Software update management device and software update management method

By setting up a software update management device in the vehicle and storing update recommendation information corresponding to the vehicle control unit, the problem of difficulty in judging the update suitability of different control units is solved, and safety and reliability are improved.

CN120704703APending Publication Date: 2025-09-26HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510190186.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-26
Filing Date
2025-02-20
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

In vehicles, the suitability of software updates varies depending on the type of control device, making it difficult to determine whether software updates should be performed, which affects traffic safety.

Method used

By installing a software update management device in a vehicle, update recommendation information corresponding to the vehicle control unit is stored, including vehicle status and conditions suitable for update, and software update is recommended when appropriate.

Benefits of technology

It improves the security of software updates, avoids difficulties caused by inappropriate updates, and enhances the safety and reliability of transportation systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120704703A_ABST
    Figure CN120704703A_ABST
Patent Text Reader

Abstract

The invention provides a software update management device and a software update management method, and aims to improve security by updating software under appropriate conditions. The software update management device is provided with: a storage unit that associates and stores update recommendation information, which includes conditions for recommending update of software for a vehicle control unit, with the vehicle control unit mounted on a vehicle; and a recommendation processing unit that recommends an update of the software on the basis of a condition of the update recommendation information including a vehicle condition relating to a state of the vehicle and a condition condition indicating a condition suitable for the update of the software.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a software update management device and a software update management method. Background Art

[0002] In recent years, research and development efforts have been underway to improve transportation safety and energy efficiency, ensuring that more people use reliable, sustainable, and advanced energy sources. For example, Patent Document 1 discloses a technology in which a vehicle downloads and updates software for an onboard control device from a server. In the structure of Patent Document 1, the update process begins when the user agrees to start the software update. If the user does not respond, the system determines whether to start the update process based on the time required for the update process.

[0003] [Prior art literature]

[0004] [Patent Document]

[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2023-018282 Summary of the Invention

[0006] [Problems to be Solved by the Invention]

[0007] However, there is a problem in that various types of control devices are mounted on vehicles, and whether or not software updates are suitable varies depending on the type of control device, making it difficult to determine whether software updates should be performed.

[0008] In order to solve the above-mentioned problems, the present application aims to improve safety by updating software under appropriate circumstances, and further contribute to the development of a sustainable transportation system that further improves traffic safety.

[0009] [Means for solving the problem]

[0010] One embodiment of the present disclosure is a software update management device comprising: a storage unit that stores update recommendation information corresponding to a vehicle control unit mounted on a vehicle, the update recommendation information including conditions for recommending an update of the software of the vehicle control unit; and a recommendation processing unit that recommends an update of the software based on the conditions of the update recommendation information, the conditions of the update recommendation information including vehicle conditions related to a state of the vehicle and condition conditions indicating a condition suitable for an update of the software.

[0011] Another embodiment of the present disclosure is a software update management method, which includes the following processing performed by a computer that manages vehicle software updates: updating recommendation information is stored corresponding to a vehicle control unit mounted on the vehicle, the update recommendation information includes conditions for recommending updating the software of the vehicle control unit, the conditions of the update recommendation information include vehicle conditions related to the state of the vehicle and condition conditions indicating conditions suitable for updating the software, and the software update is recommended based on the conditions of the update recommendation information.

[0012] [Effects of the Invention]

[0013] According to one aspect of the present disclosure, based on the update recommendation information stored corresponding to the vehicle control unit, it is recommended to update the software of the vehicle control unit under appropriate circumstances, thereby achieving further improvement in safety. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 It is a diagram showing a configuration example of a software updating system.

[0015] Figure 2 It is a diagram showing the structure of a vehicle.

[0016] Figure 3 : is a schematic diagram showing an example of updating recommendation information.

[0017] Figure 4 This is a flowchart showing an example of the operation of the management ECU.

[0018] Figure 5 This is a flowchart showing an example of the operation of the management ECU. DETAILED DESCRIPTION

[0019] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.

[0020] [1. Structure of the software update system]

[0021] Figure 1 1 is a diagram showing a configuration example of a software updating system 3 related to updating of software of a vehicle 1. The software updating system 3 includes a vehicle control unit 13 ( Figure 2 ) is executed by a software update system 3. Server 2 is communicatively connected to vehicle 1 via a communication network NW. Vehicle 1 downloads software from server 2 to update the software in vehicle control unit 13. In other words, software update system 3 can update vehicle 1 software via OTA (Over The Air).

[0022] Here, updating software refers to the process of replacing the software executed by the processor with a newer version of the software. The specific method can be any of the following: adding, deleting, or overwriting the software. In addition, the process of deleting part or all of the software executed by the processor, installing new software, and deleting, adding, or overwriting the data used when executing the software can also be included in the process of updating the software. In the following description, software includes programs executed by the processor and data that is referenced, generated, updated, deleted, etc. in association with the programs, including firmware.

[0023] Server 2 is connected to communication network NW via a wired or wireless communication line. Vehicle 1 is connected to communication network NW via wireless communication, for example, via a cellular communication base station B. The specific form of communication network NW is not limited. For example, communication network NW may include a cellular communication network, the Internet, a WAN (Wide Area Network), a LAN (Local Area Network), a public line network, a provider device, a dedicated line, a base station, and the like.

[0024] [2. Vehicle structure]

[0025] Figure 2 1 is a diagram showing the structure of the vehicle 1 .

[0026] Vehicle 1 may be any of a four-wheeled vehicle, a two-wheeled vehicle, or other vehicles, and may also be a large vehicle, a commercial vehicle, or a work vehicle. As an example, this embodiment assumes a four-wheeled vehicle for description. Furthermore, vehicle 1 may be any of an electric vehicle equipped with a motor driven by electricity as a driving source, and a vehicle equipped with an internal combustion engine. The internal combustion engine may function as a power source for driving vehicle 1, or may be a power generation device that drives a generator.

[0027] The vehicle 1 includes a plurality of devices 11 that realize the functions of the vehicle 1. Each device 11 includes a vehicle control unit 13 that controls the device 11. The vehicle control unit 13 is, for example, an ECU (Electronic Control Unit) and controls the device 11 by executing a program.

[0028] In this embodiment, the vehicle 1 transitions between three operating states: ignition-on, ignition-off, and stopped. The ignition-on state refers to the state in which the motor or internal combustion engine, which is the driving source of the vehicle 1, is operating. The state in which the motor is operating is not limited to the state in which the motor is rotating. It also includes the state in which power can be supplied to the motor from an inverter circuit, etc., and the motor can rotate rapidly in response to an operation such as the driver's accelerator. For example, the ignition-on state can also be referred to as the state in which the inverter circuit is started. The state in which the motor is not rotating during the ignition-on state is sometimes referred to as ignition ready (IG_Ready), but this state is also included in ignition-on. If the vehicle 1 is equipped with an internal combustion engine, the ignition-on state includes the state in which the internal combustion engine is rotating and the state in which the internal combustion engine can be started rapidly. The ignition-off state refers to the state in which the motor or internal combustion engine, which is the driving source of the vehicle 1, is not operating, and power is supplied to at least a portion of the vehicle 1's control devices, including the vehicle control unit 13, so that these control devices are able to operate. The stopped state refers to a state in which power is supplied to the minimum control devices required to shift vehicle 1 to the ignition-off state, and power supply to other control devices and the drive source of vehicle 1 is stopped. For example, the alarm device 11B and door lock device 11C, described later, operate even in the stopped state, and the in-vehicle detection device 11A is deactivated when vehicle 1 is stopped.

[0029] exist Figure 2 , an interior detection device 11A, an alarm device 11B, and a door lock device 11C are shown as examples of the devices 11 included in the vehicle 1 , and are described as the devices 11 without distinguishing them.

[0030] The vehicle interior detection device 11A is a device that detects the presence of people in a vehicle cabin in which the driver and passengers other than the driver are riding in the vehicle 1 .

[0031] The vehicle interior detection device 11A includes a first ECU 13A, to which an interior sensor 25 and an alarm output unit 26 are connected. The first ECU 13A is an example of the vehicle control unit 13. The interior sensor 25 detects the presence of people in the vehicle interior. Examples of the interior sensor 25 include ultrasonic or radar sensors that detect the presence and / or movement of objects in the vehicle interior, weight sensors that detect loads applied to seats in the vehicle 1, infrared sensors that detect people or animals in the vehicle interior, or other sensors. The alarm output unit 26 is a device that generates notifications under the control of the first ECU 13A. The alarm output unit 26 may include a display that displays notifications, an LED (Light Emitting Diode) or other indicator light that illuminates during notifications, or a speaker that outputs notification sounds. The alarm output unit 26 may also be a communication device equipped with communication capabilities that outputs alarms by transmitting signals, data, or sounds to pre-set destinations under the control of the first ECU 13A. The first ECU 13A is an example of a first vehicle control unit.

[0032] The first ECU 13A includes a processor 130 and a memory 135. The memory 135 is a nonvolatile storage device composed of a magnetic storage medium or a semiconductor storage element, and stores a control program 136 executed by the processor 130 and data referenced, generated, or processed when the control program 136 is executed.

[0033] The processor 130 functions as a vehicle interior detection unit 131 by executing a control program 136. The vehicle interior detection unit 131 initiates detection using the interior sensor 25 when the vehicle 1 transitions from the ignition-on state to the ignition-off state. If the vehicle interior detection unit 131 detects the presence of a person inside the interior of the vehicle 1 during the detection operation, the alarm output unit 26 issues a notification. The interior detection device 11A is used, for example, to prevent situations such as children and pets from being left inside the interior of the vehicle 1.

[0034] The alarm device 11B is a device that detects vibrations of the vehicle 1, suspicious approach or contact with the vehicle 1, or a person approaching another vehicle 1 while the vehicle 1 is stopped or parked, and outputs an alarm. The alarm device 11B operates when the vehicle 1 is stopped.

[0035] The alarm device 11B includes a second ECU 13B, to which are connected an exterior sensor 27, a camera 28, and an alarm output unit 29. The second ECU 13B is an example of the vehicle control unit 13. The exterior sensor 27 is a sensor outside the vehicle 1 that detects people or objects approaching the periphery of the vehicle 1. The exterior sensor 27 may also be a sensor that detects contact with the vehicle 1. Examples of the exterior sensor 27 include ultrasonic sensors, vibration sensors, and radar sensors. The camera 28 is a digital camera outside the vehicle 1 that captures images of the periphery of the vehicle 1, capturing both moving and still images. The alarm output unit 29 is a device that outputs an alarm under the control of the second ECU 13B. The alarm output unit 29 includes, for example, a display that displays notifications, an LED indicator or other indicator light that illuminates during notifications, and a speaker that outputs notification sounds. The alarm output unit 29 may be a shared device with the alarm output unit 26 or a separate device. The alarm output unit 29 may be a communication device having a communication function, and outputs an alarm by transmitting a signal, data, sound, etc. to a predetermined destination under the control of the second ECU 13B. The second ECU 13B is an example of a second vehicle control unit.

[0036] The second ECU 13B includes a processor 150 and a memory 155. The memory 155 is a nonvolatile storage device composed of a magnetic storage medium or a semiconductor memory element. The memory 155 stores a control program 156 executed by the processor 150 and data referenced, generated, or processed when executing the control program 156. For example, the memory 155 stores setting data 157.

[0037] The processor 150 functions as an alarm control unit 151 by executing a control program 156. The alarm control unit 151, triggered by the vehicle 1 coming to a stop, initiates detection using at least one of the exterior sensor 27 and the camera 28. During this detection process, the alarm control unit 151 analyzes the detection results of the exterior sensor 27 and the images captured by the camera 28. By comparing the analysis results with the setting data 157, the alarm control unit 151 detects suspicious movements against the vehicle 1, vibrations of the vehicle 1, and the like. Upon detecting suspicious movements against the vehicle 1 or vibrations of the vehicle 1, the alarm control unit 151 issues a notification via the alarm output unit 29 and stores the images captured by the camera 28 in the memory 155. The alarm device 11B is used, for example, to prevent damage to the vehicle 1 while it is parked or stopped, or to prevent theft.

[0038] The door lock device 11C is a device that controls the locking and unlocking of the opening and closing parts of the vehicle 1. The opening and closing parts include doors that are provided on the side of the vehicle body 1 and are opened and closed when the passengers are raised or lowered, rear doors provided at the rear of the vehicle body, a trunk lid, etc. The door lock device 11C is provided with a locking mechanism (not shown) on the opening and closing parts to lock the opening and closing parts so that the opening and closing parts are not opened, and the locking drive unit 32 that operates the locking mechanism is controlled by the third ECU 13C. The locking drive unit 32 is a power device that locks and unlocks the locking mechanism, such as an actuator or a motor. The door lock device 11C operates when the ignition is on, the ignition is off, and the vehicle 1 is stopped. The third ECU 13C is an example of a third vehicle control unit.

[0039] The camera 30 and the sensor 31 are connected to the third ECU 13C. The camera 30 is a digital camera on the outside of the vehicle 1 that captures the surroundings of the vehicle 1, capturing dynamic images or still images. The camera 30 may be a device shared with the camera 28, or may be provided separately from the camera 28. The sensor 31 is a device that detects operations performed by the occupant on the vehicle 1. The sensor 31 includes, for example, a touch sensor that detects contact operations on the door handle of the vehicle 1. In addition, the sensor 31 may also include a wireless communication device that wirelessly communicates with a FOB key or a smartphone held by the occupant. In addition, the sensor 31 may also include a switch that detects the insertion of a key (physical key) held by the occupant into a keyhole provided in the opening and closing portion of the vehicle 1 to physically lock and unlock the lock.

[0040] The third ECU 13C includes a processor 170 and a memory 175. The memory 175 is a nonvolatile storage device composed of a magnetic storage medium or a semiconductor memory element. The memory 175 stores a control program 176 executed by the processor 170 and data referenced, generated, or processed when executing the control program 176. For example, the memory 175 stores setting data 177.

[0041] The processor 170 functions as a door lock control unit 171 by executing a control program 176. The door lock control unit 171 performs image input for the vehicle 1 and locks and unlocks the vehicle 1 using a fob key or physical key. The door lock control unit 171 receives images captured by the camera 30, compares them with the setting data 177, and analyzes them. When it detects that a person pre-registered as a user of the vehicle 1 intends to board the vehicle 1, it activates the lock driver 32 to unlock the vehicle 1's door opening and closing. Furthermore, when the sensor 31 detects an unlocking operation by a passenger of the vehicle 1, the door lock control unit 171 activates the lock driver 32 to unlock the vehicle 1's door opening and closing. Furthermore, when the sensor 31 detects a locking operation by a passenger of the vehicle 1, the door lock control unit 171 activates the lock driver 32 to lock the vehicle 1's door opening and closing.

[0042] The vehicle 1 includes a management ECU 10. The management ECU 10 manages software updates of a vehicle control unit 13 included in the vehicle 1. Figure 2 In the example shown in FIG. 1 , the management ECU 10 manages the updating of programs executed by the first ECU 13A, the second ECU 13B, and the third ECU 13C and data processed during the execution of the programs. The management ECU 10 is an example of a software update management device.

[0043] The management ECU 10 is connected to a TCU (Telematics Control Unit) 21, a display 22, a touch sensor 23, and a GNSS (Global Navigation Satellite System) 24. The TCU 21 is a communication device that complies with the communication standards of a mobile communication system and communicates with devices outside the vehicle 1. The TCU 21 includes, for example, an antenna, a transmitter, and a receiver, and performs communications under the control of the management ECU 10.

[0044] The display 22 includes a liquid crystal display panel and an organic EL (electroluminescence) panel, and displays text and images. The display 22 is installed, for example, on the instrument panel of the vehicle 1. The touch sensor 23 is positioned superimposed on the display screen of the display 22 to detect touch operations by a passenger of the vehicle 1. The GNSS 24 measures the position of the vehicle 1 by receiving radio signals transmitted from satellites.

[0045] The management ECU 10 includes a processor 110 and a memory 120. The memory 120 is a non-volatile storage device composed of a magnetic storage medium and a semiconductor storage element, and stores a control program 121 executed by the processor 110. In addition, the memory 120 stores device information 122 and update recommendation information 123. The device information 122 includes information related to the devices 11 equipped in the vehicle 1 and the vehicle control unit 13 that controls the devices 11. The device information 122 includes, for example, the version, last update date, size, etc. of the program executed by the vehicle control unit 13 and the data used by the vehicle control unit 13 for each device 11. The update recommendation information 123 will be described later. The memory 120 is equivalent to an example of a storage unit.

[0046] The processor 110 functions as a program management unit 111 and a recommendation processing unit 112 by executing the control program 121 .

[0047] The program management unit 111 manages updates of programs executed by the vehicle control unit 13 and data processed by the vehicle control unit 13 .

[0048] Specifically, the program management unit 111 detects the version of the control program 136 and, if a new version of the control program 136 is available from the server 2, updates the control program 136. In this case, the program management unit 111 downloads update data D1 for updating the control program 136 from the server 2. The program management unit 111 updates the control program 136 using the downloaded update data D1 in response to an operation by an occupant of the vehicle 1.

[0049] Furthermore, the program management unit 111 detects the versions of the control program 156 and the setting data 157. If a new version of the control program 156 and / or the setting data 157 is available from the server 2, the program management unit 111 updates the control program 156 and / or the setting data 157. In this case, the program management unit 111 downloads update data D1 for updating the control program 156 and / or the setting data 157 from the server 2. The program management unit 111 uses the downloaded update data D1 to update the control program 156 and / or the setting data 157 in response to an operation by an occupant of the vehicle 1. The program management unit 111 performs the same process for the control program 176 and the setting data 177.

[0050] If the program management unit 111 is able to execute the software update for the vehicle control unit 13, the recommendation processing unit 112 recommends the software update to the occupants of the vehicle 1. For example, the recommendation processing unit 112 causes the display 22 to display a message recommending the software update and a message requesting input regarding whether or not to approve the software update. The recommendation processing unit 112 may cause the display 22 to display information regarding the vehicle control unit 13 that is the target of the software update, or information regarding the devices 11 controlled by the vehicle control unit 13.

[0051] The recommendation processing unit 112 receives an operation on the touch sensor 23 by a passenger of the vehicle 1 in response to a message displayed on the display 22. If the passenger of the vehicle 1 performs an operation to consent to the software update, the recommendation processing unit 112 causes the program management unit 111 to execute the software update. Furthermore, if the passenger of the vehicle 1 performs an operation to disapprove of the software update (a disapproval operation), the recommendation processing unit 112 suspends the recommended software update for a predetermined period of time.

[0052] The recommendation processing unit 112 recommends to the occupant of the vehicle 1 that the software of the vehicle control unit 13 be updated under a situation that satisfies the conditions of the update recommendation information 123 .

[0053] The update recommendation information 123 includes conditions for recommending an update of the software of the vehicle control unit 13 , and is information stored in the memory 120 in correspondence with the vehicle control unit 13 .

[0054] [3. Update recommended information]

[0055] Figure 3 123 is a schematic diagram showing an example of the update recommendation information 123 .

[0056] Update recommendation information 123 includes conditions related to states or situations suitable for software updates. Recommendation processing unit 112 recommends a software update based on the conditions included in update recommendation information 123. If a passenger of vehicle 1 agrees to the software update, recommendation processing unit 112 causes program management unit 111 to execute the software update if the recommended conditions are met.

[0057] For example, Figure 3 As shown, the update recommendation information 123 includes vehicle conditions, status conditions, and additional conditions. The vehicle conditions are conditions related to the state of the vehicle 1. Specifically, the state of the vehicle 1 refers to the ignition on state (IG_ON), ​​ignition off state (IG_OFF), and stopped state of the vehicle 1.

[0058] The situation conditions in update recommendation information 123 are conditions regarding the situation of vehicle 1. Examples of vehicle 1's situation include the time of the software update and the vehicle's location. Additional conditions are conditions added to the situation conditions. For example, additional conditions are applied when an event occurs that affects the suitability of the software update while the situation conditions are satisfied.

[0059] The update recommendation information 123 is stored in the memory 120 in association with the vehicle control unit 13 to be updated. The update recommendation information 123 includes conditions corresponding to the device 11 controlled by the vehicle control unit 13 .

[0060] exist Figure 3 , update recommendation information 123A, 123B, 123C, and 123D are shown as examples of update recommendation information 123. Update recommendation information 123A is an example of first update recommendation information, update recommendation information 123B and 123C are examples of second update recommendation information, and update recommendation information 123D is an example of third update recommendation information.

[0061] Recommended update information 123A is associated with the first ECU 13A that controls the in-vehicle detection device 11A. Recommended update information 123A includes the condition that the vehicle 1 is in the ignition-off state as a vehicle condition. Recommended update information 123A also includes the condition that 20 minutes have elapsed since the vehicle 1 transitioned to the ignition-off state as a situation condition. The 20 minutes included in recommended update information 123A is the time during which the in-vehicle detection device 11A performs detection operations. In other words, recommended update information 123A recommends that the software of the first ECU 13A be updated after the in-vehicle detection device 11A completes its detection operations.

[0062] The update recommendation information 123A includes additional conditions. These additional conditions are applied when the in-vehicle detection device 11A detects a person, including a timeout period of 50 minutes from the time the ignition is turned off. When the in-vehicle detection device 11A detects a person inside the vehicle, it notifies the user and performs a further 30 minutes of detection after the detection. The 50 minutes included in the additional conditions of the update recommendation information 123A represents the maximum time the in-vehicle detection device 11A can perform detection after detecting a person. In other words, the additional conditions of the update recommendation information 123A recommend that the software of the first ECU 13A be updated after the detection is complete if the in-vehicle detection device 11A detects a person.

[0063] Generally, it is recommended that the vehicle 1 be in the ignition-off or stopped state while updating software related to the device 11 of the vehicle 1. Furthermore, the in-vehicle detection device 11A cannot be operated while the software of the first ECU 13A is being updated. Therefore, it is preferable to update the software related to the in-vehicle detection device 11A while the ignition of the vehicle 1 is not on and there is no difficulty even if the in-vehicle detection device 11A is not operated. To facilitate such software updates, the update recommendation information 123A includes as a condition that the vehicle 1 is in a state where the ignition is not on and there is no difficulty even if the in-vehicle detection device 11A is not operated.

[0064] The update recommendation information 123B and the update recommendation information 123C are associated with the second ECU 13B that controls the alarm device 11 B. The update recommendation information 123B and the update recommendation information 123C include, as a vehicle condition, the condition that the vehicle 1 is in the ignition-off state.

[0065] Recommended update information 123B includes as a condition the condition that the time is outside the predetermined alert period. Recommended update information 123C includes as a condition the condition that the location of vehicle 1 is outside the alert area. Alert periods are periods when there is a high risk of damage or theft of vehicle 1. Alert areas are areas where there is a high risk of damage or theft of vehicle 1. Alert periods and alert areas are determined based on, for example, crime statistics in the area where vehicle 1 is primarily used.

[0066] While the software associated with the alarm device 11B is being updated, an alert based on the alarm device 11B cannot be issued. Therefore, the update recommendation information 123B and the update recommendation information 123C recommend a situation in which the likelihood of not issuing an alert based on the alarm device 11B is low as a situation in which a software update is required. Both the update recommendation information 123B and the update recommendation information 123C are associated with the alarm device 11B and the second ECU 13B. The recommendation processing unit 112 may recommend a software update for the second ECU 13B based on either the update recommendation information 123B or the update recommendation information 123C. Furthermore, the recommendation processing unit 112 may recommend a software update based on both the update recommendation information 123B and the update recommendation information 123C. For example, the recommendation processing unit 112 may recommend a software update when the vehicle conditions and situation conditions of both the update recommendation information 123B and the update recommendation information 123C are met.

[0067] Recommended update information 123D corresponds to the third ECU 13C that controls the door lock system 11C. Recommended update information 123D includes the condition that the vehicle 1 is in the ignition-off state as a vehicle condition. Recommended update information 123D also includes the condition that the vehicle 1 is located within the recommended update area as a situation condition. The recommended update area is an area where the door lock system 11C is less likely to fail to operate during the software update process. For example, if the software update process for the third ECU 13C is executed while the driver of vehicle 1 is out shopping and parked, the driver will be unable to board the vehicle 1 until the update process is complete. On the other hand, if the software update process for the third ECU 13C is executed while the vehicle 1 is parked in the driver's home parking lot, the driver's inconvenience caused by being unable to board the vehicle 1 is less severe. Recommended update information 123D includes conditions for executing the software update for the third ECU 13C in a situation where the driver is less likely to be unable to board the vehicle 1.

[0068] The update recommendation area of ​​the update recommendation information 123D is preferably determined based on the usage status and usage location of the vehicle 1. Therefore, as described later, the recommendation processing unit 112 can generate the update recommendation information 123D based on the usage history of the vehicle 1.

[0069] Although not shown, the update recommendation information 123D may also include a condition specifying a time period during which the door lock device 11C is less likely to fail to operate during the software update process. In this case, the recommendation processing unit 112 recommends that both the time period and the location of the vehicle 1 satisfy the conditions of the update recommendation information 123D.

[0070] The recommended update information 123 may be pre-stored by the management ECU 10, or the management ECU 10 may obtain the recommended update information 123 from the server 2 and store it in the memory 120. Furthermore, the management ECU 10 may generate or edit the recommended update information 123 based on input from the touch sensor 23. Furthermore, the management ECU 10 may generate or edit the recommended update information 123 based on information obtained from the server 2. For example, the management ECU 10 may obtain information related to alert time periods and alert areas from the server 2 and edit or update the recommended update information 123B and 123C based on the obtained information.

[0071] [4. Management ECU Operation]

[0072] Figure 4 as well as Figure 5 : is a flowchart showing an example of the operation of the management ECU 10 . Figure 5 The action is equivalent to an example of a software update management method. Figure 4 Steps S1 to S6 are executed by the recommendation processing unit 112. Figure 5 Steps S11 to S13 and step S19 are executed by the program management unit 111 , and steps S14 to S18 are executed by the recommendation processing unit 112 .

[0073] Figure 4 The operation of generating the update recommendation information 123 based on the usage history of the vehicle 1 is shown. For example, by Figure 4 action to generate update recommendation information 123D.

[0074] The management ECU 10 obtains the history of the position information of the vehicle 1 (step S1). The history of the position information of the vehicle 1 may also be recorded by the management ECU 10. The management ECU 10 may store the history of the position measured by the GNSS 24 in the memory 120 to create a history. In addition, the management ECU 10 may also obtain the history of the position information of the vehicle 1 from the server 2.

[0075] The management ECU 10 determines the location where the vehicle 1's parking time exceeds a threshold time based on the history of the location information acquired in step S1 (step S2). Here, the parking time of the vehicle 1 refers to the time the vehicle 1 remains at the same location, regardless of whether the vehicle 1 is stopped or the ignition is off, for example, regardless of whether the vehicle 1 is parked or stopped.

[0076] The management ECU 10 identifies locations where the parking time of the vehicle 1 exceeds a threshold value with high frequency from the locations determined in step S2 (step S3). The management ECU 10 sets a recommended update area that includes the location determined in step S3 (step S4), and generates recommended update information 123D corresponding to the door lock device 11C, including the set recommended update area (step S5). The management ECU 10 stores the generated recommended update information 123D in the memory 120, corresponding to the door lock device 11C (step S6), and terminates this process.

[0077] Figure 5 An example of the operation of the management ECU 10 updating the software of the vehicle control unit 13 is shown.

[0078] The management ECU 10 checks the software update by communicating with the server 2 (step S11 ). Specifically, in step S11 , the management ECU 10 checks whether the vehicle control unit 13 included in the vehicle 1 is a target for software update based on the device information 122 .

[0079] The management ECU 10 determines whether there is a vehicle control unit 13 to be updated (step S12). If there is no vehicle control unit 13 to be updated (step S12: No), the management ECU 10 returns to step S11 and executes step S11 at a predetermined cycle.

[0080] If a vehicle control unit 13 is present that is subject to software update (step S12: YES), the management ECU 10 identifies the target vehicle control unit 13 (step S13) and retrieves the update recommendation information 123 stored corresponding to the identified vehicle control unit 13 from the memory 120 (step S14).

[0081] The management ECU 10 outputs a recommended software update based on the update recommendation information 123 acquired in step S14 (step S15). In step S15, the management ECU 10 displays, for example, a message on the display 22 recommending the software update and a message requesting approval of the software update. The management ECU 10 may also display, on the display 22, information regarding the vehicle control unit 13 targeted for software update and information regarding the devices 11 controlled by the vehicle control unit 13. Furthermore, if the vehicle 1 is equipped with a speaker, the management ECU 10 may also recommend the software update via voice in step S15.

[0082] The management ECU 10 determines, based on the message displayed on the display 22, whether the occupant of the vehicle 1 has operated the touch sensor 23 to approve the software update (step S16). If the occupant has not operated to approve the software update (step S16: No), the management ECU 10 determines whether the occupant has operated to disapprove of the software update (a disapproval operation) (step S17). If the disapproval operation has not been performed (step S17: No), the management ECU 10 returns to step S16. If the disapproval operation has been performed (step S17: Yes), the management ECU 10 suspends the software update recommendation for a predetermined period (step S18). After the predetermined period, the management ECU 10 returns to step S15 to make the recommendation.

[0083] If the software update is approved (step S16: Yes), the management ECU 10 then executes the software update (step S19) if the conditions indicated by the update recommendation information 123 obtained in step S14 are met. The management ECU 10 may also download the update data D1 from the server 2 before step S19. For example, the management ECU 10 may download the update data D1 from the server 2 during steps S13 to S18.

[0084] Furthermore, if there are multiple vehicle control units 13 identified as targets for software updating in step S13, the management ECU 10 may recommend, in step S15, a software update for each of the multiple vehicle control units 13. Alternatively, the operations of steps S14 to S18 may be performed individually for each of the multiple vehicle control units 13.

[0085] [5. Other Implementation Methods]

[0086] The above-described embodiment is merely one embodiment of the present invention, and can be arbitrarily modified and applied without departing from the spirit of the present invention.

[0087] Figure 2 The structure of the vehicle 1 shown is an example, and the vehicle 1 may also include Figure 2Structure not shown in. For example, the vehicle 1 may also have an ICB (Infotainment Control Box), an MPU (Map Positioning Unit), an MVC (Multi View Camera), a PKS (Parking Support System), an ADAS (Advanced Driver Assistance System) as the device 11. In addition, the vehicle 1 may also have a driving motor, an accelerator, a brake and other controllers for driving the vehicle 1, a VSA (Vehicle Stability Assist) device, a driving battery for the driving motor and the like as the device 11. The vehicle 1 may also have a vehicle control unit 13 that controls each of the above-mentioned devices 11. In addition, the present disclosure can also be applied to Figure 2 The vehicle 1 is shown without part of the device 11 .

[0088] In the above embodiment, the management ECU 10, which includes the program management unit 111 and the recommendation processing unit 112, is described as being provided separately from the vehicle control unit 13 of the control device 11. However, this is merely an example. The specific configuration of the functional units corresponding to the management ECU 10 can be modified as appropriate. For example, any vehicle control unit 13 included in the vehicle 1 may also have the functions of the program management unit 111 and the recommendation processing unit 112 of the management ECU 10. Furthermore, the management ECU 10 may also have the same functions as the vehicle control unit 13.

[0089] Figure 2 The schematic diagrams are provided to distinguish and represent the structure of the vehicle 1 for easy understanding of the present invention. The application of the present invention is not limited to the structures shown in these diagrams. In addition, the processing of each structural element can be performed by one hardware unit or by multiple hardware units. Figure 4 as well as Figure 5 The processing shown may be executed by one program or by a plurality of programs.

[0090] [6. Structure supported by the above-mentioned embodiment]

[0091] The above-mentioned embodiment supports the following structure.

[0092] (Structure 1) A software update management device, which comprises: a storage unit that stores update recommendation information corresponding to a vehicle control unit installed in a vehicle, the update recommendation information including conditions for recommending an update of the software of the vehicle control unit; and a recommendation processing unit that recommends an update of the software based on the conditions of the update recommendation information, the conditions of the update recommendation information including vehicle conditions related to the state of the vehicle and condition conditions indicating conditions suitable for an update of the software.

[0093] The software update management device of Configuration 1 uses update recommendation information that specifies conditions related to software updates for the vehicle control unit. This allows for recommendations for updating the vehicle control unit's software under appropriate circumstances. This avoids the difficulty associated with temporarily unavailable vehicle control units and software updates. This prevents adverse effects associated with software updates, further improving safety.

[0094] (Structure 2) The software update management device according to Structure 1, wherein the vehicle condition includes the vehicle transitioning to an ignition-off state, and the situation condition includes the vehicle situation being a situation suitable for updating the software.

[0095] According to the software update management device of configuration 2, it is possible to recommend that the software be updated when the vehicle is in an ignition-off state and in an appropriate state of the vehicle. Therefore, it is possible to more reliably prevent problems associated with software updates and further improve safety.

[0096] (Structure 3) A software update management device according to Structure 1 or Structure 2, wherein the vehicle control unit includes a first vehicle control unit that controls a functional unit that operates from the time the vehicle is switched to an ignition-off state to the time a first prescribed period has passed, and the update recommendation information stored in the storage unit includes first update recommendation information corresponding to the first vehicle control unit, and the first update recommendation information includes a condition that the first prescribed period has passed since the vehicle was switched to an ignition-off state as the condition condition.

[0097] The software update management device of Configuration 3 can recommend updating the software of the first vehicle control unit while avoiding the operating time of the devices controlled by the first vehicle control unit. Therefore, for devices operating at specific operating times, it is possible to prevent problems associated with software updates, further improving safety.

[0098] (Structure 4) The software update management device according to Structure 3, wherein the functional unit is an in-vehicle detection device that detects the presence of a person in the vehicle.

[0099] According to the software update management device of the fourth configuration, it is possible to recommend software updating to avoid difficulties in using the in-vehicle detection device.

[0100] (Structure 5) A software update management device according to Structure 4, wherein the first update recommendation information includes an additional condition applied when the in-vehicle detection device detects a person as the condition condition, and the additional condition includes a second prescribed period longer than the first prescribed period from the time the vehicle is switched to an ignition-off state.

[0101] According to the software update management device of Configuration 5, it is possible to recommend software updating so that even when the in-vehicle detection device detects a person, there will be no difficulty in subsequent use of the in-vehicle detection device.

[0102] (Structure 6) A software update management device according to any one of Structures 1 to 5, wherein the vehicle control unit includes a second vehicle control unit that controls an alarm device that performs an alarm function when the vehicle is parked, and the update recommendation information stored in the storage unit includes second update recommendation information corresponding to the second vehicle control unit, and the second update recommendation information includes at least one of the following two conditions as the status condition, and the two conditions are: the location of the vehicle is not an area with a high possibility of theft; and the moment when the vehicle is switched to the ignition-off state is not included in a time period with a high possibility of theft.

[0103] The software update management device of Configuration 6 can recommend updating the software related to the vehicle alarm device under conditions that are less likely to cause concerns about the alarm device being stopped for the software update. This prevents adverse events associated with updating the alarm device software, further improving safety.

[0104] (Structure 7) A software update management device according to any one of Structures 1 to 6, wherein the vehicle control unit includes a third vehicle control unit that controls a locking device that locks and unlocks the vehicle, and the update recommendation information stored in the storage unit includes third update recommendation information corresponding to the third vehicle control unit, and the third update recommendation information includes a condition as the condition condition that the vehicle is in a condition estimated to be suitable for software update based on the usage history of the vehicle.

[0105] The software update management device of configuration 7 can recommend updating the locking device software under conditions where there is less concern about the locking device being stopped for the software update. This prevents undesirable situations associated with updating the vehicle's locking and unlocking software, further improving safety.

[0106] (Structure 8) A software update management method, which includes the following processing performed by a computer that manages vehicle software updates: updating recommendation information is stored corresponding to a vehicle control unit installed in the vehicle, the update recommendation information includes conditions for recommending updating the software of the vehicle control unit, the conditions of the update recommendation information include vehicle conditions related to the state of the vehicle and condition conditions indicating conditions suitable for updating the software, and the software update is recommended based on the conditions of the update recommendation information.

[0107] According to the software update management method of Configuration 8, by using update recommendation information that specifies conditions related to software updates corresponding to the vehicle control unit, it is possible to recommend updating the vehicle control unit software under appropriate circumstances. This avoids the difficulty associated with temporarily unavailable vehicle control units during software updates. Consequently, it is possible to prevent adverse events associated with software updates, further improving safety.

[0108] Description of Reference Numerals

[0109] 1…Vehicle, 2…Server, 3…Software Update System, 10…Management ECU (Software Update Management Device), 11…Device, 11A…In-Vehicle Detection Device, 11B…Alarm Device, 11C…Door Lock Device, 13…Vehicle Control Unit, 13A…First ECU (First Vehicle Control Unit), 13B…Second ECU (Second Vehicle Control Unit), 13C…Third ECU (Third Vehicle Control Unit), 21…TCU, 22…Display, 23…Touch Sensor, 24…GNSS, 25…In-Vehicle Sensor, 26…Alarm Output Unit, 27…External Sensor, 28…Camera, 29…Alarm Output Unit, 30…Camera, 31…Sensor, 32…Lock Driver, 110…Processor, 111…Program Management Unit, 112 …recommendation processing unit, 120…memory (storage unit), 121…control program, 122…device information, 123…update recommendation information, 123A…update recommendation information (first update recommendation information), 123B…update recommendation information (second update recommendation information), 123C…update recommendation information (second update recommendation information), 123D…update recommendation information (third update recommendation information), 130…processor, 131…in-vehicle detection unit, 135…memory, 136…control program, 150…processor, 151…alarm control unit, 155…memory, 156…control program, 157…setting data, 170…processor, 171…door lock control unit, 175…memory, 176…control program, 177…setting data.

Claims

1. A software update management device, comprising: a storage unit that stores update recommendation information corresponding to a vehicle control unit mounted on a vehicle, the update recommendation information including a condition for recommending updating software of the vehicle control unit; and a recommendation processing unit that recommends updating the software based on the conditions of the update recommendation information, The conditions of the update recommendation information include a vehicle condition related to the state of the vehicle and a situation condition indicating a situation suitable for updating the software.

2. The software update management device according to claim 1, wherein: The vehicle condition includes the vehicle transitioning to an ignition-off state, The condition includes whether the vehicle's condition is suitable for updating the software.

3. The software update management device according to claim 1, wherein: The vehicle control unit includes a first vehicle control unit that controls a functional unit that operates during a period from when the vehicle is switched to an ignition-off state to when a first predetermined period has elapsed. The update recommendation information stored in the storage unit includes first update recommendation information corresponding to the first vehicle control unit, The first update recommendation information includes, as the situation condition, a condition that the first predetermined period has elapsed since the vehicle transitioned to the ignition-off state.

4. The software update management device according to claim 3, wherein: The functional unit is an in-vehicle detection device that detects the presence of a person in the vehicle.

5. The software update management device according to claim 4, wherein: The first update recommendation information includes, as the situation condition, an additional condition to be applied when the vehicle interior detection device detects a person. The additional condition includes a second predetermined period that is longer than the first predetermined period having passed since the vehicle transitioned to the ignition-off state.

6. The software update management device according to claim 1, wherein: The vehicle control unit includes a second vehicle control unit that controls an alarm device that performs an alarm function when the vehicle is parked. The update recommendation information stored in the storage unit includes second update recommendation information corresponding to the second vehicle control unit, The second update recommendation information includes at least one of the following two conditions as the situation condition, the two conditions being: the location of the vehicle is not an area with a high possibility of being stolen; and the time when the vehicle is turned into the ignition-off state is not included in a time period with a high possibility of being stolen.

7. The software update management device according to claim 1, wherein: The vehicle control unit includes a third vehicle control unit that controls a locking device that locks and unlocks the vehicle. The update recommendation information stored in the storage unit includes third update recommendation information corresponding to the third vehicle control unit. The third update recommendation information includes, as the situation condition, a condition that the vehicle is in a situation estimated to be suitable for software updating based on a usage history of the vehicle.

8. A software update management method, the software update management method comprising the following processing executed by a computer that manages vehicle software updates: storing update recommendation information corresponding to a vehicle control unit mounted on the vehicle, the update recommendation information including conditions for recommending updating software of the vehicle control unit, the conditions of the update recommendation information including a vehicle condition related to a state of the vehicle and a condition condition indicating a condition suitable for updating the software; An update of the software is recommended based on a condition of the update recommendation information.

Citation Information

Patent Citations

  • Software update device, software update system, and software update method

    JP2023018282A