Main device for vehicle, execution control method for rollback, and recording medium

Through the vehicle main device and the rollback control method, after the cancellation of the request, the memory type and update data type of the nonvolatile memory are used to ensure that the ECU state is rolled back to the state before rewriting, solving the abnormal operation problem caused by the ECU program rewriting interruption, and achieving the normal completion of the rewriting process.

CN112585575BActive Publication Date: 2025-07-11DENSO CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN201980052885.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-07-12
Filing Date
2019-08-07
Publication Date
2025-07-11
Estimated Expiration
2039-08-07

AI Technical Summary

Technical Problem

In the process of rewriting the vehicle ECU program, if a cancellation request occurs, the prior art will find it difficult to ensure the normal completion of the rewriting process, especially in the case of interruption of program rewriting, which may cause abnormal ECU operation.

Method used

Through the vehicle main device and the rollback control method, after determining the cancellation request, the rollback method is determined, and the memory type and update data type of the nonvolatile memory are used to instruct the rewrite object ECU to operate with the old program to ensure that the state is rolled back to the state before rewriting, and to complete the rewriting process.

Benefits of technology

Even when the request is cancelled, the rewriting of the ECU program can be done normally, ensuring the normal operation of the ECU and avoiding abnormal operation in the state of incomplete rewriting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112585575B_ABST
    Figure CN112585575B_ABST
Patent Text Reader

Abstract

The main device (11) for a vehicle includes: a cancellation request determination unit (86a) that determines whether a cancellation request has occurred in the program rewrite from an old program to a new program by distributing update data to an electronic control device to be rewritten through an update data distribution unit; a rollback method determination unit (86b) that, when it is determined that a cancellation request has occurred, determines a rollback method for returning the state of the electronic control device to be rewritten to the state before starting to write the update data based on the memory type of the non-volatile memory mounted on the electronic control device to be rewritten and the data type of the update data of the new program or the old program; and a rollback execution unit (86c) that instructs the electronic control device to be rewritten to perform a rollback corresponding to the rollback method, causing the electronic control device to be rewritten to operate with the old program.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - reference to related applications

[0002] This application is based on Japanese Application No. 2018 - 151418 filed on August 10, 2018 and Japanese Application No. 2019 - 129958 filed on July 12, 2019, and the contents thereof are incorporated herein by reference. Technical field

[0003] The present disclosure relates to a main device for a vehicle, a method for controlling execution of rollback, a program for controlling execution of rollback, and a data structure of specification data. Background art

[0004] In recent years, along with the diversification of vehicle control such as driving assistance functions and autonomous driving functions, the scale of programs for vehicle control, diagnosis, etc. of electronic control units (hereinafter referred to as ECUs (Electronic Control Unit)) mounted on vehicles has been increasing. In addition, along with version upgrades based on function improvements, etc., the opportunity to rewrite (re - program) the programs of ECUs has also been increasing. On the other hand, along with the development of communication networks, etc., the technology of connected cars has become increasingly popular. In light of such circumstances, for example, Patent Document 1 proposes the following technology: A main device for a vehicle as a relay device is provided on the vehicle side, and the main device for a vehicle distributes update data received wirelessly from a central device to an ECU to be rewritten, thereby rewriting the program of the ECU to be rewritten by OTA (Over The Air).

[0005] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2017 - 157004

[0006] In Patent Document 1, it is described that, for example, when the rewriting of the program is interrupted in any one of the ECUs due to a power failure or the like, the programs of all the ECUs are rewritten again. Here, for example, when the user performs a cancellation operation and the rewriting from the old - version program to the new - version program is interrupted, it may be necessary to operate the old - version program. At this time, if the rewritten area of the ECU is left in an incomplete state, it is possible that the subsequent operation of the ECU cannot be performed normally. Summary of the invention

[0007] The present disclosure has been made in view of the above circumstances, and an object thereof is to provide a main device for a vehicle, a method for controlling execution of rollback, a program for controlling execution of rollback, and a data structure of specification data that can normally complete the subsequent program rewriting even when a cancellation request occurs during the program rewriting.

[0008] According to an aspect of the present disclosure, an update data acquisition unit acquires update data from the outside. An update data distribution unit distributes the update data acquired by the update data acquisition unit to an electronic control device to be rewritten, which is equipped with a non-volatile memory having a program storage surface on one or more surfaces. A cancellation request determination unit determines whether a cancellation request occurs in the program rewrite from an old program to a new program when the update data is distributed to the electronic control device to be rewritten by the update data distribution unit. If the cancellation request determination unit determines that a cancellation request has occurred, a rollback method determination unit determines a rollback method for returning the state of the electronic control device to be rewritten to the state before starting to write the update data, based on the memory type of the non-volatile memory mounted on the electronic control device to be rewritten and the data type of the update data of the new program or the old program. A rollback execution unit instructs the electronic control device to be rewritten to perform a rollback corresponding to the rollback method determined by the rollback method determination unit, causing the electronic control device to be rewritten to operate with the old program.

[0009] If a cancellation request occurs, a rollback method for returning the state of the electronic control device to be rewritten to the state before starting to write the update data is determined, and the electronic control device to be rewritten is caused to operate with the old program. Even when a cancellation request occurs, the subsequent program rewrite can be normally completed.

[0010] According to an aspect of the present disclosure, an update data acquisition unit acquires update data from the outside. An update data distribution unit distributes the update data acquired by the update data acquisition unit to an electronic control device to be rewritten, which is equipped with a non-volatile memory having a program storage surface on one or more surfaces. A cancellation request determination unit determines whether a cancellation request occurs in the program rewrite from an old program to a new program when the update data is distributed to the electronic control device to be rewritten by the update data distribution unit. If the cancellation request determination unit determines that a cancellation request has occurred, the rollback execution unit continues to distribute the update data of the new program until the rewrite is completed when the program storage surface is one surface, instructs the electronic control device to be rewritten to write the update data of the old program, and causes the electronic control device to be rewritten to operate with the old program. When the program storage surface is two or more surfaces including an operating surface and a non-operating surface that is the surface for writing the new program, the rollback execution unit continues to distribute the update data of the new program until the rewrite is completed, and causes the electronic control device to be rewritten to operate with the program stored on the operating surface.

[0011] If a cancellation request is generated, when the program storage surface is a single surface, the distribution of the update data of the new program is continued until the rewrite is completed, and the electronic control device to be rewritten is instructed to write the update data of the old program, so that the electronic control device to be rewritten operates with the old program. If a cancellation request is generated, when the program storage surface is two or more surfaces, the distribution of the update data of the new program is continued until the rewrite is completed, and the electronic control device to be rewritten operates with the program stored in the operation surface. Even if a cancellation request is generated, the subsequent program rewrite can be normally completed. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] With reference to the accompanying drawings and the following detailed description, the above objects and other objects, features, and advantages of the present disclosure become more apparent. Among them, the drawings are as follows:

[0013] Figure 1 It is a diagram showing the overall configuration of one embodiment.

[0014] Figure 2 It is a diagram showing the electrical structure of the CGW.

[0015] Figure 3 It is a diagram showing the electrical structure of the DCM.

[0016] Figure 4 It is a diagram showing the electrical structure of the ECU.

[0017] Figure 5 It is a diagram showing the connection method of the power line.

[0018] Figure 6 It is a diagram showing the method of packing the recompiled data and the distribution specification data.

[0019] Figure 7 It is a diagram showing the rewrite specification data for the DCM.

[0020] Figure 8 It is a diagram showing the rewrite specification data for the CGW.

[0021] Fig. 9 It is a diagram showing the distribution specification data.

[0022] Fig.10 It is a diagram showing the method of unpacking the distribution data packet.

[0023] Fig.11 It is a diagram showing the method during normal operation in the embedded single-sided independent memory.

[0024] Fig.12 It is a diagram showing the method during the rewrite operation in the embedded single-sided independent memory.

[0025] Fig.13 This is a diagram showing the normal operation mode of a download-type single-sided stand-alone memory.

[0026] Fig.14 This is a diagram showing the rewrite operation mode of a download-type single-sided stand-alone memory.

[0027] Fig.15 This is a diagram showing the normal operation mode of an embedded single-sided suspended memory.

[0028] Fig.16 This is a diagram showing the rewrite operation mode of an embedded single-sided suspended memory.

[0029] Fig.17 This is a diagram showing the normal operation mode of a download-type single-sided suspended memory.

[0030] Fig.18 This is a diagram showing the rewrite operation mode of a download-type single-sided suspended memory.

[0031] Fig.19 This is a diagram showing the normal operation mode of an embedded double-sided memory.

[0032] Fig. 20 This is a diagram showing the rewrite operation mode of an embedded double-sided memory.

[0033] Fig.21 This is a diagram showing the normal operation mode of a download-type double-sided memory.

[0034] Fig. 22 This is a diagram showing the rewrite operation mode of a download-type double-sided memory.

[0035] Fig.23 This is a diagram showing the method of rewriting an application program.

[0036] Fig.24 This is a diagram showing the method of rewriting an application program.

[0037] Fig.25 This is a diagram showing the method of rewriting an application program.

[0038] Fig.26 This is a timing diagram showing the method of rewriting an application program through power control.

[0039] Fig. 27 This is a timing diagram showing the method of rewriting an application program through power control.

[0040] Fig.28 This is a timing diagram showing the method of rewriting an application program through power self-holding.

[0041] Fig.29It is a timing diagram showing the method of rewriting the application program by power self-holding.

[0042] Fig.30 It is a diagram showing the stage.

[0043] Fig.31 It is a diagram showing the normal screen.

[0044] Fig.32 It is a diagram showing the screen when the activity notification is generated.

[0045] Fig.33 It is a diagram showing the screen during the activity notification.

[0046] Fig.34 It is a diagram showing the screen when the download consent is given.

[0047] Fig.35 It is a diagram showing the screen when the download consent is given.

[0048] Fig.36 It is a diagram showing the screen during the download execution.

[0049] Fig.37 It is a diagram showing the screen during the download execution.

[0050] Fig.38 It is a diagram showing the screen when the download is completed.

[0051] Fig.39 It is a diagram showing the screen when the installation consent is given.

[0052] Fig.40 It is a diagram showing the screen when the installation consent is given.

[0053] Fig.41 It is a diagram showing the screen during the installation execution.

[0054] Fig.42 It is a diagram showing the screen during the installation execution.

[0055] Fig.43 It is a diagram showing the screen when the activation consent is given.

[0056] Fig.44 It is a diagram showing the screen when the IG is turned on.

[0057] Fig.45 It is a diagram showing the screen during the confirmation operation.

[0058] Fig.46 It is a diagram showing the screen during the confirmation operation.

[0059] Fig.47 It is a functional block diagram of the central device.

[0060] Fig.48 It is the functional block diagram of the DCM.

[0061] Fig.49 It is the functional block diagram of the CGW.

[0062] Fig.50 It is the functional block diagram of the CGW.

[0063] Fig.51 It is the functional block diagram of the ECU.

[0064] Fig.52 It is the functional block diagram of the in-vehicle display.

[0065] Fig.53 It is the functional block diagram of the transmission determination unit for distributing data packets.

[0066] Fig.54 It is the flowchart showing the transmission determination process for distributing data packets.

[0067] Fig.55 It is the functional block diagram of the download determination unit for distributing data packets.

[0068] Fig.56 It is the flowchart showing the download determination process for distributing data packets.

[0069] Fig.57 It is the functional block diagram of the transmission determination unit for writing data.

[0070] Fig.58 It is the flowchart showing the transmission determination process for writing data.

[0071] Fig.59 It is the functional block diagram of the acquisition determination unit for writing data.

[0072] Fig.60 It is the flowchart showing the acquisition determination process for writing data.

[0073] Fig.61 It is the functional block diagram of the instruction determination unit for installation.

[0074] Fig.62 It is the flowchart showing the instruction determination process for installation.

[0075] Fig.63 It is the diagram showing the method of instructing installation.

[0076] Fig.64 It is the diagram showing the method of instructing installation.

[0077] Fig.65 It is the diagram showing the method of generating a random value.

[0078] Fig.66It is a functional block diagram of the management unit for the secure access key.

[0079] Fig.67 It is a flowchart showing the generation process of the secure access key.

[0080] Fig.68 It is a diagram showing the method of generating the secure access key.

[0081] Fig.69 It is a flowchart showing the elimination process of the secure access key.

[0082] Fig.70 It is a diagram showing the process flow related to the verification of the written data.

[0083] Fig.71 It is a functional block diagram of the verification unit for the written data.

[0084] Fig.72 It is a flowchart showing the verification process of the written data.

[0085] Fig.73 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0086] Fig.74 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0087] Fig.75 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0088] Fig.76 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0089] Fig.77 It is a diagram showing the process flow of the verification of the written data and the rewriting of the application program.

[0090] Fig.78 It is a diagram showing the process flow of the verification of the written data and the rewriting of the application program.

[0091] Fig.79 It is a functional block diagram of the transmission control unit for the data storage surface information.

[0092] Fig.80 It is a flowchart showing the transmission control process of the data storage surface information.

[0093] Fig.81 It is a sequence diagram showing the method of notifying the double-sided rewriting information.

[0094] Fig.82 It is a functional block diagram of the power management unit for the non-rewriting object.

[0095] Fig.83 It is a flowchart showing the power management process that is not the object to be rewritten.

[0096] Fig.84 It is a diagram showing the transition of the start state, stop state, and sleep state.

[0097] Fig.85 It is a diagram showing the transition of the start state, stop state, and sleep state.

[0098] Fig.86 It is a diagram showing the connection method of the power cord.

[0099] Fig.87 It is a flowchart showing the monitoring process of the battery remaining amount.

[0100] Fig.88 It is a functional block diagram of the file transfer control unit.

[0101] Fig.89 It is a flowchart showing the file transfer control process.

[0102] Fig.90 It is a diagram showing the method of receiving and sending files.

[0103] Fig.91 It is a diagram showing the method of receiving and sending files.

[0104] Fig.92 It is a diagram showing the splitting and writing of files.

[0105] Fig.93 It is a diagram showing the method by which the CGW sends a transfer request to the DCM.

[0106] Fig.94 It is a diagram showing the method by which the CGW sends a transfer request to the DCM.

[0107] Fig.95 It is a diagram showing the method by which the CGW distributes the write data to the ECU to be rewritten.

[0108] Fig.96 It is a diagram showing the method by which the CGW distributes the write data to the ECU to be rewritten.

[0109] Fig.97 It is a diagram showing the method by which the CGW distributes the write data to the ECU to be rewritten.

[0110] Fig.98 It is a diagram showing the connection method of the ECU.

[0111] Fig.99 It is a functional block diagram of the distribution control unit for write data.

[0112] Fig.100 It is a diagram showing a bus load table.

[0113] Fig.101 It is a diagram showing the table to which the ECU to be rewritten belongs.

[0114] Fig.102 It is a flowchart showing the distribution control process of the written data.

[0115] Fig.103 It is a diagram showing the method of distributing the written data.

[0116] Fig.104 It is a diagram showing the method of distributing the written data.

[0117] Fig.105 It is a diagram showing the method of distributing the written data during vehicle driving.

[0118] Fig.106 It is a diagram showing the method of distributing the written data during parking.

[0119] Fig.107 It is a diagram showing the distribution amount of the written data.

[0120] Fig.108 It is a diagram showing the distribution amount of the written data.

[0121] Fig.109 It is a functional block diagram of the instruction unit for activation request.

[0122] Fig.110 It is a flowchart showing the instruction process of activation request.

[0123] Fig.111 It is a diagram showing the method of instructing activation request.

[0124] Fig.112 It is a functional block diagram of the execution control unit for activation.

[0125] Fig.113 It is a flowchart showing the rewriting process.

[0126] Fig.114 It is a flowchart showing the execution control process of activation.

[0127] Fig.115 It is a functional block diagram of the grouping unit for the object to be rewritten.

[0128] Fig.116 It is a flowchart showing the group management process of the object to be rewritten.

[0129] Fig.117 It is a flowchart showing the group management process of the object to be rewritten.

[0130] Fig.118It is a diagram showing the way of grouping objects to be rewritten.

[0131] Fig.119 It is a functional block diagram of the execution control section for rollback.

[0132] Fig.120 It is a flowchart showing the determination process of the rollback method.

[0133] Fig.121 It is a flowchart showing the determination process of the cancellation request.

[0134] Fig.122 It is a flowchart showing the determination process of the cancellation request.

[0135] Fig.123 It is a flowchart showing the determination process of the cancellation request.

[0136] Fig.124 It is a flowchart showing the determination process of the cancellation request.

[0137] Fig.125 It is a flowchart showing the determination process of the cancellation request.

[0138] Fig.126 It is a diagram showing the way of performing rollback.

[0139] Fig.127 It is a diagram showing the way of performing rollback.

[0140] Fig.128 It is a diagram showing the way of performing rollback.

[0141] Fig.129 It is a diagram showing the way of performing rollback.

[0142] Fig.130 It is a diagram showing the way of performing rollback.

[0143] Fig.131 It is a functional block diagram of the display control section for the progress of rewriting.

[0144] Fig.132 It is a flowchart showing the display control process for the progress of rewriting.

[0145] Fig.133 It is a flowchart showing the display control process for the progress of rewriting.

[0146] Fig.134 It is a diagram showing the screen of the progress of rewriting.

[0147] Fig.135 It is a diagram showing the screen of the progress of rewriting.

[0148] Fig.136It is a diagram of a screen indicating the progress of rewriting.

[0149] Fig.137 It is a diagram of a screen indicating the progress of rewriting.

[0150] Fig.138 It is a diagram of a screen indicating the progress of rewriting.

[0151] Fig.139 It is a diagram showing the transition of the progress diagram display.

[0152] Fig.140 It is a diagram showing the transition of the progress diagram display.

[0153] Fig.141 It is a diagram showing the transition of the progress diagram display.

[0154] Fig.142 It is a diagram showing the transition of the progress diagram display.

[0155] Fig.143 It is a diagram of a screen indicating the progress of rewriting.

[0156] Fig.144 It is a functional block diagram of the differential data matching determination unit.

[0157] Fig.145 It is a flowchart showing the differential data matching determination process.

[0158] Fig.146 It is a diagram showing the method of determining the matching of differential data.

[0159] Fig.147 It is a diagram showing the method of determining the matching of differential data.

[0160] Fig.148 It is a functional block diagram of the rewrite execution control unit.

[0161] Fig.149 It is a flowchart showing the normal operation process.

[0162] Fig.150 It is a flowchart showing the rewrite operation process.

[0163] Fig.151 It is a flowchart showing the information notification process.

[0164] Fig.152 It is a flowchart showing the verification process of the rewrite program.

[0165] Fig.153 It is a diagram showing the method of sending identification information and writing data.

[0166] Fig.154It is a diagram showing the method of sending identification information and writing data.

[0167] Fig.155 It is a flowchart showing the installation instruction process.

[0168] Fig.156 It is a functional block diagram of the session establishment section.

[0169] Fig.157 It is a diagram showing the program structure.

[0170] Fig.158 It is a diagram showing the state transition.

[0171] Fig.159 It is a diagram showing the state transition.

[0172] Fig.160 It is a diagram showing the state transition.

[0173] Fig.161 It is a diagram showing the session mediation.

[0174] Fig.162 It is a diagram showing the session mediation.

[0175] Fig.163 It is a flowchart showing the state transition management process of the first state.

[0176] Fig.164 It is a flowchart showing the state transition management process of the first state.

[0177] Fig.165 It is a flowchart showing the state transition management process of the first state.

[0178] Fig.166 It is a flowchart showing the state transition management process of the second state.

[0179] Fig.167 It is a flowchart showing the state transition management process of the second state.

[0180] Fig.168 It is a diagram showing the program structure.

[0181] Fig.169 It is a diagram showing the state transition.

[0182] Fig.170 It is a functional block diagram of the retry point determination section.

[0183] Fig.171 It is a diagram showing the flash memory structure.

[0184] Fig.172 It is a flowchart showing the process of setting the processing flag.

[0185] Fig.173 It is a flowchart of a determination process indicating a processing flag.

[0186] Fig.174 It is a flowchart of a determination process indicating a processing flag.

[0187] Fig.175 It is a functional block diagram of a synchronization control unit for progress status.

[0188] Fig.176 It is a functional block diagram of a synchronization control unit for progress status.

[0189] Fig.177 It is a diagram showing the method of transmitting and receiving progress status signals.

[0190] Fig.178 It is a flowchart of a synchronization control process for progress status.

[0191] Fig.179 It is a flowchart of a synchronization control process for progress status.

[0192] Fig.180 It is a flowchart of a display process for progress status.

[0193] Fig.181 It is a functional block diagram of a transmission control unit for display control information.

[0194] Fig.182 It is a flowchart of a transmission control process for display control information.

[0195] Fig.183 It is a functional block diagram of a reception control unit for display control information.

[0196] Fig.184 It is a flowchart of a reception control process for display control information.

[0197] Fig.185 It is a diagram showing the information included in the distribution specification data.

[0198] Fig.186 It is a functional block diagram of a screen display control unit for progress display.

[0199] Fig.187 It is a diagram showing the rewritten specification data.

[0200] Fig.188 It is a diagram showing the screen at the time of menu selection.

[0201] Fig.189 It is a diagram showing the screen at the time of user selection.

[0202] Fig.190 It is a diagram showing the screen at the time of user registration.

[0203] Fig.191 It is a flowchart of the screen display control process for progress display.

[0204] Fig.192 It is a flowchart of the screen display control process for progress display.

[0205] Fig.193 It is a diagram showing a message frame.

[0206] Fig.194 It is a diagram showing the screen at the time of activation consent.

[0207] Fig.195 It is a diagram showing the setting of the display presence or absence of items.

[0208] Fig.196 It is a diagram showing the setting of the display presence or absence of items.

[0209] Fig.197 It is a diagram showing the screen at the time of activation consent.

[0210] Fig.198 It is a diagram showing the data communication method.

[0211] Fig.199 It is a diagram showing the message frame at the time of activity notification.

[0212] Fig.200 It is a diagram showing the message frame at the time of download consent.

[0213] Fig.201 It is a diagram showing the message frame at the time of installation consent.

[0214] Fig.202 It is a diagram showing the message frame at the time of activation consent.

[0215] Fig.203 It is a diagram showing the screen transition.

[0216] Fig.204 It is a diagram showing the screen at the time of activity notification generation.

[0217] Fig.205 It is a diagram showing the screen at the time of download consent.

[0218] Fig.206 It is a diagram showing the screen at the time of download consent.

[0219] Fig.207 It is a diagram showing the screen during download execution.

[0220] Fig.208 It is a diagram showing the screen at the time of download completion.

[0221] Fig.209 It is a diagram showing the screen when installation consent is given.

[0222] Fig.210 It is a diagram showing the screen when activation consent is given.

[0223] Fig.211 It is a functional block diagram of the report control section for program update.

[0224] Fig.212 It is a flowchart showing the report control process for program update.

[0225] Fig.213 It is a diagram showing the reporting method of the indicator.

[0226] Fig.214 It is a diagram showing the migration of the reporting method in the case where the rewrite target is a double-sided memory.

[0227] Fig.215 It is a diagram showing the migration of the reporting method in the case where the rewrite target is a single-sided suspended memory.

[0228] Fig.216 It is a diagram showing the migration of the reporting method in the case where the rewrite target is a single-sided separate memory.

[0229] Fig.217 It is a diagram showing the connection method.

[0230] Fig.218 It is a functional module of the execution control section for power self-holding in CGW.

[0231] Fig.219 It is a functional module of the execution control section for power self-holding in ECU.

[0232] Fig.220 It is a flowchart showing the execution control process for power self-holding in CGW.

[0233] Fig.221 It is a flowchart showing the execution control process for power self-holding in ECU.

[0234] Fig.222 It is a diagram showing the period requiring power self-holding.

[0235] Fig.223 It is an overall sequence diagram showing the method of rewriting the application program.

[0236] Fig.224 It is an overall sequence diagram showing the method of rewriting the application program.

[0237] Fig.225 It is an overall sequence diagram showing the method of rewriting the application program.

[0238] Fig.226 It is an overall sequence diagram showing the way to rewrite the application program.

[0239] Fig.227 It is an overall sequence diagram showing the way to rewrite the application program.

[0240] Fig.228 It is an overall sequence diagram showing the way to rewrite the application program.

[0241] Fig.229 It is an overall sequence diagram showing the way to rewrite the application program.

[0242] Fig.230 It is an overall sequence diagram showing the way to rewrite the application program.

[0243] Fig.231 It is an overall sequence diagram showing the way to rewrite the application program.

[0244] Fig.232 It is an overall sequence diagram showing the way to rewrite the application program.

[0245] Fig.233 It is an overall sequence diagram showing the way to rewrite the application program.

[0246] Fig.234 It is a diagram showing the overall configuration of the vehicle information communication system in the first embodiment.

[0247] Fig.235 It is a diagram showing the electrical structure of the CGW.

[0248] Fig.236 It is a diagram showing the electrical structure of the ECU.

[0249] Fig.237 It is a diagram showing the connection method of the power line.

[0250] Fig.238 It is a diagram showing the way to package the recompiled data and the distribution specification data.

[0251] Fig.239 It is a diagram showing the way to unpack the distribution data packet.

[0252] Fig.240 It is a diagram showing, in the form of a block diagram, the main parts related to the functions of the server in the central device.

[0253] Fig.241 It is an image diagram showing the processing flow in the central device.

[0254] Fig.242 It is a diagram showing an example of the structure information of the vehicle registered in the structure information DB.

[0255] Fig.243 It is a diagram showing an example of the programs and data registered in the ECU reprogramming data DB.

[0256] Fig.244 It is a diagram showing an example of the specification data registered in the ECU metadata DB.

[0257] Fig.245 It is a diagram showing an example of the structural information of the vehicle registered in the individual vehicle information DB.

[0258] Fig.246 It is a diagram showing an example of the distribution packet data registered in the data packet DB.

[0259] Fig.247 It is a diagram showing an example of the activity data registered in the activity DB.

[0260] Fig.248 It is a flowchart showing the process of generating the programs and data registered in the ECU reprogramming data DB.

[0261] Fig.249 It is a flowchart showing an example of the process of generating the specification data registered in the ECU metadata DB.

[0262] Fig.250 It is a diagram showing an example of the specification data.

[0263] Fig.251 It is a diagram showing an example of the bus load table.

[0264] Fig.252 It is a flowchart showing the process of generating the distribution packets registered in the data packet DB.

[0265] Fig.253 It is a diagram showing the content of the data packet file in graphical form.

[0266] Fig.254 It is a sequence diagram showing the order of the processes executed between the central device and the vehicle-side system in the second embodiment.

[0267] Fig.255 It is a flowchart showing the process performed by the central device.

[0268] Fig.256 It is a diagram showing graphically the Fig.248 processing content carried out in steps D6 and D7 of the flowchart shown.

[0269] Fig.257 It is a flowchart showing the process when a hash value is sent from the vehicle-side system to the central device.

[0270] Fig.258 This is a sequence diagram showing the processing flow executed between the central device and the vehicle-side system in the third embodiment.

[0271] Fig.259 This is a flowchart showing the processing performed by the central device.

[0272] Fig.260 This is a sequence diagram showing the states in which the central device notifies the EV vehicle and the combined vehicle respectively via SMS.

[0273] Fig.261 This is a sequence diagram showing the processing flow executed between the central device and the vehicle-side system in the fourth embodiment.

[0274] Fig.262 This is a diagram showing, in graphical form, the processing performed among the supplier, the central device, and the vehicle-side system in the fifth embodiment.

[0275] Fig.263 This is a sequence diagram (Part 1) showing the processing flow performed among the supplier, the central device, and the vehicle-side system.

[0276] Fig.264 This is a sequence diagram (Part 2) showing the processing flow performed among the supplier, the central device, and the vehicle-side system.

[0277] Fig.265 This is a sequence diagram (Part 3) showing the processing flow performed among the supplier, the central device, and the vehicle-side system.

[0278] Fig.266 This is a variation (Part 1) of the first embodiment and is a diagram showing the data format of the data packet DB in the case where multiple data packets correspond to one activity.

[0279] Fig.267 This is a diagram showing the data format of the activity DB in the case where multiple data packets correspond to one activity.

[0280] Fig.268 This is a diagram corresponding to Fig.242 when generating specification data in groups.

[0281] Fig.269 This is a diagram corresponding to Fig.245 when generating distribution data packets in groups.

[0282] Fig.270 This is a variation (Part 2) of the first embodiment and is a diagram showing the processing content of the data packet generation tool. Detailed implementation manners

[0283] Hereinafter, an embodiment will be described with reference to the accompanying drawings. The vehicle program rewriting system (equivalent to the vehicle electronic control system) is a system capable of rewriting application programs such as vehicle control and diagnosis mounted on an electronic control unit (hereinafter referred to as ECU (Electronic Control Unit)) through OTA (Over The Air). In this embodiment, the case of rewriting application programs through wired or wireless means is described, but it can also be applied to cases where map data used in a map application, control parameters used in an ECU, etc., data used in various applications are rewritten through wired or wireless means, for example.

[0284] The rewriting of the application program through wired means includes not only obtaining the application program from outside the vehicle via wired and rewriting it, but also obtaining various data used when executing the application program from outside the vehicle via wired and rewriting it. The rewriting of the application program through wireless means includes not only obtaining the application program from outside the vehicle via wireless and rewriting it, but also obtaining various data used when executing the application program from outside the vehicle via wireless and rewriting it.

[0285] As Figure 1 shown, the vehicle program rewriting system 1 includes a central device 3 on the communication network 2 side, a vehicle-side system 4 on the vehicle side, and a display terminal 5. The communication network 2 is composed of, for example, a mobile communication network using a 4G line or the like, the Internet, WiFi (Wireless Fidelity) (registered trademark), etc. In addition, in this embodiment, the configuration on the vehicle side is mainly described, and the configuration of the central device 3 is described in detail in Figures 234 to 270 .

[0286] The display terminal 5 is a terminal having a function of accepting operation inputs from a user and a function of displaying various screens, and is, for example, a mobile terminal 6 such as a smartphone or a tablet that the user can carry, or an in-vehicle display 7 arranged in the vehicle compartment. If the mobile terminal 6 is within the communication range of the mobile communication network, it can perform data communication with the central device 3 via the communication network 2. The in-vehicle display 7 is connected to the vehicle-side system 4 and may also have a configuration with a navigation function. In addition, the in-vehicle display 7 may be an in-vehicle display ECU having the function of an ECU, or may have a function of controlling the display to a central display, an instrument display, etc.

[0287] When the user is outside the vehicle compartment and within the communication range of the mobile communication network, the user can perform operation inputs while confirming various screens related to the rewriting of the application program through the mobile terminal 6, and perform the procedures related to the rewriting of the application program. When the user is inside the vehicle compartment, the user can perform operation inputs while confirming various screens related to the rewriting of the application program through the in-vehicle display 7, and perform the procedures related to the rewriting of the application program. That is, the user can separately use the mobile terminal 6 and the in-vehicle display 7 outside and inside the vehicle compartment to perform the procedures related to the rewriting of the application program.

[0288] The central device 3 aggregates the program update function on the communication network 2 side in the vehicle program rewriting system 1 and functions as an OTA center. The central device 3 includes a file server 8, a web server 9, and a management server 10, and each of the servers 8 to 10 is configured to be able to perform data communication with each other. That is, the central device 3 is composed of different multiple servers according to each function.

[0289] The file server 8 is a server that manages the files of the application programs distributed from the central device 3 to the vehicle-side system 4. The file server 8 manages the update data (hereinafter, also referred to as reprogram data, write data) provided by the provider of the application program distributed from the central device 3 to the vehicle-side system 4, that is, the supplier, etc., the distribution specification data provided by the OEM (Original Equipment Manufacturer), the vehicle status obtained from the vehicle-side system 4, etc. The file server 8 can perform data communication with the vehicle-side system 4 via the communication network 2, and when a download request for a distribution data packet is generated, it sends a distribution data packet that packages the reprogram data and the distribution specification data into one file to the vehicle-side system 4.

[0290] The web server 9 is a server that manages web page information. The web server 9 sends the web page data it manages according to requests from web browsers in the mobile terminal 6 and the like. The management server 10 is a server that manages the personal information of users registered in the application program rewriting service, the rewriting history of the application program for each vehicle, and the like.

[0291] The vehicle side system 4 has a main device 11 (equivalent to a vehicle main device). The main device 11 has a DCM (Data Communication Module) 12 (equivalent to an in-vehicle communication device) and a CGW (Central GateWay) 13 (equivalent to a vehicle gateway device). The DCM 12 and the CGW 13 are connected via a first bus 14 so as to be able to perform data communication. Data communication is performed between the DCM 12 and the central device 3 via the communication network 2. When the DCM 12 downloads a distribution data packet from the file server 8, it extracts write data from the downloaded distribution data packet and transmits the extracted write data to the CGW 13.

[0292] The CGW 13 has a data relay function. When it obtains write data from the DCM 12, it instructs the rewrite target ECU, which is the rewrite target of the application program, to write the obtained write data, and distributes the write data to the rewrite target ECU. In addition, when the writing of the write data is completed in the rewrite target ECU and the rewrite of the application program is completed, the CGW 13 instructs the rewrite target ECU to activate the application program after the rewrite is completed.

[0293] The main device 11 summarizes the program update function on the vehicle side in the vehicle program rewrite system 1 and functions as an OTA host. In addition, in Figure 1 it is exemplified that the DCM 12 and the in-vehicle display 7 are connected to the same first bus 14, but the DCM 12 and the in-vehicle display 7 may also be connected to different buses. In addition, either the CGW 13 may have a part or the whole of the functions of the DCM 12, or the DCM 12 may have a part or the whole of the functions of the CGW 13. That is, in the main device 11, the function sharing between the DCM 12 and the CGW 13 can be arbitrarily configured. The main device 11 may be composed of two ECUs, namely the DCM 12 and the CGW 13, or may be composed of one integrated ECU having the functions of the DCM 12 and the CGW 13.

[0294] In addition to the first bus 14, a second bus 15, a third bus 16, a fourth bus 17, and a fifth bus 18 are also connected to the CGW 13 as in-vehicle buses. Various ECUs 19 are connected via the buses 15 to 17, and a power management ECU 20 is connected via the bus 18.

[0295] The second bus 15 is, for example, a bus of a vehicle body system network. The ECU 19 connected to the second bus 15 is an ECU that controls the vehicle body system. The ECU that controls the vehicle body system is, for example, a door ECU that controls the locking / unlocking of doors, an instrument ECU that controls the display on the instrument display, an air conditioner ECU that controls the driving of the air conditioner, a window ECU that controls the opening / closing of windows, a security ECU that is driven for vehicle anti-theft, and the like.

[0296] The third bus 16 is, for example, a bus of a driving system network. The ECU 19 connected to the third bus 16 is an ECU that controls the driving system. The ECU that controls the driving system is, for example, an engine ECU that controls the driving of the engine, a brake ECU that controls the driving of the brakes, an ECT (Electronic Controlled Transmission) ECU that controls the driving of the automatic transmission, a power steering ECU that controls the driving of the power steering, and the like.

[0297] The fourth bus 17 is, for example, a bus of a multimedia system network. The ECU 19 connected to the fourth bus 17 is an ECU that controls the multimedia system. The ECU that controls the multimedia system is, for example, a navigation ECU that controls the navigation system, an ETC (Electronic Toll Collection System, registered trademark) ECU that controls the electronic toll collection system (ETC), and the like. The buses 15 to 17 may also be buses of systems other than the vehicle body system network, the driving system network, and the multimedia system network. In addition, the number of buses and the number of ECUs 19 are not limited to the illustrated configurations. The power management ECU 20 is an ECU that manages the power supplied to the DCM 12, CGW 13, various ECUs 19, and the like.

[0298] A sixth bus 21 is connected to the CGW 13 as a bus outside the vehicle. A DLC (Data Link Coupler) connector 22 to which a tool 23 (equivalent to a service tool) can be detachably connected is connected to the sixth bus 21. The in-vehicle buses 14 to 18 and the out-of-vehicle bus 21 are constituted by, for example, a CAN (Controller Area Network, registered trademark) bus, and the CGW 13 performs data communication with the DCM 12, various ECUs 19, and the tool 23 according to the CAN data communication standard and the diagnostic communication standard (UDS (Unified Diagnosis Services): ISO14229). In addition, the DCM 12 and the CGW 13 may be connected by Ethernet, and the DLC connector 22 and the CGW 13 may be connected by Ethernet.

[0299] If the ECU 19 to be rewritten receives the write data from the CGW 13, it writes the received write data to the flash memory (equivalent to a non-volatile memory) to rewrite the application program. In the above configuration, the CGW 13 functions as a reprogramming host that distributes the write data to the ECU 19 to be rewritten if it receives a request for acquiring the write data from the ECU 19 to be rewritten. The ECU 19 to be rewritten functions as a reprogramming slave that writes the received write data to the flash memory to rewrite the application program if it receives the write data from the CGW 13.

[0300] As a method of rewriting the application program, there are a method of rewriting via wire and a method of rewriting via wireless. The method of rewriting the application program via wire means a method of rewriting the ECU 19 to be rewritten using the application program obtained from outside the vehicle via wire. Specifically, if the tool 23 is connected to the DLC connector 22, the tool 23 transmits the write data to the CGW 13. The CGW 13 functions as a gateway, sends a wire rewriting request to the ECU 19 to be rewritten, instructs the ECU 19 to be rewritten to write (install) the write data, and distributes the write data transmitted from the tool 23 to the ECU 19 to be rewritten. Distributing the write data to the ECU 19 to be rewritten is to relay the write data.

[0301] The method of rewriting the application program via wireless means a method of rewriting the ECU 19 to be rewritten using the application program obtained from outside the vehicle via wireless. Specifically, if the DCM 12 downloads the distribution data packet from the file server 8, it extracts the write data from the downloaded distribution data packet and transmits the write data to the CGW 13. The CGW 13 functions as a rewriting tool, instructs the ECU 19 to be rewritten to write (install) the write data, and distributes the write data transmitted from the DCM 12 to the ECU 19 to be rewritten.

[0302] As a method of diagnosing the ECU 19, there are a method of diagnosing via wire and a method of diagnosing via wireless. The method of diagnosing via wire means a method of diagnosing the ECU 19 from outside the vehicle via wire. Specifically, if the tool 23 is connected to the DLC connector 22, the tool 23 transmits the diagnosis request to the CGW 13. The CGW 13 functions as a gateway, sends the diagnosis request to the ECU 19 to be diagnosed, and distributes the diagnosis instruction transmitted from the tool 23 to the ECU 19 to be diagnosed. The ECU 19 to be diagnosed performs the diagnosis process corresponding to the diagnosis instruction received from the CGW 13.

[0303] The so-called wireless diagnosis method refers to a method of diagnosing the ECU19 wirelessly from outside the vehicle. Specifically, if a diagnostic instruction is sent from the central device 3 to the DCM12 as a diagnostic request, the DCM12 transmits the diagnostic instruction to the CGW13. The CGW13 acts as a gateway and distributes the diagnostic instruction as a diagnostic request to the diagnostic target ECU19. The diagnostic target ECU performs diagnostic processing corresponding to the diagnostic instruction received from the CGW13.

[0304] As Figure 2 shown, the CGW13 has a microcomputer (hereinafter referred to as a microcomputer) 24, a data transmission circuit 25, a power supply circuit 26, and a power supply detection circuit 27 as electrical function modules. The microcomputer 24 has a CPU (Central Processing Unit), a ROM (Read Only Memory) 24b, a RAM (Random Access Memory) 24c, and a flash memory 24d. A secure area in which information cannot be read from the outside of the CGW13 is included in the flash memory 24d. The microcomputer 24 executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the CGW13.

[0305] The data transmission circuit 25 controls data communication based on the CAN data communication standard and the diagnostic communication standard between the buses 14 to 18 and 21. The power supply circuit 26 inputs a battery power supply (hereinafter referred to as +B power supply), an accessory power supply (hereinafter referred to as ACC power supply), and an ignition power supply (hereinafter referred to as IG power supply). The power supply detection circuit 27 detects the voltage values of the +B power supply, the ACC power supply, and the IG power supply input by the power supply circuit 26, compares these detected voltage values with a specified voltage threshold value, and outputs the comparison result to the microcomputer 24. The microcomputer 24 determines whether the +B power supply, the ACC power supply, and the IG power supply supplied from the outside to the CGW13 are normal or abnormal based on the comparison result input from the power supply detection circuit 27.

[0306] As Figure 3 shown, the DCM12 has a microcomputer 28, a wireless circuit 29, a data transmission circuit 30, a power supply circuit 31, and a power supply detection circuit 32 as electrical function modules. The microcomputer 28 has a CPU 28a, a ROM 28b, a RAM 28c, and a flash memory 28d. A secure area in which information cannot be read from the outside of the DCM12 is included in the flash memory 28d. The microcomputer 28 executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the DCM12. A flash memory for storing data downloaded from the central device 3 may also be configured in the CGW13.

[0307] The radio circuit 29 controls the data communication via the communication network 2 with the central device 3. The data transmission circuit 30 controls the data communication based on the CAN data communication standard with the bus 14. The power supply circuit 31 inputs the +B power supply, the ACC power supply, and the IG power supply. The power supply detection circuit 32 detects the voltage values of the +B power supply, the ACC power supply, and the IG power supply input by the power supply circuit 31, compares these detected voltage values with a prescribed voltage threshold value, and outputs the comparison result to the microcomputer 28. The microcomputer 28 determines whether the +B power supply, the ACC power supply, and the IG power supply supplied from the outside to the DCM 12 are normal or abnormal based on the comparison result input from the power supply detection circuit 32.

[0308] In addition, the DCM 12 has a vehicle position detection function of detecting the vehicle position by, for example, GPS (Global Positioning System). The flash memory 28d of the DCM 12 has a sufficient memory capacity capable of storing the distribution data packet downloaded from the central device 3, and has a larger memory capacity than the flash memory 24d of the CGW 13. That is, the flash memory 28d of the DCM 12 has a structure with a sufficient memory capacity, so that even if the flash memory 24d of the CGW 13 does not have a sufficient memory capacity, in the main device 11, the distribution data packet can be downloaded from the central device 3 and the downloaded distribution data packet can be stored in the DCM 12.

[0309] As Figure 4 shown, the ECU 19 has a microcomputer 33, a data transmission circuit 34, a power supply circuit 35, and a power supply detection circuit 36 as electrical function modules. The microcomputer 33 has a CPU 28a, a ROM 28b, a RAM 33c, and a flash memory 28d. A security area in which information cannot be read from the outside of the ECU 19 is included in the flash memory 28d. The microcomputer 33 executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the ECU 19.

[0310] The data transmission circuit 34 controls the data communication based on the CAN data communication standard with the buses 15 to 17. The power supply circuit 35 inputs the +B power supply, the ACC power supply, and the IG power supply. The power supply detection circuit 36 detects the voltage values of the +B power supply, the ACC power supply, and the IG power supply input by the power supply circuit 35, compares these detected voltage values with a prescribed voltage threshold value, and outputs the comparison result to the microcomputer 33. The microcomputer 33 determines whether the +B power supply, the ACC power supply, and the IG power supply supplied from the outside to the ECU 19 are normal or abnormal based on the comparison result input from the power supply detection circuit 27. In addition, the ECU 19 has substantially the same configuration except that the loads such as sensors and actuators connected to itself are different.

[0311] The in-vehicle display 7 has Figure 4 the same configuration as that of the ECU 19 shown. The power management ECU 20 has the same configuration as that of Figure 4 the ECU 19 shown. The power management ECU 20 is connected so as to be able to communicate data with a power control circuit 43 described later.

[0312] As Figure 5 shown, the power management ECU 20, the CGW 13, the ECU 19 are connected to a +B power supply line 37, an ACC power supply line 38, and an IG power supply line 39 which are power supply lines. The +B power supply line 37 is connected to the positive electrode of the vehicle battery 40. The ACC power supply line 38 is connected to the positive electrode of the vehicle battery 40 via an ACC switch 41. When the user performs an ACC operation, the ACC switch 41 switches from OFF to ON, and the output voltage of the vehicle battery 40 is applied to the ACC power supply line 38. For example, in the case of a vehicle of the type in which a key is inserted into an insertion port, the ACC operation is an operation of inserting the key into the insertion port and turning it from the "OFF" position to the "ACC" position. In the case of a vehicle of the type in which a start button is pressed, the ACC operation is an operation of pressing the start button once.

[0313] The IG power supply line 39 is connected to the positive electrode of the vehicle battery 40 via an IG switch 42. When the user performs an IG operation, the IG switch 42 switches from OFF to ON, and the output voltage of the vehicle battery 40 is applied to the IG power supply line 39. For example, in the case of a vehicle of the type in which a key is inserted into an insertion port, the IG operation is an operation of inserting the key into the insertion port and turning it from the "OFF" position to the "ON" position. In the case of a vehicle of the type in which a start button is pressed, the IG operation is an operation of pressing the start button twice. The negative electrode of the vehicle battery 40 is grounded.

[0314] When both the ACC switch 41 and the IG switch 42 are OFF, only the +B power supply is supplied to the vehicle side system 4. The state in which only the +B power supply is supplied to the vehicle side system 4 is called the +B power supply state. When the ACC switch 41 is ON and the IG switch 42 is OFF, the ACC power supply and the +B power supply are supplied to the vehicle side system 4. The state in which the ACC power supply and the +B power supply are supplied to the vehicle side system 4 is called the ACC power supply state. When both the ACC switch 41 and the IG switch 42 are ON, the +B power supply, the ACC power supply, and the IG power supply are supplied to the vehicle side system 4. The state in which the +B power supply, the ACC power supply, and the IG power supply are supplied to the vehicle side system 4 is called the IG power supply state. In addition to the above power supply states, a power supply state that gives a power supply suitable for program update by wireless or the like is also considered.

[0315] For the ECU 19, the start-up conditions vary depending on the power supply state and are classified into the +B power supply system ECU that starts in the +B power supply state, the ACC system ECU that starts in the ACC power supply state, and the IG system ECU that starts in the IG power supply state. For example, the ECU 19 driven for purposes such as vehicle anti-theft is classified as the +B power supply system ECU. For example, the ECU 19 driven for purposes of non-driving systems such as audio is classified as the ACC system ECU. For example, the ECU 19 driven for purposes of driving systems such as engine control is classified as the IG system ECU.

[0316] The +B power supply system ECU is configured to be connected to the +B power supply line 37, the ACC power supply line 38, and the IG power supply line 39, selects the +B power supply line 37 in the +B power supply state, selects the ACC power supply line 38 in the ACC power supply state, and selects the IG power supply line 39 in the IG power supply state. The ACC system ECU is configured to be connected to the ACC power supply line 38 and the IG power supply line 39, selects the ACC power supply line 38 in the ACC power supply state, and selects the IG power supply line 39 in the IG power supply state. The IG system ECU is connected to the IG power supply line 39.

[0317] The CGW 13 causes the ECU 19, which is the destination of the start-up request, to transfer from the sleep state to the start-up state by sending a start-up request to the ECU 19 in the sleep state. In addition, the CGW 13 causes the ECU 19, which is the destination of the sleep request, to transfer from the start-up state to the sleep state by sending a sleep request to the ECU 19 in the start-up state. The CGW 13 can cause a specific ECU 19 to transfer to the start-up state or the sleep state by, for example, making the waveforms of the transmission signals sent to the buses 15 to 17 different. That is, the start-up request waveform and the sleep request waveform are determined in advance for each ECU 19. If the ECU 19 receives a start-up request waveform suitable for itself, it transfers from the sleep state to the start-up state, and if it receives a sleep request waveform suitable for itself from the CGW 13, it transfers from the start-up state to the sleep state.

[0318] The CGW 13, for example, sends the first waveform when the ECU (ID1) and the ECU (ID2) are in the start-up state, thereby causing the ECU (ID1) to transfer from the start-up state to the sleep state and keeping the ECU (ID2) in the start-up state. In addition, the CGW 13 sends the second waveform when the ECU (ID1) and the ECU (ID2) are in the start-up state, thereby keeping the ECU (ID1) in the start-up state and causing the ECU (ID2) to transfer from the start-up state to the sleep state.

[0319] The power control circuit 43 is connected in parallel with the ACC switch 41 and the IG switch 42. The CGW13 sends a power control request to the power management ECU 20, causing the power management ECU 20 to control the power control circuit 43. That is, the CGW13 causes the positive electrodes of the ACC power supply line 38, the IG power supply line 39, and the vehicle battery 40 to be internally connected within the power control circuit 43 by sending a power start request as a power control request to the power management ECU 20. In this state, even if the ACC switch 41 and the IG switch 42 are turned off, the ACC power supply and the IG power supply are supplied to the vehicle-side system 4. In addition, the CGW13 causes the positive electrodes of the ACC power supply line 38, the IG power supply line 39, and the vehicle battery 40 to be internally disconnected within the power control circuit 43 by sending a power stop request as a power control request to the power management ECU 20.

[0320] The DCM 12, CGW 13, ECU 19, and power management ECU 20 each have a power self-holding circuit and have a power self-holding function for maintaining the power supply from the vehicle battery 40. That is, for the DCM 12, CGW 13, ECU 19, and power management ECU 20, if the vehicle power is switched from the ACC power supply or the IG power supply to the +B power supply when in the startup state, they do not immediately transfer from the startup state to the stop state or the sleep state after the switch, but continue to self-hold the drive power for a specified time (e.g., several minutes) using the power supply from the vehicle battery 40 to maintain the startup state. The DCM 12, CGW 13, ECU 19, and power management ECU 20 transfer from the startup state to the stop state or the sleep state after a specified time has elapsed after the vehicle power is switched from the ACC power supply or the IG power supply to the +B power supply. For example, if it is the ECU 19 of the engine control system, the power self-holding function operates after the vehicle power is switched from the ACC power supply or the IG power supply to the +B power supply, thereby storing various data related to engine control obtained during vehicle operation as a log.

[0321] Next, the distribution data packet distributed from the central device 3 to the master device 11 will be described. As Figure 6 shown, in the vehicle program rewriting system 1, recompiled data is generated based on the write data provided by the supplier, which is the application program provider, and the rewriting specification data (equivalent to the specification data) provided by the OEM. The rewriting specification data can also be generated in the central device 3. As the write data provided by the supplier, there is differential data equivalent to the difference between the old application program and the new application program and all data equivalent to the entire new application program. The differential data and all data can also be compressed by a known data compression technique. In Figure 6In this example, differential data is provided as write data from suppliers A to C, and recompiled data is generated based on the encrypted differential data and authentication symbols of the ECU (ID1) provided by supplier A, the encrypted differential data and authentication symbols of the ECU (ID2) provided by supplier B, the encrypted differential data and authentication symbols of the ECU (ID3) provided by supplier C, and the rewrite specification data provided by the OEM.

[0322] The authentication symbol is data assigned to each write data to verify the integrity of the differential data, and is generated based on, for example, the ECU (ID), the key information associated with the ECU (ID), and the differential data. Here, in the case where the rewrite of the application is cancelled midway, the write data used for writing back (rolling back) to the old version may also be included in the recompiled data.

[0323] The rewrite specification data provided by the OEM includes information capable of identifying the rewrite target ECU19, information capable of determining the rewrite order in the case where there are multiple rewrite target ECUs19, information capable of determining the rollback method described later, etc. as information related to the rewrite of the application. The rewrite specification data is data that defines the actions related to the rewrite in the DCM12, CGW13, rewrite target ECU19, etc. The rewrite specification data is classified into DCM rewrite specification data used by the DCM12 and CGW rewrite specification data used by the CGW13.

[0324] As Figure 7 shown, the DCM rewrite specification data includes specification data information and ECU information. The specification data information includes address information and file names. The ECU information includes the address information, etc. referred to when sending the update program (write data) of each rewrite target ECU19 to the CGW13 in the number corresponding to the number of rewrite target ECUs19. Specifically, the ECU information includes at least the ID (ECU (ID)) for identifying the ECU, the reference address (update program acquisition address) when acquiring the update program, the update program size, the reference address (rollback program acquisition address) when acquiring the rollback program, and the rollback program size. The rollback program is a program (write data) for returning the application to the original version in the case where the rewrite of the application is cancelled midway.

[0325] As Figure 8As shown, the rewriting specification data for the CGW includes group information, a bus load table, a battery load, the vehicle state during rewriting, and ECU information. In addition to these, the rewriting specification data for the CGW may also include rewriting step information, displayed scenario information, etc. The group information is information indicating the group to which the target ECU 19 for rewriting belongs and the rewriting order. For example, as the first group information, it is specified that the application content is rewritten in the order of ECU (ID1), ECU (ID2), and ECU (ID3). As the second group information, it is specified that the application content is rewritten in the order of ECU (ID4), ECU (ID5), and ECU (ID6). The bus load table is the table shown in Fig.100 which will be described in detail later. The battery load is information indicating the lower limit value of the battery margin of the vehicle battery 40 that can be allowed in the vehicle. The vehicle state during rewriting is information indicating in what vehicle state the rewriting is performed.

[0326] The ECU information is information related to the target ECU 19 for rewriting, and at least includes ECU_ID (equivalent to device identification information), connected bus (equivalent to bus identification information), connected power supply, secure access key information, memory type, rewriting method, power self-holding time, rewriting surface information, updated program version, updated program acquisition address, updated program size, rollback program version, rollback program acquisition address, rollback program size, and written data type.

[0327] The connected bus indicates the bus to which the ECU 19 is connected. The connected power supply indicates the power supply line to which the ECU 19 is connected. The secure access key information indicates the key information used for the authentication of the CGW 13 to access the target ECU 19 for rewriting, and includes a random value or unique information, a key mode, and a decryption operation mode. The memory type indicates which of a single-sided single memory, a single-sided suspended memory (also called a pseudo double-sided memory), and a double-sided memory is mounted on the target ECU 19 for rewriting. The rewriting method indicates which of the rewriting based on power self-holding and the rewriting based on power control it is. The power self-holding time indicates the time for continuing power self-holding when the rewriting method is the rewriting based on power self-holding. The rewriting surface information indicates which surface is the application surface and which surface is the non-application surface. The application surface is also called the startup surface, and the non-application surface is also called the rewriting surface.

[0328] The update program version represents the version of the update program. The update program acquisition address represents the address of the update program. The update program size represents the data size of the update program. The rollback program version represents the version of the rollback program. The rollback program acquisition address represents the address of the rollback program. The rollback program size represents the data size of the rollback program. The write data type indicates whether the write data is differential data or all data. In addition, the rewritten specification data can include information defined independently by the system in addition to these information.

[0329] If DCM12 acquires the rewritten specification data for DCM, it parses the acquired rewritten specification data for DCM. If DCM12 parses the rewritten specification data for DCM, it controls actions related to obtaining write data from the address storing the update program of the ECU19 to be rewritten and transmitting the obtained write data to CGW13, etc.

[0330] If CGW13 acquires the rewritten specification data for CGW, it parses the acquired rewritten specification data for CGW. If CGW13 parses the rewritten specification data for CGW, it controls actions related to requesting the transmission of a specified amount of the update program of the ECU19 to be rewritten from DCM12 according to the parsing result, or distributing the write data to the ECU19 to be rewritten in the specified order.

[0331] The above recompiled data and the distribution specification data provided by the OEM are registered in the file server 8. The distribution specification data provided by the OEM is data that defines actions related to the display of various screens in the display terminal 5. As Fig. 9 shown, the distribution specification data includes language information, display statements, data packet information, image data, display modes, display control programs, etc.

[0332] If the display terminal 5 acquires the distribution specification data from CGW13, it parses the acquired distribution specification data and controls the display of various screens according to the parsing result. For example, the display terminal 5 overlays the display statements obtained from the distribution specification data on the display frames held in advance, or executes the display control program obtained from the distribution specification data. In addition, the distribution specification data can include information defined independently by the system in addition to these information.

[0333] If the file server 8 registers the recompiled data and the distribution specification data, it encrypts the registered recompiled data to generate a distribution data packet storing a data packet authentication symbol for authenticating the data packet, the encrypted recompiled data, and the distribution specification data. The authentication symbol is data given to verify the integrity of the recompiled data and the distribution specification data, and is generated based on, for example, the key information associated with the CGW 13, the recompiled data, and the distribution specification data. If the file server 8 receives a download request for the distribution data packet from the outside, it sends the distribution data packet to the DCM 12. In addition, in Figure 6 it is exemplified that the file server 8 generates a distribution data packet storing the recompiled data and the distribution specification data and sends the recompiled data and the distribution specification data to the DCM 12 as one file at the same time, but the recompiled data and the distribution specification data may also be sent to the DCM 12 as different files. That is, the file server 8 may first send the distribution specification data to the DCM 12 and then send the recompiled data to the DCM 12. In this case, authentication symbols can be given to the distribution specification data and the recompiled data respectively.

[0334] As Fig.10 shown, if the DCM 12 downloads the distribution data packet from the file server 8, it uses the data packet authentication symbol stored in the downloaded distribution data packet to verify the integrity of the encrypted recompiled data. If the verification result is positive, the DCM 12 decrypts the encrypted recompiled data. If the DCM 12 decrypts the encrypted recompiled data, it unpacks the decrypted recompiled data and extracts it into encrypted differential data and an authentication symbol, DCM-specific rewriting specification data, and CGW-specific rewriting specification data. In Fig.10 it is exemplified that it is extracted into encrypted differential data and an authentication symbol for the ECU (ID1), encrypted differential data and an authentication symbol for the ECU (ID2), encrypted differential data and an authentication symbol for the ECU (ID3), DCM-specific rewriting specification data, and CGW-specific rewriting specification data.

[0335] Next, the flash memory 33d of the ECU 19 will be described with reference to Figures 11 to 22 The flash memory 33d of the ECU 19 is divided into a single-sided separate memory having a flash memory surface on one side, a single-sided suspended memory having a flash memory surface on a pseudo two sides, and a double-sided memory having a flash memory surface on a substantial two sides according to the memory structure. After that, the ECU 19 equipped with the single-sided separate memory is called a single-sided separate memory ECU, the ECU 19 equipped with the single-sided suspended memory is called a single-sided suspended memory ECU, and the ECU 19 equipped with the double-sided memory is called a double-sided memory ECU.

[0336] The single-sided standalone memory is configured with a flash memory surface on one side, so the concepts of an active surface and an inactive surface are not applicable, and the application program cannot be rewritten during the execution of the application program. On the other hand, the single-sided suspended memory and the double-sided memory are configured with flash memory surfaces on two sides, so the concepts of an active surface and an inactive surface exist, and the application program on the inactive surface can be rewritten during the execution of the application program on the active surface. The double-sided memory is configured with flash memory surfaces on two completely separate sides, so the application program can be rewritten at any time, such as when the vehicle is running. The single-sided suspended memory is a configuration in which the single-sided standalone memory is pseudo-divided into two sides, and the timing for normal reading and writing is limited. The application program cannot be rewritten when the vehicle is running, but can be rewritten when the vehicle is parked with the IG power off.

[0337] In addition, the single-sided standalone memory, the single-sided suspended memory, and the double-sided memory each have a recompilation firmware embedded type (hereinafter referred to as the embedded type) in which the recompilation firmware is embedded and a recompilation firmware download type (hereinafter referred to as the download type) in which the recompilation firmware is downloaded from the outside. The recompilation firmware is the firmware used to rewrite the application program.

[0338] Hereinafter, the configurations of each flash memory will be described in sequence.

[0339] (A) Single-sided standalone memory

[0340] (A-1) Embedded single-sided standalone memory

[0341] Refer to Fig.11 and Fig.12 The embedded single-sided standalone memory will be described. The embedded single-sided standalone memory has a differential engine working area, an application program area, and a boot program area. In the application program area, version information, parameter data, the application program, firmware, and a normal-time vector table are configured. In the boot area, a boot program, progress status point 2, progress status point 1, startup determination information, wireless recompilation firmware, wired recompilation firmware, a startup determination program, and a boot-time vector table are configured.

[0342] As Fig.11 shown, when the microcomputer 33 is performing normal operations such as vehicle control processing and diagnostic processing, it executes the startup determination program, searches for the starting address with reference to the boot-time vector table and the normal-time vector table, and executes the specified address of the application program.

[0343] When the microcomputer 33 is performing a rewrite operation for rewriting the application program, it does not execute the application program but executes the wireless or wired recompilation firmware. Fig.12 This represents the operation of rewriting the application program using differential data as the update program. As Fig.12As shown, the microcomputer 33 temporarily saves the application program as old data to the differential engine working area. The microcomputer 33 reads out the old data temporarily saved to the differential engine working area, and restores new data according to the read old data and the differential data stored in the RAM 33c through the differential engine included in the embedded reprogramming firmware. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to a specified address in the memory to rewrite the application program.

[0344] (A - 2) Downloadable single-sided standalone memory

[0345] Refer to Fig.13 and Fig.14 A downloadable single-sided standalone memory will be described. Compared with the above-mentioned embedded type, the downloadable type is different in that after downloading wireless reprogramming firmware and wired reprogramming firmware from the outside and rewriting the application program, the wireless reprogramming firmware and the wired reprogramming firmware are deleted. In the case of updating the application program wirelessly, for example, in the Figure 6 shown reprogramming data, the wireless reprogramming firmware executed by each ECU 19 is included. The ECU 19 receives the wireless reprogramming firmware for its own ECU from the CGW 13 and saves the received wireless reprogramming firmware for its own ECU to the RAM.

[0346] As Fig.13 shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing, it executes the startup determination program in the same way as the embedded type, refers to the boot-time vector table and the normal-time vector table to search for the starting address, and executes the specified address of the application program.

[0347] As Fig.14 shown, when the microcomputer 33 performs the rewrite operation of the application program rewrite process, it temporarily saves the application program as old data to the differential engine working area. The microcomputer 33 reads out the old data temporarily saved to the differential engine working area, and restores new data according to the read old data and the differential data stored in the RAM 33c through the differential engine included in the reprogramming firmware downloaded from the outside. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to rewrite the application program.

[0348] (B) Single-sided suspended memory

[0349] (B - 1) Embedded single-sided suspended memory

[0350] Refer to Fig.15 and Fig.16An embedded single-sided suspended memory is described. The embedded single-sided suspended memory has a differential engine working area, an application area, and a bootstrap area. The reprogrammed firmware for program update is configured in the bootstrap area in the same way as the single-sided individual memory and is not an object of program update. The application area that is an object of program update has an A side and a B side in a pseudo manner, and version information, an application program, and a normal-time vector table are respectively configured on the A side and the B side. A bootstrap program, reprogrammed firmware, a reprogramming-time vector table, a startup side determination function, startup side determination information, and a boot-time vector table are configured in the boot area.

[0351] As Fig.15 shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing in application processing, it executes the bootstrap program, and determines which of the A side and the B side is the operating side according to the respective startup side determination information of the A side and the B side through the startup side determination function. If the microcomputer 33 determines that the A side is set as the operating side, it searches for the starting address with reference to the normal-time vector table of the A side and executes the application program of the A side. Similarly, if the microcomputer 33 determines that the B side is set as the operating side, it searches for the starting address with reference to the normal-time vector table of the B side and executes the application program of the B side. In addition, in Fig.15 the reprogrammed firmware is configured in the bootstrap area, but it can also be configured such that the reprogrammed firmware is also an object of program update and is configured in the respective areas of the A side or the B side.

[0352] As Fig.16 shown, when the microcomputer 33 performs a rewrite operation for rewriting the application program on the non-operating side, it temporarily saves the application program on the non-operating side as old data to the differential engine working area. The microcomputer 33 reads out the old data temporarily saved in the differential engine working area, and restores new data according to the read old data and the differential data in the embedded differential engine of the reprogrammed firmware. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the non-operating side to rewrite the application program on the non-operating side. In Fig.16 it illustrates the case where the A side is the operating side and the B side is the non-operating side.

[0353] (B - 2) Downloadable single-sided suspended memory

[0354] Refer to Fig.17 and Fig.18 to describe the downloadable single-sided suspended memory. The downloadable type is different from the above-mentioned embedded type in that it downloads the reprogrammed firmware and the reprogramming-time vector table from the outside, and deletes the reprogrammed firmware and the reprogramming-time vector table after rewriting the application program.

[0355] As Fig.17As shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing, similar to the embedded type, it executes the boot program, and determines the new and old based on the start surface determination information of each of the A surface and the B surface through the start surface determination function, and determines which of the A surface and the B surface is the operation surface. If the microcomputer 33 determines that the A surface is the operation surface, it refers to the normal time vector table of the A surface to search for the start address and executes the application program of the A surface. Similarly, if the microcomputer 33 determines that the B surface is the operation surface, it refers to the normal time vector table of the B surface to search for the start address and executes the application program of the B surface.

[0356] As Fig.18 shown, when the microcomputer 33 performs the rewrite operation of the application program rewrite process, it temporarily saves the application program of the non-operation surface as old data to the differential engine working area. The microcomputer 33 reads the old data temporarily saved to the differential engine working area, and through the differential engine in the recompiled firmware downloaded from the outside, restores the new data based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to rewrite the application program. In Fig.18 it, a case where the A surface is the operation surface and the B surface is the non-operation surface is illustrated. In this way, in the single-sided suspended memory, it is possible to execute the rewrite of the application program of the B surface in the background while executing the application program of the A surface.

[0357] (C) Dual-sided memory

[0358] (C-1) Embedded dual-sided memory

[0359] Refer to Fig.19 and Fig. 20 The embedded dual-sided memory will be described. The embedded single-sided independent memory has an application program area and a rewrite program area for the A surface, an application program area and a rewrite program area for the B surface, and a boot program area. In the boot area, the boot program is configured not to be rewritten. The boot program includes a boot swap function and a boot time vector table. Version information, parameter data, application programs, firmware, and normal time vector tables are configured in each application program area. A program for controlling rewriting, recompilation progress management information 2, recompilation progress management information 1, start surface determination information, wireless recompiled firmware, wired recompiled firmware, and a boot time vector table are configured in each rewrite program area. A boot program, a boot swap function, and a boot time vector table are configured in the boot area.

[0360] As Fig.19As shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing, and when performing rewrite operations for rewriting application programs on the non-operating side, it executes the boot program, and determines the new and old through the boot swap function based on the start surface determination information of each of the A surface and the B surface, and determines which of the A surface and the B surface is the operating surface. If the microcomputer 33 determines that the A surface is set as the operating surface, it searches for the start address with reference to the boot-time vector table of the A surface and the normal-time vector table of the A surface, and executes the application program of the A surface. Similarly, if the microcomputer 33 determines that the B surface is set as the operating surface, it searches for the start address with reference to the boot-time vector table of the B surface and the normal-time vector table of the B surface, and executes the application program of the B surface.

[0361] As Fig. 20 shown, when the microcomputer 33 performs rewrite operations for rewriting application programs on the non-operating side, it temporarily stores the non-operating side application program as old data in the differential engine working area. The microcomputer 33 reads out the old data temporarily stored in the differential engine working area, and through the differential engine embedded in the reprogramming firmware, restores new data based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the non-operating side to rewrite the non-operating side application program. In addition, the old data temporarily stored in the differential engine working area can target either the application program on the operating side or the application program on the non-operating side. At this time, when targeting the application program on the operating side, the data on the non-operating side is erased before writing the new data. Here, when the reprogramming data obtained from outside the vehicle is not differential data but all data (full data), the obtained reprogramming data is written as new data to the non-operating side. In Fig. 20 it, a case where the A surface is the operating surface and the B surface is the non-operating surface is illustrated. In addition, the old data temporarily stored in the differential engine working area can target either the application program on the operating side or the application program on the non-operating side. When it is necessary to match the execution address of the application program, the non-operating side application program is stored as old data.

[0362] (C - 2) Downloadable Dual-Sided Memory

[0363] Refer to Fig.21 and Fig. 22 to describe the downloadable dual-sided memory. Compared with the above-mentioned embedded type, the downloadable type is different in that it downloads wireless reprogramming firmware and wired reprogramming firmware from the outside, and deletes the wireless reprogramming firmware and wired reprogramming firmware after rewriting the application program.

[0364] As Fig.21As shown, when the microcomputer 33 executes normal operations such as vehicle control processing and diagnostic processing, and when it executes rewrite operations for rewriting application programs on the non-operation side, similar to the embedded type, it executes the boot program, determines the old and new through the boot swap function based on the start surface determination information of each of the A surface and the B surface, and determines which of the A surface and the B surface is the operation surface, and executes the application program on the operation surface to execute the application processing.

[0365] As Fig. 22 shown, when the microcomputer 33 executes the rewrite operation for rewriting the application program, it temporarily stores the application program on the non-operation side as old data in the differential engine working area. The microcomputer 33 reads the old data temporarily stored in the differential engine working area, and restores new data based on the read old data and the differential data stored in the RAM 33c through the reprogramming firmware downloaded from the outside. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the non-operation side to rewrite the application program on the non-operation side. In addition, the old data temporarily stored in the differential engine working area can target either the application program on the operation side or the application program on the non-operation side. At this time, when targeting the application program on the operation side, the data on the non-operation side is erased before writing the new data. Here, when the reprogramming data obtained from outside the vehicle is not differential data but all data (full data), the obtained reprogramming data is written as new data to the non-operation side. In Fig. 22 it, a case where the A surface is the operation surface and the B surface is the non-operation surface is illustrated. In addition, the old data temporarily stored in the differential engine working area can target either the application program on the operation side or the application program on the non-operation side. In this way, in the dual-sided memory, it is possible to rewrite the application program on the B surface in the background while executing the application program on the A surface.

[0366] As described above, in any of the embedded type and the download type configurations, an application program and a rewrite program for rewriting the application program are arranged in each application area. In addition, in Fig. 20 and Fig. 22 it, the application program is shown as the reprogramming target, but the rewrite program can also be the reprogramming target. In addition, when it is desired that the rewrite program cannot be rewritten, the rewrite program can be arranged in the boot area. A program for wired rewriting can also be arranged in the boot area so that, for example, reliable wired rewriting via the tool 23 can be implemented at a dealership or the like.

[0367] Next, referring to Figure 23 to Figure 25The overall order of the rewriting application is described. Here, the case where the user operates the mobile terminal 6 as the display terminal 5 to rewrite the application while the vehicle is parked is described, but the case where the in-vehicle display 7 is operated to rewrite the application while the vehicle is parked is the same. The distribution data packet sent from the central device 3 stores the write data for one or more ECUs 19 to be rewritten. That is, in the distribution data packet, if there is one ECU 19 to be rewritten, one write data for the one ECU 19 to be rewritten is stored, and if there are multiple ECUs 19 to be rewritten, multiple write data for each of the multiple ECUs 19 to be rewritten is stored. Here, there are two ECUs 19 to be rewritten, and the two ECUs 19 to be rewritten are referred to as the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2). In addition, the ECU 19 other than the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) is referred to as other ECU.

[0368] If the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively determine that a transmission request for, for example, a version notification signal is received from the master device 11, it is determined that the transmission condition of the version notification signal is satisfied. If the transmission condition of the version notification signal is satisfied, the ECU to be rewritten (ID1) sends a version notification signal including the version information of the application program stored in itself and the ECU (ID) that can identify itself to the master device 11. If the master device 11 receives a version notification signal from the ECU to be rewritten (ID1), the received version notification signal is sent to the central device 3. Similarly, if the transmission condition of the version notification signal is satisfied, the ECU to be rewritten (ID2) sends a version notification signal including the version of the application program stored in itself and the ECU (ID) that can identify itself to the master device 11. If the master device 11 receives a version notification signal from the ECU to be rewritten (ID2), the received version notification signal is sent to the central device 3.

[0369] If the central device 3 receives version notification signals from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), it determines the version of the application program and the ECU (ID) included in the received version notification signal, and determines whether there is write data for the ECU 19 to be rewritten that should be distributed to the source of the version notification signal. The central device 3 determines the current version of the application program of the ECU 19 to be rewritten based on the version notification signal received from the ECU to be rewritten, and compares the current version of the application program with the latest version being managed.

[0370] If the version determined based on the version notification signal is the same as the latest version being managed, the central device 3 determines that there is no write data for the rewrite target ECU 19 to which the version notification signal should be distributed, and there is no need to update the application program stored in the rewrite target ECU 19. On the other hand, if the version determined based on the version notification signal is less than the latest version being managed, the central device 3 determines that there is write data for the rewrite target ECU 19 to which the version notification signal should be distributed, and it is necessary to update the application program stored in the rewrite target ECU 19.

[0371] If the central device 3 determines that it is necessary to update the application program stored in the rewrite target ECU 19, it notifies the mobile terminal 6 of the gist that an update is required. If notified of the gist that an update is required, the mobile terminal 6 displays a distribution confirmation screen (A1). The distribution confirmation screen is the same as the activity notification screen described later. The user can confirm the gist that an update is required through the distribution confirmation screen displayed on the mobile terminal 6 and can select whether to update.

[0372] If the user selects the gist of performing an update (A2) on the mobile terminal 6, the mobile terminal 6 notifies the central device 3 of a download request for the distribution data packet. If notified of the download request for the distribution data packet from the mobile terminal 6, the central device 3 sends the distribution data packet to the main device 11.

[0373] If the main device 11 downloads the distribution data packet from the central device 3, it starts a data packet authentication process (B1) for the downloaded distribution data packet. The main device 11 authenticates the distribution data packet. If the data packet authentication process is completed, it starts a write data extraction process (B2). The main device 11 extracts the write data from the distribution data packet. If the write data extraction process is completed, it sends a download completion notification signal to the central device 3.

[0374] If the central device 3 receives the download completion notification signal from the main device 11, it notifies the mobile terminal 6 of the download completion. If notified of the download completion from the central device 3, the mobile terminal 6 displays a download completion notification screen (A3). The user can confirm the gist of the download completion through the download completion notification screen displayed on the mobile terminal 6 and can set the rewrite start time of the vehicle-side application program.

[0375] If the user sets the rewrite start time of the vehicle-side application program (A4) on the mobile terminal 6, the mobile terminal 6 notifies the central device 3 of the rewrite start time. If notified of the rewrite start time from the mobile terminal 6, the central device 3 stores the rewrite start time set by the user as the set start time. If the current time reaches the set start time (A5), the central device 3 sends a rewrite instruction signal to the main device 11.

[0376] When the main device 11 receives a rewriting instruction signal from the central device 3, it sends a power-on request to the power management ECU 20, causing the ECU to be rewritten (ID1), the ECU to be rewritten (ID2), and other ECUs to transition from the stopped state or sleep state to the startup state (X1).

[0377] The main device 11 starts distributing the write data to the ECU to be rewritten (ID1) and instructs the ECU to be rewritten (ID1) to write the write data. The ECU to be rewritten (ID1) starts receiving the write data from the main device 11 and, if instructed to write the write data, starts writing the write data and starts the program rewriting process (C1). When the ECU to be rewritten (ID1) finishes receiving the write data from the main device 11, finishes writing the write data, and finishes the program rewriting process, it sends a rewrite completion notification signal to the main device 11.

[0378] When the main device 11 receives a rewrite completion notification signal from the ECU to be rewritten (ID1), it starts distributing the write data to the ECU to be rewritten (ID2) and instructs the ECU to be rewritten (ID2) to write the write data. The ECU to be rewritten (ID2) starts receiving the write data from the main device 11 and, if instructed to write the write data, starts writing the write data and starts the program rewriting process (D1). When the ECU to be rewritten (ID2) finishes receiving the write data from the main device 11, finishes writing the write data, and finishes the program rewriting process, it sends a rewrite completion notification signal to the main device 11. When the main device 11 receives a rewrite completion notification signal from the ECU to be rewritten (ID2), it sends a rewrite completion notification signal to the central device 3.

[0379] When the central device 3 receives a rewrite completion notification signal from the main device 11, it notifies the mobile terminal 6 of the completion of the application program rewrite. If notified of the completion of the application program rewrite from the central device 3, the mobile terminal 6 displays a rewrite completion notification screen (A6). The user can confirm the main idea of the completion of the application program rewrite through the rewrite completion notification screen displayed on the mobile terminal 6 and can set the synchronization implementation as activation.

[0380] If the user sets the synchronization implementation (A7) on the mobile terminal 6, that is, the user sets the consent for the activation of the new program, the mobile terminal 6 notifies the central device 3 of the synchronization implementation. If notified of the synchronization implementation from the mobile terminal 6, the central device 3 sends a synchronization switching instruction signal to the main device 11. When the main device 11 receives the synchronization switching instruction signal from the central device 3, it distributes the received synchronization switching instruction signal to the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2).

[0381] Upon receiving the synchronization switching instruction signal from the main device 11, the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively start the program switching process (C2, D2) of switching the application program to be started next from the old application program to the new application program. Upon completion of the program switching process, the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively send a switching completion notification signal to the main device 11.

[0382] Upon receiving the switching completion notification signal from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), the main device 11 distributes the version reading signal to the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2). Upon receiving the version reading signal from the main device 11, the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively read the version of the application program to be used later (C3, D3), and send the latest version notification signal including the read version to the main device 11. The main device 11 checks the software version by receiving the version notification signal from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), or performs a rollback as needed.

[0383] Upon receiving the version notification signal from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), the main device 11 sends a power stop request to the power management ECU 20, causing the ECU to be rewritten (ID1), the ECU to be rewritten (ID2), and other ECUs to transition from the startup state to the stop state or the sleep state (X2).

[0384] The main device 11 sends the latest version notification signal to the central device 3. Upon receiving the latest version notification signal from the main device 11, the central device 3 determines the latest version of the application programs of the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) based on the received latest version notification signal, and notifies the determined latest version to the mobile terminal 6. If the mobile terminal 6 is notified of the latest version by the central device 3, a latest version notification screen indicating the notified latest version is displayed on the mobile terminal 6 (A8). The user can confirm the latest version through the latest version notification screen displayed on the mobile terminal 6 and can confirm the gist of the activation completion.

[0385] Next, refer to Figure 26 to Figure 29A timing diagram of the operations of the DCM 12, CGW 13, and the ECU 19 to be rewritten in the case of a rewrite application program will be described. In addition, here, a case where the application program of the dual-sided memory ECU is rewritten while the IG switch 42 is turned on by a user operation, that is, while the vehicle can run, and the application programs of the single-sided suspended memory ECU and the single-sided separate memory ECU are rewritten during parking after the IG switch 42 is turned off by a user operation will be described. In addition, a case where the application program is rewritten by power control and a case where the application program is rewritten by power self-holding will be described.

[0386] (1) Case of Rewriting Application Program by Power Control

[0387] Refer to Fig.26 and Fig. 27 A case of rewriting an application program by power control will be described. The rewriting of the application program by power control refers to a configuration in which the rewrite operation is controlled according to the switching of the power supply without using a power self-holding circuit. When the user switches the IG switch from off to on and the vehicle power supply is switched from the +B power supply to the IG power supply, the DCM 12, CGW 13, dual-sided memory ECU, single-sided suspended memory ECU, and single-sided separate memory ECU each start normal operation (t1).

[0388] If notified of the start of download from the central device 3, the DCM 12 transfers from normal operation to download operation and starts downloading the distribution data packet from the central device 3 (t2). The DCM 12 can download the distribution data packet in the background while performing normal operation. When the DCM 12 finishes downloading the distribution data packet from the central device 3, it resumes from the download operation to normal operation (t3).

[0389] If notified of a rewrite instruction signal (installation instruction signal) from the central device 3 or CGW 13, the DCM 12 transfers from normal operation to data transfer / central communication operation and starts the data transfer / central communication operation (t4). That is, the DCM 12 extracts the write data from the distribution data packet, starts transmitting the write data to the CGW 13, and obtains the progress of the rewrite from the CGW 13 and starts notifying the central device 3 of the progress of the rewrite.

[0390] When the CGW 13 starts obtaining the write data from the DCM 12, it transfers from normal operation to recompilation operation, starts the recompilation operation, starts distributing the write data to the dual-sided memory ECU, and instructs the writing of the write data. When the dual-sided memory ECU starts receiving the write data from the CGW 13, it starts the programming phase (hereinafter, also referred to as the installation phase) during normal operation. That is, the dual-sided memory ECU installs the application program in the background while performing normal operation. The dual-sided memory ECU starts writing the received write data to the flash memory and starts rewriting the application program.

[0391] During the period of rewriting the application program in the dual-sided memory ECU, if the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from ON to OFF, the DCM12 interrupts the data transmission / center communication operation, the CGW13 interrupts the reprogramming operation, the dual-sided memory ECU interrupts the installation stage, and interrupts the rewriting of the application program (t5).

[0392] Then, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the DCM12 starts the data transmission / center communication operation again, the CGW13 starts the reprogramming operation again, the dual-sided memory ECU starts the installation stage again, and starts the rewriting of the application program again (t6). That is, by the user switching the IG switch from ON to OFF and the vehicle power supply is switched from the IG power supply to the +B power supply, and then, by the user switching the IG switch from OFF to ON and the vehicle power supply is switched from the +B power supply to the IG power supply, every time a trip occurs, the dual-sided memory ECU repeats the interruption and restart of the rewriting of the application program (t7, t8).

[0393] If the dual-sided memory ECU finishes writing the data and finishes rewriting the application program, it ends the installation stage and transfers from the normal operation to the waiting for activation. That is, when the activation stage is not performed, the dual-sided memory ECU does not start on the new side (B side) where the application program has been rewritten, and keeps starting on the old side (A side) (t9).

[0394] After the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from ON to OFF (t10), if the dual-sided memory ECU finishes rewriting the application program at this time, the CGW13 sends a power start request to the power management ECU20. If the vehicle power supply is switched from the +B power supply to the IG power supply by the CGW13 sending a power start request to the power management ECU20, the DCM12 starts the data transmission / center communication operation again, the CGW13 starts the reprogramming operation again, and starts distributing the written data to the single-sided suspended memory ECU and the single-sided independent memory ECU. If the single-sided suspended memory ECU and the single-sided independent memory ECU respectively start receiving the written data from the CGW13, they transfer from the normal operation to the boot process, and start the installation stage in the boot process (t11). That is, the single-sided suspended memory ECU and the single-sided independent memory ECU do not perform the installation in parallel with the normal operation, but perform the installation in the boot process where the application program does not operate.

[0395] If the single-sided suspended memory ECU starts rewriting the application program, when the IG switch 42 is switched from OFF to ON by a user operation before the rewriting of the application program is completed, the rewriting of the application program is interrupted. The single-sided suspended memory ECU restores the operating surface (A surface) as the start surface instead of the non-operating surface (B surface) where the rewriting of the application program has been interrupted. If the single-sided stand-alone memory ECU starts rewriting the application program, even if the IG switch 42 is switched from OFF to ON by a user operation before the rewriting of the application program is completed, the rewriting of the application program continues. This is because if the single-sided stand-alone memory ECU is interrupted during the rewriting of the application program, it cannot be restored to the normal operation. Preferably, after the single-sided stand-alone memory ECU starts rewriting the application program and before the rewriting of the application program is completed, the operation of the IG switch 42 by the user is invalidated.

[0396] If the single-sided suspended memory ECU finishes writing the write data and finishes rewriting the application program, it ends the installation phase in the boot process and transfers from the boot process to waiting for activation. That is, the single-sided suspended memory ECU does not start on the newly rewritten surface (B surface) when the activation phase has not been performed, and keeps starting on the old surface (A surface). If the single-sided stand-alone memory ECU finishes writing the write data and finishes rewriting the application program, it ends the installation phase in the boot process and becomes waiting for activation (t12).

[0397] If the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation instruction from the CGW 13, the double-sided memory ECU and the single-sided suspended memory ECU respectively perform the switching from the old surface to the new surface, start on the new surface, and start the post-programming phase (hereinafter, also referred to as the activation phase) during the start on the new surface. The single-sided stand-alone memory ECU starts to restart and starts the activation phase (t13, t14) during the restart after the installation is completed. During activation, confirmation of correct start by the new program, notification of version information to the CGW 13, etc. are performed.

[0398] If the activation is completed and the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation completion instruction from the CGW 13, the DCM 12 transfers from the data transmission / central communication operation to the sleep / stop operation and starts the sleep / stop operation. The CGW 13 transfers from the reprogramming active operation to the sleep / stop operation and starts the sleep / stop operation. The double-sided memory ECU, the single-sided suspended memory ECU, and the single-sided stand-alone memory ECU respectively transfer from the start on the new surface to the sleep / stop operation (t15).

[0399] After that, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the dual-sided memory ECU and the single-sided suspended memory ECU respectively set the new side (side B) as the startup side and start a new application program, and the single-sided separate memory ECU starts a new application program (t16).

[0400] (2) Case of rewriting the application program by power self-holding

[0401] Refer to Fig.28 and Fig.29 The case of rewriting the application program by power self-holding will be described. The rewriting of the application program by power self-holding refers to a configuration that controls the rewriting operation using a power self-holding circuit. If the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the DCM12, CGW13, dual-sided memory ECU, single-sided suspended memory ECU, and single-sided separate memory ECU respectively start normal operations (t21).

[0402] If notified of the start of download from the central device 3, that is, notified of an update based on a new program, the DCM12 transfers from normal operation to download operation and starts downloading the distribution data packet from the central device 3 (t22). If the DCM12 finishes downloading the distribution data packet from the central device 3, it resumes from the download operation to normal operation (t23).

[0403] If notified of a rewrite instruction signal (installation instruction signal) from the central device 3 or CGW13, the DCM12 transfers from normal operation to data transfer / central communication operation and starts the data transfer / central communication operation (t24). That is, the DCM12 extracts the write data from the distribution data packet, starts transmitting the write data to the CGW13, and obtains the progress of the rewrite from the CGW13 and starts notifying the central device 3 of the progress of the rewrite.

[0404] If the CGW13 starts obtaining the write data from the DCM12, it transfers from normal operation to the recompilation active operation, starts the recompilation active operation, starts distributing the write data to the dual-sided memory ECU, and instructs the writing of the write data. If the dual-sided memory ECU starts receiving the write data from the CGW13, it starts the programming stage (hereinafter, also referred to as the installation stage) during normal operation. That is, the dual-sided memory ECU installs the application program in the background while performing normal operations. The dual-sided memory ECU starts writing the received write data to the flash memory and starts rewriting the application program.

[0405] During the period of rewriting the application program in the dual-sided memory ECU, if the vehicle power supply is switched from the IG power supply to the +B power supply (t25) by the user switching the IG switch from ON to OFF, then immediately after the vehicle power supply is switched from the IG power supply to the +B power supply, DCM12 continues the data transmission / central communication operation, CGW13 continues the reprogramming active operation, the dual-sided memory ECU continues the installation stage, and continues the rewriting of the application program. If a preset time, i.e., the self-holding period, has elapsed since the vehicle power supply was switched from the IG power supply to the +B power supply, then DCM12 interrupts the data transmission / central communication operation, CGW13 interrupts the reprogramming active operation, the dual-sided memory ECU interrupts the installation stage, and interrupts the rewriting of the application program (t26). That is, before a specified time has elapsed since the IG switch 42 was turned OFF, the installation is continued by the power supply from the vehicle battery 40.

[0406] After that, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, then DCM12 starts the data transmission / central communication operation again, CGW13 starts the reprogramming active operation again, the dual-sided memory ECU starts the installation stage again, and starts the rewriting of the application program again (t27). That is, when the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from ON to OFF, and then the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, every time an open circuit occurs, the dual-sided memory ECU repeats the interruption and restart of the rewriting of the application program (t28 - t30). However, before the self-holding period has elapsed since the vehicle power supply was switched from the IG power supply to the +B power supply, DCM12 continues the data transmission / central communication operation, CGW13 continues the reprogramming active operation, the dual-sided memory ECU continues the installation stage, and continues the rewriting of the application program.

[0407] If the dual-sided memory ECU finishes writing the data and finishes rewriting the application program, it ends the installation stage and transfers from the normal operation to the waiting for activation. That is, when the dual-sided memory ECU is not in the activation stage, it does not start on the new side (B side) where the application program has been rewritten, and keeps the old side (A side) started (t31).

[0408] If the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from ON to OFF, and at this moment the rewriting of the application program is completed in the dual-sided memory ECU, then the single-sided suspended memory ECU and the single-sided separate memory ECU respectively transfer from the normal operation to the boot process, start the boot process, and start the installation stage in the boot process (t32).

[0409] If the single-sided suspended memory ECU and the single memory ECU each complete the writing of the written data and the rewriting of the application program, the installation phase (t33) ends in the boot process. If a power-on request is sent to the power management ECU 20 through CGW13 and the vehicle power supply is switched from the +B power supply to the IG power supply, the DCM12 starts the data transmission / central communication operation again (t34).

[0410] If the single-sided suspended memory ECU completes the writing of the written data and the rewriting of the application program, it transfers from the boot process to waiting for activation. That is, when the single-sided suspended memory ECU is not in the activation phase, it does not start on the new side (B side) where the application program has been rewritten and remains starting on the old side (A side). If the single-sided single memory ECU completes the writing of the written data and the rewriting of the application program, the installation phase ends in the boot process and it becomes waiting for activation (t35).

[0411] If the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation instruction from CGW13, the dual-sided memory ECU and the single-sided suspended memory ECU each perform the switch from the old side to the new side, start on the new side, and start the activation phase during the startup on the new side. The single-sided single memory ECU starts a restart and starts the activation phase during the restart after the installation is completed (t36, t37).

[0412] If the activation is completed and the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation completion instruction from CGW13, the DCM12 transfers from the data transmission / central communication operation to the sleep / stop operation and starts the sleep / stop operation. CGW13 transfers from the reprogramming active operation to the sleep / stop operation and starts the sleep / stop operation. The dual-sided memory ECU, the single-sided suspended memory ECU, and the single-sided single memory ECU each transfer from the startup on the new side to the sleep / stop operation (t38).

[0413] After that, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from off to on, the dual-sided memory ECU and the single-sided suspended memory ECU each use the new side (B side) as the startup side and start a new application program, and the single-sided single memory ECU starts a new application program (t39).

[0414] Before downloading and distributing the data packet from the central device 3 and before distributing it to the ECU 19 which is the object to be rewritten with the written data, CGW13 performs the following checks. Before downloading the data packet from the central device 3, CGW13 checks the radio wave environment, the remaining battery capacity of the vehicle battery 40, and the memory capacity of the DCM 12 so as to be able to perform the download normally. Before distributing to the ECU 19 which is the object to be rewritten with the written data, as a check for the manned environment to prevent the installation environment from becoming unstable, CGW13 performs detection of intrusion sensors, detection of vehicle locks, detection of curtains, and detection of IG disconnection. As a check on whether the ECU 19 which is the object to be rewritten can be written, CGW13 performs version and abnormality generation checks so as to be able to distribute the written data normally. In addition, as a check on the written data distributed to the ECU 19 which is the object to be rewritten, before starting the installation, CGW13 performs tampering check, access authentication, version check, etc. During the execution of the installation, CGW13 performs communication interruption check, abnormality generation check, etc. After the installation is completed, CGW13 performs version check, integrity check, DTC (Diagnostic Trouble Code) check, etc.

[0415] Next, refer to Figures 30 to 46 to explain the screen displayed on the display terminal 5. As Fig.30 shown, in the configuration where the application program of the ECU 19 which is the object to be rewritten is rewritten by OTA, there are stages of activity notification, download, installation, and activation. Activity notification means notification of program update. For example, receiving a judgment in the central device 3 that there is an update of the application program, and the main device 11 downloading and distributing specification data, etc. are activity notifications. The display terminal 5 displays screens in each stage as the rewriting of the application program progresses. In addition, here, the screen displayed on the in-vehicle display 7 is explained.

[0416] As Fig.31 shown, in the normal state before the activity notification, CGW13 causes a navigation screen 501 such as a well-known route guidance screen which is one of the navigation functions to be displayed on the in-vehicle display 7. If an activity notification occurs from this state, as Fig.32 shown, CGW13 causes an activity notification icon 501a indicating the occurrence of the activity notification to be displayed at the lower right of the navigation screen 501. By confirming the display of the activity notification icon 501a, the user can grasp the occurrence of the activity notification related to the update of the application program.

[0417] If the user operates the activity notification icon 501a from this state, then as Fig.33As shown, CGW13 causes the activity notification screen 502 to pop up and be displayed on the navigation screen 501. In addition, CGW13 is not limited to causing the activity notification screen 502 to pop up and display, and other display methods can also be adopted. In the activity notification screen 502, CGW13, for example, displays a guidance such as "There is a software update available" to notify the user of the generation of the activity notification, and causes the "Confirm" button 502a and the "Later" button 502b to be displayed, waiting for the user's operation. In this case, by operating the "Confirm" button 502a, the user can enter the next screen for starting the rewrite of the application. In addition, when the user operates the "Later" button 502b, CGW13 cancels the pop-up display of the activity notification screen 502 and returns to Fig.32 the screen showing the activity notification icon 501a as shown.

[0418] If the user operates the "Confirm" button 502a from this state, then as Fig.34 shown, CGW13 switches the display from the navigation screen 501 to the download consent screen 503 and causes the download consent screen 503 to be displayed on the in-vehicle display 7. In the download consent screen 503, CGW13 notifies the user of the activity ID and the update name, and causes the "Start Download" button 503a, the "Detailed Confirmation" button 503b, and the "Return" button 503c to be displayed, waiting for the user's operation. In this case, by operating the "Start Download" button 503a, the user can start the download. By operating the "Detailed Confirmation" button 503b, the user can view the details of the download. By operating the "Return" button 503c, the user can reject the download and return to the previous screen. When the "Return" button 503c is operated, and the user operates the activity notification icon 501a, the user can enter the screen for starting the download.

[0419] If the user operates the "Detailed Confirmation" button 503b from the state where the download consent screen 503 is displayed, then as Fig.35 shown, CGW13 switches the display content of the download consent screen 503 and causes the details of the download to be displayed on the in-vehicle display 7. As the details of the download, CGW13 uses the received distribution specification data to display the update content, the update time required, the restrictions on vehicle functions accompanying the update, etc. In addition, if the user operates the "Start Download" button 503a, CGW13 starts the download of the data packet via DCM12. In parallel with starting the download of the data packet, as Fig.36 shown, CGW13 switches the display from the download consent screen 503 to the navigation screen 501, causes the navigation screen 501 to be displayed on the in-vehicle display 7 again, and causes the download in progress icon 501b indicating that the download is in progress to be displayed in the lower right of the navigation screen 501. By confirming the display of the download in progress icon 501b, the user can grasp that the download of the data packet is in progress.

[0420] If the user operates the download in progress icon 501b from this state, then as Fig.37 shown, CGW13 will switch the display from the navigation screen 501 to the download in progress screen 504, and cause the download in progress screen 504 to be displayed on the in-vehicle display 7. In the download in progress screen 504, CGW13 notifies the user that the download is in progress, and causes the "Detailed Confirmation" button 504a, "Return" button 504b, and "Cancel" button 504c to be displayed, waiting for the user's operation. In this case, by operating the "Detailed Confirmation" button 504a, the user can display the details of the download in progress, and by operating the "Cancel" button 504c, the user can interrupt the download.

[0421] If CGW13 completes the download, then as Fig.38 shown, it causes the download completion notification screen 505 to pop up and be displayed on the navigation screen 501. In the download completion notification screen 505, CGW13 notifies the user of the completion of the download by, for example, displaying a guidance such as "The download has been completed. Software update can be performed", and causes the "Confirmation" button 505a and "Later" button 505b to be displayed, waiting for the user's operation. In this case, by operating the "Confirmation" button 505a, the user can enter the screen for starting the installation.

[0422] If the user operates the "Confirmation" button 505a from this state, then as Fig.39 shown, CGW13 will switch the display from the navigation screen 501 to the installation consent screen 506, and cause the installation consent screen 506 to be displayed on the in-vehicle display 7. In the installation consent screen 506, CGW13 notifies the user of the required time, restrictions, and schedule settings related to the installation, and causes the "Update Immediately" button 506a, "Schedule Update" button 506b, and "Return" button 506c to be displayed, waiting for the user's operation. In this case, the user can start the installation immediately by operating the "Update Immediately" button 506a. In addition, by setting the desired time for the installation to be executed and operating the "Schedule Update" button 506b, the user can start the installation in a scheduled manner. In addition, by operating the "Return" button 506c, the user can reject the installation and return to the previous screen. In the case where the "Return" button 506c is operated, and the user operates the download in progress icon 501b, the user can enter the screen for starting the installation.

[0423] If the user operates the "Update Immediately" button 506a from this state, then as Fig.40 shown, CGW13 switches the display content of the installation consent screen 506, and causes the details of the installation to be displayed on the in-vehicle display 7. In the installation consent screen 506 here, CGW13 notifies the user of the main idea of accepting the installation request and starting the installation.

[0424] If CGW13 starts installation, as shown Fig.41 below, the display will switch from the installation consent screen 506 to the navigation screen 501, causing the navigation screen 501 to be displayed again on the in-vehicle display 7, and causing the installation-in-progress icon 501c indicating that installation is in progress to be displayed in the lower right of the navigation screen 501. By confirming the display of the installation-in-progress icon 501c, the user can grasp that installation is in progress.

[0425] If the user operates the installation-in-progress icon 501c from this state, as shown Fig.42 below, CGW13 will switch the display from the navigation screen 501 to the installation-in-progress screen 507, causing the installation-in-progress screen 507 to be displayed on the in-vehicle display 7. CGW13 notifies the user that installation is in progress on the installation-in-progress screen 507. CGW13 may also, for example, display the remaining required time for installation and the percentage of progress on the installation-in-progress screen 507.

[0426] If CGW13 completes installation, as shown Fig.43 below, the display will switch from the navigation screen 501 to the activation consent screen 508, causing the activation consent screen 508 to be displayed on the in-vehicle display 7. On the activation consent screen 508, CGW13 notifies the user of the content of activation and causes the "Back" button 508a and the "OK" button 508b to be displayed, waiting for the user's operation. In this case, the user can reject activation and return to the previous screen by operating the "Back" button 508a. In addition, the user can consent to activation by operating the "OK" button 508b. Furthermore, in the case where the "Back" button 508a has been operated, and the user operates the installation-in-progress icon 501c, the user can enter the screen for performing activation. In addition, regarding these displays and consents, it is also possible to omit them without display according to the user's settings and the scenarios of the program.

[0427] If the user turns on the IG power in the state after the user has operated the "OK" button 508b, as shown Fig.44 below, CGW13 causes the activation completion notification screen 509 to pop up and be displayed on the navigation screen 501. On the activation completion notification screen 509, CGW13 notifies the user of the completion of activation by, for example, displaying a guidance of "Software update completed", and causes the "OK" button 509a and the "Detailed confirmation" button 509b to be displayed, waiting for the user's operation. In this case, the user can cancel the pop-up display of the activation completion notification screen 509 by operating the "OK" button 509a, and can display the details of the completion of activation by operating the "Detailed confirmation" button 509b.

[0428] If the user operates the "OK" button 509a from this state, as shown Fig.45As shown, CGW13 will switch the display from the navigation screen 501 to the confirmation operation screen 510, and display the confirmation operation screen 510 on the in-vehicle display 7. In the confirmation operation screen 510, CGW13 notifies the user of the activation completion, and displays the "Detailed Confirmation" button 510a and the "OK" button 510b, waiting for the user's operation. In this case, by operating the "Detailed Confirmation" button 510a, the user can view the detailed activation completion.

[0429] If the user operates the "Detailed Confirmation" button 510a from this state, then as Fig.46 shown, CGW13 switches the display content of the confirmation operation screen 510, and displays the detailed activation completion on the in-vehicle display 7. CGW13 displays the updated functions, changed functions, etc. as the update details, and also displays the "OK" button 510b. CGW13 determines that the user has confirmed the software update completion based on the user's operation of the "OK" buttons 509a and 510b.

[0430] As described above, the vehicle-side system 4 controls each action stage such as the activity notification, download, installation, activation, and update completion, and presents a display matching each action stage to the user. In addition, in the above description, it is configured that CGW13 performs the display control, but it can also be configured that the in-vehicle display 7 receives the action stage and the distribution specification data from CGW13 and performs the display.

[0431] Next, refer to Figure 47 to Figure 233 to describe the characteristic processing performed by the vehicle program rewriting system 1. The vehicle program rewriting system 1 performs the following characteristic processing.

[0432] (1) Transmission determination processing of the distribution data packet

[0433] (2) Download determination processing of the distribution data packet

[0434] (3) Transmission determination processing of the written data

[0435] (4) Acquisition determination processing of the written data

[0436] (5) Installation instruction determination processing

[0437] (6) Management processing of the security access key

[0438] (7) Verification processing of the written data

[0439] (8) Transmission control processing of the data storage surface information

[0440] (9) Power management processing of the non-rewrite object

[0441] (10) File transmission control processing

[0442] (11) Distribution control processing for writing data

[0443] (12) Indication processing for activation request

[0444] (13) Execution control processing for activation

[0445] (14) Group management processing for rewrite objects

[0446] (15) Execution control processing for rollback

[0447] (16) Display control processing for rewrite progress status

[0448] (17) Matching determination processing for differential data

[0449] (18) Execution control processing for rewrite

[0450] (19) Session establishment processing

[0451] (20) Determination processing for retry points

[0452] (21) Synchronization control processing for progress status

[0453] (22) Transmission control processing for display control information

[0454] (23) Reception control processing for display control information

[0455] (24) Screen display control processing for progress display

[0456] (25) Report control processing for program update

[0457] (26) Execution control processing for power self-holding

[0458] The central device 3, DCM 12, CGW 13, ECU 19, and in-vehicle display 7 respectively have the following functional modules as the components for performing the characteristic processing of the above (1) to (26).

[0459] As Fig.47As shown, the central device 3 has a distribution data packet transmission unit 51. If the distribution data packet transmission unit 51 receives a download request for a distribution data packet from the DCM 12, it transmits the distribution data packet to the DCM 12. As a configuration for performing characteristic processing, in addition to the above configuration, the central device 3 further has a transmission determination unit 52 for distribution data packets, a synchronization control unit 53 for progress status, a transmission control unit 54 for display control information, and a write data selection unit 55 (equivalent to an update data selection unit). If the write data selection unit 55 (equivalent to the update data selection unit) receives data storage surface information from the master device 11, it selects write data suitable for the non-operating surface based on the software version and the operating surface determined according to the received data storage surface information. That is, the distribution data packet transmission unit 51 transmits a distribution data packet including the write data selected by the write data selection unit 55 to the DCM 12. The functional modules for performing characteristic processing will be described later.

[0460] As Fig.48 shown, the DCM 12 has a download request transmission unit 61, a distribution data packet download unit 62, a write data extraction unit 63, a write data transmission unit 64, a rewrite specification data extraction unit 65, and a rewrite specification data transmission unit 66. The download request transmission unit 61 transmits a download request for a distribution data packet to the central device 3. The distribution data packet download unit 62 downloads a distribution data packet from the central device 3. If a distribution data packet is downloaded from the central device 3 by the distribution data packet download unit 62, the write data extraction unit 63 extracts write data from the downloaded distribution data packet.

[0461] If write data is extracted from the distribution data packet by the write data extraction unit 63, the write data transmission unit 64 transmits the extracted write data to the CGW 13. If a distribution data packet is downloaded from the central device 3 by the distribution data packet download unit 62, the rewrite specification data extraction unit 65 extracts rewrite specification data from the downloaded distribution data packet. If rewrite specification data is extracted from the distribution data packet by the rewrite specification data extraction unit 56, the rewrite specification data transmission unit 66 transmits the extracted rewrite specification data to the CGW 13. As a configuration for performing characteristic processing, in addition to the above configuration, the DCM 12 further has a download determination unit 67 for distribution data packets and a transmission determination unit 68 for write data. The functional modules for performing characteristic processing will be described later.

[0462] As Fig.49 and Fig.50As shown in the figure, CGW13 has a request sending unit 71 for acquisition, a write data acquisition unit 72 (equivalent to an update data storage unit), a write data distribution unit 73 (equivalent to an update data distribution unit), a rewrite specification data acquisition unit 74, and a rewrite specification data analysis unit 75. The write data acquisition unit 72 acquires write data from DCM12 when the write data is transmitted from DCM12. When the write data is acquired by the write data acquisition unit 72 and it becomes the distribution timing of the write data, the write data distribution unit 73 distributes the acquired write data to the ECU19 to be rewritten. The rewrite specification data acquisition unit 74 acquires rewrite specification data from DCM12 when the rewrite specification data is transmitted from DCM12. When the rewrite specification data is acquired by the rewrite specification data acquisition unit 74, the rewrite specification data analysis unit 75 analyzes the acquired rewrite specification data.

[0463] As a configuration for performing characteristic processing, in addition to the above configuration, CGW13 also has a write data acquisition determination unit 76, an installation instruction determination unit 77, a security access key management unit 78, a write data verification unit 79, a data storage surface information transmission control unit 80, a power management unit 81 for non-rewrite objects, a file transmission control unit 82, a write data distribution control unit 83, an activation request instruction unit 84, a rewrite object group management unit 85, a rollback execution control unit 86, a rewrite progress status display control unit 87, a progress status synchronization control unit 88, a display control information reception control unit 89, a progress display screen display control unit 90, a program update report control unit 91, and a power self-holding execution control unit 92. The functional modules for performing characteristic processing will be described later.

[0464] As Fig.51 shown in the figure, ECU19 has a write data reception unit 101 and a program rewrite unit 102. The write data reception unit 101 receives write data from CGW13. When the write data is received from CGW13 by the write data reception unit 101, the program rewrite unit 102 writes the received write data into the flash memory to rewrite the application program. As a configuration for performing characteristic processing, in addition to the above configuration, ECU19 also has a differential data matching determination unit 103, a rewrite execution control unit 104, a session establishment unit 105, a retry point determination unit 106, an activation execution control unit 107, and a power self-holding execution control unit 108. The functional modules for performing characteristic processing will be described later.

[0465] As Fig.52 shown in the figure, the in-vehicle display 7 has a reception control unit 111 for distribution specification data. The reception control unit 111 for distribution specification data controls the reception of distribution specification data.

[0466] Hereinafter, each of the processes (1) to (26) described above will be described in sequence.

[0467] (1) Transmission determination process for distribution data packets, (2) Download determination process for distribution data packets

[0468] Refer to Fig.53 and Fig.54 Regarding the transmission determination process reference for distribution data packets in the central device 3, refer to Fig.55 and Fig.56 Describe the download determination process for distribution data packets in the main device 11.

[0469] As Fig.53 shown, the central device 3 has a software information acquisition unit 52a, an update presence determination unit 52b, an update suitability determination unit 52c, and an activity information transmission unit 52d in the transmission determination unit 52 for distribution data packets. The software information acquisition unit 52a acquires the software information of each ECU 19 from the vehicle side. Specifically, the software information acquisition unit 52a acquires the ECU structure information including software information such as version and writing surface and hardware information from the vehicle side. The software information acquisition unit 52a may also acquire vehicle status information such as fault codes, settings of anti-theft alarm functions, and license agreement information from the vehicle side together with these ECU structure information.

[0470] If the software information is acquired by the software information acquisition unit 52a, the update presence determination unit 52b determines whether there is update data for the vehicle based on the acquired software information. That is, the update presence determination unit 52b compares the version of the acquired software information with the version of the latest software information managed by itself, determines whether the two are the same, and determines whether there is update data for the vehicle. If the update presence determination unit 52b determines that the two are the same, it determines that there is no update data for the vehicle, and if it determines that the two are different, it determines that there is update data for the vehicle.

[0471] If the update presence determination unit 52b determines that there is update data for the vehicle, the update suitability determination unit 52c determines whether the vehicle status is a status suitable for updating programs such as distribution data packets. Specifically, the update suitability determination unit 52c determines whether the license agreement is established, whether the vehicle position is within a specified range pre-registered by the user, whether the setting of the vehicle's alarm function is valid, and whether fault information of the ECU 19 is generated, and determines whether the vehicle status is a status suitable for downloading distribution data packets. That is, the update suitability determination unit 52c determines whether the vehicle has a possibility of an update that violates the user's intention and whether the vehicle has a possibility of failure during installation after downloading even if the download is successful.

[0472] When the update suitability determination unit 52c determines that the license agreement is established, the vehicle position is within the specified range pre-registered by the user, the setting of the vehicle's alarm function is validated, and no fault information of the ECU 19 has occurred, it determines that the vehicle state is suitable for updating programs such as the distributed data packet. When the update suitability determination unit 52c determines that at least any one of the license agreement is not established, the vehicle position is not within the specified range pre-registered by the user, the setting of the vehicle's alarm function is not validated, and fault information of the ECU 19 has occurred, it determines that the vehicle state is not suitable for updating programs such as the distributed data packet.

[0473] If the update suitability determination unit 52c determines that the vehicle state is suitable for updating programs such as the distributed data packet, the activity information transmission unit 52d transmits the activity information to the main device 11. If the update suitability determination unit 52c determines that the vehicle state is not suitable for updating programs such as the distributed data packet, the activity information transmission unit 52d does not transmit the activity information to the main device 11. By making the above determination, the activity information transmission unit 52d pre-stores information related to the vehicle for which the activity information has not been transmitted to the main device 11. In addition, information related to the vehicle for which the activity information has not been transmitted to the main device 11 may also be displayed on the central device 3.

[0474] Next, refer to Fig.54 The operation of the distributed data packet transmission determination unit 52 in the central device 3 will be described. The central device 3 executes a distributed data packet transmission determination program and performs a distributed data packet transmission determination process.

[0475] When the central device 3 starts the distributed data packet transmission determination process, it acquires software information from the vehicle side (S101, equivalent to the software information acquisition step). That is, the central device 3 determines whether there is a software update for the vehicle. The central device 3 determines whether there is update data for the vehicle based on the acquired software information (S102, equivalent to the update presence determination step). If the central device 3 determines that there is update data for the vehicle (S102: Yes), it determines whether the vehicle state is suitable for updating programs such as the distributed data packet (S103, equivalent to the update suitability determination step). If the central device 3 determines that the vehicle state is suitable for updating programs such as the distributed data packet (S103: Yes), it transmits the activity information to the main device 11 (S104, equivalent to the activity information transmission step) and ends the distributed data packet transmission determination process.

[0476] If the central device 3 determines that there is no update data for the vehicle (S102: No), it sends the gist that it is not the transmission target of the distribution data packet, that is, the gist that there is no update of the application program, to the host device 11 (S105), and ends the transmission determination process of the distribution data packet. If the central device 3 determines that the vehicle state is not a state suitable for updating a program or the like using the distribution data packet (S103: No), it sends the gist that the update of the program or the like is not suitable and the reason therefor to the host device 11 (S106), and ends the transmission determination process of the distribution data packet. In this case, the host device 11 displays the gist that the update of the program or the like is not suitable and the reason therefor on the in-vehicle display 7. For example, if the license agreement is not established, the host device 11 displays, for example, "The program cannot be updated due to invalid license. Please consult the dealer." on the in-vehicle display 7. Thus, the reason for the gist that the update of the program or the like is not suitable can be presented to the user, and appropriate information can be presented to the user.

[0477] As described above, the central device 3 can determine whether it is a state suitable for updating a program or the like using the distribution data packet by performing the transmission determination process of the distribution data packet before sending the distribution data packet to the host device 11 and before sending the activity information. Moreover, the central device 3 can send the activity information to the host device 11 only when it determines that it is a state suitable for updating a program or the like using the distribution data packet in order to send the distribution data packet to the host device 11.

[0478] As a case of updating a program or the like suitable for using the distribution data packet, when the license agreement is established, the vehicle position is within a specified range pre-registered by the user, the setting of the vehicle alarm function is validated, and no fault information of the ECU 19 is generated, the central device 3 can send the activity information to the host device 11. That is, the central device 3 can avoid the situation of sending the activity information to the host device 11 when the license agreement is not established, or the vehicle position is outside the specified range such as a position far from home, or the setting of the vehicle alarm function is invalidated, or fault information of the ECU 19 is generated. In this way, for a vehicle that may have an update contrary to the user's intention or a vehicle that may fail during installation even if the download is successful, the central device 3 can refrain from sending the activity information to the host device 11.

[0479] In addition, the central device 3 can also perform a transmission determination process for the distribution data packet during the transmission of the distribution data packet. In this case, if the central device 3 determines during the transmission of the distribution data packet that the vehicle state is a state suitable for updating a program or the like using the distribution data packet, the transmission of the distribution data packet continues. However, if the central device 3 determines during the transmission of the distribution data packet that the vehicle state is not a state suitable for updating a program or the like using the distribution data packet, the transmission of the distribution data packet is interrupted. That is, if a fault message of the ECU 19 is generated during the transmission of the distribution data packet, for example, the central device 3 interrupts the transmission of the distribution data packet.

[0480] Next, the processing of the master device 11 that receives the activity information transmitted from the central device 3 will be described. Refer to Fig.55 and Fig.56 The download determination process for the distribution data packet in the master device 11 will be described. The vehicle program rewriting system 1 performs the download determination process for the distribution data packet in the master device 11. The above-mentioned (1) transmission determination process for the distribution data packet is a determination process performed by the central device 3 in the activity notification stage before the download stage, but the download determination process for the distribution data packet is a determination process performed by the master device 11 in the download stage. In addition, in the present embodiment, the case where the DCM 12 performs the download determination process for the distribution data packet in the master device 11 will be described. However, the CGW 13 may have the function of the DCM 12, so that the CGW 13 performs the download determination process for the distribution data packet.

[0481] As Fig.55 shown, the DCM 12 includes an activity information receiving unit 67a, a downloadable determination unit 67b, and a download execution unit 67c in the download determination unit 67 for the distribution data packet. The activity information receiving unit 67a receives the activity information from the central device 3. In addition, if the activity information is received from the central device 3, the Fig.32 shown activity notification icon 501a is displayed. If the activity information is received by the activity information receiving unit 67a, the downloadable determination unit 67b determines whether the vehicle state is a state in which the distribution data packet can be downloaded. That is, the downloadable determination unit 67b determines whether the radio wave environment for communicating with the central device 3 is good, whether the battery remaining capacity of the vehicle battery 40 is equal to or greater than the specified capacity, and whether the memory free capacity of the DCM 12 is equal to or greater than the specified capacity, and determines whether the vehicle state is a state in which the distribution data packet can be downloaded.

[0482] If the downloadable determination unit 67b determines that the radio wave environment is good, the remaining battery capacity of the vehicle battery 40 is equal to or greater than the specified capacity, and the free capacity of the memory of the DCM 12 is equal to or greater than the specified capacity, it determines that the vehicle state is a state in which the distribution data packet can be downloaded. If the downloadable determination unit 67b determines that at least any one of the radio wave environment is not good, the remaining battery capacity of the vehicle battery 40 is not equal to or greater than the specified capacity, and the free capacity of the memory of the DCM 12 is not equal to or greater than the specified capacity, it determines that the vehicle state is not a state in which the distribution data packet can be downloaded.

[0483] In this way, the downloadable determination unit 67b determines whether there is a possibility that the download cannot be completed normally. In addition, the determination of the downloadable determination unit 67b is made on the condition that the "download start" button 503a is operated by the user in the download consent screen 503 shown in Fig.34 and Fig.35 . Further, the downloadable determination unit 67b may be configured to also determine the determination items in the center device 3. That is, the downloadable determination unit 67b determines that it is a downloadable state when, for example, the setting of the alarm function of the vehicle is validated and no failure information of the ECU 19 is generated.

[0484] If the downloadable determination unit 67b determines that the vehicle state is a state in which the distribution data packet can be downloaded, the download execution unit 67c downloads the distribution data packet from the center device 3. That is, after confirming that the download can be completed normally, the download execution unit 67c executes the download of the distribution data packet.

[0485] If the downloadable determination unit 67b determines that the vehicle state is not a state in which the distribution data packet can be downloaded, the download execution unit 67c does not download the distribution data packet from the center device 3. That is, when there is a possibility that the download cannot be completed normally, the download execution unit 67c does not execute the download of the distribution data packet. In this case, the download execution unit 67c instructs the in-vehicle display 7 to display a pop-up screen on the navigation screen 501 indicating the gist and reason for not being able to start the download.

[0486] Next, the operation of the distribution data packet download determination unit 67 in the main device 11 will be described with reference to Fig.56 . The main device 11 executes a distribution data packet download determination program and performs a distribution data packet download determination process.

[0487] When the main device 11 starts the download determination process for distributing data packets, it receives activity information from the central device 3 (S201, corresponding to the activity information reception step). The main device 11 determines whether the vehicle state is a state in which the distributed data packets can be downloaded (S202, corresponding to the downloadable determination step). If the main device 11 determines that the vehicle state is a state in which the distributed data packets can be downloaded (S202: Yes), it downloads the distributed data packets corresponding to the activity from the central device 3 (S203, corresponding to the download execution step), and ends the download determination process for the distributed data packets. If the main device 11 determines that the vehicle state is not a state in which the distributed data packets can be downloaded (S202: No), it does not download the distributed data packets from the central device 3 and ends the download determination process for the distributed data packets.

[0488] As described above, the main device 11 can determine whether the vehicle state is a state in which the distributed data packets can be downloaded by performing the download determination process for the distributed data packets before downloading the distributed data packets from the central device 3. Moreover, the main device 11 can download the distributed data packets only when the vehicle state is a state in which the distributed data packets can be downloaded.

[0489] As a case suitable for downloading the distributed data packets, when the radio wave environment is good, the battery remaining capacity of the vehicle battery 40 is equal to or more than the specified capacity, and the free capacity of the memory of the DCM 12 is equal to or more than the specified capacity, the main device 11 can download the distributed data packets from the central device 3. That is, it is possible to avoid the situation of downloading the distributed data packets from the central device 3 when the radio wave environment is not good, or the battery remaining capacity of the vehicle battery 40 is less than the specified capacity, or the free capacity of the memory of the DCM 12 is less than the specified capacity.

[0490] In addition, the main device 11 may perform the download determination process for the distributed data packets during the download of the distributed data packets. In this case, if the main device 11 determines during the download of the distributed data packets that the vehicle state is a state in which the distributed data packets can be downloaded, it continues to download the distributed data packets from the central device 3, but if it determines during the download of the distributed data packets that the vehicle state is not a state in which the distributed data packets can be downloaded, it interrupts the download of the distributed data packets from the central device 3. That is, if, for example, the radio wave environment is not good, or the battery remaining capacity of the vehicle battery 40 is less than the specified capacity, or the free capacity of the memory of the DCM 12 is less than the specified capacity during the download of the distributed data packets, the main device 11 interrupts the download of the distributed data packets.

[0491] In this way, by determining in the central device 3 whether there is a vehicle that may be updated against the user's intention or a vehicle that may have an installation failure, and determining in the main device 11 whether there is a possibility of a download failure, it is possible to suppress the transmission of unnecessary activity information or distributed data packets from the central device 3 to the main device 11.

[0492] The central device 3 has the following configuration. It includes: a software information acquisition unit 52a that acquires software information of the electronic control device from the vehicle side; an update presence determination unit 52b that determines whether there is update data for the vehicle based on the software information acquired by the software information acquisition unit; an update suitability determination unit 52c that determines whether the vehicle state is a state suitable for update when the update presence determination unit determines that there is update data; and an activity information transmission unit 52d that transmits activity information related to the update to the vehicle main device when the update suitability determination unit determines that the vehicle state is a state suitable for update.

[0493] The main device 11 has the following configuration. It includes: an activity information reception unit 67a that receives activity information from the central device; a downloadable determination unit 67b that determines whether the vehicle state is a state capable of downloading a distribution data packet when the activity information reception unit receives the activity information; and a download execution unit 67c that downloads the distribution data packet from the central device when the downloadable determination unit determines that the vehicle state is a state capable of downloading the distribution data packet.

[0494] (3) Transmission determination process for write data, (4) Acquisition determination process for write data, (5) Installation instruction determination process

[0495] Refer to Fig.57 And Fig.58 For the description of the transmission determination process for write data, refer to Fig.59 And Fig.60 For the description of the acquisition determination process for write data, refer to Figure 61 to Figure 64 Describe the installation instruction determination process. The vehicle program rewriting system 1 performs the transmission determination process for write data in the DCM 12. Here, it is assumed that the distribution data packet sent from the central device 3 to the DCM 12 is unpacked and the write data is extracted from the distribution data packet.

[0496] As Fig.57As shown, DCM12 has an acquisition request receiving unit 68a and a communication status determination unit 68b in the write data transmission determination unit 68. The acquisition request receiving unit 68a receives an acquisition request for write data from CGW13. If the acquisition request receiving unit 68a receives an acquisition request for write data, the communication status determination unit 68b determines the data communication status between the central device 3 and DCM12, for example, when the transmission permission determination flag preset by the user is the first specified value. The transmission permission determination flag is 1 (the first specified value) when the specified conditions are checked during installation, and 0 (the second specified value) when the check is omitted. The write data transmission unit 64 transmits the write data to CGW13 on the condition that the communication status determination unit 68b determines that the data communication between the central device 3 and DCM12 is in a connected state.

[0497] Next, refer to Fig.58 The operation of the write data transmission determination unit 68 in DCM12 will be described. DCM12 executes a write data transmission determination program to perform write data transmission determination processing. Here, the processing in the case where CGW13 requests to acquire write data from DCM12 according to an installation instruction from the central device 3 will be described.

[0498] If DCM12 determines that it has received an acquisition request for write data from CGW13, it starts the write data transmission determination processing. If DCM12 starts the write data transmission determination processing, it determines the transmission permission determination flag (S301, S302). If DCM12 determines that the transmission permission determination flag is the first specified value (S301: Yes), it determines the data communication status between the central device 3 and itself (S303). If DCM12 determines that the data communication between the central device 3 and itself is in a connected state (S303: Yes), it transmits the write data to CGW13 (S304) and ends the write data transmission determination processing. If DCM12 determines that the data communication between the central device 3 and itself is not in a connected state but in an interrupted state (S303: No), it does not transmit the write data to CGW13 and ends the write data transmission determination processing.

[0499] In addition, if DCM12 determines that the transmission permission determination flag is the second specified value (S302: Yes), it transmits the write data to CGW13 without determining the data communication status between the central device 3 and itself and ends the write data transmission determination processing.

[0500] As described above, DCM12 determines the state of data communication between the central device 3 and itself when the transmission permission determination flag is the first specified value by performing a transmission determination process for write data before transmitting the write data to CGW13. If DCM12 determines that the data communication is in a connected state, it starts transmitting the write data. If it determines that the data communication is in an interrupted state, it does not start transmitting the write data and stands by. In a situation where data communication with the central device 3 is possible, the write data can be transmitted to CGW13 and installation can be executed in the ECU 19 to be rewritten.

[0501] For example, when there are multiple ECUs 19 to be rewritten and the installation takes time, the progress of the installation can be notified from the in-vehicle system 4 to the central device 3, and the progress can be displayed one by one on the mobile terminal 6. In addition, DCM12 can also perform a transmission determination process for write data during the transmission of the write data. In this case, if DCM12 determines that the data communication is in a connected state during the transmission of the write data, it continues to transmit the write data. However, if it determines that the data communication is in an interrupted state during the transmission of the write data, it interrupts the transmission of the write data.

[0502] Next, the acquisition determination process for write data will be described. The vehicle program rewriting system 1 performs an acquisition determination process for write data in CGW13. The above-mentioned (3) transmission determination process for write data is a determination process performed by DCM12 at the installation stage, and the acquisition determination process for write data is a determination process performed by CGW13 at the same installation stage.

[0503] As Fig.59 shown, CGW13 has an event generation determination unit 76a and a communication state determination unit 76b in the write data acquisition determination unit 76. The event generation determination unit 76a determines the generation of an event of a write data acquisition request (installation instruction) from the central device 3. If the event generation determination unit 76a determines that the event of the write data acquisition request has occurred, the communication state determination unit 76b determines the state of data communication between the central device 3 and DCM12, for example, when the acquisition permission determination flag preset by the user is the first specified value. The acquisition permission determination flag is 1 (the first specified value) when specified conditions are checked during installation, and 0 (the second specified value) when the check is omitted. Here, the event generation determination unit 76a can also determine the event generation based on the user instructing installation. For example, if it receives a notification that the user has performed an installation instruction operation through the in-vehicle display 7 (refer to Fig.39 ), it determines that the event of the write data acquisition request has occurred.

[0504] Next, refer to Fig.60The function of the write data acquisition determination unit 76 in the CGW13 will be described. The CGW13 executes a write data acquisition determination program to perform write data acquisition determination processing.

[0505] If the CGW13 determines that an event of a write data acquisition request has occurred, it starts the write data acquisition determination processing. If the CGW13 starts the write data acquisition determination processing, it determines the acquisition permission determination flag (S401, S402). If the CGW13 determines that the acquisition permission determination flag is the first specified value (S401: Yes), it determines the data communication state between the central device 3 and the DCM12 (S403). If the CGW13 determines that the data communication between the central device 3 and the DCM12 is connected (S403: Yes), it sends a write data acquisition request to the DCM12 (S404) and ends the write data acquisition determination processing. After that, if the CGW13 receives write data transmitted from the DCM12, it distributes the transmitted write data to the ECU 19 to be rewritten. If the CGW13 determines that the data communication between the central device 3 and the DCM12 is not connected but interrupted (S403: No), it does not send a write data acquisition request to the DCM12 and ends the write data acquisition determination processing.

[0506] In addition, if the CGW13 determines that the acquisition permission determination flag is the second specified value (S402: Yes), it sends a write data acquisition request to the DCM12 without determining the data communication state between the central device 3 and the DCM12 and ends the write data acquisition determination processing.

[0507] As described above, the CGW13 performs write data acquisition determination processing before acquiring write data from the DCM12 to determine the data communication state between the central device 3 and the DCM12 when the acquisition permission determination flag is the first specified value. If the CGW13 determines that the data communication is in a connected state, it starts acquiring write data. If it determines that the data communication is in an interrupted state, it does not start acquiring write data and waits. In a situation where communication with the central device 3 can be performed, write data can be acquired from the DCM12 and installation can be executed in the ECU 19 to be rewritten.

[0508] For example, when there are multiple ECUs 19 to be rewritten and the installation takes time, the progress of the installation can be notified from the in-vehicle system 4 to the central device 3, and the progress can be displayed one by one on the mobile terminal 6. In addition, the CGW13 can also perform write data acquisition determination processing during the acquisition of write data. In this case, if it is determined that the data communication is in a connected state during the acquisition of write data, the CGW13 continues to acquire write data. However, if it is determined that the data communication is in an interrupted state during the acquisition of write data, the CGW13 interrupts the acquisition of write data.

[0509] Next, the acquisition determination of the above-described written data will be described in more detail. The acquisition of the written data is one of the processes related to installation. Here, with reference to Figure 61 to Figure 64 the instruction determination process for installation will be described. The vehicle program rewriting system 1 performs an instruction determination process for installation in the CGW 13. The above-described (1) transmission determination process for the distribution data packet and (2) download determination process for the distribution data packet are determination processes performed in the download stage, and (3) transmission determination process for the written data and (4) acquisition determination process for the written data are processes performed in the installation stage after the download is completed. The (5) instruction determination process for installation is a process performed in the installation stage and the activation stage. Here, it is assumed that the distribution data packet is downloaded to the DCM 12, and as Fig.10 shown, the written data (update data, differential data) to the write target ECU 19 is in an unpacked state.

[0510] As Fig.61 shown, the CGW 13 includes an installation condition determination unit 77a, an installation instruction unit 77b, a vehicle state information acquisition unit 77c, an activation condition determination unit 77d, and an activation instruction unit 77e in the installation instruction determination unit 77. The installation condition determination unit 77a determines whether the first condition, the second condition, the third condition, the fourth condition, and the fifth condition are satisfied. The first condition is a condition that user consent related to installation has been obtained. User consent related to installation means, for example, the user's consent operation for installation (for example, pressing the "Update Immediately" button 506a) in the screen as Fig.39 shown. Alternatively, it is also possible to regard the period from download to activation as one update, and use the user's consent operation for the update as such.

[0511] The second condition is a condition that the CGW 13 can communicate with the center device 3. The third condition is a condition that the vehicle state allows installation. The fourth condition is a condition that the rewrite target ECU 19 allows installation. Here, the fourth condition includes not only that the rewrite target ECU 19 as the installation target allows installation, but also that the rewrite target ECU 19 that cooperates with the rewrite target ECU 19 as the installation target also allows installation. The fifth condition is a condition that the written data is normal data. Here, the normal data includes data suitable for the rewrite target ECU 19, data that has not been tampered with, and the like.

[0512] If the installation condition determination unit 77a determines that all of the first condition, the second condition, the third condition, the fourth condition, and the fifth condition are satisfied, the installation instruction unit 77b instructs the ECU 19 to be rewritten to install the application program. That is, if the installation condition determination unit 77a determines that user consent related to installation has been obtained, the CGW 13 can communicate with the central device 3, the vehicle state is in a state where installation is possible, the ECU 19 to be rewritten is in a state where installation is possible, and the write data is normal data, the installation instruction unit 77b instructs the ECU 19 to be rewritten to install the application program. Specifically, the installation instruction unit 77b acquires the write data from the DCM 12 and transmits the acquired write data to the ECU 19 to be rewritten. If the installation condition determination unit 77a determines that at least any one of the first condition, the second condition, the third condition, the fourth condition, and the fifth condition is not satisfied, the installation instruction unit 77b waits without instructing the ECU 19 to be rewritten to install the application program, or notifies the user of the gist and reason for not being able to start the installation.

[0513] The vehicle state information acquisition unit 77c acquires vehicle state information from the central device 3. The activation condition determination unit 77d determines whether the sixth condition, the seventh condition, and the eighth condition are satisfied when the installation of the application program is completed in all of the ECUs 19 to be rewritten. The sixth condition is a condition that user consent related to activation has been obtained. User consent related to activation means, for example, a consent operation by the user for activation (such as pressing the "OK" button 508b) on the screen as shown in Fig.43 shown. Alternatively, it is also possible to regard the period from download to activation as one update and use the user's consent operation for the update. The seventh condition is a condition that the vehicle state is in a state where activation is possible. The eighth condition is a condition that the ECU 19 to be rewritten is in a state where activation is possible.

[0514] If the activation condition determination unit 77d determines that all of the sixth condition, the seventh condition, and the eighth condition are satisfied, the activation instruction unit 77e instructs the ECU 19 to be rewritten to activate the application program. The specific details will be described in the subsequent (12) activation request instruction process. That is, if the activation condition determination unit 77d determines that user consent related to activation has been obtained, the vehicle state is in a state where activation is possible, and the ECU 19 to be rewritten is in a state where activation is possible, the activation instruction unit 77e instructs the ECU 19 to be rewritten to activate the application program. By performing activation, the update program written to the ECU 19 to be rewritten becomes valid. If the activation condition determination unit 77d determines that at least any one of the sixth condition, the seventh condition, and the eighth condition is not satisfied, the activation instruction unit 77e waits without instructing the ECU 19 to be rewritten to activate the application program, or notifies the user of the gist and reason for not being able to start the activation.

[0515] Next, refer to Figure 62 to Figure 64 The operation of the installation instruction determination unit 77 in the CGW13 will be described. The CGW13 executes an installation instruction determination program and performs installation instruction determination processing.

[0516] When the CGW13 starts the installation instruction determination processing, it determines whether the first condition is satisfied and determines whether user consent related to the installation has been obtained (S501, which is part of the installation condition determination step). If the CGW13 determines that user consent related to the installation has been obtained (S501: Yes), it determines whether the second condition is satisfied and determines whether data communication with the central device 3 is possible (S502, which is part of the installation condition determination step). The CGW13 determines whether data communication with the central device 3 is possible based on the communication radio wave conditions in the DCM12.

[0517] If the CGW13 determines that data communication with the central device 3 is possible (S502: Yes), it determines whether the third condition is satisfied and determines whether the vehicle state is suitable for installation (S503, which is part of the installation condition determination step). As the vehicle state, the CGW13 determines, for example, whether the remaining battery capacity of the vehicle battery 40 is equal to or greater than a specified capacity, and whether the vehicle is in a parked state (IG off state) when the memory structure of the ECU 19 to be rewritten is a single-sided memory, etc., to determine whether the vehicle state is suitable for installation. These vehicle state conditions can also be configured to refer to the received rewrite specification data (refer to Figure 8 ). For example, the CGW13 determines that the vehicle state is suitable for installation when the remaining battery capacity of the vehicle battery 40 is equal to or greater than the specified capacity specified by the rewrite specification data and matches the vehicle state specified by the rewrite specification data (only parked state allowed, or only driving state allowed, or both parked state and driving state allowed).

[0518] If the CGW13 determines that the vehicle state is suitable for installation (S503: Yes), it determines whether the fourth condition is satisfied and determines whether the ECU 19 to be rewritten is suitable for installation (S504, which is part of the installation condition determination step). For example, the CGW13 determines that the ECU 19 to be rewritten is suitable for installation when no fault code has occurred in the ECU 19 to be rewritten and the secure access to the ECU 19 to be rewritten is successful. Here, regarding the occurrence of a fault code, in addition to confirming for the ECU 19 to be rewritten for writing the write data, confirmation is also performed for the ECU 19 that collaborates with the ECU 19 to be rewritten. That is, the CGW13 determines whether a fault code has occurred not only for the ECU 19 to be rewritten but also for the ECU 19 that collaborates with the ECU 19 to be rewritten.

[0519] If it is determined that the ECU 19 to be rewritten is installable (S504: Yes), then it is determined whether the fifth condition is met, and it is determined whether the written data is normal data (S505, which is part of the installation condition determination step). The CGW 13 determines that the written data is normal data when the written data matches the writing surface (non-operation surface) of the ECU 19 to be rewritten and the verification result of the integrity of the written data is normal, etc. If the CGW 13 determines that the written data is normal data (S505: Yes), it instructs the ECU 19 to be rewritten to install the application program (S506, which is equivalent to the installation instruction step). In this way, the CGW 13 makes the determination of the second condition and subsequent conditions with the satisfaction of the first condition as the condition. In addition, the CGW 13 finally makes the determination of the fifth condition. If the CGW 13 determines that all of the first condition to the fifth condition are met, it instructs the ECU 19 to be rewritten to install the application program.

[0520] On the other hand, if the CGW 13 determines that the user consent related to installation has not been obtained (S501: No), determines that data communication with the central device 3 cannot be performed (S502: No), determines that the vehicle state is not installable (S503: No), determines that the ECU 19 to be rewritten is not installable (S504: No), and determines that the written data is not normal data (S505: No), then it does not instruct the ECU 19 to be rewritten to install the application program. In addition, in the above processing, the configuration in which the condition of obtaining the user consent related to installation is determined earlier than other conditions has been described, but it can also be a configuration in which it is determined later than other conditions.

[0521] If the CGW 13 instructs the ECU 19 to be rewritten to install the application program, it distributes the written data to the ECU 19 to be rewritten (S507) and determines whether the installation is completed (S508). If the CGW 13 determines that the installation is completed (S508: Yes), it determines whether the sixth condition is met and determines whether the user consent related to activation has been obtained (S509). If the CGW 13 determines that the user consent related to activation has been obtained (S509: Yes), it determines whether the seventh condition is met and determines whether the vehicle state is an activatable state (S510).

[0522] If the CGW 13 determines that the vehicle state is an activatable state (S510: Yes), it determines whether the eighth condition is met and determines whether the ECU 19 to be rewritten is an activatable state (S511). If the CGW 13 determines that the ECU 19 to be rewritten is an activatable state (S511: Yes), it instructs the ECU 19 to be rewritten to be activated (S512). In this way, if the CGW 13 determines that all of the sixth condition to the eighth condition are met, it instructs the ECU 19 to be rewritten to be activated.

[0523] In addition, when there are multiple ECUs 19 to be rewritten, CGW13 can either indicate installation separately and independently or indicate it together. In the case of separately and independently indicating installation when the ECUs 19 to be rewritten are ECU(ID1) and ECU(ID2), as Fig.63 shown, CGW13 determines whether the installation conditions are met for ECU(ID1). If CGW13 determines that the installation conditions are met for ECU(ID1), it indicates installation to ECU(ID1). Next, CGW13 determines whether the installation conditions are met for ECU(ID2). Here, as the installation conditions, CGW13 only needs to determine whether the fourth condition and the fifth condition are met for ECU(ID2). If CGW13 determines that the installation conditions are met for ECU(ID2), it indicates installation to ECU(ID2).

[0524] In the case of indicating installation together when the ECUs 19 to be rewritten are ECU(ID1) and ECU(ID2), as Fig.64 shown, CGW13 determines whether the installation conditions are met for ECU(ID1). That is, CGW13 determines the first to third conditions, and the fourth and fifth conditions regarding ECU(ID1). If CGW13 determines that the installation conditions are met for ECU(ID1), it determines whether the installation conditions are met for ECU(ID2). That is, CGW13 determines the fourth and fifth conditions regarding ECU(ID2). If the installation conditions are met regarding ECU(ID2), CGW13 indicates installation to ECU(ID1) and ECU(ID2). For example, CGW13 simultaneously and in parallel transmits the rewrite data to ECU(ID1) and transmits the rewrite data to ECU(ID2). In this way, in the case of indicating installation together, CGW13 determines the first to third conditions, and the fourth and fifth conditions regarding all ECUs to be rewritten. Moreover, CGW13 indicates installation after satisfying all these conditions.

[0525] As described above, by performing the installation instruction determination process before indicating installation to the ECU 19 to be rewritten, CGW13 indicates the installation of the application program to the ECU 19 to be rewritten if it determines that all of the first condition of obtaining user consent related to installation, the second condition of being able to communicate with the central device 3, the third condition that the vehicle state is in an installable state, the fourth condition that the ECU 19 to be rewritten is in an installable state, and the fifth condition that the write data is normal data are satisfied. It is possible to appropriately indicate the installation of the application program to the ECU 19 to be rewritten.

[0526] (6) Management process of the security access key

[0527] Refer to Figure 65 to Figure 69A description is given of the management process for the secure access key. The secure access key is the key for device authentication when the CGW13 accesses and rewrites the target ECU19 before installing the written data. The vehicle program rewrite system 1 performs the management process for the secure access key in the CGW13. Here, the description is given on the premise that the CGW13 is in a state where it can obtain the written data from the DCM12 through the above (3) transmission determination process for the written data or (4) acquisition determination process for the written data. The device authentication using the secure access key corresponds to the fourth condition (step S505) in the above (5) installation instruction determination process.

[0528] When the CGW13 distributes the written data to the target ECU19 for rewriting, secure access (device authentication) using the secure access key is required between the CGW13 and the target ECU19. In this case, a method is considered where the CGW13 requests the generation of a random value from the target ECU19, obtains the random value generated by the target ECU19 from the target ECU19, and calculates the secure access key from the obtained random value. However, in such a method, if the random value is obtained from the target ECU19 even when the application program is not rewritten, the secure access key can also be maintained, so there may be a risk of leakage of the secure access key.

[0529] In addition, if it is configured to send the random value obtained from the target ECU19 in the CGW13 to the central device 3, and the central device 3 calculates the random value and generates the secure access key, the secure access key does not need to be maintained, so the risk of leakage of the secure access key can be reduced. However, in the configuration where the central device 3 calculates the random value, the standby time until the target ECU19 obtains the random value from the central device 3 is long, and it is difficult to meet the time regulations for diagnostic communication. Based on such a situation, in the present embodiment, the following configuration is adopted.

[0530] As Fig.65 shown, the supplier encrypts the secure access key for each target ECU19 using the encryption / decryption key for the secure access key to generate a random value. The random value mentioned here includes either a value different from the value used in the past or a value the same as the value used in the past, and refers to a random value. The random value is the encrypted secure access key. The supplier provides the generated random value together with the reprogrammed data. The secure access key, the encryption / decryption key for the secure access key, and the random value are unique keys for each ECU19.

[0531] If the random value is provided from the supplier together with the reprogrammed data, the OEM establishes a correspondence between the provided random value and the ECU (ID) identifying the ECU19 and stores it in Figure 8The rewrite specification data for the CGW as shown. In addition, the OEM also stores the key mode and decryption operation mode required for decrypting the random value in the rewrite specification data for the CGW. As the key mode, methods such as shared key / public key and key length are stored, and as the decryption operation mode, the type of algorithm used for decryption operation is stored. If the random value, key mode, and decryption operation mode are stored in the rewrite specification data for the CGW, the OEM will provide the rewrite specification data for the CGW storing the random value to the central device 3 together with the reprogramming data. The information provided by the supplier is stored in the ECU reprogramming data DB and ECU metadata DB described later.

[0532] If the rewrite specification data (rewrite specification data for the DCM and rewrite specification data for the CGW) is provided from the OEM together with the reprogramming data, the central device 3 will send a distribution data packet including the provided rewrite specification data and reprogramming data to the master device 11. In the master device 11, if the DCM 12 downloads the distribution data packet from the central device 3, it will transfer the rewrite specification data and the write data to the CGW 13.

[0533] As Fig.66 shown, the CGW 13 has a secure area 78a (equivalent to the decryption key storage section), a random value extraction section 78b (equivalent to the key derived value extraction section), a key mode extraction section 78c, a decryption operation mode extraction section 78d, a key generation section 78e, a secure access execution section 78f, a session transfer request section 78g, and a key elimination section 78h in the secure access key management section 78. Regarding the secure area 78a, information cannot be read from the outside of the ECU 19, and the encryption / decryption key of the secure access key and the decryption operation algorithm are configured. The random value extraction section 78b extracts the random value (key derived value) included in the rewrite specification data from the analysis result of the rewrite specification data for the CGW. The random value is a value encrypted in correspondence with the ECU (ID) of the ECU to be rewritten.

[0534] The key mode extraction section 78c extracts the key mode included in the rewrite specification data from the analysis result of the rewrite specification data for the CGW. The decryption operation mode extraction section 78d extracts the decryption operation mode included in the rewrite specification data from the analysis result of the rewrite specification data for the CGW.

[0535] If the random value extraction unit 78b extracts a random value, the key generation unit 78e searches the secure area 78a, decrypts the extracted random value using the decryption key corresponding to the ECU (ID) from the decryption key bundle of the secure access key configured in the secure area 78a, and generates a secure access key. In this case, the key generation unit 78e uses the decryption key determined by the key pattern extracted by the key pattern extraction unit 78c and decrypts the key derivation value according to the decryption operation method determined by the decryption operation pattern extracted by the decryption operation pattern extraction unit 78d. That is, multiple key patterns and multiple decryption operation patterns are prepared, and the key pattern and the decryption operation pattern are specified by the rewriting specification data for the CGW, so that the key generation unit 78e generates a secure access key using the key pattern and the decryption operation pattern.

[0536] If the key generation unit 78e generates a secure access key, the secure access execution unit 78f performs a secure access to the target ECU 19 to be rewritten using the generated secure access key. Specifically, the secure access execution unit 78f sends, for example, encrypted data obtained by encrypting the ECU (ID) using the secure access key, and requests access to the target ECU 19 to be rewritten. If the target ECU 19 to be rewritten receives the encrypted data, it decrypts the received encrypted data using the secure access key held by itself. Further, the target ECU 19 to be rewritten compares the decrypted data generated by the decryption with its own ECU (ID), permits access to itself when the two match, and does not permit access to itself when the two do not match.

[0537] The session transfer request unit 78g requests a transfer to the rewriting session. After transferring from the default session to the rewriting session, the secure access execution unit 78f performs a secure access. In addition, it is also possible to perform a secure access after transferring to a session other than the default session (for example, a diagnostic session), and then transfer to the rewriting session. The key elimination unit 78h eliminates the secure access key generated by the key generation unit 78e after the secure access execution unit 78f performs a secure access to the target ECU 19 to be rewritten and the rewriting of the application program of the target ECU 19 to be rewritten is completed.

[0538] Next, refer to Figure 67 to Figure 69 The operation of the secure access key management unit 78 in the CGW 13 will be described. The CGW 13 executes a secure access key management program and performs secure access key management processing. As the secure access key management processing, the CGW 13 performs secure access key generation processing and secure access key elimination processing. Hereinafter, each processing will be described in turn.

[0539] (6-1) Secure access key generation processing

[0540] If CGW13 starts the generation process of the secure access key, it analyzes the rewrite specification data obtained from DCM12 (S601, corresponding to the rewrite specification data analysis step), and extracts a random value, a key mode, and a decryption operation mode from the rewrite specification data for CGW (S602, corresponding to the key derived value extraction step).

[0541] CGW13 searches the secure area 78a, decrypts the random value extracted from the rewrite specification data for CGW using the decryption key pair corresponding to the ECU (ID) from the decryption key bundle of the secure access key configured in the secure area 78a, and generates a secure access key (S603, corresponding to the key generation step).

[0542] As Fig.68 shown, CGW13 generates a secure access key according to the rewrite specification data for CGW. CGW13 makes a session transfer request to the rewrite session capable of writing the write data (S604), performs secure access to the rewrite target ECU19 using the secure access key (S605). If CGW13 finishes the execution of the secure access, it distributes the write data to the rewrite target ECU19 (S606), and makes a session maintenance request (S607). If CGW13 determines that the installation is completed (S608: Yes), it ends the generation process of the secure access key.

[0543] (6-2) Secure access key elimination process

[0544] If CGW13 starts the secure access key elimination process, it determines whether the application program of the rewrite target ECU19 has been rewritten (S611). If CGW13 determines that the application program of the rewrite target ECU19 has been rewritten (S611: Yes), it eliminates the secure access key generated by executing the secure access key generation process (S612), and ends the secure access key elimination process.

[0545] As described above, CGW13 extracts the random value corresponding to the rewrite target ECU19 from the analysis result of the rewrite specification data by performing the management process of the secure access key, decrypts the random value using the decryption key corresponding to the rewrite target ECU19 stored in the secure area 78a, and generates a secure access key. By generating the secure access key in CGW13 instead of obtaining it from the outside, the risk of leakage of the secure access key can be reduced, and secure access to the rewrite target ECU19 can be appropriately executed.

[0546] In addition, when there are multiple ECUs 19 to be rewritten, it is preferable that CGW13 performs the generation process of the security access key before installing each write data. That is, preferably: when the ECUs 19 to be rewritten are ECU(ID1), ECU(ID2), and ECU(ID3), CGW13 performs the generation process of the security access key for ECU(ID1), installs the write data for ECU(ID1), performs the generation process of the security access key for ECU(ID2), installs the write data for ECU(ID2), performs the generation process of the security access key for ECU(ID3), and installs the write data for ECU(ID3) in this order. For example, as Fig.63 shown, CGW13 performs the security access process as one process for determining whether the installation condition for ECU(ID1) is satisfied. When the access is normally permitted, it instructs the installation for ECU(ID1). Then, CGW13 performs the security access process as one process for determining whether the installation condition for ECU(ID2) is satisfied. When the access is normally permitted, it instructs the installation for ECU(ID2).

[0547] In addition, if the ECU 19 to be rewritten permits access to itself through the security access by CGW13, it releases the security access by receiving the session transfer request from CGW13 and becomes a state where the write data can be written to the flash memory. The session transfer request is, for example, the "rewrite session transfer request" in the second state as Fig.155 shown. If the ECU 19 to be rewritten does not receive the session transfer request from CGW13 within a specified time (for example, 5 seconds) from the permission of access to itself, it times out, locks the security access, and does not accept the reception of the session transfer request. When CGW13 does not send the session transfer request to the ECU 19 to be rewritten within the specified time from the determination of the permission of access to the ECU 19 to be rewritten, it is necessary to send the session maintenance request to the ECU 19 to be rewritten, keep the ECU 19 to be rewritten from timing out, and send the session transfer request to the ECU 19 to be rewritten.

[0548] In addition, for example, when the application program of version 1.0 is written to the operation surface and the application program of version 2.0 is written to the non-operation surface during the rewrite due to a cancellation operation, if an activation notice for version 2.0 is generated from this state, it is possible to only perform activation without installation, so the security access process can also be omitted.

[0549] (7) Verification process of write data

[0550] Refer to Figures 70 to 78A description will be given of the verification process for the written data. The vehicle program rewriting system 1 performs the verification process for the written data in the CGW 13. The CGW 13 can perform the verification process for the written data described in the present embodiment either before obtaining the access permission in the management process of the above-mentioned (6) security access key or after obtaining the access permission.

[0551] As Fig.70 shown, if a supplier or OEM generates written data, a data verification value calculation algorithm is applied to the generated written data to generate a data verification value. Here, the written data can be either a new program to be updated or differential data from an old program to a new program. The supplier or OEM applies encryption using a prescribed key (key value) to the data verification value to generate an authentication symbol, and registers the written data and the authentication symbol in the central device 3 in a corresponding relationship. Specifically, these data are stored in the reprogramming data DB described later for each ECU 19. Moreover, the central device 3 generates a distribution data packet including the written data and the authentication symbol, and stores it in the data packet DB.

[0552] If a download request for a distribution data packet from the host device 11 is generated, the central device 3 sends the distribution data packet including the written data and the authentication symbol to the host device 11 according to the download request. In this case, the written data sent from the central device 3 to the host device 11 is in ciphertext, and the authentication symbol sent from the central device 3 to the host device 11 is also in ciphertext. In addition, the authentication symbol sent from the central device 3 to the host device 11 can also be in plaintext. In the case where the authentication symbol sent from the central device 3 to the host device 11 is in plaintext, the decryption process described later is not required.

[0553] When the host device 11 downloads a distribution data packet from the central device 3, it extracts the written data of the ECU 19 to be rewritten from the downloaded distribution data packet, and verifies the propriety of the written data before distributing the written data to the ECU 19 to be rewritten. That is, the host device 11 sequentially performs a decryption process, a first verification value calculation process, a second verification value calculation process, a comparison process, and a determination process to verify the written data. The decryption process is a process of decrypting the authentication symbol sent in ciphertext. The first verification value calculation process is a process of calculating a first data verification value as an expected value using a key (key value) based on the decrypted authentication symbol. The second verification value calculation process is a process of calculating a second data verification value using the data verification value calculation algorithm based on the written data. The comparison process is a process of comparing the first data verification value and the second data verification value. The determination process is a process of determining the propriety of the written data based on the comparison result of the comparison process.

[0554] As Fig.71As shown, CGW13 has a writable determination unit 79a, a processing execution request unit 79b, a processing result acquisition unit 79c, and a verification unit 79d in the verification unit 79 for writing data. The writable determination unit 79a determines whether data can be written in the ECU 19 to be rewritten. If the writable determination unit 69a determines that data can be written in the ECU 19 to be rewritten, the processing execution request unit 79b notifies the DCM 12 of a processing execution request and requests the execution of processing from the DCM 12. The processing execution request unit 68b notifies the DCM 12 of a processing execution request for at least any one of decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. The processing result acquisition unit 68c acquires the processing result from the DCM 12 by being notified of the processing result from the DCM 12. If the processing result acquisition unit 68c acquires the processing result, the verification unit 79d verifies the written data using the processing result. That is, in the above configuration, CGW13 corresponds to the first device and the first functional unit, and DCM12 corresponds to the second device and the second functional unit.

[0555] Next, refer to Figure 72 to Figure 77 The operation of the verification unit 79 for the written data in CGW13 will be described. CGW13 executes a verification program for the written data and performs verification processing on the written data.

[0556] When CGW13 starts the verification processing of the written data, it notifies the DCM 12 of a processing execution request and requests the execution of processing from the DCM 12 (S701, corresponding to the processing execution request step). CGW13 notifies the DCM 12 of a processing execution request for at least any one of the above decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. When CGW13 acquires the processing result from the DCM 12 (S702, corresponding to the processing result acquisition step), it verifies the written data using the acquired processing result (S703, corresponding to the verification step).

[0557] Hereinafter, several cases where CGW13 notifies the DCM 12 of a processing execution request will be exemplified. In Fig.73In the example, CGW13 notifies DCM12 of the processing execution requests for decryption processing, first verification value calculation processing, and second verification value calculation processing. If DCM12 is notified by CGW13 of the processing execution requests for decryption processing, first verification value calculation processing, and second verification value calculation processing, it sequentially executes decryption processing, first verification value calculation processing, and second verification value calculation processing. DCM12 executes the processing result notification processing and notifies CGW13 of the first data verification value calculated through the first verification value calculation processing and the second data verification value calculated through the second verification value calculation processing as the processing results. If CGW13 executes the processing result acquisition processing and acquires the first data verification value and the second data verification value from DCM12, it sequentially executes comparison processing and determination processing using the first data verification value and the second data verification value. CGW13 verifies and writes data according to whether the determination result of the determination processing is positive. In this example, DCM12 holds the key for calculating the first data verification value.

[0558] In Fig.74 the example, CGW13 notifies DCM12 of the processing execution requests for decryption processing and second verification value calculation processing. If DCM12 is notified by CGW13 of the processing execution requests for decryption processing and second verification value calculation processing, it sequentially executes decryption processing and second verification value calculation processing and notifies CGW13 of the second data verification value calculated through the second verification value calculation processing. If CGW13 executes the processing result acquisition processing and acquires the second data verification value from DCM12, it executes the first verification value calculation processing and sequentially executes comparison processing and determination processing using the first data verification value calculated through the first verification value calculation processing and the second data verification value. CGW13 verifies and writes data according to whether the determination result of the determination processing is positive. In this example, CGW13 holds the key for calculating the first data verification value.

[0559] In Fig.75 the example, CGW13 notifies DCM12 of the processing execution requests for decryption processing, first verification value calculation processing, second verification value calculation processing, and comparison processing. If DCM12 is notified by CGW13 of the processing execution requests for decryption processing, first verification value calculation processing, second verification value calculation processing, and comparison processing, it sequentially executes decryption processing, first verification value calculation processing, second verification value calculation processing, and comparison processing. DCM12 executes the processing result notification processing and notifies CGW13 of the comparison result of the comparison processing as the processing result. If CGW13 executes the processing result acquisition processing and acquires the comparison result from DCM12, it executes the determination processing using the comparison result. CGW13 verifies and writes data according to whether the determination result of the determination processing is positive. In this example, DCM12 holds the key for calculating the first data verification value.

[0560] In Fig.76 the example, CGW13 notifies DCM12 of the processing execution requests for decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. If DCM12 is notified of the processing execution requests for decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing from CGW13, it sequentially executes decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. DCM12 performs the processing result notification processing and notifies CGW13 of the determination result of the determination processing as the processing result. If CGW13 performs the processing result acquisition processing and acquires the processing result from DCM12, it verifies and writes data according to whether the determination result indicated by the processing result is positive verification. In this example, DCM12 holds the key for calculating the first data verification value.

[0561] When there are multiple rewrite target ECUs 19, CGW13 performs the verification processing of the write data for the multiple rewrite target ECUs 19 as follows. When there are multiple rewrite target ECUs 19, there are a method of verifying the write data for the multiple rewrite target ECUs 19 together and a method of verifying the write data independently for each.

[0562] In the method of verifying the write data for the multiple rewrite target ECUs 19 together, for example, as Fig.77 shown, CGW13 verifies the write data of ECU (ID1), the write data of ECU (ID2), and the write data of ECU (ID3) together, and distributes the write data distributed to the write target ECU (ID1) of ECU (ID1), the write data distributed to the write target ECU (ID2) of ECU (ID2), and the write data distributed to the write target ECU (ID3) of ECU (ID3). In this case, by verifying the write data for the multiple rewrite target ECUs 19 together, it is possible to shorten the time required from the start of the verification of the write data for the multiple rewrite target ECUs 19 to the completion of the program rewrite. That is, compared with the configuration of verifying the write data for the multiple rewrite target ECUs 19 independently for each, it is possible to shorten the time required from the start of the verification of the write data for the multiple rewrite target ECUs 19 to the completion of the program rewrite.

[0563] In the method of verifying the write data for the multiple rewrite target ECUs 19 independently for each, for example, as Fig.78As shown, CGW13 verifies the write data of ECU (ID1), distributes it to the write target ECU (ID1) of the write data distributed to ECU (ID1), verifies the write data of ECU (ID2), distributes it to the write target ECU (ID2) of the write data distributed to ECU (ID2), verifies the write data of ECU (ID3), and distributes it to the write target ECU (ID2) of the write data distributed to ECU (ID3). In this case, by verifying the write data before distributing the write data, illegal access can be avoided and reliability can be improved. That is, in the configuration where the write data is verified together for multiple rewrite target ECUs 19, the time from the completion of verification to the distribution of the write data varies according to the rewrite order. If the time from the completion of verification to the distribution of the write data becomes long, there is a risk of tampering caused by illegal access during that period. However, by verifying the write data immediately before distributing the write data, such a situation can be avoided.

[0564] As described above, CGW13 makes DCM12, which downloads and distributes the data packet from the central device 3, execute at least a part of the processing related to the verification of the write data by performing the verification processing of the write data. In CGW13 and the rewrite target ECU 19, even if the area for storing the write data cannot be ensured or the arithmetic program for verification cannot be mounted, the write data can be appropriately verified before writing the write data to the rewrite target ECU 19.

[0565] In Fig.74 In the configuration where CGW13 performs the first verification value calculation process illustrated, CGW13 holds the key (key value) and performs the verification process without sending the key to DCM12. Therefore, compared with the configuration where DCM12 performs the first verification value calculation process, the security can be improved. In addition, when there are multiple rewrite target ECUs 19, the first verification value calculation process can be performed using a shared key (key value) shared by the multiple rewrite target ECUs 19, or can be performed using individual keys (key values) different for the multiple rewrite target ECUs 19.

[0566] In addition, the configuration in which CGW13 notifies the DCM12 of the process execution request has been illustrated above. However, for example, in a case where the processing load in the DCM12 increases and hinders the original processing, instead of the DCM12, a navigation device or an ECU other than the ECU 19 to be rewritten may be used to notify the navigation device or an ECU other than the ECU 19 to be rewritten of the process execution request. Further, in a case where the DCM12 and the CGW13 are integrated, in a case where a response can be made without hindering the original processing, a process execution request may be requested to the own process execution unit. For example, it may be performed between different software components in the same ECU. Further, the above configuration may be applied to the main device 11 of a single integrated ECU configured to have the functions of the DCM12 and the CGW13. For example, in Figure 73 to Figure 76 the processing function in the CGW13 is used as a first functional unit, the processing function in the DCM12 is used as a second functional unit, a process execution request is notified from the first functional unit to the second functional unit, and an execution result is returned from the second functional unit to the first functional unit. In the main device 11 configured as an integrated ECU, in a case where the processing load increases and hinders communication processing and relay processing, instead of the second functional unit, a process execution request may be notified to a navigation device or an ECU other than the ECU 19 to be rewritten.

[0567] In addition, the data verification value may be calculated as one value for the entire application program or may be calculated as multiple values in units of modules of the application program. If the written data is all data, it can be used in integrity verification after the written data is completed.

[0568] In addition, with respect to secure access, it is a method of verifying whether the CGW13 and the ECU 19 to be rewritten can also be connected. Verification of the written data includes concepts such as the central device 3 as the distribution destination of the written data being regular (connection based on TLS communication, mutual authentication), the communication path for downloading the written data from the central device 3 being regular (communication path hiding, encryption), the written data downloaded from the central device 3 not being tampered with (tampering detection), and the written data downloaded from the central device 3 not being able to be tampered with (encryption).

[0569] In addition, the written data at the time of rewriting a new program has been described, but the written data at the time of rollback when writing back to an old program is the same. In this case, the CGW13 may perform verification at the time of downloading the written data for rollback from the central device 3, but may also perform verification immediately before distributing the written data for rollback to the ECU 19 to be rewritten by generating a cancellation request for writing.

[0570] (8) Transmission control process of data storage surface information

[0571] Refer to Figure 79 to Figure 81A description will be given of the transmission control process for data storage surface information. The vehicle program rewrite system 1 performs the transmission control process for data storage surface information in the CGW 13.

[0572] As Fig.79 shown, the CGW 13 has a data storage surface information acquisition unit 80a, a data storage surface information transmission unit 80b, a rewrite method determination unit 80c, and a rewrite method instruction unit 80d in the data storage surface information transmission control unit 80. The data storage surface information acquisition unit 80a acquires information related to hardware and software as ECU structure information from each ECU 19. Specifically, in the case of a double-sided memory ECU and a single-sided suspended memory ECU having data storage surfaces on multiple surfaces, software IDs including version information of each data storage surface and information capable of determining the usage surface are acquired as double-sided rewrite information (hereinafter referred to as surface information).

[0573] If the ECU structure information including the surface information is acquired by the data storage surface information acquisition unit 80a, the data storage surface information transmission unit 80b causes the acquired surface information to be transmitted from the DCM 12 to the central device 3 as one of the ECU structure information. The data storage surface information transmission unit 80b can transmit the ECU structure information to the central device 3 each time the ON / OFF of the IG switch 42 is switched, or can transmit the ECU structure information to the central device 3 according to a request from the central device 3. In addition, not only for the double-sided memory ECU and the single-sided suspended memory ECU, but also for the single-sided independent memory ECU, the data storage surface information transmission unit 80b can also transmit the ECU configuration including the surface information together.

[0574] The rewrite method determination unit 80c determines the rewrite method based on the analysis result of the rewrite specification data for the CGW 13. The rewrite method indicates the power supply switching method at the time of installation in the rewrite target ECU 19. If the rewrite method is determined by the rewrite method determination unit 80c, the rewrite method instruction unit 80d instructs the rewrite target ECU 19 to rewrite the application program based on the determined rewrite method. That is, if the rewrite method determination unit 80c determines the rewrite method based on power self-holding, the rewrite method instruction unit 80d instructs the rewrite target ECU 19 to rewrite the application program based on power self-holding. If the rewrite method determination unit 80c determines the rewrite method based on power control, the rewrite method instruction unit 80d instructs the rewrite target ECU 19 to rewrite the application program based on power control without using power self-holding.

[0575] Next, with reference to Fig.80 and Fig.81 a description will be given of the operation of the data storage surface information transmission control unit 80 in the CGW 13. The CGW 13 executes a data storage surface information transmission control program and performs a data storage surface information transmission control process.

[0576] When CGW13 starts the transmission control process of data storage surface information, it sends an ECU structure information request including surface information to all ECUs 19 (S801), and obtains ECU structure information including surface information from all ECUs 19 (S802, corresponding to the data storage surface information acquisition step). If CGW13 obtains ECU structure information from each ECU 19 to be rewritten, it sends the obtained ECU structure information to DCM12 (S803, corresponding to the data storage surface information transmission step), and waits to obtain write data and rewrite specification data from DCM12 (S804). Here, CGW13 can also, when the ECU 19 to be rewritten is determined in advance, obtain surface information, etc. only from the determined ECU 19 to be rewritten.

[0577] When DCM12 receives ECU structure information from CGW13, it temporarily stores the received ECU structure information, and when it is time to send (upload) the ECU structure information to the central device 3, it sends the ECU structure information to the central device 3. When the central device 3 receives ECU structure information from DCM12, it saves and analyzes the received ECU structure information.

[0578] The central device 3 determines the version of the application program for each surface of each ECU 19 that is the source of the surface information and which surface is the operating surface, and determines the version of the application program and the write data (corresponding to the update data selection step) of the operating surface suitable for the two determined surfaces. For example, when surface A is the operating surface, the application program stored on this operating surface is version 2.0, surface B is the non-operating surface, and the application program stored on this non-operating surface is version 1.0, the central device 3 determines the write data of version 3.0 for surface B as the write data. When the write data is differential data, the central device 3 determines the differential data updated from version 1.0 to version 3.0. If the central device 3 determines the write data, it sends a distribution data packet including the determined write data and rewrite specification data to DCM12 (corresponding to the distribution data packet transmission step).

[0579] The central device 3 can either statically select the distribution data packet to be sent to DCM12 or dynamically generate it. When the central device 3 statically selects the distribution data packet to be sent to DCM12, it manages multiple distribution data packets storing write data, selects the write data suitable for the non-operating surface, and selects and sends the distribution data packet storing the selected write data from the multiple distribution data packets to DCM12. When the central device 3 dynamically generates the distribution data packet to be sent to DCM12, if it determines the write data suitable for the non-operating surface, it generates a distribution data packet storing the determined write data and sends it to DCM12.

[0580] If DCM12 downloads and distributes a data packet from the central device 3, it extracts the write data and rewrite specification data from the downloaded distribution data packet, and transmits the extracted write data and rewrite specification data to CGW13.

[0581] If CGW13 determines that it has obtained the write data and rewrite specification data from DCM12 (S804: Yes), it analyzes the obtained rewrite specification data (S805), and determines the rewrite method for the target ECU19 to be rewritten according to the analysis result of the rewrite specification data (S806, S807).

[0582] If CGW13 determines that the rewrite method is a rewrite based on power self-holding (S806: Yes), it sends a write data acquisition request to DCM12 on the condition that the vehicle state is installable, obtains the write data from DCM12, distributes the obtained write data to the target ECU19 to be rewritten, and ends the transmission control process of the data storage surface information through the power self-holding rewrite application program (S808). The method of the power self-holding rewrite application program is as described above using Fig.28 and Fig.29 as described in (2) in the case of the power self-holding rewrite application program.

[0583] If CGW13 determines that the rewrite method is a rewrite based on power control (S807: Yes), it sends a write data acquisition request to DCM12 on the condition that the vehicle is parked, obtains the write data from DCM12, distributes the obtained write data to the target ECU19 to be rewritten, and ends the transmission control process of the data storage surface information through the power control rewrite application program (S809). The method of the power control rewrite application program is as described above using Fig.26 and Fig. 27 as described in (1) in the case of the power control rewrite application program.

[0584] As described above, CGW13 notifies the central device 3 of the ECU structure information including the surface information by performing the transmission control process of the data storage surface information, and causes the distribution data packet including the write data suitable for the ECU structure information to be downloaded from the central device 3 to DCM12. CGW13 obtains the write data suitable for the surface information from DCM12 and distributes the write data to the target ECU19 to be rewritten. It is possible to appropriately rewrite the application program when ECU19 equipped with a flash memory having a data storage surface on two sides is used as the target to be rewritten.

[0585] In addition, as the method by which the central device 3 distributes the distribution data packet, there are a first distribution method to a third distribution method as shown below. In the first distribution method, the central device 3 distributes, for example, one distribution data packet storing the write data of version 2.0 for side A and the write data of version 2.0 for side B. The DCM 12 extracts the write data of version 2.0 for side A and the write data of version 2.0 for side B from the distribution data packet downloaded from the central device 3, and transmits the extracted write data to the CGW 13. If the CGW 13 is transmitted the write data of version 2.0 for side A and the write data of version 2.0 for side B from the DCM 12, it selects one of them and distributes it to the ECU 19 to be rewritten. That is, it is a configuration in which the write data corresponding to each data storage surface is included in the distribution data packet, and the main device 11 selects the rewrite data suitable for the ECU 19 to be rewritten.

[0586] In the second distribution method, the central device 3 selects and distributes, for example, either the distribution data packet storing the write data of version 2.0 for side A or the distribution data packet storing the write data of version 2.0 for side B. The DCM 12 extracts the write data from the distribution data packet downloaded from the central device 3, and transmits the extracted write data to the CGW 13. The CGW 13 distributes the write data transmitted from the DCM 12 to the ECU 19 to be rewritten. That is, it is a configuration in which the central device 3 selects the distribution data packet including the write data for the non-operating surface based on the surface information uploaded from the DCM 12.

[0587] In the third distribution method, the central device 3 distributes, for example, a distribution data packet storing the write data of version 2.0 shared by side A and side B. The DCM 12 extracts the write data of version 2.0 shared by side A and side B from the distribution data packet downloaded from the central device 3, and transmits the extracted write data to the CGW 13. The CGW 13 distributes the write data of version 2.0 shared by side A and side B transmitted from the DCM 12 to the ECU 19 to be rewritten. If the ECU 19 to be rewritten receives the write data of version 2.0 shared by side A and side B from the CGW 13, it writes the received write data to either side A or side B. In this case, in the ECU 19 to be rewritten, when the application program is executed, the address resolution function of the microcomputer is activated, so that it operates properly regardless of whether the write data is written to side A or side B. That is, by the microcomputer of the write target ECU 19 resolving the difference in the execution address due to the surface difference, the central device 3 and the main device 11 can operate without knowing the surface.

[0588] The ECU structure information including the surface information sent from CGW13 to the central device 3 via DCM12 may also include vehicle identification information, system identification information, ECU identification information, usage environment information, etc. in addition to the versions of the application programs for two surfaces and the information capable of determining the usage surface.

[0589] The vehicle identification information is the unique information of the vehicle used to determine the distribution destination of the distributed data packet. For example, it is the VIN (Vehicle Identification Number). In vehicles compliant with the OBD (On-board diagnostics) regulations, the VIN can be used through the provisions of the OBD regulations. However, in vehicles that do not comply with the OBD regulations, such as EV vehicles, the VIN cannot be used. Therefore, individual vehicle identification information can be used instead of the VIN.

[0590] The system identification information is the unique information used to determine which reprogramming system it is. CGW13 can perform wireless reprogramming on the system that can perform wired reprogramming of the diagnostic communication managed by itself, but cannot perform wireless reprogramming on other systems with independent methods. That is, this is because it is a system that uses the mechanism of program update obtained via wire to perform program update obtained via wireless. Therefore, in the central device 3, it is necessary to determine which distributed data packet to distribute to which system. By using the system identification information, it is possible to manage what systems are installed in the vehicle. The central device 3 can determine the reprogramming method for each system and the reprogramming order when multiple systems are the reprogramming targets by determining the system identification information.

[0591] The ECU identification information is the unique information used to determine the ECU19 to be reprogrammed, and it includes the software version and hardware version information used to uniquely determine the reprogrammed ECU and the application program written to the ECU19 to be reprogrammed. The ECU identification information is also equivalent to the ECU product number. When writing the latest software using all the data, it can also be just the hardware version. In addition, it is possible to define information such as the specification version and configuration version that can determine the application program, and it is also possible to define the microcomputer ID, sub-microcomputer ID, flash memory ID, software sub-version, software grandchild-version, etc.

[0592] The usage environment information is the unique information used to determine the environment in which the user uses the vehicle. By sending the usage environment information from CGW13 to the central device 3 via DCM12, the central device 3 can distribute application programs suitable for the environment in which the user uses the vehicle. For example, distribute an application program that enhances acceleration to a user who likes to drive with rapid acceleration from a stop, and distribute an application program that enhances eco-driving but has poor acceleration performance to a user who likes eco-driving. It is possible to distribute application programs suitable for the environment in which the user uses the vehicle.

[0593] In addition, the case where the microcomputer of the ECU 19 to be rewritten is equipped with a flash memory has been described above. However, in the case where an external memory is connected to the microcomputer of the ECU 19 to be rewritten, the external memory is treated equally to the dual-sided memory, and the write area of the external memory is divided into two to write the write data. In the case where the microcomputer of the ECU 19 to be rewritten is equipped with a flash memory and an external memory is connected, there is also a case where the program stored in the external memory is temporarily copied (duplicated) to the memory of the microcomputer. Since the external memory is generally used as a storage area for the operation log of the ECU, it is preferable to interrupt the storage of the operation log when the writing of the write data to the external memory is started, and to resume the storage of the operation log when the writing of the write data to the external memory is completed.

[0594] It is not limited to the case of rewriting the application program. For example, for data such as map data that has the property of being updated one by one, there are also concepts such as dual-sided and version, so the same applies to the case of rewriting map data.

[0595] (9) Power management processing for non-rewrite objects

[0596] Refer to Figure 82 to Figure 87 The power management processing for the non-rewrite object ECU 19 will be described. The vehicle program rewriting system 1 performs the power management processing for the non-rewrite object ECU 19 in the CGW 13. In the present embodiment, it is assumed that the download of the distribution data packet is completed by the DCM 12, the CGW 13 acquires the rewrite specification data, and the CGW 13 distributes the write data to the ECU 19 to be rewritten in the vehicle stop state. When the CGW 13 distributes the write data to the ECU 19 to be rewritten, the CGW 13 requests the power management ECU 20 to turn on the IG power supply, and makes all the ECUs 19 in the start state.

[0597] As Fig.82 shown, the CGW 13 includes a rewrite object determination unit 81a, an installability determination unit 81b, a state transition control unit 81c, and a rewrite order determination unit 81d in the power management unit 81 of the non-rewrite object ECU 19. The rewrite object determination unit 81a determines the rewrite object ECU 19 and the non-rewrite object ECU 19 based on the analysis result of the rewrite specification data. The installability determination unit 81b determines whether the rewrite object ECU 19 can be installed.

[0598] The state transition control unit 81c can transition the state of the ECU 19, causing the ECU 19 in the stopped state or sleep state to transition to the startup state (wake-up state), or causing the ECU 19 in the startup state to transition to the stopped state or sleep state. Additionally, the state transition control unit 81c causes the ECU 19 in the normal operation state to transition to the power-saving operation state, or causes the ECU 19 in the power-saving operation state to transition to the normal operation state. If it is determined by the installability determination unit 81b that installation is possible, the state transition control unit 81c controls at least one non-overwrite target ECU 19 to the stopped state, sleep state, or power-saving operation state. The rewrite order determination unit 81d determines the rewrite order of the overwrite target ECU 19 based on the analysis result of the rewrite specification data.

[0599] Next, refer to Figure 83 to Figure 87 The operation of the power management unit 81 of the non-overwrite target ECU 19 in the CGW 13 will be described. The CGW 13 executes a power management program for non-overwrite targets and performs power management processing for non-overwrite targets. Here, the case where the CGW 13 makes all the ECUs 19 to be managed enter the startup state will be described.

[0600] When the CGW 13 starts the power management processing for the non-overwrite target ECU 19, it determines the overwrite target ECU 19 and the non-overwrite target ECU 19 based on the analysis result of the CGW-specific rewrite specification data (S901), and determines the rewrite order of one or more overwrite target ECUs 19 based on the analysis result of the rewrite specification data (S902). The CGW 13 determines whether it is possible to write the write data (S903, equivalent to the writable determination step). If it is determined that it is possible to write the write data (S903: Yes), it sends a power-off request (stop request) to the non-overwrite target ECU 19 of the ACC system and the non-overwrite target ECU 19 of the IG system, causing the non-overwrite target ECU 19 of the ACC system and the non-overwrite target ECU 19 of the IG system to transition from the startup state to the stopped state (S904, equivalent to the state transition control step).

[0601] The CGW 13 determines whether the power-off request has been sent to all the compliant ECUs 19 (S905). If it is determined that the power-off request has been sent to all the compliant ECUs 19 (S905: Yes), it sends a sleep request to the non-overwrite target ECU 19 of the +B power supply system, causing the non-overwrite target ECU 19 of the +B power supply system to transition from the startup state to the sleep state (S906, equivalent to the state transition control step).

[0602] CGW13 determines whether the sleep request has been sent to all the compliant ECUs 19 (S907). If it is determined that the sleep request has been sent to all the compliant ECUs 19 (S907: Yes), then it is determined whether the application program has been rewritten for all the ECUs 19 to be rewritten (S908). If CGW13 determines that the application program has been rewritten for all the ECUs 19 to be rewritten (S908: Yes), then the power management process for the non-rewritten ECUs 19 ends. If CGW13 determines that the application program has not been rewritten for all the ECUs 19 to be rewritten (S908: No), then it returns to step S904 and repeats step S904 and the subsequent steps.

[0603] When there are multiple ECUs 19 to be rewritten, CGW13 can either transfer the states of the multiple ECUs 19 to be rewritten independently or transfer the states of the multiple ECUs 19 to be rewritten together. That is, in Fig.83 the process of CGW13 sending a power-off request or a sleep request to the non-rewritten ECUs 19 is shown. In the following Fig.84 and Fig.85 the case where, in addition to the power management process for the non-rewritten ECUs 19, the power management process for the ECUs 19 to be rewritten is also carried out is described.

[0604] First, Fig.84 is used to describe the case where CGW13 transfers the states of the multiple ECUs 19 to be rewritten independently. As shown in Fig.84 for example, the case where the ECUs 19 to be rewritten are ECU (ID1), ECU (ID2), ECU (ID3), and during parking, the ECUs 19 to be rewritten are specified in the rewrite order from early to late by ECU (ID1), ECU (ID2), ECU (ID3) is described.

[0605] CGW13 transfers all of ECU (ID1), ECU (ID2), and ECU (ID3) from the stop state or the sleep state to the start state. CGW13 keeps the first rewritten ECU (ID1) in the start state unchanged, transfers ECU (ID2) and ECU (ID3) from the start state to the stop state or the sleep state, and distributes the write data to ECU (ID1). If CGW13 finishes distributing the write data to ECU (ID1), then it transfers ECU (ID1) from the start state to the stop state or the sleep state, transfers the second rewritten ECU (ID2) from the stop state or the sleep state to the start state, keeps ECU (ID3) in the stop state or the sleep state unchanged, and distributes the write data to ECU (ID2).

[0606] If CGW13 finishes distributing the written data to ECU (ID2), it keeps ECU (ID1) in the stopped state or sleep state unchanged, transfers ECU (ID2) from the start state to the stopped state or sleep state, transfers the third rewritten ECU (ID3) from the stopped state or sleep state to the start state, and distributes the written data to ECU (ID3). If CGW13 finishes distributing the written data to ECU (ID3), it keeps ECU (ID1) and ECU (ID2) in the stopped state or sleep state unchanged, and transfers ECU (ID3) from the start state to the stopped state or sleep state. In this way, CGW13 is controlled to make only the currently rewritten ECU19 among the multiple ECUs19 to be rewritten in the start state.

[0607] Next, use Fig.85 to illustrate the case where CGW13 transfers the states of multiple ECUs19 to be rewritten together. As Fig.85 shown, the case where the ECUs19 to be rewritten are, for example, ECU (ID1), ECU (ID2), and ECU (ID3), and during parking, the ECUs19 to be rewritten are specified in the order of rewriting from the earliest to the latest by ECU (ID1), ECU (ID2), and ECU (ID3) will be illustrated.

[0608] CGW13 transfers all of ECU (ID1), ECU (ID2), and ECU (ID3) from the stopped state or sleep state to the start state. CGW13 keeps all of ECU (ID1), ECU (ID2), and ECU (ID3) in the start state unchanged and distributes the written data to ECU (ID1). If CGW13 finishes distributing the written data to ECU (ID1), it distributes the written data to ECU (ID2). If CGW13 finishes distributing the written data to ECU (ID2), it distributes the written data to ECU (ID3). If CGW13 finishes distributing the written data to ECU (ID3), it transfers all of ECU (ID1), ECU (ID2), and ECU (ID3) from the start state to the stopped state or sleep state. In this way, CGW13 controls all the multiple ECUs19 to be rewritten to be in the start state until the installation is completed. Here, CGW13 can also distribute the written data to ECU (ID1), ECU (ID2), and ECU (ID3) simultaneously in parallel.

[0609] When rewriting the application program of the target ECU 19 during parking, the environment in which the supply voltage to the target ECU 19 is stable is not necessarily guaranteed. Therefore, there is a concern about the situation where the vehicle battery 40 runs out of power during the rewriting of the application program. In particular, if there are multiple target ECUs 19, the time required to rewrite the application program becomes longer, so the possibility of the vehicle battery 40 running out of power during the rewriting of the application program increases. Regarding this point, by making the non-target ECUs 19 enter the stopped state or the sleep state as described above, it is possible to prevent the situation where the battery reserve of the vehicle battery 40 becomes insufficient during the program rewriting. Moreover, by making the ECUs 19 that are not currently being rewritten in the target ECU 19 enter the stopped state or the sleep state, power consumption can be further suppressed.

[0610] As described above, the case of rewriting the application program of the target ECU 19 during parking has been explained. Now, the case of rewriting the application program of the target ECU 19 during vehicle driving will be explained. When rewriting the application program of the target ECU 19 during vehicle driving, the environment in which the supply voltage to the target ECU 19 is stable is guaranteed. Therefore, there is no concern about the situation where the vehicle battery 40 runs out of power during the rewriting of the application program. However, there may be a case where the battery reserve of the vehicle battery 40 is less. In such a case, it is preferable to make the ECUs 19 that do not need to operate enter the stopped state or the sleep state during vehicle driving. As Fig.86 shown, in the case where the ECU 44 that does not need to operate during vehicle driving is connected to the +B power supply line 37 but not to the ACC power supply line 38 and the IG power supply line 39, the CGW 13 makes the ECU 44 that does not need to operate during vehicle driving transfer from the startup state to the stopped state or the sleep state. The ECU 44 is, for example, an ECU having functions such as anti-theft. That is, the CGW 13 makes the ECUs 44 that do not need to operate and are not the target for rewriting transfer to the stopped state or the sleep state during the period when all the ECUs 19 are in the startup state during vehicle driving. Thereby, an increase in power consumption associated with the installation during vehicle driving can be suppressed.

[0611] In addition, the CGW 13 monitors the battery reserve of the vehicle battery 40 and performs the above-described power management process for non-targets. Here, Fig.87 the monitoring process for the battery reserve will be described. When the CGW 13 starts the monitoring process for the battery reserve, it monitors the battery reserve (S911) during the period of distributing the write data to the target ECU 19, and determines whether the battery reserve is equal to or greater than the first specified capacity, or whether the battery reserve is less than the first specified capacity and equal to or greater than the second specified capacity, or whether the battery reserve is less than the second specified capacity (S912 to S914).

[0612] If CGW13 determines that the remaining battery capacity is equal to or greater than the first specified capacity (S912: Yes), it keeps the non-rewrite target ECU19 in the activated state and continues to distribute the data to be written to the rewrite target ECU19 (S915). If CGW13 determines that the remaining battery capacity is less than the first specified capacity and equal to or greater than the second specified capacity (S913: Yes), it transfers the ECUs that do not need to operate during driving in the non-rewrite target ECU19 to the stopped state or the sleep state, and continues to distribute the data to be written to the rewrite target ECU19 (S916). If CGW13 determines that the remaining battery capacity is less than the second specified capacity (S914: Yes), it determines whether the rewrite can be interrupted (S917).

[0613] If CGW13 determines that the rewrite can be interrupted (S917: Yes), it interrupts the distribution of the data to be written (S918). If CGW13 determines that the rewrite cannot be interrupted (S917: No), it transfers all the ECUs in the non-rewrite target ECU19 that can be transferred to the stopped state or the sleep state to the stopped state or the sleep state (S919).

[0614] CGW13 determines whether the rewrite is completed (S920). If it determines that the rewrite is not completed (S920: No), it returns to step S911 and repeats step S911 and the subsequent steps. If it determines that the rewrite is completed (S920: Yes), CGW13 transfers the rewrite target ECU19 in the stopped state or the sleep state to the activated state (S921), and ends the monitoring process of the remaining battery capacity. Here, the values of the first specified capacity and the second specified capacity can be pre-held by CGW13, or the values specified by rewriting the specification data can be used.

[0615] In addition, CGW13 can also exclude, for example, the ECU19 with a specific function such as an alarm function from the objects to be transferred to the stopped state or the sleep state in step S919, and transfer the non-rewrite target ECU19 other than the ECU19 with the specific function from the activated state to the stopped state or the sleep state. When it is possible to execute application control in the rewrite target ECU19 for rewriting the application program, CGW13 can also set the non-rewrite target ECU19 other than the ECU19 that can communicate with the rewrite target ECU19 to the stopped state or the sleep state. When all the ECUs19 are in the stopped state or the sleep state, and if the rewrite condition is satisfied, for example, the vehicle position becomes the specified position or the current time becomes the specified time, CGW13 can also transfer the rewrite target ECU19 from the stopped state or the sleep state to the activated state.

[0616] CGW13 can also group the rewrite target ECU19 or non-rewrite target ECU19 with any one of the start power supply (+B power supply system ECU, ACC system ECU, IG system ECU), domain group (body system, driving system, multimedia system), and synchronization timing as a reference, and make the rewrite target ECU19 in the start state in units of groups, or make the non-rewrite target ECU19 in the stop state or sleep state in units of groups.

[0617] In addition, CGW13 can also be configured to perform power control in units of buses. That is, if it is determined that all ECUs 19 connected to a specific bus are non-rewrite target ECUs 19, CGW13 can also transfer all non-rewrite target ECUs 19 connected to the specific bus to the stop state or sleep state by disconnecting the power supply of the specific bus.

[0618] As described above, CGW13 performs power management processing for non-rewrite targets. Thus, if it is determined that the rewrite target ECU19 can be installed, at least one or more non-rewrite target ECUs 19 are made into the stop state, sleep state, or power-saving operation state. It is possible to prevent the situation where the battery margin of the vehicle battery 40 becomes insufficient during the rewrite of the application program. In addition, since the non-rewrite target ECU19 is in the stop state, sleep state, or power-saving operation state, it is possible to suppress an increase in communication load.

[0619] (10) Transmission control processing of files

[0620] Refer to Figures 88 to 97 The transmission control processing of files will be described. The vehicle program rewrite system 1 performs the transmission control processing of files in CGW13. This embodiment is the processing when the rewrite data held by DCM12 (equivalent to the first device) is sent to the rewrite target ECU19 (equivalent to the third device) via CGW13 (equivalent to the second device).

[0621] As Fig.88 shown, CGW13 has a transmission target file determination unit 82a, a first data size determination unit 82b, an acquisition information determination unit 82c, a second data size determination unit 82d, and a split file transmission request unit 82e in the file transmission control unit 82. The transmission target file determination unit 82a determines the file including the write data to be written to the rewrite target ECU19 as the transmission target file using the analysis result of the rewrite specification data. For example, when the rewrite target ECU19 is ECU (ID1), ECU (ID2), and ECU (ID3), the transmission target file determination unit 82a selects from Figure 8The ECU information of the rewriting specification data acquisition ECU (ID1), ECU (ID2), and ECU (ID3) for CGW is obtained, and the file including the write data is determined as the transfer target file based on the obtained ECU information. As the transfer target file, it is possible to determine the address and index at the time of obtaining the file, or the file name of the file.

[0622] If the transfer target file is determined by the transfer target file determination unit 82a, the first data size determination unit 82b determines the first data size for obtaining the transfer target file. If the transfer target file is determined by the transfer target file determination unit 82a, the acquisition information determination unit 82c determines the address as the acquisition information for obtaining the transfer target file. In addition, in the present embodiment, the address is determined as the acquisition information for obtaining the transfer target file, but if it is the acquisition information for obtaining the transfer target file, it is not limited to the address, and may also be a file name, ECU (ID), etc. The second data size determination unit 82d determines the second data size for distributing the write data to the rewrite target ECU 19. That is, the first data size is the data transfer size from the DCM 12 to the CGW 13, and the second data size is the data transfer size from the CGW 13 to the rewrite target ECU 19.

[0623] If the address is determined by the acquisition information determination unit 82c and the first data size is determined by the first data size determination unit 82b, the split file transfer request unit 82e designates the address and the first data size to the DCM 12 and requests the transfer of the split file from the DCM 12. For example, when the amount of data of the write file to be distributed to the ECU (ID1) is 1 Mbyte, the split file transfer request unit 82e requests the transfer of the write data in 1 kbyte units from the address 0x10000000.

[0624] Next, refer to Figures 89 to 97 The operation of the file transfer control unit 82 in the CGW 13 will be described. The CGW 13 executes a file transfer control program and performs file transfer control processing.

[0625] If the CGW 13 determines that it has received the unpacking completion notification signal from the DCM 12, it starts file transfer control processing. Unpacking refers to the process of dividing the distributed data packet file into data for each ECU and each rewriting specification data as shown in Fig.10 If the CGW 13 starts file transfer control processing, it sends a specified address to the DCM 12 (S1001). When the DCM 12 receives the specified address from the CGW 13, it takes the reception of the specified address as an opportunity to transfer the rewriting specification data for CGW to the CGW 13. The CGW 13 obtains the rewriting specification data for CGW by being transferred the rewriting specification data for CGW from the DCM 12 (S1002).

[0626] If CGW13 obtains the rewriting specification data for CGW from DCM12, it parses the obtained rewriting specification data for CGW (S1003), and determines the file to be transmitted according to the parsing result of the rewriting specification data (S1004, equivalent to the transmission object file determination step). CGW13 determines the address corresponding to the file to be transmitted (S1005, equivalent to the information acquisition determination step), and determines the first data size corresponding to the file to be transmitted (S1006, equivalent to the first data size determination step). CGW13 sends the determined address and data size to DCM12 according to the provisions of SID (Service Identifier) 35, designates the address and data size for the memory area, and requests DCM12 to transmit the split file (S1007).

[0627] If DCM12 receives the address and data size from CGW13, it parses the rewriting specification data for DCM, and transmits the file corresponding to the address and data size to CGW13 as a split file. CGW13 obtains the split file by receiving the split file transmitted from DCM12 (S1008). In this case, CGW13 can also store the obtained file in the flash memory after storing it in the RAM.

[0628] CGW13 determines whether the acquisition of all split files to be acquired has been completed (S1009). For example, when the data volume of the write file to be distributed to the ECU (ID1) is 1M bytes, CGW13 acquires split files of every 1k bytes, repeats the acquisition of split files of every 1k bytes, and determines whether the acquisition of 1M byte data volume has been completed. If CGW13 determines that the acquisition of all split files to be acquired has not been completed (S1009: "No"), it returns to step S1004 and repeats the steps after step S1004. If CGW13 determines that the acquisition of all files to be acquired has been completed (S1009: "Yes"), it ends the file transfer control process. In addition, when there are multiple ECUs 19 to be rewritten, CGW13 repeats the above file transfer control process for each ECU 19 to be rewritten.

[0629] That is, for example, when the ECUs 19 to be rewritten are ECU (ID1), ECU (ID2), and ECU (ID3), if CGW13 finishes distributing the write data to ECU (ID1), it performs the file transfer control process for ECU (ID2), and if it finishes distributing the write data to ECU (ID2), it performs the file transfer control process for ECU (ID3). In addition, CGW13 can perform the transfer control process for multiple ECUs 19 to be rewritten sequentially, or can perform it in parallel.

[0630] In Fig.90 it, it means that in the memory of DCM12, for example, the written data file of ECU (ID1) is stored at addresses "1000" to "3999", the written data file of ECU (ID2) is stored at addresses "4000" to "6999", and the written data file of ECU (ID3) is stored at addresses "7000" to.

[0631] In this case, as Fig.91 shown, if CGW13 receives the unpacking completion notification signal from DCM12, it sends address "0000" to DCM12 and obtains the rewrite specification data from DCM12. That is, if DCM12 determines that the reception of address "0000" is a request for obtaining rewrite data for CGW, it sends the rewrite specification data for CGW to CGW13. CGW13 designates ECU (ID1) as the transmission object of the written data, designates address "1000" and data size "1 kbyte", and obtains the split file containing the written data of ECU (ID1) stored at addresses "1000" to "1999" from DCM12. If CGW13 obtains the split file from DCM12, it distributes the written data contained in the split file to ECU (ID1).

[0632] Next, CGW13 similarly designates ECU (ID1) as the transmission object of the written data, designates address "2000" and data size "1 kbyte", and obtains the split file containing the written data of ECU (ID1) stored at addresses "2000" to "2999" from DCM12. If CGW13 obtains the split file from DCM12, it distributes the written data contained in the split file to ECU (ID1). Until the writing of the written data to ECU (ID1) is completely finished, CGW13 repeats obtaining the split file in 1 kbyte units from DCM12 and repeats distributing the written data contained in the split file to ECU (ID1). That is, if CGW13 obtains 1 kbyte of written data from DCM12, it sends the 1 kbyte of written data to the rewrite target ECU19, and if the sending to the rewrite target ECU19 is completed, it obtains the next 1 kbyte of written data from DCM12. CGW13 repeats these processes until the writing is completely finished.

[0633] If the writing of the write data is normally completed in the ECU (ID1), the ECU (ID2) is specified as the transfer object of the write data, the address "4000" and the data size "1 kbyte" are specified, and the split file containing the write data of the ECU (ID2) stored at the addresses "4000" to "4999" is obtained from the DCM12. If the CGW13 obtains the split file from the DCM12, the write data included in the split file is distributed to the ECU (ID2).

[0634] If the writing of the write data is normally completed in the ECU (ID2), the ECU (ID3) is specified as the transfer object of the write data, the address "7000" and the data size "1 kbyte" are specified, and the split file containing the write data of the ECU (ID2) stored at the addresses "7000" to "7999" is obtained from the DCM12. If the CGW13 obtains the split file from the DCM12, the write data included in the split file is distributed to the ECU (ID2).

[0635] As described above, the CGW13 determines the transfer object file according to the analysis result of the rewrite specification data by performing the file transfer control process, and determines the address and data size corresponding to the transfer object file. The CGW13 specifies the address and data size to the DCM12, requests the DCM12 to transfer the split file obtained by splitting the transfer object file, and obtains the split file from the DCM12. Thus, in the state where the write data of a large capacity is stored in the memory of the DCM12, the write data can be distributed to the ECU19. That is, in the CGW13, there is no need to prepare a memory for storing a file of a large capacity, and the memory capacity of the CGW13 can be reduced.

[0636] Here, the relationship between the data amount of the split file transferred from the DCM12 to the CGW13 and the data amount of the write file distributed from the CGW13 to the rewrite target ECU19 will be described. In the above example, as Fig.92 shown, the case where the data amount of the split file transferred from the DCM12 to the CGW13 is 1 kbyte is described, but the relationship between the data amount of the split file transferred from the DCM12 to the CGW13 and the data amount of the write file distributed from the CGW13 to the rewrite target ECU19 can also be arbitrary.

[0637] That is, for example, if, due to reasons related to CAN communication, the ECU 19 to be rewritten adopts a specification of receiving write data in 4-kilobyte units, the CGW 13 distributes the data volume of the write file to the ECU 19 to be rewritten in 4-kilobyte units. In this case, if the data volume of the split file transmitted from the DCM 12 to the CGW 13 is 1 kilobyte, the CGW 13 distributes 4 kilobytes to the ECU 19 to be rewritten after obtaining four split files from the DCM 12. That is, the data volume of the split file transmitted from the DCM 12 to the CGW 13 is smaller than the data volume of the write file distributed from the CGW 13 to the ECU 19 to be rewritten. In such a relationship, in the CGW 13, an increase in the memory capacity can be suppressed, and the split files can be obtained from the DCM 12 in parallel and the write data can be distributed to the ECU 19 to be rewritten.

[0638] That is, if the data volume of the split file transmitted from the DCM 12 to the CGW 13 is 4 kilobytes, in order to obtain the split files from the DCM 12 in parallel and distribute the write data to the ECU 19 to be rewritten, the memory capacity of the CGW 13 needs to be 8 kilobytes. By making the data volume of the split file transmitted from the DCM 12 to the CGW 13 1 kilobyte, it is possible to obtain the split files from the DCM 12 in parallel and distribute the write data to the ECU 19 to be rewritten without making the memory capacity of the CGW 13 8 kilobytes. For example, if the memory capacity of the CGW 13 is ensured to be 5 kilobytes in advance, the CGW 13 distributes 4 kilobytes obtained from the DCM 12 to the ECU 19 to be rewritten, and obtains the next 1 kilobyte from the DCM 12. Moreover, after the CGW 13 has completed distributing 4 kilobytes to the ECU 19 to be rewritten, it further obtains the next 1 kilobyte from the DCM 12.

[0639] On the other hand, for example, if, due to reasons related to CAN communication, the ECU 19 to be rewritten adopts a specification of receiving write data in 128-byte units, the CGW 13 distributes the write data to the ECU 19 to be rewritten in 128-byte units. In this case, if the data volume of the split file transmitted from the DCM 12 to the CGW 13 is 1 kilobyte, the CGW 13 distributes the data in 128-byte units to the ECU 19 to be rewritten after obtaining one split file from the DCM 12. That is, the data volume of the split file transmitted from the DCM 12 to the CGW 13 is larger than the data volume of the write file distributed from the CGW 13 to the ECU 19 to be rewritten. For example, if the memory capacity of the CGW 13 is ensured to be 2 kilobytes in advance, the CGW 13 distributes 1 kilobyte obtained from the DCM 12 to the ECU 19 to be rewritten in 128-byte units, and obtains the next 1 kilobyte from the DCM 12. Moreover, after the CGW 13 has completed distributing 128 bytes × 8 times to the ECU 19 to be rewritten, it further obtains the next 1 kilobyte from the DCM 12.

[0640] In this way, as long as the data volume of the split file transmitted from DCM12 to CGW13 is a fixed value (e.g., 1 kbyte), the data volume of the write file distributed from CGW13 to the ECU19 to be rewritten can be a variable value according to the specifications of the ECU19 to be rewritten. For example, CGW13 can also use the data transfer size of each ECU specified by the rewrite specification data to determine the data volume distributed to the ECU19 to be rewritten.

[0641] CGW13 sends a transfer request to DCM12 to request the transfer of the split file. As the method of requesting the transfer of the split file from DCM12, there are a first request method and a second request method. If the ECU19 to be rewritten finishes receiving the write data, it sends a reception completion notice indicating the completion of the reception of the write data to CGW13. If the ECU19 to be rewritten finishes writing the write data, it sends a write completion notice indicating the completion of the writing of the write data to CGW13.

[0642] Use Fig.93 The first distribution method will be described. If CGW13 obtains the split file from DCM12, it distributes the obtained split file as write data to the ECU19 to be rewritten. If the ECU19 to be rewritten finishes receiving the write data, it sends a reception completion notice to CGW13 and starts the write processing of the write data. If CGW13 receives the reception completion notice of the write data from the ECU19 to be rewritten, it sends a transfer request to DCM12 to request the transfer of the next split file. If CGW13 obtains the next split file from DCM12, it distributes the obtained next split file as write data to the ECU19 to be rewritten.

[0643] In this way, in the first distribution method, CGW13 obtains the next write data from DCM12 and distributes it to the ECU19 to be rewritten without waiting for the completion of the writing of the write data by the ECU19 to be rewritten. Therefore, in the first distribution method, in CGW13, if the ECU19 to be rewritten has not completed the writing of the write data, even if the next split file is obtained from DCM12 and the next write data is distributed to the ECU19 to be rewritten, the ECU19 to be rewritten may not be able to receive the next write data. However, if the ECU19 to be rewritten finishes writing the write data, it can quickly obtain the next split file from DCM12 and quickly distribute the next write data to the ECU19 to be rewritten.

[0644] Use Fig.94A description is given of the second distribution method. If CGW13 obtains a segmented file from DCM12, the obtained segmented file is distributed as write data to the ECU19 to be rewritten. If the ECU19 to be rewritten finishes receiving the write data, it sends a reception completion notification to CGW13 and starts the write process of the write data. If the ECU19 to be rewritten finishes writing, it sends a write completion notification to CGW13. If CGW13 receives a write completion notification from the ECU19 to be rewritten, it sends a transmission request to DCM12 and requests the transmission of the next segmented file. If CGW13 obtains the next segmented file from DCM12, the obtained next segmented file is distributed as write data to the ECU19 to be rewritten.

[0645] In this way, in the second distribution method, after waiting for the completion of the writing of the write data by the ECU19 to be rewritten, CGW13 obtains the next write data from DCM12 and distributes it to the ECU19 to be rewritten. Therefore, in the second distribution method, in CGW13, it takes time until the next segmented file is obtained from DCM12, and it is possible to request the transmission of the segmented file to DCM12 in a state where the writing of the write data by the ECU19 to be rewritten is completed. Therefore, if the next write data is distributed to the ECU19 to be rewritten by obtaining the next segmented file from DCM12, the next write data can be reliably distributed to the ECU19 to be rewritten.

[0646] In addition, CGW13 distributes write data to the ECU19 to be rewritten through SID34, 36, and 37. As a method of distributing write data to the ECU19 to be rewritten, there are a first distribution method and a second distribution method. In the first distribution method, as Fig.95 shown, CGW13 segments the write data to be distributed according to a specified data volume (for example, 1 kbyte) and distributes it. In the second distribution method, as Fig.96 shown, CGW13 distributes the write data to be distributed without segmentation in a unified manner. CGW13 selects either the first distribution method or the second distribution method through SID34 initially distributed to the ECU19 to be rewritten. As Fig.97 shown, CGW13 determines the reception of the write data of the ECU19 to be rewritten by receiving an ACK (SID74) for SID37 finally distributed to the ECU19 to be rewritten. The ACK for this SID37 is equivalent to passing through Fig.93 and Fig.94The above-mentioned reception completion notice for writing data. That is, in the first distribution method, if CGW13 receives the ACK for the last distribution of SID37 to the rewrite target ECU19, by incrementing the address of the next write data by 1, while distributing the next write data to the rewrite target ECU19, it further obtains the next write data from DCM12.

[0647] In addition, in the rewrite specification data for DCM, the address is associated with the file. However, as a method of associating the address with the file, for example, a folder structure can also be designed. Manage by storing the specification data in folder 1, storing file 1 in folder 2, and storing file 2 in folder 3. It can also be managed in the order of file names. For example Fig.10 In the unpacking shown, store the rewrite specification data for DCM and the rewrite specification data for CGW in folder 1, store the authentication symbol and differential data of ECU (ID1) in folder 2, and store the authentication symbol and differential data of ECU (ID2) in folder 3 for management.

[0648] In addition, for example, when CGW13 interrupts the distribution of write data to the rewrite target ECU19 for some reason such as communication interruption, it obtains information from the rewrite target ECU19 that can determine the address of the write where the write data is completed, and requests DCM12 to transmit the split file containing the write data from the moment when the write is not completed. Alternatively, CGW13 can also request DCM12 to transmit the split file containing the write data from the start.

[0649] As described above, if CGW13 determines the file containing the write data written to the rewrite target ECU19 as the transfer target file through file transfer control processing, determines the address and the first data size for obtaining the transfer target file, requests DCM12 to transmit the split file, and transmits the split file from DCM12, then it distributes the write data to the rewrite target ECU. The transmission of write data from DCM12 to CGW13 and the distribution of write data from CGW13 to the rewrite target ECU19 can be efficiently performed.

[0650] (11) Distribution control processing for write data

[0651] Refer to Figures 98 to 108 The distribution control processing for write data will be described. The vehicle program rewrite system 1 performs the distribution control processing for write data in CGW13. Since CGW13 sends write data to ECU19 via the in-vehicle bus, it performs the distribution control processing so that the bus load during the process of distributing the write data does not become too high.

[0652] As Fig.98As shown, assume a case where the +B power supply system ECU, the ACC system ECU, and the IG system ECU are connected to the same bus. In this case, in the +B power supply state, only the +B power supply system ECU is activated, and the ACC system ECU and the IG system ECU are stopped. Therefore, the vehicle control data of only the +B power supply system ECU is transmitted to the bus. When in the ACC power supply state, the +B power supply system ECU and the ACC system ECU are activated, and the IG system ECU is stopped. Therefore, the vehicle control data of the +B power supply system ECU and the ACC system ECU is transmitted to the bus. When in the IG power supply state, the +B power supply system ECU, the ACC system ECU, and the IG system ECU are activated. Therefore, the vehicle control data of the +B power supply system ECU, the ACC system ECU, and the IG system ECU is transmitted to the bus. That is, the order of the transmission amount of vehicle control data from the largest to the smallest is the IG power supply state, the ACC power supply state, and the +B power supply state.

[0653] As Fig.99 shown, CGW13 has a first correspondence determination unit 83a, a second correspondence determination unit 83b, a transmission allowance determination unit 83c, a distribution frequency determination unit 83d, a bus load measurement unit 83e, and a distribution control unit 83f in the data writing distribution control unit 83.

[0654] The first correspondence determination unit 83a determines a first correspondence indicating the relationship between the power supply state and the transmission allowance of the bus based on the analysis result of the rewrite specification data, and determines Fig.100 the bus load table shown. The transmission allowance refers to the value of the transmission load at which data can be transmitted and received without data collision or delay. The bus load table is a table showing the correspondence between the power supply state and the transmission allowance of the bus, and is specified for each bus. The transmission allowance is the sum of the transmission amounts of the vehicle control data and the written data that can be transmitted relative to the maximum transmission allowance.

[0655] In Fig.100 the example shown, the transmission allowance of the first bus is "80%" relative to the maximum transmission allowance. Therefore, in the IG power supply state, CGW13 allows "50%" of the maximum transmission allowance as the transmission allowance of the vehicle control data, and allows "30%" of the maximum transmission allowance as the transmission allowance of the written data. In addition, for the first bus, in the ACC power supply state, CGW13 allows "30%" of the maximum transmission allowance as the transmission allowance of the vehicle control data, and allows "50%" of the maximum transmission allowance as the transmission allowance of the written data. In addition, for the first bus, in the +B power supply state, CGW13 allows "20%" of the maximum transmission allowance as the transmission allowance of the vehicle control data, and allows "60%" of the maximum transmission allowance as the transmission allowance of the written data. As Fig.100 As shown, the second bus and the third bus are also defined in the same way.

[0656] The second correspondence determination unit 83b determines a second correspondence indicating the relationship between the bus to which the ECU 19 to be rewritten belongs and the power supply system based on the analysis result of the rewrite specification data, and determines Fig.101 the table of the ECU to be rewritten shown. The table of the ECU to be rewritten is a table indicating the bus and the power supply system to which the ECU 19 to be rewritten belongs.

[0657] In Fig.101 the example shown, for the first ECU 19 to be rewritten, the CGW 13 connects it to the first bus and starts in any of the +B power supply state, ACC power supply state, and IG power supply state. Therefore, the first ECU 19 to be rewritten is determined to be a +B power supply system ECU. In addition, for the second ECU 19 to be rewritten, the CGW 13 connects it to the second bus, stops in the +B power supply state, but starts in the ACC power supply state and the IG power supply state. Therefore, the second ECU 19 to be rewritten is determined to be an ACC system ECU. In addition, for the third ECU 19 to be rewritten, the CGW 13 connects it to the third bus, stops in the +B power supply state and the ACC power supply state, but starts in the IG power supply state. Therefore, the third ECU 19 to be rewritten is determined to be an IG system ECU.

[0658] The CGW 13 uses Figure 8 the data of "connected bus" and "connected power supply" in the rewrite specification data shown to determine which bus the ECU 19 to be rewritten is connected to and which power supply system it is. In addition, if these information can be determined, it is not necessarily required to be saved in the form of a table.

[0659] The transmission allowance determination unit 83c determines the transmission allowance of the bus to which the ECU 19 to be rewritten belongs, that is, the transmission allowance corresponding to the power supply state of the vehicle when the program is updated, based on the determination result of the first correspondence and the determination result of the second correspondence. Specifically described, the transmission allowance determination unit 83c uses the second correspondence, that is, the table of the ECU to be rewritten, to determine the bus to which the ECU 19 to be rewritten belongs, and uses the first correspondence, that is, the bus load table, to determine the transmission allowance for each power supply state for the determined bus.

[0660] The distribution frequency determination unit 83d determines the distribution frequency of the write data corresponding to the power supply state at the time of installation, using the correspondence relationship between the power supply state determined in advance and the distribution frequency of the write data. Specifically, the distribution frequency determination unit 83d uses the bus load table to determine the transmission allowance allocated for distributing the write data among the transmission allowances determined by the transmission allowance determination unit 83c, and determines the distribution frequency of the write data. For example, the distribution frequency determination unit 83d determines that the bus to which the ECU 19 to be rewritten belongs is the first bus, determines that the power supply state at the time of installation is the IG power supply state, determines the transmission allowance as "80%", and determines the transmission allowance allocated for distributing the write data among them as "30%", thereby determining the distribution frequency of the write data. The transmission allowance allocated for distributing the write data corresponds to the transmission limit information.

[0661] The bus load measurement unit 83e measures the bus load of the bus to which the ECU 19 to be rewritten belongs. For example, the bus load measurement unit 83e measures the bus load by counting the number of frames or bits received per unit time. The distribution control unit 83f controls the distribution of the write data according to the distribution frequency determined by the distribution frequency determination unit 83d.

[0662] Next, refer to Figures 102 to 108 The operation of the write data distribution control unit 83 in the CGW 13 will be described. The CGW 13 executes a write data distribution control program to perform write data distribution control processing.

[0663] When the CGW 13 receives the unpacking completion notification signal from the DCM 12, it starts the write data distribution control processing. The CGW 13 obtains the rewriting specification data for the CGW from the DCM 12 (S1101), and determines the bus load table and the table of the ECUs to be rewritten based on the rewriting specification data for the CGW (S1102). The CGW 13 determines the bus to which the ECU 19 to be rewritten belongs based on the table of the ECUs to be rewritten (S1103). The CGW 13 determines the transmission allowance corresponding to the bus to which the ECU 19 to be rewritten belongs, that is, the power supply state of the vehicle at the time of update, based on the bus load table. Moreover, the CGW 13 determines the distribution frequency of the write data in consideration of the determined transmission allowance (S1104, corresponding to the distribution frequency determination step). For example, when distributing the write data during vehicle travel for the first ECU 19 to be rewritten, that is, the ECU (ID1), the CGW 13 refers to the transmission allowance of the first bus in the IG power supply state. In Fig.100In the example, the transmission allowance of the first bus in the IG power supply state is "80%", where "50%" is allowed for vehicle control data transmission and "30%" is allowed for write data transmission. Additionally, the transmission allowance is ultimately a value used to represent an example, and for the numerical value, it is set within the allowable range according to the applicable communication specifications.

[0664] Since the specification for CAN at 500 [kbps] is about 250 [μs] per frame, if there are 4 interruptions in 1 second, four frames are generated and the bus load is 100%. CGW13 determines the distribution frequency of the write data by judging the interruptions generated on the bus. CGW13 starts measuring the number of frames received per unit time and starts measuring the bus load (S1105), judges whether the measured bus load exceeds the transmission allowance (S1106), and sets the distribution interval. The distribution interval refers to the time interval in CGW13 from distributing the write data to the target ECU19 to receiving the write completion notification (ACK) from the target ECU19 until the next write data is sent to the target ECU19.

[0665] If CGW13 determines that the measured bus load does not exceed the transmission allowance (S1106: "No"), it sets the distribution interval of the write data to the shortest interval set in advance, as Fig.103 shown, and starts distributing the write data to the target ECU19 (S1107, equivalent to the distribution control step). That is, CGW13 sets the distribution interval of one frame on CAN to the shortest interval set in advance and starts distributing the write data to the target ECU19. Additionally, one frame on CAN contains write data with a data volume of 8 bytes. Additionally, one frame on CAN FD (CAN with Flexible Data-Rate) contains write data with a data volume of 64 bytes.

[0666] On the other hand, if CGW13 determines that the measured bus load exceeds the transmission allowance (S1106: "Yes"), it calculates the interval when the bus load does not exceed the transmission allowance (S1108), sets the distribution interval of the write data to the calculated interval, as Fig.104 shown, and starts distributing the write data to the target ECU19 (S1109, equivalent to the distribution control step).

[0667] For example, in the IG power supply state, CGW13 determines whether the bus load exceeds the transmission allowance of "80%" for the first bus. If it determines that the bus load does not exceed the transmission allowance, it sets the distribution interval T1 with the transmission allowance of the write data being "30%". That is, as Fig.100As shown in the bus load table, CGW13 uses the transfer allowance of "30%" for the write data in the first bus in the IG power state to set the distribution interval T1. CGW13 sets the distribution interval T1 to be the maximum allowable transfer amount. In addition, CGW13 can also converge the measurement object to the frame of the write data to measure the bus load, and determine whether the bus load based on the write data exceeds the transfer allowance of the write data "30%". If CGW13 determines that the bus load exceeds the transfer allowance, it changes to the distribution interval T2 (>T1) where the bus load does not exceed the transfer allowance according to the amount by which the bus load exceeds the transfer allowance. In this way, after CGW13 obtains the write data from DCM12, it waits until the set distribution interval is reached, and then distributes the write data to the ECU19 to be rewritten.

[0668] If CGW13 starts to distribute the write data to the ECU19 to be rewritten, it determines whether the distribution of the write data to the ECU19 to be rewritten is completed, and continuously determines whether the measured bus load exceeds the transfer allowance (S1110, S1011). If CGW13 determines that the measured bus load does not exceed the transfer allowance (S1111: "No"), it sets the distribution interval of the write data to the shortest interval set in advance, and changes the distribution interval for distributing the write data to the ECU19 to be rewritten (S1112). On the other hand, if CGW13 determines that the measured bus load exceeds the transfer allowance (S1111: "Yes"), it calculates the interval where the bus load does not exceed the transfer allowance (S1113), sets the distribution interval of the write data to the calculated interval, and changes the distribution interval for distributing the write data to the ECU19 to be rewritten (S1114).

[0669] If CGW13 determines that the distribution of the write data to the ECU19 to be rewritten is completed (S1110: "Yes"), it stops measuring the number of frames received per unit time, stops measuring the bus load (S1115), and ends the distribution control process of the write data. Here, when there are multiple ECUs19 to be rewritten, CGW13 performs the distribution control process of the write data for the installation to all the ECUs19 to be rewritten.

[0670] As described above, by performing the distribution control process of the write data, CGW13 uses the correspondence relationship between the predetermined power state and the distribution frequency of the write data to determine the distribution frequency of the write data distributed to the ECU19 to be rewritten, and controls the distribution of the write data according to the distribution frequency. It is possible to suppress data conflicts, delays, etc. during installation. In addition, it is possible to make the distribution of the write data coexist without interfering with the distribution of the vehicle control data in the same bus.

[0671] In addition, as described above, in CGW13, the configuration of the bus load table is exemplified as being determined based on the analysis result of the rewrite specification data, or the configuration of the bus load table may be pre-stored. In addition, in CGW13, the configuration of the table to which the ECU to be rewritten belongs is exemplified as being determined based on the analysis result of the rewrite specification data, but the configuration of the table to which the ECU to be rewritten belongs may be pre-stored.

[0672] It is also possible to make the distribution amount of the written data relatively small in the power supply state during vehicle driving and make the distribution amount of the written data relatively large in the power supply state during parking. That is, as Fig.105 shown, when the IG power supply is turned on during vehicle driving, CGW13 sends CAN frames through the IG system ECU, the ACC system ECU, and the +B power supply system ECU, and makes the transmission amount of application data such as vehicle control and diagnosis relatively large, so the distribution amount of the written data is relatively small. In addition, as Fig.106 shown, when the IG power supply is turned off during parking, CGW13 sends CAN frames only through the +B power supply system ECU, and makes the transmission amount of application data such as vehicle control and diagnosis relatively small, and makes the distribution amount of the written data relatively large. That is, CGW13 adjusts the distribution amount of the written data within the idle capacity that does not interfere with the transmission of application data such as vehicle control and diagnosis.

[0673] In addition, it is also possible to, as Fig.107 shown, in CGW13, when an event frame is sent from the ECU 19 to be rewritten, the frequency of interruption becomes higher and the bus load becomes higher by receiving the event frame, so the distribution amount of the written data is relatively small. When an event frame is not sent from the ECU 19 to be rewritten, the distribution amount of the written data is relatively large.

[0674] In addition, it is also possible to, as Fig.108 shown, in the vehicle system, when it is determined that CGW13 is in the distribution of the written data, the bus load is reduced by extending the transmission interval of application data such as vehicle control and diagnosis to the maximum allowed interval. In CGW13, it is also possible to reduce the bus load by extending the transmission interval of application data by the vehicle system, thereby making the distribution amount of the written data relatively large.

[0675] The bus load table embedded in the rewrite specification data is, for example, uniformly shared and set regardless of the vehicle manufacturer's model, grade, etc. This is because if the equipment of the ECU varies greatly due to, for example, the model, grade, etc., the bus load varies greatly. If the optimal bus load table is set independently according to the model, grade, etc., it is necessary to spend time and effort in the verification and it is cumbersome, so such cumbersome troubles are avoided.

[0676] Similarly to the case where the vehicle is installed while in motion as described above, when the vehicle is installed while parked, distribution control processing for writing data is also performed. In this case, if the ECU 19 to be rewritten is a +B power supply system ECU, it can also be updated in the +B power supply state, so the transmission allowance amount in the +B power supply state in the bus load table is referred to. On the other hand, when the ECU 19 to be rewritten is an IG system ECU, it is installed in the IG power supply state, so the transmission allowance amount in the IG power supply state in the bus load table is referred to. Here, for example, when the ECU 19 to be rewritten is an ACC system ECU, it can also be installed in the IG power supply state. In this case, the transmission allowance amount in the IG power supply state in the bus load table is referred to. In addition, the configuration of the bus load table and the table to which the ECU to be rewritten belongs has been described, but as long as the distribution frequency of the data to be written for each power supply state can be determined, it can also be in the form of saving any table.

[0677] (12) Indication processing of activation request

[0678] Refer to Figures 109 to 111 The indication processing of the activation request will be described. The vehicle program rewriting system 1 performs the indication processing of the activation request in the CGW 13. The CGW 13 makes an activation request to make the rewritten program effective for a plurality of ECUs 19 to be rewritten for which the application program has been rewritten. In the present embodiment, the CGW 13 becomes aware of the state of the group of the ECUs 19 to be rewritten by analyzing the rewriting specification data for the CGW. In addition, the CGW 13 makes an activation request only while the vehicle is parked and does not make an activation request while the vehicle is in motion.

[0679] As Fig.109 shown, the CGW 13 has a rewriting object determination unit 84a, a rewriting completion determination unit 84b, an activation executable determination unit 84c, and an activation request indication unit 84d in the activation request indication unit 84. The rewriting object determination unit 84a targets a plurality of ECUs 19 for cooperative control and determines the plurality of ECUs 19 to be rewritten. If the rewriting completion determination unit 84b determines a plurality of ECUs 19 to be rewritten through the rewriting o...

Claims

1. A main device for a vehicle, wherein, Comprising: An update data acquisition unit that acquires update data from the outside; An update data distribution unit that distributes the update data acquired by the update data acquisition unit to an electronic control device to be rewritten, which is equipped with a non-volatile memory having a program storage surface on one surface or more surfaces; A cancellation request determination unit that determines whether a cancellation request has occurred in the program rewrite from an old program to a new program achieved by distributing the update data to the electronic control device to be rewritten through the update data distribution unit; A rollback method determination unit that, when the cancellation request determination unit determines that the cancellation request has occurred, determines a rollback method for returning the state of the electronic control device to be rewritten to the state before starting to write the update data, based on the memory type of the non-volatile memory mounted on the electronic control device to be rewritten and the data type of the update data of the new program or the old program. As the memory type of the non-volatile memory, it is determined whether the program storage surface is one surface or two or more surfaces. As the data type of the update data, it is determined whether the update data is all data equivalent to the entire program or differential data equivalent to the difference between the old application program and the new application program; and A rollback execution unit that instructs the electronic control device to be rewritten to perform a rollback corresponding to the rollback method determined by the rollback method determination unit, so that the electronic control device to be rewritten operates with the old program.

2. The main device for a vehicle according to claim 1, wherein when the program storage surface is one surface, the rollback execution unit instructs the electronic control device to be rewritten to write the update data of the old program, so that the electronic control device operates with the old program.

3. The main device for a vehicle according to claim 2, wherein when the program storage surface is one surface and the update data of the old program is all data equivalent to the entire program, the rollback execution unit aborts the writing of the update data of the new program. When the program storage surface is one surface and the update data of the old program is differential data equivalent to the difference between the old application program and the new application program, the writing of the update data of the new program is continued until completion.

4. The main device for a vehicle according to claim 1, wherein when the program storage surface is two or more surfaces, the rollback execution unit instructs the electronic control device to be rewritten to suppress the switching of the operation surface from the old surface to the new surface, so that the electronic control device to be rewritten operates with the old program.

5. A main device for a vehicle, wherein, Comprising: An update data acquisition unit that acquires update data from the outside; An update data distribution unit that distributes the update data acquired by the update data acquisition unit to an electronic control device to be rewritten, which is equipped with a non-volatile memory having a program storage surface on one surface or more surfaces; A cancellation request determination unit that determines whether a cancellation request has occurred in the program rewrite from an old program to a new program achieved by distributing the update data to the electronic control device to be rewritten through the update data distribution unit; And The rollback execution unit, when the cancellation request determination unit determines that the cancellation request has been generated, continues to distribute the update data of the new program until the rewriting is completed if the program storage surface is one surface, instructs the electronic control device of the rewriting object to write the update data of the old program, and causes the electronic control device of the rewriting object to operate with the old program; and when the program storage surface is two or more surfaces having an operating surface and a non-operating surface as a surface for writing the new program, continues to distribute the update data of the new program until the rewriting is completed, and causes the electronic control device of the rewriting object to operate with the program stored on the operating surface.

6. The vehicle main device according to claim 5, wherein: When there are two or more program storage surfaces, the rollback execution unit instructs the electronic control device to be rewritten to suppress switching of the operation surface from the old surface to the new surface after continuing to distribute the update data of the new program until rewriting is completed.

7. The vehicle main device according to claim 5, wherein: When the cancellation request determination unit determines that the cancellation request has been generated, the rollback execution unit suspends writing of the update data of the new program when the program storage surface is one surface and the update data of the old program are all data equivalent to the entire program, and the rollback execution unit continues writing of the update data of the new program until completion when the program storage surface is one surface and the update data of the old program are differential data equivalent to the difference between the old application and the new application.

8. A rollback execution control method, comprising: performing the following steps in a vehicle main device that acquires update data from an external device and distributes the acquired update data to an electronic control device to be rewritten, the electronic control device having a non-volatile memory having a program storage surface on one or more surfaces: a cancellation request determination step of determining whether a cancellation request has been generated in program rewriting from an old program to a new program by distributing update data to an electronic control device to be rewritten; Rollback method determination step: When it is determined in the above cancellation request determination step that the above cancellation request has occurred, a rollback method for returning the state of the electronic control device to be rewritten to the state before starting to write the update data is determined according to the memory type of the non-volatile memory mounted on the electronic control device to be rewritten and the data type of the update data of the new program or the old program, where As the memory type of the nonvolatile memory, it is determined whether the program storage surface is one surface or two or more surfaces, and as the data type of the updated data, it is determined whether the updated data is all data corresponding to the entire program or differential data corresponding to the difference between the old application and the new application; as well as The rollback execution step instructs the electronic control device to be rewritten to perform a rollback corresponding to the rollback method determined in the rollback method determination step, so that the electronic control device to be rewritten operates with the old program.

9. A rollback execution control method, comprising: performing the following steps in a vehicle main device that acquires update data from an external device and distributes the acquired update data to an electronic control device to be rewritten, the electronic control device being equipped with a non-volatile memory having a program storage surface on one or more surfaces: a cancellation request determination step of determining whether a cancellation request has been generated in program rewriting from an old program to a new program by distributing update data to an electronic control device to be rewritten; and Rollback execution step: In the case where it is determined by the above cancellation request determination step that the above cancellation request has occurred, when the program storage surface is a single surface, continue the distribution of the update data of the above new program until the rewrite is completed, instruct the electronic control device of the above rewrite target to write the update data of the old program, and cause the electronic control device of the above rewrite target to operate with the above old program. When the program storage surface is two or more surfaces including an operating surface and a non-operating surface for writing the above new program, continue the distribution of the update data of the above new program until the rewrite is completed, and cause the electronic control device of the above rewrite target to operate with the program stored in the above operating surface.

10. A recording medium stores an execution control program for rollback, which causes a vehicle main device that acquires update data from the outside and distributes the acquired update data to an electronic control device of a rewrite target equipped with a non-volatile memory having a program storage surface on one or more surfaces to perform the following steps: Cancellation request determination step: Determine whether a cancellation request has occurred in the program rewrite from the old program to the new program achieved by distributing the update data to the electronic control device of the rewrite target. Rollback method determination step: In the case where it is determined by the above cancellation request determination step that the above cancellation request has occurred, a rollback method for returning the state of the electronic control device to be rewritten to the state before starting to write the update data is determined according to the memory type of the non-volatile memory mounted on the electronic control device to be rewritten and the data type of the update data of the new program or the old program, where As the memory type of the non-volatile memory, determine whether the program storage surface is a single surface or two or more surfaces. As the data type of the update data, determine whether the update data is all data equivalent to the entire program or differential data equivalent to the difference between the old application program and the new application program. And Rollback execution step: Instruct the electronic control device of the rewrite target to perform a rollback corresponding to the rollback method determined by the above rollback method determination step, and cause the electronic control device of the above rewrite target to operate with the old program.

11. A recording medium stores an execution control program for rollback, which causes a vehicle main device that acquires update data from the outside and distributes the acquired update data to an electronic control device of a rewrite target equipped with a non-volatile memory having a program storage surface on one or more surfaces to perform the following steps: Cancellation request determination step: Determine whether a cancellation request has occurred in the program rewrite from the old program to the new program achieved by distributing the update data to the electronic control device of the rewrite target; and Rollback execution step: In the case where it is determined by the above cancellation request determination step that the above cancellation request has occurred, when the program storage surface is a single surface, continue the distribution of the update data of the above new program until the rewrite is completed, instruct the electronic control device of the above rewrite target to write the update data of the old program, and cause the electronic control device of the above rewrite target to operate with the above old program. When the program storage surface is two or more surfaces including an operating surface and a non-operating surface for writing the above new program, continue the distribution of the update data of the above new program until the rewrite is completed, and cause the electronic control device of the above rewrite target to operate with the program stored in the above operating surface.

Citation Information

Patent Citations

  • System, method, and computer program for updating programs

    JP2017157004A

  • Image forming apparatus, replacement unit, and method for determining replacement unit

    JP2018151418A

  • X-ray examination aid set

    JP2019129958A

  • Method and device for upgrading recovery partition of intelligent equipment

    CN107133056A

  • Software staging and back spacing method

    CN1889041A