Vehicle control system

By configuring an MPU and adding a firewall in the vehicle control system to build an internal communication path, the problems of insufficient data transmission and security in the vehicle communication system are solved, and high-speed and secure data transmission and software updates are achieved.

CN116032959BActive Publication Date: 2025-09-16HONDA MOTOR CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202211291594.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-26
Filing Date
2022-10-19
Publication Date
2025-09-16
Estimated Expiration
2042-10-19

AI Technical Summary

Technical Problem

In the prior art, in-vehicle communication systems have deficiencies in data transmission and security, especially in vehicles with driving assistance functions. The size of update data increases and the security of external communications is threatened, which may lead to illegal access.

Method used

By configuring the MPU as the second control unit in the vehicle control system, connecting the CGW and ADAS, adding a firewall, and building a high-speed communication path through the internal communication path IL2 and the communication path L11, data transmission speed and security are ensured.

Benefits of technology

It improves the data transmission speed and security of the vehicle communication system without increasing costs, inhibits illegal access, reduces energy and power consumption, and improves the efficiency of software updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032959B_ABST
    Figure CN116032959B_ABST
Patent Text Reader

Abstract

The present invention provides a vehicle-mounted control system (10a), comprising: an ADAS (11), an MPU (12) connected to the ADAS (11) via a communication path (L1), and a CGW (13) connected to the MPU (12) via a communication path (L11). The MPU (12) has an internal communication path (IL2) capable of connecting the communication path (L1) and the communication path (L11). When the vehicle (1) is in a predetermined operating state, the communication path (L1) and the communication path (L11) are connected via the internal communication path (IL2).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a vehicle-mounted control system having a plurality of ECUs connected via a vehicle-mounted communication network. Background Art

[0002] As such a device, there is a known device that downloads update data for updating software in an electronic control device of a vehicle from an external server and installs it in the electronic control device (see Patent Document 1). In the device described in Patent Document 1, an update management unit connected to the Internet provides the update data downloaded from the external server to the electronic control device via the Internet.

[0003] However, in recent years, the size of update data in vehicles equipped with driver assistance functions has increased. Furthermore, drivers are prioritizing the security of external communications. Therefore, there is a desire to establish an in-vehicle communication network that balances efficient data transmission with security. However, the device described in Patent Document 1 presents the possibility of unauthorized access to the electronic control unit through an update management unit connected to the internet.

[0004] Prior art literature

[0005] Patent Literature

[0006] Patent Document 1: Japanese Patent Application Publication No. 2021-105924 (JP 2021-105924 A). Summary of the Invention

[0007] An in-vehicle control system according to one embodiment of the present invention is mounted on a vehicle and includes: a first control unit; a second control unit connected to the first control unit via a first communication path; and a third control unit connected to the second control unit via a second communication path. The second control unit has an internal communication path capable of connecting the first and second communication paths, and when the vehicle is in a predetermined operating state, the first and second communication paths are connected via the internal communication path. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] The objects, features and advantages of the present invention will be further clarified through the following description of the embodiments in conjunction with the accompanying drawings.

[0009] Figure 1A It is a diagram showing a reference example of an in-vehicle control system.

[0010] Figure 1B It shows Figure 1A A diagram showing an example of the configuration of an in-vehicle control system.

[0011] Figure 2 This is a diagram showing an example of the configuration of an in-vehicle control system according to an embodiment of the present invention.

[0012] Figure 3 This is a block diagram showing the main configuration of a software updating device according to an embodiment of the present invention.

[0013] Figure 4 It is shown by Figure 3 A flowchart of an example of processing executed by a computing unit of a software updating device.

[0014] Figure 5 This is a diagram showing another example of the configuration of the vehicle-mounted control system according to the embodiment of the present invention.

[0015] Figure 6 This is a block diagram showing an example of the configuration of an in-vehicle control system according to a modified example of the embodiment of the present invention. DETAILED DESCRIPTION

[0016] The following reference Figures 1A to 6 An embodiment of the present invention will be described. The vehicle-mounted control system according to the embodiment of the present invention can be applied to a vehicle equipped with a driving assistance system (Advanced Driver-Assistance Systems: ADAS).

[0017] First, the vehicle-mounted control system will be described. Figure 1A FIG is a diagram showing a reference example of a vehicle-mounted control system. Figure 1A As shown, an in-vehicle control system 10 is mounted on a vehicle 1. The in-vehicle control system 10 is communicatively connected to an external device such as a server 3 via a network 2. The network 2 includes not only public wireless communication networks but also closed communication networks established for each specified management area, such as wireless LANs (local area networks), Wi-Fi (registered trademark), and Bluetooth (registered trademark). Figure 1B It shows Figure 1A FIG. 1 is a diagram showing a reference example of the configuration of the vehicle-mounted control system 10. Figure 1B As shown, the vehicle control system 10 includes ECUs (Electronic Control Units) 11 to 14. Furthermore, the vehicle control system 10 includes multiple vehicle communication networks connected via CAN (Controller Area Network), specifically, a vehicle communication network including ECUs 311 and 312 and a vehicle communication network including ECUs 321 and 322.

[0018] ECU 14 is a communication unit (TCU: Telematics Control Unit) that wirelessly communicates with external devices such as server 3 via network 2. ECU 13 is a CGW (Central Gateway) with gateway functionality. ECU (CGW) 13 relays communications between external devices and the in-vehicle communication network, or between multiple in-vehicle communication networks, conducted via ECU (TCU) 14. CGW 13 also oversees various control functions necessary for driving vehicle 1, including powertrain control and chassis control.

[0019] The ECU 12 is an MPU (Map Positioning Unit) that generates high-precision map information (maps with more information than those used in navigation systems) (hereinafter referred to as map data). The ECU (MPU) 12 includes a storage unit (not shown) in which it stores the generated map data. If the storage unit contains map data that overlaps with the generated map data, the MPU 12 updates the map data stored in the storage unit with the generated map data. In response to a request from the ECU 11, the MPU 12 reads the map data from the storage unit and supplies it to the ECU 11.

[0020] ECU11 is an ADAS ECU (hereinafter referred to as ADAS) that realizes the driving assistance function (ADAS) possessed by vehicle 1. The camera 21 is connected to the ECU (ADAS) 11 via an LVDS (Low Voltage Differential Signaling) signal line. In addition, the radar 22 is connected to ADAS11 via CAN-FD (CAN with Flexible Data Rate). ADAS11 controls the actuators used for driving based on the information (map data) supplied from MPU12 and the information detected by the camera 21 and the radar 22. For example, the steering actuator that drives the steering device is controlled so that the vehicle 1 does not deviate from the lane in which it is traveling. In this way, ADAS11 realizes the driving assistance function possessed by vehicle 1.

[0021] ADAS 11 and CGW 13, CGW 13 and MPU 12, and MPU 12 and TCU 14 are connected via communication paths L1, L2, and L3, respectively. Communication paths L1, L2, and L3 are formed by communication lines that are faster than CAN and CAN-FD, such as Ethernet lines.

[0022] CGW 13 has an internal communication path IL1 that can connect communication path L1 and communication path L2. Furthermore, CGW 13 includes an Ethernet switch (not shown) and controls the Ethernet switch to connect or disconnect internal communication path IL1. MPU 12 has an internal communication path IL2 that can connect communication path L2 and communication path L3. MPU 12 includes an Ethernet switch (not shown) and controls the Ethernet switch to connect or disconnect internal communication path IL2.

[0023] The server 3 includes a storage unit (not shown) that stores data (hereinafter referred to as update data) used to update the software (programs) executed by each ECU of the vehicle-mounted control system 10. The server 3 stores at least the update data for the software executed by the ADAS 11. The vehicle-mounted control system 10 downloads the update data for each ECU from the server 3 via the network 2 and supplies it to each ECU, thereby updating the software in each ECU.

[0024] In recent years, with the development of ADAS and interoperability features, the amount of data sent and received between the vehicle-mounted control system 10 and external devices, as well as the amount of data sent and received between the various vehicle-mounted communication networks within the vehicle-mounted control system 10, has increased. Furthermore, the data size of the software installed on each ECU responsible for these functions has also increased. Furthermore, in ADAS and interoperability features, the security of communications with external devices has become increasingly important. To address these challenges, further improvements in the data transmission performance and security of the vehicle-mounted control system 10 are required. Therefore, this embodiment configures the vehicle-mounted control system as follows.

[0025] Figure 2 1 is a diagram showing an example of the configuration of a vehicle-mounted control system according to an embodiment of the present invention. Figure 2 In the vehicle-mounted control system 10a shown, Figure 1B In the vehicle-mounted control system 10, the MPU 12 disposed between the TCU 14 and the CGW 13 is disposed at a position downstream of the CGW 13. Specifically, the MPU 12 is disposed between the CGW 13 and the ADAS 11. In the following, the side close to the TCU 14 is represented as the upstream side, and the side away from the TCU 14 is represented as the downstream side. In this way, by disposing the MPU 12 on the downstream side of the CGW 13, a firewall can be added on the downstream side of the CGW 13. In more detail, by setting a firewall on the MPU 12 disposed on the downstream side of the CGW 13, a firewall can be added on the downstream side of the CGW 13. As a result, it is easy to suppress illegal access to the ADAS 11 via the CGW 13.

[0026] Also, such as Figure 2 In this way, by moving MPU12 to the downstream side of CGW13 and using Figure 1BThe high-speed communication path (Ethernet line) L12 directly connects the CGW 13 and TCU 14, thereby increasing the data transmission speed between the CGW 13 and TCU 14. It should be noted that the communication path L12 only needs to be a communication path that is at least higher than CAN and CAN-FD, and can also have a communication capacity equivalent to that of the communication paths L2 and L3.

[0027] MPU12 is connected to ADAS11 via communication path L1 and is connected to CGW13 via communication path L11. MPU12 can connect communication path L1 and communication path L11 via internal communication path IL2. Thus, CGW13 and ADAS11 can be connected via communication path CL1 constructed by communication path L1, MPU12 (internal communication path IL2) and communication path L11. Figure 1B By adding the communication path L11 to the structure, the MPU 12 can be arranged between the CGW 13 and the ADAS 11 without reducing the data transmission speed between the CGW 13 and the ADAS 11. It should be noted that the communication path L11 has a communication capacity greater than that of the communication path L1.

[0028] Furthermore, by disposing the MPU 12 with the internal communication path IL2 between the CGW 13 and the ADAS 11, the CGW 13 and ADAS 11 can be connected or disconnected as needed. For example, when installing software only in the ADAS 11, the internal communication path IL2 is set to the connected state, connecting the CGW 13 and ADAS 11. Otherwise, the internal communication path IL2 is set to the disconnected state, disconnecting the CGW 13 and ADAS 11. This makes it easier to prevent unauthorized access to the ADAS 11 via the CGW 13.

[0029] Figure 3 This is a block diagram showing the main configuration of a software updating device according to an embodiment of the present invention. Figure 3 The software updating device 100 constitutes a part of the vehicle-mounted control system 10a. Figure 3As shown, the software update device 100 includes a computer having a computing unit 110 such as a CPU (central processing unit), a ROM (read-only memory), a RAM (random access memory), a storage unit 120 such as a hard disk, and other peripheral circuits. The computing unit 110 includes a command receiving unit 111, a data acquisition unit 112, a status determination unit 113, a path construction unit 114, and a data supply unit 115 as functional components. The command receiving unit 111, the data acquisition unit 112, the status determination unit 113, and the path construction unit 114 are configured by a CPU (not shown) included in the MPU 12. The data supply unit 115 is configured by a CPU (not shown) included in the CGW 13. It should be noted that the computing unit 110 can be configured by a single CPU (a CPU included in a single ECU) or, as described above, by combining CPUs included in multiple ECUs. Furthermore, the storage unit 120 can be configured by a ROM included in a single ECU or by combining ROMs included in multiple ECUs.

[0030] The command receiving unit 111 receives update commands for updating the software of each ECU in the vehicle-mounted control system 10a. The update command includes information about the ECU to be updated (e.g., identification information of the target ECU) and information identifying the location where the updated data is stored (e.g., a URL). The command receiving unit 111 can receive update commands from an external device via the TCU 14 or from an unillustrated operating unit (e.g., a liquid crystal display with a touch panel) provided in the vehicle 1 in response to user operation.

[0031] The data acquisition unit 112 acquires update data for updating the software of each ECU from an external device or the like based on the update command received by the command reception unit 111. For example, if the update command indicates that the ECU to be updated is the ADAS 11 and that the update data is stored in the server 3, the data acquisition unit 112 downloads and acquires the update data for the ADAS 11 stored in the storage unit (not shown) of the server 3.

[0032] The state determination unit 113 determines whether the vehicle 1 is in a predetermined operating state. The predetermined operating state is a state in which the software update process (program rewriting) of the ADAS 11 can be performed, for example, a state in which the vehicle 1 is stopped and the ignition switch is off.

[0033] When the state determination unit 113 determines that the vehicle 1 is in the specified operating state, the path construction unit 114 constructs a communication path for supplying update data to the ADAS 11. Specifically, the path construction unit 114 sets the internal communication path IL2 to the connected state, connecting the communication paths L1 and L11. On the other hand, when the state determination unit 113 determines that the vehicle 1 is not in the specified operating state, the path construction unit 114 sets the internal communication path IL2 to the disconnected state, disconnecting the communication paths L1 and L11. For example, when the ignition switch is turned on, the state determination unit 113 determines that the vehicle 1 is not in the specified operating state. The initial state of the internal communication path IL2 is disconnected.

[0034] The data supply unit 115 supplies the update data acquired by the data acquisition unit 112 to the ADAS 11 via the communication path CL1 established by the path construction unit 114 and installs the software. More specifically, the data supply unit 115 expands the update data in the ADAS ROM (not shown) and updates the software of the ADAS 11.

[0035] Figure 4 This flowchart illustrates an example of processing executed by the computing unit 110 of the software update device 100 according to a pre-stored program. The processing illustrated in this flowchart begins, for example, when power is supplied to the in-vehicle control system 10a and is repeated at a predetermined interval. The following example uses the case where the software update device 100 downloads update data stored in the storage unit of the server 3, thereby updating the software of the target ECU.

[0036] First, in step S1, it is determined whether an update command has been received. If the answer to step S1 is negative (S1: No), the process ends. If the answer to step S1 is positive (S1: Yes), the update data is acquired in step S2. Specifically, based on the information included in the update command, the update data is downloaded from the storage unit of server 3. The downloaded update data is stored in storage unit 120.

[0037] In step S3, a determination is made as to whether the communication path required for software installation, i.e., communication path CL1, needs to be established. If step S3 is negative (S3: No), the process proceeds to step S5. If step S3 is positive (S3: Yes), communication path CL1 is established in step S4. For example, if the update command received in step S1 includes information indicating that ADAS 11 is the target of a software update, step S3 determines that communication path CL1 needs to be established. Then, in step S4, when the vehicle 1 is in a specified operating state, the internal communication path IL2 is set to a connected state, connecting communication path L1 and communication path L11. At this time, the internal communication path IL1 is also set to a connected state, connecting communication path L11 and communication path L12. These communication paths are established when the ignition switch is turned off, for example, by the software update device 100 activating the ECUs 11 to 14. It should be noted that the internal communication path IL1 can also be set to a connected state at all times while power is being supplied to the in-vehicle control system 10a.

[0038] In step S5 , the update data downloaded in step S1 is read from the storage unit 120 and expanded in the ROM of the ADAS 11 , thereby updating the software of the ADAS 11 .

[0039] The embodiments of the present invention can achieve the following effects.

[0040] (1) The vehicle-mounted control system 10a is mounted on the vehicle 1 and includes: an ADAS 11 as a first control unit; an MPU 12 as a second control unit connected to the ADAS 11 via a first communication path (communication path L1); and a CGW 13 as a third control unit connected to the MPU 12 via a second communication path (communication path L11). The MPU 12 generates map data and supplies the map data to the ADAS 11 via the communication path L1. The MPU 12 has a first internal communication path (internal communication path IL2) that can connect the communication paths L1 and L11. When the vehicle 1 is in a predetermined operating state, the MPU 12 connects the communication paths L1 and L11 via the internal communication path IL2.

[0041] With this configuration, the communication path for supplying data from the CGW 13 to the ADAS 11 is established by combining the internal communication path IL2 of the MPU 12 and the communication path L1 used to supply map data from the MPU 12 to the ADAS 11. Therefore, there is no need to establish a separate communication path directly connecting the CGW 13 and the ADAS 11; simply adding the communication path L11 allows data to be supplied from the CGW 13 to the ADAS 11. This helps minimize cost increases for the in-vehicle control system 10a.

[0042] Furthermore, by disposing the MPU 12 between the CGW 13 and the ADAS 11 , a firewall can be added on the downstream side of the CGW 13 . Figure 5 FIG. 1 is a diagram showing another example of the configuration of the vehicle-mounted control system according to the embodiment of the present invention. Figure 5 Shown in Figure 2 This is an example of a case where the MPU 12, CGW 13, and TCU 14 of the vehicle-mounted control system 10a are each provided with a firewall FW. Figure 5 As shown, by installing a firewall FW in the MPU 12 disposed between the CGW 13 and the ADAS 11 , a firewall can be added downstream of the CGW 13 . As a result, unauthorized access to the ADAS 11 from external devices or other in-vehicle communication networks via the CGW 13 can be suppressed.

[0043] (2) When rewriting the ADAS 11 program, the MPU 12 connects the communication path L1 and the communication path L11 via the internal communication path IL2. This configuration allows update data for rewriting the ADAS 11 program to be supplied from the CGW 13 via the MPU 12 to the ADAS 11. Furthermore, since the communication paths L1 and L11 are connected only when rewriting the ADAS 11 program, unauthorized access to the ADAS 11 from external devices or other in-vehicle communication networks via the CGW 13 can be suppressed.

[0044] (3) ADAS11, MPU12, and CGW13 are connected to each other via a third communication path (communication path L13) whose communication capacity is smaller than any of the communication paths L1, L11, and the internal communication path IL2. Through this configuration, the communication path can be switched based on the capacity of the data transmitted between ADAS11, MPU12, and CGW13. For example, when transmitting relatively small data such as commands and control data between ADAS11, MPU12, and CGW13, communication path L13 is used. When transmitting relatively large data such as update data, the communication path constructed by communication path L1, MPU12 (internal communication path IL2), and communication path L11 is used. As a result, the power consumption required to transmit data can be reduced.

[0045] (4) The vehicle-mounted control system 10a also has a TCU14 that can communicate with an external device of the vehicle 1 (such as a server 3). CGW13 obtains update data for rewriting the program of ADAS11 from the external device via TCU14. Through this structure, CGW13 can obtain update data from the external device and can flexibly update the software of ADAS11. In addition, CGW13 and TCU14 are connected via a fourth communication path (communication path L12) having a communication capacity greater than that of communication path L13. Through this structure, the time (download time) required for CGW13 to download update data from the external device can be shortened. Therefore, the energy efficiency required for software updates can be improved.

[0046] The above embodiment can be modified in various ways. The following describes a modified example. In the above embodiment, the vehicle-mounted control system 10a having an MPU 12 that supplies map data to the ADAS 11 is used as an example. However, the present invention can also be applied to a vehicle-mounted control system having an ECU (hereinafter referred to as an identification extension unit (ADAS Perception Extension: APEX)) that supplies information about the driving road of the vehicle 1 (hereinafter referred to as driving road information) to the ADAS 11. Figure 6 This is a block diagram showing an example of the configuration of the vehicle-mounted control system according to this modification.

[0047] like Figure 6 As shown, the in-vehicle control system 10b includes an ADAS 11, an ECU (APEX) 15, and a CGW 13. A camera 23 is connected to the APEX 15 via a communication path L14. The camera 23 captures the space surrounding the vehicle 1 (e.g., the space in front) and outputs the captured image data to the APEX 15 via the communication path L14. The communication path L14 is, for example, an LVDS signal line and has a greater communication capacity than the communication path L13.

[0048] APEX15 identifies the driving road of vehicle 1 based on the captured image data input from camera 23, and outputs the driving road information including the recognition result to ADAS11 via communication path L1. In addition, APEX15 has an internal communication path IL3 that can connect communication path L1 and communication path L11. In addition, APEX15 has an Ethernet switch (not shown) and controls the Ethernet switch to set the internal communication path IL3 to a connected state or a disconnected state. ADAS11 controls the actuators used for the vehicle 1 based on the information (driving road information) supplied by APEX15 so that the vehicle 1 does not deviate from the lane in which it is traveling. In this way, in this modified example, ADAS11 realizes the driving assistance function of vehicle 1 based on the driving road information supplied from APEX15.

[0049] The structure and operation of the software update device constituting a part of the vehicle-mounted control system 10b are similar to those of the vehicle-mounted control system 10b. Figure 3 The structure and operation of the software updating device 100 are the same as those of the modified example. It should be noted that in the software updating device of this modified example, when the state determination unit 113 determines that the vehicle 1 is in a predetermined operating state, the path construction unit 114 sets the internal communication path IL3 to the connected state, thereby connecting the communication paths L1 and L11. Furthermore, when the state determination unit 113 determines that the vehicle 1 is not in the predetermined operating state, the path construction unit 114 sets the internal communication path IL3 to the disconnected state, thereby disconnecting the communication paths L1 and L11.

[0050] This configuration allows data to be supplied from the ADAS 11 to the CGW 13 via the communication path CL2 constructed by the communication path L1, the APEX 15 (internal communication path IL3), and the communication path L11. This eliminates the need for a separate communication path directly connecting the ADAS 11 and the CGW 13. This reduces the cost of the in-vehicle control system 10b. Furthermore, by providing a firewall in the APEX 15, located between the ADAS 11 and the CGW 13, the security of data supplied to the ADAS 11 from external devices and the in-vehicle communication network can be enhanced.

[0051] Furthermore, in the above embodiment, the Ethernet switch included in the MPU 12 connects or disconnects the internal communication path IL1. However, a network device other than the Ethernet switch may connect or disconnect the first internal communication path. Similarly, the Ethernet switches included in the ECUs 13 and 15 (CGW 13 and APEX 15) connect or disconnect the internal communication paths IL2 and IL3. However, a network device other than the Ethernet switch may connect or disconnect the second internal communication path.

[0052] In addition, in the above embodiment, the configuration of the vehicle-mounted control system 10b is described by taking the case where the camera 23 serving as the shooting unit is connected to the APEX15 via the LVDS signal line, i.e., the fifth communication path (communication path L14), as an example. However, the fifth communication path can be a communication line (signal line) having a communication capacity greater than that of the communication path L13, and can also be connected via other communication lines (signal lines).

[0053] One or more of the above-described embodiments and modifications may be arbitrarily combined, and modifications may be combined with each other.

[0054] By adopting the present invention, it is possible to form an in-vehicle communication network that can take into account both safety and efficient data transmission.

[0055] The present invention has been described above with reference to preferred embodiments. However, it will be understood by those skilled in the art that various modifications and changes can be made without departing from the scope of the claims set forth below.

Claims

1. A vehicle-mounted control system, which is a vehicle-mounted control system mounted on a vehicle, characterized in that: have: a first control unit (11); a second control unit (12) connected to the first control unit (11) via a first communication path (L1); and a third control unit (13) connected to the second control unit (12) via a second communication path (L11); and an instruction receiving unit (111) for receiving an update instruction for updating the software of the first control unit (11), The second control unit (12) includes an internal communication path (IL2) capable of connecting the first communication path (L1) and the second communication path (L11), and a network device for switching the internal communication path (IL2) between a connected state and a disconnected state. The second control unit (12) further controls the network device to set the internal communication path (IL2) to a disconnected state when the ignition switch is turned on, and when the ignition switch of the vehicle is turned off, the instruction receiving unit (111) receives the update instruction, controls the network device, and sets the internal communication path (IL2) to a connected state.

2. The vehicle-mounted control system according to claim 1, characterized in that: The first control unit (11), the second control unit (12), and the third control unit (13) are connected to each other via a third communication path (L13) having a communication capacity smaller than that of the first communication path (L1), the second communication path (L11), and the internal communication path (IL2).

3. The vehicle-mounted control system according to claim 2, characterized in that: It also includes a communication unit (14) capable of communicating with an external device (3) of the vehicle (1). The third control unit (13) and the communication unit (14) are connected via a fourth communication path (L12) having a larger communication capacity than the third communication path (L13).

4. The vehicle-mounted control system according to claim 3, characterized in that: The third control unit (13) obtains update data for rewriting the program of the first control unit (11) from the external device (3) via the communication unit (14).

5. The vehicle-mounted control system according to claim 4, characterized in that: The internal communication path (IL2) is a first internal communication path, The third control unit (13) has a second internal communication path (IL1) capable of connecting the second communication path (L11) and the fourth communication path (L12), The second control unit (12), the third control unit (13) and the communication unit (14) are provided with a firewall (FW). The firewall (FW) of the second control unit (12) is arranged on the first internal communication path (IL2), The firewall (FW) of the third control unit (13) is provided on the second internal communication path (IL1), The third control unit (13) supplies the update data obtained from the external device (3) via the firewall (FW) of the communication unit (14) and the fourth communication path (L12) to the first control unit (11) via the second internal communication path (IL1), the second communication path (L11), the first internal communication path (IL2) and the first communication path (L1).

6. The vehicle-mounted control system according to any one of claims 1 to 5, characterized in that: The second control unit (12) is an electronic control unit that generates map data.

7. The vehicle-mounted control system according to claim 6, characterized in that: The second control unit supplies the map data to the first control unit (11) via the first communication path (L1).

8. The vehicle-mounted control system according to any one of claims 2 to 5, characterized in that: The second control unit (12) is an electronic control unit for identifying the driving road of the vehicle. A fifth communication path (L14) having a communication capacity greater than that of the third communication path (L13) is connected to a photographing unit (23) that outputs photographic image data of the periphery of the vehicle (1), the photographic image data is obtained from the photographing unit (23) via the fifth communication path (L14), and the photographic image data is supplied to the first control unit (11) via the first communication path (L1).

Citation Information

Patent Citations

  • Vehicle and software update method

    JP2021105924A

  • Programming vehicle modules from remote devices and related methods and systems

    US20150121071A1

  • Software Update Device and Software Update System

    US20190354363A1

  • Configuring a firewall system in a vehicle network

    US20190394089A1

  • Anomaly detection device, in-vehicle network system, and anomaly detection method

    US20200304532A1