Software update device, software update method, and software update processing program
By providing two storage units in the vehicle ECU, the vehicle can be updated without malfunctioning of the engine or battery, thereby improving the convenience of the update.
Patent Information
- Application Number
- CN202180020702.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-18
- Filing Date
- 2021-03-15
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2041-03-15
AI Technical Summary
During the vehicle ECU software update, the engine and other components may malfunction and cause accidents, and stopping the engine for a long time will cause the battery to deplete, reducing convenience.
An electronic control unit with two storage units is used to store the first and second software respectively. Software updates are performed when no driving force is output through the powertrain to ensure that the engine and other parts do not malfunction. Updates can also be performed by connecting to an external battery.
Prevents malfunction of the engine, etc. during software updates, shortens the time the engine, etc. are stopped, avoids battery depletion, and improves update convenience.
Smart Images

Figure CN115279627B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a software update device, a software update method, and a software update processing program. BACKGROUND
[0002] In the past, when software of an ECU (Electronic Control Unit) mounted on a vehicle is updated in a wired manner, in order to prevent battery depletion due to a decrease in battery voltage, the ECU must be connected to an external battery during the update processing.
[0003] In view of this, in JP 2010-19175 A, a data writing system that determines a vehicle that is a program (software) rewriting object of an ECU by wireless communication and performs data writing and writing work of writing data is disclosed. In this data writing system, the engine being in an operating state is set as a precondition for performing data writing, in order to avoid battery depletion in the middle of data writing work. SUMMARY
[0004] During the update of the software of the ECU, the function of a device that is a control object of the ECU is stopped. Thus, as in the technology described in Patent Document 1, if the engine and the like is in an operating state during software update, for example, in the case where the brake function is stopped, an unexpected accident can occur. Thus, it is necessary to stop the operation of the power transmission system such as the engine during software update, so that the engine and the like do not perform a misoperation.
[0005] However, if the engine is stopped for a long time for software update, battery depletion can occur. In order to prevent battery depletion, it is also possible to perform the update of the software while being connected to an external battery, but a device such as a high-voltage battery is required, and thus convenience is reduced.
[0006] The present application was made in view of the above problems, and aims to provide a software update device, a software update method, and a software update processing program that prevent misoperation of the engine and the like during software update and improve the convenience at the time of update work.
[0007] Solution to the problem
[0008] According to one embodiment of the present application, there is provided a software update device that performs an update process of software for causing a device mounted on a vehicle to operate. The software update device includes a controller that acquires the software and controls the device by applying the software to the device. The controller has a first storage section that stores first software acquired and a second storage section that stores second software acquired. Further, the controller performs the update process of the software by changing the software applied to the device from the first software to the second software in a state in which a driving force is not output from a power train system of the vehicle. BRIEF DESCRIPTION OF DRAWINGS
[0009] Figure 1 is a schematic configuration diagram of a software update system according to one embodiment of the present application.
[0010] Figure 2 is a flowchart illustrating software update control according to one embodiment of the present application. DETAILED DESCRIPTION
[0011] Hereinafter, an embodiment of the present application will be described with reference to the drawings.
[0012] Reference will be made to Figure 1 and Figure 2 to describe one embodiment of the present application. Figure 1 is a schematic configuration diagram of a software update system 100 and a software update device 110 according to an embodiment of the present application.
[0013] As shown in Figure 1 , the software update system 100 is configured of an external server 2 and the software update device 110 mounted on the vehicle 1, and the software update device 110 is configured of a controller 10 and a detection section 3.
[0014] The controller 10 includes a gateway 11 for acquiring software from the external server 2 and an electronic control unit (ECU) 12 for controlling each device mounted on the vehicle 1.
[0015] The gateway 11 is capable of communicating with the external server 2 and the electronic control unit 12, acquires software for update from the external server 2, and transmits the acquired software for update to the electronic control unit 12 as an update target. In addition, the gateway 11 acquires control information of each device from the electronic control unit 12 and acquires a driving force output state of the power train system from the detection section 3 described later.
[0016] The gateway 11 is constituted by a computer provided with a central processing unit (CPU), a read only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface), and performs unified control of the software updating device 110. The gateway 11 performs processing for controlling the software updating device 110 by executing a specific program. The gateway 11 performs software update control described later, for example, together with the electronic control units 12.
[0017] The electronic control units (ECUs) 12 are controllers for controlling each device mounted on the vehicle 1, and are, for example, a BCM (Body Control Module), a VDC (Vehicle Dynamics Control), an HEVC (Hybrid Electric Vehicle Control), and the like. Each electronic control unit 12 is constituted by a computer provided with a central processing unit (CPU), a read only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface). The BCM controls the moving elements of the vehicle body of the vehicle 1 including an engine starter, a door lock, and the like of the vehicle 1. The VDC controls the braking of the vehicle 1, the output of the engine, and controls the posture of the vehicle 1, thereby preventing the vehicle 1 from skidding and the like. The HEVC controls the engine and the motor as a driving source to achieve efficient operation in the case where the vehicle 1 is a hybrid vehicle.
[0018] The electronic control units 12 are capable of communicating with the gateway 11, and continuously transmit control information of each device as a signal to the gateway 11. Each electronic control unit 12 acquires software containing a specific program from the gateway 11, and controls the object device by applying the acquired software to the device as a control object. In addition, the electronic control units 12 perform software update control described later together with the gateway 11.
[0019] In addition, each electronic control unit 12 is provided with two storage sections 121, 122 for storing the software acquired from the gateway 11. The electronic control unit 12 applies the software stored in one storage section (first storage section) 121 to the device. In addition, the electronic control unit 12 performs update of the software by changing the software applied to the device to the software stored in the other storage section (second storage section) 122. Further, details of the update processing of the software are described later.
[0020] The detection section 3 includes a crank angle sensor for detecting driving of the engine, an accelerator pedal sensor, and the like, and detects the driving force output state of the powertrain system of the vehicle 1. The driving force output state of the powertrain system detected by the detection section 3 is transmitted as a signal to the gateway 11.
[0021] Next, the update processing of the software will be described.
[0022] As described above, each of the electronic control units 12 is provided with two storage sections 121, 122. When the electronic control unit 12 acquires the software (first software) transmitted from the gateway 11, the software is stored in one of the storage sections (first storage section) 121, and the electronic control unit 12 applies the software to the device. Further, the first software can not be acquired from the gateway 11, but can be stored in the first storage section 121 in an initial state.
[0023] Next, when the electronic control unit 12 acquires the software for update (second software) transmitted from the gateway 11, the software for update is stored in the other storage section (second storage section) 122. The electronic control unit 12 still applies the first software to the device during the period of acquiring and storing the second software.
[0024] Thus, each of the electronic control units 12 is provided with two storage sections 121, 122, whereby the electronic control unit 12 can acquire (download) and store (install) the software for update in a state where the first software is applied to the device. That is, the software for update can be acquired and stored without stopping the operation of the control target device.
[0025] When the software for update (second software) is acquired and stored, the electronic control unit 12 changes the software applied to the device from the first software to the second software. Thus, the software applied to the device is updated. Hereinafter, the processing of changing the software applied to the device from the first software to the second software will be referred to as the update processing (activation) of the software.
[0026] However, if the state of outputting the driving force by the power transmission system such as the engine is continued during the update processing of the software, for example, in the case where the brake function is stopped, an unexpected accident can occur. Thus, in the present embodiment, the update processing of the software is executed in a state where the driving force is not outputted by the power transmission system.
[0027] Specifically, after the detection section 3 detects that the state of outputting the driving force by the power transmission system of the vehicle 1 is not continued, the gateway 11 executes the update processing of the software, and prohibits the output of the driving force by the power transmission system during the update processing of the software. For example, when it is detected by the detection section 3 that the state of the engine speed being 0 and the engine being off, the state of the transmission being in neutral (N) or park (P), or the like is continued, the update processing of the software is started, and the output of the driving force by the power transmission system is prohibited. The output of the driving force by the power transmission system is prohibited until the update processing of the software is completed, and when the activation is completed, the output of the driving force by the power transmission system is permitted.
[0028] Thus, since the update processing of the software is executed in a state where the power transmission system of the vehicle 1 does not output the driving force, it is possible to prevent the power transmission system such as the engine from operating erroneously during activation. In addition, in a state where the first software is applied to the device, the electronic control unit 12 acquires (downloads) and stores (installs) the software for update, and only during activation, the output of the driving force by the power transmission system is prohibited. That is, during the period in which the electronic control unit 12 acquires and stores the software for update, the output of the driving force by the power transmission system is permitted, and thus it is possible to acquire and store the software for update while the vehicle 1 is running. In addition, it is possible to operate the engine and the like during the period in which the software for update is acquired and stored, and thus compared to a case where the engine and the like are stopped during the period in which the software for update is acquired and stored, it is possible to shorten the stop time of the engine and the like for software update. Thus, it is possible to prevent the battery from running out of power during software update.
[0029] Further, the detection of the driving force output state of the power transmission system of the vehicle 1 does not necessarily have to be performed using the probe 3. For example, it is also possible to not provide the probe 3, and to provide a structure in which the gateway 11 is capable of directly receiving the ignition switch signal, to detect the driving force output state of the power transmission system.
[0030] Figure 2 This is a flowchart illustrating software update control according to an embodiment of the present application. Further, the following control is performed by the controller 10 (gateway 11, electronic control unit 12). In addition, it is assumed that in an initial state, the first software is stored in the first storage section 121 of the electronic control unit 12, and the first software is applied to the control target device.
[0031] In step S101, the gateway (GW) 11, when acquiring the software for update (second software) from the external server 2, transmits the software for update to the electronic control unit 12 which is the update target.
[0032] In step S102, the electronic control unit 12 acquires (downloads) the software for update (second software) from the gateway 11.
[0033] Next, in step S103, the electronic control unit 12 stores (installs) the software for update (second software) in the second storage section 122. During the period in which the second software is acquired and stored in steps S102 and S103, the first software is still applied to the control target device of the electronic control unit 12. That is, the device including the engine and the like is not stopped during the period in which the electronic control unit 12 acquires and stores the second software.
[0034] In step S104, the gateway 11 obtains a signal indicating the driving force output state of the vehicle 1's powertrain (PT) as detected by the detector 3. If driving force is not being output through the powertrain, the gateway 11 executes step S105. As previously mentioned, a state in which driving force is not being output through the powertrain includes, for example, a state in which the engine speed is zero and the engine is off, or a state in which the transmission is in neutral (N) or park (P). On the other hand, if driving force is being output through the powertrain, the gateway 11 repeats step S104 until driving force is not being output through the powertrain.
[0035] In addition, when the vehicle 1 is in a state where the output of the driving force through the powertrain is output in step S104, if the vehicle 1 is in a state where no malfunction occurs even if the output of the driving force through the powertrain is stopped, the output of the driving force may be stopped. For example, when the vehicle 1 is in a state where no malfunction occurs even if the output of the driving force through the powertrain is stopped, an instruction to stop the output of the driving force through the powertrain is sent from the gateway 11 to the electronic control unit 12. When the instruction to stop the output of the driving force is received, the electronic control unit 12 stops the output of the driving force through the powertrain. For example, it is possible to determine whether the vehicle 1 is in a state where no malfunction occurs even if the output of the driving force through the powertrain is stopped based on the control information received by the gateway 11 from each electronic control unit 12.
[0036] When the driving force is not being outputted through the powertrain, the gateway 11 allows the electronic control unit 12 to perform software update processing (activation) in step S105 .
[0037] Next, in step S106 , the gateway 11 prohibits output of driving force through the power transmission system.
[0038] In step S107, the electronic control unit 12 changes the software applied to the device being controlled by the electronic control unit 12 from the first software to the second software. Thus, the software applied to the device is updated from the first software to the second software. Furthermore, during the software update process, it is preferable to notify the driver of the update process via a display device or the like.
[0039] When the update of the software is completed, in step 108 , the gateway 11 allows the driving force to be output through the powertrain system.
[0040] In this manner, the gateway 11 prohibits the powertrain from outputting driving force while the software update process is being executed, thereby more reliably preventing the powertrain, such as the engine, from malfunctioning during the active period.
[0041] Furthermore, to more reliably prevent malfunctions of the powertrain, it is preferable to prohibit the output of driving force from the powertrain during the activation period, but this is not necessarily the only option. The software update process in this embodiment does not involve acquiring and storing the updated software, and therefore is completed in a short period of time. Therefore, if the software update process is initiated while driving force is not being output by the powertrain, it is not necessary to specifically prohibit the output of driving force from the powertrain during the activation period. In other words, steps S106 and S108 may be omitted.
[0042] When the output of the driving force through the power transmission system is permitted in step S108 , the gateway 11 ends the software update control.
[0043] When the software is updated again next time, the update software sent from the gateway 11 to the electronic control unit 12 is stored (overwritten) in the first storage unit 121. The software applied to the device is changed from the second software stored in the second storage unit 122 to the update software stored in the first storage unit 121, thereby performing the software update again.
[0044] also, Figure 2 The processes shown are configured as programs for execution by the controller 10 , which is a computer, and these programs are recorded on a storage medium.
[0045] According to the software updating device 110 of the above-described embodiment, the following effects can be obtained.
[0046] In the software update device 110, the electronic control unit 12 (controller 10) has a first storage unit 121 for storing the first software and a second storage unit 122 for storing the second software. Therefore, it is possible to obtain the software for update (the second software) and store it in the second storage unit 122 while the first software stored in the first storage unit 121 is applied to the device. Therefore, even while the vehicle 1 is traveling, the software for update can be obtained and stored. On the other hand, the controller 10 performs the software update process while the driving force is not output through the power transmission system of the vehicle 1. In this way, the vehicle 1 can travel while the software for update is obtained and stored, and on the other hand, the software update process is performed while the driving force is not output through the power transmission system of the vehicle 1. Therefore, it is possible to provide a software update device 110 that prevents malfunction of the engine, etc. during the software update and improves the convenience during the update operation.
[0047] Furthermore, since the updated software can be acquired and stored while the first software stored in first storage unit 121 is being applied to the device, it is sufficient to stop the output of driving force from the powertrain, such as the engine, only during the active period. In other words, the engine, etc. can be operated while the updated software is being acquired and stored. This shortens the time the engine, etc. is stopped for the software update, compared to stopping the engine, etc. during the acquisition and storage of the updated software. Consequently, battery depletion during the software update can be prevented.
[0048] In software update device 110, controller 10 permits execution of the software update process when detection unit 3 detects that driving force is not being output by the powertrain of vehicle 1. By permitting execution of the software update process after detection of a state in which driving force is not being output by the powertrain, malfunctions of the engine, etc., can be more reliably prevented during the software update.
[0049] In the software update device 110, the controller 10 prohibits the powertrain of the vehicle 1 from outputting driving force while executing the software update process (activation). This can more reliably prevent the powertrain, such as the engine, from malfunctioning during activation.
[0050] In software update device 110, controller 10 prohibits the output of driving force from the vehicle 1's powertrain while executing the software update process (activation). Once the update process is complete, controller 10 permits the output of driving force from the powertrain. By prohibiting the output of driving force from the powertrain only during the activation period, the engine and other components are stopped for the software update, shortening the time it takes to stop. This prevents battery depletion during the software update.
[0051] In the present embodiment, the electronic control unit (ECU) 12 is a BCM, a VDC, or an HEVC. However, the type and number of the electronic control unit 12 are not limited thereto as long as the ECU 12 is a device for controlling equipment mounted on the vehicle 1 .
[0052] The software update control including the software update process of the present embodiment may be executed simultaneously for a plurality of electronic control units 12 , or may be executed at different times for each electronic control unit 12 .
[0053] In addition, in this embodiment, the gateway 11 is configured to perform unified control of the software update device 110, and the electronic control unit 12 is configured to control each device installed in the vehicle 1. However, the main body of each control may be either the gateway 11 or the electronic control unit 12. For example, the electronic control unit 12 may directly prohibit the output of driving force by the powertrain during the activation period without receiving instructions from the gateway 11. In addition, the software changes applied to the devices (software update processing) may be performed by the gateway 11 instead of the electronic control unit 12.
[0054] While the embodiments of the present invention have been described above, the above embodiments merely illustrate a part of application examples of the present invention and are not intended to limit the technical scope of the present invention to the specific configurations of the above embodiments.
[0055] This application claims priority based on Japanese Patent Application No. 2020-048340 filed with the Japan Patent Office on March 18, 2020, the entire contents of which are incorporated herein by reference.
Claims
1. A software updating device for executing an update process for software used to operate a device mounted on a vehicle. The device includes a power transmission system of the vehicle, The software updating device comprises: a detection unit that detects a driving force output state of a power transmission system of the vehicle; and a controller that acquires the software and controls the device by applying the software to the device, in, The controller has: a first storage unit storing the acquired first software; as well as a second storage unit storing the acquired second software; When the detection unit detects that the driving force is not output through the power transmission system of the vehicle, the controller performs the software update process by changing the software applied to the device from the first software to the second software in the state in which the driving force is not output through the power transmission system of the vehicle. The controller prohibits the output of driving force by the powertrain of the vehicle during the execution of the software update process. The state where the driving force is not outputted by the power transmission system of the vehicle is a state where the engine speed is 0 and the engine is turned off, or a state where the transmission is in neutral or parking.
2. The software updating device according to claim 1, wherein: When the software update process is completed, the controller allows the driving force to be output through the powertrain of the vehicle.
3. The software updating device according to claim 1 or 2, wherein: When the detection unit detects that the driving force is not output through the vehicle's power transmission system, the controller allows the software update process. After allowing the software update process, the controller prohibits the software update process when the driving force is output through the vehicle's power transmission system.
4. A method for updating software for operating a device mounted on a vehicle, The device includes a power transmission system of the vehicle, The software updating method includes the following steps: applying the first software stored in the first storage unit to the device; Acquire second software, and store the second software in a second storage unit; detecting a driving force output state of a power transmission system of the vehicle; as well as When it is detected that the driving force is not outputted through the powertrain of the vehicle, the software update process is performed by changing the software applied to the device from the first software to the second software in the state where the driving force is not outputted through the powertrain of the vehicle. During the execution of the software update process, output of driving force through the powertrain system of the vehicle is prohibited. The state where the driving force is not outputted by the power transmission system of the vehicle is a state where the engine speed is 0 and the engine is turned off, or a state where the transmission is in neutral or parking.
5. A computer program product comprising a software update processing program for implementing software update processing, the software for operating a device mounted on a vehicle, The device includes a power transmission system of the vehicle, The software update processing program is used to enable the controller to implement the following steps: applying the first software stored in the first storage unit to the device; Acquire second software, and store the second software in a second storage unit; detecting a driving force output state of a power transmission system of the vehicle; When it is detected that the driving force is not outputted by the powertrain of the vehicle, the software applied to the device is updated from the first software to the second software while the driving force is not outputted by the powertrain of the vehicle. as well as During the execution of the software update process, output of driving force through the powertrain of the vehicle is prohibited, The state where the driving force is not outputted by the power transmission system of the vehicle is a state where the engine speed is 0 and the engine is turned off, or a state where the transmission is in neutral or parking. 6 . A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, executes the software updating method according to claim 4 .
Citation Information
Patent Citations
Data writing system for in-vehicle electronic control unit
JP2010019175A
Stator and motor
JP2020048340A
Software update apparatus, software update system and software update method
JP2018200510A
On-board update system, on-board update device, and communication device update method
US20190250902A1