Apparatus and method for controlling updates of vehicle ecus

By using a state division strategy based on battery SOC to coordinate and control ECU updates, the problem of not being able to complete all ECU updates within a driving cycle in traditional technologies is solved. This enables efficient ECU updates when the vehicle has limited battery power, ensuring the normal operation of autonomous driving functions.

CN113859145BActive Publication Date: 2025-11-04HYUNDAI MOTOR CO LTD +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202011370258.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-06-30
Filing Date
2020-11-30
Publication Date
2025-11-04
Estimated Expiration
2040-11-30

AI Technical Summary

Technical Problem

Traditional technologies cannot complete the relevant software update within one driving cycle when updating vehicle ECU software, causing autonomous driving functions to malfunction, especially when the battery power is low, as it cannot efficiently complete the update of all ECUs.

Method used

By dividing the ECU update strategy based on the battery SOC state into updates for startup and shutdown states, and using communication devices and controllers to coordinate the control of ECU updates, the software updates of all ECUs are ensured to be completed within a driving cycle.

Benefits of technology

It enables efficient software updates for all ECUs even with limited battery power, ensuring the normal operation of the vehicle's autonomous driving functions during driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113859145B_ABST
    Figure CN113859145B_ABST
Patent Text Reader

Abstract

The present invention relates to an apparatus and method for controlling updates of vehicle ECUs. A communication device receives a request for a related software update of electronic control units (ECUs) arranged within a vehicle, a controller determines whether to start the vehicle based on a state of charge (SOC) of a battery. The controller performs the update on ECUs in a first group in a started state of the vehicle and performs the update on ECUs in a second group in an off state of the vehicle to complete the software update involving functions of the plurality of ECUs.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims priority to Korean Patent Application No. 10-2020-0080432, filed on June 30, 2020, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This invention relates to a technique for controlling updates (e.g., firmware updates) of electronic control units (ECUs) located in a vehicle. Background Technology

[0004] With the rapid development of vehicle component digitization, the types and number of electronic devices installed in vehicles have greatly increased. These electronic devices can be used in powertrain control systems, body control systems, chassis control systems, vehicle networks, multimedia systems, etc. Powertrain control systems can include engine control systems, automatic transmission control systems, etc. Body control systems can include body electronic control systems, convenience device control systems, and lighting control systems, etc. Chassis control systems can include steering control systems, braking control systems, and suspension control systems, etc. Vehicle networks can include Controller Area Networks (CAN), FlexRay-based networks, and Media-Oriented System Transport (MOST)-based networks, etc. Multimedia systems can include navigation systems, telematics systems, and infotainment systems, etc.

[0005] These systems and the electronic devices that make up each system are interconnected via a vehicle network, which is required to support the functionality of each electronic device. CAN can support transmission speeds up to 1 Mbps and can support automatic retransmission of collision frames, error detection based on Cyclic Redundancy Check (CRC), etc. FlexRay-based networks can support transmission speeds up to 10 Mbps and can support simultaneous data transmission through two channels, synchronous data transmission, etc. MOST-based networks are communication networks for high-quality multimedia and can support transmission speeds up to 150 Mbps.

[0006] In one example, a vehicle's telematics system, infotainment system, and enhanced safety systems require high transmission speeds and system scalability, which CAN and FlexRay-based networks cannot adequately support. While MOST-based networks can support even higher transmission speeds compared to CAN and FlexRay, applying MOST-based networks to all vehicle networks would be prohibitively expensive. Therefore, Ethernet-based networks can be considered as vehicle networks. Ethernet-based networks can support bidirectional communication via a pair of windings and can support transmission speeds up to 10Gbps.

[0007] Recently, the demand for updates (software updates) of ECUs arranged in a vehicle is increasing, and accordingly, various schemes for updating each ECU connected to a vehicle network have been proposed. In the process of updating a plurality of ECUs, when the state of charge (SOC) of a battery arranged in a vehicle is equal to or less than a reference value (for example, 75%), a conventional technique for updating each ECU arranged in a vehicle performs an update on an ECU that is currently being updated; when the SOC of the battery in the future exceeds the reference value, an update is performed on the remaining ECUs (for example, ECUs waiting for an update).

[0008] In the case of updating an ECU (single software update) for a function that operates independently of each other, the conventional technique does not affect the travel of the vehicle. However, in the case of performing a related software update (for example, an update of an ECU related to an autonomous driving function), such a conventional technique must update all ECUs related to the autonomous driving function, which is not possible, thereby making the vehicle unable to normally travel. In other words, the problem of the conventional technique is that since the related software update of the ECU is not possible to be completed within one driving cycle, normal autonomous driving is not possible.

[0009] The matters described in this BACKGROUND section are intended to provide background information and can include matters that are not prior art with respect to the present application. SUMMARY

[0010] The present application provides an apparatus and method for controlling an update of a vehicle ECU, which is capable of determining whether to start a vehicle based on a state of charge (SOC) of a battery when a related software update is performed on an ECU arranged in the vehicle, dividing ECUs to be updated in a state in which the vehicle is started and ECUs to be updated in a state in which the vehicle is turned off, and collectively performing the related software update on the ECUs, thereby normally completing a software update of a function related to a plurality of ECUs.

[0011] The technical problems solved by the present application concept are not limited to the above problems, and any other technical problems not mentioned herein will be clearly understood by those skilled in the art from the following description.

[0012] According to an aspect of the present application, an apparatus for controlling an update of a vehicle ECU can include a communication device configured to receive a request for a related software update of an electronic control unit (ECU) arranged in a vehicle; and a controller configured to determine whether to start a vehicle based on a state of charge (SOC) of a battery, perform an update on ECUs in a first group in a started state of the vehicle, and perform an update on ECUs in a second group in an off state of the vehicle.

[0013] In one embodiment, the controller can be configured to start the vehicle when the SOC of the battery is equal to or less than a reference SOC in case that the battery outputs total electric power required for updating the ECUs. In one embodiment, the controller can be configured to perform rollback on the ECUs for which the update is completed when there is an ECU for which the update fails in case that the update is performed on the ECUs in the first group. Further, the controller can be configured to turn off the vehicle when the update of the ECUs in the first group is completed and then perform the update of the ECUs in the second group.

[0014] The controller can be configured to turn off the vehicle when the SOC of the battery exceeds the reference SOC in case that the battery outputs total electric power required for updating the ECUs in the second group. The controller can be configured to perform rollback on the ECUs for which the update is completed when there is an ECU for which the update fails in case that the update is performed on the ECUs in the second group. The communication device can be configured to receive information on the plurality of ECUs to be updated, update data applied to each of the plurality of ECUs, information on the ECUs included in the first group, and information on the ECUs included in the second group from the update server. The device can further include an output device configured to display a window asking whether a user approves of the relevant software update, and an input device configured to receive approval or rejection of the relevant software update from the user.

[0015] According to another aspect of the present application, a method for controlling update of ECUs of a vehicle can include receiving a request for a relevant software update of electronic control units (ECUs) arranged in the vehicle, determining whether to start the vehicle based on a state of charge (SOC) of a battery, performing the update on ECUs in a first group in a started state of the vehicle, and performing the update on ECUs in a second group in an off state of the vehicle.

[0016] In one embodiment, determining whether to start the vehicle can include starting the vehicle when the SOC of the battery is equal to or less than a reference SOC in case that the battery outputs total electric power required for updating the ECUs. Further, performing the update on the ECUs in the first group can include performing rollback on the ECUs for which the update is completed when there is an ECU for which the update fails. Performing the update on the ECUs in the second group can include turning off the vehicle when the update of the ECUs in the first group is completed.

[0017] Further, performing the update on the ECUs in the second group can include turning off the vehicle when the SOC of the battery exceeds the reference SOC in case that the battery outputs total electric power required for updating the ECUs in the second group at a point in time when the update of the ECUs in the first group is completed. In one embodiment, performing the update on the ECUs in the second group can include performing rollback on the ECUs for which the update is completed when there is an ECU for which the update fails.

[0018] Further, receiving the request for the related software update of the ECUs arranged in the vehicle can include receiving, from the update server, information on a plurality of ECUs to be updated, update data applied to each of the plurality of ECUs, information on the ECUs included in the first group, and information on the ECUs included in the second group. The method can further include displaying a window asking the user for approval of the related software update, and receiving approval or rejection of the related software update from the user.

[0019] According to another aspect of the present application, a method for controlling an update of ECUs of a vehicle can include receiving a request for a related software update of electronic control units (ECUs) arranged in the vehicle, displaying a window asking a user for approval of the update, receiving approval from the user, starting the vehicle when a state of charge (SOC) of a battery is equal to or less than a reference SOC in case that the battery outputs a total amount of electric power required to update the ECUs, performing the update on the ECUs in the first group in a state that the vehicle is started, shutting down the vehicle when the SOC of the battery exceeds the reference SOC in case that the battery outputs a total amount of electric power required to update the ECUs in the second group at a time point that the update of the ECUs in the first group is completed, and performing the update on the ECUs in the second group in a state that the vehicle is shut down. BRIEF DESCRIPTION OF DRAWINGS

[0020] The above and other objects, features and advantages of the present application will be more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0021] Figure 1 is an exemplary diagram of a network environment to which an exemplary embodiment of the present application is applied;

[0022] Figure 2 is a configuration diagram of an apparatus for controlling an ECU update of a vehicle according to an exemplary embodiment of the present application;

[0023] Figure 3 is a flowchart of a method for controlling an ECU update of a vehicle according to an exemplary embodiment of the present application; and

[0024] Figure 4 is a block diagram illustrating a computing system that performs a method for controlling an ECU update of a vehicle according to an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0025] It should be understood that the terms "vehicle" or "vehicular" or other similar terms used herein generally include motor vehicles, such as passenger vehicles including sport utility vehicles (SUVs), buses, trucks, various commercial vehicles, watercraft including various boats, ships, aircraft, etc., and includes hybrid vehicles, electric vehicles, internal combustion engine vehicles, plug-in hybrid electric vehicles, hydrogen powered vehicles, and other alternative fuel vehicles (e.g., fuel derived from non-fossil sources).

[0026] Although the exemplary embodiments are described as utilizing a plurality of units to perform the exemplary processes, it should be understood that the exemplary processes can also be performed by one or more modules. Furthermore, it should be understood that the term controller / control unit denotes a hardware device that includes a memory and a processor and is specifically programmed to carry out the processes described herein. The memory is configured to store modules and the processor is specifically configured to execute the modules to carry out one or more processes described further below.

[0027] Furthermore, the control logic of the present application can be implemented as non-transitory computer readable media on a computer readable medium, which contains executable program instructions for execution by a processor, controller / control unit, etc. Examples of computer readable media include but are not limited to ROM, RAM, compact discs (CD)-ROMs, magnetic tapes, floppy disks, flash memories, smart cards, and optical data storage devices. The computer readable recording medium can also be distributed over network coupled computer systems so that the computer readable media is stored and executed in a distributed fashion, e.g., over a remote information processing server or a controller area network (CAN).

[0028] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0029] The term "about" as used herein is understood as being within the normal tolerances of the art, for example within 2 standard deviations of the mean. "About" can be understood to be within 10%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, 0.1%, 0.05%, or 0.01% of the indicated value. Unless otherwise clear from context, all numerical values provided herein are modified by the term "about."

[0030] Some embodiments of the present application will be described below in detail with reference to the accompanying drawings. When adding reference numerals to components of each drawing, it should be noted that the same reference numerals are designated even when the same or equivalent components are shown on other drawings. Also, in describing embodiments of the present application, detailed descriptions of related known configurations or functions incorporated herein will be omitted when it is determined that the relevant known configurations or functions do not contribute to the understanding of the embodiments of the present application.

[0031] When describing components according to exemplary embodiments of the present application, terms such as first, second, A, B, (a), (b), etc. can be used. These terms are used only to distinguish one component from another component, and the terms do not limit the nature, order or sequence of the components. Unless otherwise defined, all terms used herein, including technical terms and scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which the present application pertains. It should further be understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0032] In exemplary embodiments of the present application, the start state of the vehicle refers to a state in which the battery 810 supplying power to the power load is being charged, can refer to a state in which the engine is operating in an internal combustion engine vehicle, refers to a state in which the vehicle can travel in an electric vehicle, and refers to a state in which the fuel cell is operating in a fuel cell vehicle.

[0033] Figure 1 is an exemplary diagram of a network environment to which exemplary embodiments of the present application are applied. As shown in Figure 1 The network environment to which exemplary embodiments of the present application are applied can include an ECU update control apparatus 100 of a vehicle, an update server 200, a wireless communication network 300, a vehicle network 400, an engine control unit (ECU) 500, a transmission control unit (TCU) 600, an integrated body control unit (IBU) 700, a battery management system (BMS) 800, an intelligent cruise control (SCC) system 900, etc.

[0034] When performing a related software update on electronic control units (ECUs) arranged in a vehicle, the electronic control unit (ECU) update control device 100 can be configured to determine whether to start the vehicle based on the SOC of the battery 810, divide the electronic control units (ECUs) to be updated in the start state of the vehicle and the electronic control units (ECUs) to be updated in the off state of the vehicle, and collectively perform a related software update on the electronic control units (ECUs) to thereby normally complete the software update of functions involving multiple electronic control units (ECUs). In this regard, collective performance refers to active updating without a time interval.

[0035] For reference, passive updating refers to updating in which, during the process of updating multiple electronic control units (ECUs), the update can be performed on the electronic control unit (ECU) that is currently being updated when the SOC of the battery 810 arranged in the vehicle is equal to or less than a reference value, and the update of the remaining ECUs (ECUs waiting for update) can be performed when the vehicle is in the start state by the driver in the future and the battery 810 is charged.

[0036] On the other hand, active updating refers to updating in which, by starting the vehicle as needed, rather than waiting for an unknown time for the driver to put the vehicle in the start state and for the battery 810 to be charged, which creates a time interval, the related software update on the electronic control units (ECUs) is completed without a time interval (within one driving cycle). In other words, active updating refers to updating in which, in the start state of the vehicle caused by starting the vehicle, the electronic control units (ECUs) in the first group are updated by the ECU update control device 100, and when the battery 810 is charged to a certain degree, the electronic control units (ECUs) in the second group are updated in the off state of the vehicle caused by turning off the vehicle.

[0037] The ECU update control device 100 of the vehicle can be configured to perform an update for each electronic control unit (ECU), and the actual update target is each electronic control unit (ECU). The ECU update control device 100 of the vehicle can be configured to perform an over the air (OTA) update process related to the update server 200. As an example, the update server 200 can be implemented as an over the air (OTA) server, and can be configured to manage information of each ECU related to each function and update data corresponding to the related ECU. In other words, the update server 200 can be configured to store information about a plurality of ECUs to be updated related to a specific function (e.g., an autonomous driving function) and update data applied to each of the plurality of ECUs in a database (DB) 210. In this regard, the information about the plurality of ECUs can include identification information about ECUs to be updated in a start state of the vehicle, and identification information about ECUs to be updated in an off state of the vehicle. In this regard, the ECUs that should be updated in the off state of the vehicle refer to ECUs participating in the start of the vehicle.

[0038] The update server 200 can be configured to communicate with the ECU update control device 100 through a wireless communication network 300. The update server 200 can be configured to transmit information about ECUs related to related software updates and update data applied to each ECU to the ECU update control device 100 of the vehicle. The wireless communication network 300 can include a mobile communication network, a wireless Internet, a short-range communication network, etc. The vehicle network 400 can include a controller area network (CAN), a controller area network with flexible data rate (CAN-FD), a local interconnect network (LIN), FlexRay, a media oriented system transport (MOST), Ethernet, etc.

[0039] The ECU 500 can be connected to the vehicle network 400, and can be configured to perform overall control on an engine arranged in the vehicle. In an electric vehicle, the ECU 500 can be replaced with a vehicle control unit (VCU), and in a fuel cell vehicle, the ECU 500 can be replaced with a fuel cell control unit (FCU). The TCU 600 can be connected to the vehicle network 400, and can be configured to perform overall control on a transmission arranged in the vehicle.

[0040] The IBU 700 is an ECU including a body control unit (BCM), a smart key system (SKS), and a tire pressure monitoring system (TPMS), which can communicate with individual ECUs that control a wiper, a headlamp, a power seat, etc., respectively, to operate electrical devices of the vehicle in an integrated manner. Specifically, the IBU 700 can be configured to start or stop the vehicle. In this regard, the BCM can have functions of a rear curtain control, a vehicle lock control, an exterior light control, a wiper / washer control as a convenience function, and can have functions of a vehicle warning condition control, a mobile telematics system (MTS)-related warning control, a forward and rear parking assist control, and a warning control based on a seat belt or a door opening as a safety function. The SKS can be configured to recognize a smart key to lock / unlock the vehicle with a button of a door handle, to open a trunk, to generate a warning based on a location of the smart key, and to perform vehicle start with a start button near a steering wheel when the smart key is located inside the vehicle. The TPMS can be configured to monitor air pressure of each tire based on each tire pressure sensor (TPS) installed on each wheel of the vehicle.

[0041] The BMS 800 can be configured to perform overall control of the battery 810 that supplies power to power loads of the vehicle. Specifically, the BMS 800 can be configured to manage an SOC of the battery 810 and to provide the SOC information of the battery 810 to the ECU update control device 100 of the vehicle through the vehicle network 400. Further, the BMS 800 can be configured to adjust charging of the battery 810 in a start state of the vehicle. The SCC system 900 can provide speed information of the vehicle to the ECU update control device 100 of the vehicle through the vehicle network 400.

[0042] Figure 2 is a configuration diagram of a device for performing ECU update of a vehicle according to an exemplary embodiment of the present application. As shown in Figure 2 the ECU update control device 100 of the vehicle according to an exemplary embodiment of the present application can include a storage device 10, an input device 20, an output device 30, a communication device 40, a connector 50, and a controller 60. In this regard, according to an exemplary embodiment of the present application, components can be coupled to each other to be implemented as a single component or some components can be omitted based on a scheme in which the ECU update control device 100 of the vehicle is implemented.

[0043] In the description of each component, first, the storage 10 can be configured to store various logics, algorithms, and programs required in a process of determining whether to start the vehicle based on the SOC of the battery 810, dividing ECUs to be updated in the start state of the vehicle and ECUs to be updated in the off state of the vehicle, and collectively performing the relevant software update on the ECUs (e.g., completing the update of the ECUs within one driving cycle) when performing the relevant software update on the ECUs arranged in the vehicle.

[0044] The storage 10 can be configured to store information on a plurality of ECUs to be updated in relation to a specific function (e.g., an autonomous driving function) and update data applied to each of the plurality of ECUs. In this regard, the information on the plurality of ECUs can include identification information on ECUs to be updated in the start state of the vehicle and identification information on ECUs to be updated in the off state of the vehicle. The information can be received from the update server 200.

[0045] The storage 10 can be configured to store a reference SOC value (e.g., about 75%) for determining the battery 810 charge. The storage 10 can be configured to store the operating current of each of the ECUs arranged in the vehicle, the communication speed in the vehicle, etc. The storage 10 can include at least one type of storage medium such as a flash memory type, a hard disk type, a micro type, and a card type (e.g., a secure digital card (SD card) or an extreme digital card (XD card)), etc., and a memory such as a random access memory (RAM), a static RAM (SRAM), a read-only memory (ROM), a programmable ROM (PROM), an electrically erasable PROM (EEPROM), a magnetic RAM (MRAM), a magnetic disk, and an optical disk.

[0046] The input device 20 can include a touch key and a key (mechanical key), and can be configured to receive information from a user. As an example, the input device 20 can be configured to receive approval of the relevant software update from the user. The output device 30 can include a video output device and an audio output device, and can be configured to display a window asking the user whether to approve the relevant software update. The communication device 40 is a module that provides an interface for communication with the update server 200, and can be configured to receive information on a plurality of ECUs to be updated in relation to a specific function of the vehicle and update data applied to each of the plurality of ECUs.

[0047] Specifically, the communication device 40 can include at least one of a mobile communication module, a wireless Internet module, and a short-range communication module. The mobile communication module can be configured to receive update data via a mobile communication network established based on a technical standard or a communication scheme for mobile communication, such as Global System for Mobile Communications (GSM), Code Division Multiple Access (CDMA), Code Division Multiple Access 2000 (CDMA 2000), Enhanced Voice-Data Optimized or Enhanced Voice-Data Only (EV-DO), Wideband CDMA (WCDMA), High Speed Downlink Packet Access (HSDPA), High Speed Uplink Packet Access (HSUPA), Long Term Evolution (LTE), Long Term Evolution Advanced (LTE-A), or the like.

[0048] The wireless Internet module is a module for wireless Internet access, which is configured to receive update data through Wireless LAN (WLAN), Wireless Fidelity (Wi-Fi), Wi-Fi Direct, Digital Living Network Alliance (DLNA), Wireless Broadband (WiBro), Worldwide Interoperability for Microwave Access (WiMAX), High Speed Downlink Packet Access (HSDPA), High Speed Uplink Packet Access (HSUPA), Long Term Evolution (LTE), Long Term Evolution Advanced (LTE-A), or the like.

[0049] The short-range communication module can support short-range communication using at least one of Bluetooth TM , Radio Frequency Identification (RFID), Infrared Data Association (IrDA), Ultra Wideband (UWB), ZigBee, Near Field Communication (NFC), and Wireless Universal Serial Bus (USB) technology. The connector 50 can provide an interface for connection with a vehicle network.

[0050] The controller 60 can be configured to perform overall control so that each component performs its function. The controller 60 can be implemented in the form of hardware, can be implemented in the form of software, or can be implemented in the form of hardware and software coupled to each other. The controller 60 can be implemented as a microprocessor, but can not be limited thereto.

[0051] Specifically, the controller 60 can be configured to perform various controls in the following procedures when performing a relevant software update on the ECUs arranged in the vehicle: determining whether to start the vehicle based on the SOC of the battery 810; dividing the ECUs to be updated in the start state of the vehicle (hereinafter, ECUs in the first group) and the ECUs to be updated in the off state of the vehicle (hereinafter, ECUs in the second group), and collectively performing a relevant software update on the ECUs (completing the update of the ECUs within one driving cycle).

[0052] Hereinafter, the operation of the controller 60 will be described in detail. Figure 3 The operation of the controller 60 will be described in detail. Figure 3is a flowchart of a method for controlling ECU update of a vehicle according to an exemplary embodiment of the present application. First, the update server 200 can be configured to request update to the ECU update control device 100 of the vehicle. In this regard, the update server 200 can be configured to transmit information on a plurality of ECUs to be updated and update data applied to each of the plurality of ECUs.

[0053] Thereafter, when the vehicle is turned off, the transmission of the vehicle is located at the park (P) range, the vehicle is in a stopped state, and the SOC of the battery 810 exceeds the reference SOC, the controller 60 in the ECU update control device 100 of the vehicle can be configured to display an update approval window through the output device 30, and can be configured to receive the approval or rejection of the user through the input device 20. In this regard, in the case of the relevant software update of the ECU disposed in the vehicle, the controller 60 can be configured to output a notification indicating that the update is being performed to the user driver through the output device 30 when the driver is on the vehicle.

[0054] Thereafter, when the relevant software update is performed on the ECU disposed in the vehicle (step 301), the controller 60 can be configured to determine whether the SOC of the battery 810 is sufficient for the ECU to perform the update (step 302). In other words, the controller 60 can be configured to calculate the total amount of power A required for the ECU to perform the update, and to identify whether the SOC of the battery 810 exceeds the reference SOC even when the battery 810 outputs the total amount of power A. In this regard, the controller 60 can be configured to calculate the total amount of power P based on the following Equation 1 total .

[0055] Equation 1

[0056] P total = I total × (C total / S)

[0057] where I total is the sum of operating currents of the ECUs, C total is the sum of update data capacities of the ECUs, and S is the communication speed in the vehicle.

[0058] As a result of the identification (step 302), when the SOC of the battery 810 is sufficient to perform the update on the ECUs, the controller 60 can be configured to collectively perform the relevant software update on the ECUs without starting the vehicle (step 303). As a result of the identification (step 302), when the SOC of the battery 810 is insufficient to perform the update on the ECUs (i.e., when the SOC of the battery 810 is equal to or less than the reference SOC in the case where the total electric quantity A is output from the battery 810), the controller 60 can be configured to start the vehicle in conjunction with the IBU 700 (step 304) and perform the relevant software update on the ECUs in the first group (step 305). In this regard, when the vehicle is started, charging of the battery 810 can be started.

[0059] Thereafter, the controller 60 can be configured to determine whether there is an ECU that failed in the update in the process of performing the relevant software update on the ECUs in the first group (step 306). In this regard, the controller 60 performs the relevant software update only on the ECUs, and the actual update can be performed directly by the ECUs. As a result of the identification (step 306), in response to determining that there is an ECU that failed in the update, the controller 60 can be configured to perform a rollback on the ECUs for which the update is completed (step 307). As a reference, the rollback refers to a function to return to a pre-update state.

[0060] As a result of the identification (step 306), when there is no ECU that failed in the update, the controller 60 can be configured to calculate the total electric quantity B required to update the ECUs in the second group and determine whether the SOC of the battery 810 exceeds the reference SOC even when the total electric quantity B is output from the battery 810 (step 308). As a result of the identification (step 308), when the ECUs in the second group cannot be updated, i.e., when the SOC of the battery 810 is less than the reference SOC in the case where the total electric quantity B is output from the battery 810, the controller 60 can be configured to maintain the start of the vehicle (step 309).

[0061] As a result of the identification (step 308), when the ECUs in the second group can be updated, the controller 60 can be configured to turn off the vehicle in conjunction with the IBU 700 (step 310). Thereafter, the controller 60 can be configured to perform the relevant software update on the ECUs in the second group (step 311). Then, the controller 60 can be configured to determine whether there is an ECU that failed in the update in the process of performing the relevant software update on the ECUs in the second group (step 312).

[0062] As a result of the identification (step 312), the controller 60 can be configured to perform rollback on the ECUs for which the update is completed (including the ECUs in the first group) when there is an update failure of the ECUs (step 313). As a result, the controller 60 can be configured to perform rollback on all the ECUs for which the update is completed when even one of the ECUs to be updated fails in the update. As a result of the identification (step 312), the controller 60 can be configured to terminate the update when the update of all the ECUs in the second group is normally completed (step 314).

[0063] Figure 4 is a block diagram illustrating a computing system that performs a method for controlling ECU update of a vehicle according to an exemplary embodiment of the present application. Referring to Figure 4 The method for controlling ECU update of a vehicle according to the above-described exemplary embodiment of the present application can also be implemented by a computing system. The computing system 1000 can include at least one processor 1100, a memory 1300, a user interface input device 1400, a user interface output device 1500, a storage area 1600, and a network interface 1700 connected via a bus 1200.

[0064] The processor 1100 can be a central processing unit (CPU) or a semiconductor device that executes processing of instructions stored in the memory 1300 and / or the storage area 1600. The memory 1300 and the storage area 1600 can include various types of volatile or non-volatile storage media. For example, the memory 1300 can include read-only memory (ROM) 1310 and random access memory (RAM) 1320.

[0065] Accordingly, the operations of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor 1100, or in a combination of the two. A software module can reside in a storage medium (i.e., the memory 1300 and / or the storage area 1600), such as RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, solid state drive (SSD), removable disk, and CD-ROM. An example storage medium is coupled to the processor 1100 such that the processor 1100 can read information from, and write information to, the storage medium. In another approach, the storage medium is integral to the processor 1100. The processor and the storage medium can reside in an application-specific integrated circuit (ASIC). The ASIC can reside in a user terminal. In another approach, the processor and the storage medium can reside as discrete components in a user terminal.

[0066] The above description merely illustrates the technical idea of the present application, and those skilled in the art can make various modifications and changes without departing from the essential characteristics of the present application. Therefore, the embodiments disclosed in the present application are not intended to limit the technical idea of the present application, but to illustrate the present application, and the scope of the technical idea of the present application is not limited by the exemplary embodiments. The scope of the present application should be interpreted as covered by the scope of the appended claims, and all technical ideas falling within the scope of the claims should be interpreted as included in the scope of the present application.

[0067] The apparatus and method for controlling ECU update of a vehicle according to exemplary embodiments of the present application can determine whether to start the vehicle based on the SOC of the battery when performing a relevant software update on ECUs arranged in the vehicle, divide ECUs to be updated in a start state of the vehicle and ECUs to be updated in an off state of the vehicle, and collectively perform a relevant software update on the ECUs, thereby normally completing software update of functions involving a plurality of ECUs.

[0068] In the foregoing, although the present application has been described with reference to the exemplary embodiments and the accompanying drawings, the present application is not limited thereto, but those skilled in the art can make various modifications and changes without departing from the spirit and scope of the present application claimed in the appended claims.

Claims

1. An apparatus for controlling updates of electronic control units of a vehicle, comprising: a communication device configured to receive a request for related software updates of electronic control units arranged in the vehicle, wherein the related software updates of the electronic control units relate to an autonomous driving function of the vehicle; and a controller configured to: determine whether to start the vehicle based on a state of charge of a battery; perform updates of electronic control units in a first group in a started state of the vehicle based on the state of charge of the battery; perform updates of electronic control units in a second group in an off state of the vehicle; wherein the electronic control units in the first group and the electronic control units in the second group are two different groups; complete the related software updates of the electronic control units in the first group and the electronic control units in the second group within one driving cycle.

2. The apparatus for controlling update of an electronic control unit of a vehicle according to claim 1, wherein, the controller is configured to start the vehicle when the state of charge of the battery is equal to or less than a reference state of charge in a case where the battery outputs a total amount of electric power required for updating the electronic control units.

3. The apparatus for controlling update of an electronic control unit of a vehicle according to claim 1, wherein, the controller is configured to perform a rollback of electronic control units for which the updates are completed when there is an electronic control unit for which the update fails during the updates of the electronic control units in the first group.

4. The apparatus for controlling update of an electronic control unit of a vehicle according to claim 1, wherein, the controller is configured to turn off the vehicle and then perform the updates of the electronic control units in the second group when the updates of the electronic control units in the first group are completed.

5. The apparatus for controlling updating of an electronic control unit of a vehicle according to claim 4, wherein, the controller is configured to turn off the vehicle when the state of charge of the battery exceeds the reference state of charge in a case where the battery outputs the total amount of electric power required for updating the electronic control units.

6. The apparatus for controlling update of an electronic control unit of a vehicle according to claim 1, wherein, the controller is configured to perform a rollback of electronic control units for which the updates are completed when there is an electronic control unit for which the update fails during the updates of the electronic control units in the second group.

7. The apparatus for controlling update of an electronic control unit of a vehicle according to claim 1, wherein, the communication device is configured to receive, from an update server, information about a plurality of electronic control units to be updated, update data applied to each of the plurality of electronic control units, information about electronic control units included in the first group, and information about electronic control units included in the second group. 8.The apparatus for controlling updates of electronic control units of a vehicle according to claim 1, further comprising: an output device configured to display a window that asks a user for approval of the related software updates; and an input device configured to receive, from the user, approval or rejection of the related software updates. 9.A method for controlling updates of electronic control units of a vehicle, comprising: receiving, by a controller, a request for related software updates of electronic control units arranged in the vehicle, wherein the related software updates of the electronic control units relate to an autonomous driving function of the vehicle; determining, by the controller, whether to start the vehicle based on a state of charge of a battery; performing, by the controller, updates of electronic control units in a first group in a started state of the vehicle based on the state of charge of the battery; performing, by the controller, updates of electronic control units in a second group in an off state of the vehicle; wherein the electronic control units in the first group and the electronic control units in the second group are two different groups; and completing, by the controller, the related software updates of the electronic control units in the first group and the electronic control units in the second group within one driving cycle. The related software update of the electronic control units in the first group and the electronic control units in the second group is completed by the controller in one driving cycle.

10. The method of claim 9, wherein, The determination of whether to start the vehicle includes: In a case where the total amount of battery output required to update the electronic control units is output, the vehicle is started by the controller in response to the determination that the state of charge of the battery is equal to or less than the reference state of charge.

11. The method of claim 9, wherein, The update of the electronic control units in the first group includes: When there is an electronic control unit that failed to update, the electronic control units that completed the update are rolled back by the controller.

12. The method of claim 9, wherein, The update of the electronic control units in the second group includes: When the update of the electronic control units in the first group is completed, the vehicle is turned off by the controller.

13. The method of claim 9, wherein, The update of the electronic control units in the second group includes: In a case where the total amount of battery output required to update the electronic control units in the second group is output at the point in time when the update of the electronic control units in the first group is completed, the vehicle is turned off by the controller in response to the determination that the state of charge of the battery exceeds the reference state of charge.

14. The method of claim 9, wherein, The update of the electronic control units in the second group includes: When there is an electronic control unit that failed to update, the electronic control units that completed the update are rolled back by the controller.

15. The method of claim 9, wherein, The receiving of the request for the related software update of the electronic control units arranged in the vehicle includes: The information on the plurality of electronic control units to be updated, the update data applied to each of the plurality of electronic control units, the information on the electronic control units included in the first group, and the information on the electronic control units included in the second group are received from the update server.

16. The method of claim 9, further comprising: displaying, by the controller, a window that asks the user for approval of the related software update; receiving, by the controller, approval or rejection of the related software update from the user.

17. A method for controlling an update of electronic control units of a vehicle, comprising: receiving, by the controller, a request for a related software update of electronic control units arranged in the vehicle; displaying, by the controller, a window that asks the user for approval of the update; receiving, by the controller, approval from the user; starting, by the controller, the vehicle when the state of charge of the battery is equal to or less than the reference state of charge in a case where the total amount of battery output required to update the electronic control units is output; performing, by the controller, the update of the electronic control units in the first group in a state where the vehicle is started; turning off, by the controller, the vehicle when the state of charge of the battery exceeds the reference state of charge in a case where the total amount of battery output required to update the electronic control units in the second group is output at the point in time when the update of the electronic control units in the first group is completed; performing, by the controller, the update of the electronic control units in the second group in a state where the vehicle is turned off.

18. The method of claim 17, wherein, The update of the electronic control units in the first group includes: When there is an electronic control unit that failed to update, the electronic control units that completed the update are rolled back by the controller.

19. The method of claim 17, wherein, The update of the electronic control units in the second group includes: When there is an electronic control unit that failed to update, the electronic control units that completed the update are rolled back by the controller.

Citation Information

Patent Citations

  • Method for diagnosing growth state employing analyzing of image of strawberry

    KR1020200080432A

  • Software update device and software update system

    CN110114761A

  • Control device, control method, and computer program

    CN110998518A

  • Update control apparatus and method for a vehicle controller and vehicle having same

    CN111301315A

  • Update control device, terminal, and method of controlling

    US20190057214A1