Device and method for managing electronic control units of a motor vehicle
By introducing two dedicated programmable update interfaces into the electronic control unit, the problem of distinguishing update commands from those of the manufacturer and the technical coordinator is solved, ensuring that configuration parameters are updated independently according to their respective requirements, thus achieving data protection and consistency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 安培簡式股份有限公司
- Filing Date
- 2021-03-18
- Publication Date
- 2026-07-21
AI Technical Summary
Existing technologies cannot effectively distinguish and protect the configuration updates of electronic control units by motor vehicle manufacturers and technical coordinators, resulting in discrepancies between update commands that lead to data loss and inconsistencies.
Two dedicated programmable update interfaces are used, one accessible to the vehicle manufacturer and the other to the technical coordinator, to control the updating and masking of configuration parameters respectively, ensuring the independent execution of update commands.
It enables the protection and execution of configuration parameters separately under update commands from vehicle manufacturers and technical coordinators, avoiding data loss and inconsistency during the update process.
Smart Images

Figure CN115668130B_ABST
Abstract
Description
Technical Field
[0001] This invention generally relates to automotive electronic products, and particularly to an apparatus and method for controlling an electronic control unit for a motor vehicle. Background Technology
[0002] Modern vehicles use many electronic control units (ECUs) to control the operation of components such as the engine, powertrain, transmission, brakes, suspension, infotainment system, communication system, body system, and chassis system.
[0003] An electronic control unit (ECU) is an onboard computer or system configured to electronically control the functions or physical equipment of a vehicle. Each ECU sends control signals to its corresponding device to control it and stores data related to the device it controls. The data stored in the ECU is particularly useful for diagnosing the causes of vehicle malfunctions.
[0004] Diagnostics of electronic control units are typically performed by a diagnostic tool (also known as a 'tester') connected to the electronic control unit via a wired or wireless connection, through which the electronic control unit exchanges data with the diagnostic tool.
[0005] Electronic control units (ECUs) are initialized by vehicle manufacturers during factory manufacturing. Once the ECU is initially programmed in the vehicle, it may prove necessary to modify or change certain parts of the initial program code, for example, to change configuration parameter values, add data, or correct application files. Therefore, diagnostic systems have been developed so that product development teams, software / hardware testing teams, and after-sales teams can detect and fix defects or improve vehicle settings by connecting their diagnostic tools to the ECU.
[0006] In this way, the configuration data stored in the electronic control unit's memory can be updated throughout the vehicle's lifespan.
[0007] The (wireless or wired) communication between the (remote or in-vehicle) diagnostic tool and the electronic control unit is set up using automotive protocols that allow for fault diagnosis and reprogramming of the electronic control unit.
[0008] The UDS protocol (an acronym for Unified Diagnostic Services) is an internationally standardized automotive diagnostic service protocol. It allows various electronic control units (ECUs) to be queried via a diagnostic server, requesting them to upload information about faults or specific events that occurred during vehicle operation.
[0009] The electronic control unit can be updated remotely by the vehicle manufacturer or by a technical coordinator via a remote diagnostic server or via an on-board diagnostic server using a diagnostic port.
[0010] There are already updated technologies for electronic control units used to manage and control motor vehicles.
[0011] A first technique for automatically updating the electronic control unit of a motor vehicle is described in U.S. Patent No. 10,416,989 B2. This technique allows software updates to be delivered to the vehicle's onboard computer via air or through an onboard diagnostic server. First, it is confirmed that a software update is needed for the onboard computer. Then, a configuration file is sent from a (remote or onboard) server to the onboard computer requiring the software update in order to perform the necessary update. Update parameters are contained in temporary files, which are pre-stored in the onboard computer's memory, then executed, and finally deleted after reprogramming.
[0012] A second technique for reprogramming electronic control units (ECUs) of motor vehicles has been disclosed in US Patent Application No. US 20140058532 A1. This second technique allows for the programming and configuration of ECUs using a partial flash memory method, enabling the ECU's memory to be partitioned into multiple partitions based on existing digital file types, and only the partitions requiring reprogramming to be reconfigured. The reprogramming method according to US Patent Application No. US 20140058532 A1 allows for the initial definition of a memory within the ECU to store various types of content files, each content file including lines of code. The method then allows for segmenting the memory by dividing it into segments, each segment characterized by the nature of the files it contains (application code, operating system code, calibration files, etc.) and potentially including blank memory space where additional code can be written. Therefore, if it is conceivable to specifically reprogram a certain type of file, a memory segment characterized by the same file type is considered, and the blank space of that segment is used for reprogramming, while the remaining content files in that memory remain unaffected.
[0013] A third technique for remotely updating electronic control units (ECUs) located in a vehicle is described in US Patent Application No. 10101992 B2. This technique allows for the reprogramming of automotive microcontrollers using a wireless over-the-air communication network and allows for differentiation between various types of computers. Wireless communication with a remote network ensures data exchange between the automotive microcontroller and a server to obtain a set of differential updates. All update packets are stored in the storage memory of a telematics unit. The update data is then managed by the processor of the telematics unit and transmitted via the vehicle's controller network to the target ECU, where it is subsequently installed.
[0014] Existing technologies for updating electronic control units allow for reprogramming of the electronic control units by both the vehicle manufacturer and the technical coordinator.
[0015] For strategic, architectural, or contractual reasons, electronic control unit updates implemented by technical coordinators are not always delivered to vehicle manufacturers.
[0016] For example, a technical coordinator can update the configuration data of the electronic control unit, but will not transmit the update to the vehicle manufacturer, because the standard list in the vehicle manufacturer's world vehicle database is considered a component of the vehicle's identity, and therefore the vehicle manufacturer does not want to change that list.
[0017] The technical coordinator can also consolidate the state of the options in the vehicle rather than on the vehicle manufacturer's server, without sending updates to the options to the vehicle manufacturer.
[0018] The technical coordinator may also be obligated under a contract to ensure the availability of the option once the vehicle leaves the garage, and may not be permitted to establish a reliable connection and communication with the manufacturer's servers.
[0019] In the prior art, if configuration data is updated by the vehicle manufacturer after one or more updates by the technical coordinator, the data updated by the technical coordinator will be lost. The prior art does not allow for a difference between the parameterization of the electronic control unit performed in response to an update command received from the vehicle manufacturer and the parameterization performed in response to an update command received from a third party (e.g., the technical coordinator).
[0020] Therefore, it is necessary to protect parameters that are modified in response to update commands transmitted by the technical coordinator, so that they are not changed during updates performed at the request of motor vehicle manufacturers, without the need to deploy new infrastructure or other tools. Summary of the Invention
[0021] The present invention aims to improve this situation. To this end, the present invention provides an apparatus for controlling an electronic control unit of a motor vehicle, the apparatus including a module for updating the configuration of the electronic control unit, the configuration being defined by a set of configuration parameters, at least one configuration parameter being associated with a parameter value and a filter value, the updating module comprising:
[0022] - A first programmable update interface, configured to update a parameter value associated with at least one configuration parameter in response to an update command received from a first source, and to update a filter value associated with the at least one configuration parameter in response to the update of the value;
[0023] - A second programmable update interface, configured to update parameter values associated with the configuration parameters based on filter values associated with at least some of the configuration parameters in the set of configuration parameters in response to an update command received from a second source.
[0024] According to some embodiments, the parameter values associated with this set of configuration parameters can be initialized to initial factory values and / or generated by previous updates.
[0025] According to some embodiments, the second update interface can be configured to update the set of configuration parameters defining the configuration in response to an update command received from the second source.
[0026] According to some embodiments, the first update interface can be configured to read filter values associated with one or more configuration parameters.
[0027] According to some embodiments, the first update interface can be configured to modify filter values associated with one or more configuration parameters to convert one or more automatic or manual parameters into one or more manual or automatic parameters, where automatic parameters are configuration parameters associated with parameter values updated in response to an update command received from the second source, and manual parameters are configuration parameters associated with parameter values updated in response to an update command received from the first source.
[0028] According to some embodiments, the second update interface can be configured to remove the filter value associated with a given configuration parameter.
[0029] According to some embodiments, the first source may be a diagnostic tool accessible to the vehicle manufacturer to initialize parameter values associated with the set of configuration parameters. This diagnostic tool may be accessible to a technical coordinator to update values associated with at least one configuration parameter and, in response to such update, update filter values associated with the at least one configuration parameter via the first update interface.
[0030] According to some embodiments, the second source may be a remote update server accessible to the vehicle manufacturer for updating at least some of the configuration parameters in the set of configuration parameters.
[0031] The present invention further provides a method for controlling an electronic control unit of a motor vehicle, the method comprising updating the configuration of the electronic control unit, the configuration being defined by a set of configuration parameters, at least one configuration parameter being associated with a parameter value and a filter value, the method comprising the following steps:
[0032] - Initialize the parameter values associated with this set of configuration parameters to their initial factory values;
[0033] - In response to an update command received from a first source, update the parameter value associated with at least one configuration parameter via a first programmable update interface;
[0034] - In response to an update of the parameter value associated with at least one configuration parameter, update the filter value associated with the at least one configuration parameter through the first programmable update interface;
[0035] - In response to an update command received from a second source, update the parameter values associated with the configuration parameters based on filter values associated with at least some of the configuration parameters in the set of configuration parameters.
[0036] Advantageously, embodiments of the invention provide a mechanism for protecting parameters modified in response to an update command requested by a technical coordinator from being altered during an update process performed in response to an update command requested by a motor vehicle manufacturer.
[0037] Advantageously, embodiments of the invention allow for the separation of parameterization of the electronic control unit configuration performed at the request of the motor vehicle manufacturer from parameterization performed at the request of the technical coordinator.
[0038] Advantageously, embodiments of the present invention provide an apparatus for protecting personalized configurations performed by a technical coordinator before a motor vehicle manufacturer performs a software update.
[0039] Advantageously, embodiments of the invention provide two dedicated programmable update interfaces: a first update interface accessible to a technical coordinator, and a second programmable update interface dedicated to the vehicle manufacturer. These two programmable update interfaces provide programmable protection mechanisms that allow protection of the prior configuration version installed by the technical coordinator.
[0040] Advantageously, embodiments of the invention allow reading the state of the configuration mask, adding references to at least one given configuration parameter, deleting references to at least one given configuration parameter, and deleting any references to the configuration parameter via a first programmable update interface accessible by a technical coordinator.
[0041] Advantageously, embodiments of the present invention provide programmable protection of data via a diagnostic interface. Attached Figure Description
[0042] Other features, details, and advantages of the invention will become apparent from the description given by way of example, with reference to the accompanying drawings, which illustrate the invention in detail below:
[0043] [ Figure 1 ] Figure 1 It is a schematic diagram showing a motor vehicle equipped with an electronic control unit.
[0044] [ Figure 2 ] Figure 2 This is a schematic diagram illustrating an example of the block structure of a device for controlling an electronic control unit according to certain embodiments of the present invention.
[0045] [ Figure 3 ] Figure 3 This is a flowchart illustrating a method for controlling an electronic control unit according to certain embodiments of the present invention.
[0046] [ Figure 4 ] Figure 4 This is a schematic diagram illustrating an example of a set of configuration parameters and a configuration shielding structure according to certain embodiments of the present invention.
[0047] [ Figure 5 ] Figure 5 An example of a timing diagram illustrating the initialization of a set of configuration parameters according to certain embodiments of the present invention is shown.
[0048] [ Figure 6 ] Figure 6 This is a schematic diagram illustrating an example of a set of configuration parameters and a configuration shield structure following an initialization step according to certain embodiments of the present invention.
[0049] [ Figure 7 ] Figure 7 An example of a timing diagram showing the configuration update of an electronic control unit at the request of a technical coordinator, according to certain embodiments, is shown.
[0050] [ Figure 8 ] Figure 8 This is a schematic diagram illustrating an example of a set of configuration parameters and a configuration mask structure after an update is performed at the request of a technical coordinator, according to certain embodiments.
[0051] [ Figure 9 ] Figure 9 An example of a timing diagram is shown illustrating an update to the configuration of an electronic control unit following an update implemented at the request of a technical coordinator, according to certain embodiments.
[0052] [ Figure 10 ] Figure 10 This is a schematic diagram illustrating an example of a set of configuration parameters and a configuration shield structure following an update implemented at the request of a technical coordinator and then performed at the request of a motor vehicle manufacturer. Detailed Implementation
[0053] Embodiments of the present invention provide an apparatus and method for controlling an electronic control unit (ECU) of a motor vehicle. The apparatus and method according to the invention provide protection for the configuration data of the ECU, ensuring it is not altered during updates performed by the motor vehicle manufacturer following updates implemented by a technical coordinator. The data protection according to the invention is based on a configuration shielding implementation via two dedicated programmable update interfaces.
[0054] As used herein, "motor vehicle manufacturer" refers to the manufacturer of a motor vehicle whose electronic control unit is controlled by the device and method according to the invention.
[0055] As used herein, a technical coordinator refers to a third party, distinct from the vehicle manufacturer, capable of maintaining and managing the electronic control unit (ECU) and installing updates on the ECU of a vehicle. By way of non-limiting example, a technical coordinator could be a component manufacturer (e.g., the developer of the ECU or a manufacturer whose products use the ECU), capable of installing software updates for ECUs manufactured or supported by that component manufacturer. In another example, a technical coordinator could be a service provider (e.g., a dealer, mechanic, engineer, or service center), capable of updating the ECU installed in vehicles supported by that service provider.
[0056] As used herein, the first update interface can be accessed by a first source such as a technical coordinator, and the second update interface can be accessed by a second source such as a motor vehicle manufacturer.
[0057] As used here, automatic parameterization refers to the parameterization of the configuration of the electronic control unit implemented by the motor vehicle manufacturer.
[0058] As used here, manual parameterization refers to the parameterization of the electronic control unit configuration performed by the technical coordinator.
[0059] As used herein, the configuration parameter 'automatic' or referred to as 'in automatic mode' means a configuration parameter whose value is updated in response to commands transmitted by the motor vehicle manufacturer (e.g., in response to an initialization command transmitted during the initialization phase of factory manufacturing or in response to an update command transmitted during the lifecycle of a vehicle in after-sales service).
[0060] As used here, 'manual' or 'in manual mode' configuration parameters refer to configuration parameters whose values are updated in response to update commands transmitted by the technical coordinator.
[0061] As used here, parameter conversion operations represent commands transmitted by the vehicle manufacturer or technical coordinator to change the manual or automatic characteristics of configuration parameters.
[0062] As used herein, parameter masking (also referred to as 'reference' or 'parameter filter') refers to a software filter that represents a value stored in the electronic control unit and is used to protect manually input parameters during configuration updates of the electronic control unit implemented at the request of the vehicle manufacturer. Therefore, parameter masking represents a software filter used to protect the parameter values during updates in response to an update command received from a second source. Thus, configuration masking includes configuration parameters referred to herein as 'manual', which will be protected from subsequent updates in response to update commands received from the second source. The filter does not require a dimension n of the parameter, and therefore any change in its dimension is insignificant. Therefore, it is not necessary to know in advance the configuration parameters of interest or their memory addresses.
[0063] As used here, adding a parameter mask involves adding a reference to a given configuration parameter to the configuration mask.
[0064] As used here, removing parameter masking includes removing references to a given configuration parameter from the configuration mask.
[0065] As used herein, a configuration mask refers to a set of parameter filters that represent digital values stored in the electronic control unit (ECU) and are used by the ECU to protect manual parameters during configuration updates implemented at the request of the vehicle manufacturer. A configuration mask may involve some or all of the ECU's configuration parameters. A configuration mask contains a reference to each manual parameter. Configuration masks can be progressively built over the vehicle's lifecycle through partial updates of configuration parameters, allowing for individual addition or removal of parameter masks after updates implemented by a technical coordinator. A configuration mask is a protection mechanism that allows configuration parameters to be protected from subsequent changes after updates implemented by the vehicle manufacturer.
[0066] As shown here, air communication refers to wireless communication between the electronic control unit and one or more remote servers that are accessible to and managed by the vehicle manufacturer.
[0067] Figure 1 A motor vehicle 1 is shown, which includes various functional components (not shown) that implement and / or control various electronic control units integrated into the vehicle 1. For clarity, Figure 1 A single electronic control unit 10 is shown in the figure.
[0068] According to some embodiments, the electronic control unit 10 can be configured to control the operation of components in the vehicle 1.
[0069] According to certain embodiments, the components may be selected from the group specifically including: engine, powertrain, transmission, brake, suspension, in-vehicle infotainment system, communication system, body system, chassis system, power steering system, acceleration system, door locking system, electronic fuel injection system, and anti-lock braking system.
[0070] According to some embodiments, the electronic control unit 10 can be configured to collect and analyze driving data that can be provided to insurance companies or used to improve the driving experience or provide advanced or automated driving assistance.
[0071] According to some embodiments, the electronic control unit 10 can be configured to detect anomalies in itself and in the components it controls, and store the component operation anomaly data in ( Figure 1 (In storage units not shown in the image)
[0072] According to some embodiments, the electronic control unit 10 may be configured with software instructions to detect faults and predict downtime, allowing the entire software of the electronic control unit to be rolled back to a previous version, to perform diagnostic service updates, and other operations.
[0073] According to some embodiments, the electronic control unit 10 may be selected from the group consisting of: a unit for controlling in-vehicle infotainment, a unit for ensuring panoramic surround view monitoring, an engine control unit, or a hybrid vehicle controller or an electric vehicle controller.
[0074] The electronic control unit 10 can be configured to store data related to configuration parameters, such as allowing personalization of the vehicle's human-machine interface based on the vehicle model, applicable country, vehicle color, and other options (such as whether a reversing camera has been added).
[0075] According to some embodiments, the configuration parameters may be selected from, for example, the group including: towing hook configuration parameters, CD changer configuration parameters, rear camera configuration parameters, after-sales alarm configuration parameters, vehicle color configuration parameters, engine speed configuration parameters, configuration parameters for the use of a non-vehicle-original but vehicle-compatible pump, and configuration parameters for the fleet speed limiter.
[0076] refer to Figure 2 An embodiment of the present invention provides a device 20 for controlling an electronic control unit 10 of a motor vehicle 1. The device 20 includes an update module 201 configured to update the configuration of the electronic control unit 10. The configuration of the electronic control unit 10 is defined, in particular, by a set of configuration parameters, at least one of which is associated with a parameter value (the size of the configuration parameter is expressed in bits) and a filter value.
[0077] According to some embodiments, the electronic control unit 10 may include a storage unit 101 configured to store configuration data of the electronic control unit 10, including parameter values and filter values associated with manually configured parameters.
[0078] According to some embodiments, storage unit 101 may include one or more read-only memories and / or one or more random access memories.
[0079] According to some embodiments, the electronic control unit 10 may further include a processor 102 and a communication controller ( Figure 2 (Not shown in the image) and input-output interface 103. Processor 102 can be configured to perform calculations based on a control program stored in read-only memory. Random access memory can be configured to temporarily store data generated by the processor's calculations. Processor 102, storage unit 101, and communication controller can be interconnected via bidirectional bus 104 and connected to the input-output interface.
[0080] According to some embodiments, the input-output interface 103 may be connected to one or more sensors, and the data delivered by the sensors may be stored in the storage unit 101.
[0081] The update module 201 according to the invention allows for the protection of configuration parameters from being altered during the operating cycle of vehicle 1. The protection of configuration data according to the invention is based on an implementation of two programmable electronic control unit update interfaces, including a first update interface accessible by a technical coordinator and a second update interface accessible by the vehicle manufacturer, which thus allows for the identification of the update source. More specifically, refer to... Figure 2 The update module 201 may include a first programmable update interface 202, which is configured to update a parameter value associated with at least one configuration parameter in response to an update command received from a first source 21, and to update the configuration mask in response to the update of the parameter value by adding a reference to the at least one configuration parameter to the configuration mask, the addition of the reference to the configuration parameter allowing the update of the filter value associated with the parameter.
[0082] According to some embodiments, the first source 21 may be an on-board diagnostic tool that communicates with the electronic control unit 20 via a wired connection 23, which may use the centralized diagnostic port 22 of the vehicle 1 to allow access to various electronic control units of the vehicle 1.
[0083] According to some embodiments, diagnostic port 22 may be configured to be electrically connected to electronic control unit 10, for example, via a communication medium such as a bidirectional serial K-line or via a bidirectional serial network such as a CAN network (CAN is an abbreviation for Controller Area Network).
[0084] According to some embodiments, the first source 21 may be configured to communicate with the electronic control unit 10 via an electronic control unit network or via a gateway electronic control unit.
[0085] According to some embodiments, the first source 21 may be accessed by a technical coordinator to update the value associated with at least one configuration parameter and, in response to the update, to update the filter value associated with the at least one configuration parameter via the first update interface 202.
[0086] To differentiate between parameterization performed by the vehicle manufacturer and parameterization implemented by the technical coordinator, update module 201 may further include a second programmable update interface 203 configured to update parameter values associated with at least some of the configuration parameters in response to an update command received from the second source 24, based on filter values associated with at least some of the configuration parameters in the set of configuration parameters. The updated parameter values may be generated by initialization steps performed at the factory and / or by previous update steps performed by the technical coordinator and / or the vehicle manufacturer.
[0087] According to some embodiments, the second source 24 may be a remote update server accessible to the vehicle manufacturer, intended to update at least some of the configuration parameters in the set of configuration parameters via the second update interface 203. Communication between the second source 24 and the electronic control unit 10 may be, for example, over-the-air communication or communication via a USB key. Over-the-air communication refers to electromagnetic communication employing wireless communication technologies or techniques via a wireless communication network 25 (e.g., cellular networks, mobile ad hoc networks such as Bluetooth or Wi-Fi).
[0088] According to some embodiments, the first source 21 and the second source 24 can be configured to communicate with the electronic control unit 10 using the UDS diagnostic protocol. The UDS protocol provides various services, including reading and writing data to and from the electronic control unit 10, reprogramming the electronic control unit 10, remotely activating routines, etc. Therefore, the first source 21 and the second source 24 can be configured to communicate with the electronic control unit 10, which is installed in the vehicle 1 and has activated the UDS service.
[0089] The UDS service uses the layers of the OSI model (OSI is an acronym for Open Systems Interconnection). The data transmission capabilities of the UDS protocol stack allow reading or writing any type of information to or from the electronic control unit 10.
[0090] The UDS protocol service is associated with a service identifier (SID) and service parameters, which are contained in the data of message frames transmitted by an on-board diagnostic tool (or even the first source 21) or a remote diagnostic tool (or even the second source 24). Messages defined in the UDS protocol can be sent to the electronic control unit 10, which provides the predetermined service.
[0091] The UDS protocol stack includes a set of services related to data transmission, such as 'read data by identifier', 'read memory by address', 'write data by identifier', and 'write memory by address'.
[0092] Therefore, data can be read from or written to the electronic control unit 10 (and more precisely to the storage unit 101) using a data identifier (DID) and a periodic identifier, and the data can be read from a specified address in the physical memory, or even written to the electronic control unit 10 (and more precisely to the storage unit 101) by the identifier and the memory address.
[0093] The data read from and written to the electronic control unit 10 may involve static information, such as the serial number of the electronic control unit 10, current sensor status, engine speed, configuration parameters, etc. In particular, the write service allows modification of configuration parameters during updates at the request of the vehicle manufacturer or technical coordinator.
[0094] Configuration data can be initialized or set at the factory during vehicle manufacturing.
[0095] According to some embodiments, configuration data (and similarly, configuration parameters) can be initialized to associate the vehicle model selected by the customer with various options offered by the motor vehicle manufacturer (e.g., engine size, speed limiter, cruise control, transmission). The application code residing in the first memory space can be common to all vehicles of a given model, or it can vary depending on the various options subscribed to by the customer.
[0096] The electronic control unit 10 can be initialized in the factory when the vehicle is on the production line, once the vehicle is assembled, or when the vehicle is in the assembly process.
[0097] According to some embodiments, the parameter values associated with the set of configuration parameters can be initialized to initial factory values. In particular, the second source 24 may be a diagnostic tool (or update tool) accessible by the vehicle manufacturer in the factory (e.g., on the production line) to initialize the parameter values associated with at least some of the configuration parameters in the set of configuration parameters via the second update interface 203.
[0098] At the time of manufacture, each configuration parameter of the electronic control unit 220 can be considered automatic, and the parameter value associated with each configuration parameter has been defined during initialization in response to an initialization command transmitted by the motor vehicle manufacturer. The parameter mask associated with each configuration parameter of the electronic control unit is empty at the time of manufacture (or even associated with an initial value or default value).
[0099] According to an embodiment of the present invention, the update module 201 may be configured to control subsequent updates of configuration parameters during operation of the vehicle 1 in response to an update command transmitted by the vehicle manufacturer and / or technical coordinator, which may be generated for different purposes in different contexts.
[0100] According to certain embodiments of the invention, the configuration parameters defining the configuration of the electronic control unit 10 can be updated specifically in response to an update command transmitted by a technical coordinator, or can be updated globally in response to an update command transmitted by a motor vehicle manufacturer—the updated parameters must then be manually updated. In other words, the first update interface 202 can be configured to simultaneously update one or more parameters in response to an update command transmitted by the technical coordinator and received from a first source 21 accessible to the technical coordinator.
[0101] The second update interface 203 can be configured to update at least some of the configuration parameters in the set of configuration parameters that define the configuration of the electronic control unit 10 in response to an update command transmitted by the vehicle manufacturer and received from a second source 24 accessible by the vehicle manufacturer.
[0102] According to some embodiments, the configuration of the electronic control unit 10 can be updated to allow for subscription options, unsubscription options, or bug fixes. Specifically, the configuration of the electronic control unit 10 can be updated at the request of the vehicle manufacturer to correct bugs or improve settings. For example, a bug could be an incorrect parameter setting, a stack overflow, a stack underflow, or a difference between normal and expected operation.
[0103] For example, at the request of the technical coordinator, the configuration of the electronic control unit 10 can be updated after the owner requests the activation of new options (e.g., tow hook, reversing camera, or after-sales alarm). Repainting the vehicle with a new color requires updating the parameters of the human-machine interface so that the vehicle representation on the passenger compartment display matches the new appearance of the vehicle.
[0104] According to some embodiments, the first programmable update interface 202 can be configured to read the state of a configuration mask in response to a read command transmitted by a technical coordinator and received from a first source 21. Specifically, the first programmable update interface 202 can be configured to read filter values associated with one or more configuration parameters in response to a read command transmitted by a technical coordinator and received from the first interface 202. Therefore, the first interface 202 allows for partial or global reading of parameter masks.
[0105] According to some embodiments, the first update interface 202 can be configured to modify filter values associated with one or more configuration parameters in response to an update command transmitted by a technical coordinator and received from a first source 21. This allows one or more automatic or manual parameters to be converted to one or more manual or automatic parameters. More specifically, modification of the filter value associated with an automatic parameter allows the parameter to be converted to a manual parameter (which is equivalent to performing an add operation on a parameter mask), and modification of the filter value associated with a manual parameter allows the parameter to be converted to an automatic parameter (which is equivalent to performing a remove operation on a parameter mask or even performing a remove operation on the filter value associated with the configuration parameter).
[0106] According to some embodiments, the first update interface 202 can be used to restore the initial values associated with configuration parameters, which correspond to the factory values initialized by the motor vehicle manufacturer during the manufacture of vehicle 1.
[0107] According to certain embodiments in which an update to the electronic control unit 10 is performed in order to unsubscribe from the option, the parameter mask associated with the configuration parameter corresponding to the unsubscribe option can be withdrawn, and the value associated with the configuration parameter can be reset to a value extracted from the manufacturer's configuration profile, updated to implement any possible latest modifications.
[0108] According to some embodiments, the second update interface 203 can be configured to update only automatic parameters, i.e., configuration parameters not protected by parameter masking, in response to an update command transmitted by the vehicle manufacturer and received from the second source 24. In other words, during a configuration parameter update at the request of the vehicle manufacturer, the automatic configuration parameters can be updated using the values indicated by the vehicle manufacturer in the update command received from the second source 24. Conversely, manually configured parameters that have been updated beforehand by the technical coordinator and are therefore protected by configuration masking will not be modified.
[0109] According to some embodiments, the second update interface 203 can be configured to, in response to an update command transmitted by the vehicle manufacturer and received from the second source 24, convert manual parameters back to automatic parameters by removing parameter masks associated with manual parameters. Advantageously, the removal of parameter masks allows the vehicle manufacturer to regain control over updates to the electronic control unit 10. The mask removal capability provided to the vehicle manufacturer via the second interface 203 may prove necessary in cases including when the vehicle manufacturer corrects errors.
[0110] According to some embodiments, the second update interface 24 can be configured to update the set of configuration parameters in response to a global update command transmitted by the vehicle manufacturer and received from the second source 24, while circumventing parameter shielding associated with the manual parameters of the set of configuration parameters. In other words, regardless of whether the set of configuration parameters is manual or automatic, i.e., regardless of whether the set of configuration parameters is protected by parameter shielding, the second update interface 24 can allow the vehicle manufacturer to modify the values associated with the set of configuration parameters through the second source 24. The ability to circumvent configuration shielding avoids the risk of errors requiring a vehicle recall by the manufacturer.
[0111] refer to Figure 3 An embodiment of the present invention further provides a method for controlling an electronic control unit 10 of a motor vehicle 1, the method comprising updating the configuration of the electronic control unit 10, the configuration being defined by a set of configuration parameters, at least one configuration parameter being associated with a parameter value and a filter value.
[0112] Initialization step 300 may include initializing the parameter values associated with the set of configuration parameters. Initialization step 300 may be performed by the vehicle manufacturer using the first source 21. In the initialization step, all parameters are automatic, and the parameter masks associated with the set of configuration parameters are initialized to represent values for blank fields.
[0113] Step 301, which involves updating from the first source, may include updating a parameter value associated with at least one configuration parameter via a first update interface in response to an update command transmitted by the technical coordinator and received from the first source 21.
[0114] Step 302 of updating the filter may include updating the filter value associated with the at least one configuration parameter via a first update interface in response to an update of the parameter value associated with the at least one configuration parameter. During the update of the filter value associated with the configuration parameter whose parameter value has been modified, the parameter is switched from an automatic parameter to a manual parameter and is protected by the parameter filter.
[0115] Step 303, where the update is performed by the second source, may include updating parameter values associated with at least some of the configuration parameters in the set of configuration parameters based on a filter value associated with the set of configuration parameters, in response to an update command transmitted by the vehicle manufacturer and received from the second source 24. Step 303 may be followed by step 301, where the values associated with the parameters updated in step 301 may be generated by initialization step 300 or by step 303 where the update is performed by the second source.
[0116] According to some embodiments, in step 303, the parameter values associated with the set of configuration parameters may be updated in response to an update command transmitted by the vehicle manufacturer and received from the second source 24, in such a way that only automatic parameters are updated. In other words, the automatic configuration parameters may be updated in step 303 using the values indicated by the vehicle manufacturer in the update command received from the second source 24. Conversely, manually configured parameters that have been updated beforehand by the technical coordinator and are therefore protected by configuration masking may not be modified in step 303.
[0117] According to some embodiments, in step 303, the parameter values associated with the set of configuration parameters may be updated in response to an update command transmitted by the vehicle manufacturer and received from the second source 24, by removing parameter masks associated with manual parameters to convert the manual parameters back to automatic parameters. Here, the command to remove the masks may involve a subset of manual parameters.
[0118] According to some embodiments, in step 303, the parameter values associated with the set of configuration parameters may be updated in response to an update command transmitted by the vehicle manufacturer and received from the second source 24, in a manner that parameter masking associated with the manual parameters of the set of configuration parameters is circumvented. This allows the parameter values associated with the manual parameters to be updated in response to an update command transmitted by the vehicle manufacturer and received from the second source 203. Here, masking circumvention may involve all manual parameters.
[0119] Figures 4 to 10 The steps of a method for controlling an electronic control unit 10 according to certain embodiments of the present invention are illustrated by timing diagrams and block structures, wherein the electronic control unit is a unit for controlling infotainment in a motor vehicle, the configuration is defined by ten parameters, denoted as p1 to p10, with a bit length ranging from 1 to 3 bits, and the first source 21 and the second source 24 use the UDS protocol.
[0120] Figure 4This is a schematic diagram illustrating an example of the structure of the set of parameters p1 to p10 and configuration mask 43. Configuration mask 43 includes the configuration identifier to which parameters p1 to p10 belong, the position of these parameters within their configuration identifiers (the specified configuration DID), and the bit size 42 of these parameters (here, from 1 to 3 bits). Configuration mask 43 can be programmed via a first source 21 through a first update interface accessible by a technical coordinator, and via a second source 24 through a second update interface accessible by the vehicle manufacturer. Figure 4 In this context, the parameter mask is empty, and the value associated with the parameter is associated with the initial value (predefined value or default value).
[0121] Figure 5 An example of a timing diagram illustrating the initialization of a set of configuration parameters p1 to p10 by a motor vehicle manufacturer 50 according to certain embodiments of the present invention is shown, wherein the initialization of parameter values associated with the set of parameters p1 to p10 uses a 'write data by identifier' service.
[0122] In step 500, the motor vehicle manufacturer 50 may submit a request to the first source 21 to load the configuration by indicating the configuration identifier 'DID=0x2003' and the initial data (i.e., factory data).
[0123] In step 501, the first source 21 can be configured to confirm that the configuration has been loaded after request 500.
[0124] In step 502, the vehicle manufacturer may request the first source to send the configuration loaded in step 500 to the electronic control unit 10 to initialize the configuration parameters by indicating the configuration identifier 'DID=0x2003'.
[0125] In step 503, the electronic control unit 10 may receive the command 'Write data by identifier DID=0x2003 data=factory data' via the first update interface 202 of the first source 21 accessible by the vehicle manufacturer during the initialization process at the factory. Steps 504 and 505 may be executed to indicate that the initialization of this set of configuration parameters has been completed.
[0126] Figure 6 It shows the relationship with Figure 5 Correspondingly, a schematic diagram of the configuration parameters p1 to p10 and the configuration shielding structure after the initialization step is shown. (See diagram below.) Figure 6 The parameter values associated with this set of parameters have been modified and correspond to the initial factory value 61. The configuration mask status has not been modified: all parameters p1 to p10 are considered automatic, and the associated masks are empty (or still associated with the initial values).
[0127] Figure 7 The illustration shows the installation of new options related to the required update of parameters p3, p6, and p8, according to certain embodiments, by the technical coordinator 70 through the first source 21 and the first update interface. Figure 7 An example of a timing diagram (not shown) for updating the configuration of the electronic control unit 10.
[0128] In step 700, the technical coordinator 70 may request the first source 21 to install a new option.
[0129] In step 701, the first source 21 can be configured to transmit an open session command to the electronic control unit 10, which can be configured to acknowledge receipt of the command in step 702.
[0130] In step 703, the electronic control unit 10 can be configured to receive the command 'Read data by identifier' with the identifier 'DID=0x2003' from the first source 21, and in step 704 confirm that reading data by identifier has been executed.
[0131] In step 705, the first source 21 can be configured to update parameters p3, p6, and p8 via the first update interface 202 by sending a command 'Write data by identifier' to the electronic control unit 10. Steps 706 and 707 can be performed to indicate to the first source and technical coordinator that the write data command has been executed and the parameters have been updated for the installation of the new option.
[0132] Figure 8 It shows the relationship with Figure 7 Correspondingly, a schematic diagram of the structure of the configuration parameters p1 to p10 and configuration mask 81 after the update step used to install new options. (See diagram below.) Figure 8 As shown, the parameter values associated with parameters p3, p6, and p8 have been modified and correspond to the value 80 updated by the technical coordinator. The shielding status associated with these parameters has been modified in response to the technical coordinator's update of the parameter values associated with these parameters. Parameters p3, p6, and p8 have become manual parameters protected by parameter shields 82, 83, and 84, respectively. The shielding status of the parameters associated with each of the other parameters p1, p2, p4, p5, p7, p9, and p10 has not changed; these parameters remain automatic parameters.
[0133] Figure 9 The demonstration shows the vehicle manufacturer 50 using the second source 24 and the second update interface ( Figure 9 (Not shown) An example of a timing diagram for updating the configuration of the electronic control unit 10, where updating the electronic control unit 10 includes updating the set of configuration parameters p1 to p10.
[0134] In steps 900 and 901, the vehicle manufacturer 50 can submit a configuration update request to the electronic control unit 10 via the second source 24, by indicating the configuration identifier 'DID=0x2003' and data equivalent to update data. This request can be made via the second update interface ( Figure 9 (Not shown in the text) to receive. ECU 10 can confirm the execution of the update with the second source 24 and the motor vehicle manufacturer in steps 902 and 903 respectively.
[0135] Figure 10 It shows the relationship with Figure 9 The timing diagram shown corresponds to the steps of updating the configuration at the request of the vehicle manufacturer, and is a schematic diagram of the configuration parameters p1 to p10 and the structure of the configuration shielding. (See also...) Figure 10 The parameter values associated with parameters p3, p6, and p8 shown have not been modified and correspond to the value 80 previously updated by the technical coordinator. Only automatic parameters p1, p2, p4, p5, p7, p9, and p10 are updated to the updated value 1000 in response to commands transmitted by the vehicle manufacturer.
[0136] This invention is not limited to the embodiments described above by way of non-limiting examples. It covers any variations of the embodiments that may be conceived by those skilled in the art.
[0137] Generally, routines executed to implement embodiments of the present invention, whether implemented in the context of an operating system or in the context of a particular application, component, program, object, module, or sequence of instructions, or even a subset thereof, can be represented as "computer program code" or simply "program code." Program code typically includes computer-readable instructions that reside at different times in various memories and storage devices within a computer, and when read and executed by one or more processors in the computer, cause the computer to perform operations necessary to implement the operations and / or elements specific to various aspects of embodiments of the present invention. The computer-readable instructions of a program for performing operations of embodiments of the present invention can be, for example, assembly language, or source code or object code written in combination with one or more programming languages.
Claims
1. A device (20) for controlling an electronic control unit (10) of a motor vehicle (1), the device comprising an update module (201) for updating the configuration of the electronic control unit (10), the configuration being defined by a set of configuration parameters, at least one configuration parameter being associated with a parameter value and a filter value, each configuration parameter being initialized as an automatic parameter, and each filter value being initialized as a null value, the filter value being used to indicate whether the at least one configuration parameter is an automatic parameter or a manual parameter, characterized in that, This update module (201) includes: - A first programmable update interface (202) is configured to update a parameter value associated with at least one configuration parameter in response to an update command received from a first source (21), and to update a filter value associated with the at least one configuration parameter in response to the update of the parameter value in order to convert the configuration parameter into a manual parameter; - A second programmable update interface (203) is configured to update the parameter values of automatic parameters associated with the configuration parameters based on filter values associated with at least some of the configuration parameters in the set of configuration parameters in response to an update command received from a second source (24). Automatic parameters are configuration parameters associated with parameter values updated in response to an update command received from the second source (24), and manual parameters are configuration parameters associated with parameter values updated in response to an update command received from the first source (21).
2. The device as described in claim 1, characterized in that, The parameter values associated with the set of configuration parameters are initialized to initial factory values and / or generated by previous updates.
3. The device as described in claim 1 or 2, characterized in that, The second programmable update interface (203) is configured to update the set of configuration parameters that define the configuration in response to an update command received from the second source (24).
4. The device as described in claim 1 or 2, characterized in that, The first programmable update interface (202) is configured to read filter values associated with one or more configuration parameters.
5. The device as described in claim 1 or 2, characterized in that, The first programmable update interface (202) is configured to modify the filter value associated with one or more configuration parameters to convert one or more automatic or manual parameters into one or more manual or automatic parameters.
6. The device as described in claim 1 or 2, characterized in that, The second programmable update interface (203) is configured to remove the filter value associated with a given configuration parameter.
7. The device as described in claim 1 or 2, characterized in that, The first source (21) is a diagnostic tool accessible to the vehicle manufacturer for initializing parameter values associated with the set of configuration parameters. The diagnostic tool is accessible to the technical coordinator for updating parameter values associated with at least one configuration parameter and, in response to the update, updating filter values associated with the at least one configuration parameter via the first programmable update interface (202).
8. The device as described in claim 1 or 2, characterized in that, The second source (24) is a remote update server accessible to the vehicle manufacturer for updating at least some of the configuration parameters in the set of configuration parameters.
9. A method for controlling an electronic control unit of a motor vehicle, the method comprising updating a configuration of the electronic control unit, the configuration being defined by a set of configuration parameters, at least one configuration parameter being associated with a parameter value and a filter value, each configuration parameter being initialized as an automatic parameter, and each filter value being initialized as a null value, the filter value being used to indicate whether the at least one configuration parameter is an automatic parameter or a manual parameter, characterized in that, The method includes the following steps: - Initialize (300) the parameter values associated with the set of configuration parameters to their initial factory values; - In response to an update command received from a first source, update (301) the parameter value associated with at least one configuration parameter via a first programmable update interface; - In response to an update of the parameter value associated with at least one configuration parameter, update (302) the filter value associated with the at least one configuration parameter via the first programmable update interface to convert the configuration parameter into a manual parameter; - In response to an update command received from a second source, the parameter values of the automatic parameters associated with the configuration parameters are updated (303) via a second programmable update interface based on filter values associated with at least some of the configuration parameters in the set of configuration parameters. Automatic parameters are configuration parameters associated with parameter values updated in response to an update command received from the second source (24), and manual parameters are configuration parameters associated with parameter values updated in response to an update command received from the first source (21).