Information processing apparatus and information processing method

By setting multiple software areas and data areas in the information processing device, the problem of inconsistent data structures when the vehicle software is updated and rolled back is solved, and the vehicle operates normally after the software is rolled back is achieved.

CN119998788APending Publication Date: 2025-05-13SONY GROUP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380071365.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-14
Filing Date
2023-09-25
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

After the vehicle's software is updated, the modification of the data structure causes the software to fail to maintain consistency with the previous version of the software when it is rolled back, resulting in the vehicle being unable to operate normally.

Method used

An information processing device and method are designed to ensure that the data structure can be correctly restored when the software is rolled back by setting multiple software areas and data areas in the storage unit, storing the current software and old software respectively, and compatible data.

Benefits of technology

It realizes the consistency of data structures during software update and rollback, ensuring that the vehicle can operate normally after software rollback.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119998788A_ABST
    Figure CN119998788A_ABST
Patent Text Reader

Abstract

The present technology pertains to an information processing device and an information processing method that make it possible to appropriately roll back software. An information processing apparatus according to the present invention comprises: a software management unit that manages software; and a storage unit including a first software area, a second software area, a first data area corresponding to the first software area, and a second data area corresponding to the second software area. The software management unit stores current software in one software area, stores past software in another software area, stores data in a format corresponding to the current software in one data area, and stores data in a format corresponding to the past software in another data area. The present technology can be applied to, for example, a vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present technology relates to an information processing device and an information processing method, and more particularly, to an information processing device and an information processing method that ensure appropriate software rollback. Background Art

[0002] A method has been proposed in which, in the event of cancelling a program update of a plurality of onboard electronic control units (ECUs), a cancellation and rollback method for each ECU is managed to maintain the overall health of the software of the onboard system (eg, see Patent Document 1).

[0003] Reference List

[0004] Patent Literature

[0005] Patent Document 1: Japanese Patent Application Publication No. 2020-27630 Summary of the invention

[0006] Problems to be solved by the present invention

[0007] It is assumed that the invention disclosed in Patent Document 1 is based on the system configuration of a conventional vehicle using a large number of single-function and highly independent ECUs. In addition, for conventional vehicles, the data structure is an important element of the software and is generally not modified from the time of shipment.

[0008] On the other hand, in the future, it is predicted that in high-performance vehicles such as connected cars, a high-performance system on chip (SoC) will be used in the ECU, thereby consolidating the ECU and increasing its functionality. Thus, as vehicles become increasingly software-driven, it is predicted that not only will software control increase, but also various kinds of operating data (such as user preference settings) will be retained, and the amount of data will increase, similar to modern personal computers (PCs) and smartphones.

[0009] Thus, as seen in PCs and smartphones, it is predicted that as software continues to evolve, data structures will be modified to keep pace with the software evolution. Where data structures have been modified, a process known as data migration will need to be performed immediately following a software update to tailor the structure of the retained data to the new software.

[0010] On the other hand, for in-vehicle software, rolling back to the previous version of the software is mandatory as an emergency measure in the event of a failure during or after an update.

[0011] However, when data migration is performed on a new version of software to modify a data structure, in the case where a rollback is performed, consistency with the previous version of software may not be maintained, and the vehicle may not operate normally.

[0012] The present technology is made in view of such situations and is intended to ensure proper software rollback.

[0013] Solution to the problem

[0014] According to the first aspect of the present technology, an information processing device includes: a software management unit, which manages software; and a storage unit, which includes a first software area, a second software area, a first data area corresponding to the first software area, and a second data area corresponding to the second software area, wherein the software management unit stores a first current software as an execution target in one of the first software area or the second software area, stores a first old software as a software version previous to the first current software in another software area, stores data in a format compatible with the first current software in a data area corresponding to the one software area in the first data area or the second data area, and stores data in a format compatible with the first old software in another data area.

[0015] An information processing method according to a second aspect of the present technology enables an information processing device to perform processing, the processing comprising: storing current software as an execution target in one of a first software area or a second software area of ​​a storage unit, and storing old software as a software version previous to the current software in another software area; and storing data in a format compatible with the current software in a data area corresponding to the one software area in the first data area or the second data area of ​​the storage unit, and storing data in a format compatible with the old software in another data area.

[0016] According to the first aspect or the second aspect of the present technology, current software as an execution target is stored in one of the first software area or the second software area of ​​a storage unit, and old software as a software version previous to the current software is stored in another software area, and data in a format compatible with the current software is stored in a data area corresponding to one of the first data area or the second data area of ​​the storage unit, and data in a format compatible with the old software is stored in another data area. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a block diagram illustrating a configuration example of a NOR (Non-OR) flash memory system.

[0018] Figure 2 is a block diagram illustrating a configuration example of a NAND (NAND) flash memory system.

[0019] Figure 3is a diagram illustrating a first data configuration example of a NAND flash memory of a NAND flash memory system.

[0020] Figure 4 is a diagram illustrating a second data configuration example of a NAND flash memory of a NAND flash memory system.

[0021] Figure 5 is a block diagram illustrating a configuration example of a vehicle control system.

[0022] Figure 6 is a diagram illustrating an example of a sensing area.

[0023] Figure 7 is a block diagram illustrating a configuration example of an information processing system to which the present technology is applied.

[0024] Figure 8 is a block diagram illustrating a configuration example of a high-performance ECU.

[0025] Fig. 9 is a block diagram illustrating a configuration example of a legacy ECU.

[0026] Fig.10 is a sequence diagram for describing a first embodiment of a firmware (FW) update process for a high-performance ECU.

[0027] Fig.11 is a diagram illustrating an example of a state of a flash memory of a high-performance ECU during the first embodiment of the FW update process of the high-performance ECU.

[0028] Fig.12 This is a sequence diagram for describing the startup process of a high-performance ECU.

[0029] Fig.13 is a diagram illustrating an example of a state of a flash memory of a high-performance ECU during a startup process of the high-performance ECU.

[0030] Fig.14 It is a sequence diagram for describing the rollback process of a high-performance ECU.

[0031] Fig.15 is a diagram illustrating an example of a state of a flash memory of a high-performance ECU during a rollback process of the high-performance ECU.

[0032] Fig.16 It is a sequence diagram used to describe the backup process of a high-performance ECU.

[0033] Fig.17 is a diagram illustrating an example of a state of a flash memory of a high-performance ECU during a backup process of the high-performance ECU.

[0034] Fig.18 is a sequence diagram for describing the second embodiment of the FW update process of the high-performance ECU.

[0035] Fig.19 is a diagram illustrating an example of a state of a flash memory of a high-performance ECU during the second embodiment of the FW update process of the high-performance ECU.

[0036] Fig. 20 is a sequence diagram for describing the first embodiment of the FW update process of the legacy ECU.

[0037] Fig.21 is a sequence diagram for describing the first embodiment of the FW update process of the legacy ECU.

[0038] Fig. 22 is a diagram illustrating an example of the states of the flash memory of the high-performance ECU and the flash memory of the legacy ECU during the first embodiment of the FW update process of the legacy ECU.

[0039] Fig.23 This is a sequence diagram for describing the rollback process for legacy ECUs.

[0040] Fig.24 is a diagram illustrating an example of the states of the flash memory of the high-performance ECU and the flash memory of the legacy ECU during the rollback process of the legacy ECU.

[0041] Fig.25 This is a sequence diagram used to describe the data backup process of legacy ECUs.

[0042] Fig.26 is a diagram illustrating an example of the states of the flash memory of the high-performance ECU and the flash memory of the legacy ECU during the data backup process of the legacy ECU.

[0043] Fig. 27 is a sequence diagram for describing the second embodiment of the FW update process of the legacy ECU.

[0044] Fig.28 is a sequence diagram for describing the second embodiment of the FW update process of the legacy ECU.

[0045] Fig.29 is a diagram illustrating an example of the states of the flash memory of the high-performance ECU and the flash memory of the legacy ECU during the second embodiment of the FW update process of the legacy ECU.

[0046] Fig.30 is a block diagram illustrating a configuration example of a computer. DETAILED DESCRIPTION

[0047] Hereinafter, a mode for carrying out the present technology will be described. The description will be given in the following order.

[0048] 1. Background of this technology

[0049] 2. Configuration example of vehicle control system

[0050] 3. Example

[0051] 4. Variant

[0052] 5. Others

[0053] 《1. Background of this technology》

[0054] First, refer to Figures 1 to 4 Describe the background of the present technology.

[0055] Figure 1 The diagram shows a configuration example of a NOR flash memory system 2001 applied to a conventional vehicle. The NOR flash memory system 2001 includes a central processing unit (CPU) 2011, a NOR flash memory 2012, and a random access memory (RAM) 2013. As the RAM 2013, for example, a static random access memory (SRAM) is used. In addition, an external non-volatile random access memory (NVRAM) 2013 is provided as needed.

[0056] The CPU 2011 uses a high-speed memory interface (I / F) to communicate with the NOR flash memory 2012 and the RAM 2013. On the other hand, the CPU communicates with the external NVRAM 2014 using a storage device I / F that is slower than the memory I / F.

[0057] The NOR flash memory 2012 stores, for example, software to be executed by the CPU 2011 and data used by the software and required to be retained. In the case where the capacity of the NOR flash memory 2012 is insufficient, part of the data is stored in the external NVRAM 2014. In the RAM 2013, for example, data temporarily used by the software and not required to be retained is temporarily stored.

[0058] In the NOR flash system 2001, when the CPU 2011 executes a program, first, a boot loader initializes the hardware, and then sets the program counter to the address of the main program on the NOR flash memory 2012. This causes the main program to start running while remaining stored in the NOR flash memory 2012.

[0059] Figure 2The diagram shows a configuration example of a NAND flash memory system 2051 applied to a smartphone, etc. The NAND flash memory system 2051 includes a CPU 2061, a NAND flash memory 2062, and a RAM 2063. As the RAM 2063, for example, a double data rate synchronous dynamic random access memory (DDR SDRAM) is used.

[0060] The CPU 2061 communicates with the NAND flash memory 2062 using a high-speed storage device I / F. The CPU 2061 communicates with the RAM 2063 using a memory I / F which is slower than the storage device I / F.

[0061] The NAND flash memory 2062 stores, for example, software to be executed by the CPU 2061 and data used by the software and required to be retained. In the RAM 2013, for example, software as an execution target and data temporarily used by the software and not required to be retained are temporarily stored.

[0062] In the NAND flash memory system 2051, in the case where the CPU 2061 executes a program, first, the boot loader initializes the hardware, and then copies (shadows) the main program from the NAND flash memory 2062 to the RAM 2063. Then, the boot loader sets the program counter to the address of the main program loaded into the RAM 2063. This starts the main program loaded into the RAM 2063 to run. In addition, as needed, a required program is loaded into the RAM 2063, and a program with a lower priority is cleared from the RAM 2063.

[0063] Since the NOR flash memory 2012 can control data rewriting bit by bit, it avoids unnecessary processing and is generally reliable and durable compared to the NAND flash memory 2062. In addition, since the NOR flash memory 2012 supports execution in place (XiP), it has a shorter program startup time than the NAND flash memory system 2051. On the other hand, compared to the NOR flash memory 2012, the NAND flash memory 2062 has a lower cost per bit and a larger capacity.

[0064] In conventional vehicles, ECUs are generally distributed according to their functions, and the scale of software installed on each ECU is relatively small. Therefore, the ECU of conventional vehicles adopts an architecture that uses NOR flash memory, such as Figure 1 NOR flash memory system 2001 is shown in FIG.

[0065] On the other hand, in the future, it is predicted that vehicles including connected cars will become more software-driven, the scale of software will become larger, and the amount of data processed by software will increase. For example, it is predicted that a rich operating system (OS), an application framework, larger downloadable content, etc. will be used for a human-machine interface (HMI) of a vehicle, etc. In addition, for example, in order to reduce costs and simplify software management, it is predicted that the number of ECUs will decrease and the functionality of each ECU will increase. Therefore, it is predicted that an architecture using NOR flash memory will face problems of insufficient data capacity and increased costs.

[0066] Therefore, it is predicted that the architecture using NAND flash memory such as NAND flash system 2051 will become the mainstream of ECUs for vehicles in the future. In fact, for information technology (IT) devices such as smartphones and digital cameras and consumer electronics (CE) devices, the architecture using NAND flash memory is becoming more dominant than the architecture using NOR flash memory due to the increase in software size and data.

[0067] Figure 3 A first example of a data structure of the NAND flash memory 2062 of the NAND flash memory system 2051 is illustrated.

[0068] exist Figure 3 In the NAND flash memory system 2051 shown in FIG. 2 , the NAND flash memory 2062 includes a main system area, an update system area, and a data area.

[0069] The main system area stores software (program group) to be executed by the CPU 2061. The main system area is basically non-rewritable (read-only (RO)) except when the software is updated.

[0070] The update system area stores software for updating the software in the main system area. The update system area is basically non-rewritable (RO).

[0071] The data area is used by the NAND flash memory system 2051 and stores data that needs to be retained. The data area is rewritable (RW).

[0072] In the case where the software in the main system area is updated, it is technically possible to rewrite the software stored in the main system area using the program copied from the main system area to the RAM 2063. However, in this case, the program cleared from the RAM 2063 cannot be reloaded, making the operation unstable.

[0073] Therefore, the program for updating in the update system area is loaded into the RAM 2063 and executed to update the software in the main system area. In this case, during the software update, the NAND flash memory system 2051 stops its normal operation. Then, after the software in the main system area has been rewritten, when the NAND flash memory system 2051 is restarted, the new software stored in the main system area is executed, and the NAND flash memory system 2051 starts its normal operation.

[0074] At this time, in the case where the data format that can be processed by the new software has changed, data migration is performed immediately after the software is updated. As a result, the format of the data stored in the data area is converted into a format that can be processed by the new software.

[0075] Note that the data stored in the data area differs for each device or system including the NAND flash memory system 2051 and therefore cannot be uniformly updated like software.

[0076] Figure 4 A second example of the data structure of the NAND flash memory 2062 of the NAND flash memory system 2051 is illustrated.

[0077] exist Figure 4 In the NAND flash memory system 2051 shown in FIG. 2 , the NAND flash memory 2062 includes a main system area A, a main system area B, and a data area.

[0078] In this architecture, for example, while software in one of the main system area A or the main system area B is running, software in the other area can be rewritten and updated.

[0079] Therefore, when the NAND flash memory system 2051 is in normal operation, new software can be installed on the NAND flash memory 2062 and executed after rebooting. Note that in the case where the data format that can be processed by the new software changes, for example, data migration is performed at rebooting after installing the new software.

[0080] and Figure 3 Compared to the example illustrated in , this allows the NAND flash memory system 2051 to reduce the time it stops its normal operation during software updates. In addition, since new software and old software can be stored simultaneously, when the new software does not function correctly due to a defect (bug), etc., the new software can be rolled back to the old software.

[0081] In a vehicle, in order to reduce the time that the vehicle is inoperable during a software update, or to enable the vehicle to operate even with old software when the new software does not function correctly, it is recommended to store the software in two partitions: slot A and slot B, as in Figure 4 As shown in the architecture shown in the figure.

[0082] However, after the software is updated, when data migration is performed, even if the software is rolled back to the old software, the data in the data area is not in a format compatible with the old software. Therefore, there is a possibility that the old software will not function correctly.

[0083] Note that, for example, it is conceivable to assign different file names to the data in the data area for each format, and switch the file to be used based on the software version. However, in this case, the main system area storing the file name will also be updated; therefore, there is a possibility that implementation and testing will be neglected, resulting in a breeding ground for defects.

[0084] To address the above issues, this technology aims to ensure proper software rollback.

[0085] 《2. Configuration example of vehicle control system》

[0086] Figure 5 is a block diagram illustrating a configuration example of a vehicle control system 11 which is an example of a mobile device control system to which the present technology is applied.

[0087] The vehicle control system 11 is provided in the vehicle 1 , and executes processing related to driver assistance and automatic driving of the vehicle 1 .

[0088] The vehicle control system 11 includes a vehicle control electronic control unit (ECU) 21, a communication unit 22, a map information accumulation unit 23, a position information acquisition unit 24, an external identification sensor 25, an on-board sensor 26, a vehicle sensor 27, a storage unit 28, a driver assistance / autonomous driving control unit 29, a driver monitoring system (DMS) 30, a human-machine interface (HMI) 31 and a vehicle control unit 32.

[0089] The vehicle control ECU 21, the communication unit 22, the map information accumulation unit 23, the position information acquisition unit 24, the external identification sensor 25, the vehicle sensor 26, the vehicle sensor 27, the storage unit 28, the driver assistance / automatic driving control unit 29, the driver monitoring system (DMS) 30, the human-machine interface (HMI) 31, and the vehicle control unit 32 are communicatively connected via the communication network 41. For example, the communication network 41 includes an on-vehicle communication network, a bus, etc. that conforms to a digital two-way communication standard, such as a controller area network (CAN), a local interconnect network (LIN), a local area network (LAN), FlexRay (registered trademark), or Ethernet (registered trademark). The communication network 41 can be selectively used in a manner depending on the type of data to be transmitted. For example, CAN can be applied to data related to vehicle control, and Ethernet can be applied to large-capacity data. Note that, for example, without using the communication network 41, each component of the vehicle control system 11 can be directly connected using wireless communication suitable for relatively short-range communication, such as near field communication (NFC) or Bluetooth (registered trademark).

[0090] Note that, hereinafter, in the case where each component of the vehicle control system 11 performs communication via the communication network 41, the description of the communication network 41 will be omitted. For example, the case where the vehicle control ECU 21 and the communication unit 22 perform communication via the communication network 41 will be simply described as the vehicle control ECU 21 and the communication unit 22 performing communication.

[0091] The vehicle control ECU 21 includes various processors such as a central processing unit (CPU) and a micro processing unit (MPU), for example. The vehicle control ECU 21 controls all or some of the functions of the vehicle control system 11 .

[0092] The communication unit 22 communicates with various devices inside and outside the vehicle, other vehicles, servers, base stations, etc., and transmits and receives various types of data. In doing so, the communication unit 22 can perform communication using a variety of communication schemes.

[0093] The communication with the outside of the vehicle that can be performed by the communication unit 22 will be schematically described. For example, the communication unit 22 communicates with a server (hereinafter referred to as an external server) existing on an external network via a base station or an access point using a wireless communication method such as a fifth generation mobile communication system (5G), long term evolution (LTE), dedicated short range communication (DSRC), etc. Examples of the external network through which the communication unit 22 performs communication include the Internet, a cloud network, a private network, etc. The communication method by which the communication unit 22 performs communication through the external network is not particularly limited as long as the method is a wireless communication method that allows digital two-way communication at a communication speed equal to or higher than a predetermined speed and at a distance equal to or longer than a predetermined distance.

[0094] In addition, the communication unit 22 can communicate with a terminal present near the vehicle using, for example, a point-to-point (P2P) technology. For example, the terminal present near the vehicle is a terminal attached to a moving object (such as a pedestrian or a bicycle) moving at a relatively low speed, a terminal fixedly installed in a store, etc., or a machine type communication (MTC) terminal. In addition, the communication unit 22 can also perform V2X communication. For example, V2X communication refers to communication between the vehicle and another vehicle (such as vehicle-to-vehicle communication with another vehicle), vehicle-to-infrastructure communication with roadside equipment, etc., vehicle-to-home communication, and vehicle-to-pedestrian communication with a terminal carried by a pedestrian, etc.

[0095] For example, the communication unit 22 may receive a program for updating software that controls the operation of the vehicle control system 11 from the outside (over the air). The communication unit 22 may also receive map information, traffic information, information about the surrounding environment of the vehicle 1, and the like from the outside. Furthermore, for example, the communication unit 22 may transmit information about the vehicle 1, information about the surrounding environment of the vehicle 1, and the like to the outside. Examples of the information about the vehicle 1 transmitted to the outside by the communication unit 22 include data indicating the state of the vehicle 1, a recognition result from the recognition unit 73, and the like. Furthermore, for example, the communication unit 22 performs communication compatible with a vehicle emergency call system such as eCall.

[0096] For example, the communication unit 22 receives electromagnetic waves transmitted by a Vehicle Information and Communication System (VICS) (registered trademark) such as a radio beacon, an optical beacon, or FM multiplex broadcasting.

[0097] The communication with the inside of the vehicle that can be performed by the communication unit 22 will be schematically described. For example, the communication unit 22 can communicate with each device in the vehicle using wireless communication. For example, the communication unit 22 can use a wireless communication method that allows digital two-way communication at a communication speed equal to or higher than a predetermined speed (such as wireless LAN, Bluetooth, NFC, or wireless universal serial bus (WUSB)) to communicate wirelessly with the device in the vehicle. The communication unit 22 can also communicate with each device in the vehicle using wired communication instead of wireless communication. For example, the communication unit 22 can communicate with each device in the vehicle using wired communication via a cable connected to a connection terminal not shown in the figure. For example, the communication unit 22 can communicate with each device in the vehicle using a wired communication method that allows digital two-way communication at a communication speed equal to or higher than a predetermined speed (such as a universal serial bus (USB), a high-definition multimedia interface (HDMI) (registered trademark) or a mobile high-definition link (MHL)) to communicate with each device in the vehicle.

[0098] Here, the device in the vehicle refers to, for example, a device in the vehicle that is not connected to the communication network 41. Possible examples of the device in the vehicle include mobile devices and wearable devices carried by passengers such as the driver, information devices brought into the vehicle and temporarily installed, and the like.

[0099] The map information accumulation unit 23 accumulates either or both of maps acquired from the outside and maps created by the vehicle 1. For example, the map information accumulation unit 23 accumulates three-dimensional high-precision maps, global maps that are less accurate than high-precision maps but cover a wider area, and the like.

[0100] Examples of high-precision maps include dynamic maps, point cloud maps, vector maps, and the like. For example, a dynamic map is a map including four layers of dynamic information, semi-dynamic information, semi-static information, and static information, and is provided to the vehicle 1 from an external server or the like. A point cloud map is a map including a point cloud (point cloud data). For example, a vector map is a map suitable for an advanced driver assistance system (ADAS) or autonomous driving (AD), which is obtained by associating traffic information such as lane positions and traffic light positions with a point cloud map.

[0101] The point cloud map and the vector map may be provided from, for example, an external server or the like, or may be created by the vehicle 1 based on sensing results from the camera 51, the radar 52, the LiDAR 53, etc. as a map for matching with a local map to be described later, and may be accumulated in the map information accumulation unit 23. Alternatively, in the case where a high-precision map is provided from an external server or the like, in order to reduce communication capacity, for example, map data of several hundred square meters about a planned route that the vehicle 1 will follow is acquired from the external server or the like.

[0102] The position information acquisition unit 24 receives a global navigation satellite system (GNSS) signal from a GNSS satellite and acquires position information of the vehicle 1. The acquired position information is supplied to the driver assistance / automatic driving control unit 29. Note that, for example, the position information acquisition unit 24 may acquire position information using not only a GNSS signal but also a beacon.

[0103] The exterior recognition sensor 25 includes various sensors for recognizing conditions outside the vehicle 1, and supplies sensor data from each sensor to each component of the vehicle control system 11. The type and number of sensors included in the exterior recognition sensor 25 are determined as desired.

[0104] For example, the external recognition sensor 25 includes a camera 51, a radar 52, a light detection and ranging or laser imaging detection and ranging (LiDAR) 53, and an ultrasonic sensor 54. Alternatively, it is only necessary for the external recognition sensor 25 to include at least one of the camera 51, the radar 52, the LiDAR 53, or the ultrasonic sensor 54. The number of the camera 51, the radar 52, the LiDAR 53, and the ultrasonic sensor 54 is not particularly limited as long as these numbers are practical numbers to be installed in the vehicle 1. In addition, the type of sensor included in the external recognition sensor 25 is not limited to this example, and the external recognition sensor 25 may include some other type of sensor. An example of a sensing area of ​​each sensor included in the external recognition sensor 25 will be described later.

[0105] Note that the imaging method of the camera 51 is not particularly limited. For example, as necessary, a camera suitable for various imaging methods that allow distance measurement, such as a time-of-flight (ToF) camera, a stereo camera, a monocular camera, and an infrared camera, can be used as the camera 51. The camera 51 is not limited to such a camera, and may be a camera for simply acquiring a captured image without performing distance measurement.

[0106] In addition, for example, the exterior recognition sensor 25 may include an environment sensor for detecting the environment around the vehicle 1. The environment sensor is a sensor for detecting the environment such as weather, climate, and brightness, and may include, for example, various sensors such as a raindrop sensor, a fog sensor, a sunshine sensor, a snow sensor, and an illumination sensor.

[0107] Furthermore, for example, the exterior recognition sensor 25 includes a microphone for detecting sounds around the vehicle 1 , the position of a sound source, and the like.

[0108] The on-board sensor 26 includes various sensors for detecting information about the interior of the vehicle, and supplies sensor data from each sensor to each component of the vehicle control system 11. The type and number of various sensors included in the on-board sensor 26 are not particularly limited as long as the type and number are practical types and data to be installed in the vehicle 1.

[0109] For example, the onboard sensor 26 may include one or more types of sensors among a camera, a radar, a seat sensor, a steering wheel sensor, a microphone, and a biometric sensor. As the camera included in the onboard sensor 26, for example, a camera suitable for various imaging methods that allow distance measurement, such as a ToF camera, a stereo camera, a monocular camera, and an infrared camera, can be used. The camera included in the onboard sensor 26 is not limited to such a camera, and may be a camera for simply acquiring a captured image without performing distance measurement. The biometric sensor included in the onboard sensor 26 is, for example, provided on a seat, a steering wheel, etc., and detects various types of biometric information about an occupant such as a driver.

[0110] The vehicle sensor 27 includes various sensors for detecting the state of the vehicle 1, and supplies sensor data from each sensor to each component of the vehicle control system 11. The type and number of various sensors included in the vehicle sensor 27 are not particularly limited as long as the type and number are practical types and numbers to be installed in the vehicle 1.

[0111] For example, the vehicle sensor 27 includes a speed sensor, an acceleration sensor, an angular velocity sensor (gyroscope), and an inertial measurement unit (IMU) obtained by integrating these sensors. For example, the vehicle sensor 27 includes a steering angle sensor that detects the steering angle of the steering wheel, a yaw rate sensor, an accelerator sensor that detects the operation amount of the accelerator pedal, and a brake sensor that detects the operation amount of the brake pedal. For example, the vehicle sensor 27 includes a rotation sensor that detects the engine speed or the motor speed, a pneumatic sensor that detects the tire pressure, a slip rate sensor that detects the tire slip rate, and a wheel speed sensor that detects the wheel speed. For example, the vehicle sensor 27 includes a battery sensor that detects the remaining battery power and the battery temperature, and an impact sensor that detects an external impact.

[0112] The storage unit 28 includes at least one of a nonvolatile storage medium or a volatile storage medium, and stores data and programs. The storage unit 28 is used as, for example, an electrically erasable programmable read-only memory (EEPROM) and a random access memory (RAM), and a magnetic storage device such as a hard disk drive (HDD), a semiconductor storage device, an optical storage device, and a magneto-optical storage device can be used as a storage medium. The storage unit 28 stores various programs and data to be used by each component of the vehicle control system 11. For example, the storage unit 28 includes an event data recorder (EDR) and a data storage system for autonomous driving (DSSAD), and stores information about the vehicle 1 before and after an event such as an accident and information acquired by the on-board sensor 26.

[0113] The driver assistance / automatic driving control unit 29 controls driver assistance and automatic driving of the vehicle 1. For example, the driver assistance / automatic driving control unit 29 includes an analysis unit 61, a motion planning unit 62, and an operation control unit 63.

[0114] The analysis unit 61 performs analysis processing on the vehicle 1 and the conditions around the vehicle 1. The analysis unit 61 includes a self-position estimation unit 71, a sensor fusion unit 72, and a recognition unit 73.

[0115] The own position estimation unit 71 estimates the own position of the vehicle 1 based on the sensor data from the external recognition sensor 25 and the high-precision map accumulated in the map information accumulation unit 23. For example, the own position estimation unit 71 generates a local map based on the sensor data from the external recognition sensor 25, and performs matching between the local map and the high-precision map to estimate the own position of the vehicle 1. The position of the vehicle 1 is based on, for example, the center of the rear wheel pair axle.

[0116] Examples of local maps include three-dimensional high-precision maps created by using technologies such as simultaneous localization and mapping (SLAM), occupancy grid maps, etc. For example, the three-dimensional high-precision map is the above-mentioned point cloud map, etc. The occupancy grid map is a map in which the three-dimensional or two-dimensional space around the vehicle 1 is divided into grids of a predetermined size, and the occupancy status of objects is indicated in units of the grids. The occupancy status of an object is indicated, for example, by the presence or absence of the object or the probability of its presence. The local map is also used for detection processing and recognition processing performed, for example, by the recognition unit 73 on the condition outside the vehicle 1.

[0117] Note that the own position estimating unit 71 may estimate the own position of the vehicle 1 based on the position information acquired by the position information acquiring unit 24 and the sensor data from the vehicle sensor 27 .

[0118] The sensor fusion unit 72 performs a sensor fusion process of combining a plurality of different types of sensor data (eg, image data supplied from the camera 51 and sensor data supplied from the radar 52) to acquire new information. Methods for combining different types of sensor data include integration, fusion, correlation, and the like.

[0119] The recognition unit 73 performs a detection process of a condition outside the vehicle 1 and a recognition process of a condition outside the vehicle 1 .

[0120] For example, the recognition unit 73 performs detection processing and recognition processing of the situation outside the vehicle 1 based on information from the exterior recognition sensor 25 , information from the own position estimation unit 71 , information from the sensor fusion unit 72 , and the like.

[0121] Specifically, for example, the recognition unit 73 performs detection processing, recognition processing, and the like on objects around the vehicle 1. The object detection processing is, for example, a process of detecting the presence or absence, size, shape, position, movement, and the like of an object. The object recognition processing is, for example, a process of recognizing an attribute such as a type of an object or recognizing a specific object. However, the detection processing and the recognition processing are not necessarily clearly separated and may overlap.

[0122] For example, the recognition unit 73 detects objects around the vehicle 1 by performing clustering to classify point clouds based on sensor data from the radar 52, LiDAR 53, etc. into point cloud clusters. This allows the presence, size, shape, and position of objects around the vehicle 1 to be detected.

[0123] For example, the recognition unit 73 detects the movement of the object around the vehicle 1 by performing tracking to follow the movement of the point cloud clusters classified by clustering. This allows the speed and the traveling direction (movement vector) of the object around the vehicle 1 to be detected.

[0124] For example, the recognition unit 73 detects or recognizes vehicles, people, bicycles, obstacles, structures, roads, traffic lights, traffic signs, road signs, etc. based on the image data supplied from the camera 51. In addition, the recognition unit 73 can recognize the type of objects around the vehicle 1 by performing recognition processing such as semantic segmentation.

[0125] For example, the recognition unit 73 may perform recognition processing on traffic regulations around the vehicle 1 based on the map accumulated in the map information accumulation unit 23, the estimation result of the own position by the own position estimation unit 71, and the recognition result of the objects around the vehicle 1 by the recognition unit 73. Through this processing, the recognition unit 73 can recognize the position and state of traffic lights, the details of traffic signs and road signs, the details of traffic regulations, drivable lanes, and the like.

[0126] For example, the recognition unit 73 may perform recognition processing on the surrounding environment of the vehicle 1. Possible examples of the surrounding environment to be recognized by the recognition unit 73 include weather, air temperature, humidity, brightness, road surface conditions, and the like.

[0127] The action planning unit 62 creates an action plan of the vehicle 1. For example, the action planning unit 62 creates the action plan by performing path planning and path following processing.

[0128] Note that path planning (global path planning) is a process of planning a rough path from the starting point to the target. The path planning also includes a process called trajectory planning that performs trajectory generation (local path planning) that takes into account the motion characteristics of the vehicle 1 in the planned path to enable safe and smooth progress near the vehicle 1.

[0129] Path following is a process of planning an operation for safely and accurately traveling along a path planned by path planning within a planning time. For example, the action planning unit 62 may calculate a target speed and a target angular velocity of the vehicle 1 based on the result of the path following process.

[0130] The operation control unit 63 controls the operation of the vehicle 1 to implement the maneuver plan created by the maneuver planning unit 62 .

[0131] For example, the operation control unit 63 controls the steering control unit 81, the braking control unit 82, and the driving control unit 83 included in the vehicle control unit 32 to be described later, to perform acceleration and deceleration control and direction control so that the vehicle 1 follows the path calculated by trajectory planning. For example, the operation control unit 63 performs coordinated control to realize ADAS functions such as collision avoidance or mitigation, following driving, speed maintenance driving, collision warning for the host vehicle, lane departure warning for the host vehicle, etc. For example, the operation control unit 63 performs coordinated control to realize automatic driving in which the vehicle autonomously drives without relying on the operation of the driver, etc.

[0132] The DMS 30 performs authentication processing of the driver, recognition processing of the driver's state, etc. based on sensor data from the on-vehicle sensor 26, data input to the HMI 31 to be described later, etc. For example, the driver's state to be recognized may be physical condition, alertness level, concentration level, fatigue level, sight direction, drunkenness level, driving operation, posture, etc.

[0133] Note that the DMS 30 may perform authentication processing of an occupant other than the driver and recognition processing of the occupant's state. In addition, for example, the DMS 30 may perform recognition processing of the vehicle interior condition based on sensor data from the onboard sensor 26. Possible examples of the vehicle interior condition to be recognized include temperature, humidity, brightness, odor, and the like.

[0134] The HMI 31 receives input of various types of data, instructions, and the like, and presents various types of data to a driver or the like.

[0135] The data input performed by the HMI 31 will be schematically described. The HMI 31 includes an input device for a person to input data. The HMI 31 generates an input signal based on the data, instructions, etc. input by the input device, and supplies the input signal to each component of the vehicle control system 11. For example, the HMI 31 includes operating elements such as a touch panel, a button, a switch, and a lever as an input device. The HMI 31 may also include an input device capable of inputting information by methods such as voice or gestures other than manual operation. In addition, the HMI 31 may use, for example, a remote control device using infrared rays or radio waves or an external connection device such as a mobile device or a wearable device suitable for the operation of the vehicle control system 11 as an input device.

[0136] How the HMI 31 presents data will be schematically described. The HMI 31 generates visual information, auditory information, and tactile information about the occupant or the outside of the vehicle. In addition, the HMI 31 performs output control for controlling the output of each piece of information generated, output content, output timing, output method, etc. For example, as visual information, the HMI 31 generates and outputs information indicated by an image or light, such as an operation screen, a status display of the vehicle 1, a warning display, and a monitor image indicating the conditions around the vehicle 1. In addition, for example, as auditory information, the HMI 31 generates and outputs information indicated by sound, such as voice guidance, warning sound, and warning message. In addition, for example, as tactile information, the HMI 31 generates and outputs information that will give the occupant a sense of touch through force, vibration, motion, etc.

[0137] As an output device through which the HMI 31 outputs visual information, for example, a display device that presents visual information by displaying an image by itself or a projector device that presents visual information by projecting an image can be used. Note that, for example, in addition to a display device having a normal display, the display device can also be a device that displays visual information within the field of vision of the occupant, such as a head-up display, a transmissive display, or a wearable device with an augmented reality (AR) function. In addition, in the HMI 31, a display device included in a navigation device, an instrument panel, a camera monitoring system (CMS), an electronic mirror, a lamp, etc. provided in the vehicle 1 can also be used as an output device for outputting visual information.

[0138] As an output device from which the HMI 31 outputs auditory information, for example, an audio speaker, a headphone, or an earphone may be used.

[0139] As an output device from which the HMI 31 outputs tactile information, for example, a tactile element using tactile technology may be used The tactile element is provided at a portion to be touched by an occupant of the vehicle 1, such as a steering wheel or a seat, for example.

[0140] The vehicle control unit 32 controls each component of the vehicle 1. The vehicle control unit 32 includes a steering control unit 81, a brake control unit 82, a drive control unit 83, a body system control unit 84, a light control unit 85, and a horn control unit 86.

[0141] The steering control unit 81 performs detection and control of the state of the steering system of the vehicle 1. The steering system includes, for example, a steering mechanism including a steering wheel, an electric power steering device, etc. The steering control unit 81 includes, for example, a steering ECU that controls the steering system, an actuator that drives the steering system, etc.

[0142] The brake control unit 82 performs detection, control, etc. of the state of the brake system of the vehicle 1. The brake system includes, for example, a brake mechanism including a brake pedal, etc., an anti-lock brake system (ABS), a regenerative brake mechanism, etc. The brake control unit 82 includes, for example, a brake ECU that controls the brake system, an actuator that drives the brake system, etc.

[0143] The drive control unit 83 performs detection, control, etc. of the state of the drive system of the vehicle 1. The drive system includes, for example, an accelerator pedal, a drive force generating device such as an internal combustion engine or a drive motor for generating a drive force, a drive force transmission mechanism for transmitting the drive force to the wheels, etc. The drive control unit 83 includes, for example, a drive ECU that controls the drive system, an actuator that drives the drive system, etc.

[0144] The body system control unit 84 performs detection, control, etc. of the state of the body system of the vehicle 1. The body system includes, for example, a keyless entry system, a smart key system, a power window device, a power seat, an air conditioner, an air bag, a seat belt, a shift lever, etc. The body system control unit 84 includes, for example, a body system ECU that controls the body system, an actuator that drives the body system, etc.

[0145] The light control unit 85 performs detection, control, etc. of the states of various lights of the vehicle 1. Possible examples of lights to be controlled include headlights, taillights, fog lights, turn lights, brake lights, projector lights, bumper indicators, etc. The light control unit 85 includes a light ECU that controls the lights, an actuator that drives the lights, etc.

[0146] The horn control unit 86 performs detection, control, etc. of the state of the car horn of the vehicle 1. The horn control unit 86 includes, for example, a horn ECU that controls the car horn, an actuator that drives the car horn, and the like.

[0147] Figure 6 The diagram is provided by Figure 5 FIG. 5 is a diagram showing an example of a sensing area covered by the camera 51, radar 52, LiDAR 53, ultrasonic sensor 54, etc. in the external recognition sensor 25 illustrated in FIG. Figure 6 The vehicle 1 is schematically illustrated when viewed from above, wherein the left end side is the front end (front) side of the vehicle 1 , and the right end side is the rear end (rear) side of the vehicle 1 .

[0148] The sensing area 101F and the sensing area 101B indicate examples of sensing areas of the ultrasonic sensor 54. The sensing area 101F covers an area around the front end of the vehicle 1 using multiple ultrasonic sensors 54. The sensing area 101B covers an area around the rear end of the vehicle 1 using multiple ultrasonic sensors 54.

[0149] For example, the sensing results in the sensing area 101F and the sensing area 101B are used for parking assistance of the vehicle 1 or the like.

[0150] Sensing areas 102F to 102B indicate examples of sensing areas of the short-range or medium-range radar 52. Sensing area 102F covers an area extending further than sensing area 101F in front of the vehicle 1. Sensing area 102B covers an area extending further than sensing area 101B behind the vehicle 1. Sensing area 102L covers an area around the left rear side of the vehicle 1. Sensing area 102R covers an area around the rear right side of the vehicle 1.

[0151] For example, the sensing result in the sensing area 102F is used for detection of a vehicle, pedestrian, etc. existing in front of the vehicle 1. For example, the sensing result in the sensing area 102B is used for a collision avoidance function for preventing a collision on the rear side of the vehicle 1. For example, the sensing results in the sensing area 102L and the sensing area 102R are used for detection of an object in a blind spot on the side of the vehicle 1.

[0152] Sensing areas 103F to 103B indicate examples of sensing areas of the camera 51. The sensing area 103F covers an area extending further than the sensing area 102F in front of the vehicle 1. The sensing area 103B covers an area extending further than the sensing area 102B behind the vehicle 1. The sensing area 103L covers an area around the left side of the vehicle 1. The sensing area 103R covers an area around the right side of the vehicle 1.

[0153] For example, the sensing result in the sensing area 103F can be used for the recognition of traffic lights or traffic signs, lane departure prevention assistance systems, and automatic headlight control systems. For example, the sensing result in the sensing area 103B can be used for parking assistance and surround view systems. For example, the sensing results in the sensing areas 103L and 103R can be used for surround view systems.

[0154] The sensing area 104 indicates an example of the sensing area of ​​the LiDAR 53. The sensing area 104 covers an area extending farther than the sensing area 103F in front of the vehicle 1. However, the sensing area 104 has a narrower range in the lateral direction than the sensing area 103F.

[0155] For example, the sensing results in the sensing area 104 are used for detection of objects such as neighboring vehicles.

[0156] The sensing area 105 indicates an example of a sensing area of ​​the long-range radar 52. The sensing area 105 covers an area extending farther in front of the vehicle 1 than the sensing area 104. However, the sensing area 105 has a narrower range than the sensing area 104 in the lateral direction.

[0157] For example, the sensing result in the sensing area 105 is used for adaptive cruise control (ACC), emergency braking, collision avoidance, etc.

[0158] Note that the sensing areas of the sensors including the camera 51, the radar 52, the LiDAR 53, and the ultrasonic sensor 54 included in the exterior recognition sensor 25 may have a plurality of Figure 6 Various configurations other than those in . Specifically, the ultrasonic sensor 54 may also perform sensing on the side of the vehicle 1, or the LiDAR 53 may perform sensing on the rear side of the vehicle 1. In addition, the installation position of each sensor is not limited to the above examples. In addition, the number of each sensor may be one or more.

[0159] 《3. Implementation Examples》

[0160] Next, we will refer to Figures 7 to 19 Embodiments of the present technology are described.

[0161] <Configuration Example of Information Processing System 201>

[0162] Figure 7 A configuration example of an information processing system 201 to which the present technology is applied is illustrated.

[0163] For example, information processing system 201 is implemented Figure 5 Among the functions of the vehicle control system 11 of the vehicle 1 illustrated in FIG. 8 , a system of functions mainly executed by software.

[0164] The information processing system 201 includes high-performance ECUs 211-1 to 211-m and legacy ECUs 212-1 to 212-n. The high-performance ECUs 211-1 to 211-m and the legacy ECUs 212-1 to 212-n are each connected to a bus 213 to communicate with each other.

[0165] Hereinafter, the high-performance ECUs 211-1 to 211-m will be referred to simply as the high-performance ECU 211 unless otherwise distinguished. Hereinafter, the old ECUs 212-1 to 212-n will be referred to simply as the old ECU 212 unless otherwise distinguished. Hereinafter, in the case where the ECUs communicate via the bus 213, the description of the bus 213 will be omitted. For example, the case where the high-performance ECU 211 communicates with the old ECU 212 via the bus 213 will be referred to simply as the case where the high-performance ECU 211 communicates with the old ECU 212.

[0166] For example, the high-performance ECU 211 is a high-performance ECU equipped with a SoC. For example, the high-performance ECU 211 is an ECU with integrated functions. That is, one high-performance ECU 211 can perform various functions of the vehicle 1. In addition, the high-performance ECU 211 controls the software upgrade and rollback of the legacy ECU 212 as needed.

[0167] For example, the legacy ECU 212 is an ECU having lower performance than the high-performance ECU 211. For example, the legacy ECU 212 is an ECU having limited functions as found in a conventional vehicle.

[0168] Note that the number of high-performance ECUs 211 and the number of legacy ECUs 212 are not particularly limited. Furthermore, the legacy ECUs 212 do not necessarily need to be provided in the information processing system 201.

[0169] <Configuration example of high-performance ECU 211>

[0170] Figure 8 The high-performance ECU 211 is similar in configuration to the high-performance ECU 211. Figure 2 The NAND flash memory system 2051 shown in FIG. 2051 is a high-performance ECU 211. The high-performance ECU 211 includes a CPU 251, a flash memory 252, and a RAM 253. As the flash memory 252, for example, a NAND flash memory is used. As the RAM 253, for example, a DDR SDRAM is used.

[0171] The CPU 251 communicates with the flash memory 252 using the storage device I / F. The CPU 251 communicates with the RAM 253 using the memory I / F.

[0172] The CPU 251 executes a predetermined control program to implement a software management unit 261 that manages software and data stored in the flash memory 252. The software management unit 261 includes a main module 271, a backup module 272, and a data migration module 273.

[0173] The main module 271 controls the entire software management unit 261 while communicating with the outside. For example, the main module 271 controls software execution, software upgrade and rollback of the high-performance ECU 211. In addition, the main module 271 controls software upgrade and rollback of, for example, the legacy ECU 212 as needed.

[0174] For example, the backup module 272 controls software and data backup of the high-performance ECU 211. In addition, the backup module 272 controls software and data backup of, for example, the legacy ECU 212 as needed.

[0175] For example, the data migration module 273 controls data migration of the high-performance ECU 211. Furthermore, for example, the data migration module 273 controls data migration of the legacy ECU 212 as needed.

[0176] For example, the flash memory 252 stores software to be executed by the CPU 251 and data used by the software and required to be retained. In addition, for example, the flash memory 252 stores (backs up) software and data of the legacy ECU 212 as needed.

[0177] The flash memory 252 includes a main system area A, a nonvolatile data area A, a main system area B, a nonvolatile data area B, an other ECU SW area, and an other ECU data area.

[0178] The main system area A and the main system area B each store software to be executed by the CPU 251. The main system area A and the main system area B may each store different versions of software. The main system area A and the main system area B are basically non-rewritable (read-only (RO)) except when the software is updated.

[0179] The nonvolatile data area A is an area corresponding to the main system area A, and stores data used by software stored in the main system area A. The nonvolatile data area A is rewritable (RW).

[0180] The nonvolatile data area B is an area corresponding to the main system area B, and stores data used by software stored in the main system area B. The nonvolatile data area B is rewritable (RW).

[0181] The other ECU SW area is an area for backing up the software of the old ECU 212. The other ECU SW area is basically non-rewritable (RO) except for the case where the software is backed up.

[0182] The other ECU data area is an area for backing up data of the old ECU 212. The other ECU data area is basically non-rewritable (RO) except when data is backed up.

[0183] Note that in this figure, the other ECU SW area and the other ECU data area are each shown as one, but the number of the other ECU SW area and the other ECU data area is not particularly limited. For example, the number of the other ECU SW area and the other ECU data area is set based on the number of legacy ECUs 212 whose software and data are backed up.

[0184] In the RAM 253 , for example, software that is an execution target, data that is temporarily used by the software and does not need to be retained are temporarily stored.

[0185] <Configuration example of the old ECU 212>

[0186] Fig. 9 The figure shows an example of the configuration of the legacy ECU 212. The legacy ECU 212 is similar in configuration to Figure 1 The NOR flash memory system 2001 shown in FIG. The legacy ECU 212 includes a CPU 301, a flash memory 302, and a RAM 303. As the flash memory 302, for example, a NOR flash memory is used. As the RAM 303, for example, an SRAM is used. In addition, an external NVRAM 304 is provided as needed.

[0187] The CPU 301 communicates with the flash memory 302 and the RAM 303 using the storage device I / F. The CPU 301 communicates with the external NVRAM 304 using the memory I / F.

[0188] The CPU 301 executes a predetermined control program to implement a software management unit 311 that manages software and data stored in the flash memory 302. The software management unit 311 includes a main module 321 and a data migration module 322.

[0189] The main module 321 controls the entire software management unit 311 while communicating with the outside. For example, the main module 321 controls software execution of the legacy ECU 212, and software upgrade and rollback.

[0190] For example, the data migration module 322 controls data migration of the legacy ECU 212. Note that the data migration module 322 does not necessarily need to be provided.

[0191] For example, the flash memory 302 stores software to be executed by the CPU 301 and data used by the software and required to be retained.

[0192] The flash memory 302 includes a main system area and a non-volatile data area.

[0193] The main system area stores software to be executed by the CPU 301. The main system area is basically non-rewritable (RO) except for the case where the software is updated or rolled back.

[0194] The nonvolatile data area is an area corresponding to the main system area A, and stores data used by software stored in the main system area A. The nonvolatile data area is rewritable (RW).

[0195] In the RAM 303 , for example, data that is temporarily used by software and does not need to be retained is temporarily stored.

[0196] In the case where the capacity of the flash memory 302 is insufficient, the external NVRAM 304 stores a portion of the data.

[0197] <Processing by Information Processing System 201>

[0198] Next, we will refer to Figures 10 to 29 Description of the processing of the information processing system 201. Specifically, the following describes processing related to update, rollback, etc. of firmware (hereinafter, referred to as FW) which is software installed on and executed by the high-performance ECU 211 and the legacy ECU 212.

[0199] <First Embodiment of FW Update Processing of High-Performance ECU 211>

[0200] First, refer to Fig.10 The sequence diagram in describes a first embodiment of the FW update process of the high performance ECU 211.

[0201] Note that in the following, it is assumed that the flash memory 252 of the high-performance ECU 211 is in Fig.11 The state shown in figure A.

[0202] Specifically, it is assumed that FW (Ver. X) currently being the execution target is stored in the main system area A. It is assumed that data for FW (Ver. X) in a format compatible with FW (Ver. X) and used by FW (Ver. X) are stored in the non-volatile data area A. It is assumed that FW (Ver. X-1) which is a previous version of FW (Ver. X) is stored in the main system area B. It is assumed that data for FW (Ver. X-1) in a format compatible with FW (Ver. X-1) and used by FW (Ver. X-1) are stored in the non-volatile data area B.

[0203] Note that the main system area in which the FW that is the execution target is stored and the non-volatile data area corresponding to the main system area will be referred to as a valid area or an active area hereinafter. The FW stored in the valid area or the active area will be referred to as a valid FW or an active FW hereinafter. The data stored in the valid area or the active area will be referred to as valid data or active data hereinafter. Note that the main system area in which the FW that is not the execution target is stored and the non-volatile data area corresponding to the main system area will be referred to as a reserved area hereinafter.

[0204] Notice, Fig.11 The shaded area in indicates a valid area or active area, and the white area indicates a reserved area. This applies similarly to the following figures.

[0205] In step S1, high performance ECU 211 receives a FW update request from, for example, an external server, etc. by OTA via communication unit 22, etc. The FW update request includes, for example, FW for upgrading (hereinafter, referred to as FW for updating).

[0206] In step S2 , a FW update request is provided to the main module 271 .

[0207] In step S3, the main module 271 transitions to the update mode. This forces the high-performance ECU 211 to temporarily stop its normal operation, so that the normal operation of the vehicle 1 (such as driving) is temporarily disabled.

[0208] In step S4 , the main module 271 sends a backup request to the backup module 272 .

[0209] In step S5, the backup module 272 copies the data in the active non-volatile data area to the reserved non-volatile data area. As a result, the data in the reserved non-volatile data area is updated to the data in the active non-volatile data area, and the data of both are synchronized accordingly.

[0210] For example, data in the reserved nonvolatile data area B is updated to data for FW (Ver. X) in the active nonvolatile data area A, and the data in the nonvolatile data area A and the data in the nonvolatile data area B are synchronized accordingly.

[0211] In step S6 , the backup module 272 notifies the main module 271 of the completion of the backup.

[0212] In step S7, the main module 271 writes the FW for update to the reserved main system area. As a result, the FW in the reserved main system area is updated to the FW for update.

[0213] For example, the FW in the main system area B is updated to the FW for update (Ver. X+1) which is the next version of the FW. Fig.11 As shown in Figure B, Fig.11 Compared with the state in A, the FW in the main system area B is updated to the latest FW (Ver.X+1), and the data in the nonvolatile data area B is updated to the data for the FW (Ver.X) which is the previous version of the FW.

[0214] In step S8, the main module 271 changes the startup system. That is, the main module 271 exchanges the active area with the reserved area, and sets the FW stored in the active area after the change as the execution target. As a result, the FW set as the execution target is started at the next startup and subsequent startups of the high-performance ECU 211.

[0215] For example, Fig.11 As shown in FIG. 1B, the main system area B and the non-volatile data area B are set as active areas, and the main system area A and the non-volatile data area A are set as reserved areas. Then, FW (Ver. X+1) in the main system area B is set as an execution target, and FW (Ver. X+1) is started at the next startup and subsequent startups of the high-performance ECU 211.

[0216] Thereafter, the FW update process of the high performance ECU 211 is terminated. Then, the update mode of the high performance ECU 211 is disabled.

[0217] <System startup processing of high-performance ECU 211>

[0218] Next, we will refer to Fig.12 The sequence diagram in describes the system startup processing executed by the high-performance ECU 211.

[0219] Note that in the following, it is assumed that the flash memory 252 is in Fig.13 The state shown in A is similar to the above Fig.11 The state of B.

[0220] In step S21 , for example, the high performance ECU 211 receives a start request from the vehicle control ECU 21 or the like.

[0221] In step S22 , a start request is provided to the main module 271 .

[0222] Next, when the high performance ECU 211 is started for the first time after the FW update process, that is, when the first start-up is performed after the FW update process, steps S23 to S25 are executed.

[0223] Specifically, in step S23, the main module 271 requests the data migration module 273 to perform data format migration processing (data migration).

[0224] In step S24, the data migration module 273 updates the format of the data in the non-volatile data area used by the upgraded FW (hereinafter referred to as the new FW). That is, the data migration module 273 converts the format of the data in the non-volatile data area used by the new FW into a format compatible with the new FW.

[0225] For example, Fig.13 As shown in FIG. 1B, the data in the nonvolatile data area B used by FW (Ver. X+1) as the new FW is converted into a format compatible with FW (Ver. X+1). That is, the data for FW (Ver. X) stored in the nonvolatile data area B is converted into data for FW (Ver. X+1). This makes FW (Ver. X+1) stored in the main system area B executable.

[0226] In step S25 , the data migration module 273 notifies the main module 271 of the completion of the data migration.

[0227] Thereafter, the process proceeds to step S26.

[0228] Note that in the case where the format of the data for the new FW is not different from the format for the previous FW, steps S23 to S25 may be skipped.

[0229] On the other hand, in the case where the high performance ECU 211 performs the second or subsequent activation after the FW update process, steps S23 to S25 are skipped, and the process proceeds to step S26.

[0230] In step S26, the main module 271 starts the FW as the execution target. That is, after at least a part of the FW as the execution target is loaded into the RAM 253, the main module 271 is started.

[0231] For example, the main module 271 is started after at least a part of FW (Ver. X+1) stored in the main system area B is loaded into the RAM 253. Then, as necessary, data for FW (Ver. X+1) stored in the nonvolatile data area B is loaded into the RAM 253 and used while the FW (Ver. X+1) data is running.

[0232] Thereafter, the system startup process is terminated.

[0233] <Rollback processing of high performance ECU 211>

[0234] Next, we will refer to Fig.14 The sequence diagram in describes the rollback process performed by the high performance ECU 211.

[0235] Note that in the following, it is assumed that the flash memory 252 is in Fig.15 The state shown in A is similar to the above Fig.13 The state of B.

[0236] In step S41 , high performance ECU 211 receives a rollback request from, for example, an external server or the like via communication unit 22 or the like by OTA.

[0237] In step S42 , a rollback request is provided to the main module 271 .

[0238] In step S43, Fig.10 The startup system is changed in a similar manner as in step S8.

[0239] For example, Fig.15 As shown in FIG. 1B, the main system area B and the nonvolatile data area B are set as active areas, and the main system area A and the nonvolatile data area A are set as reserved areas. Then, the FW (Ver. X) in the main system area A is set as the execution target, and the FW (Ver. X) is started at the next startup and subsequent startups of the high-performance ECU 211.

[0240] As described above, even after the FW is updated and data migration is performed, the FW rollback can be correctly performed. That is, the data for the FW (Ver.X) corresponding to the FW (Ver.X) as the previous version of the FW is maintained as it is in the non-volatile data area A. Therefore, after the rollback, even in the case where a specific data conversion or the like is not required, the FW (Ver.X) as the previous version of the FW can be operated as it is.

[0241] Thereafter, the rollback process is ended.

[0242] Here, in Fig.10 During the above-mentioned FW update processing of the high-performance ECU 211 in the vehicle 1, in step S5, the data in the active non-volatile data area is copied to the reserved non-volatile data area. Therefore, as the amount of data in the non-volatile data area increases, the time required to copy the data in the non-volatile data area becomes longer, and the time required for the FW update processing also becomes longer. During the FW update processing, the vehicle 1 cannot perform its normal operation (such as driving), and as a result, there is a possibility that user convenience will be reduced.

[0243] In order to solve the above problem, a method for shortening the time required for the FW update process will be described below.

[0244] <Data backup processing of high-performance ECU 211>

[0245] First, refer to Fig.16 The sequence diagram in describes the data backup processing of the high performance ECU 211 to be performed after the FW update.

[0246] Note that in the following, it is assumed that the flash memory 252 is in Fig.17 The state shown in A is similar to the above Fig.13 The state of B.

[0247] For example, in the case where the main module 271 determines that rollback does not occur in the future and it is timing for backup, steps S101 to S104 are performed.

[0248] Here, a specific example of a method for determining whether a rollback occurs in the future will be described.

[0249] For example, the main module 271 determines that there is a possibility that a rollback will occur in the future until a notification indicating that a rollback will not occur in the future is given from the FW provider, etc. On the other hand, for example, in the case where a notification indicating that a rollback will not occur in the future has been given from the FW provider, etc. through OTA, etc., the main module 271 determines that a rollback will not occur in the future.

[0250] Alternatively, for example, main module 271 determines that there is a possibility that rollback will occur in the future until a prescribed time has passed since the last update of FW of high-performance ECU 211. On the other hand, for example, after a prescribed time has passed since the last update of FW of high-performance ECU 211, main module 271 determines that rollback will not occur in the future.

[0251] Note that the prescribed time may be preset to a prescribed time such as one week or one month. Alternatively, for example, the prescribed time may be specified by a FW provider or the like at the time of FW update or the like.

[0252] In addition, the backup timing is set to, for example, a timing when the vehicle 1 is unlikely to be used. For example, the backup timing is set to when the vehicle 1 is being charged and at a predetermined date and time. The predetermined date and time is set to, for example, a predetermined time every day, a predetermined time on a predetermined day of the week, or a predetermined time on a predetermined date, etc.

[0253] Then, in step S101 , the main module 271 sends a backup request to the backup module 272 .

[0254] In response to the request, if the backup is the first backup, that is, if the backup is the first backup after the FW is updated, step S102 is performed.

[0255] Specifically, in step S102, Fig.10 In a similar manner to S5 in , data in the active non-volatile data area is copied to the reserved non-volatile data area.

[0256] For example, Fig.17 As shown in FIG. 1B, the data for FW (Ver.X+1) in the active nonvolatile data area B is copied to the reserved nonvolatile data area A. For example, the data in the reserved nonvolatile data area A is updated to the data for FW (Ver.X+1) in the active nonvolatile data area B, and the data in the nonvolatile data area A is synchronized with the data in the nonvolatile data area B accordingly. That is, the data for FW (Ver.X+1) in the nonvolatile data area B is backed up to the nonvolatile data area A.

[0257] Thereafter, the process proceeds to step S104.

[0258] On the other hand, in the case where the backup has been performed so far, that is, in the case where the backup is the second backup or subsequent backup after the FW update, step S103 is performed.

[0259] Specifically, in step S103 , the backup module 272 copies the difference between the active non-volatile data area and the reserved non-volatile data area to the reserved non-volatile data area.

[0260] For example, the backup module 272 copies the difference between the data in the active nonvolatile data area and the data in the reserved nonvolatile data area to the reserved nonvolatile data area, that is, copies the data that exists in the active nonvolatile data area but does not exist in the reserved nonvolatile data area to the reserved nonvolatile data area.

[0261] In addition, for example, the backup module 272 deletes the difference between the data in the active nonvolatile data area and the data in the reserved nonvolatile data area from the reserved nonvolatile data area. That is, the data existing in the reserved nonvolatile data area but not in the active nonvolatile data area is deleted from the reserved nonvolatile data area.

[0262] This synchronizes the data in the active non-volatile data area with the data in the reserved non-volatile data area.

[0263] For example, data that exists in the active nonvolatile data area B but does not exist in the reserved nonvolatile data area A is copied to the reserved nonvolatile data area A. In addition, data that exists in the reserved nonvolatile data area A but does not exist in the active nonvolatile data area B is deleted from the nonvolatile data area A. This synchronizes the data in the reserved nonvolatile data area A with the data for FW (Ver. X+1) in the active nonvolatile data area B, as shown in FIG. Fig.17 As shown in Figure B.

[0264] Thereafter, the process proceeds to step S104.

[0265] In step S104 , the backup module 272 notifies the main module 271 of the completion of the backup.

[0266] Thereafter, the backup process of the high performance ECU 211 is terminated.

[0267] As a result, after it is determined that a rollback will not occur in the future, for example, the data in the reserved non-volatile data area and the data in the active non-volatile data area are periodically synchronized and matched accordingly.

[0268] <Second Embodiment of FW Update Processing of High Performance ECU 211>

[0269] First, refer to Fig.18 The sequence diagram in describes a second embodiment of the FW update process of the high performance ECU 211.

[0270] Note that in the following, it is assumed that the flash memory 252 is in Fig.19 The state shown in A is similar to the above Fig.17 The state of B.

[0271] In steps S121 to S124, the Fig.10 The same processing is performed as in steps S1 to S4.

[0272] Then, in the case where there is a data difference between the non-volatile data areas, step S125 is performed.

[0273] Specifically, in step S125, Fig.16 In a similar manner to S103 in FIG. 1 , the difference between the active non-volatile data area and the reserved non-volatile data area is copied to the reserved non-volatile data area. This synchronizes the data in the reserved non-volatile data area with the data in the active non-volatile data area.

[0274] In steps S126 to S128, the Fig.10 The same processing is performed as in steps S6 to S8.

[0275] As a result, for example, Fig.19 As shown in FIG. 2B , the FW in the main system area A is updated to FW (Ver. X+2). In addition, the main system area A and the non-volatile data area A are set as active areas, and the main system area B and the non-volatile data area B are set as reserved areas. Then, FW (Ver. X+2) in the main system area A is set as an execution target, and FW (Ver. X+2) is started at the next startup and subsequent startups of the high-performance ECU 211.

[0276] As described above, during FW update, only the difference between the active nonvolatile data area and the reserved nonvolatile data area is copied to the reserved nonvolatile data area, which shortens the time required to copy the data in the nonvolatile data area. As a result, the time required for FW update is shortened.

[0277] <First Embodiment of FW Update Processing of the Legacy ECU 212>

[0278] Next, we will refer to Fig. 20 and Fig.21 The sequence diagram in describes the first embodiment of the FW update process of the legacy ECU 212.

[0279] Note that, in the following, it is assumed that the flash memory 252 of the high-performance ECU 211 and the flash memory 302 of the legacy ECU 212 are in Fig. 22 The state shown in figure A.

[0280] Specifically, it is assumed that FW (Ver. Y) currently being the target of execution on the legacy ECU 212 is stored in the main system area of ​​the flash memory 302 of the legacy ECU 212. It is assumed that data for FW (Ver. Y) in a format compatible with FW (Ver. Y) and used by FW (Ver. Y) are stored in the non-volatile data area of ​​the flash memory 302 of the legacy ECU 212. It is assumed that FW (Ver. Y-1) which is the previous version of FW is stored in the other ECU SW area of ​​the flash memory 252 of the high-performance ECU 211. It is assumed that data for FW (Ver. Y-1) in a format compatible with FW (Ver. Y-1) and used by FW (Ver. Y-1) are stored in the other ECU data area of ​​the flash memory 252 of the high-performance ECU 211.

[0281] In step S201, the high-performance ECU 211 receives a FW update request for the legacy ECU 212 from, for example, an external server, etc. by OTA via the communication unit 22, etc. For example, the FW update request for the legacy ECU 212 includes the FW for upgrading (hereinafter, referred to as FW for updating) of the legacy ECU 212.

[0282] In step S202 , a FW update request for the legacy ECU 212 is provided to the main module 271 of the high-performance ECU 211 .

[0283] In step S203, main module 271 of high performance ECU 211 shifts to update mode. This forces high performance ECU 211 to temporarily stop its normal operation, so that normal operation of vehicle 1 (such as driving) is temporarily disabled.

[0284] In step S204 , the main module 271 of the high-performance ECU 211 sends a FW transfer request to the legacy ECU 212 .

[0285] Then, the main module 321 of the legacy ECU 212 receives the FW transfer request from the high-performance ECU 211 .

[0286] In step S205 , the FW is transferred from the legacy ECU 212 to the main module 271 of the high-performance ECU 211 .

[0287] Specifically, the main module 321 of the legacy ECU 212 sends the FW before updating, which is stored in the main system area of ​​the flash memory 302 and is currently active, to the high-performance ECU 211 .

[0288] Then, the main module 271 of the high-performance ECU 211 receives the FW from the legacy ECU 212 .

[0289] As a result, for example, FW (Ver. Y) stored in the main system area of ​​the legacy ECU 212 is transferred from the legacy ECU 212 to the high-performance ECU 211 .

[0290] In step S206 , the main module 271 of the high-performance ECU 211 sends a data transfer request to the legacy ECU 212 .

[0291] Then, the main module 321 of the legacy ECU 212 receives the data transfer request from the high-performance ECU 211 .

[0292] In step S207 , data is transferred from the legacy ECU 212 to the main module 271 of the high-performance ECU 211 .

[0293] Specifically, the main module 321 of the legacy ECU 212 sends the data before updating, which is stored in the non-volatile data area of ​​the flash memory 302 and is currently active, to the high-performance ECU 211 .

[0294] Then, the main module 271 of the high-performance ECU 211 receives the data from the legacy ECU 212 .

[0295] As a result, for example, data for FW (Ver. Y) stored in the nonvolatile data area of ​​the legacy ECU 212 is transferred from the legacy ECU 212 to the high-performance ECU 211 .

[0296] In step S208 , main module 271 of high performance ECU 211 sends a backup request to backup module 272 .

[0297] In step S209, the backup module 272 of the high-performance ECU 211 backs up the FW and data of the old ECU 212 before the update.

[0298] Specifically, the backup module 272 copies the FW received from the old ECU 212 to the other ECU SW area of ​​the flash memory 252. As a result, the FW in the other ECU SW area of ​​the high-performance ECU 211 is updated to the FW of the old ECU 212, which is currently active and before the update. That is, the FW of the old ECU 212 before the update is backed up to the other ECU SW area of ​​the high-performance ECU 211.

[0299] Specifically, the backup module 272 copies the data received from the old ECU 212 to the other ECU data area of ​​the flash memory 252. As a result, the data in the other ECU data area of ​​the high-performance ECU 211 is updated to the data for the FW of the old ECU 212, which is currently active and before the update. That is, the data for the FW of the old ECU 212 before the update is backed up to the other ECU data area of ​​the high-performance ECU 211.

[0300] For example, Fig. 22 As illustrated in B, the FW in the other ECU SW area of ​​the high performance ECU 211 is updated to the FW (Ver. Y) that is currently active and before the update. The data in the other ECU data area of ​​the high performance ECU 211 is updated to the data for the FW (Ver. Y) that is currently active and before the update.

[0301] In step S210, backup module 272 of high performance ECU 211 notifies main module 271 of the completion of the backup.

[0302] In step S211, the main module 271 of the high-performance ECU 211 sends a FW update request to the legacy ECU 212. For example, the FW update request includes the FW for updating.

[0303] Then, the main module 321 of the legacy ECU 212 receives the FW update request from the high-performance ECU 211 .

[0304] In step S212, the main module 321 of the legacy ECU 212 updates the FW. Specifically, the main module 321 writes the FW for update to the main system area of ​​the flash memory 302. As a result, the FW in the main system area of ​​the flash memory 302 is updated to the FW for update.

[0305] For example, Fig. 22 As shown in FIG. 1B , the FW in the main system area of ​​the legacy ECU 212 is updated to the latest FW (Ver. Y+1).

[0306] In step S213 , the main module 321 of the legacy ECU 212 notifies the main module 271 of the high-performance ECU 211 of the completion of the FW update.

[0307] Next, in the case where the legacy ECU 212 cannot perform data migration, steps S214 to S219 are executed.

[0308] Specifically, in step S214, main module 271 of high performance ECU 211 requests data migration module 273 to execute data format migration processing (data migration).

[0309] In step S215, data migration module 273 of high performance ECU 211 generates data for the updated FW. Specifically, data migration module 273 generates data obtained by converting data in the other ECU data area of ​​high performance ECU 211 into a format compatible with the updated FW.

[0310] As a result, for example, data for FW (Ver. Y+1) is generated in a format compatible with FW (Ver. Y+1) after update.

[0311] In step S216 , data migration module 273 of high performance ECU 211 transmits data for the updated FW to main module 271 .

[0312] In step S217, the main module 271 of the high-performance ECU 211 sends a data update request to the legacy ECU 212. For example, the data update request includes data for the updated FW.

[0313] Then, the main module 321 of the legacy ECU 212 receives the data update request from the high-performance ECU 211 .

[0314] In step S218, the main module 321 of the legacy ECU 212 updates the data. Specifically, the main module 321 copies the data for the updated FW received from the high-performance ECU 211 to the non-volatile data area of ​​the flash memory 302. As a result, the data in the non-volatile data area of ​​the flash memory 302 is updated to the data for the updated FW.

[0315] For example, Fig. 22 As illustrated in C of FIG. 1 , the data in the nonvolatile data area of ​​the legacy ECU 212 is updated to data for FW (Ver. Y+1). As a result, the legacy ECU 212 becomes capable of executing FW (Ver. Y+1).

[0316] In step S219 , the main module 321 of the legacy ECU 212 notifies the main module 271 of the high-performance ECU 211 of the completion of the data update.

[0317] Thereafter, the FW update process of the legacy ECU 212 is terminated.

[0318] On the other hand, in the case where the legacy ECU 212 is capable of performing data migration, steps S220 to S222 are performed.

[0319] Specifically, in step S220, the main module 271 of the high-performance ECU 211 requests the legacy ECU 212 to execute a data format migration process (data migration).

[0320] In step S221 , the data migration module 322 of the legacy ECU 212 updates the format of the data in the nonvolatile data area of ​​the legacy ECU 212 .

[0321] For example, Fig. 22 As illustrated in FIG. C, the data for FW (Ver. Y) in the nonvolatile data area of ​​the legacy ECU 212 is updated to data for FW (Ver. Y+1) in a format compatible with FW (Ver. Y+1). As a result, the legacy ECU 212 becomes capable of executing FW (Ver. Y+1).

[0322] In step S222 , the data migration module 273 of the legacy ECU 212 notifies the main module 271 of the high-performance ECU 211 of the completion of the data migration.

[0323] Thereafter, the FW update process of the legacy ECU 212 is ended. Then, the update mode of the high-performance ECU 211 is disabled.

[0324] <Rollback Processing for Old ECU 212>

[0325] Next, we will refer to Fig.23 The sequence diagram in describes the rollback process of the legacy ECU 212.

[0326] Note that, in the following, it is assumed that the flash memory 252 of the high-performance ECU 211 and the flash memory 302 of the legacy ECU 212 are in Fig.24 The state shown in A is similar to the above Fig. 22 The state of C.

[0327] In step S241 , the high-performance ECU 211 receives a rollback request for the legacy ECU 212 from, for example, an external server or the like by OTA via the communication unit 22 or the like.

[0328] In step S242 , a rollback request is provided to the main module 271 of the high performance ECU 211 .

[0329] In step S243, the main module 271 of the high performance ECU 211 sends a FW rollback request to the legacy ECU 212. For example, the FW rollback request includes the FW stored in the other ECU SW area of ​​the high performance ECU 211, that is, the previous version of the FW.

[0330] Then, the main module 321 of the legacy ECU 212 receives the FW rollback request from the high-performance ECU 211 .

[0331] In step S244, the main module 321 of the old ECU 212 rolls back the FW. Specifically, the main module 321 copies the FW included in the FW rollback request (i.e., the previous version of the FW) to the main system area of ​​the flash memory 302. As a result, the FW in the main system area of ​​the old ECU 212 is rolled back to the previous version of the FW.

[0332] For example, Fig.24 As illustrated in B of FIG. 2 , the FW in the main system area of ​​the legacy ECU 212 is rolled back from FW (Ver. Y+1) to FW (Ver. Y).

[0333] In step S245 , the main module 321 of the legacy ECU 212 notifies the main module 271 of the high performance ECU 211 of the completion of the FW rollback.

[0334] In step S246, the main module 271 of the high-performance ECU 211 sends a data rollback request to the legacy ECU 212. For example, the data rollback request includes data stored in the other ECU data area of ​​the high-performance ECU 211, ie, data for the previous version of FW.

[0335] Then, the main module 321 of the legacy ECU 212 receives the data rollback request from the high-performance ECU 211 .

[0336] In step S247, the main module 321 of the old ECU 212 rolls back the data. Specifically, the main module 321 copies the data included in the data rollback request (i.e., the data for the previous version of FW) to the non-volatile data area of ​​the flash memory 302. As a result, the data in the non-volatile data area of ​​the old ECU 212 is rolled back to the data for the previous version of FW.

[0337] For example, Fig.24 As illustrated in B, the data in the nonvolatile data area of ​​the legacy ECU 212 is rolled back from the data for FW (Ver. Y+1) to the data for FW (Ver. Y). As a result, the legacy ECU 212 becomes capable of executing FW (Ver. Y) which is the previous version of FW.

[0338] In step S248 , the main module 321 of the legacy ECU 212 notifies the main module 271 of the high-performance ECU 211 of the completion of the data rollback.

[0339] Thereafter, the rollback process of the old ECU 212 is ended.

[0340] As described above, since the high-performance ECU 211 backs up the previous version of the FW of the old ECU 212, it is easy to perform the rollback of the FW of the old ECU 212. In addition, since the high-performance ECU 211 backs up the data for the previous version of the FW of the old ECU 212, the old ECU 212 can start the previous version of the FW as it is without requiring specific data conversion or the like.

[0341] Here, in Fig. 20 During the above-mentioned FW update processing of the old ECU 212 in the high-performance ECU 211, in step S209, the data in the non-volatile data area of ​​the old ECU 212 is copied to the other ECU data area of ​​the high-performance ECU 211. Therefore, as the amount of data in the non-volatile data area of ​​the old ECU 212 increases, the time required to copy the data becomes longer, and the time required for the FW update processing of the old ECU 212 also becomes longer. During the FW update processing of the old ECU 212, the vehicle 1 cannot perform its normal operation (such as driving), and as a result, there is a possibility that user convenience will be reduced.

[0342] In view of the above problems, a method for shortening the time required for the FW update processing of the legacy ECU 212 will be described below.

[0343] <Data backup processing for old ECU 212>

[0344] First, refer to Fig.25 The sequence diagram in describes the data backup processing of the legacy ECU 212 to be performed after the updating of the FW of the legacy ECU 212.

[0345] Note that, in the following, it is assumed that the flash memory 252 of the high-performance ECU 211 and the flash memory 302 of the legacy ECU 212 are in Fig.26 The state shown in A is similar to the above Fig. 22 The state of C.

[0346] For example, in the case where the main module 271 of the high-performance ECU 211 determines that the data rollback of the legacy ECU 212 does not occur in the future and that this is the timing for backup, steps S301 to S306 are performed.

[0347] Note that, for example, the method for determining whether a rollback of the legacy ECU 212 will occur in the future is similar to that described above with reference to Fig.16 A method for determining whether a rollback of the high-performance ECU 211 occurs during the backup process of the high-performance ECU 211 is described.

[0348] In addition, for example, the timing for backup is also similar to the above reference Fig.16The timing of the backup process of the high performance ECU 211 is described.

[0349] In steps S301 to S303, the above Fig. 20 Similar processing is performed from steps S206 to S208 in FIG.

[0350] Then, in the case where the backup is the first backup, that is, in the case where the backup is the first backup after the update of the FW of the legacy ECU 212, step S304 is performed.

[0351] Specifically, in step S304, the backup module 272 of the high-performance ECU 211 copies the data of the old ECU 212 to the other ECU data area. That is, the backup module 272 copies the data received from the old ECU 212 to the other ECU data area of ​​the flash memory 252. As a result, the data in the other ECU data area of ​​the high-performance ECU 211 is updated to the data in the non-volatile data area of ​​the old ECU 212, and the data in the non-volatile data area of ​​the old ECU 212 and the data in the other ECU data area of ​​the high-performance ECU 211 are synchronized accordingly.

[0352] For example, Fig.26 As illustrated in FIG. 1B, the data in the other ECU data area of ​​the high-performance ECU 211 is updated to the data for FW (Ver. Y+1) in the non-volatile data area of ​​the old ECU 212, and the data in the non-volatile data area of ​​the old ECU 212 is synchronized with the data in the other ECU data area of ​​the high-performance ECU 211 accordingly. That is, the data for FW (Ver. Y+1) in the non-volatile data area of ​​the old ECU 212 is backed up to the other ECU data area of ​​the high-performance ECU 211.

[0353] Thereafter, the process proceeds to step S306.

[0354] On the other hand, in a case where the backup of the old ECU 212 has been performed so far, that is, in a case where the backup is the second backup or subsequent backup after the updating of the FW of the old ECU 212, step S305 is performed.

[0355] Specifically, in step S305, the backup module 272 of the high-performance ECU 211 copies the difference between the data of the legacy ECU 212 and the data of the other ECU data area to the other ECU data area.

[0356] For example, the backup module 272 copies the difference between the data in the other ECU data area of ​​the high-performance ECU 211 and the data in the non-volatile data area of ​​the legacy ECU 212 to the other ECU data area. That is, the data that exists in the non-volatile data area of ​​the legacy ECU 212 but does not exist in the other ECU data area of ​​the high-performance ECU 211 is copied to the other ECU data area.

[0357] In addition, for example, the backup module 272 deletes the difference between the data in the nonvolatile data area of ​​the legacy ECU 212 and the data in the other ECU data area of ​​the high-performance ECU 211 from the other ECU data area. That is, the data that exists in the other ECU data area of ​​the high-performance ECU 211 but does not exist in the nonvolatile data area of ​​the legacy ECU 212 is deleted from the other ECU data area.

[0358] This synchronizes the data in the nonvolatile data area of ​​the legacy ECU 212 with the data in the other ECU data area of ​​the high-performance ECU 211 .

[0359] For example, Fig.26 As illustrated in B, the data in the other ECU data area of ​​the high-performance ECU 211 is synchronized with the data for FW (Ver. Y+1) in the non-volatile data area of ​​the legacy ECU 212.

[0360] Thereafter, the process proceeds to step S306.

[0361] In step S306, backup module 272 of high performance ECU 211 notifies main module 271 of the completion of the backup.

[0362] Thereafter, the data backup process of the old ECU 212 is ended.

[0363] As a result, after determining that rollback of the legacy ECU 212 does not occur in the future, for example, the other ECU data area of ​​the high-performance ECU 211 and the nonvolatile data area of ​​the legacy ECU 212 are periodically synchronized, and their respective data are matched accordingly.

[0364] <Second Embodiment of FW Update Processing of Legacy ECU 212>

[0365] Next, we will refer to Fig. 27 and Fig.28 The sequence diagram in describes a second embodiment of the FW update process of the legacy ECU 212.

[0366] Note that, in the following, it is assumed that the flash memory 252 of the high-performance ECU 211 and the flash memory 302 of the legacy ECU 212 are in Fig.29 The state shown in A is similar to the above Fig.26 The state of B.

[0367] In steps S301 to S308, the Fig. 20 Similar processing is performed to steps S201 to S208 in FIG.

[0368] Then, when the backup module 272 of the high-performance ECU 211 determines that there is a difference between the data in the old ECU 212 and the data in other ECU data areas, that is, when the backup module 272 determines that there is a difference between the data in the non-volatile data area of ​​the old ECU 212 and the data in other ECU data areas of the high-performance ECU 211, step S309 is executed.

[0369] Specifically, in step S309 , the backup module 272 of the high-performance ECU 211 backs up the difference in data and FW of the legacy ECU 212 before the update.

[0370] Specifically, with the above Fig. 20 In a similar manner to S209 in FIG. 2 , the backup module 272 copies the FW received from the legacy ECU 212 to the other ECU SW area of ​​the flash memory 252 .

[0371] In addition, with the above Fig.25 In a similar manner to S305 in FIG. 1 , the backup module 272 copies the difference between the data of the old ECU 212 and the data of the other ECU data areas to the other ECU data areas.

[0372] As a result, for example, Fig.29 As shown in FIG. 1B, the FW in the other ECU SW area of ​​the high-performance ECU 211 is updated to FW (Ver. Y+1). In addition, for example, the data in the other ECU data area of ​​the high-performance ECU 211 is synchronized with the data for FW (Ver. Y+1) in the non-volatile data area of ​​the legacy ECU 212. As a result, the FW (Ver. Y+1) before the update and the data for FW (Ver. Y+1) are backed up by the high-performance ECU 211.

[0373] Thereafter, the processing proceeds to step S311.

[0374] On the other hand, when the backup module 272 of the high-performance ECU 211 determines that there is no difference between the data in the old ECU 212 and the data in other ECU data areas, that is, when the backup module 272 determines that there is no difference between the data in the non-volatile data area of ​​the old ECU 212 and the data in other ECU data areas of the high-performance ECU 211, step S310 is executed.

[0375] Specifically, in step S310, the backup module 272 of the high-performance ECU 211 backs up the FW of the old ECU 212 before the update. Fig. 20 In a similar manner to S209 in FIG. 2 , the backup module 272 copies the FW received from the legacy ECU 212 to the other ECU SW area of ​​the flash memory 252 .

[0376] As a result, for example, Fig.29 As illustrated in FIG. 1B , the FW in the other ECU SW area of ​​the high-performance ECU 211 is updated to FW (Ver. Y+1). In addition, for example, the data in the other ECU data area of ​​the high-performance ECU 211 has been synchronized with the data for FW (Ver. Y+1) in the non-volatile data area of ​​the legacy ECU 212. As a result, the FW (Ver. Y+1) before the update and the data for FW (Ver. Y+1) are backed up by the high-performance ECU 211.

[0377] Thereafter, the processing proceeds to step S311.

[0378] In steps S311 to S323, the above Fig. 20 Steps S210 to S211 Fig.21 Similar processing is performed in step S222.

[0379] For example, Fig.29 As shown in FIG. 1B, the FW in the main system area of ​​the legacy ECU 212 is updated to FW (Ver. Y+2). In addition, the data in the non-volatile data area of ​​the legacy ECU 212 is updated to data for FW (Ver. Y+2) in a format compatible with FW (Ver. Y+2). As a result, the legacy ECU 212 becomes capable of executing FW (Ver. Y+2).

[0380] Thereafter, the FW update process of the legacy ECU 212 is terminated.

[0381] As described above, during the update of the FW of the old ECU 212, only the difference between the data in the nonvolatile data area of ​​the old ECU 212 and the data in the other ECU data area of ​​the high-performance ECU 211 is copied to the other ECU data area of ​​the high-performance ECU 211. Therefore, the time required to copy the data of the old ECU 212 is shortened. As a result, the time required for the update of the FW of the old ECU 212 is shortened.

[0382] 《4. Transformation》

[0383] Hereinafter, modifications of the above-described embodiment of the present technology will be described.

[0384] For example, in the case where the legacy ECU 212 is capable of storing two or more versions of FW, the high-performance ECU 211 does not necessarily need to back up the FW of the legacy ECU 212. Furthermore, in this case, other ECU SW areas of the high-performance ECU 211 may be deleted.

[0385] For example, the high-performance ECU 211 may be provided with two other ECU SW areas and two other ECU data areas for each legacy ECU 212. Then, the high-performance ECU 211 may back up the FW and data for the FW as the execution target, and the old version of the FW and data for the FW.

[0386] The present technology is applicable to, for example, a configuration having a nonvolatile and rewritable memory (storage unit) other than a flash memory.

[0387] The present technology can be applied to devices or systems other than vehicles that perform software updates or rollbacks by OTA, etc. Possible examples of applications include smartphones, PCs, tablet terminals, digital cameras, robots, mobile objects other than vehicles, etc.

[0388] 《5. Others》

[0389] <Computer configuration example>

[0390] The above series of processes can be performed by hardware or software. In the case of performing the series of processes by software, a program that configures the software is installed in a computer. Here, examples of computers include computers incorporated in dedicated hardware, general-purpose personal computers that can perform various functions by installing various programs, etc.

[0391] Fig.30 : is a block diagram illustrating a hardware configuration example of a computer that executes the above-described series of processes according to a program.

[0392] In a computer 1000 , a central processing unit (CPU) 1001 , a read only memory (ROM) 1002 , and a random access memory (RAM) 1003 are connected to one another via a bus 1004 .

[0393] An input / output interface 1005 is further connected to the bus 1004. An input unit 1006, an output unit 1007, a storage unit 1008, a communication unit 1009, and a drive 1010 are connected to the input / output interface 1005.

[0394] The input unit 1006 includes an input switch, a button, a microphone, an imaging element, etc. The output unit 1007 includes a display, a speaker, etc. The storage unit 1008 includes a hard disk, a nonvolatile memory, etc. The communication unit 1009 includes a network interface, etc. The drive 1010 drives a removable medium 1011 such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory.

[0395] In the computer 1000 configured as described above, for example, the above-described series of processes is performed by the CPU 1001 loading a program stored in the storage unit 1008 into the RAM 1003 via the input / output interface 1005 and the bus 1004 and executing the program.

[0396] For example, the program executed by the computer 1000 (CPU 1001) can be provided by being recorded in the removable medium 1011 as a package medium, etc. Furthermore, the program can be provided via a wired or wireless transmission medium such as a local area network, the Internet, or digital satellite broadcasting.

[0397] In the computer 1000, the program can be installed in the storage unit 1008 via the input / output interface 1005 with the removable medium 1011 attached to the drive 1010. In addition, the program can be received by the communication unit 1009 by means of a wired or wireless transmission medium to be installed in the storage unit 1008. In addition, the program can be pre-installed in the ROM 1002 or the storage unit 1008.

[0398] Note that the program executed by the computer may be a program that executes processing in the time series described in this specification, or may be a program that executes processing in parallel or at necessary timing such as when a call is made.

[0399] In addition, in this specification, a system means a collection of multiple components (devices, modules (components), etc.), and it does not matter whether all the components are in the same housing. Therefore, multiple devices housed in separate housings and connected to each other via a network and a single device including multiple modules housed in a single housing are both systems.

[0400] Furthermore, the embodiments of the present technology are not limited to the above-described embodiments, and various modifications may be made without departing from the gist of the present technology.

[0401] For example, the present technology may be implemented in cloud computing in which functions are performed by a plurality of devices in a shared manner via a network.

[0402] Furthermore, for example, each step described in the above sequence diagrams may be performed by one device, or may be shared and performed by a plurality of devices.

[0403] Furthermore, in the case where a single step includes a plurality of processes, the plurality of processes included in the single step may be performed by a single device, or may be performed by a plurality of devices in a shared manner.

[0404] <Configuration combination example>

[0405] The present technology may also have the following configurations.

[0406] (1) An information processing device comprising:

[0407] a software management unit that manages software; and

[0408] A storage unit, the storage unit comprising a first software area, a second software area, a first data area corresponding to the first software area, and a second data area corresponding to the second software area, wherein:

[0409] The software management unit stores the first current software as an execution target in one of the first software area or the second software area, stores the first old software as a software version previous to the first current software in the other software area, stores data in a format compatible with the first current software in a data area corresponding to the one software area in the first data area or the second data area, and stores data in a format compatible with the first old software in the other data area.

[0410] (2) The information processing device according to (1) above, wherein:

[0411] In case of rolling back the first current software to the first old software, the software management unit performs control to execute the first old software in the another software area and use data in the another data area.

[0412] (3) The information processing device according to (2) above, wherein:

[0413] In a case where it is determined that the rollback from the first current software to the first old software does not occur, the software management unit updates the data in the other data area to the data in the one data area.

[0414] (4) The information processing device according to (3) above, wherein:

[0415] After the data in the other data area is updated, the software management unit copies a difference between the data in the one data area and the data in the other data area to the other data area at a predetermined timing.

[0416] (5) The information processing device according to (4) above, wherein:

[0417] In the case where the first current software is upgraded to new software which is a later version of the first current software, the software management unit stores the new software in the other software area, and when there is a difference between the data in the one data area and the data in the other data area, copies the difference between the data in the one data area and the data in the other data area to the other data area.

[0418] (6) The information processing device according to (5) above, wherein:

[0419] The software management unit converts the data in the another data area into a format compatible with the new software.

[0420] (7) The information processing device according to any one of (3) to (6) above, which is installed in a vehicle, wherein:

[0421] In a case where it is determined that rollback from the first current software to the first old software does not occur, the software management unit updates the data in the other data area to the data in the one data area while the vehicle is being charged.

[0422] (8) The information processing device according to (1) above, wherein:

[0423] In the case of upgrading the first current software to new software which is a later version of the first current software, the software management unit stores the new software in the other software area, updates the data in the other data area to the data in the one data area, and converts the data in the other data area after the update into a format compatible with the new software.

[0424] (9) The information processing device according to (1) above, wherein:

[0425] The storage unit further includes a third data area, and

[0426] The software management unit stores old data which is data in a format compatible with second old software which is software of a previous version of second current software as an execution target on another information processing device in the third data area.

[0427] (10) The information processing device according to (9) above, wherein:

[0428] In case of rolling back the second current software to the second old software, the software management unit transmits the old data in the third data area to the another information processing device.

[0429] (11) The information processing device according to (9) or (10) above, wherein:

[0430] When the second current software is upgraded to new software which is a later version of the second current software, the software management unit obtains current data which is data in a format compatible with the second current software from the other information processing device, and updates the data in the third data area to the current data.

[0431] (12) The information processing device according to (11) above, wherein:

[0432] The software management unit generates new data obtained by converting the current data into a format compatible with the new software, and transmits the new data to the another information processing device.

[0433] (13) The information processing device according to any one of (9) to (12) above, wherein:

[0434] The storage unit further includes a third software area, and

[0435] The software management unit stores the second old software in the third software area.

[0436] (14) The information processing device according to (13) above, wherein:

[0437] In the case of rolling back the second current software to the second old software, the software management unit transmits the second old software in the third software area and the old data in the third data area to the another information processing device.

[0438] (15) The information processing device according to (13) or (14) above, wherein:

[0439] In the case of upgrading the second current software to new software which is a later version of the second current software, the software management unit obtains the second current software and current data which is data in a format compatible with the second current software from the other information processing device, updates the software in the third software area to the second current software, and updates the data in the third data area to the current data.

[0440] (16) The information processing device according to any one of (1) to (15) above, wherein:

[0441] The storage unit includes a flash memory.

[0442] (17) The information processing device according to any one of (1) to (16) above, wherein:

[0443] The information processing device is installed in a vehicle.

[0444] (18) An information processing method causing an information processing device to execute a process, the process comprising:

[0445] storing current software as an execution target in one of a first software area or a second software area of ​​a storage unit, and storing old software as software of a previous version of the current software in the other software area; and

[0446] Data in a format compatible with the current software is stored in one data area corresponding to the one software area in the first data area or the second data area of ​​the storage unit, and data in a format compatible with the old software is stored in another data area.

[0447] Note that the effects described in this specification are merely examples and not limitations, and other effects may be provided.

[0448] Reference Symbols List

[0449] 1 Vehicle

[0450] 11 Vehicle Control System

[0451] 21 Vehicle Control System

[0452] 201 Information Processing Systems

[0453] 211-1 to 211-m High-performance ECU

[0454] 212-1 to 212-n Legacy ECU

[0455] 251 CPU

[0456] 252 Flash memory

[0457] 253 RAM

[0458] 261 Software Management Unit

[0459] 271 Main Module

[0460] 272 Backup Module

[0461] 273 Data Migration Module

[0462] 301 CPU

[0463] 302 Flash memory

[0464] 303 RAM

[0465] 304 External NVRAM

[0466] 311 Software Management Unit

[0467] 321 Main Module

[0468] 322 Data Migration Module

Claims

1. An information processing device, comprising: A software management unit, wherein the software management unit manages software; as well as A storage unit, the storage unit comprising a first software area, a second software area, a first data area corresponding to the first software area, and a second data area corresponding to the second software area, wherein: The software management unit stores the first current software as an execution target in one of the first software area or the second software area, stores the first old software as a software version previous to the first current software in the other software area, stores data in a format compatible with the first current software in a data area corresponding to the one software area in the first data area or the second data area, and stores data in a format compatible with the first old software in the other data area.

2. The information processing device according to claim 1, wherein: In case of rolling back the first current software to the first old software, the software management unit performs control to execute the first old software in the another software area and use data in the another data area.

3. The information processing device according to claim 2, wherein: In a case where it is determined that the rollback from the first current software to the first old software does not occur, the software management unit updates the data in the other data area to the data in the one data area.

4. The information processing device according to claim 3, wherein: After the data in the other data area is updated, the software management unit copies a difference between the data in the one data area and the data in the other data area to the other data area at a predetermined timing.

5. The information processing device according to claim 4, wherein: In the case where the first current software is upgraded to new software which is a later version of the first current software, the software management unit stores the new software in the other software area, and when there is a difference between the data in the one data area and the data in the other data area, copies the difference between the data in the one data area and the data in the other data area to the other data area.

6. The information processing device according to claim 5, wherein: The software management unit converts the data in the another data area into a format compatible with the new software.

7. The information processing device according to claim 3, wherein the information processing device is installed in a vehicle, In a case where it is determined that rollback from the first current software to the first old software does not occur, the software management unit updates the data in the other data area to the data in the one data area while the vehicle is being charged.

8. The information processing device according to claim 1, wherein: In the case of upgrading the first current software to new software which is a later version of the first current software, the software management unit stores the new software in the other software area, updates the data in the other data area to the data in the one data area, and converts the data in the other data area after the update into a format compatible with the new software.

9. The information processing device according to claim 1, wherein: The storage unit further includes a third data area, and The software management unit stores old data which is data in a format compatible with second old software which is software of a previous version of second current software as an execution target on another information processing device in the third data area.

10. The information processing device according to claim 9, wherein: In case of rolling back the second current software to the second old software, the software management unit transmits the old data in the third data area to the another information processing device.

11. The information processing device according to claim 9, wherein: When the second current software is upgraded to new software which is a later version of the second current software, the software management unit obtains current data which is data in a format compatible with the second current software from the other information processing device, and updates the data in the third data area to the current data.

12. The information processing device according to claim 11, wherein: The software management unit generates new data obtained by converting the current data into a format compatible with the new software, and transmits the new data to the another information processing device.

13. The information processing device according to claim 9, wherein: The storage unit further includes a third software area, and The software management unit stores the second old software in the third software area.

14. The information processing device according to claim 13, wherein: In the case of rolling back the second current software to the second old software, the software management unit transmits the second old software in the third software area and the old data in the third data area to the another information processing device.

15. The information processing device according to claim 13, wherein: In the case of upgrading the second current software to new software which is a later version of the second current software, the software management unit obtains the second current software and current data which is data in a format compatible with the second current software from the other information processing device, updates the software in the third software area to the second current software, and updates the data in the third data area to the current data.

16. The information processing device according to claim 1, wherein: The storage unit includes a flash memory.

17. The information processing device according to claim 1, wherein: The information processing device is installed in a vehicle.

18. An information processing method for causing an information processing device to perform a process, the process comprising: storing current software as an execution target in one of a first software area or a second software area of ​​a storage unit, and storing old software as software of a previous version of the current software in the other software area; as well as Data in a format compatible with the current software is stored in one data area corresponding to the one software area in the first data area or the second data area of ​​the storage unit, and data in a format compatible with the old software is stored in another data area.