Vehicle-mounted device, software update method, non-transitory storage medium, vehicle, electronic control unit
By setting storage and control components in the on-board equipment, efficient copying and activation of the vehicle's inherent set values and learning values during the software update process is achieved, the problem of inefficiency in the prior art is solved, and the efficiency of software update is improved.
Patent Information
- Application Number
- CN202111074994.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-09-17
- Filing Date
- 2021-09-14
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-09-14
AI Technical Summary
During the software update process of on-board equipment, the prior art requires special tools to independently copy the vehicle's inherent set values and learning values from one storage area to another, resulting in inefficiency in operation.
By setting a storage unit and a control unit in the vehicle-mounted device, the update software is written to a second area different from the software to be executed, and the vehicle's inherent set values and learning values are stored in this area, and efficient copying and activation is performed using communication and control components in the vehicle-mounted network.
Efficiently inherit the vehicle's inherent set values and learning values without additional work, improving the efficiency of software updates.
Smart Images

Figure CN114201187B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a vehicle-mounted device, a software update method, a non-transitory storage medium, a vehicle, and an electronic control unit. Background Art
[0002] A network system is mounted on a vehicle, in which a plurality of in-vehicle devices called ECUs (Electronic Control Unit) are interconnected via a communication line. Each in-vehicle device transmits and receives messages to and from each other and shares the execution of each function of the vehicle.
[0003] Generally, an in-vehicle device includes a processor, a temporary storage unit such as a RAM, and a non-volatile storage unit such as a flash ROM. Software (program) executed by the processor is stored in the non-volatile storage unit. By updating the software by overwriting it with a newer version, improvement and enhancement of the functions of the in-vehicle device can be achieved.
[0004] In the software update, there are a download step of receiving update data from a server (center) via wireless communication or the like, and an installation step of writing the updated software into the storage unit of the in-vehicle device according to the downloaded update data. Regarding the installation, depending on the specifications of the in-vehicle device, there are an overwrite installation in which the downloaded updated software is written in an area (one side) of the storage area determined as the software storage area in a manner of overwriting the software (old software) to be executed at the installation time, and an other-side installation in which it is written in an area (the other side) of two areas (both sides) determined as the software storage area, which is an area (one side) where the software (old software) to be executed at the installation time is not stored. The two areas determined as the software storage areas can be, for example, areas included in different libraries (structural units) of the same memory component, or corresponding areas of different memory components such as a memory component of a standard device and a memory component of an extended device.
[0005] In the case of other-side installation, in addition to the download and installation steps, there is an activation step of validating the installed updated software as the software to be executed.
[0006] Regarding the software update of the ECU, the content disclosed in Japanese Unexamined Patent Application Publication No. 2011-148398 is that a specific ECU functions as a host ECU, communicates with a server, and updates the software of the host ECU itself and other ECUs. Summary of the Invention
[0007] In-vehicle devices typically execute software using set values and learned values inherent in the vehicle. Such values are usually stored in an area (referred to as the first area) where the software to be executed is stored. When implementing software updates by mounting on the other side as described above, in order to inherit the use of such values, independently of the process of writing the updated software to a second area different from the first area, it is also necessary to implement the process of reading such values from the first area and writing them to the second area. This process requires, for example, operations using a dedicated tool, resulting in reduced operation efficiency.
[0008] The present invention provides an in-vehicle device, a software update method, a non-transitory storage medium, a vehicle, and an electronic control unit that can efficiently inherit set values and learned values inherent in a vehicle during software updates of the in-vehicle device.
[0009] The in-vehicle device according to the first aspect of the present invention is included in an in-vehicle network. The in-vehicle device has: a storage unit that stores software and one or more values for executing the software; and a control unit configured to store updated software generated based on update data obtained from a server outside the vehicle in a second area different from a first area in the storage unit that stores the software and the one or more values as an execution object program, and after storing the one or more values stored in the first area as one or more values for executing the updated software in the second area, change the execution object program from the software to the updated software.
[0010] The software update method according to the second aspect of the present invention is executed by a computer of an in-vehicle device, and the in-vehicle device is included in an in-vehicle network and has a storage unit that stores software and one or more values for executing the software.
[0011] The non-transitory storage medium according to the third aspect of the present invention stores a software update program that can be executed in a computer of an in-vehicle device and causes the computer to execute the software update method according to the second aspect. The in-vehicle device is included in an in-vehicle network and has a storage unit that stores software and one or more values for executing the software.
[0012] The vehicle according to the fourth aspect of the present invention has the in-vehicle device according to the first aspect.
[0013] The electronic control unit according to the fifth aspect of the present invention is included in a vehicle network. The electronic control unit has: a memory that stores software and one or more values for executing the software; a microcontroller configured to install updated software in a second area different from a first area in the memory that stores the software to be executed and the one or more values, based on update data obtained from a center, and to activate the updated software after storing the one or more values stored in the first area as one or more values for executing the updated software in the second area.
[0014] The software update method according to the sixth aspect of the present invention is executed by a microcontroller of an electronic control unit included in a vehicle network and having a memory that stores software and one or more values for executing the software. The software update method has: a step of installing updated software in a second area different from a first area in the memory that stores the software to be executed and the one or more values, based on update data obtained from a center; a step of storing the one or more values stored in the first area as one or more values for executing the updated software in the second area; and a step of activating the updated software.
[0015] The non-transitory storage medium according to the seventh aspect of the present invention stores a software update program that can be executed in a microcontroller of an electronic control unit included in a vehicle network and having a memory that stores software and one or more values for executing the software, and causes the microcontroller to execute the software update method according to the sixth aspect.
[0016] According to the technology of the present invention, when software is updated in a vehicle device, since the vehicle-specific setting values and learning values are copied, these values can be efficiently inherited without additional writing operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Hereinafter, with reference to the drawings, the features, advantages, and technical and industrial significance of the exemplary embodiments of the present invention will be described. In the drawings, the same reference numerals denote the same elements.
[0018] Figure 1 It is a structural diagram of a network system according to an embodiment.
[0019] Figure 2 It is a structural diagram of a vehicle device according to an embodiment.
[0020] Figure 3 It shows a timing diagram of a process according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] <Structure> Figure 1 This shows an example of the structure of the network system 1 of this embodiment. The network system 1 is mounted on a vehicle. The network system 1 includes a software update device 50. In the software update device (OTA (Over-The-Air) host) 50, multiple buses 10, 20, 30... are connected. Multiple in-vehicle devices (electronic control units) 11, 12... are connected to the bus 10. Multiple in-vehicle devices 21, 22... are connected to the bus 20. Multiple actuators 31, 32... are connected to the bus 30. In Figure 1 In the following description, as buses, buses 10, 20, 30 are exemplified, as in-vehicle devices, in-vehicle devices 11, 12, 21, 22 are exemplified, and actuators 31, 32 are exemplified, but the number of them is not limited. In addition, various sensors for obtaining the state of the vehicle and its surroundings are appropriately connected to the buses 10, 20, 30 or the in-vehicle devices 11, 12, 21, 22.
[0022] The software update device 50 includes a communication unit (communication module) 51 capable of communicating with a server (center, external device) 100 provided outside the vehicle, a storage unit (memory) 52 for storing various data, and a control unit 53.
[0023] Each in-vehicle device 11, 12, 21, 22 communicates with each other via a network and performs various processes for controlling the vehicle. Figure 2 This shows an example of the structure of the in-vehicle device 11. The in-vehicle device 11 includes a non-volatile storage unit (memory) 112 such as a flash ROM, a control unit (one or more processors, one or more microcontrollers) 113 that performs various processes by reading and executing software from the storage unit 112, and a communication unit 111 that communicates with other in-vehicle devices and the software update device 50. In addition, although not shown in the figure, it includes a temporary storage unit such as a RAM that stores a part of the software and data. The in-vehicle devices 12, 21, 22 are also configured in the same way. In addition, the software update device 50 also stores software (program) for the software update device 50 in the storage unit 52 in the same way, and by reading and executing the software by the control unit 53 (one or more processors, one or more microcontrollers), the functions of the software update device 50 can be executed. That is, each in-vehicle device 11, 12, 21, 22 and the software update device 50 can be implemented as a computer including a processor or a microcontroller, etc.
[0024] The control unit 53 of the software update device 50 controls and relays communication between the server 100 and each in-vehicle device 11, 12, 21, 22, communication between the in-vehicle devices 11, 12, 21, 22, and communication between each in-vehicle device 11, 12, 21, 22 and each actuator 31, 32 via the respective buses 10, 20, 30. In this way, the software update device 50 also functions as a relay device for relaying communication. Alternatively, the software update device 50 may be provided as part of such a relay device, or may be provided independently of such a relay device and connected to one of the buses 10, 20, 30.
[0025] The actuators 31, 32 are in-vehicle devices that exert a mechanical action on the vehicle or a part thereof, such as a brake, an engine, or a power steering device, and operate according to instructions from the in-vehicle devices 11, 12, 21, 22. The actuators 31, 32 may also include a computer composed of a processor, a microcontroller, a memory, etc.
[0026] The control unit 53 of the software update device 50 can update the software stored in the storage units of the in-vehicle devices 11, 12, 21, 22 respectively. That is, the software update device 50 performs download control, installation control, or further activation control. Regarding download, it is a process of receiving and storing update data (distribution package) for updating the software of any one of the in-vehicle devices 11, 12, 21, 22 sent from the server 100. The control of download not only includes the execution of download, but also can include the control of a series of processes related to download, such as the judgment of whether download can be executed and the verification of update data. Regarding installation, it is a process of writing the updated version of the software (updated software) into the second storage unit of the in-vehicle device to be updated as the software update object according to the downloaded update data. The control of installation not only includes the execution of installation, but also can include the control of a series of processes related to installation, such as the judgment of whether installation can be executed, the transmission of update data, and the verification of the updated version of the software. Regarding activation, it is a process of, for example, configuring the set value of the execution head address of the software to validate the installed updated version of the software as the software to be executed. The control of activation can not only include the execution of activation, but also can include a series of controls related to activation, such as the judgment of whether activation can be executed and the verification of the execution result.
[0027] In the installation control, when the update data includes the update software itself, the control unit 53 can send the update software to the in-vehicle device. Further, when the update data includes compressed data, differential data, or split data of the update software, the control unit 53 can perform decompression or assembly of the update data to generate the update software and send it to the in-vehicle device. Alternatively, the control unit 53 may send the update data to the in-vehicle device, and the in-vehicle device performs decompression or assembly of the update data to generate the update software.
[0028] Regarding the execution of the installation itself of writing the update software into the second storage unit of the in-vehicle device, it can be performed by the control unit 53, or can be implemented by the in-vehicle device that has received an instruction from the control unit 53. The in-vehicle device that has received the update data (or update software) may also autonomously perform the installation without an explicit instruction from the control unit 53.
[0029] Regarding the execution of the activation itself of validating the installed update software, it can be implemented by the control unit 53, or can be implemented by the in-vehicle device that has received an instruction from the control unit 53. The in-vehicle device may also autonomously perform the activation after installation without an explicit instruction from the control unit 53.
[0030] Further, such software update processing can be continuously or parallelly performed for each of multiple in-vehicle devices. Further, the update data is data for generating the update software, and its content and form are not limited. As described above, for example, it includes the update software itself, differential data for generating the update software, or compressed data or split data thereof. Further, the update data may also include an identifier (ECUID) of the in-vehicle device (target electronic control unit) to be software updated and an identifier (ECU Software ID) of the version of the software before the update.
[0031] As an example, the server 100 is a server or other computer device such as a server installed in a specific center, etc., and can send respective update data for updating the software of the in-vehicle devices of each of multiple vehicles. The server 100 includes a communication unit (communication module) 101 that communicates with the software update device 50 and a control unit 102 that controls the communication unit 101. The functions of the control unit 102 are executed by a processor or a microcontroller, etc. Further, the server 100 has a storage unit (not shown) and can receive and store data for updating the software of each of multiple in-vehicle devices from the outside.
[0032] <Process> Hereinafter, an example of the software update process of the present embodiment will be described. In Figure 3 A timing chart showing an example of this process is shown. This process starts, for example, in a state where the vehicle power is turned on (ignition switch is turned on, power is turned on).
[0033] (Step S101) The control unit 53 of the software update device 50 controls the communication unit 51 to inquire of the server 100 about the availability of updated software.
[0034] (Step S102) When the communication unit 101 of the server 100 receives the inquiry, the control unit 102 controls the communication unit 101 to send an update notification to the software update device 50 if updated software exists. For example, the control unit 102 can determine the availability of updated software for these in-vehicle devices based on information indicating the types of multiple in-vehicle devices included in the network system 1 and the current software versions. Such information can be pre-stored in the server 100 or received from the software update device 50 together with the inquiry. In addition, when no updated software exists, the control unit 102 controls the communication unit 101 to send a no-update notification to the software update device 50.
[0035] (Step S103) When the communication unit 51 of the software update device 50 receives the update notification, the control unit 53 controls the communication unit 51 to request update data from the server 100.
[0036] (Step S104) When the communication unit 101 of the server 100 receives the update data request, the control unit 102 of the server 100 generates update data to be sent to the vehicle based on the updated software provided to the server 100. The update data includes data for updating the software of one or more in-vehicle devices (target electronic control units) that are the update targets of the software.
[0037] (Step S105) The control unit 102 of the server 100 controls the communication unit 101 to send the update data.
[0038] (Step S106) The communication unit 51 of the software update device 50 receives the update data, and the control unit 53 causes the storage unit 52 to store the update data (download).
[0039] (Step S107) The control unit 53 of the software update device 50 starts the process of installation or installation and activation. Here, as an example, the in-vehicle device 11 is included in the in-vehicle devices that are the update targets of the software, and the control unit 53 sends the data for updating the software of the in-vehicle device 11 included in the update data received from the server 100 to the in-vehicle device 11. In addition, the in-vehicle device 11 is the above-mentioned on-the-other-side installation type of in-vehicle device.
[0040] (Step S108) When the communication unit 111 of the in-vehicle device 11 receives data, the control unit 113 of the in-vehicle device 11 performs the above-mentioned other-side installation according to the received data. That is, the control unit 113 of the in-vehicle device 11 writes the updated software in a second area different from the first area in the storage unit 112 where the software of the current execution object is stored. As described above, this process can be performed mainly by either the control unit 113 of the in-vehicle device 11 or the control unit 53 of the software update device 50. In addition, the first area and the second area can be different libraries of the same memory component, or areas of different memory components.
[0041] (Step S109) The control unit 113 of the in-vehicle device 11 reads the values such as the vehicle-specific setting values and learning values stored at the specified positions in the first area of the storage unit 112, and writes them to the specified positions in the second area. That is, the setting values, etc. are copied from the first area to the second area. The setting values and learning values are values that are set or learned through the characteristics of the vehicle, user operations, etc., and are vehicle-specific values that can vary according to the vehicle model and user preferences. For example, they are values indicating the designation of the driving mode (sport, eco, etc.), the set temperature of the air conditioner, etc. The change of the setting values and learning values can be implemented, for example, by the in-vehicle device 11 executing software, or by another in-vehicle device requesting the in-vehicle device 11. Through the processing of this step, even after the software is updated, the setting values and learning values can continue to be used for control.
[0042] (Step S110) The control unit 113 of the in-vehicle device 11 performs the above-mentioned activation. That is, the control unit 113 of the in-vehicle device 11 switches the software of the execution object from the pre-update software stored in the first area to the updated software stored in the second area, and validates the updated software. The order is as described above.
[0043] The above example is an example of the case where the update data received from the server 100 includes data for updating the software of the in-vehicle device 11, but the software update of other in-vehicle devices can be implemented in the same way. In addition, the number of in-vehicle devices to be updated is not limited, and the software update of two or more in-vehicle devices can also be implemented. In addition, regarding the data sent from the software update device 50 to the in-vehicle device in step S107, as described above, it can actually be the updated software itself, its compressed data, or the differential data from the pre-update software, etc.
[0044] When the power supply of the vehicle is in the power-on state (ignition switch on, accessory conduction, etc.) (any state other than the off state), in-vehicle device 11 and other in-vehicle devices may operate, and the set values and learned values stored in the first area may change. For example, when the power supply changes from a state other than off to the off state, most in-vehicle devices stop operating, so the changes in the set values and learned values are small, and these values can be stably copied to the second area. Therefore, the process of step S109 described above may also be implemented after the vehicle's power supply is changed to the off state.
[0045] In addition, among the data downloaded in step S106 and received by in-vehicle device 11 in step S108, at least part of the data may include set values and learned values. In this case, the control unit 113 of in-vehicle device 11 may also write the set and learned values included in the data to the second area in step S108. In addition, in this case, in step S109, the control unit 113 of in-vehicle device 11 does not copy the set and learned values that have already been written to the second area from the first area. In this way, the set values and learned values can be reset as needed, and the set values and learned values included in the downloaded update data can be used as initial values to execute the updated software.
[0046] <Effect> In this embodiment, when the in-vehicle device performs software update, since the inherent set values and learned values of the vehicle are copied, the inheritance of these values can be efficiently implemented without the need for additional operations such as writing.
[0047] The technology of the present invention can be understood as an in-vehicle device, a network system including the in-vehicle device, a method executed by a computer included in the in-vehicle device, a program, a non-transitory computer-readable storage medium storing the program, a vehicle having the in-vehicle device, and the like.
[0048] The technology of the present invention is beneficial to a network system mounted on a vehicle or the like.
Claims
1. A vehicle-mounted device, which is included in a vehicle-mounted network, characterized in that, comprising: a storage unit that stores software and one or more values that are vehicle - specific set values or learned values for executing the software; a control unit configured to store, in a second area different from a first area in the storage unit that stores the software of the program to be executed and the one or more values, updated software generated based on update data obtained from an external server, and after storing the one or more values stored in the first area as one or more values for executing the updated software in the second area, change the program to be executed from the software to the updated software.
2. The in - vehicle device according to claim 1, wherein: the control unit is configured to perform a process of storing the one or more values stored in the first area in the second area when the power of the vehicle is in an off state.
3. The in - vehicle device according to claim 1 or 2, wherein: the control unit is configured to, when the update data includes at least a part of the one or more values for executing the updated software, store the values included in the update data in the second area in place of the values stored in the first area.
4. A software update method, executed by a computer of an in - vehicle device, the in - vehicle device being included in an in - vehicle network and having a storage unit that stores software and one or more values that are vehicle - specific set values or learned values for executing the software, the software update method being characterized by comprising: a step of storing, in a second area different from a first area in the storage unit that stores the software of the program to be executed and the one or more values, updated software generated based on update data obtained from an external server; a step of, after storing the one or more values stored in the first area as one or more values for executing the updated software in the second area, changing the program to be executed from the software to the updated software.
5. A non - transitory storage medium that stores a software update program, the software update program being executable in a computer of an in - vehicle device and causing the computer to execute the software update method according to claim 4, the in - vehicle device being included in an in - vehicle network and having a storage unit that stores software and one or more values that are vehicle - specific set values or learned values for executing the software.
6. A vehicle having the in - vehicle device according to any one of claims 1 to 3.
7. An electronic control unit is included in a vehicle network, characterized in that, comprising: a memory that stores software and one or more values that are vehicle - specific set values or learned values for executing the software; A microcontroller configured to install updated software in a second area in the memory different from a first area storing software to be executed and the one or more values, according to updated data obtained from a center, and to activate the updated software after storing the one or more values stored in the first area as the one or more values for executing the updated software in the second area.
8. The electronic control unit according to claim 7, characterized in that By activating the updated software, the updated software becomes the software to be executed.
9. A software update method executed by a microcontroller of an electronic control unit, the electronic control unit being included in a vehicle network and having a memory for storing software and one or more values for executing the software, which are set values or learned values inherent to the vehicle, the software update method being characterized by comprising: A step of installing updated software in a second area in the memory different from a first area storing software to be executed and the one or more values, according to updated data obtained from a center; A step of storing the one or more values stored in the first area as the one or more values for executing the updated software in the second area; A step of activating the updated software.
10. A non-transitory storage medium storing a software update program that can be executed in a microcontroller of an electronic control unit, and causes the microcontroller to execute the software update method according to claim 9, the electronic control unit being included in a vehicle network and having a memory for storing software and one or more values for executing the software, which are set values or learned values inherent to the vehicle.
Citation Information
Patent Citations
Program update system for vehicle
JP2011148398A
Pre-shutdown swap verification
CN108268264A