Vehicle management system
Patent Information
- Application Number
- JP2025028845
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2026-09-07
AI Technical Summary
【0010】 本発明によれば、車両メーカから出荷された車両においてディーラオプション等の個別の設定を販売会社側で行うことができ且つ車両出荷後における変更が認められない設定を販売会社側などで車両出荷時の設定以外に変更できないようにすることができる。
Smart Images

Figure 2026142012000001_ABST
Abstract
Description
[[Technical Field]]
[0001] The present invention relates to a vehicle management system. [[Background Art]]
[0002] In recent years, technology for integrating control of each part of a vehicle into a single electronic control unit (ECU) has been advancing. This technology enables a single electronic control unit to also control cockpit-related in-vehicle devices such as an independent navigation system, display audio, and a meter.
[0003] In existing systems, since vehicle specifications differ according to a user's requests, software is created at a vehicle manufacturer's factory in accordance with combinations of vehicle specifications. Since the created software differs according to the vehicle specifications requested by the user, combinations with matching vehicle specifications are managed under the same control number, and software of the same combination is stored in electronic control units having the same control number. [[Prior Art Documents]] [[Patent Documents]]
[0004] [[Patent Document 1]] Japanese Unexamined Patent Application Publication No. 2007-11466 [[Summary of the Invention]] [[Problem to be Solved by the Invention]]
[0005] As described above, a vehicle manufacturer's factory manages electronic control units with different control numbers depending on the combination of software stored in the electronic control units. For this reason, when attempting to store software for different vehicle specifications in an electronic control unit at a vehicle manufacturer's factory, the number of control numbers for electronic control units increases, management becomes complicated, and additional space is required to store electronic control units separately for each control number.
[0006] Furthermore, as the control of cockpit-related in-vehicle equipment, such as dealer options, becomes integrated, the software for these dealer options also needs to be stored in the electronic control unit. This further increases the number of software combinations, leading to greater management complexity and storage space issues.
[0007] Furthermore, since individual settings such as dealer options may be made by sales companies after the vehicle is shipped from the manufacturer, there is a problem in that there is no mechanism to prove that settings that cannot be changed after the vehicle is shipped are exactly the same as the settings at the time of shipment.
[0008] The objective of the present invention is to provide a vehicle management system that allows dealerships to make individual settings such as dealer options on vehicles shipped from the vehicle manufacturer, and that prevents dealerships from changing settings other than those at the time of vehicle shipment, which are not permitted to be changed after the vehicle has been shipped. [Means for solving the problem]
[0009] To achieve the above objective, the vehicle management system according to the present invention comprises: an electronic control unit equipped with software for multiple vehicle specifications and which sets vehicle specifications by parameters; a first setting device which sets the parameters in the electronic control unit before vehicle shipment; and a second setting device which sets the parameters in the electronic control unit of a vehicle after shipment. The first setting device generates signature data and transmits the setting information and the signature data to the electronic control unit when setting the parameters, and the second setting device sets the parameters in the electronic control unit of a vehicle after shipment based on the setting information and the signature data transmitted by the first setting device to the electronic control unit. [Effects of the Invention]
[0010] According to the present invention, individual settings such as dealer options can be made by the sales company in vehicles shipped from the vehicle manufacturer, and settings that are not permitted to be changed after the vehicle has been shipped cannot be changed by the sales company or others to settings other than those at the time of vehicle shipment. [Brief explanation of the drawing]
[0011] [Figure 1] Figure 1 is a schematic diagram illustrating the vehicle management system according to an embodiment. [Figure 2] Figure 2 shows an example of the configuration of a vehicle's electronic control unit. [Figure 3] Figure 3 is an explanatory diagram showing an example of the configuration of the parameter sequence. [Figure 4] Figure 4 shows an example of the structure of the data to be written to an electronic control unit (ECU). [Figure 5] Figure 5 shows an example of the configuration of a specifications storage table. [Figure 6] Figure 6 shows an example of a vehicle production flow. [Figure 7] Figure 7 shows an example of the purchase flow for dealer options. [Figure 8] Figure 8 is a schematic diagram illustrating the process of replacing an electronic control unit. [Figure 9] Figure 9 shows an example of the supply installation flow. [Figure 10] Figure 10 shows an example of an order table for a sales server. [Figure 11] Figure 11 shows an example of the management flow of electronic control units (ECUs) within a vehicle production plant. [Figure 12] Figure 12 shows an example of the hardware block configuration of a vehicle management system. [Figure 13] Figure 13 shows an example of a specifications storage table. [Figure 14] Figure 14 is an explanatory diagram illustrating an example of the process for generating electronic signatures in a vehicle production plant. [Figure 15]FIG. 15 is a diagram showing an example of the configuration of write data for setting parameters of an ECU after replacement. [Figure 16] FIG. 16 is an explanatory diagram showing an example of processing that uses an electronic signature on a vehicle sales company side. DESCRIPTION OF EMBODIMENTS
[0012] Hereinafter, a vehicle management system according to an embodiment of the present invention will be described in detail with reference to the accompanying drawings.
[0013] <Embodiment> In the present embodiment, a method of setting vehicle specifications to an electronic control device by providing a management server that manages vehicle specification setting information will be described.
[0014] Vehicle specification setting includes vehicle specification setting performed on an electronic control device at a vehicle production factory 1 (see FIG. 1), and vehicle specification setting performed on an electronic control device of a vehicle 4 (see FIG. 1) after the vehicle 4 is shipped from the vehicle production factory 1 to a vehicle sales company 3 (see FIG. 1). The setting after shipment is performed outside the vehicle production factory 1, and is thus referred to as setting on the vehicle sales company 3 side.
[0015] Setting information is a value set for a vehicle specification parameter of an electronic control device. A setting device that sets the electronic control device writes a configuration parameter value corresponding to a vehicle specification into a parameter of the electronic control device. Through this writing, the vehicle specification of the electronic control device is set to a predetermined vehicle specification. An example of the setting device is a diagnostic device that diagnoses an electronic control device. Hereinafter, the first setting device and the second setting device will be described by taking a first diagnostic device and a second diagnostic device as an example.
[0016] The parameters include a parameter for setting a value corresponding to a model, and a parameter for selectively setting "enable" and "disable" of software.
[0017] Furthermore, the parameter settings may include options such as "Yes" or "No". For example, the drive recorder target cameras used to capture images of the surroundings of the vehicle, among the front camera, rear camera, left side camera, and right side camera that monitor the area around the vehicle 4, may be set by writing "Yes" or "No". In this case, combinations such as only the front camera, the front camera and rear camera, the front camera, rear camera and left and right side cameras, and no camera are possible, so the drive recorder target cameras are set by writing "Yes" or "No". In addition, the images of the surroundings of the vehicle captured by the cameras may be recorded in a storage unit such as the memory in the in-vehicle drive recorder or electronic control unit.
[0018] Vehicle production plant 1 ships vehicle 4 with all the software for all vehicle specifications already installed in its electronic control unit. This includes software that supports dealer options that can be set later for the vehicle specifications.
[0019] In the following, the vehicle specification settings will be explained assuming, as an example, that they include "items related to the model," "items related to the manufacturer," and "items related to dealer options." Vehicle production plant 1 sets the "items related to the model," "items related to the manufacturer," and "items related to dealer options." Vehicle sales company 3 sets the items among these that can be changed. In this example, the item that can be changed is assumed to be "items related to dealer options." Therefore, in this embodiment, an example is shown in which the settings for "items related to the model" and "items related to the manufacturer" are set in the first vehicle specification write data, and the settings for "items related to dealer options" are set in the second vehicle specification write data.
[0020] Furthermore, if there are other items in the "Items related to dealer options" that are permitted to be changed later, you may include them in the data written to the second vehicle specification and set them accordingly.
[0021] Furthermore, as will be explained in detail in the second embodiment, there are cases where the vehicle sales company 3 replaces the electronic control unit. In that case, the "model-related items" and "manufacturer-related items" are also written to the new electronic control unit that replaces the old one. These "model-related items" and "manufacturer-related items" are written when the electronic control unit is configured at the time of vehicle shipment.
[0022] Figure 1 is a schematic diagram illustrating the vehicle management system according to an embodiment. Figure 1 shows the configuration of the vehicle management system between a vehicle production plant 1, a vehicle manufacturer 2, and a vehicle sales company 3.
[0023] As shown in Figure 1, the vehicle production plant 1 ships the vehicle 4 after workers or production robots assemble parts onto the vehicle 4 and configure the electronic control device of the vehicle 4 on the vehicle production line 10.
[0024] For example, in vehicle production plant 1, electronic control units are all managed under a common management number 1. As will be explained in more detail later, each electronic control unit with management number 1 stores the same combination of software and is managed under the common management number 1 until shipment.
[0025] The factory server 11 of the vehicle production plant 1 is an information processing device that comprehensively manages the production of vehicles 4 at the vehicle production plant 1. The factory server 11 is connected to the system of the vehicle production line 10 and the first diagnostic device 12 in a communication manner.
[0026] The first diagnostic device 12 is a diagnostic device for the electronic control unit. The first diagnostic device 12 is also a writing tool that writes configuration information to the electronic control unit, and is therefore also called a writing device. The first diagnostic device 12 is secure and communicates with a diagnostic communication unit provided in the electronic control unit to read and write to the electronic control unit.
[0027] Vehicle manufacturer 2 manages information about vehicle 4 using a sales server 21 and a specification storage server 22. In addition, a production instruction generation unit 23 is also shown in Figure 1 for illustrative purposes. The sales server 21, specification storage server 22, and production instruction generation unit 23 are built on, for example, the internal network of vehicle manufacturer 2. In addition to these, the internal network of vehicle manufacturer 2 also has a traceability information management server (see Figure 8) for managing traceability information and a parts supply unit (see Figure 8) for supplying parts, but these are omitted from explanation and illustration here.
[0028] The sales server 21 and the specification storage server 22 are examples of "management servers". The sales server 21 is an information processing device that processes orders based on the purchase information of vehicle 4. The specification storage server 22 is an information processing device that stores the latest configuration information of vehicle 4.
[0029] The production instruction generation unit 23 is an information processing device that generates production instruction information for vehicle 4. The production instruction information is information that instructs the production of vehicle 4 based on the vehicle specifications in the purchase information. For example, the production instruction generation unit 23 generates production instruction information corresponding to several hundred digits of specifications for vehicle 4. If it is a two-wheel drive vehicle, it generates information instructing that the parts for a two-wheel drive vehicle be assembled at the vehicle production plant 1.
[0030] Vehicle sales company 3 sells vehicles 4 and performs repairs on them. Figure 1 shows one of the stores located in various locations. Vehicle sales company 3 has a vehicle sales company terminal 31 and a second diagnostic device 32. The vehicle sales company terminal 31 is an information processing device that accepts vehicle purchases and dealer option purchases.
[0031] The second diagnostic device 32 is a diagnostic device used by the vehicle sales company 3 to diagnose the electronic control unit of the vehicle 4. The second diagnostic device 32 is also a writing tool that writes setting information to the electronic control unit, and is therefore also called a writing device. The second diagnostic device 32 is secure and communicates with the diagnostic communication unit provided in the electronic control unit of the vehicle 4 to read and write to the electronic control unit.
[0032] The communication networks N1 and N2 shown in Figure 1 are communication networks. Communication network N1 connects vehicle sales company 3 and vehicle manufacturer 2 in a communication-enabled manner. Communication network N2 connects vehicle manufacturer 2 and vehicle production plant 1 in a communication-enabled manner. Communication networks include, for example, the internet or dedicated lines. Communication with the specification storage server 22 is assumed to be highly secure.
[0033] Figure 2 shows an example of the configuration of the electronic control unit of vehicle 4. The ECU41 shown in Figure 2 is an electronic control unit called an HCU (HMI Control Unit) or integrated ECU (Electronic Control Unit) that integrates the control of various parts of the vehicle. The ECU41 can also integrate the control of cockpit-related in-vehicle equipment of vehicle 4, and can control individual in-vehicle equipment such as a navigation system, display audio, and meters. If there are changes to the specifications of dealer options, the specifications of vehicle 4 will be changed by setting the parameters of the ECU41.
[0034] The ECU41 shown in Figure 2 stores software sets (Software 1, Software 2, ...) 40 for all specifications. As shown in Figure 2, by setting the parameters (parameter column 200) of the ECU41, the corresponding software is enabled or disabled, a value corresponding to the model is set, and it is set to "Yes" or "No". In this way, the ECU41 is set to the predetermined vehicle specifications. Furthermore, after the vehicle 4 is shipped, by switching the items in the parameter column 200 corresponding to dealer options to enable or disable, the software in the software group 40 corresponding to the dealer options is enabled or disabled after shipment.
[0035] Each unit 42 shown in Figure 2 is connected to the ECU 41 via the CGW (Central Gateway) 43. These units include a VCU (Vehicle Control Unit) that controls the brakes, and an EFI (Electronic Fuel Injector) that controls devices related to the engine and other power sources. Each unit 42 and the CGW 43 are connected via a CAN (Controller Area Network). The ECU 41 and the CGW 43 are also connected via a CAN.
[0036] CGW43 is a control unit that controls multiple communication paths and also has ports for diagnostic communication that connect to the first diagnostic device 12 and the second diagnostic device 32. The first diagnostic device 12 and the second diagnostic device 32 communicate with the ECU41 via the diagnostic communication ports of CGW43 to read data from each unit 42 and to read and write data to the ECU41.
[0037] Figure 3 is an explanatory diagram showing an example of the configuration of items in parameter column 200. Parameter column 200 includes setting item 210 and setting item 220.
[0038] Setting item 210 includes items for setting the vehicle type information of vehicle 4 and items for setting manufacturer options. The items for setting the vehicle type information of vehicle 4 are regulatory items such as OEM information 211 and tire diameter 212. The parameters for the items for setting the vehicle type information of vehicle 4 and the items for setting manufacturer options in the parameter sequence 200 of the ECU41 are set to parameter values corresponding to the vehicle specifications of vehicle 4 from among multiple parameter values of the corresponding items shown in Figure 3 (for example, A0 and A1). Even if the electronic control unit is replaced later for repair or restoration purposes, the setting item 210 of the new electronic control unit that replaces the old one will have the exact same values as when the vehicle was shipped.
[0039] The other setting item 220 includes items related to dealer options such as the navigation system 221 and television 222. These items can be switched on or off later upon request. Each of these parameters can be selectively set to one of multiple parameter values for the corresponding item shown in Figure 3, for example, A0 (disabled) or A1 (enabled).
[0040] Note that in items including dealer options, only parameters for enabling or disabling the software are shown, but parameters such as selecting "Yes" or "No" may also be included.
[0041] Figure 4 shows an example of the structure of the write data used to set the parameters of the ECU41. Figure 4 shows the structure of the write data d3 for setting the first vehicle specification and the structure of the write data d5 for setting the second vehicle specification.
[0042] As an example, the write data d3 for the setting of the first vehicle specification and the write data d5 for the setting of the second vehicle specification both consist of data sequences of data values to be set as parameters. The data values correspond to the parameter values shown in Figure 4. The arrangement of the parameter values in data sequences 110 and 120 shown in Figure 4 corresponds to the arrangement of items in parameter sequence 200 (see Figure 3). Here, Figure 4 shows the items of parameter sequence 200 corresponding to data sequences 110 and 120, respectively, but these are illustrated for explanatory purposes to show the correspondence between the items of parameter sequence 200 and data sequences 110 and 120.
[0043] The write data d3 for the first vehicle specification setting is the write data acquired at vehicle production plant 1. At the beginning of data column 110, an identification parameter value is set to indicate that it is the write data for the first vehicle specification setting.
[0044] Each parameter value in data column 110 is set using the input method shown for the items in vehicle specification setting item 210 (see Figure 3). For example, the parameter value of data 111 is one of several parameter values set in vehicle specification setting item 211 (see Figure 3). The parameter value of data 112 is one of several parameter values set in vehicle specification setting item 212 (see Figure 3). Each parameter value in data column 113 is one of several parameter values set in vehicle specification setting item 213 (see Figure 3).
[0045] The write data d5 for the second vehicle specification setting is the write data acquired by the vehicle production plant 1 and the vehicle sales company 3. At the beginning of data column 120, an identification parameter value is set to indicate that it is the write data for the second vehicle specification setting.
[0046] Each parameter value in data column 120 is set using the input method for the corresponding item shown in vehicle specification setting item 220 (see Figure 3). For example, the parameter value of data 121 is one of several parameter values set in vehicle specification setting item 221 (see Figure 3). The parameter value of data 122 is one of several parameter values set in vehicle specification setting item 222 (see Figure 3).
[0047] Although it was explained that the vehicle production plant 1 obtains the write data d3 for the first vehicle specification setting and the write data d5 for the second vehicle specification setting, the availability of dealer options is not determined until after shipment and before delivery. Therefore, the vehicle production plant 1 temporarily sets the dealer option parameters of the ECU 41 to predetermined parameter values (e.g., disabled) using the write data d5 for the second vehicle specification setting. Then, before delivery, the vehicle sales company 3 may obtain the write data d5 for the second vehicle specification setting with the confirmed value and update the dealer option parameter settings of the ECU 41.
[0048] Furthermore, if any dealer options are purchased or canceled after delivery, the vehicle sales company 3 will use the second vehicle specification setting data d5 to update the ECU 41 to the latest parameter values, ensuring it is always up-to-date.
[0049] Here, as an example, we have shown a data configuration in which the write data acquired at the vehicle production plant 1 is the write data d3 for the setting of the first vehicle specification and the write data d5 for the setting of the second vehicle specification, and the write data acquired at the vehicle sales company 3 is the write data d5 for the setting of the second vehicle specification. However, this is not the only configuration. For example, when the electronic control unit is replaced at the vehicle sales company 3, the vehicle sales company 3 may also acquire the write data d3 for the setting of the first vehicle specification and the write data d5 for the setting of the second vehicle specification.
[0050] Alternatively, the data to be written may be combined into a single data structure that includes all items, rather than splitting the data into two parts: items set at the vehicle production plant 1 and items set at the vehicle sales company 3.
[0051] As in this embodiment, by writing the parameter values of each item for setting the vehicle specifications as a set of data columns to the ECU41, it is possible to set the vehicle specifications to the ECU41 all at once.
[0052] The ECU41 settings described above involve enabling or disabling the parameter column 200 in a batch based on the data sequence of the written data, but this method is not the only way to configure it. Other configuration methods are also acceptable. For example, one could configure it by individually selecting the parameter values for the relevant items in the parameter column 200 from the available options.
[0053] Figure 5 shows an example of the configuration of the specification storage table 100. As shown in Figure 5, the specification storage table 100 is a table that associates "VIN information," "serial number," "specification information 1," and "specification information 2" with each other. In addition to these, the specification storage table 100 can also associate signature data.
[0054] "VIN information" refers to vehicle identification information called a VIN (Vehicle Identification Number) that is assigned to each vehicle.
[0055] The "serial number" is identification information assigned to each ECU41.
[0056] "Specification Information 1" refers to vehicle specification items whose parameter values cannot be changed from those set at the time of vehicle shipment. "Specification Information 2" refers to vehicle specification items whose parameter values can be changed by the vehicle sales company.
[0057] Figure 5 shows the state before and after an update when parameter values set at the vehicle production plant are set in "Specification Information 1" and "Specification Information 2," and then the parameter value of "Specification Information 2" is changed due to the purchase of a dealer option. An explanation of the state before and after the update using Figure 5 will be given later.
[0058] Next, we will explain the vehicle production flow shown in Figure 6 and the dealer option purchase flow shown in Figure 7, referring to the overall diagram in Figure 1. Note that the dotted arrows in Figure 1 represent the data flow when setting vehicle specifications at the time of vehicle purchase (ordering), and the solid arrows represent the data flow when setting vehicle specifications for dealer options. First, we will explain the vehicle production flow in Figure 6, referring to the dotted arrows in Figure 1.
[0059] First, when a customer purchases a vehicle, the vehicle sales company terminal 31 sends the customer's vehicle specifications information D1 to the sales server 21, and the sales server 21 receives the customer's vehicle specifications information D1 (step S1).
[0060] Next, the sales server 21 processes the vehicle order based on the received customer vehicle specification information D1 and instructs the production instruction generation unit 23 to generate production information, etc., corresponding to the customer vehicle specification information D1 (step S2).
[0061] The production instruction generation unit 23 generates converted data D2 by converting the customer's vehicle purchase information into production information and sends the converted data D2 to the factory server 11 (step S3). The converted data D2 is data in which VIN information is added to vehicle production information (called VLT) created based on vehicle specifications (such as model and option information).
[0062] When the factory server 11 receives the conversion data D2, it creates production instruction information D3 for vehicle 4 from the conversion data D2 and stores it in the master 11-1. The factory server 11 also communicates with the vehicle production line 10 based on the production instruction information D3 stored in the master 11-1 and issues production instructions to the vehicle production line 10 (step S4).
[0063] The first diagnostic device 12 acquires production instruction information D3, converts it into first write data D3-1, and writes the first write data D3-1 to the vehicle 4's ECU 41 (see Figure 2) (step S5).
[0064] Here, the first write data D3-1 is data that includes write data converted from production instruction information D3 and VIN information to be added to ECU41. The write data consists of the first vehicle specification setting write data d3 (see Figure 4), the second vehicle specification setting write data d5 (see Figure 4), and signature data. By writing the first write data D3-1 to ECU41, the parameter values of the vehicle specifications for each item of setting item 210 (see Figure 3) are set in parameter column 200 (see Figure 2). Also, the parameter values of the vehicle specifications for each item of setting item 220 (see Figure 3) are set in parameter column 200 (see Figure 2). In vehicle production plant 1, the first diagnostic device 12 writes values to the vehicle specification parameters for each item of setting item 220. Note that these values will remain as they are (specifications) unless the user purchasing vehicle 4 selects a dealer option. In addition, the VIN information may be written from the first diagnostic device 12 to other ECUs such as VCU42 and stored there.
[0065] Once the first diagnostic device 12 has finished writing the first write data D3-1 to the ECU 41, it reads the data (referred to as management data) D3-2 written from the ECU 41 during the pre-shipment inspection process of the vehicle 4, and sends the management data D3-2 to the specification storage server 22 (step S6). The management data D3-2 read from the ECU 41 consists of the values of the parameter column 200, VIN information, the serial number of the ECU 41, and signature data.
[0066] Then, the specification storage server 22 stores the management data D3-2 in the specification storage table 100 (step S7).
[0067] Note that in Figure 1, management data D3-2 is sent to the specification storage server 22 via the factory server 11, but this is just one example. Any path is acceptable in which the management data D3-2 read by the first diagnostic device 12 is stored in the specification storage server 22 while maintaining its identity.
[0068] Furthermore, during communication between devices, a checksum shall be performed to verify that there is no data corruption in the management data D3-2. A detailed explanation is omitted here, but any known method may be used for the checksum. In the following flowchart 7, although the explanation is omitted, checksums shall be performed as appropriate.
[0069] In addition to the checksum, the first diagnostic device 12 performs an electronic signature to prove the identity of the combination of the VIN information and the parameter values of the first vehicle specification setting write data d3 (see Figure 4) when writing to the ECU 41. Furthermore, the first diagnostic device 12 may also perform an electronic signature to prove the identity of the combination of the VIN information and the parameter values of the second vehicle specification setting write data d5 (see Figure 4).
[0070] When writing data to and reading data from ECU41, the identity of the data is verified using signature data, and the verified data and signature data are sent to the specification storage server 22. The method of digital signature will be explained in detail later using diagrams.
[0071] Next, the dealer option purchase flow shown in Figure 7 will be explained with reference to the solid arrows shown in Figure 1. First, when a customer purchases a dealer option, the vehicle sales company terminal 31 sends dealer option purchase information D11 to the sales server 21 (step S11). Dealer option purchase information D11 is information that includes information indicating whether the dealer option setting item is enabled or disabled, and the VIN information of the corresponding vehicle 4. The VIN information is read from the vehicle 4 after it has been delivered.
[0072] The sales server 21 processes the order based on the received dealer option purchase information D11. The sales server 21 also sends registration information D11-1 to the specification storage server 22, which registers the specifications of the dealer option based on the dealer option purchase information D11 (step S12).
[0073] The specification storage server 22 stores the registration information D11-1 as update information in the specification storage table 100, associating it with the management data D3-2 which is associated with the VIN information (step S13), and updates the dealer option specifications in the management data D3-2 (step S14). Furthermore, if an electronic signature is also performed before shipment to prove the identity with the combination of parameter values of the written data d5 for the second vehicle specification setting, the latest signature data based on the registration information D11-1 is generated and the signature data set in the specification storage server 22 is updated to the latest signature data.
[0074] The device that generates the signature data may be the specification storage server 22, the second diagnostic device 32, or another device. If the second diagnostic device 32 generates the data, it may obtain registration information D11-1 from the specification storage server 22, generate the signature data, and then send the generated signature data to the specification storage server 22 for updating.
[0075] Next, the second diagnostic device 32 reads the verification data D12 from the ECU 41 of the vehicle 4 after shipment (see Figure 2) and transmits the verification data D12 to the specification storage server 22 (step S15). The verification data D12 consists of the VIN information of the vehicle 4 and the serial number of the ECU 41 of the vehicle 4. Transmission and reception between the second diagnostic device 32 and the specification storage server 22 is performed by connecting the communication device 30 of the second diagnostic device 32 (for example, the communication equipment of the vehicle sales company) to the communication network N1.
[0076] The specification storage server 22 compares the VIN information and serial number contained in the received verification data D12 with the VIN information and serial number in the management data D3-2 stored in the specification storage table 100 (step S16).
[0077] When the specification storage server 22 finds that the VIN information and serial number in the matching data D12 and the management data D3-2 are a perfect match, it extracts the update information associated with the perfectly matched VIN information, i.e., the latest write data D12-1 for dealer options, from the specification storage table 100 and sends it to the second diagnostic device 32 (step S17). The write data d5 of the second vehicle specification settings acquired by the second diagnostic device 32 (see Figure 4) contains the latest data columns, such as whether the dealer options are enabled or disabled.
[0078] Note that in Figure 1, communication with the specification storage server 22 is shown via the vehicle sales company's communication equipment 30, but this is just one example. Any method that allows the second diagnostic device 32 to send and receive data while maintaining data identity with the specification storage server 22 is acceptable.
[0079] Furthermore, as will be the case below, a checksum will be performed each time a device communicates with another device to ensure that there is no data corruption.
[0080] Furthermore, if the specification storage server 22 has electronic signature data set to prove the identity between the VIN information and the combination of parameter values in the second vehicle specification setting write data d5, it also sends the set signature data to the second diagnostic device 32.
[0081] The second diagnostic device 32 writes the latest dealer option write data D12-1 to the ECU 41 of the vehicle 4, thereby updating the vehicle specification setting of setting item 220 (see Figure 3) of parameter sequence 200 (see Figure 2) to the latest value, and enabling the purchased dealer option (step S18). Here, the writing to the ECU 41 by the second diagnostic device 32 is performed via the diagnostic communication unit of the ECU 41 of the vehicle 4.
[0082] Here, in addition to the checksum, an electronic signature may be performed to prove identity with the management data D3-2. The method of electronic signing will be explained in detail later using diagrams.
[0083] After writing to the ECU 41, the second diagnostic device 32 reads the data written to the ECU 41, and if the written content and the read content match, it notifies the specification storage server 22 that the writing was successful (step S19).
[0084] Here, the updating of data in the specification storage table 100 by the specification storage server 22 will be explained in more detail with reference to Figure 5.
[0085] As shown in Figure 5, the specification storage table 100 stores VIN information, serial number, and specification information data linked together. As shown in Figure 5, the "VIN information" is set to "XXXX" d2, which is the VIN information read from vehicle 4. The "serial number" is set to "YYYY" d4, which is the serial number read from ECU 41. Note that "XXXX" and "YYYY" are individual identification information that is a combination of letters or numbers.
[0086] In the example shown in Figure 5, at the setup stage in vehicle production plant 1, the dealer options have not been selected by the buyer, so all items in "Specification Information 2" are set to their initial value or a temporary setting of A0 (disabled) to match the vehicle's state at that stage. In other words, vehicle production plant 1 is configured to write the parameter values of "Specification Information 2" to ECU 41. Subsequently, when the buyer purchases dealer options, vehicle sales company 3 configures the ECU 41 of vehicle 4 with the latest dealer option settings from "Specification Information 2". In the example shown in Figure 5, a dealer option navigation system is later purchased, and vehicle sales company 3 configures the ECU 41 for the dealer options, so "Navigation" is updated to A1 (enabled).
[0087] In the example shown in Figure 5, all items in "Specification Information 2" were set to A0 (disabled) during the setup stage at Vehicle Production Plant 1. However, the items in "Specification Information 2" may be set to include manufacturer options as well as dealer options. In that case, the items in "Specification Information 2" may be enabled (A1) during the setup stage at Vehicle Production Plant 1.
[0088] In this embodiment, a vehicle sales company terminal 31 accepts the purchase of dealer options, and the vehicle sales company updates the dealer option settings of the ECU 41 using a second diagnostic device 32. However, the method for accepting and setting dealer options can be carried out by various means and methods.
[0089] For example, a customer may access a designated website using a smartphone or other device and apply to purchase dealer options through the website. In this case, the website transmits the dealer option purchase information D11 to the sales server 21 on behalf of the vehicle sales company terminal 31. The rest of the data flow is the same as described above.
[0090] Furthermore, if the vehicle 4 is equipped with a wireless communication unit and has a configuration that allows communication between the ECU 41 and external devices via the wireless communication unit, communication between the second diagnostic device 32 and the ECU 41 may be performed wirelessly. In addition, the vehicle 4 may communicate with the communication device 30 via an access point from any area, not limited to within the vehicle sales company 3, and communicate with the second diagnostic device 32 to update the settings of the vehicle 4's ECU 41.
[0091] Furthermore, vehicle 4 may be equipped with an in-vehicle communication device (for example, a TCU [Telematics Control Unit]) that communicates with the outside, and may be able to access various servers such as the sales server 21 and the specification storage server 22 via the in-vehicle communication device to update the settings of the specification storage server 22 and the ECU 41. This allows the dealer option settings of the ECU 41 to be updated via communication through the in-vehicle communication device in response to operations input into the control unit of vehicle 4, such as the display audio.
[0092] Up to this point, we have explained the cases where electronic control units do not need to be replaced. Next, we will explain the cases where electronic control units need to be replaced for repair or restoration purposes.
[0093] Figure 8 is a schematic diagram illustrating the process of replacing an electronic control unit. Figure 8 clearly shows the configuration when a vehicle dealership replaces the electronic control unit (ECU41 shown in Figure 2) of vehicle 4, as shown in Figure 1. In Figure 8, the same components as in Figure 1 are numbered the same way. Below, explanations of identical components will be omitted as they would be repetitive, and different components will be explained in detail.
[0094] Figure 8 shows a different configuration for vehicle manufacturer 2, in that it clearly indicates the traceability information management server 24 and the parts supply unit 25.
[0095] The traceability information management server 24 is an information processing device that manages the software version and parameter update history of each electronic control unit.
[0096] The parts supply unit 25 is an information processing device that receives parts orders when there are hardware changes. When the parts supply unit 25 receives a parts order, it ships the relevant parts (replacement parts) to the vehicle sales company 3. An example of a replacement part is the ECU 51. The ECU 51 is a replacement part that replaces the original ECU 41 installed in the vehicle, and is a new ECU.
[0097] Next, we will explain the flow shown in Figure 9, referring to the dotted and solid arrows shown in Figure 8. Figure 9 is a diagram showing an example of the supply installation flow.
[0098] First, the vehicle sales company terminal 31 sends the purchase information D21 for the replacement part (ECU) to the sales server 21 (step S21).
[0099] Next, the sales server 21 sends order information D22 for the replacement part (ECU) to the parts supply unit 25 based on the purchase information D21 for the replacement part (ECU), and places an order (step S22). As a result, the parts supply unit 25 delivers the replacement part (ECU 51) to the vehicle sales company 3.
[0100] Next, vehicle sales company 3 installs the replacement part (ECU51) into vehicle 4 (step S23).
[0101] Next, the second diagnostic device 32 reads the vehicle 4 verification data D23 (VIN information and serial number) from another onboard ECU or similar device and transmits it to the specification storage server 22 (step S24). The VIN information is read from the VIN of vehicle 4, stored in, for example, the VCU 42 (see Figure 2), and the serial number is read from the serial number of the replacement part (ECU 51).
[0102] The specification storage server 22 retrieves the latest written data linked to the VIN information of the vehicle 4 in the traceability information management server 24 from the traceability information management server 24 (step S25).
[0103] When the latest write data obtained from the traceability information management server 24 matches the write data that the specification storage server 22 stores in association with the VIN information of the vehicle 4, the specification storage server 22 changes the serial number associated with the VIN information of the vehicle 4 to the serial number of the replacement part (ECU 51) (step S26).
[0104] Next, the specification storage server 22 sends the latest write data to the second diagnostic device 32 (step S27). The latest write data sent by the specification storage server 22 includes the write data d3 for the first vehicle specification settings, the write data d5 for the second vehicle specification settings, VIN information, and signature data. The write data d3 for the first vehicle specification settings is the write data for the vehicle's factory settings in the ECU 41 before replacement.
[0105] Next, the second diagnostic device 32 writes parameter values to the ECU 51 of the vehicle 4 (step S28). Since the parameters of the replacement part (ECU 51) are at their initial values, parameter values are written to all parameters in the "Model-related items," "Manufacturer-related items," and "Dealer option-related items" to set the first vehicle specifications and the second vehicle specifications.
[0106] This setting ensures that the setting item 210 for the replacement part is set to the exact same value as the setting item 210 of the ECU41 before replacement, which is the exact same value as when the vehicle was shipped.
[0107] The second diagnostic device 32 notifies the specification storage server 22 of the success of the write operation when the write operation is successful (step S29).
[0108] In this example, we explained that in step S26, the specification storage server 22 changes the serial number associated with the VIN information of the vehicle 4 to the serial number of the replacement part (ECU 51). However, it is also possible to change the serial number after the successful writing in step S29. Furthermore, it is not necessary to check for consistency between the written data stored by the specification storage server 22 in association with the VIN information of the vehicle 4 and the latest written data obtained from the traceability information management server 24.
[0109] (License management) Next, we will describe the license management for dealer option products or services performed on the sales server 21. In this embodiment, the electronic control unit enables / disables the dealer option by setting it to enable / disable. Therefore, payment of license usage fees to the relevant companies for the dealer option occurs when the function is enabled. In this embodiment, since the sales server 21 stores order details, we will describe the mechanism for paying license usage fees using that data.
[0110] Figure 10 shows an example of an order table on the sales server 21. The order table 300 contains data corresponding to the specification management table 200 (see Figure 5), and stores the latest settings for each vehicle using VIN information and serial numbers.
[0111] The license management table 310 is a table that aggregates the total license usage fees for each payee who pays the dealer option license usage fees, based on the latest settings (parameter settings) for each vehicle in the order table 300.
[0112] The license management table 310 manages the number of dealer options used (n, m, ...) for each payee (Company B, Company C, ...), and calculates the total payment amount based on the number of uses (n, m, ...) and each company's license fee (ZZZ, ZZ1, ...). The number of uses can be calculated by aggregating the A1 (enabled) parameter set in "Specification Information 2" of the order table 300. By providing such a license management table 310, the sales server 21 can easily calculate the total license fee for each payee based on the number of uses, and make payments to each payee via the settlement system.
[0113] (Management of trial dealer options) The sales server 21 may manage free trials of dealer options by creating a subscription table based on the order table 300.
[0114] For example, the sales server 21 sets the type of dealer option and the trial period in the subscription table, and when the trial period begins, it notifies the specification storage server 22 to enable the corresponding item in "Specification Information 2" in the specification storage table 100. When the corresponding item in the specification storage table 100 is enabled, it becomes possible to switch the parameters of the target vehicle's ECU 41, and the switched settings are written to the parameters of the target vehicle's ECU 41 via wireless communication or a second writing device. When the trial period expires, the sales server 21 notifies the specification storage server 22 to disable the corresponding item in "Specification Information 2" in the specification storage table 100 (see Figure 5), and the settings of the target vehicle's ECU 41 parameters are also returned to the settings before the switch. Note that the trial is not limited to free; it may also be offered at a special price.
[0115] For example, dealer options include upgrading to a higher-end feature or setting the interior illumination to a special color. After the trial period, the settings revert to their original state, but if the customer purchases the vehicle during the trial period, the dealer option setting will remain in effect.
[0116] (Effects of the embodiment) In this embodiment, vehicles are shipped from the production plant with the necessary software for dealer options stored in the electronic control unit. Furthermore, the electronic control unit can enable / disable dealer options even after shipment by setting parameters. Therefore, vehicle dealerships can configure dealer options on vehicles after shipment.
[0117] Furthermore, while electronic control devices often have numerous dealer options, and their combinations can make management complicated, this embodiment eliminates the need to manage each electronic control device with a separate management number based on the vehicle model and dealer option combination. For example, it becomes possible to manage them using just one management number.
[0118] Figure 11 shows an example of the management flow of ECU41 within the vehicle production plant 1. As shown in Figure 11, when an ECU41 is ordered, it is managed with a common management number 1. Both ECU41s with management number 1 store the same combination of software group 40, and since the activation / deactivation of software 1, software 2, etc. can be performed later by rewriting the parameter values, they are both managed with a common management number 1 until shipment.
[0119] Therefore, the need for separate numbering and management based on vehicle model and dealer option combinations is reduced, thus minimizing management complexity. Furthermore, because the ECU41 eliminates the need for separate numbering and management, it also reduces the need to allocate separate spaces for each different management number, thus reducing the space required for ECU41 installation. Specifically, it reduces the increase in internal and external management evaluation man-hours and factory space, and theoretically allows for a single management number. It also reduces hardware costs and hardware reconfiguration man-hours. Moreover, centralized management of vehicle specifications and dealer option purchase information allows for easy analysis of user preferences, which can be used for future sales promotion.
[0120] (A mechanism to guarantee that the settings of the electronic control unit have been restored to the exact same settings as when the vehicle was shipped.) When replacing vehicle 4's ECU41 with a replacement ECU51, the vehicle specifications of ECU51 are restored to the exact same state as the vehicle specifications of the original ECU41. At this time, the settings of the non-changeable setting item 210 (see Figure 3) are restored to the exact same state as when the vehicle was shipped. The following is an explanation of the mechanism to ensure that the settings of the non-changeable setting item 210 are restored to the exact same state as when the vehicle was shipped.
[0121] The following primarily explains the mechanism and process when writing to the non-changeable setting item 210 using the first vehicle specification setting write data d3 (see Figure 4). The other changeable setting item 220 is the same as explained above, so a detailed explanation is omitted here.
[0122] Figure 12 shows an example of the hardware block configuration of the vehicle management system 1. Figure 12(a) shows an example of the hardware block configuration of the first diagnostic device 12. As shown in Figure 12(a), the first diagnostic device 12 has a CPU 12-1, a memory 12-2, and a communication controller 12-3. The CPU 12-1, memory 12-2, and communication controller 12-3 are connected to a bus 12-4. The memory 12-2 is a ROM (Read Only Memory) or RAM (Random Access Memory), etc.
[0123] CPU12-1 is a central processing unit that executes a program P1 stored in ROM, for example. In addition to program P1, the ROM also stores a common key M1 for using digital signatures.
[0124] The second diagnostic device 32 has the same configuration as the first diagnostic device 12 shown in Figure 12(a). The second diagnostic device 32 differs from the first diagnostic device 12 in its processing; the ROM of the second diagnostic device 32 stores program P2, and it does not have a common key M1.
[0125] Figure 12(b) shows an example of the hardware block configuration of ECU41. As shown in Figure 12(b), ECU41 has a CPU 41-1, memory 41-2, and communication controller 41-3. The CPU 41-1, memory 41-2, and communication controller 41-3 are connected to bus 41-4. Memory 41-2 is ROM or RAM, etc.
[0126] CPU41-1 is a central processing unit that executes a program P3 stored in ROM, for example. In addition to program P3, the ROM also stores a common key M1 for using digital signatures.
[0127] The ECU51, which replaces the ECU41, has the same configuration as the ECU41 shown in Figure 12(b), and the ROM of the ECU51 stores program P3 and the common key M1.
[0128] Figure 12(c) shows an example of the hardware block configuration of the specification storage server 22. As shown in Figure 12(c), the specification storage server 22 has a CPU 22-1, memory 22-2, and a communication controller 22-3. The CPU 22-1, memory 22-2, and communication controller 22-3 are connected to a bus 22-4. The memory 22-2 is ROM or RAM, etc.
[0129] CPU22-1 is a central processing unit that executes a program P4 stored in ROM, for example. In addition to program P4, the ROM also stores a specification storage table 100.
[0130] The sales server 21 has the same configuration as the specification storage server 22 shown in Figure 12(c). Since the processing of the sales server 21 is different from that of the specification storage server 22, program P5 and the order table 300 are stored in the ROM of the sales server 21.
[0131] Figure 13 shows an example of the specification storage table 100. The specification storage table 100-1 shown in Figure 13 is an example table configuration in which "signature data" is associated with the specification storage table 100 shown in Figure 5.
[0132] As shown in Figure 13, in the specification storage table 100-1, the data column of "Specification Information 1" and the "ZZZZ" d6 of "Signature Data" are linked and stored. "ZZZZ" d6 is signature data generated by the first diagnostic device 12.
[0133] Figure 14 is an explanatory diagram showing an example of the process for generating an electronic signature in the vehicle production plant 1. Referring to the functional block shown as an example in Figure 14, the electronic signature process between the first diagnostic device 12 and the ECU 41 before vehicle shipment will be explained in detail.
[0134] As shown in Figure 14, the first diagnostic device 12 has a processing unit 1200. The processing unit 1200 is a function performed by the CPU 12-1 of the first diagnostic device 12 executing the program P1 in the ROM.
[0135] Furthermore, the ECU41 has a processing unit 4100. The processing unit 4100 is a function that is performed when the CPU 41-1 of the ECU41 executes the ROM program P3.
[0136] First, the processing unit 1200 of the first diagnostic device 12 receives the VIN and parameter values (step S31).
[0137] Next, the processing unit 1200 calculates a hash value of the document data, which is a set of the acquired VIN and the unchangeable parameter values (step S32).
[0138] Next, the processing unit 1200 encrypts the hash value calculated in step S32 with the common key M1 stored in the ROM of the first diagnostic device 12 (step S33).
[0139] Furthermore, the hash function and encryption algorithm used will be those listed in, for example, the e-Government Recommended Cryptographic List (CRYPTREC Cryptographic List).
[0140] Next, the processing unit 1200 transmits the document data for which the hash value was calculated in step S32 and the signature data generated by encryption in step S33 to the ECU 41 (step S34).
[0141] In response, the processing unit 4100 of the ECU 41 receives the document data and signature data transmitted from the first diagnostic device 12 (step S41).
[0142] Next, the processing unit 4100 calculates a hash value for the document data among the received document data and signature data (step S42).
[0143] Furthermore, the processing unit 4100 decrypts the signature data from the received document data and signature data using the common key M1 stored in the ROM of the ECU 41, and obtains a hash value from the signature data (step S43).
[0144] Next, the processing unit 4100 determines whether the hash value obtained by calculation in step S42 matches the hash value obtained by decryption in step S43 (step S44).
[0145] If the processing unit 4100 determines in step S44 that there is a match, it takes the VIN and the unchangeable parameter value and sets them (step S45).
[0146] Up to this point, we have explained how to set parameter values that cannot be changed. However, for parameter values that can be changed, if signature data is not used, the processing unit 4100 of the ECU 41 receives the changeable parameter values sent from the processing unit 1200 of the first diagnostic device 12 and sets them by performing checksums and other methods as previously described.
[0147] Furthermore, when using signature data for modifiable parameter values, the same method used for immutable parameter values may be applied to generate and implement signature data for modifiable parameter values as well. Alternatively, common signature data may be generated and implemented using both immutable and modifiable parameter values.
[0148] If a mismatch is determined in step S44, the system will not perform any settings and will notify the processing unit 1200 of the first diagnostic device 12 of the error.
[0149] After being set correctly, the processing unit 1200 of the first diagnostic device 12 communicates with the processing unit 4100 of the ECU 41 of the vehicle 4 during the inspection process immediately before vehicle shipment, and reads the VIN, serial number, parameter settings, and signature data generated in step S33 from the ECU 41 (step S51).
[0150] Then, the processing unit 1200 of the first diagnostic device 12 uploads the VIN, serial number, and parameter settings read from the ECU 41, along with the signature data generated in step S33, to the specification storage server 22 (step S52).
[0151] As a result, the shipment data of vehicle 4 is associated and stored in the "VIN information," "serial number," "specification information 1," "signature data," and "specification information 2" fields of specification storage table 100-1.
[0152] Figure 15 shows an example of the structure of the write data used to set the parameters of the replaced ECU51. The write data d3 for setting the first vehicle specifications shown in Figure 15 has a data structure in which signature data is associated with the write data d3 for setting the first vehicle specifications shown in Figure 4. In the example shown in Figure 15, the signature data "ZZZZ" 130 is set after the data sequence 110.
[0153] The write data d5 for the second vehicle specification setting shown in Figure 15 has the same data structure as the write data d5 for the second vehicle specification setting shown in Figure 4.
[0154] Here, as an example, the data to be written is divided into two parts, but it is also possible to use a single data structure that includes everything.
[0155] Figure 16 is an explanatory diagram showing an example of a process using electronic signatures on the vehicle sales company 3 side. Referring to the functional block shown as an example in Figure 16, the electronic signature process between the second diagnostic device 32 and the replaced ECU 51 will be explained in detail.
[0156] As shown in Figure 16, the second diagnostic device 32 has a processing unit 3200. The processing unit 3200 is a function performed by the CPU 12-1 of the second diagnostic device 32 executing the program P2 in the ROM.
[0157] Furthermore, the ECU 51 has a processing unit 5100. The processing unit 5100 is a function that is performed when the CPU 41-1 of the ECU 51 executes the ROM program P3.
[0158] First, the processing unit 3200 of the second diagnostic device 32 reads the VIN from the ECU 51 of the vehicle 4. If the VIN of the ECU 51 is an initial value, it reads the VIN from, for example, the ECU 42 of the vehicle 4 and sends it to the specification storage server 22 (step S61). The serial number of the ECU 51 may be included at this time.
[0159] Next, the processing unit 3200 of the second diagnostic device 32 receives the parameter settings and signature data transmitted from the specification storage server 22 based on the VIN, and obtains the VIN, parameters, and signature data (step S62).
[0160] Next, the processing unit 3200 sends document data and signature data, which consist of the VIN and unchangeable parameter values, to the processing unit 5100 of the ECU 51 (step S63).
[0161] First, when a read request is received from the processing unit 3200 of the second diagnostic device 32, the processing unit 5100 of ECU 51 transmits the VIN to the processing unit 3200 of the second diagnostic device 32 (step S71). When ECU 41 is replaced with ECU 51 in vehicle 4, the initial value of the VIN information is transmitted to the processing unit 3200 of the second diagnostic device 32, so the processing unit 3200 of the second diagnostic device 32 reads the VIN information from another ECU in vehicle 4, such as ECU 42. The serial number of ECU 51 is transmitted by the processing unit 5100 of ECU 51 to the processing unit 3200 of the second diagnostic device 32 in step S71 or in a subsequent inspection process.
[0162] Next, the processing unit 5100 receives the document data and signature data transmitted from the processing unit 3200 of the second diagnostic device 32 (step S72).
[0163] Next, the processing unit 5100 calculates the hash value of the document data from the received document data and signature data (step S73).
[0164] Furthermore, the processing unit 5100 decrypts the signature data from the received document data and signature data using the common key M1 stored in the ROM of the ECU 51, and obtains a hash value from the signature data (step S74).
[0165] Next, the processing unit 5100 determines whether the hash value obtained by calculation in step S73 matches the hash value obtained by decryption in step S74 (step S75).
[0166] If the processing unit 5100 determines that there is a match in step S75, it takes the VIN and the unchangeable parameter value and sets them (step S76).
[0167] For modifiable parameter values, if signature data is not used, the processing unit 5100 of the ECU 51 receives the modifiable parameter values transmitted from the processing unit 3200 of the second diagnostic device 32, and incorporates and sets them using the methods described above, such as performing checksums on them.
[0168] Furthermore, when using signature data for modifiable parameter values, the same method used for immutable parameter values may be applied to generate and implement signature data for modifiable parameter values as well. Alternatively, common signature data may be generated and implemented using both immutable and modifiable parameter values.
[0169] If a mismatch is determined in step S75, the system will not perform any settings and will notify the processing unit 3200 of the second diagnostic device 32 of the error.
[0170] Once the setup is complete, the process is the same as described above. Further explanation would be repetition, so it will be omitted.
[0171] As described above, the system prevents dealerships and others from changing immutable parameters from the settings at the time of vehicle shipment. Therefore, the replaced ECU51 will have the same settings as the ECU41 at the time of vehicle shipment. Furthermore, the use of electronic signatures can guarantee that the parameters of the replaced ECU51 have been written with values that are exactly the same as those of the ECU41 at the time of vehicle shipment.
[0172] It should be noted that the present invention is not limited to the embodiments described above, and various modifications other than those described above are possible without departing from the spirit of the invention. [Explanation of symbols]
[0173] 1. Vehicle production plant 2. Vehicle manufacturers 3. Vehicle sales companies 4 vehicles 10 Vehicle production lines 11 Factory Server 12. First diagnostic device 21 Business Server 22. Specification storage server 23 Production Instruction Generation Unit 31. Vehicle sales company terminal 32 Second diagnostic device 40 Software Groups 41 ECU (Electronic Control Unit) 51 ECU (Supplies) 100 Specification Storage Table 200 parameter list N1 Communication Network N2 Communication Network
Claims
1. An electronic control unit equipped with software for multiple vehicle specifications, which allows setting vehicle specifications using parameters, A first setting device that sets the parameters in the electronic control unit before the vehicle is shipped, A second setting device for setting the parameters in the electronic control unit of a vehicle after shipment, It has, The first setting device generates signature data in setting the parameters and transmits the setting information and the signature data to the electronic control unit. The second setting device sets the parameters for the electronic control unit of the vehicle after shipment, based on the setting information and signature data transmitted by the first setting device to the electronic control unit. Vehicle management system.
2. The second setting device sets the parameters of a new electronic control unit that has been replaced from the electronic control unit set by the first setting device, based on the setting information and signature data transmitted to the electronic control unit set by the first setting device. The vehicle management system according to claim 1.
3. The system includes a management server that manages vehicle identification information and the setting information and signature data transmitted to the vehicle's electronic control unit by the first setting device in association with each other. The second setting device obtains the setting information and signature data from the management server based on the vehicle identification information read from the vehicle, transmits them to the new electronic control unit, and sets the parameters of the new electronic control unit. The vehicle management system according to claim 2.
4. The setting of the parameters by the second setting device allows for the modification of parameters for which the modification conditions are met, while parameters for which the modification conditions are not met remain the same as the settings set by the first setting device at the time of vehicle shipment. A vehicle management system according to any one of claims 1 to 3.
Citation Information
Patent Citations
Sales support device and sales support method of automobile
JP2007011466A