Software update device, update control method, non-transitory storage medium, server, OTA host and center

By using a software update device and method to control the timing of approval requests based on the type of non-volatile memory in the electronic control unit, the problem of inappropriate approval timing in the prior art is solved, ensuring the smooth progress of software updates and the stability of functions.

CN113961214BActive Publication Date: 2026-03-17TOYOTA JIDOSHA KK
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-15
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In the prior art, the timing of software updates for electronic control units cannot be flexibly controlled according to the specifications of their non-volatile memory, resulting in inappropriate timing of user or administrator approval requests and affecting the smooth progress of software updates.

Method used

A software update device and method are designed to control the timing of approval request processing by determining the type of non-volatile memory in the electronic control unit, ensuring that approval is requested from the user or administrator at the appropriate time. This includes displaying the approval request screen on a display device and processing the approval request before or after installation or activation, depending on the type of memory.

Benefits of technology

It enables flexible adjustment of the software update approval timing according to the specifications of the electronic control unit, ensuring the smooth progress of the update process and avoiding unnecessary functional limitations and impacts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113961214B_ABST
    Figure CN113961214B_ABST
Patent Text Reader

Abstract

This invention relates to a software update apparatus for controlling software updates of electronic control units. The software update apparatus includes a control unit configured to, during the execution of software update processing for an electronic control unit, control the timing of an approval request processing based on the type of non-volatile memory possessed by the electronic control unit to be updated, wherein the approval request processing is used to request approval for the software update processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a software update apparatus, update control method, non-temporary storage medium, server, OTA host and center for controlling software updates of electronic control units. Background Technology

[0002] Vehicles are equipped with multiple Electronic Control Units (ECUs) to control the vehicle's movements. Each ECU has a processor, temporary storage such as RAM, and non-volatile storage such as flash ROM. The processor executes the software stored in the non-volatile storage to implement the ECU's control functions. The software stored in each ECU can be rewritten; by updating to a newer version of the software, the functionality of each ECU can be improved, and new vehicle control functions can be added.

[0003] As a technology for updating ECU software, an OTA (Over The Air) technology is known. In this OTA technology, the vehicle communication device connected to the vehicle network and the Internet or other communication networks are connected wirelessly. The software is downloaded from the server and installed via wireless communication, thereby updating or adding programs to the ECU (for example, see Japanese Patent Application Laid-Open No. 2004-326689).

[0004] As a non-volatile memory (storage unit) installed in the ECU, there are memory with one storage area for storing software (single-sided memory) and memory with two storage areas for storing software (double-sided memory), depending on the ECU specifications, etc. ECUs equipped with double-sided memory can store both new and old versions of the program in the two storage areas. Summary of the Invention

[0005] OTA-based software update processing includes: the stage where the software update device downloads update data from the server; the stage where the downloaded update data is transmitted to the electronic control unit of the updated object and installed in the storage area of ​​the electronic control unit of the updated object; and the stage where the updated software is activated in the electronic control unit of the updated object.

[0006] In an ECU equipped with the aforementioned dual-sided memory, the currently running software stored in one storage area can be maintained, while an updated version of the software is installed in the other storage area. In contrast, in an ECU equipped with the aforementioned single-sided memory, the currently running software stored in the storage area is rewritten by the installation of the updated software.

[0007] When implementing OTA-based software updates, it is necessary to notify users and administrators of the changes to vehicle functions resulting from the software update, functional limitations that arise during the software update process, and to request the approval of users and administrators.

[0008] However, as mentioned above, the timing of the impact on the electronic control unit of the updated object varies depending on the specifications of the non-volatile memory installed in the electronic control unit, and therefore, there is still room for research regarding the timing of the request for approval.

[0009] Therefore, the present invention provides a software update device, update control method, non-temporary storage medium for storing update control programs, server, OTA host and center capable of changing the approval time of software updates according to the specifications of the electronic control unit.

[0010] The first aspect of the present invention is a software update apparatus for controlling software updates of an electronic control unit. The software update apparatus includes a control unit configured to, during the execution of software update processing of the electronic control unit, control the timing of the execution of an approval request processing based on the type of non-volatile memory possessed by the electronic control unit to be updated, wherein the approval request processing is used to request approval for the software update processing.

[0011] In the first embodiment described above, the control unit is configured to, when the non-volatile memory of at least one electronic control unit mounted on the update target is a first type of memory, perform the approval request processing before installing update data into the storage area of ​​the non-volatile memory; and when the non-volatile memory of the electronic control unit mounted on the update target is a second type of memory, perform the approval request processing after installing update data into the storage area of ​​the non-reading target of the non-volatile memory and before activating the storage area where update data has been written as a read target.

[0012] In the first embodiment described above, the software update device may further include a determination unit configured to determine whether the non-volatile memory mounted on the electronic control unit of the update target is a first type of memory with one storage area or a second type of memory with two storage areas. The control unit is configured to control the timing of the approval request processing based on the determination result of the determination unit.

[0013] In the first embodiment described above, the software update device may also include a storage unit configured to store the types of non-volatile memory mounted on the electronic control unit, and the determination unit configured to determine the type of non-volatile memory of the electronic control unit to be updated based on the type of non-volatile memory stored in the storage unit.

[0014] In the first method described above, the software update device may also include a communication unit configured to receive from a server the type of non-volatile memory mounted on the electronic control unit; a storage unit configured to store the received type of non-volatile memory; and a determination unit configured to determine the type of non-volatile memory of the electronic control unit to be updated based on the type of non-volatile memory stored in the storage unit.

[0015] In the first method described above, the software update device may further include a communication unit configured to receive instruction information from a server, the instruction information indicating the timing of the approval request processing based on the type of non-volatile memory possessed by the electronic control unit of the update object, and the control unit configured to control the timing of the approval request processing based on the received instruction information.

[0016] In the first method described above, the control unit is configured to cause the display device to display a screen requesting approval for a software update during the approval request processing.

[0017] The second aspect of the present invention is an update control method executed by a computer for controlling software updates of an electronic control unit. The computer has a processor, a memory, and a storage device. The update control method includes the following steps: when executing the software update process of the electronic control unit, the timing of the execution of an approval request process is controlled according to the type of non-volatile memory possessed by the electronic control unit to be updated. The approval request process is used to request approval for the software update process.

[0018] A third aspect of the present invention is a non-temporary storage medium storing a program executable by a computer that performs the following functions to control software updates of an electronic control unit: the computer has a processor, a memory, and a storage device. The function of the non-temporary storage medium is to control the timing of the execution of an approval request processing based on the type of non-volatile memory possessed by the electronic control unit being updated during software update processing. This approval request processing is used to request approval for the software update processing.

[0019] A fourth aspect of the present invention provides a server comprising: a storage unit configured to store, for each vehicle identification information of an identified vehicle, the types of non-volatile memory possessed by an electronic control unit mounted on the vehicle; a communication unit configured to receive, from the vehicle, a confirmation request containing vehicle identification information; and a control unit configured to, when the communication unit receives the confirmation request, determine whether there is software update data for the vehicle identified by the vehicle identification information contained in the confirmation request, wherein the communication unit is configured to, if the control unit determines that software update data for the vehicle exists, send instruction information to the vehicle, the instruction information indicating the timing of processing an approval request based on the type of non-volatile memory possessed by the electronic control unit of the updated object.

[0020] The fifth aspect of the present invention is an OTA host that controls software updates of an electronic control unit. The OTA host includes a control unit configured to control the timing of an approval request process based on the type of non-volatile memory of the electronic control unit being updated when performing software update processing of the electronic control unit. The approval request process is used to request approval for the software update process.

[0021] The sixth aspect of the present invention is a center comprising: a storage unit configured to store, for each vehicle identification information of the identified vehicle, the types of non-volatile memory possessed by the electronic control unit of the vehicle; a communication unit configured to receive, from the vehicle, a confirmation request containing vehicle identification information; and a control unit configured to, when the communication unit receives the confirmation request, determine whether there is software update data for the vehicle identified by the vehicle identification information contained in the confirmation request, wherein the communication unit is configured to, if the control unit determines that software update data for the vehicle exists, send instruction information to the vehicle, the instruction information indicating the timing of the approval request processing according to the type of non-volatile memory possessed by the electronic control unit of the updated object.

[0022] According to various embodiments of the present invention, a software update apparatus, an update control method, a non-temporary storage medium for storing update control programs, a server, an OTA host, and a center are provided that can change the user approval timing for software updates according to the specifications of the electronic control unit. Attached Figure Description

[0023] Hereinafter, with reference to the accompanying drawings, the features, advantages, and technical and industrial significance of exemplary embodiments of the present invention will be described, in which the same reference numerals denote the same elements.

[0024] Figure 1This is a block diagram illustrating the overall structure of the network system implemented in this way.

[0025] Figure 2 It means Figure 1 The diagram shows a summary structure of the server.

[0026] Figure 3 It means Figure 1 The diagram shows a block diagram of the general structure of the software update device.

[0027] Figure 4A It is a block diagram showing the general structure of the electronic control unit.

[0028] Figure 4B It is a block diagram showing the general structure of the electronic control unit.

[0029] Figure 5 yes Figure 1 The diagram shows the functional block diagram of the server.

[0030] Figure 6 yes Figure 1 The diagram shows the functional block diagram of the software update device.

[0031] Figure 7 This is a flowchart illustrating an example of the control processing performed by the server in the first embodiment.

[0032] Figure 8 This is a flowchart illustrating an example of the control processing performed by the software update apparatus of the first embodiment.

[0033] Figure 9 It means Figure 8 The detailed flowchart of the installation and / or activation process is shown.

[0034] Figure 10 This is a flowchart illustrating an example of the control processing performed by the server in the second embodiment.

[0035] Figure 11 This is a flowchart illustrating an example of the control processing performed by the software update apparatus of the second embodiment. Detailed Implementation

[0036] First Implementation Method

[0037] Figure 1 This is a block diagram illustrating the overall structure of the network system in the implementation method. Figure 2 It means Figure 1 The diagram shown is a summary of the server's structure. Figure 3 It means Figure 1 The diagram shows a block diagram of the general structure of the software update device.

[0038] Figure 1The network system shown is a system for updating the software of the electronic control units 13a to 13d installed in the vehicle, and has a server 1 (center) and an in-vehicle network 2 installed in the vehicle.

[0039] Server 1 can communicate with the software update device 11 installed in the vehicle via network 5 and manage the software updates of the electronic control units 13a to 13d installed in the vehicle.

[0040] like Figure 2 As shown, server 1 includes a CPU 21, RAM 22, storage device 23, and communication device 24. Storage device 23 has a read / write storage medium such as a hard disk or SSD, and stores programs for executing software update management, update management information, and update data for the electronic control unit. In server 1, CPU 21 executes programs read from storage device 23 using RAM 22 as its working area, thereby performing the control processing described later. Communication device 24 is a device that communicates with software update device 11 via a network.

[0041] The vehicle network 2 includes a software update device 11 (OTA host), a communication module 12, multiple electronic control units (ECUs) 13a-13d, and a display device 14. The software update device 11 is connected to the communication module 12 via bus 15a, to ECUs 13a and 13b via bus 15b, to ECUs 13c and 13d via bus 15c, and to the display device 14 via bus 15d. The software update device 11 can wirelessly communicate with the server 1 via the communication module 12. Based on update data obtained from the server 1, the software update device 11 controls the software updates of the ECUs among the target ECUs 13a-13d. The software update device 11 is sometimes referred to as a central gateway. The communication module 12 is a communication device that connects the vehicle network 2 to the server 1. The ECUs 13a-13d are ECUs that control the operation of various parts of the vehicle. The display device 14 (HMI) is used to perform various displays during the software update process of the electronic control units 13a-13d, such as displaying update data, displaying an approval request screen for requesting approval of the software update from users or administrators, and displaying update results. Typically, the display device 14 is a display device that can be used with a car navigation system, but it is not particularly limited to any device capable of displaying information required for program update processing. Furthermore, in Figure 1 The example shows four electronic control units 13a to 13d, but the number of electronic control units is not particularly limited. Furthermore, in Figure 1 The bus 15d shown can also be further connected to an electronic control unit other than the display device 14.

[0042] like Figure 3 As shown, the software update device 11 includes a microcomputer 35 and a communication device 36. The microcomputer 35 includes a CPU 31, RAM 32, ROM 33, and a storage device 34. In the software update device 11, the CPU 31 of the microcomputer 35 executes a program read from the ROM 33 using the RAM 32 as its working area, thereby performing the control processing described later. The communication device 36 is connected via... Figure 1 The buses 15a to 15d shown are devices that communicate with the communication module 12, the electronic control unit 13a to 13d, and the display device 14.

[0043] Figure 4A and Figure 4B This is a block diagram showing the general structure of the electronic control units 13a to 13d.

[0044] Figure 4A The illustrated electronic control unit 13a includes a CPU 41, RAM 42, non-volatile memory 43a, and a communication device 44. The CPU 41 uses RAM 42 as its working area to execute programs read from the non-volatile memory 43a, thereby implementing the functions of the electronic control unit 13a. The non-volatile memory 43a has a storage area 45 for storing software. Hereinafter, this type of non-volatile memory 43a will be referred to as "Type I". In addition to the software used to implement the functions of the electronic control unit 13a, the storage area 45 may also store version information, parameter data, boot programs, software update programs, etc. The communication device 44 is a device that communicates with the software update device 11, other electronic control units 13b-13d connected to the vehicle network 2, and the display device 14.

[0045] Figure 4BThe electronic control unit 13b shown, like the electronic control unit 13a, includes a CPU 41, RAM 42, non-volatile memory 43b, and a communication device 44. However, the non-volatile memory 43b mounted in the electronic control unit 13b has two storage areas 46a and 46b for storing programs. Hereinafter, this type of non-volatile memory 43b will be referred to as "the second type". In addition to the software used to implement the functions of the electronic control unit 13b, storage areas 46a and 46b sometimes store version information, parameter data, boot programs for startup, programs for software updates, etc. The CPU 41 of the electronic control unit 13b uses one of the two storage areas 46a and 46b of the non-volatile memory 43b as the storage area (operation surface) to be read, and executes the software stored in the storage area to be read. In the other storage area (non-operation surface), which is not the storage area to be read, update data can be written in the background during the execution of the program in the storage area (operation surface) to be read. During software update processing, the updated version of the software can be activated by switching the storage area of ​​the program read target based on CPU 41. For example, suppose the currently running software is stored in storage area 46a, and the updated version of the software is installed in storage area 46b. When the software update device 11 instructs the activation of the updated version of the software, for example, by switching the read start address of CPU 41 from the start address of storage area 46a to the start address of storage area 46b, the storage area (operation plane) of the CPU 41's read target can be switched, and the updated version of the software installed in storage area 46b can be executed. Furthermore, in this invention, a structure called "single-sided suspended memory," which simulates dividing a single-sided storage area into two sides and allows writing a program to the other side while the program on one side is being executed, is also classified as a second type of memory.

[0046] Figure 5 yes Figure 1 The diagram shows the functional block diagram of server 1.

[0047] Server 1 includes a storage unit 26, a communication unit 27, and a control unit 28. The functions of the communication unit 27 and the control unit 28 are achieved through... Figure 2 The CPU 21 shown uses RAM 22 to execute programs stored in storage device 23, and the functions of storage unit 26 are achieved through... Figure 2 The storage device 23 shown is used to implement this.

[0048] Storage unit 26 stores update management information and update data for the software of the electronic control units. In this update management information, for each vehicle identification number (Vehicle ID) of the identified vehicle, information indicating the software usable in one or more electronic control units installed in the vehicle is associated. For example, information indicating the software usable in the electronic control units may define a combination of the latest version information of the software for each of the multiple electronic control units.

[0049] The communication unit 27 can receive software update confirmation requests from the software update device 11. An update confirmation request is, for example, information sent from the software update device 11 to the server 1 when the vehicle is powered on or the ignition is activated, requesting confirmation from the server 1 that update data for the electronic control unit exists. Furthermore, the communication unit 27 receives transmission requests (download requests) for distribution packages from the software update device 11. Upon receiving a download request for a distribution package, the communication unit 27 sends a distribution package containing update data for the electronic control unit's software to the software update device 11.

[0050] When the communication unit 27 receives an update confirmation request, the control unit 28 determines, based on the update management information stored in the storage unit 26, whether there is software update data for the vehicle identified by the vehicle ID included in the update confirmation request. If the control unit 28 determines that update data for the electronic control unit exists, and if it receives a download request for a distribution package from the software update device 11, it generates a distribution package containing the update data stored in the storage unit 26.

[0051] Figure 6 yes Figure 1 The diagram shows the functional block diagram of the software update device.

[0052] The software update device 11 includes a storage unit 37, a judgment unit 38, a communication unit 39, and a control unit 40. The functions of the storage unit 37 are achieved through… Figure 3 The functions of the storage device 34 shown are implemented, and the functions of the judgment unit 38, communication unit 39, and control unit 40 are achieved through... Figure 3 The CPU 31 shown uses RAM 32 to execute programs stored in ROM 33.

[0053] The storage unit 37 stores information indicating whether the type of non-volatile memory installed in each electronic control unit 13a-13d is either a first type or a second type. This information (type information) regarding the type of non-volatile memory installed in the electronic control units 13a-13d can also be pre-generated according to the specifications of the electronic control units 13a-13d constituting the vehicle network 2 and stored in the storage unit 37 during vehicle manufacturing. Alternatively, during software update processing, the communication unit 39 (described later) can obtain information indicating the type of non-volatile memory of the electronic control unit to be updated via communication within the vehicle network 2.

[0054] During software update processing, the determination unit 38 determines whether the non-volatile memory installed in the electronic control unit of the object being updated is a first type of memory with one storage area or a second type of memory with two storage areas. The determination of the type of non-volatile memory based on the determination unit 38 can be performed using non-volatile memory type information stored in the storage unit 37. As described above, the non-volatile memory type information stored in the storage unit 37 can be information pre-generated during vehicle manufacturing, or it can be information generated based on information indicating the type of non-volatile memory obtained from the electronic control unit of the object being updated during software update processing.

[0055] For example, when the vehicle's power or ignition is turned on, the communication unit 39 sends a software update confirmation request to the server 1. The update confirmation request includes the vehicle ID used to identify the vehicle and the software version of the electronic control units 13a-13d connected to the vehicle network 2. The vehicle ID and the software version of the electronic control units 13a-13d are compared with the latest software version stored by the server 1 for each vehicle ID to determine whether update data for the electronic control unit software exists. Furthermore, the communication unit 39 receives a notification from the server 1 indicating whether update data exists, as a response to the update confirmation request. If update data for the electronic control unit software exists, the communication unit 39 sends a download request for a distribution package to the server 1 and receives the distribution package sent from the server 1. The distribution package may contain, in addition to the update data, verification data for verifying the authenticity of the update data, the quantity of update data, the installation order, and various control information used during the software update. Furthermore, when obtaining the type information of the non-volatile memory of the electronic control unit from the electronic control unit of the object being updated during software update processing, the communication unit 39 obtains the type information by communicating with the electronic control unit of the object being updated.

[0056] Based on the response to the update confirmation request received by the communication unit 39, the control unit 40 determines whether update data for the electronic control unit's software exists. The control unit 40 verifies the authenticity of the distribution packet received by the communication unit 39 from the server 1 and stored in the storage unit 37. The control unit 40 transmits one or more downloaded update data files to the electronic control unit to be updated and instructs the electronic control unit to install the update data. After installation is complete, the control unit 40 instructs the electronic control unit to activate the installed updated software version.

[0057] Here, if the non-volatile memory of the electronic control unit is of the first type of memory, installation and activation are performed consecutively; therefore, before installation, approval request processing for software updates, requesting approval from the user or administrator, is implemented. If the non-volatile memory of the electronic control unit is of the second type of memory, approval request processing for software updates is implemented at least after installation and before activation. If the non-volatile memory of the electronic control unit is of the second type of memory, approval request processing for software updates may be implemented or omitted before installation.

[0058] Regarding the control unit 40, during approval request processing, the output device outputs a notification indicating that a software update requires approval, or a notification urging input indicating that the software update has been approved. As the output device, the display device 14 installed in the vehicle network 2, or a voice output device that performs voice-based notifications, can be used. For example, when the display device 14 is used as the output device during approval request processing, the control unit 40 causes the display device 14 to display an approval request screen for requesting software update approval, and, if the user or administrator approves, causes the display device 14 to display a notification urging the user to press the approval button, or other specific input operations. Furthermore, regarding the control unit 40, during approval request processing, the display device 14 can display statements, icons, etc., notifying the existence of software update data for the electronic control unit, or display limitations in the execution of the software update process.

[0059] The control unit 40 performs approval request processing at the time corresponding to the type of memory of the electronic control unit to be updated. When it receives input indicating that the user or manager has approved the request, it performs the above-mentioned installation and activation control processing and updates the software of the electronic control unit to be updated.

[0060] Here, the software update process consists of a stage of downloading update data from server 1, a stage of transmitting the downloaded update data to the electronic control unit of the updated object and installing the update data in the storage area of ​​the electronic control unit of the updated object, and a stage of activating the installed updated version of the software in the electronic control unit of the updated object.

[0061] The download process involves receiving and storing update data sent from server 1 to update the software of the electronic control unit. This download phase includes not only receiving the update data but also controlling a series of download-related processes, such as determining whether the download can be executed and verifying the update data. The installation process involves writing the updated version of the program (updated software) into the storage area of ​​the electronic control unit being updated, based on the downloaded update data. This installation phase includes not only executing the installation but also controlling a series of installation-related processes, such as determining whether the installation can be executed, transmitting the update data, and verifying the updated version of the program. The activation process involves making the installed updated version of the program valid (activated). This activation phase includes not only executing the activation but also controlling a series of activation-related processes, such as determining whether the activation can be executed and verifying the execution result.

[0062] The update data sent from server 1 to software update device 11 may include any one of the following: updated software for electronic control units (ECUs), compressed data containing the updated software, or split data containing either the updated software or the compressed data. Furthermore, the update data may also include an identifier (ECUID) identifying the ECU being updated and an identifier (ECU software ID) identifying the software prior to the update. The update data is downloaded as a distribution package containing update data for one or more ECUs.

[0063] When the update data includes the update software itself, during the installation phase, the software update device 11 transmits the update data (update software) to the electronic control unit (ECU) of the target device. Furthermore, when the update data includes compressed data, differential data, or segmented data of the update software, the software update device 11 can transmit the update data to the ECU of the target device, and the ECU of the target device can generate the update software based on the update data. Alternatively, the update software can be transmitted to the ECU of the target device after the software update device 11 has generated the update software based on the update data. Here, the generation of the update software can be implemented by decompressing compressed data or combining differential or segmented data.

[0064] The installation of the updated software can be performed by the electronic control unit of the object being updated, based on an installation request from the software update device 11. Alternatively, the electronic control unit of the object being updated, having received the update data, can also perform the installation autonomously without receiving explicit instructions from the software update device 11.

[0065] The activation of the updated software can be performed by the electronic control unit of the updated object based on the activation request from the software update device 11. Alternatively, the electronic control unit of the updated object, having received the update data, can also perform activation autonomously without receiving explicit instructions from the software update device 11.

[0066] Furthermore, software updates can be implemented continuously or in parallel for multiple electronic control units.

[0067] Furthermore, the "program update processing" in this manual includes not only the complete process of continuously performing download, installation, and activation, but also the process of performing only a part of the download, installation, and activation.

[0068] Figure 7 This is a flowchart illustrating an example of the control processing performed by server 1 in the first embodiment. Figure 7 The control process shown is executed repeatedly at specified time intervals, for example.

[0069] In step S1, the communication unit 27 determines whether an update confirmation request has been received from the software update device 11. If the determination in step S1 is "yes", the process proceeds to step S2; otherwise, the process proceeds to step S3.

[0070] In step S2, the communication unit 27 sends information indicating whether there is software update data for the electronic control unit to the vehicle that sent the update confirmation request. In the control unit 28, for example, the control unit 28 compares the combination of software versions stored in the update management information and associated with the vehicle ID included in the update confirmation request with the combination of current software versions included in the update confirmation request. If the combination of current software versions included in the update confirmation request is older than the combination of versions stored in the update management information, it can determine that update data exists. Then, the process proceeds to step S3.

[0071] In step S3, the communication unit 27 determines whether it has received a download request for the distribution package from the software update device 11. If the determination in step S3 is "yes", the process proceeds to step S4; otherwise, the process proceeds to step S1.

[0072] In step S4, the communication unit 27 sends a distribution package containing software update data to the software update device 11. Afterwards, the process proceeds to step S1.

[0073] Figure 8 This is a flowchart illustrating an example of the control processing performed by the software update apparatus 11 in the first embodiment. Figure 8 The control process shown is executed, for example, when the vehicle's power supply or ignition device is turned on.

[0074] In step S11, the communication unit 39 sends an update confirmation request to the server 1, which includes a combination of the vehicle ID and the software version of the electronic control unit. Afterwards, the process proceeds to step S12.

[0075] In step S12, the communication unit 39 receives the confirmation result from the server 1. Afterwards, the process proceeds to step S13.

[0076] In step S13, the control unit 40 determines whether there is update data for the software of the electronic control units 13a to 13d based on the response from the server 1 to the update confirmation request sent in step S1. If the determination in step S13 is "yes", the process proceeds to step S14; otherwise, the process ends.

[0077] In step S14, the communication unit 39 performs the download process. More specifically, the communication unit 39 sends a download request for a distribution packet to the server 1, receives a distribution packet sent in response to the download request, and stores the received distribution packet in the storage unit 37. The control unit 40 verifies the authenticity of the updated data contained in the received distribution packet. In step S14, a determination of whether the download can be performed and a notification of download completion to the server 1 may also be implemented. Afterward, the process proceeds to step S15.

[0078] In step S15, the determination unit 38 determines the type of non-volatile memory possessed by the electronic control unit of the object to be updated and determines the timing for executing the approval request processing. When information regarding the type of memory, including the type of non-volatile memory mounted in each electronic control unit 13a-13d, is pre-stored in the storage unit 37, the determination unit 38 determines the type of memory of the electronic control unit of the object to be updated based on the type information stored in the storage unit 37. Furthermore, in step S15, the communication unit 39 performs a process of obtaining information indicating the type of memory through communication with the electronic control unit of the object to be updated and storing it in the storage unit 37; the determination unit 38 can also determine the type of memory of the electronic control unit of the object to be updated based on the type information stored in the storage unit 37 by the communication unit 39. If at least one electronic control unit in the electronic control unit of the object to be updated has a memory of the first type, approval before installation is necessary. Therefore, the determination unit 38 determines that the approval request processing should be executed at least before installation. In this case, the determination unit 38 can also determine, based on pre-registered settings, that the approval request processing should be executed not only before installation but also before activation. On the other hand, if all electronic control units of the updated object have a second type of memory, since approval before activation is necessary, the determination unit 38 determines that the approval request processing should be performed at least before activation. In this case, the determination unit 38 may also determine, based on pre-registered settings, that the approval request processing should be performed not only before activation but also before installation. Afterward, the process proceeds to step S16.

[0079] In step S16, the control unit 40 performs installation and activation processes for the electronic control unit of the updated target, and then ends the process.

[0080] Figure 9 It means Figure 8 The detailed flowchart of the installation and / or activation process is shown.

[0081] In step S21, the control unit 40 determines the amount of data collected based on the data collected in the control unit. Figure 8 In step S15, the decision unit 38 determines the timing of the approval request processing and whether approval request processing is required before installation. If the decision in step S21 is "yes", the process proceeds to step S22; otherwise, the process proceeds to step S24.

[0082] In step S22, the control unit 40 performs approval request processing for the installation. For example, the control unit 40 displays an indication that a software update of the electronic control unit is starting, an indication that the user is requesting approval for the software update, and displays the installation time required for the update data, limitations during installation, and precautions as needed. It also accepts user input via input units such as the touch panel and operation buttons. Afterward, the process proceeds to step S23.

[0083] In step S23, the control unit 40 determines whether an operation input indicating approval of the software update (installation) has been performed. This operation input can be determined, for example, by whether a button such as "Approve" or "Start Update" displayed on the display device 14 has been pressed. Furthermore, if the user does not immediately approve the start (installation) of the software update but wishes to proceed with it later, the control unit 40 can accept this intention by pressing a button such as "Proceed Later," and in this case, the control unit 40 determines "No" in step S24. If the determination in step S23 is "Yes," the process proceeds to step S24; otherwise, the process ends.

[0084] In step S24, the control unit 40 transmits update data to the electronic control unit of the device being updated and instructs it to install. Afterwards, the process proceeds to step S25. The electronic control unit of the device being updated writes the update data received from the software update device 11 into the software storage area.

[0085] In step S25, the control unit 40, based on the... Figure 8 In step S15, the timing of the approval request processing determined by the determination unit 38 determines whether the previous approval request processing needs to be activated. If the determination in step S25 is "yes", the process proceeds to step S26; otherwise, the process proceeds to step S28.

[0086] In step S26, the control unit 40 performs approval request processing for activation. For example, the control unit 40 completes preparation for software updates of the electronic control unit, displays the main points of the updated program by performing specific operations such as turning off the power or ignition switch, and displays the activation time, limitations and precautions during activation as needed, and accepts user input using input units such as touch panel and operation buttons. After that, the process proceeds to step S27.

[0087] In step S27, the control unit 40 determines whether an operation input for approving a software update (activation) has been performed. For example, it can determine the operation input for approving activation based on whether the "Approve" or "Update" button displayed on the display device 14 has been pressed. Furthermore, if the user does not immediately approve the software update (activation) but wishes to perform the software update later, the control unit 40 can accept this situation by pressing a button such as "Perform later," and in this case, the control unit 40 determines "No" in step S27. If the determination in step S27 is "Yes," the process proceeds to step S28; otherwise, the process ends.

[0088] In step S28, the control unit 40 instructs the electronic control unit (ECU) targeted for update to activate the updated software. Afterward, the process ends. Furthermore, the ECU targeted for update is restarted and executes the updated software after a specific operation, such as turning off the power or ignition switch. Thus, the software update (function update) of the ECU is completed.

[0089] As described above, when the non-volatile memory in the electronic control unit (ECU) of the update target is of the first type, the currently running software is rewritten by installing update data, thus affecting the ECU of the update target during the update data installation phase. Therefore, when the ECU of the update target includes an ECU equipped with the first type of memory, an approval request processing must be performed before writing the update data, and acceptance of approval is a condition for the start of installation. On the other hand, when the non-volatile memory in the ECU of the update target is of the second type of memory, the effect occurs not during the update data installation phase but during the phase of activating the updated version of the software after installation. Therefore, when all the ECUs of the update target are ECUs equipped with the second type of memory, after installing the update data and before activating the updated version of the software, an approval request screen requesting user approval must be displayed on the display device 14. User approval of the program update (activation of the update program) is necessary for performing the approval request processing, and acceptance of approval is a condition for the start of activation.

[0090] The software update apparatus 11 of this embodiment varies the timing of the approval request processing during software updates based on the type of non-volatile memory of the electronic control unit to be updated. Therefore, the software update apparatus of this embodiment can request approval at an appropriate time according to the specifications of the electronic control unit to be updated.

[0091] Specifically, when the non-volatile memory of at least one electronic control unit mounted on the target of the update is a first type of memory, the software update device 11 displays an approval request screen on the display device 14 before writing the update program into the storage area of ​​the non-volatile memory. On the other hand, when all the non-volatile memories of the electronic control unit mounted on the target of the update are second type of memory, the software update device 11 displays an approval request screen on the display device 14 after installing the update data into the non-readable storage area of ​​the non-volatile memory and before activating the storage area where the updated version of the software has been written. Therefore, the software update device 11 according to this embodiment can perform approval request processing at an appropriate time depending on the number of storage areas of the non-volatile memory of the electronic control unit mounted on the target of the update.

[0092] Variations of the first embodiment

[0093] In the above example, the software update device 11 determines the approval request processing based on information pre-stored in the storage unit 37 indicating the type of memory for electronic control units 13a-13d, or information obtained from the electronic control unit to be updated via communication. The structure (type, memory type) of the electronic control units 13a-13d mounted in the vehicle is managed by the server 1; therefore, the communication unit 39 can also obtain information from the server 1 via communication regarding the type of non-volatile memory for the electronic control unit to be updated, and store it in the storage unit 37. In this configuration, Figure 7 In step S4, the communication unit 27 of server 1 includes update data and information indicating the type of memory of the electronic control unit to be updated in a distribution package and sends it to the vehicle. In the software update device 11, the control unit 40, according to... Figure 8 In step S14, the communication unit 39 receives information in the distribution packet that indicates the type of memory of the electronic control unit to be updated, and performs the processing in step S15, thereby determining the timing for processing the approval request.

[0094] Second Implementation Method

[0095] In the first embodiment described above, the software update device 11 has a storage unit that stores information indicating the type of memory of the electronic control units 13a to 13d. The structure for controlling the execution timing of approval request processing is explained based on the memory type of the electronic control units 13a to 13d pre-stored in the storage unit, or the information indicating the type of memory obtained by the software update device 11 from the electronic control units 13a to 13d or from the server 1 via communication. On the other hand, in this embodiment, the server 1 stores information indicating the type of non-volatile memory mounted on the electronic control units 13a to 13d in the storage unit 26, and sends instruction information indicating the execution timing of approval request processing to the vehicle's software update device 11. Hereinafter, the differences between this embodiment and the first embodiment will be described.

[0096] Figure 10 This is a flowchart illustrating an example of control processing performed by the server in the second embodiment. Figure 10 The control process shown is to Figure 7 The control process step S4 shown is replaced by the process step S4'.

[0097] In step S3, when the communication unit 27 receives a download request for a distribution package from the software update device 11, in step S4', the communication unit 27 sends a distribution package containing update data and instruction information for the electronic control unit's software to the software update device 11. The instruction information is information used to instruct the software update device 11 on the timing of processing an approval request when performing software update processing, and is generated based on the type of non-volatile memory of the electronic control unit mounted on the target of the update. For example, the instruction information can be generated by the control unit 28 performing the following steps.

[0098] First, the control unit 28 determines the electronic control unit (ECU) and its memory type that were determined to have update data in step S2 for the vehicle identified by the vehicle ID included in the download request received in step S3. The types of ECUs and memory types installed in each vehicle are pre-registered in the storage unit 26 of server 1 during manufacturing. Therefore, the control unit 28 can obtain the memory type of each ECU (i.e., the ECU with update data) identified in step S2 as the target of the update based on the pre-registered information. Next, the control unit 28 generates instruction information based on the memory type of the non-volatile memory installed in the ECU of the target of the update. Specifically, if the target ECU includes an ECU equipped with a first type of memory, the control unit 28 generates information instructing that an approval request process be performed before installation that has a substantial impact on the ECU of the update. Furthermore, if all the target ECUs are ECUs equipped with a second type of memory, the control unit 28 generates information instructing that an approval request process be performed before activation that has a substantial impact on the ECU of the update. The communication unit 27 includes the instruction information generated by the control unit 28 along with the update data of the electronic control unit of the updated target in a distribution package and sends it to the vehicle that sent the download request.

[0099] Figure 11 This is a flowchart illustrating an example of the control processing performed by the software update device 11 in the second embodiment. Figure 11 The control process shown is to Figure 8 The control process step S15 shown is replaced by the process of step S15'.

[0100] In the software update device 11, when the communication unit 39 receives a distribution packet (step S14), in step S15', the control unit 40 determines the timing for executing the approval request processing based on the instruction information contained in the distribution packet. The installation and / or activation process in step S16... Figure 9 In step S15, execution is performed according to the execution timing determined in step S15. Figure 9 The judgments in steps S21 and S25 are shown.

[0101] In this embodiment, if an instruction message indicating the timing of the approval request processing is generated in the server 1 and sent to the vehicle, it is not necessary to determine the memory type of the electronic control unit of the update target in the software update device 11, thus making the control processing of the software update device 11 simpler.

[0102] The functions of the server 1 exemplified in the above embodiments can also be implemented as an update management method executed by a computer having a processor (CPU), memory, and storage device, or as an update management program executed by the computer, or as a non-temporary storage medium readable by a computer storing the update management program. Similarly, the functions of the software update device 11 exemplified in the embodiments can also be implemented as an update control method executed by an onboard computer having a processor (CPU), memory, and storage device, or as an update control program executed by the onboard computer, or as a non-temporary storage medium readable by a computer storing the update control program.

[0103] In the above embodiments, an example has been described in which the software update device 11 installed on the vehicle side in the vehicle network 2 acts as a host device to control the program updates of all electronic control units 13a to 13d. However, instead of installing the software update device 11, any one of the electronic control units 13a to 13d may have... Figure 8 as well as Figure 9 The update control function shown controls the program updates of other electronic control units. Alternatively, instead of installing the software update device 11, it can be used to... Figure 8 and Figure 9 The update control function shown is set in an external device that can be connected to the vehicle network 2 via a wired connection, and the program update process of the electronic control units 13a to 13d is performed using the external device.

[0104] The technology of this invention can be applied to network systems that update the programs of electronic control units.

Claims

1. A software update device that controls software update of an electronic control unit, the software update device characterized by comprising: a control section configured to control a timing of execution of an approval request process for requesting approval for a software update process, according to a kind of a nonvolatile memory possessed by an electronic control unit that is an update target, when performing the software update process of the electronic control unit, the kind of the nonvolatile memory being classified into a first kind having one storage area and a second kind having two storage areas, the control section being configured to execute the approval request process before installation of update data in a storage area of the nonvolatile memory, in a case where the nonvolatile memory mounted on at least one electronic control unit that is an update target is the first kind of memory, and to execute the approval request process after installation of the update data in a non-reading-target storage area of the nonvolatile memory and before activation of a storage area in which the update data is written as a reading-target, in a case where the nonvolatile memory mounted on the electronic control unit that is an update target is the second kind of memory.

2. The software update device according to claim 1, characterized by further comprising a determination section configured to determine whether the nonvolatile memory mounted on the electronic control unit that is an update target is the first kind of memory or the second kind of memory, the control section being configured to control the timing of execution of the approval request process according to a determination result of the determination section.

3. The software update device according to claim 2, characterized by further comprising a storage section configured to store the kind of the nonvolatile memory mounted on the electronic control unit, the determination section being configured to determine the kind of the nonvolatile memory mounted on the electronic control unit that is an update target, according to the kind of the nonvolatile memory stored in the storage section. further comprising: a communication section configured to receive the kind of the nonvolatile memory mounted on the electronic control unit from a server; 4. The software updating apparatus according to claim 2, wherein a storage section configured to store the received kind of the nonvolatile memory, the determination section being configured to determine the kind of the nonvolatile memory mounted on the electronic control unit that is an update target, according to the kind of the nonvolatile memory stored in the storage section.

5. The software update device according to claim 1, characterized by further comprising a communication section configured to receive indication information from a server, the indication information indicating the timing of execution of the approval request process according to the kind of the nonvolatile memory possessed by the electronic control unit that is an update target, the control section being configured to control the timing of execution of the approval request process according to the received indication information.

6. The software update device according to any one of claims 1 to 5, characterized in that the control section is configured to cause a display device to display a screen requesting approval for software update in the approval request process. ​ ​ ​ ​ 7. A non-transitory storage medium storing a program capable of being executed by a computer to cause the computer having a processor, a memory, a storage device to execute the following function in order to control software update of an electronic control unit, the non-transitory storage medium characterized by, the function being, at the time of executing a software update process of the electronic control unit, controlling an execution timing of an approval request process for requesting approval for the software update process in accordance with a kind of a nonvolatile memory possessed by an electronic control unit that is an update target, in a case where the nonvolatile memory mounted on at least one electronic control unit that is an update target is a first kind of memory having one storage area, executing the approval request process before update data is installed in the storage area of the nonvolatile memory, in a case where the nonvolatile memory mounted on the electronic control unit that is an update target is a second kind of memory having two storage areas, executing the approval request process after the update data is installed in a non-reading target storage area of the nonvolatile memory and before a storage area in which the update data is written is activated as a reading target.

8. An OTA host that controls software update of an electronic control unit, the OTA host characterized by having: a control section configured to, at the time of executing a software update process of the electronic control unit, control an execution timing of an approval request process for requesting approval for the software update process in accordance with a kind of a nonvolatile memory possessed by an electronic control unit that is an update target, the kind of the nonvolatile memory being divided into a first kind having one storage area and a second kind having two storage areas, the control section being configured to, in a case where the nonvolatile memory mounted on at least one electronic control unit that is an update target is the first kind of memory, execute the approval request process before update data is installed in the storage area of the nonvolatile memory, and in a case where the nonvolatile memory mounted on the electronic control unit that is an update target is the second kind of memory, execute the approval request process after the update data is installed in a non-reading target storage area of the nonvolatile memory and before a storage area in which the update data is written is activated as a reading target.

Citation Information

Patent Citations

  • Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device

    JP2004326689A

  • Multiple-Stage Secure Vehicle Software Updating

    CN106484457A

  • Software Update Device and Software Update System

    US20190354363A1

  • Vehicle information communication system

    US20200050378A1