Control system, mobile object, control method, and computer-readable storage medium
By restricting the control unit to execute only one of diagnosis or program update when the diagnostic device is connected, program update failures caused by commercially available scan tools are resolved, and the reliability of program updates and user convenience are improved.
Patent Information
- Application Number
- CN202111477894.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-01-13
- Filing Date
- 2021-12-06
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2041-12-06
AI Technical Summary
During the vehicle ECU program update process, connecting a commercially available scan tool may cause program update failures, and existing technologies are difficult to effectively avoid such problems.
The limitation control unit limits the diagnosis and program update of the diagnostic device to ensure that only one of them is executed when the diagnostic device is connected, avoiding simultaneous execution to prevent program update failure.
This reduces program update failures caused by commercially available scanning tools, improving program update reliability and user convenience.
Smart Images

Figure CN114763110B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a control system, a mobile object, a control method and a computer-readable storage medium. Background Art
[0002] Patent Document 1 discloses an ECU capable of rewriting application programs as an ECU for a vehicle.
[0003] Patent Document 1: Japanese Patent Application Laid-Open No. 2020-27666 Summary of the Invention
[0004] In a first embodiment, a control system is provided. The control system includes a mobile body control unit that controls a mobile body. The control system includes an update control unit that controls program updates for the mobile body control unit. The control system includes a communication path for communicating information between the mobile body control unit and the update control unit. The communication path and the path for transmitting mobile body information to an external diagnostic device that diagnoses the mobile body control unit are at least partially shared. The control system includes a restriction control unit that, when a program update and an external diagnostic device diagnoses the mobile body control unit, restricts either the external diagnostic device's diagnosis or the program update.
[0005] The restriction control unit may be configured such that, when the program is updated and the external diagnostic device is diagnosing the movable body control unit, the restriction control unit prohibits the program update until the diagnosis by the external diagnostic device is terminated.
[0006] The restriction control unit may be configured to issue a user notification indicating that the diagnosis by the external diagnostic device is stopped while the program is being updated and the mobile body control unit is being diagnosed by the external diagnostic device.
[0007] The update control unit may be configured to perform configuration synchronization by acquiring, via a communication path, management information stored in the mobile unit control unit, the management information including at least a version of the mobile unit control unit required for program updates of the mobile unit control unit. When the connection of an external diagnostic device to the mobile unit is detected during startup of the mobile unit, the restriction control unit prohibits configuration synchronization until the connection to the external diagnostic device is released.
[0008] The restriction control unit may be configured to prohibit reception of the update program for the mobile body control unit from a server that transmits the update program for the mobile body when the connection of the external diagnostic device to the mobile body is detected at startup of the mobile body.
[0009] The update control unit may be configured to control receipt of a notification of the presence of an update program from a server that transmits an update program for the mobile unit control unit. When the mobile unit detects that an external diagnostic device is connected to the mobile unit at startup, the restriction control unit may notify the user of the presence of the update program and request disconnection of the external diagnostic device.
[0010] The restriction control unit may be configured to start receiving the update program from the server when it is detected that the external diagnostic device is connected to the mobile body when the mobile body is started and then the connection of the external diagnostic device is disconnected.
[0011] The restriction control unit may be configured to interrupt writing of the update program into the mobile body control unit when it is detected that the external diagnostic device is connected to the mobile body while the update program for updating the program of the mobile body control unit is being written into the mobile body control unit.
[0012] The restriction control unit may be configured to further perform a user notification requesting disconnection of the external diagnostic device when it is detected that the external diagnostic device is connected to the mobile body while the update program is being written to the mobile body control unit.
[0013] In a second aspect, a mobile object is provided. The mobile object includes the above-mentioned control system.
[0014] The mobile object may be a vehicle.
[0015] In a third aspect, a control method is provided. The control method is a control method executed by a control system. The control system includes a mobile body control unit that controls a mobile body, an update control unit that controls program updates for the mobile body control unit that controls the mobile body, and a communication path that serves as a path for communicating information with the update control unit. The path and the communication path that are connected to an external diagnostic device that diagnoses the mobile body control unit and are used to transmit information about the mobile body to the external diagnostic device are at least partially shared. The control method includes the following steps: when a program update and an external diagnostic device diagnoses the mobile body control unit, limiting one of the diagnosis performed by the external diagnostic device and the program update.
[0016] In a fourth aspect, a program is provided. The program causes a computer to function as a mobile body control unit that controls a mobile body. The program causes the computer to function as an update control unit that controls program updates for the mobile body control unit. The computer has a communication path for information communication between the mobile body control unit and the update control unit. The communication path and the path used to connect to an external diagnostic device that diagnoses the mobile body control unit and transmit information about the mobile body to the external diagnostic device share at least a portion. The program causes the computer to function as a restriction control unit that, when a program update and an external diagnostic device diagnoses the mobile body control unit, restricts either the external diagnostic device's diagnosis or the program update.
[0017] In addition, the above summary of the invention does not list all the necessary features of the present invention. In addition, sub-combinations of these features may also be inventions. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 An updating system 10 according to one embodiment is schematically shown.
[0019] Figure 2 The system configuration of the control system 200 is schematically shown.
[0020] Figure 3 FIG. 2 shows a data structure of management information data stored by the update control unit 220 .
[0021] Figure 4 An example of a sequence diagram related to program update processing is schematically shown.
[0022] Figure 5 Another example of a sequence diagram related to program update processing is schematically shown.
[0023] Figure 6 An example of user notification information 600 displayed on the IVI 299 is shown.
[0024] Figure 7 An example of user notification information 700 displayed on the MID 298 is shown.
[0025] Figure 8 is a flowchart illustrating an example of execution steps of a process related to program update.
[0026] Figure 9 is a flowchart illustrating an example of execution steps of a process related to program update.
[0027] Figure 10 is a flowchart illustrating an example of execution steps of a process related to program update.
[0028] Figure 11 An example of a computer 2000 is shown. DETAILED DESCRIPTION
[0029] The present invention will be described below by way of its embodiments, but the following embodiments do not limit the claimed invention. Furthermore, not all combinations of features described in the embodiments are essential to the solution of the present invention.
[0030] Figure 1 An update system 10 according to one embodiment is schematically shown. Update system 10 includes a vehicle 20 and a server 70. Vehicle 20 includes a control system 200. Control system 200 is responsible for controlling vehicle 20 and communicating with server 70 via a communication network 90. Communication network 90 includes an IP network such as the Internet, a P2P network, a dedicated line including a VPN, a virtual network, a mobile communication network, and the like.
[0031] In the vehicle 20, the control system 200 is provided with a plurality of ECUs (Electronic Control Units) for controlling the vehicle 20. The control system 200 obtains an update program for the ECU provided in the control system 200 from the outside. For example, the control system 200 receives the update program sent from the server 70 via the communication network 90 using wireless communication. The control system 200 reprograms the ECU provided in the control system 200 using the update program. Reprogramming is performed for the purpose of upgrading the functions of the ECU provided in the control system 200, etc. Thus, the control system 200 updates the ECU by reprogramming the ECU via OTA (Over The Air). In this embodiment, updating a device such as an ECU by an update program is referred to as "program update."
[0032] The control system 200 has a diagnostic port 34 for connecting a diagnostic device 30. The diagnostic port is, for example, an OBD (OnBoard Diagnostics) connector. The diagnostic device 30 is connected to the diagnostic port 34 via a cable 32. The diagnostic port 34 can communicate with multiple ECUs via the network of the vehicle 20. The diagnostic device 30 is a dedicated scan tool used, for example, for vehicle maintenance at a dealership. The dedicated scan tool is used to collect information stored in each ECU installed in the control system 200 via the network of the vehicle 20. The diagnostic port 34 is provided primarily for connecting such a dedicated scan tool. Therefore, when the dedicated scan tool is connected to the diagnostic port 34 to collect information, the information requested by the dedicated scan tool is expanded in the network of the vehicle 20, diversifying the amount of information flowing in the network of the vehicle 20 compared to a state where the dedicated scan tool is not connected. On the other hand, since commercially available scan tools different from the dedicated scan tool are also in circulation, there is a possibility that a commercially available scan tool may be connected to the diagnostic port 34. When a commercial scan tool is connected to the diagnostic port 34 , the program update may fail because the program update target ECU may not be able to communicate with other ECUs when the program update target ECU communicates with the commercial scan tool.
[0033] When performing an ECU program update, control system 200 determines whether a diagnostic device is connected to diagnostic port 34. If a diagnostic device is connected to diagnostic port 34, control system 200 limits at least a portion of the processing related to the ECU program update. For example, control system 200 halts the process of writing the update program to the ECU and subsequently halts the program update process. This reduces the possibility of commercially available scan tools or dedicated scan tools causing malfunctions during the program update.
[0034] Figure 2 The system configuration of the control system 200 is schematically shown. The control system 200 includes a TCU 201, an ECU 202, an ECU 204, an ECU 205, an ECU 206, an MID 298, an IVI 299, and a diagnostic port 34. Figure 2 , the FI 294, the battery 295, and the air conditioning device 296 are devices provided in the vehicle 20. The FI 294, the battery 295, and the air conditioning device 296 are examples of controlled devices of the vehicle 20.
[0035] ECU 202 is connected to TCU 201, ECU 204, ECU 205, and ECU 206 via an on-vehicle communication line 280. ECU 202 communicates information with TCU 201, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299 via on-vehicle communication line 280. ECU 202 controls TCU 201, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299 as a whole. For example, on-vehicle communication line 280 may include a CAN (Controller Area Network), an Ethernet network, or the like. On-vehicle communication line 280 is an example of a "communication path" that is a path for performing information communication.
[0036] TCU 201 is a telematics control unit. TCU 201 is primarily responsible for mobile communications. Under the control of ECU 202, TCU 201 transmits and receives data to and from server 70. Under the control of ECU 202, TCU 201 receives update programs from server 70 via mobile communications. TCU 201 can function as a wireless communication unit.
[0037] MID 298 is a multi-information display. IVI 299 is, for example, an in-vehicle infotainment (IVI). MID 298 and IVI 299 can function as a display control unit. IVI 299 has wireless LAN communication capabilities. Under the control of ECU 202, IVI 299 receives update programs sent from server 70 via wireless LAN communication.
[0038] The diagnostic port 34 is connected to the diagnostic device 30 for diagnosing the ECU 202, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299. The diagnostic port 34 is connected to the in-vehicle communication line 280. When the diagnostic device 30 is connected to the diagnostic port 34, the diagnostic device 30 receives vehicle 20 information stored in the ECU 202, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299 via the in-vehicle communication line 280. Thus, the path connected to the diagnostic device 30 and used to transmit vehicle 20 information to the diagnostic device 30 and at least a portion of the in-vehicle communication line 280 are shared. Furthermore, the diagnostic port 34 is connected to the CAN (Connected Controller Area Network) that constitutes a portion of the in-vehicle communication line 280, allowing the diagnostic device 30 to receive vehicle 20 information via CAN communication with the ECU 202, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299.
[0039] ECU 204, ECU 205, and ECU 206 are each an ECU serving as a vehicle control unit for controlling vehicle 20. ECU 204, ECU 205, and ECU 206 are examples of "mobile body control units." ECU 204, ECU 205, and ECU 206 control various devices installed in vehicle 20. For example, ECU 204 controls FI 294, a fuel injection device, and the like. ECU 205 controls battery 295, a high-voltage battery, and the like. ECU 206 controls air conditioning equipment 296 and the like.
[0040] In this embodiment, the control system 200 is shown as including a system configuration of a TCU 201, an ECU 202, an ECU 204, an ECU 205, an ECU 206, an MID 298, and an IVI 299. However, the system configuration of the control system 200 is not limited to the example of this embodiment. Furthermore, in this embodiment, as an example, the mobile control unit that can be the target of a program update is ECU 205, and ECU 202 functions as an update control unit for controlling the program update. Furthermore, the mobile control unit that can be the target of a program update is not limited to ECU 205. The mobile control unit that can be the target of a program update can be any of the TCU 201, ECU 202, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299.
[0041] ECU 202 includes an update control unit 220 and a restriction control unit 250. Update control unit 220 controls program updates for ECU 205. When a program update and diagnostic device is performing a diagnosis on ECU 205, restriction control unit 250 restricts either the diagnostic device 30's diagnostics or the program update. For example, restriction control unit 250 restricts program updates when a program update and diagnostic device 30 is performing a diagnosis on ECU 205.
[0042] While the program update and diagnostic device 30 are performing a diagnosis on ECU 205, restriction control unit 250 may prohibit the program update until the diagnostic device 30 stops performing the diagnosis. While the program update and diagnostic device 30 are performing a diagnosis on ECU 205, restriction control unit 250 may issue a user notification indicating that the diagnostic device 30 has stopped performing the diagnosis. The user may be, for example, an occupant of vehicle 20. For example, restriction control unit 250 may cause MID 298 and IVI 299 to issue the user notification. For example, restriction control unit 250 may display notification information to the user on MID 298 and IVI 299.
[0043] Update control unit 220 may execute configuration synchronization when vehicle 20 is started. This configuration synchronization is used to acquire management information stored in ECU 205, including at least the version of ECU 205 required for program updates of ECU 205, via in-vehicle communication line 280. For example, update control unit 220 may execute configuration synchronization when the ignition (IG) power of vehicle 20 is turned on. If, at vehicle 20 startup, it is detected that diagnostic device 30 is connected to vehicle 20, restriction control unit 250 may prohibit configuration synchronization until diagnostic device 30 is disconnected.
[0044] When it is detected that the diagnostic device 30 is connected to the vehicle 20 when the vehicle 20 is started, the restriction control portion 250 may prohibit reception of the update program for the ECU 205 from the server that transmits the update program.
[0045] Update control unit 220 may control receiving a notification of the presence of an update program from a server that transmits the update program for ECU 205. When connection of diagnostic device 30 to vehicle 20 is detected at startup of vehicle 20, restriction control unit 250 may perform user notification indicating the presence of the update program and user notification requesting disconnection of diagnostic device 30.
[0046] After detecting the connection between the diagnostic device 30 and the vehicle 20 when the vehicle 20 starts, the restriction control unit 250 may start the process of receiving the update program from the server when the connection between the diagnostic device 30 and the vehicle 20 is released.
[0047] When the connection of the diagnostic device 30 to the vehicle 20 is detected during writing of the update program to the ECU 205, the restriction control unit 250 may interrupt writing of the update program to the ECU 205. When the connection of the diagnostic device 30 to the vehicle 20 is detected during writing of the update program to the ECU 205, the restriction control unit 250 may further perform a user notification requesting disconnection of the diagnostic device 30.
[0048] Here, program updates are explained. The program update process is described for an ECU whose firmware storage device is a single-bank memory (so-called single-side ROM). In this case, since the ECU's firmware storage area is single, the update program cannot be written to the program storage area while the ECU is operating based on the program stored in the program storage area. When performing an ECU program update, the update control unit 220 transfers the update program to the ECU, stores it in a predetermined data storage area, and then instructs the ECU to update the program. Upon receiving the program update instruction, the ECU executes control code for the program update, writes the update program transferred to the data storage area, and activates the update program. Activating the update program, for example, involves setting the ECU's startup parameters so that the update program is loaded upon startup and control based on the updated program begins. Furthermore, when the ECU's firmware storage area is a single-bank memory, "a state in which an ECU program update is possible" may mean a state in which the update program is stored in the predetermined data storage area.
[0049] Next, we will describe the program update process when the ECU's internal memory is a dual-bank memory (i.e., double-sided ROM). In this case, since the ECU has two program storage areas for firmware storage, while the ECU is operating based on the program stored in the first program storage area, the update program can be written to the second program storage area. For example, the update program can be written to the second program storage area even while the vehicle 20 is driving. Therefore, after the update control unit 220 transfers the update program to the ECU, it instructs the ECU to write the update program to the second program storage area. When the update program is written to the ECU's second program storage area, the ECU becomes ready for program updates. When the update control unit 220 executes the ECU program update, it instructs the ECU to activate the update program written to the second program storage area. Activating the update program involves setting the ECU's startup parameters so that, for example, when the ECU boots up, the update program stored in the second program storage area is loaded and control based on the updated program begins. For example, activating the update program involves validating the second program storage area as a program read area and deactivating the first program storage area as a program read area. Thus, "ECU program update" is a concept including writing an update program into a program storage area of the ECU. Also, "ECU program update" is a concept including activating the update program written into the program storage area.
[0050] In this embodiment, a case will be described where the device to be updated with the program is the ECU 205. It is also assumed that the internal memory of the ECU 205 is a dual-bank memory.
[0051] Figure 3 The following figure shows the data structure of management information data stored by update control unit 220. When the IG power supply of vehicle 20 is turned on, update control unit 220 obtains management information stored in each device (TCU 201, ECU 204, ECU 205, ECU 206, MID 298, and IVI 299) targeted for program update via in-vehicle communication line 280. In this embodiment, obtaining management information via in-vehicle communication line 280 is referred to as "in-vehicle configuration synchronization."
[0052] Management information includes version information and identification information for each device. Version information may include each device's software version information. Version information may also include each device's hardware version information. Identification information may include each device's serial number. Update control unit 220 stores the management information acquired from each device in the internal memory of ECU 202, in association with the ID information assigned to the ECU.
[0053] When the IG power is turned on, ECU 202 transmits management information collected from each device to server 70. Server 70 stores the management information for each device received from vehicle 20. Based on the management information received from vehicle 20, server 70 determines whether a program update for each device is possible. When a program update for each device is possible, server 70 transmits a notification of the existence of an updated program to vehicle 20. For example, when an updated program with a newer software version than the current software version in the management information exists, a notification of the existence of the updated program is transmitted to vehicle 20. Upon receiving the notification of the existence of the updated program, update control unit 220 receives the updated program from server 70. In this way, server 70 determines the existence of an updated program based on the management information received from vehicle 20. Management information is an example of information required for program updates of the devices included in control system 200.
[0054] Furthermore, when diagnostic device 30 is connected to in-vehicle communication line 280 while the IG power supply is on, ECU 202 does not perform in-vehicle configuration synchronization and transmits a notification indicating the absence of management information to server 70. In this embodiment, transmitting management information or transmitting the absence of management information to server 70 is referred to as "external configuration synchronization."
[0055] Figure 4 An example of a sequence diagram related to program update processing is schematically shown. Figure 4The status of the IG switch, the execution status of the update-related process, the power supply status, the driving status of the vehicle 20 , and the connection status of the diagnostic device 30 are shown. Figure 4 The timing chart is a timing chart when the diagnostic device 30 is connected to the diagnostic port 34 before the IG switch is turned on. In addition, it is assumed that the device to be updated is the ECU 205.
[0056] At time t1, when the user turns off the IG switch, the update control unit 220 executes configuration synchronization. At this time, upon detecting that the diagnostic device 30 is connected to the in-vehicle communication line 280, the update control unit 220 only executes external configuration synchronization, not in-vehicle configuration synchronization (Configuration Synchronization 1). In this case, the server 70 determines the presence of an update program based on management information stored therein and, if so, transmits a notification of its presence to the vehicle 20. Upon receiving the notification from the server 70, the update control unit 220 notifies the user of the presence of the update program, notifies the user to remove the diagnostic device 30 from the diagnostic port 34 (Update Notification), and interrupts the update process (Standby).
[0057] At time t2, upon detecting that the diagnostic device 30 has been removed from the diagnostic port 34, the update control unit 220 executes in-vehicle configuration synchronization and external configuration synchronization (Configuration Synchronization 2) and downloads the update program from the server 70 (Download). Once the download is complete, the update control unit 220 writes the update program to the ECU 205, which is the target of the program update. Furthermore, since the internal memory for firmware storage in the ECU 205 is dual-bank memory, the update program can be written to the ECU 205 while the vehicle 20 is in motion.
[0058] At time t3, when the IG switch is turned off, the update control unit 220 confirms that the diagnostic device 30 is not connected to the diagnostic port 34 and executes a program update (update) on the ECU 205. The process executed by this program update is the activation of the update program described above. Furthermore, when executing the program update, the power supply of the devices required for the program update is turned on, and the power supply of other devices is turned off (updating state). When the program update is complete, the IG power supply is turned off.
[0059] like Figure 4 As shown in the timing diagram, when the IG power is on and the diagnostic device 30 is connected to the diagnostic port 34, even if an update program is available, the processes of receiving the update program from the server 70, writing the update program, and activating the update program can be disabled. Furthermore, when the diagnostic device 30 is removed from the diagnostic port 34, the update program can be received after re-execution of configuration synchronization, including in-vehicle configuration synchronization. This allows in-vehicle configuration synchronization to be properly executed and appropriate update programs to be received even when the diagnostic device 30 is not connected to the diagnostic port 34.
[0060] Figure 5 Schematically shows another example of a sequence diagram related to program update processing. Figure 4 same, Figure 5 The status of the IG switch, the execution status of the update-related process, the power supply status, the driving status of the vehicle 20 , and the connection status of the diagnostic device 30 are shown. Figure 5 The timing chart is a timing chart when the diagnostic device 30 is connected to the diagnostic port 34 during startup of the vehicle 20. It is assumed that the device to be updated with the program is the ECU 205.
[0061] exist Figure 5 Assume that the vehicle 20 is traveling and the update program of the ECU 205 is being downloaded at the start timing of the timing chart in FIG. 2. When the download is completed, the update control unit 220 writes the update program to the ECU 205 to be updated (write 1).
[0062] After the vehicle 20 stops, when the update control portion 220 detects connection of the diagnostic device 30 to the diagnostic port 34 at time t1 during writing of the update program, the update control portion 220 interrupts writing of the update program to the ECU 205 and requests the user to remove the diagnostic device 30 (removal notification).
[0063] When it is detected at time t2 that the diagnostic device 30 is removed from the diagnostic port 34 , the update control unit 220 stops the removal notification and enters a standby state to wait for the start of writing of the update program.
[0064] At time t3, the IG switch is turned off, shutting off the IG power supply. Then, at time t4, the IG switch is turned on. Update control unit 220 confirms that diagnostic device 30 is not connected to diagnostic port 34 and restarts writing the update program to ECU 205 (Write 2). When writing the update program is complete, ECU 205 program update (Update) is executed. The process executed by this program update is the activation of the update program described above. When the program update in ECU 205 is complete, vehicle 20 becomes drivable.
[0065] Figure 6 FIG2 shows an example of user notification information 600 displayed on the IVI 299. When it is detected that the diagnostic device 30 is connected to the diagnostic port 34, the update control section 220 displays the user notification information 600 on the IVI 299. Figure 4 The user notification information 600 is displayed during the "update notification" period in the timing diagram of Figure 5 The user notification information 600 is displayed during the "removal notification" period in the timing diagram.
[0066] User notification information 600 includes notification information 610 for the user and notification information 620. Notification information 610 indicates the presence of an update program. Notification information 620 indicates that the diagnostic device 30 has been disconnected. Notification information 620 may also indicate that diagnostics by the diagnostic device 30 have been stopped. While the diagnostic device 30 is connected to the diagnostic port 34, the update control unit 220 may display user notification information 600 on the IVI 299. The update control unit 220 may cause the IVI 299 to reproduce the contents of notification information 620 in audio.
[0067] Figure 7 FIG2 shows an example of user notification information 700 displayed on the MID 298. When the update control section 220 detects that the diagnostic device 30 is connected to the diagnostic port 34, the update control section 220 displays the user notification information 700 on the MID 298. Figure 4 The user notification information 700 is displayed during the "update notification" period in the timing diagram of Figure 5 The user notification information 700 is displayed during the "removal notification" period in the timing diagram.
[0068] User notification information 700 includes notification information 720 for the user. Notification information 720 indicates that the diagnostic device 30 has been disconnected. Notification information 720 may indicate that diagnostics by the diagnostic device 30 have been stopped. While the diagnostic device 30 is connected to the diagnostic port 34, the update control unit 220 may display the user notification information 700 on the MID 298.
[0069] In addition to the IVI 299, the update control unit 220 also displays user notification information through the MID 298. This allows the user to reliably recognize the need to disconnect the diagnostic device 30 to execute the update program. For example, even if the IVI 299 fails, the user can be notified through the MID 298.
[0070] Update control unit 220 may display user notification information 600 and user notification information 720 under the condition that vehicle 20 has a speed of 0 and a shift position of parking.
[0071] Figure 8 This is a flowchart showing an example of execution steps of processing related to program update. Figure 8 Flowchart processing. Figure 8 The flowchart shows the processing until the configuration synchronization is performed after the IG power supply is turned on according to the off operation of the IG switch.
[0072] In S802, the update control unit 220 determines whether the diagnostic device 30 is connected to the diagnostic port 34. The update control unit 220 may determine whether the diagnostic device 30 is connected to the diagnostic port 34 based on the signal state of the in-vehicle communication line 280. The update control unit 220 may determine whether the diagnostic device 30 is connected to the diagnostic port 34 within a period from when the IG switch is turned on until a predetermined time has passed.
[0073] If the diagnostic device 30 is not connected to the diagnostic port 34, the update control unit 220 performs in-vehicle configuration synchronization in step S804. Next, in step S806, the update control unit 220 transmits the management information acquired during in-vehicle configuration synchronization in step S804 to the server 70 (external configuration synchronization). If the diagnostic device 30 is determined to be connected to the diagnostic port 34 in step S802, the update control unit 220 transmits a message indicating "no configuration information" to the server 70 in step S808.
[0074] in addition, Figure 8 This is a flowchart for the case where there is no program update process in the interrupt state when the IG power is turned on. Figure 4 As described above, if the writing of the update program to ECU 205 is interrupted before the IG switch is turned on, the program update process is interrupted. In this case, the update control unit 220 restarts the program update process, assuming that the diagnostic device 30 is no longer connected to the diagnostic port 34. For example, the update control unit 220 restarts writing the update program to ECU 205. On the other hand, if the diagnostic device 30 is connected to the diagnostic port 34, the update control unit 220 issues a user notification indicating that the diagnostic device 30 has been removed from the diagnostic port 34. For example, the update control unit 220 displays user notification information 700 on the IVI 299 and user notification information 600 on the MID 298.
[0075] Figure 9 is a flowchart illustrating an example of execution steps of a process related to program update. Figure 9 The processing in the flowchart is processing when the existence notification information of the update program is received from the server 70.
[0076] Upon receiving notification of the presence of the updated program from server 70, update control unit 220 determines in step S902 whether diagnostic device 30 is connected to diagnostic port 34. If diagnostic device 30 is connected to diagnostic port 34, the process proceeds to step S904; if not, the process proceeds to step S910.
[0077] At S904, the update control unit 220 notifies the user that the diagnostic device 30 has been removed from the diagnostic port 34, and the process of this flowchart ends. At S904, the update control unit 220 displays, for example, user notification information 700 on the IVI 299 and user notification information 600 on the MID 298. This allows the user to be notified of the presence of an update program even when the diagnostic device 30 is connected to the diagnostic port 34, thereby preventing important update programs from remaining unapplied for an extended period of time.
[0078] If it is determined in S902 that the diagnostic device 30 is not connected to the diagnostic port 34 , then in S910 the update control unit 220 downloads update data including the update program from the server 70 and transfers it to the ECU 205 to be updated.
[0079] When the transfer of the update program is complete, in S912, update control unit 220 instructs ECU 205 to write the updated program transferred to ECU 205. In S914, it is determined whether diagnostic device 30 is connected to diagnostic port 34. If diagnostic device 30 is not connected to diagnostic port 34, the process proceeds to S916; if diagnostic device 30 is connected to diagnostic port 34, the process proceeds to S918.
[0080] At S916, update control unit 220 determines whether writing of the update program is complete. Upon receiving a notification from ECU 205 indicating completion of writing of the update program via in-vehicle communication line 280, update control unit 220 determines that writing of the update program is complete. If writing of the update program is not complete, the process proceeds to S914. If writing of the update program is complete, the process in this flowchart ends.
[0081] If it is determined in S914 that the diagnostic device 30 is connected to the diagnostic port 34 , the update control unit 220 instructs the ECU 205 to stop writing the update program in S918 , and the process proceeds to S904 .
[0082] Figure 10 This is a flowchart showing an example of execution steps of processing related to program update. Figure 10 Flowchart processing.
[0083] At S1002, update control unit 220 determines whether update preparation is complete. For example, if a notification indicating that update program writing is complete is received from ECU 205 before the IG switch is turned off, update control unit 220 determines that update preparation is complete. If update preparation is not complete, the process in this flowchart ends. If update preparation is complete, at S1004, it is determined whether diagnostic device 30 is connected to diagnostic port 34. If so, the process proceeds to S1006; otherwise, the process proceeds to S1010.
[0084] If the diagnostic device 30 is not connected to the diagnostic port 34, a determination is made in S1010 as to whether the user has consented to the execution of the system update. For example, the update control unit 220 displays a screen on the IVI 299 for accepting a user instruction to execute the system update. If the user instruction to execute the system update is received from the IVI 299, the update control unit 220 determines that the user has consented to the execution of the system update. If the user has not consented to the execution of the system update, the process in this flowchart ends.
[0085] If the user agrees to execute the system update, in S1012, the ECU 205 is instructed to start updating the program of the ECU 205. When a notification indicating the completion of the program update is received from the ECU 205 via the in-vehicle communication line 280, in S1014, the update control unit 220 notifies the server 70 of the completion of the program update and ends the processing in this flowchart.
[0086] If it is determined in S1004 that the diagnostic device 30 is connected to the diagnostic port 34, the update control unit 220 issues a user notification in S1006 indicating that the diagnostic device 30 has been removed from the diagnostic port 34, and the process of this flowchart ends. In S1006, the update control unit 220 displays user notification information 700 on the IVI 299 and user notification information 600 on the MID 298, for example.
[0087] Next, in S1008, the update control unit 220 determines whether the diagnostic device 30 has been removed from the diagnostic port 34 within a predetermined time. If the diagnostic device 30 has been removed from the diagnostic port 34 within the predetermined time, the process proceeds to S1010. If the diagnostic device 30 has not been removed from the diagnostic port 34 within the predetermined time, the process of this flowchart ends. When the process of this flowchart ends, the IG power supply state of the vehicle 20 becomes off.
[0088] As described above, according to the control system 200 of this embodiment, when executing a program update, ECU program updates are restricted when a diagnostic device is connected to the diagnostic port 34. This reduces the possibility of program update failures caused by commercially available scan tools. Furthermore, when executing a process that requires disconnection of external communication via the diagnostic port 34, such as a program update, the ECU program update is halted to notify the user of the removal of the diagnostic device 30. This prevents the use of the diagnostic port 34 from being prohibited during normal operation, thereby improving user convenience.
[0089] In addition, in the embodiment described above, a specific example of a case where a program update is restricted when the diagnostic device is connected to the diagnostic port 34 is mainly described. On the other hand, in the case of a program update, when the diagnostic device is connected to the diagnostic port 34, the diagnosis of the diagnostic device can be restricted. For example, the restriction control unit 250 can prohibit each device in the control system 200 from communicating with the diagnostic device. In addition, the restriction control unit 250 can also cut off the communication line between the diagnostic port 34 and the vehicle-mounted communication line 280. For example, a switching circuit for switching the connection and non-connection between the diagnostic port 34 and the vehicle-mounted communication line 280 can also be set at the connection point of the diagnostic port 34 and the vehicle-mounted communication line 280, and the communication line between the diagnostic port 34 and the vehicle-mounted communication line 280 can be cut off by the switching circuit.
[0090] In addition, the vehicle 20 is a vehicle as an example of a transport device. The vehicle may be a car equipped with an internal combustion engine, an electric car, a fuel cell vehicle (FCV), or the like. Cars include buses, trucks, two-wheeled vehicles, etc. The vehicle may be a saddle-type vehicle, etc., or a motorcycle. As transport devices, in addition to vehicles, there are also devices such as aircraft including unmanned aerial vehicles, ships, etc. The transport device may be any device that transports people or goods. The transport device is an example of a mobile body. The mobile body is not limited to the transport device, and may be any movable device.
[0091] Figure 11 This figure illustrates an example of a computer 2000 that can fully or partially embody various embodiments of the present invention. Programs installed on computer 2000 can cause computer 2000 to function as a system, device, or each unit of a control system, etc., related to the embodiments, to perform operations associated with the device or each unit of the device, and / or to perform processes or steps related to the embodiments. Such programs can be executed by CPU 2012 to cause computer 2000 to perform the processing flow described in this specification and specific operations associated with some or all of the functional blocks in the block diagrams.
[0092] The computer 2000 according to this embodiment includes a CPU 2012 and a RAM 2014, which are interconnected via a main controller 2010. The computer 2000 further includes a ROM 2026, a flash memory 2024, a communication interface 2022, and an input / output chip 2040. The ROM 2026, the flash memory 2024, the communication interface 2022, and the input / output chip 2040 are connected to the main controller 2010 via the input / output controller 2020.
[0093] The CPU 2012 operates according to the programs stored in the ROM 2026 and the RAM 2014 , thereby controlling each unit.
[0094] The communication interface 2022 communicates with other electronic devices via a network. The flash memory 2024 stores programs and data used by the CPU 2012 in the computer 2000. The ROM 2026 stores startup programs and the like executed by the computer 2000 when activated, and / or programs dependent on the hardware of the computer 2000. The input / output chip 2040 can also connect various input / output units such as a keyboard, mouse, and monitor to the input / output controller 2020 via input / output ports such as a serial port, a parallel port, a keyboard port, a mouse port, a monitor port, a USB port, and an HDMI (registered trademark) port.
[0095] The program is provided via a computer-readable medium such as a CD-ROM, DVD-ROM, or USB flash drive, or via a network. RAM 2014, ROM 2026, or flash memory 2024 are examples of computer-readable media. The program is installed in flash memory 2024, RAM 2014, or ROM 2026 and executed by CPU 2012. The information processing described in these programs is read by computer 2000, enabling collaboration between the program and the various types of hardware resources described above. A device or method can be constructed by implementing information manipulation or processing in accordance with the use of computer 2000.
[0096] For example, when communication is performed between the computer 2000 and an external device, the CPU 2012 can execute a communication program loaded into the RAM 2014 and, based on the processing described in the communication program, instruct the communication interface 2022 to perform communication processing. Under the control of the CPU 2012, the communication interface 2022 reads transmission data stored in a transmission buffer area provided in the RAM 2014 and a recording medium such as the flash memory 2024, transmits the read transmission data to the network, and writes reception data received from the network to a reception buffer area provided on the recording medium.
[0097] Furthermore, the CPU 2012 can read all or a required portion of a file or database stored in a recording medium such as the flash memory 2024 into the RAM 2014 and perform various processes on the data in the RAM 2014. The CPU 2012 then writes the processed data back to the recording medium.
[0098] Various types of programs, data, tables, and various information such as databases can be saved to a recording medium and applied to information processing. CPU2012 can perform various processing described in this specification, including various operations specified by the instruction sequence of the program, information processing, conditional judgment, conditional branching, unconditional branching, information retrieval / replacement, etc., on the data read from RAM2014, and write the results back to RAM2014. In addition, CPU2012 can retrieve information in files, databases, etc. in the recording medium. For example, when a plurality of items each having an attribute value of a first attribute associated with an attribute value of a second attribute are stored in a recording medium, CPU2012 can retrieve an item that specifies an attribute value of the first attribute and is consistent with the condition from the plurality of items, read the attribute value of the second attribute stored in the item, and thereby obtain the attribute value of the second attribute associated with the first attribute that meets the pre-set condition.
[0099] The programs or software modules described above can be stored in a computer-readable medium on or near the computer 2000. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can be used as the computer-readable medium. The program stored in the computer-readable medium can be provided to the computer 2000 via the network.
[0100] Programs installed in computer 2000 and causing computer 2000 to function as control system 200 can be run on CPU 2012 and other devices, causing computer 2000 to function as each unit of control system 200. Information processing described in these programs is read into computer 2000, causing it to function as specific units that collaborate with the various hardware resources described above, namely, the units of control system 200. Furthermore, by utilizing these specific units to perform calculations or processing of information corresponding to the intended use of computer 2000 in this embodiment, a unique control system 200 corresponding to the intended use can be constructed.
[0101] Various embodiments are described with reference to block diagrams, etc. In the block diagrams, each functional block may represent (1) a step of a process for performing an operation or (2) each unit of a device having the function of performing an operation. Specific steps and each unit may be implemented by a dedicated circuit, a programmable circuit supplied together with computer-readable instructions stored on a computer-readable medium, and / or a processor supplied together with computer-readable instructions stored on a computer-readable medium. The dedicated circuit may include digital and / or analog hardware circuits, and may also include integrated circuits (ICs) and / or discrete circuits. The programmable circuit may include logical AND, logical OR, logical XOR, logical NAND, logical NOR, and other logical operations, flip-flops, registers, field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), and other reconfigurable hardware circuits including memory elements.
[0102] A computer-readable medium may include any tangible device capable of storing instructions for execution by an appropriate device. Consequently, a computer-readable medium having instructions stored therein constitutes at least a portion of an article containing instructions executable to implement a means for performing the operations specified in the process flow or block diagram. Examples of computer-readable media include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, and the like. More specific examples of computer-readable media include floppy disks (registered trademark), flexible magnetic disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), electrically erasable programmable read-only memories (EEPROM), static random access memories (SRAM), compact disc read-only memories (CD-ROMs), digital versatile disks (DVDs), Blu-ray discs (RTMs), memory sticks, integrated circuit cards, and the like.
[0103] Computer-readable instructions may include assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine delegate instructions, microcode, firmware instructions, state setting data, or any source code or object code described in any combination of one or more programming languages including object-oriented programming languages such as Smalltalk, JAVA (registered trademark), C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages.
[0104] Computer-readable instructions are provided to a processor or programmable circuit of a general-purpose computer, a special-purpose computer, or other programmable data processing device via a local area network (LAN) or a wide area network (WAN) such as the Internet. The computer-readable instructions can be executed to implement a unit for performing the operations specified in the processing flow or block diagram. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, etc.
[0105] While the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications or improvements can be made to the above embodiments. It will be apparent from the claims that such modifications or improvements are also within the technical scope of the present invention.
[0106] Regarding the order in which actions, processes, steps, and processes, etc., in the apparatus, system, program, and method described in the claims, specifications, and drawings, it should be noted that unless specifically indicated by "before," "preceding," or the like, these processes may be performed in any order, as long as the output of a previous process is not used in a subsequent process. Even if the process flow in the claims, specifications, and drawings is described using "first," "next," or the like for convenience, this does not necessarily mean that the process must be performed in that order.
[0107] [Explanation of Reference Numerals]
[0108] 10. Update the system
[0109] 20 vehicles
[0110] 30 Diagnostic Devices
[0111] 32 Cable
[0112] 34 Diagnostic port
[0113] 70 servers
[0114] 90 Communication Network
[0115] 200 Control System
[0116] 201 TCU
[0117] 202 ECU
[0118] 204 ECU
[0119] 205 ECU
[0120] 206 ECU
[0121] 220 Update Control Department
[0122] 250 Restriction Control Department
[0123] 280 Vehicle Communication Line
[0124] 294 FI
[0125] 295 battery
[0126] 296 Air conditioning equipment
[0127] 298 MID
[0128] 299 IVI
[0129] 600 User Notification Information
[0130] 610 Notification Information
[0131] 620 Notification Information
[0132] 700 User notification information
[0133] 720 Notification Information
[0134] 2000 Computer
[0135] 2010 Main Controller
[0136] 2012 CPU
[0137] 2014 RAM
[0138] 2020 Input / Output Controller
[0139] 2022 Communication Interface
[0140] 2024 Flash Memory
[0141] 2026 ROM
[0142] 2040 Input / Output Chip.
Claims
1. A control system, wherein: have: a moving body control unit that controls the moving body; an update control unit that controls program update of the mobile body control unit; as well as a communication path for information communication between the mobile body control unit and the update control unit; The communication path is at least partially shared with an external scanning device that is connected to an external scanning device that performs diagnosis on the mobile body control unit and is used to transmit information about the mobile body to the external scanning device. The control system includes a restriction control unit configured to restrict one of the diagnosis performed by the external scanning device and the program update when the program update and the diagnosis of the movable body control unit by the external scanning device are performed.
2. The control system according to claim 1, wherein: When the program update and the diagnosis of the movable body control unit by the external scanning device are being performed, the restriction control unit prohibits the program update until the diagnosis by the external scanning device is terminated.
3. The control system according to claim 2, wherein: When the program update and the diagnosis of the movable body control unit by the external scanning device are being performed, the restriction control unit performs a user notification indicating that the diagnosis by the external scanning device is stopped.
4. The control system according to claim 2 or 3, wherein: The restriction control section prohibits reception of the update program of the mobile body control section from a server that transmits the update program when the connection of the external scanning device to the mobile body is detected when the mobile body starts.
5. The control system according to claim 2 or 3, wherein: The update control unit controls reception of a notification of the presence of the update program of the mobile body control unit from a server that transmits the update program of the mobile body control unit. When the connection of the external scanning device to the mobile body is detected when the mobile body starts, the restriction control unit performs user notification indicating the presence of the update program and user notification requesting release of the connection of the external scanning device.
6. The control system according to claim 5, wherein: The restriction control section starts receiving the update program from the server when it is detected that the external scanning device is connected to the mobile body when the mobile body starts, and then the connection of the external scanning device is released.
7. The control system according to claim 2 or 3, wherein: The restriction control section interrupts writing of the update program to the mobile body control section when it is detected that the external scanning device is connected to the mobile body during writing of the update program for the program update to the mobile body control section.
8. The control system according to claim 7, wherein: When it is detected that the external scanning device is connected to the mobile body during writing of the update program to the mobile body control section, the restriction control section further performs user notification requesting release of the connection of the external scanning device.
9. A control system, wherein: have: a moving body control unit that controls the moving body; an update control unit that controls program update of the mobile body control unit; as well as a communication path for information communication between the mobile body control unit and the update control unit; The communication path is at least partially shared with an external diagnostic device that diagnoses the mobile body control unit and is used to transmit information about the mobile body to the external diagnostic device. The control system includes a restriction control unit that restricts one of the diagnosis performed by the external diagnostic device and the program update when the program update and the diagnosis of the movable body control unit by the external diagnostic device are performed. When the program update and the diagnosis of the movable body control unit by the external diagnostic device are being performed, the restriction control unit prohibits the program update until the diagnosis by the external diagnostic device is terminated. When the mobile body is started, the update control unit performs configuration synchronization, wherein the configuration synchronization acquires management information stored in the mobile body control unit through the communication path, the management information including at least a version of the mobile body control unit required for program update of the mobile body control unit. When it is detected that the external diagnostic device is connected to the moving body when the moving body starts, the restriction control portion prohibits the configuration synchronization until the connection of the external diagnostic device is released.
10. A mobile object, wherein: A control system according to any one of claims 1 to 9 is provided.
11. The moving object according to claim 10, wherein The mobile object is a vehicle.
12. A control method is a control method performed by a control system, wherein: The control system includes a moving body control unit for controlling a moving body, an update control unit for controlling an update of a program for the moving body control unit for controlling the moving body, and a communication path as a path for communicating information with the update control unit. The communication path is at least partially shared with an external scanning device that is connected to an external scanning device that performs diagnosis on the mobile body control unit and is used to transmit information about the mobile body to the external scanning device. The control method has the following features: When the program update and the diagnosis of the movable body control unit by the external scanning device are performed, a step of limiting one of the diagnosis and the program update performed by the external scanning device is performed.
13. A computer-readable storage medium storing a program, wherein: The program causes the computer to function as the following unit: a moving body control unit that controls the moving body; an update control unit that controls program update of the mobile body control unit, The computer includes a communication path for information communication between the mobile body control unit and the update control unit. The communication path is at least partially shared with an external scanning device that is connected to an external scanning device that performs diagnosis on the mobile body control unit and is used to transmit information about the mobile body to the external scanning device. The program causes the computer to function as a restriction control unit that restricts one of the diagnosis performed by the external scanning device and the program update when the program update and the diagnosis of the movable body control unit by the external scanning device are performed.
Citation Information
Patent Citations
Electronic control device, electronic control system for vehicle, and data structure of specification data
JP2020027666A
In-vehicle update device, update process method, and update process program
CN112020456A
Vehicle HMI replacement
US20120221188A1