Inspection device and inspection system
The inspection device and system improve connection testing efficiency in electronic control systems by using power supply switching units and verification information to perform connection inspections without dedicated equipment, enhancing accuracy and speed.
Patent Information
- Application Number
- PCT/JP2025/006682
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-26
- Filing Date
- 2025-02-26
- Publication Date
- 2025-09-04
AI Technical Summary
The inefficiency of connection testing in electronic control systems due to the need for dedicated equipment, which hampers the overall efficiency of the process.
An inspection device and system that utilize a determination unit, continuity control unit, information acquisition unit, and storage unit to perform connection inspections without dedicated equipment, using power supply switching units to switch between conductive and cut-off states, and acquire verification information for connection verification.
Enhances the efficiency of connection inspection by allowing connection tests to be performed without dedicated equipment, improving the accuracy and speed of the testing process.
Smart Images

Figure JP2025006682_04092025_PF_FP_ABST
Abstract
Description
Inspection equipment and inspection system CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This international application claims the benefit of Japanese Patent Application No. 2024-026697, filed with the Japan Patent Office on February 26, 2024, the entire disclosure of which is incorporated herein by reference.
[0002] The present disclosure relates to an inspection device and an inspection system that perform connection inspections.
[0003] Patent document 1 describes a connector having a female connector and a male connector, in which a connection test is performed on the male connector by inserting a connection test pin into a through hole in the male connector housing when the female connector housing and the male connector housing are in a partially engaged state.
[0004] 2. Description of the Related Art Conventionally, in the manufacturing process of an electronic control system, a connection test to check whether a predetermined device is connected to an electronic control device is carried out using a dedicated device.
[0005] Japanese Patent Application Laid-Open No. 2006-73329
[0006] As a result of detailed investigation by the inventors, it was found that the need to use dedicated equipment for connection testing is a problem that causes a decrease in the efficiency of connection testing work.
[0007] The present disclosure improves the efficiency of connection inspection work.
[0008] One aspect of the present disclosure is an inspection device including a determination unit, a continuity control unit, an information acquisition unit, a storage unit, and a connection inspection unit.
[0009] The determination unit is configured to determine whether to place each of one or more power supply switching units, which are configured to switch between a conductive state that turns on each of one or more power supply paths that supply power from a power source to one or more connected loads, and a cut-off state that cuts off the power supply path, into a conductive state or a cut-off state.
[0010] The conduction control unit is configured to individually set each of the one or more power supply switching units to a conductive state or a cut-off state in accordance with the decision made by the decision unit.
[0011] The information acquisition unit is configured to acquire, for each of the one or more power supply switching units, first verification information for connection verification that verifies whether a connected load is connected to the power supply switching unit after the power supply switching unit becomes conductive.
[0012] The storage unit stores second verification information for connection verification.
[0013] The connection test unit is configured to perform a connection test for each of the one or more power supply switching units to determine whether one or more connected loads are connected to the power supply switching unit by comparing the first verification information with the second verification information.
[0014] The inspection device of the present disclosure configured in this manner can perform connection inspection without using dedicated equipment, thereby improving the efficiency of connection inspection work.
[0015] Another aspect of the present disclosure is a test system including one or more power supply switching units and a test device configured to control the operation of the one or more power supply switching units, wherein the test device includes a determination unit, a continuity control unit, an information acquisition unit, and a connection test unit.
[0016] The inspection system of the present disclosure configured in this manner is a system equipped with the inspection device of the present disclosure, and can obtain the same effects as the inspection device of the present disclosure.
[0017] 1 is a block diagram showing the configuration of a vehicle control system of a first embodiment. FIG. 2 is a diagram showing the configuration of a connection inspection table of the first embodiment. FIG. 3 is a flowchart showing the connection inspection process of the first embodiment. FIG. 4 is a block diagram showing the configuration of a vehicle control system of a second embodiment. FIG. 5 is a diagram showing the configuration of a connection inspection table of the second embodiment. FIG. 6 is a flowchart showing the connection inspection process of the second embodiment. FIG. 7 is a block diagram showing the configuration of a vehicle control system of a third embodiment. FIG. 8 is a diagram showing the configuration of a communication connection inspection table of the third embodiment. FIG. 9 is a flowchart showing the communication connection inspection process of the third embodiment. FIG. 10 is a block diagram showing the configuration of a vehicle control system of a fourth embodiment. FIG. 11 is a diagram showing the configuration of a connection inspection table of the fourth embodiment. FIG. 12 is a flowchart showing the connection inspection process of the fourth embodiment. FIG. 13 is a diagram showing the configuration of a connection inspection table of the fifth embodiment. FIG. 14 is a flowchart showing the connection inspection process of the fifth embodiment. FIG. 15 is a block diagram showing the configuration of a vehicle control system of a sixth embodiment. FIG. 16 is an explanatory diagram illustrating affiliation information and startup information. FIG. 17 is a diagram showing the correspondence relationship between control objects and clusters. FIG. 18 is a block diagram showing the configuration of a vehicle control system of a seventh embodiment. FIG. 19 is a block diagram showing the configuration of a central ECU and an upstream power distribution unit of the seventh embodiment. FIG. 20 is a first block diagram showing the configuration of a zone ECU of the seventh embodiment. FIG. 21 is a second block diagram showing the configuration of a zone ECU of the seventh embodiment. FIG. 22 is a block diagram showing the configuration of a slave ECU of the seventh embodiment. FIG. 23 is a diagram showing the configuration of a startup table of the seventh embodiment. 13 is a flowchart showing a connection inspection process of the seventh embodiment. FIG. 14 is a diagram showing the configuration of a start-up table of the eighth embodiment. FIG. 15 is a first block diagram showing the configuration of a zone ECU of the eighth embodiment. FIG. 16 is a second block diagram showing the configuration of a zone ECU of the eighth embodiment. FIG. 17 is a diagram showing the configuration of a connection inspection table of the eighth embodiment. FIG. 18 is a flowchart showing a connection inspection process of the eighth embodiment. FIG. 19 is a block diagram showing the configuration of a vehicle control system of the ninth embodiment. FIG. 20 is a diagram showing the configuration of a communication connection inspection table of the ninth embodiment. FIG. 21 is a flowchart showing a communication connection inspection process of the ninth embodiment.
[0018] First Embodiment A first embodiment of the present disclosure will be described below with reference to the drawings.
[0019] A vehicle control system 1 of this embodiment is mounted on a vehicle, and as shown in Fig. 1, includes a master ECU 2, slave ECUs 3, 4, and 5, and a battery 7. ECU is an abbreviation for Electronic Control Unit.
[0020] The master ECU 2 and the slave ECUs 3, 4, and 5 are connected to each other via a communication bus 8 so as to be able to communicate data with each other.
[0021] The battery 7 supplies power to each part of the vehicle at a DC battery voltage (for example, 12 V). The master ECU 2 and the slave ECUs 3 to 5 operate by receiving power from the battery 7.
[0022] The master ECU 2 includes a control unit 11, a CAN communication unit 12, a storage unit 13, electronic fuses 14 and 15, and a current detection unit 16. CAN is an abbreviation for Controller Area Network and is a registered trademark.
[0023] The control unit 11 is an electronic control device mainly composed of a microcomputer including a CPU 21, a ROM 22, a RAM 23, etc. The various functions of the microcomputer are realized by the CPU 21 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 22 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 21 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 11 may be one or more.
[0024] The CAN communication unit 12 communicates with the slave ECUs 3, 4, and 5 connected to the communication bus 8 by transmitting and receiving communication frames based on the CAN communication protocol.
[0025] The storage unit 13 is a storage device for storing various data, and stores a connection inspection table 25, which will be described later.
[0026] The electronic fuse 14 is disposed on the power supply path 9 between the battery 7 and the slave ECU 3. The electronic fuse 15 is disposed on the power supply path 10 between the battery 7 and the slave ECU 4.
[0027] The electronic fuses 14 and 15 each include a switching element (e.g., a MOSFET) and a control circuit. The control circuit of the electronic fuses 14 and 15 is configured to switch the switching element from an on state to an off state to cut off the power supply paths 9 and 10 when the current flowing through the power supply paths 9 and 10 exceeds a preset overcurrent determination value.
[0028] The control circuits of the electronic fuses 14 and 15 are configured to turn on or off the switching elements in accordance with commands from the control unit 11, thereby making the power supply paths 9 and 10 conductive or cut off.
[0029] The control circuits of the electronic fuses 14 and 15 are configured to measure the current values flowing through the electronic fuses 14 and 15 (i.e., the current values flowing through the power supply paths 9 and 10), respectively, and output current value information indicating the measured current values to the master ECU 2. The current values indicated by the current value information output by the electronic fuses 14 and 15 correspond to the values of current consumed by the slave ECUs 3 and 4 (hereinafter referred to as current consumption values), respectively.
[0030] The current detection unit 16 is configured to detect the value of a current flowing through the power supply paths 9 and 10 and output power supply path current value information indicating the detected current value to the master ECU 2 .
[0031] Each of the slave ECUs 3 to 5 includes a control unit 31 , a CAN communication unit 32 , and a storage unit 33 .
[0032] The control unit 31 is an electronic control device mainly composed of a microcomputer including a CPU 41, a ROM 42, a RAM 43, etc. The various functions of the microcomputer are realized by the CPU 41 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 42 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 41 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 31 may be one or more.
[0033] The CAN communication units 32 of the slave ECUs 3 to 5 communicate with the communication devices connected to the communication bus 8 (that is, the master ECU 2 and the slave ECUs 3 to 5) based on the CAN communication protocol.
[0034] The storage unit 33 is a storage device for storing various data.
[0035] A vehicle fault diagnosis device 90 (so-called diagnostic tester) is connected to the master ECU 2. The fault diagnosis device 90 is installed at a vehicle dealer, a vehicle repair shop, or the like.
[0036] The fault diagnosis device 90 is configured to be detachable via a connector (not shown) and is connected to the master ECU 2 during fault diagnosis, etc. The fault diagnosis device 90 can obtain various information from the master ECU 2 and the slave ECUs 3, 4, and 5 via the master ECU 2, and can update the data stored in the master ECU 2 and the slave ECUs 3, 4, and 5.
[0037] 2, the connection inspection table 25 sets an electronic fuse ID, a connected load type, and an expected current consumption value (hereinafter, "expected current consumption value") for each of the multiple electronic fuses 14, 15 included in the vehicle control system 1. The connected load type is the type of load connected to the target electronic fuse. Examples of the connected load type include an ECU, a sensor, and an actuator.
[0038] In the connection inspection table 25 of this embodiment, the electronic fuse 14 is set to "eFuse_1" as the electronic fuse ID, "ECU" as the connected load type, and "500 mA" as the expected current consumption value. The electronic fuse 15 is set to "eFuse_2" as the electronic fuse ID, "ECU" as the connected load type, and "200 mA" as the expected current consumption value.
[0039] Next, a description will be given of the procedure of the connection check process executed by the control unit 11 of the master ECU 2. The connection check process is a process that is repeatedly executed while the master ECU 2 is running.
[0040] When the connection test process is executed, the CPU 21 of the control unit 11 determines whether the master ECU 2 is set to the connection test mode in S10, as shown in Fig. 3. When the control unit 11 of the master ECU 2 receives a connection test command from the fault diagnosis device 90, the control unit 11 sets the master ECU 2 to the connection test mode.
[0041] If the master ECU 2 is not set to the connection inspection mode, the CPU 21 proceeds to S100. On the other hand, if the master ECU 2 is set to the connection inspection mode, the CPU 21 sets the electronic fuse indication value i stored in the RAM 23 to 0 in S20.
[0042] In S30, the CPU 21 increments the electronic fuse indication value i (i.e., adds 1).
[0043] In S40, the CPU 21 turns on the i-th electronic fuse (that is, the electronic fuse for which "eFuse_i" is set as the electronic fuse ID).
[0044] In S50, the CPU 21 waits for a preset ON state waiting time.
[0045] In S60, the CPU 21 acquires current value information from the i-th electronic fuse.
[0046] In S70, the CPU 21 performs a connection test on the i-th electronic fuse. Specifically, if the current value indicated by the current value information acquired in S60 is equal to or greater than the connection determination value, the CPU 21 determines the connection as "connected," and if the current value indicated by the current value information acquired in S60 is less than the connection determination value, the CPU 21 determines the connection as "disconnected." The connection determination value is the expected current consumption value of the i-th electronic fuse multiplied by a preset connection test ratio. The connection test ratio is, for example, 0.1. For example, since the expected current consumption value of the first electronic fuse is 500 mA, the connection determination value for the first electronic fuse is 500 × 0.1 = 50 mA.
[0047] In S80, the CPU 21 stores the connection test result for the i-th electronic fuse (i.e., the result of the connection test in S70) in the storage unit 13.
[0048] In S90, the CPU 21 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (2 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 21 proceeds to S30.
[0049] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 21 proceeds to S100.
[0050] When the process proceeds to S100, the CPU 21 determines whether or not the master ECU 2 is connected to the fault diagnosis device 90. If the master ECU 2 is not connected to the fault diagnosis device 90, the CPU 21 ends the connection inspection process.
[0051] On the other hand, if the master ECU 2 is connected to the fault diagnosis device 90, the CPU 21 transmits, at S110, one or more connection test results stored in the memory unit 13 that have not been transmitted to the fault diagnosis device 90, to the fault diagnosis device 90, and terminates the connection test process.
[0052] The master ECU 2 configured in this manner is configured to individually turn on the electronic fuses 14 and 15. The electronic fuses 14 and 15 are configured to switch between a conductive state that turns on the power supply paths 9 and 10 and a cut-off state that cuts off the power supply paths 9 and 10.
[0053] The master ECU 2 is configured to acquire, from the electronic fuses 14, 15, current value information indicating the value of the current flowing through the power supply paths 9, 10 after the electronic fuses 14, 15 are brought into a conductive state.
[0054] The master ECU 2 is configured to perform a connection test for each of the electronic fuses 14, 15 to determine whether the slave ECUs 3, 4 are connected to the electronic fuses 14, 15 or not by comparing a current consumption value that is preset as the current value consumed by the slave ECUs 3, 4 that are connected to the electronic fuses 14, 15 and receive power from the battery 7 with a current value indicated by the current value information.
[0055] Such a master ECU 2 can perform a connection test to check whether the slave ECUs 3 and 4 are connected to the electronic fuses 14 and 15 without using any dedicated equipment, thereby improving the efficiency of the connection test.
[0056] The master ECU 2 is also configured to store the connection test results and transmit the stored connection test results to a fault diagnosis device 90 installed outside the master ECU 2. This allows the master ECU 2 to notify the operator who performs the connection test of the connection test results.
[0057] In the embodiment described above, the master ECU 2 corresponds to an inspection device and a master control device, the battery 7 corresponds to a power source, the slave ECUs 3 and 4 correspond to a connected load and a slave control device, the electronic fuses 14 and 15 correspond to a power supply switching unit, and the vehicle control system 1 corresponds to an inspection system.
[0058] Furthermore, S20 to S30 correspond to processing as a determination unit, S40 corresponds to processing as a continuity control unit, S60 and electronic fuses 14 and 15 correspond to processing as an information acquisition unit, S70 corresponds to processing as a connection inspection unit, S80 corresponds to processing as a connection inspection result storage unit, and S110 corresponds to processing as a connection inspection result transmission unit.
[0059] The current value information corresponds to first verification information, and the current consumption value corresponds to second verification information.
[0060] Second Embodiment A second embodiment of the present disclosure will be described below with reference to the drawings. In the second embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.
[0061] The vehicle control system 1 of the second embodiment differs from the first embodiment in that the configuration of the vehicle control system 1 and the connection inspection process are changed.
[0062] 4, the vehicle control system 1 of the second embodiment differs from the first embodiment in that the slave ECU 3, the slave ECU 5, and the sensor 50 are connected to the electronic fuse 14, and the actuator 60 is connected to the electronic fuse 15. The sensor 50 and the actuator 60 are mounted on the vehicle.
[0063] 5 , in the connection inspection table 25 of the second embodiment, for the electronic fuse 14, "eFuse_1" is set as the electronic fuse ID, "ECU" is set as the first connected load type, "ECU" is set as the second connected load type, and "sensor" is set as the third connected load type. Furthermore, in the connection inspection table 25 of the second embodiment, "500 mA" is set as the expected current consumption value of the first connected load, "200 mA" is set as the expected current consumption value of the second connected load, and "100 mA" is set as the expected current consumption value of the third connected load.
[0064] For the electronic fuse 15, "eFuse_2" is set as the electronic fuse ID, "actuator" is set as the connected load type, and "500 mA" is set as the expected current consumption value.
[0065] Next, a procedure of the connection inspection process of the second embodiment will be described. The connection inspection process of the second embodiment differs from the first embodiment in that the processes of S72, S82, and S112 are executed instead of S70, S80, and S110.
[0066] As shown in FIG. 6, after the process of S60 is completed, the CPU 21 performs a connection test on the i-th electronic fuse in S72.
[0067] Specifically, when one load is connected to the i-th electronic fuse, the CPU 21 determines that the load is "connected" if the current value indicated by the current value information acquired in S60 is equal to or greater than the connection judgment value, as in S70, and determines that the load is "disconnected" if the current value indicated by the current value information acquired in S60 is less than the connection judgment value.
[0068] Furthermore, when one load is connected to the i-th electronic fuse, the CPU 21 determines that the current value indicated by the current value information acquired in S60 is less than the assembly judgment value and greater than or equal to the connection judgment value, indicating "misassembly." "Misassembly" means that the load is connected to the i-th electronic fuse incorrectly. The assembly judgment value is the expected current consumption value of the i-th electronic fuse multiplied by a preset assembly inspection ratio. The assembly inspection ratio is, for example, 0.7. For example, since the expected current consumption value of the second electronic fuse is 500 mA, the assembly judgment value of the second electronic fuse is 500 x 0.75 = 350 mA.
[0069] Furthermore, when multiple loads are connected to the i-th electronic fuse, the CPU 21 determines that the load is "connected" if the sum of the expected current consumption values of the multiple connected loads connected to the i-th electronic fuse is equal to or greater than the connection judgment value, and determines that the load is "not connected" if the sum of the expected current consumption values of the multiple connected loads connected to the i-th electronic fuse is less than the connection judgment value. The connection judgment value when multiple loads are connected is the sum of the expected current consumption values of the multiple connected loads multiplied by a preset connection inspection ratio.
[0070] Furthermore, when multiple loads are connected to the i-th electronic fuse, the CPU 21 determines that the corresponding connected load is "disconnected" if the difference between the sum of the expected current consumption values of the multiple connected loads connected to the i-th electronic fuse and the current value indicated by the current value information acquired in S60 is close to the expected current consumption value of one connected load connected to the i-th electronic fuse. For example, the sum of the expected current consumption values of the three connected loads connected to the first electronic fuse (i.e., electronic fuse 14) is 500 + 200 + 100 = 800 mA. If the current value indicated by the current value information acquired in S60 is 600 mA, the difference between the sum of the expected current consumption values and the current value indicated by the acquired current value information is 200 mA. This 200 mA is close to the expected current consumption value of the second connected load (i.e., slave ECU 5). Therefore, the CPU 21 determines that the slave ECU 5 is "disconnected."
[0071] When the process of S72 is completed, the CPU 21 stores the connection test result (i.e., the result of the connection test in S72) for the i-th electronic fuse in the storage unit 13 in S82.
[0072] Also, in S100, if the master ECU 2 is connected to the fault diagnosis device 90, the CPU 21 in S112 transmits to the fault diagnosis device 90 one or more connection test results stored in the memory unit 13 that have not been transmitted to the fault diagnosis device 90, and terminates the connection test process.
[0073] The master ECU 2 of the present disclosure configured as described above is configured to identify connected loads that are not connected to the electronic fuse 14 when multiple connected loads (i.e., slave ECUs 3, 5 and sensor 50) are connected to the electronic fuse 14 by comparing the difference between the total of multiple current consumption values of each of the multiple connected loads and the current value indicated by the current value information with the multiple current consumption values. In this way, when multiple connected loads are connected to the electronic fuse 14, the master ECU 2 can identify connected loads that are not connected to the electronic fuse 14.
[0074] In the embodiment described above, the slave ECUs 3 and 5, the sensor 50, and the actuator 60 correspond to the connection load, S72 corresponds to the processing of the connection inspection unit, S82 corresponds to the processing of the connection inspection result storage unit, and S112 corresponds to the processing of the connection inspection result transmission unit.
[0075] Third Embodiment A third embodiment of the present disclosure will be described below with reference to the drawings. In the third embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.
[0076] The vehicle control system 1 of the third embodiment differs from the first embodiment in that the configuration of the vehicle control system 1 is changed and that a communication connection test process is executed instead of a connection test process.
[0077] As shown in FIG. 7, the vehicle control system 1 of the third embodiment differs from the first embodiment in that the storage unit 13 includes a communication connection inspection table 27 instead of the connection inspection table 25 .
[0078] As shown in FIG. 8, the communication connection inspection table 27 sets, for each of the electronic fuses 14 and 15 included in the vehicle control system 1, an electronic fuse ID and an ECU ID that identifies the ECU to which the fuse is connected.
[0079] In the communication connection inspection table 27 of this embodiment, the electronic fuse ID is set to "eFuse_1" and the ECU ID is set to "ECU_A" for the electronic fuse 14. The electronic fuse ID is set to "eFuse_2" and the ECU ID is set to "ECU_B" for the electronic fuse 15.
[0080] Next, a description will be given of the procedure of the communication connection test process executed by the control unit 11 of the master ECU 2. The communication connection test process is a process that is repeatedly executed while the master ECU 2 is running.
[0081] When the communication connection test process is executed, the CPU 21 of the control unit 11 determines whether the master ECU 2 is set to the communication connection test mode in S210, as shown in Fig. 9. When the control unit 11 of the master ECU 2 receives a communication connection test command from the fault diagnosis device 90, the control unit 11 sets the master ECU 2 to the communication connection test mode.
[0082] If the master ECU 2 is not set to the communication connection test mode, the CPU 21 proceeds to S310. On the other hand, if the master ECU 2 is set to the communication connection test mode, the CPU 21 sets the electronic fuse indication value i stored in the RAM 23 to 0 in S220.
[0083] In step S230, the CPU 21 increments the electronic fuse indication value i.
[0084] In step S240, the CPU 21 turns on the i-th electronic fuse.
[0085] In S250, the CPU 21 waits for a preset ON state waiting time.
[0086] In step S260, the CPU 21 transmits an ID request to the ECU connected to the i-th electronic fuse.
[0087] In step S270, the CPU 21 receives an ECU ID from the ECU connected to the i-th electronic fuse.
[0088] In S280, the CPU 21 performs a communication connection test on the i-th electronic fuse. Specifically, the CPU 21 determines whether the ECU ID received in S270 matches the ECU ID set for the i-th electronic fuse in the communication connection test table 27. If the ECU ID received in S270 does not match the ECU ID set for the i-th electronic fuse in the communication connection test table 27, the CPU 21 determines that the electronic fuse is "misassembled." If the ECU ID received in S270 matches the ECU ID set for the i-th electronic fuse in the communication connection test table 27, the CPU 21 determines that the electronic fuse is "correctly assembled."
[0089] In S290, the CPU 21 stores the communication connection test result for the i-th electronic fuse (i.e., the result of the communication connection test in S280) in the storage unit 13.
[0090] In S300, the CPU 21 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (2 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 21 proceeds to S230.
[0091] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 21 proceeds to S310.
[0092] In S310, the CPU 21 determines whether the master ECU 2 is connected to the fault diagnosis device 90. If the master ECU 2 is not connected to the fault diagnosis device 90, the CPU 21 ends the communication connection inspection process.
[0093] On the other hand, if the master ECU 2 is connected to the fault diagnosis device 90, the CPU 21 transmits, at S320, one or more communication connection test results stored in the memory unit 13 that have not been transmitted to the fault diagnosis device 90, to the fault diagnosis device 90, and terminates the communication connection test process.
[0094] The master ECU 2 configured in this manner is configured to individually turn on the electronic fuses 14 and 15. The electronic fuses 14 and 15 are configured to switch between a conductive state that turns on the power supply paths 9 and 10 and a cut-off state that cuts off the power supply paths 9 and 10.
[0095] The master ECU 2 is configured to transmit an ID request to the slave ECUs 3 and 4 connected to the electronic fuses 14 and 15 after the electronic fuses 14 and 15 are respectively brought into a conductive state.
[0096] The master ECU 2 is configured to receive ECU IDs for identifying the slave ECUs 3 and 4 from the slave ECUs 3 and 4 connected to the electronic fuses 14 and 15 after transmitting an ID request to each of the electronic fuses 14 and 15 .
[0097] The master ECU 2 is configured to perform a communication connection test for each of the electronic fuses 14, 15, in which if the ECU ID that identifies a legitimate connection device that has been preset as a device to be connected to the electronic fuses 14, 15 matches the received ECU ID, it determines that a legitimate connection device is connected to the electronic fuses 14, 15, and if they do not match, it determines that a legitimate connection device is not connected to the electronic fuses 14, 15.
[0098] Such a master ECU 2 can perform a communication connection test to check whether the slave ECUs 3 and 4 are connected to the electronic fuses 14 and 15 without using any dedicated equipment, thereby improving the efficiency of the connection test.
[0099] The master ECU 2 is also configured to store the communication connection test results and transmit the stored communication connection test results to a fault diagnosis device 90 installed outside the master ECU 2. This allows the master ECU 2 to notify the operator who performs the connection test of the communication connection test results.
[0100] In the embodiment described above, S220 to S230 correspond to processing as a determination unit, S240 corresponds to processing as a continuity control unit, S260 corresponds to processing as an identification information request unit, S270 corresponds to processing as an identification information receiving unit, and S280 corresponds to processing as a connection inspection unit.
[0101] In addition, the slave ECUs 3 and 4 correspond to connected loads, the ID request corresponds to an identification information request, the ECU ID received by the master ECU 2 corresponds to load identification information and first verification information, and the ECU ID set in the communication connection inspection table 27 corresponds to valid identification information and second verification information.
[0102] Moreover, S290 corresponds to the processing performed by the communication connection test result storage unit, and S320 corresponds to the processing performed by the communication connection test result transmission unit.
[0103] Fourth Embodiment A fourth embodiment of the present disclosure will be described below with reference to the drawings. In the fourth embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.
[0104] The vehicle control system 1 of the fourth embodiment differs from the first embodiment in that the configuration of the vehicle control system 1 and the connection inspection process are changed.
[0105] As shown in FIG. 10 , the vehicle control system 1 of the fourth embodiment differs from the first embodiment in that a voltage detection unit 17 is provided instead of the current detection unit 16 .
[0106] The voltage detection unit 17 is configured to detect the voltage value applied, for example, downstream of the electronic fuses 14, 15 in the power supply paths 9, 10 (i.e., between the electronic fuses 14, 15 and the slave ECUs 3, 4), and output power supply path voltage value information indicating the detected voltage value to the master ECU 2.
[0107] As shown in FIG. 11 , the connection inspection table 25 of the fourth embodiment sets an electronic fuse ID, a connected load type, and an expected power supply path voltage value (hereinafter, expected power supply path voltage value) for each of the multiple electronic fuses 14, 15 provided in the vehicle control system 1.
[0108] In the connection inspection table 25 of the fourth embodiment, for the electronic fuse 14, "eFuse_1" is set as the electronic fuse ID, "ECU" is set as the connected load type, and "12V" is set as the expected power supply path voltage value. For the electronic fuse 15, "eFuse_2" is set as the electronic fuse ID, "ECU" is set as the connected load type, and "12V" is set as the expected power supply path voltage value.
[0109] Next, a procedure of the connection inspection process of the fourth embodiment will be described. The connection inspection process of the fourth embodiment differs from the first embodiment in that the processes of S64 and S74 are executed instead of S60 and S70.
[0110] 12 , when the processing of S50 is completed, in S64 the CPU 21 acquires the power supply path voltage value information of the i-th electronic fuse from the voltage detection unit 17. Note that the power supply path voltage value information of the first electronic fuse is the power supply path voltage value information of the power supply path 9, and the power supply path voltage value information of the second electronic fuse is the power supply path voltage value information of the power supply path 10.
[0111] In S74, the CPU 21 performs a connection test on the i-th electronic fuse. Specifically, the CPU 21 determines that the i-th electronic fuse is connected when the voltage value indicated by the power supply path voltage value information acquired in S64 is equal to or greater than a voltage connection determination value. Alternatively, the CPU 21 determines that the i-th electronic fuse is not connected when the voltage value indicated by the power supply path voltage value information acquired in S64 is less than the voltage connection determination value. The voltage connection determination value is the expected power supply path voltage value of the i-th electronic fuse multiplied by a preset connection test ratio. Note that the power supply paths 9 and 10 are configured to have a voltage value near the expected power supply path voltage value downstream of the electronic fuses 14 and 15 (i.e., the location where the voltage detection unit 17 detects voltage) when the slave ECUs 3 and 4 are connected to the power supply paths 9 and 10, respectively. When the slave ECUs 3 and 4 are not connected to the power supply paths 9 and 10, the voltage value near 0 V downstream of the electronic fuses 14 and 15 is configured.
[0112] When the process of S74 ends, the CPU 21 proceeds to S80.
[0113] The master ECU 2 configured in this manner is configured to acquire power supply path voltage value information indicating the value of the voltage applied to the power supply paths 9 and 10 for each of the electronic fuses 14 and 15 after the electronic fuses 14 and 15 become conductive.
[0114] The master ECU 2 is configured to perform a connection test to determine whether the slave ECUs 3 and 4 are connected to the electronic fuses 14 and 15 by comparing, for each of the electronic fuses 14 and 15, an expected power supply path voltage value that is preset as a voltage to be applied to the power supply paths 9 and 10 connected to the electronic fuses 14 and 15 with a voltage value indicated by the power supply path voltage value information.
[0115] Such a master ECU 2 can perform a connection test to check whether the slave ECUs 3 and 4 are connected to the electronic fuses 14 and 15 without using any dedicated equipment, thereby improving the efficiency of the connection test.
[0116] In the embodiment described above, S64 and the voltage detection unit 17 correspond to processing as an information acquisition unit, S74 corresponds to processing as a connection inspection unit, the power supply path voltage value information corresponds to voltage value information and first verification information, and the expected power supply path voltage value corresponds to the power supply path voltage value and second verification information.
[0117] Fifth Embodiment A fifth embodiment of the present disclosure will be described below with reference to the drawings. In the fifth embodiment, differences from the fourth embodiment will be described. The same reference numerals will be used to designate common components.
[0118] The vehicle control system 1 of the fifth embodiment differs from the fourth embodiment in that the connection inspection table 25 and the connection inspection process are changed.
[0119] As shown in FIG. 13, the connection inspection table 25 of the fifth embodiment sets an electronic fuse ID, a connected load type, an expected current consumption value, and an expected power supply path voltage value for each of the multiple electronic fuses 14, 15 provided in the vehicle control system 1.
[0120] In the connection inspection table 25 of the fifth embodiment, for the electronic fuse 14, "eFuse_1" is set as the electronic fuse ID, "ECU" is set as the connected load type, "500 mA" is set as the standby current consumption value, and "12 V" is set as the expected power supply path voltage value. For the electronic fuse 15, "eFuse_2" is set as the electronic fuse ID, "ECU" is set as the connected load type, "200 mA" is set as the expected current consumption value, and "12 V" is set as the expected power supply path voltage value.
[0121] Next, a procedure of the connection inspection process of the fifth embodiment will be described. The connection inspection process of the fifth embodiment differs from the fourth embodiment in that the processes of S66 and S76 are executed instead of S64 and S74.
[0122] As shown in FIG. 14, when the process of S50 is completed, the CPU 21 acquires current value information from the i-th electronic fuse and acquires power supply path voltage value information of the i-th electronic fuse from the voltage detection unit 17 in S66.
[0123] In S76, the CPU 21 performs a connection test on the i-th electronic fuse. Specifically, the CPU 21 determines that the electronic fuse is "connected" if the current value indicated by the current value information acquired in S66 is equal to or greater than the connection determination value and the voltage value indicated by the power supply path voltage value information acquired in S66 is equal to or greater than the voltage connection determination value. The CPU 21 also determines that the electronic fuse is "disconnected" if the current value indicated by the current value information acquired in S66 is less than the connection determination value or if the voltage value indicated by the power supply path voltage value information acquired in S66 is less than the voltage connection determination value.
[0124] When the process of S76 is completed, the CPU 21 proceeds to S80.
[0125] The master ECU 2 configured in this manner is configured to acquire, for each of the electronic fuses 14, 15, current value information indicating the value of the current flowing through the power supply paths 9, 10 after the electronic fuses 14, 15 become conductive, and power supply path voltage value information indicating the value of the voltage applied to the power supply paths 9, 10.
[0126] The master ECU 2 is configured to perform a connection test to determine whether the slave ECUs 3, 4 are connected to the electronic fuses 14, 15 by comparing, for each of the electronic fuses 14, 15, a current consumption value that is preset as the current value consumed by the slave ECUs 3, 4 that are connected to the electronic fuses 14, 15 and receive power supply from the battery 7 with a current value indicated by the current value information, and by comparing, for each of the electronic fuses 14, 15, an expected power supply path voltage value that is preset as the voltage to be applied to the power supply paths 9, 10 connected to the electronic fuses 14, 15 with a voltage value indicated by the power supply path voltage value information.
[0127] Such a master ECU 2 can perform a connection test to check whether the slave ECUs 3 and 4 are connected to the electronic fuses 14 and 15 without using any dedicated equipment, thereby improving the efficiency of the connection test.
[0128] In the embodiment described above, S66, the electronic fuses 14 and 15, and the voltage detection unit 17 correspond to the processing performed by the information acquisition unit, and S76 corresponds to the processing performed by the connection inspection unit.
[0129] Sixth Embodiment A sixth embodiment of the present disclosure will be described below with reference to the drawings. In the sixth embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.
[0130] As shown in FIG. 15, the vehicle control system 1 of the sixth embodiment differs from the first embodiment in that a smart sensor 501, a smart actuator 502, a wireless device 503, and electronic fuses 504 and 505 are added.
[0131] The smart sensor 501 is a sensor equipped with a communication function and is connected to the communication bus 8.
[0132] The smart actuator 502 is an actuator equipped with a communication function and is connected to the communication bus 8.
[0133] The radio 503 is a wireless communication device for performing wireless communication with an external communication device installed outside the vehicle. The radio 503 is, for example, a DCM. DCM is an abbreviation for Data Communication Module.
[0134] The electronic fuse 504 is disposed on the power supply path between the battery 7 and the smart sensor 501. The electronic fuse 505 is disposed on the power supply path between the battery 7 and the smart actuator 502.
[0135] Each of the electronic fuses 504 and 505 is configured to switch between a conductive state in which the power supply path is connected and a cut-off state in which the power supply path is cut off in accordance with a command from the control unit 11 .
[0136] Hereinafter, the master ECU 2, the slave ECUs 3 to 5, the smart sensor 501, and the smart actuator 502 will also be collectively referred to as nodes.
[0137] A CAN frame consists of a start of frame, arbitration field, control field, data field, CRC field, ACK field, and end of frame. The arbitration field consists of an 11-bit or 29-bit identifier (i.e., ID) and a 1-bit RTR bit.
[0138] The 11-bit identifier used in CAN communication is called a CAN ID. The CAN ID is set in advance based on the content of the data included in the CAN frame, the source of the CAN frame, the destination of the CAN frame, etc.
[0139] The data field is a payload consisting of first data, second data, third data, fourth data, fifth data, sixth data, seventh data, and eighth data, each of which is 8 bits (i.e., 1 byte).
[0140] The vehicle control system 1 forms a partial network, which is a power supply control method based on communication control of the CAN protocol standard specified in ISO 11898-6. For this reason, the vehicle control system 1 achieves low power consumption by individually transitioning one or more nodes belonging to each communication group (described later) into a wake-up state (i.e., an active state) or a sleep state (i.e., a dormant state) for each communication group. By waking up, a node enters a normal operating state in which the functions assigned to the node can be used without any restrictions, and by sleeping, it enters a low-power operating state in which the available functions are limited.
[0141] In the vehicle control system 1, when waking up a node in a sleep state, an NM frame, which is a CAN frame including activation information that specifies an activation group, is used. NM is an abbreviation for Network Management.
[0142] The activation information is set, for example, as shown in FIG. 16 . DLC stands for Data Length Code, and is an area that represents the size of the data field in a CAN frame in bytes. That is, the activation information is stored in the data field of the CAN frame. For simplicity, the DLC is shown here as being 1 byte (i.e., 8 bits). Each bit of the 8-bit data representing the activation information is associated with an activation group.
[0143] In the activation information set in the NM frame, a bit corresponding to the activation group to be activated is set to 1.
[0144] Each node stores affiliation information that indicates the activation group to which the node belongs. The affiliation information has the same data length as the activation information, and the allocation of each bit is also the same as that of the activation information. In the affiliation information, the bit corresponding to the activation group to which the node belongs is set to 1.
[0145] Each node compares the activation information extracted from the NM frame with the belonging information stored in the node itself to determine whether the communication group to which the node itself belongs is an activation target.
[0146] For example, the affiliation information shown in Fig. 16 indicates that the node belongs to the first communication group, the third communication group, and the fifth communication group. The activation information shown in Fig. 16 indicates that the second communication group, the third communication group, the fourth communication group, and the fifth communication group are to be activated. Since the third communication group and the fifth communication group are included in both the affiliation information and the activation information shown in Fig. 16, the node determines that the node is to be activated as the third communication group and the fifth communication group.
[0147] 15, the storage unit 13 stores a management table 29. The management table 29 may be stored in the ROM 22 or the RAM 23.
[0148] The management table 29 sets, for each of a plurality of communication groups, a correspondence between the communication group and one or more nodes (that is, one or more nodes to be started) belonging to the corresponding communication group.
[0149] The management table 29 sets, for example, that the master ECU 2 and the slave ECUs 3 and 4 belong to a first communication group.
[0150] The management table 29 sets, for example, that the slave ECUs 3, 4, and 5 belong to the second communication group.
[0151] In addition, when the master ECU 2 and the slave ECUs 3 to 5 detect that the start conditions for each of multiple events have been met, they are configured to generate and transmit an NM frame that includes information indicating the communication group involved in the corresponding event as the above-mentioned startup information.
[0152] (Prerequisites) The master ECU 2 and the slave ECU 5 are always powered by the battery 7 without using electronic fuses, and can independently switch between a wake-up state and a sleep state. Hereinafter, the master ECU 2 and the slave ECU 5 are also referred to as NM-equipped nodes. An NM-equipped node is a node that has the function of generating an NM frame.
[0153] The slave ECUs 3 and 4, smart sensor 501, and smart actuator 502 are powered via electronic fuses and cannot switch to a wake-up state or a sleep state by themselves. That is, they enter a wake-up state when the electronic fuse is turned on, and enter a sleep state when the electronic fuse is turned off. Hereinafter, the slave ECUs 3 and 4, smart sensor 501, and smart actuator 502 are also referred to as NM-non-equipped nodes. An NM-non-equipped node is a node that does not have the function of generating and interpreting NM frames.
[0154] The non-NM node includes at least one of an actuator and a sensor in addition to an ECU having a control function.
[0155] The power supply paths of the non-NM nodes are connected to the electronic fuses 14, 15, 504, and 505 of the master ECU 2, respectively.
[0156] The non-NM-equipped node and the electronic fuse may be connected one-to-one, or multiple non-NM-equipped nodes belonging to the same cluster (i.e., a group that activates simultaneously) may be connected under one electronic fuse.
[0157] The master ECU 2 and the NM-equipped node have a communication function and are capable of transmitting and receiving NM frames.
[0158] An NM-equipped node determines whether the node is in a wake-up state or a sleep state based on an NM frame transmitted and received via a communication bus.
[0159] The master ECU 2 turns on or off the electronic fuses 14, 15, 504, and 505 to which the NM non-mounted nodes are connected, based on the NM frame transmitted and received via the communication bus.
[0160] The payload (i.e., data area) of the NM frame transmitted and received by the master ECU 2 and the NM-equipped node stores one or more bits of information indicating which cluster to activate.
[0161] One or more master ECUs (ie, ECUs with built-in electronic fuses) are installed in a vehicle.
[0162] As shown in Figure 17, one or more nodes belonging to each cluster are determined in advance by the system developer. Although it is possible to assign a cluster to each node, multiple nodes can be registered in one cluster. When the bit corresponding to each cluster is active (i.e., bit = 1), the cluster wakes up. In the case of the master ECU, waking up means turning on the electronic fuse.
[0163] (First Activation Example) The first activation example is an operation example in which a fault diagnosis of the slave ECU 3 is performed in response to a request from the cloud.
[0164] First, a connection request is sent from the base station (i.e., cloud) to the vehicle's radio 503.
[0165] Next, when the wireless device 503 determines that the connection is valid, it notifies the master ECU 2 of the event received from the cloud.
[0166] Next, the master ECU 2 determines the service "fault diagnosis of the slave ECU 3" based on the event, and generates an NM frame in which the bit of the third cluster to which only the slave ECU 3 belongs is enabled in order to activate the slave ECU 3.
[0167] Next, the master ECU 2 transmits the generated NM frame onto the communication bus 8 .
[0168] Since there is no NM-equipped node belonging to the third cluster on the communication bus 8, there is no change in the devices on the communication bus.
[0169] Next, the master ECU 2 executes processing based on the NM frame in the control unit 11, assuming that it has received an NM frame with the bit of the third cluster enabled at the same time as the above.
[0170] Next, the control unit 11 of the master ECU 2 determines a wake-up instruction to the third cluster based on the NM frame, and turns on the electronic fuse 14 since the third cluster includes the electronic fuse 14 .
[0171] When the electronic fuse 14 is turned on, power is supplied to the downstream slave ECU 3, which starts up.
[0172] The master ECU 2 waits for the slave ECU 3 to start up, requests a diagnostic code from the slave ECU 3, and transmits the response from the slave ECU 3 to the base station via the wireless device 503.
[0173] (Second Activation Example) The second activation example is an operation example in which a fault diagnosis of the slave ECU 5 is performed in response to a request from the cloud.
[0174] First, a connection request is sent from the base station (i.e., cloud) to the vehicle's radio 503.
[0175] Next, if the wireless device 503 determines that the connection is valid, it notifies the master ECU 2 of the event received from the cloud.
[0176] Next, the master ECU 2 determines the service "fault diagnosis of the slave ECU 5" based on the event, and generates an NM frame in which the bit of the fourth cluster to which only the slave ECU 5 belongs is enabled in order to activate the slave ECU 5.
[0177] Next, the master ECU 2 transmits the generated NM frame onto the communication bus 8 .
[0178] Since the slave ECU 5 exists on the communication bus 8 as a node belonging to the fourth cluster, the slave ECU 5 wakes up.
[0179] Next, the master ECU 2 executes processing based on the NM frame in the control unit 11, assuming that it has received an NM frame with the bit of the fourth cluster enabled at the same time as the above.
[0180] Next, even if the control unit 11 of the master ECU 2 determines to issue a wake-up instruction to the fourth cluster based on the NM frame, it ignores the instruction because the fourth cluster does not include the corresponding electronic fuse.
[0181] When the slave ECU 5 is activated, the master ECU 2 requests a diagnostic code from the slave ECU 5 via the communication bus 8 and transmits the response from the slave ECU 5 to the base station via the wireless device 503 .
[0182] (Third Activation Example) The third activation example is an operation example in which a user activates remote air conditioning using a smartphone.
[0183] First, the user issues a command to turn on the vehicle air conditioner from the smartphone.
[0184] When the wireless device 503 receives the instruction signal from the smartphone and determines that the instruction signal is valid, it transmits the event (i.e., the instruction signal) received from the cloud to the master ECU 2 .
[0185] The master ECU 2 determines the "air conditioning service" based on the event and generates an NM frame in which the second cluster is activated as the air conditioning cluster.
[0186] If the master ECU 2 wants to maintain an active state in which it periodically transmits the generated NM frame to the communication bus 8 until an instruction to stop the air conditioner is issued, it must continue to periodically transmit the NM frame. At the same time, the control unit 11 of the master ECU 2 executes processing based on the NM frame.
[0187] When an NM frame that activates the second cluster occurs on the communication bus 8, the slave ECU 5 (i.e., the air conditioner ECU) belonging to the second cluster receives the NM frame and wakes up in accordance with the received NM frame.
[0188] When the control unit 11 of the master ECU 2 detects that the second cluster is active, it turns on the electronic fuses 504 and 505 that belong to the second cluster.
[0189] When electronic fuse 504 and electronic fuse 505 are in the ON state, power is supplied to smart sensor 501 (i.e., temperature sensor) and smart actuator 502 (i.e., compressor).
[0190] As a result, power supply to the air conditioner ECU, smart sensor 501, and smart actuator 502 begins, making it possible to turn on the in-vehicle air conditioner.
[0191] When the user issues an instruction to turn off the in-vehicle air conditioner from the smartphone, the master ECU 2 stops the periodic transmission of the NM frame.
[0192] When the NM frame is interrupted, the slave ECU 5 transitions to a sleep state, and the master ECU 2 turns off the electronic fuse 504 and the electronic fuse 505. This stops the in-vehicle air conditioner.
[0193] (Fourth Activation Example) The fourth activation example is an operation example in which the slave ECU 5 activates the vehicle air conditioner.
[0194] Since the slave ECU 5 is always supplied with power even when the vehicle is stopped, it can wake up even when it is in sleep mode by detecting the input of a signal indicating that the start switch connected to the slave ECU 5 has been turned on.
[0195] When the woken-up slave ECU 5 detects an input to start the in-vehicle air conditioner, it generates an NM frame with the bit corresponding to the second cluster turned on.
[0196] The slave ECU 5 transmits the generated NM frame via the CAN communication unit 32. When the master ECU 2 receives this NM frame, the master ECU 2 turns on the electronic fuses 504 and 505 that belong to the second cluster.
[0197] When the start switch of the vehicle air conditioner is turned off, the slave ECU 5 stops transmitting NM frames and after a while goes into a sleep state.
[0198] When the NM frame is interrupted, the master ECU 2 turns off the electronic fuses 504 and 505 after a while, and ends the control.
[0199] If the master ECU 2 determines that control must continue even after the transmission of the NM frame has stopped, the master ECU 2 transmits an NM frame with the bit corresponding to the second cluster turned on, which allows the slave ECU 5 and the electronic fuses 504 and 505 to remain activated until the transmission of the NM frame generated by the master ECU 2 has stopped.
[0200] Seventh Embodiment A seventh embodiment of the present disclosure will be described below with reference to the drawings. In the seventh embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.
[0201] 18 , the vehicle control system 100 includes a central ECU 101, upstream power distribution units 102 and 103, zone ECUs 104, 105, 106, and 107, slave ECUs 108, 109, 110, 111, 112, 113, 114, 115, and 116, a battery 117, and a slave ECU 118. Hereinafter, the central ECU 101, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118 will also be collectively referred to as nodes. Hereinafter, the zone ECU may be an ECU that bundles slave ECUs located in a predetermined area within the vehicle, or an ECU that bundles slave ECUs belonging to a predetermined domain.
[0202] The battery 117 supplies power to each part of the vehicle at a DC battery voltage (for example, 12 V). The central ECU 101, the upstream power distribution units 102 and 103, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118 operate by receiving power from the battery 117.
[0203] The upstream power supply distribution unit 102 receives power from the battery 117 via a power supply path 121 between the battery 117 and the upstream power supply distribution unit 102 .
[0204] The upstream power supply distribution unit 103 receives power supply from the battery 117 via a power supply path 122 between the battery 117 and the upstream power supply distribution unit 103 .
[0205] The zone ECUs 104 and 105 receive power from the battery 117 via power supply paths 123 and 124 between the upstream power distribution unit 102 and the zone ECUs 104 and 105, respectively.
[0206] The zone ECUs 106 and 107 receive power from the battery 117 via power supply paths 125 and 126 between the upstream power distribution unit 103 and the zone ECUs 106 and 107, respectively.
[0207] The slave ECUs 108 and 109 receive power from the battery 117 via power supply paths 127 and 128 between the zone ECU 104 and the slave ECUs 108 and 109, respectively.
[0208] The slave ECUs 110 and 111 receive power from the battery 117 via power supply paths 129 and 130 between the zone ECU 105 and the slave ECUs 110 and 111, respectively.
[0209] The slave ECUs 112, 113, and 114 receive power from the battery 117 via power supply paths 131, 132, and 133 between the zone ECU 106 and the slave ECUs 112, 113, and 114, respectively.
[0210] The slave ECUs 115 and 116 receive power from the battery 117 via power supply paths 134 and 135 between the zone ECU 107 and the slave ECUs 115 and 116, respectively.
[0211] The slave ECU 118 receives power from the battery 117 via a power supply path 136 .
[0212] The central ECU 101 and the upstream power distribution unit 102 are connected to each other via a communication line 141 so as to be able to communicate data with each other.
[0213] The central ECU 101 and the upstream power distribution unit 103 are connected to each other via a communication line 142 so as to be able to communicate data with each other.
[0214] The central ECU 101 and the zone ECUs 104, 105, 106, and 107 are connected to each other via communication lines 143, 144, 145, and 146, respectively, so as to be able to communicate data with each other.
[0215] The zone ECU 104 and the slave ECUs 108, 109, and 118 are connected to each other via a communication bus 147 so as to be able to communicate data with each other.
[0216] The zone ECU 105 and the slave ECUs 110 and 111 are connected to each other via a communication bus 148 so as to be able to communicate data with each other.
[0217] The zone ECU 106 and the slave ECUs 112, 113, and 114 are connected to each other via a communication bus 149 so as to be able to communicate data with each other.
[0218] The zone ECU 107 and the slave ECUs 115 and 116 are connected to each other via a communication bus 150 so as to be able to communicate data with each other.
[0219] As shown in FIG. 19, the central ECU 101 includes a control unit 151 , communication units 152 , 153 , 154 , 155 , 156 , and 157 , and a storage unit 158 .
[0220] The control unit 151 is an electronic control device mainly composed of a microcomputer including a CPU 161, a ROM 162, a RAM 163, etc. The various functions of the microcomputer are realized by the CPU 161 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 162 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 161 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 151 may be one or more.
[0221] The communication unit 152 communicates with the upstream power distribution unit 102 connected to the communication line 141 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol. Ethernet is a registered trademark.
[0222] The communication unit 153 communicates with the upstream power distribution unit 103 connected to the communication line 142 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0223] The communication unit 154 communicates with the zone ECU 104 connected to the communication line 143 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0224] The communication unit 155 communicates with the zone ECU 105 connected to the communication line 144 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0225] The communication unit 156 communicates with the zone ECU 106 connected to the communication line 145 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0226] The communication unit 157 communicates with the zone ECU 107 connected to the communication line 145 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0227] The storage unit 158 is a storage device for storing various data, and stores a startup table 165, which will be described later.
[0228] The upstream power distribution unit 102 includes a control circuit 171 , a communication unit 172 , and electronic fuses 173 and 174 .
[0229] The control circuit 171 controls the electronic fuses 173 and 174 to switch between an on state and an off state based on an instruction received from the central ECU 101 via the communication unit 172 .
[0230] The communication unit 172 communicates with the central ECU 101 connected to the communication line 141 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0231] The electronic fuse 173 is disposed between the power supply path 121 and the power supply path 123. The electronic fuse 174 is disposed between the power supply path 121 and the power supply path .
[0232] The upstream power distribution unit 103 includes a control circuit 181 , a communication unit 182 , and electronic fuses 183 and 184 .
[0233] The control circuit 181 controls the electronic fuses 183 and 184 to switch between an on state and an off state based on an instruction received from the central ECU 101 via the communication unit 182 .
[0234] The communication unit 182 communicates with the central ECU 101 connected to the communication line 142 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0235] The electronic fuse 183 is disposed between the power supply path 122 and the power supply path 125. The electronic fuse 184 is disposed between the power supply path 122 and the power supply path 126.
[0236] As shown in FIG. 20, the zone ECU 104 includes a control unit 191 , a communication unit 192 , a CAN communication unit 193 , a storage unit 194 , and electronic fuses 195 and 196 .
[0237] The control unit 191 is an electronic control device mainly composed of a microcomputer including a CPU 201, a ROM 202, a RAM 203, etc. Various functions of the microcomputer are realized by the CPU 201 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 202 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 201 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 191 may be one or more.
[0238] The communication unit 192 communicates with the central ECU 101 connected to the communication line 143 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0239] The CAN communication unit 193 communicates with the slave ECUs 108 and 109 connected to the communication bus 147 by transmitting and receiving communication frames based on the CAN communication protocol.
[0240] The storage unit 194 is a storage device for storing various types of data.
[0241] The electronic fuse 195 is disposed between the power supply path 123 and the power supply path 127. The electronic fuse 196 is disposed between the power supply path 123 and the power supply path 128.
[0242] The zone ECU 105 includes a control unit 211 , a communication unit 212 , a CAN communication unit 213 , a storage unit 214 , and electronic fuses 215 and 216 .
[0243] The control unit 211 is an electronic control device mainly configured with a microcomputer including a CPU 221, a ROM 222, a RAM 223, etc. Various functions of the microcomputer are realized by the CPU 221 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 222 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 221 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 211 may be one or more.
[0244] The communication unit 212 communicates with the central ECU 101 connected to the communication line 144 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0245] The CAN communication unit 213 communicates with the slave ECUs 110 and 111 connected to the communication bus 148 by transmitting and receiving communication frames based on the CAN communication protocol.
[0246] The storage unit 214 is a storage device for storing various types of data.
[0247] The electronic fuse 215 is disposed between the power supply path 124 and the power supply path 129. The electronic fuse 216 is disposed between the power supply path 124 and the power supply path 130.
[0248] As shown in FIG. 21, the zone ECU 106 includes a control unit 231 , a communication unit 232 , a CAN communication unit 233 , a storage unit 234 , and electronic fuses 235 , 236 , and 237 .
[0249] The control unit 231 is an electronic control device mainly configured with a microcomputer including a CPU 241, a ROM 242, a RAM 243, etc. Various functions of the microcomputer are realized by the CPU 241 executing a program stored in a non-transitory physical recording medium. In this example, the ROM 242 corresponds to the non-transitory physical recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 241 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 231 may be one or more.
[0250] The communication unit 232 communicates with the central ECU 101 connected to the communication line 145 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0251] The CAN communication unit 233 communicates with the slave ECUs 112, 113, and 114 connected to the communication bus 149 by transmitting and receiving communication frames based on the CAN communication protocol.
[0252] The storage unit 234 is a storage device for storing various data.
[0253] The electronic fuse 235 is disposed between the power supply path 125 and the power supply path 131. The electronic fuse 236 is disposed between the power supply path 125 and the power supply path 132. The electronic fuse 237 is disposed between the power supply path 125 and the power supply path 133.
[0254] The zone ECU 107 includes a control unit 251 , a communication unit 252 , a CAN communication unit 253 , a storage unit 254 , and electronic fuses 255 and 256 .
[0255] The control unit 251 is an electronic control device mainly composed of a microcomputer including a CPU 261, a ROM 262, a RAM 263, etc. Various functions of the microcomputer are realized by the CPU 261 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 262 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 261 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 251 may be one or more.
[0256] The communication unit 252 communicates with the central ECU 101 connected to the communication line 146 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.
[0257] The CAN communication unit 253 communicates with the slave ECUs 115 and 116 connected to the communication bus 150 by transmitting and receiving communication frames based on the CAN communication protocol.
[0258] The storage unit 254 is a storage device for storing various data.
[0259] The electronic fuse 255 is disposed between the power supply path 126 and the power supply path 134. The electronic fuse 256 is disposed between the power supply path 126 and the power supply path 135.
[0260] As shown in FIG. 22 , the slave ECUs 108 , 109 , and 118 each include a control unit 271 , a CAN communication unit 272 , and a storage unit 273 .
[0261] The control unit 271 is an electronic control device mainly composed of a microcomputer including a CPU 281, a ROM 282, a RAM 283, etc. Various functions of the microcomputer are realized by the CPU 281 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 282 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 281 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 271 may be one or more.
[0262] The CAN communication unit 272 communicates with the zone ECU 104 connected to the communication bus 147 based on the CAN communication protocol.
[0263] The storage unit 273 is a storage device for storing various data.
[0264] The slave ECUs 110 and 111 each include a control unit 291 , a CAN communication unit 292 , and a storage unit 293 .
[0265] The control unit 291 is an electronic control device mainly composed of a microcomputer including a CPU 301, a ROM 302, a RAM 303, etc. The various functions of the microcomputer are realized by the CPU 301 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 302 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 301 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 291 may be one or more.
[0266] The CAN communication unit 292 communicates with the zone ECU 105 connected to the communication bus 148 based on the CAN communication protocol.
[0267] The storage unit 293 is a storage device for storing various data.
[0268] The slave ECUs 112 , 113 , and 114 each include a control unit 311 , a CAN communication unit 312 , and a storage unit 313 .
[0269] The control unit 311 is an electronic control device mainly configured with a microcomputer including a CPU 321, a ROM 322, a RAM 323, etc. Various functions of the microcomputer are realized by the CPU 321 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 322 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 321 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 311 may be one or more.
[0270] The CAN communication unit 312 communicates with the zone ECU 106 connected to the communication bus 149 based on the CAN communication protocol.
[0271] The storage unit 313 is a storage device for storing various data.
[0272] The slave ECUs 115 and 116 each include a control unit 331 , a CAN communication unit 332 , and a storage unit 333 .
[0273] The control unit 331 is an electronic control device mainly composed of a microcomputer including a CPU 341, a ROM 342, a RAM 343, etc. The various functions of the microcomputer are realized by the CPU 341 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 342 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 341 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 331 may be one or more.
[0274] The CAN communication unit 332 communicates with the zone ECU 107 connected to the communication bus 150 based on the CAN communication protocol.
[0275] The storage unit 333 is a storage device for storing various data.
[0276] 23 , the activation table 165 of the central ECU 101 stores a communication group (i.e., an activation group) to be activated for each event. The activation table 165 also stores a correspondence between the activation group and the slave ECU to be put into a wake-up state. The activation table 165 also stores a correspondence between the slave ECU and the electronic fuse connected to the slave ECU. The activation table 165 may be set in a manner that indicates the correspondence between the zone ECU under which the slave ECU is located.
[0277] When the central ECU 101 detects the occurrence of an event, it determines the activation group by referring to the activation table 165 based on the detected event.
[0278] When the central ECU 101 receives an NM frame, it determines that the communication group corresponding to the bit set to 1 in the received NM frame is the activation group.
[0279] The central ECU 101 starts a process of transmitting an NM frame indicating an activation group determined upon detection of an event occurrence or reception of an NM frame to the zone ECUs 104, 105, 106, and 107. After starting transmission of the NM frame, the central ECU 101 thereafter periodically transmits the same NM frame.
[0280] By referring to the activation table 165, the central ECU 101 instructs the electronic fuses corresponding to the activation group determined due to the detection of the occurrence of an event or the reception of an NM frame to be turned on, and transmits an electronic fuse control instruction to the upstream power distribution units 102, 103 and the zone ECUs 104, 105, 106, and 107 to turn off electronic fuses other than the electronic fuses corresponding to the activation group.
[0281] The upstream power distribution unit 102 turns the electronic fuses 173 and 174 on or off based on the received electronic fuse control instruction.
[0282] The upstream power distribution unit 103 turns the electronic fuses 183 and 184 on or off based on the received electronic fuse control instruction.
[0283] The zone ECU 104 turns the electronic fuses 195 and 196 on or off based on the received electronic fuse control instruction.
[0284] The zone ECU 105 turns the electronic fuses 215 and 216 on or off based on the received electronic fuse control instruction.
[0285] The zone ECU 106 turns the electronic fuses 235, 236, and 237 on or off based on the received electronic fuse control instruction.
[0286] The zone ECU 107 turns the electronic fuses 255 and 256 on or off based on the received electronic fuse control instruction.
[0287] The central ECU 101 is connected to the fault diagnosis device 90 of the first embodiment.
[0288] The fault diagnosis device 90 is configured to be detachable via a connector (not shown) and is connected to the central ECU 101 during fault diagnosis, etc. The fault diagnosis device 90 can acquire various information from the central ECU 101, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118 via the central ECU 101, and can update data stored in the central ECU 101, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118.
[0289] As shown in FIG. 19, the storage unit 158 of the central ECU 101 stores a connection inspection table 167 .
[0290] The upstream power supply distribution unit 102 further includes a current detection unit 175. The current detection unit 175 is configured to detect the value of a current flowing through the power supply paths 123 and 124, and to output power supply path current value information indicating the detected current value to the central ECU 101 via the communication unit 172.
[0291] The upstream power supply distribution unit 103 further includes a current detection unit 185. The current detection unit 185 is configured to detect the value of a current flowing through the power supply paths 125 and 126, and to output power supply path current value information indicating the detected current value to the central ECU 101 via the communication unit 172.
[0292] 20 , the zone ECU 104 further includes a current detection unit 197. The current detection unit 197 is configured to detect the value of a current flowing through the power supply paths 127 and 128, and to output power supply path current value information indicating the detected current value to the control unit 191.
[0293] The zone ECU 105 further includes a current detection unit 217. The current detection unit 217 is configured to detect the value of a current flowing through the power supply paths 129 and 130, and to output power supply path current value information indicating the detected current value to the control unit 211.
[0294] 21 , the zone ECU 106 further includes a current detection unit 238. The current detection unit 238 is configured to detect the value of a current flowing through the power supply paths 131, 132, and 133, and to output power supply path current value information indicating the detected current value to the control unit 231.
[0295] The zone ECU 107 further includes a current detection unit 257. The current detection unit 257 is configured to detect the value of a current flowing through the power supply paths 134 and 135, and to output power supply path current value information indicating the detected current value to the control unit 251.
[0296] As shown in FIG. 24, the connection inspection table 167 sets an electronic fuse ID, a connected load type, and an expected current consumption value for each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 included in the vehicle control system 100.
[0297] 24, in the connection inspection table 167 of this embodiment, for the electronic fuse 195, "eFuse_1" is set as the electronic fuse ID, "ECU" is set as the connected load type, and "200 mA" is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 108.
[0298] For the electronic fuse 196, “eFuse_2” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “150 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 109.
[0299] For the electronic fuse 215, “eFuse_3” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “100 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 110.
[0300] For the electronic fuse 216, “eFuse_4” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “250 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 111.
[0301] For the electronic fuse 235, “eFuse_5” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “200 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 112.
[0302] For the electronic fuse 236, “eFuse_6” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “150 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 113.
[0303] For the electronic fuse 237, “eFuse_7” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “100 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 114.
[0304] For the electronic fuse 255, “eFuse_8” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “200 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 115.
[0305] For the electronic fuse 256, “eFuse_9” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “200 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 116.
[0306] Next, a description will be given of the procedure of the connection inspection process executed by the control unit 151 of the central ECU 101. The connection inspection process is a process that is repeatedly executed while the central ECU 101 is running.
[0307] When the connection test process is executed, the CPU 161 of the control unit 151 determines whether the central ECU 101 is set to the connection test mode in S410, as shown in Fig. 25. When the control unit 151 of the central ECU 101 receives a connection test command from the fault diagnosis device 90, the control unit 151 is configured to set the central ECU 101 to the connection test mode.
[0308] If the central ECU 101 is not set to the connection inspection mode, the CPU 161 proceeds to S500. On the other hand, if the central ECU 101 is set to the connection inspection mode, the CPU 161 sets the electronic fuse indication value i stored in the RAM 163 to 0 in S420.
[0309] In S430, the CPU 161 increments the electronic fuse indication value i (i.e., adds 1).
[0310] In S440, the CPU 161 turns on the i-th electronic fuse (i.e., the electronic fuse for which "eFuse_i" is set as the electronic fuse ID). The CPU 161 also turns on the electronic fuses located upstream of the i-th electronic fuse. For example, when turning on the electronic fuse 195, the electronic fuse 173 is also turned on.
[0311] In S450, the CPU 161 waits for a preset ON state waiting time.
[0312] In S460, the CPU 161 acquires power supply path current value information corresponding to the i-th electronic fuse. For example, the power supply path current value information corresponding to the first electronic fuse, electronic fuse 195, is power supply path current value information of the power supply path 127, and is acquired from the current detection unit 197. Furthermore, the power supply path current value information corresponding to the fifth electronic fuse, electronic fuse 235, is power supply path current value information of the power supply path 131, and is acquired from the current detection unit 238.
[0313] In S470, the CPU 161 performs a connection test on the i-th electronic fuse. Specifically, the CPU 161 determines that the electronic fuse is "connected" if the current value indicated by the power supply path current value information acquired in S460 is equal to or greater than the connection determination value, and determines that the electronic fuse is "disconnected" if the current value indicated by the current value information acquired in S460 is less than the connection determination value. The connection determination value is the expected current consumption value of the i-th electronic fuse multiplied by a preset connection test ratio.
[0314] In S480, the CPU 161 stores the connection test result for the i-th electronic fuse (i.e., the result of the connection test in S470) in the storage unit 158.
[0315] In S490, the CPU 161 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (9 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 161 proceeds to S430.
[0316] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 161 proceeds to S500.
[0317] When the process proceeds to S500, the CPU 161 determines whether or not the central ECU 101 is connected to the fault diagnosis device 90. If the central ECU 101 is not connected to the fault diagnosis device 90, the CPU 161 ends the connection inspection process.
[0318] On the other hand, if the central ECU 101 is connected to the fault diagnosis device 90, the CPU 161 transmits, at S510, one or more connection test results stored in the memory unit 158 that have not been transmitted to the fault diagnosis device 90, to the fault diagnosis device 90, and terminates the connection test process.
[0319] Furthermore, if the determination in S490 is affirmative, the CPU 161 of the central ECU 101 transmits a test completion notification indicating that the connection test process has ended to the fault diagnosis device 90. The master ECU 2 is configured to cancel the connection test mode upon receiving a connection test mode end command from the fault diagnosis device 90.
[0320] The central ECU 101 configured in this manner is configured to determine whether to place each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 in a conductive state or a cut-off state. The electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 are configured to switch between a conductive state that connects each of the power supply paths 127 to 135 that supply power from the battery 117 to the slave ECUs 108 to 116 to a cut-off state that cuts off the power supply path.
[0321] The central ECU 101 is configured to individually set each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 to a conductive state or a cut-off state in accordance with the above determination.
[0322] The central ECU 101 is configured to acquire, for each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256, current value information for power supply path for connection verification to verify whether or not the slave ECUs 108 to 116 are connected to the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 after the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 have become conductive.
[0323] The storage unit 158 stores the expected current consumption value for connection verification.
[0324] The central ECU 101 is configured to perform a connection test to determine whether the slave ECUs 108 to 116 are connected to the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 by comparing the power supply path current value information with the expected current consumption value for each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256.
[0325] Such a central ECU 101 can perform a connection test to check whether the slave ECUs 108 to 116 are connected to the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 without using any dedicated equipment, thereby improving the efficiency of the connection test work.
[0326] In the embodiment described above, the central ECU 101 corresponds to the inspection device and the second integrated control device, the battery 117 corresponds to the power source, the slave ECUs 108 to 116 correspond to the connected loads and the slave control devices, the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 correspond to the power supply switching unit, and the vehicle control system 100 corresponds to the inspection system.
[0327] Furthermore, S420 to S430 correspond to processing as a determination unit, S440 corresponds to processing as a continuity control unit, S460 corresponds to processing as an information acquisition unit, S470 corresponds to processing as a connection inspection unit, S480 corresponds to processing as a connection inspection result storage unit, and S510 corresponds to processing as a connection inspection result transmission unit.
[0328] The power supply path current value information corresponds to first verification information, the expected current consumption value corresponds to second verification information, and the zone ECUs 104 to 107 correspond to a first integrated control device.
[0329] Eighth Embodiment An eighth embodiment of the present disclosure will be described below with reference to the drawings. In the eighth embodiment, differences from the seventh embodiment will be described. The same reference numerals will be used to designate common components.
[0330] 26 , the vehicle control system 100 of the eighth embodiment differs from the seventh embodiment in that the configuration of the activation table 165 provided in the central ECU 101 is changed. That is, the activation table 165 of the eighth embodiment has an activation group set for each event. In other words, the activation table 165 of the eighth embodiment does not set a correspondence between the activation group and the slave ECU to be put into a wake-up state.
[0331] As shown in FIG. 27, the seventh embodiment differs from the seventh embodiment in that the storage unit 194 of the zone ECU 104 further stores an activation table 205, which will be described later.
[0332] The seventh embodiment differs from the seventh embodiment in that the storage unit 214 of the zone ECU 105 further stores an activation table 225, which will be described later.
[0333] As shown in FIG. 28, the seventh embodiment differs from the seventh embodiment in that the storage unit 234 of the zone ECU 106 further stores an activation table 245, which will be described later.
[0334] The seventh embodiment differs from the seventh embodiment in that the storage unit 254 of the zone ECU 107 further stores an activation table 265, which will be described later.
[0335] 26, the activation table 205 stores a correspondence between the activation group and the slave ECU to be put into a wake-up state for the slave ECUs 108, 109, and 118 under the control of the zone ECU 104. The activation table 205 also stores a correspondence between the slave ECUs 108, 109, and 118 and the electronic fuses connected to the slave ECUs 108, 109, and 118.
[0336] The activation table 225 stores a correspondence between an activation group and a slave ECU to be put into a wake-up state for each of the slave ECUs 110 and 111 under the zone ECU 105. The activation table 225 also stores a correspondence between the slave ECUs 110 and 111 and the electronic fuses connected to the slave ECUs 110 and 111.
[0337] The activation table 245 stores a correspondence between an activation group and a slave ECU to be put into a wake-up state for the slave ECUs 112, 113, and 114 under the control of the zone ECU 106. The activation table 225 further stores a correspondence between the slave ECUs 112, 113, and 114 and the electronic fuses connected to the slave ECUs 112, 113, and 114.
[0338] The activation table 265 stores a correspondence between an activation group and a slave ECU to be put into a wake-up state for each of the slave ECUs 115 and 116 under the zone ECU 107. The activation table 265 also stores a correspondence between the slave ECUs 115 and 116 and the electronic fuses connected to the slave ECUs 115 and 116.
[0339] When the central ECU 101 detects the occurrence of an event, it determines the activation group by referring to the activation table 165 based on the detected event.
[0340] When the central ECU 101 receives an NM frame, it determines that the communication group corresponding to the bit set to 1 in the received NM frame is the activation group.
[0341] The central ECU 101 starts a process of transmitting an NM frame indicating an activation group determined upon detection of an event occurrence or reception of an NM frame to the zone ECUs 104, 105, 106, and 107. After starting transmission of the NM frame, the central ECU 101 thereafter periodically transmits the same NM frame.
[0342] When the zone ECUs 104, 105, 106, and 107 receive the NM frame, they transfer the received NM frame to the slave ECUs under their control.
[0343] Based on the received NM frame, zone ECUs 104, 105, 106, and 107 refer to activation tables 205, 225, 245, and 265 to turn on the electronic fuses corresponding to the activation group indicated by the NM frame for the subordinate slave ECUs, and turn off electronic fuses other than the electronic fuses corresponding to the activation group.
[0344] 27, the storage unit 194 of the zone ECU 104 stores a connection check table 207. The storage unit 214 of the zone ECU 105 stores a connection check table 227.
[0345] 28, the storage unit 234 of the zone ECU 106 stores a connection check table 247. The storage unit 254 of the zone ECU 107 stores a connection check table 267.
[0346] As shown in FIG. 29, the connection inspection table 207 sets an electronic fuse ID, a connected load type, and an expected current consumption value for each of the plurality of electronic fuses 195 and 196 provided in the zone ECU 104 .
[0347] In the connection inspection table 207 of this embodiment, the electronic fuse ID is set to "eFuse_1," the connected load type is set to "ECU," and the expected current consumption value is set to "200 mA" for the electronic fuse 195. This expected current consumption value corresponds to the slave ECU 108.
[0348] For the electronic fuse 196, “eFuse_2” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “150 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 109.
[0349] The connection inspection table 227 sets an electronic fuse ID, a connected load type, and an expected current consumption value for each of the electronic fuses 215 and 216 included in the zone ECU 105 .
[0350] In the connection inspection table 227 of this embodiment, the electronic fuse ID is set to "eFuse_1," the connected load type is set to "ECU," and the expected current consumption value is set to "100 mA" for the electronic fuse 215. This expected current consumption value corresponds to the slave ECU 110.
[0351] For the electronic fuse 216, “eFuse_2” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “250 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 111.
[0352] The connection check table 247 sets an electronic fuse ID, a connected load type, and an expected current consumption value for each of the electronic fuses 235 , 236 , and 237 provided in the zone ECU 106 .
[0353] In the connection inspection table 247 of this embodiment, the electronic fuse ID is set to "eFuse_1," the connected load type is set to "ECU," and the expected current consumption value is set to "200 mA" for the electronic fuse 235. This expected current consumption value corresponds to the slave ECU 112.
[0354] For the electronic fuse 236, “eFuse_2” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “150 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 113.
[0355] For the electronic fuse 237, “eFuse_3” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “100 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 114.
[0356] The connection inspection table 267 sets an electronic fuse ID, a connected load type, and an expected current consumption value for each of the plurality of electronic fuses 255 and 256 provided in the zone ECU 107 .
[0357] In the connection inspection table 267 of this embodiment, the electronic fuse ID of the electronic fuse 255 is set to "eFuse_1," the connected load type is set to "ECU," and the expected current consumption value is set to "200 mA." This expected current consumption value corresponds to the slave ECU 115.
[0358] For the electronic fuse 256, “eFuse_2” is set as the electronic fuse ID, “ECU” is set as the connected load type, and “200 mA” is set as the expected current consumption value. This expected current consumption value corresponds to the slave ECU 116.
[0359] Next, the procedure of the connection inspection process of the eighth embodiment will be described. The connection inspection process of the eighth embodiment is a process that is repeatedly executed by the control units 191, 211, 231, 251 of the zone ECUs 104, 105, 106, 107 while the zone ECUs 104, 105, 106, 107 are running. The procedure of the connection inspection process will be described below using the zone ECU 104 as a representative.
[0360] When the connection test process is executed, the CPU 161 of the control unit 191 of the zone ECU 104 determines whether the central ECU 101 is set to the connection test mode in S610, as shown in Fig. 30. When the control unit 151 of the central ECU 101 receives a connection test command from the fault diagnosis device 90, the control unit 151 sets the central ECU 101 to the connection test mode.
[0361] If the central ECU 101 is not set to the connection inspection mode, the CPU 201 proceeds to S700. On the other hand, if the central ECU 101 is set to the connection inspection mode, the CPU 201 sets the electronic fuse indication value i stored in the RAM 203 to 0 in S620.
[0362] In step S630, the CPU 201 increments the electronic fuse indication value i (i.e., adds 1).
[0363] In S640, the CPU 201 turns on the i-th electronic fuse (that is, the electronic fuse for which "eFuse_i" is set as the electronic fuse ID).
[0364] In S650, the CPU 201 waits for a preset ON state waiting time.
[0365] In S660, the CPU 201 acquires power supply path current value information corresponding to the i-th electronic fuse. For example, the power supply path current value information corresponding to the first electronic fuse, electronic fuse 195, is power supply path current value information of the power supply path 127, and is acquired from the current detection unit 197. Furthermore, the power supply path current value information corresponding to the second electronic fuse, electronic fuse 196, is power supply path current value information of the power supply path 127, and is acquired from the current detection unit 197.
[0366] In S670, the CPU 201 performs a connection test on the i-th electronic fuse. Specifically, the CPU 201 determines that the electronic fuse is "connected" if the current value indicated by the power supply path current value information acquired in S660 is equal to or greater than the connection determination value, and determines that the electronic fuse is "disconnected" if the current value indicated by the current value information acquired in S660 is less than the connection determination value. The connection determination value is the expected current consumption value of the i-th electronic fuse multiplied by a preset connection test ratio.
[0367] In S680, the CPU 201 stores the connection test result for the i-th electronic fuse (i.e., the result of the connection test in S670) in the storage unit 194.
[0368] In S690, the CPU 201 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (2 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 201 proceeds to S630.
[0369] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 161 proceeds to S700.
[0370] When the process proceeds to S700, the CPU 201 determines whether or not the central ECU 101 is connected to the fault diagnosis device 90. If the central ECU 101 is not connected to the fault diagnosis device 90, the CPU 201 ends the connection inspection process.
[0371] On the other hand, if the central ECU 101 is connected to the fault diagnosis device 90, the CPU 201 transmits, at S710, one or more connection test results stored in the memory unit 194 that have not been transmitted to the fault diagnosis device 90, to the fault diagnosis device 90, and terminates the connection test process.
[0372] The zone ECU 104 configured in this manner is configured to determine whether to place each of the electronic fuses 195, 196 in a conductive state or a cut-off state. The electronic fuses 195, 196 are configured to switch between a conductive state that connects each of the power supply paths 127, 128 that supply power from the battery 117 to the slave ECUs 108, 109 and a cut-off state that cuts off the power supply paths.
[0373] The zone ECU 104 is configured to individually set each of the electronic fuses 195 and 196 to a conductive state or a cut-off state in accordance with the above determination.
[0374] The zone ECU 104 is configured to acquire, for each of the electronic fuses 195, 196, power supply path current value information for connection verification to verify whether the slave ECUs 108, 109 are connected to the electronic fuses 195, 196 after the electronic fuses 195, 196 are in a conductive state.
[0375] The storage unit 194 stores the expected current consumption value for connection verification.
[0376] The zone ECU 104 is configured to perform a connection test to determine whether the slave ECUs 108, 109 are connected to the electronic fuses 195, 196 by comparing the power supply path current value information with the expected current consumption value for each of the electronic fuses 195, 196.
[0377] Such a zone ECU 104 can perform a connection test to check whether the slave ECUs 108, 109 are connected to the electronic fuses 195, 196 without using dedicated equipment, thereby improving the efficiency of the connection test.
[0378] In the embodiment described above, the zone ECUs 104 to 107 correspond to the inspection device and the first integrated control device, and the slave ECUs 108 to 116 correspond to the connected load and the slave control device.
[0379] Furthermore, S620 to S630 correspond to processing as a determination unit, S640 corresponds to processing as a continuity control unit, S660 corresponds to processing as an information acquisition unit, S670 corresponds to processing as a connection inspection unit, S680 corresponds to processing as a connection inspection result storage unit, and S710 corresponds to processing as a connection inspection result transmission unit.
[0380] The power supply path current value information corresponds to first verification information, and the expected current consumption value corresponds to second verification information.
[0381] Ninth Embodiment A ninth embodiment of the present disclosure will be described below with reference to the drawings. In the ninth embodiment, differences from the seventh embodiment will be described. The same reference numerals will be used to designate common configurations.
[0382] The vehicle control system 100 of the ninth embodiment differs from the seventh embodiment in that the configuration of the vehicle control system 100 is changed and that a communication connection test process is executed instead of a connection test process.
[0383] As shown in FIG. 31 , the vehicle control system 100 of the ninth embodiment differs from the seventh embodiment in that the storage unit 158 includes a communication connection inspection table 169 instead of the connection inspection table 167 .
[0384] As shown in FIG. 32, the communication connection inspection table 169 sets an electronic fuse ID and an ECU ID that identifies the connected ECU for each of the multiple electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 provided in the vehicle control system 100.
[0385] In the communication connection inspection table 169 of this embodiment, for the electronic fuse 195, "eFuse_1" is set as the electronic fuse ID and "ECU_A" is set as the ECU ID.
[0386] For the electronic fuse 196, "eFuse_2" is set as the electronic fuse ID, and "ECU_B" is set as the ECU ID.
[0387] For the electronic fuse 215, "eFuse_3" is set as the electronic fuse ID, and "ECU_C" is set as the ECU ID.
[0388] For the electronic fuse 216, "eFuse_4" is set as the electronic fuse ID, and "ECU_D" is set as the ECU ID.
[0389] For the electronic fuse 235, "eFuse_5" is set as the electronic fuse ID, and "ECU_E" is set as the ECU ID.
[0390] For the electronic fuse 236, "eFuse_6" is set as the electronic fuse ID, and "ECU_F" is set as the ECU ID.
[0391] For the electronic fuse 237, "eFuse_7" is set as the electronic fuse ID, and "ECU_G" is set as the ECU ID.
[0392] For the electronic fuse 255, "eFuse_8" is set as the electronic fuse ID, and "ECU_H" is set as the ECU ID.
[0393] For the electronic fuse 256, "eFuse_9" is set as the electronic fuse ID, and "ECU_I" is set as the ECU ID.
[0394] Next, a description will be given of the procedure of a communication connection test process executed by the control unit 151 of the central ECU 101. The communication connection test process is a process that is repeatedly executed while the central ECU 101 is running.
[0395] When the communication connection test process is executed, the CPU 161 of the control unit 151 determines whether the central ECU 101 is set to the communication connection test mode in S810, as shown in Fig. 33. When the control unit 11 of the central ECU 101 receives a communication connection test command from the fault diagnosis device 90, the control unit 11 sets the central ECU 101 to the communication connection test mode.
[0396] If the central ECU 101 is not set to the communication connection inspection mode, the CPU 161 proceeds to S910. On the other hand, if the central ECU 101 is set to the communication connection inspection mode, the CPU 161 sets the electronic fuse indication value i stored in the RAM 163 to 0 in S820.
[0397] In S830, the CPU 161 increments the electronic fuse indication value i.
[0398] In S840, the CPU 161 turns on the i-th electronic fuse. The CPU 161 also turns on the electronic fuses located upstream of the i-th electronic fuse. For example, when turning on the electronic fuse 195, the electronic fuse 173 is also turned on.
[0399] In S850, the CPU 161 waits for a preset ON state waiting time.
[0400] In step S860, the CPU 161 transmits an ID request to the ECU connected to the i-th electronic fuse.
[0401] In step S870, the CPU 161 receives the ECU ID from the ECU connected to the i-th electronic fuse.
[0402] In S880, the CPU 161 performs a communication connection test on the i-th electronic fuse. Specifically, the CPU 161 determines whether the ECU ID received in S870 matches the ECU ID set for the i-th electronic fuse in the communication connection test table 169. If the ECU ID received in S870 does not match the ECU ID set for the i-th electronic fuse in the communication connection test table 169, the CPU 161 determines that the electronic fuse is "misassembled." If the ECU ID received in S870 matches the ECU ID set for the i-th electronic fuse in the communication connection test table 169, the CPU 161 determines that the electronic fuse is "correctly assembled."
[0403] In S890, the CPU 161 stores the communication connection test result for the i-th electronic fuse (i.e., the result of the communication connection test in S880) in the storage unit 158.
[0404] In S900, the CPU 161 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (9 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 161 proceeds to S830.
[0405] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 161 proceeds to S910.
[0406] When the process proceeds to S910, the CPU 161 determines whether or not the central ECU 101 is connected to the fault diagnosis device 90. If the central ECU 101 is not connected to the fault diagnosis device 90, the CPU 161 ends the communication connection inspection process.
[0407] On the other hand, if the central ECU 101 is connected to the fault diagnosis device 90, the CPU 161, in S920, transmits to the fault diagnosis device 90 one or more communication connection test results stored in the memory unit 158 that have not been transmitted to the fault diagnosis device 90, and terminates the communication connection test process.
[0408] The central ECU 101 configured in this manner is configured to determine whether to place each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 in a conductive state or a cut-off state. The electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 are configured to switch between a conductive state that connects each of the power supply paths 127 to 135 that supply power from the battery 117 to the slave ECUs 108 to 116 to a cut-off state that cuts off the power supply path.
[0409] The central ECU 101 is configured to individually set each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 to a conductive state or a cut-off state in accordance with the above determination.
[0410] The central ECU 101 is configured to acquire, for each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256, an ECU ID for connection verification to verify whether or not the slave ECUs 108 to 116 are connected to the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 after the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 have become conductive.
[0411] The storage unit 158 stores the ECU ID for connection verification.
[0412] The central ECU 101 is configured to perform a connection test to determine whether the slave ECUs 108 to 116 are connected to the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 by comparing the acquired ECU ID with the stored ECU ID for each of the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256.
[0413] Such a central ECU 101 can perform a connection test to check whether the slave ECUs 108 to 116 are connected to the electronic fuses 195, 196, 215, 216, 235, 236, 237, 255, and 256 without using any dedicated equipment, thereby improving the efficiency of the connection test work.
[0414] In the embodiment described above, steps S820 to S830 correspond to processing by a determination unit, step S840 corresponds to processing by a continuity control unit, step S860 corresponds to processing by an information acquisition unit, and step S870 corresponds to processing by a connection inspection unit.
[0415] Furthermore, the ECU ID received by the central ECU 101 corresponds to the load identification information and the first verification information, and the ECU ID set in the communication connection inspection table 169 corresponds to the validity identification information and the second verification information.
[0416] Furthermore, S890 corresponds to the processing performed by the communication connection test result storage unit, and S920 corresponds to the processing performed by the communication connection test result transmission unit.
[0417] Although one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modifications.
[0418] [Variation 1] In the above embodiment, the vehicle control system 1 is shown to have two electronic fuses 14, 15, but the vehicle control system 1 may also be configured to have one electronic fuse, or three or more electronic fuses.
[0419] [Modification 2] In the above embodiment, the connection test result indicates "connected" or "disconnected." However, the connection test result may include at least one of current value information indicating the current value measured by the electronic fuses 14 and 15 and a reason for determining that the connected load is not connected to the electronic fuses 14 and 15. The reason for determining that the connected load is not connected to the electronic fuses 14 and 15 is, for example, the determination result in S70 and the determination result in S72. That is, the determination result in S70 is that the current value indicated by the current value information is less than the connection determination value. The determination result in S72 is that the difference between the sum of the expected current consumption values of the multiple connected loads connected to the electronic fuse and the current value indicated by the current value information is close to the expected current consumption value of one connected load connected to the electronic fuse.
[0420] [Modification 3] In the above embodiment, the connection test result or the communication connection test result is transmitted to the fault diagnosis device 90, but it may be transmitted to a server installed outside the master ECU 2.
[0421] [Modification 4] In the above embodiment, the electronic fuses 14 and 15 are used to make or break the power supply paths 9 and 10, but relays may be used instead of the electronic fuses 14 and 15.
[0422] [Variation 5] In the above embodiment, a connection test is performed using current value information acquired from the electronic fuses 14 and 15. However, a connection test may also be performed using power supply path current value information acquired from the current detection unit 16.
[0423] [Variation 6] In the above embodiment, the master ECU 2 and the slave ECUs 3, 4, and 5 perform CAN communication. However, the communication performed by the master ECU 2 and the slave ECUs 3, 4, and 5 is not limited to CAN and may be, for example, Ethernet communication or LIN communication. LIN is an abbreviation for Local Interconnect Network. Ethernet is a registered trademark.
[0424] [Seventh Modification] In the seventh embodiment, the central ECU 101 executes the connection inspection process for the slave ECUs 108 to 116 under its control. However, the central ECU 101 may execute the connection inspection process for the zone ECUs 104 to 107 under its control. In this case, the central ECU 101 corresponds to the inspection device, and the zone ECUs 104 to 107 correspond to the connected loads.
[0425] [Variation 8] In the eighth embodiment, the zone ECU 104 executes a connection test process on the slave ECUs 108 and 109 under its control. However, the upstream power distribution unit 102 may execute a connection test process on the zone ECUs 104 and 105 under its control. Alternatively, the upstream power distribution unit 103 may execute a connection test process on the zone ECUs 106 and 107 under its control. However, in order for the upstream power distribution units 102 and 103 to execute a connection test process, the upstream power distribution units 102 and 103 must include a control unit configured around a microcomputer including a CPU, ROM, RAM, etc., instead of the control circuits 171 and 181. In this case, the upstream power distribution units 102 and 103 correspond to test devices and the zone ECUs 104 to 107 correspond to connected loads.
[0426] The control unit 11, 151, 191 and its method described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to execute one or more functions embodied in a computer program. Alternatively, the control unit 11, 151, 191 and its method described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit 11, 151, 191 and its method described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to execute one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible recording medium. The method for implementing the functions of each unit included in the control unit 11, 151, 191 does not necessarily need to include software; all of the functions may be implemented using one or more hardware.
[0427] In the above embodiments, multiple functions of one component may be realized by multiple components, or one function of one component may be realized by multiple components. Furthermore, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, part of the configuration of the above embodiments may be omitted. Furthermore, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.
[0428] In addition to the above-mentioned master ECU 2, central ECU 101, and zone ECUs 104 to 107, the present disclosure can also be realized in various forms, such as a system having the master ECU 2, central ECU 101, and zone ECUs 104 to 107 as components, a program for causing a computer to function as the master ECU 2, central ECU 101, and zone ECUs 104 to 107, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and an inspection method.[Technical Idea Disclosed in the Present Specification] [Item 1] One or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) configured to switch between a conduction state for conducting each of one or more power supply paths (9, 10, 123-135) that supply power from a power source (7, 117) to one or more connected loads (3, 4, 5, 50, 60, 104-116) and a cut-off state for cutting off the power supply path, and a determination unit (S20-S30, S220-S230, S420-S430, S620-S630, S820-S830) configured to determine whether to put each of the one or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) into the conduction state or the cut-off state; a continuity control unit (S40, S240, S440, S640, S840) configured to individually set each of the one or more power supply switching units to the conductive state or the cut-off state in accordance with the decision made by the decision unit; an information acquisition unit (S60, S64, S66, 14, 15, 16, 17, S260, S270, S460, S660, S870) configured to acquire, for each of the one or more power supply switching units, first verification information for connection verification that verifies whether the connected load is connected to the power supply switching unit after the power supply switching unit is set to the conductive state; and a storage unit (13, 158, 194, 214, 234, 254) that stores second verification information (25, 27, 167, 169, 207, 227, 247, 267) for the connection verification. and a connection inspection unit (S70, S72, S74, S76, S280, S470, S670, S880) configured to perform a connection inspection to determine whether or not one or more of the connected loads are connected to the power supply switching unit by comparing the first verification information with the second verification information for each of the one or more power supply switching units.
[0429] [Item 2] An inspection device according to Item 1, wherein the first verification information is at least one of current value information indicating a value of a current flowing through the power supply path and voltage value information indicating a value of a voltage applied to the power supply path, and the second verification information is one or more current consumption values that are set in advance as current values consumed by one or more connected loads that are connected to the power supply switching unit and receive power from the power source, for each of the one or more power supply switching units, and a power supply path voltage value that is set in advance as a voltage applied to the power supply path connected to the power supply switching unit, for each of the one or more power supply switching units, and the connection inspection unit (S70, S72, S74, S76, S470, S670) is configured to perform the connection inspection by at least one of comparing, for each of the one or more power supply switching units, the one or more current consumption values with a current value indicated by the current value information, and comparing, for each of the one or more power supply switching units, the power supply path voltage value with a voltage value indicated by the voltage value information.
[0430] [Item 3] The inspection device according to Item 2, wherein the connection inspection unit (S72) is configured to, when a plurality of the connected loads are connected to the power supply switching unit, identify the connected loads that are not connected to the power supply switching unit by comparing a difference between a sum of a plurality of the current consumption values of the plurality of the connected loads and a current value indicated by the current value information with the plurality of the current consumption values.
[0431] [Item 4] The inspection device according to item 2 or 3, further comprising: a connection inspection result storage unit (S80, S82, S480, S680) configured to store inspection results by the connection inspection unit; and a connection inspection result transmission unit (S110, S112, S510, S710) configured to transmit the inspection results stored in the connection inspection result storage unit to an external device installed outside the inspection device.
[0432] [Item 5] The inspection device according to any one of items 2 to 4, wherein the inspection result by the connection inspection unit includes at least one of the current value information, and, when it is determined that the connected load is not connected to the power supply switching unit, a reason for determining that the connected load is not connected to the power supply switching unit.
[0433] [Item 6] An inspection device according to Item 1, wherein the first verification information is load identification information for identifying the connected load, the information acquisition unit (S270, S870) is configured to acquire the first verification information by receiving the load identification information from the connected load connected to the power supply switching unit for each of one or more of the power supply switching units, the second verification information is authenticity identification information that is preset for each of the one or more power supply switching units as identification information for identifying an authentic connected load that is preset as the connected load to be connected to the power supply switching unit, and the connection inspection unit (S280, S880) is configured, as the connection inspection, to determine that an authentic connected load is connected to the power supply switching unit if the authenticity identification information and the load identification information acquired by the information acquisition unit match for each of the one or more power supply switching units, and to determine that an authentic connected load is not connected to the power supply switching unit if the authenticity identification information and the load identification information do not match.
[0434] [Item 7] The inspection device according to Item 6, further comprising: a communication connection inspection result storage unit (S290, S890) configured to store inspection results by the connection inspection unit; and a communication connection inspection result transmission unit (S320, S920) configured to transmit the inspection results stored in the communication connection inspection result storage unit to an external device installed outside the inspection device.
[0435] [Item 8] The inspection device according to any one of items 1 to 7, wherein when the inspection device is set to a connection inspection mode for executing the connection inspection, the determination unit, the continuity control unit, the information acquisition unit, and the connection inspection unit are configured to execute the processes of the determination unit, the continuity control unit, the information acquisition unit, and the connection inspection unit, respectively.
[0436] [Item 9] An inspection system (1, 100) comprising one or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) configured to switch between a conduction state that conducts each of one or more power supply paths (9, 10, 123-135) that supply power from a power source (7, 117) to one or more connected loads (3, 4, 5, 50, 60, 104-116) and a cut-off state that cuts off the power supply path, and an inspection device (2, 101-107) configured to control the operation of the one or more power supply switching units, wherein the inspection device: a determination unit (S20 to S30, S220 to S230, S420 to S430, S620 to S630, S820 to S830) configured to determine whether to place each of the one or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) in the conductive state or the cut-off state; and a conduction control unit (S40, S240, S440, S640, S840) configured to individually place each of the one or more power supply switching units in the conductive state or the cut-off state in accordance with the determination by the determination unit. an information acquisition unit (S60, S64, S66, 14, 15, 16, 17, S260, S270, S460, S660, S870) configured to acquire, for each of the one or more power supply switching units, first verification information for connection verification that verifies whether or not the connected load is connected to the power supply switching unit after the power supply switching unit has entered the conductive state; and a storage unit (13, 158, 194, 214, 234, 254) that stores second verification information (25, 27, 167, 169, 207, 227, 247, 267) for the connection verification. and a connection inspection unit (S70, S72, S74, S76, S280, S470, S670, S880) configured to perform a connection inspection for each of the one or more power supply switching units to determine whether or not the one or more connected loads are connected to the power supply switching unit by comparing the first verification information with the second verification information.
[0437] [Item 10] The inspection system (1) according to Item 9, wherein the inspection system includes slave control devices (3, 4) as the connected loads, and includes a master control device (2) as the inspection device, connected to the slave control devices so as to be able to communicate data with the master control devices, and equipped with one or more of the power supply switching units (14, 15).
[0438] [Item 11] The inspection system (100) according to Item 9, wherein the inspection system includes slave control devices (108-116) as the connected load, a first integrated control device (104-107) connected to the slave control devices so as to be able to communicate data with each other and equipped with one or more of the power supply switching units (195, 196, 215, 216, 235, 236, 237, 255, 256), and a second integrated control device (101) connected to the first integrated control device so as to be able to communicate data with each other as the inspection device, and the slave control devices and the second integrated control device are connected to each other so as to be able to communicate data with each other via the first integrated control device.
[0439] [Item 12] The inspection system (100) according to Item 9, wherein the inspection system includes slave control devices (108-116) as the connected loads, and includes first integrated control devices (104-107) as the inspection devices, which are connected to the slave control devices so as to be able to communicate data with each other and which are equipped with one or more of the power supply switching units (195, 196, 215, 216, 235, 236, 237, 255, 256), and a second integrated control device (101) connected to the first integrated control device so as to be able to communicate data with each other, and the slave control devices and the second integrated control device are connected to each other so as to be able to communicate data with each other via the first integrated control device.
[0440] [Item 13] The inspection system (100) according to Item 9, comprising: slave control devices (108-116); a first integrated control device (104-107) connected to the slave control devices so as to be able to communicate data with the slave control devices as the connected load; an upstream power supply distribution unit (102, 103) having one or more of the power supply switching units (173, 174, 183, 184); and a second integrated control device (101) connected to the first integrated control device and the upstream power supply distribution unit so as to be able to communicate data with the first integrated control device.
[0441] [Item 14] The inspection system (100) according to Item 9, comprising: slave control devices (108-116); a first integrated control device (104-107) connected as the connected load so as to be able to communicate data with the slave control devices; an upstream power distribution unit (102, 103) provided with one or more of the power supply switching units (173, 174, 183, 184) as the inspection device; and a second integrated control device (101) connected so as to be able to communicate data with the first integrated control device and the upstream power distribution unit.
Claims
1. One or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) configured to switch between a conduction state for conducting one or more power supply paths (9, 10, 123 to 135) that supply power from a power source (7, 117) to one or more connected loads (3, 4, 5, 50, 60, 104 to 116) and a cut-off state for cutting off the power supply paths, and a determination unit (S20 to S30, S220 to S230, S420 to S430, S620 to S630, S820 to S830) configured to determine whether to switch between the conduction state or the cut-off state for each of the one or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256); a continuity control unit (S40, S240, S440, S640, S840) configured to individually set each of the one or more power supply switching units to the conductive state or the cut-off state in accordance with the decision made by the decision unit; an information acquisition unit (S60, S64, S66, 14, 15, 16, 17, S260, S270, S460, S660, S870) configured to acquire, for each of the one or more power supply switching units, first verification information for connection verification that verifies whether the connected load is connected to the power supply switching unit after the power supply switching unit is set to the conductive state; and a storage unit (13, 158, 194, 214, 234, 254) that stores second verification information (25, 27, 167, 169, 207, 227, 247, 267) for the connection verification. and a connection inspection unit (S70, S72, S74, S76, S280, S470, S670, S880) configured to perform a connection inspection to determine whether or not one or more of the connected loads are connected to the power supply switching unit by comparing the first verification information with the second verification information for each of the one or more power supply switching units.
2. An inspection device according to claim 1, wherein the first verification information is at least one of current value information indicating a value of a current flowing in the power supply path and voltage value information indicating a value of a voltage applied to the power supply path, and the second verification information is one or more current consumption values that are set in advance as current values consumed by one or more connected loads that are connected to the power supply switching unit and receive power from the power source, for each of the one or more power supply switching units, and a power supply path voltage value that is set in advance as a voltage applied to the power supply path connected to the power supply switching unit, for each of the one or more power supply switching units, and the connection inspection unit (S70, S72, S74, S76, S470, S670) is configured to perform the connection inspection by at least one of comparing, for each of the one or more power supply switching units, the one or more current consumption values with a current value indicated by the current value information, and comparing, for each of the one or more power supply switching units, the power supply path voltage value with a voltage value indicated by the voltage value information.
3. An inspection device according to claim 2, wherein the connection inspection unit (S72) is configured to, when a plurality of connected loads are connected to the power supply switching unit, identify a connected load that is not connected to the power supply switching unit by comparing the difference between the sum of the plurality of current consumption values of each of the plurality of connected loads and the current value indicated by the current value information with the plurality of current consumption values.
4. An inspection device according to claim 2 or 3, further comprising: a connection inspection result storage unit (S80, S82, S480, S680) configured to store the inspection results obtained by said connection inspection unit; and a connection inspection result transmission unit (S110, S112, S510, S710) configured to transmit the inspection results stored in said connection inspection result storage unit to an external device installed outside said inspection device.
5. An inspection device according to claim 2 or claim 3, wherein the inspection result by the connection inspection unit includes at least one of the current value information, and, when it is determined that the connected load is not connected to the power supply switching unit, the reason for determining that the connected load is not connected to the power supply switching unit.
6. An inspection device according to claim 1, wherein the first verification information is load identification information for identifying the connected load, the information acquisition unit (S270, S870) is configured to acquire the first verification information for each of one or more of the power supply switching units by receiving the load identification information from the connected load connected to the power supply switching unit, the second verification information is valid identification information that is preset for each of one or more of the power supply switching units as identification information for identifying a valid connected load that is preset as the connected load to be connected to the power supply switching unit, and the connection inspection unit (S280, S880) is configured, as the connection inspection, to determine that the valid connected load is connected to the power supply switching unit if the valid identification information and the load identification information acquired by the information acquisition unit match for each of the one or more of the power supply switching units, and to determine that the valid connected load is not connected to the power supply switching unit if the valid identification information and the load identification information do not match.
7. An inspection device as set forth in claim 6, further comprising: a communication connection inspection result storage unit (S290, S890) configured to store the inspection results obtained by the connection inspection unit; and a communication connection inspection result transmission unit (S320, S920) configured to transmit the inspection results stored in the communication connection inspection result storage unit to an external device installed outside the inspection device.
8. An inspection device according to any one of claims 1, 2 and 6, wherein when the inspection device is set to a connection inspection mode for executing the connection inspection, the determination unit, the continuity control unit, the information acquisition unit and the connection inspection unit are configured to execute the processes of the determination unit, the continuity control unit, the information acquisition unit and the connection inspection unit, respectively.
9. An inspection system (1, 100) comprising one or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) configured to switch between a conductive state that connects one or more power supply paths (9, 10, 123-135) that supply power from a power source (7, 117) to one or more connected loads (3, 4, 5, 50, 60, 104-116) and a cut-off state that cuts off the power supply paths, and an inspection device (2, 101-107) configured to control the operation of one or more of the power supply switching units, wherein the inspection device: a determination unit (S20 to S30, S220 to S230, S420 to S430, S620 to S630, S820 to S830) configured to determine whether to place each of the one or more power supply switching units (14, 15, 173, 174, 183, 184, 195, 196, 215, 216, 235, 236, 237, 255, 256) in the conductive state or the cut-off state; and a conduction control unit (S40, S240, S440, S640, S840) configured to individually place each of the one or more power supply switching units in the conductive state or the cut-off state in accordance with the determination by the determination unit. an information acquisition unit (S60, S64, S66, 14, 15, 16, 17, S260, S270, S460, S660, S870) configured to acquire, for each of the one or more power supply switching units, first verification information for connection verification that verifies whether or not the connected load is connected to the power supply switching unit after the power supply switching unit has entered the conductive state; and a storage unit (13, 158, 194, 214, 234, 254) that stores second verification information (25, 27, 167, 169, 207, 227, 247, 267) for the connection verification. and a connection inspection unit (S70, S72, S74, S76, S280, S470, S670, S880) configured to perform a connection inspection for each of the one or more power supply switching units to determine whether or not the one or more connected loads are connected to the power supply switching unit by comparing the first verification information with the second verification information.
10. An inspection system (1) according to claim 9, comprising slave control devices (3, 4) as the connected loads, and a master control device (2) as the inspection device, connected to the slave control devices so as to be able to communicate data with the slave control devices and equipped with one or more of the power supply switching units (14, 15).
11. An inspection system (100) according to claim 9, comprising: a slave control device (108-116) as the connected load; a first integrated control device (104-107) connected to the slave control device so as to be able to communicate data with it and equipped with one or more of the power supply switching units (195, 196, 215, 216, 235, 236, 237, 255, 256); and a second integrated control device (101) connected to the first integrated control device so as to be able to communicate data with it as the inspection device; and the slave control device and the second integrated control device are connected to each other so as to be able to communicate data with each other via the first integrated control device.
12. An inspection system (100) according to claim 9, comprising: slave control devices (108-116) as the connected load; a first integrated control device (104-107) as the inspection device, connected to the slave control devices so as to be able to communicate data with the slave control devices and equipped with one or more of the power supply switching units (195, 196, 215, 216, 235, 236, 237, 255, 256); and a second integrated control device (101) connected to the first integrated control device so as to be able to communicate data with the first integrated control device, wherein the slave control devices and the second integrated control device are connected to each other so as to be able to communicate data with each other via the first integrated control device.
13. An inspection system (100) according to claim 9, comprising: slave control devices (108-116); a first integrated control device (104-107) connected to said slave control devices so as to be able to communicate data with said slave control devices as said connected load; an upstream power distribution unit (102, 103) having one or more of said power supply switching units (173, 174, 183, 184); and a second integrated control device (101) connected to said first integrated control device and said upstream power distribution unit so as to be able to communicate data with said first integrated control device.
14. An inspection system (100) according to claim 9, comprising: slave control devices (108-116); a first integrated control device (104-107) connected as the connected load so as to be capable of data communication with the slave control devices; an upstream power distribution unit (102, 103) equipped with one or more of the power supply switching units (173, 174, 183, 184) as the inspection device; and a second integrated control device (101) connected so as to be capable of data communication with the first integrated control device and the upstream power distribution unit.
Citation Information
Patent Citations
In identification device
JP1984138779U
Inspecting apparatus of impedance of electronic circuit
JP1993080093A
Electric power source device for working and method for controlling electric power source
JP1995284929A
Electric circuit device, method for detecting fault, and method for correcting signal
JP1997281172A
Inspecting device for wiring board and its inspection method
JP2000346898A