Center, OTA manager, method, non-transitory storage medium, and vehicle
By designing a distribution data packet generation method that is compatible with wired and wireless communications, the problem of inefficient data packet generation in electronic control unit software updates is solved, and more efficient software update management is achieved.
Patent Information
- Application Number
- CN202210518956.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-06-22
- Filing Date
- 2022-05-13
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2042-05-13
AI Technical Summary
In the existing technology, when updating software of an electronic control unit, it is necessary to create distribution data packets in wired and wireless communication modes respectively, resulting in inefficient generation and management processes.
A center and OTA manager are designed to generate distribution data packets compatible with wired and wireless communication methods. The identification information determines the type of information that external devices and OTA managers should refer to, thus achieving unified data packet generation and management.
Through a unified distribution data packet generation method, the efficiency of software updates is improved, the redundancy of data packet generation is reduced, and the efficiency of the update process is improved.
Smart Images

Figure CN115514743B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a center, an OTA manager, a method, a non-transitory storage medium, and a vehicle that control updating of software of an electronic control unit. Background Art
[0002] Vehicles are equipped with multiple electronic control units (ECUs) for controlling vehicle operations. Each ECU includes a processor, temporary storage such as RAM, and nonvolatile storage such as flash ROM, also known as nonvolatile memory. The processor executes software stored in the nonvolatile memory to implement the ECU's control functions. The software stored in each ECU is rewritable. By updating to a newer version of software, the functionality of each ECU can be improved and new vehicle control functions can be added.
[0003] At a vehicle dealership or the like, the ECU software can be updated or added by connecting an external device such as a diagnostic tool to the in-vehicle network connected to the ECU via a wired connection and installing update software previously stored in the external device into the ECU.
[0004] OTA (Over the Air) technology is also known as a technique for updating software in electronic control units. In OTA technology, a device responsible for updating vehicle software wirelessly connects an on-board communication device connected to an on-board network to a communication network such as the Internet. The software update device downloads software from a server via wireless communication and installs the downloaded software in the electronic control unit, thereby updating or adding software to the electronic control unit. For example, see Japanese Patent Application Laid-Open No. 2004-326689.
[0005] When updating ECU software using an external device connected to the vehicle network via a wired connection, the communication methods and required conditions differ from those when updating ECU software using OTA technology (wireless connection to the vehicle network). Therefore, when updating ECU software, two distribution data packages must be created: one containing the data and information required for the wired software update, and one containing the data and information required for the OTA software update. Summary of the Invention
[0006] The present disclosure provides a center, an OTA manager, a method, a non-transitory storage medium, and a vehicle capable of efficiently generating a distribution data packet.
[0007] The first mode of the disclosed technology is a center configured to communicate with an OTA manager configured to control software updates of electronic control units mounted on vehicles. The center includes a control unit and a communication unit. The control unit is configured to generate a distribution data packet including update data of the software of a target electronic control unit, first information, and second information. The target electronic control unit is the electronic control unit that is the object of the update. When an external device connected to the vehicle by wire performs a software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device. When the OTA manager connected to the center wirelessly performs a software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager. The communication unit is configured to send the distribution data packet to the OTA manager based on a request from the OTA manager.
[0008] In the center according to the first aspect of the presently disclosed technology, the distribution packet may further include identification information for identifying which of the first information and the second information the external device and the OTA manager should refer to.
[0009] The second mode of the disclosed technology is an OTA manager configured to control the software update of an electronic control unit mounted on a vehicle. The OTA manager includes a communication unit and a control unit. The communication unit is configured to receive a distribution data packet including update data of the software of a target electronic control unit, first information, and second information from a center. The target electronic control unit is the electronic control unit that is the object of the update. When an external device connected to the vehicle by wire performs a software update of the target electronic control unit via the vehicle network, the first information is referenced by the external device. When the OTA manager connected to the center wirelessly performs a software update of the target electronic control unit via the vehicle network, the second information is referenced by the OTA manager. The control unit is configured to control the software update of the target electronic control unit based on the update data and the second information.
[0010] In the OTA manager according to the second aspect of the present disclosure, the distribution packet may further include identification information indicating which of the first information and the second information the external device and the OTA manager should refer to. The control unit may determine the second information based on the identification information.
[0011] A third embodiment of the disclosed technology is a method executed by a center configured to communicate with an OTA manager configured to control software updates of electronic control units mounted on a vehicle. The OTA manager includes a memory and one or more processors. The method includes processing for generating a distribution data packet including update data of the software of a target electronic control unit, first information, and second information. The target electronic control unit is the electronic control unit that is the object of the update. When an external device connected to the vehicle by wire performs a software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device. When the OTA manager connected to the center wirelessly performs a software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager. The method includes processing for sending the distribution data packet to the OTA manager based on a request from the OTA manager.
[0012] The fourth mode of the disclosed technology is a method executed by an OTA manager, which is configured to control the software update of an electronic control unit installed in a vehicle. The above-mentioned OTA manager has a memory and one or more processors. The above-mentioned method has a process of receiving a distribution data packet including update data of the software of the target electronic control unit, the first information and the second information from the above-mentioned center. The above-mentioned target electronic control unit is the above-mentioned electronic control unit that becomes the update object. When an external device connected to the vehicle by wire performs the software update of the above-mentioned target electronic control unit via the vehicle network, the above-mentioned first information is referenced by the above-mentioned external device. When the above-mentioned OTA manager connected to the above-mentioned center wirelessly performs the software update of the above-mentioned target electronic control unit via the above-mentioned vehicle network, the above-mentioned second information is referenced by the above-mentioned OTA manager. The above-mentioned method has a process of controlling the software update of the above-mentioned target electronic control unit based on the above-mentioned update data and the above-mentioned second information.
[0013] The fifth mode of the disclosed technology is a non-transitory storage medium storing commands that can be executed by computers at one or more centers and cause the computers at the one or more centers to perform the following functions. The center is configured to communicate with an OTA manager, which is configured to control the software update of an electronic control unit mounted on a vehicle. The OTA manager includes a memory and one or more processors. The function includes processing for generating a distribution data packet including update data of the software of a target electronic control unit, first information, and second information. The target electronic control unit is the electronic control unit to be updated. When an external device connected to the vehicle by wire performs a software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device. When the OTA manager connected to the center wirelessly performs a software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager. The function includes processing for sending the distribution data packet to the OTA manager based on a request from the OTA manager.
[0014] The sixth mode of the disclosed technology is a non-transitory storage medium storing commands that can be executed by one or more OTA manager computers and cause the one or more OTA manager computers to perform the following functions. The OTA manager is configured to control the software update of the electronic control unit installed in the vehicle. The OTA manager has a memory and one or more processors. The function includes processing for receiving a distribution data packet including update data of the target electronic control unit's software, first information, and second information from a center. The target electronic control unit is the electronic control unit that becomes the update object. When an external device connected to the vehicle by wire performs a software update of the target electronic control unit via the vehicle network, the first information is referenced by the external device. When the OTA manager connected to the center wirelessly performs a software update of the target electronic control unit via the vehicle network, the second information is referenced by the OTA manager. The function includes processing for controlling the software update of the target electronic control unit based on the update data and the second information.
[0015] The OTA manager according to the second aspect of the disclosed technology can be mounted on a vehicle.
[0016] According to the center, OTA manager, method, non-transitory storage medium and vehicle disclosed herein, distribution data packets can be generated that can be referenced by both external devices connected to the vehicle by wire and the OTA manager connected to the center by wireless, so distribution data packets can be generated efficiently. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Hereinafter, features, advantages, technical and industrial significance of exemplary embodiments of the present invention will be described with reference to the accompanying drawings, in which like reference numerals represent like elements, and in which:
[0018] Figure 1 This is a block diagram showing the overall configuration of a network system according to an embodiment.
[0019] Figure 2 It is a block diagram showing the schematic structure of the center.
[0020] Figure 3 This is the functional block diagram of the center.
[0021] Figure 4 is an example of a centrally generated distribution data package.
[0022] Figure 5 This is a block diagram showing the brief structure of the OTA manager.
[0023] Figure 6 This is the functional block diagram of the OTA manager.
[0024] Figure 7 This is a flowchart of the distribution packet generation process performed by the center.
[0025] Figure 8 This is a flowchart of the distribution control process executed by the center.
[0026] Figure 9 This is a flowchart of the software update control process performed by the OTA manager. DETAILED DESCRIPTION
[0027] The present disclosure generates a distribution package that can be referenced by both external devices connected to the vehicle via a wired connection and an OTA manager connected wirelessly to a central server. This eliminates the need to create two separate distribution packages: one containing the data and information required for a wired software update and another containing the data and information required for an OTA software update. This allows for efficient distribution package generation.
[0028] Hereinafter, one embodiment of the present disclosure will be described in detail with reference to the accompanying drawings.
[0029] Implementation Method
[0030] constitute
[0031] Figure 1 This is a block diagram showing the overall configuration of a network system according to one embodiment of the present disclosure. Figure 1The network system shown is a system for updating software of a plurality of electronic control units 50a to 50d mounted in a vehicle. The network system includes a center 10 and an external device 110 located outside the vehicle, an in-vehicle network 90 constructed within the vehicle, and a network 100 .
[0032] (1) Center
[0033] The center 10 is capable of wirelessly communicating with an OTA manager 30 (described later) included in the in-vehicle network 90 via a network 100. The center 10 transmits software update data for the electronic control units 50a to 50d to the OTA manager 30 and receives notifications from the OTA manager 30 indicating the progress of the software update process. The center 10 is capable of controlling and managing software updates for the multiple electronic control units 50a to 50d connected to the OTA manager 30. The center 10 functions as a so-called server.
[0034] Figure 2 Yes Figure 1 A block diagram of the simplified structure of the center 10 is shown in FIG. Figure 2 As shown, the center 10 includes a CPU (Central Processing Unit) 11, RAM (Random Access Memory) 12, a storage device 13, and a communication device 14. The storage device 13 includes a readable and writable storage medium such as a hard disk drive (HDD) or a solid-state drive (SSD). The storage device 13 stores programs for executing software update management, information used in software update management, and update data for each electronic control unit. In the center 10, the CPU 11 executes the program read from the storage device 13 using the RAM 12 as a work area to perform predetermined processing related to software updates. The communication device 14 communicates with the OTA manager 30 via the network 100.
[0035] Figure 3 yes Figure 2 A functional block diagram of the center 10 is shown. Figure 3 The center 10 shown in FIG. 1 includes a storage unit 16, a communication unit 17, and a control unit 18. The storage unit 16 is composed of Figure 2 The communication unit 17 and the control unit 18 can be realized by Figure 2 The CPU 11 shown is implemented by executing a program stored in the storage device 13 using the RAM 12 .
[0036] The storage unit 16 stores information related to the software update process of one or more electronic control units installed in the vehicle. As information related to the software update process, the storage unit 16 stores at least update management information and update data of the software of the electronic control units 50a to 50d. The update management information is information that associates information representing the software that can be used in the electronic control units 50a to 50d with each vehicle identification information (vehicle ID) that identifies the vehicle. As information representing the software that can be used in the electronic control units 50a to 50d, for example, a combination of the latest version information of each software of multiple electronic control units 50a to 50d can be defined. In addition, as information related to the software update process, the storage unit 16 can store the update status of the software being implemented in the vehicle. In addition, the storage unit 16 can store information related to the type of non-volatile memory installed in each of the multiple electronic control units 50a to 50d (described later).
[0037] The communication unit 17 functions as a transmitter and receiver for transmitting and receiving data, information, and requests with the OTA manager 30. The communication unit 17 receives a software update confirmation request from the OTA manager 30 (receiver). The update confirmation request is sent from the OTA manager 30 to the center 10, for example, when the power or ignition of the vehicle is turned on (hereinafter referred to as "power on"). The update confirmation request is information used to request the center 10 to confirm whether update data for the electronic control units 50a to 50d exists based on vehicle configuration information described later. In response to the update confirmation request received from the OTA manager 30, the communication unit 17 transmits information indicating the presence of update data to the OTA manager 30 (transmitter). Furthermore, the communication unit 17 receives a request to send a distribution data packet (download request) from the OTA manager 30 (receiver). Upon receiving the download request for the distribution data packet, the communication unit 17 transmits the distribution data packet containing the software update data for the electronic control units 50a to 50d, generated by the control unit 18 described later, to the OTA manager 30.
[0038] When the communication unit 17 receives an update confirmation request from the OTA manager 30, the control unit 18 determines whether software update data exists for the electronic control units 50a-50d installed in the vehicle identified by the vehicle ID included in the update confirmation request, based on the update management information stored in the storage unit 16. The control unit 18's determination of whether update data exists is transmitted by the communication unit 17 to the OTA manager 30. If the control unit 18 determines that software update data exists for the electronic control units 50a-50d, and receives a download request for a distribution data package from the OTA manager 30, the control unit 18 generates a distribution data package for the corresponding update data, which is stored in the storage unit 16.
[0039] The control unit 18 generates a distribution packet that includes at least software update data for the electronic control unit (hereinafter referred to as the "target ECU") to be updated, external device information (an example of "first information"), and OTA manager information (an example of "second information"). The external device information is referenced by an external device 110 connected to the vehicle via the in-vehicle network 90 when performing a software update on the target ECU. The external device information defines the conditions that the external device 110 should determine when updating the target ECU's software, the units used to transfer update data to the target ECU, and the responses to errors. The OTA manager information is referenced by the OTA manager 30 connected wirelessly to the center 10 when performing a software update on the target ECU via the in-vehicle network 90. The OTA manager information defines the conditions that the OTA manager 30 should determine when updating the target ECU's software, the units used to transfer update data to the target ECU, and the responses to errors.
[0040] Figure 4 An example of a distribution data packet generated by the control unit 18 is shown in FIG. Figure 4 The illustrated distribution data packet includes not only update data, information for external devices, and information for OTA managers, but also identification information (flags, etc.). The identification information is used to determine the information (location of information) that the external device 110 and the OTA manager 30 that have obtained the distribution data packet should refer to. In addition, when the external device 110 and the OTA manager 30 predetermine the target address of the information referenced in the distribution data packet, the identification information can be omitted. In addition, Figure 4 , an example is shown in which one update data shared by the external device 110 and the OTA manager 30 is packaged. However, the update data for the external device 110 and the update data for the OTA manager 30 may be distributed as separate data packets.
[0041] (2) External devices
[0042] The external device 110 is connected to a communication interface such as a connector (not shown) equipped on the vehicle by wire and communicates with the vehicle. An example of the external device 110 is a service tool used in a repair shop, dealership, etc., which transmits data required for software updates to multiple electronic control units 50a to 50d connected to the vehicle network 90 and performs so-called diagnostic communications for performing vehicle self-diagnosis. The external device 110 can communicate with the center 10 via a predetermined network. The external device 110 is configured to be able to obtain distribution data packets generated by the center 10. Similar to the OTA manager 30, the external device can include a CPU, RAM, ROM, storage device, and communication device. The communication device of the external device can communicate with the center 10 via a predetermined network.
[0043] (3) In-vehicle network
[0044] In-vehicle network 90 includes an OTA manager 30, multiple electronic control units 50a to 50d, a display device 70, and a communication module 80. The OTA manager 30 is connected to the communication module 80 via a bus 60a. The OTA manager 30 is connected to the electronic control units 50a and 50b via a bus 60b. The OTA manager 30 is connected to the electronic control units 50c and 50d via a bus 60c. The OTA manager 30 is connected to the display device 70 via a bus 60d.
[0045] The OTA manager 30 is capable of wirelessly communicating with the center 10 via the bus 60a and the communication module 80 through the network 100. In addition, the OTA manager 30 is capable of wired communication with the electronic control units 50a to 50d and the display device 70 via the buses 60b to 60d. The OTA manager 30 is a device that has the function of managing the OTA state (the software update control state using wireless communication connection with the center 10) and controlling the update sequence as a process of software update processing to implement the software update of the target electronic control unit that is the update object. The OTA manager 30 controls the software update of the target electronic control unit among the electronic control units 50a to 50d based on the update data obtained from the center 10 through wireless communication. There is also a case where the OTA manager 30 is called a central gateway (CGW). One or more target electronic control units 50a to 50d can function as the OTA manager 30.
[0046] Figure 5 Yes Figure 1 A block diagram of the simplified structure of the OTA manager 30 in FIG. Figure 5As shown, the OTA manager 30 includes a CPU 31, a RAM 32, a ROM (Read-Only Memory) 33, a storage device 34, and a communication device 36. The CPU 31, RAM 32, ROM 33, and the storage device 34 constitute a microcomputer 35. In the OTA manager 30, the CPU 31 executes a program read from the ROM 33 using the RAM 32 as a work area to perform predetermined processing related to software updates. The communication device 36 communicates with the OTA manager 30 via Figure 1 The illustrated buses 60 a - 60 d communicate with the communication module 80 , the electronic control units 50 a - 50 d , and the display device 70 .
[0047] Figure 6 yes Figure 5 A functional block diagram of the OTA manager 30 is shown. Figure 6 The OTA manager 30 shown in FIG. 1 includes a storage unit 37, a communication unit 38, and a control unit 39. The storage unit 37 is composed of Figure 5 The communication unit 38 and the control unit 39 are implemented by the storage device 34 shown. Figure 5 The CPU 31 shown is implemented by executing a program stored in the ROM 33 using the RAM 32 .
[0048] The storage unit 37 stores a program for executing software updates for the multiple electronic control units 50a to 50d (control program for the OTA manager 30), various data used when executing software updates, and software update data downloaded from the center 10 via distribution packages.
[0049] The communication unit 38 functions as a transmitter and receiver for transmitting and receiving data, information, and requests with the center 10. For example, upon powering on the vehicle, the communication unit 38 transmits a software update confirmation request to the center 10 (transmitter). The update confirmation request includes, for example, the vehicle ID identifying the vehicle and information regarding the current software versions of the electronic control units 50a-50d connected to the in-vehicle network 90. The vehicle ID and the current software versions of the electronic control units 50a-50d are used to determine whether there is software update data for the electronic control units 50a-50d by comparing them with the latest software versions stored by the center 10 for each vehicle ID. Furthermore, the communication unit 38 receives a notification indicating the presence of software update data from the center 10 as a response to the update confirmation request (receiver). If there is software update data for the electronic control units 50a-50d, the communication unit 38 transmits a download request for a distribution package containing the software update data to the center 10 (transmitter). The communication unit 38 receives (downloads) the distribution data package transmitted from the center 10 (receiving unit). In addition, the communication unit 38 transmits the update status of the software transmitted by the electronic control units 50a to 50d to the center 10 (transmitting unit).
[0050] Based on the response from the center 10 to the update confirmation request received by the communication unit 38, the control unit 39 determines whether update data for the software of the electronic control units 50a-50d exists. Furthermore, the control unit 39 verifies the authenticity of the distribution data package received (downloaded) from the center 10 by the communication unit 38 and stored in the storage unit 37. Furthermore, the control unit 39 uses the update data received (downloaded) from the center 10 to control the software update process (various verification, installation, activation, etc.) for the electronic control units 50a-50d. Specifically, the control unit 39 transfers one or more update data downloaded via the distribution data package to the target electronic control unit, causing the target electronic control unit to install the updated software based on the update data. After the installation is complete, the control unit 39 instructs the target electronic control unit to activate the installed updated software.
[0051] The plurality of electronic control units 50a to 50d are devices (ECUs) for controlling the operation of various parts of the vehicle. Figure 1 In the embodiment, four electronic control units 50a to 50d are illustrated, but the number of electronic control units is not particularly limited. In addition, the number of buses connecting the electronic control units and the OTA manager 30 is also not particularly limited.
[0052] The display device 70 is a human-machine interface (HMI) used to display various displays such as the existence of update data when the software of the electronic control units 50a to 50d is being updated, the display of a consent request screen for requesting the user or manager of the vehicle to consent to the software update, and the display of the results of the software update. As the display device 70, a display device of a car navigation system can typically be used. The display device 70 is not particularly limited as long as it can display the information required for the software update process. In addition, Figure 1 The bus 60 d shown may be connected to an electronic control unit and the like in addition to the display device 70 .
[0053] The communication module 80 controls communication between the center 10 and the vehicle and is a communication device used to connect the in-vehicle network 90 to the center 10. The communication module 80 is wirelessly connected to the center 10 via the network 100. The OTA manager 30 performs vehicle authentication, update data downloads, and other functions via the communication module 80. Alternatively, the communication module 80 may be included in the OTA manager 30.
[0054] Overview of software update processing
[0055] The OTA manager 30, for example, sends a software update confirmation request to the center 10 when the vehicle is powered on. The update confirmation request includes a vehicle ID for identifying the vehicle and vehicle configuration information. Vehicle configuration information is information related to the status (system configuration) of the electronic control units 50a-50d connected to the in-vehicle network 90, including the current versions of the hardware and software of the electronic control units 50a-50d. The vehicle configuration information can be created by obtaining the electronic control unit identification number (ECU_ID) and the electronic control unit software version identification number (ECU_Software_ID) from the electronic control units 50a-50d connected to the in-vehicle network 90. The vehicle ID and the current version of the software of the electronic control units 50a-50d are used to determine whether there is update data for the software of the electronic control units 50a-50d by comparing it with the latest version of the software stored by the center 10 for each vehicle ID. The center 10 sends a notification indicating the presence of update data to the OTA manager 30 as a response to the update confirmation request received from the OTA manager 30. If there is update data for the software of the electronic control units 50a to 50d, the OTA manager 30 sends a download request for a distribution data package to the center 10. In response to the download request received from the OTA manager 30, the center 10 sends the distribution data package for the update data to the OTA manager 30. In addition to the update data, external device information, and OTA manager information described above, the distribution data package may also include verification data for verifying the authenticity of the update data, the amount and type of the update data, and various control information used during the software update.
[0056] The OTA manager 30 determines whether update data for the software of the electronic control units 50a-50d exists based on the response to the update confirmation request received from the center 10. Furthermore, the OTA manager 30 verifies the authenticity of the distribution data package received from the center 10 and stored in the storage device 34. Furthermore, the OTA manager 30 transfers one or more update data downloaded via the distribution data package to the target electronic control unit, causing the target electronic control unit to install the update data (update software). After the installation is complete, the OTA manager 30 instructs the target electronic control unit to validate the installed updated software.
[0057] Furthermore, during the consent request process, the OTA manager 30 causes an output device to output a notification indicating that consent to the software update is required, or a notification urging the user to input consent to the software update. The output device may include a display device 70 located on the in-vehicle network 90, or a sound output device that provides notifications via audio or voice. For example, during the consent request process, when the display device 70 is used as the output device, the OTA manager 30 may cause the display device 70 to display a consent request screen requesting the user or administrator's consent to the software update, or a notification urging the user or administrator to press a specific input operation, such as an consent button, if the user or administrator agrees. Furthermore, during the consent request process, the OTA manager 30 may cause the display device 70 to display a message, icon, or other notification indicating the presence of software update data for the electronic control units 50a to 50d, or to display restrictions on executing the software update process. Upon receiving consent input from the user or administrator, the OTA manager 30 executes the aforementioned control process for installing and activating the updated software, thereby updating the software in the target electronic control unit.
[0058] Here, in the case where the non-volatile memory of the electronic control unit is a single-bank memory having one storage area for storing control programs, update data, etc., installation and activation are performed continuously. Therefore, before the installation is performed, a consent request process for the software update is performed. In the case where the non-volatile memory of the electronic control unit is a dual-bank memory having two storage areas for storing control programs, update data, etc., installation and activation can be performed discontinuously. Therefore, a consent request process for the software update is performed at least after the installation is performed and before the activation is performed. In addition, in the case where the non-volatile memory of the electronic control unit is a dual-bank memory, the consent request process for the software update before the installation is performed may be performed or omitted.
[0059] The software update process consists of a download phase, an installation phase, and an activation phase. During the download phase, the OTA manager 30 downloads (receives) update data from the center 10. During the installation phase, the OTA manager 30 transfers the downloaded update data to the target electronic control unit and installs (writes) the update software based on the update data into the target electronic control unit's storage area. During the activation phase, the target electronic control unit activates (validates) the installed update software.
[0060] Downloading is the process in which the OTA manager 30 receives update data for updating the software of the electronic control units 50a-50d, sent from the center 10 via a distribution data packet, and stores the update data in the storage device 34. The downloading phase includes not only the execution of the download but also the control of a series of download-related processes, such as determining whether the download can be executed, requesting download approval from the vehicle user or administrator, and verifying the update data.
[0061] The update data sent from the hub 10 to the OTA manager 30 may include the update software (full data or differential data) for the electronic control units 50a-50d, compressed data obtained by compressing the update software, or segmented data obtained by segmenting the update software or compressed data. Furthermore, the update data may include the ECU_ID (or serial number) of the target electronic control unit and the ECU_Software_ID of the electronic control unit before the update. The update data is downloaded as a distribution data package. A distribution data package includes the update data for one or more electronic control units.
[0062] Installation is the process by which the OTA manager 30 writes updated software (an updated version of the program) to the target electronic control unit based on the update data downloaded from the center 10. The installation phase includes not only the execution of the installation but also the control of a series of installation-related processes, such as determining whether the installation can be performed, requesting consent from the vehicle user or administrator, transferring the update data, and verifying the updated software.
[0063] In the case where the update data includes the update software itself (complete data), during the installation phase, the OTA manager 30 transfers the update data (update software) to the target electronic control unit. In addition, in the case where the update data includes compressed data, differential data, or segmented data of the update software, the OTA manager 30 may transfer the update data to the target electronic control unit, and the target electronic control unit generates the update software based on the update data. In addition, the update software may be sent to the target electronic control unit after the OTA manager 30 generates the update software based on the update data. Here, the generation of the update software can be performed by decompressing the compressed data, the combination (integration) of differential data or segmented data.
[0064] The target ECU can install the updated software based on an installation request (or instruction) from the OTA manager 30 (or the center 10 ). The target ECU may also autonomously install the updated software without receiving explicit instructions from the OTA manager 30 .
[0065] Activation is the process by which the target electronic control unit validates (activates) the installed update software. The activation phase includes not only the execution of activation but also a series of activation-related controls, such as determining whether activation is executable, requesting consent from the vehicle user or administrator, and verifying the execution results.
[0066] The target ECU can activate the updated software based on an activation request (or instruction) from the OTA manager 30 (or the center 10). In addition, the target ECU that receives the updated data can also activate itself after installation without receiving explicit instructions from the OTA manager 30.
[0067] Here, the software update process can be performed on a plurality of target electronic control units respectively, successively or in parallel.
[0068] Furthermore, the “software update process” includes not only a process of continuously performing all of downloading, installation, and activation but also a process of performing only a part of downloading, installation, and activation.
[0069] deal with
[0070] Next, refer to Figure 7 、 Figure 8 as well as Figure 9 Next, the processing executed in the network system according to this embodiment will be described.
[0071] Figure 7 This is a flowchart illustrating a specific example of a distribution packet generation process performed by the control unit 18 of the center 10. For example, the process is started by an event, that is, an activity, in which a software update is performed on a vehicle. Figure 7 The illustrated distribution packet generation process.
[0072] Step S701
[0073] The control unit 18 of the center 10 generates external device information. The external device information is referenced when the external device 110 updates the software of the target electronic control unit via the in-vehicle network 90. The external device information defines the conditions that the external device 110 should use to determine when updating the software of the target electronic control unit, the units used to transfer update data to the target electronic control unit, and the response to errors. Once the external device information is generated, the process proceeds to step S702.
[0074] Step S702
[0075] The control unit 18 of the center 10 generates OTA manager information. The OTA manager information is referenced by the OTA manager 30 when performing a software update on the target ECU. The OTA manager information defines the conditions the OTA manager 30 should determine when updating the software on the target ECU, the units used to transfer update data to the target ECU, and the response to errors. Once the OTA manager information is generated, the process proceeds to step S703.
[0076] Step S703
[0077] The control unit 18 of the center 10 generates identification information. This identification information is referenced by the external device 110 and the OTA manager 30. The identification information is used to identify the location of information for the external device and the OTA manager when the update data is distributed in a data package. If the location of the information referenced by the external device 110 and the OTA manager 30 is known in advance, the generation of the identification information in step S703 can be omitted. If the identification information is generated, the process proceeds to step S704.
[0078] Step S704
[0079] The control unit 18 of the center 10 generates a distribution packet including the update data, information for the external device, and information for the OTA manager, and generates a distribution packet further including the identification information if the identification information is generated.
[0080] Figure 8 This is a flowchart for explaining an example of the distribution control process executed by each component of the center 10. The center 10 starts the process when it receives the update confirmation request sent by the OTA manager 30. Figure 8 The distribution control process shown.
[0081] Step S801
[0082] The communication unit 17 of the center 10 determines whether there is a software update confirmation request from the OTA manager 30. If there is an update confirmation request (step S801, yes), the process proceeds to step S802. If there is no update confirmation request (step S801, no), the process proceeds to step S804.
[0083] Step S802
[0084] The control unit 18 of the center 10 checks for software that requires updating. This check is performed by comparing the current versions of the software for each electronic control unit 50a to 50d installed in the vehicle, obtained from the vehicle configuration information included in the update confirmation request, with the latest versions of each software stored in the storage unit 16 of the center 10. If the check for software that requires updating is completed, the process proceeds to step S803.
[0085] Step S803
[0086] The control unit 18 of the center 10 determines whether software update data exists for the electronic control units 50a-50d mounted on the vehicle and included in the update confirmation request, based on the update management information stored in the storage unit 16 of the center 10. Based on the determination result, the control unit 18 transmits information indicating the presence of update data to the OTA manager 30. If the presence of update data is transmitted, the process proceeds to step S804.
[0087] Step S804
[0088] The communication unit 17 of the center 10 determines whether there is a download request for the distribution package from the OTA manager 30. If there is a download request (step S804, yes), the process proceeds to step S805. If there is no download request (step S804, no), the process proceeds to step S801.
[0089] Step S805
[0090] The communication unit 17 of the center 10 transmits the distribution packet to the OTA manager 30. If the distribution packet is transmitted, the process proceeds to step S801.
[0091] Figure 9 This is a flowchart for explaining an example of the software update control process executed by each component of the OTA manager 30. For example, the process is executed when the vehicle is powered on. Figure 9 The software update control process is shown.
[0092] Step S901
[0093] The communication unit 38 of the OTA manager 30 sends an update confirmation request to the center 10 to check whether the software update data for the electronic control units 50a-50d exists. This update confirmation request includes the vehicle ID and the current software version of the electronic control units 50a-50d. If the update confirmation request is sent to the center 10, the process proceeds to step S902.
[0094] Step S902
[0095] The communication unit 38 of the OTA manager 30 receives a response to the update confirmation request (confirmation result of the update data) from the center 10. If the response to the update confirmation request is received, the process proceeds to step S903.
[0096] Step S903
[0097] The control unit 39 of the OTA manager 30 determines whether software update data exists for at least one of the electronic control units 50a-50d based on the response to the update confirmation request received by the communication unit 38 of the OTA manager 30. If at least one piece of software update data exists (step S903, yes), the process proceeds to step S904. If no software update data exists at all (step S903, no), the software update control process ends.
[0098] Step S904
[0099] The control unit 39 of the OTA manager 30 downloads the update data. More specifically, the communication unit 38 of the OTA manager 30 sends a download request for a distribution data packet containing the update data to the center 10 and receives the distribution data packet sent from the center 10 in response to the download request. The communication unit 38 stores the received distribution data packet in the storage unit 37 of the OTA manager 30. If the update data is downloaded, the process proceeds to step S905.
[0100] Step S905
[0101] The control unit 39 of the OTA manager 30 executes software installation based on the update data to the target electronic control unit. More specifically, based on the OTA manager information included in the distribution data packet (which can be determined based on the identification information), the control unit 39 transfers the update data included in the distribution data packet to the target electronic control unit, instructing the target electronic control unit to install the update software. The target electronic control unit writes the update data received from the OTA manager 30 to the data storage area. If the update software is installed, the process proceeds to step S906.
[0102] Step S906
[0103] The control unit 39 of the OTA manager 30 activates the update software installed in the target electronic control unit. More specifically, based on the OTA manager information included in the distribution data packet, the control unit 39 instructs the target electronic control unit, where the update software has been written to the data storage area, to activate the update software. The target electronic control unit restarts in response to a specific input operation, such as power off, and executes the update software. Once the update software activation process is complete, the software update control process ends.
[0104] Above, use Figure 8 as well as Figure 9 The details of the software update control in the software update using the OTA manager 30 (the software update using the OTA manager 30 wirelessly connected to the vehicle network) are described. The software update control using an external device wired to the vehicle network is also performed in the same way. In the software update control using the external device, the external device can be started by connecting the connector to the vehicle. Figure 8 The distribution control process shown and Figure 9 The software update control process shown in FIG. Furthermore, in the software update control using an external device, in step S905, the external device transfers the update data included in the distribution data packet to the target electronic control unit based on the external device information included in the distribution data packet (which can be identified based on the identification information), and instructs the target electronic control unit to install the updated software. Furthermore, in step S906, the external device instructs the target electronic control unit, which has written the updated software into the data storage area, to activate the updated software based on the external device information included in the distribution data packet.
[0105] Effect
[0106] As described above, a network system according to one embodiment of the present disclosure generates a distribution package that can be referenced by both external devices connected to the vehicle via a wired connection and an OTA manager connected to the center via a wireless connection. This eliminates the need to create two distribution packages: one containing the data and information required for a wired software update and another containing the data and information required for an OTA software update. This allows for efficient distribution package generation.
[0107] In addition, since the distribution data packet including the update data includes information (identification information) that determines the information referenced by the OTA manager (information for the OTA manager), the software update of the electronic control unit can be achieved through OTA using a distribution data packet common to the OTA manager and external devices.
[0108] While one embodiment of the disclosed technology has been described above, the present disclosure can be understood not only as a hub, but also as a distribution control method, a distribution control program, or a computer-readable non-transitory storage medium storing the distribution control program, executed by the hub, which includes a processor, memory, and storage device. The OTA manager can include one or more processors. The hub can also include one or more processors.
[0109] The disclosed technology can be utilized in a network system for updating software of an electronic control unit.
Claims
1. A software update control center configured to communicate with an OTA manager configured to control software updates of an electronic control unit mounted on a vehicle. The software update control center is characterized by comprising: a control unit configured to generate a distribution data packet including software update data for a target electronic control unit, the target electronic control unit being the electronic control unit to be updated, first information, and second information, wherein when an external device connected to the vehicle by wire performs a software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device, and when the OTA manager connected wirelessly to the software update control center performs a software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager; and The communication unit is configured to transmit the distribution packet to the OTA manager based on a request from the OTA manager.
2. The software update control center according to claim 1, characterized in that: The distribution packet further includes identification information for identifying which of the first information and the second information the external device and the OTA manager should refer to.
3. An OTA manager configured to control software updates of an electronic control unit mounted on a vehicle, The OTA manager is characterized by including: a communication unit configured to receive, from a software update control center, a distribution data packet including update data for software of a target electronic control unit, first information, and second information, the target electronic control unit being the electronic control unit to be updated, the first information being referenced by an external device connected to the vehicle by wire when the external device updates the software of the target electronic control unit via an in-vehicle network, and the second information being referenced by the OTA manager connected wirelessly to the software update control center when the OTA manager updates the software of the target electronic control unit via the in-vehicle network; and The control unit is configured to control software update of the target electronic control unit based on the update data and the second information.
4. The OTA manager according to claim 3, wherein: The distribution data packet further includes identification information indicating which of the first information and the second information the external device and the OTA manager should refer to. The control unit specifies the second information based on the identification information.
5. A software update control method, executed by a software update control center configured to communicate with an OTA manager configured to control software updates of an electronic control unit mounted on a vehicle, the OTA manager comprising a memory and one or more processors. The software update control method is characterized by comprising: generating a distribution data packet including software update data for a target electronic control unit, first information, and second information, wherein the target electronic control unit is the electronic control unit to be updated, wherein when an external device connected to a vehicle by wire performs software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device, and when the OTA manager connected to the software update control center by wireless communication performs software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager; and The distribution data packet is sent to the OTA manager based on a request from the OTA manager.
6. A software update control method, executed by an OTA manager configured to control software updates of an electronic control unit mounted on a vehicle, the OTA manager comprising a memory and one or more processors. The software update control method is characterized by comprising: receiving, from a software update control center, a distribution data packet including update data for software of a target electronic control unit, first information, and second information, the target electronic control unit being the electronic control unit to be updated, wherein when an external device connected to a vehicle by wire performs a software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device, and when the OTA manager connected to the software update control center by wireless performs a software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager; and Software update of the target electronic control unit is controlled based on the update data and the second information.
7. A non-transitory storage medium storing commands executable by computers in one or more software update control centers and causing the computers in the one or more software update control centers to perform the following functions, wherein the software update control center is configured to communicate with an OTA manager configured to control software updates of electronic control units mounted in a vehicle, the OTA manager comprising a memory and one or more processors; The non-transitory storage medium is characterized in that The features include: generating a distribution data packet including software update data for a target electronic control unit, first information, and second information, wherein the target electronic control unit is the electronic control unit to be updated, wherein when an external device connected to a vehicle by wire performs software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device, and when the OTA manager connected to the software update control center by wireless communication performs software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager; and The distribution data packet is sent to the OTA manager based on a request from the OTA manager.
8. A non-transitory storage medium storing instructions executable by one or more OTA manager computers and causing the one or more OTA manager computers to perform the following functions, wherein the OTA manager is configured to control software updates of electronic control units mounted on vehicles, the OTA manager comprising a memory and one or more processors. The non-transitory storage medium is characterized in that The features include: receiving, from a software update control center, a distribution data packet including update data for software of a target electronic control unit, first information, and second information, the target electronic control unit being the electronic control unit to be updated, wherein when an external device connected to a vehicle by wire performs a software update of the target electronic control unit via an in-vehicle network, the first information is referenced by the external device, and when the OTA manager connected to the software update control center by wireless performs a software update of the target electronic control unit via the in-vehicle network, the second information is referenced by the OTA manager; and Software update of the target electronic control unit is controlled based on the update data and the second information.
9. A vehicle, characterized in that: Equipped with the OTA manager according to claim 3 or 4.
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Update control device, update control system, and update control method
CN112313618A
Vehicle-mounted communication device and communication method
CN112449000A