Server, update management method, non-temporary storage medium, and center
By establishing the correlation between vehicle identification information and life cycle status information in the server, the problem that the vehicle position and approval subject are difficult to grasp in the OTA software update is solved, and timely software updates are achieved during the vehicle life cycle.
Patent Information
- Application Number
- CN202110693721.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-08
- Filing Date
- 2021-06-22
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2041-08-15
AI Technical Summary
In the prior art, it is difficult to grasp the location of the vehicle and the implementation approval subject when updating the OTA software, resulting in the inability to proceed in time.
The server establishes correlation between vehicle identification information and life cycle status information, judges the existence of software update data and sends indication information to indicate whether approval is required.
It realizes the implementation of software updates in a timely manner during the vehicle life cycle to ensure the timeliness and rationality of updates.
Smart Images

Figure CN113918184B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a server, an update management method, a non-transitory storage medium and a center for managing updates of software of an electronic control unit. Background Art
[0002] Vehicles are equipped with multiple electronic control units (ECUs) to control their operation. An ECU consists of a processor, temporary storage such as RAM, and non-volatile storage such as flash ROM. The processor implements the ECU's control functions by executing software stored in the non-volatile storage. The software stored in each ECU can be rewritten, and by updating to a newer version, the functionality of each ECU can be improved and new vehicle control functions can be added.
[0003] As a technology for updating ECU software, an OTA (Over The Air) technology is known. In this technology, an electronic control unit connected to an in-vehicle network is wirelessly connected to a communication network such as the Internet, and software is downloaded from a server via wireless communication and installed, thereby implementing ECU software updates and additions (for example, refer to Japanese Patent Application Laid-Open No. 2004-326689). Summary of the Invention
[0004] When updating software via OTA, it is necessary to notify the user or administrator of the updated content of the vehicle functions and the associated restrictions, and obtain approval from the user or administrator. The entity that implements the approval will change according to the circulation status of the vehicle. For example, when the vehicle is in the factory, the entity that implements the approval is the manufacturer, when the vehicle is in transit to the sales store, the entity that implements the approval is the sales store, and after the OTA contract or the sales contract is signed, the entity that implements the approval is the owner. For example, when the vehicle is in a factory or a transport ship and there is a software update activity, it is preferred to implement the software update based on the prescribed operation for the vehicle so that the software of the electronic control unit is in the latest state.
[0005] However, if it is difficult for an OTA server to know the location of the vehicle and who is responsible for approving software updates based on OTA, software updates cannot be performed in a timely manner during the vehicle's life cycle.
[0006] Therefore, the present invention provides a server, an update management method, a non-transitory storage medium, and a center that can implement software updates in a timely manner throughout the life cycle of a vehicle.
[0007] A first embodiment of the present invention is a server comprising: a processor configured to, for each vehicle identification information identifying a vehicle, associate the vehicle identification information with life cycle status information indicating the circulation status of the vehicle after manufacture and store the associated information; receive a confirmation request containing the vehicle identification information from the vehicle; when the processor receives the confirmation request, determine whether software update data for the vehicle identified by the vehicle identification information contained in the confirmation request exists; and in a case where the processor determines that the software update data for the vehicle exists, the processor sends an indication message to the vehicle based on the life cycle status information associated with the vehicle identification information contained in the confirmation request, the indication message indicating whether approval is required when executing software update processing in the vehicle.
[0008] A second embodiment of the present invention is an update management method executed by a computer having a processor, a memory, and a storage device. The update management method comprises: for each piece of vehicle identification information identifying a vehicle, associating the vehicle identification information with lifecycle status information indicating the circulation status of the vehicle after manufacture and storing the associated information; receiving a confirmation request containing the vehicle identification information from the vehicle; upon receiving the confirmation request, determining whether software update data for the vehicle identified by the vehicle identification information contained in the confirmation request exists; and, if it is determined that the software update data for the vehicle exists, sending an instruction to the vehicle based on the lifecycle status information associated with the vehicle identification information contained in the confirmation request, the instruction indicating whether approval is required for executing a software update in the vehicle.
[0009] A third embodiment of the present invention is a non-temporary storage medium storing instructions executable by one or more processors to cause the one or more processors to perform the following functions, the functions comprising: a step of associating and storing, for each vehicle identification information identifying a vehicle, the vehicle identification information with life cycle status information indicating the circulation status of the vehicle after manufacture; a step of receiving a confirmation request containing the vehicle identification information from the vehicle; a step of determining, when receiving the confirmation request, whether software update data for the vehicle identified by the vehicle identification information contained in the confirmation request exists; and a step of sending, when determining that software update data for the vehicle exists, an indication message to the vehicle based on the life cycle status information associated with the vehicle identification information contained in the confirmation request, the indication message indicating whether approval is required when executing software update processing in the vehicle.
[0010] The fourth embodiment of the present invention is a center comprising: a processor configured to, for each vehicle identification information identifying a vehicle, associate the vehicle identification information with life cycle status information indicating the circulation status of the vehicle after manufacture and store the associated information; receive a confirmation request containing the vehicle identification information from the vehicle; when the processor receives the confirmation request, determine whether software update data for the vehicle identified by the vehicle identification information contained in the confirmation request exists; if the processor determines that software update data for the vehicle exists, the processor sends an indication message to the vehicle based on the life cycle status information associated with the vehicle identification information contained in the confirmation request, the indication message indicating whether approval is required when executing software update processing in the vehicle.
[0011] According to the present invention, a server, an update management method, a non-transitory storage medium, and a center are provided that can implement software updates in a timely manner throughout the life cycle of a vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Hereinafter, features, advantages, and technical and industrial significance of exemplary embodiments of the present invention will be described with reference to the accompanying drawings, in which like symbols denote like elements.
[0013] Figure 1 This is a block diagram showing the overall configuration of a network system according to an embodiment.
[0014] Figure 2 Yes Figure 1 A block diagram of the schematic structure of the server is shown.
[0015] Figure 3 Yes Figure 1 FIG. 1 is a block diagram showing a schematic structure of a software updating device.
[0016] Figure 4 yes Figure 1 The functional block diagram of the server is shown.
[0017] Figure 5 Yes Figure 1 FIG. 1 is a diagram showing an example of update management information stored in the server shown.
[0018] Figure 6 Is used to illustrate Figure 5 Diagram showing the life cycle states.
[0019] Figure 7 yes Figure 1 The functional block diagram of the software updating device is shown.
[0020] Figure 8 This is a flowchart showing an example of control processing executed by the server according to the embodiment.
[0021] Figure 9 This is a flowchart showing an example of a software update process executed by the software update device according to the embodiment.
[0022] Figure 10 Yes Figure 9 A detailed flow chart of the installation and / or activation process is shown. DETAILED DESCRIPTION
[0023] Figure 1 is a block diagram showing the overall structure of a network system according to an embodiment of the present invention. Figure 2 Yes Figure 1 The block diagram of the server schematic structure shown in FIG. Figure 3 Yes Figure 1 FIG. 1 is a block diagram showing a schematic structure of a software updating device.
[0024] Figure 1 The network system shown is a system for updating programs of electronic control units 13a to 13d mounted on a vehicle, and includes a server 1 (center) and an in-vehicle network 2 mounted on the vehicle.
[0025] The server 1 can communicate with a software update device 11 mounted on the vehicle via the network 5 , and manages software updates of the electronic control units 13 a to 13 d mounted on the vehicle.
[0026] like Figure 2 As shown, server 1 includes a CPU 21, RAM 22, a storage device 23, and a communication device 24. The storage device 23 comprises a readable and writable storage medium such as a hard disk or SSD, and stores programs for managing software updates, update management information described later, and update data for the electronic control unit. In server 1, CPU 21 executes programs read from storage device 23 using RAM 22 as a work area, thereby performing the control processing described later. The communication device 24 communicates with the software update device 11 via a network.
[0027] The in-vehicle network 2 has a software update device 11 (OTA host), a communication module 12, a plurality of electronic control units 13a to 13d, and a display device 14. The software update device 11 is connected to the communication module 12 via a bus 15a, is connected to the electronic control units 13a and 13b via a bus 15b, is connected to the electronic control units 13c and 13d via a bus 15c, and is connected to the display device 14 via a bus 15d. The software update device 11 can communicate wirelessly (Over The Air) with the server 1 via the communication module 12. The software update device 11 controls the software update of the electronic control units 13a to 13d that are the update targets based on the update data obtained from the server 1. The software update device 11 is sometimes also referred to as a central gateway. The communication module 12 is a communication device that connects the in-vehicle network 2 and the server 1. The electronic control units 13a to 13d are ECUs that control the actions of various parts of the vehicle, and have non-volatile storage devices such as a CPU, RAM, cache, and EEPROM. The CPU uses the RAM as a working area and executes the program stored in the storage device, thereby performing control functions. The display device 14 (HMI) is used to implement various displays such as display of the existence of update data, display of permission requests for software updates requested by users, and display of update results when the software of the electronic control units 13a to 13d is updated. As the display device 14, a display device of a car navigation system can typically be used, but there is no particular limitation as long as it is a device that can display the information required for the software update process. In addition, in Figure 1 In the embodiment, four electronic control units 13a to 13d are shown, but the number of electronic control units is not particularly limited. Figure 1 Electronic control units other than the display device 14 may also be connected to the bus 15 d shown.
[0028] like Figure 3 As shown, the software updating device 11 includes a microcomputer 35 and a communication device 36. The microcomputer 35 includes a CPU 31, a RAM 32, a ROM 33, and a storage device 34. In the software updating device 11, the CPU 31 of the microcomputer 35 executes the program read from the ROM 33 using the RAM 32 as a work area, thereby performing the control processing described later. The communication device 36 is connected to the microcomputer 35 via the communication device 36. Figure 1 The buses 15 a - 15 d shown are devices that communicate with the communication module 12 , the electronic control units 13 a - 13 d , and the display device 14 .
[0029] Figure 4 yes Figure 1 The functional block diagram of the server shown in Figure 5 Yes Figure 1 FIG. 1 is a diagram showing an example of update management information stored in a server shown in FIG. Figure 6Is used to illustrate Figure 5 Diagram showing the life cycle states.
[0030] The server 1 includes a storage unit 26, a communication unit 27, and a control unit 28. The communication unit 27 and the control unit 28 are connected by Figure 2 The CPU 21 shown in the figure uses the RAM 22 to execute the program stored in the storage device 23, and the storage unit 26 is implemented by Figure 2 This is achieved by the storage device 23 shown.
[0031] The storage unit 26 stores update management information. Figure 5 As shown, update management information is information that associates vehicle identification information (vehicle ID) for identifying a vehicle, lifecycle status information indicating the post-manufacturing circulation status of the vehicle identified by the vehicle ID, and information indicating software that can be used by the electronic control unit. In this embodiment, the information indicating software that can be used by the electronic control unit defines a combination of the latest version information of the software of multiple electronic control units.
[0032] Lifecycle status information is information used to determine the status of a vehicle during its lifecycle, e.g. Figure 6 As shown, it can be set as being located at a factory before shipment, being transported by a transport ship, being transported to a sales store, being at a sales store, having completed a sales contract with a user (i.e., the ownership is transferred to the user), being circulated as a used car, being transported from the original country of shipment to other countries, being scrapped, etc. Figure 6 The life cycle states shown are examples and can also be defined Figure 6 The vehicle status other than that shown. For example, as lifecycle status information, information indicating at least one of the following can be set: vehicle under development, vehicle under manufacturing, vehicle in transportation, vehicle on sale, vehicle owned by a user, vehicle under repair, vehicle user registration status (before or after user registration), vehicle ownership status (vehicle owned by the user or not owned by the user), and vehicle user type (individual, legal entity, shared, etc.). Figure 5 The life cycle status information of the update management information shown can be appropriately acquired and set from information sources such as a manufacturing management database, a sales management database, a user information database, and a registration information database.
[0033] exist Figure 6In the example, the update management information is configured as a single table that associates lifecycle status information and available software version information for each vehicle ID. However, a table that associates lifecycle status information for each vehicle ID and a table that associates available software version information for each vehicle ID may also be configured. When the lifecycle status information and available software version information are configured in separate tables, the lifecycle status information needs to be configured for each vehicle ID, but the available software version information does not necessarily need to be configured for each vehicle ID. For example, the available software version information may be configured for each vehicle ID that identifies the vehicle model.
[0034] Furthermore, the storage unit 26 also stores update data of the electronic control unit. However, instead of storing the update data in the storage unit 26 , a server for distributing the update data may be provided separately from the server 1 .
[0035] The communication unit 27 is capable of receiving software update confirmation requests from the software update device 11. This update confirmation request is, for example, information sent from the software update device 11 to the server 1 when the vehicle's power is turned on or the ignition is turned on, requesting the server 1 to confirm the existence of updated data for the electronic control unit. Furthermore, the communication unit 27 receives a request to send a distribution package (a download request) from the software update device 11. Upon receiving the request to download the distribution package, the communication unit 27 transmits instruction information to the software update device 11 indicating whether approval is required for executing the software update process.
[0036] When the communication unit 27 receives the update confirmation request, the control unit 28 determines whether there is update data for the software of the vehicle specified by the vehicle ID included in the update confirmation request based on the update management information stored in the storage unit 26 .
[0037] The above-mentioned instruction information is generated based on the lifecycle status information included in the update management information stored in the storage unit 26. For example, upon receiving a distribution package download request from the software update device 11, the control unit 28 can generate instruction information based on the lifecycle status information of the vehicle ID included in the download request. As another example, the control unit 28 can generate instruction information based on the updated lifecycle status information when the lifecycle status information included in the update management information is updated.
[0038] When executing the software update process of the electronic control unit, in principle, the approval of the user (or administrator) is required. However, for example, in the case where the vehicle is in the factory before transportation or in the case of transportation based on a transport ship, since the vehicle has not yet been sold and the manufacturer is the owner, the user's approval is not required. In this case, it is preferable to update the software of the electronic control unit to the latest state without requesting approval. Therefore, the life cycle status information set in the update management information is Figure 6 In the case of "1" or "2", the control unit 28 generates an instruction message indicating that approval is not required for the update process. In addition, the life cycle status information set in the update management information is Figure 6 In the case of "3" to "7" of the control unit 28, the control unit 28 generates instruction information indicating that approval is required for the update process.
[0039] Furthermore, whether or not the software update device 11 needs to be instructed to approve the update through instruction information can be appropriately changed in consideration of pre-registered information set separately in addition to the life cycle status information. For example, when the vehicle is being transported to the dealership or the vehicle is at the dealership ( Figure 6 In the case of "3" or "4" of the above), when registration indicating that the software update process is executed without approval is performed in advance, the control unit 28 may also generate instruction information indicating approval when the update process is not required.
[0040] Figure 7 yes Figure 1 The functional block diagram of the software updating device is shown.
[0041] The software updating device 11 includes a communication unit 37, a storage unit 38, and a control unit 39. The communication unit 37 and the control unit 39 are connected by Figure 3 The CPU 31 shown is implemented by executing the program stored in the ROM 33 using the RAM 32. The storage unit 38 is composed of Figure 3 The storage device 34 is shown implemented.
[0042] For example, when the power supply or ignition of the vehicle is turned on, the communication unit 37 sends an update confirmation request for the electronic control unit software to the server 1 and receives the confirmation result (information indicating whether the update data exists) from the server 1. The update confirmation request includes, for example, the vehicle ID for identifying the vehicle and the version of the program of the electronic control unit 13a~13d connected to the vehicle network 2. In the case where there is update data for the electronic control unit software, the communication unit 37 sends a download request for the distribution package to the server 1 and receives the distribution package sent from the server 1. The distribution package contains the update data for the electronic control unit software and indication information indicating whether approval is required when executing the software update process. In addition to the update data and indication information, the distribution package may also include verification data for verifying the authenticity of the update data, the amount of update data, the installation order, various control information used when updating the software, etc.
[0043] The control unit 39 verifies the authenticity of the distribution package received from the server 1 by the communication unit 37 and stored in the storage unit 38. The control unit 39 then transmits the downloaded update data to the target ECU, causing it to install the update data. After installation is complete, the control unit 39 instructs the target ECU to validate the installed update data. If only one software storage area is provided in the ECU's storage device, installation and activation are performed sequentially. The control unit 39 executes the installation and activation control process, completing the software update in the target ECU.
[0044] Here, the software update process consists of a stage of downloading update data from server 1, a stage of forwarding the downloaded update data to the electronic control unit of the update object and installing the update data in the storage area of the electronic control unit of the update object, and a stage of activating the installed updated version of the software in the electronic control unit of the update object.
[0045] Downloading is the process of receiving and storing update data sent from the server 1 for updating the software of the electronic control unit. In the downloading stage, it includes not only the reception of the update data, but also the control of a series of processes related to the download, such as whether the download can be executed, the verification of the update data, etc. Installation is the process of writing an updated version of the program (update software) to the storage area of the vehicle-mounted device in the electronic control unit of the update object based on the downloaded update data. In the installation stage, it includes not only the execution of the installation, but also the control of a series of processes related to the installation, such as whether the installation can be executed, the transmission of the update data, and the verification of the updated version of the program. Activation is the process of activating the installed updated version of the program. Activation control includes not only the execution of the activation, but also the control of a series of processes related to the activation, such as whether the activation can be executed, the verification of the execution result, etc.
[0046] The update data sent from the server 1 to the software update device 11 may include any of the following: update software for the electronic control unit, compressed data containing the update software, or segmented data containing the update software or compressed data. Furthermore, the update data may include an identifier (ECUID) for the electronic control unit to be updated and an identifier (ECU software ID) for the software before the update. The update data is downloaded as the aforementioned distribution package, but the distribution package contains update data for one or more electronic control units.
[0047] If the update data includes the update software itself, the software update device forwards the update data (update software) to the target ECU during the installation phase. Alternatively, if the update data includes compressed data, differential data, or segmented data of the update software, the software update device 11 may transmit the update data to the target ECU, and the target ECU may generate the update software based on the update data. Alternatively, the software update device 11 may generate the update software based on the update data and then transmit the update software to the target ECU. The generation of the update software can be accomplished by decompressing the compressed data, using differential data, or using segmented data.
[0048] The updated software can be installed by the target ECU in response to an installation request from the software update device 11. Alternatively, the target ECU receiving the updated data may autonomously install the software without receiving an explicit instruction from the software update device 11.
[0049] The updated software can be activated by the target ECU in response to an activation request from the software update device 11 . Alternatively, the target ECU that has received the update data can autonomously activate the software without receiving an explicit instruction from the software update device 11 .
[0050] Furthermore, the software update process may be performed sequentially or in parallel for each of the plurality of electronic control units.
[0051] In addition, the "software update process" in this specification includes not only a process of continuously performing all downloading, installation, and activation, but also a process of performing only a portion of the downloading, installation, and activation.
[0052] Hereinafter, the control processing executed by the server 1 and the software updating device 11 will be described.
[0053] Figure 8 This is a flowchart showing an example of control processing executed by the server according to the embodiment. Figure 8 The control process shown is repeatedly executed at predetermined time intervals, for example.
[0054] In step S1, the communication unit 27 determines whether an update confirmation request has been received from the software update device 11. If the determination in step S1 is yes, the process proceeds to step S2, and otherwise, the process proceeds to step S3.
[0055] In step S2, the communication unit 27 transmits information indicating whether or not there is update data for the electronic control unit software to the vehicle that has transmitted the update confirmation request. Regarding the presence or absence of update data, for example, the control unit 28 checks the combination of software versions stored in the update management information in association with the vehicle ID included in the update confirmation request (see Figure 5 ), and compare it with the current software version combination included in the update confirmation request. If the current software version combination included in the update confirmation request is older than the version combination stored in the update management information, it can be determined that update data exists. The process then proceeds to step S3.
[0056] In step S3, the communication unit 27 determines whether a download request for the distribution package has been received from the software update device 11. If the determination in step S3 is yes, the process proceeds to step S4, and otherwise, the process proceeds to step S1.
[0057] In step S3, the communication unit 27 transmits a distribution package containing the software update data and instruction information to the software update device 11. Furthermore, if the vehicle identified by the vehicle ID included in the download request has pre-registered that approval is not required for software updates, the requirement for approval in the instruction information may be changed based on this pre-registered information. The process then proceeds to step S1.
[0058] Figure 9 This is a flowchart showing an example of control processing executed by the software updating device according to the embodiment. Figure 9 The control process shown is executed when, for example, the power source or ignition of the vehicle is turned on.
[0059] In step S11, the communication unit 37 transmits an update confirmation request including a combination of the vehicle ID and the software version of the electronic control unit to the server 1. Thereafter, the process proceeds to step S12.
[0060] In step S12, the communication unit 37 receives the confirmation result from the server 1. Thereafter, the process proceeds to step S13.
[0061] In step S13, the control unit 39 determines whether there is software update data for the electronic control units 13a to 13d based on the confirmation result received in step S12 from the server 1. If the determination in step S13 is yes, the process proceeds to step S14. Otherwise, the process ends.
[0062] In step S14, the communication unit 37 executes the download process. Specifically, the communication unit 37 sends a download request for the distribution package to the server 1, receives the distribution package sent in response to the download request, and stores the received distribution package in the storage unit 38. The control unit 39 verifies the authenticity of the update data contained in the received distribution package. In step S14, a determination is made as to whether the download can be performed, and a notification of download completion is sent to the server 1. Processing then proceeds to step S15.
[0063] In step S15 , the control unit 39 executes the installation process and the activation process for the electronic control unit to be updated, and ends the process.
[0064] Figure 10 Yes Figure 9 A detailed flow chart of the installation and / or activation process is shown.
[0065] In step S21, the control unit 39 performs the following operations according to the Figure 9 The instruction information contained in the distribution package received from server 1 in step S14 is used to determine whether user or administrator approval is required before installation. As described above, the instruction information is set based on the lifecycle status information stored in server 1. If the determination in step S21 is yes, the process proceeds to step S22; otherwise, the process proceeds to step S24.
[0066] In step S22, the control unit 39 performs installation confirmation processing. For example, the control unit 39 displays a message indicating the start of the program update for the in-vehicle device, displays a message requesting the user's approval to start the program update, displays the time required for installing the updated program, installation restrictions, and precautions as needed, and accepts user input using input devices such as the touch panel and operation buttons. The process then proceeds to step S23.
[0067] In step S23, the control unit 39 determines whether an operation input indicating approval of the software update (installation) has been performed. The operation input indicating approval of the installation can be determined by, for example, whether a button such as "Approve" or "Start Update" displayed on the display device 14 has been pressed. Alternatively, if the user wishes to approve the start (installation) of the software update (installation) at a later time rather than immediately, they can proceed to this request by pressing a button such as "Proceed Later." In this case, the control unit 39 determines a negative result in step S23. If the determination in step S23 is positive, the process proceeds to step S24; otherwise, the process terminates.
[0068] In step S25, the control unit 39 performs the following operations according to the Figure 9 The instruction information contained in the distribution package received from server 1 in step S14 is used to determine whether user or administrator approval is required before activation. As described above, the instruction information is set based on the lifecycle status information stored in server 1. If the determination in step S25 is yes, the process proceeds to step S26; otherwise, the process proceeds to step S28.
[0069] In step S26, the control unit 39 performs activation confirmation processing. As part of the activation confirmation process, the control unit 39 displays a message indicating that the program update for the vehicle-mounted device is ready and that the program has been updated by a specific operation, such as turning off the power or ignition. Furthermore, the control unit 39 displays the activation time required, activation restrictions, and precautions, as needed, and accepts user input operations using input devices such as the touch panel and operation buttons. The process then proceeds to step S27.
[0070] In step S27, the control unit 39 determines whether an operation input has been made to approve the software update (activation). This can be determined by, for example, whether a button such as "Approve" or "Update" displayed on the display device 14 has been pressed. Alternatively, if the user wishes to approve the software update (activation) later rather than immediately, they can press a button such as "Proceed Later" to accept the request. In this case, the control unit 39 determines a negative result in step S27. If the determination in step S27 is positive, the process proceeds to step S28; otherwise, the process ends.
[0071] In step S28, the control unit 39 instructs the target ECU to activate the updated software. The process then ends. Furthermore, the target ECU restarts upon a specific operation, such as turning off the power or ignition, and executes the updated software. This completes the software update (function update) of the ECU.
[0072] In addition, if there is only one software storage area in the storage device of the electronic control unit, the old software stored in the software storage area is overwritten by writing the update data, so it is necessary to perform installation and activation as a series of processes. Figure 10 In the processing of , the processing of steps S25 to S27 can also be omitted.
[0073] As described above, the server 1 of this embodiment stores lifecycle status information for each vehicle ID. This lifecycle status information indicates the vehicle's status after manufacture. When a vehicle software update is required, the server 1 can instruct the software update device 11 whether to forcibly perform the software update without requesting approval, depending on the vehicle's current lifecycle status. Therefore, the server 1 of this embodiment can implement software updates in a timely manner throughout the vehicle's lifecycle.
[0074] The functions of the server 1 illustrated as an embodiment may also be implemented as an update management method executed by a computer having a processor (CPU), memory, and storage, or as an update management program executed by the computer, or as a computer-readable non-transitory storage medium storing the update management program. Similarly, the functions of the software update device 11 illustrated as an embodiment may also be implemented as an update control method executed by an onboard computer having a processor (CPU), memory, and storage, or as an update control program executed by the onboard computer, or as a computer-readable non-transitory storage medium storing the update control program.
[0075] In the above embodiment, the software update device 11 provided in the vehicle network as the host device controls the software update of all the electronic control units 13a to 13d. However, instead of providing the software update device 11, any one of the electronic control units 13a to 13d may have a Figure 9 as well as Figure 10 The update control function shown in FIG. 11 can also be used to control the software update of other electronic control units. Figure 9 as well as Figure 10 The update control function shown is provided in an external device that can be connected to the in-vehicle network 2 in a wired manner, and the software update process of the electronic control units 13 a to 13 d is executed using the external device.
[0076] The server 1 of the above-mentioned embodiment centrally manages lifecycle status information, so it can be used as an information source that grasps the software update status of registered vehicles (for example, the number of vehicles that have completed OTA-based software updates and the number of vehicles that have not completed them) and the current status of the vehicle.
[0077] Furthermore, in the server 1 of the above-described embodiment, if a legal entity owns multiple vehicles, a lifecycle state of "Legally Owned (Pre-approved)" can be set to allow forcible execution of software updates by the owners who collectively approve the updates. For vehicles with this lifecycle state set, indication information indicating that approval is not required is generated, assuming that the owner has previously approved the updates. This configuration facilitates OTA software updates for multiple vehicles owned by the same owner.
[0078] The technology of the present invention can be used in a network system for updating software of an electronic control unit.
Claims
1. A server, characterized in that: have: a processor configured to, For each piece of vehicle identification information identifying a vehicle, the vehicle identification information is associated with life cycle status information indicating the circulation status of the vehicle after manufacture and stored. receiving a confirmation request including the vehicle identification information from the vehicle, When the processor receives the confirmation request, it determines whether software update data for the vehicle identified by the vehicle identification information included in the confirmation request exists. When the processor determines that the update data for the software of the vehicle exists, the processor sends instruction information to the vehicle based on the lifecycle status information associated with the vehicle identification information included in the confirmation request, the instruction information indicating whether approval is required when executing a software update process in the vehicle. When the lifecycle status information indicates that approval related to the software update process is collectively performed on a plurality of vehicles including the vehicle, the processor transmits the instruction information to the vehicle indicating that approval is not required when executing the software update process in the vehicle.
2. The server according to claim 1, wherein The processor is configured to store update data of software installed in an electronic control unit of the vehicle, The processor is configured to send the indication information together with the update data to the vehicle.
3. The server according to claim 1 or 2, wherein: As the lifecycle state information, information indicating at least one of vehicle under development, vehicle under manufacture, vehicle under transport, vehicle under sale, vehicle owned by a user, vehicle under repair, and the type of vehicle user is set.
4. The server according to claim 3, wherein: When information indicating that the vehicle is in a factory or a transport ship is set as the lifecycle state information, the processor transmits instruction information indicating that approval is not required when executing the software update process to the vehicle.
5. An update management method, executed by a computer having a processor, a memory, and a storage device, wherein the update management method comprises: a step of associating and storing, for each piece of vehicle identification information identifying a vehicle, the vehicle identification information with life cycle status information indicating a circulation status of the vehicle after manufacture; receiving a confirmation request including the vehicle identification information from the vehicle; When receiving the confirmation request, determining whether software update data for the vehicle identified by the vehicle identification information included in the confirmation request exists; If it is determined that update data for the vehicle software exists, a step of sending instruction information to the vehicle based on the lifecycle status information associated with the vehicle identification information included in the confirmation request, the instruction information indicating whether approval is required when executing software update processing in the vehicle; When the lifecycle status information indicates that approval related to the software update process has been collectively performed on a plurality of vehicles including the vehicle, the instruction information indicating that no approval is required when executing the software update process in the vehicle is transmitted to the vehicle.
6. A non-transitory storage medium storing instructions executable by one or more processors for causing the one or more processors to perform the following functions, wherein the non-transitory storage medium is characterized in that the functions include: a step of associating and storing, for each piece of vehicle identification information identifying a vehicle, the vehicle identification information with life cycle status information indicating a circulation status of the vehicle after manufacture; receiving a confirmation request including the vehicle identification information from the vehicle; When receiving the confirmation request, determining whether software update data for the vehicle identified by the vehicle identification information included in the confirmation request exists; If it is determined that update data for the vehicle software exists, a step of sending instruction information to the vehicle based on the lifecycle status information associated with the vehicle identification information included in the confirmation request, the instruction information indicating whether approval is required when executing software update processing in the vehicle; When the lifecycle status information indicates that approval related to the software update process has been collectively performed on a plurality of vehicles including the vehicle, the instruction information indicating that no approval is required when executing the software update process in the vehicle is transmitted to the vehicle.
7. A center, characterized in that have: a processor configured to, For each piece of vehicle identification information identifying a vehicle, the vehicle identification information is associated with life cycle status information indicating the circulation status of the vehicle after manufacture and stored. receiving a confirmation request including vehicle identification information from the vehicle, When the processor receives the confirmation request, it determines whether software update data for the vehicle identified by the vehicle identification information included in the confirmation request exists. When the processor determines that update data for the vehicle software exists, the processor sends instruction information to the vehicle based on the lifecycle status information associated with the vehicle identification information included in the confirmation request, the instruction information indicating whether approval is required when executing the software update process in the vehicle. When the lifecycle status information indicates that approval related to the software update process is collectively performed on a plurality of vehicles including the vehicle, the processor transmits the instruction information to the vehicle indicating that approval is not required when executing the software update process in the vehicle.
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Software updating apparatus and software updating method
US20180018160A1