Vehicle control system
Abstract
Problem to be solved.To appropriately implement a fail-safe measure as needed.
Solution.An acceleration required by a driver (required acceleration) and an actual acceleration of a vehicle are obtained, and it is determined whether or not the actual acceleration is larger than the required acceleration (steps S101 to S103). If the actual acceleration> the required acceleration, it is considered to be an abnormality that the driver feels dangerous, and stronger fail-safe measures such as stopping fuel injection and reducing fuel injection amount are executed (step S104). When the actual acceleration the required acceleration, strong fail-safe measures such as stopping fuel injection and reducing fuel injection amount are not executed. After that, abnormality detection is performed on the system components such as sensors and actuators, and when an abnormality occurs in the sensors and actuators, weak fail-safe measures such as lighting the warning lamp and limiting the vehicle speed are executed ( Steps S105 to S107). [Selection diagram] Fig. 3

Term
Term ended
Projected expiry passed 5 April 2024, 2.5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
6 claims: 2 independent, 4 dependent
- 1運転者の要求に応じて動力源の運転状態を制御し、車両を走行させる車両制御システムに適用され、 車両の実際の加速度に基づいて運転者が意図しない車両の加減速の状態であるかどうかを判定する手段と、運転者が意図しない車両の加減速の状態である場合に前記動力源に関して所定のフェールセーフ処置を実行する手段と、を備えたことを特徴とする車両制御システム。
- 2当該システムにおける各種構成要素を対象に異常を検出する手段を更に備え、運転者が意図しない車両の加減速の状態である旨検出され、且つ前記各種構成要素での異常発生が検出されていれば、その異常発生情報をその時の異常原因としてメモリに記憶保持する請求項1に記載の車両制御システム。
- 3複数のCPUを備え、各CPUでそれぞれ個別のアクチュエータを制御する車両制御システムであって、 前記複数のCPUは各々、車両の実際の加速度を監視すると共に該監視の結果に基づいてCPU個別のフェールセーフ処置を実行する請求項1又は2に記載の車両制御システム。
- 4運転者の要求に応じて動力源の運転状態を制御し、車両を走行させる車両制御システムに適用され、 走行中の車両の挙動変化が運転者が意図するものかどうかにより異常検出を行う第1の異常検出手段と、 当該システムにおける各種構成要素の状態に基づいて異常検出を行う第2の異常検出手段と、 前記第1の異常検出手段により異常発生の旨が検出された時、フェールセーフ処置として少なくとも前記動力源の出力を停止又は低減する第1のフェールセーフ手段と、 前記第2の異常検出手段により異常発生の旨が検出された時、フェールセーフ処置として少なくとも運転者等に対して警告を発する、又は異常発生情報をメモリに記憶する第2のフェールセーフ手段と、を備えたことを特徴とする車両制御システム。
- 5前記第1の異常検出手段は、車両の実際の加速度が運転者が要求する要求加速度と異なる場合に異常発生の旨を検出する請求項4に記載の車両制御システム。
- 6複数のCPUを備え、各CPUでそれぞれ個別のアクチュエータを制御する車両制御システムであって、 前記複数のCPUは各々、前記第1の異常検出手段及び前記第2の異常検出手段による各異常検出を実施すると共に、前記第1のフェールセーフ手段及び前記第2のフェールセーフ手段による各フェールセーフ処置を実施する構成とし、更に少なくとも前記第1の異常検出手段により異常発生が検出された場合に前記第1のフェールセーフ手段によるCPU個別のフェールセーフ処置を実行する請求項4又は5に記載の車両制御システム。
Independent claims6
35 paragraphs, as filed
The present invention relates to a vehicle control system, and more particularly to a technique capable of ensuring the running safety of a vehicle.
In recent vehicle control systems, a wide variety of parts, sensors, and software that make up the system are monitored in a very redundant and careful manner, and if a failure is detected on the system, fail-safe measures are taken to execute the vehicle. It limits the running performance. As a result, even if the driver unexpectedly accelerates due to some kind of system failure, the driver does not feel afraid. For example, in Patent Document 1, it is determined whether or not the change in engine output is within an allowable range, and fail-safe measures are executed according to the result of the comparison.
However, the change in engine output does not always match the actual change in vehicle behavior, and even if the change in engine output is out of the permissible range, it may not be necessary to immediately execute a fail-safe measure. Here, if the behavior of the vehicle does not change, the driver does not feel a sense of fear, and therefore it is considered unnecessary to take fail-safe measures such as limiting the engine output. If the fail-safe measures are excessively implemented, there is an inconvenience that the running performance of the vehicle is lowered.
Moreover, in more complicated systems today and in the future, the monitoring becomes more complicated, which leads to an increase in design man-hours and an increase in monitoring programs. Along with this, there is a concern that problems such as failure detection cannot be caused due to design / program mistakes / omissions. In this case, if the failure detection omission of the system occurs, there is a possibility that the safety during vehicle running cannot be guaranteed.<patcit num="1"><text>Special Table 2001-522966</text></patcit>
<p> An object of the present invention is to provide a vehicle control system capable of appropriately performing fail-safe measures as needed.</p>
<p> In the vehicle control system, it is important not to give the driver a feeling of fear due to changes in the behavior of the vehicle, and for that purpose, whether or not the driver has unintentionally accelerated or decelerated the vehicle. It is considered good to monitor. That is, the abnormal acceleration (or deceleration) of the vehicle is one of the events that occur as a result of some system abnormality, and can be regarded as a higher-level event with respect to the abnormality of the sensor, actuator, software, etc. on the system.</p><p> Based on this idea, in the invention of claim 1, it is determined whether or not the driver is in an unintended acceleration / deceleration state of the vehicle based on the actual acceleration of the vehicle. Then, when the driver is in an unintended acceleration / deceleration state of the vehicle, a predetermined fail-safe measure is executed with respect to the power source of the vehicle. As a fail-safe measure, for example, the output of a power source such as an engine is forcibly stopped or limited. In this case, by executing the fail-safe measure based on the abnormal acceleration (or deceleration) which is a higher-level event, it is possible to realize at least the vehicle running without giving a fear to the driver. It is also possible to suppress a decrease in vehicle drivability due to excessive fail-safe measures. As a result, fail-safe measures can be appropriately implemented as needed. Further, even if a system abnormality is detected and omitted due to a mistake / omission of a design / program due to a complicated system or the like, the running safety of the vehicle can be ensured.</p><p> In the invention according to claim 2, if it is detected that the driver is in an unintended acceleration / deceleration state of the vehicle and an abnormality occurrence in a system component is detected, the abnormality occurrence information is used as the cause of the abnormality at that time. It is stored in the memory as. As a result, the upper event (abnormal acceleration / deceleration) and the lower event (component abnormality) of the abnormality can be associated and stored in memory, and the subsequent abnormality analysis becomes easy.</p><p> In addition, a failure of the CPU itself can be considered as one of the factors that cause unexpected acceleration. When this CPU fails, fail-safe measures cannot be executed by the CPU, or even if they can be executed, their reliability is low. Therefore, as described in claim 3, it is preferable that each of the plurality of CPUs provided monitors the actual acceleration of the vehicle and executes fail-safe measures for each CPU based on the result of the monitoring. That is, fail-safe measures are executed in a plurality of systems. As a result, even if one of the CPUs fails, the other CPU can surely execute the fail-safe measure, and the running safety of the vehicle can be maintained.</p><p> On the other hand, in the invention of claim 4, an abnormality is detected depending on whether or not the behavior change of the moving vehicle is intended by the driver, and if the occurrence of the abnormality is detected at that time, at least power is used as a fail-safe measure. Stop or reduce the output of the source. In addition, abnormality detection is performed based on the state of various components in the system, and if the occurrence of an abnormality is detected at that time, at least a warning is issued to the driver or the like as a fail-safe measure, or abnormality occurrence information. Is stored in the memory.</p><p> In this case, an abnormality in which the behavior change of the vehicle is not intended by the driver can be considered as a higher-level event, and an abnormality in various components of the system can be considered as a lower-level event. Can be executed. Since the output of the power source is stopped or reduced at least based on the change in the behavior of the vehicle, it is possible to drive the vehicle without giving a fear to the driver, and the vehicle is subjected to excessive fail-safe measures. Deterioration of running performance can be suppressed. Further, even if a system abnormality is detected and omitted due to a mistake / omission of a design / program due to a complicated system or the like, the running safety of the vehicle can be ensured.</p><p> As described in claim 5, it is preferable to detect the occurrence of an abnormality when the actual acceleration of the vehicle is different from the required acceleration required by the driver. That is, in this case, when the vehicle is in an abnormal acceleration (or deceleration) state, the output of the power source is stopped or reduced as a fail-safe measure. As a result, even if acceleration / deceleration occurs unintentionally by the driver, safe driving of the vehicle can be realized.</p><p> Further, in the invention according to claim 6, since the fail-safe measures are executed in a plurality of systems, even if one of the CPUs fails, the fail-safe measures are surely executed by the other CPU, and the vehicle travels. Safety can be maintained.</p>
Hereinafter, an embodiment embodying the present invention will be described with reference to the drawings. This embodiment is applied to a control system of a gasoline engine for automobiles, and the method for appropriately controlling the operating state of the engine by an electronic control unit (hereinafter referred to as an ECU) in the control system is described below. It will be described in detail. Although not shown because it is a well-known configuration, the vehicle includes an engine and a transmission connected to the crankshaft of the engine, and the output of the engine is transmitted to the transmission via the crankshaft and is further automatic. The rotation of the output shaft of the transmission is transmitted to the wheels via the differential gear and the axle, so that the vehicle runs.
FIG. 1 is a block diagram showing a main configuration of the control system. Note that FIG. 1 illustrates a configuration in which the injector of the engine and the throttle valve are electrically controlled by the ECU.
The ECU 10 includes a first CPU 11, a second CPU 12, and a signal input unit 13. An air flow meter 21, a throttle opening sensor 22, an engine rotation speed sensor 23, an accelerator sensor 24, and an acceleration sensor 25 are connected to the signal input unit 13, and detection signals are input from each of these sensors. All of these sensors are well known, but briefly, the air flow meter 21 detects the amount of air taken in from the engine intake pipe (intake air amount). The throttle valve opening degree (throttle opening degree) is detected by the throttle opening degree sensor 22. The engine speed sensor 23 detects the crank angle position accompanying the rotation of the engine, and detects the engine speed based on the signal. The accelerator sensor 24 detects the amount of depression of the accelerator pedal (accelerator operation amount) by the driver. The acceleration sensor 25 detects the acceleration of the vehicle while the vehicle is running.
The first CPU 11 and the second CPU 12 execute control programs prepared for each of them based on various detection information input via the signal input unit 13. In this case, in particular, the first CPU 11 controls the drive of the injector 31, and the second CPU 12 controls the drive of the throttle actuator 32. More specifically, the first CPU 11 calculates a target fuel amount based on the intake air amount, engine speed, and the like each time, and controls the drive of the injector 31 based on the target fuel amount. Further, the second CPU 12 calculates the target throttle opening degree based on the accelerator operation amount and the like each time, and controls the drive of the throttle actuator 32 based on the target throttle opening degree. By driving the throttle actuator 32, the actual throttle opening is adjusted to the target throttle opening.
Further, the ECU 10 is configured to execute a predetermined fail-safe measure when some abnormality occurs in the system. In particular, in the present embodiment, the first CPU 11 and the second CPU 12 independently monitor the abnormality, and when the occurrence of the abnormality is detected, each of the CPUs 11 and 12 individually executes a fail-safe measure. At this time, basically, the first CPU 11 executes a fail-safe measure on the injector 31, and the second CPU 12 executes a fail-safe measure on the throttle actuator 32.
By the way, the abnormality (failure) that occurs in the control system can be classified from an abnormality in a lower event such as a sensor and software to an abnormality in a higher event such as a change in the behavior of a vehicle. This will be described with reference to FIG. When an abnormality occurs in a sensor, software, etc. as a subordinate event (for example, abnormality a, b, c, etc.), various actuators malfunction due to the abnormality (malfunction A, B, C, etc.). Of course, in addition to the cause of sensor abnormality, malfunction may occur due to failure of the actuator itself. Then, when the engine output increases due to an abnormality in these sensors, software, actuators, etc., an abnormal acceleration unintentional by the driver may occur in the vehicle as a higher-level event.
To explain specifically the case of electronic throttle control, for example, if a failure of the throttle opening sensor or the throttle actuator occurs, the throttle opening cannot be controlled to the position intended by the system, and in the worst case, the throttle is fully opened, that is, the accelerator. It is erroneously controlled to the same position as when the pedal is depressed deeply. In this case, it is predicted that the vehicle will behave unintentionally by the driver and a dangerous state will occur.
Abnormalities in sensors, software, actuators, etc. (lower events) do not necessarily cause behavioral changes that the driver perceives as dangerous, whereas abnormal acceleration of the vehicle (upper events) causes behavioral changes that the driver perceives as dangerous. Is thought to cause.
Therefore, in the present embodiment, it is classified into (1) an abnormality in which a behavior change that the driver feels dangerous in the vehicle appears, and (2) an abnormality in other systems, and each of them is constantly detected and an abnormality occurs. Occasionally, fail-safe measures are taken according to the abnormality.
More specifically, the abnormality in (1) above can be detected, for example, when the actual acceleration of the vehicle becomes larger than the acceleration required by the driver (required acceleration). Then, when the occurrence of the above-mentioned abnormality (1) is detected, a relatively strong fail-safe measure such as immediately stopping or limiting the operation of the engine is executed. For example, the first CPU 11 stops fuel injection or reduces the fuel injection amount, and the second CPU 12 controls the throttle opening to the fully closed side to reduce the intake air amount. As a result, the engine output is significantly suppressed. In this case, since the first CPU 11 and the second CPU 12 execute the fail-safe measures of two systems, even if one CPU is not functioning properly, the other CPU can execute the appropriate fail-safe measures. In other words, anomaly detection and fail-safe measures are less reliable on a CPU that is not functioning properly, but the other CPU compensates for it.
Further, if the abnormality of (2) is also detected at the time of detecting the abnormality of (1) above, the cause of the abnormality of (1) is identified as the abnormality of (2). In this case, along with the information on the occurrence of the abnormality, the information that the cause is (2) above is stored and held in the backup memory (for example, EEPROM, backup RAM, etc.) of the ECU 10. At a vehicle repair shop or the like, failure analysis is performed based on the information stored in the backup memory.
If only the occurrence of the abnormality in (1) above is detected, the cause cannot be identified as (2) above, but when the abnormality in (1) above occurs, the implementation of fail-safe measures to avoid danger is the highest priority. There is no problem as long as safety is guaranteed.
The abnormality in (2) above can be detected by appropriately monitoring the sensor output and the operating state of various actuators. Here, when only the abnormality in (2) above is detected, it is not necessarily a dangerous state, so a strong fail-safe as in the case of detecting the abnormality in (1) above is not necessary. Therefore, a relatively minor fail-safe measure is implemented in order to prevent the situation from becoming dangerous due to the subsequent occurrence of a secondary abnormality. For example, in each of the CPUs 11 and 12, the warning lamp in the meter panel is turned on to urge the driver to repair, and the abnormality occurrence information is stored in the backup memory. In addition, it is possible to limit the vehicle speed, suppress acceleration, and prohibit the execution of cruise control.
Next, the processing procedure of the abnormality diagnosis executed by the first CPU 11 and the second CPU 12, respectively, will be described. FIG. 3 is a flowchart showing the abnormality diagnosis process executed by the first CPU 11.
In FIG. 3, in step S101, the acceleration required by the driver (required acceleration) is calculated. At this time, the required acceleration is calculated from the accelerator operation amount (absolute amount) or / and the degree of change thereof detected by the accelerator sensor 24. Further, in step S102, the actual acceleration of the vehicle detected by the acceleration sensor 25 is read. It is also possible to estimate the actual acceleration of the vehicle from the amount of change in each wheel speed.
After that, in step S103, it is determined whether or not the actual acceleration is larger than the required acceleration. If the actual acceleration> the required acceleration, it is considered to be an abnormality that the driver feels dangerous, and in step S104, a strong fail-safe measure such as stopping fuel injection or reducing fuel injection amount is executed. When the actual acceleration the required acceleration, strong fail-safe measures such as stopping fuel injection and reducing fuel injection amount are not executed. However, in this case, in addition to the direct comparison between the actual acceleration and the required acceleration, a fail-safe measure may be executed when their deviation (= actual acceleration-required acceleration) is equal to or greater than a predetermined threshold value.
After that, in step S105, abnormality detection is performed for system components such as sensors and actuators. Then, when an abnormality is detected in the sensor, actuator, or the like (when step S106 becomes YES), a weak fail-safe measure such as turning on the warning lamp or limiting the vehicle speed is executed in step S107. Finally, in step S108, when an abnormality occurrence is detected, the abnormality occurrence information or the like is stored in EEPROM or the like as diagnostic data. The second CPU 12 also executes the same abnormality diagnosis process as in FIG. 3 above. The only difference is the content of the fail-safe procedure, and illustrations and explanations are omitted here.
According to the present embodiment described in detail above, the following excellent effects can be obtained.
When the actual acceleration of the vehicle is larger than the required acceleration required by the driver, the output of the engine is stopped or reduced as a fail-safe measure, and an abnormality occurs in various components (sensors, actuators, etc.) of the system. In addition, as a fail-safe measure, a warning to the driver, etc. is executed. Therefore, even if the vehicle is abnormally accelerated, the vehicle can be driven without giving a fear to the driver. In addition, it is possible to suppress a decrease in vehicle drivability due to excessive fail-safe measures. Further, even if a system abnormality is detected and omitted due to a mistake / omission of a design / program due to a complicated system or the like, the running safety of the vehicle can be ensured.
Two CPUs 11 and 12 were provided, and each of these CPUs 11 and 12 was configured to execute abnormality detection and fail-safe measures in two systems. As a result, the redundancy of the system is enhanced, and even if one of the CPUs fails, the fail-safe measure is surely executed by the other CPU, and the running safety of the vehicle can be maintained.
The present invention is not limited to the description of the above embodiment, and may be implemented as follows, for example.
When an abnormality occurs in which the actual acceleration is larger than the required acceleration, feedback control may be performed so that the actual acceleration matches the required acceleration as a fail-safe measure. Simply stopping or reducing the output of the engine will significantly reduce the running performance of the vehicle, which is not preferable from the viewpoint of limp home performance. Therefore, even in the event of a system failure, the acceleration intended by the driver is maximized so that driving performance can be ensured as much as possible.
In the above embodiment, when monitoring the change in the behavior of the vehicle, it is determined whether or not the actual acceleration is in the abnormal acceleration state larger than the required acceleration, but instead of or in addition to this, the abnormal deceleration state is determined. It may be determined whether or not it is. In the case of abnormal deceleration, as in the case of abnormal acceleration, the engine output is stopped or reduced as a fail-safe measure.
In the above embodiment, it is determined whether the change in the behavior of the vehicle is intended by the driver by directly comparing the required acceleration based on the driver's accelerator operation with the actual acceleration of the vehicle, but this configuration is changed. To do. For example, it may be determined whether or not the actual acceleration of the vehicle is within a predetermined allowable range, thereby determining whether or not the change in the behavior of the vehicle is intended by the driver. The permissible range is determined by excluding, for example, an impossible acceleration operation by the driver. In this case, the permissible range can be variably set with parameters such as vehicle speed and gear ratio.
In the above embodiment, the engine ECU having two CPUs has been described, but the ECU may be an ECU having a single CPU. Even in such a case, by monitoring the actual acceleration of the vehicle and the like and executing the fail-safe measure according to the result as described above, the fail-safe measure can be appropriately carried out as necessary.
In the above embodiment, abnormality detection and fail-safe measures have been described for a case where the power source of the vehicle is a gasoline engine, but the present invention can also be applied to a vehicle having a power source other than the gasoline engine. For example, in the case of a vehicle powered by a diesel engine, the output is suppressed by stopping fuel injection or reducing the amount of fuel injection as a fail-safe measure. In the case of an electric vehicle powered by an electric motor, the output is suppressed by completely stopping the power supply or reducing the power supply as a fail-safe measure. Furthermore, in the case of a hybrid vehicle powered by an electric motor and a gasoline engine, as a fail-safe measure, the output is suppressed by completely stopping the power supply to the motor or reducing the power supply, and the fuel injection to the engine is completely stopped. Alternatively, the output is suppressed by forcibly returning the throttle opening to a low opening at the same time or independently as the output is suppressed by reducing the fuel injection amount.
<figref num="1">It is a block diagram which shows the outline of the vehicle control system in embodiment of the invention.</figref><figref num="2">It is a figure for demonstrating from the lower-order event to the upper-order event of an abnormality.</figref><figref num="3">It is a flowchart which shows the abnormality diagnosis processing.</figref>
Code description
10 ... ECU, 11 ... 1st CPU, 12 ... 2nd CPU, 31 ... injector, 32 ... throttle actuator.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP2072366A1 | Cited by | European Patent Office (EPO) | Applicant |
| JP2009008056A | Cited by | Japan | Examiner |
| US8918228B2 | Cited by | United States of America | Applicant |
| US7287514B2 | Cited by | United States of America | Search report |
| JP2010224680A | Cited by | Japan | Search report |
| US8160790B2 | Cited by | United States of America | Applicant |
| JP2016094883A | Cited by | Japan | Search report |
| US8155843B2 | Cited by | United States of America | Applicant |
| EP2796696A4 | Cited by | European Patent Office (EPO) | Search report |
| US8155829B2 | Cited by | United States of America | Applicant |
| JP2021193281A | Cited by | Japan | Search report |
| CN113829889A | Cited by | China | Search report |
| US11535266B2 | Cited by | United States of America | Search report |
2 members in 1 office
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2005291173AThis record | Japan | A | |
| JP4623991B2 | Japan | B2 |
20 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of patent or utility model registrationJAPANESE INTERMEDIATE CODE: R151R151 | R151 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Re-examination (zenchi) completed and case transferred to appeal boardAppealJAPANESE INTERMEDIATE CODE: A912A912 | A912 | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: A7422RD02 | RD02 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2005291173
- Application
- 110977
Titles2
- Japanese
- 車両制御システム
- English
- Vehicle control system
Classification
- IPC, 2
- F02D45 00
- F02D41 22