Vehicle software update method and vehicle system

By managing software updates for downstream ECUs through a regional control unit, predicting battery voltage, and controlling it within a voltage threshold range, the problem of insufficient battery power during vehicle software updates is solved, achieving efficient power management and update processes.

CN115202681BActive Publication Date: 2026-02-03YAZAKI CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210285689.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-04-07
Filing Date
2022-03-22
Publication Date
2026-02-03
Estimated Expiration
2042-03-22

AI Technical Summary

Technical Problem

During vehicle software updates, insufficient battery power can cause interruptions and wasted time, especially when multiple ECUs need to be updated. Existing technology cannot effectively manage power consumption, leading to repeated updates and extended update times.

Method used

The system manages software updates for downstream ECUs through a regional control unit, predicts battery voltage and controls updates within voltage threshold ranges, and switches operating modes to reduce power consumption, including switching to power-saving mode when the voltage is below a warning threshold, and ensuring that the battery voltage does not fall below the threshold before the update is complete.

Benefits of technology

It reduces the frequency of software update interruptions and power waste, improves update efficiency, prevents battery depletion, and shortens update time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115202681B_ABST
    Figure CN115202681B_ABST
Patent Text Reader

Abstract

A vehicle-mounted software update method includes: after starting software update, acquiring a voltage measurement value of a vehicle-mounted power supply; in a case where the voltage measurement value is equal to or less than a second threshold value, acquiring a progress rate in the software update. The software update is interrupted in a case where the progress rate is less than a set value. In a case where the progress rate is equal to or greater than the set value, an operation mode of the region control unit is switched to a power saving mode, and a second predicted voltage value of the vehicle-mounted power supply at a time when the update is completed is calculated. The software update is continued in a case where the second predicted voltage value is greater than a first threshold value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method for updating vehicle software and a vehicle system. Background Technology

[0002] In recent vehicles, an over-the-air (OTA) software update system has been attempted, which uses wireless communication to update the vehicle's software. However, this software update has encountered various problems.

[0003] Therefore, for example, Patent Document 1 discloses calculating the remaining battery capacity based on the read voltage value and temperature, and predicting the battery power consumed during memory rewriting (current value × time) based on the time and current value required to rewrite the memory. Furthermore, Patent Document 1 discloses restarting the rewrite process after reducing power consumption to rewrite areas where the remaining capacity does not exceed the predicted power consumption.

[0004] Patent document 2 discloses a method for predicting the battery state after rewriting the ECU program based on the battery state at the start of the rewriting process and the planned processing time for rewriting the program, and rewriting the program when the predicted battery state meets the conditions for restarting the vehicle.

[0005] Patent Document 3 discloses a first acquisition unit for acquiring the remaining battery power, a second acquisition unit for acquiring a predicted amount of power consumption for each vehicle control device up to the point in time when the control program update is completed, and a determination unit for determining whether the predicted remaining battery power at the point in time when the update is completed is equal to or greater than a threshold based on the remaining battery power and the predicted power consumption. Furthermore, Patent Document 3 discloses that when it is determined during the control program update that the predicted remaining power is less than a threshold, the user interface device performs information output to prompt the start of battery charging.

[0006] Patent Document 1: JP-A-2008-155892;

[0007] Patent Document 2: WO-A1-2012 / 017719;

[0008] Patent document 3: WO-A1-2019 / 030985. Summary of the Invention

[0009] As disclosed in Patent Documents 1-3, when updating software, control is typically performed taking into account the remaining battery capacity and the predicted amount of power consumption during the software update. However, for various reasons, the state may not actually change as predicted.

[0010] Therefore, software updates may be interrupted midway. Then, after returning to a state where the software can be updated again, the software will start updating again from scratch. Thus, repeating the same operation multiple times from the beginning results in redundant processing and consumes extra power. Furthermore, when the number of electronic control units (ECUs) to be updated is large, the time required to complete a software update for the entire system can be significantly extended due to the added time-wasting repetitive processing.

[0011] This disclosure is made in response to the above circumstances, and its purpose is to provide an in-vehicle software update method and in-vehicle system that can reduce power consumption waste and time waste caused by software update interruptions.

[0012] This disclosure provides an in-vehicle software update method for updating software in an in-vehicle system, the in-vehicle system including a region control unit configured to manage multiple control targets connected downstream of the region control unit. The in-vehicle software update method includes: storing update data in a first region pre-allocated in the memory of the region control unit; calculating a first predicted voltage value of the vehicle power supply at the time of update completion before starting the software update using the update data; starting the software update if the first predicted voltage value is greater than the first threshold; acquiring a voltage measurement value of the vehicle power supply after starting the software update; acquiring a progress rate in the software update if the voltage measurement value is equal to or less than the second threshold, the second threshold being greater than the first threshold; interrupting the software update if the progress rate is less than the set value; and switching the operating mode of the region control unit to a power-saving mode if the progress rate is equal to or greater than the set value, calculating a second predicted voltage value of the vehicle power supply at the time of update completion, and continuing the software update if the second predicted voltage value is greater than the first threshold.

[0013] This disclosure provides an in-vehicle system, including: a region control unit configured to manage a plurality of control targets connected downstream of the region control unit, wherein the memory of the region control unit has a first region configured to store update data that can be used for software updates of the plurality of control targets, and wherein the region control unit is configured to: calculate a first predicted voltage value of the vehicle power supply at an update completion time before starting a software update using the update data in the first region; start the software update if the first predicted voltage value is greater than a first threshold; after starting the software update, acquire a voltage measurement value of the vehicle power supply; if the voltage measurement value is equal to or less than a second threshold, the second threshold being greater than the first threshold; interrupt the software update if the progress rate is less than the set value; and switch the operating mode of the region control unit to a power-saving mode if the progress rate is equal to or greater than the set value, calculate a second predicted voltage value of the vehicle power supply at the update completion time, and continue the software update if the second predicted voltage value is greater than the first threshold.

[0014] This disclosure has been briefly described above. Furthermore, the details of this disclosure will be further explained by reading the accompanying drawings, which illustrate aspects of the invention for implementation (hereinafter referred to as "Embodiments"). Attached Figure Description

[0015] Figure 1 This is a block diagram illustrating the construction of an in-vehicle system according to an embodiment of the present disclosure;

[0016] Figure 2 It shows the relationship with Figure 1 Block diagrams of in-vehicle systems in different states;

[0017] Figure 3 This is a block diagram illustrating a specific example of the internal structure of a regional ECU;

[0018] Figure 4 It is shown in Figure 3 A block diagram illustrating an example of state changes for each component in the ECU region shown;

[0019] Figure 5 This is a timing diagram illustrating an example of battery voltage changes when a software update cannot be initiated via voltage prediction;

[0020] Figure 6 This is a timing diagram illustrating an example of battery voltage changes when a software update can be initiated via voltage prediction;

[0021] Figure 7 This is a flowchart illustrating the control content of software updates in a regional ECU;

[0022] Figure 8 This is a block diagram showing the internal structure of the regional ECU in the modified example;

[0023] Figure 9 This is a block diagram illustrating an example of the state changes of each component in a regional ECU in software update mode;

[0024] Figure 10 This is a block diagram illustrating an example of state changes of components in a region ECU during sleep mode; and

[0025] Figure 11 It is shown in Figure 8 A flowchart of the mode switching control for the ECU in the middle region. Detailed Implementation

[0026] The specific embodiments of this disclosure will now be described with reference to the accompanying drawings.

[0027] <Vehicle System Structure>

[0028] Figure 1 This is a block diagram illustrating the construction of an in-vehicle system 10 according to an embodiment of the present disclosure. Figure 2 It shows the relationship with Figure 1 Block diagram of the vehicle system 10 in different states.

[0029] Installed Figure 1 The onboard system 10 on the vehicle 17 shown includes a central ECU 11, a regional ECU 12, a terminal ECU 13, and a smart actuator 14. The central ECU 11 is connected to the regional ECU 12 via a communication line 18, and the regional ECU 12 is connected to the terminal ECU 13 and the smart actuator 14 via a communication line 19.

[0030] In a real vehicle, vehicle 17 is divided into multiple zones, and each zone ECU 12 is set up for a specific zone. That is, the central ECU 11 is connected to multiple zone ECUs 12. These zones can be assigned to represent multiple zones such as the left and right positions in the space of vehicle 17, or they can be assigned to represent multiple zones representing different functional groups.

[0031] The central ECU 11 has the function of integrating and managing the entire vehicle system 10, which includes multiple areas, and also has a gateway function for securely connecting the vehicle system 10 to a communication network such as the Internet outside the vehicle using wireless communication functions.

[0032] therefore, Figure 1The regional ECU 12 shown is connected downstream of the central ECU 11, which is located at the highest level in the vehicle 17. The regional ECU 12 manages the terminal ECU 13 and the smart actuator 14 connected downstream of the regional ECU 12.

[0033] The central ECU 11, regional ECU 12, and terminal ECU 13 each include a microcomputer capable of independent control and communication functions. The intelligent actuator 14 has the function of changing actuator functions through software and communication functions.

[0034] therefore, Figure 1 The illustrated regional ECU 12, terminal ECU 13, and intelligent actuator 14 each include software consisting of programs and data required for their operation. For example, each piece of software is in a rewritable state by being installed on non-volatile memory. Therefore, each piece of software can be updated as needed. In this embodiment, these software updates (SUs) can be performed via over-the-air (OTA) downloads using wireless communication.

[0035] Figure 1 The onboard system 10 shown manages all updates to the software used by the regional ECU 12 and the software used by the terminal ECU 13 and the smart actuator 14, respectively. The regional ECU 12 includes a dedicated update storage area 12a (OTA SU storage area).

[0036] exist Figure 1 In the vehicle 17 shown, the power required for the operation of the on-board system 10 can be supplied by the on-board battery 15 and alternator 16 located in the vehicle 17. However, when the engine stops, the alternator 16 also stops generating electricity, so when the vehicle 17 is parked, the power stored in the on-board battery 15 can be used independently.

[0037] When the vehicle battery 15 is abnormally depleted, the power supply from the vehicle battery 15 may be limited. Whether the alternator 16 is running can be identified by starting or stopping the ignition. Figure 1 The area shown, ECU12, monitors the ignition signal SG-IG output from vehicle 17 to identify whether the ignition is started or stopped.

[0038] In this embodiment, the vehicle system 10 is equipped with a cloud 20 that serves as a source of update data for updating the software of each unit. For example, the cloud 20 is located on a server in a pre-defined data center. The cloud 20 has the function of providing the update data required for software updates of the vehicle system 10.

[0039] Therefore, when the software for the regional ECU 12, the software for the terminal ECU 13, and the software for the intelligent actuator 14 are ready to be updated, such as Figure 1As shown, the regional ECU update program 31, terminal ECU update program 32, and intelligent actuator update program 33 corresponding to each update target are stored in the cloud 20.

[0040] exist Figure 1 In this state, the vehicle system 10 can download and obtain the regional ECU update program 31, the terminal ECU update program 32, and the intelligent actuator update program 33 via wireless data communication 25. Figure 1 In the example shown, the regional ECU update program 31A downloaded from cloud 20 is stored in the update-dedicated storage area (first area) 12a. The regional ECU update program 31A is identical to the copy of the regional ECU update program 31 on cloud 20.

[0041] The update processing unit 12b of the regional ECU 12 can read the regional ECU update program 31A in the dedicated update storage area 12a and update its software.

[0042] exist Figure 2 In this state, the terminal ECU update program 32A and the smart actuator update program 33A obtained through download are stored in the dedicated update storage area 12a. The terminal ECU update program 32A and the smart actuator update program 33A are copies with the same content as the terminal ECU update program 32 and the smart actuator update program 33 on the cloud 20, respectively.

[0043] Therefore, in Figure 2 In this state, update processing unit 13a can obtain the terminal ECU update program 32A in the dedicated update storage area 12a via communication and update the software of terminal ECU 13. Update processing unit 14a can obtain the smart actuator update program 33A in the dedicated update storage area 12a via communication and update the software of smart actuator 14.

[0044] Typically, when large amounts of update data are downloaded via wireless data communication 25, each unit of the vehicle system 10 can be expected to consume a relatively large amount of power from the power source over a prolonged period. Therefore, in this embodiment, each update data is downloaded when the vehicle 17 is started.

[0045] On the other hand, when the software on the vehicle system 10 is actually updated using the downloaded update data, it is desirable that the update is unlikely to be affected by interruptions from other ECUs unrelated to the update target. When the software is actually updated, the operation of other ECUs unrelated to the update target can be restricted to reduce the power consumption of the entire system. Therefore, in this embodiment, the vehicle system 10 performs the software update when the ignition of the vehicle 17 is turned off.

[0046] However, when the ignition of vehicle 17 is turned off, only the power stored in the on-board battery 15 can be supplied, so it is necessary to prevent vehicle 17 from becoming immobile due to battery depletion. A considerable amount of time is required to read the downloaded update data, begin the software update, and complete the software update. Since the regional ECU 12 and others continuously consume power from the power source during this period, the regional ECU 12 needs to perform special controls, described later, to prevent battery depletion.

[0047] <Regional ECU Structure>

[0048] Figure 3 This is a block diagram showing a specific example of the internal structure of region ECU12.

[0049] Figure 3 The area ECU12 shown includes control circuit 41, power supply circuit 42, communication circuit 43, standby input circuits 44a-44d for four systems, input circuits 45a-45f for six systems, output circuits 46 and 47, communication circuit 48, standby output circuits 49a-49d for four systems, and output circuits 51a-51f for six systems.

[0050] The control circuit 41 includes various control elements similar to a general computer unit, such as a processor (the microcomputer in this embodiment) and a memory. Various software required for the operation of the microcomputer are stored in non-volatile memory for easy updating. When the instructions of the software stored in the memory (e.g., a non-transitory computer-readable medium) are executed by the processor, they cause the region ECU 12 to perform operations such as the vehicle software update method in this embodiment.

[0051] exist Figure 3 In the example, two ECUs, 13A and 13B, are connected to the output sides of the output circuits 46 and 47 of the region ECU12.

[0052] The power circuit 42 in the regional ECU 12 is connected to the power supply and ground (GND) of the vehicle 17.

[0053] The communication circuits 43 and 48 in the area ECU 12 are connected to a communication network such as the Controller Area Network (CAN) on the vehicle 17 and are used for communication between the area ECU 12 and other ECUs.

[0054] Each of the four system standby input circuits 44a-44d and the six system input circuits 45a-45f is an interface for inputting signals from pre-assigned onboard electronic components, and is divided into three types. The six system input circuits 45a-45f are divided into a group that only allows operation in normal states such as ignition start-up. The four system standby input circuits 44a-44d are divided into a standby group, allowing standby operation even when ignition is off, and are further divided into "M: Must" and "W: Required" groups according to their importance.

[0055] The standby group (M) is assigned critical functions that are expected to operate until low voltage is reached, such as event data loggers or intrusion detection. The standby group (W) is assigned comfort and convenience functions of relatively lower importance, such as remote keyless devices or smart keys.

[0056] The standby output circuits 49a-49d required by the four systems and the output circuits 51a-51f required by the six systems are interfaces for outputting signals to pre-assigned vehicle electronic components, and are divided into three types as described above.

[0057] That is, the output circuits 51a-51f of the six systems are divided into a group that is only allowed to operate in normal conditions such as starting ignition. The standby output circuits 49a-49d of the four systems are divided into standby group (M) or standby group (W).

[0058] <Regional ECU Status Changes>

[0059] Figure 4 It is shown in Figure 3 A block diagram illustrating an example of state changes for each component in the ECU12 region shown.

[0060] exist Figure 4 In the diagram, among the components inside area ECU 12, those in a closed state where no power is supplied from the power source are shaded in their respective frames. ECUs 13A and 13B, connected to the output side of area ECU 12, are also shaded in their respective frames to indicate that no power is supplied from the power source.

[0061] exist Figure 4In the example, among the standby input circuits 44a-44d of the four systems, the standby input circuits 44a, 44b, and 44d belonging to the standby group (W) are in the off state, and only the standby input circuit 44c belonging to the standby group (M) remains in the operable start state. Among the standby output circuits 49a-49d of the four systems, the standby output circuits 49a and 49b belonging to the standby group (W) are in the off state, and the standby output circuits 49c and 49d belonging to the standby group (M) remain in the start state.

[0062] In fact, even when the ignition is off, the operating mode of the regional ECU12 switches to normal mode when the regional ECU12 updates its software. Therefore, as Figure 3 All components in the area ECU12 shown are operable. Then, when the operating mode of area ECU12 switches to power-saving mode during software update processing, as... Figure 4 In the area ECU12 shown, all components except those required for minimum function execution are switched off.

[0063] <Example of battery voltage change>

[0064] Unable to start software update

[0065] Figure 5 This is a timing diagram illustrating an example of battery voltage changes when a software update cannot be initiated via voltage prediction. Figure 5 In the figure, the horizontal axis represents the change in time t, and the vertical axis represents the change in the output voltage [V] of the on-board battery 15.

[0066] When the ignition of vehicle 17 is turned off, the power supply from alternator 16 is stopped, so while power current flows to loads such as zone ECU 12, the battery voltage Vx (e.g., the detected value) changes along the path... Figure 5 The solid line shown in the image, with a roughly constant slope, gradually decreases in elevation.

[0067] When the software update (SU) of the regional ECU12 is in such Figure 5 Starting at time point t1, it is necessary to confirm in advance whether there are any problems with the battery voltage at the updated time point (t2). Therefore, in step S01, the region ECU 12 calculates the predicted voltage Vp at time point t1 and compares the predicted voltage Vp at the updated time point with the low voltage threshold VL1. The low voltage threshold VL1 is predetermined based on the minimum power supply voltage that needs to be maintained to prevent the battery of vehicle 17 from being depleted.

[0068] exist Figure 5In the example, at time point t1, it is found that the predicted voltage Vp at a future time point t2 is less than the low voltage threshold VL1. Therefore, at this time, the regional ECU 12 decides not to start the software update in step S02. Thus, for example, the operating mode of the regional ECU 12 is switched to a hibernation state, which can reduce the voltage drop of the vehicle battery 15 and thus prevent battery depletion.

[0069] <When software updates can begin>

[0070] Figure 6 This is a timing diagram illustrating an example of battery voltage changes when a software update can be initiated via voltage prediction. Figure 6 In the figure, the horizontal axis represents the change in time t, and the vertical axis represents the change in the output voltage [V] of the on-board battery 15.

[0071] exist Figure 6 In the example, it was found that the predicted voltage Vp predicted in step S01 at time t1 was greater than the low voltage threshold VL1 at the end of the software update (t2). Therefore, as step S02B, region ECU12 started the software update at time t1.

[0072] However, the actual voltage Vx does not necessarily change in the same way as the predicted voltage Vp, and as... Figure 6 As shown, voltage Vx can decrease earlier than the predicted voltage Vp. Therefore, region ECU12 compares the actual voltage Vx with a low voltage warning threshold VL2 to detect if the voltage decreases earlier than expected. The low voltage warning threshold VL2 is greater than the low voltage threshold VL1 and is predetermined as the threshold for noticing if voltage Vx decreases earlier than expected.

[0073] When the actual voltage Vx drops to the low voltage warning threshold VL2, in step S03, the area ECU12 shuts down the standby circuit (W), switches the operating mode of the area ECU12 to power saving mode, and performs the prediction of the predicted voltage Vp2 again.

[0074] That is, if the actual voltage Vx drops to the low voltage warning threshold VL2, and the state remains unchanged, it is assumed that the voltage Vx drops to a level equal to or less than the low voltage threshold VL1 earlier than the expected time point t2 for completing the software update. However, when the operating mode of the region ECU12 switches to power-saving mode, the rate of voltage Vx decreases, so it is possible that the voltage Vx remains above the low voltage threshold VL1 until the expected time point t2 for completing the software update. Therefore, the prediction of the predicted voltage Vp2 is executed again.

[0075] exist Figure 6In the example, it is determined that the predicted voltage Vp2 has not reached the low voltage threshold VL1 by time point t2. Therefore, while the operating mode of the area ECU12 is power saving mode, the area ECU12 continues to update the software (S04).

[0076] <Control of Software Updates>

[0077] Figure 7 This is a flowchart showing the control content of software updates in region ECU12. Figure 7 The controls in the document will be described below.

[0078] In S11, the region ECU12 calculates as follows: Figure 5 and Figure 6 The predicted voltage Vp is shown. For example, it can be based on... Figure 5 The future change of voltage Vx at each time point t after time point t1 is predicted by using the trend of voltage Vx changes detected before time point t1 and the voltage Vx at time point t1. That is, the predicted voltage Vp(t) can be estimated as a linear function approximating the expected change of voltage Vx. Then, the value of the predicted voltage Vp at the time point (t2) when the software update is completed can be calculated. The time required from the start of the software update to its completion (t2-t1) can be estimated based on factors such as the size of the update data present in the dedicated update storage area 12a and the number of files.

[0079] Region ECU12 compares the predicted voltage Vp at the expected software update completion time (t2) with the low voltage threshold VL1 (S12). When the predicted voltage value Vp(t2) is equal to or less than the low voltage threshold VL1, the process proceeds to S13, at which point the software update is not started.

[0080] When the predicted voltage value Vp(t2) is greater than the low voltage threshold VL1, the process proceeds to S14, and the regional ECU 12 begins the corresponding software update process. Subsequently, in S15, the regional ECU 12 checks whether the software update is complete; if not, the process proceeds to S16. Then, in S16, the regional ECU 12 compares the latest voltage Vx, which is actually detected by measurement, with the low voltage warning threshold VL2. When the condition "Vx≤VL2" is not met, the process returns from S16 to S14, and the regional ECU 12 continues the software update process as before.

[0081] When the region ECU 12 detects that the voltage Vx is equal to or less than the low voltage warning threshold VL2, the process proceeds from S16 to S17. Then, the current progress rate Rx of the software update is calculated and compared with a predetermined update continuation threshold R1. The progress rate Rx can be calculated, for example, as the ratio of the data volume and total number of files updated by the region ECU 12 before the current moment based on the update data in the dedicated update storage region 12a to the total volume and total number of update data.

[0082] Here, when the current progress rate Rx is less than the update continuation threshold R1, the region ECU12 interrupts the software update in S17.

[0083] When the current progress rate Rx is equal to or greater than the update continuation threshold R1, the process transitions from S17 to S18, and the region ECU 12 switches its operating mode to power-saving mode. That is, power is cut off to all circuits except for the standby circuit (M) required for continued subsequent processing, and power is obtained... Figure 4 The state shown indicates that power consumption from the vehicle battery 15 can be reduced.

[0084] Next, in S19, the area ECU 12 again predicts the change in voltage Vx after that point in time as the predicted voltage Vp2. At this time, the predicted voltage Vp2 is calculated, taking into account the actual change in voltage Vx up to the execution of S19 and the effect of switching the operating mode of the area ECU 12 to power-saving mode.

[0085] Next, in S20, the region ECU12 compares the calculated value of the predicted voltage Vp2 (t2) at the software update completion time point (t2) with the low voltage threshold VL1. In S20, if the predicted voltage Vp2 (t2) at the software update completion time point is equal to or less than the low voltage threshold VL1, the software update is interrupted.

[0086] When the predicted voltage Vp2(t2) at the software update completion time point is greater than the low voltage threshold VL1, the process transitions from S20 to S21, and the region ECU12 continues the currently being processed software update as is.

[0087] Subsequently, in S22, the regional ECU12 identifies whether the software update process is complete. If not, the process proceeds to S23. Then, in S23, the regional ECU12 compares the latest voltage Vx, which is actually detected by measurement, with the low voltage threshold VL1.

[0088] When the condition "Vx>VL1" is met, the process returns from S23 to S21, and the regional ECU 12 continues to perform the software update process as before. On the other hand, in S23, when the condition "Vx≤VL1" is met, the regional ECU 12 interrupts the software update.

[0089] Therefore, when the area ECU12 executes Figure 7 When the control shown can be executed Figure 5 and Figure 6 The operation is as shown. That is, even if the condition "Vp1(t2)>VL1" is met in S12 and the software update begins, and the actual rate of voltage Vx decreases faster than expected and "Vx≤VL2", when the progress rate Rx is large, the operating mode of the region ECU12 switches to power-saving mode, thereby continuing the software update. Therefore, battery depletion can be reliably prevented, and the frequency of software update interruptions can be reduced. That is, the situation of repeatedly performing the same software update can be reduced.

[0090] <Example of a Modified Regional ECU>

[0091] Figure 8 This is a block diagram showing the internal structure of region ECU12A in the modified example.

[0092] Figure 8 The illustrated regional ECU 12A includes a control circuit 61, a power supply circuit 62, a communication circuit 63, four system standby input circuits 64, six system input circuits 65, power supply units 66 and 67, communication circuits 68 and 69, and output circuits 71, 72, and 73. Similar to control circuit 41, control circuit 61 includes instructions such as a processor and memory, and software stored in the memory, which, when executed by the processor, cause the regional ECU 12A to perform operations such as the on-board software update method described in this modified example.

[0093] ECU13A is connected to the output side of output circuit 71, and ECU13B is connected to the output side of output circuit 72.

[0094] exist Figure 8 In the area ECU12A, in order to switch the state of the area ECU12A to three types of states, it can be powered independently from the three power supply systems "A", "B" and "C".

[0095] The control circuit 61, which includes a microcomputer, is continuously powered from the power supply system "A". In addition, it is powered from the power supply system "B" through the power supply unit 66, and also from the power supply system "C" through the power supply unit 67.

[0096] Each standby input circuit 64 operates using power from power source system "A". Communication circuits 63 and 69, power supply unit 66, and output circuits 71 and 72 all operate using power source system "B". Input circuit 65, power supply unit 67, communication circuit 68, and output circuit 73 all operate using power source system "C".

[0097] For example, when starting the ignition of vehicle 17, if there is a relatively large power consumption in the allowable area ECU12A of vehicle 17, normal power from the power supply is supplied to such... Figure 8 All circuits in the area ECU12A shown. That is, power from the three systems "A", "B" and "C" of the power supply is supplied to each circuit in the area ECU12A. This situation corresponds to the normal mode in which the area ECU12A is activated. In the normal mode, the control circuit 61 is in a state where it can operate normally (RUN).

[0098] <Changes in Software Update Mode>

[0099] Figure 9 This is a block diagram illustrating an example of the state changes of each component in the region ECU12A under software update (OTA SU) mode. Figure 9 In the middle, elements that are in a state different from the normal mode are displayed as shadow boxes.

[0100] like Figure 9 As shown, in software update mode, power supply to system "C" of the power source for input circuit 65, power supply unit 67, communication circuit 68, and output circuit 73 is stopped. Control circuit 61 is in a power-saving state (STOP mode). Power supply circuit 62, communication circuit 63, standby input circuit 64, power supply unit 66, communication circuit 69, and output circuits 71 and 72 are all in a state where they can operate normally by power supply from system "A" or "B" of the power source.

[0101] Therefore, in Figure 9 In the software update mode shown, the power consumption of the regional ECU12A is... Figure 8 The normal pattern was significantly reduced.

[0102] <Sleep Mode Status Changes>

[0103] Figure 10 This is a block diagram illustrating an example of the state changes of components in the region ECU12A when it is in sleep mode. Figure 10 In the middle, elements that are in a state different from the normal mode are displayed as shadow boxes.

[0104] like Figure 10 As shown, in sleep mode, power supply to system "C" (input circuit 65, power supply unit 67, communication circuit 68, and output circuit 73) from the power source is stopped, and power supply to system "B" (communication circuit 63, power supply unit 66, communication circuit 69, and output circuits 71 and 72) from the power source is also stopped. Control circuit 61 is in a DEEP STOP state with extremely low power consumption.

[0105] Therefore, in Figure 10 In the sleep mode shown, the power consumption of the area ECU12A is... Figure 9 The software update mode in the middle is further reduced compared to the previous one.

[0106] That is, by switching the state of the region ECU12A to Figure 8 , Figure 9 ,as well as Figure 10 In any of these states, three types of power consumption states can be selectively used. Table 1 below shows a list of the ON / OFF categories of the functions of each unit in the region ECU12A in these three modes.

[0107] (Table 1)

[0108]

[0109] In Table 1, "Requires Standby I / O" corresponds to the input / output (I / O) interfaces used for connecting features such as remote keyless entry or smart key functionality. Furthermore, in Table 1, the "ON" setting for the "CAN" system in software update mode is limited to the bus associated with the corresponding software update.

[0110] <Operation of Region ECU12A>

[0111] Figure 11 It shows Figure 8 A flowchart of the mode switching control for the ECU12A in the middle region.

[0112] When using Figure 8 When the area ECU 12A is in operation, i.e., when the vehicle 17 is in motion and ignition is started, it also performs the operation of downloading updated data from the cloud 20 and storing the updated data in the dedicated update storage area 12a. Whether a software update can be performed is confirmed in advance by the driver's input. When the driver has given prior permission for the software update, the area ECU 12A begins the software update process after the ignition is turned off.

[0113] Figure 11 The controls shown will be described below.

[0114] When the area ECU12A is operating in normal mode, from Figure 11Step S31 of the process begins. In S31, the region ECU12A identifies whether the predetermined sleep condition is ON.

[0115] For example, in S31, any one of the following conditions, such as when the ignition is turned off, when a door is opened, and after the key is locked, or a combination of these conditions, is identified as a sleep condition. When the sleep condition is ON, the zone ECU12A transitions from S31 to S32.

[0116] In S32, the region ECU 12A checks whether a software update exists. That is, the region ECU 12A checks whether update data that can be used to update the software of the region ECU 12A, etc., is stored in the dedicated update storage area 12a. When a software update exists, the process proceeds from S32 to S33, and when no software update exists, the process proceeds from S32 to S35.

[0117] Before initiating the software update process, the operating mode of the area ECU12A will be switched to [mode name missing]. Figure 9 The software update mode shown is (S33). Therefore, a software update can be performed when the power consumption of the region ECU12A from the power supply is reduced.

[0118] In S34, region ECU12A begins software update processing. Then, after the software update processing is complete, the process proceeds to S35.

[0119] In S35, the area ECU12A switches its operating mode to... Figure 10 The sleep mode is shown. Therefore, the power consumption of the regional ECU12A from the power source is very small, and its impact on the voltage of the on-board battery 15 is almost eliminated.

[0120] In S36, the area ECU 12A identifies whether the predetermined wake-up condition is ON, and when the wake-up condition is ON, in S37, the area ECU 12A switches its operating mode to... Figure 8 The normal mode shown.

[0121] As mentioned above, in Figure 1 In the vehicle system 10 shown, the regional ECU 12 can perform actions such as Figure 7 The illustrated method describes an onboard software update procedure. Therefore, even if the actual voltage Vx of the onboard battery 15 is, for example... Figure 6 Even if the predicted voltage Vp decreases earlier than expected, the software update can continue as scheduled without interruption due to considerations of the software update progress rate or switching the operating mode of region ECU12 to power-saving mode. Therefore, the frequency of software update interruptions can be reduced. That is, repeated software updates can be prevented, and software updates can be performed efficiently.

[0122] In particular, Figure 7 During the operation, when the voltage Vx drops to the low voltage warning threshold VL2, considering that the operating mode of the area ECU12A is switched to power saving mode (S18), the predicted voltage Vp2 is calculated again (S19), so it is very likely that the software update will continue until the end.

[0123] The regional ECU 12 performs the download when the vehicle 17 is started and begins the software update after the ignition is turned off, thus enabling efficient software updates. That is, when the ignition is turned off, it is unlikely that there will be interruptions from other ECUs unrelated to the software update, allowing the software to be updated in a favorable environment.

[0124] Even after the regional ECU12 switches its operating mode to power-saving mode during a software update, the regional ECU12 still performs control to keep the battery voltage equal to or greater than the low voltage threshold VL1 (S23), thus preventing the battery of the vehicle 17 from being depleted.

[0125] By switching such Figures 8 to 10 The operating mode of ECU12A shown in the diagram can also more effectively prevent the battery from being depleted due to software updates.

[0126] According to an embodiment of this disclosure, an in-vehicle software update method is used to update software in an in-vehicle system 10. The in-vehicle system includes a region control unit (e.g., a region ECU 12), configured to manage multiple control targets (e.g., a terminal ECU 13 and a smart actuator 14) connected downstream of the region control unit. The in-vehicle software update method includes: storing update data in a first region (e.g., an update-dedicated storage region 12a) pre-allocated in the memory of the region control unit; calculating a first predicted voltage value (e.g., predicted voltage Vp) of the vehicle power supply at the time of update completion before starting the software update using the update data; and starting the software update if the first predicted voltage value is greater than a first threshold (e.g., a low voltage threshold VL1). Update (S12 and S14); after starting the software update, obtain the voltage measurement value of the vehicle power supply (e.g., voltage Vx); if the voltage measurement value is equal to or less than a second threshold (e.g., low voltage warning threshold VL2), obtain the progress rate of the software update (S17), the second threshold being greater than the first threshold; if the progress rate is less than a set value, interrupt the software update; and if the progress rate is equal to or greater than the set value, switch the operation mode of the area control unit to power saving mode (S18), calculate the second predicted voltage value of the vehicle power supply at the time of update completion (e.g., predicted voltage Vp2), and continue the software update if the second predicted voltage value is greater than the first threshold (e.g., low voltage threshold VL1) (S21).

[0127] According to this method, even if the on-board power supply voltage drops earlier than expected after the software update begins, the software update can continue as is if the progress rate at that point in time is equal to or greater than a set value. Therefore, the number of times the same software update is repeated due to interruptions can be reduced, and power consumption and time waste can be minimized. Even if the software update progress rate is equal to or greater than the set value, the software update can be interrupted if the second predicted voltage value is equal to or less than a first threshold, thus allowing the on-board power supply voltage to be managed to remain above the first threshold.

[0128] An in-vehicle system 10 according to an embodiment of the present disclosure includes: a region control unit (e.g., region ECU 12) configured to manage a plurality of control targets (e.g., terminal ECU 13 and smart actuator 14) connected downstream of the region control unit. The region control unit's memory has a first region (e.g., an update-dedicated storage region 12a), the first region being configured to retain update data that can be used for software updates of the plurality of control targets; and the region control unit is configured to: calculate a first predicted voltage value (predicted voltage Vp) of the vehicle power supply at the time of update completion (S11) before initiating a software update using the update data in the first region; initiate the software update if the first predicted voltage value is greater than a first threshold (e.g., a low voltage threshold VL1) (S12 and S14); and acquire a voltage measurement value (e.g., voltage Vx) of the vehicle power supply after initiating the software update (S16). If the voltage measurement value is equal to or less than a second threshold (e.g., low voltage warning threshold VL2), the progress rate of the software update is obtained, where the second threshold is greater than the first threshold (S17); if the progress rate is less than a set value, the software update is interrupted (S17); and if the progress rate is equal to or greater than the set value, the operation mode of the area control unit is switched to power saving mode (S18), the second predicted voltage value of the vehicle power supply at the time of update completion (e.g., predicted voltage Vp2) is calculated, and if the second predicted voltage value is greater than the first threshold (e.g., low voltage threshold VL1), the software update continues (S21).

[0129] According to this design, even if the on-board power supply voltage drops earlier than expected after the software update begins, the software update can continue as is if the progress rate at that point in time is equal to or greater than a set value. Therefore, the number of times the same software update is repeated due to interruptions can be reduced, and power consumption and time waste can be minimized. Even if the software update progress rate is equal to or greater than the set value, the software update can be interrupted if the second predicted voltage value is equal to or less than the first threshold, thus allowing the on-board power supply voltage to be managed to remain above the first threshold.

[0130] The area control unit is configured to: assign priority to each of a plurality of circuits, the plurality of circuits being under the management of the area control unit; and in the power-saving mode, switch the power supply state of the plurality of circuits to a state of suppressing the power supply to at least one of the plurality of circuits having a low priority, such that the change in power supply is reflected in the calculation of the second predicted voltage value (e.g., predicted voltage Vp2).

[0131] According to this design, when the onboard power supply voltage drops earlier than expected after a software update begins, the regional control unit switches to a power-saving mode, thereby suppressing the functions of low-priority circuits and slowing down the consumption of onboard power. Therefore, the likelihood of software updates can be further increased.

[0132] The area control unit is configured to: store the updated data downloaded from a software supply source in response to vehicle ignition in the first area; and, after the ignition is turned off, switch the operating mode of the area control unit to a software update mode using the updated data.

[0133] According to this configuration, when downloading update data, power supplied from the vehicle's alternator (e.g., alternator) can be used, thus allowing for efficient downloading without needing to consider the consumption of the vehicle's battery. Furthermore, when performing software updates, the update process can begin even when many ECUs are not functioning, such as when the main unit is stopped. Therefore, the update process is less likely to be affected by interruptions from other ECUs and can be executed efficiently.

[0134] The area control unit is configured to: repeatedly acquire the voltage measurement value of the vehicle power supply after switching the operating mode of the area control unit to the power saving mode; and interrupt the software update (S23) if the voltage measurement value (e.g., voltage Vx) is equal to or less than the first threshold (e.g., low voltage threshold VL1).

[0135] Based on this configuration, even if the software update progress rate is equal to or greater than a set value, the software update will continue as is. When the voltage of the vehicle power supply actually drops to the first threshold, the software update will also be interrupted at that point. Therefore, the voltage of the vehicle power supply can be managed to keep it equal to or greater than the first threshold.

[0136] According to the vehicle software update method and vehicle system disclosed herein, power consumption waste and time waste caused by software update interruptions can be reduced. That is, even if the vehicle power supply voltage drops earlier than expected after the software update begins, the software update can continue as long as the progress rate at that point in time is equal to or greater than a set value. Therefore, the occurrence of repeated software updates due to interruptions can be reduced.

Claims

1. A method for updating software in an in-vehicle system, the in-vehicle system including a region control unit configured to manage a plurality of control targets connected downstream of the region control unit, the method comprising: The updated data is stored in a first area pre-allocated in the memory of the area control unit; Before starting the software update using the updated data, calculate the first predicted voltage value of the vehicle power supply at the time the update is completed; The software update begins if the first predicted voltage value is greater than the first threshold. After the software update is initiated, the voltage measurement value of the vehicle power supply is obtained; If the voltage measurement value is equal to or less than a second threshold, the progress rate of the software update is obtained, where the second threshold is greater than the first threshold. The software update will be interrupted if the progress rate is less than a set value. as well as If the progress rate is equal to or greater than the set value, the operation mode of the area control unit is switched to power saving mode, the second predicted voltage value of the vehicle power supply at the time of update completion is calculated, and the software update continues if the second predicted voltage value is greater than the first threshold.

2. A vehicle-mounted system, comprising: A zone control unit is configured to manage multiple control targets connected downstream of the zone control unit. The memory of the region control unit has a first region configured to retain update data that can be used for software updates of the plurality of control objectives. The area control unit is configured as follows: Before initiating a software update using the updated data from the first region, calculate the first predicted voltage value of the vehicle power supply at the time the update is completed. The software update begins if the first predicted voltage value is greater than the first threshold. After the software update is initiated, the voltage measurement value of the vehicle power supply is obtained; If the voltage measurement value is equal to or less than a second threshold, the progress rate of the software update is obtained, where the second threshold is greater than the first threshold. The software update will be interrupted if the progress rate falls below a set value; and If the progress rate is equal to or greater than the set value, the operation mode of the area control unit is switched to power saving mode, the second predicted voltage value of the vehicle power supply at the time of update completion is calculated, and the software update continues if the second predicted voltage value is greater than the first threshold.

3. The vehicle-mounted system according to claim 2, in, The region control unit is configured as follows: Each of the multiple circuits is assigned a priority, and the multiple circuits are under the management of the area control unit; as well as In the power-saving mode, the power supply state of the plurality of circuits is switched to a state that suppresses the power supply to at least one of the plurality of circuits with low priority, such that the change in power supply is reflected in the calculation of the second predicted voltage value.

4. The vehicle-mounted system according to claim 2 or 3, in, The region control unit is configured as follows: The first area stores the updated data downloaded from the software supply in response to vehicle ignition; and After the ignition is turned off, the operating mode of the area control unit is switched to software update mode using the updated data.

5. The vehicle-mounted system according to claim 2 or 3, in, The region control unit is configured as follows: After switching the operating mode of the area control unit to the power-saving mode, the voltage measurement value of the vehicle power supply is repeatedly acquired; and The software update is interrupted if the voltage measurement value is equal to or less than the first threshold.

Citation Information

Patent Citations

  • Vehicular power supply system

    JP2008155892A

  • Module updating device

    US20150007155A1

  • Control device, control method, and computer program

    WO2019030985A1