ECU control system and ECU control method

WO2026159833A1PCT designated stage Publication Date: 2026-07-30NISSAN MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NISSAN MOTOR CO LTD
Filing Date
2025-01-23
Publication Date
2026-07-30

Smart Images

  • Figure JP2025002088_30072026_PF_FP_ABST
    Figure JP2025002088_30072026_PF_FP_ABST
Patent Text Reader

Abstract

An ECU control system is mounted on a vehicle and comprises: a management ECU 20 which has a first calculation processing part 91 for executing first calculation processing; and downstream ECUs 30, 40, 50 which have a second calculation processing part 92 for executing second calculation processing simpler than the first calculation processing and which are connected downstream of the management ECU 20. The management ECU 20: receives vehicle information from a first in-vehicle device connected to the downstream ECUs 30, 40, 50, via the downstream ECUs 30, 40, 50; executes the first calculation processing on the basis of the vehicle information; and transmits the first calculation result obtained by the first calculation processing to a second in-vehicle device connected to the downstream ECUs 30, 40, 50, via the downstream ECUs 30, 40, 50. The downstream ECUs 30, 40, 50 execute the second calculation processing on the basis of the vehicle information received from the first in-vehicle device and transmit the second calculation result obtained by the second calculation processing to the second in-vehicle device. At least one ECU among the management ECU 20 and the downstream ECUs 30, 40, 50 has a monitoring function for detecting, as a specific state, a state in which an abnormality occurs in the management ECU 20 or a processing load of a core included in the management ECU 20 is high. When the specific state is detected, an execution part for executing calculation processing necessary for controlling the second in-vehicle device is switched from the first calculation processing part to the second calculation processing part.
Need to check novelty before this filing date? Find Prior Art

Description

ECU Control System and ECU Control Method

[0001] The present invention relates to an ECU control system and an ECU control method.

[0002] Conventionally, an in-vehicle network system in which in-vehicle control devices and a plurality of ECUs are connected to a network bus conforming to the CAN communication policy is known. For example, in the in-vehicle network system described in Patent Document 1, a plurality of ECUs are connected to communication buses corresponding to the systems (control system, body system, safety system, information system, etc.) to which they belong, and each forms an in-vehicle network.

[0003] Japanese Patent Application Laid-Open No. 2019-159661

[0004] In the in-vehicle network system described in Patent Document 1, the processing of various functions of the vehicle is executed by a plurality of ECUs. When the vehicle functions processed by the plurality of ECUs are aggregated and arranged in the in-vehicle control device, if an abnormality occurs in the in-vehicle control device or the calculation load in the in-vehicle control device becomes high and the in-vehicle control device cannot perform normal calculation processing, there is a problem that at least a part of the vehicle functions becomes dysfunctional.

[0005] The problem to be solved by the present invention is to provide an ECU control system and an ECU control method that can maintain vehicle functions when the management ECU is in a specific state such as an abnormality or a high load.

[0006] The present invention detects a state in which an abnormality has occurred in the management ECU or the processing load of the core is high as a specific state, and when the specific state is detected, switches an execution unit that executes calculation processing necessary for controlling in-vehicle devices from the first calculation processing unit of the management ECU to the second calculation processing unit of the downstream ECU to solve the above problems.

[0007] According to the present invention, when the management ECU is in a specific state such as an abnormality or a high load, vehicle functions can be maintained.

[0008] FIG. 1 is a block diagram of the ECU control system according to the present embodiment. FIG. 2 is a diagram for explaining the control sequence of the ECU control system according to the present embodiment.

[0009] Hereinafter, embodiments of the ECU control system according to the present invention will be described with reference to the drawings.

[0010] Figure 1 is a schematic diagram of the configuration of the ECU control system 100 according to this embodiment. The ECU control system 100 according to this embodiment is a system that controls a plurality of ECUs and is mounted on a vehicle. The vehicle is a hybrid vehicle or electric vehicle equipped with an engine and a motor. The ECU control system 100 may also be mounted on a vehicle that obtains power from an engine (ICE vehicle). The ECU control system 100 includes a communication unit 10, a management ECU 20, downstream ECUs 30, 40, 50, a sensor 31, brake actuators 41, 51, and communication lines 61 to 66. The communication unit 10, management ECU 20, and downstream ECUs 30, 40, 50 shown in Figure 1 are just examples of a plurality of ECUs included in a vehicle, and the vehicle is not limited to the communication unit 10, etc., and may include other ECUs. In addition, other ECUs may be connected downstream of the downstream ECUs 30, 40, 50.

[0011] The communication unit 10 connects to communication terminals such as smartphones and servers, and sends and receives data. The communication unit 10 receives necessary data from the server in response to system requests or user requests. For example, when updating applications included in the in-vehicle system, downloading new applications, or updating software included in the ECU, the communication unit 10 communicates with the server. Also, when operating in-vehicle equipment from outside the vehicle, the communication unit 10 receives operation commands for the in-vehicle equipment from the communication terminal.

[0012] The management ECU (central ECU) 20 is connected to the communication unit 10 and processes the received signals from the communication unit 10, then transmits the signals to the downstream ECUs. In this embodiment, "upstream" and "downstream" refer to the signal flow in the in-vehicle communication network. The communication unit 10 side is referred to as "upstream" with respect to the management ECU 20, and the downstream ECUs 30, 40, and 50 are referred to as "downstream" with respect to the management ECU 20. The management ECU 20 is also connected to multiple downstream ECUs 30, 40, and 50, and forwards signals transmitted from one of the downstream ECUs 30, 40, and 50 to the other ECUs. In other words, the management ECU 20 functions as a gateway.

[0013] A vehicle has multiple control groups, each divided according to its basic configuration; these control groups are also called domains. Domains include the vehicle drivetrain domain, the vehicle driving assistance system domain, the body domain, the multimedia domain, the powertrain domain which controls the engine, etc., and the chassis domain which controls the steering mechanism, etc. Each domain includes an ECU as a control unit for control; for example, the chassis domain has a CMC (Chassis Domain Controller), the vehicle drivetrain domain has a VMC (Vehicle Motion Control), and the vehicle driving assistance system domain has an ADCU (Assisted Driving Control Unit).

[0014] Conventional vehicle network systems have numerous ECUs connected, and these ECUs can communicate with each other via gateways that have relay functions. Therefore, in conventional vehicle network systems, vehicle functions are distributed among the ECUs. In other words, in conventional vehicle network systems, it was common to connect each ECU, corresponding to the CMC, VMC, and ADCU, downstream to a control unit (also called a PIU) that has a gateway.

[0015] In this embodiment, in order to consolidate multiple vehicle functions into the management ECU 20, the management ECU 20 has multiple cores, and the vehicle functions are arranged on the multiple cores 21 to 24. The vehicle functions include functions that should be started in a short time, functions that should be executed by a processor with high processing power, and functions necessary for starting the vehicle, depending on the content of the function and the processing load of the task processing. For this reason, the management ECU 20 is equipped with a real-time core (hereinafter also referred to as "RT core") as a core with a fast startup time, and an application core (hereinafter also referred to as "AP core") as a core with high processing power. As shown in Figure 1, the management ECU 20 has cores 21 to 24, and cores 21 to 24 include core 21, which is an RT core, and cores 22 to 24, which are AP cores.

[0016] Cores 21-24 are control units that process programs (software), such as microcontrollers or processors. Cores 21-24 have memory for storing programs. Cores 21-24 also have a communication network connecting them so that each core can send and receive commands.

[0017] Core 21 is an RT core and is driven by a processing sequence that completes task processing included in vehicle functions within a predetermined period. Vehicle functions are functions installed in the vehicle, such as powertrain control functions, chassis system control functions, body system control functions, and communication system control functions. For example, task processing included in brake control functions corresponds to the processing sequence executed by the core when controlling the brakes. Task processing is executed for each of the multiple cores 21 to 24.

[0018] When an RT core performs a task, such as controlling the braking force to a predetermined value, it completes the task within a predetermined period (for example, a predetermined period of several tens to 100 ms). Furthermore, in RT10, if cores 11 to 13 are executing one task within a predetermined period, they will not execute any other tasks within the same core and the same period. For example, if core 21 is executing a task to control the braking force to a predetermined value, and a command to control the braking force to a different value is input to the same core 21, core 21 will complete the currently executing task within the predetermined period and execute the other task (the task to set the braking force to a different value) after the predetermined period has elapsed. In other words, core 21 executes tasks according to an arbitration rule that the currently executing task will be completed within a predetermined period, and no other tasks will be executed while a task is being executed.

[0019] The AP core does not need to complete task processing within a predetermined cycle. For example, when a vehicle calculates a route to its destination, it obtains real-time information such as road congestion from a server to provide optimal route guidance. Obtaining information from a server is performed as a task process included in the functions of the vehicle communication system (CCS). For example, the AP core communicates with a server and executes a task process related to data acquisition. Since the AP core has no periodic limit on completing task processing, the timing of task completion varies depending on the processing time of the task. In other words, the processing cycle of task processing in the AP core is random. Also, for example, if a command to execute another task process is input while the AP core is executing a task process related to data acquisition via external communication, it will select which task process to execute according to the processing load of the competing task processes. For example, if the load of the data acquisition task process is smaller than the load of the input task process, the AP core will interrupt the data acquisition task process or slow down the processing speed to prioritize the input task process. In other words, if an interrupt command for another task is input to the same AP core while it is executing a task, the core will execute the other task if the processing load (computational load) of the other task is greater than the processing load of the task currently being executed. That is, the AP core does not have a predetermined order for executing tasks, and in the event of a task conflict, the AP core will execute the task with the highest priority. The priority may be determined according to the processing load of the task, or it may be pre-set by the system according to the type of task.

[0020] Cores 22-24, which are AP cores, use cores with higher processing power compared to core 21, which is an RT core. Therefore, cores 22-24 can perform computationally intensive tasks such as image processing, compared to core 21. Also, because cores 22-24 use cores with higher processing power, each core 22-24 can determine the priority of conflicting task processing and execute conflicting task processing in parallel. On the other hand, core 21 uses a core with lower processing power than cores 22-24, so core 21 simplifies the task processing arbitration rules and executes task processing with reduced processing power. Furthermore, core 21 does not process conflicting task processing in parallel, but instead executes task processing so that one task processing is completed within a predetermined cycle.

[0021] The management ECU 20 receives vehicle information from in-vehicle equipment connected to the downstream ECUs 30, 40, and 50 via the downstream ECUs 30, 40, and 50. This vehicle information includes sensor detection values, operation commands for in-vehicle equipment, and control commands for the ECU. In the example shown in Figure 1, sensor 31 is connected to the downstream ECU 30, and sensor 31 detects the amount of brake pedal operation (brake depression). The management ECU 20 receives the detection value (brake depression) from sensor 31 via the downstream ECU 30.

[0022] The management ECU 20 executes predetermined calculation processing based on vehicle information. The predetermined calculation processing may be performed on multiple cores 21 to 24, or it may be performed on at least one of the cores 21 to 24. Note that the calculation processing performed on cores 21 to 24 is different for each core. Cores 21 and 23 are VMC control processors, core 22 is a CDC control processor, and core 24 is an AD control processor. Each of the CDC, VMC, and AD control processors (cores 21 to 24) executes predetermined calculation processing based on vehicle information. The management ECU 20 also transmits the calculation results of the calculation processing performed on cores 21 to 24 to the in-vehicle equipment via the downstream ECUs 30, 40, and 50.

[0023] Core 21 has a first arithmetic processing unit 91. The first arithmetic processing unit 91 is a functional block representing the arithmetic function of core 21. Cores 22 to 24 also have functional blocks for arithmetic functions, similar to core 21. The functional blocks of cores 21 to 24, including the first arithmetic processing unit 91, then execute predetermined arithmetic processing based on vehicle information.

[0024] The first arithmetic processing unit 91 calculates control parameters for controlling other in-vehicle devices in response to operation commands input from in-vehicle devices. For example, when a driver operates the brake pedal to generate braking force, the first arithmetic processing unit 91 obtains the amount of brake pedal operation detected by the sensor 31 from the downstream ECU 30, uses the amount of operation as an input value to perform calculation processing, and outputs the calculation result to the brake actuators 41 and 51 via the downstream ECUs 40 and 50. The calculation result is indicated by the target braking force (braking amount) of the brake actuator 41 and brake actuator 51, respectively. The brake actuators 41 and 51 are driven according to the target braking force, and braking force is generated. The value detected by the sensor 31 corresponds to the vehicle information transmitted to the management ECU 20. In the following description, the calculation processing performed by the first arithmetic processing unit 91 is also referred to as the first calculation processing. The first calculation processing may also be the calculation processing performed by cores 22 to 24.

[0025] The management ECU 20 has a monitoring function that monitors the status of the management ECU 20 and / or the processing load of cores 21-24. The management ECU 20 detects whether its status is normal or abnormal through self-diagnosis. For example, the management ECU 20 detects abnormalities in programs or data recorded in memory. The management ECU 20 may also detect abnormalities in each core 21-24 from the logs left behind by the calculation processing of each core 21-24. The management ECU 20 also detects whether cores 21-24 are under heavy load from their processing speed or the amount of data being processed. The management ECU 20 may have both monitoring functions, or it may have only one of them, a monitoring function for the status of the management ECU 20 and a monitoring function for the processing load of cores 21-24. In the following description, a state in which the management ECU 20 is abnormal or a state in which the processing load of cores 21-24 is high will also be referred to as a "specific state".

[0026] The downstream ECUs 30, 40, and 50 are connected downstream of the management ECU 20. The downstream ECUs 30, 40, and 50 are control units assigned to each zone. In the example in Figure 1, the in-vehicle network system is divided into three groups. Zones 1 to 3 correspond to the installation areas in the vehicle; for example, Zone 1 corresponds to the area in front of the driver's seat, Zone 2 corresponds to the area near the bottom of the driver's seat, and Zone 3 corresponds to the area behind the driver's seat. The downstream ECU 30, located in Zone 1, becomes the hub of the network connecting the in-vehicle equipment installed in the forward area. The downstream ECUs 40 and 50 become the hubs for the networks belonging to Zones 2 and 3. In this way, by dividing the network into zones according to the layout of the in-vehicle equipment in the vehicle and placing the downstream ECUs 30, 40, and 50, which act as hubs in each zone, the harness can be shortened.

[0027] The downstream ECUs 30, 40, and 50 are connected to the management ECU 20 via communication networks 61-63. The downstream ECU 30 is connected to the sensor 31 via communication network 64. The downstream ECU 40 is connected to the brake actuator 41 via communication network 65. The downstream ECU 50 is connected to the brake actuator 51 via communication network 66. Furthermore, the downstream ECUs 30 and 40 are connected via a bypass route, and the downstream ECUs 40 and 50 are also connected via a bypass route. The downstream ECUs 30 and 50 are also connected via a bypass route.

[0028] The downstream ECU 40 has a second arithmetic processing unit 92. The second arithmetic processing unit 92 is a functional block that represents the calculation function of the downstream ECU 40. The second arithmetic processing unit 92 calculates control parameters for controlling other in-vehicle equipment in response to operation commands input from in-vehicle equipment. For example, when the driver operates the brake pedal to generate braking force, the second arithmetic processing unit 92 acquires the amount of brake pedal operation detected by the sensor 31, performs calculation processing using the amount of operation as an input value, and outputs the calculation result of the calculation processing to the brake actuators 41 and 51. In the following description, the calculation processing performed by the second arithmetic processing unit 92 will also be referred to as the second calculation processing. The second calculation processing may also be the calculation processing performed by the downstream ECUs 30 and 50.

[0029] Furthermore, the second arithmetic process is simpler than the first arithmetic process. In other words, the complexity of the calculation performed by the second arithmetic process is less than the complexity of the calculation performed by the first arithmetic process. Also, the second arithmetic process is a simplified version of the first arithmetic process. For example, the first arithmetic process is assumed to be a process that takes multiple vehicle information as input, performs a predetermined calculation on multiple input values, and outputs the calculation result. On the other hand, the second arithmetic process takes one vehicle information as input, performs a predetermined calculation on one input value, and outputs the calculation result. In other words, the number of parameters that can be input into the arithmetic process is smaller for both the first and second arithmetic processes. Furthermore, the second arithmetic process may be simplified by changing the complexity of the processing steps of the arithmetic process. For example, the second arithmetic processing unit 92 may have a map, and the second arithmetic process may be executed by an calculation that refers to the map.

[0030] Communication networks 61-63 are harnesses compliant with standards such as Ethernet, and connect the management ECU 20 to the downstream ECUs 30, 40, and 50. Communication networks 64-66 are harnesses compliant with standards such as CAN, and connect the downstream ECUs 30, 40, and 50 to the sensor 31 and brake actuators 41 and 51. Sensor 31 detects the amount the brake pedal is pressed. Brake actuator 41 is a mechanism that controls the braking force of the front wheel brakes, and brake actuator 51 is a mechanism that controls the braking force of the front wheel brakes.

[0031] In this embodiment, the management ECU 20 has multiple cores 21 to 24, and multiple vehicle functions are arranged on the multiple cores 21 to 24. For example, functions related to the basic driving of the vehicle are arranged on the management ECU 20. Therefore, the management ECU 20 acquires operation commands such as accelerator pedal, brake pedal, and steering via the downstream ECUs 30, 40, and 50, and calculates control amounts for the drive system such as the engine and motor, and control amounts for the brake actuators 41 and 51 according to the operation commands. The management ECU 20 then outputs the calculated control amounts to the downstream ECUs 30, 40, and 50. If the management ECU 20 is functioning normally, it can acquire vehicle information from in-vehicle equipment via the downstream ECUs 30, 40, and 50, and can execute the first calculation process based on the vehicle information. On the other hand, if the management ECU 20 is in a specific state, it cannot execute the first calculation process. Therefore, there is a possibility that at least some of the vehicle functions integrated into the management ECU 20 cannot be maintained. Therefore, as will be described in detail below, in the ECU control system according to this embodiment, when a specific state is detected by the monitoring function, the execution unit for the calculation processing necessary for controlling the in-vehicle equipment is switched from the first calculation processing unit 91 to the second calculation processing unit 92.

[0032] If the management ECU 20 detects from its monitoring function that it is not in a specific state, it assigns an execution unit (hereinafter simply referred to as the "execution unit") that performs the calculation processing necessary for controlling the in-vehicle equipment to the first calculation processing unit 91. When controlling the brake actuators 41 and 51, the core that executes the processing flow corresponds to the execution unit. For example, if it is not in a specific state, the execution unit for controlling the brake actuators 41 and 51 is assigned to the first calculation processing unit 91 and not to the second calculation processing unit.

[0033] On the other hand, if the monitoring function detects that the management ECU 20 is in a specific state, the management ECU 20 switches the execution unit from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. Specifically, when the management ECU 20 detects a specific state, it sends a switching command to the downstream ECUs 30, 40, and 50 to switch the execution unit from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. Based on the switching command, the downstream ECU 30 switches the output destination of the detected value (vehicle information) from the sensor 31 from the communication network 61 to the bypass route 71. The downstream ECU 40 also sets the second arithmetic processing unit 92 as the execution unit based on the switching command. The downstream ECU 40 transmits the calculation result of the second arithmetic processing of the second arithmetic processing unit 92 to the brake actuator 41. The downstream ECU 40 also transmits the calculation result of the second arithmetic processing of the second arithmetic processing unit 92 to the downstream ECU 50 via the bypass route 72. The downstream ECU 40 transmits the calculation result of the second arithmetic processing of the second arithmetic processing unit 92 to the brake actuator 51.

[0034] When the execution unit switches from the first arithmetic processing unit 91 to the second arithmetic processing unit 92, vehicle functions that could be executed by the first arithmetic processing unit can now be executed by the second arithmetic processing unit. However, since the second arithmetic processing unit is a simplified version of the first arithmetic processing unit, some vehicle functions are limited. Specifically, when the management ECU 20 enters a specific state, it transfers control authority for the arithmetic processing unit from the management ECU 20 to the downstream ECUs 30, 40, and 50, and switches from normal mode to safe mode. This allows the vehicle functions centralized in the management ECU 20 to be maintained.

[0035] In this embodiment, the monitoring function may be provided in the downstream ECUs 30, 40, and 50. For example, if the downstream ECU 30 has a monitoring function, the downstream ECU 30 may detect whether the management ECU is normal or abnormal based on the communication status of the signal transmitted from the management ECU 20. For example, the management ECU 20 transmits a signal to the downstream ECU 30 at a predetermined period or at any arbitrary timing. If the downstream ECU 30 receives a signal from the management ECU 20 normally, it determines that the management ECU 20 is normal. On the other hand, if the downstream ECU 30 does not receive a signal from the management ECU 20, or if the frequency of receiving signals from the management ECU 20 is lower than a predetermined frequency, it determines that the management ECU 20 is abnormal. The downstream ECU 30 also transmits vehicle information to the management ECU 20 and receives the calculation result of the first calculation process based on the vehicle information from the management ECU 20. The downstream ECU 20 may estimate the processing load of cores 21-24 from the elapsed time from the timing of transmission of vehicle information to the timing of reception of the calculation result of the first calculation process. For example, if the elapsed time is less than or equal to a predetermined time threshold, the downstream ECU 30 estimates that the processing load of cores 21-24 is normal. If the elapsed time is less than the predetermined time threshold, the downstream ECU 30 estimates that the processing load of cores 21-24 is high. When a specific state is detected by the monitoring function of the downstream ECU 30, the downstream ECU 30 switches the execution unit from the first calculation processing unit 91 to the second calculation processing unit 92. The downstream ECU 30 may send a switching command to the management ECU 20 to switch the execution unit, or it may switch the execution unit by switching the destination of vehicle information transmission from the management ECU 20 to other downstream ECUs 40, 50. In other words, in this embodiment, it is sufficient that at least one of the management ECU 20 and the downstream ECUs 30, 40, 50 has a monitoring function.

[0036] In this embodiment, the management ECU 20 may notify the vehicle user that the execution unit has switched from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. The notification to the user is made by displaying it on the meter or on the in-vehicle display. This allows the vehicle user to confirm that some vehicle functions may be restricted. The downstream ECUs 30, 40, and 50 may also notify the vehicle user that the execution unit has switched from the first arithmetic processing unit 91 to the second arithmetic processing unit 92.

[0037] In this embodiment, the management ECU 20 may notify the vehicle user to request permission to switch the execution unit before switching the execution unit from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. For example, the management ECU 20 may display a message such as "Do you want to start in safe mode?" on a pre-registered communication terminal or in-vehicle display. When the management ECU 20 receives an operation command that permits starting in safe mode, it switches the execution unit from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. This allows the system to switch to safe mode after confirming the user's permission. The downstream ECUs 30, 40, and 50 may also notify the vehicle user to request permission to switch the execution unit before switching the execution unit from the first arithmetic processing unit 91 to the second arithmetic processing unit 92.

[0038] Next, we will explain the processing sequence of a vehicle control system with a specific example. Figure 2 is a diagram illustrating the processing sequence of a vehicle control system. The specific example is one in which braking force is output by operating the brake pedal. In Figure 2, solid arrows represent the processing sequence before a specific state is detected, and dotted arrows represent the processing sequence after a specific state is detected.

[0039] In step S1, core 22, which is the CDC control processor, sets the drive mode based on the user's operation. The drive mode indicates the vehicle's driving mode, such as sport mode or eco mode, and the responsiveness of the braking force to the amount of brake pedal depression and the distribution of braking force to the front and rear brakes differ depending on the mode. Core 21 transmits the set drive mode information to core 23.

[0040] In step S2, core 24, which is the AD control processor, determines the road surface condition using the image captured by the in-vehicle camera. For example, if the road surface is covered with snow, the optimal braking force and distribution of braking force are determined to prevent the vehicle from slipping during braking. Core 24 transmits the road surface determination result to core 23.

[0041] In step S3, core 23 performs characteristic adjustment according to the set drive mode (characteristic adjustment A). For example, the characteristics of the target braking force in relation to the amount of brake pedal depression are stored in memory as a map for each drive mode. Core 23 performs characteristic adjustment according to the drive mode by referring to the map. Core 23 also transmits the result of the characteristic adjustment to core 21.

[0042] In step S4, core 24 performs characteristic adjustment according to the road surface determination result (characteristic adjustment B). For example, the characteristics of the target braking force in relation to the amount of brake pedal depression are stored in memory as a map for each road surface condition. Core 23 performs characteristic adjustment according to the road surface determination result by referring to the map. Core 23 also transmits the result of the characteristic adjustment to core 21.

[0043] In step S5, the downstream ECU 30 transmits the detected value (vehicle information) input from the sensor 31 to the management ECU 20.

[0044] In step S6, the core 21 calculates the target driving force by executing the first arithmetic processing based on the detection value of the sensor 31 received from the downstream ECU 30. Further, when there is an adjustment of the characteristics of the target braking force with respect to the depression amount of the brake by the characteristic adjustment A and / or the characteristic adjustment B, the core 21 calculates the target driving force taking the characteristic adjustment into account. For example, a target braking force map for calculating the target braking force with respect to the brake depression amount is stored in the core 21 in advance, and the target braking force map is made possible in advance according to the adjustment results of the characteristic adjustment A and the characteristic adjustment B. That is, the target braking force map is stored in combination with a mode that can be set in the drive mode and a road surface state that can be distinguished by road surface determination. The target braking force map may also use control parameters other than the brake depression amount, such as the vehicle speed, as input values. Then, the core 21 selects the optimal target braking force map from the adjustment results of the characteristic adjustment A and / or the characteristic adjustment B, and then calculates the target braking force with respect to the brake depression amount.

[0045] In step S7, the core 21 transmits the calculation result (target driving force) obtained by the first arithmetic processing to the brake actuators 41 and 51 via the downstream ECUs 40 and 50. The brake actuators 41 and 51 are driven according to the target driving force.

[0046] In step S8, the management ECU 20 detects a specific state by monitoring the state of the management ECU and / or the processing loads of the cores 21 to 24. Regarding the control flow of the monitoring function by the management ECU 20, in the control sequence shown in FIG. 2, the control flow of the monitoring function is, for the sake of convenience, the eighth step, but the management function control flow does not necessarily have to be executed in the order in the control sequence, and may be executed at a predetermined cycle or at a predetermined timing. The monitoring function may be assigned to any one of the cores 21 to 24, or may be assigned to a core other than the cores 21 to 24.

[0047] In step S9, when a specific state is detected, the management ECU 20 transmits a switching command for switching the execution unit to the core 21 and the downstream ECUs 30 and 40. The core 21 releases the authority of the execution unit given to the first arithmetic processing unit 91. The downstream ECU 30 switches the transmission destination of the detection value of the sensor 31 from the management ECU 20 to the downstream ECU 40. The downstream ECU 40 grants the authority of the execution unit to the second arithmetic processing unit 92. Thereby, the execution unit switches from the first arithmetic processing unit 91 to the second arithmetic processing unit.

[0048] In step S10, the downstream ECU 30 transmits the detection value (vehicle information) input from the sensor 31 to the downstream ECU 40. In step S11, the downstream ECU 40 calculates the target driving force by executing the second arithmetic processing based on the detection value of the sensor 31 received from the downstream ECU 30. In step S12, the downstream ECU 40 transmits the arithmetic result (target driving force) obtained by the second arithmetic processing to the brake actuator 41 and transmits the arithmetic result (target driving force) to the brake actuator 51 via the downstream ECU 50. The brake actuators 41 and 51 are driven according to the target driving force.

[0049] In this embodiment, when a specific state is detected, the management ECU 20 may switch the execution unit between the first arithmetic processing unit 91 and the second arithmetic processing unit 92 depending on whether the core in the specific state is an RT core or an AP core. For example, when core 23 is in a specific state, the control flow of step S4 cannot be executed, so characteristic adjustment A and characteristic adjustment B are not input to core 21. Even if characteristic adjustment A and characteristic adjustment B are not input to core 21, core 21 can execute the first arithmetic processing based on the detected value (vehicle information) input from sensor 31. Therefore, when a specific state of cores 22 to 24, which are AP cores, is detected by the monitoring function, the management ECU 20 uses the first arithmetic processing unit as the execution unit. On the other hand, when core 21 is in a specific state, the control flow of step S6 cannot be executed, so core 21 cannot execute the first arithmetic processing. Therefore, when a specific state of core 21, which is an RT core, is detected by the monitoring function, the management ECU 20 switches the execution unit from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. In other words, in the ECU control system according to this embodiment, the core 21 has a first arithmetic processing unit 91, and when a specific state of the core 21 is detected, the execution unit switches from the first arithmetic processing unit 91 to the second arithmetic processing unit 92, and when a specific state of the cores 22 to 24 is detected, the execution unit is the first arithmetic processing unit 91. This makes it possible to maintain vehicle functions when the RT core enters a specific state.

[0050] As described above, the ECU control system according to this embodiment comprises a management ECU 20 having a first calculation processing unit 91 and downstream ECUs 30, 40, and 50 having a second calculation processing unit 92. The management ECU 20 receives vehicle information from the sensor 31 via the downstream ECU 30, performs a first calculation process based on the vehicle information, and transmits the calculation result obtained from the first calculation process (corresponding to the "first calculation result" of the present invention) to the brake actuators 41 and 51 via the downstream ECUs 40 and 50. The downstream ECUs 30, 40, and 50 perform a second calculation process based on the vehicle information received from the sensor 31, and transmit the calculation result obtained from the second calculation process (corresponding to the "second calculation result" of the present invention) to the brake actuators 41 and 51. At least one of the management ECU 20 and the downstream ECUs 30, 40, and 50 has a monitoring function for detecting a specific state, and when a specific state is detected, it switches the execution unit from the first calculation processing unit 91 to the second calculation processing unit 92. This allows the vehicle's functions to be maintained even if the management ECU enters a specific state such as an abnormality or high load.

[0051] Furthermore, in the ECU control system according to this embodiment, the downstream ECUs 20, 30, and 40 include a first downstream ECU and a second downstream ECU connected by bypass routes 71 and 72, the first in-vehicle equipment is connected to the first downstream ECU, and the second in-vehicle equipment is connected to the second downstream ECU, and when a specific condition is detected, the downstream ECUs 20, 30, and 40 transmit vehicle information and / or the second calculation result using the bypass route. This makes it possible to maintain vehicle functions when the management ECU enters a specific condition such as an abnormality or high load.

[0052] Furthermore, in the ECU control system according to this embodiment, the downstream ECU 40 has a second arithmetic processing unit 92, and when a specific state is detected, the downstream ECU 30 switches the destination of vehicle information transmission from the management ECU 20 to the downstream ECU 40. This makes it possible to maintain vehicle functions when the management ECU enters a specific state such as an abnormality or high load.

[0053] Furthermore, in this embodiment, the ECU control method transmits vehicle information input from sensor 31 from downstream ECU 30 to management ECU 20, the management ECU 20 performs a first calculation process based on the vehicle information, transmits the calculation result obtained from the first calculation process from management ECU 20 to brake actuators 41 and 51 via downstream ECUs 40 and 50, the downstream ECU 40 performs a second calculation process based on the vehicle information, and transmits the calculation result obtained from the second calculation process from downstream ECU 40 to brake actuators 41 and 51. The ECU control method also detects a specific state of the management ECU 20, and when a specific state is detected, switches the execution unit from the first calculation processing unit 91 to the second calculation processing unit 92. This allows the vehicle functions to be maintained when the management ECU enters a specific state such as an abnormality or high load.

[0054] In this embodiment, the second calculation processing unit 92 may be provided in the downstream ECU 30. The downstream ECU 30 receives the detected value from the sensor 31, and the second calculation processing unit 92 included in the downstream ECU 30 executes a second calculation process based on the detected value from the sensor 31. The downstream ECU 30 calculates the target driving force by executing the second calculation process based on the detected value from the sensor 31. The downstream ECU 30 switches the destination of the target driving force from the management ECU 20 to the brake actuator 41. In other words, in this embodiment, the downstream ECU 30 has a second calculation processing unit 92, and when a specific state is detected, the downstream ECU 30 switches the destination of the calculation result of the second calculation process from the management ECU 20 to the downstream ECU 40. This allows the vehicle to maintain its functions even when the management ECU is in a specific state such as abnormality or high load.

[0055] In a modified version of this embodiment, if a specific state is detected while the brake actuators 41 and 51 are operating due to input from the sensor 31, the execution unit may switch from the first arithmetic processing unit 91 to the second arithmetic processing unit 92 after the input from the sensor 31 ceases. For example, if the management ECU 20 enters a specific state while the user is operating the brakes, the execution unit does not switch from the first arithmetic processing unit 91 to the second arithmetic processing unit 92 at the time the specific state is detected. Instead, it calculates the target braking force of the brake actuators 41 and 51 based on the detected value (pressure amount) from the sensor 31 that was input immediately before the specific state was detected. For example, if the brakes are operated and the brake pressure amount changes after the timing when the specific state is detected, the target braking force should be changed by a predetermined percentage relative to the current target braking force. If the brake pressure amount increases, the predetermined percentage is, for example, +10%, and if the brake pressure amount increases, the predetermined percentage is, for example, -10%. Then, after the brake operation by the drive is completed and there is no input from the sensor 31, the execution unit switches from the first arithmetic processing unit 91 to the second arithmetic processing unit 92. That is, the braking force is adjusted according to the change in the position of the brake pedal, based on the braking force at the time when the specific state is detected. In this embodiment, when the management ECU 20 enters a specific state, the execution unit switches from the first arithmetic processing unit 91 to the second arithmetic processing unit 92, thereby transitioning to safe mode. If braking force has already been generated when transitioning to safe mode, and the system transitions to safe mode at the time the specific state is detected, the control authority for the arithmetic processing changes from the management ECU 20 to the downstream ECU 40, so the calculation result (target braking force) may change significantly before and after transitioning to safe mode. In the modified example, the target braking force is calculated based on the braking force generated at the time the specific state is detected, so changes in the target braking force that occur when the execution unit switches can be suppressed.

[0056] As a concrete example used to explain the processing sequence of the vehicle control system, an example of outputting braking force by operating the brake pedal was given. However, the processing sequence of the vehicle control system is not limited to the amount of braking, but can also be applied to torque control by operating the accelerator and steering control by steering. Another concrete example is that the processing sequence of the vehicle control system can also be applied to the seat position adjustment function based on user operation. The seat position can be changed electrically by driving an actuator by operating a switch. In addition to this normal seat position adjustment function, it also has a function that detects the occupant's physique from images captured by an in-vehicle camera and adjusts the seat position to match the occupant's physique. Task processing included in such functions is executed by the management ECU 20, and the calculation processing of the target seat position based on camera images and switch operation commands is executed by the first calculation processing unit 91. When a specific state is detected in the management ECU 20, the second calculation processing unit 92 makes the calculation processing of the target seat position based on switch operation commands executable as a second calculation process in order to enable at least the normal seat position adjustment function. The second calculation processing unit 92 is also provided in the downstream ECUs 30, 40, and 50. This allows the normal seat position adjustment function to be maintained even if the management ECU 20 enters a specific state and is unable to execute the first calculation process.

[0057] In this embodiment, the sensor 31 corresponds to the "first on-board device" of the present invention, and the brake actuators 41 and 51 correspond to the "second on-board device" of the present invention. Furthermore, one of the downstream ECUs 20, 30, and 40 corresponds to the "first downstream ECU," and the other ECUs correspond to the "second downstream ECU."

[0058] 10 Communication Unit 20 Management ECU 21-24 Core 30, 40, 50 Downstream ECU 31 Sensor 41, 51 Brake Actuator 61-66 Communication Line 71, 72 Bypass Route 91 First Processing Unit 92 Second Processing Unit 100 ECU Control System

Claims

1. An ECU control system mounted on a vehicle, comprising: a management ECU having a first arithmetic processing unit that executes a first arithmetic processing unit; a downstream ECU connected downstream of the management ECU and having a second arithmetic processing unit that executes a second arithmetic processing unit that is simpler than the first arithmetic processing unit; the management ECU receives vehicle information from a first in-vehicle device connected to the downstream ECU via the downstream ECU, executes the first arithmetic processing unit based on the vehicle information, and transmits the first calculation result obtained by the first arithmetic processing unit to a second in-vehicle device connected to the downstream ECU via the downstream ECU; the downstream ECU executes the second arithmetic processing unit based on the vehicle information received from the first in-vehicle device, and transmits the second calculation result obtained by the second arithmetic processing unit to the second in-vehicle device; and at least one of the management ECU and the downstream ECU has a monitoring function that detects a state in which an abnormality has occurred in the management ECU or the processing load of the cores included in the management ECU has become high as a specific state. An ECU control system in which, when the aforementioned specific state is detected, the execution unit that performs the calculation processing necessary for controlling the second in-vehicle device switches from the first calculation processing unit to the second calculation processing unit.

2. An ECU control system according to claim 1, wherein the downstream ECU includes a first downstream ECU and a second downstream ECU connected by a bypass route, the first in-vehicle device is connected to the first downstream ECU, the second in-vehicle device is connected to the second downstream ECU, and when the specific state is detected, the downstream ECU transmits the vehicle information and / or the second calculation result using the bypass route.

3. An ECU control system according to claim 2, wherein the second downstream ECU has the second arithmetic processing unit, and when the specific state is detected, the first downstream ECU switches the destination of the vehicle information transmission from the management ECU to the second downstream ECU.

4. An ECU control system according to claim 2, wherein the first downstream ECU has the first calculation processing unit, and when the specific state is detected, the first downstream ECU switches the destination of the second calculation result from the management ECU to the second downstream ECU.

5. An ECU control system according to any one of claims 1 to 3, wherein the management ECU includes a first core that completes the processing of tasks included in vehicle functions within a predetermined period, and a second core that does not need to complete the processing of tasks within the predetermined period and has higher processing capacity than the first core, the first core has a first arithmetic processing unit, and when an abnormal state of the first core and / or a state of high processing load on the first core is detected by the monitoring function, the execution unit switches from the first arithmetic processing unit to the second arithmetic processing unit, and when an abnormal state of the second core and / or a state of high processing load on the second core is detected by the monitoring function, the execution unit is the first arithmetic processing unit.

6. An ECU control system according to any one of claims 1 to 5, wherein the management ECU or the downstream ECU notifies the user of the vehicle that the execution unit has switched from the first arithmetic processing unit to the second arithmetic processing unit.

7. An ECU control system according to any one of claims 1 to 5, wherein the management ECU or the downstream ECU notifies the user to grant permission for the switching of the execution unit before switching the execution unit from the first arithmetic processing unit to the second arithmetic processing unit.

8. An ECU control system according to any one of claims 1 to 7, wherein when the specific state is detected while the second in-vehicle device is operating in response to an input from the first in-vehicle device, the execution unit switches from the first arithmetic processing unit to the second arithmetic processing unit after the input from the first in-vehicle device ceases.

9. An ECU control method executed by an ECU control system mounted on a vehicle, comprising: transmitting vehicle information input from a first in-vehicle device from a downstream ECU connected to the first in-vehicle device to a management ECU connected downstream of the downstream ECU; executing the first calculation process based on the vehicle information using a management ECU having a first calculation processing unit that executes the first calculation process; transmitting the first calculation result obtained from the first calculation process from the management ECU to a second in-vehicle device via the downstream ECU; executing a second calculation process that is simpler than the first calculation process based on the vehicle information using a downstream ECU having a second calculation processing unit; transmitting the second calculation result obtained from the second calculation process from the downstream ECU to the second in-vehicle device; detecting a state in which an abnormality has occurred in the management ECU or the processing load of the cores included in the management ECU has become high as a specific state; and, when the specific state is detected, switching the execution unit that executes the calculation process necessary for controlling the second in-vehicle device from the first calculation processing unit to the second calculation processing unit.