ECU control system and ECU control method

By parallel execution of software updates and remote diagnostics through non-interfering communication paths, the ECU control system addresses the issue of reduced diagnostic data acquisition, improving data collection efficiency.

WO2026069602A1PCT designated stage Publication Date: 2026-04-02NISSAN MOTOR CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-27
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing vehicle control systems face a decrease in diagnostic data acquisition rate due to interference between software update and remote diagnosis processes, leading to incomplete data acquisition during simultaneous operations.

Method used

The management ECU performs parallel execution of software updates and remote diagnostics by identifying non-interfering communication paths between ECUs, allowing simultaneous data acquisition and update processes.

Benefits of technology

This approach increases the acquisition rate of diagnostic data by ensuring that software updates and remote diagnostics can be conducted concurrently without interference, thereby enhancing data collection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024034719_02042026_PF_FP_ABST
    Figure JP2024034719_02042026_PF_FP_ABST
Patent Text Reader

Abstract

In an ECU control system 100, a management ECU 30 performs first communication with a first ECU to update software of the first ECU, and performs second communication with a second ECU to acquire diagnostic data from the second ECU. When the first communication and the second communication do not interfere with each other, the management ECU 30 executes software update and remote diagnosis in parallel.
Need to check novelty before this filing date? Find Prior Art

Description

ECU Control System and ECU Control Method

[0001] The present invention relates to an ECU control system and an ECU control method.

[0002] Conventionally, a program update technology for collectively managing the update status of software installed in a vehicle control device is known. The vehicle control device described in Patent Document 1 aggregates the first update status of the first program executed by the vehicle control device and the second update status of the second program executed by the second vehicle control device, and transmits them to an update server. It receives updated version programs corresponding to the first update status and the second update status from the update server and performs update processing.

[0003] Japanese Unexamined Patent Application Publication No. 2022-107913

[0004] In the vehicle control device described in Patent Document 1, when a remote diagnosis command is received from outside the vehicle or when it is time to execute remote diagnosis during software update of the vehicle control device, it is not determined how to process software update and remote diagnosis respectively. Therefore, although it is possible to configure logic so as not to accept remote diagnosis during software update, there is a problem that diagnostic data used for remote diagnosis cannot be acquired from the vehicle control device and the acquisition rate of diagnostic data decreases.

[0005] The problem to be solved by the present invention is to provide an ECU control system and an ECU control method with an increased acquisition rate of diagnostic data.

[0006] The present invention performs first communication with a first ECU to update the software of the first ECU, performs second communication with a second ECU to acquire diagnostic data from the second ECU, and when the first communication and the second communication do not interfere, the management ECU 30 solves the above problem by executing software update and remote diagnosis in parallel.

[0007] According to the present invention, the acquisition rate of diagnostic data can be increased.

[0008] FIG. 1 is a schematic configuration diagram of the ECU control system according to the present embodiment.

[0009] Hereinafter, embodiments of the ECU control system according to the present invention will be described with reference to the drawings.

[0010] Figure 1 is a schematic diagram of the configuration of the ECU control system 100, remote diagnostic server 1, and software update server 2 according to this embodiment. The ECU control system 100 according to this embodiment is a system that controls a plurality of ECUs and is mounted on a vehicle. The vehicle is a hybrid vehicle or electric vehicle equipped with an engine and a motor. The ECU control system 100 may also be mounted on a vehicle that obtains power from an engine (ICE vehicle). The ECU control system 100 includes a communication unit 10, an OBD terminal 20, a management ECU 30, a VCM 40, an IVI 41, a BMS 42, an ADCU 50, a camera 51, a LiDAR 52, a BCM 60, an ACU 61, a Meter 62, and buses 400-402, 500-502, and 600-602. The ECUs and loads (onboard devices) included in the ECU control system 100 are connected by an in-vehicle communication network such as CAN or LIN.

[0011] Remote diagnostic server 1 is a server that diagnoses the condition of a vehicle remotely. Remote diagnostic server 1 connects to the vehicle wirelessly and accesses the vehicle remotely to diagnose its condition. Remote diagnostic server 1 sends a diagnostic command to the vehicle to be diagnosed. Remote diagnostic server 1 sends a diagnostic command after specifying the data to be extracted from the vehicle. Remote diagnostic server 1 may also send a diagnostic command after specifying the ECU to be diagnosed from among the ECUs included in the vehicle. Remote diagnostic server 1 uses the data obtained from the vehicle to diagnose whether or not there is an abnormality in the vehicle. The data sent from the vehicle to remote diagnostic server 1 includes fault codes (DTCs), ECU logs, or data indicating the vehicle's driving status. In remote diagnosis, the diagnosis of whether or not there is an abnormality in the vehicle may be performed on the server side or on the vehicle side.

[0012] The software update server 2 is a system for sending and receiving data via OTA (over-the-air) communication (wireless communication) and manages the updates of the ECU software (firmware) included in the ECU control system 100. The software update server 2 stores update data for updating the ECU software in a database and sends the update data to the vehicle in response to an update request. The update data is the latest software data. The update data may also include the time required for the software update. The software update server 2 manages campaigns in the database that include vehicle identification information (VIN) and ECU identification information (e.g., ECU name). For example, when the latest version of the ECU software is uploaded, the software update server 2 sends an update request signal to obtain the information necessary for the software update from the vehicle. The update request signal may include the software to be updated or the identification information (ID) of the ECU. The vehicle's ECU control system 100 sends a signal to the software update server 2 that includes ECU update information (version information), etc., in response to a request from the software update server 2. The software update server 2 determines from the update information whether the ECU software is up to date. If the software update server 2 determines that the current version of the ECU is outdated, it sends the latest software (update data, reprogramming data) to the vehicle. The management ECU 30 of the vehicle's ECU control system 100 downloads the update data sent from the software update server 2. The ECU control system 100 then uses the update data to update the software of the ECU to be updated.

[0013] Next, the configuration of the ECU control system 100 will be described. The communication unit 10 controls the in-vehicle communication device to connect to a communication network such as an internet line (mobile line) and communicates with the remote diagnostic server 1 and the software update server 2.

[0014] The OBD terminal (On-Board Diagnostics) 20 is a connection terminal for connecting an external diagnostic terminal to the ECU via a cable. The OBD terminal 20 is also called a DLC connector. For example, a user takes their vehicle to a dealer or repair shop for maintenance. The worker connects the diagnostic terminal to the OBD terminal 20 via a wire and sends a diagnostic command to the vehicle. The ECU control system 100 outputs data necessary for fault diagnosis in response to the diagnostic command input from the OBD terminal 20. The data necessary for fault diagnosis includes fault codes (DTCs), ECU logs, or data indicating the vehicle's driving status. In the following description, a diagnosis performed with the diagnostic terminal connected to the OBD terminal 20 via a wire is also referred to as an OBD diagnosis.

[0015] The management ECU 30 connects multiple ECUs downstream and forwards signals transmitted from one ECU to another. In other words, the management ECU 30 functions as a gateway. The management ECU 30 is connected to the communication unit 10 and the OBD terminal 20, and performs software updates, remote diagnostics, and OBD diagnostics based on commands input from the communication unit 10 and / or the OBD terminal.

[0016] The management ECU 30 connects to the VCM 40 via bus 400, to the ADCU 50 via bus 500, and to the BCM 60 via bus 600.

[0017] This section describes the software update process performed by the management ECU 30. The management ECU 30 receives a software update command from the software update server 2 via the communication unit 10 to perform the software update. The software update command corresponds to an update request signal and / or a signal containing the latest software. Based on the software update command, the management ECU 30 identifies the target ECU for software update, or an ECU that is eligible for software update. The target ECU is an ECU connected downstream of the management ECU 30, for example, VCM 40, ADCU 50, and BCM 60, or an ECU connected downstream of VCM 40, ADCU 50, and BCM 60. The management ECU 30 downloads the software update data from the software update server 2 and stores it in its memory. The management ECU 30 assigns a software update ID to the target ECU and sends and receives signals to the target ECU in order to send and receive the data necessary for the software update.

[0018] The target ECU has memory for storing software. In the software update sequence control, the target ECU communicates with the management ECU 30 to identify the version information and software associated with the software update ID from the data stored in memory, and then transmits the version information of the target ECU, installs the software, and activates the software. Specifically, when the target ECU receives the software, the software is written to the target ECU's memory (installation). With both the old and new software stored in memory, the target ECU switches the software to be processed from the old software to the new software (activation). In this embodiment, the process for such software updates does not necessarily have to be performed in a continuous sequence; the target ECU may first perform the software installation and then, separately, perform the activation when the management ECU 30 receives an update start request.

[0019] Remote diagnosis by the management ECU 30 will now be described. The management ECU 30 receives a diagnostic command to perform remote diagnosis from the remote diagnosis server 1 via the communication unit 10. Based on the diagnostic command, the management ECU 30 identifies the target ECU to be remotely diagnosed. The target ECU is an ECU connected downstream of the management ECU 30, or downstream of the VCM 40, ADCU 50, and BCM 60. The management ECU 30 assigns a diagnostic ID to the target ECU and transmits and receives signals with the target ECU in order to send and receive data used for remote diagnosis.

[0020] The target ECU stores fault codes (DTCs), ECU logs, or data indicating the vehicle's driving status in its memory as diagnostic data used for diagnosis. In the diagnostic sequence control, the target ECU communicates with the management ECU 30 to identify the data associated with the diagnostic ID from the data stored in memory, and transmits the identified diagnostic data to the management ECU 30. The management ECU 30 transmits the diagnostic data transmitted from the target ECU to the remote diagnostic server 1. As a result, the management ECU 30 communicates with the remote diagnostic server 1 and obtains diagnostic data from the target ECU to be used for diagnosing the vehicle's condition. The management ECU 30 then transmits the diagnostic data obtained from the target ECU to the remote diagnostic server 1 via the communication unit 10. The management ECU 30 may perform a remote diagnosis immediately after receiving a diagnostic command from the remote diagnostic server 1, or it may perform a remote diagnosis at a predetermined execution timing. The predetermined execution timing may be a periodic timing, such as once a day, or it may be the timing of switching the power switch (ignition switch or power switch) on and off.

[0021] This section describes the OBD diagnosis performed by the management ECU 30. The management ECU 30 communicates with the diagnostic terminal while a wired connection (cable) is connected to the OBD terminal 20, and receives diagnostic commands from the diagnostic terminal. The management ECU 30 identifies the target ECU to be diagnosed using the same method as in remote diagnosis. The management ECU 30 also assigns a diagnostic ID to the target ECU and sends a command to acquire data used for diagnosis. The target ECU identifies the data based on the command with the assigned diagnostic ID and transmits the identified data to the management ECU 30. The method for identifying data based on the diagnostic ID is the same as in remote diagnosis. The management ECU 30 transmits the data transmitted from the target ECU to the diagnostic terminal. In this way, the management ECU 30 can communicate with the diagnostic terminal via a wired connection and acquire data used for diagnosing the vehicle's condition from the target ECU. The management ECU 30 then transmits the data acquired from the target ECU to the diagnostic terminal via the OBD terminal 20.

[0022] VCM40, ADCU50, and BCM60 are ECUs and are connected downstream of the management ECU30 via buses 400, 500, and 600. Note that the communication unit 10, management ECU30, VCM40, ADCU50, and BCM60 are examples of multiple ECUs included in a vehicle, and the vehicle may include other ECUs. Furthermore, the management ECU30 is not limited to CM40, ADCU50, and BCM60, and may be connected to other ECUs.

[0023] The VCM (Vehicle Control Module) 40 is a control unit that controls the vehicle's drivetrain. The VCM 40 monitors the amount of accelerator pedal depression and controls the drivetrain, such as the motor and engine. Downstream of the VCM 40 are connected the INV (Inverter) 41, BMS (Battery Management System) 42, etc. The INV 41 is connected to bus 401, which branches off from bus 400 downstream of the VCM 40. The INV 41 is connected between the vehicle battery and the vehicle motor, and converts the voltage of the vehicle battery to output to the vehicle motor. The BMS 42 is a control unit (ECU) for controlling the charging and discharging of the vehicle battery. The BMS 42 is connected to bus 402, which branches off from bus 400 downstream of the VCM 40. If the vehicle is an ICE vehicle or a hybrid vehicle, the engine is connected downstream of the VCM 40. Furthermore, the downstream of VCM40 may be connected to other devices besides INV41 and BMS42, such as a DC-DC converter.

[0024] The ADCU (Assisted Driving Control Unit) 50 is a control unit that assists in the driving of the vehicle. A camera 51, LiDAR 52, etc., are connected downstream of the ADCU 50. The camera 51 is connected to bus 501, which branches off from bus 500 downstream of the ADCU 50. The LiDAR 52 is connected to bus 502, which branches off from bus 500 downstream of the ADCU 50. The ADCU 50 detects white lines from the image captured by the camera 51 and performs steering control to prevent the vehicle from deviating from its lane. The ADCU 50 also measures the distance to the preceding vehicle from the detection data of the LiDAR 52 and performs steering control and / or vehicle speed control to maintain the distance between the preceding vehicle and the vehicle itself and to follow the preceding vehicle. Note that, in addition to the camera 51 and LiDAR 52, a memory containing high-precision map data may also be connected downstream of the ADCU 50. The ADCU 50 may not only perform lane departure prevention control and preceding vehicle following control, but may also use high-precision maps to recognize the road layout and perform autonomous driving control that is appropriate to the current road conditions.

[0025] The BCM (Body Control Module) 60 is a control unit that controls the overall functions of the vehicle body, including interior and exterior lighting, doors, windows, mirrors, and wipers. Downstream of the BCM 60 are the ACU (Airbag Control Unit) 61, Meter 62, etc. The ACU 61 is connected to bus 601, which branches off from bus 600 downstream of the BCM 60. The Meter 62 is connected to bus 602, which branches off from bus 600 downstream of the ADCU 50. The ACU 61 is an airbag control unit (ECU). The Meter 62 displays speed, etc. Note that downstream of the BCM 60, other components such as HVAC (Heating Ventilation and Air-Conditioning) may be connected, not just the ACU 61 and Meter 62.

[0026] Bus 400 is a bus that groups the VCM 40 and multiple ECUs downstream of the VCM 40. Bus 400 branches downstream of the VCM 40, and the branched buses 401 and 402 are each connected to an ECU or load. Note that buses 401 and 402 may be connected to more than one ECU or load, or multiple ECUs and / or multiple loads. Buses 500-502 and buses 600-602 have the same communication network as buses 400-402. Note that an ECU or load may be connected between the management ECU 30 and the VCM 40, ADCU 50, and BCM 60. In this way, the ECU control system 100 consists of multiple control groups divided according to the basic configuration of the vehicle. These control groups are also called domains. For example, in the example in Figure 1, there is a vehicle drive system domain including the VCM 40, a vehicle driving support system domain including the ADCU 50, and a body domain including the BCM 60. The domains include a multimedia domain that controls information display within the vehicle, a powertrain domain that controls the engine, and a chassis domain that controls the steering mechanism. By defining the domain configuration, the configurations of buses 400-402, 500-502, and 600-602 can be separated.

[0027] Incidentally, when the management ECU 30 performs software updates, remote diagnostics, and OBD diagnostics, it may assign the same ID to the software update ID and the update ID. For example, if the ECU targeted for software updates and the ECU targeted for remote diagnostics are the same ECU, and the data stored in the target ECU's memory that is targeted for software updates and the data identified for diagnostics are the same, the management ECU 30 assigns the same ID and sends a control command to the target ECU. The target ECU identifies the data and transmits the data based on the control command sent from the management ECU 30. For example, suppose the target ECU is performing a software update based on a control command with a predetermined ID, and at the same time receives a control command for remote diagnostics with the same ID from the management ECU 30. Since the target ECU cannot determine which process, software update or remote diagnostics, should take priority, receiving a control command with the same ID from the management ECU 30 will cause interference between the software update and the remote diagnostics. As a result, the management ECU 30 may not be able to acquire the data used for remote diagnostics, and the software update for the target ECU may not be completed.

[0028] Interference between software update processing and remote diagnostic processing occurs when communication for performing software updates and communication for performing remote diagnostics interfere with each other between the management ECU 30 and multiple ECUs connected downstream of the management ECU 30. On the other hand, if communication for performing software updates and communication for performing remote diagnostics do not interfere with each other, there will be no interference between the software update and remote diagnostic processes.

[0029] Therefore, in this embodiment, the management ECU 30 executes software updates and remote diagnostics in parallel if the communication for performing software updates and the communication for performing remote diagnostics do not interfere with each other.

[0030] The management ECU 30 identifies the second ECU to be remotely diagnosed when it receives a remote diagnostic command while performing a software update on the first ECU, or when it is time to perform a remote diagnostic. The first and second ECUs are ECUs such as VCM 40, IVI 41, BMS 42, ADCU 50, camera 51, LiDAR 52, BCM 60, ACU 61, and Meter 62, which are connected downstream of the management ECU 30. The first ECU is the ECU to be updated, and the second ECU is the ECU to be remotely diagnosed. The management ECU 30 also identifies the first communication used when updating the software of the first ECU and the second communication used when performing a remote diagnostic on the second ECU. The first communication is the communication that takes place between the management ECU 30 and the first ECU when updating the software of the first ECU. The second communication is the communication that takes place between the management ECU 30 and the second ECU when performing a remote diagnostic on the second ECU. The management ECU 30 then determines whether the first communication and the second communication interfere with each other. The management ECU 30 compares the buses through which signals flow in the first communication and the buses through which signals flow in the second communication, and determines that the first and second communications interfere if there is overlap in at least some of the buses. On the other hand, the management ECU 30 compares the buses through which signals flow in the first communication and the buses through which signals flow in the second communication, and determines that the first and second communications do not interfere if there is no overlap in any of the buses. If the first and second communications do interfere, the management ECU 30 performs a remote diagnosis on the second ECU after completing the software update on the first ECU. Alternatively, the management ECU 30 interrupts the software update on the first ECU and starts a remote diagnosis on the second ECU. The management ECU 30 then resumes the software update on the first ECU after completing the remote diagnosis on the second ECU. On the other hand, if the first and second communications do not interfere with each other, the management ECU 30 performs a software update for the first ECU and a remote diagnosis for the second ECU in parallel.

[0031] For example, let's assume that the first ECU is BMS42 and the second ECU is ACU61. When updating the software of BMS42, the management ECU30 and BMS42 communicate via buses 400 and 402 (corresponding to the first communication). When performing remote diagnostics on ACU61, the management ECU30 and ACU61 communicate via buses 600 and 601 (corresponding to the second communication). Since buses 400, 402 and buses 600, 601 do not overlap, the first and second communications do not interfere with each other. For example, the management ECU30 can send data for software updates to BMS42 and simultaneously acquire diagnostic data from ACU61. Therefore, the management ECU30 can perform software updates for BMS42 and remote diagnostics for ACU61 in parallel. In other words, the management ECU30 can perform remote diagnostics without interrupting a software update process that is already underway, or without waiting for the software update to complete.

[0032] On the other hand, let's assume, for example, that the first ECU is BMS42 and the second ECU is INV41. When updating the software of BMS42, the management ECU 30 and BMS42 communicate (corresponding to the first communication) via buses 400 and 402. Also, when performing remote diagnostics on INV41, the management ECU 30 and INV41 communicate (corresponding to the second communication) via buses 400 and 401. Because there is bus duplication on bus 400, the first and second communications interfere with each other. Therefore, the management ECU 30 does not perform software updates for BMS421 and remote diagnostics for ACU61 in parallel.

[0033] As described above, in this embodiment, the management ECU 30 performs a first communication with the first ECU to update the software of the first ECU, and performs a second communication with the second ECU to acquire diagnostic data from the second ECU. If the first and second communications do not interfere with each other, the management ECU 30 performs the software update and remote diagnosis in parallel. This makes it possible to increase the acquisition rate of diagnostic data.

[0034] In this embodiment, the first ECU is connected to the management ECU 30 via a first bus, and the second ECU is connected to the management ECU 30 via a second bus. When the management ECU 30 performs software updates and remote diagnostics in parallel, it performs first communication via the first bus and second communication via the second bus. This increases the acquisition rate of diagnostic data. The first bus is used when the software of the first ECU is updated and communication is performed between the first ECU and the management ECU 30, and the second bus is used when remote diagnostics are performed on the second ECU and communication is performed between the second ECU and the management ECU 30. This increases the acquisition rate of diagnostic data.

[0035] Furthermore, in this embodiment, the ECU control method executed by the management ECU 30 includes performing a software update to update the software of the first ECU by acquiring data from outside the vehicle, performing a remote diagnosis to acquire diagnostic data used to diagnose the vehicle's condition from the second ECU by communicating with a remote server, and executing the software update and remote diagnosis in parallel if the first communication between the management ECU and the first ECU during the software update of the first ECU and the second communication between the management ECU and the second ECU during the remote diagnosis of the second ECU do not interfere with each other. This makes it possible to increase the acquisition rate of diagnostic data.

[0036] As a modification of this embodiment, the management ECU 30 may download update data for updating the software of the target ECU from the remote diagnostic server 1, and perform a remote diagnosis on the target ECU while the update data is being downloaded from the remote diagnostic server 1. When the ECU to be updated and the ECU to be diagnosed remotely are the same, the same bus is used for communication between the management ECU 30 and the target ECU for the software update and for the remote diagnosis. The software update includes a process of receiving update data transmitted from the software update server 2 and saving it to the in-vehicle memory (hereinafter referred to as the vehicle download process). The vehicle download process is performed by the management ECU 30, but is performed via the bus connecting the communication unit 10 and the management ECU 30. On the other hand, the remote diagnosis may be performed at a predetermined execution timing, and depending on the remote diagnosis sequence, the remote diagnosis can be performed without using the bus connecting the communication unit 10 and the management ECU 30. Therefore, while the management ECU 30 is downloading update data from the remote diagnostic server 1 to update the software of the target ECU, the software update communication and the remote diagnostic communication may not interfere with each other. For this reason, in the modified example, even if the ECU to be updated and the ECU to be diagnosed are the same, the software update and the remote diagnostic are executed in parallel during periods when the software update process and the remote diagnostic process do not interfere with each other, according to the sequence control of the software update. This makes it possible to increase the acquisition rate of diagnostic data.

[0037] 1 Remote diagnostic server 2 Software update server 10 Communication unit 20 OBD terminal 30 Management ECU 40 VCM 50 ADCU 60 BCM 100 ECU control system 400-402, 500-502, 600-602 bus

Claims

1. An ECU control system mounted on a vehicle, comprising: a management ECU that performs software updates by acquiring data from outside the vehicle and updating the ECU's software; a management ECU that communicates with a remote server and performs remote diagnostics by acquiring diagnostic data from the ECU used to diagnose the vehicle's condition; and a first ECU and a second ECU connected to the management ECU via a communication network, wherein the management ECU performs first communication with the first ECU and updates the software of the first ECU; performs second communication with the second ECU and acquires the diagnostic data from the second ECU; and performs the software update and the remote diagnostics in parallel when the first and second communications do not interfere with each other.

2. An ECU control system according to claim 1, wherein the first ECU is connected to the management ECU by a first bus, the second ECU is connected to the management ECU by a second bus, and the management ECU performs the first communication via the first bus and the second communication via the second bus when performing the software update and the remote diagnosis in parallel.

3. An ECU control system according to claim 1 or 2, wherein the management ECU downloads update data for updating the software of the target ECU from a server, and performs the remote diagnosis on the target ECU while the update data is being downloaded from the server.

4. An ECU control method executed by a management ECU mounted on a vehicle, comprising: performing a software update to update the software of a first ECU by acquiring data from outside the vehicle; performing a remote diagnosis by communicating with a remote server and acquiring diagnostic data used to diagnose the state of the vehicle from a second ECU; and performing the software update and the remote diagnosis in parallel if the first communication between the management ECU and the first ECU during the software update of the first ECU and the second communication between the management ECU and the second ECU during the remote diagnosis of the second ECU do not interfere with each other.

Citation Information

Patent Citations

  • Communication device using shared priority id

    JP2014171131A

  • Relay device, communication system, transmission method, and computer program

    JP2018046515A

  • Electronic controller and session establishing program

    JP2020021506A

  • Control system, movable object, control method, and program

    JP2022108390A

  • Method for interacting with a computer on an onboard bus of a vehicle - Patent Application 20070122997

    JP2022538080A