Main device for vehicle, vehicle electronic control system, method for instructing rewriting of configuration information, and recording medium recording program for instructing rewriting of configuration information

By overriding the configuration information in the vehicle main device, the problem of non-volatile memory structure changes when rewriting the ECU program is solved, and the configuration information can be used appropriately after rewriting the program is achieved.

CN114698390BActive Publication Date: 2025-06-10DENSO CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080073741.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-08-28
Filing Date
2020-08-05
Publication Date
2025-06-10
Estimated Expiration
2040-08-05

AI Technical Summary

Technical Problem

When rewriting the program of the electronic control device (ECU), the configuration change of the nonvolatile memory results in the inability to properly use the stored configuration information.

Method used

The update data is received from the central device by the vehicle master device and instructs the ECU to rewrite the object to write. At the same time, the configuration information overwrite instructions ensure the overwrite of the new configuration information after the program is overwritten.

Benefits of technology

Even when the nonvolatile memory structure is changed during program rewriting, configuration information can be used appropriately after the application rewriting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114698390B_ABST
    Figure CN114698390B_ABST
Patent Text Reader

Abstract

The present invention provides a main device (11) for a vehicle. If it is determined based on a notification from a central device (3) that there is an activity notification related to program update, the rewritten specification data, reprogrammed data, and new configuration information are downloaded from the central device. Based on the above rewritten specification data, it is determined whether it is a rewrite of the application program or a rewrite of the configuration information. If it is determined that it is a rewrite of the application program, the electronic control device (19) to be rewritten is instructed to rewrite the application program. If it is determined that it is a rewrite of the configuration information, the electronic control device (19) to be rewritten is instructed to rewrite the configuration information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - reference to related applications

[0002] This application claims priority to Japanese Application No. 2019 - 155686, filed on August 28, 2019, the entire contents of which are hereby incorporated by reference. Technical field

[0003] The present disclosure relates to an in - vehicle electronic control system, an in - vehicle main device, a method for instructing rewriting of a coverage based on configuration information, and a program for instructing rewriting of a coverage based on configuration information. Background art

[0004] In recent years, along with the diversification of vehicle control such as driving assistance functions and autonomous driving functions, the scale of programs for vehicle control, diagnosis, etc. of electronic control devices (hereinafter referred to as ECUs (Electronic Control Unit)) mounted on vehicles has been increasing. In addition, along with version upgrades based on function improvements, etc., the opportunity to rewrite (re - program) the programs of ECUs has also been increasing. On the other hand, along with the development of communication networks, etc., the technology of connected cars has become increasingly popular. In light of such circumstances, for example, Patent Document 1 proposes the following technology: An in - vehicle main device as a relay device is provided on the vehicle side, and the in - vehicle main device distributes update data received wirelessly from a central device to an ECU to be rewritten, thereby rewriting the program of the ECU to be rewritten by OTA (Over The Air).

[0005] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2016 - 224898

[0006] In an ECU to be rewritten, if the structure of the non - volatile memory is changed when writing update data to rewrite the program, there is a concern that configuration information such as learned values stored in the non - volatile memory may not be used properly. In view of such a situation, a structure that can properly use the configuration information even when the structure of the non - volatile memory is changed when rewriting the program of the ECU to be rewritten is preferable. Summary of the invention

[0007] An object of the present disclosure is to be able to properly use configuration information after rewriting a program even when the structure of the non - volatile memory is changed when rewriting the program in an electronic control device to be rewritten.

[0008] According to one aspect of the present disclosure, a vehicle main device distributes update data received from a central device to an electronic control device to be rewritten, and instructs the electronic control device to be rewritten to write the update data. If the electronic control device receives the update data from the vehicle main device, the electronic control device uses the received update data to rewrite the program in the non-volatile memory. The electronic control device stores configuration information in the non-volatile memory. In the vehicle main device, during or after the program is rewritten in the electronic control device to be rewritten, the configuration information overwrite instruction unit instructs the electronic control device to be rewritten to overwrite the new configuration information.

[0009] During or after the program is rewritten in the electronic control device to be rewritten, the electronic control device to be rewritten is instructed to overwrite the new configuration information. By instructing the electronic control device to be rewritten to overwrite the new configuration information during or after the program is rewritten in the electronic control device to be rewritten, it is possible to rewrite from the old configuration information to the new configuration information in the electronic control device to be rewritten. Even when the structure of the non-volatile memory is changed when the program is rewritten in the electronic control device to be rewritten, the configuration information can be appropriately used after the application program is rewritten. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The above and other objects, features, and advantages of the present disclosure will become more apparent by referring to the accompanying drawings and the following detailed description. The accompanying drawings are as follows:

[0011] Figure 1 It is a diagram showing the overall configuration of one embodiment.

[0012] Figure 2 It is a diagram showing the electrical structure of the CGW.

[0013] Figure 3 It is a diagram showing the electrical structure of the DCM.

[0014] Figure 4 It is a diagram showing the electrical structure of the ECU.

[0015] Figure 5 It is a diagram showing the connection method of the power line.

[0016] Figure 6 It is a diagram showing the method of packing the recompiled data and the distribution specification data.

[0017] Figure 7 It is a diagram showing the rewrite specification data for the DCM.

[0018] Figure 8 It is a diagram showing the rewrite specification data for the CGW.

[0019] Figure 9It is a diagram showing the distribution specification data.

[0020] Figure 10 It is a diagram showing the way to unpack the distribution data packet.

[0021] Figure 11 It is a diagram showing the way during normal operation in an embedded single-sided standalone memory.

[0022] Figure 12 It is a diagram showing the way during rewrite operation in an embedded single-sided standalone memory.

[0023] Figure 13 It is a diagram showing the way during normal operation in a download-type single-sided standalone memory.

[0024] Figure 14 It is a diagram showing the way during rewrite operation in a download-type single-sided standalone memory.

[0025] Figure 15 It is a diagram showing the way during normal operation in an embedded single-sided suspended memory.

[0026] Figure 16 It is a diagram showing the way during rewrite operation in an embedded single-sided suspended memory.

[0027] Figure 17 It is a diagram showing the way during normal operation in a download-type single-sided suspended memory.

[0028] Figure 18 It is a diagram showing the way during rewrite operation in a download-type single-sided suspended memory.

[0029] Figure 19 It is a diagram showing the way during normal operation in an embedded double-sided memory.

[0030] Figure 20 It is a diagram showing the way during rewrite operation in an embedded double-sided memory.

[0031] Figure 21 It is a diagram showing the way during normal operation in a download-type double-sided memory.

[0032] Figure 22 It is a diagram showing the way during rewrite operation in a download-type double-sided memory.

[0033] Figure 23 It is a diagram showing the way to rewrite the application program.

[0034] Figure 24 It is a diagram showing the way to rewrite the application program.

[0035] Figure 25It is a diagram showing the way to rewrite the application program.

[0036] Figure 26 It is a timing diagram showing the way to rewrite the application program through power control.

[0037] Figure 27 It is a timing diagram showing the way to rewrite the application program through power control.

[0038] Figure 28 It is a timing diagram showing the way to rewrite the application program through power self-holding.

[0039] Figure 29 It is a timing diagram showing the way to rewrite the application program through power self-holding.

[0040] Figure 30 It is a diagram showing the stage.

[0041] Figure 31 It is a diagram showing the normal screen.

[0042] Figure 32 It is a diagram showing the screen when the activity notification is generated.

[0043] Figure 33 It is a diagram showing the screen during the activity notification.

[0044] Figure 34 It is a diagram showing the screen when the download consent is given.

[0045] Figure 35 It is a diagram showing the screen when the download consent is given.

[0046] Figure 36 It is a diagram showing the screen during the download execution.

[0047] Figure 37 It is a diagram showing the screen during the download execution.

[0048] Figure 38 It is a diagram showing the screen when the download is completed.

[0049] Figure 39 It is a diagram showing the screen when the installation consent is given.

[0050] Figure 40 It is a diagram showing the screen when the installation consent is given.

[0051] Figure 41 It is a diagram showing the screen during the installation execution.

[0052] Figure 42 It is a diagram showing the screen during the installation execution.

[0053] Figure 43 It is a diagram showing the screen when the activation consent is given.

[0054] Figure 44 It is a diagram showing the screen when the IG is turned on.

[0055] Figure 45 It is a diagram showing the screen during the confirmation operation.

[0056] Figure 46 It is a diagram showing the screen during the confirmation operation.

[0057] Figure 47 It is a functional block diagram of the central unit.

[0058] Figure 48 It is a functional block diagram of the DCM.

[0059] Figure 49 It is a functional block diagram of the CGW.

[0060] Figure 50 It is a functional block diagram of the CGW.

[0061] Figure 51 It is a functional block diagram of the ECU.

[0062] Figure 52 It is a functional block diagram of the in-vehicle display.

[0063] Figure 53 It is a functional block diagram of the transmission determination unit for distributing data packets.

[0064] Figure 54 It is a flowchart showing the transmission determination process for distributing data packets.

[0065] Figure 55 It is a functional block diagram of the download determination unit for distributing data packets.

[0066] Figure 56 It is a flowchart showing the download determination process for distributing data packets.

[0067] Figure 57 It is a functional block diagram of the transmission determination unit for writing data.

[0068] Figure 58 It is a flowchart showing the transmission determination process for writing data.

[0069] Figure 59 It is a functional block diagram of the acquisition determination unit for writing data.

[0070] Figure 60 It is a flowchart showing the acquisition determination process for writing data.

[0071] Figure 61 It is a functional block diagram of the installation instruction determination unit.

[0072] Figure 62 It is a flowchart showing the instruction determination process for installation.

[0073] Figure 63 It is a diagram showing the method of instructing installation.

[0074] Figure 64 It is a diagram showing the method of instructing installation.

[0075] Figure 65 It is a diagram showing the method of generating a random value.

[0076] Figure 66 It is a functional block diagram of the management unit for the secure access key.

[0077] Figure 67 It is a flowchart showing the generation process of the secure access key.

[0078] Figure 68 It is a diagram showing the method of generating the secure access key.

[0079] Figure 69 It is a flowchart showing the elimination process of the secure access key.

[0080] Figure 70 It is a diagram showing the process flow related to the verification of the written data.

[0081] Figure 71 It is a functional block diagram of the verification unit for the written data.

[0082] Figure 72 It is a flowchart showing the verification process of the written data.

[0083] Figure 73 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0084] Figure 74 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0085] Figure 75 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0086] Figure 76 It is a diagram showing the method of dispersing the process related to the verification of the written data.

[0087] Figure 77 It is a diagram showing the process flow of the verification of the written data and the rewriting of the application program.

[0088] Figure 78 It is a diagram showing the process flow of the verification of the written data and the rewriting of the application program.

[0089] Figure 79 It is a functional block diagram of a transmission control unit for data storage surface information.

[0090] Figure 80 It is a flowchart showing the transmission control process of data storage surface information.

[0091] Figure 81 It is a sequence diagram showing the method of notifying double-sided rewrite information.

[0092] Figure 82 It is a functional block diagram of a power management unit that is not an object to be rewritten.

[0093] Figure 83 It is a flowchart showing the power management process of an object not to be rewritten.

[0094] Figure 84 It is a diagram showing the transition of the start state, stop state, and sleep state.

[0095] Figure 85 It is a diagram showing the transition of the start state, stop state, and sleep state.

[0096] Figure 86 It is a diagram showing the connection method of the power cord.

[0097] Figure 87 It is a flowchart showing the monitoring process of the battery remaining amount.

[0098] Figure 88 It is a functional block diagram of a file transfer control unit.

[0099] Figure 89 It is a flowchart showing the file transfer control process.

[0100] Figure 90 It is a diagram showing the method of exchanging files.

[0101] Figure 91 It is a diagram showing the method of exchanging files.

[0102] Figure 92 It is a diagram showing file splitting and file writing.

[0103] Figure 93 It is a diagram showing the method by which CGW sends a transfer request to DCM.

[0104] Figure 94 It is a diagram showing the method by which CGW sends a transfer request to DCM.

[0105] Figure 95 It is a diagram showing the method by which CGW distributes write data to a rewrite target ECU.

[0106] Figure 96It is a diagram showing the way in which the CGW distributes the write data to the ECU to be rewritten.

[0107] Figure 97 It is a diagram showing the way in which the CGW distributes the write data to the ECU to be rewritten.

[0108] Figure 98 It is a diagram showing the connection method of the ECU.

[0109] Figure 99 It is a functional block diagram of the distribution control unit for the write data.

[0110] Figure 100 It is a diagram showing the bus load table.

[0111] Figure 101 It is a diagram showing the table to which the ECU to be rewritten belongs.

[0112] Figure 102 It is a flowchart showing the distribution control process of the write data.

[0113] Figure 103 It is a diagram showing the way of distributing the write data.

[0114] Figure 104 It is a diagram showing the way of distributing the write data.

[0115] Figure 105 It is a diagram showing the way of distributing the write data during vehicle driving.

[0116] Figure 106 It is a diagram showing the way of distributing the write data during parking.

[0117] Figure 107 It is a diagram showing the distribution amount of the write data.

[0118] Figure 108 It is a diagram showing the distribution amount of the write data.

[0119] Figure 109 It is a functional block diagram of the instruction unit for the activation request.

[0120] Figure 110 It is a flowchart showing the instruction process for the activation request.

[0121] Figure 111 It is a diagram showing the way of instructing the activation request.

[0122] Figure 112 It is a functional block diagram of the execution control unit for the activation.

[0123] Figure 113 It is a flowchart showing the rewriting process.

[0124] Figure 114 It is a flowchart showing the activation execution control process.

[0125] Figure 115 It is a functional block diagram of the grouping section of the object to be rewritten.

[0126] Figure 116 It is a flowchart showing the group management process of the object to be rewritten.

[0127] Figure 117 It is a flowchart showing the group management process of the object to be rewritten.

[0128] Figure 118 It is a diagram showing the method of grouping the object to be rewritten.

[0129] Figure 119 It is a functional block diagram of the execution control section for rollback.

[0130] Figure 120 It is a flowchart showing the determination process of the rollback method.

[0131] Figure 121 It is a flowchart showing the determination process of the cancellation request.

[0132] Figure 122 It is a flowchart showing the determination process of the cancellation request.

[0133] Figure 123 It is a flowchart showing the determination process of the cancellation request.

[0134] Figure 124 It is a flowchart showing the determination process of the cancellation request.

[0135] Figure 125 It is a flowchart showing the determination process of the cancellation request.

[0136] Figure 126 It is a diagram showing the method of performing rollback.

[0137] Figure 127 It is a diagram showing the method of performing rollback.

[0138] Figure 128 It is a diagram showing the method of performing rollback.

[0139] Figure 129 It is a diagram showing the method of performing rollback.

[0140] Figure 130 It is a diagram showing the method of performing rollback.

[0141] Figure 131 It is a functional block diagram of the display control section for the rewrite progress status.

[0142] Figure 132It is a flowchart of a display control process indicating the progress of rewriting.

[0143] Figure 133 It is a flowchart of a display control process indicating the progress of rewriting.

[0144] Figure 134 It is a diagram of a screen indicating the progress of rewriting.

[0145] Figure 135 It is a diagram of a screen indicating the progress of rewriting.

[0146] Figure 136 It is a diagram of a screen indicating the progress of rewriting.

[0147] Figure 137 It is a diagram of a screen indicating the progress of rewriting.

[0148] Figure 138 It is a diagram of a screen indicating the progress of rewriting.

[0149] Figure 139 It is a diagram showing the transition of progress chart display.

[0150] Figure 140 It is a diagram showing the transition of progress chart display.

[0151] Figure 141 It is a diagram showing the transition of progress chart display.

[0152] Figure 142 It is a diagram showing the transition of progress chart display.

[0153] Figure 143 It is a diagram of a screen indicating the progress of rewriting.

[0154] Figure 144 It is a functional block diagram of a differential data matching determination unit.

[0155] Figure 145 It is a flowchart of a differential data matching determination process.

[0156] Figure 146 It is a diagram showing the method of determining the matching of differential data.

[0157] Figure 147 It is a diagram showing the method of determining the matching of differential data.

[0158] Figure 148 It is a functional block diagram of an execution control unit for rewriting.

[0159] Figure 149 It is a flowchart of a normal operation process.

[0160] Figure 150It is a flowchart showing the rewrite operation process.

[0161] Figure 151 It is a flowchart showing the information notification process.

[0162] Figure 152 It is a flowchart showing the verification process of the rewrite program.

[0163] Figure 153 It is a diagram showing the method of sending identification information and writing data.

[0164] Figure 154 It is a diagram showing the method of sending identification information and writing data.

[0165] Figure 155 It is a flowchart showing the installation instruction process.

[0166] Figure 156 It is a functional block diagram of the session establishment unit.

[0167] Figure 157 It is a diagram showing the composition of the program.

[0168] Figure 158 It is a diagram showing the state transition.

[0169] Figure 159 It is a diagram showing the state transition.

[0170] Figure 160 It is a diagram showing the state transition.

[0171] Figure 161 It is a diagram showing the mediation of the session.

[0172] Figure 162 It is a diagram showing the mediation of the session.

[0173] Figure 163 It is a flowchart showing the state transition management process of the first state.

[0174] Figure 164 It is a flowchart showing the state transition management process of the first state.

[0175] Figure 165 It is a flowchart showing the state transition management process of the first state.

[0176] Figure 166 It is a flowchart showing the state transition management process of the second state.

[0177] Figure 167 It is a flowchart showing the state transition management process of the second state.

[0178] Figure 168 It is a diagram showing the composition of the program.

[0179] Figure 169 It is a diagram showing state transition.

[0180] Figure 170 It is a functional block diagram of the determination unit of the re - trial point.

[0181] Figure 171 It is a diagram showing the structure of the flash memory.

[0182] Figure 172 It is a flowchart showing the setting process of the processing flag.

[0183] Figure 173 It is a flowchart showing the determination process of the processing flag.

[0184] Figure 174 It is a flowchart showing the determination process of the processing flag.

[0185] Figure 175 It is a functional block diagram of the synchronization control unit of the progress status.

[0186] Figure 176 It is a functional block diagram of the synchronization control unit of the progress status.

[0187] Figure 177 It is a diagram showing the method of sending and receiving the progress status signal.

[0188] Figure 178 It is a flowchart showing the synchronization control process of the progress status.

[0189] Figure 179 It is a flowchart showing the synchronization control process of the progress status.

[0190] Figure 180 It is a flowchart showing the display process of the progress status.

[0191] Figure 181 It is a functional block diagram of the transmission control unit of the display control information.

[0192] Figure 182 It is a flowchart showing the transmission control process of the display control information.

[0193] Figure 183 It is a functional block diagram of the reception control unit of the display control information.

[0194] Figure 184 It is a flowchart showing the reception control process of the display control information.

[0195] Figure 185 It is a diagram showing the information included in the distribution specification data.

[0196] Figure 186It is a functional block diagram of a screen display control unit for progress display.

[0197] Figure 187 It is a diagram showing the rewritten specification data.

[0198] Figure 188 It is a diagram showing the screen at the time of menu selection.

[0199] Figure 189 It is a diagram showing the screen at the time of user selection.

[0200] Figure 190 It is a diagram showing the screen at the time of user registration.

[0201] Figure 191 It is a flowchart showing the screen display control process for progress display.

[0202] Figure 192 It is a flowchart showing the screen display control process for progress display.

[0203] Figure 193 It is a diagram showing the message frame.

[0204] Figure 194 It is a diagram showing the screen at the time of activation consent.

[0205] Figure 195 It is a diagram showing the setting of the display presence or absence of items.

[0206] Figure 196 It is a diagram showing the setting of the display presence or absence of items.

[0207] Figure 197 It is a diagram showing the screen at the time of activation consent.

[0208] Figure 198 It is a diagram showing the data communication method.

[0209] Figure 199 It is a diagram showing the message frame at the time of activity notification.

[0210] Figure 200 It is a diagram showing the message frame at the time of download consent.

[0211] Figure 201 It is a diagram showing the message frame at the time of installation consent.

[0212] Figure 202 It is a diagram showing the message frame at the time of activation consent.

[0213] Figure 203 It is a diagram showing the screen transition.

[0214] Figure 204 It is a diagram showing the screen at the time of activity notification generation.

[0215] Figure 205 It is a diagram showing the screen when download consent is given.

[0216] Figure 206 It is a diagram showing the screen when download consent is given.

[0217] Figure 207 It is a diagram showing the screen during download execution.

[0218] Figure 208 It is a diagram showing the screen when download is completed.

[0219] Figure 209 It is a diagram showing the screen when installation consent is given.

[0220] Figure 210 It is a diagram showing the screen when activation consent is given.

[0221] Figure 211 It is a functional block diagram of the report control section for program update.

[0222] Figure 212 It is a flowchart showing the report control process for program update.

[0223] Figure 213 It is a diagram showing the reporting method of the indicator.

[0224] Figure 214 It is a diagram showing the migration of the reporting method in the case where the rewrite object is a double-sided memory.

[0225] Figure 215 It is a diagram showing the migration of the reporting method in the case where the rewrite object is a single-sided suspended memory.

[0226] Figure 216 It is a diagram showing the migration of the reporting method in the case where the rewrite object is a single-sided separate memory.

[0227] Figure 217 It is a diagram showing the connection method.

[0228] Figure 218 It is a functional module of the execution control section for power self-holding in CGW.

[0229] Figure 219 It is a functional module of the execution control section for power self-holding in ECU.

[0230] Figure 220 It is a flowchart showing the execution control process for power self-holding in CGW.

[0231] Figure 221 It is a flowchart showing the execution control process for power self-holding in ECU.

[0232] Figure 222 It is a diagram showing the period during which power self - holding is required.

[0233] Figure 223 It is a functional block diagram of a rewrite instruction unit based on the overwrite of configuration information.

[0234] Figure 224 It is a flowchart showing the rewrite instruction process based on the overwrite of configuration information.

[0235] Figure 225 It is a diagram showing the way of mixing the rewrite of an application program and the overwrite of configuration information.

[0236] Figure 226 It is a diagram showing the way of mixing the rewrite of an application program and the overwrite of configuration information.

[0237] Figure 227 It is a diagram showing the way of sending and receiving configuration information.

[0238] Figure 228 It is a functional module of a rewrite instruction unit for write - back based on configuration information.

[0239] Figure 229 It is a flowchart showing the rewrite instruction process for write - back based on configuration information.

[0240] Figure 230 It is a flowchart showing the rewrite instruction process for write - back based on configuration information.

[0241] Figure 231 It is a flowchart showing the rewrite instruction process for write - back based on configuration information.

[0242] Figure 232 It is a diagram showing the way of mixing the rewrite of an application program and the write - back of configuration information.

[0243] Figure 233 It is a diagram showing the way of mixing the rewrite of an application program and the write - back of configuration information.

[0244] Figure 234 It is a diagram showing the way of mixing the rewrite of an application program and the write - back of configuration information.

[0245] Figure 235 It is a diagram showing the way of mixing the rewrite of an application program and the write - back of configuration information.

[0246] Figure 236 It is a diagram showing the way of mixing the rewrite of an application program and the write - back of configuration information.

[0247] Figure 237 It is a diagram showing the way of mixing the rewrite of an application program and the write - back of configuration information.

[0248] Figure 238 It is a diagram showing the way of sending and receiving configuration information.

[0249] Figure 239 It is a diagram showing the way of sending and receiving configuration information.

[0250] Figure 240 It is a diagram showing the structure of the flash memory.

[0251] Figure 241 It is a functional block diagram of the rewriting instruction unit based on a specific pattern.

[0252] Figure 242 It is a diagram showing the way of connecting to factory equipment.

[0253] Figure 243 It is a diagram showing the way of connecting to dealer equipment.

[0254] Figure 244 It is a flowchart showing the rewriting instruction process based on a specific pattern.

[0255] Figure 245 It is a flowchart showing the rewriting process based on a specific pattern.

[0256] Figure 246 It is a diagram showing the content of rewriting based on the factory mode and rewriting based on the dealer mode.

[0257] Figure 247 It is an overall sequence diagram showing the way of rewriting the application program.

[0258] Figure 248 It is an overall sequence diagram showing the way of rewriting the application program.

[0259] Figure 249 It is an overall sequence diagram showing the way of rewriting the application program.

[0260] Figure 250 It is an overall sequence diagram showing the way of rewriting the application program.

[0261] Figure 251 It is an overall sequence diagram showing the way of rewriting the application program.

[0262] Figure 252 It is an overall sequence diagram showing the way of rewriting the application program.

[0263] Figure 253 It is an overall sequence diagram showing the way of rewriting the application program.

[0264] Figure 254 It is an overall sequence diagram showing the way of rewriting the application program.

[0265] Figure 255 It is an overall sequence diagram showing the way of rewriting the application program.

[0266] Figure 256 It is an overall sequence diagram showing the way of rewriting the application program.

[0267] Figure 257 It is an overall sequence diagram showing the way of rewriting the application program.

[0268] Figure 258 It is a diagram showing the overall configuration of the vehicle information communication system in the first embodiment.

[0269] Figure 259 It is a diagram showing the electrical structure of the CGW.

[0270] Figure 260 It is a diagram showing the electrical structure of the ECU.

[0271] Figure 261 It is a diagram showing the connection method of the power line.

[0272] Figure 262 It is a diagram showing the way of packing the reprogramming data and the distribution specification data.

[0273] Figure 263 It is a diagram showing the way of unpacking the distribution data packet.

[0274] Figure 264 It is a diagram showing, in the form of a block diagram, the parts in the central device mainly related to the functions of the server.

[0275] Figure 265 It is an image diagram showing the processing flow in the central device.

[0276] Figure 266 It is a diagram showing an example of the structure information of the vehicle registered in the structure information DB.

[0277] Figure 267 It is a diagram showing an example of the programs and data registered in the ECU reprogramming data DB.

[0278] Figure 268 It is a diagram showing an example of the specification data registered in the ECU metadata DB.

[0279] Figure 269 It is a diagram showing an example of the structure information of the vehicle registered in the individual vehicle information DB.

[0280] Figure It is a diagram showing an example of the distribution data packet data registered in the data packet DB.

[0281] ​This is a diagram showing an example of the activity data registered in the activity DB.

[0282] ​ This is a flowchart showing the process of generating the programs and data registered in the ECU reprogramming data DB.

[0283] ​ This is a flowchart showing an example of the process of generating the specification data registered in the ECU metadata DB.

[0284] ​ This is a diagram showing an example of the specification data.

[0285] ​ This is a diagram showing an example of the bus load table.

[0286] ​ This is a flowchart showing the process of generating the distribution data packets registered in the data packet DB.

[0287] ​ This is a diagram showing the content of the data packet file in graphical form.

[0288] Figure 278 This is a sequence diagram showing the order of the process executed between the central device and the vehicle-side system in the second embodiment.

[0289] Figure 279 This is a flowchart showing the process performed by the central device.

[0290] Figure 280 This is in graphical form showing Figure 279 the processing content performed in steps D6 and D7 of the flowchart shown.

[0291] Figure 281 This is a flowchart showing the process when a hash value is sent from the vehicle-side system to the central device.

[0292] Figure 282 This is a sequence diagram showing the order of the process executed between the central device and the vehicle-side system in the third embodiment.

[0293] Figure 283 This is a flowchart showing the process performed by the central device.

[0294] Figure 284 This is a sequence diagram showing the status of the central device notifying the EV vehicle and the conventional vehicle respectively via SMS.

[0295] Figure 285 This is a sequence diagram showing the order of the process executed between the central device and the vehicle-side system in the fourth embodiment.

[0296] Figure 286 This is a diagram showing the processes carried out among the supplier, the central device, and the vehicle-side system in the fifth embodiment in graphical form.

[0297] Figure 287 This is a sequence diagram (part 1) showing the process flow carried out among the supplier, the central device, and the vehicle-side system.

[0298] Figure 288 This is a sequence diagram (part 2) showing the process flow carried out among the supplier, the central device, and the vehicle-side system.

[0299] Figure 289 This is a sequence diagram (part 3) showing the process flow carried out among the supplier, the central device, and the vehicle-side system.

[0300] Figure 290 This is a modification of the first embodiment (part 1), and is a diagram showing the data format of the packet DB in the case where multiple data packets correspond to one activity.

[0301] Figure 291 This is a diagram showing the data format of the activity DB in the case where multiple data packets correspond to one activity.

[0302] Figure 292 This is a diagram corresponding to Figure 273 in the case of generating specification data by group.

[0303] Figure 293 This is a diagram corresponding to Figure 276 in the case of generating and distributing data packets by group.

[0304] Figure 294 This is a modification of the first embodiment (part 2), and is a diagram showing the processing content of the data packet generation tool. Detailed Embodiment

[0305] Hereinafter, an embodiment will be described with reference to the drawings. The vehicle program rewriting system (equivalent to the vehicle electronic control system) is a system capable of rewriting application programs such as vehicle control and diagnosis installed in an electronic control unit (hereinafter referred to as ECU (Electronic Control Unit)) via OTA (Over The Air). In this embodiment, the case of rewriting the application program by wire or wireless is described, but it can also be applied, for example, to the case of rewriting map data used in a map application, control parameters used in an ECU, etc., and data used in various applications by wire or wireless.

[0306] In addition to obtaining and rewriting the application program via a wired connection from outside the vehicle, the rewriting of the application program via a wired connection also includes obtaining and rewriting various data used when executing the application program via a wired connection from outside the vehicle. In addition to obtaining and rewriting the application program via a wireless connection from outside the vehicle, the rewriting of the application program via a wireless connection also includes obtaining and rewriting various data used when executing the application program via a wireless connection from outside the vehicle.

[0307] As Figure 1 shown, the vehicle program rewriting system 1 includes a central device 3 on the communication network 2 side, a vehicle-side system 4 on the vehicle side, and a display terminal 5. The communication network 2 is composed of, for example, a mobile communication network using a 4G line or the like, the Internet, WiFi (Wireless Fidelity) (registered trademark), and the like. In addition, in the present embodiment, the configuration of the vehicle side will be mainly described, and the configuration of the central device 3 will be described in detail in Figures 234 to 270 this regard.

[0308] The display terminal 5 is a terminal having a function of accepting operation inputs from a user and a function of displaying various screens, and is, for example, a mobile terminal 6 such as a smartphone or a tablet that the user can carry, or an in-vehicle display 7 disposed inside the vehicle compartment. If the mobile terminal 6 is within the communication range of the mobile communication network, it can perform data communication with the central device 3 via the communication network 2. The in-vehicle display 7 is connected to the vehicle-side system 4 and may also be configured to have a navigation function. In addition, the in-vehicle display 7 may be an in-vehicle display ECU having the function of an ECU, or may have a function of controlling the display to a central display, an instrument display, or the like.

[0309] If the user is outside the vehicle compartment and within the communication range of the mobile communication network, the user can perform operation inputs while confirming various screens related to the rewriting of the application program through the mobile terminal 6, and perform procedures related to the rewriting of the application program. When the user is inside the vehicle compartment, the user can perform operation inputs while confirming various screens related to the rewriting of the application program through the in-vehicle display 7, and perform procedures related to the rewriting of the application program. That is, the user can separately use the mobile terminal 6 and the in-vehicle display 7 outside and inside the vehicle compartment to perform procedures related to the rewriting of the application program.

[0310] The central device 3 summarizes the program update function on the communication network 2 side in the vehicle program rewriting system 1 and functions as an OTA center. The central device 3 includes a file server 8, a web server 9, and a management server 10, and each of the servers 8 to 10 is configured to be able to perform data communication with each other. That is, the central device 3 is composed of a plurality of different servers according to each function.

[0311] The file server 8 is a server that manages the files of the application programs distributed from the central device 3 to the vehicle-side system 4. The file server 8 manages the update data (hereinafter, also referred to as reprogram data (Reprogram-Data), write data) provided by the provider of the application program distributed from the central device 3 to the vehicle-side system 4, i.e., the supplier, etc., the distribution specification data provided by the OEM (Original Equipment Manufacturer), the vehicle status obtained from the vehicle-side system 4, etc. The file server 8 can perform data communication with the vehicle-side system 4 via the communication network 2, and if a download request for a distribution data packet is generated, it sends a distribution data packet that packages the reprogram data and the distribution specification data into one file to the vehicle-side system 4.

[0312] The web server 9 is a server that manages web page information. The web server 9 sends the web page data it manages according to a request from a web browser possessed by the mobile terminal 6, etc. The management server 10 is a server that manages the personal information of users registered for the application program rewrite service, the rewrite history of the application program for each individual vehicle, etc.

[0313] The vehicle-side system 4 has a main device 11 (equivalent to a vehicle main device). The main device 11 has a DCM (Data Communication Module) 12 (equivalent to an in-vehicle communication device) and a CGW (Central GateWay) 13 (equivalent to a vehicle gateway device). The DCM 12 and the CGW 13 are connected via the first bus 14 so as to be able to perform data communication. The DCM 12 performs data communication with the central device 3 via the communication network 2. If the DCM 12 downloads a distribution data packet from the file server 8, it extracts the write data from the downloaded distribution data packet and transfers the extracted write data to the CGW 13.

[0314] The CGW 13 has a data relay function. If it obtains write data from the DCM 12, it instructs the rewrite target ECU, which is the rewrite target of the application program, to write the obtained write data, and distributes the write data to the rewrite target ECU. In addition, if the writing of the write data is completed in the rewrite target ECU and the rewrite of the application program is completed, the CGW 13 instructs the rewrite target ECU to activate the application program after the rewrite is completed.

[0315] The main device 11 generalizes the program update function on the vehicle side in the vehicle program rewrite system 1 and functions as an OTA host. In addition, in Figure 1In this case, a configuration is illustrated in which the DCM 12 and the in-vehicle display 7 are connected to the same first bus 14. However, a configuration in which the DCM 12 and the in-vehicle display 7 are connected to different buses is also possible. Additionally, either a configuration in which the CGW 13 has a part or the whole of the function of the DCM 12, or a configuration in which the DCM 12 has a part or the whole of the function of the CGW 13 is possible. That is, in the main device 11, the functional sharing between the DCM 12 and the CGW 13 can be arbitrarily configured. The main device 11 can be composed of two ECUs, namely the DCM 12 and the CGW 13, or can be composed of a single integrated ECU having the functions of the DCM 12 and the CGW 13.

[0316] In addition to the first bus 14, a second bus 15, a third bus 16, a fourth bus 17, and a fifth bus 18 are also connected to the CGW 13 as in-vehicle-side buses. Various ECUs 19 are connected via the buses 15 to 17, and a power management ECU 20 is connected via the bus 18.

[0317] The second bus 15 is, for example, a bus of a body system network. The ECU 19 connected to the second bus 15 is an ECU that controls the body system. The ECU that controls the body system is, for example, a door ECU that controls the locking / unlocking of the doors, an instrument ECU that controls the display on the instrument display, an air conditioner ECU that controls the driving of the air conditioner, a window ECU that controls the opening and closing of the windows, a security ECU that is driven for vehicle anti-theft, etc.

[0318] The third bus 16 is, for example, a bus of a driving system network. The ECU 19 connected to the third bus 16 is an ECU that controls the driving system. The ECU that controls the driving system is, for example, an engine ECU that controls the driving of the engine, a brake ECU that controls the driving of the brakes, an ECT (Electronic Controlled Transmission) ECU that controls the driving of the automatic transmission, a power steering ECU that controls the driving of the power steering, etc.

[0319] The fourth bus 17 is, for example, a bus of a multimedia system network. The ECU 19 connected to the fourth bus 17 is an ECU that controls the multimedia system. The ECU that controls the multimedia system is, for example, a navigation ECU that controls the navigation system, an ETC (Electronic Toll Collection System, registered trademark) ECU that controls the electronic toll collection system, etc. The buses 15 to 17 can also be buses of systems other than the body system network bus, the driving system network bus, and the multimedia system network bus. Additionally, the number of buses and the number of ECUs 19 are not limited to the illustrated configuration.

[0320] The power management ECU 20 is an ECU that manages the power supplied to the DCM 12, CGW 13, various ECUs 19, etc.

[0321] A sixth bus 21 is connected to the CGW 13 as a bus outside the vehicle. A DLC (Data Link Coupler) connector 22 to which a tool 23 (equivalent to a service tool) can be detachably connected is connected to the sixth bus 21. The in-vehicle buses 14 to 18 and the out-of-vehicle bus 21 are constituted by, for example, a CAN (Controller Area Network, registered trademark) bus. The CGW 13 performs data communication with the DCM 12, various ECUs 19, and the tool 23 according to the CAN data communication standard and the diagnostic communication standard (UDS (Unified Diagnosis Services): ISO 14229). In addition, the DCM 12 and the CGW 13 may be connected via Ethernet, and the DLC connector 22 and the CGW 13 may be connected via Ethernet.

[0322] When the rewrite target ECU 19 receives write data from the CGW 13, it writes the received write data to a flash memory (equivalent to a non-volatile memory) to rewrite the application program. In the above configuration, the CGW 13 functions as a reprogramming host that distributes write data to the rewrite target ECU 19 when it receives a request for acquisition of write data from the rewrite target ECU 19. The rewrite target ECU 19 functions as a reprogramming slave that writes the received write data to the flash memory to rewrite the application program when it receives write data from the CGW 13.

[0323] As a method of rewriting the application program, there are a method of rewriting via wire and a method of rewriting via wireless. The method of rewriting the application program via wire means a method of rewriting the rewrite target ECU 19 using an application program obtained via wire from outside the vehicle. Specifically, when the tool 23 is connected to the DLC connector 22, the tool 23 transmits write data to the CGW 13. The CGW 13 functions as a gateway, sends a wired rewrite request to the rewrite target ECU 19, instructs the rewrite target ECU 19 to write (install) the write data, and distributes the write data transmitted from the tool 23 to the rewrite target ECU 19. Distributing the write data to the rewrite target ECU 19 is to relay the write data.

[0324] The method of wirelessly rewriting the application program refers to the method of rewriting the target ECU19 with the application program obtained wirelessly from outside the vehicle. Specifically, if the DCM12 downloads the distribution data packet from the file server 8, it extracts the write data from the downloaded distribution data packet and transmits the write data to the CGW13. The CGW13 acts as a rewriting tool, instructs the target ECU19 to write (install) the write data, and distributes the write data transmitted from the DCM12 to the target ECU19.

[0325] As a method of diagnosing the ECU19, there are a method of diagnosing via wire and a method of diagnosing via wireless. The method of diagnosing via wire refers to the method of diagnosing the ECU19 via wire from outside the vehicle. Specifically, if the tool 23 is connected to the DLC connector 22, the tool 23 transmits a diagnostic request to the CGW13. The CGW13 acts as a gateway, sends the diagnostic request to the target ECU19 for diagnosis, and distributes the diagnostic instruction transmitted from the tool 23 to the target ECU19. The target ECU19 performs diagnostic processing corresponding to the diagnostic instruction received from the CGW13.

[0326] The method of diagnosing via wireless refers to the method of diagnosing the ECU19 via wireless from outside the vehicle. Specifically, if the diagnostic instruction is sent from the central device 3 to the DCM12 as a diagnostic request, the DCM12 transmits the diagnostic instruction to the CGW13. The CGW13 acts as a gateway, distributes the diagnostic instruction as a diagnostic request to the target ECU19 for diagnosis. The target ECU performs diagnostic processing corresponding to the diagnostic instruction received from the CGW13.

[0327] As Figure 2 shown, the CGW13 has a microcomputer (hereinafter referred to as a microcomputer) 24, a data transmission circuit 25, a power supply circuit 26, and a power supply detection circuit 27 as electrical function modules. The microcomputer 24 has a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), and a flash memory 24d. A secure area in which information cannot be read from the outside of the CGW13 is included in the flash memory 24d. The microcomputer 24 executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the CGW13.

[0328] The data transmission circuit 25 controls data communication with the buses 14-18, 21 based on the CAN data communication standard and the diagnostic communication standard. The power supply circuit 26 inputs the battery power supply (hereinafter referred to as the +B power supply), the accessory power supply (hereinafter referred to as the ACC power supply), and the ignition power supply (hereinafter referred to as the IG power supply). The power supply detection circuit 27 detects the voltage values of the +B power supply, the ACC power supply, and the IG power supply input by the power supply circuit 26, compares these detected voltage values with a specified voltage threshold, and outputs the comparison result to the microcomputer 24. The microcomputer 24 determines whether the +B power supply, the ACC power supply, and the IG power supply supplied from the outside to the CGW 13 are normal or abnormal according to the comparison result input from the power supply detection circuit 27.

[0329] As Figure 3 shown, the DCM 12 has a microcomputer 28, a radio circuit 29, a data transmission circuit 30, a power supply circuit 31, and a power supply detection circuit 32 as electrical function modules. The microcomputer 28 has a CPU 28a, a ROM 28b, a RAM 28c, and a flash memory 28d. A secure area in which information cannot be read from the outside of the DCM 12 is included in the flash memory 28d. The microcomputer 28 executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the DCM 12. The flash memory for storing data downloaded from the central device 3 may also be configured in the CGW 13.

[0330] The radio circuit 29 controls data communication with the central device 3 via the communication network 2. The data transmission circuit 30 controls data communication with the bus 14 based on the CAN data communication standard. The power supply circuit 31 inputs the +B power supply, the ACC power supply, and the IG power supply. The power supply detection circuit 32 detects the voltage values of the +B power supply, the ACC power supply, and the IG power supply input by the power supply circuit 31, compares these detected voltage values with a specified voltage threshold, and outputs the comparison result to the microcomputer 28. The microcomputer 28 determines whether the +B power supply, the ACC power supply, and the IG power supply supplied from the outside to the DCM 12 are normal or abnormal according to the comparison result input from the power supply detection circuit 32.

[0331] In addition, the DCM 12 has a vehicle position detection function for detecting the vehicle position through, for example, GPS (Global Positioning System). The flash memory 28d of the DCM 12 has a sufficient memory capacity capable of storing the distribution data packet downloaded from the central device 3, and has a larger memory capacity than the flash memory 24d of the CGW 13. That is, the flash memory 28d of the DCM 12 is configured to have a sufficient memory capacity, so that even if the flash memory 24d of the CGW 13 is not configured to have a sufficient memory capacity, in the main device 11, the distribution data packet can be downloaded from the central device 3 and the downloaded distribution data packet can be stored in the DCM 12.

[0332] As Figure 4 shown, the ECU 19 has a microcomputer 33, a data transmission circuit 34, a power supply circuit 35, and a power supply detection circuit 36 as electrical function modules. The microcomputer 33 has a CPU 28a, a ROM 28b, a RAM 33c, and a flash memory 28d. A security area in which information cannot be read from the outside of the ECU 19 is included in the flash memory 28d. The microcomputer 33 executes various control programs stored in a non-transitory physical storage medium to perform various processes and control the operation of the ECU 19.

[0333] The data transmission circuit 34 controls data communication based on the CAN data communication standard between the buses 15 to 17. The power supply circuit 35 inputs the +B power supply, the ACC power supply, and the IG power supply. The power supply detection circuit 36 detects the voltage values of the +B power supply, the ACC power supply, and the IG power supply input by the power supply circuit 35, compares these detected voltage values with a specified voltage threshold, and outputs the comparison result to the microcomputer 33. The microcomputer 33 determines whether the +B power supply, the ACC power supply, and the IG power supply supplied from the outside to the ECU 19 are normal or abnormal based on the comparison result input from the power supply detection circuit 27. In addition, the ECU 19 has substantially the same configuration except for differences in loads such as sensors and actuators connected thereto.

[0334] The in-vehicle display 7 has the same configuration as the Figure 4 shown ECU 19. The power management ECU 20 has the same configuration as the Figure 4 shown ECU 19. The power management ECU 20 is connected so as to be able to perform data communication with a power supply control circuit 43 described later.

[0335] As Figure 5As shown, the power management ECU 20, CGW 13, and ECU 19 are connected to the +B power supply line 37, ACC power supply line 38, and IG power supply line 39, which serve as power supply lines. The +B power supply line 37 is connected to the positive electrode of the vehicle battery 40. The ACC power supply line 38 is connected to the positive electrode of the vehicle battery 40 via the ACC switch 41. If the user performs an ACC operation, the ACC switch 41 switches from off to on, and the output voltage of the vehicle battery 40 is applied to the ACC power supply line 38. For example, in the case of a vehicle of the type where a key is inserted into an insertion port, the ACC operation is an operation of inserting the key into the insertion port and turning it from the "OFF" position to the "ACC" position. In the case of a vehicle of the type where a start button is pressed, the ACC operation is an operation of pressing the start button once.

[0336] The IG power supply line 39 is connected to the positive electrode of the vehicle battery 40 via the IG switch 42. If the user performs an IG operation, the IG switch 42 switches from off to on, and the output voltage of the vehicle battery 40 is applied to the IG power supply line 39. For example, in the case of a vehicle of the type where a key is inserted into an insertion port, the IG operation is an operation of inserting the key into the insertion port and turning it from the "OFF" position to the "ON" position. In the case of a vehicle of the type where a start button is pressed, the IG operation is an operation of pressing the start button twice. The negative electrode of the vehicle battery 40 is grounded.

[0337] When both the ACC switch 41 and the IG switch 42 are off, only the +B power supply is supplied to the vehicle-side system 4. The state in which only the +B power supply is supplied to the vehicle-side system 4 is referred to as the +B power supply state. When the ACC switch 41 is on and the IG switch 42 is off, the ACC power supply and the +B power supply are supplied to the vehicle-side system 4. The state in which the ACC power supply and the +B power supply are supplied to the vehicle-side system 4 is referred to as the ACC power supply state. When both the ACC switch 41 and the IG switch 42 are on, the +B power supply, the ACC power supply, and the IG power supply are supplied to the vehicle-side system 4. The state in which the +B power supply, the ACC power supply, and the IG power supply are supplied to the vehicle-side system 4 is referred to as the IG power supply state. In addition to the above power supply states, a power supply state that gives power suitable for program update via wireless is also considered, etc.

[0338] For the ECU 19, the start conditions vary depending on the power supply state and are classified into a +B power supply system ECU that starts in the +B power supply state, an ACC system ECU that starts in the ACC power supply state, and an IG system ECU that starts in the IG power supply state. For example, the ECU 19 driven for purposes such as vehicle anti-theft is classified as a +B power supply system ECU. For example, the ECU 19 driven for purposes of non-driving systems such as audio is classified as an ACC system ECU. For example, the ECU 19 driven for purposes of driving systems such as engine control is classified as an IG system ECU.

[0339] The +B power supply system ECU is configured to be connected to the +B power supply line 37, the ACC power supply line 38, and the IG power supply line 39. It selects the +B power supply line 37 in the +B power supply state, selects the ACC power supply line 38 in the ACC power supply state, and selects the IG power supply line 39 in the IG power supply state. The ACC system ECU is configured to be connected to the ACC power supply line 38 and the IG power supply line 39. It selects the ACC power supply line 38 in the ACC power supply state and selects the IG power supply line 39 in the IG power supply state. The IG system ECU is connected to the IG power supply line 39.

[0340] CGW13 causes the ECU19, which is the destination of the start request, to transition from the sleep state to the start state by sending a start request to the ECU19 in the sleep state. In addition, CGW13 causes the ECU19, which is the destination of the sleep request, to transition from the start state to the sleep state by sending a sleep request to the ECU19 in the start state. CGW13 can cause a specific ECU19 to transition to the start state or the sleep state by, for example, making the waveforms of the transmission signals sent to the buses 15 - 17 different. That is, for each ECU19, the start request waveform and the sleep request waveform are predetermined. If the ECU19 receives a start request waveform suitable for itself, it transitions from the sleep state to the start state. If it receives a sleep request waveform suitable for itself from CGW13, it transitions from the start state to the sleep state.

[0341] For example, when the ECU (ID1) and the ECU (ID2) are in the start state, CGW13 sends the first waveform, causing the ECU (ID1) to transition from the start state to the sleep state and keeping the ECU (ID2) in the start state. In addition, when the ECU (ID1) and the ECU (ID2) are in the start state, CGW13 sends the second waveform, keeping the ECU (ID1) in the start state and causing the ECU (ID2) to transition from the start state to the sleep state.

[0342] The power control circuit 43 is connected in parallel with the ACC switch 41 and the IG switch 42. CGW13 sends a power control request to the power management ECU20 to cause the power management ECU20 to control the power control circuit 43. That is, CGW13 causes the positive poles of the ACC power supply line 38, the IG power supply line 39, and the vehicle battery 40 to be connected inside the power control circuit 43 by sending a power start request as the power control request to the power management ECU20. In this state, even if the ACC switch 41 and the IG switch 42 are turned off, the ACC power supply and the IG power supply are supplied to the vehicle - side system 4. In addition, CGW13 causes the positive poles of the ACC power supply line 38, the IG power supply line 39, and the vehicle battery 40 to be disconnected inside the power control circuit 43 by sending a power stop request as the power control request to the power management ECU20.

[0343] The DCM 12, CGW 13, ECU 19, and power management ECU 20 each have a power self-holding circuit, which has a power self-holding function for maintaining the power supply from the vehicle battery 40. That is, regarding the DCM 12, CGW 13, ECU 19, and power management ECU 20, when the vehicle power is switched from the ACC power or IG power to the +B power while in the startup state, they do not immediately transfer from the startup state to the stop state or sleep state after this switch. Instead, they use the power supply from the vehicle battery 40 to continue the startup state for a specified time (e.g., several minutes) to self-hold the drive power. The DCM 12, CGW 13, ECU 19, and power management ECU 20 transfer from the startup state to the stop state or sleep state after a specified time has elapsed since the vehicle power was switched from the ACC power or IG power to the +B power. For example, in the case of the ECU 19 of the engine control system, after the vehicle power is switched from the ACC power or IG power to the +B power, the power self-holding function operates, and various data related to engine control obtained during vehicle driving is stored as a log.

[0344] Next, the distribution data packet distributed from the central device 3 to the main device 11 will be described. As Figure 6 shown, in the vehicle program rewriting system 1, recompiled data is generated based on the write data provided by the supplier, who is the provider of the application program, and the rewriting specification data (equivalent to the specification data) provided by the OEM. The rewriting specification data can also be generated in the central device 3. As the write data provided by the supplier, there are differential data equivalent to the difference between the old application program and the new application program, and all data equivalent to the entire new application program. The differential data and all data can also be compressed by a known data compression technique. In Figure 6 , an example is shown where differential data is provided as the write data from suppliers A to C, and recompiled data is generated based on the encrypted differential data and authentication code of the ECU (ID1) provided by supplier A, the encrypted differential data and authentication code of the ECU (ID2) provided by supplier B, the encrypted differential data and authentication code of the ECU (ID3) provided by supplier C, and the rewriting specification data provided by the OEM.

[0345] The authentication code is data assigned to each write data to verify the integrity of the differential data, and is generated, for example, based on the ECU (ID), the key information associated with the ECU (ID), and the differential data. Here, in the case where the rewriting of the application program is cancelled midway, the write data used for writing back (rolling back) to the old version can also be included in the recompiled data.

[0346] The rewritten specification data provided by the OEM includes information capable of determining the ECU 19 to be rewritten, information capable of determining the rewrite order when there are multiple ECUs 19 to be rewritten, information capable of determining the rollback method described later, etc. as information related to the rewrite of the application program. The rewritten specification data is data that defines the actions related to the rewrite in the DCM 12, CGW 13, the ECU 19 to be rewritten, etc. The rewritten specification data is classified into DCM-specific rewritten specification data used by the DCM 12 and CGW-specific rewritten specification data used by the CGW 13.

[0347] As Figure 7 shown, the DCM-specific rewritten specification data includes specification data information and ECU information. The specification data information includes address information and file name. The ECU information includes the corresponding number of copies of the ECU 19 to be rewritten, such as the address information referred to when sending the update program (write data) of each ECU 19 to be rewritten to the CGW 13. Specifically, the ECU information includes at least the ID for identifying the ECU (ECU (ID)), the reference address when obtaining the update program (update program acquisition address), the update program size, the reference address when obtaining the rollback program (rollback program acquisition address), and the rollback program size. The rollback program is a program (write data) for returning the application program to the original version when the rewrite of the application program is cancelled midway.

[0348] As Figure 8 shown, the CGW-specific rewritten specification data includes group information, bus load table, battery load, vehicle state at the time of rewrite, and ECU information. The CGW-specific rewritten specification data may also include rewrite step information, display scenario information, etc. in addition to these. The group information is information indicating the group to which the ECU 19 to be rewritten belongs and the rewrite order. For example, as the first group information, it is stipulated that the application program is rewritten in the order of ECU (ID1), ECU (ID2), ECU (ID3), and as the second group information, it is stipulated that the application program is rewritten in the order of ECU (ID4), ECU (ID5), ECU (ID6). The bus load table is the table Figure 100 shown later and will be described in detail later. The battery load is information indicating the lower limit value of the battery margin of the vehicle battery 40 that can be allowed in the vehicle. The vehicle state at the time of rewrite is information indicating in what vehicle state the rewrite is performed.

[0349] The ECU information is information related to the ECU 19 to be rewritten, and includes at least ECU_ID (equivalent to device identification information), connection bus (equivalent to bus identification information), connection power supply, security access key information, memory type, rewriting method, power self-holding time, rewritten surface information, update program version, update program acquisition address, update program size, rollback program version, rollback program acquisition address, rollback program size, and write data type.

[0350] The connection bus indicates the bus to which the ECU 19 is connected. The connection power supply indicates the power supply line to which the ECU 19 is connected. The security access key information indicates the key information used for authentication of the CGW 13 to access the ECU 19 to be rewritten, including a random value or unique information, key mode, and decryption operation mode. The memory type indicates which of a single-sided independent memory, single-sided suspended memory (also called pseudo double-sided memory), and double-sided memory is the memory mounted on the ECU 19 to be rewritten. The rewriting method indicates which of rewriting based on power self-holding and rewriting based on power control it is. The power self-holding time indicates the time for continuing power self-holding when the rewriting method is rewriting based on power self-holding. The rewritten surface information indicates which surface is the operation surface and which surface is the non-operation surface. The operation surface is also called the startup surface, and the non-operation surface is also called the rewritten surface.

[0351] The update program version indicates the version of the update program. The update program acquisition address indicates the address of the update program. The update program size indicates the data size of the update program. The rollback program version indicates the version of the rollback program. The rollback program acquisition address indicates the address of the rollback program. The rollback program size indicates the data size of the rollback program. The write data type indicates whether the write data is differential data or all data. In addition, the rewriting specification data can include information defined independently by the system in addition to these information.

[0352] If the DCM 12 acquires the rewriting specification data for the DCM, it analyzes the acquired rewriting specification data for the DCM. If the DCM 12 analyzes the rewriting specification data for the DCM, it controls the acquisition of write data from the address storing the update program of the ECU 19 to be rewritten, and transfers the acquired write data to the actions related to rewriting such as the CGW 13.

[0353] If the CGW 13 acquires the rewriting specification data for the CGW, it analyzes the acquired rewriting specification data for the CGW. If the CGW 13 analyzes the rewriting specification data for the CGW, it controls actions related to rewriting such as requesting the transfer of a specified amount of the update program of the ECU 19 to be rewritten from the DCM 12 according to the analysis result, or distributing the write data to the ECU 19 to be rewritten in the specified order.

[0354] The recompiled data described above is registered in the file server 8, and the distribution specification data provided by the OEM is also registered. The distribution specification data provided by the OEM is data that defines the actions related to the display of various screens in the display terminal 5. As Figure 9 shown, the distribution specification data includes language information, display statements, data packet information, image data, display modes, display control programs, etc.

[0355] If the display terminal 5 obtains the distribution specification data from the CGW 13, it parses the obtained distribution specification data and controls the display of various screens based on the parsing result. For example, the display terminal 5 overlays the display statements obtained from the distribution specification data on the display frames held in advance, or executes the display control program obtained from the distribution specification data. In addition, the distribution specification data can include information defined independently by the system in addition to these information.

[0356] If the file server 8 registers the recompiled data and the distribution specification data, it encrypts the registered recompiled data to generate a distribution data packet that stores the data packet authentication symbol for authenticating the data packet, the encrypted recompiled data, and the distribution specification data. The authentication symbol is data given to verify the integrity of the recompiled data and the distribution specification data, and is generated based on, for example, the key information associated with the CGW 13, the recompiled data, and the distribution specification data. If the file server 8 receives a download request for the distribution data packet from the outside, it sends the distribution data packet to the DCM 12. In addition, in Figure 6 it is exemplified that the file server 8 generates a distribution data packet storing the recompiled data and the distribution specification data and sends the recompiled data and the distribution specification data to the DCM 12 as one file at the same time, but the recompiled data and the distribution specification data can also be sent to the DCM 12 as different files. That is, the file server 8 can also send the distribution specification data to the DCM 12 first and then send the recompiled data to the DCM 12. In this case, authentication symbols can be given to the distribution specification data and the recompiled data respectively.

[0357] As Figure 10 shown, if the DCM 12 downloads the distribution data packet from the file server 8, it uses the data packet authentication symbol stored in the downloaded distribution data packet to verify the integrity of the encrypted recompiled data. If the verification result is positive, the DCM 12 decrypts the encrypted recompiled data. If the DCM 12 decrypts the encrypted recompiled data, it unpacks the decrypted recompiled data and extracts it into the encrypted differential data, the authentication symbol, the rewrite specification data for the DCM, and the rewrite specification data for the CGW. In Figure 10illustrates a case where encrypted differential data and an authenticator for ECU (ID1), encrypted differential data and an authenticator for ECU (ID2), encrypted differential data and an authenticator for ECU (ID3), rewrite specification data for DCM, and rewrite specification data for CGW are extracted.

[0358] Next, refer to Figures 11 to 22 The flash memory 33d of the ECU 19 will be described. The flash memory 33d of the ECU 19 is divided into a single-sided single memory having a flash memory surface on one side, a single-sided suspended memory having flash memory surfaces on a pseudo two sides, and a double-sided memory having flash memory surfaces on substantially two sides according to the memory structure. After that, the ECU 19 equipped with the single-sided single memory is called a single-sided single memory ECU, the ECU 19 equipped with the single-sided suspended memory is called a single-sided suspended memory ECU, and the ECU 19 equipped with the double-sided memory is called a double-sided memory ECU.

[0359] Since the single-sided single memory has a configuration with a flash memory surface on one side, there are no concepts of an active surface and a non-active surface, and the application program cannot be rewritten during the execution of the application program. On the other hand, the single-sided suspended memory and the double-sided memory have configurations with flash memory surfaces on two sides, so there are concepts of an active surface and a non-active surface, and the application program on the non-active surface can be rewritten during the execution of the application program on the active surface. Since the double-sided memory has a configuration with flash memory surfaces on two completely separated sides, the application program can be rewritten at any time such as during vehicle running. The single-sided suspended memory is a configuration in which the single-sided single memory is divided into two sides in a pseudo manner, and the timing for normal reading and writing is limited, and the application program cannot be rewritten during vehicle running, but can be rewritten during parking with the IG power off.

[0360] In addition, the single-sided single memory, the single-sided suspended memory, and the double-sided memory each have a recompiled firmware embedded type (hereinafter referred to as the embedded type) in which the recompiled firmware is embedded and a recompiled firmware download type (hereinafter referred to as the download type) in which the recompiled firmware is downloaded from the outside. The recompiled firmware is firmware for rewriting the application program.

[0361] Hereinafter, the configurations of each flash memory will be described in sequence.

[0362] (A) Single-sided single memory

[0363] (A-1) Embedded type single-sided single memory

[0364] Refer to Figure 11 and Figure 12An embedded single-sided standalone memory will be described. The embedded single-sided standalone memory has a differential engine working area, an application area, and a boot program area. In the application area, version information, parameter data, an application program, firmware, and a normal-time vector table are configured. In the boot area, a boot program, progress status point 2, progress status point 1, startup determination information, wireless reprogramming firmware, wired reprogramming firmware, a startup determination program, and a boot-time vector table are configured.

[0365] As Figure 11 shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing, it executes the startup determination program, searches for the starting address with reference to the boot-time vector table and the normal-time vector table, and executes the specified address of the application program.

[0366] When the microcomputer 33 performs a rewrite operation for rewriting the application program, it does not execute the application program but executes wireless or wired reprogramming firmware. Figure 12 This represents an operation of rewriting the application program using differential data as an update program. As Figure 12 shown, the microcomputer 33 temporarily saves the application program as old data to the differential engine working area. The microcomputer 33 reads out the old data temporarily saved to the differential engine working area, and uses the differential engine included in the embedded reprogramming firmware to restore new data based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the specified address of the memory to rewrite the application program.

[0367] (A - 2) Downloadable single-sided standalone memory

[0368] Refer to Figure 13 and Figure 14 to describe the downloadable single-sided standalone memory. The downloadable type is different from the above-mentioned embedded type in that it downloads wireless reprogramming firmware and wired reprogramming firmware from the outside, and deletes the wireless reprogramming firmware and wired reprogramming firmware after rewriting the application program. In the case of updating the application program wirelessly, for example, the wireless reprogramming firmware executed by each ECU 19 is included in the reprogramming data as shown in Figure 6 . The ECU 19 receives the wireless reprogramming firmware for its own ECU from the CGW 13 and saves the received wireless reprogramming firmware for its own ECU to the RAM.

[0369] As Figure 13 shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing, it executes the startup determination program in the same way as the embedded type, searches for the starting address with reference to the boot-time vector table and the normal-time vector table, and executes the specified address of the application program.

[0370] As Figure 14As shown, when the microcomputer 33 performs the rewrite operation of the rewrite process of the application program, the application program is temporarily saved as old data in the differential engine working area. The microcomputer 33 reads out the old data temporarily saved in the differential engine working area, and through the differential engine included in the reprogramming firmware downloaded from the outside, restores the new data based on the read old data and the differential data stored in the RAM 33c. When the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to rewrite the application program.

[0371] (B) Single-sided suspended memory

[0372] (B-1) Embedded single-sided suspended memory

[0373] Refer to Figure 15 and Figure 16 The embedded single-sided suspended memory will be described. The embedded single-sided suspended memory has a differential engine working area, an application program area, and a boot program area. The reprogramming firmware for program update is configured in the boot program area in the same way as the single-sided individual memory and is not the object of program update. The application program area that is the object of program update pseudo-has an A side and a B side, and version information, application programs, and normal-time vector tables are respectively configured on the A side and the B side. A boot program, reprogramming firmware, reprogramming time vector table, start surface determination function, start surface determination information, and boot time vector table are configured in the boot area.

[0374] As Figure 15 shown, when the microcomputer 33 performs the normal operation of application processes such as vehicle control processing and diagnostic processing, it executes the boot program, and determines which of the A side and the B side is the operation surface through the start surface determination function based on the start surface determination information of each of the A side and the B side. If the microcomputer 33 determines that the A side is set as the operation surface, it refers to the normal-time vector table of the A side to search for the start address and executes the application program of the A side. Similarly, if the microcomputer 33 determines that the B side is set as the operation surface, it refers to the normal-time vector table of the B side to search for the start address and executes the application program of the B side. In addition, in Figure 15 , the reprogramming firmware is configured in the boot program area, but it can also be configured such that the reprogramming firmware is also the object of program update and is configured in the respective areas of the A side or the B side.

[0375] As Figure 16As shown, when the microcomputer 33 performs the rewrite operation of the application program on the non-active surface, the application program on the non-active surface is temporarily saved as old data in the differential engine working area. The microcomputer 33 reads out the old data temporarily saved in the differential engine working area, and through the differential engine in the embedded reprogramming firmware, restores new data based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the non-active surface to rewrite the application program on the non-active surface. In Figure 16 an example is shown where the A surface is the active surface and the B surface is the non-active surface.

[0376] (B - 2) Downloadable single-sided suspended memory

[0377] Refer to Figure 17 and Figure 18 to describe the downloadable single-sided suspended memory. Compared with the above-mentioned embedded type, the downloadable type is different in that it downloads the reprogramming firmware and the reprogramming time vector table from the outside, and deletes the reprogramming firmware and the reprogramming time vector table after rewriting the application program.

[0378] As Figure 17 shown, when the microcomputer 33 performs the normal operation of application processing such as vehicle control processing and diagnostic processing, similar to the embedded type, it executes the boot program, and determines the old and new based on the respective boot surface determination information of the A surface and the B surface through the boot surface determination function, and determines which surface of the A surface and the B surface is the active surface. If the microcomputer 33 determines that the A surface is the active surface, it searches for the starting address with reference to the normal time vector table of the A surface and executes the application program on the A surface. Similarly, if the microcomputer 33 determines that the B surface is the active surface, it searches for the starting address with reference to the normal time vector table of the B surface and executes the application program on the B surface.

[0379] As Figure 18 shown, when the microcomputer 33 performs the rewrite operation of the application program, the application program on the non-active surface is temporarily saved as old data in the differential engine working area. The microcomputer 33 reads out the old data temporarily saved in the differential engine working area, and through the differential engine in the reprogramming firmware downloaded from the outside, restores new data based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to rewrite the application program. In Figure 18 an example is shown where the A surface is the active surface and the B surface is the non-active surface. In this way, in the single-sided suspended memory, it is possible to perform the rewrite of the application program on the B surface in the background while executing the application program on the A surface.

[0380] (C) Double-sided memory

[0381] (C - 1) Embedded double-sided memory

[0382] Reference Figure 19 and Figure 20 An embedded double-sided memory will be described. The embedded single-sided independent memory has an application program area and a rewrite program area on side A, an application program area and a rewrite program area on side B, and a boot program area. In the boot area, the boot program is configured to be unrewritable. The boot program includes a boot swap function and a boot-time vector table. In each application program area, version information, parameter data, application programs, firmware, and a normal-time vector table are configured. In each rewrite program area, a program for controlling rewriting, recompilation progress management information 2, recompilation progress management information 1, start surface determination information, wireless recompilation firmware, wired recompilation firmware, and a boot-time vector table are configured. In the boot area, a boot program, a boot swap function, and a boot-time vector table are configured.

[0383] As Figure 19 shown, when the microcomputer 33 performs normal operations such as vehicle control processing and diagnostic processing and when performing rewrite operations for rewriting application programs on the non-operating surface, it executes the boot program, and determines the old and new through the boot swap function based on the start surface determination information of side A and side B, and determines which of side A and side B is the operating surface. If the microcomputer 33 determines that side A is the operating surface, it searches for the start address with reference to the boot-time vector table of side A and the normal-time vector table of side A, and executes the application program of side A. Similarly, if the microcomputer 33 determines that side B is the operating surface, it searches for the start address with reference to the boot-time vector table of side B and the normal-time vector table of side B, and executes the application program of side B.

[0384] As Figure 20 shown, when the microcomputer 33 performs a rewrite operation for rewriting an application program on the non-operating surface, it temporarily saves the application program on the non-operating surface as old data to the differential engine working area. The microcomputer 33 reads out the old data temporarily saved to the differential engine working area, and through the differential engine in the embedded recompilation firmware, restores new data based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the non-operating surface to rewrite the application program on the non-operating surface. In addition, the old data temporarily saved to the differential engine working area can target either the application program on the operating surface or the application program on the non-operating surface. At this time, when targeting the application program on the operating surface, the data on the non-operating surface is erased before writing the new data. Here, when the recompilation data obtained from outside the vehicle is not differential data but all data (full data), the obtained recompilation data is written as new data to the non-operating surface. In Figure 20In this case, an example is shown where the A side is the operating side and the B side is the non-operating side. In addition, the old data temporarily stored in the differential engine working area can target either the application programs on the operating side or the application programs on the non-operating side. When it is necessary to match the execution addresses of the application programs, the application programs on the non-operating side are saved as old data.

[0385] (C-2) Downloadable Dual-Sided Memory

[0386] Refer to Figure 21 and Figure 22 A downloadable dual-sided memory will be described. Compared with the above-mentioned embedded type, the downloadable type is different in that after downloading wireless reprogramming firmware and wired reprogramming firmware from the outside and rewriting the application programs, the wireless reprogramming firmware and the wired reprogramming firmware are deleted.

[0387] As Figure 21 shown, when the microcomputer 33 performs normal operations such as application processing and diagnostic processing of vehicle control and the rewriting operation of rewriting the application programs on the non-operating side, similar to the embedded type, it executes the boot program, determines the old and new through the boot swap function based on the start surface determination information of each of the A side and the B side, and determines which side of the A side and the B side is the operating side, and executes the application programs on the operating side to perform application processing.

[0388] As Figure 22 shown, when the microcomputer 33 performs the rewriting operation of rewriting the application programs, the application programs on the non-operating side are temporarily saved as old data in the differential engine working area. The microcomputer 33 reads out the old data temporarily stored in the differential engine working area, and restores the new data from the downloaded reprogramming firmware based on the read old data and the differential data stored in the RAM 33c. If the microcomputer 33 generates new data based on the old data and the differential data, it writes the new data to the non-operating side to rewrite the application programs on the non-operating side. In addition, the old data temporarily stored in the differential engine working area can target either the application programs on the operating side or the application programs on the non-operating side. At this time, when targeting the application programs on the operating side, the data on the non-operating side is erased before writing the new data. Here, when the reprogramming data obtained from outside the vehicle is not differential data but all data (full data), the obtained reprogramming data is written as new data to the non-operating side. In Figure 22 In this case, an example is shown where the A side is the operating side and the B side is the non-operating side. In addition, the old data temporarily stored in the differential engine working area can target either the application programs on the operating side or the application programs on the non-operating side. In this way, in the dual-sided memory, it is possible to execute the rewriting of the application programs on the B side in the background while executing the application programs on the A side.

[0389] As described above, in either the embedded type or the download type configuration, an application program and a rewriting program for rewriting the application program are arranged in each application area. In addition, in Figure 20 and Figure 22 , the application program is shown as the recompilation object, but the rewriting program can also be used as the recompilation object. Additionally, in the case where it is desired that the rewriting program cannot be rewritten, the rewriting program can be arranged in the boot area. A program for wired rewriting can also be arranged in the boot area so that, for example, reliable wired rewriting via the tool 23 can be implemented among dealers and the like.

[0390] Next, with reference to Figures 23 to 25 the overall procedure for rewriting the application program will be described. Here, the case where the user operates the mobile terminal 6 which is the display terminal 5 to rewrite the application program while parked will be described, but the case where the in-vehicle display 7 is operated to rewrite the application program while parked is the same. The distribution data packet sent from the central device 3 stores the write data for one or more ECUs 19 to be rewritten. That is, in the distribution data packet, if there is one ECU 19 to be rewritten, one write data for that one ECU 19 to be rewritten is stored, and if there are multiple ECUs 19 to be rewritten, multiple write data for each of the multiple ECUs 19 to be rewritten are stored. Here, there are 2 ECUs 19 to be rewritten, and the 2 ECUs 19 to be rewritten are referred to as the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2). Additionally, the ECU 19 other than the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) is referred to as the other ECU.

[0391] If the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively determine that a transmission request for, for example, a version notification signal is received from the master device 11, it is determined that the transmission condition for the version notification signal is satisfied. If the transmission condition for the version notification signal is satisfied, the ECU to be rewritten (ID1) sends a version notification signal including the version information of the application program stored in itself and the ECU (ID) that can identify itself to the master device 11. If the master device 11 receives a version notification signal from the ECU to be rewritten (ID1), it sends the received version notification signal to the central device 3. Similarly, if the transmission condition for the version notification signal is satisfied, the ECU to be rewritten (ID2) sends a version notification signal including the version of the application program stored in itself and the ECU (ID) that can identify itself to the master device 11. If the master device 11 receives a version notification signal from the ECU to be rewritten (ID2), it sends the received version notification signal to the central device 3.

[0392] When the central device 3 receives version notification signals from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), it determines the version of the application program included in the received version notification signal and the ECU (ID), and determines whether there is write data to be distributed to the ECU 19 to be rewritten, which is the source of the version notification signal. The central device 3 determines the current version of the application program of the ECU 19 to be rewritten based on the version notification signal received from the ECU to be rewritten, and compares this current version of the application program with the latest version being managed.

[0393] If the version determined based on the version notification signal is the same as the latest version being managed, the central device 3 determines that there is no write data to be distributed to the ECU 19 to be rewritten, which is the source of the version notification signal, and there is no need to update the application program stored in the ECU 19 to be rewritten. On the other hand, if the version determined based on the version notification signal is less than the latest version being managed, the central device 3 determines that there is write data to be distributed to the ECU 19 to be rewritten, which is the source of the version notification signal, and the application program stored in the ECU 19 to be rewritten needs to be updated.

[0394] If the central device 3 determines that the application program stored in the ECU 19 to be rewritten needs to be updated, it notifies the mobile terminal 6 of the main idea that an update is required. If notified of the main idea that an update is required, the mobile terminal 6 displays a distribution confirmation screen (A1). The distribution confirmation screen is the same as the activity notification screen described later. The user can confirm the main idea that an update is required through the distribution confirmation screen displayed on the mobile terminal 6 and can select whether to update.

[0395] If the user selects the main idea of updating (A2) on the mobile terminal 6, the mobile terminal 6 notifies the central device 3 of a download request for the distribution data packet. If notified of the download request for the distribution data packet from the mobile terminal 6, the central device 3 sends the distribution data packet to the main device 11.

[0396] If the main device 11 downloads the distribution data packet from the central device 3, it starts packet authentication processing (B1) for the downloaded distribution data packet. The main device 11 authenticates the distribution data packet, and if it completes the packet authentication processing, it starts write data extraction processing (B2). The main device 11 extracts the write data from the distribution data packet, and if it completes the write data extraction processing, it sends a download completion notification signal to the central device 3.

[0397] When the central device 3 receives the download completion notification signal from the main device 11, it notifies the mobile terminal 6 of the download completion. When notified of the download completion by the central device 3, the mobile terminal 6 displays a download completion notification screen (A3). The user can confirm the gist of the download completion through the download completion notification screen displayed on the mobile terminal 6 and can set the rewrite start time of the vehicle-side application program.

[0398] If the user sets the rewrite start time (A4) of the vehicle-side application program in the mobile terminal 6, the mobile terminal 6 notifies the central device 3 of the rewrite start time. When notified of the rewrite start time by the mobile terminal 6, the central device 3 stores the rewrite start time set by the user as the set start time. When the current time reaches the set start time (A5), the central device 3 sends a rewrite instruction signal to the main device 11.

[0399] When the main device 11 receives the rewrite instruction signal from the central device 3, it sends a power-on request to the power management ECU 20, causing the ECU to be rewritten (ID1), the ECU to be rewritten (ID2), and other ECUs to transition from the stopped state or the sleep state to the start state (X1).

[0400] The main device 11 starts distributing the write data to the ECU to be rewritten (ID1) and instructs the ECU to be rewritten (ID1) to write the write data. The ECU to be rewritten (ID1) starts receiving the write data from the main device 11. When instructed to write the write data, it starts writing the write data and starts the program rewrite process (C1). When the ECU to be rewritten (ID1) finishes receiving the write data from the main device 11, finishes writing the write data, and finishes the program rewrite process, it sends a rewrite completion notification signal to the main device 11.

[0401] When the main device 11 receives the rewrite completion notification signal from the ECU to be rewritten (ID1), it starts distributing the write data to the ECU to be rewritten (ID2) and instructs the ECU to be rewritten (ID2) to write the write data. The ECU to be rewritten (ID2) starts receiving the write data from the main device 11. When instructed to write the write data, it starts writing the write data and starts the program rewrite process (D1). When the ECU to be rewritten (ID2) finishes receiving the write data from the main device 11, finishes writing the write data, and finishes the program rewrite process, it sends a rewrite completion notification signal to the main device 11. When the main device 11 receives the rewrite completion notification signal from the ECU to be rewritten (ID2), it sends a rewrite completion notification signal to the central device 3.

[0402] When the central device 3 receives the rewrite completion notification signal from the master device 11, it notifies the mobile terminal 6 of the completion of the application program rewrite. When notified by the central device 3 of the completion of the application program rewrite, the mobile terminal 6 displays a rewrite completion notification screen (A6). The user can confirm the gist of the completion of the application program rewrite through the rewrite completion notification screen displayed on the mobile terminal 6 and can set the synchronization implementation as activation.

[0403] If the user sets the synchronization implementation (A7) in the mobile terminal 6, that is, the user sets the consent for the activation of the new program, the mobile terminal 6 notifies the central device 3 of the synchronization implementation. When notified of the synchronization implementation by the mobile terminal 6, the central device 3 sends a synchronization switching instruction signal to the master device 11. When the master device 11 receives the synchronization switching instruction signal from the central device 3, it distributes the received synchronization switching instruction signal to the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2).

[0404] When the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively receive the synchronization switching instruction signal from the master device 11, they start the program switching process (C2, D2) of switching the application program to be started next from the old application program to the new application program. When the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively complete the program switching process, they send a switching completion notification signal to the master device 11.

[0405] When the master device 11 receives the switching completion notification signal from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), it distributes a version read signal to the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2). When the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) respectively receive the version read signal from the master device 11, they read the version of the application program to be used later (C3, D3) and send the latest version notification signal including the read version to the master device 11. The master device 11 checks the software version by receiving the version notification signal from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2) and performs a rollback as needed.

[0406] When the master device 11 receives the version notification signal from the ECU to be rewritten (ID1) and the ECU to be rewritten (ID2), it sends a power stop request to the power management ECU 20 to transfer the ECU to be rewritten (ID1), the ECU to be rewritten (ID2), and other ECUs from the startup state to the stop state or the sleep state (X2).

[0407] The main device 11 sends the latest version notification signal to the central device 3. If the central device 3 receives the latest version notification signal from the main device 11, it determines the latest version of the application programs of the ECUs to be rewritten (ID1) and (ID2) based on the received latest version notification signal, and notifies the determined latest version to the mobile terminal 6. If the mobile terminal 6 is notified of the latest version by the central device 3, a latest version notification screen (A8) indicating the notified latest version is displayed on the mobile terminal 6. The user can confirm the latest version through the latest version notification screen displayed on the mobile terminal 6 and can confirm the gist of the activation completion.

[0408] Next, refer to Figures 26 to 29 The timing diagrams of the operations of the DCM 12, CGW 13, and the ECU 19 to be rewritten will be described in the case of rewriting the application program. In addition, here, the case of rewriting the application program of the dual-sided memory ECU during the period when the IG switch 42 is turned on by the user operation, that is, when the vehicle can run, and rewriting the application programs of the single-sided suspended memory ECU and the single-sided individual memory ECU during parking after the IG switch 42 is turned off by the user operation will be described. In addition, the case of rewriting the application program by power control and the case of rewriting the application program by power self-holding will be described.

[0409] (1) Case of rewriting the application program by power control

[0410] Refer to Figure 26 and Figure 27 The case of rewriting the application program by power control will be described. The rewriting of the application program by power control means a configuration that controls the rewriting operation according to the switching of the power supply without using a power self-holding circuit. If the user switches the IG switch from off to on and the vehicle power supply switches from the +B power supply to the IG power supply, the DCM 12, CGW 13, dual-sided memory ECU, single-sided suspended memory ECU, and single-sided individual memory ECU respectively start their normal operations (t1).

[0411] If notified of the start of download from the central device 3, the DCM 12 transfers from the normal operation to the download operation and starts downloading the distribution data packet from the central device 3 (t2). The DCM 12 can download the distribution data packet in the background while performing the normal operation. If the DCM 12 finishes downloading the distribution data packet from the central device 3, it resumes from the download operation to the normal operation (t3).

[0412] If notified of a rewrite instruction signal (installation instruction signal) from the central device 3 or the CGW 13, the DCM 12 transfers from the normal operation to the data transmission / central communication operation and starts the data transmission / central communication operation (t4). That is, the DCM 12 extracts the write data from the distributed data packet, starts transmitting the write data to the CGW 13, and obtains the progress of the rewrite from the CGW 13, and starts notifying the central device 3 of the progress of the rewrite.

[0413] When the CGW 13 starts obtaining the write data from the DCM 12, it transfers from the normal operation to the recompilation active operation, starts the recompilation active operation, starts distributing the write data to the dual-sided memory ECU, and instructs the writing of the write data. When the dual-sided memory ECU starts receiving the write data from the CGW 13, it starts the programming phase (hereinafter, also referred to as the installation phase) in the normal operation. That is, the dual-sided memory ECU installs the application program in the background while performing the normal operation. The dual-sided memory ECU starts writing the received write data to the flash memory and starts rewriting the application program.

[0414] During the period of rewriting the application program in the dual-sided memory ECU, if the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from ON to OFF, the DCM 12 interrupts the data transmission / central communication operation, the CGW 13 interrupts the recompilation active operation, and the dual-sided memory ECU interrupts the installation phase and interrupts the rewriting of the application program (t5).

[0415] Then, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the DCM 12 starts the data transmission / central communication operation again, the CGW 13 starts the recompilation active operation again, the dual-sided memory ECU starts the installation phase again, and starts rewriting the application program again (t6). That is, by the user switching the IG switch from ON to OFF, the vehicle power supply is switched from the IG power supply to the +B power supply, and then, by the user switching the IG switch from OFF to ON, the vehicle power supply is switched from the +B power supply to the IG power supply. Whenever a trip occurs, the dual-sided memory ECU repeats the interruption and restart of the rewriting of the application program (t7, t8).

[0416] When the dual-sided memory ECU finishes writing the write data and finishes rewriting the application program, it ends the installation phase and transfers from the normal operation to waiting for activation. That is, when the activation phase is not performed, the dual-sided memory ECU does not start on the new side (B side) where the application program has been rewritten and keeps starting on the old side (A side) (t9).

[0417] After the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from ON to OFF (t10), if the dual-sided memory ECU completes the rewriting of the application program at this time, CGW13 sends a power startup request to the power management ECU20. If the vehicle power supply is switched from the +B power supply to the IG power supply by CGW13 sending a power startup request to the power management ECU20, DCM12 resumes data transmission / central communication operations, and CGW13 resumes reprogramming operations, starting to distribute write data to the single-sided suspended memory ECU and the single-sided separate memory ECU. When the single-sided suspended memory ECU and the single-sided separate memory ECU start receiving write data from CGW13 respectively, they transfer from normal operations to the boot process, and the installation phase (t11) starts in the boot process. That is, the single-sided suspended memory ECU and the single-sided separate memory ECU do not perform installation in parallel with normal operations, but perform installation in the boot process where the application program is not operating.

[0418] If the single-sided suspended memory ECU starts rewriting the application program and the IG switch 42 is switched from OFF to ON by a user operation before the rewriting of the application program is completed, the rewriting of the application program is interrupted. The single-sided suspended memory ECU restores the operating surface (A surface) as the startup surface instead of the non-operating surface (B surface) where the rewriting of the application program was interrupted. If the single-sided separate memory ECU starts rewriting the application program, even if the IG switch 42 is switched from OFF to ON by a user operation before the rewriting of the application program is completed, the rewriting of the application program continues. This is because for the single-sided separate memory ECU, if the rewriting of the application program is interrupted midway, it cannot be restored to normal operations. It is preferable to disable the operation of the IG switch 42 by the user after the rewriting of the application program of the single-sided separate memory ECU has started and before the rewriting of the application program is completed.

[0419] If the single-sided suspended memory ECU finishes writing the write data and completes the rewriting of the application program, it ends the installation phase in the boot process and transfers from the boot process to waiting for activation. That is, the single-sided suspended memory ECU does not start on the newly rewritten surface (B surface) of the application program at the time when the activation phase has not been performed, and keeps starting on the old surface (A surface). If the single-sided separate memory ECU finishes writing the write data and completes the rewriting of the application program, it ends the installation phase in the boot process and becomes waiting for activation (t12).

[0420] If the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation instruction from the CGW 13, the dual-sided memory ECU and the single-sided suspended memory ECU respectively perform the switching from the old side to the new side, start on the new side, and start the post-programming phase (hereinafter, also referred to as the activation phase) during the startup on the new side. The single-sided independent memory ECU starts a restart and starts the activation phase (t13, t14) during the restart after the installation is completed. During the activation, confirmation of correct startup with the new program, notification of the version information to the CGW 13, etc. are performed.

[0421] If the activation is completed and the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation completion instruction from the CGW 13, the DCM 12 transfers from the data transmission / central communication operation to the sleep / stop operation and starts the sleep / stop operation. The CGW 13 transfers from the reprogramming active operation to the sleep / stop operation and starts the sleep / stop operation. The dual-sided memory ECU, the single-sided suspended memory ECU, and the single-sided independent memory ECU respectively transfer from the startup on the new side to the sleep / stop operation (t15).

[0422] After that, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the dual-sided memory ECU and the single-sided suspended memory ECU respectively use the new side (B side) as the startup side and start a new application program, and the single-sided independent memory ECU starts a new application program (t16).

[0423] (2) Case of rewriting the application program by power self-holding

[0424] Refer to Figure 28 and Figure 29 The case of rewriting the application program by power self-holding will be described. The rewriting of the application program by power self-holding refers to a configuration that controls the rewriting operation using a power self-holding circuit. If the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the DCM 12, the CGW 13, the dual-sided memory ECU, the single-sided suspended memory ECU, and the single-sided independent memory ECU respectively start the normal operation (t21).

[0425] If it is notified from the central device 3 that the download has started, that is, it is notified of an update based on a new program, the DCM 12 transfers from the normal operation to the download operation and starts downloading the distribution data packet from the central device 3 (t22). If the DCM 12 completes downloading the distribution data packet from the central device 3, it resumes from the download operation to the normal operation (t23).

[0426] If notified of a rewrite instruction signal (installation instruction signal) from the central device 3 or the CGW 13, the DCM 12 transfers from the normal operation to the data transmission / central communication operation and starts the data transmission / central communication operation (t24). That is, the DCM 12 extracts the write data from the distributed data packet, starts transmitting the write data to the CGW 13, and obtains the progress of the rewrite from the CGW 13, and starts notifying the central device 3 of the progress of the rewrite.

[0427] When the CGW 13 starts obtaining the write data from the DCM 12, it transfers from the normal operation to the recompilation active operation, starts the recompilation active operation, starts distributing the write data to the dual-sided memory ECU, and instructs the writing of the write data. When the dual-sided memory ECU starts receiving the write data from the CGW 13, it starts the programming phase (hereinafter, also referred to as the installation phase) in the normal operation. That is, the dual-sided memory ECU installs the application program in the background while performing the normal operation. The dual-sided memory ECU starts writing the received write data to the flash memory and starts rewriting the application program.

[0428] During the period of rewriting the application program in the dual-sided memory ECU, if the vehicle power supply is switched from the IG power supply to the +B power supply by the user switching the IG switch from on to off (t25), then immediately after the vehicle power supply is switched from the IG power supply to the +B power supply, the DCM 12 continues the data transmission / central communication operation, the CGW 13 continues the recompilation active operation, the dual-sided memory ECU continues the installation phase, and continues rewriting the application program. If a preset time, that is, the self-holding period, has elapsed since the vehicle power supply was switched from the IG power supply to the +B power supply, the DCM 12 interrupts the data transmission / central communication operation, the CGW 13 interrupts the recompilation active operation, the dual-sided memory ECU interrupts the installation phase, and interrupts the rewriting of the application program (t26). That is, before the specified time has elapsed since the IG switch 42 was turned off, the installation is continued by the power supply from the vehicle battery 40.

[0429] After that, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the DCM12 starts the data transmission / center communication operation again, the CGW13 starts the reprogramming operation again, the dual-sided memory ECU starts the installation phase again, and the rewriting of the application program starts again (t27). That is, when the user switches the IG switch from ON to OFF and the vehicle power supply is switched from the IG power supply to the +B power supply, and then the user switches the IG switch from OFF to ON and the vehicle power supply is switched from the +B power supply to the IG power supply, every time an open circuit occurs, the dual-sided memory ECU repeats the interruption and restart of the rewriting of the application program (t28 to t30). However, before the self-holding period elapses after the vehicle power supply is switched from the IG power supply to the +B power supply, the DCM12 continues the data transmission / center communication operation, the CGW13 continues the reprogramming operation, the dual-sided memory ECU continues the installation phase, and the rewriting of the application program continues.

[0430] If the dual-sided memory ECU finishes writing the write data and finishes rewriting the application program, it ends the installation phase and transfers from the normal operation to waiting for activation. That is, when the activation phase is not performed, the dual-sided memory ECU does not start on the new side (B side) where the application program has been rewritten, and keeps starting on the old side (A side) (t31).

[0431] If the user switches the IG switch from ON to OFF and the vehicle power supply is switched from the IG power supply to the +B power supply, and at this time the rewriting of the application program is completed in the dual-sided memory ECU, the single-sided suspended memory ECU and the single-sided independent memory ECU respectively transfer from the normal operation to the boot process, start the boot process, and start the installation phase in the boot process (t32).

[0432] If the single-sided suspended memory ECU and the independent memory ECU respectively finish writing the write data and finish rewriting the application program, they end the installation phase in the boot process (t33). If the power-on request is sent from the CGW13 to the power management ECU20 and the vehicle power supply is switched from the +B power supply to the IG power supply, the DCM12 starts the data transmission / center communication operation again (t34).

[0433] If the single-sided suspended memory ECU finishes writing the write data and finishes rewriting the application program, it transfers from the boot process to waiting for activation. That is, when the activation phase is not performed, the single-sided suspended memory ECU does not start on the new side (B side) where the application program has been rewritten, and keeps starting on the old side (A side). If the single-sided independent memory ECU finishes writing the write data and finishes rewriting the application program, it ends the installation phase in the boot process and becomes waiting for activation (t35).

[0434] If the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation instruction from the CGW 13, the dual-sided memory ECU and the single-sided suspended memory ECU respectively perform the switching from the old side to the new side, start on the new side, and start the activation phase during the startup on the new side. The single-sided independent memory ECU starts a restart and starts the activation phase (t36, t37) during the restart after the installation is completed.

[0435] If the activation is completed and the power management ECU 20 switches the vehicle power supply from the IG power supply to the +B power supply according to the activation completion instruction from the CGW 13, the DCM 12 transfers from the data transmission / central communication operation to the sleep / stop operation and starts the sleep / stop operation. The CGW 13 transfers from the reprogramming active operation to the sleep / stop operation and starts the sleep / stop operation. The dual-sided memory ECU, the single-sided suspended memory ECU, and the single-sided independent memory ECU respectively transfer from the startup on the new side to the sleep / stop operation (t38).

[0436] After that, if the vehicle power supply is switched from the +B power supply to the IG power supply by the user switching the IG switch from OFF to ON, the dual-sided memory ECU and the single-sided suspended memory ECU respectively use the new side (B side) as the startup side and start a new application program, and the single-sided independent memory ECU starts a new application program (t39).

[0437] Before downloading the distribution data packet from the central device 3 and before distributing to the ECU 19 which is the rewrite object of the written data, the CGW 13 performs the following checks. Before downloading the distribution data packet from the central device 3, the CGW 13 checks the radio wave environment, the battery margin of the vehicle battery 40, and the memory capacity of the DCM 12 to enable normal downloading. Before distributing to the ECU 19 which is the rewrite object of the written data, as a check of the manned environment to prevent the installation environment from being unstable, the CGW 13 detects intrusion sensors, vehicle locks, curtains, and IG disconnection. As a check of whether the rewrite object ECU 19 can be written, the CGW 13 checks the version and occurrence of abnormalities to enable normal distribution of the written data. In addition, as a check of the written data distributed to the rewrite object ECU 19, before starting the installation, the CGW 13 performs tampering checks, access authentication, version checks, etc. During the execution of the installation, the CGW 13 performs communication interruption checks, occurrence of abnormality checks, etc. After the installation is completed, the CGW 13 performs version checks, integrity checks, DTC (Diagnostic Trouble Code) checks, etc.

[0438] Next, refer to Figures 30 to 46 Describe the screen displayed on the display terminal 5. As Figure 30As shown, in the configuration for rewriting the application program of the ECU 19 to be rewritten via OTA, there are stages of activity notification, download, installation, and activation. Activity notification refers to the notification of program update. For example, receiving the judgment in the central device 3 that there is an update of the application program, and the main device 11 downloading and distributing specification data, etc. are activity notifications. The display terminal 5 displays screens in each stage as the rewriting of the application program progresses. In addition, here, the screen displayed on the in-vehicle display 7 will be described.

[0439] As Figure 31 shown, in the normal state before the activity notification, the CGW 13, for example, causes a navigation screen 501 such as a well-known route guidance screen which is one of the navigation functions to be displayed on the in-vehicle display 7. If an activity notification occurs from this state, as Figure 32 shown, the CGW 13 causes an activity notification icon 501a indicating the occurrence of the activity notification to be displayed at the lower right of the navigation screen 501. By confirming the display of the activity notification icon 501a, the user can grasp the occurrence of the activity notification related to the update of the application program.

[0440] If the user operates the activity notification icon 501a from this state, as Figure 33 shown, the CGW 13 causes the activity notification screen 502 to pop up and be displayed on the navigation screen 501. In addition, the CGW 13 is not limited to causing the activity notification screen 502 to pop up and be displayed, and other display methods can also be adopted. In the activity notification screen 502, the CGW 13, for example, displays a guidance such as "There is an available software update" to notify the user of the occurrence of the activity notification, and causes a "Confirm" button 502a and a "Later" button 502b to be displayed, waiting for the user's operation. In this case, by operating the "Confirm" button 502a, the user can enter the next screen for starting the rewriting of the application program. In addition, when the user operates the "Later" button 502b, the CGW 13 cancels the pop-up display of the activity notification screen 502 and returns to Figure 32 the screen shown with the activity notification icon 501a displayed.

[0441] If the user operates the "Confirm" button 502a from this state, as Figure 34As shown, CGW13 will switch the display from the navigation screen 501 to the download consent screen 503, and cause the download consent screen 503 to be displayed on the in-vehicle display 7. In the download consent screen 503, CGW13 notifies the user of the activity ID and the update name, and causes the "Download Start" button 503a, the "Detailed Confirmation" button 503b, and the "Return" button 503c to be displayed, waiting for the user's operation. In this case, the user can start the download by operating the "Download Start" button 503a, can display the details of the download by operating the "Detailed Confirmation" button 503b, and can reject the download and return to the previous screen by operating the "Return" button 503c. When the "Return" button 503c is operated and the user operates the activity notification icon 501a, the user can enter the screen for starting the download.

[0442] If the user operates the "Detailed Confirmation" button 503b from the state where the download consent screen 503 is displayed, then as Figure 35 shown, CGW13 switches the display content of the download consent screen 503, and causes the details of the download to be displayed on the in-vehicle display 7. As the details of the download, CGW13 uses the received distribution specification data to display the update content, the update required time, the restrictions on vehicle functions accompanying the update, etc. In addition, if the user operates the "Download Start" button 503a, CGW13 starts the download of the data packet via DCM12. In parallel with starting the download of the data packet, as Figure 36 shown, CGW13 switches the display from the download consent screen 503 to the navigation screen 501, causes the navigation screen 501 to be displayed on the in-vehicle display 7 again, and causes the download in progress icon 501b indicating that the download is in progress to be displayed at the lower right of the navigation screen 501. The user can grasp that the download of the data packet is in progress by confirming the display of the download in progress icon 501b.

[0443] If the user operates the download in progress icon 501b from this state, then as Figure 37 shown, CGW13 switches the display from the navigation screen 501 to the download in progress screen 504, and causes the download in progress screen 504 to be displayed on the in-vehicle display 7. In the download in progress screen 504, CGW13 notifies the user that the download is in progress, and causes the "Detailed Confirmation" button 504a, the "Return" button 504b, and the "Cancel" button 504c to be displayed, waiting for the user's operation. In this case, the user can display the details of the download in progress by operating the "Detailed Confirmation" button 504a, and can interrupt the download by operating the "Cancel" button 504c.

[0444] If CGW13 finishes the download, then as Figure 38As shown, the download completion notification screen 505 pops up and is displayed on the navigation screen 501. In the download completion notification screen 505, CGW13, for example, displays a guidance such as "Download completed. Software update can be performed" to notify the user of the completion of the download, and also displays an "OK" button 505a and a "Later" button 505b, waiting for the user's operation. In this case, by operating the "OK" button 505a, the user can enter the screen for starting the installation.

[0445] If the user operates the "OK" button 505a from this state, then as Figure 39 shown, CGW13 switches the display from the navigation screen 501 to the installation consent screen 506 and makes the installation consent screen 506 displayed on the in-vehicle display 7. In the installation consent screen 506, CGW13 notifies the user of the required time, restrictions, and schedule settings related to the installation, and also displays an "Update Now" button 506a, a "Schedule Update" button 506b, and a "Back" button 506c, waiting for the user's operation. In this case, by operating the "Update Now" button 506a, the user can start the installation immediately. In addition, by setting the time when the user hopes to perform the installation and operating the "Schedule Update" button 506b, the user can start the installation in a scheduled manner. In addition, by operating the "Back" button 506c, the user can reject the installation and return to the previous screen. In the case where the "Back" button 506c is operated, and the user operates the download in-progress icon 501b, the user can enter the screen for starting the installation.

[0446] If the user operates the "Update Now" button 506a from this state, then as Figure 40 shown, CGW13 switches the display content of the installation consent screen 506 and makes the details of the installation displayed on the in-vehicle display 7. In the installation consent screen 506 here, CGW13 notifies the user of the main idea of accepting the installation request and starting the installation.

[0447] If CGW13 starts the installation, then as Figure 41 shown, it switches the display from the installation consent screen 506 to the navigation screen 501, makes the navigation screen 501 displayed on the in-vehicle display 7 again, and makes an installation in-progress icon 501c indicating that the installation is in progress displayed at the lower right of the navigation screen 501. By confirming the display of the installation in-progress icon 501c, the user can grasp that the installation is in progress.

[0448] If the user operates the installation in-progress icon 501c from this state, then as Figure 42As shown, CGW13 will switch the display from the navigation screen 501 to the installation in-progress screen 507, and display the installation in-progress screen 507 on the in-vehicle display 7. In the installation in-progress screen 507, CGW13 notifies the user of the progress of the installation. CGW13 can also display, for example, the remaining time required for the installation and the percentage of progress on the installation in-progress screen 507.

[0449] If CGW13 completes the installation, as Figure 43 shown, it will switch the display from the navigation screen 501 to the activation consent screen 508, and display the activation consent screen 508 on the in-vehicle display 7. In the activation consent screen 508, CGW13 notifies the user of the content of the activation, and displays the "Return" button 508a and the "OK" button 508b, waiting for the user's operation. In this case, the user can reject the activation and return to the previous screen by operating the "Return" button 508a. In addition, the user can consent to the activation by operating the "OK" button 508b. Furthermore, when the "Return" button 508a is operated, and the user can enter the screen for performing the activation by operating the installation in-progress icon 501c. In addition, regarding these displays and consents, they can also be omitted without being displayed according to the user's settings and the scenarios of the program.

[0450] If the user turns on the IG power in the state after operating the "OK" button 508b, as Figure 44 shown, CGW13 pops up and displays the activation completion notification screen 509 on the navigation screen 501. In the activation completion notification screen 509, CGW13 notifies the user of the completion of the activation by displaying, for example, a guidance of "Software update completed", and displays the "OK" button 509a and the "Detailed confirmation" button 509b, waiting for the user's operation. In this case, the user can cancel the pop-up display of the activation completion notification screen 509 by operating the "OK" button 509a, and can display the details of the completion of the activation by operating the "Detailed confirmation" button 509b.

[0451] If the user operates the "OK" button 509a from this state, as Figure 45 shown, CGW13 will switch the display from the navigation screen 501 to the confirmation operation screen 510, and display the confirmation operation screen 510 on the in-vehicle display 7. In the confirmation operation screen 510, CGW13 notifies the user of the completion of the activation, and displays the "Detailed confirmation" button 510a and the "OK" button 510b, waiting for the user's operation. In this case, the user can display the details of the completion of the activation by operating the "Detailed confirmation" button 510a.

[0452] If the user operates the "Detailed confirmation" button 510a from this state, as Figure 46As shown, the display content of the CGW13 switching confirmation operation screen 510 causes the details of the activation completion to be displayed in detail on the in-vehicle display 7. CGW13 displays the functions added by the update, the changed functions, etc. as update details, and also displays an "OK" button 510b. CGW13 determines that the user has confirmed the completion of the software update based on the user operating the "OK" button 509a, 510b.

[0453] As described above, the vehicle-side system 4 controls each action stage such as activity notification, download, installation, activation, and update completion, and presents a display matching each action stage to the user. In addition, in the above description, it is configured that CGW13 performs the display control, but it can also be configured that the in-vehicle display 7 receives the action stage and the distribution specification data from CGW13 and performs the display.

[0454] Next, refer to Figures 47 to 233 The characteristic processing performed by the vehicle program rewriting system 1 will be described. The vehicle program rewriting system 1 performs the following characteristic processing.

[0455] (1) Transmission determination processing of distribution data packets

[0456] (2) Download determination processing of distribution data packets

[0457] (3) Transmission determination processing of written data

[0458] (4) Acquisition determination processing of written data

[0459] (5) Instruction determination processing of installation

[0460] (6) Management processing of security access keys

[0461] (7) Verification processing of written data

[0462] (8) Transmission control processing of data storage surface information

[0463] (9) Power management processing of non-overwrite objects

[0464] (10) Transmission control processing of files

[0465] (11) Distribution control processing of written data

[0466] (12) Instruction processing of activation requests

[0467] (13) Execution control processing of activation

[0468] (14) Group management processing of overwrite objects

[0469] (15) Execution control processing of rollback

[0470] (16) Display control process for rewrite progress status

[0471] (17) Matching determination process for differential data

[0472] (18) Execution control process for rewrite

[0473] (19) Session establishment process

[0474] (20) Determination process for retry points

[0475] (21) Synchronization control process for progress status

[0476] (22) Transmission control process for display control information

[0477] (23) Reception control process for display control information

[0478] (24) Screen display control process for progress display

[0479] (25) Report control process for program update

[0480] (26) Execution control process for power self-holding

[0481] (27) Rewrite instruction process for overwrite based on configuration information

[0482] (28) Rewrite instruction process for write-back based on configuration information

[0483] (29) Rewrite instruction process based on a specific pattern

[0484] The central device 3, DCM 12, CGW 13, ECU 19, and in-vehicle display 7 respectively have the following functional modules as components for performing the characteristic processes of the above (1) to (26).

[0485] As Figure 47As shown, the central device 3 has a distribution data packet transmission unit 51. If the distribution data packet transmission unit 51 receives a download request for a distribution data packet from the DCM 12, it transmits the distribution data packet to the DCM 12. As a configuration for performing characteristic processing, in addition to the above configuration, the central device 3 also has a transmission determination unit 52 for distribution data packets, a synchronization control unit 53 for progress status, a transmission control unit 54 for display control information, and a write data selection unit 55 (equivalent to an update data selection unit). If the write data selection unit 55 (equivalent to the update data selection unit) receives data storage surface information from the master device 11, it selects write data suitable for the non-usage surface based on the software version and usage surface determined according to the received data storage surface information. That is, the distribution data packet transmission unit 51 transmits a distribution data packet including the write data selected by the write data selection unit 55 to the DCM 12. The functional modules for performing characteristic processing will be described later.

[0486] As Figure 48 shown, the DCM 12 has a download request transmission unit 61, a distribution data packet download unit 62, a write data extraction unit 63, a write data transmission unit 64, a rewrite specification data extraction unit 65, and a rewrite specification data transmission unit 66. The download request transmission unit 61 transmits a download request for a distribution data packet to the central device 3. The distribution data packet download unit 62 downloads a distribution data packet from the central device 3. If a distribution data packet is downloaded from the central device 3 by the distribution data packet download unit 62, the write data extraction unit 63 extracts write data from the downloaded distribution data packet.

[0487] If write data is extracted from the distribution data packet by the write data extraction unit 63, the write data transmission unit 64 transmits the extracted write data to the CGW 13. If a distribution data packet is downloaded from the central device 3 by the distribution data packet download unit 62, the rewrite specification data extraction unit 65 extracts rewrite specification data from the downloaded distribution data packet. If rewrite specification data is extracted from the distribution data packet by the rewrite specification data extraction unit 56, the rewrite specification data transmission unit 66 transmits the extracted rewrite specification data to the CGW 13. As a configuration for performing characteristic processing, in addition to the above configuration, the DCM 12 also has a download determination unit 67 for distribution data packets and a transmission determination unit 68 for write data. The functional modules for performing characteristic processing will be described later.

[0488] As Figure 49 and Figure 50As shown, CGW13 has a request sending unit 71 for obtaining requests, a write data acquisition unit 72 (equivalent to an update data storage unit), a write data distribution unit 73 (equivalent to an update data distribution unit), a rewrite specification data acquisition unit 74, and a rewrite specification data analysis unit 75. The write data acquisition unit 72 acquires write data from DCM12 when the write data is transmitted from DCM12. When the write data is acquired by the write data acquisition unit 72 and it becomes the distribution timing of the write data, the write data distribution unit 73 distributes the acquired write data to the ECU19 to be rewritten. The rewrite specification data acquisition unit 74 acquires rewrite specification data from DCM12 when the rewrite specification data is transmitted from DCM12. When the rewrite specification data is acquired by the rewrite specification data acquisition unit 74, the rewrite specification data analysis unit 75 analyzes the acquired rewrite specification data.

[0489] As a configuration for performing characteristic processing, in addition to the above configuration, CGW13 also has a write data acquisition determination unit 76, an installation instruction determination unit 77, a security access key management unit 78, a write data verification unit 79, a data storage surface information transmission control unit 80, a power management unit 81 for non-rewrite objects, a file transmission control unit 82, a write data distribution control unit 83, an activation request instruction unit 84, a rewrite object group management unit 85, a rollback execution control unit 86, a rewrite progress status display control unit 87, a progress status synchronization control unit 88, a display control information reception control unit 89, a progress display screen display control unit 90, a program update report control unit 91, a power self-holding execution control unit 92, a rewrite instruction unit 93 for overwrite based on configuration information, a rewrite instruction unit 94 for write-back based on configuration information, and a rewrite instruction unit 95 based on a specific mode. The functional modules for performing characteristic processing will be described later.

[0490] As Figure 51 shown, ECU19 has a write data reception unit 101 and a program rewrite unit 102. The write data reception unit 101 receives write data from CGW13. When the write data is received from CGW13 by the write data reception unit 101, the program rewrite unit 102 writes the received write data to the flash memory to rewrite the application program. As a configuration for performing characteristic processing, in addition to the above configuration, ECU19 also has a differential data matching determination unit 103, a rewrite execution control unit 104, a session establishment unit 105, a retry point determination unit 106, an activation execution control unit 107, and a power self-holding execution control unit 108. The functional modules for performing characteristic processing will be described later.

[0491] As Figure 52As shown in the figure, the in-vehicle display 7 has a reception control unit 111 for distributing specification data. The reception control unit 111 for distributing specification data controls the reception of the distributed specification data.

[0492] Hereinafter, each of the above-mentioned processes (1) to (29) will be described in sequence.

[0493] (1) Transmission determination process of distribution data packet, (2) Download determination process of distribution data packet

[0494] Refer to Figure 53 and Figure 54 The transmission determination process of the distribution data packet in the central device 3 will be described with reference to Figure 55 and Figure 56 The download determination process of the distribution data packet in the main device 11 will be described.

[0495] As Figure 53 shown, the central device 3 has a software information acquisition unit 52a, an update presence / absence determination unit 52b, an update suitability determination unit 52c, and an activity information transmission unit 52d in the transmission determination unit 52 of the distribution data packet. The software information acquisition unit 52a acquires the software information of each ECU 19 from the vehicle side. Specifically, the software information acquisition unit 52a acquires the ECU structure information including software information such as version and writing surface and hardware information from the vehicle side. The software information acquisition unit 52a may also acquire vehicle state information such as fault codes, setting of anti-theft alarm function, and license agreement information from the vehicle side together with these ECU structure information.

[0496] If the software information is acquired by the software information acquisition unit 52a, the update presence / absence determination unit 52b determines whether there is update data for the vehicle based on the acquired software information. That is, the update presence / absence determination unit 52b compares the version of the acquired software information with the version of the latest software information managed by itself, determines whether the two are the same, and determines whether there is update data for the vehicle. If the update presence / absence determination unit 52b determines that the two are the same, it determines that there is no update data for the vehicle, and if it determines that the two are different, it determines that there is update data for the vehicle.

[0497] If the update presence / absence determination unit 52b determines that there is update data for the vehicle, the update suitability determination unit 52c determines whether the vehicle state is a state suitable for updating a program such as a distribution data packet. Specifically, the update suitability determination unit 52c determines whether the license agreement is established, whether the vehicle position is within a specified range pre-registered by the user, whether the setting of the vehicle's alarm function is validated, and whether there is a fault message in the ECU 19, and determines whether the vehicle state is a state suitable for downloading the distribution data packet. That is, the update suitability determination unit 52c determines whether the vehicle has a possibility of an update that violates the user's intention, and whether the vehicle has a possibility of failure during installation after downloading even if the download is successful.

[0498] If the update suitability determination unit 52c determines that the license agreement is established, the vehicle position is within the specified range pre-registered by the user, the setting of the vehicle's alarm function is validated, and there is no fault message in the ECU 19, it determines that the vehicle state is a state suitable for updating a program such as a distribution data packet. If the update suitability determination unit 52c determines that at least one of the license agreement is not established, the vehicle position is not within the specified range pre-registered by the user, the setting of the vehicle's alarm function is not validated, and there is a fault message in the ECU 19, it determines that the vehicle state is not a state suitable for updating a program such as a distribution data packet.

[0499] If the update suitability determination unit 52c determines that the vehicle state is a state suitable for updating a program such as a distribution data packet, the activity information transmission unit 52d transmits the activity information to the main device 11. If the update suitability determination unit 52c determines that the vehicle state is not a state suitable for updating a program such as a distribution data packet, the activity information transmission unit 52d does not transmit the activity information to the main device 11. By making the above determination, the activity information transmission unit 52d pre-stores information related to the vehicle for which the activity information is not transmitted to the main device 11. In addition, the information related to the vehicle for which the activity information is not transmitted to the main device 11 can also be displayed on the central device 3.

[0500] Next, refer to Figure 54 The operation of the distribution data packet transmission determination unit 52 in the central device 3 will be described. The central device 3 executes a distribution data packet transmission determination program and performs a distribution data packet transmission determination process.

[0501] If the central device 3 starts the transmission determination process of the distribution data packet, it acquires software information from the vehicle side (S101, equivalent to the software information acquisition step). That is, the central device 3 determines whether there is a software update for the vehicle. The central device 3 determines whether there is update data for the vehicle based on the acquired software information (S102, equivalent to the update presence / absence determination step). If the central device 3 determines that there is update data for the vehicle (S102: Yes), it determines whether the vehicle state is a state suitable for updating programs, etc., using the distribution data packet (S103, equivalent to the update suitability determination step). If the central device 3 determines that the vehicle state is a state suitable for updating programs, etc., using the distribution data packet (S103: Yes), it sends activity information to the main device 11 (S104, equivalent to the activity information sending step) and ends the transmission determination process of the distribution data packet.

[0502] If the central device 3 determines that there is no update data for the vehicle (S102: No), it sends the gist that the distribution data packet is not a transmission target, that is, the gist that there is no application program update, to the main device 11 (S105) and ends the transmission determination process of the distribution data packet. If the central device 3 determines that the vehicle state is not a state suitable for updating programs, etc., using the distribution data packet (S103: No), it sends the gist that the program, etc., is not suitable for update and the reason thereto to the main device 11 (S106) and ends the transmission determination process of the distribution data packet. In this case, the main device 11 displays the gist that the program, etc., is not suitable for update and the reason thereto on the in-vehicle display 7. For example, if the license agreement is not established, the main device 11 displays, for example, "The program cannot be updated due to invalid license. Please consult the dealer." etc. on the in-vehicle display 7. Thus, the reason for the gist that the program, etc., is not suitable for update can be presented to the user, and appropriate information can be presented to the user.

[0503] As described above, the central device 3 can determine whether it is a state suitable for updating programs, etc., using the distribution data packet by performing the transmission determination process of the distribution data packet before sending the distribution data packet to the main device 11 and before sending the activity information. Moreover, the central device 3 can send the activity information to the main device 11 in order to send the distribution data packet to the main device 11 only when it determines that it is a state suitable for updating programs, etc., using the distribution data packet.

[0504] In the case of an update of a program or the like suitable for using a distribution data packet, when a license agreement is established, the vehicle position is within a specified range pre-registered by the user, the setting of the vehicle's alarm function is validated, and no fault information of the ECU 19 is generated, the central device 3 can send activity information to the main device 11. That is, the central device 3 can avoid the situation of sending activity information to the main device 11 when the license agreement is not established, or the vehicle position is outside the specified range such as a position far from home, or the setting of the vehicle's alarm function is invalidated, or fault information of the ECU 19 is generated. In this way, for vehicles that may have an update contrary to the user's intention and vehicles that may fail during installation even if the download is successful, the central device 3 can prevent the activity information from being sent to the main device 11.

[0505] In addition, the central device 3 may perform a transmission determination process for the distribution data packet during the transmission of the distribution data packet. In this case, if the central device 3 determines during the transmission of the distribution data packet that the vehicle state is a state suitable for updating a program or the like using the distribution data packet, it continues to transmit the distribution data packet. However, if it determines during the transmission of the distribution data packet that the vehicle state is not a state suitable for updating a program or the like using the distribution data packet, it interrupts the transmission of the distribution data packet. That is, if fault information of the ECU 19 is generated, for example, during the transmission of the distribution data packet, the central device 3 interrupts the transmission of the distribution data packet.

[0506] Next, the processing of the main device 11 that receives the activity information sent from the central device 3 will be described. Refer to Figure 55 and Figure 56 The download determination process for the distribution data packet in the main device 11 will be described. The vehicle program rewriting system 1 performs the download determination process for the distribution data packet in the main device 11. The above-mentioned (1) transmission determination process for the distribution data packet is a determination process performed by the central device 3 at the activity notification stage before the download stage, but the download determination process for the distribution data packet is a determination process performed by the main device 11 at the download stage. In addition, in the present embodiment, the case where the DCM 12 performs the download determination process for the distribution data packet in the main device 11 will be described, but the CGW 13 may have the function of the DCM 12, so that the CGW 13 performs the download determination process for the distribution data packet.

[0507] As Figure 55 shown, the DCM 12 has an activity information receiving unit 67a, a downloadable determination unit 67b, and a download execution unit 67c in the download determination unit 67 for the distribution data packet. The activity information receiving unit 67a receives the activity information from the central device 3. In addition, if the activity information is received from the central device 3, it displays Figure 32The activity notification icon 501a shown. When the activity information receiving unit 67a receives the activity information, the downloadable determination unit 67b determines whether the vehicle state is a state in which a distribution data packet can be downloaded. That is, the downloadable determination unit 67b determines whether the radio wave environment for communicating with the center device 3 is good, whether the remaining battery capacity of the vehicle battery 40 is equal to or greater than a specified capacity, and whether the free memory capacity of the DCM 12 is equal to or greater than a specified capacity, and determines whether the vehicle state is a state in which a distribution data packet can be downloaded.

[0508] If the downloadable determination unit 67b determines that the radio wave environment is good, the remaining battery capacity of the vehicle battery 40 is equal to or greater than a specified capacity, and the free memory capacity of the DCM 12 is equal to or greater than a specified capacity, it determines that the vehicle state is a state in which a distribution data packet can be downloaded. If the downloadable determination unit 67b determines that at least any one of the radio wave environment is not good, the remaining battery capacity of the vehicle battery 40 is not equal to or greater than a specified capacity, and the free memory capacity of the DCM 12 is not equal to or greater than a specified capacity, it determines that the vehicle state is not a state in which a distribution data packet can be downloaded.

[0509] In this way, the downloadable determination unit 67b determines whether there is a possibility that the download cannot be completed normally. In addition, it is determined by the downloadable determination unit 67b on the condition that the "download start" button 503a is operated by the user in the download consent screen 503 shown in Figure 34 and Figure 35 shown. In addition, the downloadable determination unit 67b may also be configured to determine the determination items in the center device 3. That is, the downloadable determination unit 67b determines that it is in a downloadable state, for example, when the setting of the vehicle's alarm function is validated and no fault information of the ECU 19 is generated.

[0510] If the downloadable determination unit 67b determines that the vehicle state is a state in which a distribution data packet can be downloaded, the download execution unit 67c downloads the distribution data packet from the center device 3. That is, the download execution unit 67c executes the download of the distribution data packet after confirming that the download can be completed normally.

[0511] If the downloadable determination unit 67b determines that the vehicle state is not a state in which a distribution data packet can be downloaded, the download execution unit 67c does not download the distribution data packet from the center device 3. That is, the download execution unit 67c does not execute the download of the distribution data packet when there is a possibility that the download cannot be completed normally. In this case, the download execution unit 67c instructs the in-vehicle display 7 to display a pop-up screen indicating the gist and reason for not being able to start the download on the navigation screen 501.

[0512] Next, referring to Figure 56The function of the download determination unit 67 for distributing data packets in the main device 11 will be described. The main device 11 executes a download determination program for distributing data packets and performs a download determination process for distributing data packets.

[0513] When the main device 11 starts the download determination process for distributing data packets, it receives activity information from the central device 3 (S201, corresponding to the activity information reception step). The main device 11 determines whether the vehicle state is a state in which the distribution data packet can be downloaded (S202, corresponding to the downloadable determination step). If the main device 11 determines that the vehicle state is a state in which the distribution data packet can be downloaded (S202: Yes), it downloads the distribution data packet corresponding to the activity from the central device 3 (S203, corresponding to the download execution step) and ends the download determination process for distributing data packets. If the main device 11 determines that the vehicle state is not a state in which the distribution data packet can be downloaded (S202: No), it does not download the distribution data packet from the central device 3 and ends the download determination process for distributing data packets.

[0514] As described above, the main device 11 can determine whether the vehicle state is a state in which the distribution data packet can be downloaded by performing a download determination process for distributing data packets before downloading the distribution data packet from the central device 3. Moreover, the main device 11 can download the distribution data packet only when the vehicle state is a state in which the distribution data packet can be downloaded.

[0515] In a case suitable for downloading the distribution data packet, when the radio wave environment is good, the battery remaining capacity of the vehicle battery 40 is equal to or greater than a specified capacity, and the free capacity of the memory of the DCM 12 is equal to or greater than a specified capacity, the main device 11 can download the distribution data packet from the central device 3. That is, it is possible to avoid the situation of downloading the distribution data packet from the central device 3 when the radio wave environment is not good, or the battery remaining capacity of the vehicle battery 40 is less than the specified capacity, or the free capacity of the memory of the DCM 12 is less than the specified capacity.

[0516] In addition, the main device 11 may perform a download determination process for distributing data packets during the download of the distribution data packet. In this case, if the main device 11 determines during the download of the distribution data packet that the vehicle state is a state in which the distribution data packet can be downloaded, it continues to download the distribution data packet from the central device 3, but if it determines during the download of the distribution data packet that the vehicle state is not a state in which the distribution data packet can be downloaded, it interrupts the download of the distribution data packet from the central device 3. That is, if, for example, the radio wave environment is not good, or the battery remaining capacity of the vehicle battery 40 is less than the specified capacity, or the free capacity of the memory of the DCM 12 is less than the specified capacity during the download of the distribution data packet, the main device 11 interrupts the download of the distribution data packet.

[0517] In this way, by determining in the central device 3 whether there is a vehicle with a possibility of an update that violates the user's intention or a vehicle with a possibility of installation failure, and determining in the main device 11 whether there is a possibility of download failure, it is possible to suppress the transmission of useless activity information or distribution data packets from the central device 3 to the main device 11.

[0518] The central device 3 has the following configuration. It includes: a software information acquisition unit 52a that acquires software information of an electronic control device from the vehicle side; an update presence determination unit 52b that determines whether there is update data for the vehicle based on the software information acquired by the software information acquisition unit; an update suitability determination unit 52c that determines whether the vehicle state is a state suitable for update when the update presence determination unit determines that there is update data; and an activity information transmission unit 52d that transmits activity information related to the update to the vehicle main device when the update suitability determination unit determines that the vehicle state is a state suitable for update.

[0519] The main device 11 has the following configuration. It includes: an activity information reception unit 67a that receives activity information from the central device; a downloadable determination unit 67b that determines whether the vehicle state is a state capable of downloading a distribution data packet when the activity information reception unit receives the activity information; and a download execution unit 67c that downloads the distribution data packet from the central device when the downloadable determination unit determines that the vehicle state is a state capable of downloading the distribution data packet.

[0520] (3) Transmission determination process for written data, (4) Acquisition determination process for written data, (5) Instruction determination process for installation

[0521] Refer to Figure 57 And Figure 58 For the description of the transmission determination process for written data, refer to Figure 59 And Figure 60 For the description of the acquisition determination process for written data, refer to Figures 61 to 64 The instruction determination process for installation is described. The vehicle program rewriting system 1 performs the transmission determination process for written data in the DCM 12. Here, it is assumed that the distribution data packet transmitted from the central device 3 to the DCM 12 is unpacked, and the state where the written data is extracted from the distribution data packet.

[0522] As Figure 57As shown, DCM12 has an acquisition request receiving unit 68a and a communication state determination unit 68b in the write data transmission determination unit 68. The acquisition request receiving unit 68a receives an acquisition request for write data from CGW13. If the acquisition request receiving unit 68a receives an acquisition request for write data, the communication state determination unit 68b determines the state of data communication between the central device 3 and DCM12, for example, when the transmission permission determination flag preset by the user is the first specified value. The transmission permission determination flag is, for example, 1 (the first specified value) when specified conditions are checked during installation, and 0 (the second specified value) when the check is omitted. The write data transmission unit 64 transmits the write data to CGW13 on the condition that the communication state determination unit 68b determines that the data communication between the central device 3 and DCM12 is in a connected state.

[0523] Next, refer to Figure 58 The operation of the write data transmission determination unit 68 in DCM12 will be described. DCM12 executes a write data transmission determination program to perform write data transmission determination processing. Here, the processing in the case where CGW13 requests to acquire write data from DCM12 according to an installation instruction from the central device 3 will be described.

[0524] If DCM12 determines that it has received an acquisition request for write data from CGW13, it starts the write data transmission determination processing. If DCM12 starts the write data transmission determination processing, it determines the transmission permission determination flag (S301, S302). If DCM12 determines that the transmission permission determination flag is the first specified value (S301: Yes), it determines the state of data communication between the central device 3 and itself (S303). If DCM12 determines that the data communication between the central device 3 and itself is in a connected state (S303: Yes), it transmits the write data to CGW13 (S304) and ends the write data transmission determination processing. If DCM12 determines that the data communication between the central device 3 and itself is not in a connected state but in an interrupted state (S303: No), it does not transmit the write data to CGW13 and ends the write data transmission determination processing.

[0525] In addition, if DCM12 determines that the transmission permission determination flag is the second specified value (S302: Yes), it transmits the write data to CGW13 without determining the state of data communication between the central device 3 and itself and ends the write data transmission determination processing.

[0526] As described above, DCM12 determines the state of data communication between the central device 3 and itself when the transmission enable / disable determination flag is the first specified value by performing a transmission determination process for write data before transmitting the write data to CGW13. If DCM12 determines that the data communication is in a connected state, it starts transmitting the write data. If it determines that the data communication is in an interrupted state, it does not start transmitting the write data and stands by. In a situation where data communication with the central device 3 can be performed, the write data can be transmitted to CGW13 and installation can be executed in the ECU 19 to be rewritten.

[0527] For example, when there are multiple ECUs 19 to be rewritten and the installation takes time, the progress of the installation can be notified from the in-vehicle side system 4 to the central device 3, and the progress can be displayed one by one on the mobile terminal 6. In addition, DCM12 can also perform a transmission determination process for write data during the transmission of the write data. In this case, if DCM12 determines that the data communication is in a connected state during the transmission of the write data, it continues to transmit the write data. However, if it determines that the data communication is in an interrupted state during the transmission of the write data, it interrupts the transmission of the write data.

[0528] Next, the acquisition determination process for write data will be described. The vehicle program rewriting system 1 performs an acquisition determination process for write data in CGW13. The above-mentioned (3) transmission determination process for write data is a determination process performed by DCM12 in the installation stage, and the acquisition determination process for write data is a determination process performed by CGW13 in the same installation stage.

[0529] As Figure 59 shown, CGW13 has an event generation determination unit 76a and a communication state determination unit 76b in the write data acquisition determination unit 76. The event generation determination unit 76a determines the generation of an event of a write data acquisition request (installation instruction) from the central device 3. If the event generation determination unit 76a determines that the event of the write data acquisition request has occurred, the communication state determination unit 76b determines the state of data communication between the central device 3 and DCM12, for example, when the acquisition enable / disable determination flag preset by the user is the first specified value. The acquisition enable / disable determination flag is 1 (the first specified value) when specified conditions are checked during installation, and 0 (the second specified value) when the check is omitted. Here, the event generation determination unit 76a can also determine the event generation based on the user indicating installation. For example, if it receives a notification that the user has performed an installation instruction operation through the in-vehicle display 7 (refer to Figure 39 ), it determines that the event of the write data acquisition request has occurred.

[0530] Next, refer to Figure 60The function of the write data acquisition determination unit 76 in the CGW13 will be described. The CGW13 executes a write data acquisition determination program to perform write data acquisition determination processing.

[0531] If the CGW13 determines that an event of a write data acquisition request has occurred, it starts the write data acquisition determination processing. If the CGW13 starts the write data acquisition determination processing, it determines the acquisition permission determination flag (S401, S402). If the CGW13 determines that the acquisition permission determination flag is the first specified value (S401: Yes), it determines the data communication state between the central device 3 and the DCM12 (S403). If the CGW13 determines that the data communication between the central device 3 and the DCM12 is connected (S403: Yes), it sends a write data acquisition request to the DCM12 (S404) and ends the write data acquisition determination processing. After that, if the CGW13 receives write data transmitted from the DCM12, it distributes the transmitted write data to the ECU19 to be rewritten. If the CGW13 determines that the data communication between the central device 3 and the DCM12 is not connected but interrupted (S403: No), it does not send a write data acquisition request to the DCM12 and ends the write data acquisition determination processing.

[0532] In addition, if the CGW13 determines that the acquisition permission determination flag is the second specified value (S402: Yes), it sends a write data acquisition request to the DCM12 without determining the data communication state between the central device 3 and the DCM12 and ends the write data acquisition determination processing.

[0533] As described above, the CGW13 performs write data acquisition determination processing before acquiring write data from the DCM12 to determine the data communication state between the central device 3 and the DCM12 when the acquisition permission determination flag is the first specified value. If the CGW13 determines that the data communication is in a connected state, it starts acquiring write data. If it determines that the data communication is in an interrupted state, it does not start acquiring write data and waits. In a situation where communication with the central device 3 is possible, write data can be acquired from the DCM12 and installation can be executed in the ECU19 to be rewritten.

[0534] For example, when there are multiple ECUs19 to be rewritten and the installation takes time, the progress of the installation can be notified from the in-vehicle side system 4 to the central device 3, and the progress can be displayed one by one on the mobile terminal 6. In addition, the CGW13 can also perform write data acquisition determination processing during the acquisition of write data. In this case, if it is determined that the data communication is in a connected state during the acquisition of write data, the CGW13 continues to acquire write data. However, if it is determined that the data communication is in an interrupted state during the acquisition of write data, the CGW13 interrupts the acquisition of write data.

[0535] Next, the acquisition determination of the write data described above will be explained in more detail. The acquisition of the write data is one of the processes related to installation. Here, refer to Figures 61 to 64 the instruction determination process for installation. The vehicle program rewrite system 1 performs an instruction determination process for installation in the CGW 13. The above (1) transmission determination process of the distribution data packet, (2) download determination process of the distribution data packet are determination processes performed in the download stage, (3) transmission determination process of the write data, (4) acquisition determination process of the write data are processes performed in the installation stage after the download is completed, and (5) instruction determination process for installation is a process performed in the installation stage and the activation stage. Here, it is assumed that the distribution data packet is downloaded to the DCM 12, and as Figure 10 shown, the write data (update data, differential data) to the write target ECU 19 is in an unpacked state.

[0536] As Figure 61 shown, the CGW 13 has an installation condition determination unit 77a, an installation instruction unit 77b, a vehicle state information acquisition unit 77c, an activation condition determination unit 77d, and an activation instruction unit 77e in the installation instruction determination unit 77. The installation condition determination unit 77a determines whether the first condition, the second condition, the third condition, the fourth condition, and the fifth condition are satisfied. The first condition is a condition that user consent related to installation has been obtained. User consent related to installation means, for example, the user's consent operation for installation (such as pressing the "Update Now" button 506a) in the Figure 39 shown screen. Alternatively, it is also possible to regard the process from download to activation as one update, and use the user's consent operation for the update as such.

[0537] The second condition is a condition that the CGW 13 can communicate with the central device 3. The third condition is a condition that the vehicle state is capable of installation. The fourth condition is a condition that the rewrite target ECU 19 is capable of installation. Here, the fourth condition includes not only that the rewrite target ECU 19 as the installation target is capable of installation, but also that the rewrite target ECU 19 that cooperates with the rewrite target ECU 19 as the installation target is also capable of installation. The fifth condition is a condition that the write data is normal data. Here, normal data includes data suitable for the rewrite target ECU 19, data that has not been tampered with, etc.

[0538] If the installation condition determination unit 77a determines that all of the first condition, the second condition, the third condition, the fourth condition, and the fifth condition are satisfied, the installation instruction unit 77b instructs the ECU 19 to be rewritten to install the application program. That is, if the installation condition determination unit 77a determines that user consent related to installation has been obtained, the CGW 13 can communicate with the central device 3, the vehicle state is in a state where installation is possible, the ECU 19 to be rewritten is in a state where installation is possible, and the written data is normal data, the installation instruction unit 77b instructs the ECU 19 to be rewritten to install the application program. Specifically, the installation instruction unit 77b acquires the written data from the DCM 12 and transmits the acquired written data to the ECU 19 to be rewritten. If the installation condition determination unit 77a determines that at least any one of the first condition, the second condition, the third condition, the fourth condition, and the fifth condition is not satisfied, the installation instruction unit 77b waits without instructing the ECU 19 to be rewritten to install the application program, or notifies the user of the gist and reason why installation cannot be started.

[0539] The vehicle state information acquisition unit 77c acquires vehicle state information from the central device 3. The activation condition determination unit 77d determines whether the sixth condition, the seventh condition, and the eighth condition are satisfied when the installation of the application program has been completed in all of the ECUs 19 to be rewritten. The sixth condition is a condition that user consent related to activation has been obtained. User consent related to activation means, for example, a user's consent operation for activation (e.g., pressing the "OK" button 508b) on the screen as shown in Figure 43 FIG. Or, it is also possible to regard the period from download to activation as one update and use a user's consent operation for the update. The seventh condition is a condition that the vehicle state is in a state where activation is possible. The eighth condition is a condition that the ECU 19 to be rewritten is in a state where activation is possible.

[0540] If the activation condition determination unit 77d determines that all of the sixth condition, the seventh condition, and the eighth condition are satisfied, the activation instruction unit 77e instructs the ECU 19 to be rewritten to activate the application program. The specific details will be described in the subsequent (12) instruction process for activation requests. That is, if the activation condition determination unit 77d determines that user consent related to activation has been obtained, the vehicle state is in a state where activation is possible, and the ECU 19 to be rewritten is in a state where activation is possible, the activation instruction unit 77e instructs the ECU 19 to be rewritten to activate the application program. By performing activation, the update program written to the ECU 19 to be rewritten becomes valid. If the activation condition determination unit 77d determines that at least any one of the sixth condition, the seventh condition, and the eighth condition is not satisfied, the activation instruction unit 77e waits without instructing the ECU 19 to be rewritten to activate the application program, or notifies the user of the gist and reason why activation cannot be started.

[0541] Next, refer toFigures 62 to 64 The operation of the installation instruction determination unit 77 in the CGW13 will be described. The CGW13 executes an installation instruction determination program and performs installation instruction determination processing.

[0542] When the CGW13 starts the installation instruction determination processing, it determines whether the first condition is satisfied and whether user consent related to the installation has been obtained (S501, which is part of the installation condition determination step). If the CGW13 determines that user consent related to the installation has been obtained (S501: Yes), it determines whether the second condition is satisfied and whether data communication with the central device 3 can be performed (S502, which is part of the installation condition determination step). The CGW13 determines whether data communication with the central device 3 can be performed based on the communication radio wave condition in the DCM12.

[0543] If the CGW13 determines that data communication with the central device 3 can be performed (S502: Yes), it determines whether the third condition is satisfied and whether the vehicle state is suitable for installation (S503, which is part of the installation condition determination step). As the vehicle state, the CGW13 determines, for example, whether the remaining battery capacity of the vehicle battery 40 is equal to or greater than a specified capacity, and whether the vehicle is in a parked state (IG off state) when the memory structure of the ECU 19 to be rewritten is a single-sided memory, etc., to determine whether the vehicle state is suitable for installation. These vehicle state conditions can also be configured to refer to the received rewrite specification data (refer to Figure 8 ). For example, when the remaining battery capacity of the vehicle battery 40 is equal to or greater than the specified capacity specified by the rewrite specification data and matches the vehicle state specified by the rewrite specification data (only parked state allowed, or only driving state allowed, or both parked state and driving state allowed), the CGW13 determines that the vehicle state is suitable for installation.

[0544] If the CGW13 determines that the vehicle state is suitable for installation (S503: Yes), it determines whether the fourth condition is satisfied and whether the ECU 19 to be rewritten is suitable for installation (S504, which is part of the installation condition determination step). For example, when no fault code has occurred in the ECU 19 to be rewritten and the secure access to the ECU 19 to be rewritten is successful, the CGW13 determines that the ECU 19 to be rewritten is suitable for installation. Here, regarding the occurrence of a fault code, in addition to confirming for the ECU 19 to be rewritten for writing the write data, confirmation is also performed for the ECU 19 that collaborates with the ECU 19 to be rewritten. That is, the CGW13 determines whether a fault code has occurred not only for the ECU 19 to be rewritten but also for the ECU 19 that collaborates with the ECU 19 to be rewritten.

[0545] If it is determined that the ECU 19 to be rewritten is installable (S504: Yes), then it is determined whether the fifth condition is satisfied, and it is determined whether the written data is normal data (S505, which is part of the installation condition determination step). The CGW 13 determines that the written data is normal data when the written data matches the writing surface (non-operation surface) of the ECU 19 to be rewritten and the verification result of the integrity of the written data is normal, etc. If the CGW 13 determines that the written data is normal data (S505: Yes), it instructs the ECU 19 to be rewritten to install the application program (S506, which is equivalent to the installation instruction step). In this way, the CGW 13 makes the determination of the second condition and subsequent conditions with the satisfaction of the first condition as the condition. In addition, the CGW 13 finally makes the determination of the fifth condition. If the CGW 13 determines that all of the first to fifth conditions are satisfied, it instructs the ECU 19 to be rewritten to install the application program.

[0546] On the other hand, if the CGW 13 determines that the user consent related to installation has not been obtained (S501: No), determines that data communication with the central device 3 cannot be performed (S502: No), determines that the vehicle state is not installable (S503: No), determines that the ECU 19 to be rewritten is not installable (S504: No), and determines that the written data is not normal data (S505: No), then it does not instruct the ECU 19 to be rewritten to install the application program. In addition, in the above processing, the configuration of determining the user consent related to installation first compared with other conditions has been described, but it can also be a configuration that determines after other conditions.

[0547] If the CGW 13 instructs the ECU 19 to be rewritten to install the application program, it distributes the written data to the ECU 19 to be rewritten (S507) and determines whether the installation is completed (S508). If the CGW 13 determines that the installation is completed (S508: Yes), it determines whether the sixth condition is satisfied, and determines whether the user consent related to activation has been obtained (S509). If the CGW 13 determines that the user consent related to activation has been obtained (S509: Yes), it determines whether the seventh condition is satisfied, and determines whether the vehicle state is an activatable state (S510).

[0548] If the CGW 13 determines that the vehicle state is an activatable state (S510: Yes), it determines whether the eighth condition is satisfied, and determines whether the ECU 19 to be rewritten is an activatable state (S511). If the CGW 13 determines that the ECU 19 to be rewritten is an activatable state (S511: Yes), it instructs the ECU 19 to be rewritten to be activated (S512). In this way, if the CGW 13 determines that all of the sixth to eighth conditions are satisfied, it instructs the ECU 19 to be rewritten to be activated.

[0549] In addition, when there are multiple ECUs 19 to be rewritten, CGW13 can either indicate installation separately and independently or indicate it together. In the case of separately and independently indicating installation when the ECUs 19 to be rewritten are ECU(ID1) and ECU(ID2), as Figure 63 shown, CGW13 determines whether the installation conditions are met for ECU(ID1). If CGW13 determines that the installation conditions are met for ECU(ID1), it indicates installation to ECU(ID1). Next, CGW13 determines whether the installation conditions are met for ECU(ID2). Here, as the installation conditions, CGW13 only needs to determine whether the fourth condition and the fifth condition are met for ECU(ID2). If CGW13 determines that the installation conditions are met for ECU(ID2), it indicates installation to ECU(ID2).

[0550] In the case of indicating installation together when the ECUs 19 to be rewritten are ECU(ID1) and ECU(ID2), as Figure 64 shown, CGW13 determines whether the installation conditions are met for ECU(ID1). That is, CGW13 determines the first to third conditions, and the fourth and fifth conditions regarding ECU(ID1). If CGW13 determines that the installation conditions are met for ECU(ID1), it determines whether the installation conditions are met for ECU(ID2). That is, CGW13 determines the fourth and fifth conditions regarding ECU(ID2). If the installation conditions are met for ECU(ID2), CGW13 indicates installation to ECU(ID1) and ECU(ID2). For example, CGW13 simultaneously and in parallel transmits the rewrite data to ECU(ID1) and transmits the rewrite data to ECU(ID2). In this way, in the case of indicating installation together, CGW13 determines the first to third conditions, and the fourth and fifth conditions regarding all ECUs to be rewritten. Moreover, CGW13 indicates installation after satisfying all these conditions.

[0551] As described above, by performing the installation instruction determination process before indicating installation to the ECU 19 to be rewritten, CGW13 indicates the installation of the application program to the ECU 19 to be rewritten if it determines that all of the first condition of obtaining user consent related to installation, the second condition of being able to communicate with the central device 3, the third condition that the vehicle state is in an installable state, the fourth condition that the ECU 19 to be rewritten is in an installable state, and the fifth condition that the write data is normal data are satisfied. The installation of the application program can be appropriately indicated to the ECU 19 to be rewritten.

[0552] (6) Management process of the security access key

[0553] Refer to Figures 65 to 69The management process of the security access key is described. The security access key is the key for device authentication when the CGW13 accesses and rewrites the target ECU19 before installing the written data. The vehicle program rewriting system 1 performs the management process of the security access key in the CGW13. Here, the description is made on the premise that the CGW13 is in a state where it can obtain the written data from the DCM12 through the above-mentioned (3) transmission determination process of the written data or (4) acquisition determination process of the written data. The device authentication using the security access key corresponds to the fourth condition (step S505) in the above-mentioned (5) installation instruction determination process.

[0554] When the CGW13 distributes the written data to the target ECU19, secure access (device authentication) using the security access key is required between the CGW13 and the target ECU19. In this case, a method is considered in which the CGW13 requests the generation of a random value from the target ECU19, obtains the random value generated by the target ECU19 from the target ECU19, and calculates the obtained random value to generate the security access key. However, in such a method, if the random value is obtained from the target ECU19 even when the application program is not rewritten, the security access key can also be maintained, so there may be a risk of leakage of the security access key.

[0555] In addition, if it is configured to send the random value obtained from the target ECU19 to the central device 3 in the CGW13, and the central device 3 calculates the random value and generates the security access key, the security access key does not need to be maintained, so the risk of leakage of the security access key can be reduced. However, in the configuration where the central device 3 calculates the random value, the standby time until the target ECU19 obtains the random value from the central device 3 is long, and it is difficult to meet the time regulations of the diagnostic communication. Based on such a situation, in the present embodiment, the following configuration is adopted.

[0556] As Figure 65 shown, the supplier encrypts the security access key for each target ECU19 using the encryption / decryption key of the security access key to generate a random value. The random value here includes either a value different from the value used in the past or a value the same as the value used in the past, and means a random value. The random value is the encrypted security access key. The supplier provides the generated random value together with the reprogrammed data. The security access key, the encryption / decryption key of the security access key, and the random value are unique keys for each ECU19.

[0557] If the random value is provided from the supplier together with the reprogrammed data, the OEM establishes a correspondence between the provided random value and the ECU (ID) that identifies the ECU19 and stores it in Figure 8The rewriting specification data for the CGW shown below. In addition, the OEM also stores the key mode and decryption operation mode required for decrypting the random value in the rewriting specification data for the CGW. As the key mode, methods such as shared key / public key and key length are stored. As the decryption operation mode, the type of algorithm used for decryption operation is stored. If the random value, key mode, and decryption operation mode are stored in the rewriting specification data for the CGW, the OEM provides the rewriting specification data for the CGW storing the random value to the central device 3 together with the reprogramming data. The information provided by the supplier is stored in the ECU reprogramming data DB and ECU metadata DB described later.

[0558] If the rewriting specification data (rewriting specification data for the DCM and rewriting specification data for the CGW) is provided from the OEM together with the reprogramming data, the central device 3 sends a distribution data packet including the provided rewriting specification data and reprogramming data to the main device 11. In the main device 11, if the DCM 12 downloads the distribution data packet from the central device 3, it transfers the rewriting specification data and the write data to the CGW 13.

[0559] As Figure 66 shown, the CGW 13 has a security area 78a (equivalent to the decryption key storage unit), a random value extraction unit 78b (equivalent to the key derived value extraction unit), a key mode extraction unit 78c, a decryption operation mode extraction unit 78d, a key generation unit 78e, a secure access execution unit 78f, a session transfer request unit 78g, and a key elimination unit 78h in the security access key management unit 78. Regarding the security area 78a, information cannot be read from the outside of the ECU 19, and the encryption / decryption key of the security access key and the decryption operation algorithm are configured. The random value extraction unit 78b extracts the random value (key derived value) included in the rewriting specification data from the analysis result of the rewriting specification data for the CGW. The random value is an encrypted value corresponding to the ECU (ID) of the ECU 19 to be rewritten.

[0560] The key mode extraction unit 78c extracts the key mode included in the rewriting specification data from the analysis result of the rewriting specification data for the CGW. The decryption operation mode extraction unit 78d extracts the decryption operation mode included in the rewriting specification data from the analysis result of the rewriting specification data for the CGW.

[0561] If the random value extraction unit 78b extracts a random value, the key generation unit 78e searches the secure area 78a and decrypts the extracted random value using the decryption key corresponding to the ECU (ID) from the decryption key bundle of the secure access key configured in the secure area 78a to generate a secure access key. In this case, the key generation unit 78e uses the decryption key determined by the key pattern extracted by the key pattern extraction unit 78c and decrypts the key derivation value according to the decryption operation method determined by the decryption operation pattern extracted by the decryption operation pattern extraction unit 78d. That is, multiple key patterns and multiple decryption operation patterns are prepared, and the key pattern and the decryption operation pattern are specified by the rewriting specification data for the CGW, so that the key generation unit 78e generates a secure access key using the key pattern and the decryption operation pattern.

[0562] If the key generation unit 78e generates a secure access key, the secure access execution unit 78f uses the generated secure access key to perform a secure access to the ECU 19 to be rewritten. Specifically, the secure access execution unit 78f sends, for example, encrypted data obtained by encrypting the ECU (ID) using the secure access key, and requests access to the ECU 19 to be rewritten. If the ECU 19 to be rewritten receives the encrypted data, it decrypts the received encrypted data using the secure access key held by itself. Further, the ECU 19 to be rewritten compares the decrypted data generated by the decryption with its own ECU (ID), and permits access to itself when the two match, and does not permit access to itself when the two do not match.

[0563] The session transfer request unit 78g requests a transfer to the rewrite session. After transferring from the default session to the rewrite session, the secure access execution unit 78f performs a secure access. In addition, it is also possible to perform a secure access after transferring to a session other than the default session (for example, a diagnostic session), and then transfer to the rewrite session. The key elimination unit 78h eliminates the secure access key generated by the key generation unit 78e after the secure access execution unit 78f performs a secure access to the ECU 19 to be rewritten and the rewrite of the application program of the ECU 19 to be rewritten is completed.

[0564] Next, refer to Figures 67 to 69 The operation of the secure access key management unit 78 in the CGW 13 will be described. The CGW 13 executes a secure access key management program and performs secure access key management processing. As the secure access key management processing, the CGW 13 performs secure access key generation processing and secure access key elimination processing. Hereinafter, each processing will be described in turn.

[0565] (6-1) Secure access key generation processing

[0566] If CGW13 starts the generation process of the secure access key, it parses the rewrite specification data obtained from DCM12 (S601, corresponding to the rewrite specification data parsing step), and extracts a random value, a key mode, and a decryption operation mode from the rewrite specification data for CGW (S602, corresponding to the key-derived value extraction step).

[0567] CGW13 searches the secure area 78a, decrypts the random value extracted from the rewrite specification data for CGW using the decryption key pair corresponding to the ECU (ID) from the decryption key bundle of the secure access key configured in the secure area 78a, and generates a secure access key (S603, corresponding to the key generation step).

[0568] As Figure 68 shown, CGW13 generates a secure access key based on the rewrite specification data for CGW. CGW13 makes a session transfer request to the rewrite session capable of writing the write data (S604), performs secure access to the rewrite target ECU19 using the secure access key (S605). If CGW13 finishes the execution of the secure access, it distributes the write data to the rewrite target ECU19 (S606) and makes a session maintenance request (S607). If CGW13 determines that the installation is completed (S608: Yes), it ends the generation process of the secure access key.

[0569] (6-2) Secure access key deletion process

[0570] If CGW13 starts the secure access key deletion process, it determines whether the rewrite of the application program of the rewrite target ECU19 is completed (S611). If CGW13 determines that the rewrite of the application program of the rewrite target ECU19 is completed (S611: Yes), it deletes the secure access key generated by executing the secure access key generation process (S612) and ends the secure access key deletion process.

[0571] As described above, by performing the management process of the secure access key, CGW13 extracts the random value corresponding to the rewrite target ECU19 from the parsing result of the rewrite specification data, decrypts the random value using the decryption key corresponding to the rewrite target ECU19 stored in the secure area 78a, and generates a secure access key. By generating the secure access key in CGW13 without obtaining it from the outside, the risk of leakage of the secure access key can be reduced, and secure access to the rewrite target ECU19 can be appropriately executed.

[0572] In addition, preferably, when there are multiple ECUs 19 to be rewritten, the CGW 13 performs the generation process of the security access key before installing each piece of write data. That is, preferably, when the ECUs 19 to be rewritten are ECU (ID1), ECU (ID2), and ECU (ID3), the CGW 13 performs the generation process of the security access key for ECU (ID1), the installation of the write data to ECU (ID1), the generation process of the security access key for ECU (ID2), the installation of the write data to ECU (ID2), the generation process of the security access key for ECU (ID3), and the installation of the write data to ECU (ID3) in this order. For example, as Figure 63 shown, the CGW 13 performs the security access process as one process for determining whether the installation condition for ECU (ID1) is satisfied. When the access is normally permitted, the CGW 13 instructs the installation for ECU (ID1). Then, the CGW 13 performs the security access process as one process for determining whether the installation condition for ECU (ID2) is satisfied. When the access is normally permitted, the CGW 13 instructs the installation for ECU (ID2).

[0573] In addition, if the ECU 19 to be rewritten permits access to itself through the security access by the CGW 13, the security access is released by receiving the session transfer request from the CGW 13, and the state becomes such that the write data can be written to the flash memory. The session transfer request is, for example, the "rewrite session transfer request" in the second state as Figure 155 shown. If the ECU 19 to be rewritten does not receive the session transfer request from the CGW 13 within a specified time (for example, 5 seconds) from the permission of access to itself, it times out, locks the security access, and does not accept the reception of the session transfer request. When the CGW 13 does not send the session transfer request to the ECU 19 to be rewritten within the specified time from the determination of the permission of access to the ECU 19 to be rewritten, it is necessary to send the session maintenance request to the ECU 19 to be rewritten, keep the ECU 19 to be rewritten from timing out, and send the session transfer request to the ECU 19 to be rewritten.

[0574] In addition, for example, during the rewrite, if the application program of version 1.0 is written to the operation surface and the application program of version 2.0 is written to the non-operation surface by a cancellation operation, and if an activation notice for version 2.0 is generated from this state, it is possible to only perform activation without installation, so the security access process can also be omitted.

[0575] (7) Verification process of write data

[0576] Refer to Figures 70 to 78A description will be given of the verification process for the written data. The vehicle program rewriting system 1 performs the verification process for the written data in the CGW 13. The CGW 13 can perform the verification process for the written data described in the present embodiment either before obtaining the access permission in the management process of the above-mentioned (6) secure access key or after obtaining the access permission.

[0577] As Figure 70 shown, when a supplier or OEM generates written data, a data verification value calculation algorithm is applied to the generated written data to generate a data verification value. Here, the written data can be either a new program to be updated or differential data from an old program to a new program. The supplier or OEM applies encryption using a prescribed key (key value) to the data verification value to generate an authentication symbol, and registers the written data and the authentication symbol in a corresponding relationship in the central device 3. Specifically, these data are stored in the reprogramming data DB described later for each ECU 19. Further, the central device 3 generates a distribution data packet including the written data and the authentication symbol, and stores it in the data packet DB.

[0578] If a download request for a distribution data packet from the host device 11 is generated, the central device 3 sends the distribution data packet including the written data and the authentication symbol to the host device 11 according to the download request. In this case, the written data sent from the central device 3 to the host device 11 is in ciphertext, and the authentication symbol sent from the central device 3 to the host device 11 is also in ciphertext. In addition, the authentication symbol sent from the central device 3 to the host device 11 can also be in plaintext. When the authentication symbol sent from the central device 3 to the host device 11 is in plaintext, the decryption process described later is not required.

[0579] When the host device 11 downloads a distribution data packet from the central device 3, it extracts the written data of the ECU 19 to be rewritten from the downloaded distribution data packet, and verifies the propriety of the written data before distributing the written data to the ECU 19 to be rewritten. That is, the host device 11 sequentially executes a decryption process, a first verification value calculation process, a second verification value calculation process, a comparison process, and a determination process to verify the written data. The decryption process is a process of decrypting the authentication symbol sent in ciphertext. The first verification value calculation process is a process of calculating a first data verification value as an expected value using a key (key value) based on the decrypted authentication symbol. The second verification value calculation process is a process of calculating a second data verification value based on the written data using a data verification value calculation algorithm. The comparison process is a process of comparing the first data verification value and the second data verification value. The determination process is a process of determining the propriety of the written data based on the comparison result of the comparison process.

[0580] As Figure 71As shown, CGW13 has a writable determination unit 79a, a processing execution request unit 79b, a processing result acquisition unit 79c, and a verification unit 79d in the verification unit 79 for writing data. The writable determination unit 79a determines whether data can be written in the ECU 19 to be rewritten. If the writable determination unit 69a determines that data can be written in the ECU 19 to be rewritten, the processing execution request unit 79b notifies the DCM 12 of a processing execution request and requests the execution of processing from the DCM 12. The processing execution request unit 68b notifies the DCM 12 of a processing execution request for at least any one of decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. The processing result acquisition unit 68c acquires the processing result from the DCM 12 by being notified of the processing result from the DCM 12. If the processing result acquisition unit 68c acquires the processing result, the verification unit 79d verifies the written data using the processing result. That is, in the above configuration, CGW13 corresponds to the first device and the first functional unit, and DCM12 corresponds to the second device and the second functional unit.

[0581] Next, refer to Figures 72 to 77 The operation of the verification unit 79 for the written data in CGW13 will be described. CGW13 executes a verification program for the written data and performs verification processing on the written data.

[0582] When CGW13 starts the verification processing of the written data, it notifies the DCM 12 of a processing execution request and requests the execution of processing from the DCM 12 (S701, corresponding to the processing execution request step). CGW13 notifies the DCM 12 of a processing execution request for at least any one of the above decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. When CGW13 acquires the processing result from the DCM 12 (S702, corresponding to the processing result acquisition step), it verifies the written data using the acquired processing result (S703, corresponding to the verification step).

[0583] Hereinafter, several cases where CGW13 notifies the DCM 12 of a processing execution request are exemplified. In Figure 73In the example, CGW13 notifies DCM12 of requests to execute decryption processing, first verification value calculation processing, and second verification value calculation processing. If DCM12 is notified by CGW13 of requests to execute decryption processing, first verification value calculation processing, and second verification value calculation processing, it sequentially executes decryption processing, first verification value calculation processing, and second verification value calculation processing. DCM12 performs processing result notification processing and notifies CGW13 of the first data verification value calculated through the first verification value calculation processing and the second data verification value calculated through the second verification value calculation processing as processing results. If CGW13 performs processing result acquisition processing and obtains the first data verification value and the second data verification value from DCM12, it sequentially executes comparison processing and determination processing using the first data verification value and the second data verification value. CGW13 verifies and writes data according to whether the determination result of the determination processing is positive. In this example, DCM12 holds the key used to calculate the first data verification value.

[0584] In Figure 74 the example, CGW13 notifies DCM12 of requests to execute decryption processing and second verification value calculation processing. If DCM12 is notified by CGW13 of requests to execute decryption processing and second verification value calculation processing, it sequentially executes decryption processing and second verification value calculation processing and notifies CGW13 of the second data verification value calculated through the second verification value calculation processing. If CGW13 performs processing result acquisition processing and obtains the second data verification value from DCM12, it executes first verification value calculation processing and sequentially executes comparison processing and determination processing using the first data verification value calculated through the first verification value calculation processing and the second data verification value. CGW13 verifies and writes data according to whether the determination result of the determination processing is positive. In this example, CGW13 holds the key used to calculate the first data verification value.

[0585] In Figure 75 the example, CGW13 notifies DCM12 of requests to execute decryption processing, first verification value calculation processing, second verification value calculation processing, and comparison processing. If DCM12 is notified by CGW13 of requests to execute decryption processing, first verification value calculation processing, second verification value calculation processing, and comparison processing, it sequentially executes decryption processing, first verification value calculation processing, second verification value calculation processing, and comparison processing. DCM12 performs processing result notification processing and notifies CGW13 of the comparison result of the comparison processing as a processing result. If CGW13 performs processing result acquisition processing and obtains the comparison result from DCM12, it executes determination processing using the comparison result. CGW13 verifies and writes data according to whether the determination result of the determination processing is positive. In this example, DCM12 holds the key used to calculate the first data verification value.

[0586] In Figure 76 the example, CGW13 notifies DCM12 of the processing execution requests for decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. If DCM12 is notified of the processing execution requests for decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing from CGW13, it sequentially executes decryption processing, first verification value calculation processing, second verification value calculation processing, comparison processing, and determination processing. DCM12 executes the processing result notification processing and notifies CGW13 of the determination result of the determination processing as the processing result. If CGW13 executes the processing result acquisition processing and obtains the processing result from DCM12, it verifies and writes data according to whether the determination result indicated by the processing result is positive verification. In this example, DCM12 holds the key for calculating the first data verification value.

[0587] When there are multiple rewrite target ECUs 19, CGW13 performs the verification processing for the write data to the multiple rewrite target ECUs 19 as follows. When there are multiple rewrite target ECUs 19, there are a method of verifying the write data for the multiple rewrite target ECUs 19 together and a method of verifying the write data independently for each.

[0588] In the method of verifying the write data for the multiple rewrite target ECUs 19 together, for example, as Figure 77 shown, CGW13 verifies the write data of ECU (ID1), the write data of ECU (ID2), and the write data of ECU (ID3) together, and distributes the write data distributed to the write target ECU (ID1) of ECU (ID1), the write data distributed to the write target ECU (ID2) of ECU (ID2), and the write data distributed to the write target ECU (ID3) of ECU (ID3). In this case, by verifying the write data for the multiple rewrite target ECUs 19 together, it is possible to shorten the time required from the start of the verification of the write data for the multiple rewrite target ECUs 19 to the completion of the program rewrite. That is, compared with the configuration of verifying the write data for the multiple rewrite target ECUs 19 independently for each, it is possible to shorten the time required from the start of the verification of the write data for the multiple rewrite target ECUs 19 to the completion of the program rewrite.

[0589] In the method of verifying the write data for the multiple rewrite target ECUs 19 independently for each, for example, as Figure 78As shown, CGW13 verifies the written data of ECU (ID1), distributes the written data to the target ECU (ID1) for writing the data written to ECU (ID1), verifies the written data of ECU (ID2), distributes the written data to the target ECU (ID2) for writing the data written to ECU (ID2), verifies the written data of ECU (ID3), and distributes the written data to the target ECU (ID2) for writing the data written to ECU (ID3). In this case, by verifying the written data before distributing the written data, illegal access can be avoided and reliability can be improved. That is, in the configuration where the written data is verified together for multiple target ECUs 19, the time from the completion of verification to the distribution of the written data varies according to the rewrite order. If the time from the completion of verification to the distribution of the written data becomes long, there is a risk of tampering caused by illegal access during that period. However, by verifying the written data immediately before distributing the written data, such a situation can be avoided.

[0590] As described above, CGW13 makes DCM12 that downloads and distributes the data packet from the central device 3 execute at least a part of the processing related to the verification of the written data by performing the verification process of the written data. In CGW13 and the target ECU 19, even if the area for storing the written data cannot be ensured or the arithmetic program for verification cannot be mounted, the written data can be appropriately verified before writing the written data to the target ECU 19.

[0591] In Figure 74 In the configuration where CGW13 illustrated performs the first verification value calculation process, CGW13 holds the key (key value) and performs the verification process without sending the key to DCM12. Therefore, compared with the configuration where DCM12 performs the first verification value calculation process, the security can be improved. In addition, when there are multiple target ECUs 19, the first verification value calculation process can be performed using a shared key (key value) shared by the multiple target ECUs 19, or can be performed using individual keys (key values) different for the multiple target ECUs 19.

[0592] In addition, the configuration in which CGW13 notifies the DCM12 of the process execution request has been illustrated above. However, for example, in a case where the processing load in the DCM12 increases and hinders the original processing, instead of the DCM12, a navigation device or an ECU other than the ECU 19 to be rewritten may be used to notify the navigation device or an ECU other than the ECU 19 to be rewritten of the process execution request. Further, in a case where the DCM12 and the CGW13 are integrated, when it is possible to respond without hindering the original processing, a process execution request may be requested to the own process execution unit. For example, it may be performed between different software components in the same ECU. Further, the above disclosure may be applied to the main device 11 of a comprehensive ECU configured to have the functions of the DCM12 and the CGW13. For example, in Figures 73 to 76 the processing function in the CGW13 is used as the first functional unit, the processing function in the DCM12 is used as the second functional unit, a process execution request is notified from the first functional unit to the second functional unit, and an execution result is returned from the second functional unit to the first functional unit. In the main device 11 configured as a comprehensive ECU, in a case where the processing load increases and hinders communication processing and relay processing, instead of the second functional unit, a process execution request may be notified to a navigation device or an ECU other than the ECU 19 to be rewritten.

[0593] In addition, the data verification value may be calculated as one value for the entire application program or may be calculated as multiple values in units of modules of the application program. If the written data is all data, it can be used in integrity verification after the written data is completed.

[0594] In addition, with respect to secure access, it is a method of verifying whether the CGW13 and the ECU 19 to be rewritten can also be connected. Verification of the written data includes concepts such as the central device 3 as the distribution destination of the written data being regular (connection based on TLS communication, mutual authentication), the communication path for downloading the written data from the central device 3 being regular (communication path hiding, encryption), the written data downloaded from the central device 3 not being tampered with (tampering detection), and the written data downloaded from the central device 3 not being able to be tampered with (encryption).

[0595] In addition, the written data at the time of rewriting a new program has been described, but the written data at the time of rollback when writing back to an old program is the same. In this case, the CGW13 may perform verification at the time of downloading the written data at the time of rollback from the central device 3, but may also perform verification immediately before distributing the written data for rollback to the ECU 19 to be rewritten by generating a cancellation request for writing.

[0596] (8) Transmission control process of data storage surface information

[0597] Refer to Figures 79 to 81The transmission control process of data storage surface information will be described. The vehicle program rewriting system 1 performs the transmission control process of data storage surface information in the CGW 13.

[0598] As Figure 79 shown, the CGW 13 has a data storage surface information acquisition unit 80a, a data storage surface information transmission unit 80b, a rewriting method determination unit 80c, and a rewriting method instruction unit 80d in the data storage surface information transmission control unit 80. The data storage surface information acquisition unit 80a acquires information related to hardware and software as ECU structure information from each ECU 19. Specifically, in the case of a dual-sided memory ECU and a single-sided suspended memory ECU having data storage surfaces on multiple surfaces, software IDs including version information of each data storage surface and information capable of determining the application surface are acquired as dual-sided rewriting information (hereinafter referred to as surface information).

[0599] If the ECU structure information including the surface information is acquired by the data storage surface information acquisition unit 80a, the data storage surface information transmission unit 80b causes the acquired surface information to be transmitted from the DCM 12 to the central device 3 as one of the ECU structure information. The data storage surface information transmission unit 80b can transmit the ECU structure information to the central device 3 every time the ON / OFF of the IG switch 42 is switched, or can transmit the ECU structure information to the central device 3 according to a request from the central device 3. In addition, not only for the dual-sided memory ECU and the single-sided suspended memory ECU, but also for the single-sided independent memory ECU, the data storage surface information transmission unit 80b can also transmit the ECU configuration including the surface information together.

[0600] The rewriting method determination unit 80c determines the rewriting method based on the analysis result of the rewriting specification data for the CGW 13. The rewriting method indicates the power supply switching method at the time of installation in the target ECU 19 to be rewritten. If the rewriting method is determined by the rewriting method determination unit 80c, the rewriting method instruction unit 80d instructs the target ECU 19 to rewrite the application program based on the determined rewriting method. That is, if the rewriting method determination unit 80c determines the rewriting method based on power self-holding, the rewriting method instruction unit 80d instructs the target ECU 19 to rewrite the application program based on power self-holding. If the rewriting method determination unit 80c determines the rewriting method based on power control, the rewriting method instruction unit 80d instructs the target ECU 19 to rewrite the application program based on power control without using power self-holding.

[0601] Next, with reference to Figure 80 and Figure 81 the operation of the data storage surface information transmission control unit 80 in the CGW 13 will be described. The CGW 13 executes the data storage surface information transmission control program and performs the data storage surface information transmission control process.

[0602] When CGW13 starts the transmission control process of the data storage surface information, it sends an ECU structure information request including the surface information to all ECUs 19 (S801), and obtains the ECU structure information including the surface information from all ECUs 19 (S802, corresponding to the data storage surface information acquisition step). When CGW13 obtains the ECU structure information from each ECU 19 to be rewritten, it sends the obtained ECU structure information to DCM12 (S803, corresponding to the data storage surface information transmission step), and waits to obtain the write data and rewrite specification data from DCM12 (S804). Here, CGW13 can also, when the ECUs 19 to be rewritten are determined in advance, obtain the surface information, etc. only from the determined ECUs 19 to be rewritten.

[0603] When DCM12 receives the ECU structure information from CGW13, it temporarily stores the received ECU structure information, and when it is time to send (upload) the ECU structure information to the central device 3, it sends the ECU structure information to the central device 3. When the central device 3 receives the ECU structure information from DCM12, it saves and analyzes the received ECU structure information.

[0604] The central device 3 determines the version of the application program for each surface of each ECU 19 that is the source of the surface information and which surface is the operating surface, and determines the version of the application program and the write data (corresponding to the update data selection step) of the operating surface suitable for the two determined surfaces. For example, when surface A is the operating surface, the application program stored on this operating surface is version 2.0, surface B is the non-operating surface, and the application program stored on this non-operating surface is version 1.0, the central device 3 determines the write data of version 3.0 for surface B as the write data. When the write data is differential data, the central device 3 determines the differential data updated from version 1.0 to version 3.0. When the central device 3 determines the write data, it sends a distribution data packet including the determined write data and rewrite specification data to DCM12 (corresponding to the distribution data packet transmission step).

[0605] The central device 3 can either statically select the distribution data packet to be sent to DCM12 or dynamically generate it. When the central device 3 statically selects the distribution data packet to be sent to DCM12, it manages multiple distribution data packets storing write data, selects the write data suitable for the non-operating surface, and selects and sends the distribution data packet storing the selected write data from the multiple distribution data packets to DCM12. When the central device 3 dynamically generates the distribution data packet to be sent to DCM12, if it determines the write data suitable for the non-operating surface, it generates a distribution data packet storing the determined write data and sends it to DCM12.

[0606] If DCM12 downloads and distributes a data packet from the central device 3, it extracts the write data and rewrite specification data from the downloaded distribution data packet, and transmits the extracted write data and rewrite specification data to CGW13.

[0607] If CGW13 determines that it has obtained the write data and rewrite specification data from DCM12 (S804: Yes), it analyzes the obtained rewrite specification data (S805), and determines the rewrite method for the target ECU19 to be rewritten according to the analysis result of the rewrite specification data (S806, S807).

[0608] If CGW13 determines that the rewrite method is a rewrite based on power self-holding (S806: Yes), it sends a write data acquisition request to DCM12 on the condition that it is a vehicle state where installation is possible, obtains the write data from DCM12, distributes the obtained write data to the target ECU19 to be rewritten, and ends the transmission control process of the data storage surface information through the power self-holding rewrite application program (S808). The method of the power self-holding rewrite application program is as described above using Figure 28 and Figure 29 as described in (ii) in the case of the power self-holding rewrite application program.

[0609] If CGW13 determines that the rewrite method is a rewrite based on power control (S807: Yes), it sends a write data acquisition request to DCM12 on the condition that the vehicle is parked, obtains the write data from DCM12, distributes the obtained write data to the target ECU19 to be rewritten, and ends the transmission control process of the data storage surface information through the power control rewrite application program (S809). The method of the power control rewrite application program is as described above using Figure 26 and Figure 27 as described in (i) in the case of the power control rewrite application program.

[0610] As described above, CGW13 notifies the central device 3 of the ECU structure information including the surface information by performing the transmission control process of the data storage surface information, and causes a distribution data packet including the write data suitable for the ECU structure information to be downloaded from the central device 3 to DCM12. CGW13 obtains the write data suitable for the surface information from DCM12 and distributes the write data to the target ECU19 to be rewritten. It is possible to appropriately rewrite the application program when the ECU19 equipped with a flash memory having a data storage surface on two sides is used as the target to be rewritten.

[0611] In addition, as the method by which the central device 3 distributes the distribution data packet, there are a first distribution method to a third distribution method as shown below. In the first distribution method, the central device 3 distributes, for example, one distribution data packet storing the write data of version 2.0 for side A and the write data of version 2.0 for side B. The DCM 12 extracts the write data of version 2.0 for side A and the write data of version 2.0 for side B from the distribution data packet downloaded from the central device 3, and transmits the extracted write data to the CGW 13. If the CGW 13 is transmitted the write data of version 2.0 for side A and the write data of version 2.0 for side B from the DCM 12, it selects one of them and distributes it to the ECU 19 to be rewritten. That is, it is a configuration in which the write data corresponding to each data storage surface is included in the distribution data packet, and the main device 11 selects the rewrite data suitable for the ECU 19 to be rewritten.

[0612] In the second distribution method, the central device 3 selects and distributes, for example, either the distribution data packet storing the write data of version 2.0 for side A or the distribution data packet storing the write data of version 2.0 for side B. The DCM 12 extracts the write data from the distribution data packet downloaded from the central device 3, and transmits the extracted write data to the CGW 13. The CGW 13 distributes the write data transmitted from the DCM 12 to the ECU 19 to be rewritten. That is, it is a configuration in which the central device 3 selects the distribution data packet including the write data for the non-operating surface based on the surface information uploaded from the DCM 12.

[0613] In the third distribution method, the central device 3 distributes, for example, a distribution data packet storing the write data of version 2.0 shared by side A and side B. The DCM 12 extracts the write data of version 2.0 shared by side A and side B from the distribution data packet downloaded from the central device 3, and transmits the extracted write data to the CGW 13. The CGW 13 distributes the write data of version 2.0 shared by side A and side B transmitted from the DCM 12 to the ECU 19 to be rewritten. If the ECU 19 to be rewritten receives the write data of version 2.0 shared by side A and side B from the CGW 13, it writes the received write data to either side A or side B. In this case, in the ECU 19 to be rewritten, when the application program is executed, the address resolution function of the microcomputer comes into play, so that it operates properly regardless of whether the write data is written to side A or side B. That is, by the microcomputer of the write target ECU 19 resolving the difference in the execution address due to the surface difference, the central device 3 and the main device 11 can operate without knowing the surface.

[0614] The ECU structure information including the surface information sent from CGW13 to the central device 3 via DCM12 may also include vehicle identification information, system identification information, ECU identification information, usage environment information, etc., in addition to the versions of the application programs for two surfaces and the information capable of determining the usage surface.

[0615] The vehicle identification information is the unique information of the vehicle used to determine the distribution destination of the distributed data packet. For example, it is the VIN (Vehicle Identification Number). In vehicles compliant with the OBD (On-board diagnostics) regulations, the VIN can be used through the provisions of the OBD regulations. However, in vehicles that do not comply with the OBD regulations, such as EV vehicles, the VIN cannot be used, so individual vehicle identification information can be used instead of the VIN.

[0616] The system identification information is the unique information used to determine which reprogramming system it is. CGW13 can perform wireless reprogramming on systems that can perform wired reprogramming of diagnostic communication managed by itself, but cannot perform wireless reprogramming on other independent systems. That is, this is because it is a system that uses the mechanism of program update obtained via wire to perform program update obtained via wireless. Therefore, in the central device 3, it is necessary to determine which distributed data packet to distribute to which system, and by using the system identification information, it is possible to manage what systems are installed in the vehicle. The central device 3 can determine the reprogramming method for each system and the reprogramming order when multiple systems are the reprogramming targets by determining the system identification information.

[0617] The ECU identification information is the unique information used to determine the ECU19 to be reprogrammed, and it includes information for uniquely determining the reprogrammed ECU and the software version and hardware version of the application program written to the ECU19 to be reprogrammed. The ECU identification information is also equivalent to the ECU product number. In the case of writing the latest software using all the data, it may only be the hardware version. In addition, it is also possible to define information such as the specification version and configuration version that can determine the application program, and it is also possible to define the microcomputer ID, sub-microcomputer ID, flash memory ID, software sub-version, software grandchild-version, etc.

[0618] The usage environment information is the unique information used to determine the environment in which the user uses the vehicle. By sending the usage environment information from CGW13 to the central device 3 via DCM12, the central device 3 can distribute application programs suitable for the environment in which the user uses the vehicle. For example, distribute an application program that enhances acceleration to a user who likes to drive with sudden acceleration from a stop, and distribute an application program that enhances eco-driving but has poor acceleration performance to a user who likes eco-driving, etc., and it is possible to distribute application programs suitable for the environment in which the user uses the vehicle.

[0619] In addition, the case where the microcomputer of the ECU 19 to be rewritten is equipped with a flash memory has been described above. However, in the case where an external memory is connected to the microcomputer of the ECU 19 to be rewritten, the external memory is treated equally to the dual-sided memory, and the writing area of the external memory is divided into two to write the written data. In the case where the microcomputer of the ECU 19 to be rewritten is equipped with a flash memory and an external memory is connected, there is also a case where a process of temporarily copying (duplicating) the program stored in the external memory to the memory of the microcomputer is performed. Since the external memory is generally used as a storage area for the operation log of the ECU, it is preferable to interrupt the storage of the operation log when the writing of the written data to the external memory is started, and to resume the storage of the operation log when the writing of the written data to the external memory is completed.

[0620] The present invention is not limited to the case of rewriting the application program. For example, for data such as map data that has the property of being updated one by one, there are also concepts such as dual-sided and version, so the same applies to the case of rewriting map data.

[0621] (9) Power management processing for non-rewrite objects

[0622] Refer to Figures 82 to 87 The power management processing for the non-rewrite object ECU 19 will be described. The vehicle program rewriting system 1 performs the power management processing for the non-rewrite object ECU 19 in the CGW 13. In the present embodiment, it is assumed that the download of the distribution data packet is completed by the DCM 12, the CGW 13 acquires the rewriting specification data, and the CGW 13 distributes the written data to the ECU 19 to be rewritten in the vehicle stop state. When the CGW 13 distributes the written data to the ECU 19 to be rewritten, the CGW 13 requests the power management ECU 20 to turn on the IG power supply, and makes all the ECUs 19 in the startup state.

[0623] As Figure 82 shown, the CGW 13 includes a rewrite object determination unit 81a, an installability determination unit 81b, a state transition control unit 81c, and a rewrite order determination unit 81d in the power management unit 81 of the non-rewrite object ECU 19. The rewrite object determination unit 81a determines the rewrite object ECU 19 and the non-rewrite object ECU 19 based on the analysis result of the rewrite specification data. The installability determination unit 81b determines whether the rewrite object ECU 19 can be installed.

[0624] The state transition control unit 81c can transition the state of the ECU 19, causing the ECU 19 in the stopped state or sleep state to transition to the startup state (wake-up state), or causing the ECU 19 in the startup state to transition to the stopped state or sleep state. Additionally, the state transition control unit 81c causes the ECU 19 in the normal operation state to transition to the power-saving operation state, or causes the ECU 19 in the power-saving operation state to transition to the normal operation state. If the installability determination unit 81b determines that installation is possible, the state transition control unit 81c controls at least one or more non-overwrite target ECUs 19 to the stopped state, sleep state, or power-saving operation state. The rewrite order determination unit 81d determines the rewrite order of the overwrite target ECU 19 based on the analysis result of the rewrite specification data.

[0625] Next, refer to Figures 83 to 87 The operation of the power management unit 81 of the non-overwrite target ECU 19 in the CGW 13 will be described. The CGW 13 executes the power management program for the non-overwrite target and performs the power management process for the non-overwrite target. Here, the case where the CGW 13 makes all ECUs 19 to be managed enter the startup state will be described.

[0626] When the CGW 13 starts the power management process for the non-overwrite target ECU 19, it determines the overwrite target ECU 19 and the non-overwrite target ECU 19 based on the analysis result of the rewrite specification data for the CGW (S901), and determines the rewrite order of one or more overwrite target ECUs 19 based on the analysis result of the rewrite specification data (S902). The CGW 13 determines whether it is possible to write the write data (S903, equivalent to the writability determination step). If it is determined that it is possible to write the write data (S903: Yes), it sends a power-off request (stop request) to the non-overwrite target ECU 19 of the ACC system and the non-overwrite target ECU 19 of the IG system, causing the non-overwrite target ECU 19 of the ACC system and the non-overwrite target ECU 19 of the IG system to transition from the startup state to the stopped state (S904, equivalent to the state transition control step).

[0627] The CGW 13 determines whether the power-off request has been sent to all the conforming ECUs 19 (S905). If it is determined that the power-off request has been sent to all the conforming ECUs 19 (S905: Yes), it sends a sleep request to the non-overwrite target ECU 19 of the +B power supply system, causing the non-overwrite target ECU 19 of the +B power supply system to transition from the startup state to the sleep state (S906, equivalent to the state transition control step).

[0628] CGW13 determines whether the sleep request has been sent to all the compliant ECUs 19 (S907). If it is determined that the sleep request has been sent to all the compliant ECUs 19 (S907: Yes), then it is determined whether the application program has been rewritten for all the ECUs 19 to be rewritten (S908). If CGW13 determines that the application program has been rewritten for all the ECUs 19 to be rewritten (S908: Yes), then the power management process for the non-rewritten ECUs 19 ends. If CGW13 determines that the application program has not been rewritten for all the ECUs 19 to be rewritten (S908: No), then it returns to step S904 and repeats step S904 and the subsequent steps.

[0629] When there are multiple ECUs 19 to be rewritten, CGW13 can either transfer the states of the multiple ECUs 19 to be rewritten independently or transfer the states of the multiple ECUs 19 to be rewritten together. That is, in Figure 83 the process of CGW13 sending a power-off request or a sleep request to the non-rewritten ECUs 19 is shown. In the following Figure 84 and Figure 85 the case where, in addition to the power management process for the non-rewritten ECUs 19, the power management process for the ECUs 19 to be rewritten is also performed is described.

[0630] First, Figure 84 is used to describe the case where CGW13 transfers the states of the multiple ECUs 19 to be rewritten independently. As shown in Figure 84 for example, the case where the ECUs 19 to be rewritten are ECU (ID1), ECU (ID2), ECU (ID3), and during parking, the ECUs 19 to be rewritten are specified in the rewrite order from early to late by ECU (ID1), ECU (ID2), ECU (ID3) is described.

[0631] CGW13 transfers all of ECU (ID1), ECU (ID2), and ECU (ID3) from the stopped state or the sleep state to the started state. CGW13 keeps the first rewritten ECU (ID1) in the started state unchanged, transfers ECU (ID2) and ECU (ID3) from the started state to the stopped state or the sleep state, and distributes the written data to ECU (ID1). If CGW13 finishes distributing the written data to ECU (ID1), then it transfers ECU (ID1) from the started state to the stopped state or the sleep state, transfers the second rewritten ECU (ID2) from the stopped state or the sleep state to the started state, keeps ECU (ID3) in the stopped state or the sleep state unchanged, and distributes the written data to ECU (ID2).

[0632] If CGW13 finishes distributing the written data to ECU (ID2), it keeps ECU (ID1) in the stopped state or sleep state unchanged, transfers ECU (ID2) from the start state to the stopped state or sleep state, transfers the third rewritten ECU (ID3) from the stopped state or sleep state to the start state, and distributes the written data to ECU (ID3). If CGW13 finishes distributing the written data to ECU (ID3), it keeps ECU (ID1) and ECU (ID2) in the stopped state or sleep state unchanged, and transfers ECU (ID3) from the start state to the stopped state or sleep state. In this way, CGW13 is controlled to make only the currently rewritten ECU19 among the multiple rewritten target ECUs19 be in the start state.

[0633] Next, use Figure 85 to explain the case where CGW13 transfers the states of multiple rewritten target ECUs19 together. As Figure 85 shown, the case where the rewritten target ECU19 is, for example, ECU (ID1), ECU (ID2), ECU (ID3), and during parking, the rewritten target ECU19 specified in the order of rewriting from early to late is successively ECU (ID1), ECU (ID2), ECU (ID3) will be explained.

[0634] CGW13 transfers all of ECU (ID1), ECU (ID2), and ECU (ID3) from the stopped state or sleep state to the start state. CGW13 keeps all of ECU (ID1), ECU (ID2), and ECU (ID3) in the start state unchanged and distributes the written data to ECU (ID1). If CGW13 finishes distributing the written data to ECU (ID1), it distributes the written data to ECU (ID2). If CGW13 finishes distributing the written data to ECU (ID2), it distributes the written data to ECU (ID3). If CGW13 finishes distributing the written data to ECU (ID3), it transfers all of ECU (ID1), ECU (ID2), and ECU (ID3) from the start state to the stopped state or sleep state. In this way, CGW13 controls all of the multiple rewritten target ECUs19 to be in the start state until the installation is completed. Here, CGW13 can also distribute the written data to ECU (ID1), ECU (ID2), and ECU (ID3) simultaneously in parallel.

[0635] When rewriting the application program of the target ECU 19 during parking, the environment where the supply voltage to the target ECU 19 is stable is not necessarily guaranteed. Therefore, there is a concern about the situation where the vehicle battery 40 runs out of power during the rewriting of the application program. In particular, if there are multiple target ECUs 19, the time required to rewrite the application program becomes longer, so the possibility of the vehicle battery 40 running out of power during the rewriting of the application program increases. Regarding this point, by putting the non-target ECUs 19 in the stopped state or the sleep state as described above, it is possible to prevent the situation where the remaining battery power of the vehicle battery 40 is insufficient during the program rewriting. Moreover, by putting the ECUs 19 in the target ECU 19 that are not currently being rewritten in the stopped state or the sleep state, power consumption can be further suppressed.

[0636] As described above, the case of rewriting the application program of the target ECU 19 during parking has been explained. Now, the case of rewriting the application program of the target ECU 19 during vehicle operation will be explained. When rewriting the application program of the target ECU 19 during vehicle operation, the environment where the supply voltage to the target ECU 19 is stable is ensured. Therefore, there is no concern about the situation where the vehicle battery 40 runs out of power during the rewriting of the application program. However, there may be a case where the remaining battery power of the vehicle battery 40 is relatively low. According to such a situation, it is preferable to transfer the ECUs 19 that do not need to operate to the stopped state or the sleep state during vehicle operation. As Figure 86 shown, in the case where the ECU 44 that does not need to operate during vehicle operation is connected to the +B power supply line 37 but not to the ACC power supply line 38 and the IG power supply line 39, the CGW 13 transfers the ECU 44 that does not need to operate during this vehicle operation from the startup state to the stopped state or the sleep state. The ECU 44 is, for example, an ECU having functions such as anti-theft. That is, the CGW 13 transfers the ECUs 44 that do not need to operate and are not the target for rewriting to the stopped state or the sleep state during the period when all the ECUs 19 are in the startup state during vehicle operation. Thereby, an increase in power consumption associated with the installation during vehicle operation can be suppressed.

[0637] In addition, the CGW 13 monitors the remaining battery power of the vehicle battery 40 and performs the above-described power management process for non-targets. Here, Figure 87 the monitoring process for the remaining battery power will be explained. When the CGW 13 starts the monitoring process for the remaining battery power, it monitors the remaining battery power (S911) during the period of distributing the write data to the target ECU 19, and determines whether the remaining battery power is equal to or greater than the first specified capacity, or whether the remaining battery power is less than the first specified capacity and equal to or greater than the second specified capacity, or whether the remaining battery power is less than the second specified capacity (S912 to S914).

[0638] If CGW13 determines that the remaining battery capacity is equal to or greater than the first specified capacity (S912: Yes), it keeps the non-rewrite target ECU19 in the activated state and continues to distribute the data to be written to the rewrite target ECU19 (S915). If CGW13 determines that the remaining battery capacity is less than the first specified capacity and equal to or greater than the second specified capacity (S913: Yes), it transfers the ECUs that do not need to operate during driving in the non-rewrite target ECU19 to the stopped state or the sleep state, and continues to distribute the data to be written to the rewrite target ECU19 (S916). If CGW13 determines that the remaining battery capacity is less than the second specified capacity (S914: Yes), it determines whether the rewrite can be interrupted (S917).

[0639] If CGW13 determines that the rewrite can be interrupted (S917: Yes), it interrupts the distribution of the data to be written (S918). If CGW13 determines that the rewrite cannot be interrupted (S917: No), it transfers all the ECUs in the non-rewrite target ECU19 that can be transferred to the stopped state or the sleep state to the stopped state or the sleep state (S919).

[0640] CGW13 determines whether the rewrite is completed (S920). If it determines that the rewrite is not completed (S920: No), it returns to step S911 and repeats step S911 and the subsequent steps. If it determines that the rewrite is completed (S920: Yes), CGW13 transfers the rewrite target ECU19 in the stopped state or the sleep state to the activated state (S921), and ends the monitoring process of the remaining battery capacity. Here, the values of the first specified capacity and the second specified capacity can be pre-held by CGW13, or the values specified by rewriting the specification data can be used.

[0641] In addition, CGW13 can also exclude, for example, the ECU19 with a specific function such as an alarm function from the objects to be transferred to the stopped state or the sleep state in step S919, and transfer the non-rewrite target ECU19 other than the ECU19 with the specific function from the activated state to the stopped state or the sleep state. When it is possible to execute application control in the rewrite target ECU19 for rewriting the application program, CGW13 can set the non-rewrite target ECU19 other than the ECU19 that can communicate with the rewrite target ECU19 to the stopped state or the sleep state. When all the ECUs19 are in the stopped state or the sleep state, and if the rewrite condition is satisfied, for example, the vehicle position becomes the specified position or the current time becomes the specified time, CGW13 can also transfer the rewrite target ECU19 from the stopped state or the sleep state to the activated state.

[0642] CGW13 can also group the rewrite target ECU19 or non-rewrite target ECU19 with any one of the startup power supply (+B power supply system ECU, ACC system ECU, IG system ECU), domain group (body system, driving system, multimedia system), and synchronization timing as a reference, and make the rewrite target ECU19 in the startup state in units of groups, or make the non-rewrite target ECU19 in the stop state or sleep state in units of groups.

[0643] In addition, CGW13 can also be configured to perform power control in units of buses. That is, if it is determined that all ECUs 19 connected to a specific bus are non-rewrite target ECUs 19, CGW13 can also transfer all non-rewrite target ECUs 19 connected to the specific bus to the stop state or sleep state by disconnecting the power supply of the specific bus.

[0644] As described above, CGW13 performs power management processing for non-rewrite targets. Thus, if it is determined that the rewrite target ECU19 can be installed, at least one or more non-rewrite target ECUs 19 are made to enter the stop state, sleep state, or power-saving operation state. This can prevent the situation where the battery margin of the vehicle battery 40 becomes insufficient during the rewrite of the application program. In addition, by making the non-rewrite target ECU19 enter the stop state, sleep state, or power-saving operation state, an increase in communication load can be suppressed.

[0645] (10) Transmission control processing of files

[0646] Refer to Figures 88 to 97 The transmission control processing of files will be described. The vehicle program rewrite system 1 performs the transmission control processing of files in CGW13. This embodiment is the processing when the rewrite data held by DCM12 (equivalent to the first device) is sent to the rewrite target ECU19 (equivalent to the third device) via CGW13 (equivalent to the second device).

[0647] As Figure 88 shown, CGW13 has a transmission target file determination unit 82a, a first data size determination unit 82b, an acquisition information determination unit 82c, a second data size determination unit 82d, and a split file transmission request unit 82e in the file transmission control unit 82. The transmission target file determination unit 82a determines the file including the write data to be written to the rewrite target ECU19 as the transmission target file using the analysis result of the rewrite specification data. For example, when the rewrite target ECU19 is ECU (ID1), ECU (ID2), and ECU (ID3), the transmission target file determination unit 82a selects from Figure 8The ECU information of the rewriting specification data acquisition ECU (ID1), ECU (ID2), and ECU (ID3) for CGW is obtained, and the file including the write data is determined as the transfer target file based on the obtained ECU information. As the transfer target file, it is possible to determine the address and index at the time of obtaining the file, or the file name of the file.

[0648] If the transfer target file is determined by the transfer target file determination unit 82a, the first data size determination unit 82b determines the first data size for obtaining the transfer target file. If the transfer target file is determined by the transfer target file determination unit 82a, the acquisition information determination unit 82c determines the address as the acquisition information for obtaining the transfer target file. In addition, in the present embodiment, the address is determined as the acquisition information for obtaining the transfer target file, but if it is the acquisition information for obtaining the transfer target file, it is not limited to the address, and may also be a file name, ECU (ID), etc. The second data size determination unit 82d determines the second data size for distributing the write data to the rewrite target ECU 19. That is, the first data size is the data transfer size from the DCM 12 to the CGW 13, and the second data size is the data transfer size from the CGW 13 to the rewrite target ECU 19.

[0649] If the address is determined by the acquisition information determination unit 82c and the first data size is determined by the first data size determination unit 82b, the split file transfer request unit 82e designates the address and the first data size to the DCM 12 and requests the transfer of the split file from the DCM 12. For example, when the amount of data of the write file to be distributed to the ECU (ID1) is 1 Mbyte, the split file transfer request unit 82e requests to transfer the write data in 1 kbyte units from the address 0x10000000.

[0650] Next, refer to Figures 89 to 97 The operation of the file transfer control unit 82 in the CGW 13 will be described. The CGW 13 executes a file transfer control program and performs file transfer control processing.

[0651] If the CGW 13 determines that the unpacking completion notification signal has been received from the DCM 12, it starts file transfer control processing. Unpacking refers to the process of dividing the distributed data packet file into data for each ECU and each rewriting specification data as shown in Figure 10 If the CGW 13 starts file transfer control processing, it sends a specified address to the DCM 12 (S1001). When the DCM 12 receives the specified address from the CGW 13, it takes the reception of the specified address as an opportunity to transfer the rewriting specification data for the CGW to the CGW 13. The CGW 13 obtains the rewriting specification data for the CGW by having the rewriting specification data for the CGW transferred from the DCM 12 (S1002).

[0652] If CGW13 obtains the rewriting specification data for CGW from DCM12, it parses the obtained rewriting specification data for CGW (S1003), and determines the transfer target file according to the parsing result of the rewriting specification data (S1004, equivalent to the transfer target file determination step). CGW13 determines the address corresponding to the transfer target file (S1005, equivalent to the information acquisition determination step), and determines the first data size corresponding to the transfer target file (S1006, equivalent to the first data size determination step). CGW13 sends the determined address and data size to DCM12 according to the provisions of SID (Service Identifier) 35, designates the address and data size for the memory area, and requests DCM12 to transfer the split file (S1007).

[0653] If DCM12 receives the address and data size from CGW13, it parses the rewriting specification data for DCM, and transfers the file corresponding to the address and data size to CGW13 as a split file. CGW13 obtains the split file by receiving the split file from DCM12 (S1008). In this case, CGW13 may also store the obtained file in the flash memory after storing it in the RAM.

[0654] CGW13 determines whether the acquisition of all the split files that should be obtained has been completed (S1009). For example, when the data volume of the write file to be distributed to the ECU (ID1) is 1M bytes, CGW13 obtains the split file of every 1k bytes, repeats the acquisition of the split file of every 1k bytes, and determines whether the acquisition of 1M byte data volume has been completed. If CGW13 determines that the acquisition of all the split files that should be obtained has not been completed (S1009: "No"), it returns to step S1004 and repeats the steps after step S1004. If CGW13 determines that the acquisition of all the files that should be obtained has been completed (S1009: "Yes"), it ends the file transfer control process. In addition, when there are multiple rewriting target ECUs 19, CGW13 repeats the above file transfer control process for each rewriting target ECU 19.

[0655] That is, for example, when the rewriting target ECUs 19 are ECU (ID1), ECU (ID2), and ECU (ID3), if CGW13 finishes distributing the write data to ECU (ID1), it performs the file transfer control process for ECU (ID2), and if it finishes distributing the write data to ECU (ID2), it performs the file transfer control process for ECU (ID3). In addition, CGW13 may perform the transfer control process for multiple rewriting target ECUs 19 sequentially, or may perform it in parallel.

[0656] In Figure 90 it, in the memory of DCM12, for example, the written data file of ECU (ID1) is stored at addresses "1000" to "3999", the written data file of ECU (ID2) is stored at addresses "4000" to "6999", and the written data file of ECU (ID3) is stored at addresses "7000" and onwards.

[0657] In this case, as Figure 91 shown, if CGW13 receives the unpacking completion notification signal from DCM12, it sends address "0000" to DCM12 and obtains the rewrite specification data from DCM12. That is, if DCM12 determines that the reception of address "0000" is a request for obtaining the rewrite data for CGW, it sends the rewrite specification data for CGW to CGW13. CGW13 designates ECU (ID1) as the transmission object of the written data, designates address "1000" and data size "1 kbyte", and obtains the split file containing the written data of ECU (ID1) stored at addresses "1000" to "1999" from DCM12. If CGW13 obtains the split file from DCM12, it distributes the written data contained in the split file to ECU (ID1).

[0658] Next, CGW13 similarly designates ECU (ID1) as the transmission object of the written data, designates address "2000" and data size "1 kbyte", and obtains the split file containing the written data of ECU (ID1) stored at addresses "2000" to "2999" from DCM12. If CGW13 obtains the split file from DCM12, it distributes the written data contained in the split file to ECU (ID1). Until the writing of the written data to ECU (ID1) is completely finished, CGW13 repeats obtaining the split file in 1 kbyte increments from DCM12 and repeats distributing the written data contained in the split file to ECU (ID1). That is, if CGW13 obtains 1 kbyte of written data from DCM12, it sends the 1 kbyte of written data to the rewrite target ECU19, and if the sending to the rewrite target ECU19 is completed, it obtains the next 1 kbyte of written data from DCM12. CGW13 repeats these processes until the writing is completely finished.

[0659] If the writing of the write data is normally completed in the ECU (ID1), the ECU (ID2) is specified as the transfer destination of the write data, the address "4000" and the data size "1 kbyte" are specified, and the split file containing the write data of the ECU (ID2) stored at the addresses "4000" to "4999" is acquired from the DCM12. If the CGW13 acquires the split file from the DCM12, the write data contained in the split file is distributed to the ECU (ID2).

[0660] If the writing of the write data is normally completed in the ECU (ID2), the ECU (ID3) is specified as the transfer destination of the write data, the address "7000" and the data size "1 kbyte" are specified, and the split file containing the write data of the ECU (ID2) stored at the addresses "7000" to "7999" is acquired from the DCM12. If the CGW13 acquires the split file from the DCM12, the write data contained in the split file is distributed to the ECU (ID2).

[0661] As described above, the CGW13 determines the transfer destination file based on the analysis result of the rewrite specification data by performing the file transfer control process, and determines the address and data size corresponding to the transfer destination file. The CGW13 designates the address and data size to the DCM12, requests the DCM12 to transfer the split file obtained by splitting the transfer destination file, and acquires the split file from the DCM12. Thereby, in a state where the write data of a large capacity is stored in the memory of the DCM12, the write data can be distributed to the ECU19. That is, in the CGW13, there is no need to prepare a memory for storing a file of a large capacity, and the memory capacity of the CGW13 can be reduced.

[0662] Here, the relationship between the data amount of the split file transferred from the DCM12 to the CGW13 and the data amount of the write file distributed from the CGW13 to the rewrite target ECU19 will be described. In the above example, as Figure 92 shown, the case where the data amount of the split file transferred from the DCM12 to the CGW13 is 1 kbyte has been described, but the relationship between the data amount of the split file transferred from the DCM12 to the CGW13 and the data amount of the write file distributed from the CGW13 to the rewrite target ECU19 can also be arbitrary.

[0663] That is, for example, if, due to reasons related to CAN communication, the ECU 19 to be rewritten adopts a specification of receiving write data in 4-kilobyte units, the CGW 13 distributes the data volume of the write file to the ECU 19 to be rewritten in 4-kilobyte units. In this case, if the data volume of the split file transmitted from the DCM 12 to the CGW 13 is 1 kilobyte, the CGW 13 obtains four split files from the DCM 12 and then distributes 4 kilobytes to the ECU 19 to be rewritten. That is, the data volume of the split file transmitted from the DCM 12 to the CGW 13 is smaller than the data volume of the write file distributed from the CGW 13 to the ECU 19 to be rewritten. In such a relationship, in the CGW 13, an increase in the memory capacity can be suppressed, and the split files can be obtained from the DCM 12 in parallel and the write data can be distributed to the ECU 19 to be rewritten.

[0664] That is, if the data volume of the split file transmitted from the DCM 12 to the CGW 13 is 4 kilobytes, in order to obtain the split files from the DCM 12 in parallel and distribute the write data to the ECU 19 to be rewritten, the memory capacity of the CGW 13 needs to be 8 kilobytes. By making the data volume of the split file transmitted from the DCM 12 to the CGW 13 1 kilobyte, without making the memory capacity of the CGW 13 8 kilobytes, it is possible to obtain the split files from the DCM 12 in parallel and distribute the write data to the ECU 19 to be rewritten. For example, if the memory capacity of the CGW 13 is ensured to be 5 kilobytes in advance, the CGW 13 distributes the 4 kilobytes obtained from the DCM 12 to the ECU 19 to be rewritten, and obtains the next 1 kilobyte from the DCM 12. Moreover, after the CGW 13 has completed distributing 4 kilobytes to the ECU 19 to be rewritten, it further obtains the next 1 kilobyte from the DCM 12.

[0665] On the other hand, for example, if, due to reasons related to CAN communication, the ECU 19 to be rewritten adopts a specification of receiving write data in 128-byte units, the CGW 13 distributes the write data to the ECU 19 to be rewritten in 128-byte units. In this case, if the data volume of the split file transmitted from the DCM 12 to the CGW 13 is 1 kilobyte, the CGW 13 obtains one split file from the DCM 12 and then distributes it to the ECU 19 to be rewritten in 128-byte units. That is, the data volume of the split file transmitted from the DCM 12 to the CGW 13 is larger than the data volume of the write file distributed from the CGW 13 to the ECU 19 to be rewritten. For example, if the memory capacity of the CGW 13 is ensured to be 2 kilobytes in advance, the CGW 13 distributes the 1 kilobyte obtained from the DCM 12 to the ECU 19 to be rewritten in 128-byte units, and obtains the next 1 kilobyte from the DCM 12. Moreover, after the CGW 13 has completed distributing 128 bytes × 8 times to the ECU 19 to be rewritten, it further obtains the next 1 kilobyte from the DCM 12.

[0666] Thus, as long as the data volume of the split file transmitted from DCM12 to CGW13 is a fixed value (e.g., 1 kB), the data volume of the write file distributed from CGW13 to the ECU 19 to be rewritten may be a variable value according to the specification of the ECU 19 to be rewritten. For example, CGW13 may also use the data transfer size of each ECU specified by the rewrite specification data to determine the data volume distributed to the ECU 19 to be rewritten.

[0667] CGW13 sends a transfer request to DCM12 to request the transfer of the split file. As the method of requesting the transfer of the split file from DCM12, there are a first request method and a second request method. If the ECU 19 to be rewritten finishes receiving the write data, it sends a reception completion notice indicating the completion of the reception of the write data to CGW13. If the ECU 19 to be rewritten finishes writing the write data, it sends a write completion notice indicating the completion of the writing of the write data to CGW13.

[0668] Use Figure 93 The first distribution method will be described. If CGW13 obtains the split file from DCM12, it distributes the obtained split file as write data to the ECU 19 to be rewritten. If the ECU 19 to be rewritten finishes receiving the write data, it sends a reception completion notice to CGW13 and starts the write processing of the write data. If CGW13 receives the reception completion notice of the write data from the ECU 19 to be rewritten, it sends a transfer request to DCM12 to request the transfer of the next split file. If CGW13 obtains the next split file from DCM12, it distributes the obtained next split file as write data to the ECU 19 to be rewritten.

[0669] Thus, in the first distribution method, CGW13 obtains the next write data from DCM12 and distributes it to the ECU 19 to be rewritten without waiting for the completion of the writing of the write data by the ECU 19 to be rewritten. Therefore, in the first distribution method, in CGW13, if the ECU 19 to be rewritten has not completed the writing of the write data, even if it obtains the next split file from DCM12 and distributes the next write data to the ECU 19 to be rewritten, the ECU 19 to be rewritten may not be able to receive the next write data. However, if the ECU 19 to be rewritten finishes writing the write data, it can quickly obtain the next split file from DCM12 and quickly distribute the next write data to the ECU 19 to be rewritten.

[0670] Use Figure 94A description is given of the second distribution method. If CGW13 obtains a segmented file from DCM12, the obtained segmented file is distributed as write data to the ECU19 to be rewritten. If the ECU19 to be rewritten finishes receiving the write data, it sends a reception completion notification to CGW13 and starts the write process of the write data. If the ECU19 to be rewritten finishes writing, it sends a write completion notification to CGW13. If CGW13 receives the write completion notification from the ECU19 to be rewritten, it sends a transfer request to DCM12 and requests the transfer of the next segmented file. If CGW13 obtains the next segmented file from DCM12, the obtained next segmented file is distributed as write data to the ECU19 to be rewritten.

[0671] In this way, in the second distribution method, after waiting for the completion of the writing of the write data of the ECU19 to be rewritten, CGW13 obtains the next write data from DCM12 and distributes it to the ECU19 to be rewritten. Therefore, in the second distribution method, in CGW13, it takes time until the next segmented file is obtained from DCM12, and it is possible to request the transfer of the segmented file to DCM12 in a state where the writing of the write data by the ECU19 to be rewritten is completed. Therefore, if the next segmented file is obtained from DCM12 and the next write data is distributed to the ECU19 to be rewritten, the next write data can be reliably distributed to the ECU19 to be rewritten.

[0672] In addition, CGW13 distributes write data to the ECU19 to be rewritten through SID34, 36, 37. As a method of distributing write data to the ECU19 to be rewritten, there are a first distribution method and a second distribution method. In the first distribution method, as Figure 95 shown, CGW13 segments the write data to be distributed according to a specified data volume (for example, 1 kbyte) and distributes it. In the second distribution method, as Figure 96 shown, CGW13 distributes the write data to be distributed without segmentation in a unified manner. CGW13 selects either the first distribution method or the second distribution method through SID34 initially distributed to the ECU19 to be rewritten. As Figure 97 shown, CGW13 determines the reception of the write data of the ECU19 to be rewritten by receiving an ACK (SID74) for SID37 finally distributed to the ECU19 to be rewritten. The ACK for this SID37 is equivalent to passing through Figure 93 and Figure 94The above-mentioned notification of completion of reception of write data. That is, in the first distribution method, when CGW13 receives the ACK for the last distribution of SID37 to the rewrite target ECU19, by incrementing the address of the next write data by 1, while distributing the next write data to the rewrite target ECU19, it further obtains the next write data from DCM12.

[0673] In addition, in the rewrite specification data for DCM, the address is associated with the file. However, as a method of associating the address with the file, for example, a folder structure can be designed. The specification data is stored in folder 1, file 1 is stored in folder 2, and file 2 is stored in folder 3 for management, or it can be managed in the order of file names. For example Figure 10 In the unpacking shown, the rewrite specification data for DCM and the rewrite specification data for CGW are stored in folder 1, the authentication symbol and differential data of ECU (ID1) are stored in folder 2, and the authentication symbol and differential data of ECU (ID2) are stored in folder 3 for management.

[0674] In addition, for example, when CGW13 interrupts the distribution of write data to the rewrite target ECU19 due to some reason such as communication interruption, it obtains information from the rewrite target ECU19 that can determine the address of the completion of the write of the write data, and requests DCM12 to transmit the split file including the write data from the moment when the write is not completed. Alternatively, CGW13 can also request DCM12 to transmit the split file including the write data from the start.

[0675] As described above, if CGW13 determines the file including the write data written to the rewrite target ECU19 as the transfer target file through file transfer control processing, determines the address and the first data size for obtaining the transfer target file, requests DCM12 to transmit the split file, and transmits the split file from DCM12, it distributes the write data to the rewrite target ECU. The transfer of write data from DCM12 to CGW13 and the distribution of write data from CGW13 to the rewrite target ECU19 can be efficiently performed.

[0676] (11) Distribution control processing of write data

[0677] Refer to Figures 98 to 108 The distribution control processing of write data will be described. The vehicle program rewrite system 1 performs the distribution control processing of write data in CGW13. Since CGW13 sends write data to ECU19 via the in-vehicle bus, it performs the distribution control processing so that the bus load during the process of distributing the write data does not become too high.

[0678] As Figure 98As shown, it is assumed that the +B power supply system ECU, the ACC system ECU, and the IG system ECU are connected to the same bus. In this case, in the +B power supply state, only the +B power supply system ECU is activated, and the ACC system ECU and the IG system ECU are stopped. Therefore, only the vehicle control data of the +B power supply system ECU is transmitted to the bus. When in the ACC power supply state, the +B power supply system ECU and the ACC system ECU are activated, and the IG system ECU is stopped. Therefore, the vehicle control data of the +B power supply system ECU and the ACC system ECU is transmitted to the bus. When in the IG power supply state, the +B power supply system ECU, the ACC system ECU, and the IG system ECU are activated. Therefore, the vehicle control data of the +B power supply system ECU, the ACC system ECU, and the IG system ECU is transmitted to the bus. That is, the order of the transmission amount of the vehicle control data from more to less is the IG power supply state, the ACC power supply state, and the +B power supply state.

[0679] As Figure 99 shown, CGW13 has a first correspondence determination unit 83a, a second correspondence determination unit 83b, a transmission allowance determination unit 83c, a distribution frequency determination unit 83d, a bus load measurement unit 83e, and a distribution control unit 83f in the data writing distribution control unit 83.

[0680] The first correspondence determination unit 83a determines the first correspondence indicating the relationship between the power supply state and the transmission allowance of the bus based on the analysis result of the rewrite specification data, and determines Figure 100 the bus load table shown. The transmission allowance is the value of the transmission load at which data can be transmitted and received without data collision or delay. The bus load table is a table showing the correspondence between the power supply state and the transmission allowance of the bus, and is defined for each bus. The transmission allowance is the sum of the transmission amounts of the vehicle control data and the write data that can be transmitted relative to the maximum transmission allowance.

[0681] In Figure 100 the example, the transmission allowance of the first bus is "80%" relative to the maximum transmission allowance. Therefore, in the IG power supply state, CGW13 allows "50%" relative to the maximum transmission allowance as the transmission allowance of the vehicle control data, and allows "30%" relative to the maximum transmission allowance as the transmission allowance of the write data. In addition, for the first bus, in the ACC power supply state, CGW13 allows "30%" relative to the maximum transmission allowance as the transmission allowance of the vehicle control data, and allows "50%" relative to the maximum transmission allowance as the transmission allowance of the write data. In addition, for the first bus, in the +B power supply state, CGW13 allows "20%" relative to the maximum transmission allowance as the transmission allowance of the vehicle control data, and allows "60%" relative to the maximum transmission allowance as the transmission allowance of the write data. AsFigure 100 As shown, the second bus and the third bus are also defined in the same way.

[0682] The second correspondence determination unit 83b determines a second correspondence indicating the relationship between the bus to which the target ECU 19 to be rewritten belongs and the power supply system based on the analysis result of the rewrite specification data, and determines Figure 101 the target ECU belonging table shown. The target ECU belonging table is a table indicating the bus and the power supply system to which the target ECU 19 to be rewritten belongs.

[0683] In Figure 101 the example shown, for the first target ECU 19, CGW 13 connects it to the first bus and starts in any of the +B power supply state, ACC power supply state, and IG power supply state. Therefore, the first target ECU 19 is determined as a +B power supply system ECU. In addition, for the second target ECU 19, CGW 13 connects it to the second bus, stops in the +B power supply state, but starts in the ACC power supply state and the IG power supply state. Therefore, the second target ECU 19 is determined as an ACC system ECU. In addition, for the third target ECU 19, CGW 13 connects it to the third bus, stops in the +B power supply state and the ACC power supply state, but starts in the IG power supply state. Therefore, the third target ECU 19 is determined as an IG system ECU.

[0684] CGW 13 uses Figure 8 the data of "connected bus" and "connected power supply" in the rewrite specification data shown to determine to which bus the target ECU 19 to be rewritten is connected and which power supply system it is. In addition, if these information can be determined, it is not necessarily required to be saved in the form of a table.

[0685] The transmission allowance determination unit 83c determines the transmission allowance of the bus to which the target ECU 19 to be rewritten belongs, that is, the transmission allowance corresponding to the power supply state of the vehicle when the program is updated, based on the determination result of the first correspondence and the determination result of the second correspondence. Specifically, the transmission allowance determination unit 83c uses the second correspondence, that is, the target ECU belonging table, to determine the bus to which the target ECU 19 to be rewritten belongs, and uses the first correspondence, that is, the bus load table, to determine the transmission allowance for each power supply state for the determined bus.

[0686] The distribution frequency determination unit 83d determines the distribution frequency of the write data corresponding to the power supply state at the time of installation, using the correspondence relationship between the predetermined power supply state and the distribution frequency of the write data. Specifically, the distribution frequency determination unit 83d uses the bus load table to determine the transmission allowance allocated for distributing the write data among the transmission allowances determined by the transmission allowance determination unit 83c, and determines the distribution frequency of the write data. For example, the distribution frequency determination unit 83d determines that the bus to which the ECU 19 to be rewritten belongs is the first bus, determines that the power supply state at the time of installation is the IG power supply state, determines the transmission allowance as "80%", and determines the transmission allowance allocated for distributing the write data as "30%", thereby determining the distribution frequency of the write data. The transmission allowance allocated for distributing the write data corresponds to the transmission limit information.

[0687] The bus load measurement unit 83e measures the bus load of the bus to which the ECU 19 to be rewritten belongs. For example, the bus load measurement unit 83e measures the bus load by counting the number of frames or bits received per unit time. The distribution control unit 83f controls the distribution of the write data according to the distribution frequency determined by the distribution frequency determination unit 83d.

[0688] Next, refer to Figures 102 to 108 The operation of the write data distribution control unit 83 in the CGW 13 will be described. The CGW 13 executes the write data distribution control program and performs the write data distribution control process.

[0689] When the CGW 13 receives the unpacking completion notification signal from the DCM 12, it starts the write data distribution control process. The CGW 13 acquires the rewrite specification data for the CGW from the DCM 12 (S1101), and determines the bus load table and the table of the ECUs to be rewritten based on the rewrite specification data for the CGW (S1102). The CGW 13 determines the bus to which the ECU 19 to be rewritten belongs based on the table of the ECUs to be rewritten (S1103). The CGW 13 determines the transmission allowance corresponding to the bus to which the ECU 19 to be rewritten belongs, that is, the power supply state of the vehicle at the time of update, based on the bus load table. Moreover, the CGW 13 determines the distribution frequency of the write data in consideration of the determined transmission allowance (S1104, corresponding to the distribution frequency determination step). For example, when distributing the write data during vehicle travel for the first ECU 19 to be rewritten, that is, the ECU (ID1), the CGW 13 refers to the transmission allowance of the first bus in the IG power supply state. In Figure 100In the example, the transmission allowance of the first bus in the IG power supply state is "80%", among which "50%" is allowed for vehicle control data transmission and "30%" is allowed for write data transmission. Additionally, the transmission allowance is ultimately a value used to represent an example, and for the numerical value, it is set within the allowable range according to the applicable communication specifications.

[0690] Since the specification for CAN at 500 [kbps] is about 250 [μs] per frame, if four interruptions occur within 1 second, four frames are generated and the bus load is 100%. CGW13 determines the distribution frequency of the write data by judging the interruptions generated on the bus. CGW13 starts measuring the number of frames received per unit time and starts measuring the bus load (S1105), determines whether the measured bus load exceeds the transmission allowance (S1106), and sets the distribution interval. The distribution interval refers to the time interval from when CGW13 distributes the write data to the target ECU19 to be rewritten until it receives the write completion notification (ACK) from the target ECU19 to be rewritten until it sends the next write data to the target ECU19.

[0691] If CGW13 determines that the measured bus load does not exceed the transmission allowance (S1106: "No"), it sets the distribution interval of the write data to the shortest interval set in advance, as Figure 103 shown, and starts distributing the write data to the target ECU19 to be rewritten (S1107, equivalent to the distribution control step). That is, CGW13 sets the distribution interval of one frame on the CAN to the shortest interval set in advance and starts distributing the write data to the target ECU19 to be rewritten. Additionally, one frame on the CAN contains write data with a data volume of 8 bytes. Additionally, one frame on the CAN FD (CAN with Flexible Data-Rate) contains write data with a data volume of 64 bytes.

[0692] On the other hand, if CGW13 determines that the measured bus load exceeds the transmission allowance (S1106: "Yes"), it calculates the interval when the bus load does not exceed the transmission allowance (S1108), sets the distribution interval of the write data to the calculated interval, as Figure 104 shown, and starts distributing the write data to the target ECU19 to be rewritten (S1109, equivalent to the distribution control step).

[0693] For example, in the IG power supply state, CGW13 determines whether the bus load exceeds the transmission allowance of "80%" for the first bus. If it determines that the bus load does not exceed the transmission allowance, it sets the distribution interval T1 with the transmission allowance of the write data being "30%". That is, as Figure 100As shown in the bus load table, CGW13 sets the distribution interval T1 using the transfer allowance of "30%" for the write data in the first bus in the IG power state. CGW13 sets the distribution interval T1 to be the maximum allowable transfer volume. Additionally, CGW13 can also converge the measurement object to the frame of the write data to measure the bus load, and determine whether the bus load based on the write data exceeds the transfer allowance of the write data "30%". If CGW13 determines that the bus load exceeds the transfer allowance, it changes to the distribution interval T2 (>T1) where the bus load does not exceed the transfer allowance according to the amount by which the bus load exceeds the transfer allowance. In this way, after CGW13 obtains the write data from DCM12, it waits until the set distribution interval is reached, and then distributes the write data to the ECU19 to be rewritten.

[0694] When CGW13 starts distributing the write data to the ECU19 to be rewritten, it determines whether the distribution of the write data to the ECU19 to be rewritten is completed, and continuously determines whether the measured bus load exceeds the transfer allowance (S1110, S1011). If CGW13 determines that the measured bus load does not exceed the transfer allowance (S1111: "No"), it sets the distribution interval of the write data to the shortest interval set in advance, and changes the distribution interval for distributing the write data to the ECU19 to be rewritten (S1112). On the other hand, if CGW13 determines that the measured bus load exceeds the transfer allowance (S1111: "Yes"), it calculates the interval where the bus load does not exceed the transfer allowance (S1113), sets the distribution interval of the write data to the calculated interval, and changes the distribution interval for distributing the write data to the ECU19 to be rewritten (S1114).

[0695] If CGW13 determines that the distribution of the write data to the ECU19 to be rewritten is completed (S1110: "Yes"), it stops measuring the number of frames received per unit time, stops measuring the bus load (S1115), and ends the distribution control process of the write data. Here, when there are multiple ECUs19 to be rewritten, CGW13 performs the distribution control process of the write data for the installation to all the ECUs19 to be rewritten.

[0696] As described above, CGW13 determines the distribution frequency of distributing the write data to the ECU19 to be rewritten by performing the distribution control process of the write data, using the correspondence between the predetermined power state and the distribution frequency of the write data, and controls the distribution of the write data according to the distribution frequency. It can suppress data conflicts, delays, etc. during installation. Additionally, it can enable the coexistence of the distribution of the write data without interfering with the distribution of vehicle control data on the same bus.

[0697] In addition, as described above, in CGW13, an example is given in which the composition of the bus load table is determined based on the parsing result of the rewrite specification data, but it is also possible to pre-store the composition of the bus load table. In addition, in CGW13, an example is given in which the composition of the table to which the ECU to be rewritten belongs is determined based on the parsing result of the rewrite specification data, but it is also possible to pre-store the composition of the table to which the ECU to be rewritten belongs.

[0698] It is also possible to make the distribution volume of the written data relatively small when the vehicle is in the power-on state during driving and make the distribution volume of the written data relatively large when the vehicle is in the power-on state during parking. That is, as Figure 105 shown, when the ignition power supply is turned on during vehicle driving, CGW13 sends CAN frames through the ignition system ECU, ACC system ECU, and +B power supply system ECU, and makes the transmission volume of application data such as vehicle control and diagnosis relatively large, so the distribution volume of the written data is relatively small. In addition, as Figure 106 shown, when the ignition power supply is turned off during parking, CGW13 sends CAN frames only through the +B power supply system ECU, and makes the transmission volume of application data such as vehicle control and diagnosis relatively small, and makes the distribution volume of the written data relatively large. That is, CGW13 adjusts the distribution volume of the written data within the idle capacity that does not interfere with the transmission of application data such as vehicle control and diagnosis.

[0699] In addition, it is also possible to, as Figure 107 shown, in CGW13, when an event frame is sent from the ECU 19 to be rewritten, the frequency of interruption becomes high and the bus load becomes high by receiving the event frame, so the distribution volume of the written data is relatively small. When an event frame is not sent from the ECU 19 to be rewritten, the distribution volume of the written data is relatively large.

[0700] In addition, it is also possible to, as Figure 108 shown, in the vehicle system, when it is determined that CGW13 is in the distribution of the written data, the bus load is reduced by extending the transmission interval of application data such as vehicle control and diagnosis to the maximum allowed interval. In CGW13, it is also possible to reduce the bus load by extending the transmission interval of application data by the vehicle system, thereby making the distribution volume of the written data relatively large.

[0701] The bus load table embedded in the rewrite specification data is, for example, uniformly shared and set regardless of the vehicle manufacturer's model, grade, etc. This is because if the equipment of the ECU varies greatly due to, for example, the model, grade, etc., the bus load varies greatly. If the optimal bus load table is set independently according to the model, grade, etc., it requires labor and other cumbersome troubles in this verification, so such cumbersome troubles are avoided.

[0702] Similar to the case where the vehicle is installed while in motion as described above, in the case where the vehicle is installed while parked, distribution control processing of write data is also performed. In this case, if the ECU 19 to be rewritten is a +B power supply system ECU, it can also be updated in the +B power supply state, so the transmission allowance amount in the +B power supply state in the bus load table is referred to. On the other hand, in the case where the ECU 19 to be rewritten is an IG system ECU, it is installed in the IG power supply state, so the transmission allowance amount in the IG power supply state in the bus load table is referred to. Here, for example, in the case where the ECU 19 to be rewritten is an ACC system ECU, it can also be installed in the IG power supply state. In this case, the transmission allowance amount in the IG power supply state in the bus load table is referred to. In addition, the configuration of the bus load table and the table to which the ECU 19 to be rewritt...

Claims

1. A main device for a vehicle that distributes update data received from a central device to an electronic control device to be rewritten and instructs the electronic control device to be rewritten to write the update data. Among them, If it is determined that there is an activity notification from the central device, download the rewrite specification data and update data from the central device, determine whether it is a program rewrite or a configuration information rewrite based on the rewrite specification data. If it is determined to be a program rewrite, instruct the electronic control device to be rewritten to rewrite the program based on the recompiled data, where the recompiled data is the update data downloaded from the central device. If it is determined to be a configuration information rewrite, instruct the electronic control device to be rewritten to rewrite the configuration information based on the new configuration information, where the new configuration information is the update data downloaded from the central device. In the case of instructing the electronic control device to be rewritten to rewrite the program and the configuration information, after the installation of the new program in the electronic control device to be rewritten is completed, instruct the electronic control device to be rewritten to rewrite the configuration information.

2. The main device for a vehicle according to claim 1, Among them, Instruct the electronic control device to be rewritten to overwrite the configuration information as an instruction to rewrite the configuration information of the electronic control device to be rewritten.

3. The main device for a vehicle according to claim 1 or 2, Among them, Collect vehicle information, obtain the software version and the configuration information version as the structure information of the electronic control device to be rewritten, and send the collected vehicle information to the central device.

4. A vehicle electronic control system includes a main device for a vehicle and an electronic control device. The main device for a vehicle distributes update data received from a central device to an electronic control device to be rewritten and instructs the electronic control device to be rewritten to write the update data. The electronic control device uses the update data received from the main device for a vehicle to rewrite the program in the non-volatile memory. Among them, If the main device for a vehicle determines that there is an activity notification from the central device, download the rewrite specification data and update data from the central device, determine whether it is a program rewrite or a configuration information rewrite based on the rewrite specification data. If it is determined to be a program rewrite, instruct the electronic control device to be rewritten to rewrite the program based on the recompiled data, where the recompiled data is the update data downloaded from the central device. If it is determined to be a configuration information rewrite, instruct the electronic control device to be rewritten to rewrite the configuration information based on the new configuration information, where the new configuration information is the update data downloaded from the central device. In the case of instructing the electronic control device to be rewritten to rewrite the program and the configuration information, after the installation of the new program in the electronic control device to be rewritten is completed, instruct the electronic control device to be rewritten to rewrite the configuration information.

5. A method for instructing the rewrite of configuration information, Among them, In a vehicle main unit that distributes update data received from a central device to an electronic control device to be rewritten and instructs the electronic control device to be rewritten to write the update data, when it is determined that there is an activity notification from the central device, the rewrite specification data and update data are downloaded from the central device, and based on the rewrite specification data, it is determined whether it is a program rewrite or a configuration information rewrite. If it is determined to be a program rewrite, the electronic control device to be rewritten is instructed to rewrite the program based on the recompiled data, where the recompiled data is the update data downloaded from the central device. If it is determined to be a configuration information rewrite, the electronic control device to be rewritten is instructed to rewrite the configuration information based on the new configuration information, where the new configuration information is the update data downloaded from the central device. In the case of instructing the electronic control device to be rewritten to rewrite the program and the configuration information, after the installation of the new program in the electronic control device to be rewritten is completed, the step of instructing the electronic control device to be rewritten to rewrite the configuration information.

6. A recording medium recording a configuration information rewrite instruction program, wherein, the configuration information rewrite instruction program causes the vehicle main unit that distributes the update data received from the central device to the electronic control device to be rewritten and instructs the electronic control device to be rewritten to write the update data to execute: when it is determined that there is an activity notification from the central device, the rewrite specification data and update data are downloaded from the central device, and based on the rewrite specification data, it is determined whether it is a program rewrite or a configuration information rewrite. If it is determined to be a program rewrite, the electronic control device to be rewritten is instructed to rewrite the program based on the recompiled data. If it is determined to be a configuration information rewrite, the electronic control device to be rewritten is instructed to rewrite the configuration information based on the new configuration information, where the new configuration information is the update data downloaded from the central device. In the case of instructing the electronic control device to be rewritten to rewrite the program and the configuration information, after the installation of the new program in the electronic control device to be rewritten is completed, the step of instructing the electronic control device to be rewritten to rewrite the configuration information.

Citation Information

Patent Citations

  • On-vehicle electronic control device

    JP2016224898A

  • Image formation device

    JP2019155686A

  • Vehicular electronic control system, program update notification control method, and program update notification control program

    CN112602055A