ECU control system and ECU control method
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NISSAN MOTOR CO LTD
- Filing Date
- 2024-11-27
- Publication Date
- 2026-06-04
Smart Images

Figure JP2024042002_04062026_PF_FP_ABST
Abstract
Description
ECU Control System and ECU Control Method
[0001] The present invention relates to an ECU control system and an ECU control method.
[0002] Conventionally, a vehicle control system that automatically runs a vehicle to a target position in response to an operation on a mobile terminal by a user outside the vehicle is known (for example, Patent Document 1). In the vehicle control system of Patent Document 1, the vehicle includes a communication unit configured to be able to perform wireless communication with a mobile terminal when in an activated state, and a plurality of ECUs. When an electronic key wireless signal is received while the communication unit is in a non-activated state, it is determined whether the key identifier included in the electronic key wireless signal matches a vehicle-specific identifier stored in advance. If it is determined that the key identifier and the vehicle-specific identifier match, it is determined that the activation condition is satisfied, and the communication unit is activated.
[0003] Japanese Unexamined Patent Application Publication No. 2022-48453
[0004] In the vehicle control system described in Patent Document 1, even if the communication unit is activated, if other ECUs other than the communication unit are not activated, a user outside the vehicle cannot control the in-vehicle device by operating the mobile terminal, so the ECU for controlling the in-vehicle device must be activated. Therefore, there is a problem that it takes time to receive a command to operate the in-vehicle device from the mobile terminal until the ECU is activated.
[0005] The problem to be solved by the present invention is to provide an ECU control system and an ECU control method that accelerate the activation timing of the ECU.
[0006] In the present invention, the management ECU is activated based on a terminal command of a communication terminal, determines whether to activate a downstream ECU based on remote operation information of a registered user, and transmits an activation command to the downstream ECU according to the determination result to solve the above problem.
[0007] According to the present invention, the activation timing of the ECU can be accelerated.
[0008] Figure 1 is a schematic diagram of the configuration of the ECU control system, communication terminal, and communication network according to this embodiment. Figure 2 is a time chart for explaining the BCM startup timing and actuator drive timing. Figure 3 is a flowchart showing the control flow of the ECU control system.
[0009] Hereinafter, embodiments of the ECU control system according to the present invention will be described with reference to the drawings.
[0010] Figure 1 is a schematic diagram of the configuration of the ECU control system 100, communication terminal 200, and communication network 300 according to this embodiment. The ECU control system 100 according to this embodiment is a system that controls a plurality of ECUs and is mounted on a vehicle. The vehicle is a hybrid vehicle or electric vehicle equipped with an engine and a motor. The ECU control system 100 may also be mounted on a vehicle that obtains power from an engine (ICE vehicle). The ECU control system 100 includes a communication unit 10, memory 20, management ECU 30, VCM 40, IVI 41, BMS 42, ADCU 50, camera 51, LiDAR 52, BCM 60, ACU 61, Meter 62, and buses 400-402, 500-502, and 600-602. The ECUs and loads (on-board devices) included in the ECU control system 100 are connected by an in-vehicle communication network such as CAN or LIN.
[0011] Next, the configuration of the ECU control system 100 will be described. The communication unit 10 controls the in-vehicle communication device to connect with the communication terminal 200 via a communication network 300 such as an internet line (mobile line), and communicates with the communication terminal 200.
[0012] Memory 20 stores data related to the user and / or vehicle, such as registered user data, remote operation data, and vehicle status data. User registration data includes user information, etc., of users who are permitted to access the vehicle from the outside. For example, when a user wants to check the current status of the vehicle from outside the vehicle, such as the remaining battery level or the temperature inside the vehicle, or when they want to control in-vehicle devices from outside the vehicle, such as operating the air conditioner, unlocking the door lock function, or setting a destination in the navigation system, the user accesses the vehicle by operating the communication terminal 200. Only registered users who have been registered in advance are allowed to access the vehicle, and the user's registration information is included in the registered user data. The user's registration information may also include identification information of the communication terminal 200. When the communication terminal 200 accesses the vehicle, access may be permitted by password authentication or the like.
[0013] Remote operation data includes remote operation information indicating that an in-vehicle device was driven by remote operation. For example, if a user operates the communication terminal 200 to access the vehicle from the outside and unlocks the door lock mechanism before getting in, the act of driving the actuator to unlock the door lock via remote operation becomes part of the in-vehicle device's drive history. In other words, the remote operation information corresponds to the history information of the in-vehicle device used by the user before getting in. In the following explanation, the act of a user operating the communication terminal 200 to access the vehicle from outside will also be simply referred to as "remote operation." The memory 20 stores the remote operation information and the information of the registered user who performed the remote operation as remote operation data.
[0014] Vehicle status data is data that indicates the current state of the vehicle and includes information such as the remaining battery capacity, the temperature inside the vehicle, the mileage, and the usage period of consumables such as brake fluid. By acquiring vehicle status data through remote operation, the user can check the current vehicle status on the communication terminal 200.
[0015] The management ECU 30 has multiple ECUs connected downstream and forwards signals transmitted from one ECU to another. In other words, the management ECU 30 functions as a gateway. The management ECU 30 has a communication unit 10 connected upstream and receives commands from the communication terminal 200 via the communication unit 10. The management ECU 30 is in sleep mode when the vehicle is parked. For example, while the management ECU 30 is in sleep mode, the communication terminal 200 sends a terminal command to the communication unit 10 via remote operation. The management ECU 30 receives the terminal command from the communication unit 10. Then, the management ECU 30 starts up based on the terminal command. The terminal command is a command to access the vehicle from outside the vehicle by the communication terminal 200 and includes at least one of the following: identification information of the communication terminal 200, user information entered into the communication terminal 200, and user information recorded in the communication terminal 200. The management ECU 30 may perform user authentication when it starts up from sleep mode. For example, the management ECU 30 performs user authentication by comparing the user information included in the terminal command with the user registration information stored in the memory 20. The management ECU 30 may then start up after confirming that the user authentication result does not indicate unauthorized access.
[0016] Multiple ECUs are connected downstream of the management ECU 30. In the example shown in Figure 1, the management ECU 30 is connected to the VCM 40 via bus 400, the ADCU 50 via bus 500, and the BCM 60 via bus 600. The management ECU 30 is not limited to the VCM 40, ADCU 50, and BCM 60; other ECUs may also be connected. In the following description, ECUs such as the VCM 40 connected downstream of the management ECU 30 will be collectively referred to as "downstream ECUs."
[0017] The VCM (Vehicle Control Module) 40 is a control unit that controls the vehicle's drivetrain. The VCM 40 monitors the amount of accelerator pedal depression and controls the drivetrain, such as the motor and engine. Downstream of the VCM 40 are connected the INV (Inverter) 41, BMS (Battery Management System) 42, etc. The INV 41 is connected to bus 401, which branches off from bus 400 downstream of the VCM 40. The INV 41 is connected between the vehicle battery and the vehicle motor, and converts the voltage of the vehicle battery to output to the vehicle motor. The BMS 42 is a control unit (ECU) for controlling the charging and discharging of the vehicle battery. The BMS 42 is connected to bus 402, which branches off from bus 400 downstream of the VCM 40. If the vehicle is an ICE vehicle or a hybrid vehicle, the engine is connected downstream of the VCM 40. Furthermore, the downstream of VCM40 may be connected to other devices besides INV41 and BMS42, such as a DC-DC converter.
[0018] The ADCU (Assisted Driving Control Unit) 50 is a control unit that assists in the driving of the vehicle. A camera 51, LiDAR 52, etc., are connected downstream of the ADCU 50. The camera 51 is connected to bus 501, which branches off from bus 500 downstream of the ADCU 50. The LiDAR 52 is connected to bus 502, which branches off from bus 500 downstream of the ADCU 50. The ADCU 50 detects white lines from the image captured by the camera 51 and performs steering control to prevent the vehicle from deviating from its lane. The ADCU 50 also measures the distance to the preceding vehicle from the detection data of the LiDAR 52 and performs steering control and / or vehicle speed control to maintain the distance between the preceding vehicle and the vehicle itself and to follow the preceding vehicle. Note that, in addition to the camera 51 and LiDAR 52, a memory containing high-precision map data may also be connected downstream of the ADCU 50. The ADCU 50 may not only perform lane departure prevention control and preceding vehicle following control, but may also use high-precision maps to recognize the road layout and perform autonomous driving control that is appropriate to the current road conditions.
[0019] The BCM (Body Control Module) 60 is a control unit that controls the overall functions of the vehicle body, including interior and exterior lighting, doors, windows, mirrors, and wipers. Downstream of the BCM 60 are the ACU (Airbag Control Unit) 61, Meter 62, etc. The ACU 61 is connected to bus 601, which branches off from bus 600 downstream of the BCM 60. The actuator 62 is a drive device for switching the door lock mechanism between unlocking and locking. Note that downstream of the BCM 60, in addition to the ACU 61 and actuator 62, meters, HVAC (Heating Ventilation and Air-Conditioning), etc., may also be connected.
[0020] Bus 400 is a bus that groups the VCM 40 and multiple ECUs downstream of the VCM 40. Bus 400 branches downstream of the VCM 40, and the branched buses 401 and 402 are each connected to an ECU or load. Note that buses 401 and 402 may be connected to more than one ECU or load, or multiple ECUs and / or multiple loads. Buses 500-502 and buses 600-602 have the same communication network as buses 400-402. Note that an ECU or load may be connected between the management ECU 30 and the VCM 40, ADCU 50, and BCM 60. In this way, the ECU control system 100 consists of multiple control groups divided according to the basic configuration of the vehicle. These control groups are also called domains. For example, in the example in Figure 1, there is a vehicle drive system domain including the VCM 40, a vehicle driving support system domain including the ADCU 50, and a body domain including the BCM 60. The domains include a multimedia domain that controls information display within the vehicle, a powertrain domain that controls the engine, and a chassis domain that controls the steering mechanism. By defining the domain configuration, the configurations of buses 400-402, 500-502, and 600-602 can be separated.
[0021] While the vehicle is parked, downstream ECUs such as the VCM40 are in sleep mode. After the management ECU 30 is activated based on a terminal command, it identifies the user attempting to access the vehicle remotely from the user information or terminal identification information included in the terminal command. The management ECU 30 determines whether the remote operation data recorded in memory 20 contains information about the user attempting to access the vehicle. If the remote operation data contains information about the user attempting to access the vehicle, the management ECU 30 extracts the remote operation information corresponding to the user attempting to access the vehicle from the registered user information included in the remote operation data. Based on the registered user's remote operation information, the management ECU 30 determines whether or not to activate the downstream ECU. That is, the management ECU 30 determines, based on usage history information, whether or not the user attempting to access the vehicle has previously controlled the in-vehicle device remotely from outside the vehicle. If the user has previously controlled the in-vehicle device remotely from outside the vehicle, the management ECU 30 pre-activates the downstream ECU that controls the in-vehicle device to advance the activation timing of the downstream ECU.
[0022] For example, if user A previously operated actuator 62 remotely to unlock the door lock, the memory 20 stores this remote operation information, indicating that user A operated actuator 62 remotely. When user A operates their communication terminal 200 to access a parked vehicle remotely, the communication terminal 200 sends a terminal command. After starting up based on the terminal command, the management ECU 30 determines to start the BCM 60 to control actuator 62 based on the history information of actuator 62 indicated by the remote operation information. On the other hand, if user A's remote operation data does not include remote operation information for in-vehicle devices controlled by the BCM 60, such as the ACU 61 or actuator 62, the management ECU 30 determines not to start the BCM 60. Thus, the management ECU 30 determines whether to start the downstream ECU based on the remote operation information of the registered user registered in relation to the communication terminal 200 that sent the terminal command.
[0023] The management ECU 30 then sends a start command to the downstream ECUs that it determines should be started, and does not send a start command to the ECUs that it determines should not be started. In this way, the management ECU 30 sends a start command to the downstream ECUs based on the determination result.
[0024] Furthermore, the management ECU 30 controls the communication unit 10 to transmit vehicle status data to the communication terminal 200 after the management ECU 30 is started up.
[0025] The communication terminal 200 is a mobile device operated by the user, such as a smartphone. The communication terminal 200 has a vehicle control application (hereinafter also referred to as the "vehicle control app") installed. The vehicle control app allows for remote operation to check the current vehicle status and control in-vehicle devices. When the user launches the vehicle control app, the communication terminal 200 sends a terminal command to the parked vehicle via the communication network 300. The vehicle's communication unit 10 receives the terminal command, and the management ECU 30 starts up based on the terminal command. In other words, the terminal command to start the management ECU 30 is sent from the communication terminal 200 to the vehicle when the vehicle control app is launched. After the management ECU 30 starts up, the communication terminal 200 receives vehicle status data from the vehicle. The user can check the current vehicle status on the vehicle control app on the communication terminal 200. When the user controls an in-vehicle device remotely, they can select the in-vehicle device to control on the vehicle control app. The communication terminal 200 transmits commands to the vehicle to control the in-vehicle device selected by the user.
[0026] Next, the startup timing of the downstream ECU in this embodiment and the startup timing of the downstream ECU in the reference example will be explained. As an example of the startup timing of the downstream ECU in this embodiment, user A has previously unlocked the lock by remotely operating the actuator 62, and the remote operation data is recorded in memory 20, associating user A's registration information with the remote operation information of actuator 62. Figure 2 is a time chart for explaining the startup timing of the BCM 60 and the driving timing of actuator 62, where (a) is the time chart of this embodiment and (b) is the time chart of the reference example. Initially, the vehicle is parked, and the management ECU 30 is in sleep mode or shutdown mode (hibernation mode). The downstream ECU is in shutdown mode.
[0027] The time chart of this embodiment will be explained with reference to Figure 2(a). The user operates the communication terminal 200 and the vehicle control application starts up. The communication terminal 200 sends a terminal command to the vehicle. In step S1, the communication unit 10 receives the terminal command. The communication unit 10 also sends the terminal command to the management ECU 30. In step S2, the management ECU 30 starts up when it receives the terminal command and changes from a sleep state or shutdown state to an up state. After starting up, the management ECU 30 can read data from the memory 20. For example, the management ECU 30 may read vehicle status data from the memory 20 and control the communication unit 10 so that the vehicle status data is sent to the communication terminal 200. The communication terminal 200 receives the vehicle status data and displays the information contained in the vehicle status data on the vehicle control application. As a result, the user operating the communication terminal 200 can check the current vehicle status, such as the remaining capacity of the onboard battery, on the vehicle control application.
[0028] In step S3, after startup, the management ECU 30 determines whether to start the downstream ECU based on the remote operation information of the registered user registered in correspondence with the communication terminal 200. Then, the management ECU 30 sends a start command to the downstream ECU according to the determination result. Specifically, the management ECU 30 identifies the target in-vehicle device from the remote operation information of the registered user, for which the number of times the target user has driven the in-vehicle device before getting in the vehicle is equal to or greater than a predetermined threshold. The count threshold is a threshold used to determine whether there is a history of driving the in-vehicle device by remote operation and is set in advance. The count threshold is set to a natural number of 1 or more. For example, if the count threshold is set to "1", then if the user has driven the in-vehicle device by remote operation at least once in the past (within the period from the present to a predetermined time ago), the driven in-vehicle device will be identified as the target in-vehicle device. Also, if the count threshold is set to a natural number of 2 or more, then the in-vehicle device that has been driven multiple times by remote operation will be the target in-vehicle device. The management ECU 30 then determines which downstream ECU controls the target in-vehicle device is the ECU to be activated. In the example in Figure 2, the actuator 62 for unlocking the door lock is the target in-vehicle device, and the BCM 60 that controls the actuator 62 is the ECU to be activated. In another example, if the user activates the air conditioner remotely before getting into the vehicle, the air conditioning system that drives the air conditioner becomes the target in-vehicle device, and the ECU that controls the air conditioning system becomes the ECU to be activated. The management ECU 30 then sends an activation command to the ECU to be activated.
[0029] On the other hand, if the user who accessed the vehicle in the control flow of step S1 has never driven an in-vehicle device via remote operation, the management ECU 30 cannot identify the target in-vehicle device from the registered user's remote operation information. In other words, if the user has never driven an in-vehicle device via remote operation, the remote operation data will not record remote operation information, and the number of times the registered user drove the in-vehicle device before getting in the vehicle will be zero. Furthermore, the management ECU 30 will not send a start command to the downstream ECU in conjunction with the startup of the management ECU 30.
[0030] In step S4, the BCM 60 starts up when it receives a start command from the management ECU 30. The BCM 60 may also send a start completion command to the management ECU 30 indicating that the start-up is complete.
[0031] The management ECU 30 may also notify the communication terminal 200 that the lock mechanism can be driven after the BCM 60 has been started. For example, the management ECU 30 includes ECU status information indicating the status of the downstream ECU in the vehicle status data and records it in the memory 20. The management ECU 30 sends a start command to the downstream ECU and updates the vehicle status data when it receives a start completion command from the downstream ECU. The management ECU 30 then sends the updated vehicle status data to the communication terminal 200. The communication terminal 200 receives the vehicle status data and displays the ECU status included in the vehicle status data on the vehicle control application. The communication terminal 200 only needs to display information on the in-vehicle devices that can be controlled when the downstream ECU is started on the vehicle control application. For example, in the example in Figure 2, when the BCM 60 is started, the door lock can be unlocked, so the button for unlocking the door lock should be displayed as selectable in the vehicle control application.
[0032] In step S5, the user operates the communication terminal 200, which transmits a lock release command to the vehicle to release the lock mechanism. The communication unit 10 receives the lock release command, and when the management ECU 30 receives the lock release command from the communication unit 10, it forwards the lock release command to the BCM 60. In step S6, the BCM 60 controls the actuator 62 to unlock the door lock. In this embodiment, the BCM 60 is already activated before the vehicle receives the lock release command. Therefore, the lead time (corresponding to time Ta in Figure 2(a)) from the time the lock release command is received until the actuator 62 is driven can be shortened. In other words, in this embodiment, the activation timing of the BCM 60 can be advanced.
[0033] Next, the time chart of the reference example will be explained with reference to Figure 2(b). The control flow of steps S11 and S12 is the same as the control flow of steps S1 and S2 in this embodiment. In the reference example, the management ECU 30 does not start the downstream ECUs unless it receives an operation command from the communication terminal 200 to drive the in-vehicle device. In step S13, the user operates the communication terminal 200 to send a lock release command to the vehicle to unlock the lock mechanism. The management ECU 30 and the communication unit 10 receive the lock release command. In step S14, when the management ECU 30 receives the lock release command from the communication unit 10, it sends a start command to the BCM 60 to start the ECU. In step S15, when the BCM 60 receives the start command from the management ECU 30, it starts up. In step S16, the BCM 60 controls the actuator 62 to unlock the door lock.
[0034] In the reference example, the BCM 60 is not activated before the vehicle receives the unlock command, and is in a sleep or hibernation state. Therefore, the management ECU 30 needs to activate the BCM. After the BCM 60 is activated, the actuator 62 becomes drivable. In other words, from the time the vehicle receives the unlock command until the actuator 62 becomes drivable, the management ECU 30 executes a control flow (corresponding to step S14) in which it identifies the downstream ECU to be activated and sends an activation command to the downstream ECU, and a control flow (corresponding to step S15) in which the BCM 60 is activated. Therefore, the lead time (corresponding to time Tb in Figure 2(b)) from the time the unlock command is received until the actuator 62 is driven is longer than the lead time Ta in this embodiment. Furthermore, the activation timing of the BCM 60 in the reference example is delayed compared to the activation timing of the BCM 60 in this embodiment.
[0035] Figure 3 is a flowchart showing the control flow of the ECU control system 100. Referring to Figure 3, the ECU control method performed by the communication unit 10 and the management ECU 30 will be explained. In step S21, the communication unit 10 determines whether or not it has received a terminal command from the communication terminal 200. If no terminal command has been received, the control flow waits in step S21. If a terminal command has been received, the management ECU 30 executes the control flow from step S22 onward.
[0036] In step S22, the management ECU 30 is activated based on the terminal command from the communication terminal 200. In step S23, the management ECU 30 obtains remote operation information from the memory 20. The management ECU 30 only needs to extract remote operation information corresponding to the registered user from the remote operation data stored in the memory 20. Registered users are registered in accordance with the communication terminal 200 that sent the terminal command in the control flow of step S21.
[0037] In step S24, the management ECU 30 determines whether to activate the downstream ECU based on the registered user's remote operation information. For example, if the registered user operated the navigation system before getting into the vehicle via remote operation in the previous instance, remote operation information indicating that the navigation system was operated is recorded in memory 20. Then, during the current remote operation, the management ECU 30 determines that the downstream ECU that controls the navigation system is the ECU to be activated. On the other hand, if a user who has not driven the in-vehicle device via remote operation, or a user who has not driven the in-vehicle device via remote operation for a long time, accesses the vehicle via remote operation, the management ECU 30 determines not to activate the downstream ECU. Then, in step S25, the management ECU 30 sends an activation command to the downstream ECU according to the determination result. The control flow in Figure 3 ends.
[0038] As described above, in this embodiment, the ECU control system 100 includes a communication unit 10 that communicates with a communication terminal 200, a management ECU 30 that manages remote operation information, and a downstream ECU connected downstream of the management ECU 30 that controls the in-vehicle device. The management ECU 30 is activated based on a terminal command, determines whether to activate the downstream ECU based on the remote operation information of a registered user, and transmits an activation command to the downstream ECU according to the determination result. This makes it possible to speed up the activation timing of the downstream ECU.
[0039] In this embodiment, the management ECU 30 identifies a target in-vehicle device from the registered user's remote operation information if the number of times the registered user has driven the device before getting into the vehicle is equal to or greater than a predetermined threshold, and determines that the downstream ECU that controls the target in-vehicle device is the ECU to be activated. This makes it possible to advance the activation timing of the downstream ECU and the driving timing of the target in-vehicle device.
[0040] Furthermore, in this embodiment, if the management ECU 30 cannot identify the target in-vehicle device from the registered user's remote operation information, it does not send a start command to the downstream ECU when the management ECU 30 is started. As a result, if a user who has not driven an in-vehicle device via remote operation, or a user who has not driven an in-vehicle device via remote operation for a long time, accesses the vehicle via remote operation, the downstream ECU can be kept in a sleep state or shut down state. This reduces the power consumption of the ECU.
[0041] In this embodiment, the management ECU 30 manages vehicle status data indicating the current vehicle status and controls the communication unit 10 so that the vehicle status data is transmitted to the communication terminal 200. This makes it possible to notify users who access the vehicle remotely of the current vehicle status.
[0042] In this embodiment, the communication terminal 200 has a vehicle control application installed, and terminal commands are sent from the communication terminal to the vehicle when the control application is started. This allows the downstream ECU to be started in conjunction with the start of the vehicle control application.
[0043] In this embodiment, the ECU control method works as follows: when the communication unit 10 receives a terminal command transmitted from the communication terminal 200, the management ECU 30 starts up based on the terminal command, acquires remote operation information from the memory 20, determines whether to start the downstream ECU based on the registered user's remote operation information, and sends a start command to the downstream ECU according to the determination result. This makes it possible to speed up the startup timing of the downstream ECU.
[0044] 10 Communication Unit 20 Memory 30 Management ECU 40 VCM 50 ADCU 60 BCM 62 Actuator 100 ECU Control System 200 Communication Terminal
Claims
1. An ECU control system mounted on a vehicle, comprising: a communication unit that connects to a communication terminal operated by a user outside the vehicle via a communication network and communicates with the communication terminal; a management ECU connected to the communication unit and managing remote operation information indicating that an in-vehicle device has been driven by remote operation; and a downstream ECU connected downstream of the management ECU and controlling the in-vehicle device, wherein the communication unit receives terminal commands from the communication terminal; the management ECU is activated based on the terminal commands; the management ECU determines whether to activate the downstream ECU based on the remote operation information of a registered user registered in correspondence with the communication terminal that sent the terminal commands; and transmits an activation command to the downstream ECU according to the determination result.
2. An ECU control system according to claim 1, wherein the management ECU identifies a target in-vehicle device that has been driven by the registered user before boarding, based on the remote operation information of the registered user, and determines the downstream ECU that controls the target in-vehicle device as the ECU to be activated.
3. An ECU control system according to claim 2, wherein the management ECU does not transmit the startup command to the downstream ECU in conjunction with the startup of the management ECU if the target in-vehicle device cannot be identified from the remote operation information of the registered user.
4. An ECU control system according to any one of claims 1 to 3, wherein the management ECU manages vehicle status data indicating the current vehicle status, and controls the communication unit so that the vehicle status data is transmitted to the communication terminal.
5. An ECU control system according to any one of claims 1 to 4, wherein a vehicle control application is installed on the communication terminal, and the terminal command is transmitted from the communication terminal to the vehicle when the control application is started up.
6. An ECU control method executed by a management ECU mounted on a vehicle, wherein when a communication unit receives a terminal command transmitted from a communication terminal, the management ECU starts up based on the terminal command, obtains remote operation information from memory indicating that an in-vehicle device has been driven by remote operation, determines whether to start up a downstream ECU connected downstream of the management ECU based on the remote operation information of a registered user registered in correspondence with the communication terminal that transmitted the terminal command, and transmits a start command to the downstream ECU according to the determination result.