Abnormality monitoring system and abnormality monitoring method
The abnormality monitoring system addresses the challenge of diverse ECU activation conditions in in-vehicle communication systems by using a sub-unit and main unit to detect and distribute events, effectively managing system abnormalities and preventing further control issues.
Patent Information
- Application Number
- PCT/JP2025/025642
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-26
- Filing Date
- 2025-07-17
- Publication Date
- 2026-01-29
AI Technical Summary
Existing in-vehicle communication systems fail to effectively respond to abnormalities in ECUs with different activation conditions, such as those activated by power supply or management communication, leading to inefficiencies and potential system failures.
An abnormality monitoring system comprising a sub-unit that monitors power-start ECUs and a main unit that monitors communication-start ECUs, with the main unit determining system abnormalities and distributing events to communication nodes to prevent further control related to the affected ECU.
The system enables appropriate handling of abnormalities in in-vehicle communication systems with diverse ECU activation conditions, preventing the continuation of control related to the affected ECU and ensuring timely response to system anomalies.
Smart Images

Figure JP2025025642_29012026_PF_FP_ABST
Abstract
Description
Abnormality monitoring system and abnormality monitoring method
[0001] This application claims priority to Japanese Application No. 2024-120932 filed on July 26, 2024, and incorporates by reference the entire contents of said Japanese application.
[0002] Patent document 1 describes an in-vehicle network system that includes a power source, a host ECU (Electronic Control Unit), an intermediate ECU having a network management function (hereinafter referred to as the "NM function") that communicates with the host ECU, and multiple subordinate ECUs having the NM function that communicates with the intermediate ECU.
[0003] In Patent Document 1, the intermediate ECU supplies power to the subordinate ECU in response to receiving a message from the superior ECU. The subordinate ECU normally maintains a power-off state and transitions to a communication standby state when power is supplied from the intermediate ECU. Since the subordinate ECU with the NM function normally maintains a power-off state, the standby power consumption of the subordinate ECU in the system can be reduced.
[0004] Japanese Patent Application Laid-Open No. 2021-11228
[0005] A system according to one aspect of the present disclosure is an abnormality monitoring system comprising a sub-unit that monitors the operating status of a plurality of power-start ECUs as described below, and a main unit that monitors the operating status of a plurality of communication-start ECUs as described below, wherein the objects monitored by the sub-unit include events related to abnormalities that can be detected by the power-start ECUs, and the objects monitored by the main unit include events related to abnormalities that can be detected by the communication-start ECUs.
[0006] The main unit also executes the following processes: determining whether or not there is an abnormality in the system based on its own monitoring results and the monitoring results notified from the sub-unit; and, if the determination result is positive, distributing the determined event to a communication node in the system. First ECU: ECU that operates or stops depending on the status of the power supply system. Second ECU: ECU that operates or stops depending on management communication.
[0007] Fig. 1A is an upper diagram of a network connection diagram of an anomaly monitoring system. Fig. 1B is a lower diagram of a network connection diagram of an anomaly monitoring system. Fig. 2 is a sequence diagram showing an example of an anomaly monitoring process.
[0008] According to Patent Document 1, since the subordinate ECU can be activated by management communication based on the NM function, it is possible to reduce the number of wires in the system and the number of relays. However, Patent Document 1 does not consider how to respond to an abnormality in each ECU in a system that mixes normal ECUs that are activated according to the status of the power supply system and ECUs that are activated by management communication based on the NM function.
[0009] In view of the above-described conventional problems, the present disclosure aims to appropriately respond to an abnormality in an in-vehicle communication system including a plurality of types of ECUs with different activation conditions.
[0010] According to the present disclosure, in an in-vehicle communication system including a plurality of types of ECUs with different activation conditions, it is possible to appropriately respond to an abnormality in the system.
[0011] The following provides an outline of embodiments of the present disclosure.
[0012] (1) A system according to one aspect of this embodiment is an abnormality monitoring system including a sub-unit that monitors the operating status of a plurality of power-start ECUs as described below, and a main unit that monitors the operating status of a plurality of communication-start ECUs as described below, wherein the objects monitored by the sub-unit include events related to abnormalities that can be detected by the power-start ECUs, and the objects monitored by the main unit include events related to abnormalities that can be detected by the communication-start ECUs.
[0013] The main unit also executes the following processes: determining whether or not there is an abnormality in the system based on its own monitoring results and the monitoring results notified from the sub-unit; and, if the determination result is positive, distributing the determined event to a communication node in the system. First ECU: ECU that operates or stops depending on the status of the power supply system. Second ECU: ECU that operates or stops depending on management communication.
[0014] According to the anomaly monitoring system of this embodiment, the main unit distributes the determined event to communication nodes within the system, so that the first ECU or the second ECU that receives the distribution can immediately prevent the continuation of control related to the ECU in which the abnormality occurred, for example, by suspending cooperative control with the ECU related to the event. Therefore, in an in-vehicle communication system including a first ECU and a second ECU whose operating states vary due to different factors, an abnormality within the system can be appropriately handled.
[0015] (2) In the abnormality monitoring system of (1) above, the plurality of power startup ECUs may include an ECU that is the monitoring target of the sub-unit and an ECU that is the monitoring target of the main unit. In this case, the power startup ECUs can be monitored in a distributed manner by both the main unit and the sub-unit.
[0016] (3) The abnormality monitoring system of (1) or (2) above may further include a power system that supplies power to the power startup ECU and the communication startup ECU, and the monitoring targets of the main unit and the sub-unit may include events related to abnormalities in the power system. In this way, events related to abnormalities in the power system can also be distributed to communication nodes within the system.
[0017] (4) In the abnormality monitoring systems described above in (1) to (3), the monitoring targets of the main unit may include events related to abnormalities in its own in-vehicle communication unit, and the monitoring targets of the sub-unit may include events related to abnormalities in its own in-vehicle communication unit. In this way, events related to abnormalities in the in-vehicle communication unit of the main unit and the in-vehicle communication unit of the sub-unit can also be distributed to communication nodes within the system.
[0018] (5) A method according to one aspect of this embodiment is an abnormality monitoring method executed in the abnormality monitoring system described above in (1) to (4). Therefore, the abnormality monitoring method of this embodiment has the same effects as the abnormality monitoring system described above in (1) to (4).
[0019] The present disclosure can be realized not only as a system or device having the above-described characteristic configuration, but also as a program for causing a computer to execute such characteristic configuration. Furthermore, the present disclosure can be realized as a semiconductor integrated circuit that realizes part or all of the device and system.
[0020] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, detailed descriptions of embodiments of the present invention will be given with reference to the accompanying drawings. At least some of the embodiments described below may be combined in any desired manner.
[0021] [Overall System Configuration] Fig. 1A is the upper diagram of a network connection diagram of the abnormality monitoring system 100. Fig. 1B is the lower diagram of a network connection diagram of the abnormality monitoring system 100. Specifically, when Fig. 1A and Fig. 1B are connected at connection points A, B, and C, a network connection diagram showing an example of the overall configuration of the abnormality monitoring system 100 and power supply system 200 mounted on a vehicle 300 is obtained. Note that solid lines in the diagram represent "communication lines" and dashed lines represent "power lines." Also, blank square dots in Fig. 1 represent "relays."
[0022] 1A and 1B (hereinafter abbreviated as "FIG. 1"), a vehicle 300 is equipped with an abnormality monitoring system 100, a power supply system 200, and a switch 80. The abnormality monitoring system 100 includes a main unit 10, multiple sub-units 20 and 30, a service unit 40, multiple types of ECUs 50 and 60 with different activation conditions, and a TCU (Telematics Control Unit) 70.
[0023] The abnormality monitoring system 100 of this embodiment includes a CAN (Controller Area Network) network having a bus-type network topology. The CAN network includes multiple CAN buses B1, B2, B3, and B4 connected to the units 10, 20, 30, and 40, respectively. Multiple ECUs 50 and 60 are connected to the CAN bus B1 of the main unit 10.
[0024] A plurality of ECUs 50, 60 are connected to the CAN bus B2 of the subunit 20, and a plurality of ECUs 50, 60 are also connected to the CAN bus B3 of the subunit 30. A plurality of ECUs 50, 60 and a TCU 70 are connected to the CAN bus B4 of the service unit 40. Each ECU 50, 60 is equipped with a CAN interface capable of CAN communication.
[0025] The TCU 70 includes a CAN interface capable of CAN communication, which is a type of in-vehicle communication unit, and a wireless interface for communication outside the vehicle. The wireless interface protocol may be at least one of LTE (Long Term Evolution), 5G (5th generation mobile communication system), DSRC (Dedicated Short-Range Communications), Wi-Fi (registered trademark), etc.
[0026] Each of the units 10, 20, 30, and 40, the multiple ECUs 50 and 60, and the TCU 70 employs a communication protocol capable of transmitting and receiving periodic or non-periodic messages. The communication protocol is, for example, CAN or CAN with Flexible Data Rate (CAN FD). The main unit 10 has a relay function between the CAN buses B1, B2, B3, and B4. That is, the CAN buses B2, B3, and B4 are also connected to the main unit 10, and the main unit 10 can relay a CAN message sent to any of the CAN buses B1, B2, B3, and B4 to the other CAN buses.
[0027] The ECUs 50, 60 belong to various systems, such as a control system for the engine and transmission, a body system for headlights and power windows, and an information system for car navigation and multimedia, and are disposed in various parts of the vehicle. The ECUs 50, 60 individually control actuators in various parts of the vehicle and generate measurement data (such as temperature, speed, acceleration, or digital images) from signals received from sensors in various parts of the vehicle.
[0028] The multiple ECUs 50, 60 include the following "first ECU 50" and "second ECU 60" which have different activation conditions. First ECU 50: An ECU that does not have an NM function and therefore operates or stops depending on a power source and can detect abnormalities related to its own device. The first ECU 50 is also called a "power-on ECU." The operating state of the first ECU 50 can be either "operating" (on) or "stopped" (off), depending on whether or not power is supplied from the power supply system 200.
[0029] The second ECU 60 is an ECU that has an NM function, operates or stops via communication, and can detect abnormalities related to its own device. The second ECU 60 is also called a "communication-activated ECU." The operating state of the second ECU 60 can be either "operating" (on) or "standby" (sleep) depending on the management communication using NM messages.
[0030] In this embodiment, each of the units 10, 20, 30, and 40 is a type of communication-activated ECU having an NM function, and the main unit 10 monitors the operating states of all of the second ECUs 60 in the system. The multiple first ECUs 50 in the system are divided into the following types depending on which unit 10, 20, or 30 monitors them: First ECU 50A: First ECU 50 monitored by the main unit 10 First ECU 50B: First ECU 50 monitored by the sub-unit 20 First ECU 50C: First ECU 50 monitored by the sub-unit 30
[0031] The multiple ECUs 50, 60 have the function of providing services to the vehicle user. One service can be provided by one or multiple ECUs 50, 60. For example, a service such as "autonomous driving" performed on a vehicle 300 that is being driven by a driver is provided by an ECU group including at least one first ECU 50. Also, a service such as "smart entry" performed on a vehicle 300 that is being parked without a driver is provided by an ECU group including at least one second ECU 60.
[0032] 1, the power supply system 200 includes a high-voltage battery 110, a DC / DC converter 120, an auxiliary battery 130, and power controllers 140, 150, and 160. The high-voltage battery 110 is a battery with an output voltage of, for example, 400 V and is used to drive the vehicle. The DC / DC converter 120 is connected to the high-voltage battery 110 and reduces the output voltage of the high-voltage battery 110 to 12 V. The auxiliary battery 130 is a battery with an output voltage of, for example, 12 V and is used to drive the auxiliary devices in the vehicle 300.
[0033] In this embodiment, the plurality of power controllers 140, 150, 160 include, for example, the following controllers: Main controller 140: a power controller mounted on the main unit 10 Subcontroller 150: a power controller mounted on the subunit 20 Subcontroller 160: a power controller mounted on the subunit 30
[0034] The main controller 140 is configured with a switching circuit including multiple power semiconductors and controls the opening and closing of relays R11, R12, and R13. The relay R11 is a relay that opens and closes the power supply from the DC / DC converter 120 and the auxiliary battery 130. The relay R12 is a relay that opens and closes the power distribution to the sub-controllers 150 and 160. The relay R13 is a relay that opens and closes the power distribution to the first ECUs 50A (three in the illustrated example) connected to the CAN buses B1 and B4.
[0035] The power line on the output side of DC / DC converter 120 and the power line of auxiliary battery 130 are electrically connected downstream of relay R11. Therefore, the output power of DC / DC converter 120 can be used not only to power subunits 20, 30 and first ECU 50, but also to charge auxiliary battery 130.
[0036] Sub-controller 150 is configured with a switching circuit including multiple power semiconductors and controls the opening and closing of relay R21. Relay R21 is a relay that opens and closes the power distribution to first ECUs 50B (two in the illustrated example) connected to CAN bus B2. Sub-controller 160 is configured with a switching circuit including multiple power semiconductors and controls the opening and closing of relay R31. Relay R31 is a relay that opens and closes the power distribution to first ECUs 50C (two in the illustrated example) connected to CAN bus B3.
[0037] Each of the controllers 140, 150, 160 is connected to a switch 80 provided on the dashboard of the vehicle 300 or the like. The switch 80 is a switch that switches the status of the power supply system 200, and is, for example, a push switch. The state transitions of the power supply system 200 due to switch operations are, for example, as follows: Transition 1: Switch operation at +B → power supply status transitions to ACC Transition 2: Switch operation at ACC → power supply status transitions to IG Transition 3: Switch operation at IG → power supply status transitions to +B
[0038] Each of the controllers 140, 150, and 160 performs power supply control to switch the status of the power supply system 200 in response to a switch operation. Specifically, when each of the controllers 140, 150, and 160 detects a switch operation at +B, it switches the open / close status of the relays R11, R12, R13, R21, and R31 so as to achieve transition 1.
[0039] Similarly, when each of the controllers 140, 150, and 160 receives a switch operation at ACC, it switches the relays R11, R12, R13, R21, and R31 between open and closed states to achieve transition 2. Similarly, when each of the controllers 140, 150, and 160 receives a switch operation at IG, it switches the relays R11, R12, R13, R21, and R31 between open and closed states to achieve transition 3.
[0040] Power supply system 200 has a power supply line 170 that constantly supplies power to second ECU 60. Power supply line 170 is made up of a power line that is connected to at least one of DC / DC converter 120 and auxiliary battery 130 without passing through a relay. Power supply line 170 branches midway, and the branched ends are connected to the multiple second ECUs 60 that are connected to each of CAN buses B1, B2, B3, and B4.
[0041] In the connection example of Fig. 1 , the second ECU 60 having the NM function may be connected to a power line whose power supply status is controlled by the controllers 140, 150, and 160. In this case, the second ECU 60 shuts down when power is no longer supplied from the power line. In contrast, the first ECU 50 is not connected to the power supply line 170 for continuous power supply. This is because the first ECU 50 does not have a sleep function based on communication and therefore should not be connected to the power supply line 170 for continuous power supply.
[0042] 1, the main unit 10 includes a processor 11, a storage 12, and a CAN interface 13 in addition to the main controller 140. The processor 11 is configured by, for example, one or more central processing units (CPUs), and is capable of executing computer programs stored in the storage 12. The computer programs include a program for realizing event determination (step S15 in FIG. 2), which will be described later.
[0043] The processor 11 may be an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array). In this case, the ASIC or FPGA is configured to be able to execute functions realized by a computer program. The storage 12 is, for example, a non-volatile memory such as a flash memory, a hard disk, or a ROM (Read Only Memory). The storage 12 stores the computer program executed by the processor 11 and data necessary for the execution of the computer program.
[0044] The CAN interface 13 is a communication module that complies with the CAN, which is a type of in-vehicle communication unit. The CAN interface 13 has multiple CAN ports, each connected to a CAN bus B1, B2, B3, or B4. The processor 11 has a function for relaying CAN messages. Specifically, the processor 11 determines to which of the CAN buses B1, B2, B3, or B4 a received message should be transferred based on the CAN ID included in the received message.
[0045] When processor 11 receives a CAN message addressed to itself, it uses the data included in the message for predetermined processing, including event determination (step S15 in FIG. 2), which will be described later. When processor 11 generates data to be provided to an external device, such as a server of a vehicle manufacturer or a user's mobile terminal, it outputs a CAN message addressed to TCU 70, including the data, to CAN interface 13.
[0046] 1, the subunit 20 includes the subcontroller 150, a processor 21, and a CAN interface 22. The processor 21 is configured with, for example, one or more CPUs and is capable of executing computer programs stored in storage (not shown). The computer programs include a program for realizing information collection (step S12 in FIG. 2), which will be described later.
[0047] The CAN interface 22 is a communication module conforming to the CAN, which is a type of in-vehicle communication unit. The CAN interface 22 is connected to a CAN bus B2, whose subordinate communication nodes are the first ECU 50B and the second ECU 60.
[0048] 1, the subunit 30 includes the subcontroller 160, a processor 31, and a CAN interface 32. The processor 31 is configured with, for example, one or more CPUs and is capable of executing computer programs stored in storage (not shown). The computer programs include a program for realizing information collection (step S13 in FIG. 2), which will be described later.
[0049] The CAN interface 32 is a communication module conforming to the CAN, which is a type of in-vehicle communication unit. The CAN interface 32 is connected to a CAN bus B3, whose subordinate communication nodes are the first ECU 50 and the second ECU 60.
[0050] 1, the service unit 40 includes a processor 41 and a CAN interface 42. The processor 41 is configured with, for example, one or more CPUs and is capable of executing computer programs stored in storage (not shown). The computer programs include a program for realizing an external notification (step S18 in FIG. 2) to notify the results of on-board diagnostics, which will be described later.
[0051] The CAN interface 42 is a communication module that conforms to the CAN, which is a type of in-vehicle communication unit. The CAN interface 42 is connected to a CAN bus B4, whose subordinate communication nodes are the first ECU 50, the second ECU 60, and the TCU 70.
[0052] [Types of Abnormal Events] As shown in FIG. 1 , each of the communication nodes 10, 20, 30, 50, and 60 included in the abnormality monitoring system 100 can diagnose the presence or absence of the following events E1, E2, E3, E4, E5, E6, E7, and E8, as types of events related to abnormalities in the power supply system 200 or a communication interface, etc.
[0053] Event E1: An event related to an abnormality in the power supply system 200 monitored by the main unit 10. Event E1 is detected by the main controller 140. Event E1 includes a short circuit, open circuit, or disconnection of the power line due to a failure of relays R11, R12, or R13. Event E1 also includes overheating and overcurrent detected by a temperature sensor or current sensor provided in the main unit 10. When the main controller 140 detects event E1, it notifies the processor 11 of the detection result.
[0054] Event E2: An event related to an abnormality in CAN communication in the main unit 10. Event E2 is detected by the processor 11. Event E2 includes a failure of the CAN interface 13, an abnormality in a message received from the CAN buses B1 and B4, a communication failure that may be presumed to be caused by a break in the CAN buses B1 and B3, and the like.
[0055] Event E3: An event related to an abnormality in the power supply system 200 monitored by the subunit 20. Event E3 is detected by the subcontroller 150. Event E3 includes a short circuit, open circuit, or disconnection of the power line due to a failure of the relay R21, etc. Event E3 also includes overheating or overcurrent detected by a temperature sensor or current sensor provided in the subunit 20. When the subcontroller 150 detects event E3, it notifies the processor 21 of the detection result.
[0056] Event E4: An event related to an abnormality in CAN communication in subunit 20. Event E4 is detected by processor 21. Event E4 includes a failure of CAN interface 22, an abnormality in a message received from CAN bus B2, a communication failure that can be assumed to be caused by a break in CAN bus B2, and the like.
[0057] Event E5: An event related to an abnormality in the power supply system 200 monitored by the subunit 30. Event E5 is detected by the subcontroller 160. Event E5 includes a short circuit, an open circuit, or a disconnection of the power line due to a failure of the relay R31 or the like. Event E5 also includes overheating or overcurrent detected by a temperature sensor or a current sensor provided in the subunit 30. When the subcontroller 160 detects event E5, it notifies the processor 31 of the detection result.
[0058] Event E6: An event related to an abnormality in CAN communication in the subunit 30. Event E6 is detected by the controller 21. Event E6 includes a failure of the CAN interface 32, an abnormality in a message received from the CAN bus B3, a communication failure that may be presumed to be caused by a break in the CAN bus B3, and the like.
[0059] Event E7: An event related to an abnormality that can be detected by the first ECU 50. Event E7 includes a failure of the CAN interface of the first ECU 50, a failure of a sensor or actuator controlled by the first ECU 50, overheating or overcurrent inside the ECU, etc. When the first ECU 50 detects event E7, the first ECU 50 includes the content of the detected event E7 in, for example, an operation status response message.
[0060] Event E8: An event related to an abnormality that can be detected by the second ECU 60. Event E8 includes a failure of the CAN interface of the second ECU 60, a failure of a sensor or actuator controlled by the second ECU 60, overheating or overcurrent inside the ECU, an abnormality in the NM function (for example, inability to sleep or wake), etc. When the second ECU 60 detects event E8, it includes the detected event E6 in the response message of the operating status.
[0061] [Contents of Abnormality Monitoring Processing] FIG. 2 is a sequence diagram showing an example of abnormality monitoring processing executed in the abnormality monitoring system 100. As shown in FIG.
[0062] 2 is a trigger that instructs each unit 10, 20, 30 to collect information on the operating status. An example of the trigger T is the receipt of a UDS (Unified Diagnostic Services) message sent from an external device. Examples of the external device include a server of the vehicle manufacturer, a user's mobile terminal, or a diagnostic tool connected to the service unit 40. However, the trigger T may also be the passage of a predetermined period of time (e.g., one hour).
[0063] In the following description, each process that is executed by the main unit 10 or the sub-units 20 and 30 is actually executed by the processors 11, 21 and 31 of the main unit 10 or the sub-units 20 and 30.
[0064] 2, when the main unit 10 detects the trigger T, it executes "information collection" (step S11). In this process, the main unit 10 collects monitoring results, such as the presence or absence of events E1, E2, E7, and E8, from the monitoring targets of its own device.
[0065] Specifically, the main unit 10 causes its own main controller 140 to diagnose whether or not an event E1 has occurred, and acquires the diagnosis result from the main controller 140. The main unit 10 checks whether or not an event E2 has occurred based on the communication state in the CAN interface 13, etc.
[0066] The main unit 10 transmits an operation status request message to the first ECU 50A and checks whether the response message from the first ECU 50A includes the event E7. The main unit 10 transmits an operation status request message to the second ECU 60 and checks whether the response message from the second ECU 60 includes the event E8.
[0067] 2, when the subunit 20 detects the trigger T, it executes "information collection" (step S12). In this process, the subunit 20 collects monitoring results, such as the presence or absence of events E3, E4, and E7, from the monitoring targets of its own device.
[0068] Specifically, the subunit 20 causes its own subcontroller 150 to diagnose whether or not an event E3 has occurred, and acquires the diagnosis result from the subcontroller 150. The subunit 20 checks whether or not an event E4 has occurred from the communication state in the CAN interface 22, etc.
[0069] The subunit 20 sends an operation status request message to the first ECU 50B and checks whether the response message from the first ECU 50B includes event E7. The subunit 20 notifies the main unit 10 of the collected information (step S13). Therefore, if an abnormality such as event E3, E4, or E7 occurs in the object monitored by the subunit 20, the details of the abnormality are communicated to the main unit 10.
[0070] 2, when the subunit 30 detects the trigger T, it executes "information collection" (step S14). In this process, the subunit 30 collects monitoring results, such as the presence or absence of events E5, E6, and E7, from the monitoring targets of its own device.
[0071] Specifically, the subunit 30 causes its own subcontroller 160 to diagnose whether or not an event E5 has occurred, and acquires the diagnosis result from the subcontroller 160. The subunit 30 checks whether or not an event E6 has occurred from the communication state in the CAN interface 32, etc.
[0072] The subunit 30 sends an operation status request message to the first ECU 50C and checks whether the response message from the first ECU 50C includes event E7. The subunit 30 notifies the main unit 10 of the collected monitoring results (step S15). Therefore, if an abnormality such as event E5, E6, or E7 occurs in the object monitored by the subunit 30, the details of the abnormality are communicated to the main unit 10.
[0073] Next, the main unit 10 executes "information recording" (step S16). This process stores its own monitoring results and the monitoring results notified from the sub-units 20 and 30 in the storage 12 along with the monitoring time. Next, the main unit 10 determines whether or not the event Ei (i = 1 to 8) is included in its own monitoring results and the monitoring results notified from the sub-units 20 and 30 (step S17), and if the determination result is positive, executes "information distribution" (step S18).
[0074] This process involves sending a warning message W containing the details of the abnormal event that has occurred (e.g., event E7) and related information (e.g., CAN ID) to communication nodes within the system (subunits 20, 30, first and second ECUs 50, 60, and service unit 40).
[0075] Upon receiving the warning message W, the service unit 40 executes "external notification" (step S19), which involves generating an external message (not shown) including the notified event E7 and related information, and transmitting the generated external message to the aforementioned external device, such as the vehicle manufacturer's server.
[0076] Upon receiving the warning message W, the first ECU 50 and the second ECU 60 execute a "process for stopping related control" (step S20). This process temporarily stops the cooperative control with the CAN ID of the notified event E7, for example. This prevents the continuation of the control related to the ECU in which the abnormality occurred.
[0077] [Other Modifications] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is defined by the claims, not the above-described embodiments, and includes meanings equivalent to the claims and all modifications within the scope of the claims.
[0078] In the above-described embodiment, the network of the anomaly monitoring system 100 is a CAN network, but the network may also be an Ethernet network ("Ethernet" is a registered trademark). Furthermore, the anomaly monitoring system 100 may be configured as a network including both a CAN network and an Ethernet network. In this case, the main unit 10 may have a protocol conversion function between CAN and Ethernet.
[0079] [Additional Note] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is defined by the claims, not the above-described embodiments, and includes meanings equivalent to the claims and all modifications within the scope thereof.
[0080] 10 Main unit 11 Processor 12 Storage 13 CAN interface (in-vehicle communication unit) 20 Subunit 21 Processor 22 CAN interface (in-vehicle communication unit) 30 Subunit 31 Processor 32 CAN interface (in-vehicle communication unit) 40 Service unit 41 Processor 42 CAN interface (in-vehicle communication unit) 50 First ECU (power start ECU) 50A First ECU (power start ECU) 50B First ECU (power start ECU) 50C First ECU (power start ECU) 60 Second ECU (communication start ECU) 70 TCU 80 Switch 100 Abnormality monitoring system 110 High voltage battery 120 Converter 130 Auxiliary battery 140 Main controller 150 Subcontroller 160 Subcontroller 170 Power line 200 Power supply system 300 Vehicles E1, E2, E3, E4, E5, E6, E7, E8 Events
Claims
1. An abnormality monitoring system comprising a sub-unit that monitors the operating states of a plurality of power-start ECUs as follows: and a main unit that monitors the operating states of a plurality of communication-start ECUs as follows: The objects monitored by the sub-unit include events related to abnormalities that can be detected by the power-start ECU, and the objects monitored by the main unit include events related to abnormalities that can be detected by the communication-start ECU, and the main unit executes the following processes: determining whether or not there is an abnormality in the system based on its own monitoring results and the monitoring results notified from the sub-unit; and, if the determination result is positive, delivering the determined event to a communication node in the system. Power-start ECU: An ECU that operates or stops depending on a power source and is capable of detecting abnormalities related to its own device Communication-start ECU: An ECU that operates or stops depending on communication and is capable of detecting abnormalities related to its own device 2. The abnormality monitoring system according to claim 1, wherein the plurality of power startup ECUs include an ECU that is the object of monitoring by the sub-unit and an ECU that is the object of monitoring by the main unit.
3. An abnormality monitoring system as described in claim 1 or claim 2, further comprising a power system that supplies power to the power supply startup ECU and the communication startup ECU, and the objects monitored by the main unit and the sub-unit include events related to abnormalities in the power supply system.
4. An abnormality monitoring system as described in claim 1 or claim 2, wherein the objects monitored by the main unit include events related to abnormalities in its own in-vehicle communication unit, and the objects monitored by the sub-unit include events related to abnormalities in its own in-vehicle communication unit.
5. An abnormality monitoring method executed by a subunit that monitors the operating status of a plurality of power startup ECUs listed below, and a main unit that monitors the operating status of a plurality of communication startup ECUs listed below, wherein the objects monitored by the subunit include events related to abnormalities that can be detected by the power startup ECU, and the objects monitored by the main unit include events related to abnormalities that can be detected by the communication startup ECU, the abnormality monitoring method comprising: a step in which the main unit determines whether or not there is an abnormality in the system based on the monitoring results notified by the subunit and the monitoring results it performs itself; and a step in which the main unit distributes the determined event to a communication node in the system if the determination result is positive. Communication-activated ECU: An ECU that operates or stops via communication and can detect abnormalities related to its own device. Power-activated ECU: An ECU that operates or stops via power and can detect abnormalities related to its own device.
Citation Information
Patent Citations
Network system and managing method thereof
JP2007038816A
Vehicular power supply device
JP2016060433A
Vehicular control system
JP2018085686A
Relay control device, control system, control method and computer program
JP2023172081A