Control device, control method, and program

By displaying the activation processing progress and power status information on the display part of the vehicle, user concerns caused by activation processing during the vehicle's power disconnection are solved, and user experience is improved.

CN120066537APending Publication Date: 2025-05-30TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411509306.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-29
Filing Date
2024-10-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When the software activation process is performed during the power disconnection of the vehicle, the power cannot be turned on again, causing user concerns.

Method used

By displaying the progress status of the activation process and the status information of the inability to turn on the power supply on the display unit, the user can understand the progress of the activation process and the power supply status.

Benefits of technology

The user's convenience is improved, and the user's doubts are reduced by displaying information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066537A_ABST
    Figure CN120066537A_ABST
Patent Text Reader

Abstract

The present invention relates to a control device, a control method, and a program for controlling the display of information relating to software update of an in-vehicle device. A control device according to the present invention is configured to control a display unit configured to display information relating to software update of an in-vehicle device mounted on a vehicle. The control device is provided with a circuit configured so as to display first information and second information on the display unit during execution of an activation process for activating update software attached to the in-vehicle device in response to switching of the power supply of the vehicle from ON to OFF. The first information indicates a progress state of the activation process, and the second information indicates a state in which the power supply cannot be switched from OFF to ON.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a control device, a control method, and a program for display control of information related to software updates of in-vehicle devices. Background Art

[0002] Various in-vehicle devices that operate by executing software are mounted on a vehicle. There is known an OTA (Over The Air) technology for updating the software of in-vehicle devices by downloading software from outside the vehicle via wireless communication. As described in Japanese Unexamined Patent Application Publication No. 2022-163396, software updates are performed by an installation process of writing the downloaded update software into a storage module of the in-vehicle device and an activation process of making the installed update software effective.

[0003] There are cases where the activation process is performed while the power supply of the vehicle is turned off. In such a case, the power supply of the vehicle cannot be turned on again during the period from the start to the completion of the activation process. Since the power-on operation of the vehicle cannot be accepted during such a period, the user may have doubts about a failure or the like. Summary of the Invention

[0004] A control device according to an embodiment of the present disclosure is configured to control a display unit that is configured to display information related to software updates of in-vehicle devices mounted on a vehicle. The control device includes a circuit that is configured to: during a process of executing an activation process of making update software installed in the in-vehicle device effective according to a change of the power supply of the vehicle from on to off, display first information and second information on the display unit, the first information indicating a progress status of the activation process, and the second information indicating a state in which the power supply cannot be switched from off to on.

[0005] The circuit may also be configured to: display the first information and the second information on the display unit according to the start of the activation process.

[0006] The circuit may also be configured to: display the first information and the second information on the display unit according to a specified operation performed by a user of the vehicle during an execution process of the activation process.

[0007] The circuit may also be configured to: display the second information on the display unit according to the start of the activation process, and display the first information on the display unit according to a specified operation performed by a user of the vehicle during an execution process of the activation process.

[0008] The above circuit may also be configured to: according to the completion of the above activation process, switch the information displayed on the above display unit from the above first information and the above second information to third information, and the above third information indicates that the above activation process has been completed.

[0009] The above vehicle may also include a plurality of the above in-vehicle devices. The above circuit may also be configured to: when the power supply of the above vehicle is switched from on to off and the above activation process is respectively executed on a plurality of the above in-vehicle devices, and when the above activation process is completed for all of the above plurality of in-vehicle devices, switch the information displayed on the above display unit from the above first information and the above second information to the above third information.

[0010] The above vehicle may also include a plurality of the above in-vehicle devices. The control device may also be one of the above plurality of in-vehicle devices. The above circuit may also be configured to: when the power supply of the above vehicle is switched from on to off and the above activation process is respectively executed on a plurality of the above in-vehicle devices including the control device, and when the above activation process is completed for all of the above plurality of in-vehicle devices, switch the information displayed on the above display unit from the above first information and the above second information to the above third information.

[0011] The above circuit may also be the above in-vehicle device that executes the above activation process.

[0012] The control device is mounted on the above vehicle. The above circuit may also be configured to: during the execution of the above activation process on other above in-vehicle devices mounted on the same vehicle, display the above first information and the above second information on the above display unit.

[0013] The control device may also be a server device independent of the above vehicle.

[0014] The above display unit may also be provided on the above vehicle.

[0015] The above display unit may also be an information terminal independent of the above vehicle.

[0016] The above first information may also include the expected time until the completion of the above activation process.

[0017] A control method according to an embodiment of the present disclosure is a control method for a display unit configured to display information related to software update of an in-vehicle device mounted on a vehicle. The above control method includes: during the execution of an activation process for validating updated software installed on the above in-vehicle device when the power supply of the above vehicle is switched from on to off, displaying first information and second information on the above display unit, the above first information indicating the progress of the above activation process, and the above second information indicating a state where the power supply cannot be switched from off to on.

[0018] The program according to an embodiment of the present disclosure is executed by a control device configured to control a display unit, and the display unit is configured to display information related to software update of in-vehicle devices mounted on a vehicle. The program causes the control device to execute the following processing: in the process of executing an activation process for validating updated software installed in the in-vehicle device according to the power supply of the vehicle being switched from on to off, a process of causing a first piece of information and a second piece of information to be displayed on the display unit, the first piece of information indicating the progress status of the activation process, and the second piece of information indicating a state where the power supply cannot be switched from off to on.

[0019] A non-transitory storage medium according to an embodiment of the present disclosure stores a command that can be executed by one or more processors and causes the one or more processors to execute the following functions: controlling a display unit configured to display information related to software update of in-vehicle devices mounted on a vehicle; and executing a process of causing a first piece of information and a second piece of information to be displayed on the display unit in the process of executing an activation process for validating updated software installed in the in-vehicle device according to the power supply of the vehicle being switched from on to off, the first piece of information indicating the progress status of the activation process, and the second piece of information indicating a state where the power supply cannot be switched from off to on.

[0020] The control device has the effect of improving user convenience.

[0021] Hereinafter, with reference to the accompanying drawings, the features, advantages, and technical and industrial significance of exemplary embodiments of the present invention will be described. In the drawings, the same reference numerals denote the same elements. Description of the Drawings

[0022] Figure 1 FIG. schematically shows the structure of the control device and the vehicle according to the first embodiment.

[0023] Figure 2 FIG. is a sequence diagram showing the process flow of the activation and stage processes in the case of software update in the first update order according to the first embodiment.

[0024] Figure 3 FIG. shows an example of the display of a guidance image by the control device according to the first embodiment.

[0025] Figure 4 FIG. shows an example of the display of a completion image by the control device according to the first embodiment.

[0026] Figure 5 FIG. is a sequence diagram showing the process flow of the process related to the confirmation of the progress status of software update in the information terminal according to the second embodiment.

[0027] Figure 6 This is a diagram showing another display example of the second information.

[0028] Figure 7 This is a diagram showing another display example of the first information. Detailed implementation mode

[0029] Hereinafter, with reference to Figures 1 to 4 the first implementation mode of the control device, the vehicle, the control method, the non-transitory storage medium, and the program will be described in detail.

[0030] Structure of the control device and the vehicle

[0031] As Figure 1 shown, in the vehicle 10, in-vehicle devices such as an OTA host 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18 are mounted. These in-vehicle devices are communicably connected to each other via an in-vehicle network 19. The OTA host 11 is responsible for the management of software updates of the in-vehicle devices including itself. The DCM 12 is a data communication module (Data Communication Module), and provides a wireless communication function with the outside of the vehicle via a mobile communication network 20. In the present implementation mode, the DCM 12 undertakes the function of recording the results of self-diagnosis performed by each in-vehicle device of the vehicle 10 and sending them to a data center outside the vehicle. The ADAS 13 is an advanced driving assistance system (Advanced Driving Assistant System), and provides advanced driving assistance functions such as an automatic braking device and an emergency start prevention device. The PCU 14 is a power control unit (Power Control Unit), and is an in-vehicle device that performs power control inside the vehicle. The engine ECU 15 is an electronic control unit (Electronic Control Unit) for engine control. The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a human machine interface (Human Machine Interface), and includes an input device that accepts operations by an occupant, and a display device that displays information to the occupant by images and sounds. The HMI 18 may also have a structure including a navigation function for guiding a driving route and an entertainment function for playing music and videos. Each of these in-vehicle devices has a storage module 21 that stores software, and a processor 22 that executes the software. The OTA host 11 also has a data storage 23 that stores updated software obtained from outside the vehicle.

[0032] The vehicle 10 is provided with a power switch 24 for switching the power supply of the vehicle 10 on and off. The drive system of the vehicle 10 starts according to the switching from power-off to power-on and stops according to the switching from power-on to power-off.

[0033] The vehicle 10 is connected to an OTA server 30 via a mobile communication network 20. The OTA server 30 is a server device that distributes updated software for in-vehicle devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing the updated software, and a processor 32 that executes the distribution programs.

[0034] The OTA server 30 can communicate with an information terminal 40 of the user of the vehicle 10 via the mobile communication network 20. Examples of the information terminal 40 include a smartphone. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes software stored in the storage device 41. The HMI 43 includes an input device that accepts user operations and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as information confirmation and remote operation of the vehicle 10 owned by the user.

[0035] Outline of software update

[0036] Next, an outline of the software update of the in-vehicle devices in the vehicle 10 will be described. The in-vehicle devices subject to software update include an OTA host 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18. The software update is carried out through a download phase, an installation phase, and an activation phase.

[0037] In the download phase, the updated software is sent from the OTA server 30 to the vehicle 10. The OTA host 11 stores the updated software received from the OTA server 30 in the data storage 23. The download phase includes a series of processes related to downloading, such as judgment of whether the download can be executed and verification of the update data. The sending of the updated software from the OTA server 30 to the OTA host 11 includes sending compressed data obtained by compressing the updated software, sending segmented data obtained by segmenting the updated software or the compressed data, and sending the updated software of multiple in-vehicle devices together.

[0038] In the installation phase, the updated software is installed on the in-vehicle device to be updated. In the installation phase, the OTA host 11 writes the updated software to the storage module 21 of the in-vehicle device to be updated. The installation phase includes a series of processes related to installation, such as determining whether installation can be executed, transmitting update data, and verifying the updated software. When the update data includes the updated software itself, in the installation phase, the OTA host 11 transmits the update data to the in-vehicle device to be updated. When the update data includes compressed data, differential data, or split data of the updated software, a generation process of the updated software from the update data is performed. The generation process can be performed by the OTA host 11 or by the in-vehicle device to be updated. The generation of the updated software can be performed by decompressing the compressed data, assembling the differential data, or assembling the split data. In addition, when the installation phase is completed, the updated software is invalidated.

[0039] In the activation phase, in the in-vehicle device to be updated, activation of the updated software, that is, validation of the updated software, is performed. The activation phase includes a series of processes related to activation, such as determining whether activation can be executed, checking the matching of the updated software, and verifying the execution result of activation.

[0040] Two software update sequences

[0041] There are two types of software update sequences for in-vehicle devices: the first update sequence and the second update sequence. In both the first update sequence and the second update sequence, software updates are performed in a common order until the completion of the installation phase. In the first update sequence and the second update sequence, the timing of starting the activation process of validating the updated software in the activation phase is different. In the case of the first update sequence, the activation process is started according to the power supply of the vehicle 10 being switched from on to off. When software updates are performed in the first update sequence, before the activation process is completed, switching the power supply of the vehicle 10 to on again is prohibited. On the other hand, in the case of the second update sequence, the activation process is started according to the power supply of the vehicle 10 being switched from off to on. The in-vehicle device to be updated at this time waits for the completion of the activation process after the power supply of the vehicle 10 is switched from off to on and then starts to operate. Which of the first update sequence and the second update sequence is used for software updates is determined, for example, according to the type of in-vehicle device, the hardware structure, and the type of software.

[0042] When software updates are performed in the first update sequence, power needs to be supplied to the in-vehicle device during the activation process even when the power supply of the vehicle 10 is off. Therefore, it is necessary to connect a dedicated power line for power supply when the power supply of the vehicle 10 is off to the in-vehicle device for which software updates are performed in the first update sequence. Therefore, basically, it is preferable to perform software updates for in-vehicle devices in the second update sequence that does not require a dedicated power line.

[0043] However, when the activation process is implemented during a software update in the second update order, the in-vehicle device to be updated cannot start operating from the time when the power supply of the vehicle 10 is switched from off to on until the activation process is completed. In contrast, when the activation process is implemented during a software update in the first update order, the activation process has been completed at the moment when the power supply of the vehicle 10 is switched from off to on. In this case, the in-vehicle device to be updated can start operating immediately after the power supply of the vehicle 10 is switched from off to on. Therefore, in-vehicle devices that are required to start operating immediately after the power supply of the vehicle 10 is switched from off to on are preferably updated with the software in the first update order.

[0044] In the case of the present embodiment, the DCM 12, the ADAS 13, and the PCU 14 are classified as in-vehicle devices to be updated with the software in the first update order. The communication function provided by the DCM 12 is used to notify the outside of an abnormality that has occurred in the vehicle 10. In the case of the present embodiment, the DCM 12 is responsible for recording the results of the self-diagnosis of each in-vehicle device. The ADAS 13 needs to perform driving assistance from the moment when the vehicle 10 starts to travel. During the period when the operation of the PCU 14 stops, power cannot be supplied to the drive system, so the vehicle 10 cannot start to travel. Thus, the DCM 12, the ADAS 13, and the PCU 14 are in-vehicle devices that are required to start operating immediately after the power supply of the vehicle 10 is switched from off to on.

[0045] Depending on the hardware structure of the storage module 21 mounted on the in-vehicle device, there are also cases where software updates in the first update order are required. In the case of the present embodiment, in-vehicle devices other than the above-mentioned DCM 12, ADAS 13, and PCU 14 that are equipped with a storage module 21 with a single repository are classified as in-vehicle devices to be updated with the software in the first update order. In-vehicle devices other than the DCM 12, ADAS 13, and PCU 14 that are equipped with a storage module 21 with a dual repository are classified as in-vehicle devices to be updated with the software in the second update order.

[0046] The storage module 21 of the single repository only has a storage area for the software executed by one storage processor 22. In the case of such an in-vehicle device, the updated software is installed in the same storage area as the storage area storing the software before the update. Therefore, in the implementation of the installation, it is also necessary to stop the operation of the in-vehicle device. And, in order to recover in the case of activation failure, it is necessary to reinstall the software before the update in the storage area, which takes a long time. In the case where the software before the update is not backed up, it is necessary to download the software before the update again. Thus, in the case of an in-vehicle device equipped with the storage module 21 of the single repository, considering recovery in case of failure, it may take a very long time from the start of activation until it is possible to start operation. Therefore, in the present embodiment, the in-vehicle device equipped with the storage module 21 of the single repository performs software update in the first update order.

[0047] In contrast, the storage module 21 of the dual repository has two storage areas. One of the two storage areas is invalidated and the other is made valid. The processor 22 reads and executes the software from the storage area that is made valid. In the case of such an in-vehicle device, the updated software is installed in the invalidated storage area, that is, a storage area different from the storage area storing the software before the update. After the installation, activation is performed by switching the valid storage area. In the case of activation failure, by switching the valid storage area again, it is possible to return to the state before the update in a short time. In the case of an in-vehicle device equipped with the storage module 21 of the dual repository, even considering recovery in case of failure, it does not take a long time from the start of activation until it is possible to start operation. Therefore, in the present embodiment, software update based on the second update order is limited to the in-vehicle device equipped with the storage module 21 of the dual repository.

[0048] In addition, in many in-vehicle devices, there are sometimes multiple software programs that provide different functions installed. Sometimes among these multiple software programs, there are software programs that need to be executed immediately after the vehicle 10 is powered on, and software programs that do not need to be executed immediately. In the case of software that needs to be executed immediately after the power is turned on, if the update is performed in the second update order, it may not be possible to catch up with the execution after the power is turned on. Therefore, even for the same in-vehicle device, it is possible to divide whether to perform the update in the first update order or the second update order according to the type of software to be updated.

[0049] The in-vehicle device that performs software updates in the first update order may also include other in-vehicle devices. For example, the OTA host 11 may also be included in the in-vehicle device that performs software updates in the first update order. Consider a case where, according to the power supply of the vehicle 10 being switched from off to on, an activation process is performed on multiple in-vehicle devices including the OTA host 11. The OTA host 11 manages software updates other than itself. Therefore, when the OTA host 11 is in a state where it cannot perform management due to its own activation process, there is a situation where the activation process of other in-vehicle devices cannot be executed. In such a case, it is necessary to stagger the activation process of the OTA host 11 and the activation process of other in-vehicle devices. It is preferable to perform the activation process of the OTA host 11 when the power supply of the vehicle 10 is disconnected, where it is easy to ensure sufficient time.

[0050] Activation process in the first update order

[0051] Next, with reference to Figures 2 to 5 , the details of the activation process in the first update order, which is executed according to the power supply of the vehicle 10 being switched from on to off, will be described. In the storage module 21 of the OTA host 11, a program for software update management and a program for display control of information related to software updates are stored. The OTA host 11 performs the activation process through the execution of these programs.

[0052] If the installation phase is completed, the OTA host 11 asks the user of the vehicle 10 whether the activation process can be executed. The inquiry to the user is made through the HMI 18 mounted on the vehicle 10 or the user's information terminal 40. If the OTA host 11 confirms that the user permits the execution of the activation process, it then starts the activation process according to the power supply of the vehicle 10 being switched from on to off. In the following description, the state where the installation phase is completed and the user's permission for the activation process is obtained is referred to as the state where the preparation for the activation process is completed.

[0053] In Figure 2 shows the process flow of the activation phase in the case of software updates in the first update order. Figure 2 shows a case where the software of two in-vehicle devices D1 and D2 is updated in the first update order.

[0054] If the power supply of the vehicle 10 is switched from on to off (S10) in the state where the preparation for the activation process is completed, the OTA host 11 instructs the in-vehicle devices D1 and D2 to start the activation process (S11). The in-vehicle devices D1 and D2 start the activation process respectively according to the instruction (S13). And at this time, the OTA host 11 instructs the HMI 18 to display a guidance image (S12). The HMI 18 displays the guidance image according to the instruction (S14).

[0055] shows a display example of a guidance image. In the guidance image, a first piece of information indicating the progress of the activation process and a second piece of information indicating a state where the power supply of the vehicle 10 cannot be switched from off to on are displayed. In Figure 3 the case of Figure 3 , the progress rate of the activation process and the estimated time until the completion of the activation process are displayed as the first piece of information. In Figure 3 the case of , a progress bar representing the progress rate of the activation process with a bar graph is also displayed as the first piece of information. An operation button for confirming detailed information on software update is displayed in the guidance image. If the user operates this operation button, an image showing information such as the type, version of the updated software, and additional functions based on the update is displayed on the HMI18.

[0056] If the occupant gets out of the vehicle and locks the doors of the vehicle 10, etc., the HMI18 dims the screen and stops displaying the guidance image. Thereafter, if the vehicle 10 is unlocked, the HMI18 resumes displaying the guidance image.

[0057] Thereafter, if in-vehicle devices D1, D2 complete the activation process, they send a completion notice to the OTA host 11 (S15, S16). In Figure 2 the case of , the in-vehicle device D1 first sends a completion notice (S15), and thereafter the in-vehicle device D2 sends a completion notice (S16). If the OTA host 11 confirms that the activation process has been completed in all the in-vehicle devices D1, D2 that have performed the activation process based on the disconnection of the power supply of the vehicle 10 this time, it instructs the HMI18 to display a completion image (S17). The HMI18 displays the completion image according to the instruction (S18).

[0058] In Figure 4 shows a display example of the completion image. A third piece of information indicating the completion of the activation process is displayed in the completion image. In the case of this embodiment, the software update is completed according to the completion of the activation process. Therefore, the third piece of information in the Figure 4 completion image is displayed by a message indicating the completion of the software update. Information notifying that the functions of the updated in-vehicle device can be used and an operation button for confirming detailed information on software update are displayed in the Figure 4 completion image.

[0059] Progress confirmation of software update from an information terminal

[0060] As described above, software providing functions such as information confirmation and remote operation of the vehicle 10 owned by the user is installed on the information terminal 40. This software has a function of confirming the progress of the software update of the in-vehicle device.

[0061] In Figure 5The figure shows the process of the process related to the progress confirmation of the software update from the information terminal 40. If the user performs a confirmation operation (S20) on the progress of the software update on the information terminal 40, the information terminal 40 sends a display request for the progress information to the OTA server 30 (S21). The OTA server 30 requests the vehicle 10 of the user to send the progress information according to the display request (S22). In the vehicle 10, the OTA host 11 confirms the progress of the software update of the in-vehicle device (S23), and sends the progress information to the OTA server 30 (S24). The progress information includes information indicating the stage of the software update being executed by the vehicle 10, the progress rate of the processing in the same stage, and the estimated time until the completion of the processing in the same stage. If the OTA server 30 receives the progress information from the vehicle 10, it instructs the information terminal 40 to display an image corresponding to the progress. The information terminal 40 displays an image indicating the progress of the software update according to the instruction (S26).

[0062] When the progress information received from the vehicle 10 indicates that the activation process is being executed, the OTA server 30 instructs the information terminal 40 to display a guidance image. The content of the guidance image displayed on the information terminal 40 follows the Figure 3 image displayed on the HMI 18 of the vehicle 10. Therefore, in the guidance image displayed on the information terminal 40, the first information indicating the progress of the activation process and the second information indicating the state in which the power of the vehicle 10 cannot be switched from off to on are displayed.

[0063] When the progress information received from the vehicle 10 indicates the completion of the activation process, the OTA server 30 instructs the information terminal 40 to display a completion notification image. The content of the completion notification image displayed on the information terminal 40 follows the Figure 4 image displayed on the HMI 18 of the vehicle 10. Therefore, the third information indicating that the activation process has been completed is displayed in the completion image displayed on the information terminal 40.

[0064] Functions and effects of the embodiment

[0065] The OTA host 11 controls the HMI 18 that displays information related to the software update of the in-vehicle device mounted on the vehicle 10. When the activation process of the in-vehicle device is executed according to the power of the vehicle 10 being switched from on to off, the OTA host 11 causes the HMI 18 to display a guidance image. The first information indicating the progress of the activation process and the second information indicating the state in which the power of the vehicle 10 cannot be switched from off to on are displayed in the guidance image. For the OTA server 30, when the activation process of the in-vehicle device is being executed in the vehicle 10 with the power off, if the user performs a specified operation on the information terminal 40, the above first information and second information are displayed on the information terminal 40.

[0066] If the activation process is executed according to the switching of the power supply of the vehicle 10 from on to off, the power supply of the vehicle 10 cannot be switched from off to on until the process is completed. In the case of the present embodiment, if the activation process is started based on the disconnection of the power supply of the vehicle 10, the first information and the second information are displayed on the HMI 18 / information terminal 40. The user can confirm, based on the second information, that the power supply of the vehicle 10 cannot be switched from off to on. In addition, the user can grasp, based on the first information, the period when the activation process is completed and the power supply of the vehicle 10 can be switched from off to on.

[0067] According to the control device, vehicle, control method, non-transitory storage medium, and program of the present embodiment described above, the following effects can be achieved.

[0068] The OTA host 11 causes the HMI 18 to display a guidance image during the execution of the activation process in the case of software update in the first update order. In addition, the OTA server 30 causes the user's information terminal 40 to display the same guidance image during the execution of the activation process in the case of software update in the first update order. The first information indicating the progress of the activation process and the second information indicating the state in which the power supply of the vehicle 10 cannot be turned on are displayed in the guidance image. By observing the guidance image, the user can confirm the state in which the power supply of the vehicle 10 cannot be switched on for the activation process and the approximate period until this state is eliminated. Therefore, in the present embodiment, there is an effect of improving the convenience for the user.

[0069] The OTA host 11 causes the first information and the second information to be displayed on the HMI 18 according to the start of the activation process. Therefore, the user can confirm the first information and the second information immediately after the start of the activation process.

[0070] If, after the start of the activation process, the occupant locks the vehicle 10 and gets out, the screen of the HMI 18 darkens and the display of the first information and the second information is temporarily interrupted. The OTA host 11 causes the first information and the second information to be displayed on the HMI 18 again according to a specified operation of the user. Therefore, the user can confirm the first information and the second information at an arbitrary time by performing the above-specified operation on the vehicle 10.

[0071] The OTA host 11 causes the first information and the second information to be displayed on the HMI 18 according to a user operation related to boarding such as the release of the lock of the vehicle 10. Therefore, the user can confirm the first information and the second information when boarding the vehicle.

[0072] The OTA server 30 performs the display of the first information and the second information in the information terminal 40 according to a specified operation of the user in the information terminal 40. Accordingly, the user can confirm the first information and the second information at any time.

[0073] When the activation process is completed, the OTA host 11 / OTA server 30 switches the image displayed on the HMI 18 / information terminal 40 from the boot image to the completion notification image. A third piece of information indicating that the activation process has been completed is displayed within the completion notification image. Thus, according to the completion of the activation process, the information displayed on the HMI 18 / information terminal 40 is switched from the first information and the second information to the third information indicating that the activation process has been completed. Accordingly, the user can confirm the completion of the activation process.

[0074] There are cases where activation processes are respectively executed in a plurality of in-vehicle devices when the power supply of the vehicle 10 is switched from on to off. In such a case, even if some of the in-vehicle devices complete the activation process, the state in which the power supply of the vehicle 10 cannot be switched to the on state continues during the period when there are in-vehicle devices in which the activation process is not completed. In contrast, when the activation process is completed in all of the in-vehicle devices in which the activation process has been executed, the OTA host 11 switches the information displayed on the HMI 18 from the first information and the second information to the third information. Accordingly, the user can confirm that the power supply of the vehicle 10 can be switched to on.

[0075] The OTA host 11 and the OTA server 30 cause the first information displayed on the HMI 18 / information terminal 40 to include the expected time until the completion of the activation process. Thus, it is easy for the user to understand the period when the activation process is completed and the power supply of the vehicle 10 can be switched to on.

[0076] In the present embodiment, the HMI 18 provided in the vehicle 10 and the user's information terminal 40 are examples of display units that display information related to software update. The HMI 18 is an example of a display unit provided in the vehicle 10, and the information terminal 40 is an example of a display unit independent of the vehicle 10. For the information display of the HMI 18, the OTA host 11 mounted on the vehicle 10 is an example of a control device that controls the display unit. For the information display of the information terminal 40, the OTA server 30 is an example of a control device that controls the display unit. The OTA server 30 is an example of a server device independent of the vehicle 10.

[0077] Other embodiments

[0078] The above-described embodiment can be implemented with the following modifications. The above-described embodiment and the following modification examples can be implemented in combination with each other within a range where there is no technical contradiction.

[0079] Regarding the display form of information

[0080] In the above-described embodiment, both the first information and the second information are displayed within the same image. However, the two pieces of information may also be displayed independently. In this case, it is preferable to preferentially present the user with the second information indicating that the power supply of the vehicle 10 cannot be switched from off to on, as compared to the first information indicating the progress of the activation process. For example, it may be configured such that the second information is displayed on the display unit upon the start of the activation process, and the first information is displayed on the display unit based on a prescribed operation by the user during the execution of the activation process.

[0081] In Figure 6 a display example of an image representing the second information in the HMI 18 is shown. In Figure 6 the image, the second information indicating that the power supply of the vehicle 10 cannot be switched from off to on is displayed in the form of a statement. In Figure 6 the image, a button for confirming the progress of the software update is displayed. The OTA host 11 switches the image displayed on the HMI 18 from the image representing the second information to the image representing the first information based on the user's operation of the button.

[0082] In Figure 7 a display example of an image representing the first information in the HMI 18 is shown. In Figure 7 the image, a numerical value representing the progress rate of the activation process is displayed as the first information, and the estimated time until the completion of the activation process is displayed numerically as the first information. In Figure 7 the image, a progress bar representing the progress rate of the activation process using a bar graph is also displayed as the first information.

[0083] In addition, the display form of the information within each image in the above-described embodiment may also be appropriately changed. For example, only either the progress rate of the activation process or the estimated time until completion may be displayed as the first information. The estimated time of completion of the activation process may be displayed as the first information. Other expression methods such as still images and animations may be used to display the first information, the second information, and the third information.

[0084] Other modification examples

[0085] It may also be configured not to display the third information corresponding to the completion of the activation process in the above-described embodiment.

[0086] In Figure 5In the case where the OTA server 30, according to a request from the information terminal 40, instructs the information terminal 40 to display an image indicating the progress of software update. It is also possible to display an image indicating the progress in the information terminal 40 without waiting for a request from the information terminal 40. In this case, the OTA server 30 obtains progress information from the vehicle 10 and, based on the obtained progress information, instructs the information terminal 40 to display an image corresponding to the progress of software update.

[0087] It is also possible for the OTA server 30 to perform display control of the HMI 18 of the vehicle 10.

[0088] It is also possible for the OTA host 11 to perform display control of the information terminal 40.

[0089] It is also possible to display information related to software update only on either the HMI 18 of the vehicle 10 or the information terminal 40.

[0090] The in-vehicle device that is the object of software update can also perform display control of information related to software update.

[0091] The OTA host 11 that manages software update performs display control of information related to software update. It is also possible for other in-vehicle devices to manage software update and perform display control of information related to software update.

[0092] For display control, the control device of the present disclosure can include one or more processors that operate according to a computer program, one or more dedicated hardware circuits such as dedicated hardware for performing at least a part of various processes, or a circuit including a combination of these. As the dedicated hardware, for example, an application-specific integrated circuit (ASIC) as an integrated circuit for a specific purpose can be cited. The processor includes a central processing unit (CPU), and memories such as a random access memory (RAM) and a read only memory (ROM). The memory stores program codes or instructions configured to cause the CPU to execute processes. The memory, that is, the storage medium includes a so-called available medium that can be accessed by a general or dedicated computer. The control device of the present disclosure can also use one or two or more memories.

[0093] Supplementary Notes

[0094] [Note 1] A control device is a control device for controlling a display unit that displays information related to software updates of in-vehicle devices mounted on a vehicle. Among them, during the execution of the activation process for validating the updated software installed on the in-vehicle device when the power supply of the vehicle is switched from on to off, the first information indicating the progress of the activation process and the second information indicating the state where it is impossible to switch the power supply from off to on are displayed on the display unit.

[0095] [Note 2] The control device according to [Note 1], wherein the first information and the second information are displayed on the display unit according to the start of the activation process.

[0096] [Note 3] The control device according to [Note 1] or [Note 2], wherein the first information and the second information are displayed on the display unit according to a specified operation performed by the user of the vehicle during the execution of the activation process.

[0097] [Note 4] The control device according to any one of [Note 1] to [Note 3], wherein the second information is displayed on the display unit according to the start of the activation process, and the first information is displayed on the display unit according to a specified operation performed by the user of the vehicle during the execution of the activation process.

[0098] [Note 5] The control device according to any one of [Note 1] to [Note 4], wherein according to the completion of the activation process, the information displayed on the display unit is switched from the first information and the second information to the third information indicating that the activation process has been completed.

[0099] [Note 6] The control device according to [Note 5], wherein in the case where the activation process is respectively executed on a plurality of the in-vehicle devices when the power supply of the vehicle is switched from on to off, when the activation process is completed on all of the plurality of the in-vehicle devices, the information displayed on the display unit is switched from the first information and the second information to the third information.

[0100] [Note 7] The control device according to [Note 5] or [Note 6], wherein the control device is one of the in-vehicle devices, and in the case where the activation process is respectively executed on a plurality of the in-vehicle devices including the control device when the power supply of the vehicle is switched from on to off, when the activation process is completed on all of the plurality of the in-vehicle devices, the information displayed on the display unit is switched from the first information and the second information to the third information.

[0101] [Note 8] The control device according to any one of [Note 1] to [Note 7], wherein the control device is the in-vehicle device that executes the above activation process.

[0102] [Note 9] The control device according to any one of [Note 1] to [Note 8], wherein the control device is mounted on the above vehicle, and during the process of executing the above activation process on other in-vehicle devices mounted on the same vehicle, the above first information and the above second information are displayed on the above display unit.

[0103] [Note 10] The control device according to any one of [Note 1] to [Note 6], wherein the control device is a server device independent of the above vehicle.

[0104] [Note 11] The control device according to any one of [Note 1] to [Note 10], wherein the above display unit is provided on the above vehicle.

[0105] [Note 12] The control device according to any one of [Note 1] to [Note 10], wherein the above display unit is an information terminal independent of the above vehicle.

[0106] [Note 13] The control device according to any one of [Note 1] to [Note 12], wherein the above first information includes the expected time until the completion of the above activation process.

[0107] [Note 14] A control method is a control method of a display unit that displays information related to software update of an in-vehicle device mounted on a vehicle. During the execution of the activation process when the power supply of the above vehicle is switched from on to off and the updated software installed on the above in-vehicle device is made effective, the first information indicating the progress status of the above activation process and the second information indicating the state where the power supply cannot be switched from off to on are displayed on the above display unit.

[0108] [Note 15] The control method according to [Note 14], wherein the above first information and the above second information are displayed on the above display unit according to the start of the above activation process.

[0109] [Note 16] The control method according to [Note 14] or [Note 15], wherein the above first information and the above second information are displayed on the above display unit according to a specified operation performed by the user of the above vehicle during the execution of the above activation process.

[0110] [Note 17] According to the control method described in any one of [Note 14] to [Note 16], wherein the second information is displayed on the display unit according to the start of the activation process, and the first information is displayed on the display unit according to a specified operation performed by the user of the vehicle during the execution of the activation process.

[0111] [Note 18] According to the control method described in any one of [Note 14] to [Note 17], wherein according to the completion of the activation process, the information displayed on the display unit is switched from the first information and the second information to a third information indicating that the activation process has been completed.

[0112] [Note 19] According to the control method described in [Note 18], wherein in the case where the activation process is executed for each of the plurality of in-vehicle devices when the power supply of the vehicle is switched from on to off, when the activation process is completed for all of the plurality of in-vehicle devices, the information displayed on the display unit is switched from the first information and the second information to the third information.

[0113] [Note 20] According to the control method described in any one of [Note 14] to [Note 19], wherein the in-vehicle device that performs the activation process executes the display process of the first information and the second information on the display unit.

[0114] [Note 21] According to the control method described in any one of [Note 14] to [Note 19], wherein a control device mounted on the vehicle different from the in-vehicle device that performs the activation process executes the display process of the first information and the second information on the display unit.

[0115] [Note 22] According to the control method described in any one of [Note 14] to [Note 19], wherein a server device independent of the vehicle executes the display process of the first information and the second information on the display unit.

[0116] [Note 23] According to the control method described in any one of [Note 14] to [Note 22], wherein the first information includes the expected time until the completion of the activation process.

[0117] [Note 24] A program executed by a control device that controls a display unit for displaying information related to software updates of in-vehicle devices mounted on a vehicle. In the program, the control device is caused to execute the following display process: during the execution of the activation process in the case where, based on the power supply of the vehicle being switched from on to off, an activation process for making the updated software installed on the in-vehicle device effective is executed, a first piece of information indicating the progress status of the activation process and a second piece of information indicating a state where it is impossible to switch the power supply from off to on are displayed on the display unit.

[0118] [Note 25] According to the program described in [Note 24], the display process is a process of displaying the first piece of information and the second piece of information on the display unit based on the start of the activation process.

[0119] [Note 26] According to the program described in [Note 24] or [Note 25], the display process is a process of displaying the first piece of information and the second piece of information on the display unit based on a specified operation performed by a user of the vehicle during the execution of the activation process.

[0120] [Note 27] According to the program described in any one of [Note 24] to [Note 26], the display process is a process of displaying the second piece of information on the display unit based on the start of the activation process and displaying the first piece of information on the display unit based on a specified operation performed by a user of the vehicle during the execution of the activation process.

[0121] [Note 28] According to the program described in any one of [Note 24] to [Note 27], in the display process, the control unit device is caused to execute a process of switching the information displayed on the display unit from the first piece of information and the second piece of information to a third piece of information indicating that the activation process has been completed based on the completion of the activation process.

[0122] [Note 29] According to the program described in [Note 28], in the case where the activation process is executed for a plurality of the in-vehicle devices based on the power supply of the vehicle being switched from on to off, when the activation process is completed for all of the plurality of in-vehicle devices, the switching of the display from the first piece of information and the second piece of information to the third piece of information is executed.

[0123] [Note 30] According to the procedure described in [Note 28] or [Note 29], wherein the above control device is one of the above vehicle-mounted devices. When the power supply of the above vehicle is switched from on to off and the above activation process is respectively executed for a plurality of the above vehicle-mounted devices including the above control device, when the above activation process is completed for all of the above plurality of vehicle-mounted devices, the display is switched from the above first information and the above second information to the above third information.

[0124] [Note 31] According to the procedure described in any one of [Note 24] to [Note 30], wherein the above control device that executes this procedure is the above vehicle-mounted device that executes the above activation process.

[0125] [Note 32] According to the procedure described in any one of [Note 24] to [Note 30], wherein the above control device that executes this procedure is mounted on the above vehicle, and during the process of executing the above activation process for other above vehicle-mounted devices mounted on the same vehicle, the above first information and the above second information are displayed on the above display unit.

[0126] [Note 33] According to the procedure described in any one of [Note 24] to [Note 30], wherein this procedure is executed by a server device independent of the above vehicle.

[0127] [Note 34] According to the procedure described in any one of [Note 24] to [Note 32], wherein the above display unit is provided on the above vehicle.

[0128] [Note 35] According to the procedure described in any one of [Note 24] to [Note 33], wherein the above display unit is an information terminal independent of the above vehicle.

[0129] [Note 36] According to the procedure described in any one of [Note 24] to [Note 35], wherein the expected time until the completion of the above activation process is included in the above first information.

[0130] [Note 37] A non-transitory storage medium, wherein the above non-transitory storage medium stores the procedure described in any one of [Note 24] to [Note 36].

Claims

1. A control device configured to control a display unit configured to display information related to software update of an on-board device mounted on a vehicle, characterized in that: The control device includes a circuit configured to display first information and second information on the display unit during an activation process for activating updated software installed on the vehicle-mounted device in response to the power of the vehicle being switched from on to off, wherein the first information indicates a progress status of the activation process and the second information indicates that the power cannot be switched from off to on.

2. The control device according to claim 1, characterized in that: The circuit is configured to display the first information and the second information on the display unit in response to the start of the activation process.

3. The control device according to claim 1, characterized in that: The circuit is configured to display the first information and the second information on the display unit in response to a predetermined operation performed by a user of the vehicle during execution of the activation process.

4. The control device according to claim 1, characterized in that: The circuit is configured to display the second information on the display unit in response to the start of the activation process, and to display the first information on the display unit in response to a predetermined operation performed by a user of the vehicle during execution of the activation process.

5. The control device according to claim 1, characterized in that: The circuit is configured to switch the information displayed on the display unit from the first information and the second information to third information in response to completion of the activation process, wherein the third information indicates that the activation process has been completed.

6. The control device according to claim 5, characterized in that: The vehicle includes a plurality of the vehicle-mounted devices, The circuit is configured as follows: when the activation process is performed on multiple vehicle-mounted devices respectively according to the power of the vehicle being switched from on to off, when the activation process is completed on all of the multiple vehicle-mounted devices, the information displayed on the display unit is switched from the first information and the second information to the third information.

7. The control device according to claim 5, characterized in that: The vehicle includes a plurality of the vehicle-mounted devices, The control device is one of the plurality of vehicle-mounted devices, The circuit is configured as follows: when the activation process is respectively performed on multiple vehicle-mounted devices including the control device in accordance with the power of the vehicle being switched from on to off, when the activation process is completed on all of the multiple vehicle-mounted devices, the information displayed on the display unit is switched from the first information and the second information to the third information.

8. The control device according to claim 1, characterized in that: The control device is the vehicle-mounted equipment that executes the activation process.

9. The control device according to claim 1, characterized in that: The control device is mounted on the vehicle. The circuit is configured to display the first information and the second information on the display unit during execution of the activation process for the other in-vehicle device mounted on the same vehicle.

10. The control device according to claim 1, characterized in that: The control device is a server device independent of the vehicle.

11. The control device according to claim 1, characterized in that: The display unit is provided in the vehicle.

12. The control device according to claim 1, characterized in that: The display unit is an information terminal independent of the vehicle.

13. The control device according to claim 1, characterized in that: The first information includes an estimated time until completion of the activation process.

14. A control method for a display unit configured to display information related to software update of an in-vehicle device mounted on a vehicle, characterized in that: The control method comprises: displaying first information and second information on the display unit during an activation process for validating update software installed in the vehicle-mounted device in response to the vehicle power being switched from on to off, The first information indicates a progress status of the activation process, and the second information indicates that the power source cannot be switched from off to on.

15. A program executed by a control device configured to control a display unit configured to display information related to software update of an in-vehicle device mounted on a vehicle, characterized in that: The program causes the control device to execute the following processing: in the process of executing activation processing to validate the update software installed in the vehicle-mounted device in response to the power of the vehicle being switched from on to off, the first information and the second information are displayed on the display unit, The first information indicates a progress status of the activation process, and the second information indicates that the power source cannot be switched from off to on.

Citation Information

Patent Citations

  • OTA master, update control method, update control program, and OTA center

    JP2022163396A