Server, software update device, vehicle, software update system, control method, and non-transitory storage medium
By receiving vehicle usage information, the communication time and speed of software updates is optimized, and the bandwidth tightness and delay of software updates in the vehicle network system is solved, and an efficient software update process is realized.
Patent Information
- Application Number
- CN202110763432.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-27
- Filing Date
- 2021-07-06
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2041-07-06
AI Technical Summary
In vehicle network systems, the prior art has problems of tight communication bandwidth, increased load and delay in the software update process, especially when the vehicle usage is uneven, it is difficult to achieve fast and efficient software updates.
Receive vehicle usage status information through the server, control the transmission time and communication speed of update data, optimize the communication process of software updates, including download, installation and activation steps, and ensure efficient communication when the vehicle usage is appropriate.
It effectively suppresses bandwidth tension and load increase, reduces the delay in software updates, and ensures efficient software updates at the appropriate time of the vehicle.
Smart Images

Figure CN113986259B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a server, a software update device, a vehicle, a software update system, a control method, and a non-transitory storage medium included in a network system mounted on a vehicle or the like. Background Art
[0002] In a vehicle, a network system is mounted which is configured by connecting a plurality of in-vehicle devices called ECUs (Electronic Control Units) to each other via a communication line. Each in-vehicle device transmits and receives messages to and from each other and shares and executes each function of the vehicle.
[0003] Generally, an in-vehicle device includes a processor, a temporary storage unit such as a RAM, and a non-volatile storage unit such as a flash ROM. Software (software) executed by the processor is stored in the non-volatile storage unit. By updating the software by rewriting it to a newer version, improvement and enhancement of the functions of the in-vehicle device can be achieved.
[0004] In the update of software, there are steps of downloading update data received from a server (server, center) via wireless communication or the like, and an installation step of writing the updated software into the storage unit of the in-vehicle device based on the downloaded update data. In the installation, there are overwrite installation and side-by-side installation. Depending on the specifications of the in-vehicle device, overwrite installation or side-by-side installation is implemented. Overwrite installation is an installation in which the downloaded updated software is written in one area (single-sided) of an area determined as a software storage area in the storage area of the storage unit so as to overwrite the current software (old software). Side-by-side installation is performed in an in-vehicle device in which the storage area includes two areas (double-sided) determined as software storage areas. The two areas include an area (one side) in which the current software (old software) is stored and another area (the other side) that is not an area for storing the current software. Side-by-side installation is an installation in which the downloaded updated software is written in another area (the other side) that is not an area for storing the current software. The two areas determined as software storage areas may be, for example, areas respectively included in different banks (structural units) of the same memory component, or may be areas of different memory components.
[0005] In the case of side-by-side installation, in the software update step, in addition to the steps of downloading and installation, there is also an activation step in which setting values such as the start address of the updated software are configured so that the installed updated software can be executed.
[0006] Regarding the software update of the ECU, Japanese Patent Laid-Open No. 2011-148398 discloses that a specific ECU functions as a host ECU, communicates with a server, and updates the software of the host ECU itself and other ECUs. Summary of the Invention
[0007] A server (center) for distributing update data for software update is provided, and the update data for software update of in-vehicle devices mounted on multiple vehicles is distributed to each vehicle respectively. In order to implement software update quickly, it is preferable that the communication speed of the server is fast. However, when the communication speed is equally increased, there are problems such as tight bandwidth and increased load. Therefore, appropriate communication control is desired.
[0008] The present invention provides a server, a software update device, a vehicle, a software update system, a control method, and a non-transitory storage medium that can appropriately implement communication of update data for software update.
[0009] The first aspect of the present invention is a server configured to send update data for software update of in-vehicle devices of a vehicle to the vehicle. The server includes: a communication unit configured to receive usage information indicating the usage status of the vehicle and send the update data to the vehicle; and a control unit configured to control at least one of the time and the communication speed at which the communication unit sends the update data to the vehicle according to the usage information.
[0010] The second aspect of the present invention is a software update device mounted on a vehicle. The software update device includes: a control unit configured to obtain or generate usage information indicating the usage status of the vehicle; and a communication unit configured to send the usage information to a server and receive, at at least one of the time and the communication speed determined according to the usage information, update data for software update of in-vehicle devices of the vehicle from the server.
[0011] The third aspect of the present invention is a vehicle having the software update device according to the second aspect.
[0012] The fourth aspect of the present invention is a software update system including: a software update device configured to send usage information indicating the usage status of a vehicle; and a server configured to receive the usage information from the software update device, control at least one of the time and the communication speed at which update data for software update of in-vehicle devices of the vehicle is sent, and send the update data to the software update device.
[0013] A fifth aspect of the present invention is a control method executed by a server computer, the server being configured to send update data for updating software of in-vehicle devices of a vehicle to the vehicle, the control method including: a step of receiving usage information indicating a usage state of the vehicle; and a step of controlling at least one of a timing of sending the update data and a communication speed according to the usage information, and sending the update data to the vehicle.
[0014] A sixth aspect of the present invention is a non-transitory storage medium storing a control program executable by a computer of a server and causing the computer to execute the control method according to the fifth aspect, the server being configured to send update data for updating software of in-vehicle devices of a vehicle to the vehicle.
[0015] According to the present invention, at least one of the timing of sending update data for software update and the communication speed is controlled according to the usage state of the vehicle. Therefore, compared with the case of uniformly increasing the communication speed, it is possible to suppress bandwidth tension and load increase, and at the same time suppress the delay of software update. In this way, according to the server, software update device, vehicle, software update system, method, and non-transitory storage medium of the present invention, communication of update data for software update can be appropriately implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Hereinafter, with reference to the drawings, features, advantages, and technical and industrial significance of exemplary embodiments of the present invention will be described. In the drawings, the same reference numerals denote the same elements.
[0017] Figure 1 is a structural diagram of a network system according to an embodiment.
[0018] Figure 2 is a sequence diagram showing a process according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] <Structure>
[0020] Figure 1 shows a structural example of a network system 1 according to the present embodiment. The network system 1 is mounted on a vehicle. The network system 1 includes a software update device 50. In the software update device (OTA (Over-The-Air) host) 50, a plurality of buses 10, 20, 30 are connected. A plurality of in-vehicle devices (electronic control units) 11, 12 are connected to the bus 10. A plurality of in-vehicle devices 21, 22 are connected to the bus 20. A plurality of actuators 31, 32 are connected to the bus 30. In Figure 1In the following description and later, as buses, buses 10, 20, and 30 are exemplified. As in-vehicle devices, in-vehicle devices 11, 12, 21, and 22 are exemplified. Actuators 31 and 32 are exemplified, but their numbers are not limited. In addition, various sensors for obtaining the state of the vehicle and its surroundings are appropriately connected to buses 10, 20, 30 or in-vehicle devices 11, 12, 21, and 22.
[0021] The software update device 50 includes a communication unit (communication module) 51 capable of communicating with a server (center, external device) 100 provided outside the vehicle, a first storage unit (memory) 52 for storing various data, and a control unit 53.
[0022] Each of the in-vehicle devices 11, 12, 21, and 22 communicates with each other via a network and performs various processes for controlling the vehicle. Although not shown in the figure, these in-vehicle devices include a non-volatile second storage unit (memory) such as a flash ROM, a control unit (processor, microcontroller) that performs various processes by reading and executing software from the second storage unit, and a temporary storage unit such as a RAM that stores a part of the software and data. In addition, the software update device 50 similarly stores software (program) for the software update device 50 in the first storage unit 52, and by reading and executing the software by the control unit 53 (processor, microcontroller), the functions of the software update device 50 can be executed. That is, each of the in-vehicle devices 11, 12, 21, and 22 and the software update device 50 can be implemented as a computer including one or more processors or one or more microcontrollers, etc.
[0023] In addition, the control unit 53 of the software update device 50 controls and relays the communication between the server 100 and each of the in-vehicle devices 11, 12, 21, and 22, the communication between each of the in-vehicle devices 11, 12, 21, and 22, and the communication and relay between each of the in-vehicle devices 11, 12, 21, and 22 and each of the actuators 31 and 32 via the respective buses 10, 20, and 30. In this way, the software update device 50 also functions as a relay device for relaying communication. Alternatively, the software update device 50 can be provided as a part of such a relay device, or can be connected to any one of the buses 10, 20, and 30 separately from such a relay device.
[0024] The actuators 31 and 32 are devices that exert a mechanical action on the vehicle and its components, such as brakes, engines, or power steering devices, and operate according to instructions from the in-vehicle devices 11, 12, 21, and 22.
[0025] The control unit 53 of the software update device 50 can update the software stored in the second storage units of the in-vehicle devices 11, 12, 21, and 22 respectively. That is, the software update device 50 implements control of downloading, installation, or further activation. Regarding downloading, it is a process of receiving and storing update data (distribution package) for updating the software of any one of the in-vehicle devices 11, 12, 21, and 22 sent from the server 100. The control of downloading includes not only the execution of downloading, but also the control of a series of processes related to downloading, such as the judgment of whether downloading can be executed and the verification of update data. Regarding installation, it is a process of writing the updated version of the software (updated software) into the second storage unit of the in-vehicle device to be updated according to the downloaded update data. The control of installation includes not only the execution of installation, but also the control of a series of processes related to installation, such as the judgment of whether installation can be executed, the transmission of update data, and the verification of the updated version of the software. Activation is a process of validating (activating) the installed updated version of the software. The control of activation includes not only the execution of activation, but also a series of controls related to activation, such as the judgment of whether activation can be executed and the verification of the execution result.
[0026] In the control of installation, when the update data includes the updated software itself, the control unit 53 can send the updated software to the in-vehicle device. In addition, when the update data includes compressed data, differential data, or split data of the updated software, the control unit 53 can decompress or assemble the update data to generate the updated software and send it to the in-vehicle device. Alternatively, the control unit 53 can also send the update data to the in-vehicle device, and the in-vehicle device can decompress or assemble the update data to generate the updated software.
[0027] Regarding the execution of the installation itself of writing the updated software into the second storage unit of the in-vehicle device, it can be implemented by the control unit 53, or by the in-vehicle device that has received the instruction from the control unit 53. The in-vehicle device that has received the update data (or the updated software) can also implement it autonomously without the explicit instruction of the control unit 53.
[0028] Regarding the execution of the activation itself of validating the installed updated software, it can be implemented by the control unit 53, or by the in-vehicle device that has received the instruction from the control unit 53. The in-vehicle device can also implement it autonomously after installation without the explicit instruction of the control unit 53.
[0029] In addition, the update process of such software can be implemented continuously or in parallel for each of a plurality of in-vehicle devices. Further, the update data is data for generating updated software, and there is no limitation on the content or form. As described above, for example, it includes the updated software itself, differential data for generating the updated software, or compressed data or segmented data thereof. Further, the update data may also include an identifier (ECUID) of the in-vehicle device (target electronic control unit) to be updated with software and an identifier (ECU Software ID) of the version of the software before the update.
[0030] As an example, the server 100 is a computer device such as a server installed in a specific center or the like, and can send respective update data for updating the software of the in-vehicle devices of each of a plurality of vehicles. The server 100 includes a communication unit (communication module) 111 that communicates with the software update device 50 and a control unit 112 that controls the communication unit 111. The functions of the control unit 112 are executed by one or more processors or one or more microcontrollers or the like. Further, the server 100 has a storage unit (not shown) and can receive and store data for updating the software of each of the plurality of in-vehicle devices from the outside.
[0031] <Processing>
[0032] Hereinafter, an example of the software update process according to the present embodiment will be described. A timing chart showing an example of this process is shown in Figure 2 This process typically starts when the vehicle is powered on (ignition switch on, power on). Specifically, it may also start at the moment when the vehicle is powered on.
[0033] (Step S101)
[0034] The control unit 53 of the software update device 50 controls the communication unit 51 and asks the server 100 about the presence or absence of updated software.
[0035] (Step S102)
[0036] When the communication unit 111 of the server 100 receives the inquiry, the control unit 112 controls the communication unit 111 to send a notice of the presence of an update to the software update device 50 when there is updated software. The control unit 112 can, for example, determine the presence or absence of updated software as an updated version of the software for these in-vehicle devices based on information indicating the types of a plurality of in-vehicle devices included in the network system 1 and the current software version. Such information may be stored in the server 100 in advance or received together with the inquiry from the software update device 50. Further, when there is no updated software, the control unit 112 controls the communication unit 111 to send a notice of the absence of an update to the software update device 50.
[0037] (Step S103)
[0038] When the communication unit 51 of the software update device 50 receives a notification of the existence of an update, the control unit 53 performs a display that requests approval for downloading update data in the HMI (Human Machine Interface) device, which is one of the in-vehicle devices. When the user performs an approval operation on the HMI device, the control unit 53 controls the communication unit 51 to send an update data request and usage information to the server 100.
[0039] The usage information is information indicating the usage status of the vehicle. The usage information includes, but is not limited to, for example, the time when the vehicle has been used multiple times in the past or its average time, etc. The time when the vehicle is used refers to, for example, the time from when the ignition switch is turned on until the vehicle travels, stops, and until the ignition switch is turned off. Or, the usage information can include, for example, information indicating the usage frequency of multiple functions of the vehicle. The usage frequency of multiple functions of the vehicle refers to, for example, the number of times each function such as lane keeping, speed keeping, automatic braking, proximity alarm, etc., which constitute ADAS (Advanced Driver Assistance Systems), has been activated through user operations, etc., during a certain number of past trips. Or, the usage information can include information generated based on the driving plan set in the vehicle. The driving plan refers to, for example, the driving route to the currently set destination in the car navigation device, which is one of the in-vehicle devices. The usage information is, for example, the assumed required time to reach the destination calculated based on the driving plan. The control unit 53 can obtain the usage information generated by each in-vehicle device, or can also generate the usage information based on information such as logs and driving plans obtained from each in-vehicle device.
[0040] (Step S104)
[0041] When the communication unit 111 of the server 100 receives the update data request and the usage information, the control unit 112 of the server 100 generates update data. The update data includes data for updating the software of one or more in-vehicle devices (target electronic control units) that are the update targets of the software.
[0042] The control unit 112 determines at least one of the timing and speed for sending update data to the vehicle based on the usage information received from the vehicle. For example, when the usage information includes the usage time and shows a tendency that the usage time of the vehicle is relatively short, compared with the case showing a tendency that the usage time is relatively long, the control unit 112 makes the communication speed for the vehicle relatively fast. Regarding the relatively short usage time of the vehicle, for example, it can be determined by the average value, mode value or median value of the usage time of the vehicle being less than a fixed value, or by being smaller compared with the average value, mode value or median value of the usage time derived from the usage information received from other vehicles within a past fixed period.
[0043] Alternatively, for example, when it is assumed that the usage information includes information generated based on the driving plan set in the vehicle and shows that the current usage time during driving is relatively short, compared with the case where it is assumed that the current usage time during driving is relatively long, the control unit 112 makes the communication speed for the vehicle relatively fast. Regarding the relatively short assumed usage time of the vehicle, for example, it can be determined by the assumed usage time being smaller compared with a fixed value, or by being smaller compared with the average value of the usage time derived from the usage information received from other vehicles within a past fixed period.
[0044] Alternatively, for example, when the usage information includes information indicating the usage frequency of multiple functions of the vehicle, the control unit 112 can also determine, based on the usage information, to send the update data related to the software of the function with a relatively high usage frequency to the vehicle earlier than the update data related to the software of the function with a relatively low usage frequency. In addition, in order to determine the software corresponding to each function, the control unit 112 refers to, for example, the information associating the function with the software or in-vehicle device that implements the function. This information can be received by the server 100 from the vehicle as part of the usage information or as information different from the usage information, or can be pre-stored by the server 100.
[0045] (Step S105)
[0046] The control unit 112 of the server 100 controls the communication unit 111 to send the update data at the speed and timing determined in step S104.
[0047] (Step S106)
[0048] When the communication unit 51 of the software update device 50 receives the update data, the control unit 53 stores the update data in the first storage unit 52 (download).
[0049] (Step S107)
[0050] Regarding the control unit 53 of the software update device 50, when the communication unit 51 of the software update device 50 receives a notification that there is an update, the control unit 53 performs a display in the HMI (Human Machine Interface) device to request approval for installation and the like. When the user performs an approval operation in the HMI device, the installation or the processing of installation and activation is started. Here, as an example, the in-vehicle device 11 is included in the in-vehicle devices that are the objects of software update, and the control unit 53 sends the data for updating the software of the in-vehicle device 11, which is included in the update data received from the server 100, to the in-vehicle device 11.
[0051] (Step S108)
[0052] When the in-vehicle device 11 receives data, it updates the software according to the received data. That is, in the case where the in-vehicle device 11 is of the type that performs an overlay installation, the in-vehicle device 11 performs the above-mentioned overlay installation. In addition, in the case where the in-vehicle device 11 is of the type that performs the above-mentioned other-side installation, the in-vehicle device 11 sequentially performs the above-mentioned other-side installation and activation.
[0053] (Step S109)
[0054] Regarding the control unit 53 of the software update device 50, in the data for updating the software of each in-vehicle device, which is included in the update data received from the server 100, if there is data that has not been sent to the in-vehicle device that is the update object, the communication unit 51 is controlled to send it to the in-vehicle device that is the update object. Here, as an example, the in-vehicle device 12 is included in the in-vehicle devices that are the objects of software update, and the control unit 53 sends the data for updating the software of the in-vehicle device 12 to the in-vehicle device 12.
[0055] (Step S110)
[0056] When the in-vehicle device 12 receives data, according to the received data, similar to the in-vehicle device 11 in step S108, it performs an overlay installation or the other-side installation and activation of the software.
[0057] The above example is an example of the case where the update data received from the server 100 includes data for updating the software of the in-vehicle devices 11 and 12, but the software update of other in-vehicle devices can be implemented in the same way. In addition, the number of in-vehicle devices that are the update objects is not limited to two, and can be one or three or more. In addition, regarding the data sent from the software update device 50 to each in-vehicle device in steps S107 and S109, as described above, it can actually be the software itself, or its compressed data, or the differential data with the software before the update, etc.
[0058] Regarding downloading, typically it starts upon obtaining the approval of the user when the user enters the vehicle and starts using the vehicle. Downloading can also be performed while the vehicle is in motion. However, regarding overwriting installation and activation, during their execution, the functions of in-vehicle devices are restricted, which may pose an obstacle to the operation of the vehicle. Therefore, typically, after obtaining the approval of the installation from the user in step S107, it is performed in a state where the vehicle power is turned off (ignition switch is turned off, power is off). If the download is completed before the vehicle reaches the destination, installation and activation can be immediately performed after the user gets off the vehicle, enabling software updates without delay. However, if the download is not completed even when the vehicle reaches the destination, the download is interrupted due to power off, for example, and resumes during the next drive. Or, even if the download continues without being interrupted due to power off, installation and activation cannot be performed until the user approves and turns off the vehicle power during the next drive. As described above, in the case where the download is not completed even when the vehicle reaches the destination, software updates will be delayed.
[0059] <Effect>
[0060] Based on past usage history, in the case where there is a tendency for the usage time of the vehicle to be relatively short, compared to the case where there is a tendency for it to be relatively long, by making the communication speed for the vehicle relatively fast, even when the usage time of the vehicle is relatively short, the probability that the download is completed within the usage time and installation and activation can be immediately performed thereafter can be increased. In addition, in the case where it is assumed based on the driving route that the usage time of the vehicle during the current drive is relatively short, compared to the case where it is assumed that the usage time of the vehicle during the current drive is relatively long, by making the communication speed for the vehicle relatively fast, even when the usage time of the vehicle during the current drive is relatively short, the probability that the download is completed within the usage time and installation and activation can be immediately performed thereafter can be increased. In addition, by sending the update data of the software related to the function with a relatively high usage frequency to the vehicle earlier than the update data of the software related to the function with a relatively low usage frequency, at least the probability that the download of the update data of the software related to the function with a high usage frequency is completed within the usage time and installation and activation can be immediately performed thereafter can be increased. In addition, they can also be combined. For example, in the case where there is a tendency for the usage time of the vehicle to be relatively short based on past history and it is assumed based on the driving route that the usage time of the vehicle during the current drive is relatively short, the communication speed can be made relatively fast compared to the case based on only one of the situations. In addition, the update data of the software related to the function with a relatively high usage frequency can be sent at a relatively faster speed compared to the update data of the software related to the function with a relatively low usage frequency.
[0061] In this way, according to the present embodiment, at least one of the timing and the communication speed for transmitting update data for software update is controlled according to the usage status of the vehicle, so that the delay of software update can be suppressed. In addition, compared with the case where the communication speed is equally increased, bandwidth tension and load increase are easily suppressed.
[0062] The present invention can be regarded not only as a server, but also as a software update device, a network system including the software update device, a system including the software update device and the server, a method executed by computers respectively provided in the server and the software update device, a program, a computer-readable non-temporary storage medium storing the program, a vehicle having the software update device, and the like.
[0063] The present invention is beneficial to a network system mounted on a vehicle or the like.
Claims
1. A server configured to send update data for software of on-vehicle devices of a vehicle to the vehicle, the server being characterized by comprising: A communication unit configured to receive usage information indicating the usage status of the vehicle and send the update data to the vehicle; A control unit configured to control a communication speed of communication between the vehicle and the server, in which the communication unit sends the update data to the vehicle, according to the usage information, where The control unit is configured to control the communication speed in such a manner that, when the usage information indicates that the usage time is less than a threshold, the communication speed for the vehicle is made faster than in the case where the usage time is not less than the threshold.
2. The server according to claim 1, characterized in that The usage information further includes information indicating the usage frequency of functions of the vehicle, The control unit sends update data for software related to a first function to the vehicle earlier than update data for software related to a second function according to the usage information, the first function having a higher usage frequency than the second function.
3. A software update device is mounted on a vehicle, characterized in that, Comprising: A control unit configured to obtain or generate usage information indicating the usage status of the vehicle; A communication unit configured to send the usage information to the server and receive, at a communication speed based on the usage information of communication between the vehicle and the server, update data for software update of on-vehicle devices of the vehicle from the server, where The control unit is configured to control the communication speed in such a manner that, when the usage information indicates that the usage time is less than a threshold, the communication speed for the vehicle is made faster than in the case where the usage time is not less than the threshold.
4. A vehicle, characterized in that, Comprising the software update device according to claim 3.
5. A software update system, characterized in that, Comprising: A software update device configured to send usage information indicating the usage status of a vehicle; A server configured to receive the usage information from the software update device and control a communication speed of communication between the vehicle and the server, in which the server sends update data for software update of on-vehicle devices of the vehicle, according to the usage information, where The server is configured to control the communication speed in such a manner that, when the usage information indicates that the usage time is less than a threshold, the communication speed for the vehicle is made faster than in the case where the usage time is not less than the threshold, And send the update data to the software update device.
6. A control method executed by a computer of a server, the server being configured to send update data for software of on-vehicle devices of a vehicle to the vehicle, the control method being characterized by comprising: A step of receiving usage information indicating the usage status of the vehicle; A step of controlling a communication speed of communication between the vehicle and the server that sends the update data to the vehicle according to the usage information, wherein, The control includes judging whether the usage time is less than a threshold according to the usage information; A step of controlling the communication speed in such a manner that, when it is determined that the usage information indicates that the usage time is less than the threshold, the communication speed for the vehicle becomes faster than in the case where it is indicated that the usage time is not less than the threshold.
7. A non-transitory storage medium storing a control program executable by a computer of a server and causing the computer to execute the control method according to claim 6, the server being configured to send update data for updating software of an in-vehicle device for the vehicle.
Citation Information
Patent Citations
Program update system for vehicle
JP2011148398A
Automated Software Update Scheduling
US20150169311A1