In-vehicle software update methods and in-vehicle systems
By setting up a memory area on the regional control unit and prioritizing the download of update data, the problem of large-capacity storage required for vehicle system software updates is solved, achieving an efficient and stable update process.
Patent Information
- Application Number
- CN202210358027.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-04-07
- Filing Date
- 2022-04-06
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2042-04-06
AI Technical Summary
Existing in-vehicle systems require a large amount of storage capacity for software updates, resulting in low memory utilization efficiency and the update process being easily interrupted, which may lead to abnormal situations and duplicate processing.
A regional memory is set up on the regional control unit to store updated data. The download and storage of updated data are managed by priority and download conditions to ensure efficient use of the storage area and avoid duplication and interruption.
This reduces the storage space required for software updates, improves the stability and efficiency of updates, avoids duplicate downloads and interruptions, and ensures that the system completes updates under stable conditions.
Smart Images

Figure CN115202684B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method for updating vehicle software and a vehicle system. Background Technology
[0002] In recent years, vehicles have been experimenting with over-the-air (OTA) software update systems, which use wireless communication to update the software of the vehicle's systems.
[0003] For example, the vehicle system described in JP2019-073106A can connect to the cloud wirelessly and obtain programs and data. JP2019-073106A also shows that the memory of the rewritable node of the vehicle system includes a storage area for control, a first storage area, a second storage area, etc.
[0004] JP2006-301960A discloses a main storage area for storing the current version of the program and a sub-storage area for storing updated versions of the program.
[0005] However, in recent years, vehicle systems have been equipped with a large number of electronic control units (ECUs), and each ECU includes a built-in independent computer for control. Therefore, for example, when updating the software to add new functions to the vehicle system or to improve the overall performance of the vehicle system, it is necessary to update the software used by each computer of the numerous ECUs.
[0006] Therefore, the amount of software data that needs to be updated is enormous, and the update process is expected to take a significant amount of time. In the vehicle-mounted system of JP2019-073106A, storage areas must be secured in the memory used to store the programs and data for updates in each rewritable node.
[0007] In other words, in order to enable software updates, each ECU must be provided with a dedicated storage area with a large capacity. The entire system requires a huge amount of storage capacity.
[0008] However, the storage area set aside for storing updated software is not used except during update processing. Therefore, ensuring a large storage area is used for software updates leads to reduced memory utilization across the entire system, which is a factor in increased costs.
[0009] Unexpected situations may occur, such as software updates failing to complete. For example, the update must be interrupted if the power supply voltage of the vehicle battery or other components drops before the software update process is completed, or if the update is no longer permitted. Updates may also fail to complete due to defects in the software itself. When a software update fails to complete due to interruption or other reasons, the same update process must be performed from the beginning when a next update becomes possible. Summary of the Invention
[0010] This disclosure provides an in-vehicle software update method and an in-vehicle system that can reduce the storage space required for software updates.
[0011] According to an illustrative aspect of this disclosure, a method for updating in-vehicle software is provided for updating software included in an in-vehicle system, the in-vehicle system having a top-level control unit, a region control unit connected downstream of the top-level control unit, and a plurality of lower-level control units connected downstream of the region control unit. The updating method includes: ensuring a region in a memory on the region control unit, the region being capable of storing update data for updating the region control unit and the lower-level control units to be updated; repeatedly checking whether the update data exists in a predetermined software supply source; when update data satisfying a download condition exists in the software supply source, downloading the update data from the software supply source to store the update data in the region; and when the plurality of update data satisfying the download condition exists simultaneously in the software supply source, preferentially selecting the update data with the highest priority from the plurality of update data to perform the download.
[0012] According to another illustrative aspect of this disclosure, an in-vehicle system includes: a top-level control unit; a region control unit connected downstream of the top-level control unit; and a plurality of lower-level control units connected downstream of the region control unit, wherein the region control unit includes a memory on the region control unit, the memory having a region capable of storing any update data for updating software of the region control unit or the plurality of lower-level control units, the region control unit including: an update object selection unit configured to select an update object of the update data stored in the region, and an update control unit configured to... The system is configured to check whether the update data exists in a predetermined software supply source and to check the type of the update object. The update control unit is configured to: when the update data that satisfies a download condition exists in the software supply source, download the update data from the software supply source to store the update data in the area; and when multiple update data that satisfy the download condition exist simultaneously in the software supply source, preferentially select the update data with the highest priority from the multiple update data to perform the download.
[0013] This disclosure has been briefly described above. Furthermore, the details of this disclosure will be set forth with reference to the accompanying drawings and the construction for implementing the following disclosure (hereinafter referred to as the "Embodiments"). Attached Figure Description
[0014] Figure 1 This is a block diagram illustrating the main unit structure of an in-vehicle system according to an embodiment of the present disclosure;
[0015] Figure 2 It shows the relationship with Figure 1 Block diagrams of in-vehicle systems in different states;
[0016] Figure 3 This is a flowchart illustrating the operation of the regional ECU when the ignition is on; and
[0017] Figure 4 This is a flowchart illustrating the operation of a regional ECU when the ignition is off. Detailed Implementation
[0018] The specific embodiments of this disclosure will now be described with reference to the accompanying drawings.
[0019] <Vehicle System Structure>
[0020] Figure 1 This is a block diagram illustrating the main unit configuration of an in-vehicle system 10 according to an embodiment of the present disclosure. Figure 2 It shows the relationship with Figure 1 Block diagram of the vehicle system 10 in different states.
[0021] Installed Figure 1 The onboard system 10 on the vehicle 17 shown includes a central ECU 11, regional ECUs 12, terminal ECUs 13, and intelligent actuators 14. The central ECU 11 is connected to the regional ECU 12 via communication line 18. The regional ECU 12 is connected to the terminal ECU 13 and the intelligent actuators 14 via communication line 19. Here, the central ECU 11 can be referred to as the uppermost control unit 11. The regional ECU 12 can be referred to as the regional control unit 12. The terminal ECU 13 and the intelligent actuators 14 can be referred to as lower-level control units 13 and 14.
[0022] In a real vehicle, vehicle 17 is divided into multiple zones, and each zone has an independent zone ECU 12. That is, the central ECU 11 is connected to multiple zone ECUs 12. These zones can be assigned as multiple zones representing differences in position, such as left and right, within the space of vehicle 17, or they can be assigned as multiple zones representing differences in functional groups.
[0023] The central ECU 11 has the function of integrating and managing the entire vehicle system 10, which includes multiple areas, and also has a gateway function for securely connecting the vehicle system 10 to a communication network such as the Internet outside the vehicle using wireless communication functions.
[0024] therefore, Figure 1 The regional ECU 12 shown is connected downstream of the central ECU 11, which is located at the highest level on the vehicle 17. The regional ECU 12 manages the terminal ECU 13 and the smart actuator 14 connected to its downstream side.
[0025] The central ECU 11, regional ECU 12, and terminal ECU 13 each include communication functions and a built-in microcomputer, which can be referred to as processor 12 relative to the regional ECU 12, and is capable of independent control. The intelligent actuator 14 has the function of changing the actuator function through software, as well as communication functions.
[0026] Therefore, as Figure 1 The illustrated regional ECU 12, terminal ECU 13, and intelligent actuator 14 each include software consisting of programs and data required for their operation. For example, each piece of software is in a rewritable state by being stored in non-volatile memory. Therefore, each piece of software can be updated as needed. In this embodiment, these software updates (SUs) can be performed wirelessly via over-the-air (OTA) downloads.
[0027] Figure 1 The illustrated vehicle system 10 manages all updates to the software used by the regional ECU 12 and the software used by the terminal ECU 13 and the smart actuator 14. The regional ECU 12 includes an update-dedicated (OTASU) storage area 12a, which may be referred to as a region 12a or a first region 12a. Here, reference numeral 12a can be used to denote a memory. Neither the terminal ECU 13 nor the smart actuator 14 includes a storage area for updates.
[0028] Therefore, in Figure 1 In the illustrated vehicle system 10, the dedicated update storage area 12a of the regional ECU 12 is used as a general storage area for processing various types of update data for different update objects. That is, the software used by the regional ECU 12 and the software used by the terminal ECU 13 and the intelligent actuator 14 are all updated using the general dedicated update storage area 12a.
[0029] The storage capacity reserved in advance for the dedicated update storage area 12a is determined to be large enough to store update data of the type with the largest data capacity among all types of update data. Therefore, for example, it is possible to store multiple types of update data with relatively small capacities simultaneously in the dedicated update storage area 12a, but it is not possible to store multiple types of update data with large capacities simultaneously.
[0030] exist Figure 1 In the vehicle 17 shown, the power required for the operation of the on-board system 10 can be provided from the on-board battery 15 and alternator 16 located in the vehicle 17. However, when the engine is stopped, the alternator 16 also stops generating electricity. Therefore, when the vehicle 17 is parked, only the electrical energy stored in the on-board battery 15 can be used.
[0031] When the vehicle battery 15 is abnormally depleted, the power supply from the vehicle battery 15 can be limited. Whether the alternator 16 is running can be identified by turning the ignition on or off. Figure 1 The area shown, ECU12, monitors the ignition signal SG-IG output from vehicle 17 to identify the ignition on and off.
[0032] The vehicle system 10 of this embodiment is provided with a cloud 20 as a source of update data for updating the software of each unit. For example, the cloud 20 is deployed on a server in a predetermined data center. The cloud 20 has the function of providing the update data required for software updates of the vehicle system 10. Here, the cloud 20 can be referred to as a software supply source.
[0033] Therefore, when the software for the regional ECU 12, the software for the terminal ECU 13, and the software for the intelligent actuator 14 are all ready for updates, such as Figure 1 As shown, update programs 31, 32, and 33 corresponding to the updated objects are stored on cloud 20. Here, update programs 31, 32, and 33 can be referred to as update data 31, 32, and 33. Furthermore, update program 31 can be referred to as first update data 31, and update programs 32 and 33 can be referred to as second update data 32 and 33.
[0034] exist Figure 1 In this state, the vehicle system 10 can download three update programs 31, 32, and 33 respectively via wireless data communication 25. However, only the dedicated update storage area 12a of the vehicle system 10 can store the downloaded update data.
[0035] Therefore, it is necessary to appropriately handle the downloading and updating of each type of update data while checking the actual usage status of the dedicated update storage area 12a and considering priorities. In this embodiment, the area ECU 12 plays a central role in the vehicle system 10 to control this processing.
[0036] Typically, when downloading large amounts of update data via wireless data communication 25, it can be predicted that each unit of the vehicle system 10 will consume a considerable amount of power over a long period of time. Therefore, in this embodiment, each update data is downloaded while the vehicle 17 is ignited.
[0037] However, when actually updating the software on the vehicle system 10 using the downloaded update data, it is desirable to make it less susceptible to interruptions from other ECUs unrelated to the update target. During the actual software update, the operation of other ECUs unrelated to the update target can be restricted to reduce the overall system power consumption. Therefore, in this embodiment, the vehicle system 10 performs a software update while the ignition of the vehicle 17 is off.
[0038] exist Figure 1 In the illustrated state, although there are three types of update programs 31, 32, and 33 on cloud 20, in this embodiment, the update program 31 for the area ECU 12 has a higher priority than the other update programs. Therefore, the area ECU 12 first downloads only update program 31 via wireless data communication 25. Thus, update program 31A, as a copy of update program 31 on cloud 20, is stored in the dedicated update storage area 12a.
[0039] like Figure 1 As shown, when the update program 31A is stored in the update-dedicated storage area 12a, the update processing unit 12b of the area ECU 12 reads the update program 31A from the update-dedicated storage area 12a, performs the update processing, and updates and installs the program into the area ECU 12.
[0040] exist Figure 1 In the vehicle system 10 shown, when the update program 31A is successfully installed, the update program 31A in the dedicated update storage area 12a becomes invalid. In this case, the area ECU 12 releases the dedicated update storage area 12a.
[0041] Therefore, the dedicated update storage area 12a becomes free, and this storage area can be reused. Thus, the region ECU 12 can download a lower-priority update program 32 or 33 from the cloud 20 and store that program in the dedicated update storage area 12a. When the capacity of both update programs 32 and 33 is relatively small, both programs can be stored simultaneously in the dedicated update storage area 12a.
[0042] exist Figure 2 In the state shown, after being downloaded from the cloud 20 by the region ECU 12 using wireless data communication 25, update program 32A, as a copy of update program 32 on the cloud 20, is stored in the update-dedicated storage area 12a. Update program 33A, as a copy of update program 33, is also stored in the update-dedicated storage area 12a at the same time.
[0043] therefore, Figure 2 The update processing unit 13a shown can update the software on the terminal ECU13 by using the update program 32A stored in the update-dedicated storage area 12a of the regional ECU12. Figure 2 The update processing unit 14a shown can update the software on the smart actuator 14 by using the update program 33A stored in the update-dedicated storage area 12a of the region ECU 12.
[0044] In practice, update processing unit 13a updates the software on terminal ECU 13 while performing data communication between regional ECU 12 and terminal ECU 13 via communication line 19. Update processing unit 14a updates the software on intelligent actuator 14 while performing data communication between regional ECU 12 and intelligent actuator 14 via communication line 19.
[0045] When the regional ECU 12 successfully completes the software update using update program 31A, the regional ECU 12 notifies the cloud 20 that the software update is complete. In this way, the cloud 20 can delete the update program 31 that is no longer needed for the vehicle system 10.
[0046] <Operation of the Regional ECU> <Operation while the Ignition is On>
[0047] Figure 3 This is a flowchart illustrating the operation of the zone ECU 12 when the ignition is on. Specifically, when the ignition signal SG-IG input to the zone ECU 12 is on, the computer in the zone ECU 12 executes... Figure 3 The operation shown. Figure 3 The operations shown will be described below.
[0048] In S11, the region ECU 12 confirms the existence of the necessary software (programs and data) that has not been updated and installed in the update-dedicated storage area 12a. Then, when the update-dedicated storage area 12a becomes available, the process proceeds to S12.
[0049] In S12, the area ECU 12 confirms the necessary update program (or data) and the type of update object on the cloud 20 by performing wireless data communication 25. If an update program exists on the cloud 20, the area ECU 12 will proceed from S13 to S14. Then, the installation history of the corresponding update program is confirmed. This installation history is managed by the area ECU 12 or by the cloud 20.
[0050] In S14, region ECU12 verifies the installation history to enable efficient installation processing. For example, when an update fails due to an error contained in the update procedure, an abnormal loop of perpetually continuing the same process can be avoided by lowering the priority of installing the update procedure or postponing retry processing. Therefore, the installation history retains data used to manage the number of installation attempts for each update procedure.
[0051] Region ECU12 confirms the number of updates with the minimum number of installation attempts among the updates existing on cloud 20 (S15). Then, if the number of updates with the minimum number of installation attempts is 1, the process proceeds to S16, and if there are multiple updates with the minimum number of installation attempts, the process proceeds to S17.
[0052] In the next step S16, the regional ECU12 downloads a corresponding update program from the cloud 20 via wireless data communication 25 and stores the update program in the update-dedicated storage area 12a.
[0053] In the next step S17, the regional ECU 12 identifies whether the update program for updating the regional ECU 12 is included in the corresponding plurality of update programs. If an update program for updating the regional ECU 12 is included in the corresponding plurality of update programs, the process proceeds to S18; otherwise, the process proceeds to S19.
[0054] In S18, the regional ECU 12 downloads an update program for updating the regional ECU 12 from the cloud 20 via wireless data communication 25 and stores the update program in the update-dedicated storage area 12a.
[0055] In S19, the regional ECU 12 downloads one or more update programs for updating the terminal ECU 13 or smart actuator 14 from the cloud 20 via wireless data communication 25, and stores the update programs in the dedicated update storage area 12a. When the size of each update program is relatively small, multiple update programs can be downloaded and stored in the dedicated update storage area 12a simultaneously. However, when the size of each update program is large, the update programs are downloaded one by one in an appropriate order and stored in the dedicated update storage area 12a.
[0056] Here, steps S15 to S19, which are generally referred to as their common names, can be called download conditions S15 to S19.
[0057] <Operation when ignition is off>
[0058] Figure 4 This is a flowchart showing the operation of the ECU12 region when the ignition is off.
[0059] For example, when vehicle 17 finishes driving and stops, since the ignition is turned off to stop the engine and the alternator 16 also stops, the only power source for vehicle 17 is the onboard battery 15. Multiple ECUs on vehicle 17 switch to a suspended state, such as hibernation. In this state, area ECU 12 executes... Figure 4 The operation shown. Figure 4 The operations shown will be described below.
[0060] In S21, the region ECU 12 confirms the existence of necessary software (programs and data) that has not been updated and installed in the update-dedicated storage area 12a. Then, when update data for the software to be updated exists in the update-dedicated storage area 12a, the process proceeds to S22.
[0061] Region ECU 12 uses update data stored in the dedicated update storage area 12a to begin updating the software to be updated. For example, in Figure 1 In the shown state, since the update program 31A exists in the dedicated update storage area 12a, the update processing unit 12b updates the software of the region ECU 12 using the update program 31A. Figure 2 As shown, when update program 32A exists in the dedicated update storage area 12a, the software on terminal ECU 13 is updated using update program 32A in the dedicated update storage area 12a via communication between region ECU 12 and update processing unit 13a. The same applies to the processing of update program 33A.
[0062] For example, if the output voltage of the vehicle battery 15 drops abnormally after the regional ECU 12 begins updating its software, it is necessary to interrupt the update to further prevent the power supply voltage from dropping. In this situation, Figure 4 The operation shown is temporarily terminated. In this case, the update data on the dedicated update storage area 12a that has not yet been updated and installed will remain unchanged.
[0063] If the software update completes without any issues, in step S24, the regional ECU 12 detects the success of the update and proceeds to step S26. If the software update fails due to factors such as program errors in the update data, in step S24, the regional ECU 12 detects the update failure, records the failure in the history, and then proceeds to step S25. In this case, the regional ECU 12 performs a rollback in step S25 to restore the software version to its state before the update began.
[0064] When an update is detected to be successful or failed, the region ECU 12 releases the dedicated update storage area 12a (S26) that stores the update data used for the corresponding update. That is, update data that is no longer needed due to the completion of the update, or unnecessary update data that could not be updated due to some problem, will be erased from the dedicated update storage area 12a to ensure that the available area is used to store other update data.
[0065] As mentioned above, according to Figure 1 The vehicle-mounted system 10 and execution shown Figure 3 and Figure 4 The onboard software update method shown in the diagram allows for the updating of software for each of multiple loads, such as the regional ECU 12 and its downstream terminal ECUs 13 and smart actuators 14, by simply ensuring a dedicated update storage area 12a for storing one type of update data. In other words, by effectively utilizing a dedicated update storage area 12a, the storage area required for software updates across the entire system can be significantly reduced.
[0066] like Figure 3 and Figure 4 As shown, since the update data is downloaded and updated based on whether the ignition of vehicle 17 is on or off, stable operation can be expected. That is, since no power-saving operation is required for a considerable period of time when the ignition is on, even relatively large amounts of update data can be efficiently downloaded from the cloud 20, etc., using wireless communication. When the ignition is off, since the ECUs other than the unit to be updated are almost inactive, it is less susceptible to interruptions from other ECUs, and the software update process can be performed under stable conditions.
[0067] When multiple types of update data exist simultaneously on cloud 20, the software of the entire system can be easily managed in the latest state because the download of the update data used to update the region ECU 12 is executed first (S17, S18).
[0068] When multiple types of update data exist simultaneously on Cloud 20, some update data with fewer attempts are prioritized (S15, S16) to take into account the number of download attempts, thus enabling efficient download of software updates for each unit of the system.
[0069] According to a first illustrative aspect of this disclosure, an in-vehicle software update method is provided for updating software contained in an in-vehicle system (10), the in-vehicle system (10) having a top-level control unit (11), a regional control unit (12) connected downstream of the top-level control unit (11), and a plurality of lower-level control units (13, 14) connected downstream of the regional control unit (12). The update method includes: securing a region in a memory (12a) on the regional control unit, the region being capable of storing update data (31, 32, 33) for updating the regional control unit (12) and the lower-level control units (13, 14) as the objects of the update; and repeatedly checking the update data (31, 32, 33). 2, 33) whether they exist in the predetermined software supply source (20); when the updated data (31, 32, 33) that meets a download condition (S15 to S19) exists in the software supply source (20), the updated data (31, 32, 33) is downloaded from the software supply source (20) to store the updated data (31, 32, 33) in the area (12a); and when the multiple updated data (31, 32, 33) that meet the download condition (S15 to S19) exist simultaneously in the software supply source (20), the updated data (31, 32, 33) with the highest priority is selected from the multiple updated data (31, 32, 33) to perform the download.
[0070] According to a first illustrative aspect of this disclosure, the update method may further include: when the ignition signal (SG-IG) of the vehicle (17) is in the on state, performing the check and download of the update data (31, 32, 33) to store the update data (31, 32, 33) in the area (12a); and after the ignition signal (SG-IG) is switched to the off state, updating the software of the updated object with the update data (31, 32, 33) stored in the area (12a).
[0071] According to a first illustrative aspect of this disclosure, the update data (31, 32, 33) may include: first update data (31) of the region control unit (12) to which the update is to be performed; and second update data (32, 33) of the lower-level control unit (13, 14) to which the update is to be performed. When both the first update data (31) and the second update data (32, 33) exist in the software supply source (20), the selection of the update data (31, 32, 33) includes preferentially selecting the first update data (31).
[0072] According to a first illustrative aspect of this disclosure, the updated data (31, 32, 33) may include multiple updated data (31, 32, 33). When the multiple updated data (31, 32, 33) are simultaneously present in the software supply source (20), the selection of an updated data (31, 32, 33) may include preferentially selecting an updated data (31, 32, 33) from the multiple updated data (31, 32, 33), the updated data (31, 32, 33) having a minimum number of attempts to perform update processing.
[0073] According to a first illustrative aspect of this disclosure, a non-transient computer-readable medium is provided that stores a program that causes a computer to perform the vehicle software update method.
[0074] According to the vehicle software update method of the first aspect described above, regardless of whether the software update is performed on a regional control unit or any of the multiple lower-level control units, the downloaded update data is stored only in the first region. Therefore, it is unnecessary to secure any storage area required for software updates other than the first region. That is, since the first region can be shared by all update targets, it is not necessary to prepare a special storage area for storing update data in each of the multiple lower-level control units, and the storage area of the entire system can be used effectively. When multiple types of update data exist simultaneously, only the type of update data with the higher priority is selected and downloaded. Therefore, the storage capacity of the first region can be reduced. Situations such as duplicate downloads of update data for the same update target due to update failures can be avoided.
[0075] According to a second illustrative aspect of this disclosure, an in-vehicle system (10) includes: a top-level control unit (11); a regional control unit (12) connected downstream of the top-level control unit (11); and a plurality of lower-level control units (13, 14) connected downstream of the regional control unit (12). The regional control unit (12) includes a memory (12a) and a processor (12). The memory (12a) has a region (12a) capable of storing any update data (31, 32, 33) for updating software of the regional control unit (12) or the plurality of lower-level control units (13, 14). The processor (12) performs an update process to: when the update data (31, 32, 33) that meets a download condition (S15 to S19) exists in the software supply source (20), download the update data (31, 32, 33) from the software supply source (20) to store the update data (31, 32, 33) in the region (12a); and when the multiple update data (31, 32, 33) that meet the download condition (S15 to S19) exist simultaneously in the software supply source (20), preferentially select the update data (31, 32, 33) with the highest priority from the multiple update data (31, 32, 33) to perform the download.
[0076] According to the vehicle system described in the second aspect above, regardless of whether the software update is performed on a regional control unit or any of the multiple lower-level control units, the downloaded update data is stored only in the first region. Therefore, it is unnecessary to secure any additional storage area required for software updates besides the first region. That is, since the first region can be shared by all update targets, there is no need to prepare a special storage area for storing update data in each of the multiple lower-level control units, and the storage area of the entire system can be used efficiently. When multiple types of update data exist simultaneously, only the type of update data with the higher priority is selected and downloaded. Therefore, the storage capacity of the first region can be reduced. Situations such as duplicate downloads of update data for the same update target due to update failures can be avoided.
[0077] According to a second illustrative aspect of this disclosure, the processor (12) can perform the update process to: when the ignition signal (SG-IG) of the vehicle (17) is in the on state, perform the check and download of the update data (31, 32, 33) to store the update data (31, 32, 33) in the region (12a); and after the ignition signal (SG-IG) is switched off, update the software of the updated object with the update data (31, 32, 33) stored in the region (12a).
[0078] According to the vehicle-mounted system described in the third aspect above, power output from the vehicle's alternator (alternator) can be used when confirming and downloading updated data, thus eliminating concerns about battery consumption. Therefore, power supply can be controlled to fully utilize all necessary ECUs and communication functions, and the download can be performed efficiently. During software updates, most ECUs are in a suspended state, making it unlikely that anything will affect the software update. Therefore, software updates can be performed effectively.
[0079] According to a second illustrative aspect of this disclosure, the update data (31, 32, 33) includes: first update data (31), by which the region control unit (12) is updated; and second update data (32, 33), by which the lower-level control unit (13, 14) is updated. When both the first update data (31) and the second update data (32, 33) exist in the software supply source (20), the processor (12) can perform the update process to preferentially select the first update data (31).
[0080] According to the vehicle system described in the fourth aspect above, when update data for updating the regional control unit and each of the multiple lower-level control units is available, the regional control unit can be updated first. In this way, under the control of the regional control unit, which has been updated to the latest software, subsequent software update processing can be performed in a stable state.
[0081] According to a second illustrative aspect of this disclosure, the updated data (31, 32, 33) may include multiple updated data (31, 32, 33). When the multiple updated data (31, 32, 33) are simultaneously present in the software supply source (20), the processor (12) may perform the update process to preferentially select one updated data (31, 32, 33) from the multiple updated data (31, 32, 33), the one updated data (31, 32, 33) having a minimum number of attempts at the update process.
[0082] According to the vehicle-mounted system described in the fifth aspect above, abnormal situations such as repeatedly downloading and starting the same type of update data in a loop can be avoided. For example, the processing order of update data with large data volumes and updates that may be interrupted due to timeouts can be postponed, and updateable data can be processed efficiently in a short time.
[0083] According to the vehicle software update method and vehicle system disclosed herein, the storage space required for software updates can be reduced. That is, regardless of whether the software update is performed for a regional control unit or any of multiple lower-level control units, the downloaded update data is stored only in the first area. Therefore, it is not necessary to secure any additional storage space required for software updates besides the first area.
Claims
1. A method for updating in-vehicle software, used to update software included in an in-vehicle system, the in-vehicle system having a top-level control unit, a region control unit connected downstream of the top-level control unit, and a plurality of lower-level control units connected downstream of the region control unit, the updating method comprising: A region is secured in the memory of the region control unit, the region being able to store update data for updating the region control unit and the lower-level control unit, which are the objects of the update; Repeatedly check whether the updated data exists in the predetermined software supply source; When the software supply source contains updated data that meets a download condition, the updated data is downloaded from the software supply source to store the updated data in the area. as well as When multiple update data that meet the download condition exist simultaneously in the software supply source, the update data with the highest priority is selected from the multiple update data to perform the download; When multiple update data exist simultaneously in the software supply source, the number of update data with the minimum number of installation attempts among the multiple update data is determined; If the quantity is equal to 1, then download the updated data with the minimum number of installation attempts. If the number is greater than 1, then it is identified whether the multiple update data include the update data for updating the area control unit. If yes, then the update data for updating the area control unit is downloaded. If no, then the update data for updating the lower-level control unit is downloaded in a predetermined order.
2. The method for updating vehicle software according to claim 1 further includes: When the vehicle's ignition signal is on, the check and download of the updated data are performed to store the updated data in the area; as well as After the ignition signal is switched to the off state, the software of the updated object is updated by the update data stored in the area.
3. A non-transient computer-readable medium storing a program that enables a computer to execute the method for updating vehicle software according to claim 1 or 2.
4. A vehicle-mounted system, comprising: Topmost control unit; A regional control unit, which is connected to the downstream side of the uppermost control unit; as well as Multiple lower-level control units are connected to the downstream side of the regional control unit, wherein The region control unit includes a memory on the region control unit, the memory having a region capable of storing any update data for updating software of the region control unit or the plurality of lower-level control units. The area control unit includes: An update object selection unit is configured to select the update object of the update data stored in the region, and An update control unit is configured to check whether the update data exists in a predetermined software supply source and to check the type of the update object. The update control unit is configured as follows: When updated data meeting a download condition exists in the software supply source, the updated data is downloaded from the software supply source to store the updated data in the area; and When multiple update data that meet the download condition exist simultaneously in the software supply source, the update data with the highest priority is selected from the multiple update data to perform the download; When multiple update data exist simultaneously in the software supply source, the number of update data with the minimum number of installation attempts among the multiple update data is determined; If the quantity is equal to 1, then download the updated data with the minimum number of installation attempts. If the number is greater than 1, then it is identified whether the multiple update data include the update data for updating the area control unit. If yes, then the update data for updating the area control unit is downloaded. If no, then the update data for updating the lower-level control unit is downloaded in a predetermined order.
5. The vehicle-mounted system according to claim 4, wherein... The update control unit is configured as follows: When the vehicle's ignition signal is on, the check and download of the updated data are performed to store the updated data in the area; and After the ignition signal is switched to the off state, the software of the updated object is updated by the update data stored in the area.
Citation Information
Patent Citations
Automobile control unit
JP2006301960A
Electronic control device
JP2019073106A
Information update device and information update method
CN111201510A
Control apparatus, program updating method, and computer program
US20190354364A1