Software update device, software update method, and software update processing program
By prohibiting the output of warnings during software update processing in the vehicle's software update device, unnecessary warning problems caused by hardware reset are solved, ensuring the smooth progress of software updates and the driver's sense of security.
Patent Information
- Application Number
- CN202080098618.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-03-18
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2040-03-18
AI Technical Summary
During the software update processing of the electronic control unit of the vehicle, temporary resetting of the hardware causes interruption of communication with other on-board devices, misjudged as abnormal, recorded a fault code and issued a warning, which may lead the driver to misunderstand that the software update failed or the vehicle malfunction, causing uneasiness.
A software update device is designed to obtain the software for update through the controller and perform update processing without interrupting the operation of the device. During the execution of the software update process, the warning device is prohibited from outputting a warning to avoid unnecessary warnings.
It effectively prevents unnecessary warning output caused by software update processing, avoids driver misunderstanding and uneasiness, and ensures the smooth progress of software updates.
Smart Images

Figure CN115298064B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a software update device, a software update method, and a software update processing program. Background Art
[0002] JP2018-97764A discloses an in-vehicle data update device. The in-vehicle control unit of the in-vehicle data update device receives update data from an external server and uses the update data to update an update target unit (update process). Summary of the Invention
[0003] In addition, when performing an update process of software implemented in an electronic control unit (ECU (Electronic Control Unit)) mounted on a vehicle, in order to update the rewritten content of the software, the hardware of the electronic control unit is temporarily reset. At this time, communication with other in-vehicle devices is temporarily interrupted, so it is determined that an abnormality has occurred, a failure code is recorded in the vehicle control unit, and a warning is notified to the driver or the like. Therefore, there is a possibility that the driver or the like may be uneasy due to a misunderstanding that the software update process has failed or the vehicle has malfunctioned.
[0004] The present invention has been made in view of the above problems, and an object thereof is to provide a software update device, a software update method, and a software update processing program that prevent the output of unnecessary warnings caused by software update processing.
[0005] Solution to the Problem
[0006] According to one aspect of the present invention, there is provided a software update device that performs an update process of software for operating a device mounted on a vehicle. The software update device includes a controller that acquires software and controls the device by applying the software to the device. The controller acquires software for update and performs a software update process by applying the software to the device. When an abnormality related to the device occurs, the controller causes a warning device to output a warning. In addition, during the execution of the software update process, the controller prohibits the warning device from outputting a warning. Brief Description of the Drawings
[0007] Figure 1 is a schematic configuration diagram of a software update system according to an embodiment of the present invention.
[0008] Figure 2 is a flowchart for explaining software update control according to an embodiment of the present invention. Detailed Description of the Invention
[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings and the like.
[0010] Reference Figure 1 and Figure 2 to describe an embodiment of the present invention. Figure 1 It is a schematic structural diagram of the software update system 100 and the software update device 110 involved in the embodiment of the present invention.
[0011] As Figure 1 shown, the software update system 100 is composed of the software update device 110 mounted on the vehicle 1 and the external server 2, and the software update device 110 is composed of the controller 10 and the warning device 3. The vehicle 1 is, for example, an electric vehicle (EV).
[0012] The controller 10 includes a gateway 11 for obtaining software from the external server 2 and an electronic control unit 12 for controlling each device mounted on the vehicle 1.
[0013] The gateway 11 can communicate with the external server 2 and the electronic control unit 12, and is used to obtain the software for update from the external server 2 and send the obtained software for update to the electronic control unit 12 of the update target. In addition, the gateway 11 can communicate with the warning device 3 described later. The gateway 11 obtains the control information of each device from the electronic control unit 12 and detects the occurrence of an abnormality related to each device based on the control information. The gateway 11 has a storage area for recording a fault code when an abnormality occurs, and when it detects the occurrence of an abnormality in each device, it records the fault code corresponding to the abnormality in the storage area. When the fault code is recorded in the storage area, the gateway 11 outputs a warning through the warning device 3 based on the recorded fault code.
[0014] In addition, the gateway 11 is composed of a computer equipped with a central processing unit (CPU), a read-only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface), and is used for comprehensive control of the software update device 110. The gateway 11 executes the process for controlling the software update device 110 by executing a specific program. The gateway 11, for example, performs the software update control described later together with the electronic control unit 12.
[0015] The electronic control unit (ECU) 12 is a controller for controlling various devices mounted on the vehicle 1, such as a BCM (Body Control Module), VDC (Vehicle Dynamics Control), HEVC (Hybrid Electric Vehicle Control), etc. Each electronic control unit 12 is composed of a computer having a central arithmetic unit (CPU), a read-only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface). The BCM controls the operation elements of the vehicle body of the vehicle 1, including the engine starter, door lock, etc. of the vehicle 1. The VDC controls the posture of the vehicle 1 by controlling the brakes and the output of the engine of the vehicle 1, thereby preventing the vehicle 1 from skidding, etc. When the vehicle 1 is a hybrid vehicle, the HEVC controls the engine and the motor as drive sources to achieve efficient driving.
[0016] The electronic control unit 12 can communicate with the gateway 11 and is used to always send the control information of each device to the gateway 11 as a signal. Each electronic control unit 12 obtains software containing a specific program from the gateway 11 and controls the target device by applying the obtained software to the device to be controlled. In addition, the electronic control unit 12 performs software update control described later together with the gateway 11.
[0017] In addition, each electronic control unit 12 is respectively provided with two storage parts 121 and 122 for storing the software obtained from the gateway 11. The electronic control unit 12 updates the software by applying the software stored in one storage part (the first storage part) 121 to the device and changing the software applied to the device to the software stored in the other storage part (the second storage part) 122. In addition, the details of the software update process are described later.
[0018] The warning device 3 is, for example, a warning light of the vehicle 1 and is used to notify the driver, etc. of the abnormality when an abnormality occurs in various devices mounted on the vehicle 1. The warning device 3 can communicate with the gateway 11. When the gateway 11 detects an abnormality of the in-vehicle device, it records a fault code corresponding to the abnormality in the storage area and outputs a warning by, for example, lighting the warning light as the warning device 3. In addition, the warning device 3 is not limited to a warning light and can also be, for example, an audible alarm, etc.
[0019] Next, the software update process will be described.
[0020] As described above, each electronic control unit 12 includes two storage units 121 and 122 respectively. When the electronic control unit 12 acquires the software (the first software) sent from the gateway 11, it stores the software in one storage unit (the first storage unit) 121, and the electronic control unit 12 applies the software to the device. In addition, the first software may not be acquired from the gateway 11 but may already be stored in the first storage unit 121 in the initial state.
[0021] Next, when the electronic control unit 12 acquires the software for update (the second software) sent from the gateway 11, it stores the software for update in the other storage unit (the second storage unit) 122. During the period when the electronic control unit 12 acquires and stores the second software, the first software is also applied to the device.
[0022] In this way, by respectively providing two storage units 121 and 122 in each electronic control unit 12, the electronic control unit 12 can acquire (download) and store (install) the software for update in the state where the first software is applied to the device. That is, it is possible to acquire and store the software for update without stopping the operation of the controlled device.
[0023] When the electronic control unit 12 acquires and stores the software for update (the second software), it changes the software applied to the device from the first software to the second software. Thus, the software applied to the device is updated. Hereinafter, the process of changing the software applied to the device from the first software to the second software is referred to as the software update process (activation).
[0024] In addition, when implementing the software update process of the electronic control unit 12, in order to update the rewritten content of the software, the hardware of the electronic control unit 12 is temporarily reset. At this time, the communication between the updated electronic control unit 12 and the electronic control unit 12 for controlling other in-vehicle devices is temporarily interrupted, so it is determined that an abnormality of the device has occurred, and a fault code is recorded in the storage area of the gateway 11. Therefore, a warning is notified to the driver or the like through the warning device 3. As a result, there is a possibility that the driver or the like may be mislead into thinking that the software update process has failed or that the vehicle 1 has a fault. In addition, the software update processes of the respective electronic control units 12 are not necessarily executed simultaneously, so multiple warnings may also be notified sequentially. In this case, there is a possibility that the driver or the like may be more uneasy. Therefore, in the present embodiment, the warning device 3 is prohibited from outputting a warning during the execution of the software update process.
[0025] Specifically, even if the gateway 11 detects the occurrence of an abnormality related to the device during the execution of the software update process, it does not record the fault code in the storage area. Thereby, the output of a warning is prohibited during the execution of the software update process.
[0026] In this way, during the execution of the software update process, the warning device 3 is prohibited from outputting a warning, so that it is possible to prevent the output of unnecessary warnings caused by the software update process.
[0027] In addition, when an abnormality of the device that is not caused by the software update process is detected after the output of the warning is prohibited, if the abnormality has not been eliminated after the software update process is completed, a failure code is recorded and a warning is output after the update process is completed.
[0028] Figure 2 It is a flowchart for explaining software update control according to an embodiment of the present invention. In addition, the following controls are all executed by the controller 10 (gateway 11, electronic control unit 12). Further, in the initial state, a first software is stored in the first storage unit 121 of the electronic control unit 12, and the first software is applied to the controlled device.
[0029] In step S101, when the gateway (GW) 11 obtains the software for update (second software) from the external server 2, the software for update is sent to the electronic control unit 12 of the update target.
[0030] In step S102, the electronic control unit 12 obtains (downloads) the software for update (second software) from the gateway 11.
[0031] Next, in step S103, the electronic control unit 12 stores (installs) the software for update (second software) in the second storage unit 122. During the period of obtaining the second software in this step S102 and storing the second software in this step S103, the first software is also applied to the controlled device of the electronic control unit 12, so the controlled device of the electronic control unit 12 does not stop. Therefore, for example, even while the vehicle 1 is running, it is possible to obtain and store the software for update. In addition, since the activation of the software for update can be executed in a short time, it is also possible to perform software acquisition, storage, and update processing in a state where the ignition switch is turned on (ON) (including during the running of the vehicle 1).
[0032] In step S104, while the electronic control unit 12 starts the software update process, the gateway 11 prohibits the warning device 3 from outputting a warning.
[0033] The electronic control unit 12 performs a software update process by changing the software applied to the controlled device from the first software to the second software. Thus, the software applied to the device is updated from the first software to the second software. In addition, preferably, during the software update process, a notification of the update process is given to the driver through a display device or the like (not shown).
[0034] In addition, for example, the output of warnings is prohibited by masking the storage area of the gateway 11. As a result, even if the gateway 11 detects the occurrence of an abnormality related to the device, a failure code is not recorded in the storage area, so the warning device 3 is prohibited from outputting a warning.
[0035] Furthermore, in step S104, the update process may be permitted only when no abnormality has been detected before starting the software update process. For example, the gateway 11 detects whether an abnormality of the device has occurred for the electronic control unit 12 before software update and sends the result of the detection to the electronic control unit 12. The electronic control unit 12 performs the update process only when no occurrence of an abnormality is detected. On the other hand, when an abnormality of the device is detected before the software update process is executed, the electronic control unit 12 prohibits the software update process until the abnormality is eliminated. That is, the output of warnings is prohibited during the execution of the software update process. Therefore, warnings are not output for abnormalities that are not caused by the update process. Thus, by eliminating abnormalities not caused by the software update process before starting the software update process, it is possible to reliably prevent the response to abnormalities from being delayed until after the software update process. In addition, it may be that the gateway 11 permits or prohibits the above-described software update process.
[0036] If the software update process is started in step S104, then in step S105, the gateway 11 temporarily resets the hardware (HW) of the update target electronic control unit 12 and updates the rewritten content of the software. If the hardware of the electronic control unit 12 is reset, the communication between the update target electronic control unit 12 and the electronic control unit 12 for controlling other in-vehicle devices is temporarily interrupted. The gateway 11 detects the disconnection of this communication as the occurrence of an abnormality related to the device, but since the storage area of the gateway 11 is masked, a failure code is not recorded in the storage area. Therefore, no warning is output either.
[0037] Next, if the software update process is completed in step S106, then in step S107, the gateway 11 releases the prohibition of warning output (allows warning output) and ends the software update control.
[0038] In this way, during the execution of the software update process, the warning device 3 is prohibited from outputting a warning, so it is possible to prevent the output of unnecessary warnings caused by the software update process.
[0039] In addition, after the output of warnings is prohibited, if the gateway 11 detects the occurrence of an abnormality of the device that is not caused by the software update process during the period of steps S104 to S107, and if the abnormality has not been eliminated after the update process is completed, a warning is output after the prohibition of warning output is released.
[0040] In addition, it is preferable that the output prohibition of the warning is released immediately after the software update process is completed, but it is not necessarily limited to this. For example, the output of the warning may be permitted after a fixed time has elapsed.
[0041] After the software update process is completed and when the software is to be updated next time, the update software sent from the gateway 11 to the electronic control unit 12 is stored (overwritten) in the first storage unit 121. The software of the device is re-updated by changing the software stored in the second storage unit 122 to the update software stored in the first storage unit 121.
[0042] In addition, Figure 2 The processes shown are configured as programs for causing the controller 10, which is a computer, to execute, and these programs are recorded on a storage medium.
[0043] According to the software update device 110 of the above-described embodiment, the following effects can be obtained.
[0044] In the software update device 110, when an abnormality related to the device occurs, the gateway 11 (controller 10) causes the warning device 3 to output a warning, and during the software update process, the gateway 11 (controller 10) prohibits the warning device 3 from outputting a warning. Since the output of the warning is prohibited during the software update process, even if the hardware of the electronic control unit 12 is temporarily reset for the rewritten content of the software update and the communication with other electronic control units 12 is cut off, no warning will be output. Therefore, it is possible to prevent the output of unnecessary warnings due to the software update process.
[0045] In the software update device 110, during the software update process, the gateway 11 (controller 10) prohibits the output of a warning, and after the software update process is completed, the gateway 11 (controller 10) permits the output of a warning. Thus, it is possible to prevent the output of unnecessary warnings due to the software update process, and for abnormalities of the device that are not due to the software update process, it is possible to warn the driver or the like after the software update process.
[0046] In the software update device 110, when an abnormality related to the device occurs, the gateway 11 (controller 10) records the fault code corresponding to the abnormality in the storage area of the gateway 11 (controller 10), and based on the recorded fault code, causes the warning device 3 to output a warning. On the other hand, even if an abnormality related to the device occurs during the software update process, the gateway 11 (controller 10) does not record the fault code. Therefore, during the software update process, no warning will be output by the warning device 3. Thus, it is possible to prevent the output of unnecessary warnings due to the software update process.
[0047] In the software update device 110, the electronic control unit 12 (controller 10) has a first storage unit 121 that stores the first software and a second storage unit 122 that stores the second software. Therefore, it is possible to acquire the software for update (second software) while the first software stored in the first storage unit 121 is applied to the device, and store the software for update (second software) in the second storage unit 122. Thus, it is possible to acquire and store the software for update without stopping the device controlled by the electronic control unit 12 to be updated, thereby improving the convenience during the software update operation.
[0048] In the software update device 110, there are a plurality of electronic control units 12 that respectively control a plurality of devices, and the plurality of electronic control units 12 respectively perform software update processing. Moreover, during the execution of the software update processing, the gateway 11 (controller 10) prohibits the warning device 3 from outputting a warning. In this way, by prohibiting the output of a warning during the execution of the software update processing of each electronic control unit 12, it is possible to prevent the driver or the like from becoming more uneasy due to a plurality of warnings sequentially notified due to the software update processing of each electronic control unit 12.
[0049] In addition, in the present embodiment, the electronic control unit 12 is set as the BCM, VDC, and HEVC, but as long as it is a unit that controls the devices mounted on the vehicle 1, the type of the electronic control unit 12 is not limited to them, and the number is not limited to this either.
[0050] In addition, regarding the software update control including the software update processing of the present embodiment, a plurality of the software update controls can be executed simultaneously for the plurality of electronic control units 12, or the software update control can be executed at different times for each of the electronic control units 12.
[0051] In addition, in the present embodiment, it is configured as follows: the gateway 11 executes the comprehensive control of the software update device 110, and the electronic control unit 12 executes the control of each device mounted on the vehicle 1, but the main body of each control can also be either the gateway 11 or the electronic control unit 12. For example, the change of the software applied to the device (software update processing) can be executed by the gateway 11 instead of the electronic control unit 12.
[0052] In addition, in the present embodiment, when an abnormality related to the device occurs, a failure code corresponding to the abnormality is recorded in the storage area of the gateway 11, and the warning device 3 outputs a warning based on the recorded failure code, but the method of outputting the warning is not limited to this. For example, it can also be that when an abnormality of the device is detected, the warning device 3 directly outputs a warning without recording the failure code.
[0053] In addition, in the present embodiment, even if an abnormality related to the device occurs during the execution of the software update process, the storage area of the gateway 11 is shielded and the failure code is not recorded, thereby prohibiting the output of a warning during the execution of the update process. However, the method of prohibiting the warning is not necessarily limited to this. For example, in the case where the warning device 3 directly outputs a warning without recording the failure code when an abnormality of the device is detected as described above, the prohibition of the output of the warning also prohibits the warning device 3 from directly outputting a warning.
[0054] In addition, in the present embodiment, the electronic control unit 12 is configured to have two storage units 121 and 122, but it is not necessarily limited to this. As described above, in order to be able to acquire and store the software for update without stopping the in-vehicle device, the electronic control unit 12 preferably has two storage units 121 and 122. However, the electronic control unit 12 may also be configured to have only one storage unit. In this case, the software update process is performed by overwriting the software for update on the software stored in this storage unit. In addition, in this case, the output of a warning is also prohibited during the acquisition and storage of the software for update.
[0055] As described above, the embodiments of the present invention have been described. However, the above embodiments only show a part of the application examples of the present invention, and are not intended to limit the technical scope of the present invention to the specific structures of the above embodiments.
Claims
1. A software update device that performs an update process for software that operates a device mounted on a vehicle. The software update device includes a controller that acquires the software and controls the device by applying the software to the device. The controller acquires the software for update and performs the software update process by applying the software to the device. When an abnormality related to the device occurs, the controller causes a warning device to output a warning. When an abnormality related to the device is detected during the execution of the update process, the controller prohibits the warning device from outputting a warning. Wherein, When an abnormality of the device that is not caused by the software update process is detected after the output of the warning is prohibited, if the abnormality of the device is not eliminated after the update process is completed, the controller records a failure code corresponding to the abnormality of the device after the update process is completed and causes the warning device to output a warning based on the recorded failure code.
2. The software update device according to claim 1, Wherein, When no abnormality related to the device occurs before the execution of the software update process, the controller allows the execution of the update process.
3. The software update device according to claim 1 or 2, Wherein, When an abnormality related to the device occurs, the controller records a failure code corresponding to the abnormality in a storage area of the controller and causes the warning device to output a warning based on the recorded failure code. When an abnormality related to the device occurs during the execution of the update process, the controller does not record the failure code and prohibits the warning device from outputting a warning.
4. The software update device according to claim 1 or 2, Wherein, The controller has: A first storage unit that stores the acquired first software; And A second storage unit that stores the acquired second software. The controller performs the software update process by changing the software applied to the device from the first software to the second software. During the execution of the update process, the controller prohibits the warning device from outputting a warning.
5. The software update device according to claim 1 or 2, Wherein, The software update device performs an update process for a plurality of software that operates a plurality of devices mounted on the vehicle. The controller includes a plurality of electronic control units that respectively control the plurality of devices. The plurality of electronic control units respectively acquire the software for update and perform the software update process by applying the software to the device. During the execution of the update process, the controller prohibits the warning device from outputting a warning.
6. The software update device according to claim 5, Wherein, The controller further includes a gateway that acquires the plurality of software from the outside and sends the software to the electronic control unit for controlling the corresponding device respectively. Each of the plurality of electronic control units obtains the software for update from the gateway, and performs an update process of the software by applying the software to the device. The gateway detects the occurrence of an abnormality related to the device.
7. The software update device according to claim 6, wherein, before performing the update process, the gateway detects the occurrence of an abnormality related to the device, and sends the result of the detection to the electronic control unit.
8. The software update device according to claim 6 or 7, wherein, the electronic control unit has: a first storage unit that stores the first software obtained; and a second storage unit that stores the second software obtained, the electronic control unit performs the update process of the software by changing the software applied to the device from the first software to the second software, during the execution of the update process, the gateway prohibits the warning device from outputting a warning.
9. The software update device according to claim 1 or 2, wherein, the warning device is a warning light of the vehicle, the controller outputs a warning by lighting the warning light.
10. A method for updating software, the software being used to operate a device mounted on a vehicle, the update method comprises the following steps: obtaining software for update, and performing an update process of the software by applying the software to the device; outputting a warning when an abnormality related to the device occurs; and when an abnormality related to the device is detected during the update process, prohibiting the output of the warning, wherein, when an abnormality of the device that is not caused by the software update process is detected after the output of the warning is prohibited, if the abnormality of the device is not eliminated after the update process is completed, then after the update process is completed, a failure code corresponding to the abnormality of the device is recorded and a warning is output based on the recorded failure code.
11. A storage medium stores a software update processing program, the software update processing program is used to implement an update process of software, the software is used to operate a device mounted on a vehicle, the software update processing program is used to enable a controller to implement the following steps: obtaining software for update, and performing an update process of the software by applying the software to the device; outputting a warning when an abnormality related to the device occurs; and when an abnormality related to the device is detected during the update process, prohibiting the output of the warning, wherein, when an abnormality of the device that is not caused by the software update process is detected after the output of the warning is prohibited, if the abnormality of the device is not eliminated after the update process is completed, then the controller records a failure code corresponding to the abnormality of the device after the update process is completed and outputs a warning based on the recorded failure code.
12. A computer program product includes a computer program, the computer program executes the software update method according to claim 10 when run by a processor.
Citation Information
Patent Citations
On-vehicle data update device
JP2018097764A
Control device for vehicle and method of controlling same
JP2008195130A
Program rewriting device and program rewriting method
JP2016188022A
On-vehicle updating device, on-vehicle updating system and updating method for communication device
JP2018020718A