Update management device, update management system, and computer program

By designing an update management device that can manage software updates and activations according to vehicle power state, the software update and activation problems of multiple ECUs collaborative vehicles under different power states are solved, and the coordinated action and efficient activation of the system are achieved.

CN120153352APending Publication Date: 2025-06-13AUTONETWORKS TECH LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380079295.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-21
Filing Date
2023-11-01
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively manage software updates and activations of vehicles collaborating with multiple ECUs under different power states, resulting in the system being unable to operate in coordination.

Method used

An update management device is designed to alternately install and activate the software in the vehicle-mounted device according to the power state of the vehicle. Through the coordinated work of the receiving unit, the determining unit, the sending unit and the indicating unit, the ensuring that the software is updated and activated at an appropriate time.

Benefits of technology

In vehicles that cooperate with multiple ECUs, the software is updated and activated in sequence according to the power status to ensure that the system operates in a coordinated manner, and solve the problem that activation commands that may occur in the prior art are not understood.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120153352A_ABST
    Figure CN120153352A_ABST
Patent Text Reader

Abstract

An update management device for managing an update of software of an in-vehicle device in a vehicle having a plurality of power supply states including a first power supply state and a second power supply state, the update management device being provided with: a reception unit for receiving a first power supply state and a second power supply state; receiving first update data for updating first software and second update data for updating second software from an external device of the vehicle; a compositing unit that creates, on the basis of the first update data and the second update data, composite update data for installing composite software that includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a transmission unit that transmits the composite update data to the in-vehicle device so that the in-vehicle device installs the composite software in a recording unit, activates the first function in the first power supply state, and activates the second function in the second power supply state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an update management device, an update management system, and a computer program. This application claims priority based on Japanese Application No. 2022-185655 filed on November 21, 2022, and incorporates by reference all the disclosures described in the Japanese application. Background Art

[0002] There is known an in-vehicle device mounted on a vehicle and connected to a plurality of ECUs (Electronic Control Units). In recent years, the power supply of vehicles has become more complex, and its power supply state has become diversified. In addition, with the diversification of vehicle controls such as a parking assist system, the opportunity to update the software mounted on the ECU has also increased.

[0003] Patent Document 1 discloses a main device for a vehicle that obtains update data from the outside, instructs an ECU to be rewritten to use the obtained update data for installation, and distributes the obtained update data to the ECU to be rewritten. The main device includes: an installation condition determination unit that determines whether all of a first condition of obtaining user consent related to installation, a second condition of being able to communicate with a central device, a third condition that the vehicle state is in a state where installation is possible, a fourth condition that the ECU to be rewritten is in a state where installation is possible, and a fifth condition that the update data is normal data are satisfied; and an installation instruction unit that, when the installation condition determination unit determines that all of the first condition, the second condition, the third condition, the fourth condition, and the fifth condition are satisfied, instructs the electronic control device to be rewritten to use the obtained update data for installation.

[0004] Prior Art Documents

[0005] Patent Documents

[0006] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2020-27629 Summary of the Invention

[0007] The update management device of the present disclosure manages the update of the software of an in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle, the first update data being used to update a first software that operates in the first power state and the second power state, and the second update data being used to update a second software that does not operate in the first power state but operates in the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; a first transmission unit that, when the determination unit determines that the power state of the vehicle is the first power state, transmits the first update data to the in-vehicle device so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; and a second transmission unit that, when the determination unit determines that the power state of the vehicle is the second power state, transmits the first update data and the second update data to the in-vehicle device so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software.

[0008] The update management system of the present disclosure includes an update management device and an in-vehicle device. The update management device manages the update of the software of the in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. Among them, the update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle. The first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; a first sending unit that, when the determination unit determines that the power state of the vehicle is the first power state, sends the first update data to the in-vehicle device so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; a second sending unit that, when the determination unit determines that the power state of the vehicle is the second power state, sends the first update data and the second update data to the in-vehicle device so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software; a first instruction unit that, when the determination unit determines that the power state of the vehicle is the first power state, sends a first activation instruction to the in-vehicle device, and the first activation instruction is used to activate the updated first software installed in the first storage unit; and a second instruction unit that, when the determination unit determines that the power state of the vehicle is the second power state, sends a second activation instruction to the in-vehicle device, and the second activation instruction is used to activate the updated first software and the updated second software installed in the second storage unit. The in-vehicle device includes: a first activation unit that activates the updated first software installed in the first storage unit when receiving the first activation instruction; and a second activation unit that activates the updated first software and the updated second software installed in the second storage unit when receiving the second activation instruction.

[0009] The computer program of the present disclosure is a computer program for controlling an update management device that manages software updates of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The computer program includes: a receiving step of receiving first update data and second update data from an external device of the vehicle, where the first update data is for updating a first software that operates in the first power state and the second power state, and the second update data is for updating a second software that does not operate in the first power state but operates in the second power state; a determining step of determining whether the power state of the vehicle is the first power state or the second power state; a first sending step of sending the first update data to the in-vehicle device when it is determined that the power state of the vehicle is the first power state, so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; and a second sending step of sending the first update data and the second update data to the in-vehicle device when it is determined that the power state of the vehicle is the second power state, so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software.

[0010] The update management device of the present disclosure manages software updates of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle, where the first update data is for updating a first software that operates in the first power state and the second power state, and the second update data is for updating a second software that does not operate in the first power state but operates in the second power state; a synthesizing unit that creates synthesized update data for installing a synthesized software based on the first update data and the second update data, where the synthesized software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a sending unit that sends the synthesized update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthesized software in a recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state.

[0011] The update management system of the present disclosure includes an update management device and an in-vehicle device. The update management device manages the update of the software of the in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. Among them, the update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle. The first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state; a synthesizing unit that creates synthetic update data for installing a synthetic software according to the first update data and the second update data. The synthetic software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; a transmitting unit that transmits the synthetic update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthetic software in a recording unit, and activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state; a determining unit that determines whether the power state of the vehicle is the first power state or the second power state; a first instructing unit that, when the determining unit determines that the power state of the vehicle is the first power state, transmits a first activation instruction for activating the first function to the in-vehicle device; and a second instructing unit that, when the determining unit determines that the power state of the vehicle is the second power state, transmits a second activation instruction for activating the second function to the in-vehicle device. The in-vehicle device includes: a first activation unit that activates the first function when receiving the first activation instruction; and a second activation unit that activates the second function when receiving the second activation instruction.

[0012] The computer program of the present disclosure is a computer program for controlling an update management device that manages the update of software of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The computer program includes: a reception step of receiving first update data and second update data from an external device of the vehicle, where the first update data is for updating first software that operates in the first power state and the second power state, and the second update data is for updating second software that does not operate in the first power state but operates in the second power state; a synthesis step of creating synthesis update data for installing synthesis software based on the first update data and the second update data, where the synthesis software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a transmission step of transmitting the synthesis update data to the in-vehicle device, so that the in-vehicle device having a storage unit installs the synthesis software in a recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a block diagram showing an example of an update management system.

[0014] Figure 2 is a block diagram showing an example of the internal structure of an update management ECU.

[0015] Figure 3 is a block diagram showing an example of the internal structure of an ECU.

[0016] Figure 4 is a functional block diagram of the update management ECU according to Embodiment 1.

[0017] Figure 5 is a table showing an example of an ECU table listing ECUs.

[0018] Figure 6 is a table showing an example of an ECU table listing ECUs.

[0019] Figure 7 is a flowchart showing the control method according to Embodiment 1.

[0020] Figure 8 is a sequence diagram of the update management system according to Embodiment 1.

[0021] Figure 9 is a functional block diagram of the update management ECU according to Embodiment 2.

[0022] Figure 10 is a flowchart showing the control method according to Embodiment 2.

[0023] Figure 11 is a sequence diagram of the update management system according to Embodiment 2. Detailed Embodiment

[0024] [Problems to be Solved by the Invention]

[0025] A vehicle equipped with a plurality of ECUs is known, and the vehicle has a plurality of power supply states including a +B state which is the power supply state when the vehicle is in an inoperable state and an IG state which is the power supply state when the vehicle is in an operable state. For example, there is a case where a first ECU is installed with a first software that operates in both the +B state and the IG state and a second software that does not operate in the +B state but operates in the IG state, and a second ECU is installed with a third software that does not operate in the +B state but operates in the IG state, and a system defined by the cooperation of the second software and the third software operates.

[0026] When the first software and the second software in the first ECU are updated by update data, since the first software and the second software are installed in one first ECU, they can be activated even in the +B state. On the other hand, since the second ECU is installed with the third software that operates in the IG state, when the power supply state transitions to the IG state, the installation of the third software is started by the update data, and the third software is activated. When the second software of the first ECU has already been activated in the +B state, sometimes the second software of the first ECU issues a command to the third software of the second ECU at the timing when the power supply state transitions to the IG state. However, since the third software of the second ECU has just started to be installed and cannot understand the command issued by the second software of the first ECU, the defined system may not operate.

[0027] The main device for a vehicle in Patent Document 1 deals with one ECU, but cannot deal with the case where a system defined by the cooperation of a plurality of ECUs in a vehicle having a plurality of power supply states operates.

[0028] [Effects of the Present Disclosure]

[0029] The present disclosure can provide an update management device that, even when functions operate through the cooperation of a plurality of ECUs in a vehicle having a plurality of power supply states, installs software in each ECU through update data and activates it, and the defined system operates in a coordinated manner.

[0030] [Description of Embodiments of the Present Disclosure]

[0031] In an embodiment of the present disclosure, as its gist, it includes the following structure.

[0032] (1) The update management device of the present disclosure manages the update of the software of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. Among them, the update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle, where the first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; a first transmission unit that, when the determination unit determines that the power state of the vehicle is the first power state, transmits the first update data to the in-vehicle device, so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; and a second transmission unit that, when the determination unit determines that the power state of the vehicle is the second power state, transmits the first update data and the second update data to the in-vehicle device, so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software.

[0033] With such a configuration, according to the power state of the vehicle, the update management device sends update data for alternately installing software in two storage units of the in-vehicle device and activating it to the in-vehicle device. Thereby, according to the power state, the software of the in-vehicle device is updated and activated in due order at appropriate times, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0034] (2) In the update management device of (1) above, it may also be that the update management device further includes: a first instruction unit that, when the determination unit determines that the power state of the vehicle is the first power state, sends a first activation instruction to the in-vehicle device, and this first activation instruction is used to activate the updated first software installed in the first storage unit; and a second instruction unit that, when the determination unit determines that the power state of the vehicle is the second power state, sends a second activation instruction to the in-vehicle device, and this second activation instruction is used to activate the updated first software and the updated second software installed in the second storage unit.

[0035] With this configuration, according to the power supply state of the vehicle, the update management device installs software on the in-vehicle device through update data and activates it. Thus, according to the power supply state, the software of the in-vehicle device is updated and activated in due sequence at appropriate times, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0036] (3) In the update management device of (1) above, it may also be that the update management device further includes: a first deletion instruction unit that, when the pre-update first software and the pre-update second software are installed in the second storage unit and the updated first software is installed in the first storage unit, sends a first deletion instruction to the in-vehicle device for deleting the pre-update first software and the pre-update second software from the second storage unit; and a second deletion instruction unit that, when the updated first software is installed in the first storage unit and the updated first software and the updated second software are installed in the second storage unit, sends a second deletion instruction to the in-vehicle device for deleting the updated first software from the first storage unit.

[0037] With this configuration, after the update management device causes the in-vehicle device to install software in one storage unit and activate it, it deletes the software in the other storage unit. Thus, the storage unit for subsequent software installation, etc. is empty, and software can be installed, etc. next.

[0038] (4) In the update management device of (1) above, it may also be that the first power supply state is the power supply state when the vehicle is in a non-drivable state, and the second power supply state is the power supply state when the vehicle is in a drivable state.

[0039] With this configuration, the update management device sends update data for alternately installing software in two storage units of the in-vehicle device and activating it according to the power supply state when the vehicle is drivable and the power supply state when the vehicle is non-drivable. Thus, according to the power supply state, the software of the in-vehicle device is updated and activated in due sequence at appropriate times, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0040] (5) In the update management device of (1) above, it may also be that the receiving unit receives the first update data and the second update data from the external device during the period when the power supply state is the first power supply state.

[0041] With this configuration, since update data is downloaded to the update management device in the first power supply state, software can be quickly installed and activated after transitioning to the second power supply state.

[0042] (6) The update management system of the present disclosure is an update management system including the update management device and the in-vehicle device according to any one of (1) to (5) above.

[0043] (7) The update management system of the present disclosure includes an update management device and an in-vehicle device. The update management device manages the update of the software of the in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle. The first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; a first sending unit that, when the determination unit determines that the power state of the vehicle is the first power state, sends the first update data to the in-vehicle device so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; a second sending unit that, when the determination unit determines that the power state of the vehicle is the second power state, sends the first update data and the second update data to the in-vehicle device so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software; a first instruction unit that, when the determination unit determines that the power state of the vehicle is the first power state, sends a first activation instruction to the in-vehicle device, and the first activation instruction is used to activate the updated first software installed in the first storage unit; and a second instruction unit that, when the determination unit determines that the power state of the vehicle is the second power state, sends a second activation instruction to the in-vehicle device, and the second activation instruction is used to activate the updated first software and the updated second software installed in the second storage unit. The in-vehicle device includes: a first activation unit that, when receiving the first activation instruction, activates the updated first software installed in the first storage unit; and a second activation unit that, when receiving the second activation instruction, activates the updated first software and the updated second software installed in the second storage unit.

[0044] With this configuration, the update management device sends update data for alternately installing and activating software in two storage units of the in-vehicle device to the in-vehicle device. Based on the received update data, the in-vehicle device installs and activates the software according to the power state of the vehicle. Thus, the software of the in-vehicle device is updated and activated successively at appropriate times according to the power state, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0045] (8) In the update management device of (7) above, it may also be that the update management system further includes, in the in-vehicle device: a first deletion unit that deletes the pre-update first software and the pre-update second software from the second storage unit when the pre-update first software and the pre-update second software are installed in the second storage unit and the first software is installed in the first storage unit; and a second deletion unit that deletes the updated first software from the first storage unit when the updated first software is installed in the first storage unit and the updated first software and the updated second software are installed in the second storage unit.

[0046] With this configuration, after the update management system causes the in-vehicle device to install and activate software in one storage unit of the in-vehicle device, it deletes the software in the other storage unit. As a result, the storage unit of the in-vehicle device where software is to be installed next is empty, enabling software to be installed next.

[0047] (9) The computer program of the present disclosure is a computer program for controlling an update management device that manages the update of software of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The computer program includes: a reception step of receiving first update data and second update data from an external device of the vehicle, the first update data being for updating first software that operates in the first power state and the second power state, and the second update data being for updating second software that does not operate in the first power state but operates in the second power state; a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first transmission step of, when it is determined that the power state of the vehicle is the first power state, transmitting the first update data to the in-vehicle device so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; and a second transmission step of, when it is determined that the power state of the vehicle is the second power state, transmitting the first update data and the second update data to the in-vehicle device so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software.

[0048] With such a configuration, according to the power state of the vehicle, the update management device transmits update data for alternately installing software in two storage units of the in-vehicle device and activating it to the in-vehicle device. Thereby, the software of the in-vehicle device is updated and activated in sequence at an appropriate timing according to the power state, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0049] (10) The update management device of the present disclosure manages the update of the software of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle, the first update data being for updating a first software that operates in the first power state and the second power state, and the second update data being for updating a second software that does not operate in the first power state but operates in the second power state; a synthesizing unit that creates synthesized update data for installing a synthesized software based on the first update data and the second update data, the synthesized software including a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a transmitting unit that transmits the synthesized update data to the in-vehicle device, so that the in-vehicle device having a storage unit installs the synthesized software in a recording unit and activates the first function when the power state of the vehicle is the first power state and activates the second function when the power state of the vehicle is the second power state.

[0050] With such a configuration, the update management device creates synthesized update data based on two update data for updating two software, and transmits the update data for installation in the storage unit of the in-vehicle device and activation according to the power state of the vehicle to the in-vehicle device. Thereby, the software of the in-vehicle device is updated and activated at appropriate timings according to the power state, and functions in which the software of a plurality of ECUs cooperate to operate operate in a coordinated manner.

[0051] (11) In the update management device of (10) above, it may also be that the update management device further includes: a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; a first instruction unit that, when the determination unit determines that the power state of the vehicle is the first power state, transmits a first activation instruction for activating the first function to the in-vehicle device; and a second instruction unit that, when the determination unit determines that the power state of the vehicle is the second power state, transmits a second activation instruction for activating the second function to the in-vehicle device.

[0052] With such a configuration, according to the power state of the vehicle, the update management device causes the in-vehicle device to activate the software. Thereby, the software of the in-vehicle device is updated and activated at appropriate timings according to the power state, and functions in which the software of a plurality of ECUs cooperate to operate operate in a coordinated manner.

[0053] (12) In the update management device of the above (11), it may also be that when the determination unit determines that the power supply state of the vehicle is the first power supply state, it stores in the state storage unit that stores information indicating the power supply state the information indicating that the power supply state of the vehicle is the first power supply state, and when it determines that the power supply state of the vehicle is the second power supply state, it stores in the state storage unit the information indicating the second power supply state. The first instruction unit refers to the state storage unit and sends the first activation instruction to the in-vehicle device when the information indicating the first power supply state is stored. The second instruction unit refers to the state storage unit and sends the second activation instruction to the in-vehicle device when the information indicating the second power supply state is stored.

[0054] With such a configuration, based on the information indicating the power supply state of the vehicle, the update management device activates the software of the in-vehicle device. Thus, according to the power supply state, the software of the in-vehicle device is updated and activated in due order at appropriate times, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0055] (13) In the update management device of the above (10), it may also be that the first power supply state is the power supply state when the vehicle is in a non-drivable state, and the second power supply state is the power supply state when the vehicle is in a drivable state.

[0056] With such a configuration, the update management device creates composite update data based on two update data for updating two software, and sends the update data for installation in the storage unit of the in-vehicle device and activation according to the power supply state of the vehicle to the in-vehicle device. Thus, the software of the in-vehicle device is updated and activated in due order at appropriate times according to the power supply state, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0057] (14) In the update management device of the above (10), it may also be that the receiving unit receives the first update data and the second update data from the external device during the period when the power supply state is the first power supply state.

[0058] With such a configuration, since the update data is downloaded to the update management device in the first power supply state, the software can be quickly installed and activated after transitioning to the second power supply state.

[0059] (15) The update management system of the present disclosure is an update management system including the update management device according to any one of the above (10) to (14) and the in-vehicle device.

[0060] (16) The update management system of the present disclosure includes an update management device and an in-vehicle device. The update management device manages the update of the software of the in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. Among them, the update management device includes: a receiving unit that receives first update data and second update data from an external device of the vehicle. The first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state; a synthesizing unit that creates synthetic update data for installing a synthetic software according to the first update data and the second update data. The synthetic software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a transmitting unit that transmits the synthetic update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthetic software in the recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; a first instruction unit that, when the determination unit determines that the power state of the vehicle is the first power state, sends a first activation instruction for activating the first function to the in-vehicle device; and

[0061] a second instruction unit that, when the determination unit determines that the power state of the vehicle is the second power state, sends a second activation instruction for activating the second function to the in-vehicle device. The in-vehicle device includes: a first activation unit that activates the first function when receiving the first activation instruction; and a second activation unit that activates the second function when receiving the second activation instruction.

[0062] With such a configuration, the update management device creates synthetic update data according to two update data for updating two software, and sends the update data for installing in the storage unit of the in-vehicle device and activating according to the power state of the vehicle to the in-vehicle device. And, according to the power state of the vehicle, the update management device sends an activation instruction to the in-vehicle device, and the in-vehicle device activates the software. Thus, the software of the in-vehicle device is updated and is sequentially activated at appropriate times according to the power state, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0063] (17) In the update management system of (16) above, it may also be that when the determination unit determines that the power supply state of the vehicle is the first power supply state, it stores in the state storage unit that stores information indicating the power supply state, information indicating that the power supply state of the vehicle is the first power supply state, and when it determines that the power supply state of the vehicle is the second power supply state, it stores in the state storage unit information indicating the second power supply state. The first instruction unit refers to the state storage unit and sends the first activation instruction to the in-vehicle device when information indicating the first power supply state is stored. The second instruction unit refers to the state storage unit and sends the second activation instruction to the in-vehicle device when information indicating the second power supply state is stored.

[0064] With such a configuration, based on the information indicating the power supply state of the vehicle, the update management device activates the software of the in-vehicle device. Thus, according to the power supply state, the software of the in-vehicle device is updated and activated in due course in sequence, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0065] (18) The computer program of the present disclosure is a computer program for controlling an update management device that manages the update of the software of an in-vehicle device in a vehicle having multiple power supply states including a first power supply state and a second power supply state different from the first power supply state. The computer program includes: a receiving step of receiving, from an external device of the vehicle, first update data and second update data, where the first update data is used to update a first software that operates in the first power supply state and the second power supply state, and the second update data is used to update a second software that does not operate in the first power supply state but operates in the second power supply state; a synthesizing step of creating, based on the first update data and the second update data, synthesized update data for installing a synthesized software, where the synthesized software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a sending step of sending the synthesized update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthesized software in the recording unit, activates the first function when the power supply state of the vehicle is the first power supply state, and activates the second function when the power supply state of the vehicle is the second power supply state.

[0066] With such a configuration, the update management device creates synthesized update data based on two update data for updating two software, and sends the update data for installation in the storage unit of the in-vehicle device and activation according to the power supply state of the vehicle to the in-vehicle device. Thus, the software of the in-vehicle device is updated and activated in due course in sequence according to the power supply state, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0067] <Embodiment 1>

[0068] [1. Details of Embodiment 1 of the present disclosure]

[0069] Hereinafter, the details of Embodiment 1 of the present disclosure will be described with reference to the accompanying drawings.

[0070] [1.1 Structure of the update management system]

[0071] Figure 1 It is a diagram showing an example of the structure of the update management system 1 concerned.

[0072] The update management system 1 is a system mounted on a vehicle such as an automobile. The update management system 1 includes an update management ECU 11, a first ECU 12, a second ECU 13, communication buses 14a and 14b, and a communication device 15.

[0073] The update management ECU 11 (ECU: Electronic Control Unit) is an update management device that manages software updates of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. The first power state is, for example, the power state when the vehicle is in a non-drivable state, and the second power state is the power state when the vehicle is in a drivable state.

[0074] The first power state is, for example, the power state when the key switch for starting the engine is in the off position with the key inserted. Specifically, for example, the first power state is a state in which power is not supplied from the vehicle battery to most of the electrical devices in the vehicle, and power is directly supplied only to the minimum necessary in-vehicle devices. As the few electrical devices, for example, there are an anti-theft system, a clock, etc. Hereinafter, the first power state may sometimes be referred to as the +B state.

[0075] The second power state is, for example, the power state when the key switch for starting the engine is in the ignition position. Specifically, for example, the second power state is a state in which power is supplied to all electrical devices and the vehicle starts to move when the accelerator pedal is depressed. Hereinafter, the second power state may sometimes be referred to as the IG state.

[0076] It should be noted that, as the power states of the vehicle, two cases of the first power state and the second power state are described, but it is not limited thereto, and it may be further refined. In addition, the in-vehicle device may sometimes be referred to as an ECU.

[0077] The update management ECU 11 updates the software of in-vehicle devices in a vehicle having multiple power states. Therefore, the update management ECU 11 is configured to operate in the power state in which the software is updated. For example, the update management ECU 11 can operate in the +B state and the IG state.

[0078] The update management ECU 11 functions as an integrated ECU that manages, for example, the first ECU 12 and the second ECU 13. The update management ECU 11 can send, for example, update data downloaded from an external device outside the vehicle, i.e., the server 2, connected via the network 3 to the first ECU 12 and the second ECU 13.

[0079] The update management ECU 11 can also function as a GW-ECU (Gateway-ECU) that relays data transmitted and received between the first ECU 12 and the second ECU 13 and the communication device 15. The internal structure of the update management ECU 11 will be described later.

[0080] The communication device 15 is, for example, a communication interface that performs wireless communication. The communication device 15 communicates with the server 2 via a network 3 such as the Internet. Specifically, the communication device 15 is a TCU (Telematics Communication Unit). The communication device 15 sends data output from the update management ECU 11 to the server 2 via the network 3. In addition, the communication device 15 receives data (update data, etc.) sent from the server 2 via the network 3. The communication device 15 sends this data to the update management ECU 11 via the communication bus 14a.

[0081] The server 2 is a device provided outside the vehicle. The server 2 is, for example, a server having a control unit, a storage unit, and a communication unit (not shown). The storage unit of the server 2 stores, for example, programs or data for controlling each part of the update management system 1 (for example, the update management ECU 11, the first ECU 12, and the second ECU 13). For example, the manufacturers of the first ECU 12 and the second ECU 13 update the programs or data as needed and store the updated programs or data in the storage unit of the server 2 at any time. The control unit of the server 2 uses the communication unit to send the updated programs or data to the update management ECU 11 as update data.

[0082] The communication buses 14a and 14b are in-vehicle communication networks connected to the update management ECU 11. Various devices (the first ECU 12, the second ECU 13, the communication device 15, etc.) are connected to the communication buses 14a and 14b extending from the update management ECU 11. In Figure 1In the example, two communication buses 14a and 14b extend from the update management ECU 11, but the number of communication buses is not particularly limited. The communication buses 14a and 14b follow, for example, the communication protocols of CAN (Controller Area Network), Ethernet (registered trademark), or FlexRay (registered trademark), but are not limited thereto.

[0083] The update management ECU 11 is connected to the first ECU 12 and the second ECU 13 via the communication bus 14b. In Figure 1 the example, the update management ECU 11 is connected to the first ECU 12 and the second ECU 13 via the communication bus 14b.

[0084] The number of ECUs included in the update management system 1 is not particularly limited as long as it is two or more. The ECU is, for example, a device (operating system ECU) that controls each part of the vehicle (e.g., braking device, door, battery, air conditioner, etc.). The multiple ECUs may each have different functions or may each have the same function.

[0085] The first ECU 12 is an ECU installed with the first software that operates in the +B state and the IG state and the second software that does not operate in the +B state but operates in the IG state. The internal structure of the first ECU 12 will be described later. It should be noted that the software that operates in the +B state and the IG state is sometimes referred to as the +B software, and the software that does not operate in the +B state but operates in the IG state is sometimes referred to as the IG software.

[0086] The second ECU 13 is an ECU installed with the IG drive software. The internal structure of the second ECU 13 will be described later.

[0087] [1.2 Internal Structure of Update Management ECU 11]

[0088] Figure 2 is a diagram showing an example of the internal structure of the update management ECU 11.

[0089] The update management ECU 11 includes an information processing unit 21 including a control unit 22 and a storage unit 23, and a plurality of transceivers 25a and 25b. The above-mentioned units are electrically connected via an internal bus 24.

[0090] The control unit 22 includes, for example, one or more CPUs (Central Processing Unit), but is not limited thereto. In the case of a CPU, the control unit 22 reads out the computer program stored in the storage unit 23 and performs various operations and controls.

[0091] The storage unit 23 has a volatile memory and a non-volatile memory, and stores various data. The volatile memory includes, for example, a RAM (Random Access Memory). The non-volatile memory includes, for example, a flash memory, an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a ROM (ReadOnly Memory). A part of the non-volatile memory may also be provided outside the update management ECU 11.

[0092] The storage unit 23 stores, for example, computer programs, various parameters, and tables in the non-volatile memory. It should be noted that the storage unit 23 stores, for example, computer programs, various parameters, and tables downloaded from the server 2 via the network 3 and the communication device 15.

[0093] The plurality of transceivers 25a and 25b respectively transmit and receive signals flowing in the communication buses 14a and 14b via ports (not shown). The transceivers 25a and 25b send the information contained in the received signals to the control unit 22 via the internal bus 24. The transceivers 25a and 25b receive the information sent by the control unit 22 via the internal bus 24 and send it to the communication buses 14a and 14b. The transceiver 25a is connected to the communication bus 14a, and the transceiver 25b is connected to the communication bus 14b.

[0094] It should be noted that in the above, an example in which the control unit 22 of the information processing unit 21 includes a CPU has been described, but it is not limited thereto. For example, the information processing unit 21 may also be an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), etc. In the case of an FPGA, the information processing unit 21 performs various operations and controls through a pre-programmed structure. In the case of an ASIC, the information processing unit 21 performs various operations and controls through a structure fabricated during manufacturing.

[0095] [1.3 Internal Structure of ECU]

[0096] Figure 3 This is a diagram showing an example of the internal structure of the first ECU 12. The internal structure of the second ECU 13 is the same as that of the first ECU 12, so the description thereof is omitted.

[0097] The first ECU 12 includes an information processing unit 31, a transceiver 35, an input unit 36, and an output unit 37. The information processing unit 31 includes a control unit 32, a first storage unit 33, and a second storage unit 34. The transceiver 35 is electrically connected to the information processing unit 31 via an internal bus 38.

[0098] The control unit 32 includes, for example, one or more CPUs, but is not limited thereto. In the case of a CPU, for example, a computer program stored in the first storage unit 33 or the second storage unit 34 is read out, and various operations and controls are performed.

[0099] Similar to the storage unit 23, the first storage unit 33 and the second storage unit 34 each have a volatile memory and a non-volatile memory, and store various data. For example, the first storage unit 33 stores a computer program, various parameters, and tables in the non-volatile memory. For example, the first storage unit 33 and the second storage unit 34 are one memory bank after dividing a physical memory into several memory banks. The information processing unit 31 may also include a memory bank register (not shown) for switching memory banks. For example, the memory bank register is configured such that when 0 is written to the memory bank register, the first storage unit 33 becomes accessible, and when 1 is written to the memory bank register, the second storage unit becomes accessible. As another example, the first storage unit and the second storage unit may be the same storage unit. For example, a physical memory may be divided into several address spaces, and the memory in the first address space may be used as the first storage unit 33, and the memory in the second address space may be used as the second storage unit 34.

[0100] The transceiver 35 is formed of, for example, an integrated circuit (IC), and is, for example, a CAN transceiver. The transceiver 35 is connected to the communication bus 14b and receives various control messages from the communication bus 14b.

[0101] The transceiver 35 includes a transmission circuit and a reception circuit (not shown). The transmission circuit and the reception circuit communicate in accordance with the communication protocol of the communication bus 14b. The transmission circuit converts the data of the digital signal output from the information processing unit 31 into a prescribed analog signal and sends it to the communication bus 14b. The reception circuit converts the analog signal input from the communication bus 14b into a digital signal that can be read by the information processing unit 31, and outputs the digital signal to the information processing unit 31.

[0102] The input unit 36 is connected to, for example, sensors, input devices, etc. The input unit 36 receives signals corresponding to the state of the vehicle, signals corresponding to instructions from the driver, etc. The sensors are, for example, a temperature sensor that detects the temperature inside the vehicle, a door switch that detects when the door is closed, etc. The input devices are, for example, a switch for operating the air conditioner, etc.

[0103] The output unit 37 is connected to, for example, an electric motor, a solenoid valve, etc. Based on the information sent by the information processing unit 31, the output unit 37 drives the connected electric motor, solenoid valve, etc. This information is, for example, information indicating the operation of the connected electric motor, etc. The electric motor is, for example, an electric motor that moves the window of the vehicle door up and down. The solenoid valve is, for example, a solenoid valve that locks the vehicle door.

[0104] [1.4 Problems to be Solved by the Present Embodiment]

[0105] A vehicle is known that has multiple power supply states including a +B state, an IG state, etc. and is equipped with multiple ECUs. For example, the first ECU is installed with a first software that operates in the +B state and the IG state and a second software that does not operate in the +B state but operates in the IG state, and the second ECU is installed with a third software that does not operate in the +B state but operates in the IG state. In such a situation, sometimes the second software and the third software cooperate and a specified system operates.

[0106] When the first software and the second software in the first ECU are updated by update data, since the first software and the second software are installed in one first ECU, they can be activated even in the +B state. On the other hand, since the second ECU is installed with the third software that operates in the IG state, when the power supply state transitions to the IG state, the installation of the third software starts by the update data and the third software is activated. In the situation where the second software of the first ECU has already been activated in the +B state, sometimes at the timing when the power supply state transitions to the IG state, the second software of the first ECU issues a command to the third software of the second ECU. However, since the third software of the second ECU has just started to be installed and cannot understand the command issued by the second software of the first ECU, the specified system may not operate.

[0107] For example, the first ECU is a door ECU and the second ECU is a sensor ECU. For example, the first software is door lock control software for controlling the door lock, the second software is window control software for controlling the electric window, and the third software is raindrop detection software for a sensor that detects raindrops. The specified system is a rainy day window closing system that closes the window on a rainy day.

[0108] In this case, when the door lock software and the window software of the door ECU are updated by updated data, since the door lock software and the window software are installed in the door ECU, they can be activated even in the +B state. On the other hand, since the sensor ECU is installed with the raindrop detection software that operates in the IG state, when the power state transitions to the IG state, the installation of the raindrop detection software starts by the updated data, and the raindrop detection software is activated. Since the window software of the door ECU has been activated in the +B state, sometimes at the timing when the power state transitions to the IG state, the window software of the door ECU issues a command to the raindrop detection software of the sensor ECU. However, since the raindrop detection software of the sensor ECU has just started to be installed and cannot understand the command issued by the window software of the door ECU, the rainy-day window closing system may not operate. For example, in rainy weather, the window may not close.

[0109] Hereinafter, with appropriate reference to Figures 1 to 6 the specific control content in the update management system 1 will be described.

[0110] [1.5 Functions of the Update Management Device]

[0111] Figure 4 It is a functional block diagram showing the functions included in the update management ECU 11 according to the first embodiment. Figure 5 and Figure 6 is a table showing an example of the ECU table listing the ECUs. The update management ECU 11 includes a receiving unit 41, a determination unit 42, a first transmission unit 43, a second transmission unit 44, a first instruction unit 45, a second instruction unit 46, a first deletion instruction unit 47, and a second deletion instruction unit 48. It should be noted that Figure 5 and Figure 6 the "R" shown in indicates that the system or software operates in this power state.

[0112] [1.5.1 Receiving Unit]

[0113] The receiving unit 41 receives the first update data and the second update data from the external device of the vehicle. The first update data is used to update the first software that operates in the first power state and the second power state, and the second update data is used to update the second software that does not operate in the first power state but operates in the second power state.

[0114] Specifically, the receiving unit 41 has a function of downloading the first update data and the second data from the server 2. The server 2 is provided, for example, in the data center of the vehicle manufacturer. Update data for updating the software of each ECU is stored in the server 2, for example. The first update data is update data for installing the door lock software as the +B software of the first ECU 12. The second update data is update data for installing the window software as the IG software of the first ECU 12.

[0115] The receiving unit 41 causes the control unit 22 to operate, accesses the server 2 via the internal bus 24, the transceiver 25a, the communication device 15, and the network 3, and downloads the update data stored in the server 2. The cause of starting the download is, for example, the case where update data is newly recorded in the server 2. In this case, the server 2 sends information indicating that update data has been newly recorded to each update management system 1. The information indicating that update data has been newly recorded may include information indicating the version of the newly recorded update data. Hereinafter, the information indicating that update data has been newly recorded is referred to as update software information. For example, as an example of newly recording update data in the server 2, consider the case where the window software of the first ECU 12 for implementing the rainy-day window closing system and the rain drop detection software of the second ECU 13 are updated because the rain sensitivity is improved compared with the conventional rain sensor.

[0116] The update management ECU 11 of each update management system 1 stores, for example, Figure 5 an ECU table as shown in the storage unit 23. For example, this ECU table includes information indicating a specified system, the ECU and software that execute the specified system, the power state in which the software operates, and the version of the software of the ECU, and is recorded in the storage unit 23 in a table form for each specified system. As the specified system, for example, is the rainy-day window closing system. As Figure 5 shown, the ECU and software that execute this function are the window software of the door ECU and the rain drop detection software of the sensor ECU. The window software and the rain drop detection software are software that operate in the IG state. The version of the software is, for example, 1.02. In this example, the rainy-day window closing system is implemented by the IG drive software, and thus the whole operates in the IG state.

[0117] It should be noted that the example in which the ECU table is stored in the storage unit 23 of the update management ECU 11 is described, but it is not limited thereto. For example, it may be stored in the storage unit of the server 2.

[0118] Figure 6This is another example of the ECU table. In this example, as a specified system, for example, it is a keyless entry system. The ECU and software that execute the specified system are, for example, the software for the door lock of the door ECU and the software of the ECU that cooperates with it. Since the keyless entry system operates in the +B state, the software of each ECU also operates in the +B state.

[0119] The receiving unit 41, for example, compares the version information included in the updated software information sent from the server with the version information recorded in the ECU table to determine whether the software has been updated. In the case where it is determined that the software has been updated, the receiving unit 41 requests the update data from the server 2 and downloads it. The receiving unit 41, for example, temporarily records the downloaded update data in the storage unit 23.

[0120] It should be noted that the receiving unit 41 can also receive the first update data and the second update data from an external device during the power state being the first power state. For example, the update data for updating the door lock software as the +B software and the window software as the IG software can be downloaded during the +B state, that is, when the vehicle is in a non-drivable state, such as during parking. By downloading the update data during parking, it is possible to quickly start the transmission of the update data and the installation of the IG software, etc. for the ECU that does not install the +B software but installs the IG software at the timing when the power state transitions to the IG state.

[0121] [1.5.2 Determination Unit]

[0122] The determination unit 42 has the function of determining whether the power state of the above vehicle is the above first power state or the above second power state.

[0123] Specifically, the determination unit 42, for example, detects the power state of the vehicle and determines whether the detected power state is the +B state or the IG state. The detection of the power state of the vehicle can be performed by the update management ECU 11 or by a power monitoring ECU (not shown) that monitors the power state of the vehicle. Regarding the detection of the power state, in the case of the +B state, for example, the voltage of the power bus connected to the electrical equipment directly supplied with power by the vehicle's battery is detected, and if it is above a specified voltage, it is determined to be the +B state. In the case of the IG state, for example, the voltage of the power bus that supplies power to the ECU that operates when the vehicle starts to move if the accelerator pedal is depressed, such as the engine control ECU, is detected, and if it is above a specified voltage, it is determined to be the IG state. It should be noted that when it is the +B state and the IG state, it is determined to be the IG state.

[0124] [1.5.3 First Sending Unit]

[0125] The first transmission unit has the following function: when the power supply state of the vehicle is determined by the determination unit to be the first power supply state, it transmits the first update data to the in-vehicle device, so that the in-vehicle device having the first storage unit and the second storage unit installs the updated first software in the first storage unit and activates the updated first software.

[0126] In Figure 5 and Figure 6 cases, when the determination unit 42 determines that the power supply state of the vehicle is the +B state, the first transmission unit 43 transmits update data for installing the door lock software as the +B software to the door ECU which is the first ECU 12.

[0127] For example, the first transmission unit 43 causes the control unit 22 to operate and execute the function of the first transmission unit 43. First, the control unit 22 reads out the first update data temporarily stored. Next, the control unit 22 transmits the read first update data to the communication bus 14b via the transceiver 25b. The first update data transmitted to the communication bus 14b reaches the transceiver 35 of the first ECU 12. The first ECU 12 operates through the control unit 32, and the control unit 32 receives the reached update data via the transceiver 35. The control unit 32 causes the first storage unit 33 or a RAM (Random Access Memory) (not shown) to temporarily store the received update data.

[0128] When the first transmission unit 43 transmits the first update data, the first ECU 12 installs the +B software in the first storage unit 33 through the received first update data. For example, the door ECU installs the door lock software in the first storage unit 33.

[0129] For example, it is configured that when the first update data is transmitted from the first transmission unit 43, after the reception of the transmitted update data is completed, the control unit 32 of the first ECU 12 installs the software in the first storage unit 33 based on the temporarily stored update data.

[0130] As another example, when the first transmission unit transmits the first update data, the update management ECU 11 transmits a first installation instruction to the first ECU 12, and the first installation instruction is an instruction to install the +B software in the first storage unit 33 through the first update data. Then, it is configured that the first ECU 12 that receives the first installation instruction installs the +B software.

[0131] [1.5.4 Second Transmission Unit]

[0132] The second transmission unit has the following function: when the determination unit determines that the power supply state of the vehicle is the second power supply state, it transmits the first update data and the second update data to the in-vehicle device, so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit, and activates the updated first software and the updated second software.

[0133] In Figure 5 and Figure 6 cases, when the determination unit 42 of the second transmission unit 44 determines that the power supply state of the vehicle is the IG state, it transmits the first update data and the second update data for installing the door lock software as the +B software and the window software as the IG software to the door ECU which is the first ECU 12.

[0134] For example, the second transmission unit 44 causes the control unit 22 to operate and execute the function of the second transmission unit 44. First, the control unit 22 reads out the first update data temporarily stored in the storage unit 23. Then, the control unit 22 transmits the read first update data to the communication bus 14b via the transceiver 25b. The first update data transmitted to the communication bus 14b reaches the transceiver 35 of the first ECU 12. The first ECU 12 operates through the control unit 32, and the control unit 32 receives the reached update data via the transceiver 35. The control unit 32 causes the first storage unit 33 or the RAM (not shown) to temporarily store the received update data.

[0135] When the second transmission unit transmits the first update data and the second update data, the first ECU 12 installs the +B software and the IG software in the second storage unit 34 through the received first update data and second update data. For example, the door ECU installs the door lock software and the window software in the second storage unit 34.

[0136] When the first update data and the second update data are transmitted from the second transmission unit 44, the first ECU 12 temporarily stores the transmitted first update data and second update data in the second storage unit 34, for example. It can also be configured that after the reception of the transmitted update data is completed, the control unit 32 of the first ECU 12 installs the software based on the update data temporarily stored in the second storage unit 34.

[0137] As another example, when the second transmission unit transmits the first update data and the second update data, the update management ECU 11 transmits a second installation instruction to the first ECU 12, and the second installation instruction is an instruction to install the +B software and the IG software in the second storage unit 34 through the first update data and the second update data. Then, it can also be configured that the first ECU 12 that receives the second installation instruction installs the +B software and the IG software.

[0138] [1.5.5 First Indicator Unit]

[0139] The first indicator unit 45 has the following function: when the power supply state of the vehicle is determined by the determination unit to be the first power supply state, it sends a first activation instruction to the in-vehicle device, and this first activation instruction is used to activate the updated first software installed in the first storage unit.

[0140] In Figure 6 the example of the keyless entry system executed in the +B state, when the determination unit 42 determines that the power supply state is the +B state, the first indicator unit 45 sends an activation instruction to activate the door lock software as the +B software.

[0141] More specifically, the first indicator unit 45 refers to the ECU table stored in the storage unit 23, such as Figure 5 and Figure 6 the content shown. According to the referred ECU table, the first indicator unit 45 obtains information indicating which software for operation in which power supply state the system is executed by. In Figure 6 the example, the door lock software for the keyless entry system operates in both the +B state and the IG state. Therefore, when the power supply state is the +B state, the first indicator unit 45 sends a first activation instruction to the door ECU to activate the updated door lock software installed in the first storage unit 33. On the other hand, since the +B software is not listed in Figure 5 , the first indicator unit 45 does not send the first activation instruction.

[0142] It should be noted that the first activation instruction can also be sent to the in-vehicle device after the software is installed through the update data. This is because the software cannot be activated during installation. For example, the first indicator unit 45 is configured to wait for transmission within a specified time. In other examples, the in-vehicle device is configured to send installation completion information, which is information indicating the completion of software installation, to the update management device after the software installation is completed. Then, it is configured that when receiving the installation completion information, the first indicator unit 45 sends the first activation instruction.

[0143] It should be noted that as an example, the first ECU 12 is configured to, when receiving the first activation instruction sent by the first indicator unit 45, cause the control unit 32 (first activation unit 32a) to act and activate the first software installed in the first storage unit 33.

[0144] [1.5.6 Second Indicator Unit]

[0145] The second instruction unit has the following function: when the power supply state of the vehicle is determined by the determination unit to be the second power supply state, it sends a second activation instruction to the in-vehicle device, and the second activation instruction is used to activate the updated first software and the updated second software installed in the second storage unit.

[0146] In Figure 5 and Figure 6 example, when the determination unit 42 determines that the power supply state is the IG state, the second instruction unit 46 sends a second activation instruction for activating the window software as the IG software to the door ECU for the rainy-day window closing system. In addition, the second instruction unit 46 sends a second activation instruction for activating the raindrop detection software to the sensor ECU. In addition, the second instruction unit 46 sends a second activation instruction for activating the door lock software as the +B software to the door ECU for the keyless entry system.

[0147] More specifically, the second instruction unit 46 refers to the ECU table stored in the storage unit 23, Figure 5 and Figure 6 the content shown. According to the referred ECU table, the second instruction unit 46 obtains information indicating which software executes the system in which power supply state. In Figure 5 example, since the rainy-day window closing system is executed by the window software and the raindrop detection software that operate in the IG state, when the power supply state is the IG state, the second instruction unit 46 sends a second activation instruction for activating the updated window software installed in the second storage unit 34 to the door ECU. In addition, since the door lock software that executes the keyless entry system operates in both the +B state and the IG state, when the power supply state is the IG state, the second instruction unit 46 sends a second activation instruction for activating the updated door lock software installed in the second storage unit 34 to the door ECU. In addition, the update management device may also send an activation instruction for activating the raindrop detection software to the sensor ECU.

[0148] It should be noted that for the second instruction unit, for the same reason as the first instruction unit, after the software is installed by the update data, a second activation instruction may be sent to the in-vehicle device.

[0149] It should be noted that as an example, the first ECU 12 is configured to, when receiving the second activation instruction sent by the second instruction unit 46, cause the control unit 32 (the second activation unit 32b) to operate and activate the first software and the second software installed in the second storage unit 34.

[0150] [1.5.7 First deletion instruction unit]

[0151] The first deletion instruction unit 47 has the following function: when the pre-update first software and the pre-update second software are installed in the second storage unit, and the updated first software is installed in the first storage unit, a first deletion instruction for deleting the pre-update first software and the pre-update second software from the second storage unit is sent to the in-vehicle device.

[0152] Specifically, the control unit 22 sends the first deletion instruction to the communication bus 14b via the transceiver 25b. The sent first deletion instruction reaches the transceiver 35 of the first ECU 12 via the communication bus 14b. The control unit 32 of the first ECU 12 receives the first deletion instruction that reaches the transceiver 35. Based on the received first deletion instruction, the control unit 32 deletes the pre-update first software and the pre-update second software installed in the second storage unit 34.

[0153] This is because, by deleting the pre-update software in the second storage unit 34, the second storage unit 34 becomes empty. When software is installed later, the possibility that the residue of the pre-update software has an adverse effect on the software installed later can be suppressed. It should be noted that when there are no particular problems even when installed on the pre-update software, the sending of the first deletion instruction can be skipped.

[0154] It should be noted that the deletion of the pre-update software that was once installed in the second storage unit 34 can also be performed after the software is installed in the first storage unit 33 and activated. This is because, when the pre-update software that was once installed in the second storage unit 34 is executed until just before activation, an instant exchange with the software in the first storage unit 33 can be achieved.

[0155] [1.5.8 Second deletion instruction unit]

[0156] The second deletion instruction unit 48 has the following function: when the updated first software is installed in the first storage unit, and the updated first software and the updated second software are installed in the second storage unit, a second deletion instruction for deleting the updated first software from the first storage unit is sent to the in-vehicle device.

[0157] Specifically, the control unit 22 sends the second deletion instruction to the communication bus 14b via the transceiver 25b. The sent first deletion instruction reaches the transceiver 35 of the first ECU 12 via the communication bus 14b. The control unit 32 of the first ECU 12 receives the second deletion instruction that reaches the transceiver 35. Based on the received second deletion instruction, the control unit 32 deletes the updated first software installed in the first storage unit 33.

[0158] When the updated first software was previously installed in the first storage unit 33, when the updated first software and the updated second software are installed in the second storage unit 34, the updated first software previously installed in the first storage unit 33 can also be deleted.

[0159] This is because, after the updated first software and the updated second software are installed in the second storage unit 34, the updated first software previously installed in the first storage unit 33 will not be executed, so the first storage unit 33 is emptied.

[0160] It should be noted that the deletion of the updated software previously installed in the first storage unit 33 can also be performed after the software is installed in the second storage unit 34 and activated. This is because, when the first software installed in the first storage unit is about to be activated after being executed, it can be instantaneously exchanged with the software in the second storage unit 34.

[0161] [1.6 Control Method]

[0162] Figure 7 It is a flowchart showing an example of the control method executed by the update management ECU 11 according to Embodiment 1. Figure 7 The order of the steps shown can also be changed appropriately. Use Figure 7 to illustrate a series of control methods. It should be noted that the description starts from the state where the vehicle cannot run in the initial state. Therefore, in the initial state, the power state of the vehicle is the +B state.

[0163] It should be noted that the control executed by the update management ECU 11 is executed by the information processing unit 21. When the information processing unit 21 executes the control, the control unit 22 reads the computer program from the storage unit 23 and executes various operations and processes.

[0164] In addition, the control executed by the first ECU 12 is executed by the information processing unit 31. When the information processing unit 31 executes the control, the control unit 32 reads the computer program from the first storage unit 33 to execute various operations and processes.

[0165] [1.6.1 Step S101]

[0166] First, the receiving unit 41 of the update management ECU 11 downloads update data from the server 2 (step S101). Specifically, the receiving unit 41 receives the first update data and the second update data from an external device of the vehicle. The first update data is used to update the first software that operates in the first power state and the second power state, and the second update data is used to update the second software that does not operate in the first power state but operates in the second power state. After the reception is completed, the update management ECU 11 proceeds to step S102.

[0167] More specifically, the receiving unit 41 of the update management ECU 11 downloads the first update data and the second data from the server 2. Update data for each ECU is stored in the server 2. The first update data is the update data for installing the +B software. The second update data is the update data for installing the IG software. The update management ECU 11 accesses the server 2 via the communication bus 14a, the transceiver 25a, the communication device 15, and the network 3 to download the update data stored in the server 2.

[0168] For example, when new update data is recorded in the server 2, the server 2 sends update software information including information indicating that new update data has been recorded to the update management system 1. Information indicating the version of the newly recorded update data may also be included in the update software information.

[0169] The update management ECU 11 of the update management system 1 stores, for example, Figure 5 an ECU table as shown in the storage unit 23. In this ECU table, information indicating a specified system, the ECU and software that execute the specified system, the power state in which the software operates, and the version of the software of the ECU is recorded in a table form for each specified system.

[0170] The receiving unit 41 of the update management ECU 11 compares, for example, the update software information (including information indicating the version) sent from the server with the ECU table recorded in the storage unit 23 to determine whether the software has been updated. For example, the versions of the software are compared to determine whether it has been updated. When it is determined that the software has been updated, the receiving unit 41 requests the update data from the server 2 and downloads it. The receiving unit 41 temporarily records the downloaded update data in the storage unit 23, for example. After the download is completed, it proceeds to step S102.

[0171] [1.6.2 Step S102]

[0172] Next, when the determination unit of the update management ECU 11 determines that the power state of the vehicle is the first power state, the update management ECU 11 sends the first update data to the in-vehicle device so that the in-vehicle device having the first storage unit and the second storage unit installs the updated first software in the first storage unit and activates the updated first software (step S102). As described above, since the initial state of the power state is the +B state, step S102 is executed. Then, the update management ECU 11 proceeds to step S103.

[0173] In Figure 5 and Figure 6In the case where the +B software is the door lock software of the first ECU 12, the first transmission unit 43 of the update management ECU 11 sends first update data for installing the door lock software to the first ECU 12. The first ECU 12 includes a first storage unit 33 and a second storage unit 34, and this update data is used to be installed in and activated in the first storage unit 33.

[0174] When the first ECU 12 receives the first update data at the first transmission unit 43, the first ECU 12 installs the +B software in the first storage unit 33 through the received first update data. In Figure 5 and Figure 6 cases, the door ECU installs the door lock software in the first storage unit 33.

[0175] [1.6.3 Step S103]

[0176] Next, when the first instruction unit 45 determines that the power supply state of the vehicle is the first power supply state by the above determination unit, the first instruction unit 45 sends a first activation instruction to the in-vehicle device, and this first activation instruction is used to activate the updated first software installed in the first storage unit (step S103). As described above, since the initial state of the power supply state is the +B state, step S103 is executed. Then, the update management ECU 11 enters step S104.

[0177] In Figure 5 and Figure 6 cases, regarding the keyless entry system executed in the +B state, the first activation instruction is an activation instruction for activating the door lock software as the +B software. The first instruction unit 45 sends this first activation instruction to the first ECU 12.

[0178] Specifically, the first instruction unit 45 refers to the ECU table stored in the storage unit 23, for example, the content shown in Figure 5 and Figure 6 According to the referred ECU table, the first instruction unit 45 obtains information indicating which software the system is executed by in which power supply state. In the example of Figure 6 , the door lock software for executing the keyless entry system operates in both the +B state and the IG state. Therefore, when the power supply state is the +B state, the first instruction unit 45 sends a first activation instruction for activating the updated door lock software installed in the first storage unit 33 to the door ECU. On the other hand, since the +B software is not listed in Figure 5 , the first instruction unit 45 does not send the first activation instruction.

[0179] It should be noted that the first activation instruction can also be sent to the in-vehicle device after the software is installed through the update data.

[0180] When the first ECU 12 receives the first activation instruction, the first ECU 12 activates the first software installed in the first storage unit 33.

[0181] [1.6.4 Step S104]

[0182] Next, when the first deletion instruction unit 47 has installed the first software before update and the second software before update in the second storage unit and has installed the first software after update in the first storage unit, the first deletion instruction unit 47 sends a first deletion instruction to the vehicle device to delete the first software before update and the second software before update from the second storage unit (Step S104). Then, the update management ECU 11 proceeds to Step S105.

[0183] Specifically, the control unit 22 sends the first deletion instruction to the communication bus 14b via the transceiver 25b. The sent first deletion instruction reaches the transceiver 35 of the first ECU 12 via the communication bus 14b. The first ECU 12 receives the first deletion instruction that has reached the transceiver 35. Based on the received first deletion instruction, the control unit 32 deletes the first software before update and the second software before update installed in the first storage unit 33.

[0184] It should be noted that the deletion of the software before update that was once installed in the second storage unit 34 can also be performed after it is installed in the first storage unit 33 and the software is activated. Additionally, if there are no particular problems even when the software before update is installed, this step can be skipped.

[0185] [1.6.5 Step S105]

[0186] Next, the determination unit 42 of the update management ECU 11 determines whether the power state of the vehicle is the first power state or the second power state (Step S105). When the determination unit determines that the power state of the vehicle is the second power state, i.e., the IG state, the update management ECU 11 proceeds to Step S106. On the other hand, when the determination unit determines that the power state of the vehicle is the first power state, i.e., the +B state, the update management ECU 11 returns to Step S105 and repeats Step S105. That is, it is in a state of waiting for the power state of the vehicle to transfer from the +B state to the IG state.

[0187] [1.6.6 Step S106]

[0188] Next, when the second transmission unit of the update management ECU 11 determines that the power supply state of the vehicle is the second power supply state by the above determination unit, it transmits the first update data and the second update data to the in-vehicle device, so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software (step S106). Then, the update management ECU 11 proceeds to step S107.

[0189] In Figure 5 and Figure 6 cases, when the determination unit 42 determines that the power supply state of the vehicle is the IG state, that is, when the power supply state of the vehicle transfers from the +B state to the IG state, the second transmission unit 44 transmits the first update data for installing the door lock software as the +B software and the second update data for installing the window software as the IG software to the door ECU.

[0190] When the first ECU 12 receives the first update data and the second update data, the first ECU 12 installs the +B software and the IG software in the second storage unit 34 through the received first update data and second update data. For example, the door ECU installs the door lock software and the window software in the second storage unit 34.

[0191] [1.6.7 Step S107]

[0192] Next, when the second instruction unit 46 of the update management ECU 11 determines that the power supply state of the vehicle is the second power supply state by the above determination unit, it transmits a second activation instruction to the in-vehicle device, and the second activation instruction is used to activate the updated first software and the updated second software installed in the second storage unit (step S107). Then, the update management ECU 11 proceeds to step S108.

[0193] In Figure 5 and Figure 6 example, when the determination unit 42 determines that the power supply state is the IG state, the second instruction unit 46 transmits a second activation instruction for activating the window software as the IG software to the rainy day window closing system. In addition, the second instruction unit 46 transmits a second activation instruction for activating the door lock software as the +B software to the keyless entry system. In addition, the update management device may also transmit an activation instruction for activating the rain drop detection software to the sensor ECU.

[0194] It should be noted that the second activation instruction may also be transmitted to the in-vehicle device after the software is installed through the update data.

[0195] When the vehicle-mounted device receives the second activation instruction, the vehicle-mounted device activates the first software and the second software installed in the second storage unit. In Figure 5 and Figure 6 When the door ECU that has received the second activation instruction activates the window software and the door lock software installed in the second storage unit 34. In addition, the raindrop detection software of the sensor ECU can also be activated. This is because the window software and the raindrop detection software cooperate to execute the rainy-day window closing system.

[0196] [1.6.8 Step S108]

[0197] Next, when the second deletion instruction unit 48 of the update management ECU installs the updated first software in the first storage unit and installs the updated first software and the updated second software in the second storage unit, it sends a second deletion instruction to the vehicle-mounted device to delete the updated first software from the first storage unit (Step S108). After that, the update management ECU 11 ends a series of processes.

[0198] It should be noted that the deletion of the updated software that was once installed in the first storage unit 33 can also be performed after the software is installed in the second storage unit 34 and activated. In addition, when the first storage unit 33, etc. are not particularly used in the future, this step can also be skipped.

[0199] [1.7 Control Sequence]

[0200] Next, the control sequence of the update management system 1 will be described. Figure 8 is the sequence diagram of the update management system according to Embodiment 1. It should be noted that the description starts from the state where the vehicle cannot drive in the initial state. Therefore, in the initial state, the power state of the vehicle is the +B state. After that, the power state transfers from the +B state to the IG state.

[0201] [1.7.1 Step S201]

[0202] First, the receiving unit 41 of the update management ECU 11 downloads update data from the server 2 (Step S201). Specifically, the receiving unit 41 receives the first update data and the second update data from an external device of the vehicle. The first update data is used to update the first software that operates in the first power state and the second power state, and the second update data is used to update the second software that does not operate in the first power state but operates in the second power state. After the reception is completed, the update management system 1 enters Step S202.

[0203] Specifically, the receiving unit 41 of the update management ECU 11 downloads the first update data and the second data from the server 2. The update data of each ECU is stored in the server 2. The first update data is the update data for installing the +B software. The second update data is the installation data for updating the IG software. The update management ECU 11 accesses the server 2 via the communication bus 14a, the transceiver 25a, the communication device 15, and the network 3 to download the update data stored in the server 2.

[0204] [1.7.2 Step S202]

[0205] Next, when the determination unit determines that the power supply state of the vehicle is the first power supply state, the update management ECU 11 sends the first update data to the in-vehicle device, so that the in-vehicle device having the first storage unit and the second storage unit installs the updated first software in the first storage unit and activates the updated first software (Step S202). As described above, since the initial state of the power supply state is the +B state, Step S202 is executed. Then, the update management system 1 proceeds to Step S203.

[0206] In Figure 5 and Figure 6 cases, since the +B software is the door lock software of the first ECU 12, the first transmission unit 43 of the update management ECU 11 sends the first update data for installing the door lock software to the first ECU 12. The first ECU 12 has a first storage unit 33 and a second storage unit 34, and this update data is used to be installed and activated in the first storage unit 33.

[0207] [1.7.3 Step S203]

[0208] Next, when the first transmission unit 43 sends the first update data, the first ECU 12 installs the +B software in the first storage unit 33 by the received first update data (Step S203). In Figure 5 and Figure 6 cases, the door ECU installs the door lock software in the first storage unit 33. After the installation, the update management ECU 11 proceeds to Step S204.

[0209] [1.7.4 Step S204]

[0210] Next, when the determination unit determines that the power supply state of the vehicle is the first power supply state, the first instruction unit 45 sends a first activation instruction to the in-vehicle device. This first activation instruction is used to activate the updated first software installed in the first storage unit (step S204). As described above, since the initial state of the power supply state is the +B state, step S204 is executed. Then, the update management system 1 proceeds to step S205.

[0211] In Figure 5 and Figure 6 the example of the keyless entry system executed in the +B state, the first activation instruction is an activation instruction to activate the door lock software as the +B software. The first instruction unit 45 sends this first activation instruction to the first ECU 12.

[0212] [1.7.5 Step S205]

[0213] Next, when the first ECU 12 receives the first activation instruction, the first activation unit activates the first software installed in the first storage unit 33 (step S205). Then, the update management system 1 proceeds to step S206.

[0214] [1.7.6 Step S206]

[0215] Next, when the first deletion instruction unit 47 installs the first software before update and the second software before update in the second storage unit, and installs the updated first software in the first storage unit, it sends a first deletion instruction to the in-vehicle device to delete the first software before update and the second software before update from the second storage unit (step S206). Then, the update management ECU 11 proceeds to step S207.

[0216] [1.7.7 Step S207]

[0217] Next, when the first ECU 12 receives the first deletion instruction, the control unit 32 deletes the first software before update and the second software before update installed in the first storage unit 33 according to the received first deletion instruction (step S207). Then, the update management system 1 proceeds to step S208.

[0218] It should be noted that even if the first software before update and the second software before update are not deleted, steps S206 and S207 can be skipped when there is no possibility of problems.

[0219] [1.7.8 Step S208]

[0220] Next, the determination unit 42 of the update management ECU 11 determines whether the power supply state of the vehicle is the first power supply state or the second power supply state (step S208). When the determination unit 42 determines that the power supply state of the vehicle is the second power supply state, i.e., the IG state, the update management system 1 proceeds to step S209. On the other hand, when the determination unit determines that the power supply state of the vehicle is the first power supply state, i.e., the +B state, the update management system 1 returns to step S208 and repeats step S208. That is, it is in a state of waiting for the power supply state of the vehicle to transfer from the +B state to the IG state. Therefore, after step S209, it is in a state where the power supply state is transferring from the +B state to the IG state.

[0221] [1.7.9 Step S209]

[0222] Next, when the second transmission unit of the update management ECU 11 determines that the power supply state of the vehicle is the second power supply state by the above determination unit, it transmits the first update data and the second update data to the in-vehicle device, so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software (step S209). Then, the update management ECU 11 proceeds to step S210.

[0223] In Figure 5 and Figure 6 cases, when the determination unit 42 determines that the power supply state of the vehicle is the IG state, that is, when the power supply state of the vehicle transfers from the +B state to the IG state, the second transmission unit 44 transmits the first update data for installing the door lock software as the +B software and the second update data for installing the window software as the IG software to the door ECU.

[0224] [1.7.10 Step S210]

[0225] When receiving the first update data and the second update data transmitted by the second transmission unit, the first ECU 12 installs the +B software and the IG software in the second storage unit 34 through the received first update data and second update data (step S210). In Figure 5 and Figure 6 cases, the door ECU installs the door lock software and the window software in the second storage unit 34. Then, the update management system 1 proceeds to step S211.

[0226] [1.7.11 Step S211]

[0227] Next, when the second indicating unit of the update management ECU 11 determines that the power supply state of the vehicle is the second power supply state, it sends a second activation instruction to the in-vehicle device. This second activation instruction is used to activate the updated first software and the updated second software installed in the second storage unit (step S211). Then, the update management ECU 11 proceeds to step S212.

[0228] In Figure 5 and Figure 6 example, when the determination unit 42 determines that the power supply state is the IG state, the second indicating unit 46 sends a second activation instruction for activating the window software, which is the IG software, to the rainy-day window closing system. In addition, the second indicating unit 46 sends a second activation instruction for activating the door lock software, which is the +B software, to the keyless entry system. Furthermore, the update management device may also send an activation instruction for activating the raindrop detection software to the sensor ECU.

[0229] [1.7.12 Step S212]

[0230] Next, when the first ECU 12 receives the second activation instruction, the first ECU 12 activates the first software and the second software installed in the second storage unit 34 (step S212). Then, the update management system proceeds to step S213.

[0231] [1.7.13 Step S213]

[0232] Next, when the second deletion instruction unit 48 of the update management ECU installs the updated first software in the first storage unit and installs the updated first software and the updated second software in the second storage unit, it sends a second deletion instruction to the in-vehicle device for deleting the updated first software from the first storage unit (step S213). Then, the update management system proceeds to step S214.

[0233] [1.7.14 Step S214]

[0234] Next, when the first ECU 12 receives the second deletion instruction, the control unit 32 deletes the updated first software installed in the first storage unit 33 according to the received second deletion instruction (step S214). Then, the update management system 1 ends a series of processes.

[0235] It should be noted that when there is no possibility of problems even if the updated first software is not deleted, steps S213 and S214 can be skipped.

[0236] [1.8 Summary]

[0237] There is known a vehicle having a plurality of power states including a +B state, an IG state, etc. and equipped with a plurality of ECUs. In such a vehicle, when the software of the ECU is updated, a plurality of software for cooperatively executing a prescribed system may be activated in different power states, and a command issued by one software may not be understood by another software, and the prescribed system may not operate.

[0238] According to the present embodiment, the update management device transmits update data for alternately installing software on two storage units of the in-vehicle device and activating the software to the in-vehicle device according to the power state of the vehicle. And, according to the power state of the vehicle, the update management device installs the software on the in-vehicle device by the update data, and the update management device activates the software according to the power state of the vehicle. Thereby, according to the power state, the software of the in-vehicle device is sequentially updated and activated at an appropriate timing, and the functions in which the software of a plurality of ECUs cooperate to operate operate in a coordinated manner.

[0239] Alternatively, the +B software and the IG software may be installed on the first ECU, and the IG software may be installed on the second ECU. When the IG software of the first ECU and the IG software of the second ECU cooperate to execute a prescribed system, an activation instruction for instructing activation is simultaneously transmitted to the IG software of the first ECU and the IG software of the second ECU. The IG software of the first ECU and the IG software of the second ECU are clearly activated simultaneously, further suppressing the incoordination in which the IG software of the second ECU cannot understand the command issued by the IG software of the first ECU.

[0240] It should be noted that the example in which the in-vehicle device includes the first storage unit and the second storage unit has been described, but it is not limited thereto, and it may further have a storage unit.

[0241] <Embodiment 2>

[0242] [2. Details of Embodiment 2 of the Present Disclosure]

[0243] Hereinafter, the details of Embodiment 2 of the present disclosure will be described with reference to the drawings.

[0244] The difference between Embodiment 1 and Embodiment 2 is as follows. In Embodiment 1, software was alternately installed on two storage units provided in the in-vehicle device by first update data for updating the first software and second update data for updating the second software. On the other hand, in Embodiment 2, the update management device creates combined update data in advance from the first update data and the second update data, and installs the software on one storage unit of the in-vehicle device by the combined update data. Other aspects are the same. The same reference numerals are assigned to the same structures as those in Embodiment 1, and the description of the same structures, functions, and operations is omitted.

[0245] [Structure of the Update Management System in 2.1]

[0246] The structure of the update management system in Embodiment 2 is the same as that in Embodiment 1. It should be noted that the in-vehicle device does not necessarily require two storage units, and there can also be only one storage unit.

[0247] [Problems to be Solved in this Embodiment in 2.2]

[0248] The problems to be solved in Embodiment 2 are the same as those in Embodiment 1. However, in the case where there is only one storage unit in the in-vehicle device, it cannot be dealt with in Embodiment 1. Therefore, the purpose is to solve this problem even when there is only one storage unit.

[0249] Therefore, in this embodiment, the update management device manages the update of the software of the in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state, and includes: a receiving unit that receives first update data and second update data from an external device of the vehicle, the first update data being used to update a first software that operates in the first power state and the second power state, and the second update data being used to update a second software that does not operate in the first power state but operates in the second power state; a synthesizing unit that creates synthesized update data for installing a synthesized software based on the first update data and the second update data, the synthesized software including a first function as a function of the updated first software and a second function as a function of the updated second software; and a transmitting unit that transmits the synthesized update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthesized software in the recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state.

[0250] With such a configuration, the update management device creates synthesized update data based on two update data for updating two software, and transmits the update data for installation in the storage unit of the in-vehicle device and activation according to the power state of the vehicle to the in-vehicle device. Thereby, the software of the in-vehicle device is updated and is sequentially activated at appropriate times according to the power state, and the functions in which the software of a plurality of ECUs cooperate to operate operate in a coordinated manner.

[0251] The above update management device further includes: a determination unit that determines whether the power supply state of the vehicle is the first power supply state or the second power supply state; a first instruction unit that, when the determination unit determines that the power supply state of the vehicle is the first power supply state, sends a first activation instruction for activating the first function to the in-vehicle device; and a second instruction unit that, when the determination unit determines that the power supply state of the vehicle is the second power supply state, sends a second activation instruction for activating the second function to the in-vehicle device.

[0252] With such a configuration, according to the power supply state of the vehicle, the update management device activates the software of the in-vehicle device. Thus, according to the power supply state, the software of the in-vehicle device is updated and activated in due order at appropriate times, and the functions in which the software of multiple ECUs cooperate to operate operate in a coordinated manner.

[0253] [2.3 Functions of the update management device]

[0254] Figure 9 It is a functional block diagram showing the functions included in the update management ECU 11 according to the second embodiment. The update management ECU 11 includes a reception unit 91, a synthesis unit 92, a transmission unit 93, a determination unit 94, a first instruction unit 95, and a second instruction unit 96. A major difference from the first embodiment is the inclusion of the synthesis unit 92.

[0255] [2.3.1 Reception unit]

[0256] The reception unit 91 has the following functions: receiving first update data and second update data from an external device of the vehicle, where the first update data is used to update the first software that operates in the first power supply state and the second power supply state, and the second update data is used to update the second software that does not operate in the first power supply state but operates in the second power supply state.

[0257] Specifically, the reception unit 91 has the function of downloading the first update data and the second data from the server 2. The server 2 is, for example, set up in the data center of the vehicle manufacturer. In the server 2, for example, update data for updating the software of each ECU is stored. The first update data is update data for installing the door lock software as the +B software of the first ECU 12. The second update data is update data for installing the window software as the IG software of the first ECU 12.

[0258] The receiving unit 91 causes the control unit 22 to operate, accesses the server 2 via the internal bus 24, the transceiver 25a, the communication device 15, and the network 3, and downloads the updated data stored in the server 2. The start of the download is caused, for example, when updated data is newly recorded in the server 2. In this case, the server 2 sends information indicating that the updated data has been newly recorded to each update management system 1. The information indicating that the updated data has been newly recorded may include information indicating the version of the newly recorded updated data. For example, as an example of newly recording updated data in the server 2, consider a case where the window software of the first ECU 12 and the raindrop detection software of the second ECU 13 for implementing the rainy-day window closing system are updated because the rain sensitivity is improved compared to the conventional rain sensor.

[0259] The update management ECU 11 stores, for example, an ECU table as shown in Figure 5 in the storage unit 23. For example, this ECU table includes information indicating a specified system, the ECU and software that execute the specified system, the power state in which the software operates, and the version of the software of the ECU, and is recorded in the storage unit 23 in a table form for each specified system. As the specified system, for example, is the rainy-day window closing system. As shown in Figure 5 The ECU and software that execute this function are the window software of the door ECU and the raindrop detection software of the sensor ECU. The window software and the raindrop detection software are software that operate in the IG state. The version of the software is, for example, 1.02. In this example, the rainy-day window closing system is implemented by the IG drive software, so it operates as a whole in the IG state.

[0260] It should be noted that an example where the ECU table is stored in the storage unit 23 of the update management ECU 11 is described, but it is not limited thereto. For example, it may also be stored in the storage unit of the server 2.

[0261] Figure 6 is an ECU table of another example. In this example, as the specified system, for example, is the keyless entry system. The ECU and software that execute the specified system are, for example, the door lock software of the door ECU and the software of the ECU that cooperates therewith. Since the keyless entry system operates in the +B state, the software of each ECU also operates in the +B state.

[0262] The receiving unit 91 compares, for example, the version information included in the update software information sent from the server with the version information recorded in the ECU table to determine whether the software has been updated. In the case where it is determined that the software has been updated, the receiving unit 91 requests the updated data from the server 2 and downloads it. The receiving unit 91 temporarily records, for example, the downloaded updated data in the storage unit 23.

[0263] Note that the receiving unit 91 can also receive the first update data and the second update data from an external device during the power supply state being the first power supply state. For example, the update data for updating the door lock software as the +B software and the window software as the IG software can be downloaded during the +B state, that is, when the vehicle is in a non-drivable state, such as during parking. By downloading the update data during parking, it is possible to quickly start sending the update data and installing the IG software, etc. to the ECU that does not have the +B software installed but has the IG software installed at the timing when the power supply state transitions to the IG state.

[0264] [2.3.2 Composition Unit]

[0265] The composition unit 92 has the following function: Based on the above first update data and the above second update data, create composite update data for installing composite software, and the composite software includes a first function that is the function of the above first software after update and a second function that is the function of the above second software after update.

[0266] Specifically, the control unit 22 reads out the first update data and the second update data downloaded from the server 2, for example, from the temporarily stored storage unit 23. Then, the control unit 22 attaches specified information to the beginning and end of the data, and connects the first update data and the second update data to create composite update data for installing composite software. As the specified information, for example, it is information indicating the beginning of the data, information indicating the end of the data, and information indicating the destination ECU. In the composite update data, the part corresponding to the first update data includes the first function that is the function of the above first software after update, and the part corresponding to the second update data includes the second function that is the function of the above second software after update.

[0267] In Figure 5 and Figure 6 cases, regarding the first ECU 12, the window software as the IG software is listed in Figure 5 and the door lock software as the +B software is listed in Figure 6 . Therefore, the composition unit 92 creates composite update data including the functions of the window software and the door lock software based on the first update data for installing the door lock software and the second update data for installing the window software.

[0268] [2.3.3 Sending Unit]

[0269] The transmitting unit 93 has the following functions: transmitting the synthesized update data to the in-vehicle device, so that the in-vehicle device having a storage unit installs the synthesized software in the recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state.

[0270] Specifically, for example, the control unit 22 transmits the synthesized update data created by the synthesizing unit to the communication bus 14b via the transceiver 25b. The transmitted synthesized update data propagates in the communication bus 14b and reaches the transceiver 35 of the first ECU 12. The control unit 32 receives the synthesized update data that reaches the transceiver 35. The control unit 32 causes the first storage unit 33 or the RAM (not shown) to temporarily store the received synthesized update data.

[0271] In Figure 5 and Figure 6 cases, the transmitting unit 93 transmits the synthesized update data created from the first update data for installing the door lock software and the second update data for installing the window software to the door ECU.

[0272] It should be noted that when the first ECU 12 receives the synthesized update data, the first ECU 12 installs the synthesized software in the first storage unit 33 through the received synthesized update data. For example, it is configured to transmit the synthesized update data from the transmitting unit 93, and after the reception of the transmitted synthesized update data is completed, the control unit 32 of the first ECU 12 installs the synthesized software in the first storage unit 33 based on the temporarily stored synthesized update data. In Figure 5 and Figure 6 cases, the door ECU installs the door lock software and the window software in the first storage unit 33.

[0273] As another example, when the transmitting unit 93 transmits the synthesized update data, the update management ECU 11 transmits an installation instruction to the first ECU 12, and this installation instruction is an instruction to install the synthesized software in the first storage unit 33 through the synthesized update data. Then, it is configured that the first ECU 12 that receives the installation instruction installs the synthesized software.

[0274] [2.3.4 Determination Unit]

[0275] The determination unit 94 has the function of determining whether the power state of the vehicle is the first power state or the second power state.

[0276] Specifically, the determination unit 94 detects, for example, the power supply state of the vehicle and determines whether the detected power supply state is the +B state or the IG state. The detection of the power supply state of the vehicle can be performed by the update management ECU 11 or by a power supply monitoring ECU (not shown) that monitors the power supply state of the vehicle. Regarding the detection of the power supply state, in the case of the +B state, for example, the voltage of the power supply bus connected to the electrical equipment directly supplied with power by the vehicle battery is detected, and if it is equal to or higher than a specified voltage, it is determined to be the +B state. In the case of the IG state, for example, the voltage of the power supply bus that supplies power to the ECU that operates when the vehicle starts to move when the accelerator pedal is depressed, such as the engine control ECU, is detected, and if it is equal to or higher than a specified voltage, it is determined to be the IG state. It should be noted that when it is the +B state and the IG state, it is determined to be the IG state.

[0277] [2.3.5 First indication unit]

[0278] The first indication unit has the following function: when the power supply state of the vehicle is determined by the above determination unit to be the above first power supply state, it sends a first activation indication for activating the above first function to the above vehicle-mounted device.

[0279] Specifically, the first indication unit 95 refers to the ECU table stored in the storage unit 23, such as Figure 5 and Figure 6 the content shown. According to the referred ECU table, the first indication unit 95 obtains information indicating which software for the system operates in which power supply state. In the examples of Figure 5 and Figure 6 , the door lock software of the keyless entry system operates in both the +B state and the IG state. Therefore, when the power supply state is the +B state, the first indication unit 95 sends a first activation indication for activating the function of the door lock software of the updated composite software installed in the first storage unit 33 to the door ECU. For example, the first ECU 12 (first activation unit 32a) is configured to activate the first function of the composite software installed in the first storage unit 33 when receiving the first activation indication.

[0280] It should be noted that the first activation indication can also be sent to the vehicle-mounted device after the software is installed by the update data. This is because the software cannot be activated during installation. For example, the first indication unit 95 is configured to wait for transmission within a specified time. In other examples, the vehicle-mounted device is configured to send installation completion information, which is information indicating the completion of software installation, to the update management device after the installation of the software is completed. Then, it is configured that when receiving the installation completion information, the first indication unit 95 sends the first activation indication.

[0281] [2.3.6 Second Indicator Unit]

[0282] The second indicator unit 96 has the following function: when the power supply state of the vehicle is determined by the determination unit to be the second power supply state, it sends a second activation instruction for activating the second function to the in-vehicle device.

[0283] In Figure 5 and Figure 6 example, the second indicator unit 96 refers to the ECU table stored in the storage unit 23, Figure 5 and Figure 6 the content shown. According to the referred ECU table, the second indicator unit 96 obtains information indicating which software executes the system in which power supply state. In Figure 5 example, since the rainy-day window closing system is executed by the window software and the raindrop detection software that operate in the IG state, when the power supply state is the IG state, the second indicator unit 96 sends a second activation instruction for activating the function of the updated window software installed in the first storage unit 33 to the door ECU. In addition, the update management device may also send an activation instruction for activating the raindrop detection software to the sensor ECU. The first ECU 12 that receives the second activation instruction activates the function of the updated software. For example, the first ECU 12 (second activation unit 32b) is configured to activate the functions of the first software and the second software installed in the first storage unit 33 when receiving the second activation instruction.

[0284] It should be noted that for the second indicator unit, for the same reason as the first indicator unit, after installing the software by the update data, a second activation instruction may be sent to the in-vehicle device.

[0285] [2.4 Control Method]

[0286] Figure 10 is a flowchart showing an example of the control method executed by the update management ECU 11 according to Embodiment 2. Figure 10 The order of the steps shown can also be changed appropriately. Use Figure 10 to illustrate a series of control methods. It should be noted that the description starts from the state where the vehicle cannot run in the initial state. Therefore, in the initial state, the power supply state of the vehicle is the +B state.

[0287] It should be noted that the control executed by the update management ECU 11 is executed by the information processing unit 21. When the information processing unit 21 executes the control, the control unit 22 reads the computer program from the storage unit 23 and executes various operations and processes.

[0288] In addition, the control executed by the first ECU 12 is executed by the information processing unit 31. When the information processing unit 31 executes the control, the control unit 32 reads a computer program from the first storage unit 33 to execute various operations and processes.

[0289] [2.4.1 Step S301]

[0290] First, the receiving unit 91 of the update management ECU 11 receives first update data and second update data from an external device of the vehicle. The first update data is used to update the first software that operates in the first power state and the second power state, and the second update data is used to update the second software that does not operate in the first power state but operates in the second power state (step S301). Then, the update management ECU 11 proceeds to step S302.

[0291] Specifically, the receiving unit 91 downloads the first update data and the second data from the server 2. The server 2 is, for example, set up in the data center of the vehicle manufacturer. The server 2 stores, for example, update data for updating the software of each ECU. The first update data is update data for installing the door lock software as the +B software of the first ECU 12. The second update data is update data for installing the window software as the IG software of the first ECU 12.

[0292] The receiving unit 91 of the update management ECU 11 compares, for example, the update software information (including information indicating the version) sent from the server with the ECU table recorded in the storage unit 23 to determine whether the software has been updated. For example, the versions of the software are compared to determine whether it has been updated. When it is determined that the software has been updated, the receiving unit 91 requests the update data from the server 2 and downloads it. The receiving unit 91 temporarily records the downloaded update data in the storage unit 23, for example. After the download is completed, it proceeds to step S302.

[0293] [2.4.2 Step S302]

[0294] Next, the combining unit 92 of the update management ECU 11 creates combined update data for installing combined software based on the first update data and the second update data. The combined software includes a first function that is the function of the updated first software and a second function that is the function of the updated second software (step S302). Then, the update management ECU 11 proceeds to step S303.

[0295] Specifically, the control unit 22 reads out, from the storage unit 23 for temporary storage, for example, the first update data and the second update data downloaded from the server 2. Next, the control unit 22 attaches prescribed information to the beginning and the end of the data, and connects the first update data and the second update data to create synthetic update data for installing the synthetic software. As the prescribed information, for example, is information indicating the beginning of the data, information indicating the end of the data, and information indicating the destination ECU. In the synthetic software installed by the synthetic update data, the part corresponding to the first update data includes a first function that is the function of the first software after the update, and the part corresponding to the second update data includes a second function that is the function of the second software after the update. After creating the synthetic update data, the update management ECU 11 proceeds to step S303.

[0296] [2.4.3 Step S303]

[0297] Next, the transmission unit 93 of the update management ECU 11 transmits the synthetic update data to the in-vehicle device described above, so that the in-vehicle device having the storage unit installs the synthetic software in the recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state (step S303). Then, the update management ECU 11 proceeds to step S304.

[0298] Specifically, for example, the control unit 22 transmits the synthetic update data created by the synthesizing unit to the communication bus 14b via the transceiver 25b. The transmitted synthetic update data propagates in the communication bus 14b and reaches the transceiver 35 of the first ECU 12. The control unit 32 receives the synthetic update data that has reached the transceiver 35. The control unit 32 causes the first storage unit 33 or the RAM (not shown) to temporarily store the received synthetic update data.

[0299] In Figure 5 and Figure 6 cases, the transmission unit 93 transmits synthetic update data for installing synthetic software including the functions of the door lock software and the window software to the door ECU. Then, the update management ECU 11 proceeds to step S304.

[0300] It should be noted that when the first ECU 12 receives the synthetic update data, the first ECU 12 installs, via the received synthetic update data, synthetic software including the functions of the +B software and the IG software in the first storage unit 33. In Figure 5 and Figure 6 cases, the door ECU installs synthetic software including the functions of the door lock software and the window software in the first storage unit 33.

[0301] [2.4.4 Step S304]

[0302] Next, when the determination unit determines that the power state of the vehicle is the first power state, the first instruction unit 95 of the update management ECU 11 transmits a first activation instruction for activating the first function to the vehicle-mounted device (step S304 ). Then, the update management ECU 11 proceeds to step S305 .

[0303] Specifically, the first instruction unit 95 refers to the ECU table stored in the storage unit 23, for example Figure 5 and Figure 6 Based on the referenced ECU table, the first instruction unit 95 obtains information indicating the power state in which the system is executed by the software. Figure 5 and Figure 6 In the example of FIG. 1 , the function of the door lock software for executing the keyless entry system operates in both the +B state and the IG state, so when the power state is the +B state, the first instruction unit 95 sends a first activation instruction to the door ECU for activating the function of the door lock software of the updated composite software installed in the first storage unit 33. Then, the first ECU 12 that receives the first activation instruction activates the function of the first software of the composite software.

[0304] [2.4.5 Step S305]

[0305] Next, the determination unit 94 of the update management ECU 11 determines whether the power state of the vehicle is the first power state or the second power state (step S305). When the determination unit 94 determines that the power state of the vehicle is the second power state, i.e., the IG state, the update management ECU 11 proceeds to step S306. On the other hand, when the determination unit 94 determines that the power state of the vehicle is the first power state, i.e., the +B state, the update management ECU 11 returns to step S305 and repeats step S305. That is, the update management ECU 11 is in a state of waiting for the power state of the vehicle to transfer from the +B state to the IG state.

[0306] [2.4.6 Step S306]

[0307] Next, when the determination unit determines that the power state of the vehicle is the second power state, the second instruction unit 96 of the update management ECU 11 transmits a second activation instruction for activating the second function to the vehicle-mounted device (step S306 ). Then, the update management ECU 11 ends a series of processing.

[0308] exist Figure 5 and Figure 6 In the example of Figure 5 andFigure 6 The content shown. According to the ECU table referred to, the first indicating unit 96 obtains information indicating the execution of the functions of the software that operates in which power state for this system. In Figure 5 In the example of, since the rainy-day window closing system is executed by the functions of the window software and the raindrop detection software that operate in the IG state, when the power state is the IG state, the second indicating unit 96 sends a second activation instruction to the door ECU for activating the function of the window software of the updated composite software installed in the first storage unit 33. In addition, the update management device may also send an activation instruction for activating the function of the raindrop detection software to the sensor ECU. Then, the first ECU 12 that receives the second activation instruction activates the function of the second software of the installed composite software.

[0309] It should be noted that regarding the second indicating unit, for the same reason as the first indicating unit, after installing the software through the update data, a second activation instruction may be sent to the in-vehicle device.

[0310] [2.5 Control Sequence]

[0311] Next, the control sequence of the update management system 1 will be described. Figure 11 It is a sequence diagram of the update management system according to Embodiment 2. It should be noted that the description starts from the state where the vehicle cannot run as the initial state. Therefore, in the initial state, the power state of the vehicle is the +B state. After that, the power state transfers from the +B state to the IG state.

[0312] [2.5.1 Step S401]

[0313] First, the receiving unit 91 of the update management ECU 11 receives the first update data and the second update data from the external device of the vehicle. The first update data is used to update the first software that operates in the first power state and the second power state, and the second update data is used to update the second software that does not operate in the first power state but operates in the second power state (Step S401). Then, the update management system 1 proceeds to Step S402.

[0314] Specifically, the receiving unit 91 downloads the first update data and the second data from the server 2. The server 2 is, for example, set up in the data center of the vehicle manufacturer. The server 2 stores, for example, the update data for updating the software of each ECU. The first update data is the update data for installing the door lock software as the +B software of the first ECU 12. The second update data is the update data for installing the window software as the IG software of the first ECU 12. After the download is completed, it proceeds to Step S402.

[0315] [2.5.2 Step S402]

[0316] Next, the synthesis unit 92 of the update management ECU 11 creates synthesis update data for installing the synthesis software based on the above first update data and the above second update data. The synthesis software includes a first function that is the function of the above first software after update and a second function that is the function of the above second software after update (step S402). Then, the update management system 1 proceeds to step S403.

[0317] Specifically, the control unit 22 reads out, for example, the first update data and the second update data downloaded from the server 2 from the temporarily stored storage unit 23. Next, the control unit 22 attaches prescribed information to the beginning and end of the data, and connects the first update data and the second update data to create synthesis update data for installing the synthesis software. As the prescribed information, for example, is information indicating the beginning of the data, information indicating the end of the data, and information indicating the destination ECU. In the synthesis software installed through the synthesis update data, the part corresponding to the first update data includes the first function that is the function of the above first software after update, and the part corresponding to the second update data includes the second function that is the function of the above second software after update. After creating the synthesis update data, the update management system 1 proceeds to step 403.

[0318] [2.5.3 Step S403]

[0319] Next, the transmission unit 93 of the update management ECU 11 transmits the above synthesis update data to the above vehicle-mounted device, so that the vehicle-mounted device having a storage unit installs the above synthesis software in the above recording unit, activates the above first function when the power state of the above vehicle is the above first power state, and activates the above second function when the power state of the above vehicle is the above second power state (step S403). Then, the update management system 1 proceeds to step S404.

[0320] In Figure 5 and Figure 6 cases, the transmission unit 93 transmits synthesis update data created based on the second update data for installing the synthesis software including the functions of the door lock software and the window software to the door ECU. Then, the update management system 1 proceeds to step S404.

[0321] [2.5.4 Step S404]

[0322] Next, when the first ECU 12 receives the synthesis update data, the first ECU 12 installs the synthesis software including the functions of the +B software and the IG software in the first storage unit 33 through the received synthesis update data (step S404). In Figure 5 and Figure 6In this case, the door ECU installs the combined software including the functions of the door lock software and the window software in the first storage unit 33. After the software is installed in the first ECU 12, the update management system 1 proceeds to step S405.

[0323] [2.5.5 Step S405]

[0324] Next, when the first instruction unit 95 of the update management ECU 11 determines that the power supply state of the vehicle is the first power supply state by the above determination unit, it sends a first activation instruction for activating the first function to the in-vehicle device (step S405). Then, the update management system 1 proceeds to step S406.

[0325] Specifically, the first instruction unit 95 refers to the ECU table stored in the storage unit 23, for example Figure 5 and Figure 6 the content shown. According to the referred ECU table, the first instruction unit 95 obtains information indicating which software in which power supply state executes the system. In the examples of Figure 5 and Figure 6 , the function of the door lock software for the keyless entry system operates in both the +B state and the IG state. Therefore, when the power supply state is the +B state, the first instruction unit 95 sends a first activation instruction to the door ECU for activating the function of the door lock software of the updated combined software installed in the first storage unit 33. After sending, the update management system 1 proceeds to step S406.

[0326] [2.5.6 Step S406]

[0327] Next, the first ECU 12 that receives the first activation instruction activates the function of the first software (step S406). In the examples of Figure 5 and Figure 6 , the function of the door lock software for the keyless entry system is the function of the +B software that operates in both the +B state and the IG state. Therefore, the first ECU 12 activates the function of the door lock software of the updated combined software installed in the first storage unit 33. Then, the update management system 1 proceeds to step S407.

[0328] [2.5.7 Step S407]

[0329] Next, the determination unit 94 of the update management ECU 11 determines whether the power supply state of the vehicle is the first power supply state or the second power supply state (step S407). When the determination unit 94 determines that the power supply state of the vehicle is the second power supply state, i.e., the IG state, the update management ECU 11 proceeds to step S408. On the other hand, when the determination unit 94 determines that the power supply state of the vehicle is the first power supply state, i.e., the +B state, the update management ECU 11 returns to step S407 and repeats step S408. That is, the update management ECU 11 waits for the power supply state of the vehicle to transfer from the +B state to the IG state.

[0330] [2.5.8 Step S408]

[0331] Next, when the determination unit determines that the power supply state of the vehicle is the second power supply state, the second instruction unit 96 of the update management ECU 11 sends a second activation instruction for activating the second function to the in-vehicle device (step S408). Then, the update management system 1 proceeds to step S409.

[0332] In Figure 5 and Figure 6 example, the second instruction unit 96 refers to the ECU table stored in the storage unit 23, Figure 5 and Figure 6 the content shown. According to the referenced ECU table, the first instruction unit 96 obtains information indicating which software function the system executes in which power supply state. In Figure 5 example, since the rainy-day window closing system is executed by the window software function and the raindrop detection software function that operate in the IG state, when the power supply state is the IG state, the second instruction unit 96 sends a second activation instruction for activating the window software function of the updated composite software installed in the first storage unit 33 to the door ECU. In addition, the update management device can also send an activation instruction for activating the raindrop detection software to the sensor ECU.

[0333] [2.5.9 Step S409]

[0334] Next, the first ECU 12 that receives the second activation instruction activates the function of the updated software (step S409). In Figure 5 and Figure 6 cases, the first ECU 12 activates the function of the window software installed in the first storage unit 33. In addition, when an activation instruction is sent to the second ECU 13, the second ECU 13 activates the function of the installed raindrop detection software. Then, the update management system 1 ends a series of processes.

[0335] [2.6 Summary]

[0336] There is known a vehicle having a plurality of power states including a +B state, an IG state, etc. and equipped with a plurality of ECUs. In such a vehicle, when the software of the ECU is updated, multiple softwares that cooperate to execute a prescribed system may be activated in different power states, and a command issued by one software may not be understood by another software, and the prescribed system may not operate.

[0337] According to the present embodiment, the update management device creates composite update data in advance based on a plurality of update data, and the update management device sends update data for installing and activating software in the storage unit of the in-vehicle device to the in-vehicle device. Then, the update management device installs the software in the in-vehicle device by the update data. Then, the update management device activates the installed software according to the power state of the vehicle. Thus, the software of the in-vehicle device is sequentially updated and activated at an appropriate timing according to the power state, and the functions in which the softwares of the plurality of ECUs cooperate to operate operate in a coordinated manner.

[0338] Alternatively, it may be that the +B software and the IG software are installed in the first ECU, the IG software is installed in the second ECU, and when the IG software of the first ECU and the IG software of the second ECU cooperate to execute a prescribed system, an activation instruction for instructing activation is simultaneously sent to the IG software of the first ECU and the IG software of the second ECU. The IG software of the first ECU and the IG software of the second ECU are clearly activated simultaneously, further suppressing the incoordination in which the IG software of the second ECU cannot understand the command issued by the IG software of the first ECU.

[0339] [3.1 Appendix 1]

[0340] It should be noted that the present disclosure includes the following control method for the update management device.

[0341] A control method for an update management device, the update management device managing an update of software of an in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state, wherein the method includes: a receiving step of receiving first update data and second update data from an external device of the vehicle, the first update data being for updating first software that operates in the first power state and the second power state, and the second update data being for updating second software that does not operate in the first power state but operates in the second power state; a determining step of determining whether the power state of the vehicle is the first power state or the second power state; a first sending step of, when it is determined by the determining step that the power state of the vehicle is the first power state, sending the first update data to the in-vehicle device so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; and a second sending step of, when it is determined by the determining unit that the power state of the vehicle is the second power state, sending the first update data and the second update data to the in-vehicle device so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software.

[0342] [3.2 Appendix 2]

[0343] It should be noted that the present disclosure includes the following control method for an update management device.

[0344] The control method for the update management device described in Appendix 1 further includes: a first activation instruction step of, when it is determined by the determining step that the power state of the vehicle is the first power state, sending a first activation instruction to the in-vehicle device, the first activation instruction being for activating the updated first software installed in the first storage unit; and a second activation instruction step of, when it is determined by the determining step that the power state of the vehicle is the second power state, sending a second activation instruction to the in-vehicle device, the second activation instruction being for activating the updated first software and the updated second software installed in the second storage unit.

[0345] [3.3 Appendix 3]

[0346] It should be noted that the present disclosure includes the following control method for an update management system.

[0347] A control method for an update management system, the update management system comprising an update management device and a vehicle-mounted device, the update management device managing the update of software of the vehicle-mounted device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state, wherein the following are executed by the update management device: a receiving step of receiving first update data and second update data from an external device of the vehicle, the first update data being for updating a first software that operates in the first power state and the second power state, and the second update data being for updating a second software that does not operate in the first power state but operates in the second power state; a determining step of determining whether the power state of the vehicle is the first power state or the second power state; a first sending step of, when it is determined by the determining step that the power state of the vehicle is the first power state, sending the first update data to the vehicle-mounted device so that the vehicle-mounted device having a first storage unit and a second storage unit installs the updated first software in the first storage unit and activates the updated first software; a second sending step of, when it is determined by the determining step that the power state of the vehicle is the second power state, sending the first update data and the second update data to the vehicle-mounted device so that the vehicle-mounted device installs the updated first software and the updated second software in the second storage unit and activates the updated first software and the updated second software; a first activation instruction step of, when it is determined by the determining step that the power state of the vehicle is the first power state, sending a first activation instruction to the vehicle-mounted device, the first activation instruction being for activating the updated first software installed in the first storage unit; and a second activation instruction step of, when it is determined by the determining step that the power state of the vehicle is the second power state, sending a second activation instruction to the vehicle-mounted device, the second activation instruction being for activating the updated first software and the updated second software installed in the second storage unit, and the following are executed by the vehicle-mounted device: a first activation step of, when the first activation instruction is received, activating the updated first software installed in the first storage unit; and a second activation step of, when the second activation instruction is received, activating the updated first software and the updated second software installed in the second storage unit.

[0348] [3.4 Appendix 4]

[0349] It should be noted that the present disclosure includes the following control method for the update management system.

[0350] A control method for an update management system, the update management system comprising an update management device and an in-vehicle device, the update management device managing an update of software of the in-vehicle device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state, wherein the method includes: a receiving step in which the update management device receives first update data and second update data from an external device of the vehicle, the first update data being for updating first software that operates in the first power state and the second power state, and the second update data being for updating second software that does not operate in the first power state but operates in the second power state; a determining step in which the update management device determines whether the power state of the vehicle is the first power state or the second power state; a first sending step in which, when it is determined in the determining step that the power state of the vehicle is the first power state, the update management device sends the first update data to the in-vehicle device so that the in-vehicle device having a first storage unit and a second storage unit installs the updated first software in the first storage unit; a second sending step in which, when it is determined in the determining step that the power state of the vehicle is the second power state, the update management device sends the first update data and the second update data to the in-vehicle device so that the in-vehicle device installs the updated first software and the updated second software in the second storage unit; a first activation step in which the in-vehicle device activates the updated first software installed in the first storage unit by the first update data sent in the first sending step; and a second activation step in which the in-vehicle device activates the updated first software and the updated second software installed in the second storage unit by the first update data and the second update data sent in the second sending step.

[0351] [3.5 Appendix 5]

[0352] It should be noted that the present disclosure includes the following control method for the update management device.

[0353] A control method for an update management device, where the update management device manages the update of software of an in-vehicle device in a vehicle having multiple power states including a first power state and a second power state different from the first power state. The method includes: a receiving step of receiving first update data and second update data from an external device of the vehicle, where the first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state; a synthesizing step of creating synthesized update data for installing a synthesized software according to the first update data and the second update data, where the synthesized software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; and a sending step of sending the synthesized update data to the in-vehicle device, so that the in-vehicle device having a storage unit installs the synthesized software in a recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state;

[0354] [3.6 Appendix 6]

[0355] It should be noted that the present disclosure includes the following control method for the update management device.

[0356] The control method for the update management device described in Appendix 4 further includes: a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first activation instruction step of sending a first activation instruction for activating the first function to the in-vehicle device when it is determined by the determination step that the power state of the vehicle is the first power state; and a second activation instruction step of sending a second activation instruction for activating the second function to the in-vehicle device when it is determined by the determination step that the power state of the vehicle is the second power state.

[0357] [3.7 Appendix 7]

[0358] It should be noted that the present disclosure includes the following control method for the update management system.

[0359] A control method for an update management system, the update management system comprising an update management device and a vehicle-mounted device, the update management device managing the update of software of the vehicle-mounted device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state, wherein the following are executed by the update management device: a reception step of receiving first update data and second update data from an external device of the vehicle, the first update data being for updating a first software that operates in the first power state and the second power state, and the second update data being for updating a second software that does not operate in the first power state but operates in the second power state; a synthesis step of creating synthesis update data for installing a synthesis software according to the first update data and the second update data, the synthesis software including a first function that is a function of the updated first software and a second function that is a function of the updated second software; a transmission step of transmitting the synthesis update data to the vehicle-mounted device so that the vehicle-mounted device having a storage unit installs the synthesis software in the recording unit, and activates the first function when the power state of the vehicle is the first power state and activates the second function when the power state of the vehicle is the second power state; a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first activation instruction step of transmitting a first activation instruction for activating the first function to the vehicle-mounted device when it is determined by the determination step that the power state of the vehicle is the first power state; and a second activation instruction step of transmitting a second activation instruction for activating the second function to the vehicle-mounted device when it is determined by the determination unit that the power state of the vehicle is the second power state, and the following are executed by the vehicle-mounted device: a first activation step of activating the first function when the first activation instruction is received; and a second activation step of activating the second function when the second activation instruction is received.

[0360] [3.8 Appendix 8]

[0361] It should be noted that the present disclosure includes the following control method for an update management system.

[0362] A control method for an update management system, the update management system including an update management device and a vehicle-mounted device, the update management device managing the update of the software of the vehicle-mounted device in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state, the method including: a receiving step, in which the update management device receives first update data and second update data from an external device of the vehicle, the first update data being used to update a first software that operates in the first power state and the second power state, and the second update data being used to update a second software that does not operate in the first power state but operates in the second power state; a synthesizing step, in which the update management device creates synthesized update data for installing a synthesized software according to the first update data and the second update data, the synthesized software including a first function that is a function of the updated first software and a second function that is a function of the updated second software; a sending step, in which the update management device sends the synthesized update data to the vehicle-mounted device so that the vehicle-mounted device having a storage unit installs the synthesized software in a recording unit; a first activation step, in which when the power state of the vehicle is the first power state, the vehicle-mounted device activates the first function of the synthesized software installed in the recording unit; and a second activation step, in which when the power state of the vehicle is the second power state, the vehicle-mounted device activates the second function of the synthesized software installed in the recording unit.

[0363] [3.9 Appendix 9]

[0364] It should be noted that, regarding the above-described embodiments and various modification examples, at least a part of them can be arbitrarily combined with each other. In addition, the embodiments and modification examples disclosed this time should be considered illustrative in all aspects and not restrictive. The scope of the present disclosure is shown by the scope of the claims, and is intended to include all changes within the meaning and scope equivalent to the scope of the claims.

[0365] Reference numeral description

[0366] 1 Update management system;

[0367] 2 Server;

[0368] 3 Network;

[0369] 11 Update management ECU;

[0370] 12 First ECU;

[0371] 13 Second ECU;

[0372] 14a Communication bus;

[0373] 14b Communication bus;

[0374] 15 Communication device;

[0375] 21 Information processing unit;

[0376] 22 Control unit;

[0377] 23 Storage unit;

[0378] 24 Internal bus;

[0379] 25a Transceiver;

[0380] 25b Transceiver;

[0381] 31 Information processing unit;

[0382] 32 Control unit;

[0383] 33 First storage unit;

[0384] 34 Second storage unit;

[0385] 35 Transceiver;

[0386] 36 Input unit;

[0387] 37 Output unit;

[0388] 38 Internal bus;

[0389] 41 Receiver;

[0390] 42 Judgment unit;

[0391] 43 First transmitter;

[0392] 44 Second transmitter;

[0393] 45 First indicator;

[0394] 46 Second indicator;

[0395] 47 First deletion indicator;

[0396] 48 Second deletion indicator;

[0397] 91 Receiver;

[0398] 92 Synthesis unit;

[0399] 93 Transmitter;

[0400] 94 Judgment unit;

[0401] 95 First indicator;

[0402] 96 Second indicator.

Claims

1. An update management device manages the update of software of in-vehicle devices in a vehicle having a plurality of power states including a first power state and a second power state different from the first power state. Wherein, The update management device includes: A receiving unit that receives first update data and second update data from an external device of the vehicle. The first update data is used to update a first software that operates in the first power state and the second power state, and the second update data is used to update a second software that does not operate in the first power state but operates in the second power state. A synthesizing unit that creates synthesized update data for installing a synthesized software based on the first update data and the second update data. The synthesized software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software. And A transmitting unit that transmits the synthesized update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthesized software in the recording unit, activates the first function when the power state of the vehicle is the first power state, and activates the second function when the power state of the vehicle is the second power state.

2. The update management device according to claim 1, Wherein, The update management device further includes: A determination unit that determines whether the power state of the vehicle is the first power state or the second power state. A first instruction unit that, when the determination unit determines that the power state of the vehicle is the first power state, transmits a first activation instruction for activating the first function to the in-vehicle device. And A second instruction unit that, when the determination unit determines that the power state of the vehicle is the second power state, transmits a second activation instruction for activating the second function to the in-vehicle device.

3. The update management device according to claim 2, Wherein, When the determination unit determines that the power state of the vehicle is the first power state, it stores information indicating that the power state of the vehicle is the first power state in a state storage unit that stores information indicating the power state. When the determination unit determines that the power state of the vehicle is the second power state, it stores information indicating the second power state in the state storage unit. The first instruction unit refers to the state storage unit and transmits the first activation instruction to the in-vehicle device when information indicating the first power state is stored. The second instruction unit refers to the state storage unit and transmits the second activation instruction to the in-vehicle device when information indicating the second power state is stored.

4. The update management device according to claim 1, Wherein, The first power state is the power state when the vehicle is in a non-drivable state, and the second power state is the power state when the vehicle is in a drivable state.

5. The update management device according to claim 1, Wherein, During the period when the power supply state is the first power supply state, the receiving unit receives the first update data and the second update data from the external device.

6. An update management system, comprising: The update management device according to any one of claims 1 to 5; and The in-vehicle device.

7. An update management system, comprising an update management device and an in-vehicle device, wherein the update management device manages the update of the software of the in-vehicle device in a vehicle having a plurality of power supply states including a first power supply state and a second power supply state different from the first power supply state, wherein, The update management device includes: A receiving unit that receives first update data and second update data from an external device of the vehicle. The first update data is used to update a first software that operates in the first power supply state and the second power supply state, and the second update data is used to update a second software that does not operate in the first power supply state but operates in the second power supply state; A synthesizing unit that creates synthesized update data for installing a synthesized software according to the first update data and the second update data. The synthesized software includes a first function that is a function of the updated first software and a second function that is a function of the updated second software; A transmitting unit that transmits the synthesized update data to the in-vehicle device, so that the in-vehicle device having a storage unit installs the synthesized software in the recording unit, activates the first function when the power supply state of the vehicle is the first power supply state, and activates the second function when the power supply state of the vehicle is the second power supply state; A determination unit that determines whether the power supply state of the vehicle is the first power supply state or the second power supply state; A first instruction unit that, when the determination unit determines that the power supply state of the vehicle is the first power supply state, transmits a first activation instruction for activating the first function to the in-vehicle device; and A second instruction unit that, when the determination unit determines that the power supply state of the vehicle is the second power supply state, transmits a second activation instruction for activating the second function to the in-vehicle device, The in-vehicle device includes: A first activation unit that activates the first function when receiving the first activation instruction; and A second activation unit that activates the second function when receiving the second activation instruction.

8. The update management system according to claim 7, wherein, When the determination unit determines that the power supply state of the vehicle is the first power supply state, it stores information indicating that the power supply state of the vehicle is the first power supply state in a state storage unit that stores information indicating the power supply state, When the determination unit determines that the power supply state of the vehicle is the second power supply state, it stores information indicating the second power supply state in the state storage unit, The first instruction unit refers to the state storage unit and transmits the first activation instruction to the in-vehicle device when information indicating the first power supply state is stored, When the second indicating unit refers to the state storage unit and there is information indicating the second power supply state stored therein, the second activation instruction is sent to the in-vehicle device.

9. A computer program for controlling an update management device, the update management device managing an update of software of an in-vehicle device in a vehicle having a plurality of power supply states including a first power supply state and a second power supply state different from the first power supply state. Wherein, It includes: A receiving step of receiving first update data and second update data from an external device of the vehicle, the first update data being used to update first software that operates in the first power supply state and the second power supply state, and the second update data being used to update second software that does not operate in the first power supply state but operates in the second power supply state; A synthesizing step of creating synthesized update data for installing synthesized software according to the first update data and the second update data, the synthesized software including a first function as a function of the updated first software and a second function as a function of the updated second software; And A sending step of sending the synthesized update data to the in-vehicle device so that the in-vehicle device having a storage unit installs the synthesized software in the recording unit, activates the first function when the power supply state of the vehicle is the first power supply state, and activates the second function when the power supply state of the vehicle is the second power supply state.

Citation Information

Patent Citations

  • Master device for vehicle, and method and program for determining instruction to install

    JP2020027629A

  • Optical analyzing device

    JP2022185655A