Control device, control method, and non-transitory computer-readable storage medium storing program
By designing control devices and methods in the vehicle, the processing circuit control display unit displays software update information, and performs update processing after the power is disconnected, the problem that the user cannot grasp the situation after the vehicle software update is terminated, and the effect of the user clearly understanding the update status and being able to start the update again is achieved.
Patent Information
- Application Number
- CN202411509448.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-30
- Filing Date
- 2024-10-28
- Publication Date
- 2025-05-30
AI Technical Summary
When the software update process is performed after the vehicle power is disconnected, it may be suspended due to various important factors, which will cause users to be unable to grasp the update status the next time they ride, causing confusion.
A control device and method are designed to control the display unit to display information related to software updates through the processing circuit. According to the operation of the power disconnection of the vehicle-mounted equipment, the software update process is executed, and the abort information that the update process is not executed is displayed when the update process is hindered.
Ensure that users can clearly understand the update status when aborting software updates, and restart the update processing when conditions allow, so as to avoid users being confused by unknown status.
Smart Images

Figure CN120056884A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a control device, a control method, and a non-transitory computer-readable storage medium storing a program. Background Art
[0002] Various in-vehicle devices that operate by executing software are mounted on a vehicle. As disclosed in Japanese Unexamined Patent Application Publication No. 2022-163396, there is known an OTA (Over The Air) technology for updating the software of in-vehicle devices by downloading software from outside the vehicle via wireless communication to add or change the functions of the vehicle.
[0003] On the one hand, there is a case where software update processing is executed after a power-off operation of the vehicle. On the other hand, there is a case where the software update processing is aborted due to various important factors. When the update processing is aborted during the period when the user of the vehicle gets off, there is a possibility that the user may be confused without knowing the situation when getting in the vehicle next time. Summary of the Invention
[0004] According to one aspect of the present disclosure, there is provided a control device. The control device includes a processing circuit configured to perform: controlling a display unit that displays information related to software update, wherein, based on a specified operation for turning off the power of an in-vehicle device mounted on a vehicle, performing software update processing of the in-vehicle device; and when a situation that hinders the execution of the update processing occurs during the execution of the specified operation, causing an abort information indicating that the update processing has not been executed to be displayed on the display unit.
[0005] According to one aspect of the present disclosure, there is provided a control method. The control method includes: controlling a display unit that displays information related to software update, wherein, based on a specified operation for turning off the power of an in-vehicle device mounted on a vehicle, performing software update processing of the in-vehicle device; and when a situation that hinders the execution of the update processing occurs during the execution of the specified operation, causing an abort information indicating that the update processing has not been executed to be displayed on the display unit.
[0006] According to one aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing a program. When the program is executed by a control device, the control device is caused to perform: controlling a display unit that displays information related to software update, wherein, based on a specified operation for turning off the power of an in-vehicle device mounted on a vehicle, performing software update processing of the in-vehicle device; and when a situation that hinders the execution of the update processing occurs during the execution of the specified operation, causing an abort information indicating that the update processing has not been executed to be displayed on the display unit. Brief Description of the Drawings
[0007] Figure 1 It is a diagram schematically showing the structure of the control device and the vehicle of the first embodiment.
[0008] Figure 2 It is a flowchart of the display control program executed by the control device of the first embodiment.
[0009] Figure 3 It is a diagram showing an example of an image of the guidance information during the execution of the display update.
[0010] Figure 4 It is a diagram showing an example of an image of the guidance information when the display update is completed.
[0011] Figure 5 It is a diagram showing an example of an image of the display abort information.
[0012] Figure 6 It is a sequence diagram showing the flow of the process related to the display control of the information during the update process in the second embodiment.
[0013] Figure 7 It is a diagram showing an example of an image of the guidance information in the case where the display update process can be restarted after being aborted. Detailed Embodiment
[0014] (First Embodiment)
[0015] Hereinafter, with reference to Figures 1 to 5 the first embodiment of the control device, the vehicle, the control method, and the non-transitory computer-readable storage medium storing the program will be described in detail.
[0016] <Control Device and Vehicle Structure>
[0017] First, with reference to Figure 1 the structure of the control device and the vehicle of the present embodiment will be described. As Figure 1As shown, on vehicle 10, in-vehicle devices such as an OTA host 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18 are mounted. The HMI 18 is an example of a display unit. These in-vehicle devices are communicably connected to each other via an in-vehicle network 19. The OTA host 11 is responsible for the management of software updates for in-vehicle devices including itself. The DCM 12 is a data communication module that provides wireless communication functions with the outside of the vehicle via a mobile communication network 20. In the case of this embodiment, the DCM 12 undertakes the function of recording the results of self-diagnostics performed by each in-vehicle device of the vehicle 10 and sending them to a data center or the like outside the vehicle. The ADAS 13 is an advanced driving assistant system (Advanced Driving Assistant System) that provides advanced driving assistance functions such as an automatic braking device and an emergency start prevention device. The PCU 14 is a power control unit (Power Control Unit) that controls the power in the vehicle. The engine ECU 15 is an electronic control unit for engine control (Electronic Control Unit). The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a human machine interface (Human Machine Interface). The HMI 18 includes an input device that accepts operations by the occupants and a display device that displays information to the occupants through images and sounds. The HMI 18 may also be configured to have a navigation function for guiding a driving route and an entertainment function for playing music and videos. Each of these in-vehicle devices has a storage module 21 that stores software and a processor 22 that executes the software. The OTA host 11 also has a data storage 23 that stores updated software obtained from outside the vehicle.
[0018] The vehicle 10 has multiple power modes. The multiple power modes include a power mode for driving and a power mode for parking. According to each power mode, it is determined which in-vehicle device's power is to be turned on. When setting the power mode for driving, the power of the in-vehicle devices required for the vehicle 10 to drive and provide services during driving is turned on. In the case of this embodiment, when setting the power mode for driving, Figure 1 the power of all the in-vehicle devices shown is turned on. When setting the power mode for parking, the power of only the in-vehicle devices that need to operate even when the vehicle 10 is parked is turned on. The in-vehicle devices whose power is turned on in each power mode can be changed according to the environment and user settings.
[0019] In the vehicle 10, there is a power switch 24 for switching between the power mode for driving and the power mode for parking. The switching from the power mode for driving to the power mode for parking is performed according to the switching of the power switch 24 from on to off. The switching from the power mode for parking to the power mode for driving is performed according to the switching of the power switch 24 from off to on. In a conventional vehicle with only an engine as a drive source, the power switch 24 is sometimes called an ignition switch. In addition, in a vehicle capable of electric driving such as a BEV or PHEV, the power switch 24 is sometimes called a Ready switch.
[0020] In addition, in the vehicle 10, there is a power switch 24 for switching between power-on and power-off of the vehicle 10. The drive system of the vehicle 10 starts according to the switching from power-off to power-on and stops according to the switching from power-on to power-off.
[0021] The vehicle 10 is connected to an OTA server 30 via a mobile communication network 20. The OTA server 30 is a server device that distributes update software for in-vehicle devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing the update software, and a processor 32 that executes the distribution program.
[0022] The OTA server 30 can communicate with an information terminal 40 of a user of the vehicle 10 via the mobile communication network 20. Examples of the information terminal 40 include a smart phone. The information terminal 40 may also be a tablet terminal or a PC terminal. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes software stored in the storage device 41. The HMI 43 includes an input device that accepts user operations and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as information confirmation and remote operation of the vehicle 10 owned by the user.
[0023] <Overview of Software Update>
[0024] Next, an overview of the software update of in-vehicle devices in the vehicle 10 will be described. The in-vehicle devices that are the objects of software update include an OTA host 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18. The software update is performed through a download phase, an installation phase, and an activation phase.
[0025] In the download phase, the updated software is sent from the OTA server 30 to the vehicle 10. The OTA host 11 stores the updated software received from the OTA server 30 in the data storage 23. In the download phase, a series of processes related to downloading, including judgment of whether downloading can be executed, verification of update data, etc., are performed. The sending of the updated software from the OTA server 30 to the OTA host 11 can also be carried out by sending compressed data obtained by compressing the updated software, or by sending segmented data obtained by segmenting the updated software or the compressed data. Additionally, the updated software for multiple in-vehicle devices can be sent together.
[0026] In the installation phase, the updated software is installed on the in-vehicle device to be updated. In the installation phase, the OTA host 11 installs the updated software on the storage module 21 of the in-vehicle device to be updated based on the update data downloaded to the data storage 23. In the installation phase, a series of processes related to installation, including judgment of whether installation can be executed, transmission of update data, verification of the updated software, etc., are performed. When the update data contains the updated software itself, in the installation phase, the OTA host 11 transmits the update data to the in-vehicle device to be updated. When the update data contains compressed data, differential data, or segmented data of the updated software, the generation process of the updated software is performed. The generation process can be carried out by the OTA host 11 or by the in-vehicle device to be updated. The generation of the updated software can be performed by decompressing the compressed data, assembling the differential data, or assembling the segmented data. In addition, when the installation phase is completed, the updated software is invalidated.
[0027] In the activation phase, in the in-vehicle device to be updated, the activation of the updated software, that is, the validation of the updated software, is implemented. The activation phase includes a series of processes related to activation, including judgment of whether activation can be executed, matching check of the updated software, verification of the execution result of activation, etc.
[0028] Depending on the hardware structure of the in-vehicle device, the type of software, etc., there are cases where the software update process is executed according to the power-off operation of the vehicle 10. In the case of this embodiment, the update process includes both the installation phase and the activation phase. The update process can also be a process including either the installation phase or the activation phase.
[0029] If the download phase is completed, the OTA host 11 asks the user via the HMI 18 whether to perform the update process after the next power-off operation. When the user permits the execution of the update process in response to this query, the OTA host 11 starts the update process after performing an operation to power off the vehicle 10. The in-vehicle device that starts the update process here is the in-vehicle device whose power is turned off by the operation to power off the vehicle 10. In the case of this embodiment, the operation to power off the vehicle 10 corresponds to a prescribed operation to power off the in-vehicle device that executes the software update.
[0030] Depending on the situation, there are cases where the execution of the update process is hindered when the power-off operation of the vehicle 10 is performed. Examples of the situation that hinders the execution of the update process are situations where the power of the in-vehicle device to be updated cannot be turned off even after the power-off operation of the vehicle 10. Specific examples of such situations include the following situations (A) to (C).
[0031] Situation (A) is a situation where the execution of the software update process is hindered in association with the downhill suppression control of the vehicle 10 parked on a slope. When the vehicle 10 is parked on a steep slope, the vehicle 10 may slide due to insufficient action of the parking brake or the like. In the vehicle 10, there are vehicles that perform control to suppress the downhill movement of the vehicle 10 by the operation of the hydraulic brake and steering when the start of the vehicle 10 is detected during parking on a slope. When the vehicle 10 is parked on a slope that satisfies a predetermined condition, the downhill suppression control is executed. An example of the predetermined condition is that the slope of the slope where the vehicle 10 is parked is a predetermined value or more. When the downhill suppression control is being executed, the in-vehicle devices related to the execution continue to operate even after the power-off operation of the vehicle 10. When the downhill suppression control is being executed, there are cases where the software update process of the in-vehicle devices related to the execution cannot be performed. In addition, in order to complete the installation and activation during the update process, it is necessary to temporarily turn off the power of the in-vehicle device to restart the in-vehicle device. On the other hand, when the downhill suppression control is being executed, the power of the in-vehicle devices related to the downhill suppression control cannot be turned off even after the power-off operation of the vehicle 10, so there are cases where the update process cannot be performed. The in-vehicle devices related to the execution of the downhill suppression are the in-vehicle devices that monitor the movement of the parked vehicle 10, the in-vehicle devices that perform the braking or steering operation of the vehicle 10, etc. In Figure 1 this case, the ADAS 13 and the brake ECU 17 are the in-vehicle devices related to the execution of the downhill suppression control.
[0032] Condition (B) is a condition that hinders the execution of the update process in relation to the emergency notification system of the vehicle 10. The emergency notification system is a system that monitors the parked vehicle 10 and notifies the outside in the event of an abnormality. In the operation of the emergency notification system, in-vehicle devices associated with the operation of the system continue to operate even after the power-off operation of the vehicle 10, and thus the power cannot be turned off, so the software update cannot be executed. In Figure 1 the case of, DCM 12 and ADAS 13 are in-vehicle devices associated with the operation of the emergency notification system. In addition, the user can switch whether to operate the emergency notification system.
[0033] Condition (C) is a condition that hinders the execution of the update process in relation to the power supply setting of the HMI 18 during the power-off period of the vehicle 10. The HMI 18 is configured to be able to switch the power supply setting after the power-off operation of the vehicle 10 to the following first state and second state. The first state is a sleep state in which the screen darkens after the power-off operation of the vehicle 10, but some functions continue to operate and the display can be implemented according to an instruction from the outside. The second state is a shutdown state in which the power supply of the HMI 18 itself is turned off according to the power-off operation of the vehicle 10 and the display cannot be implemented. The HMI 18 is configured such that the user can switch such power supply settings. In the case of the present embodiment, during the software update process corresponding to the power-off operation of the vehicle 10, information related to the update is displayed on the HMI 18. When the power supply setting of the HMI 18 is the second state (shutdown state), the information display during the update process cannot be implemented. Therefore, when the power supply setting of the HMI 18 is the second state, the update process corresponding to the power-off operation of the vehicle 10 is not executed.
[0034] <Display Control of Information Corresponding to Update Process>
[0035] The OTA host 11 executes the display control of the information displayed on the HMI 18 during the update process. Hereinafter, the details of the display control will be described.
[0036] In Figure 2 is shown the processing sequence of the display control program executed by the OTA host 11 for the display control of the information corresponding to the update process. The OTA host 11 starts this program when the user permits the execution of the update process.
[0037] The OTA host 11 stands by after the start of this program until the vehicle 10 is powered off and the update process is started (S10). If the update process is started (S10: Yes), the OTA host 11 displays the guidance information indicating that the update process is in progress on the HMI 18 (S11). After that, if the update process is completed (S13: Yes), the OTA host 11 ends the process of this program after displaying the guidance information indicating the completion of the update process on the HMI 18 (S14).
[0038] On the contrary, in the case where the execution of the update process is aborted due to the occurrence of a situation that hinders the execution of the update process as described above (S12: Yes), the OTA host 11 displays the abort information indicating that the update process has not been executed on the HMI 18 (S15). After that, the OTA host 11 waits for the above situation to be eliminated and restarts the update process (S16). If the update process is restarted (S16: Yes), the OTA host 11 returns the process to S11. In this case, the OTA host 11 Figure 2 displays the guidance information indicating that the update process is in progress on the HMI 18 in S11. By seeing this guidance information after seeing the abort information, the user can grasp that the aborted update process can be executed. In this way, in the present embodiment, when the situation that hinders the execution of the update process is eliminated after the display of the abort information, the information displayed on the HMI 18 is changed from the abort information to the guidance information indicating that the update process can be executed.
[0039] In addition, there is a situation where a situation that hinders the execution of the update process has occurred at the moment when the vehicle 10 is powered off. In such a case, the OTA host 11 displays the abort information on the HMI 18 without starting the update process.
[0040] In Figure 3 shows an example of an image displaying the guidance information indicating that the update process is in progress. In the Figure 3 image, while displaying the guidance information indicating that the update process is in progress, information indicating the progress of the update process is also displayed. In addition, in the Figure 3 image, information that wakes up the user's attention, such as that the power-on operation of the vehicle 10 cannot be performed until the update process is completed, is displayed.
[0041] In Figure 4 shows an example of an image displaying the guidance information indicating that the update process has been completed. In the Figure 4 image, while displaying the guidance information indicating that the update process has been completed, information notifying that the functions of the in-vehicle devices updated can be used is also displayed. And, in the Figure 4 image, an operation button for confirming the detailed information of the software update is displayed.
[0042] In Figure 5 FIG. Figure 5 shows an example of an image displaying abort information indicating that the update process has not been executed. In Figure 5 the image of FIG. Figure 5 , operation buttons for displaying more detailed information are also displayed while the abort information is being displayed. If the operation buttons are operated, more detailed abort information is displayed on the HMI 18. The information displayed at this time includes information indicating the reason for the abort of the update process and information indicating the operations required of the user to restart the update process. For example, in the case of situation (A), the fact that parking on a steep slope has obstructed the execution of the update process and that the update process can be restarted by reparking the vehicle 10 on a flat place is displayed on the HMI 18 as detailed abort information. In the case of situation (B), the fact that the emergency notification system is operating has obstructed the execution of the update process and that the update process can be restarted by stopping the operation of the emergency notification system is displayed on the HMI 18 as detailed abort information. In the case of situation (C), the fact that the power supply setting of the HMI 18 is in the off state has obstructed the execution of the update process and that the update process can be restarted by switching the power supply setting to the sleep state is displayed on the HMI 18 as detailed abort information.
[0043] <Effect and Advantage of Embodiment>
[0044] The effect and advantage of the present embodiment will be described.
[0045] The OTA host 11 starts the update process according to the power-off operation of the vehicle 10. When the OTA host 11 starts the update process, it causes guidance information indicating that the update process is in progress to be displayed on the HMI 18. Further, when the update process is completed, the OTA host 11 causes guidance information indicating that the update process has been completed to be displayed on the HMI 18.
[0046] There are cases where the execution of the update process is aborted due to a situation that has obstructed the execution of the update process. In such a case, the OTA host 11 causes abort information indicating that the update process has not been executed to be displayed on the HMI 18. The user can confirm from this display that the update process has been aborted. Further, when the update process has been aborted, the OTA host 11 causes information indicating the reason for the abort of the update process and the operations required of the user to restart the update process to be displayed on the HMI 18. By operating according to the information displayed, the user can restart the update process.
[0047] According to the present embodiment described above, the following effects can be achieved.
[0048] (1) The OTA host 11 performs software updates for in-vehicle devices in such a way that the software of the in-vehicle devices is updated according to a specified operation that disconnects the power supply of the in-vehicle devices. When a situation that hinders the execution of the update process occurs during the specified operation, the OTA host 11 causes the HMI 18 to display abort information indicating that the update process has not been executed. Therefore, when the software update of the in-vehicle device is aborted, it is easy for the user to grasp the situation.
[0049] (2) When the situation that hinders the execution of the update process is eliminated after the display of the abort information, the OTA host 11 changes the information displayed on the HMI 18 from the abort information to guidance information indicating that the update process can be executed. Therefore, when the update process that can be temporarily aborted can be executed, it is easy for the user to grasp the situation.
[0050] (3) In the detailed abort information displayed by the OTA host 11 on the HMI 18, it includes information indicating the situation that hinders the execution of the update process and information indicating the method for eliminating this situation. Therefore, it is easy for the user to restart the update process.
[0051] (Second Embodiment)
[0052] Next, with reference to Figure 6 , the second embodiment of the control device, control method, and program will be described in detail. In addition, in this embodiment, for the structures common to the above-described embodiment, the same reference numerals are given and their detailed descriptions are omitted.
[0053] In the case of the first embodiment, the OTA host 11 causes information related to the update process to be displayed on the HMI 18 provided in the vehicle 10. In the case of this embodiment, information related to the update process is displayed on the HMI 43 of the information terminal 40 possessed by the user of the vehicle 10. Moreover, the display control is performed by the OTA server 30 in the data center.
[0054] In Figure 6 shows the flow of the process related to the display control of the information related to the update process in this embodiment. In Figure 6 's case, the update process of the in-vehicle device is started according to the power-off operation of the vehicle 10 (S20). The vehicle 10 notifies the OTA server 30 that the update process has started (S21). The OTA server 30, based on the notification, instructs the information terminal 40 to display guidance information indicating that the update process is in progress (S22). The information terminal 40 starts the display of this guidance information according to the instruction (S23). At this time, an image based on Figure 3 is displayed on the information terminal 40.
[0055] In Figure 6In the case where, afterwards, the vehicle 10 encountered a situation that hindered the execution of the update process and the update process was aborted. At this time, the vehicle 10 notified the OTA server 30 that the update process had been aborted (S24). Based on the notification, the OTA server 30 instructed the information terminal 40 to display the abort information (S25). The information terminal 40 switched the displayed information from the above-mentioned guiding information to the abort information according to the instruction (S26). Thus, an image based on Figure 5 is displayed on the information terminal 40.
[0056] Afterwards, in the vehicle 10, the update process was restarted (S28). At this time, the vehicle 10 notified the OTA server 30 of the restart of the update process (S27). Based on the notification, the OTA server 30 instructed the information terminal 40 to display information indicating that the update process was in progress (S29). The information terminal 40 switched the displayed information from the abort information to the guiding information indicating that the update process was in progress according to the instruction (S30).
[0057] In Figure 6 the case where, afterwards, the update process was continued until completion. If the update process was completed, the vehicle 10 notified the OTA server 30 of the completion of the update process (S31). Based on the notification, the OTA server 30 instructed the information terminal 40 to display the guiding information indicating the completion of the update process (S32). The information terminal 40 switched the displayed information to the guiding information indicating the completion of the update process according to the instruction (S33).
[0058] In the case of this embodiment, the user can confirm information related to the update process on the information terminal 40. In the case of this embodiment, the same functions and effects as those of the first embodiment can also be achieved. The display control of the information on the information terminal 40 in this embodiment can also be executed together with the display control of the information on the HMI 18 of the vehicle 10 in the first embodiment.
[0059] (Other embodiments)
[0060] The above embodiments can be modified and implemented as follows. The above embodiments and the following modification examples can be combined and implemented within the scope of no technical contradiction.
[0061] · When restarting the aborted update process, the user's permission can also be requested. In this case, after the situation that hindered the execution of the update process is eliminated, for example, an image as shown in Figure 7 is displayed on the HMI 18 and the information terminal 40 to ask the user whether to restart the update process. By displaying such an image, the user can confirm that the temporarily aborted update process can be executed. Therefore, the image asking the user whether to restart the update process includes guiding information indicating that the update process can be executed.
[0062] · Figures 3 to 5 and Figure 7 The display examples of each image shown are configured to display information using text. These images may be configured to display information using expressions other than text, such as still images and animations.
[0063] The suspension information may not include one or both of the information indicating the content of the situation that prevents the execution of the update process and the information indicating the method for eliminating the situation. The suspension information may include at least information indicating that the update process is not executed.
[0064] The OTA host 11 that manages software updates controls the display of information related to software updates. Software updates can also be managed and the display of information related to software updates can be controlled by other in-vehicle devices. For example, the in-vehicle device that is the target of software updates can also control the display of information of the HMI 18 in the first embodiment.
[0065] In the above embodiment, the case where the power of the vehicle-mounted device that executes the software update process is configured to be turned off in conjunction with the off operation of the power switch 24 of the vehicle 10 is described. There is a case where the vehicle-mounted device is configured so that the power is turned off according to an operation other than the above. For example, there is a case where the vehicle 10 has three power modes corresponding to the IG (ignition) on state, the ACC (accessory power supply) on state, and the vehicle power off state described below. The IG on state is a state in which the engine of the vehicle is running and the power of a plurality of ECUs is turned on. The ACC on state is a state in which only a part of the ECUs compared to the IG on state are powered on. The vehicle power off state is a state in which the power of almost all ECUs is turned off. In this case, it is conceivable that the software update process of the vehicle-mounted device whose power is turned off according to the switching operation from the IG on state to the ACC on state is started. When a situation that hinders the execution of the update process occurs after the switching operation from the IG on state to the ACC on state is performed, if the suspension information is displayed, the effect of making it easy for the user to understand the situation can also be obtained. In this way, the display of the suspension information in the above embodiment can be performed in the following cases. That is, during a software update in which the update process of the in-vehicle device is executed in response to a predetermined operation to turn off the power of the in-vehicle device, a situation that prevents the execution of the update process occurs when the predetermined operation is performed.
[0066] · The control device can be configured as one or more processors that operate according to a computer program, one or more dedicated hardware circuits such as dedicated hardware that performs at least a part of various processes, or a processing circuitry that includes a combination of these. As dedicated hardware, for example, an ASIC as an integrated circuit for a specific purpose can be cited. The processor includes a CPU and memories such as RAM and ROM, and the memories store program codes or instructions configured to cause the CPU to execute processes. The memory, that is, the storage medium includes a so-called available medium that can be accessed by a general-purpose or dedicated computer.
Claims
1. A control device, wherein: The control device includes a processing circuit, and the processing circuit is configured to perform the following processing, namely: controlling a display unit that displays information related to a software update in which a software update process of the in-vehicle device mounted on the vehicle is executed according to a prescribed operation of turning off a power source of the in-vehicle device mounted on the vehicle; and When a situation that prevents execution of the update process occurs while the predetermined operation is being performed, stop information indicating that the update process is not executed is displayed on the display unit.
2. The control device according to claim 1, wherein: The predetermined operation is an operation of turning off the power source of the vehicle.
3. The control device according to claim 1 or 2, wherein: The processing circuit is configured to change the information displayed on the display unit from the suspension information to guidance information indicating that the update process can be executed when the situation is resolved after the suspension information is displayed on the display unit.
4. The control device according to any one of claims 1 to 3, wherein: The situation is a situation in which the power supply of the in-vehicle device cannot be turned off even after the predetermined operation is performed.
5. The control device according to any one of claims 1 to 4, wherein: The situation is a situation where the vehicle is parked on a slope that satisfies a predetermined condition.
6. The control device according to claim 5, wherein: The in-vehicle device is an electronic control unit for brake control, and when the vehicle is parked on a slope that satisfies the predetermined condition, the electronic control unit for brake control executes a process related to the brake operation after the predetermined operation is performed.
7. The control device according to any one of claims 1 to 6, wherein: The condition is a condition in which the emergency notification system of the vehicle is working.
8. The control device according to any one of claims 1 to 7, wherein: The display unit is configured to be switchable between a first state in which display can be performed even after the predetermined operation, and a second state in which display cannot be performed even after the predetermined operation. The condition is a condition in which the display unit is set to the second state.
9. The control device according to claim 8, wherein: The display unit is configured to be switchable between the first state and the second state by a user of the vehicle.
10. The control device according to any one of claims 1 to 9, wherein: The suspension information includes information indicating the content of the status.
11. The control device according to any one of claims 1 to 10, wherein: The suspension information includes information indicating a method for eliminating the condition.
12. A control method, wherein: The control method comprises: controlling a display unit that displays information related to a software update in which a software update process of the in-vehicle device mounted on the vehicle is executed in accordance with a prescribed operation of turning off a power source of the in-vehicle device mounted on the vehicle; and When a situation that prevents execution of the update process occurs while the predetermined operation is being performed, stop information indicating that the update process is not executed is displayed on the display unit.
13. A non-transitory computer-readable storage medium, which is a non-transitory computer-readable storage medium storing a program, wherein: When the program is executed by the control device, the control device performs the following processing, namely: controlling a display unit that displays information related to a software update in which a software update process of the in-vehicle device mounted on the vehicle is executed according to a prescribed operation of turning off a power source of the in-vehicle device mounted on the vehicle; and When a situation that prevents execution of the update process occurs while the predetermined operation is being performed, stop information indicating that the update process is not executed is displayed on the display unit.
Citation Information
Patent Citations
OTA master, update control method, update control program, and OTA center
JP2022163396A