Management device and management system

The management device sets and transmits unique identification information to control units with shared hardware, addressing non-standardized software issues and improving manufacturing efficiency by allowing identical software installation.

WO2025183009A1PCT designated stage Publication Date: 2025-09-04DENSO CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/006684
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-26
Filing Date
2025-02-26
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

When multiple electronic control units with the same hardware are installed in a vehicle, setting unique identification information is necessary, leading to non-standardized software installation, which reduces manufacturing efficiency.

Method used

A management device with power supply switching units and identification information transmitters sets and transmits unique identification information to each control unit after installation, allowing identical software installation despite shared hardware.

Benefits of technology

This approach improves manufacturing efficiency by enabling identical software installation for control units with the same hardware, enhancing standardization and reducing setup complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025006684_04092025_PF_FP_ABST
    Figure JP2025006684_04092025_PF_FP_ABST
Patent Text Reader

Abstract

A management device (2) is provided with first and second conduction units (S40) and first and second identification information transmission units (S60). The first conduction unit places a first power feed switching unit (14), which switches between a first conduction state in which a first power feed path (9) for supplying power from a power supply (7) to a first control device (3) is made conductive and a first interruption state, in the first conduction state. The first identification information transmission unit transmits first identification information to the first control device when a first transmission condition is satisfied. After the first identification information is transmitted, the second conduction unit places a second power feed switching unit (15), which switches between a second conduction state in which a second power feed path for supplying power to a second control device (4) is made conductive and a second interruption state, in the second conduction state. The second identification information transmission unit transmits second identification information to the second control device when a second transmission condition is satisfied.
Need to check novelty before this filing date? Find Prior Art

Description

Management device and management system CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This international application claims the benefit of Japanese Patent Application No. 2024-026552, filed with the Japan Patent Office on February 26, 2024, the entire disclosure of which is incorporated herein by reference.

[0002] The present disclosure relates to a management device and a management system that manage control devices.

[0003] Non-Patent Document 1 describes DHCP, which is a protocol for automatically assigning IP addresses to multiple communication devices connected to a network. DHCP is an abbreviation for Dynamic Host Configuration Protocol.

[0004] Network Working Group, “RFC2131 Dynamic Host Configuration Protocol”, [online], March 1997, [retrieved January 31, 2020], Internet <URL: https: / / www.rfc-editor.org / rfc / pdfrfc / rfc2131.txt.pdf>

[0005] A vehicle is equipped with many electronic control units. In some cases, a single vehicle is equipped with multiple electronic control units that have the same hardware. For example, the electronic control unit that controls the driver's door and the electronic control unit that controls the passenger's door have the same hardware.

[0006] As a result of detailed investigations by the inventors, the following problem was discovered: When multiple electronic control units having the same hardware are installed in one vehicle, it is necessary to set identification information for identifying each of these multiple electronic control units in advance, and therefore it is not possible to standardize the software installed in the multiple electronic control units. As a result, it is necessary to install software that is partially different from each other on each of the multiple electronic control units having the same hardware, which reduces the work efficiency in manufacturing the electronic control units.

[0007] The present disclosure provides a management device that includes a first conductive unit, a first identification information transmitter, a second conductive unit, and a second identification information transmitter.

[0008] The first conduction unit is configured to set the first power supply switching unit, which is configured to switch between a first conduction state that conducts the first power supply path that supplies power from the power source to the first control device and a first cut-off state that cuts off the first power supply path, to the first conduction state.

[0009] The first identification information transmitting unit is configured to transmit, to the first control device, first identification information that is preset in association with the first power supply switching unit and that identifies the first control device, when a preset first transmission condition is met after the first power supply switching unit has entered the first conductive state.

[0010] The second conduction unit is configured to set the second power supply switching unit, which is configured to switch between a second conduction state in which the second power supply path that supplies power from the power source to the second control device is conductive and a second cut-off state in which the second power supply path is cut off, to a second conduction state after the first identification information is transmitted to the first control device.

[0011] The second identification information transmitting unit is configured to transmit, to the second control device, second identification information that is preset in association with the second power supply switching unit and that identifies the second control device, when a preset second transmission condition is met after the second power supply switching unit has entered the second conductive state.

[0012] The management device of the present disclosure configured in this manner can set first identification information and second identification information for the first control device and the second control device, respectively, after installing the first control device and the second control device in the vehicle. This allows the first control device and the second control device, if they have identical hardware, to be equipped with identical software during manufacturing. Therefore, the management device of the present disclosure can improve work efficiency during the manufacturing of electronic control devices.

[0013] Another aspect of the present disclosure is a management system including a first control device, a second control device, and a management device, wherein the first control device receives power from a power source via a first power supply switching unit configured to switch between a first conduction state that connects a first power supply path and a first interruption state that interrupts the first power supply path.

[0014] The second control device receives power from the power source via a second power supply switching unit configured to switch between a second conductive state in which the second power supply path is conductive and a second cut-off state in which the second power supply path is cut off.

[0015] The management device is connected to the first control device and the second control device so as to be able to communicate data with each other, and is configured to control the operation of the first power supply switching unit and the second power supply switching unit. The management device includes a first conduction unit, a first identification information transmission unit, a second conduction unit, and a second identification information transmission unit.

[0016] The management system of the present disclosure configured in this manner is a system that includes the management device of the present disclosure, and can obtain the same effects as the management device of the present disclosure.

[0017] 1 is a block diagram showing the configuration of a vehicle control system. FIG. 2 is a diagram showing the configuration of a setting table. FIG. 3 is a flowchart showing ID setting processing of the first embodiment. FIG. 4 is a flowchart showing ID setting processing of the second embodiment. FIG. 5 is a block diagram showing the configuration of a vehicle control system of the third embodiment. FIG. 6 is an explanatory diagram illustrating affiliation information and activation information. FIG. 7 is a diagram showing the correspondence between control objects and clusters. FIG. 8 is a block diagram showing the configuration of a communication system of the fourth embodiment. FIG. 9 is a block diagram showing the configuration of a central ECU and an upstream power distribution unit of the fourth embodiment. FIG. 10 is a first block diagram showing the configuration of a zone ECU of the fourth embodiment. FIG. 11 is a second block diagram showing the configuration of a zone ECU of the fourth embodiment. FIG. 12 is a block diagram showing the configuration of a slave ECU of the fourth embodiment. FIG. 13 is a diagram showing the configuration of an activation table of the fourth embodiment. FIG. 14 is a diagram showing the configuration of a setting table of the fourth embodiment. FIG. 15 is a flowchart showing ID setting processing of the fourth embodiment. FIG. 16 is a diagram showing the configuration of a setting table of the fifth embodiment. FIG. 17 is a flowchart showing ID setting processing of the fifth embodiment.

[0018] [First Embodiment] A first embodiment of the present disclosure will be described below with reference to the drawings. A vehicle control system 1 of this embodiment is mounted on a vehicle, and as shown in Fig. 1, includes a master ECU 2, slave ECUs 3 and 4, and a battery 7. ECU is an abbreviation for Electronic Control Unit.

[0019] The master ECU 2 and the slave ECUs 3 and 4 are connected to each other so as to be able to communicate data with each other via a communication bus 8. The battery 7 supplies power to each part of the vehicle at a DC battery voltage (e.g., 12 V). The master ECU 2 and the slave ECUs 3 and 4 operate by receiving power from the battery 7.

[0020] The master ECU 2 includes a control unit 11, a CAN communication unit 12, a storage unit 13, and electronic fuses 14 and 15. CAN is an abbreviation for Controller Area Network and is a registered trademark.

[0021] The control unit 11 is an electronic control device mainly composed of a microcomputer including a CPU 21, a ROM 22, a RAM 23, etc. The various functions of the microcomputer are realized by the CPU 21 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 22 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 21 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 11 may be one or more.

[0022] The CAN communication unit 12 communicates with the slave ECUs 3 and 4 connected to the communication bus 8 by transmitting and receiving communication frames based on the CAN communication protocol. The memory unit 13 is a storage device for storing various data. The memory unit 13 stores a setting table 25, which will be described later.

[0023] The electronic fuse 14 is disposed on the power supply path 9 between the battery 7 and the slave ECU 3. The electronic fuse 15 is disposed on the power supply path 10 between the battery 7 and the slave ECU 4.

[0024] The electronic fuses 14 and 15 each include a switching element (e.g., a MOSFET) and a control circuit. The control circuits of the electronic fuses 14 and 15 are configured to switch the switching element from an on state to an off state to cut off the power supply paths 9 and 10 when the current flowing through the power supply paths 9 and 10 exceeds a preset overcurrent determination value.

[0025] The control circuits of the electronic fuses 14 and 15 are configured to turn on or off the switching elements in accordance with commands from the control unit 11, thereby making the power supply paths 9 and 10 conductive or cut off, respectively.

[0026] The slave ECUs 3 and 4 each include a control unit 31, a CAN communication unit 32, and a storage unit 33. The control unit 31 is an electronic control device primarily configured with a microcomputer including a CPU 41, a ROM 42, a RAM 43, and the like. The various functions of the microcomputer are realized by the CPU 41 executing a program stored in a non-transitory physical recording medium. In this example, the ROM 42 corresponds to the non-transitory physical recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 41 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 31 may be one or more.

[0027] The CAN communication unit 32 communicates with a communication device connected to the communication bus 8 based on the CAN communication protocol. The storage unit 33 is a storage device for storing various data.

[0028] A vehicle fault diagnosis device 90 (so-called diagnostic tester) is connected to the master ECU 2. The fault diagnosis device 90 is detachably configured via a connector (not shown) and is connected to the master ECU 2 during fault diagnosis, etc. The fault diagnosis device 90 can obtain various information from the master ECU 2 and the slave ECUs 3 and 4 via the master ECU 2 and can update data stored in the master ECU 2 and the slave ECUs 3 and 4.

[0029] As shown in FIG. 2, the setting table 25 sets, for each of the electronic fuses 14 and 15 included in the vehicle control system 1, an electronic fuse ID and an ECU ID that identifies the ECU to which the fuse is connected.

[0030] In the setting table 25 of this embodiment, the electronic fuse 14 is set to have an electronic fuse ID of "eFuse_1" and an ECU ID of "ECU_A." The electronic fuse 15 is set to have an electronic fuse ID of "eFuse_2" and an ECU ID of "ECU_B."

[0031] Next, the procedure of the ID setting process executed by the control unit 11 of the master ECU 2 will be described. The ID setting process is a process that is repeatedly executed while the master ECU 2 is running. When the ID setting process is executed, the CPU 21 of the control unit 11 determines whether the master ECU 2 is set to the ID setting mode in S10, as shown in FIG. 3. The control unit 11 of the master ECU 2 is configured to set the master ECU 2 to the ID setting mode when it receives an ID setting command from, for example, the fault diagnosis device 90.

[0032] If the master ECU 2 is not in the ID setting mode, the CPU 21 ends the ID setting process. On the other hand, if the master ECU 2 is in the ID setting mode, the CPU 21 sets the electronic fuse indicator value i stored in the RAM 23 to 0 in S20.

[0033] In S30, the CPU 21 increments the electronic fuse indication value i (i.e., adds 1). In S40, the CPU 21 turns on the i-th electronic fuse (i.e., the electronic fuse for which "eFuse_i" is set as the electronic fuse ID).

[0034] In S50, the CPU 21 waits for a preset ith on-state standby time. That is, the CPU 21 waits for the first on-state standby time when the electronic fuse indication value i=1, and waits for the second on-state standby time when the electronic fuse indication value i=2. The first and second on-state standby times are set to be longer than the startup times of the ECUs connected to the electronic fuses 14 and 15, respectively.

[0035] In S60, the CPU 21 extracts the ECU ID corresponding to the i-th electronic fuse from the setting table 25, and transmits the extracted ECU ID from the CAN communication unit 12. That is, the CPU 21 transmits "ECU_A" as the ECU ID when the electronic fuse instruction value i=1, and transmits "ECU_B" as the ECU ID when the electronic fuse instruction value i=2.

[0036] In S70, the CPU 21 receives the i-th reception completion notification via the CAN communication unit 12. The i-th reception completion notification is transmitted from the slave ECU connected to the i-th electronic fuse. Note that, when the slave ECUs 3 and 4 connected to the electronic fuses 14 and 15 receive "ECU_A" and "ECU_B" from the master ECU 2, they store "ECU_A" and "ECU_B" in the storage unit 33, respectively, and then transmit the first and second reception completion notifications to the master ECU 2.

[0037] In S80, the CPU 21 transmits an ith cutoff notification from the CAN communication unit 12, notifying that the ith electronic fuse is to be turned off. In S90, the CPU 21 determines whether or not the ith cutoff permission notification has been received via the CAN communication unit 12. The ith cutoff permission notification is transmitted from the slave ECU connected to the ith electronic fuse. Note that the slave ECUs 3 and 4 connected to the electronic fuses 14 and 15 are configured to transmit the first and second cutoff permission notifications to the master ECU 2 upon receiving the first and second cutoff notifications, respectively.

[0038] If the i-th shutdown permission notification has not been received, the CPU 21 waits until the i-th shutdown permission notification is received by repeating the process of S90. Then, when the i-th shutdown permission notification is received, the CPU 21 turns off the i-th electronic fuse in S100.

[0039] In S110, the CPU 21 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (2 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 21 proceeds to S30.

[0040] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 21 cancels the ID setting mode and ends the ID setting process in S120. The master ECU 2 configured in this manner is configured to set the electronic fuse 14, which is configured to switch between a first conduction state that connects the power supply path 9 that supplies power from the battery 7 to the slave ECU 3 and a first cut-off state that cuts off the power supply path 9, to the first conduction state.

[0041] The master ECU 2 is configured to transmit, to the slave ECU 3, "ECU_A", which is an ECU ID that is preset in association with the electronic fuse 14 and that identifies the slave ECU 3, when a preset first transmission condition is met after the electronic fuse 14 has entered the first conductive state. The first transmission condition in this embodiment is that a preset first on-state standby time has elapsed since the electronic fuse 14 entered the first conductive state.

[0042] After "ECU_A" is transmitted to the slave ECU 3, the master ECU 2 is configured to set the electronic fuse 15, which is configured to switch between a second conductive state that conducts the power supply path 10 that supplies power from the battery 7 to the slave ECU 4 and a second cut-off state that cuts off the power supply path 10, to a second conductive state.

[0043] The master ECU 2 is configured to transmit, when a preset second transmission condition is met after the electronic fuse 15 has entered the second conductive state, "ECU_B", which is an ECU ID preset in association with the electronic fuse 15 and used to identify the slave ECU 4, to the slave ECU 4. The second transmission condition in this embodiment is that a preset second on-state standby time has elapsed since the electronic fuse 15 entered the second conductive state.

[0044] After the slave ECUs 3, 4 are installed in the vehicle, the master ECU 2 can set "ECU_A" and "ECU_B" for each of the slave ECUs 3, 4. This allows the slave ECUs 3, 4 to be equipped with the same software during manufacture if they have the same hardware. Therefore, the master ECU 2 can improve the efficiency of ECU manufacturing.

[0045] The first and second transmission conditions include the lapse of predetermined first and second ON state standby times after the electronic fuses 14 and 15 are turned on, respectively. This allows the master ECU 2 to transmit the ECU ID to the slave ECUs 3 and 4 after power is supplied from the battery 7 to the slave ECUs 3 and 4 and the slave ECUs 3 and 4 are started up.

[0046] Furthermore, the master ECU 2 is configured to set the electronic fuse 14 to a first cutoff state when a preset first cutoff condition is met after "ECU_A" is transmitted to the slave ECU 3. The master ECU 2 is configured to set the electronic fuse 15 to a second cutoff state when a preset second cutoff condition is met after "ECU_B" is transmitted to the slave ECU 4. This allows the master ECU 2 to prevent a situation in which, when transmitting "ECU_B," the slave ECU 3 receives "ECU_B" and "ECU_B" is set in the slave ECU 3.

[0047] Furthermore, the master ECU 2 is configured to transmit a first cutoff notification to the slave ECU 3, notifying the slave ECU 3 that the electronic fuse 14 will be put into the first cutoff state, after transmitting "ECU_A" to the slave ECU 3. The master ECU 2 is configured to transmit a second cutoff notification to the slave ECU 4, notifying the slave ECU 4 that the electronic fuse 15 will be put into the second cutoff state, after transmitting "ECU_B" to the slave ECU 4. The first and second cutoff conditions in this embodiment include receiving preset first and second cutoff permission notifications from the slave ECUs 3 and 4 after transmitting the first and second cutoff notifications to the slave ECUs 3 and 4, respectively. This allows the master ECU 2 to prevent the electronic fuses 14 and 15 from being put into the first or second cutoff state before the slave ECUs 3 and 4 have completed shutdown.

[0048] In the embodiment described above, the master ECU 2 corresponds to the management device and the master control device, the battery 7 corresponds to the power source, the slave ECU 3 corresponds to the first control device, the electronic fuse 14 corresponds to the first power supply switching unit and the power supply switching unit, and the power supply path 9 corresponds to the first power supply path.

[0049] Furthermore, the slave ECU 4 corresponds to a second control device, the electronic fuse 15 corresponds to a second power supply switching unit and a power supply switching unit, the power supply path 10 corresponds to a second power supply path, and the vehicle control system 1 corresponds to a management system.

[0050] Furthermore, "ECU_A" corresponds to the first identification information, and "ECU_B" corresponds to the second identification information. Furthermore, S40 corresponds to the processing performed by the first and second conduction units, and S60 corresponds to the processing performed by the first and second identification information transmission units.

[0051] In addition, the first on state waiting time corresponds to the first conduction waiting time, the second on state waiting time corresponds to the second conduction waiting time, S100 corresponds to processing as the first blocking unit and the second blocking unit, and S80 corresponds to processing as the first blocking notification unit and the second blocking notification unit.

[0052] Second Embodiment A second embodiment of the present disclosure will be described below with reference to the drawings. In the second embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.

[0053] The vehicle control system 1 of the second embodiment differs from the first embodiment in that the ID setting process is changed. As shown in FIG. 4, the ID setting process of the second embodiment differs from the first embodiment in that the process of S52 is executed instead of S50 and that the process of S92 is added.

[0054] That is, when the process of S40 is completed, the CPU 21 determines in S52 whether or not an ID setting request has been received via the CAN communication unit 12. The slave ECUs 3 and 4 connected to the electronic fuses 14 and 15 are configured to transmit an ID setting request to the master ECU 2 when they are powered by the battery 7 and activated.

[0055] If an ID setting request has not been received, the CPU 21 repeats the process of S52 to wait until an ID setting request is received. When an ID setting request is received, the CPU 21 proceeds to S60.

[0056] Furthermore, when permission to shut off is received in S90, the CPU 21 waits for a preset i-th off state standby time in S92, and then proceeds to S100. That is, the CPU 21 waits for the first off state standby time when the electronic fuse indication value i=1, and waits for the second off state standby time when the electronic fuse indication value i=2. The first and second off state standby times are set so as to be longer than the time it takes for the ECUs connected to the electronic fuses 14 and 15 to complete shutdown.

[0057] In the master ECU 2 configured in this manner, the first and second transmission conditions include receiving a preset ID setting request from the slave ECUs 3 and 4, which indicates that the slave ECUs 3 and 4 are in a state where they can receive an ECU ID, after the electronic fuses 14 and 15 have entered the first and second conductive states, respectively. This allows the master ECU 2 to transmit the ECU ID to the slave ECUs 3 and 4 after power from the battery 7 is supplied to the slave ECUs 3 and 4 and the slave ECUs 3 and 4 have started up.

[0058] Furthermore, the first and second cutoff conditions in this embodiment each include the elapse of a preset first and second off state standby time after the master ECU 2 receives a first and second cutoff permission notice from the slave ECUs 3 and 4 after transmitting the first and second cutoff notices to the slave ECUs 3 and 4. This allows the master ECU 2 to prevent the electronic fuses 14 and 15 from entering the first and second cutoff states before the slave ECUs 3 and 4 complete shutdown.

[0059] In the embodiment described above, the ID setting request sent by the slave ECU 3 corresponds to the first reception permission information, the ID setting request sent by the slave ECU 4 corresponds to the second reception permission information, the first off state waiting time corresponds to the first shut-off waiting time, and the second off state waiting time corresponds to the second shut-off waiting time.

[0060] Third Embodiment A third embodiment of the present disclosure will be described below with reference to the drawings. In the third embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.

[0061] As shown in FIG. 5, the vehicle control system 1 of the third embodiment differs from the first embodiment in that a slave ECU 5, a smart sensor 501, a smart actuator 502, a wireless device 503, and electronic fuses 504 and 505 are added.

[0062] The slave ECU 5 operates by receiving power supply from a battery 7. Like the slave ECUs 3 and 4, the slave ECU 5 includes a control unit 31, a CAN communication unit 32, and a storage unit 33.

[0063] The CAN communication unit 32 of the slave ECU 5 is connected to the CAN communication unit 12 of the master ECU 2 via the communication bus 8. Therefore, the master ECU 2 and the slave ECUs 3, 4, and 5 are connected via the communication bus 8 so as to be able to communicate data with each other.

[0064] The smart sensor 501 is a sensor equipped with a communication function. The smart sensor 501 is connected to the communication bus 8. The smart actuator 502 is an actuator equipped with a communication function. The smart actuator 502 is connected to the communication bus 8.

[0065] The radio 503 is a wireless communication device for performing wireless communication with an external communication device installed outside the vehicle. The radio 503 is, for example, a DCM. DCM is an abbreviation for Data Communication Module.

[0066] The electronic fuse 504 is disposed on the power supply path between the battery 7 and the smart sensor 501. The electronic fuse 505 is disposed on the power supply path between the battery 7 and the smart actuator 502.

[0067] Each of the electronic fuses 504 and 505 is configured to switch between a conductive state in which the power supply path is connected and a cut-off state in which the power supply path is cut off in accordance with a command from the control unit 11 .

[0068] Hereinafter, the master ECU 2, slave ECUs 3 to 5, smart sensor 501, and smart actuator 502 are collectively referred to as nodes. A CAN frame is composed of a start-of-frame, arbitration field, control field, data field, CRC field, ACK field, and end-of-frame. The arbitration field is composed of an 11-bit or 29-bit identifier (i.e., ID) and a 1-bit RTR bit.

[0069] The 11-bit identifier used in CAN communication is called a CAN ID. The CAN ID is set in advance based on the content of the data included in the CAN frame, the source of the CAN frame, the destination of the CAN frame, etc.

[0070] The data field is a payload consisting of first data, second data, third data, fourth data, fifth data, sixth data, seventh data, and eighth data, each of which is 8 bits (i.e., 1 byte).

[0071] The vehicle control system 1 forms a partial network, which is a power supply control method based on communication control of the CAN protocol standard specified in ISO 11898-6. For this reason, the vehicle control system 1 achieves low power consumption by individually transitioning one or more nodes belonging to each communication group (described later) into a wake-up state (i.e., an active state) or a sleep state (i.e., a dormant state) for each communication group. By waking up, a node enters a normal operating state in which the functions assigned to the node can be used without any restrictions, and by sleeping, it enters a low-power operating state in which the available functions are limited.

[0072] In the vehicle control system 1, when waking up a node in a sleep state, an NM frame, which is a CAN frame including activation information that specifies an activation group, is used. NM is an abbreviation for Network Management.

[0073] The activation information is set, for example, as shown in FIG. 6 . DLC stands for Data Length Code, and is an area that represents the size of the data field in a CAN frame in bytes. That is, the activation information is stored in the data field of the CAN frame. For simplicity of explanation, the DLC is shown here as being 1 byte (i.e., 8 bits). Each bit of the 8-bit data representing the activation information is associated with an activation group.

[0074] In the activation information set in the NM frame, a bit corresponding to the activation group to be activated is set to 1. Each node stores affiliation information indicating the activation group to which the node belongs. The affiliation information has the same data length as the activation information, and the allocation of each bit is also the same as that of the activation information. In the affiliation information, a bit corresponding to the activation group to which the node belongs is set to 1.

[0075] Each node compares the activation information extracted from the NM frame with the belonging information stored in the node itself to determine whether the communication group to which the node itself belongs is an activation target.

[0076] For example, the affiliation information shown in Fig. 6 indicates that the node belongs to the first communication group, the third communication group, and the fifth communication group. The activation information shown in Fig. 6 indicates that the second communication group, the third communication group, the fourth communication group, and the fifth communication group are to be activated. Since the third communication group and the fifth communication group are included in both the affiliation information and the activation information shown in Fig. 6, the node determines that the node is to be activated as the third communication group and the fifth communication group.

[0077] 5, the storage unit 13 stores a management table 29. The management table 29 may be stored in the ROM 22 or the RAM 23. The management table 29 sets, for each of a plurality of communication groups, a correspondence relationship between the communication group and one or more nodes belonging to the corresponding communication group (i.e., one or more nodes to be started).

[0078] The management table 29 sets, for example, that the master ECU 2 and the slave ECUs 3 and 4 belong to a first communication group, and the management table 29 sets, for example, that the slave ECUs 3, 4, and 5 belong to a second communication group.

[0079] Furthermore, when the master ECU 2 and the slave ECUs 3 to 5 detect that the start conditions for each of a plurality of events have been met, they are configured to generate and transmit an NM frame containing information indicating the communication group involved in the corresponding event as the above-mentioned start information.

[0080] (Prerequisites) The master ECU 2 and the slave ECU 5 are always powered by the battery 7 without using electronic fuses, and can independently switch between a wake-up state and a sleep state. Hereinafter, the master ECU 2 and the slave ECU 5 are also referred to as NM-equipped nodes. An NM-equipped node is a node that has the function of generating an NM frame.

[0081] The slave ECUs 3 and 4, smart sensor 501, and smart actuator 502 are powered via electronic fuses and cannot switch to a wake-up state or a sleep state by themselves. That is, they enter a wake-up state when the electronic fuse is turned on, and enter a sleep state when the electronic fuse is turned off. Hereinafter, the slave ECUs 3 and 4, smart sensor 501, and smart actuator 502 are also referred to as NM-non-equipped nodes. An NM-non-equipped node is a node that does not have the function of generating and interpreting NM frames.

[0082] The non-NM nodes include at least one of an actuator and a sensor in addition to an ECU having a control function. The power supply paths of the non-NM nodes are connected to the electronic fuses 14, 15, 504, and 505 of the master ECU 2, respectively.

[0083] The non-NM-equipped node and the electronic fuse may be connected one-to-one, or multiple non-NM-equipped nodes belonging to the same cluster (i.e., a group that activates simultaneously) may be connected under one electronic fuse.

[0084] The master ECU 2 and the NM-equipped node have a communication function and can send and receive NM frames. The NM-equipped node determines whether the node is in a wake-up state or a sleep state based on the NM frames sent and received via the communication bus.

[0085] The master ECU 2 turns on or off the electronic fuses 14, 15, 504, and 505 to which the NM non-mounted nodes are connected, based on the NM frame transmitted and received via the communication bus.

[0086] The payload (i.e., data area) of the NM frame transmitted and received by the master ECU 2 and the NM-equipped node stores one or more bits of information indicating which cluster to activate.

[0087] One or more master ECUs (i.e., ECUs with built-in electronic fuses) are installed in a vehicle. As shown in FIG. 7, one or more nodes belonging to each cluster are determined in advance by the system developer. Although it is possible to assign a cluster to each node, multiple nodes can be registered in one cluster. When the bit corresponding to each cluster is active (i.e., bit = 1), the cluster wakes up. In the case of a master ECU, waking up means turning on the electronic fuse.

[0088] (First Activation Example) The first activation example is an operation example in which a fault diagnosis of the slave ECU 3 is performed in response to a request from the cloud.

[0089] First, a connection request is sent from the base station (i.e., the cloud) to the vehicle's radio 503. Next, if the radio 503 determines that the connection is valid, it notifies the master ECU 2 of the event received from the cloud.

[0090] Next, the master ECU 2 determines the service "fault diagnosis of the slave ECU 3" based on the event, and generates an NM frame in which the bit of the third cluster to which only the slave ECU 3 belongs is enabled in order to activate the slave ECU 3.

[0091] Next, the master ECU 2 transmits the generated NM frame onto the communication bus 8. Since there are no NM-equipped nodes belonging to the third cluster on the communication bus 8, there is no change in the devices on the communication bus.

[0092] Next, the master ECU 2 simultaneously receives an NM frame that enables the bit of the third cluster, and executes processing based on the NM frame in the control unit 11. Next, the control unit 11 of the master ECU 2 determines a wake-up instruction for the third cluster based on the NM frame, and turns on the electronic fuse 14 because the third cluster includes the electronic fuse 14.

[0093] When the electronic fuse 14 is turned on, power is supplied to the downstream slave ECU 3, which then starts up. The master ECU 2 waits for the slave ECU 3 to start up, then requests a diagnostic code from the slave ECU 3, and transmits the response from the slave ECU 3 to the base station via the wireless device 503.

[0094] (Second Activation Example) The second activation example is an operation example in which a fault diagnosis of the slave ECU 5 is performed in response to a request from the cloud.

[0095] First, a connection request is sent from the base station (i.e., the cloud) to the vehicle's radio 503. Next, if the radio 503 determines that the connection is valid, it notifies the master ECU 2 of the event received from the cloud.

[0096] Next, the master ECU 2 determines the service "fault diagnosis of the slave ECU 5" based on the event, and generates an NM frame in which the bit of the fourth cluster to which only the slave ECU 5 belongs is enabled in order to activate the slave ECU 5.

[0097] Next, the master ECU 2 transmits the generated NM frame onto the communication bus 8. Since the slave ECU 5 exists on the communication bus 8 as a node belonging to the fourth cluster, the slave ECU 5 wakes up.

[0098] Next, the master ECU 2 simultaneously receives an NM frame that enables the bit of the fourth cluster, and executes processing based on the NM frame in the control unit 11. Next, even if the control unit 11 of the master ECU 2 determines a wake-up instruction for the fourth cluster based on the NM frame, it ignores it because the fourth cluster does not contain the corresponding electronic fuse.

[0099] When the slave ECU 5 is activated, the master ECU 2 requests a diagnostic code from the slave ECU 5 via the communication bus 8 and transmits the response from the slave ECU 5 to the base station via the wireless device 503 .

[0100] (Third Activation Example) The third activation example is an example of an operation in which a user activates remote air conditioning using a smartphone. First, the user issues a command to turn on the in-vehicle air conditioner using the smartphone.

[0101] When the wireless device 503 receives the instruction signal from the smartphone and determines that the instruction signal is valid, it transmits the event (i.e., the instruction signal) received from the cloud to the master ECU 2 .

[0102] The master ECU 2 determines the "air conditioning service" based on the event and generates an NM frame that activates the second cluster as the air conditioning cluster. The master ECU 2 periodically transmits the generated NM frame to the communication bus 8 until an instruction to stop the air conditioner is issued. If the master ECU 2 wants to maintain the active state, it must continue to periodically transmit the NM frame. At the same time, the control unit 11 of the master ECU 2 executes processing based on the NM frame.

[0103] When an NM frame that activates the second cluster occurs on the communication bus 8, the slave ECU 5 (i.e., the air conditioner ECU) belonging to the second cluster receives the NM frame and wakes up in accordance with the received NM frame.

[0104] When the control unit 11 of the master ECU 2 detects that the second cluster is active, it turns on the electronic fuses 504 and 505 that belong to the second cluster. When the electronic fuses 504 and 505 are turned on, power is supplied to the smart sensor 501 (i.e., the temperature sensor) and the smart actuator 502 (i.e., the compressor).

[0105] As a result, power supply to the air conditioner ECU, smart sensor 501, and smart actuator 502 begins, making it possible to turn on the in-vehicle air conditioner. If the user issues a command to turn off the in-vehicle air conditioner from the smartphone, the master ECU 2 stops the periodic transmission of NM frames.

[0106] When the NM frame is interrupted, the slave ECU 5 transitions to a sleep state, and the master ECU 2 turns off the electronic fuse 504 and the electronic fuse 505. This stops the in-vehicle air conditioner.

[0107] (Fourth Activation Example) The fourth activation example is an operation example in which an in-vehicle air conditioner is activated from the slave ECU 5. Since the slave ECU 5 is always supplied with power even when the vehicle is stopped, it is possible to wake up the slave ECU 5 even in the sleep mode by detecting the input of a signal indicating that a activation switch connected to the slave ECU 5 has been turned on.

[0108] When the woken-up slave ECU 5 detects an input to start the in-vehicle air conditioner, it generates an NM frame with the bit corresponding to the second cluster turned on. The slave ECU 5 transmits the generated NM frame via the CAN communication unit 32. When the master ECU 2 receives this NM frame, the master ECU 2 turns on the electronic fuses 504 and 505 belonging to the second cluster.

[0109] When the start switch of the vehicle air conditioner is turned off, the slave ECU 5 stops transmitting NM frames and enters a sleep state after a while. When the NM frames are discontinued, the master ECU 2 turns off the electronic fuses 504 and 505 after a while and ends control.

[0110] If the master ECU 2 determines that control must continue even after the transmission of the NM frame has stopped, the master ECU 2 transmits an NM frame with the bit corresponding to the second cluster turned on, which allows the slave ECU 5 and the electronic fuses 504 and 505 to remain activated until the transmission of the NM frame generated by the master ECU 2 has stopped.

[0111] Fourth Embodiment A fourth embodiment of the present disclosure will be described below with reference to the drawings. In the fourth embodiment, differences from the first embodiment will be described. The same reference numerals will be used to designate common components.

[0112] A vehicle control system 100 of the fourth embodiment is mounted on a vehicle and includes, as shown in FIG. 8 , a central ECU 101, upstream power distribution units 102 and 103, zone ECUs 104, 105, 106, and 107, slave ECUs 108, 109, 110, 111, 112, 113, 114, 115, and 116, a battery 117, and a slave ECU 118. Hereinafter, the central ECU 101, zone ECUs 104 to 107, and slave ECUs 108 to 116 and 118 will also be collectively referred to as nodes. Hereinafter, the zone ECU may be an ECU that bundles slave ECUs located in a predetermined area within the vehicle, or an ECU that bundles slave ECUs belonging to a predetermined domain.

[0113] The battery 117 supplies power to each part of the vehicle at a DC battery voltage (for example, 12 V). The central ECU 101, the upstream power distribution units 102 and 103, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118 operate by receiving power from the battery 117.

[0114] The upstream power distribution unit 102 receives power from the battery 117 via a power supply path 121 between the battery 117 and the upstream power distribution unit 102. The upstream power distribution unit 103 receives power from the battery 117 via a power supply path 122 between the battery 117 and the upstream power distribution unit 103.

[0115] The zone ECUs 104 and 105 receive power from the battery 117 via power supply paths 123 and 124 between the upstream power distribution unit 102 and the zone ECUs 104 and 105, respectively.

[0116] The zone ECUs 106 and 107 receive power from the battery 117 via power supply paths 125 and 126 between the upstream power distribution unit 103 and the zone ECUs 106 and 107, respectively.

[0117] The slave ECUs 108 and 109 receive power from the battery 117 via power supply paths 127 and 128 between the zone ECU 104 and the slave ECUs 108 and 109, respectively.

[0118] The slave ECUs 110 and 111 receive power from the battery 117 via power supply paths 129 and 130 between the zone ECU 105 and the slave ECUs 110 and 111, respectively.

[0119] The slave ECUs 112, 113, and 114 receive power from the battery 117 via power supply paths 131, 132, and 133 between the zone ECU 106 and the slave ECUs 112, 113, and 114, respectively.

[0120] The slave ECUs 115 and 116 receive power from the battery 117 via power supply paths 134 and 135 between the zone ECU 107 and the slave ECUs 115 and 116, respectively.

[0121] The slave ECU 118 receives power supply from the battery 117 via a power supply path 136. The central ECU 101 and the upstream power distribution unit 102 are connected to each other via a communication line 141 so as to be able to communicate data with each other.

[0122] The central ECU 101 and the upstream power distribution unit 103 are connected to each other via a communication line 142 so as to be able to communicate data with each other. The central ECU 101 and the zone ECUs 104, 105, 106, and 107 are connected to each other via communication lines 143, 144, 145, and 146 so as to be able to communicate data with each other, respectively.

[0123] The zone ECU 104 and the slave ECUs 108, 109, and 118 are connected to each other via a communication bus 147 so as to be able to communicate data with each other. The zone ECU 105 and the slave ECUs 110 and 111 are connected to each other via a communication bus 148 so as to be able to communicate data with each other.

[0124] The zone ECU 106 and the slave ECUs 112, 113, and 114 are connected to each other via a communication bus 149 so as to be able to communicate data with each other. The zone ECU 107 and the slave ECUs 115 and 116 are connected to each other via a communication bus 150 so as to be able to communicate data with each other.

[0125] As shown in FIG. 9 , the central ECU 101 includes a control unit 151, communication units 152, 153, 154, 155, 156, and 157, and a storage unit 158. The control unit 151 is an electronic control device primarily configured with a microcomputer including a CPU 161, a ROM 162, and a RAM 163. The CPU 161 executes programs stored in a non-transitory storage medium to realize various functions of the microcomputer. In this example, the ROM 162 corresponds to the non-transitory storage medium storing the programs. Furthermore, the execution of the programs results in the execution of methods corresponding to the programs. Note that some or all of the functions executed by the CPU 161 may be implemented in hardware using one or more integrated circuits (ICs). The control unit 151 may include one or more microcomputers.

[0126] The communication unit 152 communicates with the upstream power distribution unit 102 connected to the communication line 141 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol. Ethernet is a registered trademark.

[0127] The communication unit 153 communicates with the upstream power distribution unit 103 connected to the communication line 142 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol. The communication unit 154 communicates with the zone ECU 104 connected to the communication line 143 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0128] The communication unit 155 communicates with the zone ECU 105 connected to the communication line 144 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol. The communication unit 156 communicates with the zone ECU 106 connected to the communication line 145 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0129] The communication unit 157 communicates with the zone ECU 107 connected to the communication line 145 by sending and receiving communication frames based on, for example, the Ethernet communication protocol. The memory unit 158 ​​is a storage device for storing various data. The memory unit 158 ​​stores a startup table 165, which will be described later.

[0130] The upstream power supply distribution unit 102 includes a control circuit 171, a communication unit 172, and electronic fuses 173 and 174. The control circuit 171 controls the electronic fuses 173 and 174 to switch between an on state and an off state based on an instruction received from the central ECU 101 via the communication unit 172.

[0131] The communication unit 172 communicates with the central ECU 101 connected to the communication line 141 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0132] The electronic fuse 173 is disposed between the power supply path 121 and the power supply path 123. The electronic fuse 174 is disposed between the power supply path 121 and the power supply path 124. The upstream power distribution unit 103 includes a control circuit 181, a communication unit 182, and electronic fuses 183 and 184.

[0133] The control circuit 181 controls the electronic fuses 183 and 184 to switch between an on state and an off state based on an instruction received from the central ECU 101 via the communication unit 182 .

[0134] The communication unit 182 communicates with the central ECU 101 connected to the communication line 142 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0135] Electronic fuse 183 is disposed between power supply path 122 and power supply path 125. Electronic fuse 184 is disposed between power supply path 122 and power supply path 126. As shown in FIG. 10 , zone ECU 104 includes a control unit 191, a communication unit 192, a CAN communication unit 193, a memory unit 194, and electronic fuses 195 and 196.

[0136] The control unit 191 is an electronic control device mainly composed of a microcomputer including a CPU 201, a ROM 202, a RAM 203, etc. Various functions of the microcomputer are realized by the CPU 201 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 202 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 201 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 191 may be one or more.

[0137] The communication unit 192 communicates with the central ECU 101 connected to the communication line 143 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0138] The CAN communication unit 193 communicates with the slave ECUs 108 and 109 connected to the communication bus 147 by transmitting and receiving communication frames based on the CAN communication protocol.

[0139] The storage unit 194 is a storage device for storing various data. The electronic fuse 195 is disposed between the power supply path 123 and the power supply path 127. The electronic fuse 196 is disposed between the power supply path 123 and the power supply path 128.

[0140] The zone ECU 105 includes a control unit 211, a communication unit 212, a CAN communication unit 213, a storage unit 214, and electronic fuses 215 and 216. The control unit 211 is an electronic control device primarily configured with a microcomputer including a CPU 221, a ROM 222, a RAM 223, and the like. The various functions of the microcomputer are realized by the CPU 221 executing a program stored in a non-transitory storage medium. In this example, the ROM 222 corresponds to the non-transitory storage medium storing the program. Furthermore, the execution of this program executes a method corresponding to the program. Note that some or all of the functions executed by the CPU 221 may be configured as hardware using one or more integrated circuits (ICs), etc. Furthermore, the control unit 211 may include one or more microcomputers.

[0141] The communication unit 212 communicates with the central ECU 101 connected to the communication line 144 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0142] The CAN communication unit 213 communicates with the slave ECUs 110 and 111 connected to the communication bus 148 by transmitting and receiving communication frames based on the CAN communication protocol.

[0143] The storage unit 214 is a storage device for storing various data. The electronic fuse 215 is disposed between the power supply path 124 and the power supply path 129. The electronic fuse 216 is disposed between the power supply path 124 and the power supply path 130.

[0144] As shown in FIG. 11 , the zone ECU 106 includes a control unit 231, a communication unit 232, a CAN communication unit 233, a storage unit 234, and electronic fuses 235, 236, and 237. The control unit 231 is an electronic control device primarily configured with a microcomputer including a CPU 241, a ROM 242, and a RAM 243. The various functions of the microcomputer are realized by the CPU 241 executing a program stored in a non-transitory storage medium. In this example, the ROM 242 corresponds to the non-transitory storage medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 241 may be implemented in hardware using one or more integrated circuits (ICs). The control unit 231 may include one or more microcomputers.

[0145] The communication unit 232 communicates with the central ECU 101 connected to the communication line 145 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0146] The CAN communication unit 233 communicates with the slave ECUs 112, 113, and 114 connected to the communication bus 149 by transmitting and receiving communication frames based on the CAN communication protocol.

[0147] The memory unit 234 is a storage device for storing various data. The electronic fuse 235 is arranged between the power supply path 125 and the power supply path 131. The electronic fuse 236 is arranged between the power supply path 125 and the power supply path 132. The electronic fuse 237 is arranged between the power supply path 125 and the power supply path 133.

[0148] The zone ECU 107 includes a control unit 251, a communication unit 252, a CAN communication unit 253, a storage unit 254, and electronic fuses 255 and 256. The control unit 251 is an electronic control device primarily configured with a microcomputer including a CPU 261, a ROM 262, a RAM 263, and the like. The various functions of the microcomputer are realized by the CPU 261 executing a program stored in a non-transitory storage medium. In this example, the ROM 262 corresponds to the non-transitory storage medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 261 may be configured as hardware using one or more integrated circuits (ICs), etc. Furthermore, the control unit 251 may include one or more microcomputers.

[0149] The communication unit 252 communicates with the central ECU 101 connected to the communication line 146 by transmitting and receiving communication frames based on, for example, the Ethernet communication protocol.

[0150] The CAN communication unit 253 communicates with the slave ECUs 115 and 116 connected to the communication bus 150 by transmitting and receiving communication frames based on the CAN communication protocol.

[0151] The storage unit 254 is a storage device for storing various data. The electronic fuse 255 is disposed between the power supply path 126 and the power supply path 134. The electronic fuse 256 is disposed between the power supply path 126 and the power supply path 135.

[0152] As shown in FIG. 12 , the slave ECUs 108, 109, and 118 each include a control unit 271, a CAN communication unit 272, and a storage unit 273. The control unit 271 is an electronic control device primarily configured with a microcomputer including a CPU 281, a ROM 282, a RAM 283, and the like. The various functions of the microcomputer are realized by the CPU 281 executing a program stored in a non-transitory storage medium. In this example, the ROM 282 corresponds to the non-transitory storage medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 281 may be configured as hardware using one or more ICs, etc. Furthermore, the control unit 271 may include one or more microcomputers.

[0153] The CAN communication unit 272 communicates with the zone ECUs 104 connected to the communication bus 147 based on the CAN communication protocol. The storage unit 273 is a storage device for storing various data.

[0154] The slave ECUs 110 and 111 each include a control unit 291, a CAN communication unit 292, and a storage unit 293. The control unit 291 is an electronic control device primarily configured with a microcomputer including a CPU 301, a ROM 302, a RAM 303, and the like. Various functions of the microcomputer are realized by the CPU 301 executing a program stored in a non-transitory physical recording medium. In this example, the ROM 302 corresponds to the non-transitory physical recording medium storing the program. Furthermore, execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 301 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 291 may be one or more.

[0155] The CAN communication unit 292 communicates with the zone ECUs 105 connected to the communication bus 148 based on the CAN communication protocol. The storage unit 293 is a storage device for storing various data.

[0156] Each of the slave ECUs 112, 113, and 114 includes a control unit 311, a CAN communication unit 312, and a storage unit 313. The control unit 311 is an electronic control device primarily configured with a microcomputer including a CPU 321, a ROM 322, a RAM 323, and the like. The various functions of the microcomputer are realized by the CPU 321 executing a program stored in a non-transitory physical recording medium. In this example, the ROM 322 corresponds to the non-transitory physical recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 321 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 311 may be one or more.

[0157] The CAN communication unit 312 communicates with the zone ECU 106 connected to the communication bus 149 based on the CAN communication protocol. The storage unit 313 is a storage device for storing various data.

[0158] The slave ECUs 115 and 116 each include a control unit 331, a CAN communication unit 332, and a storage unit 333. The control unit 331 is an electronic control device primarily configured with a microcomputer including a CPU 341, a ROM 342, a RAM 343, and the like. The various functions of the microcomputer are realized by the CPU 341 executing a program stored in a non-transitory physical recording medium. In this example, the ROM 342 corresponds to the non-transitory physical recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 341 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 331 may be one or more.

[0159] The CAN communication unit 332 communicates with the zone ECUs 107 connected to the communication bus 150 based on the CAN communication protocol. The storage unit 333 is a storage device for storing various types of data.

[0160] 13, the activation table 165 of the central ECU 101 has a communication group (i.e., an activation group) to be activated for each event. The activation table 165 also has a correspondence between the activation group and the slave ECU to be put into a wake-up state. The activation table 165 also has a correspondence between the slave ECU and the electronic fuse connected to the slave ECU. The activation table 165 may be set in a manner that indicates the correspondence between the zone ECU under which the slave ECU is located.

[0161] When the central ECU 101 detects the occurrence of an event, it determines an activation group based on the detected event by referring to the activation table 165. When the central ECU 101 receives an NM frame, it determines that the communication group corresponding to a bit set to 1 in the received NM frame is the activation group.

[0162] The central ECU 101 starts a process of transmitting an NM frame indicating an activation group determined upon detection of an event occurrence or reception of an NM frame to the zone ECUs 104, 105, 106, and 107. After starting transmission of the NM frame, the central ECU 101 thereafter periodically transmits the same NM frame.

[0163] By referring to the activation table 165, the central ECU 101 instructs the electronic fuses corresponding to the activation group determined due to the detection of the occurrence of an event or the reception of an NM frame to be turned on, and transmits an electronic fuse control instruction to the upstream power distribution units 102, 103 and the zone ECUs 104, 105, 106, and 107 to turn off electronic fuses other than the electronic fuses corresponding to the activation group.

[0164] The upstream power distribution unit 102 turns on or off the electronic fuses 173 and 174 based on the received electronic fuse control instruction. The upstream power distribution unit 103 turns on or off the electronic fuses 183 and 184 based on the received electronic fuse control instruction.

[0165] Based on the received electronic fuse control instruction, the zone ECU 104 turns on or off the electronic fuses 195 and 196. Based on the received electronic fuse control instruction, the zone ECU 105 turns on or off the electronic fuses 215 and 216.

[0166] Based on the received electronic fuse control instruction, the zone ECU 106 turns on or off the electronic fuses 235, 236, and 237. Based on the received electronic fuse control instruction, the zone ECU 107 turns on or off the electronic fuses 255 and 256.

[0167] The fault diagnosis device 90 of the first embodiment is connected to the central ECU 101. The fault diagnosis device 90 is configured to be detachable via a connector (not shown) and is connected to the central ECU 101 during fault diagnosis, etc. The fault diagnosis device 90 can acquire various information from the central ECU 101, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118 via the central ECU 101, and can update data stored in the central ECU 101, the zone ECUs 104 to 107, and the slave ECUs 108 to 116 and 118.

[0168] 9, the storage unit 158 ​​of the central ECU 101 stores a setting table 167. As shown in FIG. 14, the setting table 167 sets, for each of the plurality of electronic fuses 195, 196 provided in the vehicle control system 100, an electronic fuse ID and an ECU ID that identifies the ECU to which the fuse is connected.

[0169] In the setting table 167 of this embodiment, "eFuse_1" is set as the electronic fuse ID and "ECU_A" is set as the ECU ID for the electronic fuse 195. "ECU_A" is the ECU ID corresponding to the slave ECU 108.

[0170] For the electronic fuse 196, "eFuse_2" is set as the electronic fuse ID, and "ECU_B" is set as the ECU ID. "ECU_B" is the ECU ID corresponding to the slave ECU 109.

[0171] The slave ECU 108 is, for example, an electronic control unit that controls the driver's door, and the slave ECU 109 is, for example, an electronic control unit that controls the passenger's door. Therefore, the slave ECU 108 and the slave ECU 109 are equipped with common software for door control. In other words, the slave ECU 108 and the slave ECU 109 are configured to be operable regardless of whether they are set as "ECU_A" or "ECU_B."

[0172] Next, a description will be given of the procedure of the ID setting process executed by the control unit 151 of the central ECU 101. The ID setting process is a process that is repeatedly executed while the central ECU 101 is running.

[0173] When the ID setting process is executed, the CPU 161 of the control unit 151 determines whether the central ECU 101 is set to the ID setting mode in S210 as shown in Fig. 15. When the control unit 151 of the central ECU 101 receives an ID setting command from, for example, the fault diagnosis device 90, the control unit 151 sets the central ECU 101 to the ID setting mode.

[0174] If the central ECU 101 is not set to the ID setting mode, the CPU 161 ends the ID setting process. On the other hand, if the central ECU 101 is set to the ID setting mode, the CPU 161 sets the electronic fuse indication value i stored in the RAM 163 to 0 in S220.

[0175] In S230, the CPU 161 increments the electronic fuse indication value i (i.e., adds 1). In S240, the CPU 161 turns on the i-th electronic fuse (i.e., the electronic fuse for which "eFuse_i" is set as the electronic fuse ID).

[0176] In S250, the CPU 161 waits for a preset ith on-state standby time. That is, the CPU 161 waits for the first on-state standby time when the electronic fuse indication value i=1, and waits for the second on-state standby time when the electronic fuse indication value i=2. The first and second on-state standby times are set to be longer than the startup times of the ECUs connected to the electronic fuses 14 and 15, respectively.

[0177] In S260, the CPU 161 extracts the ECU ID corresponding to the i-th electronic fuse from the setting table 25, and transmits the extracted ECU ID from the CAN communication unit 12. That is, the CPU 161 transmits "ECU_A" as the ECU ID when the electronic fuse instruction value i=1, and transmits "ECU_B" as the ECU ID when the electronic fuse instruction value i=2.

[0178] In S270, the CPU 161 receives the i-th reception completion notification via the communication unit 154. The i-th reception completion notification is transmitted from the slave ECU connected to the i-th electronic fuse. Note that the slave ECUs 108 and 109 connected to the electronic fuses 195 and 196 are configured to store "ECU_A" and "ECU_B" in the storage unit 273, respectively, upon receiving "ECU_A" and "ECU_B" from the central ECU 101, and then transmit the first and second reception completion notifications to the central ECU 101.

[0179] In S280, the CPU 161 transmits an ith cutoff notification from the communication unit 154, notifying the central ECU 101 that the ith electronic fuse will be turned off. In S290, the CPU 161 determines whether or not the ith cutoff permission notification has been received via the communication unit 154. The ith cutoff permission notification is transmitted from the slave ECU connected to the ith electronic fuse. Note that the slave ECUs 108 and 109 connected to the electronic fuses 195 and 196 are configured to transmit the first and second cutoff permission notifications to the central ECU 101 upon receiving the first and second cutoff notifications, respectively.

[0180] If the i-th shutdown permission notification has not been received, the CPU 161 waits until the i-th shutdown permission notification is received by repeating the process of S290. Then, when the i-th shutdown permission notification is received, the CPU 161 turns off the i-th electronic fuse in S300.

[0181] In S310, the CPU 161 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (2 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 161 proceeds to S230.

[0182] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 161 cancels the ID setting mode in S320 and ends the ID setting process. The central ECU 101 configured in this manner is configured to set the electronic fuse 195, which is configured to switch between a first conduction state that connects the power supply path 127 that supplies power from the battery 117 to the slave ECU 108 and a first cut-off state that cuts off the power supply path 127, to the first conduction state.

[0183] The central ECU 101 is configured to transmit, to the slave ECU 108, "ECU_A", which is an ECU ID that is preset in association with the electronic fuse 195 and that identifies the slave ECU 108, when a preset first transmission condition is met after the electronic fuse 195 has entered the first conductive state. The first transmission condition in this embodiment is that a preset first on-state standby time has elapsed since the electronic fuse 195 entered the first conductive state.

[0184] After "ECU_A" is transmitted to the slave ECU 108, the central ECU 101 is configured to set the electronic fuse 196, which is configured to switch between a second conductive state that conducts the power supply path 128 that supplies power from the battery 117 to the slave ECU 109 and a second cut-off state that cuts off the power supply path 128, to a second conductive state.

[0185] The central ECU 101 is configured to transmit, to the slave ECU 109, "ECU_B", which is an ECU ID that is preset in association with the electronic fuse 196 and that identifies the slave ECU 109, when a preset second transmission condition is met after the electronic fuse 196 has entered the second conductive state. The second transmission condition in this embodiment is that a preset second on-state standby time has elapsed since the electronic fuse 196 entered the second conductive state.

[0186] After the slave ECUs 108, 109 are installed in the vehicle, the central ECU 101 can set "ECU_A" and "ECU_B" for each of the slave ECUs 108, 109. This allows the slave ECUs 108, 109 to be equipped with the same software during their manufacture if they have the same hardware. Therefore, the central ECU 101 can improve the efficiency of ECU manufacturing.

[0187] In the embodiment described above, the central ECU 101 corresponds to the management device and the second integrated control device, the battery 117 corresponds to the power source, the slave ECU 108 corresponds to the first control device, the electronic fuse 195 corresponds to the first power supply switching unit and the power supply switching unit, and the power supply path 127 corresponds to the first power supply path.

[0188] In addition, the slave ECU 109 corresponds to the second control device, the electronic fuse 196 corresponds to the second power supply switching unit and the power supply switching unit, the power supply path 128 corresponds to the second power supply path, the zone ECU 104 corresponds to the first integrated control device, and the vehicle control system 100 corresponds to the management system.

[0189] Furthermore, S240 corresponds to processing as the first conduction unit and the second conduction unit, S260 corresponds to processing as the first identification information transmission unit and the second identification information transmission unit, S300 corresponds to processing as the first blocking unit and the second blocking unit, and S280 corresponds to processing as the first blocking notification unit and the second blocking notification unit.

[0190] Fifth Embodiment A fifth embodiment of the present disclosure will be described below with reference to the drawings. In the fifth embodiment, differences from the fourth embodiment will be described. The same reference numerals will be used to designate common components.

[0191] The vehicle control system 100 of the fifth embodiment differs from the fourth embodiment in that the configuration of the setting table 167 and the ID setting process are changed. As shown in Fig. 16 , the setting table 167 of the fifth embodiment sets an electronic fuse ID and an ECU ID that identifies the connected ECU for each of the multiple electronic fuses 173, 174, 183, and 184 included in the vehicle control system 100.

[0192] In the setting table 167 of this embodiment, “eFuse_1” is set as the electronic fuse ID and “ECU_A” is set as the ECU ID for the electronic fuse 173. “ECU_A” is the ECU ID corresponding to the zone ECU 104.

[0193] For the electronic fuse 174, "eFuse_2" is set as the electronic fuse ID, and "ECU_B" is set as the ECU ID. "ECU_B" is the ECU ID corresponding to the zone ECU 105.

[0194] For the electronic fuse 183, "eFuse_3" is set as the electronic fuse ID, and "ECU_C" is set as the ECU ID. "ECU_C" is the ECU ID corresponding to the zone ECU 106.

[0195] For the electronic fuse 184, "eFuse_4" is set as the electronic fuse ID, and "ECU_D" is set as the ECU ID. "ECU_D" is the ECU ID corresponding to the zone ECU 107.

[0196] The zone ECU 104 is, for example, an electronic control unit that controls the right front door of the vehicle, the zone ECU 105 is, for example, an electronic control unit that controls the left front door of the vehicle, the zone ECU 106 is, for example, an electronic control unit that controls the right rear door of the vehicle, and the zone ECU 107 is, for example, an electronic control unit that controls the left rear door of the vehicle. For this reason, the zone ECUs 104, 105, 106, and 107 are equipped with common software for door control. In other words, the zone ECUs 104, 105, 106, and 107 are configured to be operable regardless of whether they are set to "ECU_A," "ECU_B," "ECU_C," or "ECU_D."

[0197] Next, a description will be given of the procedure of the ID setting process executed by the control unit 151 of the central ECU 101. The ID setting process is a process that is repeatedly executed while the central ECU 101 is running.

[0198] When the ID setting process is executed, the CPU 161 of the control unit 151 determines whether the central ECU 101 is set to the ID setting mode in S410 as shown in Fig. 17. When the control unit 151 of the central ECU 101 receives an ID setting command from, for example, the fault diagnosis device 90, the control unit 151 sets the central ECU 101 to the ID setting mode.

[0199] If the central ECU 101 is not set to the ID setting mode, the CPU 161 ends the ID setting process. On the other hand, if the central ECU 101 is set to the ID setting mode, the CPU 161 sets the electronic fuse indication value i stored in the RAM 163 to 0 in S420.

[0200] In S430, the CPU 161 increments the electronic fuse indication value i (i.e., adds 1). In S440, the CPU 161 turns on the i-th electronic fuse (i.e., the electronic fuse for which "eFuse_i" is set as the electronic fuse ID).

[0201] In S450, the CPU 161 waits for a preset ith on-state standby time. That is, for example, the CPU 161 waits for the first on-state standby time when the electronic fuse indication value i=1, and waits for the second on-state standby time when the electronic fuse indication value i=2. The first, second, third, and fourth on-state standby times are set to be longer than the startup times of the ECUs connected to the electronic fuses 173, 174, 183, and 184, respectively.

[0202] In S460, the CPU 161 extracts the ECU ID corresponding to the i-th electronic fuse from the setting table 167, and transmits the extracted ECU ID from the CAN communication unit 12. That is, for example, the CPU 161 transmits "ECU_A" as the ECU ID when the electronic fuse instruction value i=1, and transmits "ECU_B" as the ECU ID when the electronic fuse instruction value i=2.

[0203] In S470, the CPU 161 receives the ith reception completion notification via the communication unit 154. The ith reception completion notification is transmitted from the zone ECU connected to the ith electronic fuse. Note that when the zone ECUs 104, 105, 106, and 107 connected to the electronic fuses 173, 174, 183, and 184 receive "ECU_A," "ECU_B," "ECU_C," and "ECU_D" from the central ECU 101, they store "ECU_A," "ECU_B," "ECU_C," and "ECU_D" in their storage units 194, 214, 234, and 254, respectively, and then transmit the first, second, third, and fourth reception completion notifications to the central ECU 101.

[0204] In S480, the CPU 161 transmits an ith cutoff notification from the communication unit 154, notifying the central ECU 101 that the ith electronic fuse will be turned off. In S490, the CPU 161 determines whether or not the ith cutoff permission notification has been received via the communication unit 154. The ith cutoff permission notification is transmitted from the zone ECU connected to the ith electronic fuse. Note that the zone ECUs 104, 105, 106, and 107 connected to the electronic fuses 173, 174, 183, and 184 are configured to transmit the first, second, third, and fourth cutoff permission notifications to the central ECU 101 upon receiving the first, second, third, and fourth cutoff notifications, respectively.

[0205] If the i-th shutdown permission notification has not been received, the CPU 161 waits until the i-th shutdown permission notification is received by repeating the process of S490. Then, when the i-th shutdown permission notification is received, the CPU 161 turns off the i-th electronic fuse in S500.

[0206] In S510, the CPU 161 determines whether the electronic fuse indication value i is equal to or greater than the preset total number n of electronic fuses (4 in this embodiment). If the electronic fuse indication value i is less than the total number n of electronic fuses, the CPU 161 proceeds to S430.

[0207] On the other hand, if the electronic fuse indication value i is equal to or greater than the total number n of electronic fuses, the CPU 161 cancels the ID setting mode in S520 and ends the ID setting process. The central ECU 101 configured in this manner is configured to set the electronic fuse 173, which is configured to switch between a first conduction state that connects the power supply path 123 that supplies power from the battery 117 to the zone ECU 104 and a first cut-off state that cuts off the power supply path 123, to the first conduction state.

[0208] The central ECU 101 is configured to transmit, to the zone ECU 104, "ECU_A", which is an ECU ID that is preset in association with the electronic fuse 173 and that identifies the zone ECU 104, when a preset first transmission condition is met after the electronic fuse 173 has entered the first conductive state. The first transmission condition in this embodiment is that a preset first on-state standby time has elapsed since the electronic fuse 173 entered the first conductive state.

[0209] After "ECU_A" is transmitted to the zone ECU 104, the central ECU 101 is configured to set the electronic fuse 174, which is configured to switch between a second conductive state that conducts the power supply path 124 that supplies power from the battery 117 to the zone ECU 105 and a second cut-off state that cuts off the power supply path 124, to a second conductive state.

[0210] The central ECU 101 is configured to transmit, to the zone ECU 105, "ECU_B", which is an ECU ID that is preset in association with the electronic fuse 174 and that identifies the zone ECU 105, when a preset second transmission condition is met after the electronic fuse 174 has entered the second conductive state. The second transmission condition in this embodiment is that a preset second on-state standby time has elapsed since the electronic fuse 174 entered the second conductive state.

[0211] After the zone ECUs 104, 105 are installed in the vehicle, the central ECU 101 can set "ECU_A" and "ECU_B" for each of the zone ECUs 104, 105. This allows the zone ECUs 104, 105 to be equipped with the same software during their manufacture if they have the same hardware. Therefore, the central ECU 101 can improve the efficiency of ECU manufacturing.

[0212] After "ECU_A," "ECU_B," "ECU_C," and "ECU_D" are set as the ECU IDs of the zone ECUs 104, 105, 106, and 107, the zone ECUs 104, 105, 106, and 107 perform data communication using the set ECU IDs. Specifically, "ECU_A," "ECU_B," "ECU_C," and "ECU_D" can be, for example, "1101," "1102," "1103," and "1104," respectively. This allows the zone ECUs 104 to 107 to identify the data sender in data communication between the zone ECUs 104 to 107.

[0213] In the embodiment described above, the central ECU 101 corresponds to the management device and the second integrated control device, the battery 117 corresponds to the power source, the zone ECU 104 corresponds to the first control device and the first integrated control device, the electronic fuse 173 corresponds to the first power supply switching unit and the power supply switching unit, and the power supply path 123 corresponds to the first power supply path.

[0214] Furthermore, the zone ECU 105 corresponds to the second control device and the first integrated control device, the electronic fuse 174 corresponds to the second power supply switching unit and the power supply switching unit, the power supply path 124 corresponds to the second power supply path, and the electronic fuses 183 and 184 correspond to the power supply switching unit. Furthermore, S440 corresponds to the processing performed by the first conduction unit and the second conduction unit, S460 corresponds to the processing performed by the first identification information transmission unit and the second identification information transmission unit, S500 corresponds to the processing performed by the first interruption unit and the second interruption unit, and S480 corresponds to the processing performed by the first interruption notification unit and the second interruption notification unit.

[0215] While one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modifications. [Modification 1] In the above embodiment, the vehicle control system 1 includes two electronic fuses 14 and 15. However, the vehicle control system 1 may include three or more electronic fuses.

[0216] [Modification 2] In the above embodiment, the slave ECUs 3 and 4 transmit the ID setting request. However, the slave ECUs 3 and 4 may transmit a wake-up notification indicating that they have been started up, instead of the ID setting request.

[0217] [Modification 3] In the above embodiment, the master ECU 2 transmits the ECU ID to the slave ECUs 3 and 4 via CAN communication. However, when LIN communication is performed between the master ECU 2 and the slave ECUs 3 and 4, the master ECU 2 may transmit the NAD instead of the ECU ID. LIN stands for Local Interconnect Network. NAD stands for Node Address.

[0218] The control unit 11, 151 and the method described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to execute one or more functions embodied in a computer program. Alternatively, the control unit 11, 151 and the method described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit 11, 151 and the method described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to execute one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible recording medium. The method for implementing the functions of each unit included in the control unit 11, 151 does not necessarily need to include software; all of the functions may be implemented using one or more hardware components.

[0219] In the above embodiments, multiple functions of one component may be realized by multiple components, or one function of one component may be realized by multiple components. Furthermore, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, part of the configuration of the above embodiments may be omitted. Furthermore, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.

[0220] In addition to the master ECU 2 and central ECU 101 described above, the present disclosure can also be realized in various forms, such as a system having the master ECU 2 and central ECU 101 as components, a program for causing a computer to function as the master ECU 2 and central ECU 101, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and a management method. [Technical Ideas Disclosed in the Present Specification] [Item 1] A first conduction unit (S40, S240, S440) configured to set a first power supply switching unit (14, 173, 195) configured to switch between a first conduction state in which a first power supply path (9, 123, 127) that supplies power from a power source (7, 117) to a first control device (3, 104, 108) is conductive and a first interruption state in which the first power supply path is interrupted, to the first conduction state; and a first identification information transmission unit (S60, S260, S460) configured to transmit, to the first control device, first identification information that is preset in association with the first power supply switching unit and that identifies the first control device, when a preset first transmission condition is satisfied after the first power supply switching unit has been set to the first conduction state. a second conduction unit (S40, S240, S440) configured to switch a second power supply switching unit (15, 174, 196) between a second conduction state in which a second power supply path (10, 124, 128) that supplies power from the power source to a second control device (4, 105, 109) is turned on and a second interruption state in which the second power supply path is interrupted, after the first identification information has been transmitted to the first control device; and a second identification information transmission unit (S60, S260, S460) configured to transmit, to the second control device, second identification information that is preset in association with the second power supply switching unit and that identifies the second control device, when a preset second transmission condition is satisfied after the second power supply switching unit has turned on the second conduction state.

[0221] [Item 2] The management device according to Item 1, wherein the first transmission condition includes a first conduction standby time being set in advance after the first power supply switching unit is set in the first conduction state, and the second transmission condition includes a second conduction standby time being set in advance after the second power supply switching unit is set in the second conduction state.

[0222] [Item 3] The management device according to Item 1, wherein the first transmission condition includes receiving, from the first control device, predetermined first reception permission information indicating that the first control device is in a state where it can receive the first identification information after the first power supply switching unit has entered the first conductive state, and the second transmission condition includes receiving, from the second control device, predetermined second reception permission information indicating that the second control device is in a state where it can receive the second identification information after the second power supply switching unit has entered the second conductive state.

[0223] [Item 4] The management device according to any one of Items 1 to 3, further comprising: a first cutoff unit (S100, S300, S500) configured to set the first power supply switching unit to the first cutoff state when a preset first cutoff condition is met after the first identification information is transmitted to the first control device; and a second cutoff unit (S100, S300, S500) configured to set the second power supply switching unit to the second cutoff state when a preset second cutoff condition is met after the second identification information is transmitted to the second control device.

[0224] [Item 5] The management device according to Item 4, further comprising: a first shutdown notification unit (S80, S280, S480) configured to, after transmitting the first identification information to the first control device, transmit a first shutdown notification to the first control device, notifying the first control device that the first power supply switching unit will be set to the first shutdown state; and a second shutdown notification unit (S80, S280, S480) configured to, after transmitting the second identification information to the second control device, transmit a second shutdown notification to the second control device, notifying the second control device that the second power supply switching unit will be set to the second shutdown state, wherein the first shutdown condition includes receiving a preset first shutdown permission notification from the first control device after transmitting the first shutdown notification to the first control device; and the second shutdown condition includes receiving a preset second shutdown permission notification from the second control device after transmitting the second shutdown notification to the second control device.

[0225] [Item 6] The management device according to Item 5, wherein the first blocking condition includes a predetermined first blocking wait time elapses after the first blocking permission notification is received from the first control device after the first blocking notification is sent to the first control device, and the second blocking condition includes a predetermined second blocking wait time elapses after the second blocking notification is sent to the second control device after the second blocking permission notification is received from the second control device.

[0226] [Item 7] A power supply system includes: a first control device (3, 104, 108) that receives power from a power source (7, 117) via a first power supply switching unit (14, 173, 195) that is configured to switch between a first conduction state that conducts a first power supply path and a first interruption state that interrupts the first power supply path (9, 123, 127); a second control device (4, 105, 109) that receives power from the power source via a second power supply switching unit (15, 174, 196) that is configured to switch between a second conduction state that conducts a second power supply path (10, 124, 128) and a second interruption state that interrupts the second power supply path; and a management device (2, 101) that is connected to the first control device and the second control device so as to be able to communicate data with each other and that is configured to control operations of the first power supply switching unit and the second power supply switching unit, wherein the management device: a first conduction unit (S40, S240, S440) configured to set the first power supply switching unit to the first conduction state; a first identification information transmission unit (S60, S260, S460) configured to transmit, to the first control unit, first identification information that is preset in association with the first power supply switching unit and that identifies the first control unit, when a preset first transmission condition is met after the first power supply switching unit has been set to the first conduction state; a second conduction unit (S40, S240, S440) configured to set the second power supply switching unit to the second conduction state after the first identification information has been transmitted to the first control unit; and a second identification information transmission unit (S60, S260, S460) configured to transmit, to the second control unit, second identification information that is preset in association with the second power supply switching unit and that identifies the second control unit, when a preset second transmission condition is met after the second power supply switching unit has been set to the second conduction state. A management system (1, 100) comprising:

[0227] [Item 8] The management system according to Item 7, wherein the management system includes one or more control devices (5, 104 to 118) other than the first control device and the second control device, and the first control device and the second control device are preset as targets for the management device to execute the processes of the first conduction unit, the first identification information transmission unit, the second conduction unit, and the second identification information transmission unit.

[0228] [Item 9] The management system according to item 7 or 8, wherein the first control device and the second control device are equipped with common software, and the first control device and the second control device are configured to be operable regardless of whether the first identification information or the second identification information is set.

[0229] [Item 10] The management system (1) according to any one of items 7 to 9, wherein the management system includes two slave control devices (3, 4) as the first control device and the second control device, and includes a master control device (2) as the management device, connected to the slave control devices so as to be able to communicate data with them, and equipped with one or more power supply switching units (14, 15).

[0230] [Item 11] A management system (100) according to any one of items 7 to 9, the management system including two slave control devices (108, 109) as the first control device and the second control device, a first integrated control device (104) connected to the slave control device so as to be able to communicate data with the slave control device and having a plurality of power supply switching units (195, 196), and a second integrated control device (101) connected to the first integrated control device so as to be able to communicate data with the first integrated control device as the management device, the slave control device and the second integrated control device being connected to each other so as to be able to communicate data with each other via the first integrated control device.

[0231] [Item 12] The management system (100) according to any one of items 7 to 9, comprising one or more slave control devices (108 to 116), two first integrated control devices (104, 105) connected to the slave control devices so as to be able to communicate data with each other, as the first control device and the second control device, an upstream power supply distribution unit (102, 103) having one or more power supply switching units (173, 174, 183, 184), and a second integrated control device (101) connected to the first integrated control device and the upstream power supply distribution unit so as to be able to communicate data with each other, as the management device.

Claims

1. A first conduction unit (S40, S240, S440) configured to set a first power supply switching unit (14, 173, 195) configured to switch between a first conduction state for conducting a first power supply path (9, 123, 127) that supplies power from a power source (7, 117) to a first control device (3, 104, 108) and a first interruption state for interrupting the first power supply path to the first conduction state; and a first identification information transmission unit (S60, S260, S460) configured to transmit, to the first control device, first identification information that is preset in association with the first power supply switching unit and that identifies the first control device when a preset first transmission condition is met after the first power supply switching unit has been set to the first conduction state. a second conduction unit (S40, S240, S440) configured to switch a second power supply switching unit (15, 174, 196) between a second conduction state in which a second power supply path (10, 124, 128) that supplies power from the power source to a second control device (4, 105, 109) is turned on and a second interruption state in which the second power supply path is interrupted, after the first identification information has been transmitted to the first control device; and a second identification information transmission unit (S60, S260, S460) configured to transmit, to the second control device, second identification information that is preset in association with the second power supply switching unit and that identifies the second control device, when a preset second transmission condition is satisfied after the second power supply switching unit has turned on the second conduction state.

2. A management device according to claim 1, wherein the first transmission condition includes the lapse of a predetermined first conduction standby time after the first power supply switching unit enters the first conduction state, and the second transmission condition includes the lapse of a predetermined second conduction standby time after the second power supply switching unit enters the second conduction state.

3. A management device according to claim 1, wherein the first transmission condition includes receiving, from the first control device, preset first reception permission information indicating that the first control device is in a state where it can receive the first identification information after the first power supply switching unit has entered the first conductive state, and the second transmission condition includes receiving, from the second control device, preset second reception permission information indicating that the second control device is in a state where it can receive the second identification information after the second power supply switching unit has entered the second conductive state.

4. A management device according to any one of claims 1 to 3, further comprising: a first cut-off unit (S100, S300, S500) configured to set the first power supply switching unit to the first cut-off state when a preset first cut-off condition is met after the first identification information has been transmitted to the first control device; and a second cut-off unit (S100, S300, S500) configured to set the second power supply switching unit to the second cut-off state when a preset second cut-off condition is met after the second identification information has been transmitted to the second control device.

5. A management device according to claim 4, further comprising: a first shutdown notification unit (S80, S280, S480) configured to, after transmitting the first identification information to the first control device, transmit a first shutdown notification to the first control device, notifying the first control device that the first power supply switching unit will be set to the first shutdown state; and a second shutdown notification unit (S80, S280, S480) configured to, after transmitting the second identification information to the second control device, transmit a second shutdown notification to the second control device, notifying the second control device that the second power supply switching unit will be set to the second shutdown state, wherein the first shutdown condition includes receiving a preset first shutdown permission notification from the first control device after transmitting the first shutdown notification to the first control device, and the second shutdown condition includes receiving a preset second shutdown permission notification from the second control device after transmitting the second shutdown notification to the second control device.

6. A management device as described in claim 5, wherein the first blocking condition includes a predetermined first blocking waiting time elapses after the first blocking permission notification is received from the first control device after the first blocking notification is sent to the first control device, and the second blocking condition includes a predetermined second blocking waiting time elapses after the second blocking permission notification is received from the second control device after the second blocking notification is sent to the second control device.

7. A power supply system comprising: a first control device (3, 104, 108) receiving power from a power source (7, 117) via a first power supply switching unit (14, 173, 195) configured to switch between a first conduction state for conducting a first power supply path and a first interruption state for interrupting the first power supply path (9, 123, 127); a second control device (4, 105, 109) receiving power from the power source via a second power supply switching unit (15, 174, 196) configured to switch between a second conduction state for conducting a second power supply path (10, 124, 128) and a second interruption state for interrupting the second power supply path; and a management device (2, 101) connected to enable data communication between the first control device and the second control device and configured to control the operation of the first power supply switching unit and the second power supply switching unit, wherein the management device: a first conduction unit (S40, S240, S440) configured to set the first power supply switching unit to the first conduction state; a first identification information transmission unit (S60, S260, S460) configured to transmit, to the first control unit, first identification information that is preset in association with the first power supply switching unit and that identifies the first control unit, when a preset first transmission condition is met after the first power supply switching unit has been set to the first conduction state; a second conduction unit (S40, S240, S440) configured to set the second power supply switching unit to the second conduction state after the first identification information has been transmitted to the first control unit; and a second identification information transmission unit (S60, S260, S460) configured to transmit, to the second control unit, second identification information that is preset in association with the second power supply switching unit and that identifies the second control unit, when a preset second transmission condition is met after the second power supply switching unit has been set to the second conduction state. A management system (1, 100) comprising:

8. A management system as set forth in claim 7, comprising one or more control devices (5, 104 to 118) other than the first control device and the second control device, and the first control device and the second control device are preset as targets for the management device to execute the processes of the first conduction unit, the first identification information transmission unit, the second conduction unit and the second identification information transmission unit.

9. A management system as claimed in claim 7 or claim 8, wherein the first control device and the second control device are equipped with common software, and the first control device and the second control device are configured to be operable regardless of whether the first identification information or the second identification information is set.

10. A management system (1) according to claim 7 or claim 8, comprising two slave control devices (3, 4) as the first control device and the second control device, and a master control device (2) as the management device, connected to the slave control devices so as to be able to communicate data with them and equipped with one or more power supply switching units (14, 15).

11. A management system (100) as set forth in claim 7 or claim 8, comprising: two slave control devices (108, 109) as the first control device and the second control device; a first integrated control device (104) connected to the slave control devices so as to be able to communicate data with them and equipped with a plurality of power supply switching units (195, 196); and a second integrated control device (101) connected to the first integrated control device so as to be able to communicate data with them as the management device; and the slave control devices and the second integrated control device are connected to each other so as to be able to communicate data with each other via the first integrated control device.

12. A management system (100) according to claim 7 or claim 8, comprising one or more slave control devices (108-116), two first integrated control devices (104, 105) connected to the slave control devices so as to be able to communicate data with each other as the first control device and the second control device, an upstream power distribution unit (102, 103) having one or more power supply switching units (173, 174, 183, 184), and a second integrated control device (101) connected to the first integrated control device and the upstream power distribution unit so as to be able to communicate data with each other as the management device.

Citation Information

Patent Citations

  • Sensor and sensor system

    JP2022154990A

  • Identifier setting system

    JP2023040608A

  • Storage battery management system, mobile body, storage battery, and storage battery management method

    WO2018147046A1