IP Library Granted Patent US 11,372,706
Granted Patent B2
US 11,372,706 · App. 16/481,320 · Granted Jun 28, 2022

Vehicle control device

Inventors: Tasuku Ishigooka (Tokyo, JP); Tomohito Ebina (Ibaraki, JP); Kazuyoshi Serizawa (Ibaraki, JP)
Assignee: HITACHI ASTEMO, LTD.
G06F11/079G06F9/4812G06F11/0739
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,372,706
App. No.
16/481,320
Granted
Jun 28, 2022
Kind
B2
Abstract

This invention detects deviations from design without hindering the real-time nature of interrupt processing, and assists in analyzing the impact of faults caused by unintentional interrupt processing, with the goal of curbing erroneous detection. In order to resolve this problem, this vehicle control device comprises; a deviation determination unit 129 which determines if execution timing of an execution body has deviated from design settings, and transitions to a monitoring state; and a run-time verification unit 130 which verifies the impact of deviation at timing which differs from that of the interrupt processing.

Claims (22)

1. A vehicle control device comprising a processor and a memory, the processor being configured to:

determine whether execution timing of an execution body has deviated from a design setting;

transition to a monitoring state;

verify an impact of deviation of the execution timing that differs from a timing of interrupt processing; and

in response detecting an error in the monitoring state, cause an output of a notification of a state at a time of deviation together with an error code indicating a cause of the error,

wherein determining whether the execution timing has deviated from the design setting includes comparing the execution timing with a constraint expression including a parallel execution constraint of the execution body.

2. The vehicle control device according to claim 1 , the memory being further configured to store the state at the time of deviation together with the error code when the error is detected in the monitoring state.

3. The vehicle control device according to claim 1 , wherein the execution body is at least one of interrupt processing, a task, or circuit processing.

4. The vehicle control device according to claim 1 , wherein the state at the time of deviation is an execution situation of the execution body.

5. The vehicle control device according to claim 1 , wherein the parallel execution constraint is a group of a task and interrupt processing for which parallel execution is simultaneously permitted.

6. The vehicle control device according to claim 1 , wherein the parallel execution constraint includes a serial execution constraint in a same core.

7. The vehicle control device according to claim 1 , wherein the parallel execution constraint also includes processing in a multi-core, processing of a GPU, and processing of an FPGA.

8. The vehicle control device according to claim 1 , wherein the timing that differs from the timing of the interrupt processing results from one of: that the verification of the impact of deviation is executed at a time when the interrupt processing is not executed, the verification of the impact of deviation is executed at an end time of the interrupt processing, or the verification of the impact of deviation is executed at a time having a lower priority than a priority of the interrupt processing.

9. The vehicle control device according to claim 1 , wherein the processor and the memory are further configured to determine deviation based on a state transition event of each state.

10. The vehicle control device according to claim 9 , wherein the processor and the memory determine deviation based on the state transition event by a state transition simulation.

11. The vehicle control device according to claim 1 , wherein a program to be monitored is a program for which state transition is designed.

12. A design verification support device comprising a processor and a memory which stores executable instructions, which, on execution, cause the processor to:

access a log of an execution state of an execution body;

determine, from a design in the log of the execution state of the execution body, whether a deviation in execution timing from a design setting has occurred;

perform a run-time verification that verifies an impact of deviation at execution timing that differs from timing of interrupt processing; and

in response detecting an error when verifying the impact of deviation of execution timing, output a notification of a state at a time of deviation together with an error code indicating a cause of the error,

wherein determining whether the execution timing has deviated from the design setting includes comparing the execution timing with a deviation state stored in the log.

Assignments (2)
CHANGE OF NAME Recorded Sep 2, 2021
From: HITACHI AUTOMOTIVE SYSTEMS, LTD.
To: HITACHI ASTEMO, LTD.
Reel/Frame 057655/0824 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2019
From: ISHIGOOKA, TASUKU; EBINA, TOMOHITO; SERIZAWA, KAZUYOSHI
To: HITACHI AUTOMOTIVE SYSTEMS, LTD.
Reel/Frame 049874/0115 →
Priority Claims (1)
JP JP2017-058394 · Mar 24, 2017 · national
Continuity (1)
Related Publication 20190354424A1 · Nov 21, 2019