Ota manager, system, method, non-transitory storage medium, and vehicle
Patent Information
- Application Number
- CN202210528181.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-06-22
- Filing Date
- 2022-05-16
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2042-05-16
AI Technical Summary
[0006]因此,在将搭载有单库存储器的电子控制单元和搭载有双库存储器的电子控制单元作为成为更新对象的电子控制单元而混在一起的活动应用于车辆的情况下,若根据连接有电子控制单元的车载网络的通信状况而不执行软件更新(安装以及激活),则存在使软件更新后的电子控制单元正常启动为止花费时间的担忧
[0013]根据本公开的OTA管理器,能够基于车载网络的通信状况来执行适应于单库存储器以及双库存储器的电子控制单元的软件更新(安装以及激活)。
Smart Images

Figure CN115509568B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to OTA managers, systems, methods, non-transitory storage media, and vehicles. Background Technology
[0002] The vehicle is equipped with multiple electronic control units (ECUs) for controlling the vehicle's movements. Each ECU has a processor, temporary storage such as RAM, and non-volatile storage such as flash ROM (non-volatile memory). The processor executes software stored in the non-volatile memory to implement the ECU's control functions. The software stored in each ECU can be rewritten; by updating to a newer version of the software, the functionality of each ECU can be improved, and new vehicle control functions can be added.
[0003] As a technology for updating the software of electronic control units (ECUs), OTA (Over-The-Air) technology is known: This involves wirelessly connecting an in-vehicle communication device connected to the vehicle network to a communication network such as the Internet. The device responsible for updating the vehicle's software downloads software from a server via wireless communication and installs the downloaded software into the ECU, thus updating or adding software to the ECU. For example, see Japanese Patent Application Laid-Open No. 2004-326689.
[0004] As a type of non-volatile memory integrated into electronic control units (ECUs), there are memory types with one storage area for storing data such as software (single-library memory) and memory types with two storage areas for storing data such as software (dual-library memory). The type used may vary depending on the specifications of the ECU. ECUs equipped with dual-library memory can store two versions of data, old and new, in two separate storage areas.
[0005] In vehicle software update events, there are two types of electronic control units (ECUs): one with a single-database memory and the other with a dual-database memory. The recovery methods for update failures differ between the ECUs with single and dual-database memories due to the different memory configurations.
[0006] Therefore, when an activity involving both electronic control units (ECUs) with single-database memory and ECUs with dual-database memory are applied to a vehicle as ECUs to be updated, there is a concern that if a software update (installation and activation) is not performed based on the communication status of the vehicle network connected to the ECU, there will be a concern about the time required for the updated ECU to start normally. Summary of the Invention
[0007] This disclosure provides an OTA manager, system, method, non-transitory storage medium, and vehicle capable of performing software updates for electronic control units adapted to single-library and dual-library memory.
[0008] The OTA manager according to the first aspect of this disclosure includes: a communication unit configured to receive, from a center, update data for a first electronic control unit equipped with a first type of non-volatile memory having one storage area and update data for a second electronic control unit equipped with a second type of non-volatile memory having two storage areas, wherein the first electronic control unit and the second electronic control unit are included in a plurality of electronic control units mounted in the vehicle; and a control unit configured to control the software update of a plurality of target electronic control units that are the objects of software update among the plurality of electronic control units mounted in the vehicle based on the update data for the first type and the update data for the second type.
[0009] The second aspect of this disclosure relates to a system comprising a central hub and an OTA (Over-The-Air) manager. The central hub includes a first communication unit configured to communicate with the OTA manager and transmit update data for a first type of electronic control unit equipped with a first type of non-volatile memory having one storage area, and update data for a second type of electronic control unit equipped with a second type of non-volatile memory having two storage areas, to the OTA manager. The first and second electronic control units are included in a plurality of electronic control units mounted in the vehicle. The OTA manager includes a second communication unit configured to receive the update data for the first type and the update data for the second type transmitted by the central hub; and a control unit configured to control software updates for a plurality of target electronic control units among the plurality of electronic control units mounted in the vehicle, based on the update data for the first type and the update data for the second type.
[0010] The third aspect of this disclosure is a method executed by an OTA manager having one or more processors and one or more memories. The method includes: receiving from a center update data for a first type of electronic control unit equipped with a first type of non-volatile memory having one storage area, and update data for a second type of electronic control unit equipped with a second type of non-volatile memory having two storage areas, wherein the first and second electronic control units are included in a plurality of electronic control units mounted in a vehicle; and controlling the software update of a plurality of target electronic control units among the plurality of electronic control units mounted in the vehicle that are the objects of the software update, based on the first and second type of update data.
[0011] The fourth aspect of this disclosure is a non-transitory storage medium storing commands that can be executed by a computer having one or more processors and one or more memories, and cause the computer to perform the method of the third aspect.
[0012] The fifth method disclosed herein is a vehicle that includes the OTA manager of the first method.
[0013] According to the OTA manager disclosed herein, software updates (installation and activation) for electronic control units adapted to single- or dual-library memory can be performed based on the communication status of the vehicle network. Attached Figure Description
[0014] Hereinafter, the features, advantages, technical and industrial importance of exemplary embodiments of the present invention will be described with reference to the accompanying drawings, in which the same reference numerals denote the same constituent elements, wherein:
[0015] Figure 1 It is a block diagram showing the overall structure of the network system involved in the implementation method.
[0016] Figure 2 It is a block diagram representing the simplified structure of the center.
[0017] Figure 3 This is the central functional block diagram.
[0018] Figure 4 This is a block diagram representing the simplified structure of the OTA manager.
[0019] Figure 5 This is a functional block diagram of the OTA Manager.
[0020] Figure 6A This is a block diagram illustrating an example of a simplified structure of an electronic control unit.
[0021] Figure 6B This is a block diagram illustrating an example of a simplified structure of an electronic control unit.
[0022] Figure 7 This is a diagram representing an example of category information.
[0023] Figure 8 This is a flowchart illustrating the specific download processing steps involved in Example 1, performed by the center and the OTA manager.
[0024] Figure 9A This is a flowchart illustrating the installation and activation steps involved in Example 2, performed by the OTA manager and the target electronic control unit.
[0025] Figure 9B This is a flowchart illustrating the installation and activation steps involved in Example 2, performed by the OTA manager and the target electronic control unit.
[0026] Figure 10 This is a flowchart illustrating the installation and activation steps involved in Example 3, performed by the OTA manager and the target electronic control unit. Detailed Implementation
[0027] In the network system disclosed herein, the processing order for installing and activating update data for electronic control units (ECUs) downloaded from the center, specifically for update data for ECUs equipped with single-library memory and update data for ECUs equipped with dual-library memory, is controlled. This process enables software updates for ECUs adapted to the type of memory they are equipped with.
[0028] Hereinafter, an embodiment of the present disclosure will be described in detail with reference to the accompanying drawings.
[0029] Implementation
[0030] structure
[0031] Figure 1 This is a block diagram illustrating the overall structure of a network system according to one embodiment of this disclosure. Figure 1 The network system shown is used to update the software of multiple electronic control units 40a to 40d installed in the vehicle, and has a center 10 located outside the vehicle and an in-vehicle network 20 built inside the vehicle.
[0032] (1) Center
[0033] The center 10 can communicate with the OTA manager 30 (described later) of the vehicle network 20 via the network 70. The center 10 can send software update data for the electronic control units 40a-40d and receive notifications indicating the progress of software update processing, and control and manage the software updates of multiple electronic control units 40a-40d connected to the OTA manager 30. The center 10 functions as a server.
[0034] Figure 2 It means Figure 1 A simplified block diagram of the structure of center 10. (See diagram below.) Figure 2 As shown, the center 10 includes a CPU (Central Processing Unit) 11, RAM (Random Access Memory) 12, a storage device 13, and a communication device 14. The number of each of these components is not limited to one. The storage device 13 is a device equipped with a read / write storage medium such as a hard disk drive (HDD) or a solid-state drive (SSD), storing programs used for software update management, information used in software update control and management, and software update data for each electronic control unit. In the center 10, the CPU 11 executes programs read from the storage device 13 using the RAM 12 as its working area to perform the prescribed processing related to software updates. The communication device 14 is a device for communicating with the OTA manager 30 via the network 70.
[0035] Figure 3 yes Figure 2 The functional block diagram of center 10 is shown. Figure 3 The center 10 shown includes a storage unit 16, a communication unit 17, and a control unit 18. The functions of the storage unit 16 are achieved through... Figure 2 The storage device 13 shown is used to implement this. The functions of the communication unit 17 and the control unit 18 are achieved through... Figure 2 The CPU 11 shown uses RAM 12 to execute programs stored in storage device 13.
[0036] The storage unit 16 stores information related to software update processing for one or more electronic control units (ECUs) installed in the vehicle. As information related to software update processing, the storage unit 16 stores at least update management information and software update data for ECUs 40a-40d that are associated with information indicating the software available in each ECU (Vehicle Identification Number) for the identified vehicle. For example, the information indicating the software available in ECUs 40a-40d can be a combination of the latest version information of each software in multiple ECUs 40a-40d. Furthermore, as information related to software update processing, the storage unit 16 can store update status indicating the update status of the software being implemented in the vehicle. Additionally, the storage unit 16 can store information related to the type of non-volatile memory installed in each of the multiple ECUs 40a-40d (described later).
[0037] The communication unit 17 functions as both a transmitter and a receiver for sending and receiving data, information, and requests between itself and the OTA manager 30. The communication unit 17 receives software update confirmation requests from the OTA manager 30 (receiving unit). An update confirmation request, for example, is information sent from the OTA manager 30 to the center 10 when the vehicle's power or ignition is turned on (hereinafter referred to as "power on"), and is used to request the center 10 to confirm the existence of update data for the electronic control units 40a to 40d based on the vehicle configuration information described later. Furthermore, in response to the update confirmation request received from the OTA manager 30, the communication unit 17 sends information indicating the presence or absence of update data to the OTA manager 30 (transmitting unit). Additionally, the communication unit 17 receives requests to send distribution data packets (download requests) from the OTA manager 30 (receiving unit). Furthermore, if the communication unit 17 receives a download request for a distribution data packet, it sends a distribution data packet containing update data for the software of the electronic control units 40a to 40d to the OTA manager 30.
[0038] If the communication unit 17 receives an update confirmation request from the OTA manager 30, the control unit 18 determines, based on the update management information stored in the storage unit 16, whether software update data exists for the electronic control units 40a-40d installed in the vehicle whose vehicle ID is included in the update confirmation request. The control unit 18 sends the result of its determination regarding the existence of update data to the OTA manager 30. If the control unit 18 determines that software update data for the electronic control units 40a-40d exists, and a download request for a data packet is received from the OTA manager 30, the control unit 18 controls the sending of the update data to the OTA manager 30.
[0039] (2) In-vehicle network
[0040] The vehicle network 20 includes an OTA manager 30, multiple electronic control units 40a-40d, and a communication module 50. The OTA manager 30 and the communication module 50 are connected via bus 60a. The OTA manager 30 is connected to electronic control units 40a and 40b via bus 60b. The OTA manager 30 is connected to electronic control units 40c and 40d via bus 60c.
[0041] The OTA manager 30 can wirelessly communicate with the center 10 via the bus 60a and the communication module 50 through the network 70. This OTA manager 30 is a device that manages the OTA status and controls the software update process, i.e., the update timing, to implement software updates for the electronic control units (hereinafter referred to as "target electronic control units") that are to be updated. The OTA manager 30 controls the software updates of the target electronic control units among the electronic control units 40a to 40d based on update data obtained from the center 10. The OTA manager 30 may also be referred to as a central gateway (CGW).
[0042] Figure 4 It means Figure 1 A simplified block diagram of the OTA Manager 30 in the system. (See diagram below.) Figure 4 As shown, the OTA manager 30 includes a CPU 31, RAM 32, ROM (Read-Only Memory) 33, a storage device 34, and a communication device 36. The CPU 31, RAM 32, ROM 33, and storage device 34 constitute a microcomputer 35. The number of microcomputers 35 is not limited to one. In the OTA manager 30, the CPU 31 uses RAM 32 as its working area to execute programs read from ROM 33 to perform the processing related to software updates. The communication device 36 is used for... Figure 1 The devices shown are for communicating with the bus 60a-60c, the communication module 50, and the electronic control units 40a-40d, respectively.
[0043] Figure 5 yes Figure 4 The diagram shown is a functional block diagram of OTA Manager 30. Figure 5 The OTA manager 30 shown includes a storage unit 37, a communication unit 38, and a control unit 39. The functions of the storage unit 37 are achieved through… Figure 4 The storage device 34 shown is used to implement this. The functions of the communication unit 38 and the control unit 39 are achieved through... Figure 4 The CPU 31 shown uses RAM 32 to execute programs stored in ROM 33.
[0044] In addition to storing the program (control program for OTA manager 30) used to perform software updates for the multiple electronic control units 40a-40d, and various data used during software updates, the storage unit 37 also stores software update data downloaded from the center 10. Furthermore, the storage unit 37 can store information (described later) related to the type of non-volatile memory mounted on each of the multiple electronic control units 40a-40d.
[0045] The communication unit 38 functions as both a transmitter and a receiver for sending and receiving data, information, and requests between itself and the center 10. For example, when the vehicle's power is turned on, the communication unit 38 sends a software update confirmation request to the center 10 (transmitter). The update confirmation request includes, for example, information related to the vehicle ID used to identify the vehicle and the current version of the software for the electronic control units 40a-40d connected to the vehicle network 20. The vehicle ID and the current version of the software for the electronic control units 40a-40d are used to determine whether update data for the software of the electronic control units 40a-40d exists by comparing it with the latest version of the software maintained by the center 10 for each vehicle ID. Additionally, the communication unit 38 receives a notification from the center 10 indicating the presence or absence of update data as a response to the update confirmation request (receiver). If update data for the software of the electronic control units 40a-40d exists, the communication unit 38 sends a request to download the software update data distribution data packet to the center 10 (transmitter) and receives (downloads) the distribution data packet sent from the center 10 (receiver). In addition, the communication unit 38 sends the update status of the software sent by the electronic control units 40a to 40d to the center 10 (sending unit).
[0046] The control unit 39 determines whether software update data for the electronic control units 40a-40d exists based on the response from the center 10 to the update confirmation request received by the communication unit 38. Furthermore, the control unit 39 verifies the authenticity of the distribution data packets received (downloaded) from the center 10 and stored in the storage unit 37 by the communication unit 38. Additionally, the control unit 39 uses the update data received (downloaded) from the center 10 to control the software update process (various verifications, installations, activations, etc.) of the electronic control units 40a-40d. Specifically, the control unit 39 forwards one or more update data packets downloaded via the distribution data packets to the target electronic control unit in a predetermined order, causing the target electronic control unit to install the update software based on the update data. After installation, the control unit 39 instructs the target electronic control unit to activate the installed update software in a predetermined order. During this software update process, the control unit 39 appropriately controls the order of various verifications, installations, activations, etc., among the multiple electronic control units 40a-40d.
[0047] Multiple electronic control units (ECUs) 40a-40d are devices used to control the actions of various parts of the vehicle. Figure 1 The example shown is an in-vehicle network 20 with four electronic control units 40a to 40d, but the number of electronic control units is not particularly limited. For example, a display device (HMI) for various displays, such as displaying the presence of updated data during software update processing of the electronic control units 40a to 40d, displaying a consent request screen to the vehicle user or administrator requesting consent for the software update, and displaying the results of the software update, can be connected to the OTA manager 30. As a display device, a car navigation system can be used. Furthermore, the number of buses connecting the electronic control units to the OTA manager 30 is not particularly limited. For example, the aforementioned display device can be connected to the OTA manager 30 via a bus other than buses 60a to 60c.
[0048] An example of a simplified structure of the electronic control unit 40a-40d is as follows: Figure 6A as well as Figure 6B As shown.
[0049] Figure 6A The illustrated electronic control unit 40a includes a CPU 41, RAM 42, non-volatile memory 43a, and a communication device 44. The CPU 41 executes programs read from the non-volatile memory 43a using RAM 42 as its working area to implement the functions of the electronic control unit 40a. The non-volatile memory 43a is a memory with a single storage area 45 for storing data such as software (hereinafter referred to as "single-database memory"). Hereinafter, the type of memory with this single storage area 45 is referred to as "Category 1". In some cases, the storage area 45 stores not only the software used to implement the functions of the electronic control unit 40a, but also version information, parameter data, boot programs, software update programs, etc. The communication device 44 is a device for communicating with other electronic control units 40b to 40d connected to the OTA manager 30 and the vehicle network 20.
[0050] Figure 6BThe electronic control unit 40b shown, like the electronic control unit 40a, includes a CPU 41, RAM 42, non-volatile memory 43b, and a communication device 44. The non-volatile memory 43b mounted in the electronic control unit 40b is a memory with two storage areas 46a and 46b for storing software and other data (hereinafter referred to as "dual-library memory"). Hereinafter, this type of non-volatile memory 43b with the structure of two storage areas 46a and 46b is referred to as "Category 2". There are cases where storage areas 46a and 46b store not only the software used to implement the functions of the electronic control unit 40b, but also version information, parameter data, boot programs, software update programs, etc. The CPU 41 of the electronic control unit 40b uses either of the two storage areas 46a and 46b of the non-volatile memory 43b as the storage area to be read (the application area), and executes the software stored in that storage area. In a storage area other than the read object (non-application surface, write surface), during the execution of software (program) in the storage area (application surface) of the read object, the installation (writing) of updated software (updated version of the program) based on updated data can be performed in the background. During the activation (validation of the updated software) in the software update process, the updated software can be activated by switching the storage area of the read object of the program using the CPU 41 of the electronic control unit 40b.
[0051] As a specific example, imagine a scenario where current software is stored in storage area 46a of the non-volatile memory 43b, which is a dual-library memory, and update software is installed in storage area 46b. If the OTA manager 30 instructs the activation of new software, then, for example, by switching the read start address of CPU 41 from the front address of storage area 46a to the front address of storage area 46b via the electronic control unit 40b, the storage area of the read target (application surface) of CPU 41 can be switched, and the update software installed in storage area 46b can be executed. Furthermore, in this disclosure, a structure called "single-sided suspended memory," which virtually divides one storage area into two surfaces and enables the writing of software (programs) stored in one surface to the other surface during the execution of software (programs) stored in one surface, is also classified as a second category of non-volatile memory.
[0052] Figure 7 This represents an example of category information, which relates to the category of non-volatile memory respectively mounted in multiple electronic control units 40a-40d. Figure 7In the example category information, the identifier of the electronic control unit (ECU_ID) is associated with the category (Category 1 (single library) / Category 2 (dual library)) of the non-volatile memory installed in that ECU. This category information is managed by storing it in either the storage unit 37 of the OTA manager 30 or the storage unit 16 of the center 10. Category information is pre-created based on the specifications of the electronic control units 40a-40d constituting the vehicle network 20. It can be stored in the storage unit 37 of the OTA manager 30 during vehicle manufacturing, or retrieved by the OTA manager 30 from the target ECU via communication within the vehicle network 20 during software update processing. Furthermore, when the category information is managed by the center 10, the OTA manager 30 can retrieve the category information from the center 10 via the network 70.
[0053] The communication module 50 is a unit that controls the communication between the center 10 and the vehicle, and is a communication device used to connect the vehicle network 20 to the center 10. The communication module 50 is wirelessly connected to the center 10 via the network 70 to perform vehicle authentication, download update data, and other functions related to the OTA manager 30. This communication module 50 can be configured to be included in the OTA manager 30.
[0054] Summary of software update processing
[0055] The OTA manager 30 sends a software update confirmation request to the center 10, for example, when the vehicle is powered on. The update confirmation request includes information related to the status (system configuration) of the electronic control units (ECUs) 40a-40d, such as the vehicle ID used to identify the vehicle and the current version of the hardware and software of the ECUs 40a-40d connected to the vehicle network 20; that is, vehicle configuration information. Vehicle configuration information can be created by obtaining the ECU identification number (ECU_ID) and the ECU software version identification number (ECU_Software_ID) from the ECUs 40a-40d connected to the vehicle network 20. The vehicle ID and the current version of the ECU software are used to determine whether update data for the ECUs 40a-40d exists by comparing it with the latest version of the software maintained by the center 10 for each vehicle ID. The center 10 sends a notification indicating the presence or absence of update data to the OTA manager 30 as a response to the update confirmation request received from the OTA manager 30. When update data for the software of electronic control units 40a-40d is available, the OTA manager 30 sends a download request for a distribution data packet to the center 10. The center 10, based on the download request received from the OTA manager 30, sends the update data distribution data packet to the OTA manager 30. The distribution data packet may include, in addition to the update data, verification data for verifying the authenticity of the update data, the quantity and category information of the update data, and various control information used during the software update.
[0056] The OTA manager 30 determines whether software update data for electronic control units 40a-40d exists based on the response to the update confirmation request received from the center 10. Additionally, the OTA manager 30 verifies the authenticity of the distribution data packets received from the center 10 and stored in the storage device 13. Furthermore, the OTA manager 30 forwards one or more update data packets downloaded using the distribution data packets to the target electronic control unit in a predetermined order, causing the target electronic control unit to install the update data. After installation, the OTA manager 30 instructs the target electronic control unit to activate the installed updated software in a predetermined order.
[0057] Furthermore, during the consent request processing, the OTA manager 30 outputs a notification to the output device that consent is required for a software update, or a notification urging consent to the software update. As the output device, a display device (not shown) for display-based notifications and a sound output device (not shown) for sound-based notifications, both installed in the vehicle network 20, can be used. For example, when using a display device as the output device in the consent request processing, the OTA manager 30 can display a consent request screen for requesting consent from the user or administrator for a software update, or display a notification urging the user or administrator to press the consent button, or other specific input operations. Additionally, during the consent request processing, the OTA manager 30 can display statements, icons, etc., indicating that software update data for electronic control units 40a-40d exists, or display limitations in the software update process. If the OTA manager 30 receives consent input from the user or administrator, it executes the aforementioned installation and activation control processing to update the software of the target electronic control unit.
[0058] Here, when the target electronic control unit is installed and activated continuously, a request for consent to the software update is processed before the installation is performed. When the target electronic control unit is installed and activated discontinuously, a request for consent to the software update is processed at least after the installation is performed and before the activation is performed.
[0059] The software update process consists of three phases: the OTA manager 30 downloads update data from the center 10 (download phase); the OTA manager 30 transfers the downloaded update data to the target electronic control unit and installs the update software based on the update data in the storage area of the target electronic control unit (installation phase); and the target electronic control unit activates the installed update software (activation phase).
[0060] The download process involves the OTA manager 30 receiving update data from the center 10 for updating the software of the electronic control unit and storing it in the storage unit 37. During the download, update data for electronic control units equipped with dual-database memory and update data for electronic control units equipped with single-database memory are downloaded using prescribed distribution data packets. The download phase includes not only the execution of the download but also the control of a series of download-related processes, such as determining whether the download can be executed and verifying the update data.
[0061] The update data sent from center 10 to OTA manager 30 may include any of the following: electronic control unit update software (complete data or differential data), compressed data resulting from compressed update software, split update software, or split data of compressed data. Additionally, the update data may include the ECU_ID (or serial number) of the target electronic control unit and the ECU_Software_ID of the target electronic control unit before the update. The downloaded distribution data package may include update data for a single electronic control unit or update data for multiple electronic control units.
[0062] The installation process involves the OTA manager 30 writing the updated software (updated program) to the non-volatile memories 43a and / or 43b of multiple target electronic control units (ECUs) in a predetermined order, based on the update data downloaded from the center 10. The installation is controlled based on whether the update data is intended for ECUs equipped with dual-library memories or single-library memories. The installation phase includes not only the execution of the installation but also the control of a series of installation-related processes, such as determining whether the installation can be executed, transferring the update data, and verifying the update software.
[0063] When the update data includes the update software itself (complete data), the OTA manager 30 transfers the update data (update software) to the target electronic control unit (ECU) during the installation phase. Alternatively, when the update data includes compressed, differential, or segmented data of the update software, the OTA manager 30 may transfer the update data to the target ECU, which then generates the update software based on the update data. Or, the OTA manager 30 may generate the update software based on the update data and then transfer the update software to the target ECU. Here, the generation of the update software can be performed by decompressing compressed data or combining (integrating) differential or segmented data. These processes are also referred to simply as the transfer of update data relative to the target ECU.
[0064] The installation of updated software can be performed by the target electronic control unit based on an installation request from the OTA manager 30. Furthermore, a specific target electronic control unit that receives the update data can also perform the installation autonomously without explicit instructions from the OTA manager 30.
[0065] Activation is the process by which the target electronic control unit (ECU) validates (activates) the updated software installed in non-volatile memory 43a and / or 43b. Activation is controlled based on whether the updated data is intended for an ECU with dual-database memory or an ECU with single-database memory. The activation phase includes not only the execution of activation but also the control of a series of activation-related processes, such as determining whether activation is feasible, requesting the vehicle user's or manager's consent to activation, and verifying the execution result.
[0066] The activation of the updated software can be performed by the target electronic control unit based on an activation request from the OTA manager 30. Furthermore, a specific target electronic control unit that receives the update data can also activate itself after installation without explicit instructions from the OTA manager 30.
[0067] Among them, it is capable of performing software update processing on multiple target electronic control units, either continuously or in parallel.
[0068] In addition, the "software update processing" in this manual includes not only the entire process of continuous downloading, installation and activation, but also the process of only a part of the downloading, installation and activation.
[0069] deal with
[0070] Next, refer to Figure 8 , Figure 9A , Figure 9B as well as Figure 10 Here are some specific examples related to software update processing performed in the network system described in this embodiment.
[0071] (1) Specific example of downloading 1
[0072] Figure 8 This is a flowchart illustrating the processing steps involved in Example 1 of the download performed by the center 10 and the OTA manager 30. The download begins when the center 10 receives a download request for a distribution data packet from the OTA manager 30. Figure 8 Specific example 1 of downloading is shown.
[0073] (Step S801)
[0074] Center 10 sends a distribution data packet containing update data for the target electronic control unit (ECU) that is the object of the software update to OTA manager 30. This distribution data packet may contain a mixture of update data for ECUs equipped with Category 1 non-volatile memory (single-library memory) and update data for ECUs equipped with Category 2 non-volatile memory (dual-library memory). If the distribution data packet is sent, the process proceeds to step 802.
[0075] (Step S802)
[0076] OTA Manager 30 receives a distribution data packet sent from Center 10. If a distribution data packet is received, the process proceeds to step S803.
[0077] (Step S803)
[0078] The OTA manager 30 stores the update data included in the distribution data packet received from the center 10 in the storage unit 37. Thus, the download process ends.
[0079] (2) Specific example of installation and activation 2
[0080] Figure 9A as well as Figure 9B This is a flowchart illustrating the installation and activation process steps involved in Example 2 concerning the OTA manager 30 and the target electronic control unit (hereinafter referred to as the "target ECU"). Figure 9A processing and Figure 9B The processing is linked via the X connector. It begins after the update data download is complete and certain conditions are met (installation is executable, update data verification is successful, etc.). Figure 9A as well as Figure 9B Example 2 illustrates the installation and activation process.
[0081] (Step S901)
[0082] The OTA manager 30 obtains the memory category (Category 1 / Category 2) of the non-volatile memory installed in the target ECU. If the memory category is managed by the OTA manager 30, it can be obtained by referring to the category information stored in the storage unit 37; or if the memory category is managed by the center 10, it can be obtained by referring to the memory category information included in the distribution data packet. If the memory category of the target ECU is obtained, the process proceeds to step S902.
[0083] (Step S902)
[0084] OTA Manager 30 performs installation, which involves transferring update data (update data for Category 2) to the target ECU of Category 2 equipped with Category 2 non-volatile memory (dual-library memory) and writing update software to the ECU's storage area (first process). This installation is performed sequentially and / or concurrently for all target ECUs of Category 2. Once installation for all target ECUs of Category 2 is complete, the process proceeds to step S903.
[0085] (Step S903)
[0086] OTA Manager 30 performs installation, which involves transferring update data (update data for Category 1) to the target ECU of Category 1 equipped with Category 1 non-volatile memory (single-library memory) and writing update software to the ECU's storage area (second process). This installation is performed sequentially and / or concurrently for all target ECUs of Category 1. Once installation for all target ECUs of Category 1 is complete, the process proceeds to step S904.
[0087] (Step S904)
[0088] The OTA manager 30 and the target ECU of category 1 perform activation (second process) to validate the update software already written to the storage area of the non-volatile memory of the target ECU of category 1. This activation is performed simultaneously or in a prescribed order for all target ECUs of category 1 that have completed installation. Furthermore, if performed in a prescribed order, activation can be performed sequentially starting from the target ECUs of category 1 that have completed installation without waiting for all target ECUs of category 1 to complete installation. If the activation of the update software in the target ECUs of category 1 is complete, the process proceeds to step S905.
[0089] (Step S905)
[0090] The OTA manager 30 and the target ECU of category 2 perform activation (third process) to validate the update software already written to the storage area of the non-volatile memory of the target ECU of category 2. This activation is performed simultaneously or in a prescribed order for all target ECUs of category 2 that have completed installation. If the activation of the update software in the target ECU of category 2 is completed, the installation and activation process ends.
[0091] According to the specific example 2 of installation and activation described above, the installation of the second category target ECU, which has a lower failure probability of being updated, is performed first, and the activation of the second category target ECU is performed after the installation and activation of the first category target ECU. Therefore, since the second category target ECU can be activated and started after the first category target ECU has been successfully updated, the time until the software update is completed can be shortened. The installation and activation order of the target ECUs based on the memory categories described above can be stored in the storage unit 37 of the OTA manager 30, or can be obtained by the OTA manager 30 from the center 10 (e.g., by transmission included in the distribution data packet). (3) Specific example 3 of installation and activation
[0092] Figure 10This is a flowchart illustrating the installation and activation steps involved in Example 3 for the OTA Manager 30 and the target ECU. The process begins after the update data download is complete and the specified conditions are met (installation is executable, update data verification is successful, etc.). Figure 10 Example 3 illustrates the installation and activation process.
[0093] (Step S1001)
[0094] The OTA manager 30 obtains the memory category (Category 1 / Category 2) of the non-volatile memory installed in the target ECU. If the memory category is managed by the OTA manager 30, it can be obtained by referring to the category information stored in the storage unit 37; or if the memory category is managed by the center 10, it can be obtained by referring to the memory category information included in the distribution data packet. If the memory category of the target ECU is obtained, the process proceeds to step S1002.
[0095] (Step S1002)
[0096] OTA Manager 30 performs the installation, which involves transferring update data (update data for Category 2) to the target ECU of Category 2 and writing the update software to the ECU's storage area (first process). This installation is performed sequentially and / or concurrently for all target ECUs of Category 2. Once the installation for all target ECUs of Category 2 is complete, the process proceeds to step S1003.
[0097] (Step S1003)
[0098] The OTA manager 30 and the target ECU of category 2 perform activation (first process) to validate the update software already written to the storage area of the non-volatile memory of the target ECU of category 2. This activation is performed simultaneously or in a predetermined order for all target ECUs of category 2 that have completed installation. In the case of performing in a predetermined order, activation can be performed sequentially starting from the target ECUs of category 2 that have completed installation without waiting for all target ECUs of category 2 to complete installation. If the activation of the update software in the target ECU of category 2 is completed, the process proceeds to step S1004.
[0099] (Step S1004)
[0100] OTA Manager 30 performs the installation, which involves transferring update data (update data for Category 1) to the target ECU of Category 1 and writing the update software to the ECU's storage area (second process). This installation is performed sequentially and / or concurrently for all target ECUs of Category 1. Once the installation for all target ECUs of Category 1 is complete, the process proceeds to step S1005.
[0101] (Step S1005)
[0102] The OTA manager 30 and the target ECU of category 1 perform activation (second process) to validate the update software already written to the storage area of the non-volatile memory of the target ECU of category 1. This activation is performed simultaneously or in a prescribed order for all target ECUs of category 1 that have completed installation. In the case of performing the activation in a prescribed order, activation can be performed sequentially starting from the target ECUs of category 1 that have completed installation without waiting for all target ECUs of category 1 to complete installation. Once the activation of the update software in the target ECUs of category 1 is complete, the installation and activation process ends.
[0103] In cases where it is preferable to perform the installation and activation of the second category of target ECUs before the installation and activation of the first category of target ECUs in order to shorten the time until the software update is completed, the specific example 3 of the installation and activation described above is particularly useful. The order of installation and activation of target ECUs based on the memory categories described above can be stored in the storage unit 37 of the OTA manager 30, or can be obtained by the OTA manager 30 from the center 10 (e.g., by transmission included in the distribution data packet).
[0104] In the specific example 3 of this installation and activation, the target ECU of category 2 starts before the target ECU of category 1. Therefore, if it is desired to start the target ECU of category 1 and the target ECU of category 2 simultaneously (to achieve control synchronization), it is sufficient to temporarily put the target ECU of category 2 into standby mode (by setting a stop flag) after the first process is completed.
[0105] Function / Effect
[0106] As described above, according to one embodiment of the network system disclosed herein, the OTA manager suitably controls the installation and activation (method) of update data for electronic control units equipped with single-library memory (a type 1 non-volatile memory) and update data for electronic control units equipped with dual-library memory (a type 2 non-volatile memory).
[0107] Specifically, in this embodiment, the OTA manager first performs the installation of target electronic control units equipped with dual-library memory, which has a lower probability of update failure. The activation of target electronic control units equipped with dual-library memory is performed later than the installation and activation of target electronic control units equipped with single-library memory.
[0108] This process shortens the time until the software update is complete, even if the installation and activation of the target electronic control unit equipped with a single-library memory fails. After the target electronic control unit equipped with a single-library memory confirms the final success, the installed target electronic control unit equipped with a dual-library memory will be activated and started.
[0109] Alternatively, the OTA manager described in this embodiment may perform the installation and activation of a target electronic control unit equipped with a single-library memory after performing the installation and activation of the target electronic control unit equipped with a dual-library memory.
[0110] This process makes it possible to shorten the time until the software update is complete, especially if it is better to perform the installation and activation of the target ECU of category 2 before the installation and activation of the target ECU of category 1 in order to shorten the time until the software update is completed.
[0111] The above describes one embodiment of the technology disclosed herein. However, this disclosure can be understood not only as an OTA manager, but also as a method or program executed by an OTA manager having one or more processors and one or more memories, a computer-readable non-transitory storage medium storing a program, a system having a center and an OTA manager, or a vehicle having an OTA manager, etc.
[0112] The technology disclosed herein can be utilized in network systems used for updating the software of electronic control units.
Claims
1. An OTA manager, characterized in that, include: The communication unit is configured to receive, from a center, update data for a first category of electronic control unit equipped with a first category of non-volatile memory having one storage area, and update data for a second category of electronic control unit equipped with a second category of non-volatile memory having two storage areas, wherein the first electronic control unit and the second electronic control unit are included in a plurality of electronic control units mounted in the vehicle; and The control unit is configured to control the software updates of multiple target electronic control units (ECUs) that are subject to software updates, based on the first category of update data and the second category of update data, in a predetermined order. The software update for the plurality of target electronic control units includes: The second electronic control unit performs the transmission and activation of the second category of updated data; After the transmission and activation of the updated data for the second category are performed, the updated data for the first category are also transmitted and activated for the first electronic control unit; and After the transmission and validation of the updated data in the second category are completed, a command for setting a stop flag is sent to the second electronic control unit. The stop flag enables both the first and second electronic control units to start simultaneously by temporarily suspending the second electronic control unit before the transmission and validation of the updated data in the first category are completed.
2. A system, characterized in that, include: center; and OTA Manager in, The center includes a first communication unit, which is configured as follows: Communicate with the OTA manager, The system sends update data for the first category of electronic control units equipped with a first category of non-volatile memory having one storage area, and update data for the second category of electronic control units equipped with a second category of non-volatile memory having two storage areas, to the OTA manager. The first and second electronic control units are included in a plurality of electronic control units installed in the vehicle. The OTA manager has the following features: The second communication unit is configured to receive the first type of update data and the second type of update data transmitted from the center; and The control unit is configured to control the software updates of multiple target electronic control units (ECUs) that are subject to software updates, based on the first category of update data and the second category of update data, in a predetermined order. The software update for the plurality of target electronic control units includes: The second electronic control unit performs the transmission and activation of the second category of updated data; After the transmission and activation of the updated data for the second category are performed, the updated data for the first category are also transmitted and activated for the first electronic control unit; and After the transmission and validation of the updated data in the second category are completed, a command for setting a stop flag is sent to the second electronic control unit. The stop flag enables both the first and second electronic control units to start simultaneously by temporarily suspending the second electronic control unit before the transmission and validation of the updated data in the first category are completed.
3. One method, executed by the OTA manager, The method is characterized by including: The system receives, from the center, update data for a first-category electronic control unit equipped with a first-category non-volatile memory having one storage area, and update data for a second-category electronic control unit equipped with a second-category non-volatile memory having two storage areas, wherein the first and second electronic control units are included in a plurality of electronic control units mounted in the vehicle; and Based on the first category of update data and the second category of update data, control is performed in a predetermined order to update the software of multiple target electronic control units (ECUs) that are the objects of software updates within the plurality of ECUs installed in the vehicle. The software update for the plurality of target electronic control units includes: The second electronic control unit performs the transmission and activation of the second category of updated data; After the transmission and activation of the updated data for the second category are performed, the updated data for the first category are also transmitted and activated for the first electronic control unit; and After the transmission and validation of the updated data in the second category are completed, a command for setting a stop flag is sent to the second electronic control unit. The stop flag enables both the first and second electronic control units to start simultaneously by temporarily suspending the second electronic control unit before the transmission and validation of the updated data in the first category are completed.
4. A non-transitory storage medium, characterized in that, The non-transitory storage medium stores commands that can be executed by the computer of the OTA manager and cause the computer to perform the method of claim 3.
5. A vehicle, characterized in that, Includes the OTA manager as described in claim 1.
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Vehicle electronic control system, vehicle master device, rewriting instruction method by specific mode, and rewriting instruction program by specific mode
WO2021039796A1