Update device

By using the update device in the vehicle manufacturing process and selecting different authentication methods according to the conditions, the problem of long software update time and difficult to take into account is solved, and fast and safe software updates are achieved.

CN120508301APending Publication Date: 2025-08-19TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510151503.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-02-19
Filing Date
2025-02-11
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

When software updates are performed in vehicle manufacturing processes, the prior art requires tedious authentication procedures, resulting in an increase in update time, and reducing the authentication conditions makes it difficult to ensure the security of the software.

Method used

An update device is provided, through the determination unit, to determine whether the software can be updated, and to use different authentication methods according to preset conditions, including the first method and the second method, the first method has a lower security level when the conditions are met, and the second method has a higher security level when the conditions are not met, so as to quickly and safely perform software updates under different circumstances.

Benefits of technology

When conditions are met, the update process is accelerated through a lower security level authentication method, and when conditions are not met, the software is secure through a high security level authentication method, avoiding the increase in update time and the reduction in security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120508301A_ABST
    Figure CN120508301A_ABST
Patent Text Reader

Abstract

The purpose of the present invention is to increase the time for software update while ensuring security in the update of software for controlling a mobile body. An update device that updates software stored in a moving object, the update device being provided with a determination unit that determines whether or not the software can be updated, the determination unit acquiring update target information that is information relating to at least one of the software and the moving object, and in a first case in which the update target information satisfies a preset condition, updating the software by using the update target information, and in a second case in which the update target information does not satisfy the preset condition. In a first case where the update target information satisfies a predetermined condition, the update permission is determined by a first method, and in a second case where the update target information does not satisfy the predetermined condition, the update permission is determined by a second method having a higher security level than the first method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an updating device. Background Art

[0002] There is known a technology for making a vehicle unmanned by remote control during a vehicle manufacturing process (for example, Patent Document 1). Prior art literature Patent Literature

[0003] Patent Document 1: Japanese Patent Application No. 2017-538619 Summary of the Invention Problems to be solved by the invention

[0004] If a problem occurs during the vehicle manufacturing process, the vehicle's control software may need to be updated. This software update requires a specific certification process, which increases the time required for the certification process. Furthermore, lowering the security level of the certification requirements makes it difficult to ensure software security. This problem applies not only to vehicles but to any mobile object. Technical means to solve problems

[0005] The present disclosure can be implemented as the following aspects.

[0006] (1) According to one embodiment of the present disclosure, an update device is provided for updating software stored in a mobile object. The control device includes a determination unit for determining whether the software can be updated. The determination unit obtains information related to at least one of the software and the mobile object, namely, update target information. If the update target information satisfies a predetermined condition in a first case, the determination unit determines whether the update can be updated using a first method. If the update target information does not satisfy the predetermined condition in a second case, the determination unit determines whether the update can be updated using a second method having a higher security level than the first method. According to this control device, in the first case where the update target information satisfies a predetermined condition, the first method is used to determine whether the update is permitted. In the second case where the update target information does not satisfy the predetermined condition, the second method is used to determine whether the update is permitted. Therefore, in the first case, the first method, which has a lower security level than the second method, can be used to easily determine whether the update is permitted, thereby minimizing the time required for software updates. Furthermore, in the second case, the second method, which has a higher security level than the first method, can be used to determine whether the update is permitted. This reduces the security level compared to a method that always determines whether the update is permitted using the first method. (2) In the above embodiment, the predetermined condition may include that the moving object is located within a predetermined area. According to the control device of this aspect, since the preset condition includes whether the moving object is located within the preset area, the first method and the second method can be appropriately distinguished and used depending on whether the moving object is located within the preset area. (3) In the above embodiment, the predetermined condition may include that the software is used when the moving object is present in a predetermined area. According to this method, the control device includes software used when the mobile body exists in a predetermined area. Therefore, the first method and the second method can be appropriately distinguished based on whether the software is used when the mobile body exists in the predetermined area. (4) In the above embodiment, the predetermined condition may include storing the software in a predetermined device. According to the control device of this aspect, since the preset condition includes whether the software is stored in the preset device, it is possible to easily distinguish between the first method and the second method to be used based on whether the software is stored in the preset device. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 This is a conceptual diagram showing the system configuration of the first embodiment. Figure 2 This is a block diagram showing the system configuration of the first embodiment. Figure 3 This is a flowchart showing the processing flow of the vehicle travel control in the first embodiment. Figure 4 This is a flowchart showing the flow of the update process in the first embodiment. Figure 5 This is a flowchart showing the flow of update processing in the second embodiment. Figure 6 It is a block diagram showing the system configuration in the third embodiment. Figure 7 This is a flowchart showing the processing flow of the vehicle travel control in the third embodiment. DETAILED DESCRIPTION

[0008] A. First embodiment: A-1. System composition: Figure 1This is a conceptual diagram showing the configuration of the system 10 according to the first embodiment. The system 10 includes one or more vehicles 100 as mobile bodies, a server device 200 , one or more external sensors 300 , and a process management device 400 for managing the production of the vehicles 100 in the factory FC.

[0009] In the present disclosure, a "mobile body" means an object that can move, such as a vehicle or an electric vertical take-off and landing aircraft (a so-called flying car). A vehicle can be a vehicle that moves on wheels or a vehicle that moves on tracks, such as a passenger car, a truck, a bus, a two-wheeled vehicle, a four-wheeled vehicle, a tank, an engineering vehicle, etc. Vehicles include electric vehicles (BEV: Battery Electric Vehicle), gasoline vehicles, hybrid vehicles, and fuel cell vehicles. When the mobile body is other than a vehicle, the expressions "vehicle" and "car" in the present disclosure can be appropriately replaced with "mobile body", and the expression "travel" can be appropriately replaced with "move".

[0010] The vehicle 100 is configured to be able to travel by unmanned driving. "Unmanned driving" means driving that does not rely on the driving operation of the passengers. Driving operation means an operation related to at least one of "driving", "steering" and "stopping" of the vehicle 100. Unmanned driving is achieved by automatic or manual remote control using a device located outside the vehicle 100, or autonomous control of the vehicle 100. In the vehicle 100 that travels by unmanned driving, there may also be passengers who do not perform driving operations. Passengers who do not perform driving operations include, for example, people who only sit on the seats of the vehicle 100, and people who perform operations other than driving operations such as assembly, inspection, and switch operations while riding in the vehicle 100. In addition, driving based on the driving operations of passengers is sometimes called "manned driving".

[0011] In this specification, "remote control" includes "full remote control," in which all actions of vehicle 100 are determined entirely from outside vehicle 100, and "partial remote control," in which only a portion of the actions of vehicle 100 are determined from outside vehicle 100. Furthermore, "autonomous control" includes "full autonomous control," in which vehicle 100 autonomously controls its own actions without receiving any information from devices outside vehicle 100, and "partial autonomous control," in which vehicle 100 autonomously controls its own actions using information received from devices outside vehicle 100. In the following description, control of the driving of vehicle 100 achieved through remote control or autonomous control is also referred to as "driving control." Driving control is equivalent to "mobility control" in this disclosure.

[0012] In this embodiment, the driving system 10 is used in a factory FC that manufactures vehicles 100. The reference coordinate system of the factory FC is the global coordinate system GC. That is, any position within the factory FC can be represented by the X, Y, and Z coordinates of the global coordinate system GC. The factory FC includes a first location PL1 and a second location PL2. The first location PL1 and the second location PL2 are connected by a driving road TR on which the vehicle 100 can travel. In the factory FC, a plurality of external sensors 300 are installed along the driving road TR. The position of each external sensor 300 in the factory FC is pre-adjusted. The vehicle 100 moves from the first location PL1 to the second location PL2 via the driving road TR without human control.

[0013] The external sensor 300 is located outside the vehicle 100 and acquires information related to the vehicle 100. In this embodiment, the external sensor 300 captures the vehicle 100 from outside. Specifically, the external sensor 300 is comprised of a camera. The camera serving as the external sensor 300 captures an image including the vehicle 100 and outputs the captured image as a detection result. The external sensor 300 includes a communication device (not shown) and is capable of communicating with other devices such as the server device 200 via wired or wireless communication.

[0014] Figure 2 This is a block diagram illustrating the configuration of system 10 according to the first embodiment. Vehicle 100 includes a vehicle control device 110 for controlling various components of vehicle 100, an actuator group 120 comprising one or more actuators driven under the control of vehicle control device 110, and a communication device 130 for communicating with external devices such as server device 200 via wireless communication. Actuator group 120 includes actuators for the drive system for accelerating vehicle 100, actuators for the steering system for changing the direction of travel of vehicle 100, and actuators for the braking system for decelerating vehicle 100. In addition, vehicle 100 may also include various sensors (not shown), such as a vehicle speed sensor and a yaw rate sensor.

[0015] The vehicle control device 110 is composed of a computer including a processor 111, a memory 112, an input / output interface 113, and an internal bus 114. The processor 111, the memory 112, and the input / output interface 113 are connected via the internal bus 114 for bidirectional communication. The actuator group 120 and the interface are connected to the input / output interface 113. The processor 111 implements various functions, including the function of the vehicle control unit 115, by executing the program PG1 stored in the memory 112. In this embodiment, the processor 111 functions as the vehicle control unit 115, the determination unit 116, the permission unit 117, and the update unit 118.

[0016] The vehicle control unit 115 drives the vehicle 100 by controlling the actuator group 120. The vehicle control unit 115 controls the actuator group 120 using a driving control signal received from the server device 200, thereby enabling the vehicle 100 to drive. The driving control signal is a control signal for driving the vehicle 100. In this embodiment, the driving control signal includes the acceleration and steering angle of the vehicle 100 as parameters. In other embodiments, the driving control signal may include the speed of the vehicle 100 as a parameter instead of the acceleration of the vehicle 100, or may include the speed of the vehicle 100 as a parameter in addition to the acceleration of the vehicle 100.

[0017] The determination unit 116 determines whether the software stored in the vehicle 100 can be updated. In the present embodiment, the determination unit 116 determines whether the software can be updated by determining whether the authentication information output from the terminal device 500 satisfies the authentication conditions. The terminal device 500 is a device that is operated by the user to update the software stored in the vehicle 100. In the present embodiment, the program PG1 stored in the memory 112 of the vehicle 100 is equivalent to the "software". In addition, "software" is not limited to the program PG1, and includes software pre-stored in the memory 112, and software downloaded from the server device 200 and stored in the memory 112 as needed, such as software that implements various functions for component assembly processes and inspection processes performed in the manufacturing process of the vehicle 100. Multiple terminal devices 500 may be provided in the factory FC, or only one may be provided. In addition, the terminal device 500 is not limited to Figure 1 The fixed device shown may also be a portable terminal such as a smartphone.

[0018] When performing a software update, the terminal device 500 outputs authentication information to the vehicle 100 being updated. "Authentication information" refers to information used to determine whether the software update is permitted during the update process, which will be described later. This authentication information includes, for example, the login password for the software update application, a user ID identifying the user performing the update process, a device ID identifying the terminal device 500 performing the update process, and information specifying the software being updated.

[0019] If the authorization unit 117 determines that the authentication information satisfies the authentication conditions, it authorizes the terminal device 500 to update the software. If the software update is authorized, the update unit 118 updates the software in response to a software update request from the terminal device 500. Specifically, if the authentication information satisfies the authentication conditions, the update unit 118 updates the software. Furthermore, the processor 111 may not include the authorization unit 117.

[0020] As described above, the vehicle control device 110 of this embodiment functions as the determination unit 116, the permission unit 117, and the update unit 118, and updates the software stored in the vehicle 100 when the authentication information satisfies the authentication conditions. In other words, the vehicle control device 110 of this embodiment corresponds to the "update device" in this disclosure.

[0021] The server device 200 is composed of a computer including a processor 201, a memory 202, an input / output interface 203, and an internal bus 204. The processor 201, the memory 202, and the input / output interface 203 are connected via the internal bus 204 for bidirectional communication. A communication device 205 for communicating with various devices external to the server device 200 is connected to the input / output interface 203. The communication device 205 can communicate with the vehicle 100 via wireless communication, and can communicate with the external sensors 300 and the process management device 400 via wired or wireless communication.

[0022] The processor 201 implements various functions including the function as the remote control unit 210 by executing the program PG2 stored in the memory 202. In the present embodiment, the processor 201 functions as the remote control unit 210 and the handling unit 211.

[0023] Remote control unit 210 obtains detection results from external sensors 300 and uses these detection results to generate a driving control signal that instructs the actuator group 120 of vehicle 100 on the control content. By transmitting the driving control signal to vehicle 100, vehicle 100 is remotely controlled to travel. The process flow of driving control implemented through remote control in this embodiment will be described later. Remote control unit 210 not only generates and outputs driving control signals but also generates and outputs control signals for actuators that operate various equipment, such as various auxiliary devices, wipers, power windows, and lights, included in vehicle 100. In other words, remote control unit 210 can also operate these various equipment and auxiliary devices through remote control.

[0024] In the update process described later, the handling unit 211 handles the inquiry when an inquiry is generated from the determination unit 116. The process of the handling unit 211 when an inquiry is generated from the determination unit 116 will be described later.

[0025] The process management device 400 is a device for managing the manufacturing process of the vehicle 100. The process management device 400 is composed of a computer. The process management device 400 obtains information from various devices in the factory FC, generates information related to the manufacturing process of the vehicle 100 as a product, and manages it for each vehicle 100. In the following description, information related to the manufacturing process of the product is referred to as process information. In this embodiment, the process information includes information indicating which operator is scheduled to perform which operation on which product at what time and where, information indicating which operator performed which operation on which product at what time and where, and information indicating the progress status of the operation. The process management device 400 is equipped with a communication device not shown in the figure, and transmits the process information to the server device 200 via wired communication or wireless communication. In addition, the functions of the process management device 400 can also be installed in the same device as the server device 200. In addition, the system 10 may not have the process management device 400.

[0026] A-2. Driving Control: Figure 3 This is a flowchart illustrating the process flow for driving control of vehicle 100 in the first embodiment. In step S1, remote control unit 210 uses detection results output by external sensor 300 to obtain vehicle position information of vehicle 100. Vehicle position information is the basis for generating driving control signals. In this embodiment, vehicle position information includes the position and orientation of vehicle 100 in the global coordinate system GC of factory FC. Specifically, in step S1, remote control unit 210 uses images captured by a camera serving as external sensor 300 to obtain vehicle position information.

[0027] Specifically, in step S1, the remote control unit 210 detects the shape of the vehicle 100 from a captured image, calculates the coordinates of the vehicle 100's location points in the captured image's coordinate system, i.e., the local coordinate system, and converts the calculated coordinates into coordinates in the global coordinate system GC, thereby obtaining the position of the vehicle 100. The shape of the vehicle 100 contained in the captured image can be detected, for example, by inputting the captured image into a detection model DM that utilizes artificial intelligence. The detection model DM can be prepared, for example, within or outside the system 10 and pre-stored in the memory 202 of the server device 200. An example of the detection model DM is a machine learning model that has been learned to achieve either semantic segmentation or instance segmentation. For example, a convolutional neural network (CNN) learned through supervised learning using a training dataset can be used as this machine learning model. The training dataset, for example, includes multiple training images containing the vehicle 100 and labels indicating whether each region in the training image represents the vehicle 100 or represents a region other than the vehicle 100. When learning the CNN, back-propagation (error back propagation) is preferably used to update the CNN parameters in a manner that reduces the error between the output of the detection model DM and the label. Furthermore, the remote control unit 210 can estimate the direction of the vehicle 100's motion vector, calculated from the positional changes of the vehicle's 100 feature points between captured image frames, using, for example, optical flow methods. This allows the remote control unit 210 to determine the vehicle's 100 orientation.

[0028] In step S2, the remote control unit 210 determines the target position to which the vehicle 100 should go next. In the present embodiment, the target position is represented by the X, Y, and Z coordinates in the global coordinate system GC. In the memory 202 of the server device 200, a reference path RR, which is the path that the vehicle 100 should travel, is pre-stored. The path is represented by a node indicating the departure point, a node indicating a waypoint, a node indicating the destination, and links connecting the nodes. The remote control unit 210 uses the vehicle position information and the reference path RR to determine the target position to which the vehicle 100 should go next. The remote control unit 210 determines the target position on the reference path RR that is further ahead than the current position of the vehicle 100.

[0029] In step S3, the remote control unit 210 generates a driving control signal for driving the vehicle 100 toward the determined target position. The remote control unit 210 calculates the driving speed of the vehicle 100 based on the change in the position of the vehicle 100 and compares the calculated driving speed with the target speed. Generally speaking, the remote control unit 210 determines the acceleration so as to accelerate the vehicle 100 when the driving speed is lower than the target speed, and determines the acceleration so as to decelerate the vehicle 100 when the driving speed is higher than the target speed. In addition, when the vehicle 100 is on the reference path RR, the remote control unit 210 determines the steering angle and acceleration so as to prevent the vehicle 100 from deviating from the reference path RR. When the vehicle 100 is not on the reference path RR, in other words, when the vehicle 100 has deviated from the reference path RR, the remote control unit 210 determines the steering angle and acceleration so as to return the vehicle 100 to the reference path RR.

[0030] In step S4, the remote control unit 210 transmits the generated travel control signal to the vehicle 100. The remote control unit 210 repeatedly acquires the position of the vehicle 100, determines the target position, generates and transmits the travel control signal in a predetermined cycle.

[0031] In step S5, the vehicle control unit 115 receives the driving control signal transmitted from the server device 200. In step S6, the vehicle control unit 115 uses the received driving control signal to control the actuator group 120, thereby causing the vehicle 100 to travel at the acceleration and steering angle indicated by the driving control signal. The vehicle control unit 115 repeatedly receives the driving control signal and controls the actuator group 120 at a predetermined cycle. According to the system 10 of this embodiment, the vehicle 100 can be driven by remote control, and the vehicle 100 can be moved without using transportation equipment such as cranes and conveyors.

[0032] A-3. Update Process: Figure 4 This is a flowchart illustrating the flow of the update process in the first embodiment. The "update process" is a process for updating the software stored in the vehicle 100 in response to a request from the terminal device 500. When the user inputs a preset start operation, the terminal device 500 outputs the aforementioned authentication information. The update process begins when the authentication information is output from the terminal device 500.

[0033] In step S102 , the determination unit 116 acquires the authentication information output from the terminal device 500 .

[0034] In step S104, the determination unit 116 determines whether the vehicle 100 is in an environment where software updates are possible. "Software updates are possible" refers to an environment that has been pre-set so that even if a software update is performed, the control of the vehicle 100 will not be disturbed. For example, if an environment is set where "the vehicle 100 is stopped and the software to be updated is not in use," the determination unit 116 determines that the vehicle 100 is in an environment where software updates are possible if the current environment of the vehicle 100 matches this. If it is determined that the vehicle 100 is not in an environment where software updates are possible (step S104: No), in step S120, the permission unit 117 does not permit the software update, and the update process ends.

[0035] When it is determined that the vehicle 100 is in an environment where the update is possible (step S104: Yes), in step S106, the determination unit 116 determines whether the vehicle 100 can perform the determination of step S108 described later. As described later, in this embodiment, the determination is performed using the position information of the vehicle 100 in step S108. "The position information of the vehicle 100" is information related to the vehicle 100 that has become the object of the update, and is equivalent to the "update object information" in this disclosure. In step S106, when the vehicle 100 has grasped its own position information, the determination unit 116 determines that the vehicle 100 can perform the determination of step S108. "The case where the vehicle 100 has grasped its own position information" is, for example, a case where the vehicle 100 receives and stores the driving control signal and the position information of the vehicle 100 together, or a case where the vehicle 100 is equipped with a position sensor such as a GPS sensor and detects the position information of the vehicle 100 using the position sensor.

[0036] If the vehicle 100 determines that the determination is possible (step S106: Yes), in step S108, the determination unit 116 determines whether the vehicle 100 is located within the factory FC. "Within the factory FC" corresponds to the "predetermined area" in this disclosure. Furthermore, "the vehicle 100 is located within the factory FC" corresponds to the "predetermined condition" in this disclosure.

[0037] If the vehicle 100 determines that the determination cannot be made (step S106: No), the determination unit 116 inquires the server device 200 in step S110. Upon receiving the inquiry, the response unit 211 in the server device 200 returns the aforementioned vehicle location information to the determination unit 116. Alternatively, instead of returning the vehicle location information, the response unit 211 may return the result of determining whether the vehicle 100 is located within the factory FC using the vehicle location information to the determination unit 116. The determination unit 116 then executes step S108.

[0038] When it is determined that the vehicle 100 is located in the factory FC (step S108: Yes), in step S112, the determination unit 116 determines whether the authentication information satisfies the first authentication condition. Here, "determining whether the authentication information satisfies the first authentication condition" is equivalent to the determination based on the "first method" in the present disclosure. In the present embodiment, as the first authentication condition, the determination unit 116 determines whether the login password is correct. In addition, instead of determining whether the login password is correct, the determination unit 116 may determine whether the user of the terminal device 500 has the software update permission, or whether the terminal device 500 has been identified as a device capable of performing software updates. "Determining that the vehicle 100 is located in the factory FC" is equivalent to the "first case" in the present disclosure.

[0039] If it is determined that the first authentication condition is satisfied (step S112: YES), in step S116, the permission unit 117 permits the terminal device 500 to update the software. In step S118, the update unit 118 updates the software in accordance with the updated content of the software on the terminal device 500. The update process then ends.

[0040] If it is determined that the first authentication condition is not satisfied (step S112: No), in step S120, the permission unit 117 does not permit the software update. Thereafter, the update process ends.

[0041] In the case where it is determined in the above-mentioned step S108 that the vehicle 100 is not located in the factory FC (step S108: No), in step S114, the determination unit 116 determines whether the authentication information satisfies the second authentication condition. Here, "determining whether the authentication information satisfies the second authentication condition" is equivalent to the determination based on the "second method" in the present disclosure. In this embodiment, as the second authentication condition, the determination unit 116 determines whether the login password is correct, whether the user of the terminal device 500 has the permission to update the software, and whether the terminal device 500 has been identified as a device capable of performing software updates. That is, the second authentication condition has more conditions to be met than the first authentication condition. Therefore, it can be considered that the second authentication condition has a higher security level than the first authentication condition, and the second method using the second authentication condition has a higher security level than the first method using the first authentication condition. "Determining that the vehicle 100 is not located in the factory FC" is equivalent to the "second case" in the present disclosure.

[0042] If it is determined that the second authentication condition is satisfied (step S114: Yes), the above-mentioned steps S116 and S118 are executed, and the update process ends.

[0043] If it is determined that the second authentication condition is not satisfied (step S112: No), the above-mentioned step S120 is executed, and the update process ends.

[0044] As described above, in this embodiment, when it is determined that vehicle 100 is located within the factory FC, authentication is performed using the first authentication condition, which has a lower security level than the second authentication condition used when it is determined that vehicle 100 is not located within the factory FC. This is because, when vehicle 100 is located within the factory FC, it is assumed that only those who wish to perform a software update are factory FC workers, etc., resulting in a lower security risk compared to when vehicle 100 is located outside the factory FC. In other words, generally speaking, determination unit 116 appropriately distinguishes between the first method using the first authentication condition and the second method using the second authentication condition based on pre-set conditions associated with the security risk associated with the software update. Furthermore, when vehicle 100 is located within the factory FC and a software update is attempted, it is assumed that this is intended to correct a problem that may have occurred during the vehicle 100's manufacturing process, requiring a swift response.

[0045] According to the system 10 of the first embodiment described above, when the vehicle 100 is determined to be located within the factory FC, a first authentication condition is determined as an authentication condition. When the vehicle 100 is determined not to be located within the factory FC, a second authentication condition, which has a higher security level than the first authentication condition, is determined as an authentication condition. Therefore, when the vehicle 100 is determined to be located within the factory FC, authentication can be easily performed using the first authentication condition, which has a lower security level than the second authentication condition, thereby minimizing the time required for software updates. Furthermore, when the vehicle 100 is determined not to be located within the factory FC, authentication can be performed using the second authentication condition, which has a higher security level than the first authentication condition. This reduces the security degradation compared to a system that always performs authentication using the first authentication condition.

[0046] Furthermore, the first authentication condition and the second authentication condition can be appropriately distinguished and used depending on whether the vehicle 100 is located in the factory FC.

[0047] B. Second embodiment: Figure 5 : is a flowchart showing the flow of the update process in the second embodiment. Figure 5 As shown, the difference between the system 10 of the second embodiment and the system 10 of the first embodiment is that, in the update process, step S108a is executed instead of step S108. Since the device configuration and other processes in the update process of the system 10 of the second embodiment are the same as those of the system 10 of the first embodiment, the same components and processes are denoted by the same reference numerals, and detailed descriptions are omitted.

[0048] exist Figure 5In step S106 shown, the determination unit 116 determines whether the vehicle 100 side can perform the determination of step S108a described later. As will be described later, in this embodiment, in step S108a, the determination is performed according to the purpose of the software to be updated. The "purpose of the software to be updated" is information related to the software to be updated, which is equivalent to the "update object information" in this disclosure. In step S106 of this embodiment, when the software for controlling the vehicle 100 is stored in the memory 112 of the vehicle 100 in a manner that can identify its purpose, the determination unit 116 determines that the vehicle 100 side can perform the determination of step S108a. "The software for controlling the vehicle 100 is stored in a manner that can identify its purpose" means, for example, a case where a database that manages the purpose of each software is pre-stored in the memory 112, or a case where the extension of each software is pre-set according to the purpose of each software.

[0049] When it is determined that the vehicle 100 side is capable of making the determination (step S106: Yes), in step S108a, the determination unit 116 determines whether the purpose of the software to be updated is for factory use. Here, "the purpose of the software to be updated is for factory use" means that the software is used when the vehicle 100 is in the factory FC and is not used when the vehicle 100 is outside the factory FC. More specifically, as "software that is used when the vehicle 100 is in the factory FC and is not used when the vehicle 100 is outside the factory FC", software that is used to implement various functions for component assembly processes and inspection processes performed in the manufacturing process of the vehicle 100 is qualified, and does not include functions that can be used by users of the vehicle 100 after the vehicle 100 leaves the factory, such as software for implementing object detection functions using on-board sensors.

[0050] For example, if the application of the software to be updated is set as factory use in the database, or if the extension of the software to be updated is the same as an extension pre-set as indicating factory use, the determination unit 116 determines that the application of the software is factory use. "The application of the software to be updated is factory use" corresponds to the "pre-set condition" in this disclosure.

[0051] If the vehicle 100 determines that the determination cannot be made (step S106: No), in step S110, the determination unit 116 inquires the server device 200. Upon receiving the inquiry, the response unit 211 in the server device 200 responds to the determination unit 116 regarding the purpose of the software to be updated. The response unit 211 determines the purpose of the software to be updated by, for example, referencing a pre-stored database that manages the purpose of each software program and responds to the determination unit 116 with the determined purpose. Alternatively, instead of responding with the purpose of the software to be updated, the response unit 211 may respond to the determination unit 116 with a response indicating whether the software is intended for factory use. The determination unit 116 then executes step S108a described above.

[0052] If it is determined that the software to be updated is intended for factory use (step S108a: Yes), the determination unit 116 executes the aforementioned step S112. "The case where the software to be updated is determined to be intended for factory use" corresponds to the "first case" in this disclosure. On the other hand, if it is determined that the software to be updated is not intended for factory use (step S108a: No), the determination unit 116 executes the aforementioned step S114. "The case where the software to be updated is determined to be not intended for factory use" corresponds to the "second case" in this disclosure.

[0053] As described above, in this embodiment, when the software to be updated is determined to be factory-use, authentication is performed using the first authentication condition, which has a lower security level than the second authentication condition used when the software to be updated is determined not to be factory-use. This is because, since the software to be updated is not used by the user of vehicle 100 when the software to be updated is factory-use, the software update is considered to have a minimal impact on the user of vehicle 100. Furthermore, when factory-use software is updated, it is considered to be intended to correct certain problems that may have occurred during the manufacturing process of vehicle 100, requiring a quick response.

[0054] According to the system 10 of the second embodiment described above, when the software to be updated is determined to be for factory use, the first authentication condition is determined as an authentication condition. When the software to be updated is determined not to be for factory use, the second authentication condition, which has a higher security level than the first authentication condition, is determined as an authentication condition. Therefore, it is possible to appropriately distinguish between the first and second authentication conditions depending on whether the software to be updated is for factory use.

[0055] C. Third embodiment: Figure 6This is a block diagram illustrating the configuration of a system 10v in a third embodiment. This embodiment differs from the first embodiment in that the system 10v does not include a server device 200. Furthermore, the vehicle 100v in this embodiment is capable of autonomous driving. Unless otherwise specified, all other configurations are the same as those in the first embodiment.

[0056] In this embodiment, the processor 111v of the vehicle control device 110v executes a program PG1 stored in the memory 112v to function as a vehicle control unit 115v, a determination unit 116, a permission unit 117, and an update unit 118. The vehicle control unit 115v uses vehicle position information to generate a travel control signal and outputs the generated travel control signal to activate the actuator group 120, thereby enabling the vehicle 100v to travel under autonomous control. In this embodiment, in addition to pre-stored program PG1, the memory 112v also pre-stores a detection model DM and a reference route RR.

[0057] Similar to the vehicle control device 110 of the first embodiment, the vehicle control device 110v of this embodiment functions as a determination unit 116, a permission unit 117, and an update unit 118. When the authentication information satisfies the authentication conditions, the vehicle control device 110v of this embodiment updates the software stored in the vehicle 100. In other words, the vehicle control device 110v of this embodiment corresponds to the "update device" in this disclosure.

[0058] In this embodiment, since system 10v does not include server device 200, if the vehicle 100 determines during the update process that the authentication information cannot be determined (step S106: No), determination unit 116 may not perform step S110 and determine whether the authentication information satisfies the second authentication condition. This method allows software to be updated as long as the first authentication condition, which has a lower security level than the second authentication condition, is satisfied, if the vehicle 100 can make the authentication (step S106: Yes) and the vehicle 100 is located within the factory FC (step S108: Yes). This achieves the same advantages as the above-described embodiment.

[0059] Figure 7 1 is a flowchart showing the processing flow of the driving control of the vehicle 100v in the third embodiment. In step S11, the processor 111v obtains the vehicle position information using the detection result output from the camera as the external sensor 300. In step S11 of this embodiment, Figure 3Similar to step S1, the processor 111v acquires vehicle position information using the captured image and vehicle speed. In step S12, the processor 111v determines the target location to which the vehicle 100v should next proceed. In step S13, the processor 111v generates a travel control signal for causing the vehicle 100v to travel toward the determined target location. In step S14, the processor 111v uses the generated travel control signal to control the actuator group 120, thereby causing the vehicle 100v to travel according to the parameters indicated by the travel control signal. The processor 111v repeats the acquisition of vehicle position information, determination of the target location, generation of the travel control signal, and control of the actuator group 120 at a predetermined cycle. According to the system 10v of this embodiment, the vehicle 100v can be driven autonomously even without remote control of the vehicle 100v by the server device 200. Furthermore, according to the system 10v of this embodiment, as in the above-mentioned embodiment, it is possible to appropriately distinguish between the use of the first authentication condition and the second authentication condition, thereby preventing an increase in the time required for software updates and a decrease in security.

[0060] D. Other implementation methods: (D1) In the above embodiment, the determination unit 116, the permission unit 117, and the update unit 118 are included in the vehicle control device 110, but the present disclosure is not limited to this. The determination unit 116, the permission unit 117, and the update unit 118 may also be included in the server device 200. In this embodiment, the server device 200 corresponds to the "update device" in the present disclosure. In addition, when the server device 200 functions as the update device, steps S106 and S110 of the update process do not need to be executed. If the determination in step S104 is "yes", step S108 is executed.

[0061] (D2) In the above embodiment, the determination unit 116 determines whether the vehicle 100 is located in the factory FC using the position information of the vehicle 100, but the present disclosure is not limited to this. The determination unit 116 may also determine whether the vehicle 100 is located in the factory FC using the above process information. For example, the determination unit 116 may also determine whether the vehicle 100 is located in the factory FC based on whether the vehicle 100 is in a process before a pre-set process. More specifically, when the process information of the vehicle 100 determines that the vehicle 100 is in a process before the final inspection process, the determination unit 116 may determine that the vehicle 100 is located in the factory FC. On the other hand, when the process information of the vehicle 100 determines that the vehicle 100 is in a process after the final inspection process, the determination unit 116 may determine that the vehicle 100 is not located in the factory FC. In this embodiment, if the process information is not stored in the memory 112 of the vehicle 100, the determination unit 116 may inquire about the process information from the process management device 400 in step S110 instead of inquiring from the server device 200, and obtain the process information from the process management device 400. This embodiment provides the same effects as the above-described embodiment.

[0062] (D3) In the above embodiment, the vehicle 100 may include a first control device storing software for factory use, and a second control device storing software for purposes other than factory use. In this embodiment, the determination unit 116 may, when the software to be updated is stored in the first control device, regard the software as being for factory use and perform authentication through the first authentication condition. On the other hand, when the software to be updated is stored in the second control device, the determination unit 116 may, when the software to be updated is stored in the second control device, regard the software as not being for factory use and perform authentication through the second authentication condition. According to this embodiment, since software for different purposes is stored in different control devices, the management of the software can be facilitated, and the determination of step S108a in the update process of the above-mentioned second embodiment can be facilitated. In this embodiment, the "first control device that executes software for factory use" is equivalent to the "pre-set device" in the present disclosure.

[0063] Alternatively, the vehicle 100 may include a first memory storing software for factory use, and a second memory storing software for purposes other than factory use in the vehicle control device 110. In this manner, when the software to be updated is stored in the first memory, the determination unit 116 may deem the software to be for factory use and perform authentication through the first authentication condition. On the other hand, when the software to be updated is stored in the second memory, the determination unit 116 may deem the software to be for factory use and perform authentication through the second authentication condition. According to this manner, since software for different purposes is stored in different memories, the management of the software can be facilitated, and the determination of step S108a in the update process of the second embodiment described above can be facilitated. Furthermore, in this manner, the "first memory storing software for factory use" is equivalent to the "pre-set device" in the present disclosure.

[0064] (D4) In the above embodiments, the external sensor 300 is a camera. Alternatively, the external sensor 300 may not be a camera, but may be, for example, a distance measuring device. An example of a distance measuring device is LiDAR (Light Detection and Ranging). In this case, the detection result output by the external sensor 300 may be three-dimensional point cloud data representing the vehicle 100. In this case, the server device 200 or the vehicle 100 may obtain vehicle position information by matching the three-dimensional point cloud data obtained as a detection result with a template of pre-prepared reference point cloud data.

[0065] (D5) In the first embodiment described above, the server device 200 performs the processing from acquiring vehicle position information to generating a travel control signal. Alternatively, at least a portion of the processing from acquiring vehicle position information to generating a travel control signal may be performed by the vehicle 100. For example, the following methods (1) to (3) may be employed.

[0066] (1) The server device 200 may obtain vehicle position information, determine a target location to which the vehicle 100 should next go, and generate a route from the current position of the vehicle 100 indicated by the obtained vehicle position information to the target location. The server device 200 may generate a route to the target location between the current position and the destination, or may generate a route to the destination. The server device 200 may transmit the generated route to the vehicle 100. The vehicle 100 may generate a travel control signal so that the vehicle 100 travels along the route received from the server device 200, and may control the actuator group 120 using the generated travel control signal.

[0067] (2) The server device 200 may obtain vehicle position information and transmit the obtained vehicle position information to the vehicle 100. The vehicle 100 may determine a target location to which the vehicle 100 should next go, generate a route from the current location of the vehicle 100 indicated by the received vehicle position information to the target location, generate a travel control signal so that the vehicle 100 travels along the generated route, and control the actuator group 120 using the generated travel control signal.

[0068] (3) In the above-mentioned methods (1) and (2), the vehicle 100 may be equipped with internal sensors, and the detection results outputted from the internal sensors may be used in at least one of the generation of the route and the generation of the driving control signal. The internal sensors are sensors mounted on the vehicle 100. The internal sensors may include, for example, sensors for detecting the motion state of the vehicle 100, sensors for detecting the motion state of each part of the vehicle 100, and sensors for detecting the environment surrounding the vehicle 100. Specifically, the internal sensors may include, for example, cameras, LiDAR, millimeter-wave radars, ultrasonic sensors, GPS sensors, acceleration sensors, gyroscope sensors, etc. For example, in the above-mentioned method (1), the server device 200 may obtain the detection results of the internal sensors and reflect the detection results of the internal sensors in the route when generating the route. In the above-mentioned method (1), the vehicle 100 may obtain the detection results of the internal sensors and reflect the detection results of the internal sensors in the driving control signal when generating the driving control signal. In the above-mentioned method (2), the vehicle 100 may obtain the detection results of the internal sensors and reflect the detection results of the internal sensors in the route when generating the route. In the above-mentioned embodiment (2), the vehicle 100 may obtain the detection results of the internal sensors and reflect the detection results of the internal sensors in the traveling control signal when generating the traveling control signal.

[0069] (D6) In the third embodiment, vehicle 100v may be equipped with internal sensors, and detection results output by the internal sensors may be used in at least one of generating a route and generating a driving control signal. For example, vehicle 100v may obtain detection results from the internal sensors and reflect the detection results in the route when generating a route. Vehicle 100v may obtain detection results from the internal sensors and reflect the detection results in the driving control signal when generating a driving control signal.

[0070] (D7) In the above-described embodiment in which vehicle 100 is capable of autonomous driving, vehicle 100 obtains vehicle position information using detection results from external sensors 300. Alternatively, vehicle 100 may be equipped with internal sensors, and vehicle 100 may obtain vehicle position information using the detection results from the internal sensors, determine a target location to which vehicle 100 should next proceed, generate a route from the current location of vehicle 100 indicated by the obtained vehicle position information to the target location, generate a driving control signal for driving along the generated route, and control the actuators of vehicle 100 using the generated driving control signal. In this case, vehicle 100 can travel without using any detection results from external sensors 300. Furthermore, vehicle 100 may obtain a target arrival time and / or congestion information from outside vehicle 100, and reflect the target arrival time and / or congestion information in at least one of the route and the driving control signal. Furthermore, the functional components of system 10 may all be incorporated into vehicle 100. In other words, the processing implemented by system 10 in this disclosure may be implemented solely by vehicle 100.

[0071] (D8) In the first embodiment described above, the server device 200 automatically generates a driving control signal to be transmitted to the vehicle 100. Alternatively, the server device 200 may generate a driving control signal to be transmitted to the vehicle 100 in response to an operation performed by an external operator located outside the vehicle 100. For example, the external operator may operate an operating device including a display for displaying images captured by the external sensor 300, a steering wheel for remotely operating the vehicle 100, an accelerator pedal, a brake pedal, and a communication device for communicating with the server device 200 via wired or wireless communication, and the server device 200 may generate a driving control signal in accordance with the operation performed on the operating device.

[0072] (D9) In each of the above embodiments, vehicle 100 only needs to be configured to be able to move unmanned. For example, it may be configured as a platform having the following configuration. Specifically, in order to perform the three functions of "driving," "steering," and "stopping" unmanned, vehicle 100 may be equipped with at least a control device, a drive device, a steering device, and actuators such as a braking device to control the movement of vehicle 100. If vehicle 100 acquires information from the outside for unmanned operation, vehicle 100 may also be equipped with a communication device. In other words, a vehicle 100 capable of unmanned operation may not be equipped with at least a portion of interior components such as a driver's seat and instrument panel, at least a portion of exterior components such as bumpers and fenders, or a body shell. In such cases, the remaining components such as the body shell may be assembled to vehicle 100 before it is shipped from the factory FC, or the remaining components such as the body shell may be assembled to vehicle 100 after it is shipped from the factory FC without the remaining components. Each component can be assembled from any direction, such as the top, bottom, front, rear, right, or left side of the vehicle 100. They can be assembled from the same direction or from different directions. Furthermore, the positioning of the gantry can be determined in the same manner as in the vehicle 100 of the first embodiment.

[0073] (D10) The vehicle 100 can also be manufactured by combining multiple modules. A module means a unit composed of one or more components that are aggregated according to the structure and function of the vehicle 100. For example, the platform of the vehicle 100 can be manufactured by combining a front module that constitutes the front part of the platform, a central module that constitutes the center part of the platform, and a rear module that constitutes the rear part of the platform. In addition, the number of modules that constitute the platform is not limited to three, and can also be two or less or four or more. In addition, in addition to the platform, parts of the vehicle 100 that are different from the platform can also be modularized, or parts of the vehicle 100 that are different from the platform can be modularized instead of the platform. In addition, various modules can also include any exterior parts such as bumpers and grilles, and any interior parts such as seats and consoles. In addition, not limited to the vehicle 100, any type of mobile body can be manufactured by combining multiple modules. Such a module can be manufactured, for example, by joining multiple parts using welding or fixings, or by integrally molding at least a part of the module into a single part using casting. The method of integrally molding at least a portion of a module into a single component is also known as giga-casting or mega-casting. Giga-casting allows components of a moving object, which were previously formed by joining multiple components, to be formed into a single component. For example, the front, center, and rear modules described above can also be manufactured using giga-casting.

[0074] (D11) Transporting a vehicle 100 by using the unmanned driving of the vehicle 100 is also referred to as "self-propelled transport." Furthermore, a configuration for implementing self-propelled transport is also referred to as a "vehicle remote-controlled autonomous transport system." Furthermore, a production method utilizing self-propelled transport to produce vehicles 100 is also referred to as "self-propelled production." In self-propelled production, for example, in a factory FC that manufactures vehicles 100, at least a portion of the transport of the vehicle 100 is accomplished by self-propelled transport.

[0075] (D12) In each of the above embodiments, some or all of the functions and processes implemented by software may also be implemented by hardware. Furthermore, some or all of the functions and processes implemented by hardware may also be implemented by software. Hardware for implementing the various functions in each of the above embodiments may include, for example, integrated circuits and discrete circuits.

[0076] The present disclosure is not limited to the above-mentioned embodiments and can be implemented in various configurations without departing from its main purpose. For example, the technical features of the embodiments corresponding to the technical features of the various methods described in the "Summary of the Invention" section can be appropriately replaced or combined in order to solve part or all of the above-mentioned problems or to achieve part or all of the above-mentioned effects. In addition, as long as the technical features are not described as essential parts in this specification, they can be appropriately deleted. Description of Reference Numerals

[0077] 10, 10v…system; 100, 100v…vehicle; 110, 110v…vehicle control device; 111, 111v…processor; 112, 112v…memory; 113…input / output interface; 114…internal bus; 115, 115v…vehicle control unit; 116…judgment unit; 117…permission unit; 118…update unit; 120…actuator group; 130…communication device; 200…server device; 201…processor; 202…memory; 203…input / output interface; 204…internal bus; 205…communication device; 210…remote control unit; 300…external sensor; 400…process management device; 500…terminal device; DM…detection model; FC…factory; GC…global coordinate system; PG1…program; PG2…program; PL1…first location; PL2…second location; RR…reference path; TR…driving road.

Claims

1. An updating device for updating software stored in a mobile object. The updating device includes a determination unit for determining whether the software can be updated. The determination unit obtains update target information which is information related to at least one of the software and the mobile object. In a first case where the update target information satisfies a pre-set condition, determining whether the update is possible is performed using a first method. In a second case where the update target information does not satisfy the preset condition, whether the update is permitted is determined by a second method having a higher security level than the first method.

2. The updating device according to claim 1, wherein: The preset condition includes that the moving object is located in a preset area.

3. The updating device according to claim 1, wherein: The predetermined condition includes that the software is used when the moving object is within a predetermined area.

4. The updating device according to claim 1 or 3, wherein: The pre-set condition includes that the software is stored in a pre-set device.

Citation Information

Patent Citations

  • Method for operating a vehicle and method for operating a manufacturing system

    JP2017538619A