Ota manager, system, method, non-transitory storage medium, and vehicle
Patent Information
- Application Number
- CN202210508244.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-06-22
- Filing Date
- 2022-05-11
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-05-11
AI Technical Summary
具体而言,若执行与连接有各电子控制单元的车载网络的通信状况不相应的软件的安装,则在更新因车载网络的通信状况而失败时,存在因各个电子控制单元的恢复方法而导致直到使软件更新后的电子控制单元正常启动为止花费时间的可能性
[0013]根据本公开的各方式,能够基于车载网络的通信状况来执行适应于单库存储器以及双库存储器的电子控制单元的软件更新(安装)。
Smart Images

Figure CN115509566B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to OTA managers, systems, methods, non-transitory storage media, and vehicles. Background Technology
[0002] The vehicle is equipped with multiple electronic control units (ECUs) for controlling the vehicle's movements. Each ECU has a processor, temporary storage such as RAM, and non-volatile storage such as flash ROM (non-volatile memory). The processor executes software stored in the non-volatile memory to implement the ECU's control functions. The software stored in each ECU can be rewritten; by updating to a newer version of the software, the functionality of each ECU can be improved, and new vehicle control functions can be added.
[0003] As a technology for updating the software of electronic control units (ECUs), OTA (Over-The-Air) technology is known: This involves wirelessly connecting an in-vehicle communication device connected to the vehicle network to a communication network such as the Internet. The device responsible for updating the vehicle's software downloads software from a server via wireless communication and installs the downloaded software into the ECU, thus updating or adding software to the ECU. For example, see Japanese Patent Application Laid-Open No. 2004-326689.
[0004] As a type of non-volatile memory integrated into electronic control units (ECUs), there are memory types with one storage area for storing data such as software (single-library memory) and memory types with two storage areas for storing data such as software (dual-library memory). The type used may vary depending on the specifications of the ECU. ECUs equipped with dual-library memory can store two versions of data, old and new, in two separate storage areas.
[0005] In vehicle software update events, there are two types of electronic control units (ECUs): one with a single-database memory and the other with a dual-database memory. The recovery methods for update failures differ between the ECUs with single and dual-database memories due to the different memory configurations.
[0006] Therefore, when applying software updates to vehicles that mix electronic control units (ECUs) with single-database memory and ECUs with dual-database memory, it is necessary to consider the different memory configurations of the ECUs being updated in order to appropriately perform the software update. Specifically, if software installation is performed that is incompatible with the communication status of the vehicle network connecting each ECU, there is a possibility that if the update fails due to the communication status of the vehicle network, the recovery methods for each ECU may result in a delay until the updated ECU starts normally. Summary of the Invention
[0007] The purpose of this disclosure is to provide an OTA manager, system, method, non-transitory storage medium, and vehicle capable of performing software updates adapted to electronic control units with single-library and dual-library memories.
[0008] The OTA manager according to the first aspect of the present invention includes: a communication unit configured to receive from a center first update data for a first electronic control unit equipped with a first type of non-volatile memory having one storage area, and second update data for a second electronic control unit equipped with a second type of non-volatile memory having two storage areas, wherein the first electronic control unit and the second electronic control unit are included in a plurality of electronic control units installed in a vehicle; and a control unit configured to control the software update of the plurality of target electronic control units based on the update data based on the communication status between the OTA manager and a plurality of target electronic control units whose software is to be updated, wherein the update data includes the second update data and the first update data.
[0009] The second aspect of the present invention relates to a system including an OTA manager and a center. The center includes a first communication unit configured to communicate with the OTA manager and send first update data to a first electronic control unit equipped with a first type of non-volatile memory having one storage area, and second update data to a second electronic control unit equipped with a second type of non-volatile memory having two storage areas to the OTA manager. The first and second electronic control units are included in a plurality of electronic control units installed in a vehicle. The OTA manager includes a second communication unit configured to receive the first and second update data sent by the center; and a control unit configured to control software updates of the plurality of target electronic control units based on update data, based on the communication status between the OTA manager and the plurality of target electronic control units whose software is to be updated. The update data includes the second and first update data.
[0010] The method involved in the third aspect of the present invention is executed by an OTA manager having one or more processors and one or more memories. The method includes: receiving from a center first update data for a first electronic control unit equipped with a first type of non-volatile memory having one storage area, and second update data for a second electronic control unit equipped with a second type of non-volatile memory having two storage areas, wherein the first and second electronic control units are included in a plurality of electronic control units installed in a vehicle; and controlling software updates of the plurality of target electronic control units based on the update data, based on the communication status between the OTA manager and the software of the plurality of electronic control units being updated, wherein the update data includes the second update data and the first update data.
[0011] The fourth aspect of the present invention relates to a non-transitory storage medium storing commands that can be executed by a computer having one or more processors and one or more memories, and that cause the computer to perform the method of the third aspect.
[0012] The vehicle involved in the fifth aspect of the present invention includes the OTA manager of the first aspect.
[0013] According to the various methods disclosed herein, software updates (installations) for electronic control units adapted to single-database and dual-database memory can be performed based on the communication status of the vehicle network. Attached Figure Description
[0014] Hereinafter, the features, advantages, technical and industrial importance of exemplary embodiments of the present invention will be described with reference to the accompanying drawings, in which the same reference numerals denote the same constituent elements, wherein:
[0015] Figure 1 It is a block diagram showing the overall structure of the network system involved in the implementation method.
[0016] Figure 2 It is a block diagram representing the simplified structure of the center.
[0017] Figure 3 This is the central functional block diagram.
[0018] Figure 4 This is a block diagram representing a simplified structure of the OTA manager.
[0019] Figure 5 This is a functional block diagram of the OTA Manager.
[0020] Figure 6A This is a block diagram illustrating a simplified structure of an electronic control unit.
[0021] Figure 6B This is a block diagram illustrating an example of a simplified structure of an electronic control unit.
[0022] Figure 7 This is a diagram representing an example of category information.
[0023] Figure 8 This is a flowchart example of the download processing steps performed by the center and OTA manager.
[0024] Figure 9 This is a flowchart example of the installation process steps performed by the OTA manager and the target electronic control unit.
[0025] Figure 10 This is a flowchart example of the activation process performed by the OTA manager and the target electronic control unit. Detailed Implementation
[0026] In the network system disclosed herein, the installation of update data appropriate to the memory type (single-library memory / dual-library memory) of the electronic control unit being updated is performed based on the communication status of the in-vehicle network connected to the electronic control unit. This process reduces the time spent until the software-updated electronic control unit can start normally.
[0027] Hereinafter, an embodiment of the present disclosure will be described in detail with reference to the accompanying drawings.
[0028] Implementation
[0029] structure
[0030] Figure 1 This is a block diagram illustrating the overall structure of a network system according to one embodiment of this disclosure. Figure 1 The network system shown is used to update the software of multiple electronic control units 40a to 40d installed in the vehicle, and has a center 10 located outside the vehicle and an in-vehicle network 20 built inside the vehicle.
[0031] (1) Center
[0032] The center 10 can communicate with the OTA manager 30 (described later) of the vehicle network 20 via the network 70. The center 10 can send software update data for the electronic control units 40a-40d and receive notifications indicating the progress of software update processing, and control and manage the software updates of multiple electronic control units 40a-40d connected to the OTA manager 30. The center 10 functions as a server.
[0033] Figure 2 It means Figure 1 A simplified block diagram of the structure of center 10. (See diagram below.) Figure 2 As shown, the center 10 includes a CPU (Central Processing Unit) 11, RAM (Random Access Memory) 12, a storage device 13, and a communication device 14. The number of each of these components is not limited to one. The storage device 13 is a device equipped with a read / write storage medium such as a hard disk drive (HDD) or a solid-state drive (SSD), storing programs used for software update management, information used in software update control and management, and software update data for each electronic control unit. In the center 10, the CPU 11 executes programs read from the storage device 13 using the RAM 12 as its working area to perform the prescribed processing related to software updates. The communication device 14 is a device for communicating with the OTA manager 30 via the network 70.
[0034] Figure 3 yes Figure 2 The functional block diagram of center 10 is shown. Figure 3 The center 10 shown includes a storage unit 16, a communication unit 17, and a control unit 18. The functions of the storage unit 16 are achieved through... Figure 2 The storage device 13 shown is used for implementation. The functions of the communication unit 17 and the control unit 18 are achieved through... Figure 2 The CPU 11 shown uses RAM 12 to execute programs stored in storage device 13.
[0035] The storage unit 16 stores information related to software update processing for one or more electronic control units (ECUs) installed in the vehicle. As information related to software update processing, the storage unit 16 stores at least update management information and software update data for ECUs 40a-40d that are associated with information indicating the software available in each ECU (Vehicle Identification Number) for the identified vehicle. For example, the information indicating the software available in ECUs 40a-40d can be a combination of the latest version information of each software in multiple ECUs 40a-40d. Furthermore, as information related to software update processing, the storage unit 16 can store update status indicating the update status of the software being implemented in the vehicle. Additionally, the storage unit 16 can store information related to the type of non-volatile memory installed in each of the multiple ECUs 40a-40d (described later).
[0036] The communication unit 17 functions as both a transmitter and a receiver for sending and receiving data, information, and requests between itself and the OTA manager 30. The communication unit 17 receives software update confirmation requests from the OTA manager 30 (receiving unit). An update confirmation request, for example, is information sent from the OTA manager 30 to the center 10 when the vehicle's power or ignition is turned on (hereinafter referred to as "power on"), and is used to request the center 10 to confirm the existence of update data for the electronic control units 40a to 40d based on the vehicle configuration information described later. Furthermore, in response to the update confirmation request received from the OTA manager 30, the communication unit 17 sends information indicating the presence or absence of update data to the OTA manager 30 (transmitting unit). Additionally, the communication unit 17 receives requests to send distribution data packets (download requests) from the OTA manager 30 (receiving unit). Furthermore, if the communication unit 17 receives a download request for a distribution data packet, it sends a distribution data packet containing update data for the software of the electronic control units 40a to 40d to the OTA manager 30.
[0037] If the communication unit 17 receives an update confirmation request from the OTA manager 30, the control unit 18 determines, based on the update management information stored in the storage unit 16, whether software update data exists for the electronic control units 40a-40d installed in the vehicle whose vehicle ID is included in the update confirmation request. The control unit 18 sends the result of its determination regarding the existence of update data to the OTA manager 30. If the control unit 18 determines that software update data for the electronic control units 40a-40d exists, and a download request for a data packet is received from the OTA manager 30, the control unit 18 controls the sending of the update data to the OTA manager 30.
[0038] (2) In-vehicle network
[0039] The vehicle network 20 includes an OTA manager 30, multiple electronic control units 40a-40d, and a communication module 50. The OTA manager 30 and the communication module 50 are connected via bus 60a. The OTA manager 30 is connected to electronic control units 40a and 40b via bus 60b. The OTA manager 30 is connected to electronic control units 40c and 40d via bus 60c.
[0040] The OTA manager 30 can wirelessly communicate with the center 10 via the bus 60a and the communication module 50 through the network 70. This OTA manager 30 is a device that manages the OTA status and controls the software update process, i.e., the update timing, to implement software updates for the electronic control units (hereinafter referred to as "target electronic control units") that are to be updated. The OTA manager 30 controls the software updates of the target electronic control units among the electronic control units 40a to 40d based on update data obtained from the center 10. The OTA manager 30 may also be referred to as a central gateway (CGW).
[0041] Figure 4 It means Figure 1 A simplified block diagram of the OTA Manager 30 in the system. (See diagram below.) Figure 4 As shown, the OTA manager 30 includes a CPU 31, RAM 32, ROM (Read-Only Memory) 33, a storage device 34, and a communication device 36. The CPU 31, RAM 32, ROM 33, and storage device 34 constitute a microcomputer 35. The number of microcomputers 35 is not limited to one. In the OTA manager 30, the CPU 31 uses RAM 32 as its working area to execute programs read from ROM 33 to perform the processing related to software updates. The communication device 36 is used for... Figure 1 The devices shown are for communicating with the bus 60a-60c, the communication module 50, and the electronic control units 40a-40d, respectively.
[0042] Figure 5 yes Figure 4 The diagram shown is a functional block diagram of OTA Manager 30. Figure 5 The OTA manager 30 shown includes a storage unit 37, a communication unit 38, and a control unit 39. The functions of the storage unit 37 are achieved through… Figure 4 The storage device 34 shown is used to implement this. The functions of the communication unit 38 and the control unit 39 are achieved through... Figure 4 The CPU 31 shown uses RAM 32 to execute programs stored in ROM 33.
[0043] In addition to storing the program (control program for OTA manager 30) used to perform software updates for the multiple electronic control units 40a-40d, and various data used during software updates, the storage unit 37 also stores software update data downloaded from the center 10. Furthermore, the storage unit 37 can store information (described later) related to the type of non-volatile memory mounted on each of the multiple electronic control units 40a-40d.
[0044] The communication unit 38 functions as both a transmitter and a receiver for sending and receiving data, information, and requests between itself and the center 10. For example, when the vehicle's power is turned on, the communication unit 38 sends a software update confirmation request to the center 10 (transmitter). The update confirmation request includes, for example, information related to the vehicle ID used to identify the vehicle and the current version of the software for the electronic control units 40a-40d connected to the vehicle network 20. The vehicle ID and the current version of the software for the electronic control units 40a-40d are used to determine whether update data for the software of the electronic control units 40a-40d exists by comparing it with the latest version of the software maintained by the center 10 for each vehicle ID. Additionally, the communication unit 38 receives a notification from the center 10 indicating the presence or absence of update data as a response to the update confirmation request (receiver). If update data for the software of the electronic control units 40a-40d exists, the communication unit 38 sends a request to download the software update data distribution data packet to the center 10 (transmitter) and receives (downloads) the distribution data packet sent from the center 10 (receiver). In addition, the communication unit 38 sends the update status of the software sent by the electronic control units 40a to 40d to the center 10 (sending unit).
[0045] The control unit 39 determines whether software update data for electronic control units 40a-40d exists based on the response from the center 10 to the update confirmation request received by the communication unit 38. Furthermore, the control unit 39 verifies the authenticity of the distribution data packets received (downloaded) from the center 10 and stored in the storage unit 37 by the communication unit 38. Additionally, the control unit 39 uses the update data received (downloaded) from the center 10 to control the software update process (various verifications, installations, activations, etc.) of the electronic control units 40a-40d. Specifically, the control unit 39 forwards one or more update data packets downloaded via distribution data packets to the target electronic control unit based on the communication status of the vehicle network 20, causing the target electronic control unit to install the update software based on the update data. After installation, the control unit 39 instructs the target electronic control unit to activate the installed update software. During this software update process, the control unit 39 appropriately controls the sequence of various verifications, installations, activations, etc., among the multiple electronic control units 40a-40d.
[0046] Multiple electronic control units (ECUs) 40a-40d are devices used to control the actions of various parts of the vehicle. Figure 1 The example shown is an in-vehicle network 20 with four electronic control units 40a to 40d, but the number of electronic control units is not particularly limited. For example, a display device (HMI) for various displays, such as displaying the presence of updated data during software update processing of the electronic control units 40a to 40d, displaying a consent request screen to the vehicle user or administrator requesting consent for the software update, and displaying the results of the software update, can be connected to the OTA manager 30. As a display device, a car navigation system can be used. Furthermore, the number of buses connecting the electronic control units to the OTA manager 30 is not particularly limited. For example, the aforementioned display device can be connected to the OTA manager 30 via a bus other than buses 60a to 60c.
[0047] An example of the simplified structure of the electronic control units 40a to 40d is as follows: Figure 6A as well as Figure 6B As shown.
[0048] Figure 6A The illustrated electronic control unit 40a includes a CPU 41, RAM 42, non-volatile memory 43a, and a communication device 44. The CPU 41 executes programs read from the non-volatile memory 43a using RAM 42 as its working area to implement the functions of the electronic control unit 40a. The non-volatile memory 43a is a memory with a single storage area 45 for storing data such as software (hereinafter referred to as "single-database memory"). Hereinafter, the type of memory with this single storage area 45 is referred to as "Category 1". In some cases, the storage area 45 stores not only the software used to implement the functions of the electronic control unit 40a, but also version information, parameter data, boot programs, software update programs, etc. The communication device 44 is a device for communicating with other electronic control units 40b to 40d connected to the OTA manager 30 and the vehicle network 20.
[0049] Figure 6BThe electronic control unit 40b shown, like the electronic control unit 40a, includes a CPU 41, RAM 42, non-volatile memory 43b, and a communication device 44. The non-volatile memory 43b mounted in the electronic control unit 40b is a memory with two storage areas 46a and 46b for storing software and other data (hereinafter referred to as "dual-library memory"). Hereinafter, this type of non-volatile memory 43b with the structure of two storage areas 46a and 46b is referred to as "Category 2". There are cases where storage areas 46a and 46b store not only the software used to implement the functions of the electronic control unit 40b, but also version information, parameter data, boot programs, software update programs, etc. The CPU 41 of the electronic control unit 40b uses either of the two storage areas 46a and 46b of the non-volatile memory 43b as the storage area to be read (the application area), and executes the software stored in that storage area. In a storage area other than the read object (non-application area), during the execution of the program in the storage area (application area) of the read object, the installation (writing) of the update software (updated version of the program) based on the updated data can be performed in the background. During the activation (validation of the update software) in the software update process, the update software can be activated by switching the storage area of the read object of the program using the CPU 41 of the electronic control unit 40b.
[0050] As a specific example, imagine a scenario where current software is stored in storage area 46a of the non-volatile memory 43b, which is a dual-library memory, and update software is installed in storage area 46b. If the OTA manager 30 instructs the activation of new software, then, for example, by switching the read start address of CPU 41 from the front address of storage area 46a to the front address of storage area 46b via the electronic control unit 40b, the storage area of the read target (application plane) of CPU 41 can be switched, and the update software installed in storage area 46b can be executed. Furthermore, in this disclosure, a structure called "single-sided suspended memory," which virtually divides one storage area into two planes and allows writing software (programs) stored in one plane to the other plane during execution, is also classified as a second type of memory.
[0051] Figure 7 This represents an example of category information, which relates to the category of non-volatile memory respectively mounted in multiple electronic control units 40a-40d. Figure 7In the example category information, the identifier of the electronic control unit (ECU_ID) is associated with the category (Category 1 (single library) / Category 2 (dual library)) of the non-volatile memory installed in that ECU. This category information is managed by storing it in either the storage unit 37 of the OTA manager 30 or the storage unit 16 of the center 10. Category information is pre-created based on the specifications of the electronic control units 40a-40d constituting the vehicle network 20. It can be stored in the storage unit 37 of the OTA manager 30 during vehicle manufacturing, or retrieved by the OTA manager 30 from the target ECU via communication within the vehicle network 20 during software update processing. Furthermore, when the category information is managed by the center 10, the OTA manager 30 can retrieve the category information from the center 10 via the network 70.
[0052] The communication module 50 is a unit that controls the communication between the center 10 and the vehicle, and is a communication device used to connect the vehicle network 20 to the center 10. The communication module 50 is wirelessly connected to the center 10 via the network 70 to perform vehicle authentication, download update data, and other functions related to the OTA manager 30. This communication module 50 can be configured to be included in the OTA manager 30.
[0053] Summary of software update processing
[0054] The OTA manager 30 sends a software update confirmation request to the center 10, for example, when the vehicle is powered on. The update confirmation request includes information related to the status (system configuration) of the electronic control units (ECUs) 40a-40d, such as the vehicle ID used to identify the vehicle and the current version of the hardware and software of the ECUs 40a-40d connected to the vehicle network 20; that is, vehicle configuration information. Vehicle configuration information can be created by obtaining the ECU identification number (ECU_ID) and the ECU software version identification number (ECU_Software_ID) from the ECUs 40a-40d connected to the vehicle network 20. The vehicle ID and the current version of the ECU software are used to determine whether update data for the ECUs 40a-40d exists by comparing it with the latest version of the software maintained by the center 10 for each vehicle ID. The center 10 sends a notification indicating the presence or absence of update data to the OTA manager 30 as a response to the update confirmation request received from the OTA manager 30. When update data for the software of electronic control units 40a-40d is available, the OTA manager 30 sends a download request for a distribution data packet to the center 10. The center 10, based on the download request received from the OTA manager 30, sends the update data distribution data packet to the OTA manager 30. The distribution data packet may include, in addition to the update data, verification data for verifying the authenticity of the update data, the quantity and category information of the update data, and various control information used during the software update.
[0055] The OTA manager 30 determines whether software update data for electronic control units 40a-40d exists based on the response to the update confirmation request received from the center 10. Additionally, the OTA manager 30 verifies the authenticity of the distribution data packets received from the center 10 and stored in the storage device 13. Furthermore, based on the communication status of the vehicle network 20, the OTA manager 30 forwards one or more update data downloaded using the distribution data packets to the target electronic control unit, causing the target electronic control unit to install the update data. After installation, the OTA manager 30 instructs the target electronic control unit to activate the installed updated software.
[0056] Furthermore, during the consent request processing, the OTA manager 30 outputs a notification to the output device that consent is required for a software update, or a notification urging consent to the software update. As the output device, a display device (not shown) for display-based notifications and a sound output device (not shown) for sound-based notifications, both installed in the vehicle network 20, can be used. For example, when using a display device as the output device in the consent request processing, the OTA manager 30 can display a consent request screen for requesting consent from the user or administrator for a software update, or display a notification urging the user or administrator to press the consent button, or other specific input operations. Additionally, during the consent request processing, the OTA manager 30 can display statements, icons, etc., indicating that software update data for electronic control units 40a-40d exists, or display limitations in the software update process. If the OTA manager 30 receives consent input from the user or administrator, it executes the aforementioned installation and activation control processing to update the software of the target electronic control unit.
[0057] Here, when the non-volatile memory of the target electronic control unit is a single-library memory, since installation and activation are performed continuously in principle, a request for consent to software updates is processed before installation. Furthermore, even for a target electronic control unit with a single-library memory, update processing may be temporarily suspended after installation is complete, i.e., a request for standby (delayed) activation is made. Additionally, when the non-volatile memory of the target electronic control unit is a dual-library memory, a request for consent to software updates is processed at least after installation and before activation. Furthermore, when the non-volatile memory of the target electronic control unit is a dual-library memory, the request for consent to software updates before installation may or may not be performed.
[0058] The software update process consists of three phases: the OTA manager 30 downloads update data from the center 10 (download phase); the OTA manager 30 transfers the downloaded update data to the target electronic control unit and installs the update software based on the update data in the storage area of the target electronic control unit (installation phase); and the target electronic control unit activates the installed update software (activation phase).
[0059] The download process involves the OTA manager 30 receiving update data from the center 10 for updating the software of the electronic control unit and storing it in the storage unit 37. During the download, update data for electronic control units equipped with dual-database memory and update data for electronic control units equipped with single-database memory are downloaded using prescribed distribution data packets. The download phase includes not only the execution of the download but also the control of a series of download-related processes, such as determining whether the download can be executed and verifying the update data.
[0060] The update data sent from center 10 to OTA manager 30 may include any of the following: electronic control unit update software (complete data or differential data), compressed data resulting from compressed update software, split update software, or split data of compressed data. Additionally, the update data may include the ECU_ID (or serial number) of the target electronic control unit and the ECU_Software_ID of the target electronic control unit before the update. The downloaded distribution data package may include update data for a single electronic control unit or update data for multiple electronic control units.
[0061] The installation process involves the OTA manager 30 writing the update software (updated program) to the non-volatile memories 43a and / or 43b of multiple target electronic control units (ECUs) in a predetermined order, based on the update data downloaded from the center 10 and according to the communication status of the vehicle network 20, i.e., the communication status between the OTA manager 30 and each target ECU. This writing process includes parallel execution of the transfer of update data to multiple target ECUs, and delaying the transfer of update data to target ECUs. Installation can be based solely on the communication status of the vehicle network 20, and can prioritize either update data for ECUs equipped with dual-library memory or update data for ECUs equipped with single-library memory, or perform them in a neutral manner. The installation phase includes not only the execution of the installation but also the control of a series of installation-related processes, such as determining whether the installation can be executed, transferring update data, and verifying the update software.
[0062] When the update data includes the update software itself (complete data), during the installation phase, the OTA manager 30 transfers the update data (update software) to the target electronic control unit (ECU) based on the communication status of the vehicle network 20. Alternatively, when the update data includes compressed, differential, or segmented data of the update software, the OTA manager 30 can transfer the update data to the target ECU based on the communication status of the vehicle network 20, and the target ECU can generate the update software based on the update data. Or, the OTA manager 30 can generate the update software based on the update data and then transfer the update software to the target ECU based on the communication status of the vehicle network 20. Here, the generation of the update software can be performed by decompressing compressed data or combining (integrating) differential or segmented data. Furthermore, the transfer of received (downloaded) update data from the OTA manager 30 to the target ECU, and the sending of the update software generated based on the received (downloaded) update data by the OTA manager 30 to the target ECU, can be simply referred to as the transfer of update data to the target ECU.
[0063] The installation of updated software can be performed by the target electronic control unit based on an installation request from the OTA manager 30. Furthermore, a specific target electronic control unit that receives the update data can also perform the installation autonomously without explicit instructions from the OTA manager 30.
[0064] Activation is the process by which the target electronic control unit (ECU) activates the update software installed in the non-volatile memory 43a and / or 43b. Activation can prioritize either update data for ECUs equipped with dual-library memory or update data for ECUs equipped with single-library memory, or it can proceed without preference between the two. The activation phase includes not only the execution of activation but also the control of a series of activation-related processes, such as determining whether activation is feasible, requesting the vehicle user or administrator's consent to activation, and verifying the execution result.
[0065] The activation of the updated software can be performed by the target electronic control unit based on an activation request from the OTA manager 30. Furthermore, a specific target electronic control unit that receives the update data can also activate itself after installation without explicit instructions from the OTA manager 30.
[0066] Among them, it is capable of performing software update processing on multiple target electronic control units, either continuously or in parallel.
[0067] In addition, the "software update processing" in this manual includes not only the entire process of continuous downloading, installation and activation, but also the process of only performing a part of the downloading, installation and activation.
[0068] deal with
[0069] Next, refer to Figure 8 , Figure 9 as well as Figure 10 Here are some specific examples related to software update processing performed in the network system described in this embodiment.
[0070] (1) Specific examples of downloading
[0071] Figure 8 This is a flowchart illustrating the processing steps involved in a specific example of downloading by the center 10 and the OTA manager 30. The download begins when the center 10 receives a download request for a distribution data packet from the OTA manager 30. Figure 8 The download process is illustrated.
[0072] (Step S801)
[0073] Center 10 sends a distribution data packet containing update data for the target electronic control unit (ECU) that is the object of the software update to OTA manager 30. This distribution data packet may contain a mixture of update data for ECUs equipped with Category 1 non-volatile memory (single-library memory) and update data for ECUs equipped with Category 2 non-volatile memory (dual-library memory). If the distribution data packet is sent, the process proceeds to step 802.
[0074] (Step S802)
[0075] OTA Manager 30 receives a distribution data packet sent from Center 10. If a distribution data packet is received, the process proceeds to step S803.
[0076] (Step S803)
[0077] The OTA manager 30 stores the update data included in the distribution data packet received from the center 10 in the storage unit 37. The download process then ends.
[0078] (2) Specific examples of installation
[0079] Figure 9 This is a flowchart illustrating the installation process for a specific example involving the OTA manager 30 and the target electronic control unit (hereinafter referred to as the "target ECU"). The process begins after the update data download is complete and the specified conditions are met (installation is executable, update data verification is successful, etc.). Figure 9 Specific examples of installation are shown.
[0080] (Step S901)
[0081] The OTA manager 30 confirms the communication status of the vehicle network 20. More specifically, the OTA manager 30 confirms the status of the communication lines connecting itself to each target ECU, namely buses 60b and 60c. If the communication status of the vehicle network 20 is confirmed, the process proceeds to step S902.
[0082] (Step S902)
[0083] The OTA manager 30 determines the communication load between itself and the target ECU. For example, if the communication load is less than a predetermined value, the OTA manager 30 determines it as low communication load; if the communication load is greater than the predetermined value, the OTA manager 30 determines it as high communication load. For example, the communication load may be high when the target ECU is performing an action, or even if the target ECU is not performing an action but the connected bus is congested. This predetermined value can be arbitrarily set based on the size of the update data, the communication environment installed in the vehicle (CAN (Controller Area Network), Ethernet, etc.), and the software update period. If the communication load between the OTA manager 30 and the target ECU is determined to be low (step S902, low), the process proceeds to step S903. Conversely, if the communication load between the OTA manager 30 and the target ECU is determined to be high (step S902, high), the process proceeds to step S904.
[0084] (Step S903)
[0085] If the communication load between the target ECU and itself is determined to be low, the OTA manager 30 performs the installation of the target ECU's update software by transferring update data to the target ECU. Hereinafter, such a target ECU will be referred to as the first target ECU. That is, it is determined that the communication load between the first target ECU and the OTA manager 30 is low. If there are multiple first target ECUs, the OTA manager 30 performs the installation of update software for multiple first target ECUs in parallel. If the installation of update software for the first target ECUs begins in parallel, the process proceeds to step S905.
[0086] (Step S904)
[0087] If the OTA manager 30 determines that the communication load between the target ECU and itself is high, it suspends the process of transferring update data to the target ECU to install the target ECU's update software. Hereinafter, such a target ECU will be referred to as the second target ECU. That is, it is determined that the communication load between the second target ECU and the OTA manager 30 is high. If there are multiple second target ECUs, the OTA manager 30 suspends the installation of update software for all of them. If the installation of update software for the second target ECU is suspended, the process proceeds to step S905.
[0088] (Step S905)
[0089] The OTA manager 30 determines whether the installation of the update software for all the first target ECUs is complete. If the installation of the update software for all the first target ECUs is complete (step S905, Yes), the process proceeds to step S906. On the other hand, if the installation of the update software for all the first target ECUs is incomplete (step S905, No), and there are target ECUs for which the update software installation has not yet been performed, the process proceeds to step S902.
[0090] (Step S906)
[0091] OTA Manager 30 performs the installation of the update software for the second target ECU, for which the update software installation was postponed. Once the installation of the update software for the second target ECU and the installation of update software for all target ECUs are complete, the installation process ends.
[0092] For all target ECUs that have not undergone software update installation, perform the installation process described in steps S902 to S906 above.
[0093] Based on the specific installation example described above, multiple parallel installations with high communication loads can be performed based on the communication status of the vehicle network 20 connecting the OTA manager 30 to each target ECU. This process achieves both control stability and efficient software update installation.
[0094] (3) Specific examples of activation
[0095] Figure 10This is a flowchart illustrating the processing steps involved in a specific example of activating the OTA manager 30 and the target ECU. The process begins after the installation of update software for both the target ECU equipped with Category 1 non-volatile memory (single-library memory) (hereinafter referred to as "Category 1 target ECU") and the target ECU equipped with Category 2 non-volatile memory (dual-library memory) (hereinafter referred to as "Category 2 target ECU") is completed and the specified conditions are met (activation can be performed, update data verification passed, etc.). Figure 10 The activation process is illustrated.
[0096] (Step S1001)
[0097] The OTA manager 30 and the target ECU of category 1 begin activating the update software that will be written to the storage area of the non-volatile memory of the target ECU of category 1. This activation begins simultaneously or in a predetermined order for all target ECUs of category 1. If the activation of the update software in the target ECU of category 1 begins, the process proceeds to step S1002.
[0098] (Step S1002)
[0099] The OTA manager 30 and the target ECU of category 2 begin activating the update software that will be written to the storage area of the non-volatile memory of the target ECU of category 2. This activation begins simultaneously or in a predetermined order for all target ECUs of category 2. Activation of the target ECUs of category 2 can begin after the activation of all target ECUs of category 1 is completed, or it can begin after the activation of a predetermined portion of the target ECUs of category 1 is completed. If the activation of the update software for the target ECUs of category 2 begins, the process proceeds to step S1003.
[0100] (Step S1003)
[0101] The OTA manager 30 determines whether the activation of the updated software in all target ECUs, including target ECUs of category 1 and target ECUs of category 2, is complete. The OTA manager 30 can determine completion by the presence of completion notifications from each target ECU, or by the elapsed time since the start of activation. The specified time can be set, for example, to a maximum time required for each activation. If the OTA manager 30 determines that the activation of the updated software in all target ECUs is complete (step S1003, Yes), then the activation process ends for the target ECUs.
[0102] Based on the specific example of activation described above, activation of the update software for the target ECU of category 1 begins first, followed by activation of the update software for the target ECU of category 2. Through this process, since the software update for the target ECU of category 2 can be implemented after the successful confirmation of the software update for the target ECU of category 1, it is appropriate to perform software update processing on systems comprising both target ECUs equipped with a single-library memory and target ECUs equipped with a dual-library memory.
[0103] Function / Effect
[0104] As described above, in a network system according to one embodiment of this disclosure, the OTA manager controls the update data transmitted to the target electronic control unit based on the communication status between the OTA manager and the target electronic control unit that is being updated.
[0105] This process enables the installation of appropriate software updates based on the communication status between the OTA manager and the target electronic control unit. Therefore, it reduces the time spent until the updated electronic control unit starts up normally.
[0106] More specifically, when the communication load between the OTA manager and the target electronic control unit (the first target electronic control unit) is less than a predetermined value, the OTA manager of this embodiment performs the transmission of update data to the target electronic control unit in parallel. When the communication load between the OTA manager and the target electronic control unit (the second target electronic control unit) is greater than or equal to a predetermined value, the OTA manager of this embodiment suspends the transmission of update data to the target electronic control unit.
[0107] This process allows for parallel processing of software updates for the target electronic control unit when the communication load between the OTA manager and the target electronic control unit is low. Conversely, when the communication load is high, the software update process for the target electronic control unit can be temporarily suspended to prioritize control stability.
[0108] In addition, if the communication load between one or more target electronic control units (the first target electronic control unit) and the OTA manager is less than a specified value and the communication load between other target electronic control units (the second target electronic control unit) and the OTA manager is greater than or equal to a specified value, the OTA manager according to this embodiment will perform the transmission of update data for the second target electronic control unit after all the transmission of update data for the first target electronic control unit is completed.
[0109] This process enables the stabilization of control and efficient installation by coordinating with the communication load within the vehicle (onboard network) related to software update control.
[0110] The above describes one embodiment of the technology disclosed herein. However, this disclosure can be understood not only as an OTA manager, but also as a method or program executed by an OTA manager having one or more processors and one or more memories, a computer-readable non-transitory storage medium storing a program, a system having a center and an OTA manager, or a vehicle having an OTA manager, etc.
[0111] The technology disclosed herein can be utilized in network systems used for updating the software of electronic control units.
Claims
1. An OTA manager, characterized in that, include: The communication unit is configured to receive, from a center, first update data for a first electronic control unit equipped with a first type of non-volatile memory having one storage area, and second update data for a second electronic control unit equipped with a second type of non-volatile memory having two storage areas, wherein the first electronic control unit and the second electronic control unit are included in a plurality of electronic control units mounted in the vehicle; and The control unit controls the software updates of the multiple target electronic control units based on update data, based on the communication status between the OTA manager and the multiple target electronic control units whose software is to be updated. The update data includes the second update data and the first update data. The software update includes the transmission of the update data to the target electronic control unit; The OTA manager performs the transmission of the update data in parallel with multiple first target electronic control units (ECUs), wherein the multiple first target ECUs are included within each other, and the communication load between the OTA manager and each of the multiple first target ECUs is less than a specified value. Furthermore, the transmission of the update data is temporarily suspended for one or more second target electronic control units, wherein the one or more second target electronic control units are included in the plurality of target electronic control units, and the communication load between the OTA manager and each of the one or more second target electronic control units is above a specified value. The control unit is configured to, after the transmission of update data for the plurality of first target electronic control units is completed, execute the transmission of update data for the one or more second target electronic control units. After the installation of the update software based on the update data is completed in all the target electronic control units, and after the activation of the update software of the target electronic control units equipped with the first type of non-volatile memory is completed, the activation of the update software of the target electronic control units equipped with the second type of non-volatile memory is completed.
2. A system, characterized in that, Including OTA Manager and Center, in, The center includes a first communication unit, which is configured as follows: The system communicates with the OTA manager and sends first update data to a first electronic control unit equipped with a first type of non-volatile memory having one storage area and second update data to a second electronic control unit equipped with a second type of non-volatile memory having two storage areas to the OTA manager. The first and second electronic control units are included in a plurality of electronic control units installed in the vehicle. The OTA manager has the following features: The second communication unit is configured to receive the first update data and the second update data sent by the center; and The control unit controls the software updates of the multiple target electronic control units based on update data, based on the communication status between the OTA manager and the multiple target electronic control units whose software is to be updated. The update data includes the second update data and the first update data. The software update includes the transfer of the update data to the target electronic control unit. The transmission of the update data is performed concurrently by a plurality of first target electronic control units, wherein the plurality of first target electronic control units are contained within a plurality of target electronic control units, and the communication load between the OTA manager and each of the plurality of first target electronic control units is less than a specified value. Furthermore, the transmission of the update data is temporarily suspended for one or more second target electronic control units, wherein the one or more second target electronic control units are included in the plurality of target electronic control units, and the communication load between the OTA manager and each of the one or more second target electronic control units is above a specified value. The control unit is configured to, after the transmission of update data for the plurality of first target electronic control units is completed, execute the transmission of update data for the one or more second target electronic control units. After the installation of the update software based on the update data is completed in all the target electronic control units, and after the activation of the update software of the target electronic control units equipped with the first type of non-volatile memory is completed, the activation of the update software of the target electronic control units equipped with the second type of non-volatile memory is completed.
3. A method executed by an OTA manager having one or more processors and one or more memories. The method is characterized by including: The system receives, from the center, first update data for a first electronic control unit equipped with a first type of non-volatile memory having one storage area, and second update data for a second electronic control unit equipped with a second type of non-volatile memory having two storage areas, wherein the first and second electronic control units are included in a plurality of electronic control units mounted in the vehicle; and The software updates of the multiple target electronic control units (ECUs) are controlled based on update data, according to the communication status between the OTA manager and the multiple ECUs whose software is to be updated. The update data includes the second update data and the first update data. The software update includes the transmission of the update data to the target electronic control unit; The OTA manager performs the transmission of the update data in parallel with multiple first target electronic control units (ECUs), wherein the multiple first target ECUs are included within each other, and the communication load between the OTA manager and each of the multiple first target ECUs is less than a specified value. Furthermore, the transmission of the update data is temporarily suspended for one or more second target electronic control units, wherein the one or more second target electronic control units are included in the plurality of target electronic control units, and the communication load between the OTA manager and each of the one or more second target electronic control units is above a specified value. After the transfer of the updated data for the plurality of first target electronic control units is completed, the transfer of the updated data for the one or more second target electronic control units is performed. After the installation of the update software based on the update data is completed in all the target electronic control units, and after the activation of the update software of the target electronic control units equipped with the first type of non-volatile memory is completed, the activation of the update software of the target electronic control units equipped with the second type of non-volatile memory is completed.
4. A non-transitory storage medium, characterized in that, The system stores commands that can be executed by a computer having one or more processors and one or more memories, and cause the computer to perform the method of claim 3.
5. A vehicle, characterized in that, Includes the OTA manager as described in claim 1.
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Vehicular master device, update data verification method, and update data verification program
CN112543914A
Risk based analysis of adverse event impact on system availability
US10747606B1
In-vehicle updating device, updating system, and update processing program
US20180373522A1