.

[0022] In the driver circuit 52, switching elements 521 to 523 are provided on the high potential side, and switching elements 524 to 526 are provided on the low potential side, and are bridge-connected. Switching elements 521 and 524 are connected to the U phase of the winding 122, switching elements 522 and 525 are connected to the V phase of the winding 122, and switching elements 523 and 526 are connected to the W phase of the winding 122. Hereinafter, the switching element on the high potential side will be referred to as the upper arm element, and the switching element on the low potential side will be referred to as the lower arm element, as appropriate. The switching elements in this embodiment are MOSFETs, but may also be IGBTs, bipolar transistors, etc.

[0023] The driver circuits 51 and 52 are connected to a power supply 501. A power supply relay 551, a reverse connection protection relay 556, a choke coil 562, and a capacitor 566 are provided between the power supply 501 and the driver circuit 51. The choke coil 561 and the capacitor 566 form a filter circuit. A power supply relay 552, a reverse connection protection relay 557, a choke coil 562, and a capacitor 567 are provided between the power supply 501 and the driver circuit 52. The choke coil 562 and the capacitor 567 form a filter circuit. The driver circuits 53 and 54 are connected to a power supply 502. The circuit configurations of the driver circuits 53 and 54 and the power supply relay, reverse connection protection relay, and filter circuit provided between the power supply 502 and the driver circuits 53 and 54 are similar to those of the driver circuits 51 and 52 and the power supply relays 551 and 552, etc., and therefore will not be described here.

[0024] 2, pre-driver ICs 61 to 64 are provided corresponding to driver circuits 51 to 54. Pre-driver ICs 61 and 62 are provided to be able to digitally communicate with microcomputer 21, and pre-driver ICs 63 and 64 are provided to be able to digitally communicate with microcomputer 23. Microcomputers 21 and 23 transmit three-phase drive commands for motor 11 to each of pre-driver ICs 61 to 64 as a set of digital signals.

[0025] In detail, the pre-driver IC 61 is communicatively connected to the arithmetic core 211, the pre-driver IC 62 is communicatively connected to the arithmetic core 212, the pre-driver IC 63 is communicatively connected to the arithmetic core 231, and the pre-driver IC 64 is communicatively connected to the arithmetic core 232. In addition, the communication lines connecting the pre-driver ICs 61 to 64 and the arithmetic cores 211, 212, 231, and 232 are connected by inter-system connection lines 25.

[0026] By digitizing communication between the microcomputer and the pre-drivers and providing the inter-system connection lines 25, even if an abnormality occurs in one of the arithmetic cores, it is possible to continue issuing commands from the other normal arithmetic cores to all of the pre-driver ICs 61 to 64. The inter-system connection lines 25 mean that the four connection lines connecting the cores and the pre-driver ICs are connected so that they have the same potential. Therefore, even if a line is broken at the point indicated by the arrow mid in Figure 2, it is still possible to exchange signals between the arithmetic cores 1A and 1B and the pre-drivers 2A and 2B.

[0027] An isolator 28 (not shown in FIG. 2 ), which will be described later, is provided on the inter-system connection line 25. The isolator 28 may be provided at any location on the inter-system connection line 25. Alternatively, the same effect can be obtained by providing an isolator function to a necessary component.

[0028] The position sensors 66 to 69 detect the rotation of the motor 11. The position sensors 66 to 69 are connected to the arithmetic cores 211, 212, 231, and 232, respectively. The communication lines connecting the position sensors 66 to 69 and the microcomputers 21 and 23 are connected by an inter-system connection line 256. The communication lines connecting the power supply ICs 31 and 33 and the microcomputers 21 and 23 are connected by an inter-system connection line 257, and the communication lines connecting the communication units 36 and 38 and the microcomputers 21 and 23 are connected by an inter-system connection line 258. The inter-system connection lines 256 to 258 may be omitted.

[0029] The pre-driver IC will be described with reference to Fig. 4. Here, the pre-driver IC 61 will be described as a representative example. As shown in Fig. 4, the pre-driver IC 61 includes a three-phase pre-driver circuit 611 that transmits gate signals to the switching elements that make up the driver circuit 51. The pre-driver IC 61 also includes a current detection circuit 612, a temperature detection circuit 613, an abnormality detection unit 614, a relay driver circuit 621, and the like.

[0030] The pre-driver circuit 611 outputs gate signals as drive signals to the switching elements 511 to 516 based on drive commands from the microcomputer 21. The current detection circuit 612 detects the motor current based on the detection values ​​of the current detection elements 517 to 519. In this embodiment, the current detection elements 517 to 519 are current sense MOSs, and are built into the low-side chip 713, which will be described later. The current sense MOSs may be built into the high-side chip 712, or may be chips separate from the upper and lower arm elements.

[0031] As shown in FIG. 5 , the current detection element 531 may be a shunt resistor provided in the arm of each phase. In the example of FIG. 5 , the shunt resistor is provided on the low-potential side of the lower arm element, but it may also be provided on the high-potential side of the upper arm element. Furthermore, as shown in FIG. 6 , the current detection element 532 may be a Hall element provided between the connection point of the upper and lower arm elements and the motor winding. While FIGS. 5 and 6 illustrate the current detection elements 531 and 532 as being provided within a driver component 701 (described later), they may also be provided outside the driver component 701. Note that the motor relay 131 is omitted from FIG. 6 .

[0032] 4, the temperature detection circuit 613 detects the temperatures of the driver circuit 50 and the pre-driver IC 60 itself based on the detection value of a temperature detection element (not shown). The abnormality detection unit 614 monitors abnormalities in the driver circuit 50 based on the gate-source potential difference and drain-source potential difference of the elements constituting the driver circuit 50, and on drive commands from the microcomputer 21. For example, the abnormality detection unit 614 monitors abnormalities such as short circuits and open terminals based on the potential difference. The abnormality detection unit 614 also monitors overheating abnormalities based on temperature information and abnormalities in the pre-driver IC 61 itself.

[0033] The relay driver circuit 621 outputs a gate signal as a drive signal to the power supply relay 551 , the reverse connection protection relay 556 and the motor relay 131 based on a drive command from the microcomputer 21 .

[0034] The pre-driver IC 61 transmits the current detection value, temperature information, and abnormality information to the microcomputer 21. The information transmission from the pre-driver IC 61 to the microcomputer 21 may be digital communication or analog communication.

[0035] In this embodiment, the corresponding driver circuits 51 to 54 and pre-driver ICs 61 to 64 are provided in the same package as one driver component 701 to 704. Figures 7 and 8 show an example of a driver component 701 having a driver circuit 51 and a pre-driver IC 61. In order to explain the inside of the component, a sealing portion 749 is omitted in Figure 7, and hatching of the sealing portion 749 is omitted in Figure 8.

[0036] As shown in FIGS. 7 and 8 , the driver component 701 includes a control chip 711, a high-side chip 712, a low-side chip 713, an intermediate clip 715, a ground clip 716, and a lead frame 72, and is sealed with a sealing portion 749. The sealing portion 749 is formed in a generally rectangular shape in a plan view, with terminals formed along its outer edge. The terminal arrangement and shape are not important, and the terminals may be non-lead type or may be formed to protrude outside the sealing portion 749. The driver component 701 is also provided with a temperature detection element such as a temperature-sensitive diode. The temperature detection element may be built into the high-side chip 712 or the low-side chip 713, similar to the current detection elements 517 to 519.

[0037] The lead frame 72 includes a control land 721, a power land 722, an output land 723, and a ground land 724. The back side of the lead frame 72 is exposed from the sealing portion 749 and is electrically connected to the wiring pattern of the substrate 75 by soldering or the like. Note that not all lands need to be connected to the back side of the substrate 75. Hereinafter, the region on the control land 721 side will be referred to as the IC region Ric, and the region on the power land 722 side will be referred to as the driver element region Rd. Furthermore, in the driver component 701, the end on the power land 722 side (upper side of the paper in FIG. 7) will be referred to as the element side end, and the end on the control land 721 side (lower side of the paper in FIG. 7) will be referred to as the IC side end.

[0038] The control chip 711 constitutes the pre-driver IC 61 and is disposed on a control land 721. In this embodiment, the control land 721 on which the control chip 711 is mounted is at ground potential, but if the back side of the control chip 711 is insulated, the potential of the control land 721 may be a potential other than ground potential, such as a power supply potential.

[0039] Control terminals, which are terminals provided in the control region Rc, are connected to the microcomputer 21, the power supply IC 31, the other pre-driver ICs 62 to 64, etc. The control terminals include a clock signal terminal, a PWM frequency synchronization terminal, a sample and hold terminal, etc. Furthermore, if the communication between the microcomputer 21 and the pre-driver IC 61 is, for example, SPI communication, the control terminals include a chip select terminal, a MISO terminal, a MOSI terminal, etc.

[0040] The three high-side chips 712 each have an upper arm element for each phase built in, and the three low-side chips 713 each have a lower arm element for each phase built in. The low-side chip 713 also has current detection elements 517 to 519 built in.

[0041] The three high-side chips 712 are arranged on a power land 722 that is at the power supply potential, and the high-side chips 712 are arranged side by side along the long side of the control chip 711 with their gate electrodes facing toward the control chip 711. The source electrodes of the high-side chips 712 face upward, and the drain electrodes provided on the back side are connected to the power land 722. Above the high-side chips 712, an intermediate clip 715, a low-side chip 713, and a ground clip 716 are stacked in this order from the high-side chip 712 side, forming a stack structure.

[0042] The intermediate clip 715 is a conductive metal plate made of, for example, copper, and is provided for each of the three high-side chips 712. The lower surface of the intermediate clip 715 is connected to the source electrode of the high-side chip 712, and the upper surface is connected to the drain electrode of the low-side chip 713. The intermediate clip 715 is offset from the control chip 711 side of the high-side chip 712 by an amount that allows connection of a signal line 718. The end of the intermediate clip 715 opposite the control chip 711 is bent downward and connected to an output land 723. The output land 723 is connected to a motor terminal and is connected to each phase of the motor winding 121 via circuit board wiring or the like.

[0043] If the direction in which the high-side chips 712 are adjacent to each other is defined as the width direction (the "first direction" in the drawing), the intermediate clips 715 are spaced apart in the width direction from adjacent frames to an extent that insulation can be ensured, and are formed to be wider than the high-side chips 712. The area of ​​the intermediate clips 715 is formed to be larger than the high-side chips 712. By forming the area of ​​the intermediate clips 715 as large as possible, heat dissipation efficiency is improved.

[0044] The ground clip 716 is a conductive plate made of, for example, copper, and is provided across the three low-side chips 713. The ground clip 716 is offset to an extent that a signal line 718 can be connected to the control chip 711 side of the low-side chip 713. One side of the ground clip 716 in the width direction is bent downward and connected to the ground land 724. In this embodiment, the ground clip 716 is provided inside the sealing portion 749, but the top surface side may be exposed from the sealing portion 749.

[0045] The high-side chip 712 and the low-side chip 713 are connected to the control chip 711 by signal lines 718. In this embodiment, the high-side chip 712 and the low-side chip 713 are stacked, but are offset and stacked in a staircase pattern to ensure a non-overlapping area where they do not overlap with components provided above, making it possible to connect the signal lines 718 in the non-overlapping area. The connection ends of the signal lines 718 on the control chip 711 side are concentrated on one side of the control chip 711. The signal lines 718 include lines for gate driving, current detection, and temperature detection. This allows the driver component 701 to be divided into a drive element region Rd, through which a large current flows, and an IC region Ric.

[0046] The arrangement of components on the circuit board 75 is shown in Figures 9 to 11. Figures 9 and 11 show the surface of the circuit board 75 facing the motor 11, and Figure 10 shows the surface of the circuit board 75 opposite the motor 11. Note that Figure 11 schematically shows the arrangement of the driver components 701 to 704 and the motor windings 121 to 124 on the circuit board 75. The same is true for Figure 42 and others.

[0047] As shown in Figures 9 and 11, driver components 701 to 704 are mounted on a circuit board 75. The four driver components 701 to 704 are provided on the surface of the circuit board 75 facing the motor 11. The four driver components 701 to 704 are arranged concentrically at approximately equal intervals. Furthermore, the driver components 701 and 702 and the driver components 703 and 704 are arranged symmetrically with respect to the circuit board division line D1. The circuit board division line D1 is a division line that separates regions with different power supplies.

[0048] The driver components 701-704 are arranged so that their element-side ends face radially outward. The motor windings 121-124 are connected to the substrate 75 on the radially outer side of the driver components 701-704. That is, from the radially inner side, the control chip 711, the high-side chip 712, the low-side chip 713, and the motor line connection section are arranged in this order. The lead wires of the motor windings 121-124 are arranged approximately parallel to the element-side ends of the driver components 701-704 so as to correspond to the phase arrangement of the switching elements in the driver components 701-704. Note that the phase arrangement shown in FIG. 11 is an example and may be different. In FIGS. 9-11, the winding connection points to which the lead wires of the motor windings are connected are numbered as the motor windings 121-124. The same applies to the power terminals and signal terminals.

[0049] A rotation detection unit 65 is mounted on the surface of the substrate 75 facing the motor 11, at a position facing a magnet provided at the end of a shaft (not shown) of the motor 11. In this embodiment, the rotation detection unit 65 is mounted in the center of the substrate 75. The rotation detection unit 65 includes position sensors 66 to 69.

[0050] The power terminals 761, 763 are connected to the outer edge of the board 75 in an area spanning the board center line D2, which is perpendicular to the board division line D1. The power terminals 761, 763 include a power supply terminal and a ground terminal. The power terminal 761 receives power from the power supply 501, and the power terminal 763 receives power from the power supply 502. The power supply ICs 31, 33 are mounted on the board 75 on the board center line D2 between the rotation detection unit 65 and the power terminals 761, 763. The power supply ICs 31, 33 may be located anywhere other than the board center line D2 as long as they are easily connected to the power terminals 761, 763 and the microcomputers 21, 23. A signal terminal 77 is connected to the outer edge of the board 75 in an area spanning the board division line D1.

[0051] As shown in Figure 10, on the surface opposite the motor 11, microcomputers 21 and 23 are mounted on both sides of the board center line D2 on the board division line D1. A wiring pattern is formed so that power is supplied to the microcomputer 21 from a power terminal 761 and power is supplied to the microcomputer 23 from a power terminal 763. The microcomputers 21 and 23 are connected so that they can communicate with each other, and an isolator 28 is mounted at the connection point between the microcomputers 21 and 23. In this embodiment, the isolator 28 is provided at the center of the board. Furthermore, components such as capacitors and coils that constitute a filter circuit are mounted on the surface opposite the motor 11.

[0052] In this embodiment, the drive device 10 is applied to an electric power steering device 5. When the drive device 10 is applied to a main motor or a brake motor, for example, and not limited to the electric power steering device 5, various components may be made redundant to ensure safety even if a failure occurs in one of the components.

[0053] 12 to 15 conceptually illustrate the communication configuration between the microcomputers and components. As shown in FIG. 12, if a control system is formed by a combination of microcomputers (or computing cores) M1 and M2 and components P1 and P2 communicatively connected via communication lines C1 and C2, if a failure occurs in the microcomputer M1 or component P1, which constitutes the first control system, the microcomputer M2 and component P2, which constitute the second control system, can continue operation with 50% remaining functionality. If a failure occurs anywhere in the second control system, control cannot be continued. In this embodiment, communication lines C1 and C2 correspond to "intra-system communication lines."

[0054] As shown in Figure 13, if further redundancy is achieved, for example by increasing the number of control systems to three, operation can continue with 66% of the functionality remaining in the event of a first failure, and even if a further failure occurs while operation is continuing with one failure and two control systems, operation can continue with 33% of the functionality remaining in the remaining one control system. However, increasing the number of control systems increases the number of parts.

[0055] 14A and 14B, it is assumed that the microcomputers M1 and M2 correspond to the microcomputers 21 and 23, and the components P1 and P2 correspond to the driver components 701 and 703. The driver components 701 and 703 include pre-driver ICs 61 and 63 that control the driver circuits 51 and 53, and output drive signals that drive the driver circuits 51 and 53 in response to commands transmitted from the microcomputers 21 and 23. The driver components 701 and 703 also transmit current detection values, driver outputs, abnormality information, temperature information, and the like to the microcomputers 21 and 23.

[0056] As shown in FIG. 14A , if the driver components 701 and 703 are capable of digital communication, the first communication line C1 and the second communication line C2 are connected by an inter-system connection line 25. For example, if a failure occurs in the microcomputer 21, the microcomputer 23 commands the driver components 701 and 703. This allows control to continue. Furthermore, if the second failure occurs in either the driver component 701 or 703, control can be continued with a normal microcomputer and driver component. This increases the possibility of continued operation in the event of a failure, even with two control systems. Furthermore, as shown in FIG. 14B , the driver components 701 and 703 may be connected by an inter-system connection line 25.

[0057] The communication between the microcomputers 21, 23 and the components 701, 703 is, for example, SPI communication, but may be a communication method other than SPI, such as PSI5, SENT, CAN, Ethernet, Flexray, etc., or may be wireless communication. Also, although one communication line is shown in Fig. 14A etc., the number of communication lines and the number of terminals can be set arbitrarily depending on the communication method etc.

[0058] 14A, when communication lines C1 and C2 are connected by inter-system connection line 25, if the communication lines are connected to the power supply or ground and the voltage is fixed, there is a failure mode in which all connected microcomputers and components become inoperable. Also, when microcomputers M1 and M2 are connected to different power supplies, a failure in one control system may cause a high voltage to be applied to the normal system or a large current to flow into the normal system, which may cause a failure.

[0059] Therefore, as shown in FIG. 15 , an isolator 28 is provided as a system separation component at a location where simultaneous failures are undesirable. Note that the illustration of the isolator 28 is omitted from FIG. 2 and other figures. In the example of FIG. 15 , the isolator 28 is provided in the inter-system connection line 25, but it may also be provided inside the microcontrollers M1 and M2 or the components P1 and P2, for example. Any structure capable of transmitting information while maintaining a potential difference can be used to separate the systems; for example, optical isolation, magnetic isolation, or capacitive isolation can be used. Furthermore, instead of an isolator, a passive element such as a resistor or a buffer may be provided as the system separation component. Furthermore, simultaneous failures may be prevented by using wireless communication. This also applies to isolators 281 to 283 in the embodiments described below.

[0060] Specific examples of communication configurations are shown in Figures 16 and 17. For simplicity, in Figures 16 and 17, the signal lines of the two cores of each microcontroller are shown together, and the inter-system connection lines are omitted. As shown in Figure 16, the microcontrollers 21 and 23 can transmit a common clock signal SCLK and a MOSI signal to the corresponding driver components 701 to 704, and can transmit a chip select signal CS_A to the driver components 701 and 703 and a chip select signal CS_B to the driver components 702 and 704. The driver components 701 to 704 can transmit a MISO signal to the corresponding microcontrollers 21 and 23.

[0061] The microcomputers 21 and 23 are provided to enable inter-microcomputer communication and perform PWM synchronization, duty update timing synchronization, and sample-and-hold timing synchronization for the four driver components 701 to 704. The microcomputers 21 and 23 use the MISO signal to check PWM update using the PWM reflected value and current detection value. Alternatively, PWM update check may be performed by configuring the driver components 701 to 704 to return driver output to the microcomputers 21 and 23. If the driver output is not returned to the microcomputers 21 and 23, the terminals and wiring for returning the driver output can be omitted.

[0062] 17, the microcomputer 21, the driver component 701, and the driver component 702 may be connected in a so-called "daisy chain" configuration, in which communication lines are connected in a circular fashion. Similarly, the microcomputer 23, the driver component 703, and the driver component 704 may be connected in a daisy chain configuration.

[0063] Specifically, signals from the microcomputers 21 and 23 are sent to driver components 701 and 703, and the signals are then sent from the driver components 701 and 703 to driver components 702 and 704. The driver components 702 and 704 then send MISO signals to the microcomputers 21 and 23. In this case, the chip select signal and sample and hold may be shared, which allows the number of terminals and wiring to be reduced.

[0064] In this embodiment, since the communication lines of the control systems are connected by the inter-system connection line 25, in order to prevent data from being mixed on the communication lines, the microcomputers 21 and 23 do not issue commands when communication from another microcomputer begins, or output commands after a predetermined time has elapsed since a response from the driver components 701 and 703. Furthermore, the command destination from the microcomputers 21 and 23 may be specified by chip select, ID assignment, etc.

[0065] FIG. 18 illustrates an example of data transmission and reception. In this embodiment, the microcomputers 21 and 23 output an ID and a command to specify the component to be driven. For example, the component to be driven is specified by the ID, and a current command value and on-duty are transmitted to the component side by MOSI. In the ID method, the component to be driven is specified by the ID, but it is also possible to set an ID that commands multiple components simultaneously. This makes it possible, for example, to synchronize the timing of current detection for multiple components. The component to be driven may also be specified by a chip select method.

[0066] The driver components 701 and 703 transmit current values ​​and status information to the microcomputers 21 and 23. Data transmission from the driver components 701 and 703 is performed by MISO, so information can be transmitted even while commands are being transmitted from the microcomputers 21 and 23. However, to prevent overlapping of data transmission timing from different driver components, the driver components 701 and 703 are set to start transmission when transmission from the driver component 703 is completed, for example. Data arbitration may also be performed by setting transmission to be performed in ID order, for example.

[0067] 19 and 20 show schematic diagrams of motor winding arrangements, with three-phase wiring depicted as a single line. A concentrated winding motor has multiple windings on the stator, and connecting the multiple windings forms a three-phase motor with three input terminals. Depending on how the windings are connected, it is possible to configure one set of three-phase windings or multiple sets of three-phase windings. FIG. 19 shows an example of two sets of three-phase windings; connecting windings that are 180° apart tends to complicate the wiring for connecting the multiple windings and the busbars that carry the wiring.

[0068] This embodiment has a configuration with two power sources and four motor windings. For example, when configuring four sets of three-phase windings in a concentrated winding motor using a 14-pole, 18-slot, 10-pole, 12-slot, or 8-pole, 12-slot stator as shown in Figure 20, it is not necessary to connect windings arranged opposite each other, which simplifies the wiring.

[0069] In this embodiment, the circuit board 75 is provided on one side of the motor 11 in the axial direction, and components corresponding to each power supply are concentrated in an area defined by a circuit board partition line D1 (see FIGS. 1 and 9 to 11). The four motor windings 121-124 are assigned to two power supplies 501, 502 and two microcomputers 21, 23. When driving the motor 11 with the four motor windings 121-124, winding sets that are 180° apart are often driven in phase. Allocating winding sets driven in phase to the same power supply can lead to increased size due to the complexity of components that organize the wiring, poor layout due to cross-arrangement of wiring on the circuit board 75, and the risk of common-cause failure due to wiring shorts.

[0070] Therefore, windings with different drive phases that are arranged adjacent to each other on the stator are assigned to a single power supply system. Specifically, power is supplied from power supply 501 to windings 121 and 122, and power is supplied from power supply 502 to windings 123 and 124. In this embodiment, inter-system connection line 25 is provided, so one core can also output commands to windings assigned to other power supplies. Therefore, even if two windings with different drive phases that are arranged adjacent to each other on the stator are assigned to the same power supply, drivers that are driven in the same phase can be operated by commands from the same core.

[0071] Furthermore, because the energization phases of the windings assigned to the same power supply are different, the timing at which the current draw reaches its maximum when the motor is driven differs. This allows for smoother power consumption in the driver circuit compared to when driver circuits driven in the same phase are assigned to the same power supply, making it possible to reduce the size of smoothing capacitors, for example. It also allows for the consolidation of components assigned to the same power supply system on one side of the board, improving layout operability and reducing the occurrence of common cause failures due to wiring shorts. In Figure 20, the windings 121 and 123, which are energized in the same phase, are shown as white, while the windings 122 and 124, which are energized in the same phase but different from the windings 121 and 123, are shown as matte finish.

[0072] 21, the communication between the arithmetic cores 211, 212, 231, and 232 and the pre-driver ICs 61 to 64 will be described. For simplicity in describing the communication, the arithmetic core 211 will be referred to as "core 1A," the arithmetic core 212 as "core 1B," the arithmetic core 231 as "core 2A," the arithmetic core 232 as "core 2B," the pre-driver IC 61 as "pre-driver 1A," the pre-driver IC 62 as "pre-driver 1B," the pre-driver IC 63 as "pre-driver 2A," and the pre-driver IC 64 as "pre-driver 2B."

[0073] In this embodiment, windings 121 and 123 provided corresponding to the pre-drivers 1A and 2A are wound around the stator in opposing directions and are energized in the same phase. Windings 122 and 124 provided corresponding to the pre-drivers 1B and 2B are wound around the stator in opposing directions and are energized in the same phase. The energization phase of the windings 121 and 123 is different from the energization phase of the windings 122 and 124. It is assumed that the amplitudes of the currents flowing through the windings 121 to 124 are equal.

[0074] 21 , cores 1A and 2A transmit command signals such as duty command values ​​and various drive permission signals to pre-drivers 1A and 2A, which are driven in the same phase. The pre-drivers 1A and 2A transmit current detection values ​​and status information (e.g., driver output, abnormality information, temperature information, etc.) to cores 1A and 2A. Furthermore, cores 1B and 2B transmit command signals such as duty command values ​​and various drive permission signals to pre-drivers 1B and 2B, which are driven in the same phase. The pre-drivers 1B and 2B transmit current detection values ​​and status information to cores 1B and 2B.

[0075] In this embodiment, the cores 1A and 2A transmit drive commands to the pre-drivers 1A and 2A, but do not transmit drive commands to the pre-drivers 1B and 2B. Here, the pre-drivers 1B and 2B may be configured to transmit current detection values ​​and status information to the cores 1A and 2A that have not received a drive command. Similarly, the pre-drivers 1A and 2A may be configured to transmit current detection values ​​and status information to the cores 1B and 2B that have not received a drive command. This allows each core to grasp the control state of the entire drive device 10.

[0076] The cores 1A and 2A alternately transmit commands to the pre-drivers 1A and 2A. Similarly, the cores 1B and 2B alternately transmit commands to the pre-drivers 1B and 2B. This makes it possible to reduce the calculation load on each core.

[0077] As shown in Figure 22, when one core fails, even if the processing is not changed from normal, the update period is extended, but control continues without any fatal impact. Specifically, for example, if core 2A fails, in group A, information is not updated at the update timing commanded by core 2A, and the update period is extended. In this case, the previous command value is maintained at the update timing of core 2A. The impact of the failure can be reduced by using an estimated value from past data at the update timing of core 2A.

[0078] At the timing of updating a command in the failed core 2A, a command may be sent from the normal core 1A instead of the core 2A. This makes it possible to prevent a decrease in performance, including the update period. Furthermore, the pre-drivers 1B and 2B that do not use the command from the core 2A can continue control without being affected by the failure of the core 2A.

[0079] As shown in Fig. 23, the inter-system connection line 25 may be divided between group A and group B, which are driven in the same phase. In Fig. 23, the inter-system connection line for group A is "25A" and the inter-system connection line for group B is "25B". By dividing the communication lines by phase, the amount of information on the communication lines can be reduced. Furthermore, since a common failure mode in the communication lines can be avoided, control can be continued even if an abnormality occurs in one of the communication lines.

[0080] Next, the driving of the power supply relays and reverse connection protection relays will be described. As shown in FIG. 24 , in this embodiment, power supply relays 551-554 and reverse connection protection relays 556-559 are provided for each driver circuit 51-54, and are driven in normal operation by receiving individual commands from the relay driver circuits 621-624 of the corresponding driver circuits 51-54. In FIG. 24 , the power supply relays and reverse connection protection relays are collectively referred to as "power supply / reverse connection relays," and the calculation cores within the microcomputer are omitted. Also, in FIG. 24 , the inter-system connection lines are shown as being separate for group A and group B, as in FIG. 23 , but the inter-system connection lines may be combined as in FIG. 2 .

[0081] If an abnormality occurs in the pre-driver IC 61, the power supply relay 551, or the reverse connection protection relay 556, the pre-driver IC 61 is configured to be pulled down (to the OFF side), and no driving is performed by the other pre-driver ICs 62 to 64. The same applies if an abnormality occurs in the other pre-driver ICs, the power supply relay, the reverse connection protection relay, or the motor relay (not shown in FIG. 24).

[0082] Furthermore, if an abnormality occurs in the microcomputer 21, the microcomputer 23 issues a command to the relay driver circuits 621 and 622 in the pre-driver ICs 61 and 62 to drive the power supply relays 551 and 552 and the reverse connection protection relays 556 and 557. Similarly, if an abnormality occurs in the microcomputer 23, the microcomputer 21 issues a command to the relay driver circuits 623 and 624 in the pre-driver ICs 63 and 64 to drive the power supply relays 553 and 554 and the reverse connection protection relays 558 and 559. As a result, even if an abnormality occurs in one microcomputer, the motor 11 can continue to be driven by driving the relays in response to a command from the other microcomputer.

[0083] Next, the redundant configuration within a microcomputer will be described with reference to Fig. 25. Here, the description will be made taking the microcomputer 21 as an example. The microcomputer 21 has operation cores 211 and 212, a power supply control unit 213, a clock control unit 217, and the like.

[0084] The power supply control unit 213 includes a power supply monitoring unit 214. The power supply control unit 213 is connected to multiple power supply circuits PM1 to PM3. The power supply circuits PM1 and PM2 correspond to the power supply IC 31, and the power supply circuit PM3 corresponds to the power supply IC 33. The power supply IC 31 has, for example, a core power supply voltage output (e.g., approximately 1.2 V) and a power supply output (e.g., 5 V) different from the core power supply voltage. The core power supply corresponds to the power supply circuit PM1, and the 5 V power supply corresponds to the power supply circuit PM2. Although the power supply circuits PM1 and PM2 correspond to the same power supply IC 31, they generate different voltages within the power supply IC 31 and can be considered "different power sources." In other words, the power supply control unit 213 of this embodiment can be said to have a redundant configuration in which power is supplied from three different power sources.

[0085] The power supply circuit PM1 inputs the power as is to the power supply control unit 213 and is used by the arithmetic cores 211 and 212. The power from the power supply circuit PM2 is stepped down by an internal step-down circuit 215 and input to the power supply control unit 213 and used for core arithmetic. The power from the power supply circuit PM3 is stepped down by a step-down circuit 216 external to the microcomputer and input to the power supply control unit 213. Note that the power supply circuit PM2 may be supplied with power from a power supply separate from the power supply IC 31, such as the power supply IC 33, or may be configured to step down the power using a step-down circuit external to the microcomputer. The power supply monitoring unit 214 monitors the voltages supplied from each power supply circuit.

[0086] The clock control unit 217 has a clock monitoring unit 218. The clock control unit 217 obtains a clock signal from an oscillator 41 via a phase-locked loop (PLL) 411. The clock control unit 217 also obtains clock signals from an internal clock circuit 415 and an external clock circuit. In this embodiment, the external clock circuit is the microcomputer 23 of another system, and the clock signal is obtained from the microcomputer 23. Note that the external clock circuit is not limited to the microcomputer of another system, and may be a separately provided clock circuit.

[0087] In other words, the clock control unit 217 of this embodiment has a redundant configuration in which clocks are supplied from three different clock sources. Hereinafter, the clock signal obtained from the oscillator 41 via the phase-locked loop 411 will be referred to as the "PLL clock," the clock signal obtained from the internal clock circuit 219 as the "internal clock," and the clock signal obtained from the external clock circuit as the "external clock."

[0088] The clock monitoring process of this embodiment will be described with reference to the flowchart of Figure 26. Here, the process will be described as being performed by the microcomputer 21, but similar processes are also performed by the microcomputer 23. Note that each process in the microcomputers 21 and 23 may be software processing in which a program stored in advance in a physical memory device such as a ROM (i.e., a readable non-transitory tangible recording medium) is executed by the CPU, or may be hardware processing using a dedicated electronic circuit. Hereinafter, the "step" in step S101 and other steps will be omitted and simply referred to as "S."

[0089] In S101, the clock monitor 218 determines whether the PLL clock and the internal clock match. A deviation of a degree of error is allowed, and the clock monitor 218 determines that the PLL clock and the internal clock match. The same applies to other match determinations. If it is determined that the PLL clock and the internal clock match (S101: YES), the process proceeds to S104. If it is determined that the PLL clock and the internal clock do not match (S101: NO), the process proceeds to S102.

[0090] In S102, the clock monitor 218 determines whether the internal clock and the external clock match. If it is determined that the internal clock and the external clock match (S102: YES), the process proceeds to S105. If it is determined that the internal clock and the external clock do not match (S102: NO), the process proceeds to S103.

[0091] In S103, the clock monitor 218 determines whether the PLL clock and the external clock match. If it is determined that the PLL clock and the external clock match (S103: YES), the process proceeds to S104. If it is determined that the PLL clock and the external clock do not match (S103: NO), the process proceeds to S106.

[0092] In S104, to which the process proceeds when the PLL clock matches the built-in clock or the external clock, the clock control unit 217 operates the arithmetic cores 211 and 212 using the PLL clock.

[0093] In step S105, which is reached when the PLL clock and the internal clock do not match but the internal clock and the external clock match, the clock control unit 217 operates the arithmetic cores 211 and 212 using the internal clock. That is, the PLL clock is used normally, but when the PLL clock is abnormal, it switches to the internal clock as a backup clock. At this time, the clock after switching is output to the microcomputer of the other control system, and the clock received by the microcomputer of the other system is synchronized to perform arithmetic. Furthermore, abnormality monitoring by comparing the internal clock with the external clock continues.

[0094] In S106, to which the process proceeds if none of the PLL clock, the built-in clock, and the external clock match, the clock control unit 217 stops the operations of the arithmetic cores 211 and 212 and notifies the external IC of the clock abnormality.

[0095] The power supply monitoring process will be described with reference to the flowchart of FIG. 27. In S201, the power supply monitoring unit 214 determines whether the core power supply voltage supplied from the power supply circuit PM1 is normal. If it is determined that the core power supply voltage from the power supply circuit PM1 is normal (S201: YES), the process proceeds to S202, where the processor cores 211 and 212 are operated using the core power supply voltage from the power supply circuit PM1. If it is determined that the core power supply from the power supply circuit PM1 is abnormal (S201: NO), the process proceeds to S203, where the power supply used for core operation is switched from the power supply circuit PM1 to the power supply circuit PM2 or the power supply circuit PM3. Here, the case where the backup power source is switched to the power supply circuit PM2 will be described as an example. If the power supply circuit PM2 is switched to the power supply circuit PM3, the explanation will be omitted.

[0096] In S204, the power supply monitor 214 determines whether the core power supply voltage supplied from the power supply circuit PM2 via the step-down circuit is normal. If it is determined that the core power supply voltage from the power supply circuit PM2 is normal (S204: YES), the process proceeds to S205, where the processor cores 211 and 212 are operated using the core power supply voltage from the power supply circuit PM2. If it is determined that the core power supply voltage from the power supply circuit PM2 is normal (S204: NO), the process proceeds to S206, where the processor cores 211 and 212 are stopped from operating and an external IC is notified of the core power supply voltage abnormality. As a result, even if a core power supply abnormality occurs in the power supply circuit PM1, the processor cores 211 and 212 can continue to operate by using the power supply circuits PM2 and PM3 as backup core power supplies.

[0097] As described above, the ECU 15 includes multiple microcomputers 21 and 23 and driver components 701 to 704. Each of the microcomputers 21 and 23 includes at least one processor core. In this embodiment, the microcomputer 21 includes processor cores 211 and 212, and the microcomputer 23 includes processor cores 231 and 232.

[0098] The driver components 701 to 704 are provided corresponding to the microcomputers 21 and 23, and are connected to be able to digitally communicate with the microcomputers 21 and 23. In particular, the driver components 701 to 704 are provided corresponding to the arithmetic cores 211, 212, 231, and 232, and are provided to be able to digitally communicate with them.

[0099] The combination of the corresponding microcomputers 21, 23 and driver components 701-704 is referred to as a control system, and the communication lines connecting the corresponding microcomputers 21, 23 and driver components 701-704 are referred to as intra-system communication lines C1, C2. The intra-system communication lines of different control systems, or the driver components 701, 703 of different control systems, are connected by an inter-system connection line 25. This makes it possible to increase the possibility of control continuity in the event of a failure with a relatively simple configuration. Note that the same effect can be obtained by connecting the driver components with inter-system connection lines.

[0100] The driver components 701 to 704 include pre-driver ICs 61 to 64 that transmit drive signals to switching elements that constitute driver circuits 51 to 54 related to driving the motor 11. The arithmetic cores 211, 212, 231, and 232 digitally transmit drive commands for the switching elements to the pre-driver ICs 61 to 64. The drive commands are, for example, duty command values. The pre-driver ICs 61 to 64 transmit drive information including at least one of a current detection value, temperature information, and abnormality information to the microcomputers 21 and 23. This allows the drive of the motor 11 to be appropriately controlled.

[0101] The arithmetic cores 211, 212, 231, and 232 calculate drive commands for some of the driver circuits and acquire drive information from pre-driver ICs corresponding to the driver circuits for which they have not calculated drive commands themselves. For example, the arithmetic core 211 calculates drive commands for the driver circuits 51 and 53 and also acquires drive information from the pre-driver ICs 62 and 64 corresponding to the driver circuits 52 and 54 for which they have not calculated drive commands themselves. This allows each of the arithmetic cores 211, 212, 231, and 232 to appropriately grasp the current drive state.

[0102] The arithmetic cores 211, 212, 231, and 232 transmit drive commands at a timing when the arithmetic cores of other control systems connected by the system-to-system connection line 25 are not outputting drive commands. This makes it possible to prevent data from being mixed up on the communication line.

[0103] The plurality of driver components 701 to 704 hold detection values ​​obtained at the same timing in response to commands from the microcomputers 21 and 23, and transmit the detection values ​​in sequence to the microcomputers 21 and 23. This allows appropriate control calculations to be performed using detection values ​​obtained at the same timing.

[0104] The multiple arithmetic cores 211, 231 alternately transmit drive commands to the pre-driver ICs 61, 63 for each calculation cycle. The multiple arithmetic cores 212, 232 alternately transmit drive commands to the pre-driver ICs 62, 64 for each calculation cycle. This reduces the calculation load on the arithmetic cores 211, 212, 231, 232. Furthermore, even if an abnormality occurs in some of the arithmetic cores, control calculations can be continued. Furthermore, for example, a transition to commands from a normal arithmetic core can be quickly made.

[0105] If an abnormality occurs in one of the multiple arithmetic cores 211, 231 that transmit drive signals to the same pre-driver ICs 61, 63, a normal arithmetic core takes over the transmission of drive commands. Also, if an abnormality occurs in one of the multiple arithmetic cores 212, 232 that transmit drive signals to the same pre-driver ICs 62, 64, a normal arithmetic core takes over the transmission of drive commands. This makes it possible to prevent performance degradation from normal, including the command update cycle, even if an abnormality occurs in one of the arithmetic cores.

[0106] The load in this embodiment is a motor 11 having four sets of motor windings 121 to 124, which are wound around the stator so as to be adjacent to each other in the order of motor winding 121, motor winding 122, motor winding 123, and motor winding 124. In other words, the motor windings 121 and 123 are arranged opposite each other, and the motor windings 122 and 124 are arranged opposite each other (see FIG. 20). Here, "arranged adjacent to each other" means that they are arranged in adjacent areas when viewed as a whole, and may, for example, share some slots.

[0107] The first driver circuit 51 provided for the motor winding 121 and the third driver circuit 53 provided for the motor winding 123 are driven by drive commands of the same phase. The second driver circuit 52 provided for the motor winding 122 and the fourth driver circuit 54 provided for the motor winding 124 are driven by drive commands of the same phase but different phase from the pre-driver ICs 61 and 63.

[0108] In this embodiment, the inter-system connection line 25 is provided, so it is relatively easy to send commands of the same phase from the same calculation core to opposing winding sets. Therefore, even if winding sets with different energization phases are assigned to the same microcomputer or power supply system, it becomes easier to design the circuit board and motor. Furthermore, by assigning winding sets that are energized in different phases to the same power supply system, the maximum value of the drawn current can be reduced.

[0109] The intra-system communication line connecting the first pre-driver IC 61 provided corresponding to the first driver circuit 51 to the first calculation core 211 and the intra-system communication line connecting the third pre-driver IC 63 provided corresponding to the third driver circuit 53 to the third calculation core 231 are connected by a first inter-system connection line 25A. The intra-system communication line connecting the second pre-driver IC 62 provided corresponding to the second driver circuit 52 to the second calculation core 212 and the intra-system communication line connecting the fourth pre-driver IC 64 provided corresponding to the fourth driver circuit 54 to the fourth calculation core 232 are connected by a second inter-system connection line 25B different from the first inter-system connection line 25A. By dividing the inter-system connection lines by phase, the amount of information transmitted through each communication line can be reduced. Furthermore, a common failure mode in the communication lines can be avoided.

[0110] The microcomputers 21 and 23 have a plurality of arithmetic cores 211, 212, 231, and 232, and an intra-system communication line connecting to a driver component is assigned to each of the arithmetic cores 211, 212, 231, and 232. This allows control to continue even if some of the arithmetic cores 211, 212, 231, and 232 fail.

[0111] The inter-system connection line 25 connects the control systems via an isolator 28 that allows information transmission while maintaining a potential difference. This allows the communication lines to be connected appropriately even if there is a potential difference between the connected control systems. Furthermore, even if an abnormality occurs in one of the control systems, simultaneous failures due to the application of high voltage or current flow can be prevented.

[0112] Second and Third Embodiments A second embodiment is shown in Fig. 28. Fig. 28 corresponds to Fig. 24 of the first embodiment, and differs from the above-described embodiments in the power supply relays and reverse connection protection relays. In this embodiment, power supply relays 551 and 553 and reverse connection protection relays 556 and 558 are provided for each power supply. The power supply relay 551 and reverse connection protection relay 556 are shared by the driver circuits 51 and 52, and the power supply relay 553 and reverse connection protection relay 558 are shared by the driver circuits 53 and 54.

[0113] Relay driver circuits 621 and 622 drive power supply relay 551 and reverse connection protection relay 556 via arbitration circuit 571. Relay driver circuits 623 and 624 drive power supply relay 553 and reverse connection protection relay 558 via arbitration circuit 573. By providing arbitration circuits 571 and 573, the number of relays can be reduced.

[0114] Under normal conditions, arbitration circuit 571 receives the same command from relay driver circuits 621 and 622, and matches the commands to drive power supply relay 551 and reverse connection protection relay 556. If one of relay driver circuits 621 and 622 is abnormal, arbitration circuit 571 receives different signals from relay driver circuits 621 and 622, and therefore prioritizes the signal from the normally operating side to drive power supply relay 551 and reverse connection protection relay 556.

[0115] Under normal conditions, arbitration circuit 573 receives the same command from relay driver circuits 623, 624, and matches the commands to drive power supply relay 553 and reverse connection protection relay 558. If one of relay driver circuits 623, 624 is abnormal, arbitration circuit 573 receives different signals from relay driver circuits 623, 624, and therefore prioritizes the signal from the normally operating side to drive power supply relay 553 and reverse connection protection relay 558.

[0116] The third embodiment is shown in Fig. 29. In this embodiment, power supply relays 551 to 554 and reverse connection protection relays 556 to 559 are provided for each of the driver circuits 51 to 54, and arbitration circuits 571 to 574 are also provided.

[0117] The arbitration circuit 571 receives commands from the relay driver circuits 621 and 622 and drives the power supply relay 551 and the reverse connection protection relay 556. The arbitration circuit 572 receives commands from the relay driver circuits 621 and 622 and drives the power supply relay 552 and the reverse connection protection relay 557. The arbitration circuit 573 receives commands from the relay driver circuits 623 and 624 and drives the power supply relay 553 and the reverse connection protection relay 558. The arbitration circuit 574 receives commands from the relay driver circuits 623 and 624 and drives the power supply relay 554 and the reverse connection protection relay 559. The operation of the arbitration circuits 571 to 574 is generally similar to that of the second embodiment. This allows the motor 11 to continue operating even in a wider range of failure modes. The same effects as those of the above embodiment are also achieved.

[0118] (Fourth to Eighth Embodiments) The fourth to eighth embodiments are variations of the redundant configuration. In describing the redundant system, the power supply, vehicle signal input, and torque signal input are collectively referred to as the "external input system," the power supply IC, communication unit, and oscillator are collectively referred to as the "microcomputer input system," and the pre-driver IC and driver circuit are collectively referred to as the "driver system." The external input system corresponds to input from the connector 16. Furthermore, the oscillator and inter-system connection lines are omitted as appropriate. Figure 30 shows a simplified configuration of the first embodiment. Note that unless the number of cores in a microcomputer is mentioned, it is assumed that the microcomputer has one arithmetic core with lockstep.

[0119] As shown in FIG. 31 , the fourth embodiment is provided with four microcomputers, each with one lockstep arithmetic core. The remaining configuration is generally the same as that of the first embodiment. As shown in FIG. 32 , the fifth embodiment is provided with four external input systems, and the power supply, microcomputer, driver, and motor windings are all organized into four systems. By organizing the power supply, microcomputer, and driver into four systems, it is easy to combine it with a four-system motor. Furthermore, even when using a dual-power supply configuration, it is easy to separate the power supply into two systems.

[0120] By providing three or more of each component, control can continue even if two of the same components fail. Also, as explained in the first embodiment, by connecting the signal lines with inter-system connection lines, it is possible to maintain the same output as normal unless there is a failure on the drive side. When inter-system connection lines are provided, it is preferable to insert an isolator as appropriate to avoid common cause failures.

[0121] Furthermore, the number of systems is not limited to an even number, such as two or four systems, but may be an odd number, or a mixture of odd and even numbers of components. The sixth embodiment shown in Figure 33 is an example of a three-system configuration in which three external input systems, three microcomputer input systems, three driver systems, and three motor windings are provided. As shown in Figure 34, when there are three driver systems, efficient wiring can be achieved by also providing three motor winding systems.

[0122] On the other hand, providing multiple components for redundancy raises concerns about an increase in the number of components, an increase in size, and an increase in the computational load. In such cases, components that are relatively prone to failure may be provided in three or four systems, and components that are relatively unlikely to fail may be provided in two systems. For example, if the driver circuit is most prone to failure, the driver system may be provided in four systems and the others in two systems, as in the seventh embodiment shown in FIG. 35.

[0123] 36, the ECU 15 is provided with four power supply ICs 31-34 and four oscillators 41-44, and a single microcomputer may be provided with a plurality of power supply ICs and oscillators (two in FIG. 36). In this embodiment, a total of four processor cores are provided, each of which uses a different power supply IC as a power source and a different oscillator as a clock source. This configuration also achieves the same effects as the above embodiments.

[0124] Ninth Embodiment A ninth embodiment is shown in Figures 37 and 38. In the above embodiments, the processor cores are described as having lockstep. When the processor cores have lockstep, redundant calculations are performed by the lockstep cores, and abnormalities are detected by comparing the calculation results. On the other hand, when the processor cores do not have lockstep cores, calculation errors cannot be detected. In the seventh embodiment, the processor cores do not have lockstep cores, and the microcomputers 21 and 23 each have three processor cores, and abnormality monitoring is performed by majority vote of the calculation results.

[0125] As shown in FIG. 38 , the three processor cores 261 to 263 can perform independent calculations and simultaneously perform calculations based on a common clock. In this case, for example, if momentary noise occurs, the calculations performed by the three processor cores 261 to 263 may be affected in the same way. Therefore, by shifting the calculation timing using a clock delayer 265, simultaneous calculation errors can be prevented. Since the comparator 267, which compares the calculation results, must compare calculation results at the same timing, the delays between the multiple cores are made uniform. Dynamic comparison using the comparator 267 enables rapid judgment. Alternatively, instead of comparison by the comparator 267, data may be accumulated for a certain period of time and then collectively compared by the processor cores 261 to 263. This configuration also achieves the same effects as the above embodiment.

[0126] Tenth Embodiment A tenth embodiment is shown in Figures 39 to 41. In the tenth embodiment, a method of operation in a redundant configuration will be described. For example, in a configuration in which four microcomputers and four motor windings are provided (see Figure 32), the four microcomputers may be driven equally, with the output of each set of motor windings being 25%.

[0127] In addition, two microcomputers and two sets of motor windings are used as drive systems, and the remaining two are used as backup systems. Under normal conditions, the drive systems are used to drive the motor, with each set of motor windings providing 50% of its output. If an abnormality occurs in the drive system, the system switches to drive using the backup system.

[0128] 39 shows an example in which there are four microcomputers 21-24 and four driver circuits 51-54, and two sets of motor windings 121, 123. The microcomputers 21, 22 and the driver circuits 51, 52 are connected to the motor winding 121, and the microcomputers 23, 24 and the driver circuits 53, 54 are connected to the motor winding 123. A motor relay 131 is provided between the driver circuit 51 and the motor winding 121, a motor relay 132 is provided between the driver circuit 52 and the motor winding 122, a motor relay 133 is provided between the driver circuit 53 and the motor winding 123, and a motor relay 134 is provided between the driver circuit 54 and the motor winding 124. Each of the motor relays 131-134 includes three switching elements corresponding to each phase. In the figure, the motor relay is indicated as "SW."

[0129] 40, under normal conditions, motor relays 131 and 133 are turned on to energize motor windings 121 and 123 using driver circuits 51 and 53, thereby driving motor 11. If an abnormality occurs in microcomputer 21, motor relay 131 is turned off and motor relay 132 is turned on, thereby energizing motor winding 121 using driver circuit 52 instead of driver circuit 51. If microcomputer 23 is normal, motor relay 133 remains on and motor relay 134 remains off.

[0130] Similarly, if an abnormality occurs in the microcomputer 23, the motor relay 133 is turned off and the motor relay 134 is turned on, thereby energizing the motor winding 123 using the driver circuit 54 instead of the driver circuit 53. If the microcomputer 21 is normal, the motor relay 131 remains on and the motor relay 132 remains off. As a result, even if an abnormality occurs in the microcomputers 21 and 23, the motor 11 can continue to be driven in the same state as before the abnormality occurred.

[0131] As shown in FIG. 41 , components related to the supply of current to the motor windings 121 are arranged together on one side of the substrate 75 (the left side of the paper in the example of FIG. 41 ), and components related to the supply of current to the motor windings 123 are arranged together on the other side of the substrate 75 (the right side of the paper in the example of FIG. 41 ).

[0132] The power terminals are arranged symmetrically with respect to the board partition line D1 on the board 75. The lead wires of the motor windings 121 and 123, the driver component 73, and the motor relays 131 to 134 between the motor wires and the driver component are arranged symmetrically with respect to the board partition line D1 in a configuration corresponding to the motor winding 121 and a configuration corresponding to the motor winding 123, and the phase arrangement is in reverse order.

[0133] The driver components 73 are integrally sealed with one high-side chip 712 and one low-side chip 713 corresponding to each phase, and a control chip 711 incorporating a corresponding pre-driver IC. The six driver components 73 are arranged side by side with their element-side ends facing the motor windings 121 and 123 and their IC-side ends facing the board partition line D1.

[0134] Within the driver component 73, the low-side chip 713, high-side chip 712, and control chip 711 are arranged in this order from the motor windings 121, 123 side. The low-side chip 713 is stacked and offset from the high-side chip 712, but the low-side chip 713 may be placed flat without being stacked, or the control chip 711 may be a separate component. Alternatively, the driver components 701 to 704 of the above embodiment, in which a total of six switching elements are modularized, may be used. In this case, for the phase located in the middle (V-phase in the example of FIG. 41), the drive system elements and backup system elements are assigned to different modules.

[0135] In Figure 41, the drive system components are indicated by solid lines and the backup system components by two-dot chain lines, with the drive system driver components and backup system driver components corresponding to each phase arranged adjacent to each other and alternating. Therefore, the high-side chip 712 and the low-side chip 713 used for driving the same phase are arranged adjacent to each other. This makes it easier to wire the driver components 73 and the motor windings 121, 123, and reduces the mounting area of ​​the power section on the board. This configuration also achieves the same effects as the above embodiment.

[0136] Eleventh to Thirteenth Embodiments The eleventh to thirteenth embodiments are variations in power terminal arrangement and connection. When four external input systems are provided as in the eleventh embodiment shown in Fig. 42 (see Fig. 32), power terminals 761 to 764 corresponding to the four connectors are evenly spaced at 90° intervals.

[0137] As in the twelfth embodiment shown in Figures 43 and 44, power terminals 761 and 762, and power terminals 763 and 763 may be arranged side by side at two locations on the outer edge of the board 75, on either side of the board dividing line D1. When four sets of power terminals 761 to 764 corresponding to four connectors are provided for two power supply ICs 31 and 33, the two sets of power terminals 761 to 764 are connected to the respective power supply ICs 31 and 33 via diodes 781 to 784. By electrically connecting multiple power supply inputs, it is possible to continue to supply power appropriately even if a connector malfunction or a harness becomes detached.

[0138] 45 to 47, switching elements 786 to 789 may be provided between the connector and the power supply IC instead of the diodes 781 to 784. The switching elements 786 and 787 are connected to the power supply IC 31, and the switching elements 788 and 789 are connected to the power supply IC 33.

[0139] As shown in Figure 46, both switching elements 786 and 787 are turned on during normal operation, and if an abnormality occurs in power supply 1A, switching element 786 on the side where the abnormality occurred is turned off. If an abnormality occurs in power supply 1B, switching element 787 is turned off. By keeping both switching elements 786 and 787 on during normal operation, it is possible to quickly switch the power supply to be used when an abnormality occurs.

[0140] 47, under normal circumstances, switching element 786 is turned on and switching element 787 is turned off so that power is supplied from one power supply (for example, power supply 1A). If an abnormality in power supply 1A is detected, switching element 786 may be turned off and a wake-up signal may be sent from the normal microcomputer to switching element 787, turning switching element 787 on. This makes it possible to reduce current consumption under normal circumstances. The same applies to the control of switching elements 788 and 789 connected to power supply IC 33. This configuration also achieves the same effects as the above embodiment.

[0141] (Fourteenth and Fifteenth Embodiments) The fourteenth and fifteenth embodiments are variations on the board arrangement. In the first embodiment, the motor windings 121 to 124 are provided radially outside the driver components 701 to 704 (see FIG. 11). In the fourteenth embodiment shown in FIG. 48, the motor windings 121 to 124 are provided radially inside the driver component 701.

[0142] 49, the driver components 701 and 702 are arranged symmetrically with respect to the board center line D2 so that the pre-driver ICs 61 and 62 face the power terminals 76. The driver components 703 and 704 are arranged symmetrically with respect to the board center line D2 so that the pre-driver ICs 63 and 64 face the power terminals 76. The motor windings 121 to 124 are provided on the driver circuit 51 to 54 sides of the driver components 701 to 704. This configuration also achieves the same effects as the above embodiments.

[0143] (16th Embodiment) The 16th to 18th embodiments are modified driver components. The 16th embodiment is shown in Figures 50 to 52. Figure 50 is a diagram corresponding to Figure 7, and shows each component in a simplified form. In the driver component 705 of this embodiment, the stacked structure of the chips 712 and 713 is generally similar to that of the first embodiment.

[0144] The ground lands 724 of the lead frame 725 are provided on both sides of the power lands 722. The ground clips 741 are bent downward on both sides in the width direction and connected to the ground lands 724.

[0145] As shown in Figure 52, the control land 726 on which the control chip 711 is disposed is exposed from the sealing portion 749 to the backside at the middle portion in the width direction, and is not exposed from the sealing portion 749 at the outer portions in the width direction. In other words, as indicated by the dashed square, a portion of the control land 726 is floating above the substrate 75. This ensures the ease of routing of the high-side chip 712 and the power supply line on the substrate. Furthermore, since the power supply + line and the GND line are aligned in a straight line, it becomes easier to arrange anti-noise elements such as snubber elements (not shown). Furthermore, noise loops can be reduced. This also provides the same effects as the above-mentioned embodiment.

[0146] 17th Embodiment A 17th embodiment is shown in FIGS. 53 to 55. A driver component 706 of this embodiment does not have a built-in control chip 711, and a lead frame 727 does not have a control land 726. The stacked structure of chips 712 and 713 is generally similar to that of the first embodiment. Note that the control chip 711 may also be built-in in this embodiment. Furthermore, in embodiments such as the first embodiment, the control chip 711 may not be built into the driver component, but may be provided separately.

[0147] In this embodiment, the ground lands 724 are divided for each phase and arranged on the opposite side of the power lands 722 from the output lands 723. A ground clip 742 is provided for each phase. Each ground clip 742 is provided above the low-side chip 713 and bent downward to connect to the ground land 724. The ground clip 742 has a notch 743 formed so that a portion of the high-side chip 712 and the low-side chip 713 is exposed on the top surface. This ensures a non-overlapping region, allowing the high-side chip 712 and the low-side chip 713 to be connected to signal lines.

[0148] The motor current can be detected by dividing the ground clip 742 into phases and detecting the voltage across both ends of the low-side chip 713 and the ground land 724. That is, in this embodiment, the ground clip 742 also functions as a current detection element. This makes it possible to detect the motor current with a relatively simple configuration. The same effects as those of the above embodiment can also be achieved.

[0149] 56 shows an 18th embodiment. In a driver component 707 of this embodiment, a high-side chip 712 and a low-side chip 713 are not stacked but are laid flat. In this embodiment, the control chip 711, the high-side chip 712, and the low-side chip 713 are arranged in this order from one side.

[0150] The lead frame 728 of this embodiment has a control land 721, a power land 722, an output land 729, and a ground land 724, and the low-side chip 713 is disposed on the output land 729. The intermediate clips 715 are provided above the high-side chips 712, and one end is bent downward to connect to the output land 729.

[0151] In this embodiment, because the high-side chip 712 is disposed between the low-side chip 713 and the control chip 711, it is difficult to directly connect the gate electrode of the low-side chip 713 to the control chip 711. Therefore, in this embodiment, bonding pads are provided on the high-side chip 712, and the gate terminal of the low-side chip 713 is connected to the control chip 711 via the bonding pads of the high-side chip 712. By using the high-side chip 712 provided between them as a relay, the control chip 711 and the low-side chip 713 can be appropriately connected. In addition, the same effects as those of the above embodiment can be achieved.

[0152] 57 to 62 show the 19th embodiment. The 19th to 24th embodiments will mainly describe communication between a microcomputer and a driver component, or communication between driver components. For simplicity of explanation, the following embodiments will be described assuming that there are two microcomputers, two driver components, and two motor windings, but the same can be applied to the configurations of the above embodiments.

[0153] 57, in the first control system, a microcomputer 201 and a driver component 801 are connected, and in the second control system, a microcomputer 202 and a driver component 802 are connected. Except for the communication configuration, the microcomputers 201 and 202 and the driver components 801 and 802 are generally similar to the microcomputers 21 and 23 and the driver components 701 and 703 of the above embodiment. The reference numerals of the components other than the microcomputers, driver components, and isolators will be used as appropriate from the above embodiment.

[0154] Hereinafter, the combination of the microcomputer 201 and the driver component 801 will be referred to as the "first control system," and the combination of the microcomputer 202 and the driver component 802 will be referred to as the "second control system." Furthermore, in the embodiments described below, the combination of the microcomputer 201 and the driver components 803 and 811 will be referred to as the "first control system," and the combination of the microcomputer 202 and the driver components 804 and 812 will be referred to as the "second control system." In the drawings, etc., to distinguish between the systems, the subscript "1" will be appropriately added to the configuration and signals of the first control system, and the subscript "2" will be appropriately added to the configuration and signals of the second control system. Furthermore, when there is no need to distinguish between the systems, the subscripts "1," "2," etc. will be omitted.

[0155] The microcomputers 201 and 202 are provided with a terminal for outputting a clock signal CLK, a MISO signal terminal for inputting a signal from the driver side, a MOSI signal terminal for outputting a signal to the driver side, a terminal for outputting a chip select signal CS, and a terminal for outputting an enable signal EN. The driver components 801 and 802 are provided with a terminal for inputting a clock signal CLK, a MISO signal terminal for outputting a signal to the microcomputer side, a MOSI terminal for inputting a signal from the microcomputer side, and a terminal for inputting the chip select signal CS. In this embodiment, the driver components 801 and 802 are provided with a pair of communication ports used for communication between the microcomputer and the driver.

[0156] Chip select signals CS11 and CS12 are signals output from the microcomputer 201, with the chip select signal CS11 being a signal that selects the driver component 801 and the chip select signal CS12 being a signal that selects the driver component 802. Chip select signals CS21 and CS22 are signals output from the microcomputer 202, with the chip select signal CS21 being a signal that selects the driver component 802 and the chip select signal CS22 being a signal that selects the driver component 801. The chip select signals CS12 and CS22 that select the driver component on the other system are output to the other system via isolators 281 and 282, respectively.

[0157] The enable signal EN1 is a signal output from the microcomputer 201 to the isolator 281, and the enable signal EN2 is a signal output from the microcomputer 202 to the isolator 282.

[0158] The inter-system connection line 251 connects the intra-system communication lines C1 and C2, and is mainly used for signal transmission between the microcomputer 201 and the driver component 802. In detail, the inter-system connection line 251 includes a signal line for outputting a clock signal and a MOSI signal output from the microcomputer 201 to the second control system side. The inter-system connection line 251 also includes a signal line for outputting a MISO signal output from the driver component 802 to the first control system side. An isolator 281 is provided in the inter-system connection line 251.

[0159] The inter-system connection line 252 connects the intra-system communication lines C1 and C2, and is mainly used for signal transmission between the microcomputer 202 and the driver component 801. In detail, the inter-system connection line 252 includes a signal line for transmitting a clock signal and a MOSI signal output from the microcomputer 202 to the first control system side. The inter-system connection line 252 also includes a signal line for transmitting a MISO signal output from the driver component 801 to the second system side. An isolator 282 is provided in the inter-system connection line 252.

[0160] An enable signal EN1 from the microcomputer 201 is input to the isolator 281, and an enable signal EN2 from the microcomputer 202 is input to the isolator 282. That is, the isolators 281 and 282 of this embodiment have a system separation function that connects signals so that they can be transmitted and received while maintaining a potential difference, as well as an enable function that switches between enabled and disabled signals based on the enable signals EN1 and EN2 from the microcomputers 201 and 202. The enable function may be configured to switch between enabled and disabled by an enable signal for each signal line, or may be configured to output a single enable signal collectively to multiple signal lines to switch between enabled and disabled.

[0161] As shown in Fig. 58, the isolator 281 determines the output signal using a logical operation or a switching element based on the relationship between the input signal and the enable signal. For example, as shown in Fig. 59, when the input signal is "H" and the enable signal is "enable", the output signal is "H", and when the input signal is "L" and the enable signal is "enable", the output signal is "L". Furthermore, when the enable signal is "disable", the output signal is "undefined", "fixed to H", or "fixed to L", regardless of the input signal. The same is true for the isolator 282.

[0162] In this embodiment, under normal conditions, the microcomputers 201 and 202 perform microcomputer-driver communication with their own system's driver components 801 and 802, respectively. When the microcomputer 202 is abnormal, the microcomputer 201 communicates with the driver components 801 and 802, and when the microcomputer 201 is abnormal, the microcomputer 202 communicates with the driver components 801 and 802.

[0163] In the microcontroller-driver communication, the information transmitted from the microcontrollers 201 and 202 includes duty command values ​​Du1 and Du2, which are inverter control commands, and the information transmitted from the driver components 801 and 802 includes current detection values ​​I1 and I2 and driver abnormality information E1 and E2.

[0164] 60 is a flowchart illustrating the communication processing of this embodiment. This processing is executed synchronously at a predetermined cycle by the microcomputers 21 and 23. Here, the processing by the microcomputer 21 is taken as an example, and the first control system is described as the local system and the second control system as the other system. Note that the processing by the microcomputer 23 can be interpreted as the second control system being the local system and the first control system being the other system, as appropriate. The same applies to flowcharts of the embodiments described below.

[0165] In S301, the microcomputer 201 determines whether the microcomputer of the own system is normal. If it is determined that the microcomputer of the own system is not normal (S301: NO), the process proceeds to S308, where the microcomputer of the own system is stopped. If it is determined that the microcomputer of the own system is normal (S301: YES), the process proceeds to S302.

[0166] In S302, the microcomputer 201 determines whether the microcomputer 202, which is the other microcomputer, is normal. Here, this determination is made based on information acquired through inter-microcomputer communication, for example. If it is determined that the other microcomputer is not normal (S302: NO), the process proceeds to S304. If it is determined that the other microcomputer is normal (S302: YES), the process proceeds to S303.

[0167] In S303, which is reached when it is determined that both the local system and the other system are normal, the microcomputer 201 sets the chip select signal CS11 to a state in which the driver component 801 is selected, sets the enable signal EN1 to the isolator 281 to a state in which the microcomputer 201 and the driver component 801 are not permitted, and performs communication within the local system between the microcomputer 201 and the driver component 801. At the same time, on the side of the second control system, which is the other system, communication is performed between the microcomputer 202 and the driver component 802.

[0168] Specifically, on the first control system side, chip select signal CS11 is selected, chip select signal CS12 is deselected, and enable signal EN1 is disabled. On the second control system side, chip select signal CS21 is selected, chip select signal CS22 is deselected, and enable signal EN2 is disabled. In other words, by disabling enable signals EN1 and EN2, information is sent and received simultaneously in parallel in each control system.

[0169] If it is determined that the other microcomputer is not normal (S302: NO), the microcomputer 201 proceeds to S304, where it determines whether the other microcomputer has already been stopped. If it is determined that the other microcomputer has already been stopped (S304: YES), it skips S305 and proceeds to S306. If it is determined that the other microcomputer has not been stopped (S304: NO), it proceeds to S305, performs other microcomputer stop processing, and proceeds to S306.

[0170] In S306, information is transmitted and received between the microcomputer 201 and the driver component 801. At this time, the chip select signal CS11 is in the selected state, the chip select signal CS12 is in the non-selected state, and the enable signal EN1 is disabled.

[0171] In S307, information is transmitted and received between the microcomputer 201 and the driver component 802. At this time, the chip select signal CS11 is in the non-selected state, the chip select signal CS12 is in the selected state, and the enable signal EN1 is enabled.

[0172] The communication processing of this embodiment will be described based on the time charts of Figures 61 and 62. In Figures 61 and 62, the horizontal axis represents a common time axis, and the upper row shows various signals output from the microcomputer 201 or driver component 801 in the first control system, while the lower row shows various signals output from the microcomputer 202 or driver component 802 in the second control system.

[0173] Here, the enable signal EN is described as H for permission and L for non-permission, but as long as permission / non-permission can be determined, H may be non-permission and L may be permission. Also, while an example is shown in which the data frame length is 8 bits, the frame length is arbitrary. The same applies to the time charts explaining communication processing according to the embodiment described later.

[0174] 61, when both microcomputers 201 and 202 are normal, both enable signals EN1 and EN2 are disabled, and data is transmitted and received between the microcomputer 201 and driver component 801 in the first control system, and between the microcomputer 202 and driver component 802 in the second control system. In this embodiment, the signal lines between the microcomputer and the driver are connected by inter-system connection lines 251 and 252, but isolators 281 and 282 have an enable function, and by disabling the enable signal EN, communication within each control system can be carried out in parallel. This reduces the time difference in data acquisition between the systems compared to when communication is carried out sequentially for each control system.

[0175] 62 shows an example in which the microcomputer 202 is abnormal. When the microcomputer 202 is abnormal, the microcomputer 201 transmits and receives information to and from the driver components 801 and 802. As shown in the lower part of the page, the clock signal CKL2 and the SPI signals (MISO2, MOSI2) of the microcomputer 202 are all L, the chip select signals CS21 and CS22 are not selected, and the enable signal EN2 is not permitted.

[0176] As shown in the upper part of the page, the microcomputer 201 uses a timer to alternately communicate with the driver components 801 and 802. As shown on the upper left side of the page, communication between the microcomputer 201 and the driver component 802 is the same as in the normal state example of FIG. 61. As shown on the upper right side of the page, when communication is performed between the microcomputer 201 and the driver component 802, the chip select signal CS11 is in the unselected state, the chip select signal CS12 is in the selected state, and the enable signal EN1 is enabled. This allows information to be sent and received between the microcomputer 201 and the driver component 802 via the inter-system connection line 251.

[0177] If the microcomputer 201 is abnormal, the microcomputer 202 replaces the microcomputer 201 and communicates alternately with the driver components 801 and 802. When communication is performed between the microcomputer 202 and the driver component 801, the chip select signal CS21 is in the non-selected state, the chip select signal CS22 is in the selected state, and the enable signal EN2 is in the enabled state. This allows information to be transmitted and received between the microcomputer 202 and the driver component 801 via the inter-system connection line 252.

[0178] Although communication can be established using only the chip select, if the chip select signal fluctuates due to disturbances or the like, there is a possibility of incorrect communication occurring, so the enable function is used to disable the enable signal EN during periods when communication with other systems is not taking place. Also, although an example of a microcomputer failure has been described here, it is preferable to isolate the driver side in the event of a driver failure.

[0179] In this embodiment, the inter-system connection lines 251, 252 connect the control systems via isolators 281, 282 that enable information transmission while maintaining a potential difference. The isolators 281, 282 can receive enable signals EN1, EN2 from the microcomputers 201, 202. When the enable signals EN1, EN2 are in an enable state, communication between the systems is permitted, and when the enable signals EN1, EN2 are in a disable state, communication between the systems is prohibited.

[0180] In this embodiment, the inter-system connection lines 251, 252 connect the intra-system communication lines C1, C2, which are shared for communication within the system and communication between the systems. Therefore, by using the enable signals EN1, EN2, communication within the system and communication between the systems can be performed appropriately.

[0181] When the microcomputer 202 of the other system is normal, the microcomputer 201 communicates with the driver component 801 of its own system, and when the microcomputer 202 of the other system is abnormal, the microcomputer 201 communicates with both the driver component 801 of its own system and the driver component 802 of the other system. Furthermore, when the microcomputer 201 of the other system is normal, the microcomputer 202 communicates with the driver component 802 of its own system, and when the microcomputer 201 of the other system is abnormal, the microcomputer 202 communicates with both the driver component 802 of its own system and the driver component 801 of the other system. The communication data includes a duty command value, a current detection value, abnormality information, and the like. This allows the motor 11 to continue to be driven using the two sets of motor windings 121, 123 even if an abnormality occurs in one of the microcomputers. The same effects as those of the above embodiment can also be achieved.

[0182] (Twentieth Embodiment) A twentieth embodiment is shown in Figures 63 and 64. The communication processing of this embodiment will be described based on the flowchart in Figure 63. Figure 63 differs from Figure 60 in that S309 and S310, which follow S303, have been added.

[0183] If both the local system and the other system are normal and parallel communication is performed within each system in S303, then in S309, communication is performed between the microcomputer 201 and the driver component 802, and in S310, communication is performed between the microcomputer 202 and the driver component 801. The processing order of S309 and S310 may be reversed. The microcomputers 201 and 202 synchronize their timers by inter-microcomputer communication or the like, and communicate with the other system in turn.

[0184] The communication process of this embodiment will be described based on the time chart in Fig. 64. The left side of Fig. 64 corresponds to S303, where enable signals EN1 and EN2 are turned off and communication between the microcomputer and driver is performed within each system. The signal states are the same as in Fig. 61.

[0185] 64 corresponds to S309, where communication is performed between the microcomputer 201 and the driver component 802. When communication is performed between the microcomputer 201 and the driver component 802, the chip select signal CS12 is in a selected state, the other chip select signals CS11, CS21, and CS22 are in a non-selected state, the enable signal EN1 is enabled, and the enable signal EN2 is disabled, and SPI communication is performed between the microcomputer 201 and the driver component 802.

[0186] The right side of the page in Fig. 64 corresponds to S310, where communication is performed between the microcomputer 202 and the driver component 801. When communication is performed between the microcomputer 202 and the driver component 801, the chip select signal CS22 is selected, the other chip select signals CS11, CS12, and CS21 are not selected, the enable signal EN2 is enabled, and the enable signal EN1 is disabled, and SPI communication is performed between the microcomputer 202 and the driver component 801. Communication when an abnormality occurs in the microcomputer is the same as in the 19th embodiment.

[0187] In this embodiment, even when both microcomputers 201 and 202 are normal, communication with driver components 802 and 801 on the other system side is performed using inter-system connection lines 251 and 252. This makes it possible to reduce the communication load between microcomputers. Alternatively, it is possible to omit inter-microcomputer communication. This configuration also achieves the same effects as the above embodiment.

[0188] 21st Embodiment A 21st embodiment is shown in Figures 65 to 67. In the 19th embodiment, the inter-system connection line 251 is connected to the intra-system communication line C2 of the second control system via an isolator 281, and the inter-system connection line 252 is connected to the intra-system communication line C2 of the first control system via an isolator 282.

[0189] 65, in this embodiment, the driver components 803 and 804 have, in addition to a communication port used for communication with the microcomputer of the own system, a communication port connected to the other system via isolators 281 and 282. The inter-system connection line 251 is directly connected to the driver component 804 via the isolator 281, and the inter-system connection line 252 is directly connected to the driver component 803 via the isolator 282. This allows communication between the microcomputer 201 and the driver component 804 and communication between the microcomputer 202 and the driver component 803 to occur simultaneously.

[0190] The communication processing of this embodiment will be described based on the flowchart in Fig. 66. Fig. 66 differs in that S311 replaces S309 and S310 in Fig. 63. When both the local system and the other system are normal and parallel communication is performed within each system in S303, the microcomputer 201 communicates with the driver component 804 on the other system side in S311. At the same time, the microcomputer 202 communicates with the driver component 803.

[0191] The communication processing of this embodiment will be described based on the time chart in Fig. 67. The left side of Fig. 67 corresponds to S303, where enable signals EN1 and EN2 are disabled and communication between the microcomputer and driver is performed within each system. The signal states are the same as in Fig. 61.

[0192] 67 corresponds to S311, and communication between the microcomputer 201 and the driver component 804 and communication between the microcomputer 202 and the driver component 803 are performed in parallel. The microcomputer 201 sets the chip select signal CS11 to a non-selected state, the chip select signal CS12 to a selected state, and the enable signal EN1 to an enabled state, thereby performing SPI communication between the microcomputer 201 and the driver component 804. The microcomputer 202 sets the chip select signal CS21 to a non-selected state, the chip select signal CS22 to a selected state, and the enable signal EN2 to an enabled state, thereby performing SPI communication between the microcomputer 202 and the driver component 803.

[0193] In this embodiment, a port for communication within a system and a port for communication with other systems are provided separately, so that by controlling the chip select signal CS and the enable signal EN, the microcomputers 201 and 202 can communicate in parallel with the driver components 804 and 803 of the other systems. This reduces the time difference between the data that the microcomputers 201 and 202 acquire from the driver side. It also reduces the communication time.

[0194] In this embodiment, the inter-system connection line 251 connects the intra-system communication line C1 to a driver component 804 of another control system, and the inter-system connection line 252 connects the intra-system communication line C2 to a driver component 803 of another control system. In the driver components 803 and 804, the communication ports to which the inter-system connection lines 251 and 252 are connected are provided separately from the ports to which the intra-system communication lines C1 and C2 are connected. This allows microcomputer-driver communication with other systems to be performed in parallel. In addition, the same effects as those of the above embodiment are achieved.

[0195] (Twenty-second embodiment) The twenty-second embodiment is shown in Figure 68. In this embodiment, the mounting position of the isolator differs from that of the twenty-first embodiment. As shown in Figure 68, isolators 281, 282 of this embodiment are built into driver components 803, 804. By building the isolators 281, 282 into the driver components 803, 804, it is possible to simplify the component layout and wiring on the board 75. Note that communication processing and the like are the same as in the twenty-first embodiment. Furthermore, the same effects as those of the above embodiments are achieved.

[0196] 23rd Embodiment The 23rd embodiment is shown in FIGS. 69 to 76. In the 23rd and 24th embodiments, driver components 811 and 812 are connected by an inter-system connection line 253, and an isolator 283 is provided on the inter-system connection line 253. This allows communication between the driver components 811 and 812 without going through the microcomputers 201 and 202. In the example of FIG. 69, the isolator 283 is provided on the inter-system connection line 253, but as in the 22nd embodiment, the isolator 283 may be built into at least one of the driver components 811 and 812. The same applies to the 24th embodiment. Furthermore, the isolator 283 may have an enable function, as in the above embodiments.

[0197] The driver components 811 and 812 each include a driver abnormality detection unit 813. The driver abnormality detection unit 813 detects abnormalities in its own system, such as internal voltage abnormalities, communication abnormalities, and output voltage abnormalities. Information related to the driver abnormality state is transmitted to the microcomputer of its own system and the driver components of other systems. When a driver abnormality is notified, the microcomputers 201 and 202 take measures to deal with the abnormality.

[0198] The driver component 811 transmits the duty command value Du1 and the current detection value I1 of its own system to the driver component 812 of the other system through inter-driver communication, and receives the duty command value Du2 and the current detection value I2 of the other system from the driver component 812. The driver component 812 transmits the duty command value Du2 and the current detection value I2 of its own system to the driver component 811 of the other system through inter-driver communication, and receives the duty command value Du1 and the current detection value I1 of the other system from the driver component 811. The driver components 811 and 812 update the duty command values, current detection values, and driver abnormality states of both systems as needed.

[0199] The data flows in the microcontrollers 201, 202 and driver components 811, 812 are shown in Figures 70 and 71. In Figure 70, for microcontroller-driver communication and driver-driver communication, the MISO signal is shown with a solid line and the MOSI signal with a dashed line. Note that signal lines in other locations are shown with solid lines, but this does not mean that they are MISO signals. Also, in Figures 71 and 72, microcontroller-driver communication is shown with a hollow block arrow, driver-driver communication is shown with a matte block arrow, and values ​​used for motor drive are shown with a double line. Also, the driver circuits 51 and 53 are referred to as "INV1" and "INV2."

[0200] In the communication between the microcomputers and the drivers in the system, SPI communication is performed with the microcomputers 201 and 202 as the masters and the driver components 811 and 812 as the slaves. In the communication between the drivers, an example is shown in which the driver component 811 is the master and the driver component 812 is the slave, but the driver component 812 may be the master and the driver component 811 the slave.

[0201] In the inter-driver communication, the driver component 811 receives, via MISO_d, the current detection value I2 and driver abnormality information E2 of the second control system, and the duty command value Du1 related to the first control system, from the driver component 812. Furthermore, the driver component 811 transmits, via MOSI_d, the current detection value I1 and driver abnormality information E1 of the first control system, and the duty command value Du2 related to the second control system.

[0202] In the microcomputer-driver communication, the microcomputer 201 transmits duty command values ​​Du1 and Du2 of the own system and the other system via MOSI_1 to the driver component 811. In addition, the microcomputer 201 receives current detection values ​​I1 and I2 of the own system and the other system and driver abnormality information E1 and E2 from the driver component 811 via MISO_1.

[0203] The microcomputer 202 transmits, via MOSI_2, duty command values ​​Du2 and Du1 of the own system and the other system to the driver component 812. Furthermore, via MISO_2, the microcomputer 202 receives, via MISO_2, current detection values ​​I2 and I1 of the own system and driver abnormality information E2 and E1 from the driver component 812. When the microcomputers 201 and 202 of the own system are normal, the driver components 811 and 812 control the driver circuits 51 and 53 using the duty command values ​​Du1 and Du2 transmitted from the microcomputers 201 and 202 of the own system, thereby controlling the energization of the motor windings 121 and 123.

[0204] 70 and 71, information on the own system and the other system is transmitted and received through communication between the microcomputer and the driver regardless of the state of the microcomputers 201 and 202, but if the microcomputer on the other system side is normal, it is not necessary to transmit and receive information on the other system. Also, the duty command value sent to the other system side through communication between the drivers may be calculated from the duty command value of the own system by the driver components 811 and 812 (see equation (1)). "D" in the equation * "D" is the duty command value of the own system, * "Other" is a duty command value for the other system, and K is an offset value according to the phase difference of the motor windings.

[0205] D * Others=D * Self+K...(1)

[0206] A case where one of the microcomputers (here, microcomputer 202) is abnormal will be described with reference to Fig. 72. When the microcomputer 202 is abnormal, communication between microcomputers and communication between the microcomputer 202 and the driver component 812 is not possible. In Fig. 72, the parts that cannot be sent or received due to an abnormality in the microcomputer 202 are indicated by dashed lines. Here, only the parts that are characteristic of an abnormal state will be described, and explanations of parts that are common to normal states will be omitted as appropriate.

[0207] If the microcomputer 202 is abnormal, the driver component 812 transmits the current detection value I2 and abnormality information E2 of its own system to the driver component 811 via MISO_d. The driver component 811 transmits the current detection value I2 and driver abnormality information E2 of the second control system to the microcomputer 201 via MISO_1, in addition to its own current detection value I1 and driver abnormality information E1.

[0208] The microcomputer 201 calculates a duty command value Du2 based on the current detection value I2 on the second control system side. Note that the duty command values ​​Du1 and Du2 may be calculated based on the current detection values ​​I1 and I2, for example, by sum and difference control. The same applies in normal operation. The duty command value Du2 calculated by the microcomputer 201 is transmitted to the driver component 801 via MOSI_1. The driver component 801 transmits the duty command value Du2 to the driver component 802 via MOSI. The driver component 802 controls the driver circuit 53 using the duty command value Du2 received from the first control system side, thereby controlling the energization of the motor windings 123.

[0209] If the microcomputer 201 malfunctions, the duty command value Du2 calculated by the microcomputer 202 is sent to the driver component 811 via microcomputer-driver communication, and is then sent from the driver component 811 to the driver component 812 via driver-driver communication. This allows the motor to continue to be driven by two systems even if one of the microcomputers 201 and 202 malfunctions.

[0210] If the driver component 811 becomes abnormal, the output of the motor drive signal to the driver circuit 51 is stopped, and one-system drive is performed on the second system side. If the driver component 812 becomes abnormal, the output of the motor drive signal to the driver circuit 53 is stopped, and one-system drive is performed on the first system side. The command to stop the motor drive signal may be output from any of the microcomputers in the own system, the driver in the other system, or the microcomputer in the other system that has acquired information related to the driver abnormality. As a configuration for stopping the motor drive signal, for example, a relay may be provided in the output section of the pre-driver ICs 61 and 63 to block the signal, or the pre-driver ICs 61 and 63 may have a function inside that allows the output to be stopped externally.

[0211] The microcomputer-driver communication process of this embodiment is shown in the flowchart of Figure 73. Figure 71 is similar to Figure 60 except that S307 is omitted. That is, in this embodiment, an inter-system connection line 253 is provided between the drivers, and the microcomputer 201 acquires information about the driver component 812, which is a driver of another system, via the driver component 811, which is a driver of its own system, and therefore does not directly send or receive information to or from the driver component 812.

[0212] The driver-to-driver communication process is shown in the flowchart of Fig. 74. The communication frequency of driver-to-driver communication is higher than the communication frequency of microcomputer-to-driver communication. Here, the process of the driver component 811 will be described, but the same process is also performed in the driver component 812.

[0213] In S351, the driver component 811 determines whether both the driver component 811 and the driver component 812 are normal. If it is determined that both the driver component 811 and the driver component 812 are normal (S351: YES), the process proceeds to S352, where driver-to-driver communication is performed. If it is determined that at least one of the driver component 811 and the driver component 812 is abnormal (S351: NO), the process proceeds to S353.

[0214] In S353, the driver component 811 determines whether the driver component 811 is abnormal and whether the driver component 812 is normal. If it is determined that the driver component 811 is abnormal and the driver component 812 is normal (S353: YES), the process proceeds to S354, where the driver component 811 is stopped. If it is determined that the driver component 811 is abnormal and the driver component 812 is not normal (S353: NO), the process proceeds to S355.

[0215] In S355, the driver component 811 determines whether the driver component 811 is normal and whether the driver component 812 is abnormal. If it is determined that the driver component 811 is normal and the driver component 812 is abnormal (S355: YES), the process proceeds to S356, where the driver component 812 is stopped. If both the driver components 811 and 812 are abnormal (S355: NO), the process proceeds to S366, where the driver components 811 and 812 are stopped.

[0216] The communication processing of this embodiment will be described based on the time charts of Figures 75 and 76. In Figures 75 and 76, the upper part of the page shows communication between the microcomputer 201 and the driver component 811, the middle part shows communication between the microcomputer 202 and the driver component 812, and the lower part shows communication between the driver components 811 and 812. The same applies to Figure 80, which will be described later.

[0217] As shown in Figure 75, when both the microcomputers 201 and 202 are normal, communication between the microcomputer 201 and the driver component 811, communication between the microcomputer 202 and the driver component 812, and communication between the driver components 811 and 812 are carried out in parallel. In Figure 75, the frequency of communication between the drivers is three times that of communication between the microcomputer and the driver, but the communication frequency can be set arbitrarily.

[0218] 76 , when the microcomputer 202 is abnormal, communication between the microcomputer 202 and the driver component 812 does not occur. Communication between the microcomputer 202 and the driver component 811 and communication between the driver components 811 and 812 are the same as in normal operation. The microcomputer 201 transmits duty command values ​​Du1 and Du2 of its own system and the other system to the driver component 811, and receives current detection values ​​I1 and I2 of its own system and the other system and driver abnormality information E1 and E2 from the driver component 811.

[0219] In this embodiment, the inter-system connection line 253 for driver-to-driver communication is provided independently of the intra-system communication lines C1 and C2, so that communication between the microcomputer and the driver in each control system and communication between the drivers can be executed in parallel. This increases the speed of communication and improves the simultaneity of data transfer between drivers.

[0220] The inter-system connection line 253 connects the driver components 811 and 812 of different control systems. The microcomputer 201 can transmit a duty command value Du2 to a driver component 812 of the other system via the driver component 811 of its own system, and can receive a current detection value I2, which is sensor data, and driver abnormality information E2 of the other system from the driver component 812 of the other system. The microcomputer 202 can transmit a duty command value Du1 to a driver component 811 of the other system via the driver component 812 of its own system, and can receive a current detection value I1, which is sensor data, and driver abnormality information E1 of the other system from the driver component 811 of the other system.

[0221] In this embodiment, information on the own system and the other system is continuously updated between the driver components 811 and 812. This allows the microcomputers 201 and 202 to appropriately communicate with the other system via the driver components 811 and 812 of the own system. This also provides the same effects as the above embodiment.

[0222] 77 to 80 show a 24th embodiment. As shown in Fig. 77, driver components 811 and 812 are provided with two sets of inter-system connection lines 253, each of which is provided with an isolator 283. One of the two sets of inter-system connection lines 253 is a communication line in which the driver component 811 is the master and the driver component 812 is the slave, and the other is a communication line in which the driver component 812 is the master and the driver component 811 is the slave.

[0223] In the 23rd embodiment, driver-to-driver communication is always performed. In contrast, in this embodiment, an other-system access command is issued from the microcomputer side, and when the other-system access command is received by the driver component side, communication between drivers is performed. Below, an example will be described in which the driver component 811 is the master and the driver component 812 is the slave. The microcomputer 201 is configured to be able to send two commands to the driver component 811: a command to read and write (hereinafter referred to as "R / W") only to its own system, and a command to perform R / W of its own system and the other system. The command to perform R / W of its own system and the other system corresponds to the "other-system access command."

[0224] The data flow of this embodiment will be described with reference to Fig. 78. When the driver component 811 receives R / W commands for its own system and another system from the microcomputer 201, during period [1], the microcomputer 201 transmits a duty command value Du2 for the other system to the driver component 811 through microcomputer-driver communication, and the driver component 811 transmits a current detection value I1 for its own system to the microcomputer 201.

[0225] In period [2], the microcomputer 201 transmits a duty command value Du1 of its own system to the driver component 811 through microcomputer-driver communication, and the driver component 811 transmits driver abnormality information E1 of its own system to the microcomputer 201. Furthermore, while the driver component 811 is returning data of its own system to the microcomputer 201, it also performs inter-driver communication in parallel. Specifically, through inter-driver communication, the driver component 811 transmits a duty command value Du2 to the driver component 812, and the driver component 812 transmits a current detection value I2 to the driver component 811. Furthermore, following the current detection value I2, the driver component 812 transmits driver abnormality information E2 of the second control system to the driver component 811.

[0226] The driver component 811 transmits the current detection value I2 of the other system to the microcontroller 201 during the period [3] after completion of reception of the current detection value I2, and transmits the abnormal state of the other system to the microcontroller 201 during the period [4] after completion of reception of the driver abnormality information E2 of the second control system.

[0227] The microcomputer-driver communication process of this embodiment will be described with reference to the flowchart of Figure 79. The processes of S301 to S305 and S308 are the same as those of Figure 73. In S320, which is performed when both microcomputers 201 and 202 are normal (S301: YES and S302: YES), the microcomputer 201 sends a command to the driver component 811 to perform R / W on its own system only. The process of S321 is the same as S303, in which the microcomputer 201 communicates with the driver component 811. At the same time, on the side of the second control system, which is the other system, the microcomputer 202 communicates with the driver component 812. Note that even if both microcomputers 201 and 202 are normal, if communication is to be performed with the other system, the process may be configured to proceed to S322 after a positive determination is made in S302.

[0228] In S322, which is performed after the other-system microcomputer 202 has an abnormality and has stopped, the microcomputer 201 transmits R / W commands for its own system and the other system to the driver component 811.

[0229] In S323, the microcomputer 201 performs microcomputer-driver communication with the driver component 811. At this time, the driver components 811 and 812 perform driver-to-driver communication, and the microcomputer 201 transmits and receives the duty command value Du2, the current detection value I2, and the driver abnormality information E2 via the driver component 811.

[0230] The communication processing of this embodiment will be described based on the time chart in Fig. 80. The left side of Fig. 80 shows a case where a driver component 811 is the master in inter-driver communication, and the right side of the page shows a case where a driver component 812 is the master in inter-driver communication. Here, the explanation will focus on information communication on the other system side, and an explanation of information communication within the system will be omitted.

[0231] As shown on the left side of the drawing, when the driver component 811 is used as the master, the microcomputer 201 transmits R / W commands for the own system and the other system, and a duty command value Du2 for the other system to the driver component 811. After recognizing the commands, the driver component 811 performs driver-to-driver communication, transmits the duty command value Du2 to the driver component 812, and receives the current detection value I2 and driver abnormality information E2 for the other system from the driver component 812. The driver component 811 also transmits the current detection value I2 and driver abnormality information E2 received from the driver component 812 to the microcomputer 201.

[0232] As shown on the right side of the page, when the driver component 812 is used as the master, the microcomputer 202 transmits R / W commands for the local system and the other system, and a duty command value Du1 for the other system, to the driver component 812. After recognizing the commands, the driver component 812 performs inter-driver communication, transmits the duty command value Du1 to the driver component 811, and receives the current detection value I1 and driver abnormality information E1 for the other system from the driver component 811. The driver component 812 also transmits the current detection value I1 and driver abnormality information E1 received from the driver component 811 to the microcomputer 202. This allows the motors to continue to be driven by the two systems even if an abnormality occurs in one of the microcomputers 201, 202.

[0233] In this embodiment, the driver components 811 and 812 communicate with the driver components 812 and 811 of the other system in response to commands from the microcomputers 201 and 202 of their own system. Even with this configuration, communication between the systems can be performed appropriately. In addition, the same effects as those of the above embodiment can be achieved.

[0234] In the embodiment, the motor 11 corresponds to the "load," the ECU 15 corresponds to the "communication device," the motor winding 121 corresponds to the "first winding set," the motor winding 122 corresponds to the "second winding set," the motor winding 123 corresponds to the "third winding set," the motor winding 124 corresponds to the "fourth winding set," the microcomputers 21 to 24 correspond to the "controller," the driver components 701 to 704, 801 to 804, 811, and 812, the power supply ICs 31 and 33, the communication units 36 and 38, and the position sensors 66 to 69 correspond to the "electronic components," and the isolators 28 and 281 to 283 correspond to the "system separation components." Also, the arithmetic cores 211, 212, 231, and 233 correspond to the "arithmetic circuit," the arithmetic core 211 corresponds to the "first arithmetic circuit," the arithmetic core 212 corresponds to the "second arithmetic circuit," the arithmetic core 231 corresponds to the "third arithmetic circuit," and the arithmetic core 232 corresponds to the "fourth arithmetic circuit." Moreover, the duty command values ​​Du1 and Du2 correspond to "drive commands," and the current detection values ​​I1 and I2 correspond to "sensor data."

[0235] (Other Embodiments) In the above embodiment, examples have been described in which there are two to four power supply systems and two to four control systems. In other embodiments, the numbers of power supply ICs, microcomputers, arithmetic cores, pre-driver ICs, driver circuits, motor windings, etc. can be set arbitrarily depending on the required redundancy, mounting space, etc. Furthermore, the number of components may be different, such as four for fragile components (for example, microcomputers and driver circuits) and three for other components.

[0236] In the above embodiment, the electronic components are mainly driver components with built-in pre-driver ICs. In other embodiments, the electronic components may be, for example, pre-driver ICs or sensors that are provided separately from the driver circuits as long as they are capable of digital communication with the microcomputer. In addition, in the above embodiment, the electronic components of each system are described as being the same. In other embodiments, the electronic components of each system may have different outputs, accuracies, etc.

[0237] In the above embodiment, a duty command value, a current detection value, and driver abnormality information are transmitted and received via microcomputer-driver communication or driver-driver communication. In other embodiments, the duty command value, current detection value, and driver abnormality information may be partially omitted from the information transmitted and received via microcomputer-driver communication or driver-driver communication, or other information may be included. In the above embodiment, a duty command value is used as the drive command. In other embodiments, a value other than the duty command value may be used as the drive command. Furthermore, in the above embodiment, a current detection value is shared as sensor data via microcomputer-driver communication or driver-driver communication. In other embodiments, the sensor data is not limited to a current detection value, and may be, for example, a rotation angle detection value.

[0238] In the above embodiment, the control target of the ECU is a motor. In other embodiments, the control target may be an actuator or other device other than a motor. In the above embodiment, the communication device is applied to an electric power steering device. In other embodiments, the communication device may be applied to an in-vehicle device other than an electric power steering device, or may be applied to a device other than an in-vehicle device.

[0239] (Disclosure of Technical Ideas) This specification discloses multiple technical ideas described in the following multiple clauses. Some clauses may be described in a multiple dependent form, with the subsequent clause alternatively referring to the preceding clause. Furthermore, some clauses may be described in a multiple dependent form, with the subsequent clause referring to another multiple dependent clause. These multiple dependent clauses define multiple technical ideas.

[0240] (Technical Idea 1) A communication device comprising: a plurality of control units (21-24) each having at least one arithmetic circuit (211, 212, 231, 232); and a plurality of electronic components (31, 33, 36, 38, 66-69, 701-707, 73, 801-804, 811, 812) provided corresponding to the control units and connected to the control units so as to be able to digitally communicate with the control units, wherein, assuming that a combination of the control units and the electronic components provided correspondingly is a control system, and a communication line connecting the corresponding control units and the electronic components is an intra-system communication line, the intra-system communication lines of different control systems, the intra-system communication lines and the electronic components of other control systems, or the electronic components of different control systems are connected by inter-system connection lines (25, 251-253, 256-258). (Technical Idea 2) The electronic component is a driver component (701-707, 73, 801-804, 811, 812) having a pre-driver IC (61-64) that transmits a drive signal to a driver circuit (51-54) related to driving a load (11), wherein the arithmetic circuit digitally transmits a drive command for the driver circuit to the pre-driver IC, and the pre-driver IC transmits drive information including at least one of a current detection value, temperature information, and abnormality information to the arithmetic circuit. (Technical Idea 3) The communication device according to Technical Idea 2, wherein the arithmetic circuit calculates and outputs the drive commands for some of the driver circuits, acquires the drive information from the pre-driver IC that has output the drive command, and acquires the drive information from the pre-driver IC that corresponds to a driver circuit that has not itself output the drive command. (Technical Idea 4) The communication device according to Technical Idea 2 or 3, wherein the arithmetic circuit transmits the drive command at a timing when the arithmetic circuit of another of the control systems connected by the system-to-system connection line is not outputting the drive command. (Technical Idea 5) The communication device according to Technical Idea 2, wherein the plurality of driver components hold detection values ​​at the same timing in response to a command from the control unit, and transmit the detection values ​​to the control unit in sequence. (Technical Idea 6) The communication device according to Technical Idea 2, wherein the plurality of arithmetic circuits transmit the drive command to the pre-driver IC in turn every calculation cycle.(Technical Idea 7) The communication device according to Technical Idea 6, wherein, when an abnormality occurs in one of the arithmetic circuits among the plurality of arithmetic circuits that transmit the drive command to the same pre-driver IC, a normal arithmetic circuit takes over the transmission of the drive command. (Technical Idea 8) The communication device according to Technical Idea 2, wherein the load is a motor having four sets of motor windings (121-124), which are wound around a stator so as to be adjacent to each other in the order of a first winding set (121), a second winding set (122), a third winding set (123), and a fourth winding set (124), wherein a first driver circuit (51) provided corresponding to the first winding set and a third driver circuit (53) provided corresponding to the third winding set are driven by the drive command of the same phase, and a second driver circuit (52) provided corresponding to the second winding set and a fourth driver circuit (54) provided corresponding to the fourth winding set are driven by the drive command of the same phase but different in phase from the first driver circuit and the third driver circuit. (Technical Idea 9) A communication device according to Technical Idea 8, wherein the intra-system communication line connecting a first pre-driver IC (61) provided corresponding to the first driver circuit and a first arithmetic circuit (211), and the intra-system communication line connecting a third pre-driver IC (63) provided corresponding to the third driver circuit and a third arithmetic circuit (231) are connected by a first inter-system connecting line (25A), and the intra-system communication line connecting a second pre-driver IC (62) provided corresponding to the second driver circuit and a second arithmetic circuit (212) and the intra-system communication line connecting a fourth pre-driver IC (64) provided corresponding to the fourth driver circuit and a fourth arithmetic circuit (232) are connected by a second inter-system connecting line (25B) different from the first inter-system connecting line. (Technical Idea 10) The communication device according to any one of Technical Ideas 1 to 9, wherein the control unit has a plurality of the arithmetic circuits, and the intra-system communication line is assigned to each of the arithmetic circuits. (Technical Idea 11) The communication device according to any one of Technical Ideas 1 to 10, wherein the inter-system connection line connects the control systems via system separation components (28, 281 to 283) that enable information transmission while maintaining a potential difference.(Technical Idea 12) The communication device according to Technical Idea 11, wherein the system separation component is capable of receiving an enable signal from the control unit, and when the enable signal is in an enabling state, communication between the systems is permitted, and when the enable signal is in a disabling state, communication between the systems is prohibited. (Technical Idea 13) The communication device according to Technical Idea 11 or 12, wherein the control unit communicates with the electronic component of its own system when the control unit of the other system is normal, and communicates with the electronic component of its own system and the electronic component of the other system when the control unit of the other system is abnormal. (Technical Idea 14) The communication device according to any one of Technical Ideas 11 to 13, wherein the inter-system connection line connects the intra-system communication line to the electronic component of the other control system, or between the electronic components of different control systems, and the system separation component is built into the electronic component. (Technical Idea 15) The communication device according to any one of Technical Ideas 11 to 14, wherein the inter-system connection line connects the intra-system communication line to the electronic component of the other control system, and wherein the communication port of the electronic component to which the inter-system connection line is connected is provided separately from the port to which the intra-system communication line is connected. (Technical Idea 16) The communication device according to any one of Technical Ideas 11 to 14, wherein the inter-system connection line connects the electronic components of different control systems, and wherein the control unit is capable of sending drive commands to the electronic component of the other system via the electronic component of its own system and receiving sensor data and abnormality information of the control system from the electronic component of the other system. (Technical Idea 17) The communication device according to Technical Idea 16, wherein information of its own system and the other system is continuously updated between the electronic components. (Technical Idea 18) The communication device according to Technical Idea 16, wherein the electronic component communicates with the electronic component of the other system in response to a command from the control unit of its own system.

[0241] The control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to execute one or more functions embodied in a computer program. Alternatively, the control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit and the method described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to execute one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by a computer. As described above, the present disclosure is not limited to the above embodiments and can be implemented in various forms without departing from the spirit of the present disclosure.

[0242] The present disclosure has been described based on the embodiments. However, the present disclosure is not limited to the embodiments and structures. The present disclosure also encompasses various modifications and variations within the scope of equivalents. Furthermore, various combinations and forms, as well as other combinations and forms including only one element, more than one element, or less than one element, are also within the scope and spirit of the present disclosure.

Claims

1. A communications device comprising: a plurality of control units (21-24) each having at least one arithmetic circuit (211, 212, 231, 232); and a plurality of electronic components (31, 33, 36, 38, 66-69, 701-707, 73, 801-804, 811, 812) provided corresponding to the control units and connected to the control units so as to be able to digitally communicate with the control units, wherein a combination of the corresponding control units and the electronic components is defined as a control system, and a communication line connecting the corresponding control units and the electronic components is defined as an intra-system communication line, wherein the intra-system communication lines between different control systems, the intra-system communication lines between the electronic components of other control systems, or the electronic components of different control systems are connected by inter-system connection lines (25, 251-253, 256-258).

2. The communication device according to claim 1, wherein the electronic component is a driver component (701-707, 73, 801-804, 811, 812) having a pre-driver IC (61-64) that transmits a drive signal to a driver circuit (51-54) related to driving a load (11), the arithmetic circuit digitally transmits a drive command for the driver circuit to the pre-driver IC, and the pre-driver IC transmits drive information including at least one of a current detection value, temperature information, and abnormality information to the arithmetic circuit.

3. The communication device according to claim 2, wherein the arithmetic circuit calculates and outputs the drive commands for some of the driver circuits, acquires the drive information from the pre-driver IC that has output the drive command, and acquires the drive information from the pre-driver IC corresponding to the driver circuit that has not output the drive command itself.

4. A communication device as described in claim 2 or 3, wherein the arithmetic circuit transmits the drive command at a timing when the arithmetic circuit of the other control system connected by the system-to-system connection line is not outputting the drive command.

5. A communication device according to claim 2, wherein the plurality of driver components hold detection values ​​at the same timing in response to a command from the control section, and transmit the detection values ​​to the control section in sequence.

6. The communication device according to claim 2, wherein the plurality of arithmetic circuits transmit the drive command to the pre-driver IC in turn every calculation period.

7. The communication device according to claim 6, wherein, when an abnormality occurs in one of the plurality of arithmetic circuits which transmit the drive command to the same pre-driver IC, a normal arithmetic circuit takes over the transmission of the drive command.

8. The communication device according to claim 2, wherein the load is a motor having four sets of motor windings (121-124), wound around the stator so that the first winding set (121), the second winding set (122), the third winding set (123), and the fourth winding set (124) are adjacent to each other in this order, a first driver circuit (51) provided corresponding to the first winding set and a third driver circuit (53) provided corresponding to the third winding set are driven by the drive command of the same phase, and a second driver circuit (52) provided corresponding to the second winding set and a fourth driver circuit (54) provided corresponding to the fourth winding set are driven by the drive command of the same phase but different from the phase of the first driver circuit and the third driver circuit.

9. A communication device according to claim 8, wherein the intra-system communication line connecting a first pre-driver IC (61) provided corresponding to the first driver circuit and a first arithmetic circuit (211), and the intra-system communication line connecting a third pre-driver IC (63) provided corresponding to the third driver circuit and a third arithmetic circuit (231) are connected by a first inter-system connection line (25A), and the intra-system communication line connecting a second pre-driver IC (62) provided corresponding to the second driver circuit and a second arithmetic circuit (212), and the intra-system communication line connecting a fourth pre-driver IC (64) provided corresponding to the fourth driver circuit and a fourth arithmetic circuit (232) are connected by a second inter-system connection line (25B) different from the first inter-system connection line.

10. The communication device according to claim 1, wherein the control unit has a plurality of the arithmetic circuits, and the intra-system communication line is assigned to each of the arithmetic circuits.

11. A communication device according to claim 1, wherein the inter-system connection lines connect the control systems via system separation components (28, 281 to 283) that enable information transmission while maintaining a potential difference.

12. The communication device according to claim 11, wherein the system separation component is capable of receiving an enable signal from the control unit, and when the enable signal is in an enabling state, communication between the systems is permitted, and when the enable signal is in a disabling state, communication between the systems is prohibited.

13. A communication device as described in claim 11 or 12, wherein the control unit communicates with the electronic component of the own system when the control unit of the other system is normal, and communicates with the electronic component of the own system and the electronic component of the other system when the control unit of the other system is abnormal.

14. A communication device as described in claim 11 or 12, wherein the inter-system connection line connects the intra-system communication line to an electronic component of another control system, or between electronic components of different control systems, and the system separation component is built into the electronic component.

15. A communication device as described in claim 11 or 12, wherein the inter-system connection line connects the intra-system communication line to the electronic component of the other control system, and in the electronic component, a communication port to which the inter-system connection line is connected is provided separately from a port to which the intra-system communication line is connected.

16. A communication device as described in claim 11 or 12, wherein the inter-system connection line connects the electronic components of different control systems, and the control unit is capable of transmitting drive commands to the electronic components of the other system via the electronic components of its own system, and is capable of receiving sensor data and abnormality information of the control system from the electronic components of the other system.

17. The communication device according to claim 16, wherein information on the own system and the other system is continuously updated between the electronic components.

18. The communication device according to claim 16, wherein the electronic component communicates with the electronic component of another system in response to a command from the control unit of the own system.

Citation Information

Patent Citations

  • Dynamo-electric machine control arrangement

    JP2019201500A

  • Electronic controller and power supply system

    JP2021097487A

  • Motor controller

    JP2021136735A