Server, distribution method, and non-temporary storage medium
By establishing the association between the communication module and the portable terminal in the server, the software update problem when the vehicle cannot communicate is solved, and the update data distribution of the electronic control unit is realized to ensure the implementation of functions and new functions.
Patent Information
- Application Number
- CN202510667150.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-06
- Filing Date
- 2021-08-25
- Publication Date
- 2025-08-12
AI Technical Summary
In the event that the vehicle cannot communicate with the server, the prior art cannot effectively update the software of the electronic control unit, resulting in limited functionality improvements and additional new functions.
The server establishes the association between the communication module on the vehicle and the portable terminal through the storage device identification information, judges the communication status, and sends the update data to the associated portable terminal when it is unable to communicate with the update control device to realize software update.
When the vehicle and the server communication is interrupted, the software update of the electronic control unit can still be completed to ensure the improvement of functions and the addition of new functions.
Smart Images

Figure CN120469705A_ABST
Abstract
Description
Divisional application statement This application is a divisional application of the Chinese invention patent application filed on August 25, 2021, with the invention name “Server, software update system, distribution method and non-temporary storage medium” and application number 202110982572.4. Technical Field
[0001] The present invention relates to a server, a software updating system, a distribution method and a non-temporary storage medium. Background Art
[0002] Vehicles are equipped with multiple electronic control units (ECUs) to control their operation. An ECU consists of a processor, temporary storage such as RAM, and non-volatile storage such as flash ROM. The processor executes software stored in the non-volatile storage to implement the ECU's control functions. The software stored in each ECU can be rewritten, and by updating to a newer version, the functionality of each ECU can be improved and new vehicle control functions can be added.
[0003] An example of a related technology for updating ECU software is OTA (Over The Air) technology, in which an on-vehicle communication device connected to the on-vehicle network is wirelessly connected to a communication network such as the Internet, software is downloaded from a server via wireless communication, and the downloaded software is installed to implement ECU program updates and additions (for example, refer to Japanese Patent Application Laid-Open No. 2018-181377).
[0004] OTA software updates can be initiated when the vehicle's IG-ON or power-on is activated, and an update control device mounted on the vehicle transmits version information (update confirmation) of the program on the vehicle's onboard device to a server via the vehicle's onboard communication equipment (see, for example, Japanese Patent Application Laid-Open No. 2018-181377). When the update control device downloads update data from the server, it displays it on a display device within the vehicle, notifying the user of the update data. Upon user approval via an input device such as a button, the update data is installed and activated. Summary of the Invention
[0005] Consider a scenario where the vehicle's communication module is unable to communicate with the server due to radio wave conditions, a malfunction, or other reasons. Alternatively, the vehicle may not be equipped with the communication module itself, depending on the vehicle's model or intended use. In these cases, the ECU program cannot be updated via OTA, leaving room for improvement.
[0006] The present invention provides a server, a software updating system, a distribution method and a non-temporary storage medium capable of updating the software of an electronic control unit even when the server and a vehicle cannot communicate.
[0007] In a first embodiment of the present invention, a server is configured to distribute update data of software of an electronic control unit mounted on a vehicle, and the server comprises: a first storage unit for storing device identification information, in which information for identifying a communication module mounted on the vehicle is associated with information for identifying a portable terminal, and the portable terminal is configured to communicate with an update control device mounted on the vehicle; a second storage unit for storing the update data; a judgment unit for judging whether communication with the update control device is possible; and a communication unit for sending the update data to the update control device via the communication module when a request is made from the update control device via the communication module, and sending the update data to the portable terminal associated with the communication module when the judgment unit judges that communication with the update control device is not possible.
[0008] A software update system according to a second embodiment of the present invention is configured to update software of an electronic control unit mounted on a vehicle, the software update system comprising: an update control device mounted on the vehicle and configured to control software updates of the electronic control unit; a server configured to distribute update data for the electronic control unit software; a portable terminal configured to communicate with the update control device and the server; the server comprising: a first storage unit storing device identification information, wherein the device identification information associates information identifying a communication module mounted on the vehicle with information identifying the portable terminal; a second storage unit storing the update data; a determination unit configured to determine whether communication with the update control device is possible; and a communication unit configured to, when a request for transmission of the update data is received from the update control device via the communication module, transmit the update data to the update control device via the communication module, and, when the determination unit determines that communication with the update control device is not possible, transmit the update data to the portable terminal associated with the communication module.
[0009] A third-party distribution method of the present invention distributes update data of software of an electronic control unit mounted on a vehicle by a computer, the computer having a processor, a memory and a storage device, the distribution method comprising: storing device identification information, in which information for determining a communication module mounted on the vehicle is associated with information for determining a portable terminal, and the portable terminal is capable of communicating with an update control device mounted on the vehicle; a step of storing the update data; a step of the computer determining whether it is capable of communicating with the update control device; a step of sending the update data to the update control device via the communication module when a request is made from the update control device to send the update data via the communication module; and sending the update data to the portable terminal associated with the update control device when it is determined that communication with the update control device is not possible.
[0010] A non-transitory storage medium according to a fourth aspect of the present invention stores a distribution program executable by a computer for causing the computer to execute the distribution method according to the third aspect. The computer includes a processor, a memory, and the non-transitory storage medium.
[0011] According to the present invention, a server, a software updating system, a distribution method, and a non-transitory storage medium are provided for updating software of an electronic control unit even when the server and a vehicle cannot communicate. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Hereinafter, features, advantages, and technical and industrial significance of exemplary embodiments of the present invention will be described with reference to the accompanying drawings, wherein like numerals denote like elements. Figure 1 This is a block diagram showing the overall configuration of a network system according to an embodiment. Figure 2 Yes Figure 1 A block diagram of the schematic structure of the server is shown. Figure 3 Yes Figure 1 FIG. 1 is a block diagram showing a schematic structure of a software updating device. Figure 4 Yes Figure 1 A block diagram showing the schematic structure of a portable terminal is shown. Figure 5 This is a functional block diagram of the server according to the first embodiment. Figure 6 This is a diagram showing an example of device identification information stored in a server. Figure 7 This is a diagram showing an example of update management information stored in the server. Figure 8This is a functional block diagram of the software updating device according to the first embodiment. Figure 9 This is a functional block diagram of the portable terminal according to the first embodiment. Figure 10 This is a flowchart showing an example of control processing executed by the server according to the first embodiment. Figure 11 This is a flowchart showing an example of update data distribution processing executed by the server according to the first embodiment. Figure 12 This is a flowchart showing an example of software update processing executed by the software update device. Figure 13 This is a sequence diagram showing another example of the software update process executed by the software update device. Figure 14 This is a diagram showing an example of device identification information stored in the server according to the second embodiment. Figure 15 This is a flowchart showing an example of control processing performed by the server according to the second embodiment. DETAILED DESCRIPTION
[0013] (Common Structure between the First and Second Embodiments) Figure 1 is a block diagram showing the overall structure of a network system according to an embodiment of the present invention. Figure 2 Yes Figure 1 The block diagram of the server schematic structure shown in FIG. Figure 3 Yes Figure 1 The schematic block diagram of the software updating device shown in FIG. Figure 4 Yes Figure 1 A block diagram showing the schematic structure of a portable terminal is shown.
[0014] Figure 1 The network system shown is a system for updating software of electronic control units 13a to 13d mounted on a vehicle, and includes a server 1 (center) and an in-vehicle network 2 mounted on the vehicle.
[0015] The server 1 can communicate with a software update device 11 mounted on the vehicle via the network 5 , and manages software updates of the electronic control units 13 a to 13 d mounted on the vehicle.
[0016] like Figure 2As shown, server 1 includes a CPU 21, RAM 22, a storage device 23, and a communication device 24. The storage device 23 comprises a readable and writable storage medium such as a hard disk or SSD, and stores programs for managing software updates, information used for update management, and update data for the electronic control unit. In server 1, CPU 21 executes programs read from storage device 23 using RAM 22 as a work area, thereby performing the control processing described below. The communication device 24 communicates with the software update device 11 via a network.
[0017] The in-vehicle network 2 includes a software update device 11 (OTA host), a communication module 12, multiple electronic control units 13a to 13d, and a display device 14. The software update device 11 is connected to the communication module 12 via a bus 15a, to the electronic control units 13a and 13b via a bus 15b, to the electronic control units 13c and 13d via a bus 15c, and to the display device 14 via a bus 15d. The software update device 11 can wirelessly communicate with the server 1 via the communication module 12. Furthermore, the software update device 11 can wirelessly communicate with portable terminals 3 such as smartphones and electronic keys. Based on update data distributed from the server 1, the software update device 11 controls the software update of the target electronic control units (target ECUs) among the electronic control units 13a to 13d whose software is to be updated. The software update device 11 is sometimes also referred to as a central gateway. The communication module 12 is a communication device that connects the in-vehicle network 2 and the server 1. The electronic control units 13a to 13d control the operation of various components of the vehicle. The display device 14 (HMI) is used to implement various displays such as display of the existence of update data, display of an approval request screen for requesting approval of software update from the user or administrator, and display of update results when the software of the electronic control units 13a to 13d is updated. As the display device 14, a display device of a car navigation system can typically be used, but it is not particularly limited as long as it can display the information required for the program update process. In addition, Figure 1 In the embodiment, four electronic control units 13a to 13d are shown, but the number of electronic control units is not particularly limited. Figure 1 Electronic control units other than the display device 14 may also be connected to the bus 15 d shown.
[0018] The electronic control units 13a to 13d include a CPU, RAM, non-volatile memory (storage), and a communication device. The CPU uses the RAM as a workspace to execute software (programs) read from the non-volatile memory, thereby realizing the functions of each electronic control unit. The electronic control units include those with a single data storage area (library) for storing software and those with two data storage areas (libraries) for storing software. In addition to the software used to realize the functions of the electronic control unit, the data storage areas of the electronic control units sometimes store version information, parameter data, boot programs for startup, and programs for software updates. In an electronic control unit with a single data storage area, installing update data in the data storage area affects the software in the electronic control unit. On the other hand, in an electronic unit with two data storage areas, one of the two data storage areas is designated as the storage area (operation surface) to be read, and the software stored in the storage area to be read is executed. In the other storage area (non-operation surface) that is not the storage area to be read, update data can be written in the background while the program in the storage area (operation surface) to be read is being executed. When activating the software update process, the updated version of the software can be made effective by switching the storage area to which the program is to be read by the CPU.
[0019] In addition, in the present invention, the electronic control unit having two data storage areas includes an electronic control unit having a memory with a structure called "single-sided suspended memory", which virtually divides the data storage area on one side of the non-volatile memory into two sides, and can write a program on the other side while executing a program on one side; in addition to the non-volatile memory having a data storage area on one side, the electronic control unit also has an extended non-volatile memory having a data storage area on one side, and can use these two non-volatile memories as an operating surface and a non-operating surface.
[0020] like Figure 3 As shown, the software update device 11 includes a CPU 31, a RAM 32, a ROM 33, a storage device 34, and communication devices 35 and 36. In the software update device 11, the CPU 31 executes the program read from the ROM 33 or the storage device 34 using the RAM 32 as a work area, thereby performing the control process described later. The communication device 35 is connected to the CPU 31 via the communication device 36. Figure 1 The buses 15a to 15d shown are devices that communicate with the communication module 12, the electronic control units 13a to 13d, and the display device 14. Furthermore, the communication device 36 is a device that wirelessly communicates with the portable terminal 3 and can communicate using, for example, BLE (Bluetooth (registered trademark) Low Energy), Wi-Fi (registered trademark), RF-LF communication, or other communication methods.
[0021] Here, the software update process consists of a stage of downloading update data, a stage of transmitting the downloaded update data to the electronic control unit of the update object and installing the update data in the storage area of the electronic control unit of the update object, and a stage of activating the installed updated version of the software in the electronic control unit of the update object to make it effective.
[0022] Regarding downloading, it is the process of receiving and storing update data for updating the software of the electronic control unit from the server 1. In the downloading stage, it includes not only the reception of the update data, but also the control of a series of processes related to the download, such as whether the download can be executed, the verification of the update data, etc. Regarding installation, it is the process of writing the updated version of the program (update software) into the storage unit of the vehicle-mounted device of the electronic control unit to be updated based on the downloaded update data. In the installation stage, it includes not only the execution of the installation, but also the control of a series of processes related to the installation, such as whether the installation can be executed, the transmission of the update data, and the verification of the updated version of the program. Activation is the process of validating (activating) the installed updated version of the program. The control of activation includes not only the execution of activation, but also the control of a series of processes related to the activation, such as whether the activation can be executed, the verification of the execution result, etc.
[0023] The update data may include any of the following: update software for the electronic control unit, compressed data containing the update software, or segmented data containing segmented update software or compressed data. Furthermore, the update data may include an identifier (ECUID) for identifying the electronic control unit to be updated and an identifier (ECU software ID) for identifying the software before the update. The update data is downloaded as the aforementioned distribution package, but the distribution package contains update data for one or more electronic control units.
[0024] If the update data includes the update software itself, the software update device transmits the update data (update software) to the target electronic control unit during the installation phase. Alternatively, if the update data includes compressed data, differential data, or segmented data of the update software, the software update device 11 may transmit the update data to the target electronic control unit, and the target electronic control unit may generate the update software based on the update data. Alternatively, the software update device 11 may generate the update software based on the update data and then transmit the update software to the target electronic control unit. Generation of the update software can be achieved by decompressing the compressed data, using differential data, or using segmented data.
[0025] The updated software can be installed by the target ECU in response to an installation request from the software update device 11 . Alternatively, the target ECU, having received the update data, can autonomously install the software without receiving explicit instructions from the software update device 11 .
[0026] The updated software can be activated by the target ECU in response to an activation request from the software update device 11 . Alternatively, the target ECU, having received the update data, can autonomously activate the software without receiving an explicit instruction from the software update device 11 .
[0027] Furthermore, the software update process can be performed sequentially or in parallel for each of the plurality of electronic control units.
[0028] In addition, the "software update process" in this specification includes not only a process of continuously executing all downloading, installing, and activating, but also a process of executing only part of the downloading, installing, and activating.
[0029] like Figure 4 As shown, the portable terminal 3 has a CPU 41, a RAM 42, a storage device (memory) 43 such as a non-volatile memory, and a communication device 44. The CPU 41 executes the software (program) read from the storage device 43 by using the RAM 42 as a working area, thereby realizing various functions. In the present embodiment, the portable terminal 3 is a terminal device capable of communicating with the server 1 and the software update device 11, such as a portable device (wireless key) used as a vehicle key, a smart phone, etc. There is no particular limitation on the communication method between the portable terminal 3 and the electronic control unit, and BLE (Bluetooth (registered trademark) Low Energy), Wi-Fi (registered trademark), RF-LF communication, etc. can be used.
[0030] (First embodiment) Figure 5 is a functional block diagram of a server according to the first embodiment. Figure 6 is a diagram showing an example of device identification information stored in a server. Figure 7 This is a diagram showing an example of update management information stored in the server.
[0031] The server 1 includes a first storage unit 25, a second storage unit 26, a communication unit 27, and a control unit 28. The first storage unit 25 and the second storage unit 26 are connected by Figure 2 The storage device 23 shown in the figure is implemented, and the communication unit 27 and the control unit 28 are implemented by Figure 2 The CPU 21 shown is implemented by executing a program (a control program for the software updating device 11 ) stored in the storage device 23 using the RAM 22 .
[0032] The first storage unit 25 stores device identification information and update management information.
[0033] like Figure 6 As shown, the device identification information is information that establishes an association between the vehicle identification information (vehicle ID) for each identified vehicle, the information that identifies the communication module 12 mounted on the vehicle, and the information that identifies the portable terminal 3 that can communicate with the software update device 11. The information that identifies the communication module 12 and the information that identifies the portable terminal 3 are, for example, information that allows the server 1 to uniquely identify the destination of data, such as an address on the network such as an IP address. The device identification information is used to obtain a second destination for sending update data when the server 1 cannot send update data for the software of the electronic control unit by communicating with the vehicle via the communication module 12. Figure 6 In the example, the communication module 12 and the address of the portable terminal are registered for the vehicles identified by the vehicle IDs “VID_1001” and “VID_1002”, and the address of the portable terminal is registered for the vehicle identified by the vehicle ID “VID_1003”.
[0034] like Figure 7 As shown, the update management information is information that establishes an association between the vehicle identification information (vehicle ID) for each vehicle, information indicating whether software updates based on wireless communication (whether OTA is possible), and information indicating the software that can be used by one or more electronic control units installed in the vehicle. As information indicating the software that can be used by the electronic control unit, for example, a combination of the latest version information of the software of multiple electronic control units is defined. Figure 6 As shown, the vehicle specified by the vehicle ID “VID_1003” does not have a communication module capable of communicating with the server 1 mounted thereon, and therefore “not possible” is set as the information indicating whether or not OTA is possible.
[0035] The second storage unit 26 stores update data of the electronic control unit. As described above, the update data may include update software of the electronic control unit, compressed data obtained by compressing the update software, or divided data obtained by dividing the update software or compressed data.
[0036] The communication unit 27 is capable of receiving a software update confirmation request from the software update device 11. The update confirmation request is information sent from the software update device 11 to the server 1 when the power or ignition switch is turned on in the vehicle, and is information used to request the server 1 to confirm whether the update data of the electronic control unit exists. In response to the update confirmation request received from the software update device 11, the communication unit 27 sends information indicating the presence or absence of the update data to the software update device 11. In addition, the communication unit 27 is capable of receiving a request to send a distribution package (download request) from the software update device 11. When the communication unit 27 receives the download request for the distribution package, it sends the distribution package containing the update data of the electronic control unit software to the software update device 11 that has implemented the download request. In addition, when communication between the server 1 and the software update device 11 is impossible, the communication unit 27 sends a notification indicating the presence of the update data of the electronic control unit to the portable terminal 3 associated with the software update device 11 in the device identification information. In this case, upon receiving a download request from the portable terminal 3 , the communication unit 27 transmits a distribution package including the update data of the electronic control unit software to the portable terminal 3 that has issued the download request.
[0037] When the communication unit 27 receives an update confirmation request, the control unit 28 determines whether software update data for the vehicle identified by the vehicle ID included in the update confirmation request exists, based on the update management information stored in the first storage unit 25. The control unit 28's determination of whether update data exists is transmitted to the software update device 11 via the communication unit 27. If the control unit 28 determines that update data for the electronic control unit exists, and upon receiving a distribution package download request from the software update device 11, the control unit 28 generates a distribution package containing the update data stored in the second storage unit 26. This distribution package is transmitted to the software update device 11 via the communication unit 27.
[0038] In addition, the control unit 28 determines whether the communication between the server 1 and the software update device 11 can be performed. When the communication between the server 1 and the software update device is interrupted, or when the vehicle having the software update device 11 is not equipped with the on-board equipment required for the software update, the control unit 28 determines that the communication between the server 1 and the software update device 11 (vehicle) cannot be performed. Based on the communication log of the communication unit 27, the control unit 28 can determine that the communication between the server 1 and the software update device 11 cannot be performed when the communication between the server 1 and the software update device 11 (communication related to OTA or communication other than this) has not been performed within a specified period. Alternatively, the control unit 28 can also determine that the communication between the server 1 and the software update device 11 cannot be performed when the difference between the software version of each electronic control unit recorded in the update management information and the latest software version is greater than a specified value, or when no software update of the electronic control unit is recorded in the update history of the electronic control unit within a fixed period. As to whether the on-board equipment required for the software update is installed on the vehicle, it can be determined based on Figure 6 The device identification information shown or Figure 7 As an in-vehicle device required for software update, in addition to the communication module 12 described above, a device having a display device such as a car navigation system for performing a user approval process can be exemplified.
[0039] Figure 8 This is a functional block diagram of the software updating device according to the first embodiment.
[0040] The software updating device 11 includes a storage unit 37, a communication unit 38, and a control unit 39. The storage unit 37 is composed of Figure 3 The storage device 34 shown is implemented, the communication unit 38 and the control unit 39 are implemented by Figure 3 The CPU 31 shown is implemented by executing a program (a control program for the software updating device 11 ) stored in the ROM 33 using the RAM 32 .
[0041] The storage unit 37 stores a program for executing software updates of the electronic control units 13 a to 13 d , various data used when executing software updates, and software update data downloaded from the server 1 .
[0042] The communication unit 38 transmits a software update confirmation request to the server 1 when the vehicle's power is turned on or the ignition is turned on. The update confirmation request includes, for example, the vehicle ID used to identify the vehicle and the software versions of the electronic control units 13a-13d connected to the in-vehicle network 2. The vehicle ID and software versions of the electronic control units 13a-13d are compared with the latest software versions stored by the server 1 for each vehicle ID to determine whether there is updated data for the electronic control unit software. Furthermore, the control unit 39 receives a confirmation result indicating the presence of updated data from the server 1 in response to the update confirmation request, and determines the presence of updated data based on the confirmation result. If there is updated data for any of the electronic control unit software, the control unit 39 transmits a download request for a distribution package to the server 1 and receives the distribution package sent from the server 1. In addition to the update data, the distribution package may also include verification data for verifying the authenticity of the update data, the number of update data, the installation order, and various control information used during the software update. Upon receiving the distribution package containing the update data from the server 1, the control unit 39 verifies the authenticity of the received distribution package.
[0043] After the distribution package containing the update data is downloaded, the control unit 39 performs the installation and activation of the update data, or performs an approval request process for the installation or activation process. When executing the software update, the control unit 39 performs the approval request process by causing an output device to output a notification indicating the need for approval of the software update, prompting the user to input approval for the software update, and accepting user input. The output device may include the display device 14 provided in the in-vehicle network 2 or a sound output device that provides sound notifications. For example, during the approval request process, if the display device 14 is used as the output device, the control unit 39 causes the display device 14 to display an approval request screen requesting approval for the software update, and, if the user or administrator approves, causes the display device 14 to display a notification urging the user or administrator to press a specific input operation, such as pressing an approval button. Furthermore, during the approval request process, the control unit 39 causes the display device 14 to display text, an icon, or other information notifying the user of the presence of software update data for the electronic control unit, and to display restrictions on the execution of the software update process.
[0044] Figure 9 This is a functional block diagram of the portable terminal according to the first embodiment.
[0045] The portable terminal 3 includes a storage unit 46, a communication unit 47, a control unit 48, and a display unit 49. The storage unit 46 is composed of Figure 4 The storage device 43 shown is implemented by the communication unit 47 and the control unit 48. Figure 4 The CPU 41 shown is implemented by executing a program stored in the storage device 43 using the RAM 42 .
[0046] The storage unit 46 stores a program for executing software updates of the electronic control units 13 a to 13 d , various data used when executing software updates, and software update data downloaded from the server 1 .
[0047] The communication unit 47 is capable of wireless communication with the server 1 and the software update device 11. The communication unit 47 receives a notification from the server 1 indicating the presence of update data for the electronic control unit's software. If communication between the server 1 and the software update device 11 is unavailable, the server 1 transmits this notification. Upon receiving the notification indicating the presence of update data for the electronic control unit's software, the communication unit 47 transmits a download request for the distribution package to the server 1 and is capable of receiving the distribution package from the server 1. The communication unit 47 can transmit the download request to the server 1 in response to explicit user instructions or automatically in response to the notification from the server 1. As described above, in addition to the update data, the distribution package may also include verification data for verifying the authenticity of the update data, the amount of update data, the order in which the update data should be installed, and various control information used during the software update. When the electronic control unit's software is updated through communication between the portable terminal 3 and the software update device 11, the communication unit 47 transmits the update data downloaded from the server 1 to the software update device 11.
[0048] After downloading the distribution package containing the update data, the control unit 48 uses the downloaded update data to perform an update process for the electronic control unit software via wireless communication with the software update device 11. The software update process executed by the portable terminal 3 includes installing the update data, activating the update data, and requesting approval for the installation or activation. During the installation process, the control unit 48 instructs the software update device 11 to install the software. During the activation process, the control unit 48 instructs the software update device 11 to activate the updated software. Furthermore, as part of the approval request process, the control unit 48 causes the display unit 49 to display a notification indicating that approval for the software update is required, prompts the user to enter a notification indicating approval for the software update and requests approval, and accepts user approval for the software update. In addition to displaying notifications on the display unit 49, the control unit 48 can also cause the portable terminal 3 to output notifications using, for example, a sound output device. For example, during the approval request process, the control unit 48 causes the display unit 49 to display an approval request screen requesting approval for the software update, and, if the user or administrator approves, causes the display unit 49 to display a notification urging the user to enter a specific input action, such as pressing an approval button. Furthermore, during the approval request process, the control unit 48 causes the display unit 49 to display text, images, etc. notifying that update data for the electronic control unit software exists, and causes the display unit 49 to display restrictions on execution of the software update process.
[0049] The display unit 49 has a display screen and displays various display contents accompanying the execution of software (application) by the control unit 48 .
[0050] Figure 10 This is a flowchart showing an example of control processing executed by the server according to the first embodiment, and more specifically, shows an example of processing for determining whether the server and the software updating device can communicate. Figure 10 The processing can be performed regularly, for example, at fixed intervals.
[0051] In step S11, the control unit 28 confirms the update status of the software in each vehicle. Specifically, the control unit 28 refers to the update management information ( Figure 7 ), extract the vehicle record required for the software update of the electronic control unit based on the comparison between the software version of the electronic control unit recorded in the update management information and the latest software version. Figure 7 In the example, when the latest software versions of ECU1, ECU2, ECU3, and ECU4 are 2.0, 2.0, 1.4, and 1.0, the vehicle identified by vehicle ID "VID_1001" has the latest software and does not need a software update, but the vehicles identified by vehicle IDs "VID_1002" and "VID_1003" need a software update. In addition, to simplify the explanation, Figure 7 The three vehicles shown are of the same model and are equipped with the same electronic control unit. The control unit 28 extracts the records for the vehicles identified by vehicle IDs "VID_1002" and "VID_1003" as those requiring a software update. In the following description, the vehicles requiring a software update extracted in step S11 are referred to as "target vehicles." The process then proceeds to step S12.
[0052] In step S12, the control unit 28 determines whether there is a vehicle requiring a software update. If the control unit 28 retrieved a record of a vehicle requiring a software update in step S11, the determination is yes. If the determination in step S12 is yes, the process proceeds to step S13; otherwise, the process ends.
[0053] In step S13, the control unit 28 determines whether the target vehicle identified in step S11 is capable of software updates via wireless communication (OTA). More specifically, the control unit 28 selects a record from the target vehicle records extracted in step S11. Based on the information indicating OTA availability contained in the selected record, the control unit 28 determines whether OTA software updates are possible. If the determination in step S13 is yes, the process proceeds to step S14; otherwise, the process proceeds to step S15.
[0054] In step S14, the control unit 28 determines whether communication has occurred between the server 1 and the vehicle (software update device 11) within a predetermined period. The determination in step S14 can be performed based on the communication log of the communication unit 27. If the determination in step S14 is yes, the process proceeds to step S17; otherwise, the process proceeds to step S15.
[0055] In step S15, the control unit 28 determines whether there is a registration of the portable terminal. More specifically, the control unit 28 refers to the device identification information ( Figure 6 ), it is determined whether the information of the portable terminal associated with the vehicle ID of the record selected in step S13 is registered. If the determination in step S15 is yes, the process proceeds to step S16, and in other cases, the process proceeds to step S17.
[0056] In step S16, the communication unit 27 transmits a notification indicating that the software update of the electronic control unit is necessary to the mobile terminal associated with the vehicle ID of the record selected in step S13. The process then proceeds to step S17.
[0057] In step S17, the control unit 28 determines whether all target vehicle records extracted in step S11 have been processed (whether the processes of steps S13 to S16 have been performed). If the result of step S17 is yes, the process ends. Otherwise, the process proceeds to step S13.
[0058] Figure 11 This is a flowchart showing an example of update data distribution processing executed by the server according to the first embodiment. Figure 11 The control process shown is executed repeatedly at a predetermined time interval. Figure 11 The control processing is previously registered in the storage unit (first storage unit 25, second storage unit 26).
[0059] In step S21, the communication unit 27 determines whether an update confirmation request has been received from the software update device 11. If the determination in step S21 is yes, the process proceeds to step S22, and otherwise, the process proceeds to step S23.
[0060] In step S22, the communication unit 27 transmits information indicating whether updated data for the electronic control unit software exists to the vehicle that has transmitted the update confirmation request. To determine the presence of updated data, the control unit 28 compares the software version combination stored in the update management information, associated with the vehicle ID included in the update confirmation request, with the current software version combination included in the update confirmation request. If the current software version combination included in the update confirmation request is older than the version combination stored in the update management information, the control unit 28 determines that updated data exists. Processing then proceeds to step S23.
[0061] In step S23, the communication unit 27 determines whether a request to download the update data (distribution package) has been received. If the determination in step S23 is yes, the process proceeds to step S24. Otherwise, the process proceeds to step S21.
[0062] In step S24, the control unit 28 determines whether the transmission source of the download request received in step S23 is the vehicle (software updating device 11) or the portable terminal 3. If the transmission source of the download request is the vehicle, the process proceeds to step S25; if the transmission source of the download request is the portable terminal 3, the process proceeds to step S26.
[0063] In step S25, the communication unit 27 transmits the distribution package including the software update data generated by the control unit 28 to the software updating device 11. Thereafter, the process proceeds to step S21.
[0064] In step S26, the communication unit 27 transmits the distribution package including the software update data generated by the control unit 28 to the portable terminal 3. Thereafter, the process proceeds to step S21.
[0065] also, Figure 11 The process of step S25 is executed when the server 1 and the software updating apparatus 11 are able to communicate with each other. The process of step S26 is executed when the server 1 and the software updating apparatus 11 are unable to communicate with each other.
[0066] Figure 12 This is a flowchart showing an example of software update processing executed by the software update device. Figure 12 The control process shown is a process in which the software update device 11 performs software update of the electronic control unit by communicating with the server 1 , and is executed when, for example, the vehicle power supply or ignition switch is turned on.
[0067] In step S31, the communication unit 38 transmits an update confirmation request including a combination of the vehicle ID and the software versions of the electronic control units 13a to 13d to the server 1. The process then proceeds to step S32.
[0068] In step S32, the communication unit 38 receives the update data confirmation result from the server 1. Thereafter, the process proceeds to step S33.
[0069] In step S33, the control unit 39 determines whether there is update data for the software of the electronic control units 13a to 13d based on the confirmation result received from the server 1. If the result of step S33 is yes, the process proceeds to step S34, and otherwise, the process ends.
[0070] In step S34, the communication unit 38 executes the download process. Specifically, the communication unit 38 sends a download request for the distribution package to the server 1, receives the distribution package sent in response to the download request, and stores the received distribution package in the storage unit 37. The communication unit 38 verifies the authenticity of the update data contained in the received distribution package. In step S34, a determination may be made as to whether the download can be executed, and a notification of download completion may be sent to the server 1. Processing then proceeds to step S35.
[0071] In step S35, the control unit 39 executes an installation process for the target electronic control unit. The installation process in step S35 includes determining whether the installation can be performed, requesting the user to approve the installation and accepting the user's input of approval, transmitting update data from the software update device 11 to the target electronic control unit, requesting the installation of the target electronic control unit, and requesting verification of the installation of the target electronic control unit. The target electronic control unit uses the update data received from the software update device 11 to install the updated version of the software in its storage area. The process then proceeds to step S36.
[0072] In step S36, the control unit 39 activates the target electronic control unit. The activation process in step S36 includes determining whether activation is feasible, requesting user approval for activation and accepting the user's input of approval, and requesting activation of the target electronic control unit. The target electronic control unit switches the software being executed to the updated version, thereby activating the updated version and starting the updated software. The process then terminates.
[0073] Figure 13 This is a sequence diagram showing another example of the software update process executed by the software update device. Figure 13The control process shown is a process in which the software update device 11 updates the software of the electronic control unit by communicating with the portable terminal 3 , and is executed in response to, for example, a user instruction input to the portable terminal 3 or the software update device 11 .
[0074] In step S41, the communication unit 47 of the portable terminal 3 transmits a connection request to the software update device 11. The connection request in step S41 is transmitted, for example, when an instruction is input from the user.
[0075] In step S42, the control unit 39 of the software update device 11 performs an authentication process to authenticate the portable terminal that sent the connection request. The authentication process method is not particularly limited, and a known authentication process can be used. During the authentication process, the software update device 11 can also communicate with the portable terminal multiple times. In addition, the authentication process of step S42 can also be performed by the electronic control unit that performs the authentication when unlocking and starting the vehicle instead of by the software update device 11. In this case, since the software update of the electronic control unit is performed using the portable terminal 3 used as the electronic key of the vehicle, security can be improved. After that, the process enters step S43.
[0076] In step S43, the communication unit 38 of the software updating device 11 transmits the authentication result to the portable terminal 3. Figure 13 In the example of FIG. 4 , it is assumed that the software updating apparatus 11 transmits an authentication result indicating successful authentication in step S43 .
[0077] In step S44, the control unit 48 of the portable terminal 3 displays an approval request screen for requesting approval for downloading the update data on the display unit 49. Thereafter, the process proceeds to step S45.
[0078] In step S45, the control unit 48 of the portable terminal 3 receives the input indicating that the user has approved the download of the content. When the control unit 48 detects the input indicating approval through the touch panel, button operation, etc., the process proceeds to step S46.
[0079] In step S46, the communication unit 47 of the portable terminal 3 transmits the update data stored in the storage unit 46 to the software updating device 11. Thereafter, the process proceeds to step S47.
[0080] In step S47, the control unit 39 of the software updating device 11 checks the authenticity of the update data received from the portable terminal 3. Thereafter, the process proceeds to step S48.
[0081] In step S48, the communication unit 38 of the software updating device 11 transmits the result of checking the authenticity of the update data to the portable terminal 3. Figure 13 In the example of FIG. 4 , it is assumed that the software updating apparatus 11 transmits a check result indicating that the update data is authentic in step S47 .
[0082] In step S49, the control unit 48 of the portable terminal 3 causes the display unit 49 to display an approval request screen for requesting approval to install the update data. For example, the control unit 48 causes the display unit 49 to display a message indicating that the electronic control unit software update has started, and, if necessary, a message indicating the time required for installation, any restrictions or precautions during installation. The process then proceeds to step S50.
[0083] In step S50, the control unit 48 of the portable terminal 3 accepts the user's input using the touch panel or button input unit. The input indicating approval of the installation can be determined by, for example, whether a button such as "Approve" or "Start Update" displayed on the display unit 49 has been pressed. Furthermore, if the user wishes to approve the software update (installation) later rather than immediately, they can accept this request by pressing a button such as "Proceed Later." Upon detecting approval input via the touch panel or button operation, the control unit 48 proceeds to step S51.
[0084] In step S51, the communication unit 47 of the portable terminal transmits an instruction to install the update data to the software updating device 11. Thereafter, the process proceeds to step S52.
[0085] In step S52, the control unit 39 of the software update device 11 executes an installation process on the target electronic control unit. The installation process in step S52 includes determining whether the installation can be performed, transmitting update data from the software update device 11 to the target electronic control unit, requesting the target electronic control unit for installation, and requesting verification of the installation of the target electronic control unit. The target electronic control unit uses the update data received from the software update device 11 to install the updated version of the software in its storage area. The process then proceeds to step S53.
[0086] In step S53, the communication unit 38 of the software updating device 11 transmits an installation completion notification indicating that the installation is complete to the portable terminal 3. Thereafter, the process proceeds to step S54.
[0087] In step S54, the control unit 48 of the portable terminal 3 causes the display unit 49 to display an approval request screen for requesting approval for activation of the updated software. The control unit 48 causes the display unit 49 to display, for example, information indicating that the electronic control unit software is ready for update, details of the program being updated by a specific operation such as turning off the power or ignition switch, and, if necessary, information on the time required for activation, restrictions on activation, and precautions. The process then proceeds to step S55.
[0088] In step S55, the control unit 48 of the portable terminal 3 receives an input indicating approval of activation using an input unit such as a touch panel or operation buttons. This input indicating approval of activation can be determined, for example, by whether a button such as "Approve" or "Update" displayed on the display unit 49 has been pressed. Furthermore, if the user wishes to approve the software update (activation) later rather than immediately, they can accept this request by pressing a button such as "Proceed Later." Upon detecting that an input indicating approval has been made using the touch panel or button operation, the control unit 48 proceeds to step S56.
[0089] In step S56, the communication unit 47 of the portable terminal transmits an activation instruction for the updated version of the software to the software update device 11. Thereafter, the process proceeds to step S57.
[0090] In step S57, the control unit 39 of the software update device 11 activates the target electronic control unit. The activation process in step S57 includes determining whether activation is feasible, receiving an approval input, and requesting activation of the target electronic control unit. The target electronic control unit activates the target electronic control unit by switching the software being executed to the updated version, activating the updated version, and then terminating the process.
[0091] Furthermore, if the ECU to be updated has a single data storage area, it is preferable to perform installation and activation sequentially, as the timing of installing the update data into the data storage area may affect the ECU software. Furthermore, in this case, if the ECU to be updated has a single data storage area, approval request processing for both installation and activation may be performed prior to installation, omitting the approval request processing prior to activation.
[0092] As described above, the server 1 of this embodiment stores information (such as an address) about the software update device 11 installed in the vehicle and a portable terminal (smartphone, smart key) capable of communicating with the software update device 11 as device identification information. In the event that software updates cannot be performed through communication between the server 1 and the software update device 11, the server 1 can execute software updates for the electronic control unit via the portable terminal 3 capable of communicating with the software update device 11 of the target vehicle. Therefore, even if the server 1 cannot communicate with the vehicle, the software of the electronic control unit can be updated promptly. Furthermore, in the event that the server 1 cannot perform software updates based on communication with the software update device, update data can be selectively sent to the portable terminal 3 to instruct the execution of the update process. Therefore, software updates based on communication between the server 1 and the vehicle and software updates via the portable terminal are not performed in parallel, thereby preventing duplication and mismatching of software updates.
[0093] Furthermore, the server 1 of this embodiment can perform software updates using the communication function and display screen of the portable terminal 3 without being equipped with vehicle-mounted equipment required for software updates, such as the communication module 12 and the display device 14 .
[0094] (Second embodiment) The server of the second embodiment will be described focusing on the differences from the first embodiment.
[0095] Figure 14 This is a diagram showing an example of device identification information stored in the server according to the second embodiment.
[0096] Figure 14 The device identification information shown is information that establishes an association between the vehicle identification information (vehicle ID) for each identified vehicle in order of priority, information that identifies the communication module 12 mounted on the vehicle, and information that identifies the portable terminal 3 that can communicate with the software update device 11. Similar to the first embodiment, the information that identifies the communication module 12 and the information that identifies the portable terminal 3 are, for example, information that allows the server 1 to uniquely identify the destination of data, such as an address on the network such as an IP address. The device identification information of this embodiment is used by the server 1 to obtain the destination of the update data of the software of the electronic control unit. Figure 14In the example, for the vehicle identified by vehicle ID "VID_1001", the addresses of the communication module 12 and the portable terminal 3 are registered in descending order of priority. For the vehicle identified by vehicle ID "VID_1002", the addresses of the portable terminal 3 and the communication module 12 are registered in descending order of priority. In addition, in the vehicles identified by vehicle ID "VID_1003" and "VID_1004", the addresses of the communication module 12 and the portable terminal 3 are registered respectively. Figure 14 In the example shown in FIG, information of two terminals is registered for one vehicle ID, but three or more terminals may be registered in order of priority.
[0097] Figure 15 This is a flowchart showing an example of control processing executed by the server according to the second embodiment.
[0098] In step S61, the control unit 28 confirms the update status of the software in each vehicle. Specifically, the control unit 28 refers to the update management information ( Figure 7 ), by comparing the ECU software version recorded in the update management information with the latest software version, records of vehicles requiring an ECU software update are extracted. In the following description, the vehicle requiring a software update extracted in step S11 is referred to as a "target vehicle." The process then proceeds to step S62.
[0099] In step S62, the control unit 28 determines whether there is a vehicle requiring a software update. If a record of a vehicle requiring a software update was extracted in step S61, the control unit 28 determines yes. If the determination in step S62 is yes, the process proceeds to step S63; otherwise, the process ends.
[0100] In step S63, the control unit 28 selects a record from the records of the target vehicle extracted in step S61, and referring to the device identification information, determines whether the terminal with the highest priority associated with the vehicle ID of the selected record is the mobile terminal 3. If the determination in step S63 is yes, the process proceeds to step S64; otherwise, the process proceeds to step S65.
[0101] In step S64, the communication unit 27 transmits a notification indicating that the software update of the electronic control unit is necessary to the portable terminal 3 referred to in step S63. The process then proceeds to step S65.
[0102] In step S65, the control unit 28 determines whether all target vehicle records extracted in step S61 have been processed (whether the processes of steps S63 to S64 have been performed). If the result of step S65 is yes, the process ends. Otherwise, the process proceeds to step S63.
[0103] When using the device identification information of this embodiment, if communication with the primary terminal (a terminal with a higher priority) is unavailable, a secondary terminal (a terminal with a lower priority) can be selected as a second destination for sending update data. Therefore, even if server 1 is unable to communicate with the primary terminal, communication with the secondary terminal can be used to promptly update the software of the electronic control unit. Furthermore, server 1 can selectively send update data to either the primary or secondary terminal to instruct the execution of the update process. Therefore, software updates based on communication between server 1 and the vehicle and software updates via the portable terminal are not performed in parallel, preventing duplication and mismatch of software updates.
[0104] Furthermore, in this embodiment, since the portable terminal 3 can be registered as the primary terminal in the device identification information, even if the vehicle does not have onboard equipment required for software updates, such as the communication module 12 and the display device 14, the presence of updated data for the electronic control unit software can be reliably notified. Furthermore, since software updates can be managed using pre-registered portable terminals, this is suitable for managing multiple vehicles, such as in rental or car-sharing systems.
[0105] (Other Modifications) The functions of the server 1 illustrated in each of the above embodiments may also be implemented as a method for distributing update data executed by a computer having a processor (CPU), memory, and storage, or as a distribution program executed by the computer, or as a computer-readable non-transitory storage medium storing the distribution program. Similarly, the functions of the software update device 11 illustrated in each of the embodiments may also be implemented as an update control method executed by an onboard computer having a processor (CPU), memory, and storage, or as an update control program executed by the onboard computer, or as a computer-readable non-transitory storage medium storing the update control program.
[0106] In the above-described embodiments, the software update device 11 installed in the vehicle's in-vehicle network serves as a host device (update control device) to control program updates for all of the electronic control units 13a to 13d. However, instead of installing the software update device 11, any one of the electronic control units 13a to 13d may have an update control function and control program updates for the other electronic control units. Furthermore, instead of installing the software update device 11, the update control function of the software update device 11 may be installed in an external device that can be connected to the in-vehicle network 2 by wire, and the program update process for the electronic control units 13a to 13d may be performed using this external device.
[0107] The technology of the present invention can be used in a network system for updating software of an electronic control unit.
Claims
1. A server for distributing update data for software of an electronic control unit mounted on a vehicle, the server comprising: a storage unit for storing information related to the vehicle and information related to an external terminal in association with the vehicle, the external terminal being capable of communicating with the vehicle; a receiving unit configured to receive a download request for the update data; as well as a sending unit that, in response to receipt of the download request, 1) sending the update data to the vehicle when the vehicle is equipped with a communication module capable of wirelessly communicating with the server; 2) When the vehicle is not equipped with a communication module capable of wirelessly communicating with the server, the update data is transmitted to the external terminal.
2. The server according to claim 1, wherein further comprising a determination unit for determining whether wireless communication with the vehicle is possible, When the vehicle is equipped with a communication module capable of wirelessly communicating with the server but communication with the communication module is interrupted, and when the vehicle is not equipped with a communication module capable of wirelessly communicating with the server, the judgment unit determines that wireless communication with the vehicle is not possible.
3. The server according to claim 1, wherein the receiving unit, 1) receiving the download request from the vehicle when the vehicle is equipped with a communication module capable of wirelessly communicating with the server; 2) When the vehicle is not equipped with a communication module capable of wirelessly communicating with the server, the download request is received from the external terminal.
4. The server according to claim 1, wherein The external terminal is an electronic key of the vehicle.
5. The server according to claim 1, wherein The storage unit stores vehicle identification information as information related to the vehicle and an address of the external terminal as information related to the external terminal in association with each other. The server according to claim 1 , wherein: The update data is compressed data of update software used by the electronic control unit, or divided data obtained by dividing the update software or the compressed data.
7. The server according to claim 1, wherein: It also has a notification department. The Notification Department, In a case where the vehicle is equipped with a communication module capable of wirelessly communicating with the server, notifying the vehicle of a software update, When the vehicle is not equipped with a communication module capable of wirelessly communicating with the server, the external terminal is notified of the presence of a software update.
8. The server according to claim 7, wherein: The vehicle is further provided with a confirmation unit for confirming whether the vehicle can be OTA-enabled. When it is confirmed that the vehicle is capable of OTA, the notification unit notifies that there is a software update.
9. A method for distributing, by a computer, update data of software for an electronic control unit mounted on a vehicle, the method comprising the following steps: storing information related to the vehicle and information related to an external terminal in association with each other, the external terminal being capable of communicating with the vehicle; receiving a download request for the update data; as well as In response to the receipt of the download request, 1) sending the update data to the vehicle when the vehicle is equipped with a communication module capable of wirelessly communicating with the computer; 2) When the vehicle is not equipped with a communication module capable of wirelessly communicating with the computer, the update data is transmitted to the external terminal.
10. A non-transitory storage medium storing a program executable by a computer for causing the computer to distribute update data of software of an electronic control unit mounted on a vehicle, the program causing the computer to execute: storing information related to the vehicle and information related to an external terminal in association with each other, the external terminal being capable of communicating with the vehicle; receiving a download request for the update data; as well as In response to the receipt of the download request, 1) sending the update data to the vehicle when the vehicle is equipped with a communication module capable of wirelessly communicating with the computer; 2) When the vehicle is not equipped with a communication module capable of wirelessly communicating with the computer, the update data is transmitted to the external terminal.
Citation Information
Patent Citations
Relay device, program update system, and program update method
JP2018181377A