Software update management device and software update management method

By installing monitoring equipment on the vehicle and using a replacement device for software updates, the problem of software updates when the user is not with the vehicle is solved, ensuring the vehicle's anti-crime and traffic safety, and achieving improved safety.

CN120704704APending Publication Date: 2025-09-26HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510195685.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-26
Filing Date
2025-02-21
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

In the prior art, the user cannot rewrite the program when he is not with the vehicle, resulting in insufficient opportunities for software updates and difficulty in ensuring the vehicle's anti-crime and traffic safety.

Method used

By equipping vehicles with surveillance equipment, using alternative equipment such as surveillance cameras and dashcams, performing software updates, and notifying users when necessary and obtaining information and compensation for the replacement equipment, the vehicle's security is ensured.

Benefits of technology

This enables software updates while ensuring vehicle security, improving safety and traffic security, and supporting the development of sustainable transportation systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120704704A_ABST
    Figure CN120704704A_ABST
Patent Text Reader

Abstract

The invention provides a software update management apparatus and a software update management method. The purpose of the present invention is to improve security by updating software relating to monitoring of a vehicle while ensuring criminal prevention of the vehicle. The software update management device is provided with a notification unit that notifies update information pertaining to update of software, with a vehicle control unit that controls a monitoring device that is mounted on a vehicle and monitors the vehicle, and that notifies update information pertaining to update of software. The notification unit notifies, together with the update information, alternative device information relating to an alternative device that is a device different from the monitoring device and is capable of monitoring the vehicle when software of the vehicle control unit is updated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a software update management device and a software update management method. Background Art

[0002] In recent years, research and development efforts to improve traffic safety, which contributes to energy efficiency, have been underway to ensure that more people have access to appropriate, reliable, sustainable, and advanced energy. For example, Patent Document 1 discloses a technology that allows reprogramming while ensuring the security of a vehicle. The system in Patent Document 1 aborts the reprogramming of the security-related ECUs that control vehicle safety functions if the user is not traveling with the vehicle.

[0003] Prior art literature

[0004] Patent Literature

[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2006-082648 Summary of the Invention

[0006] Problems to be solved by the invention

[0007] In the technology described in Patent Document 1, the program cannot be rewritten unless the user is traveling with the vehicle, which makes it difficult to ensure an opportunity to update the software.

[0008] In order to solve the above-mentioned problems, the present application aims to ensure the anti-crime property of the vehicle while updating the software related to vehicle monitoring to improve safety. Moreover, it further improves traffic safety and contributes to the development of sustainable transportation systems.

[0009] Means for solving problems

[0010] One embodiment of the present disclosure is a software update management device comprising a notification unit that notifies a vehicle control unit that controls a monitoring device of update information related to software updates, wherein the monitoring device is mounted on a vehicle and monitors the vehicle, and the notification unit notifies replacement device information related to a replacement device together with the update information, wherein the replacement device is a device different from the monitoring device and is capable of monitoring the vehicle when the software of the vehicle control unit is updated.

[0011] Another embodiment of the present disclosure is a software update management device comprising: an update control unit that updates software of a vehicle control unit that controls a monitoring device, wherein the monitoring device is mounted on a vehicle and monitors the vehicle; and a replacement processing unit that performs processing for making the replacement device work when the update control unit updates the software of the vehicle control unit and the importance of updating the software of the vehicle control unit is high and a replacement device can be used, wherein the replacement device is a device different from the monitoring device and can monitor the vehicle.

[0012] Another embodiment of the present disclosure is a software update management method, which performs the following processing by a computer: notifying the vehicle control unit that controls the monitoring device of the software update and the replacement device information related to the software update, wherein the monitoring device is mounted on the vehicle and monitors the vehicle, and the replacement device is a device different from the monitoring device and can monitor the vehicle when the software of the vehicle control unit is updated.

[0013] Another embodiment of the present disclosure is a software update management method, in which a computer is used to perform the following processing: updating the software of a vehicle control unit that controls a monitoring device, wherein the monitoring device is mounted on a vehicle and monitors the vehicle; when the software of the vehicle control unit is updated, if the importance of updating the software of the vehicle control unit is high and an alternative device can be used, processing is performed to enable the alternative device to operate, wherein the alternative device is a device different from the monitoring device and can monitor the vehicle.

[0014] Effects of the Invention

[0015] According to one embodiment of the present disclosure, when notifying a vehicle monitoring software update, by notifying information related to an alternative device capable of monitoring the vehicle, the vehicle monitoring software update can be performed while ensuring the vehicle's security. This can further improve security. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a diagram showing a configuration example of a software updating system.

[0017] Figure 2 It is a diagram showing the structure of a vehicle.

[0018] Figure 3 This is a flowchart showing an example of the operation of the management ECU.

[0019] Figure 4 This is a flowchart showing an example of the operation of the management ECU.

[0020] Description of Reference Numerals

[0021] 1…Vehicle, 2, 2A, 2B…Other vehicles, 3…Alternative device, 3A…Dashcam, 3B…Anti-theft camera, 3C, 3D…Camera, 3E…Public anti-theft camera, 5…Server, 10…Management ECU, 11…Monitoring device (monitoring device), 13…Device ECU (Vehicle control unit), 21…TCU, 22…Display, 23…Touch sensor, 24…GNSS, 27…External sensor, 28…Camera, 29…Alarm output unit, 100…Software update system, 110…Processor, 111…Program management unit, 112…Receiving unit, 113…Notification unit, 114…Alternative processing unit, 120…Memory, 121…Control program, 122…Device information, 123…Alternative device information, 130…Processor, 131…Alarm control unit, 135…Memory, 136…Control program, 137…Setting data, NW…Communication network DETAILED DESCRIPTION

[0022] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.

[0023] [1. Structure of the software update system]

[0024] Figure 1 1 is a diagram showing a configuration example of a software updating system 100 related to the updating of the software of the vehicle 1. The software updating system 100 includes a server 5 that provides a device ECU 13 ( Figure 2 ) is executed by a server 5, which is communicatively connected to the vehicle 1 via a communication network NW. The vehicle 1 downloads software from the server 5 to update the software in the device ECU 13. In other words, the software update system 100 can update the software of the vehicle 1 via OTA (On The Air) downloading.

[0025] Here, updating software refers to the process of replacing the software executed by the processor with a newer version of the software. The specific method can be any of the following: adding, deleting, or overwriting the software. In addition, deleting part or all of the software executed by the processor, installing new software, and deleting, adding, or overwriting the data used when executing the software can also be included in the process of updating the software. In the following description, software includes programs executed by the processor and data that is referenced, generated, updated, deleted, etc. in association with the programs, including firmware.

[0026] The server 5 is connected to the communication network NW via a wired or wireless communication line. The vehicle 1 is connected to the communication network NW via wireless communication, for example, via a cellular communication base station B. The specific form of the communication network NW is not limited. For example, the communication network NW may include a cellular communication network, the Internet, a WAN (Wide Area Network), a LAN (Local Area Network), a public line network, a provider device, a dedicated line, a base station, and the like.

[0027] The present vehicle 1 may be any of a four-wheeled vehicle, a two-wheeled vehicle, or any other vehicle, and may also be a large vehicle, a commercial vehicle, or a work vehicle. As an example, a four-wheeled vehicle is assumed for illustration in this embodiment. In addition, the present vehicle 1 may also be any of an electric vehicle having a motor that operates on electricity as a driving source and a vehicle equipped with an internal combustion engine. The internal combustion engine may function as a power source for driving the present vehicle 1, or may be a power generation device for driving a generator. The other vehicle 2 described later is a vehicle different from the present vehicle 1. The other vehicle 2 is a vehicle having the same structure as the present vehicle 1, or a vehicle having a structure different from the present vehicle 1, and its specific form is not limited.

[0028] The vehicle 1 is equipped with a monitoring device 11 for the purpose of preventing the vehicle 1 from being damaged or stolen while the vehicle 1 is parked or in a parking state. The monitoring device 11 uses a camera 28 ( Figure 2 ) etc., to monitor the vehicle 1.

[0029] During the update of the software related to the function of the monitoring device 11, the device ECU 13 ( Figure 2 ) stop function. Therefore, the vehicle 1 cannot be monitored. When updating the software related to the monitoring device 11 of the vehicle 1, the software update system 100 uses the replacement device 3 capable of monitoring the vehicle 1 instead of the monitoring device 11.

[0030] The alternative device 3 is a device that can monitor the vehicle 1 or the surroundings of the vehicle 1. For example, the alternative device 3 is a surveillance camera installed in a house or building, a driving recorder installed in another vehicle 2, a security camera, or a camera installed in a traffic light or street lamp. Figure 1In the figure, as examples of alternative equipment 3, security camera 3B, cameras 3C, 3D, and a public security camera 3E are shown. Security camera 3B is installed in house H1 and captures an area including parking lot P1, which is the parking location of vehicle 1. Camera 3C is a camera installed in another vehicle 2A parked in parking lot P2 adjacent to parking lot P1, and is, for example, a surveillance device or a driving recorder in vehicle 2A. Camera 3D is a camera installed in another vehicle 2B parked or stopped near parking lot P1, and is, for example, a driving recorder. Public security camera 3E is a camera installed at a traffic light near parking lot P1 for public purposes.

[0031] Furthermore, a camera mounted on the host vehicle 1 that operates independently of the monitoring device 11 can be used as the alternative device 3. An example of this is the drive recorder 3A mounted on the host vehicle 1. The drive recorder 3A is, for example, a device attached to the host vehicle 1 and operates independently of the management ECU 10 or the device ECU 13 of the host vehicle 1, which will be described later.

[0032] The alternative device 3 used in the software update system 100 can communicate with the server 5 via the communication network NW through the communication function. For example, the driving recorder 3A can be connected to the communication network NW via the base station B or other communication devices through the function of the wireless communication module equipped in the driving recorder 3A. The security camera 3B can be connected to the communication network NW via the communication line installed in the house H1. The camera 3C can be connected to the communication network NW via the base station B or other communication devices through the wireless communication device equipped in the other vehicle 2A or the function of the wireless communication module equipped in the camera 3C. The same is true for the camera 3D. The public anti-crime camera 3E can be connected to the communication network NW via the communication line of a public institution (not shown). Here, the wireless communication function of this vehicle 1 and other vehicles 2A and 2B refers to the function of conducting communication based on cellular communication, Wi-Fi (registered trademark) or other mobile communication standards.

[0033] The server 5 communicates with the substitute devices 3 via the communication network NW, and acquires information including the position, imaging range, and time period during which each substitute device 3 can be used as the substitute device 3 .

[0034] Security cameras 3B, 3C, and 3D, as well as public security camera 3E, are devices owned or used by a person other than the user of the vehicle 1. Therefore, in the software update system 100, when a replacement device 3 is used, a fee may be paid in connection with the use of the replacement device 3. Specifically, a fee pre-set for each replacement device 3 is generated when the replacement device 3 is used to update the software of the vehicle 1. In this case, the server 5 acquires and stores information regarding the fee paid to the owner or user of the replacement device 3. Furthermore, a configuration is conceivable in which a settlement mechanism (not shown) executes payment based on the information stored by the server 5.

[0035] [2. Vehicle structure]

[0036] Figure 2 1 is a diagram showing the structure of the vehicle 1 .

[0037] The vehicle 1 is equipped with a plurality of devices that realize the functions of the vehicle 1 and a vehicle control unit that controls these devices. Examples of the devices equipped in the vehicle 1 include an internal combustion engine that functions as the driving source of the vehicle 1 and a device that locks and unlocks the doors of the vehicle 1. Furthermore, the vehicle 1 may also be equipped with an ICB (Infotainment Control Box), an MPU (Map Positioning Unit), an MVC (Multi View Camera), a PKS (Parking Support System), and an ADAS (Advanced Driver Assistance System). Furthermore, the vehicle 1 may also be equipped with a driving motor, accelerator, brake, and other controllers that drive the vehicle 1, a VSA (Vehicle Stability Assist) device, and a battery that drives the driving motor.

[0038] In this embodiment, the operating state of the vehicle 1 transitions between three states: ignition-on, ignition-off, and stopped. The ignition-on state refers to the state in which the motor or internal combustion engine, which is the driving source of the vehicle 1, is operating. The operating state of the motor is not limited to the state in which the motor is rotating. It also includes the state in which power can be supplied to the motor from an inverter circuit, for example, or the state in which the motor can rotate rapidly in response to an operation such as an acceleration operation by the driver. For example, the ignition-on state can also be described as the state in which the inverter circuit is activated. The state in which the motor is not rotating during the ignition-on state is sometimes referred to as ignition-ready (IG_Ready), but this state is also included in the ignition-on state. If the vehicle 1 is equipped with an internal combustion engine, the ignition-on state includes the state in which the internal combustion engine is rotating and the state in which the internal combustion engine can be started rapidly. The ignition-off state refers to the state in which the motor or internal combustion engine, which is the driving source of the vehicle 1, is not operating, and power is supplied to at least a portion of the vehicle 1's control devices, including the device ECU 13, so that these control devices are operational. The stopped state refers to a state in which power is supplied to the minimum control devices required to shift the vehicle 1 to the ignition-off state, and power supply to other control devices and the drive source of the vehicle 1 is stopped. The monitoring device 11 sometimes operates at least in the stopped state and in the ignition-off state.

[0039] exist Figure 2 , a monitoring device 11 is shown as an example of equipment included in the vehicle 1. The monitoring device 11 includes an ECU 13 that functions as a vehicle control unit. The ECU (Electronic Control Unit) 13 controls the monitoring device 11 by executing a program. The monitoring device 11 is an example of monitoring equipment.

[0040] The device ECU 13 includes a processor 130 and a memory 135. Memory 135 is a nonvolatile storage device composed of a magnetic storage medium or a semiconductor memory element. It stores a control program 136 executed by the processor 130 and data referenced, generated, or processed during the execution of the control program 136. For example, memory 135 stores setting data 137.

[0041] The processor 130 functions as an alarm control unit 131 by executing a control program 136. When the vehicle 1 enters a stopped state, the alarm control unit 131 initiates detection operations using at least one of the exterior sensor 27 and the camera 28. The exterior sensor 27 is a sensor outside the vehicle 1 that detects the approach of people or objects near the vehicle 1. The exterior sensor 27 may also be a sensor that detects contact with the vehicle 1. Examples of exterior sensors 27 include ultrasonic sensors, vibration sensors, and radar sensors. During the detection process, the alarm control unit 131 analyzes the detection results of the exterior sensor 27 and the images captured by the camera 28. By comparing the analysis results with the setting data 137, the alarm control unit 131 detects suspicious movements or vibrations of the vehicle 1. Upon detecting suspicious movements or vibrations of the vehicle 1, the alarm control unit 131 issues a notification to the alarm output unit 29 and stores the images captured by the camera 28 in the memory 135. The alarm output unit 29 is a display that displays notifications, an LED indicator or other indicator light that emits light when notifying, a speaker that outputs notification sounds, or the like.

[0042] The vehicle 1 includes a management ECU 10. The management ECU 10 manages the update of the software of the vehicle control unit included in the vehicle 1. Figure 2 In the example of FIG, the management ECU 10 manages the updating of the program executed by the device ECU 13 and the data processed during the execution of the program. The management ECU 10 is an example of a software update management device.

[0043] The management ECU 10 is connected to a TCU (Telematics Control Unit) 21, a display 22, a touch sensor 23, and a GNSS (Global Navigation Satellite System) 24. The TCU 21 is a communication device that communicates with devices outside the vehicle 1 in accordance with the communication standards of mobile communication systems. The TCU 21 includes, for example, an antenna, a transmitter, and a receiver, and performs communications under the control of the management ECU 10.

[0044] The display 22 includes a liquid crystal display panel and an organic EL (electroluminescence) panel, and displays text and images. The display 22 is installed, for example, on the instrument panel of the vehicle 1. The touch sensor 23 is arranged to overlap the display screen of the display 22 and detects touch operations performed by a user riding in the vehicle 1. The GNSS 24 measures the position of the vehicle 1 by receiving wireless signals transmitted from satellites.

[0045] The management ECU 10 includes a processor 110 and a memory 120. The memory 120 is a nonvolatile storage device composed of a magnetic storage medium and a semiconductor memory element, and stores a control program 121 executed by the processor 110. The memory 120 also stores device information 122 and alternative device information 123. The device information 122 includes information related to the devices included in the vehicle 1 and the vehicle control units that control these devices. For example, the device information 122 includes information about the programs and data related to the operation of each vehicle control unit, including the version, last update date, and size.

[0046] The replacement device information 123 is information related to the replacement device 3 used when updating software in the management ECU 10. For example, the replacement device information 123 includes at least one of the following: the remuneration associated with using the replacement device 3, the time or time period during which the replacement device 3 can be used, and the function of the replacement device 3. The replacement device information 123 may include information related to the name of the replacement device 3, the location of the replacement device 3, the owner of the replacement device 3, and the like. The memory 120 corresponds to an example of a storage unit.

[0047] The processor 110 functions as a program management unit 111 , a reception unit 112 , a notification unit 113 , and an alternative processing unit 114 by executing the control program 121 .

[0048] The program management unit 111 manages updates to the programs executed by the device ECU 13 and the data processed by the device ECU 13. Based on the device information 122, the program management unit 111 inquires with the server 5 whether the device ECU 13's software needs to be updated. If the server 5 can provide a control program 136 and / or setting data 137 that is newer than the control program 136 and setting data 137 installed in the device ECU 13, the program management unit 111 determines that the device ECU 13's software needs to be updated. In this case, the program management unit 111 downloads update data for updating the control program 136 and / or setting data 137 from the server 5. The program management unit 111 uses the downloaded update data to update the control program 136 and / or setting data 137.

[0049] The receiving unit 112 detects an operation on the touch sensor 23 and receives an input based on the operation. The notifying unit 113 notifies the user of the vehicle 1 .

[0050] The notification unit 113 notifies the user of the vehicle 1 of information by, for example, displaying text or images on the display 22. For example, when the software of the device ECU 13 needs to be updated, the notification unit 113 notifies the user of the device ECU 13 of update information related to the software update. The update information includes information related to the vehicle control unit to be updated, information indicating that the vehicle 1 is in a stopped state or the ignition is off during the update, and the like.

[0051] When the replacement device 3 is available for use when updating the software of the device ECU 13, the notification unit 113 notifies the device ECU 13 of the update information along with the information included in the replacement device information 123. Furthermore, the notification unit 113 may request input regarding whether the replacement device 3 can be used. This notification may be provided by displaying an input button on the display 22. The request for input regarding whether the replacement device 3 can be used may be made simultaneously with the notification of the update information and the replacement device information 123, or may be made afterward. Furthermore, the notification unit 113 performs processing corresponding to the result of the input regarding whether the replacement device 3 can be used.

[0052] The alternative processing unit 114 performs processing related to an alternative device 3 that can be used when updating the software of the device ECU 13. For example, if an alternative device 3 is available, the alternative processing unit 114 obtains information related to the alternative device 3 from the server 5, generates alternative device information 123, and stores it in the memory 120. When using an alternative device 3, the alternative processing unit 114 requests the server 5 to activate the alternative device 3. In response to the request sent by the alternative processing unit 114, the server 5 causes the alternative device 3 designated by the alternative processing unit 114 to perform the operation of monitoring the host vehicle 1. Here, if the alternative device 3 used by the alternative processing unit 114 is the drive recorder 3A installed in the host vehicle 1, the alternative processing unit 114 can also activate the drive recorder 3A without going through the server 5.

[0053] [3. Management ECU Operation]

[0054] [3-1. First Operation Example]

[0055] Figure 3 and Figure 4 : is a flowchart showing an example of the operation of the management ECU 10 . Figure 3 1 shows a first operation example of the management ECU 10. Figure 4 A second operation example of the management ECU 10 is shown. Figure 3 and Figure 4 The illustrated operation is an example of the software update management method of the present disclosure.

[0056] First, refer to Figure 3A first operation example of the management ECU 10 will be described. Figure 3 Steps S11 and S16 are executed by the program management unit 111 , step S19 is executed by the receiving unit 112 , steps S12 , S13 , S18 , and S20 to S23 are executed by the notification unit 113 , and steps S14 , S15 , and S17 are executed by the alternative processing unit 114 .

[0057] When it is detected that the software of the device ECU 13 needs to be updated by querying the server 5 based on the device information 122 (step S11), the management ECU 10 starts Figure 3 The management ECU 10 determines whether there is a replacement device 3 that can be used when updating the software of the device ECU 13 by making an inquiry to the server 5 (step S12).

[0058] When determining that there is no available alternative device 3 (step S12 : NO), the management ECU 10 notifies the device ECU 13 of update information related to software update (step S13 ), and then proceeds to step S16 described later.

[0059] If it is determined that an available replacement device 3 exists (step S12: Yes), the management ECU 10 determines whether the update importance is high (step S14). The management ECU 10 is notified of the update importance from the server 5. For example, if a highly urgent software update or software update related to improving important functions of the device ECU 13 is required, the server 5 transmits data to the management ECU 10 with a flag indicating that the update is of high importance. The management ECU 10 makes the determination in step S14 by referring to the data transmitted from the server 5.

[0060] If the importance of the update is high (step S14 : YES), the management ECU 10 requests the server 5 to use the operation of the available alternative device 3 (step S15 ), and executes the software update of the device ECU 13 (step S16 ).

[0061] If the importance of the update is determined to be low (step S14: No), the management ECU 10 acquires information related to the replacement device 3 and generates replacement device information 123 (step S17). The management ECU 10 notifies the display 22 of the updated information and information based on the replacement device information 123 (step S18).

[0062] The management ECU 10 performs notification in step S18 and begins accepting input from the touch sensor 23 or the like (step S19). In step S19, the management ECU 10 accepts an "approval input" for approving the use of the alternative device 3 and a "disapproval input" for rejecting the use of the alternative device 3. If there are multiple available alternative devices 3, the management ECU 10 may accept an input for selecting any of the multiple available alternative devices 3 in step S19.

[0063] The management ECU 10 determines whether an input indicating consent has been received (step S20). If an input indicating consent has been received (step S20: YES), the management ECU 10 proceeds to step S15 and requests the operation of the alternative device 3. If there are multiple available alternative devices 3 and if an input indicating consent and selecting an alternative device 3 has been received, the management ECU 10 requests the operation of the selected alternative device 3 in step S15.

[0064] If no consent input has been received (step S20: No), the management ECU 10 determines whether a disapproval input has been received (step S21). If no disapproval input has been received (step S21: No), the management ECU 10 returns to step S20. In other words, the management ECU 10 waits for input until either consent or disapproval is received.

[0065] If a disagreement is input (step S21 : YES), the management ECU 10 prohibits the program management unit 111 from updating the software of the device ECU 13 (step S22 ), waits for a predetermined period of time (step S23 ), and then returns to step S12 .

[0066] Thus, in the first operational example, the management ECU 10 targets the equipment ECU 13 mounted on the host vehicle 1 and notifies the notification unit 113 of update information related to the software update of the equipment ECU 13. The management ECU 10 also notifies the update information, along with replacement device information 123 related to the replacement device 3, which is a device separate from the monitoring device 11 and capable of monitoring the host vehicle 1 when the software of the equipment ECU 13 is updated, through the notification unit 113.

[0067] Furthermore, if there is no alternative device 3 that can be used when updating the software of the device ECU 13, the notification unit 113 does not notify the alternative device information 123. If the importance of updating the software of the device ECU 13 is high and an alternative device 3 is available, the alternative processing unit 114 performs processing for activating the alternative device 3, and the program management unit 111 updates the software.

[0068] In addition, the notification unit 113 notifies the update information and the replacement device information 123 including at least one of the remuneration associated with the use of the replacement device 3, the time or time period when the replacement device 3 can be used, and the function of the replacement device 3.

[0069] After the notification is made by the notification unit 113 , at least one of an input indicating approval or rejection of the use of the alternative device 3 and an input selecting any one of the plurality of alternative devices 3 is accepted by the acceptance unit 112 .

[0070] Then, when the accepting unit 112 accepts the input of consent, the program management unit 111 can update the software of the device ECU 13 , and the program management unit 111 updates the software.

[0071] In addition, when the accepting unit 112 accepts an input of disagreement, the program management unit 111 cannot execute the update of the software of the device ECU 13 .

[0072] [3-2. Second Operation Example]

[0073] Reference Figure 4 , the second operation example of the management ECU 10 will be described. In the second operation example, steps S11 to S21 are Figure 3 The first action example is the same as that of , so the description is omitted. Figure 4 Step S31 is executed by the notification unit 113 , and step S32 is executed by the program management unit 111 and the notification unit 113 .

[0074] In the second operational example, if the management ECU 10 receives a disagreement input (step S21: Yes), it notifies the user that the monitoring device 11 is inoperable during the software update (step S31). The management ECU 10 then executes the software update by the program management unit 111 and continues to notify the user that the monitoring device 11 is inoperable during the update (step S32). This ensures that the user is reliably informed of the functional cessation of the monitoring device 11, even when the device ECU 13 software is being updated without using the replacement device 3.

[0075] [4. Other Implementation Methods]

[0076] The above-described embodiment is merely one embodiment of the present invention, and can be arbitrarily modified and applied without departing from the spirit of the present invention.

[0077] In the above embodiment, a configuration is described in which the substitute device 3 is connectable to the server 5, and the substitute processing unit 114 of the management ECU 10 obtains information related to the substitute device 3 from the server 5. This is merely an example; for example, a configuration may also be employed in which the management ECU 10 communicates with one or more substitute devices 3 and obtains from the substitute devices 3 information related to available substitute devices 3 and information related to remuneration associated with the use of the substitute devices 3.

[0078] In the above embodiment, the management ECU 10, which includes the program management unit 111, notification unit 113, and alternative processing unit 114, is described as being provided separately from the equipment ECU 13 that controls the monitoring device 11. However, this is merely an example. The specific configuration of the functional units corresponding to the management ECU 10 can be modified as appropriate. For example, any of the vehicle control units included in the vehicle 1 may have the functions of the program management unit 111, notification unit 113, and alternative processing unit 114 of the management ECU 10, or may have the functions of the reception unit 112. Furthermore, the management ECU 10 may also have the same functions as the equipment ECU 13.

[0079] Figure 2 The schematic diagrams showing the structure of the vehicle 1 are provided to facilitate understanding of the present application. The application of the present disclosure is not limited to the structures shown in these diagrams. In addition, the processing of each component can be performed by one hardware unit or by multiple hardware units. Figure 3 as well as Figure 4 The processing shown may be executed by one program or by a plurality of programs.

[0080] [5. Structures Supported by the Above-mentioned Embodiments]

[0081] The above-mentioned embodiment supports the following structure.

[0082] (Structure 1) A software update management device comprising a notification unit that notifies a vehicle control unit that controls a monitoring device of update information related to software updates, wherein the monitoring device is mounted on a vehicle and monitors the vehicle, and the notification unit notifies replacement device information related to a replacement device together with the update information, wherein the replacement device is a device different from the monitoring device and can monitor the vehicle when the software of the vehicle control unit is updated.

[0083] According to the software update management device of Structure 1, when notifying the update of the vehicle monitoring-related software, by notifying the information related to the alternative device capable of monitoring the vehicle, the vehicle monitoring-related software can be updated while ensuring the anti-crime characteristics of the vehicle. This can further improve security.

[0084] (Structure 2) A software update management device as described in Structure 1, wherein the software update management device includes a receiving unit, which receives at least one of an input indicating consent or refusal to use the alternative device and an input for selecting any one of a plurality of alternative devices after the notification unit has made a notification.

[0085] According to the software update management device of Configuration 2, after the software is updated and the notification regarding the replacement device is performed, processing reflecting the user's intention can be performed, thereby achieving improved convenience.

[0086] (Structure 3) The software update management device described in Structure 2, wherein when the receiving unit receives input indicating consent to use the alternative device or input selecting any one of multiple alternative devices, the software update of the vehicle control unit can be executed.

[0087] According to the software update management device of Configuration 3, it is possible to update the software while ensuring the security of the vehicle using a replacement device.

[0088] (Structure 4) The software update management device according to Structure 2 or 3, wherein when the accepting unit accepts input indicating refusal to use the alternative device, the software update of the vehicle control unit is disabled.

[0089] According to the software update management device of the fourth configuration, it is possible to prevent a reduction in the security of the vehicle associated with the update of the software.

[0090] (Structure 5) A software update management device according to Structure 2 or Structure 3, wherein, when the receiving unit receives input indicating a refusal to use the alternative device, the notification unit notifies the following situation: the monitoring device cannot operate during the update of the software of the vehicle control unit.

[0091] According to the software update management device of the fifth configuration, it is possible to notify the user of the impact on the security of the vehicle caused by the software update.

[0092] (Structure 6) A software update management device according to any one of Structures 1 to 5, wherein the alternative device information notified by the notification unit includes at least one of the remuneration associated with the use of the alternative device, the time or time period during which the alternative device can be used, and the function of the alternative device.

[0093] According to the software update management device of Configuration 6, detailed information on the use of the replacement device can be provided to the user.

[0094] (Structure 7) A software update management device according to Structure 2 or Structure 3, wherein, when the receiving unit receives an input indicating a refusal to use the alternative device and executes an update of the software of the vehicle control unit, the following situation is notified: during the execution of the software update, the monitoring device cannot work along with the update of the software of the vehicle control unit.

[0095] According to the software update management device of configuration 7, it is possible to execute software updates according to the user's intention and notify the user of the impact of the software update on the security of the vehicle.

[0096] (Structure 8) The software update management device according to any one of Structures 1 to 5, wherein the notification unit does not notify the alternative device information when the alternative device that can be used when executing the update of the software of the vehicle control unit does not exist.

[0097] According to the software update management device of Configuration 8, unnecessary processing associated with software updating can be omitted, thereby improving convenience.

[0098] (Structure 9) A software update management device comprising: an update control unit that updates the software of a vehicle control unit that controls a monitoring device, wherein the monitoring device is mounted on a vehicle and monitors the vehicle; and a replacement processing unit that performs processing for making the replacement device work when the update control unit updates the software of the vehicle control unit and the importance of updating the software of the vehicle control unit is high and a replacement device can be used, wherein the replacement device is a device different from the monitoring device and can monitor the vehicle.

[0099] According to the software update management device of configuration 9, when updating software related to vehicle monitoring, updates of high importance can be performed quickly while ensuring the security of the vehicle, thereby further improving safety.

[0100] (Structure 10) A software update management method, which performs the following processing by a computer: notifying a vehicle control unit that controls a monitoring device of update information and replacement device information related to software updates, wherein the monitoring device is mounted on a vehicle and monitors the vehicle, and the replacement device is a device different from the monitoring device and can monitor the vehicle when the software of the vehicle control unit is updated.

[0101] According to the software update management method of configuration 10, when notifying the update of the software related to vehicle monitoring, by notifying the information related to the alternative device capable of monitoring the vehicle, the software related to vehicle monitoring can be updated while ensuring the safety of the vehicle. This can further improve safety.

[0102] (Structure 11) A software update management method, which performs the following processing by a computer: updating the software of a vehicle control unit that controls a monitoring device, wherein the monitoring device is installed in a vehicle and monitors the vehicle, and when the software of the vehicle control unit is updated, when the importance of updating the software of the vehicle control unit is high and an alternative device can be used, processing is performed to enable the alternative device to operate, wherein the alternative device is a device different from the monitoring device and can monitor the vehicle.

[0103] According to the software update management method of configuration 11, when updating software related to vehicle monitoring, updates of high importance can be quickly performed while ensuring the security of the vehicle, thereby further improving safety.

Claims

1. A software update management device, wherein: The software update management device includes a notification unit that notifies a vehicle control unit that controls a monitoring device mounted on a vehicle to monitor the vehicle of update information related to the software update. The notification unit notifies, together with the update information, replacement device information related to a replacement device that is a device different from the monitoring device and capable of monitoring the vehicle when software of the vehicle control unit is updated.

2. The software update management device according to claim 1, wherein: The software update management apparatus includes an accepting unit configured to accept at least one of an input indicating approval or rejection of use of the replacement device and an input selecting any one of the plurality of replacement devices after the notification by the notification unit.

3. The software update management device according to claim 2, wherein: When the accepting unit accepts an input indicating approval for use of the alternative device or an input selecting any one of a plurality of alternative devices, the software of the vehicle control unit is enabled to be updated.

4. The software update management device according to claim 2 or 3, wherein: When the accepting unit accepts input indicating refusal to use the substitute device, the software of the vehicle control unit is disabled from being updated.

5. The software update management device according to claim 2 or 3, wherein: When the accepting unit accepts input indicating refusal to use the substitute device, the notifying unit notifies that the monitoring device cannot operate while the software of the vehicle control unit is being updated.

6. The software update management device according to claim 1, wherein: The substitute device information notified by the notification unit includes at least one of a remuneration associated with use of the substitute device, a time or a time period during which the substitute device can be used, and a function of the substitute device.

7. The software update management device according to claim 2 or 3, wherein: When the receiving unit receives input indicating refusal to use the alternative device and executes the software update of the vehicle control unit, the following situation is notified: during the software update, the monitoring device cannot operate along with the update of the vehicle control unit software.

8. The software update management device according to claim 1, wherein: The notification unit does not notify the alternative device information when the alternative device that can be used when executing the software update of the vehicle control unit does not exist.

9. A software update management device comprising: an update control unit that updates software of a vehicle control unit that controls a monitoring device that is mounted on a vehicle and monitors the vehicle; and The replacement processing unit performs processing for operating the alternative device when the update control unit updates the software of the vehicle control unit and the importance of the software update of the vehicle control unit is high and an alternative device can be used, wherein: The substitute device is a device different from the monitoring device and is capable of monitoring the vehicle.

10. A software update management method, comprising: performing the following processing by a computer: The vehicle control unit that controls the monitoring device is notified of update information and replacement device information related to software updates, wherein: The monitoring device is mounted on a vehicle and monitors the vehicle. The replacement device is a device different from the monitoring device and can monitor the vehicle when software of the vehicle control unit is updated.

11. A software update management method, comprising: performing the following processing by a computer: updating software of a vehicle control unit that controls a monitoring device that is mounted on a vehicle and monitors the vehicle, When the software of the vehicle control unit is updated, if the importance of the software update of the vehicle control unit is high and an alternative device is available, a process for operating the alternative device is performed, wherein: The substitute device is a device different from the monitoring device and is capable of monitoring the vehicle.

Citation Information

Patent Citations

  • Program rewriting system

    JP2006082648A