Vehicle control system and control method thereof
The vehicle control system, which is authenticated by portable devices and cameras, solves the convenience and safety issues when updating vehicle programs, realizes safety permission setting and vehicle exit detection when communication is not possible, and ensures the normal use and anti-theft function of the vehicle.
Patent Information
- Application Number
- CN202510148494.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-27
- Filing Date
- 2025-02-11
- Publication Date
- 2025-09-30
AI Technical Summary
When the vehicle program is updated, if the occupants do not have the electronic key, the vehicle may not be unlocked, affecting convenience and safety.
The system uses wireless communication and camera authentication with a portable device to obtain authentication information to control vehicle locking and unlocking. When communication is not possible, a setting screen is displayed to accept program update permission settings. Combined with vehicle exit detection and drive source control, this ensures the security and convenience of program updates.
It improves the convenience and safety of passengers when updating vehicle programs, prevents vehicle theft, and ensures the stable operation of the transportation system.
Smart Images

Figure CN120716634A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a vehicle control system and a control method thereof. Background Art
[0002] Conventionally, a program rewriting system for updating a program of a computer mounted on a vehicle has been proposed (for example, see Patent Document 1).
[0003] [Prior art literature]
[0004] [Patent Document]
[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2006-082648 Summary of the Invention
[0006] [Problems to be Solved by the Invention]
[0007] In recent years, vehicles have been equipped with multiple devices that lock and unlock the vehicle's locking mechanism. However, if a passenger does not have a device such as an electronic key to unlock the vehicle, and the electronic control device that authenticates the passenger undergoes a program update, the vehicle may not be unlocked, preventing the passenger from boarding or moving the vehicle until the program update is complete.
[0008] In order to solve the above-mentioned problems, the present application aims to improve the convenience and safety of passengers by addressing the problems that may occur when the vehicle program is updated. Moreover, it contributes to the development of a sustainable transportation system that further improves traffic safety.
[0009] [Means for solving the problem]
[0010] As a first method for achieving the above-mentioned purpose, a vehicle control system can be cited, which comprises: a first control device, which obtains first authentication information through wireless communication with a portable device, and controls the locking and unlocking of the vehicle based on the obtained first authentication information; a second control device, which obtains second authentication information based on an image captured by a camera, and controls the locking and unlocking of the vehicle based on the obtained second authentication information; a locking mechanism, which locks the door of the vehicle; an acceptance device, which accepts an operation; and an update management device, which, when the communication status between the first control device and the portable device is non-communicable and an update program for updating the program executed by the second control device is obtained, causes the vehicle-mounted display device mounted on the vehicle to display a setting screen, the setting screen accepting a setting of whether to permit the execution of the program update of the second control device and a setting of whether the vehicle needs to be locked after getting off the vehicle, and the update management device controls the second control device and the locking mechanism according to the setting accepted by the setting screen.
[0011] In the above-mentioned vehicle control system, the update management device may be configured to display a predetermined guidance on the setting screen when the program update of the second control device fails.
[0012] In the above-mentioned vehicle control system, it can also be constructed so that the update management device has an getting-off detection unit for detecting when an occupant gets off the vehicle. When the acceptance device accepts an operation of locking the vehicle after selecting to get off, when the getting-off detection unit detects that the occupant has gotten off the vehicle, the update management device sends an indication signal indicating the locking of the vehicle door to the locking mechanism, and after sending the indication signal, executes a program update of the second control device.
[0013] In the above-mentioned vehicle control system, it can also be constructed as follows: the vehicle control system includes a drive source control device for controlling a drive source mounted on the vehicle, and the update management device includes a get-off detection unit for detecting when an occupant gets off the vehicle. When the acceptance device accepts the operation of selecting to get off and there is no need to lock the vehicle, when the get-off detection unit detects that the occupant has gotten off the vehicle, the update management device sends an indication signal to the drive source control device to indicate that driving of the drive source is prohibited.
[0014] In the vehicle control system, the update management device may execute the program update of the second control device with the vehicle doors unlocked without sending an instruction signal to the locking mechanism to instruct the locking of the vehicle doors.
[0015] As a second embodiment for achieving the above-mentioned object, a control method for a vehicle control system is provided, the vehicle control system comprising: a first control device that obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; a locking mechanism that locks the doors of the vehicle; an acceptance device that accepts an operation; and an update management device that manages updates of programs executed by the first control device and the second control device, wherein the control method includes the following processing: when the communication status between the first control device and the portable device is not communicable and an update program for updating the program executed by the second control device is obtained, causing an on-vehicle display device mounted on the vehicle to display a setting screen, the setting screen accepting a setting of whether to permit execution of the program update of the second control device and a setting of whether to lock the vehicle after getting off the vehicle, and controlling the second control device and the locking mechanism in accordance with the settings accepted by the setting screen.
[0016] [Effects of the Invention]
[0017] According to the vehicle control system and control method thereof, by accepting responses from the occupant to problems that may occur when updating a vehicle program, the convenience of the occupant can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 : is a system configuration diagram showing the configuration of a vehicle control system.
[0019] Figure 2 It is a block diagram showing the structure of the central ECU.
[0020] Figure 3 This is a diagram showing an example of a permission request screen.
[0021] Figure 4 This is a flowchart showing the operation of the central ECU according to the first embodiment.
[0022] Figure 5 It is a diagram showing an example of the first setting screen.
[0023] Figure 6 It is a diagram showing an example of the second setting screen.
[0024] Figure 7 This is a flowchart showing the operation of the central ECU according to the second embodiment.
[0025] Figure 8 : is a diagram showing an example of a contact destination table.
[0026] Figure 9 This is a flowchart showing the operation of the central ECU according to the third embodiment.
[0027] Figure 10 This is a flowchart showing the operation of the central ECU according to the third embodiment. DETAILED DESCRIPTION
[0028] [1. Configuration of Vehicle Control System of First Embodiment]
[0029] Figure 1 This is a system configuration diagram showing the structure of a vehicle control system 1 installed in a vehicle 3. Vehicle control system 1 is configured such that a central ECU (Electronic Control Unit) 10, an electronic control device functioning as a central gateway, is connected to the electronic control device targeted for program updates so that data can be communicated with each other. Central ECU 10 functions as an update management device.
[0030] Connected to the central ECU 10 is a TCU (Telematics Control Unit) 14, a wireless device compliant with the communication standards of a mobile communication system. The central ECU 10 utilizes the TCU 14 to perform OTA (Over The Air) management. OTA management includes downloading update programs for the electronic control devices in the vehicle 3 from a server device 300 via a network 350 and applying the downloaded update programs to the electronic control devices.
[0031] The central ECU 10 is connected to a plurality of communication lines including the first communication lines 3a, 3b and the second communication lines 4a, 4b, and implements a gateway function for managing the exchange of communication data between these communication lines.
[0032] The first communication lines 3a, 3b and the second communication lines 4a, 4b are composed of buses that perform communication based on standards such as CAN and Ethernet (registered trademark), or communication lines that perform P2P (peer to peer) communication. The first communication lines 3a, 3b can be composed of multiple communication lines that perform communication based on the same standard, or they can be composed of multiple communication lines that perform communication based on different standards. The same applies to the second communication lines 4a, 4b.
[0033] An ICB (Infotainment Control Box) 11, a speaker 12, and a microphone 13 are connected to the first communication line 3a via an in-vehicle connection link 19. Furthermore, a TCU (Telematics Control Unit) 14, a GNSS (Global Navigation Satellite System) sensor 15, and a touch panel 16 are connected to the in-vehicle connection link 19. Touch panel 16 includes a display 17 and a touch sensor 18. Touch panel 16 corresponds to an in-vehicle display device.
[0034] The in-vehicle connection link 19 is composed of multiple communication transmission paths based on various communication standards. The in-vehicle connection link 19 may also include, for example, multiple communication networks. In this case, multiple communication networks may also be interconnected via a device with a gateway function. In addition, the in-vehicle connection link 19 may also include a communication network for P2P communication. In the communication network, various communication buses for network communication based on various standards can be used. Examples of such standards include CAN, Ethernet, USB (Universal Serial Bus), LIN (Local Interconnect Network), and LVDS (Low Voltage Differential Signaling), but other standards may also be used.
[0035] The ICB 11 is an IVI (In-Vehicle Infotainment) ECU and provides various information and entertainment to vehicle passengers using a speaker 12 , a microphone 13 , a GNSS sensor 15 , a touch panel 16 , and the like.
[0036] A DMC (Driver Monitoring Camera) 20 that monitors the driver is connected to the first communication line 3 b.
[0037] The second communication line 4a is connected to the area A-ECU 30. The area A-ECU 30 is connected to a drive device 31 and a battery 33. The drive device 31 is, for example, a motor or an internal combustion engine that drives the vehicle 3. The area A-ECU 30 corresponds to a drive source control device.
[0038] The second communication line 4b is connected to the area B-ECU 40. The area B-ECU 40 is connected to a lamp 41, a window motor 43, a door sensor 45, a door lock mechanism 47, and a weight sensor 49.
[0039] The lamp body 41 includes, for example, headlights, taillights, and turn signals. The window motor 43 opens and closes the window. The door sensor 45 detects the operation of the door. The door lock mechanism 47 performs locking and unlocking of the doors of the vehicle 3. The weight sensor 49 is arranged on the seat where the occupant sits, and detects the weight applied to the seat. The weight sensor 49 outputs sensor data indicating the weight applied to the seat to the area B-ECU 40. In this embodiment, an example of providing the weight sensor 49 is described, but it is also possible to detect the seating or non-seating (leaving) of a person based on the detection results of a pressure sensor, a human sensor, etc. instead of the weight sensor 49. The area B-ECU 40 outputs the sensor data input from the weight sensor 49 to the central ECU 10.
[0040] The key authentication ECU 50 and the image authentication ECU 60 are connected to the area B-ECU 40. The key authentication ECU 50 serves as the first control unit. The image authentication ECU 60 serves as the second control unit. The key authentication ECU 50 is connected to an LF / RF antenna 55 for wireless communication with the portable device 5. The portable device 5 is an electronic device with wireless communication capabilities and is known as a smart key or FOB key. Alternatively, the portable device 5 may be a smartphone used as a digital key.
[0041] The key authentication ECU 50 is an electronic control unit comprising a first memory 51 and a first processor 53. The first memory 51 is comprised of, for example, a nonvolatile semiconductor memory, or a combination of volatile and nonvolatile semiconductor memory. The first processor 53 is an arithmetic processing unit comprised of a CPU (Central Processing Unit) and an MPU (Micro Processor Unit). The first processor 53 may be a single processor or a plurality of processors.
[0042] The first memory 51 stores a first program as a control program executed by the first processor 53 and a key ID. The key ID is an ID for the vehicle control system 1 to identify the portable device 5, and a different value is assigned to each portable device 5.
[0043] The first processor 53 executes a first program to perform authentication processing. Upon receiving the key ID of the portable device 5 via the LF / RF antenna 55, the first processor 53 determines whether the received key ID matches the key ID stored in the first memory 51. The key ID corresponds to the first authentication information. If the received key ID matches the key ID stored in the first memory 51, the first processor 53 instructs the area B-ECU 40 to unlock or lock the door locks. Based on the instruction from the key authentication ECU 50, the area B-ECU 40 instructs the door lock mechanism 47 to unlock or lock the door locks. Furthermore, the key authentication ECU 50 outputs information indicating the communication status between the portable device 5 and the LF / RF antenna 55 to the area B-ECU 40. The area B-ECU 40 then outputs the communication status information received from the key authentication ECU 50 to the central ECU 10.
[0044] The image authentication ECU 60 is connected to a camera 65. The camera 65 is a digital camera, and is installed in the vehicle 3 so as to be able to capture the face of a passenger outside the vehicle on the driver's side. The camera 65 is, for example, located on the driver's side B-pillar, the roof edge, or a side mirror.
[0045] The image authentication ECU 60 is an electronic control unit including a second memory 61 and a second processor 63. The second memory 61 is composed of, for example, a nonvolatile semiconductor memory or a volatile and nonvolatile semiconductor memory. The second processor 63 is an arithmetic processing unit composed of a CPU or an MPU.
[0046] The second memory 61 stores a second program and feature data, which are control programs executed by the second processor 63. The feature data is data representing features of the passenger's face and is extracted from a captured image of the passenger's face.
[0047] The image authentication ECU 60 activates the camera 65 and acquires an image captured by the camera 65. The image authentication ECU 60 extracts facial features from the image captured by the camera 65 and authenticates the user based on the comparison of these features with the features stored in the second memory 61. The facial features correspond to the second authentication information. If the features match, the image authentication ECU 60 instructs the region B-ECU 40 to unlock the doors. The region B-ECU 40, in accordance with the instruction from the image authentication ECU 60, instructs the door lock mechanism 47 to unlock the doors.
[0048] Figure 2 2 is a block diagram showing the configuration of the central ECU 10 .
[0049] Will refer to Figure 2 The configuration of the central ECU 10 is described.
[0050] The central ECU 10 is an electronic control unit that includes a third memory 110 and a third processor 130. The third memory 110 is composed of, for example, a nonvolatile semiconductor memory, or a combination of volatile and nonvolatile semiconductor memories. The third memory 110 stores a third program 111 and map data 113, which are executed by the third processor 130. Furthermore, the third memory 110 serves as a calculation area for the third processor 130.
[0051] The third processor 130 is an arithmetic processing device composed of a CPU or an MPU. The third processor 130 may be composed of a single processor or a plurality of processors.
[0052] The central ECU 10 includes an information acquisition unit 131, a vehicle exit detection unit 133, a program update unit 135, and a determination unit 137 as functional components. These functional components are functions obtained by the third processor 130 executing the third program 111 and performing calculations.
[0053] The information acquisition unit 131 acquires information from the key authentication ECU 50 and the area B-ECU 40. For example, the information acquisition unit 131 acquires information indicating the communication status with the portable device 5 from the key authentication ECU 50. The information acquisition unit 131 also acquires information indicating the status of the door locks and sensor data from the weight sensor 49 from the area B-ECU 40.
[0054] The vehicle exit detection unit 133 detects the passenger's exit from the vehicle. The vehicle exit detection unit 133 detects the passenger's exit based on sensor data from the weight sensor 49. The vehicle exit detection unit 133 may also determine that the passenger has exited the vehicle based on the communication status between the key authentication ECU 50 and the portable device 5. For example, the vehicle exit detection unit 133 may determine that the passenger has exited the vehicle 3 if the communication status between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state.
[0055] When an update is required for a program executed by an electronic control unit mounted on vehicle 3, program update unit 135 downloads the updated program from server device 300. Program update unit 135 temporarily stores the obtained updated program in third memory 110. At a predetermined timing, program update unit 135 causes the target electronic control unit to update the downloaded program.
[0056] If the downloaded update program updates the second program executed by the image authentication ECU 60 and the determination unit 137 determines that program update is permitted, the program update unit 135 causes the image authentication ECU 60 to update the second program executed by the image authentication ECU 60 to the updated program.
[0057] When the update program downloaded by the program update unit 135 is a program for updating the second program, the determination unit 137 determines whether to permit the image authentication ECU 60 to update to the updated program based on the communication status between the key authentication ECU 50 and the portable device 5 .
[0058] When the key authentication ECU 50 and the portable device 5 are in a state in which communication is possible, the determination unit 137 permits the image authentication ECU 60 to update the program.
[0059] For example, if the key authentication ECU 50 and the portable device 5 are in a communicable state, the image authentication ECU 60 program update permission operation is accepted, and it is detected that the portable device 5 is taken outside the vehicle, the determination unit 137 permits the program update unit 135 to update the second program of the image authentication ECU 60.
[0060] In addition, even if the key authentication ECU 50 and the portable device 5 are in a state where communication is possible, but the permission operation for permitting the image authentication ECU 60 to update the program has not been received, when it is detected that the portable device 5 has been taken out of the vehicle, the determination unit 137 may allow the program update unit 135 to update the second program of the image authentication ECU 60.
[0061] Regarding the portable device 5 being taken out of the vehicle, for example, when the communication state between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state, and the vehicle exit detection unit 133 determines that the passenger has been detected exiting the vehicle, the determination unit 137 determines that the portable device 5 has been taken out of the vehicle.
[0062] Figure 3 1 shows an example of a permission request screen 150 that the central ECU 10 displays on the touch panel 16 when the second program is updated. The permission request screen 150 corresponds to an example of a guidance screen.
[0063] The permission request screen 150 displays a message indicating that the second program executed by the image authentication ECU 60 is to be updated, and a message inquiring whether to permit the program update of the image authentication ECU 60. Furthermore, the permission request screen 150 displays a message requesting that the portable device 5 be taken out of the vehicle if the program update of the image authentication ECU 60 is permitted and the vehicle is moved outside the vehicle.
[0064] In addition, a radio button 151 for permitting program update, a radio button 153 for rejecting program update, and a decision button 155 are displayed on the permission request screen 150 .
[0065] When the passenger approves the program update, the passenger selects the radio button 151 and presses the decision button 155. When the passenger rejects the program update, the passenger selects the radio button 153 and presses the decision button 155.
[0066] Next, a case will be described where the determination unit 137 accepts a permission operation for permitting program update on the permission request screen 150 , but the passenger gets out of the vehicle while leaving the mobile device 5 in the vehicle.
[0067] When the determination unit 137 determines that the portable device 5 remains inside the vehicle despite the vehicle exit detection unit 133 detecting that the occupant has exited the vehicle, it obtains latitude and longitude information indicating the location of the vehicle 3 from the GNSS sensor 15. Based on the obtained latitude and longitude information, the determination unit 137 references the map data 113 and obtains facility information for the facility where the vehicle 3 is parked. The GNSS sensor 15 and the central ECU 10 function as a position detection device.
[0068] Determination unit 137 first determines whether the acquired latitude and longitude information is a location registered as home. If the acquired latitude and longitude information is a location registered as home, determination unit 137 does not determine whether to permit the image authentication ECU 60 to update the program based on the communication status between the portable device 5 and the key authentication ECU 50. Determination unit 137 then determines whether to permit the update of the second program executed by the second control unit. If the vehicle's location is a location registered as home, a spare portable device, such as one from home, can be used to unlock the vehicle. This reduces the likelihood of passengers being unable to board or drive the vehicle.
[0069] Based on the acquired facility information, the determination unit 137 obtains a predicted length of time the passenger will stay at the facility indicated in the facility information. For example, the determination unit 137 stores the types of facilities the passenger has previously stayed at and the average length of stay at facilities in that category in the third memory 110 as a history of their behavior. Examples of facility categories include information indicating the type of facility, such as supermarkets, convenience stores, amusement parks, and karaoke parlors. The determination unit 137 may also calculate the average length of stay for each facility and store it in the third memory 110. Alternatively, the average length of stay for multiple users may be calculated for each facility or facility category and registered in a server device (not shown). The determination unit 137 obtains the facility category indicated in the acquired facility information and transmits an acquisition request to the server device containing the acquired category information and the average length of stay. Upon receiving the acquisition request from the vehicle 3, the server device obtains the facility category indicated by the information included in the acquisition request and obtains the average length of stay at facilities corresponding to the acquired category. The server device transmits the obtained average length of stay to the vehicle 3 that received the acquisition request.
[0070] When the determination unit 137 obtains the predicted duration of the occupant's stay at the facility, it compares the obtained predicted duration with the update time required for updating the second program. If the predicted duration is longer than the update time, the determination unit 137 permits the image authentication ECU 60 to update the second program. If the predicted duration is shorter than the update time, the determination unit 137 does not permit the image authentication ECU 60 to update the second program.
[0071] In addition, the determination unit 137 prohibits the image authentication ECU 60 from updating the program when the key authentication ECU 50 and the portable device 5 are unable to communicate. In addition, the determination unit 137 prohibits the image authentication ECU 60 from updating the program when the key authentication ECU 50 and the portable device 5 are unable to communicate. Figure 3 The permission request screen 150 shown is displayed on the touch panel 16 .
[0072] While the key authentication ECU 50 is updating the first program, the determination unit 137 does not permit the image authentication ECU 60 to update the second program. Specifically, the determination unit 137 manages the execution timing of the update processes of the key authentication ECU 50 and the image authentication ECU 60 so that the key authentication ECU 50's update of the first program and the image authentication ECU 60's update of the second program do not overlap.
[0073] [2. Operation of the Central ECU in the First Embodiment]
[0074] Figure 4 1 is a flowchart showing the operation of the central ECU 10. Figure 4 The flowchart shown explains the operation of the central ECU 10 .
[0075] The central ECU 10 determines whether there is an update program downloaded from the server device 300 (step SA1 ). If there is no update program downloaded (step SA1 / No), the central ECU 10 waits until the update program is downloaded from the server device 300 .
[0076] When there is a downloaded update program (step S1A / YES), the central ECU 10 determines whether this downloaded update program is an update program of the second program executed by the image authentication ECU 60 (step SA2).
[0077] When the downloaded update program is not the update program of the second program (step SA2 / No), the central ECU 10 ends this processing flow and executes another processing flow.
[0078] When the downloaded update program is the update program of the second program (step SA2 / Yes), the central ECU 10 determines whether the key authentication ECU 50 is in a state capable of communicating with the portable device 5 (step SA3 ).
[0079] When the key authentication ECU 50 and the portable device 5 are unable to communicate (step SA3 / No), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11 ), and ends this processing flow.
[0080] When the key authentication ECU 50 and the portable device 5 are able to communicate (step SA3 / Yes), the central ECU 10 causes the touch panel 16 to display a permission request screen 150 requesting the occupant to permit the second program update (step SA4). This permission request screen 150 displays a radio button 151 for permitting the program update, a radio button 153 for rejecting the program update, and an OK button 155. Furthermore, permission request screen 150 displays guidance requesting the removal of the portable device 5 when permitting the program update by the image authentication ECU 60 and moving the device outside the vehicle. To permit the program update, the occupant selects radio button 151 and presses OK button 155.
[0081] The central ECU 10 determines whether a permission operation is received (step SA5 ). If a rejection operation is received but a permission operation is not received (step SA5 / No), the central ECU 10 does not permit the image authentication ECU 60 to update the second program (step SA11 ).
[0082] When the permission operation is received (step SA5 / YES), the central ECU 10 determines whether the occupant has exited the vehicle 3 while carrying the portable device 5 (step SA6). The central ECU 10 detects the occupant's exit based on sensor data from the weight sensor 49. Furthermore, if the communication status between the key authentication ECU 50 and the portable device 5 changes from a communicable state to a non-communicable state, the central ECU 10 determines that the portable device 5 has been taken outside the vehicle upon detecting the occupant's exit.
[0083] When the central ECU 10 determines that the portable device 5 has been taken outside the vehicle (step SA6 / Yes), it permits the program update of the image authentication ECU 60 (step SA10 ), and ends this processing flow.
[0084] If the portable device 5 has not been taken outside the vehicle (step SA6 / No), the central ECU 10 obtains the latitude and longitude information indicating the location of the vehicle 3, as calculated by the GNSS sensor 15. Based on the obtained latitude and longitude information, the central ECU 10 references the map data 113 and obtains facility information for facilities within the site that include the obtained latitude and longitude (step SA7). Furthermore, if no facilities within the site include the obtained latitude and longitude, the central ECU 10 may obtain facility information for facilities within a predetermined range of the latitude and longitude.
[0085] Next, the central ECU 10 obtains a predicted duration of stay at the facility in the obtained facility information based on the occupant's behavioral history (step SA8). For example, the third memory 110 may store the categories of facilities the occupant has previously visited and the average duration of stay at facilities of that category as the occupant's behavioral history. The central ECU 10 obtains the average duration of stay at the facility corresponding to the facility information as the predicted duration.
[0086] Next, the central ECU 10 determines whether the average dwell time obtained in step SA8 is longer than the update time required for the image authentication ECU 60 program update (step SA9). If the predicted dwell time is longer than the update time (step SA9 / Yes), the central ECU 10 permits the image authentication ECU 60 to perform the program update (step SA10). If the predicted dwell time is less than the update time (step SA9 / No), the central ECU 10 disallows the image authentication ECU 60 from performing the program update (step SA11), terminating the process.
[0087] [3. Operation of the Central ECU in the Second Embodiment]
[0088] Next, a second embodiment will be described with reference to the drawings.
[0089] The configuration of the vehicle control system 1 of the second embodiment is the same as that of the first embodiment, and therefore the description of the configuration of the vehicle control system 1 will be omitted.
[0090] In the second embodiment, when the central ECU 10 downloads the update program of the image authentication ECU 60 from the server device 300 , it inquires the key authentication ECU 50 about the communication status with the portable device 5 .
[0091] When the central ECU 10 receives a response from the key authentication ECU 50 indicating that the communication status with the portable device 5 is enabled, the touch panel 16 displays Figure 5The first setting screen 200 is shown. If the central ECU 10 receives a reply from the key authentication ECU 50 that the communication state with the portable device 5 is not communicateable, the touch panel 16 displays Figure 6 The second setting screen 250 is shown.
[0092] Figure 5 1 is a diagram showing an example of a first setting screen 200 that the central ECU 10 displays on the touch panel 16 .
[0093] The first setting screen 200 displays a guidance display notifying the image authentication ECU 60 of a program update. The first setting screen 200 also displays a radio button 211 for selecting "Permit" program update, a radio button 213 for selecting "Reject", and a decision button 215.
[0094] When the passenger approves the program update, the passenger selects the radio button 211 and presses the decision button 215 . When the passenger rejects the program update, the passenger selects the radio button 213 and presses the decision button 215 .
[0095] Figure 6 1 is a diagram showing an example of a second setting screen 250 that the central ECU 10 displays on the touch panel 16. The second setting screen 250 corresponds to a setting screen.
[0096] A first display field 260 , a second display field 270 , and a determination button 280 are displayed on the second setting screen 250 .
[0097] A guidance display notifying the image authentication ECU 60 of a program update is displayed in first display field 260. Also displayed in first display field 260 are a radio button 261 for selecting "Apply" for program updates and a radio button 263 for selecting "Reject." To approve the program update, the occupant selects radio button 261. To disapprove the program update, the occupant selects radio button 263.
[0098] Second display field 270 displays a warning message in the event that the image authentication ECU 60 program update fails. This warning message serves as a prescribed guidance. For example, second display field 270 displays a message stating that if the image authentication ECU 60 program update fails, the image authentication ECU 60 may not operate, making it impossible to unlock the door locks using facial recognition. Furthermore, second display field 270 displays guidance asking passengers whether to lock the doors when exiting the vehicle. Second display field 270 displays a radio button 271 for selecting "Lock" and a radio button 273 for selecting "Unlock." Radio buttons 271 and 273 displayed in second display field 270 are selectable when radio button 261 is selected in first display field 260.
[0099] The passenger selects radio button 261 to approve the image authentication ECU 60 program update. Alternatively, the passenger selects radio button 263 to deny the image authentication ECU 60 program update. Furthermore, the passenger selects radio button 271 to lock the vehicle doors upon exiting the vehicle. Alternatively, the passenger selects radio button 273 to leave the vehicle doors unlocked. The passenger selects radio button 261 or 263, or radio button 271 or 273, and presses enter button 280.
[0100] When the first setting screen 200 is displayed, the communication status between the key authentication ECU 50 and the portable device 5 is enabled. Therefore, even if the image authentication ECU 60 program update is permitted, the occupant can still board the vehicle 3 by operating the portable device 5. Therefore, the central ECU 10 does not display a warning message on the first setting screen 200 in the event that the image authentication ECU 60 program update fails.
[0101] When the key authentication ECU 50 and the portable device 5 are communicating, and the radio button 211 is selected on the first setting screen 200, the central ECU 10 determines that an operation has been received to permit a program update for the image authentication ECU 60. In this case, upon detecting that the occupant has exited the vehicle, the central ECU 10 instructs the region B-ECU 40 to lock the vehicle doors, permitting a program update for the image authentication ECU 60. In response to the instruction from the central ECU 10, the region B-ECU 40 controls the door lock mechanism 47 to lock the doors.
[0102] Furthermore, if the communication status between the key authentication ECU 50 and the portable device 5 is enabled and the radio button 213 is selected in the first setting screen 200, the central ECU 10 determines that a rejection operation has been received to reject the program update of the image authentication ECU 60. In this case, the central ECU 10 prohibits the program update of the image authentication ECU 60 and does not cause the image authentication ECU 60 to execute the program update.
[0103] Furthermore, if the key authentication ECU 50 and the portable device 5 are unable to communicate, and radio buttons 261 and 271 are selected on the second setting screen 250, the central ECU 10 determines that both the permission operation for program updating and the door lock operation have been accepted. In this case, upon detecting the occupant's exit from the vehicle, the central ECU 10 instructs the region B-ECU 40 to lock the vehicle doors and permits the image authentication ECU 60 to update the program. In response to the instruction from the central ECU 10, the region B-ECU 40 controls the door lock mechanism 47 to lock the doors.
[0104] Furthermore, if the key authentication ECU 50 and the portable device 5 are unable to communicate, and if radio buttons 261 and 273 are selected on the second setting screen 250, the central ECU 10 determines that both a permission operation to permit a program update and an unlock operation to prevent the doors from being locked have been accepted. If the central ECU 10 detects the occupant exiting the vehicle, it permits the program update to the image authentication ECU 60 but does not instruct the zone B-ECU 40 to lock the doors.
[0105] Furthermore, upon receiving a permission operation to permit program updates and an unlock operation to prevent the doors from being locked, the central ECU 10 transmits an instruction to the area A-ECU 30 to prohibit the driving of the drive device 31. Furthermore, the central ECU 10 may be configured not to transmit an instruction signal to the area A-ECU 30 to lock the doors of the vehicle 3. Upon receiving the instruction from the central ECU 10, the area A-ECU 30 prohibits the driving of the drive device 31, rendering the vehicle 3 unable to travel. This prevents the theft of the vehicle 3. The prohibition of the driving of the drive device 31 continues, for example, until the occupant operates the portable device 5 and the key authentication ECU 50 receives the key ID from the portable device 5. Furthermore, the prohibition of the driving of the drive device 31 continues, for example, until the program update of the image authentication ECU 60 is completed and the image authentication ECU 60 authenticates the occupant based on images captured by the camera 65.
[0106] If the communication status between the key authentication ECU 50 and the portable device 5 is not established and the radio button 263 is selected on the second setting screen 250, the central ECU 10 determines that a rejection operation for rejecting the program update has been received. In this case, the central ECU 10 prohibits the image authentication ECU 60 from performing the program update and does not cause the image authentication ECU 60 to execute the program update.
[0107] Figure 7 This is a flowchart showing the operation of the central ECU 10 according to the second embodiment.
[0108] Reference Figure 7 The flowchart shown explains the operation of the central ECU 10 .
[0109] The central ECU 10 determines whether there is an update program downloaded from a server (not shown) (step SB1 ). If there is no update program downloaded (step SB1 / No), the central ECU 10 waits until the update program is downloaded from the server.
[0110] When there is a downloaded update program (step SB1 / Yes), the central ECU 10 determines whether the downloaded update program is an update program of the program executed by the image authentication ECU 60 (step SB2 ).
[0111] When the downloaded update program is not the update program for the image authentication ECU 60 (step SB2 / No), the central ECU 10 ends this processing flow and executes another processing flow.
[0112] If the downloaded update program is for the image authentication ECU 60 (step SB2 / Yes), the central ECU 10 inquires of the key authentication ECU 50 whether communication with the portable device 5 is possible. Upon receiving a response from the key authentication ECU 50 confirming that communication with the portable device 5 is possible (step SB3 / Yes), the central ECU 10 causes the touch panel 16 to display the first setting screen 200 (step SB4). The central ECU 10 changes the display of the first setting screen 200 in response to a touch operation on the touch panel 16. For example, the central ECU 10 changes a selected radio button to radio button 211 or 213 in response to a touch operation.
[0113] Next, the central ECU 10 determines whether the decision button 215 is pressed (step SB5 ). If the decision button 215 is not pressed (step SB5 / No), the central ECU 10 waits until the decision button 215 is pressed.
[0114] If the decision button 215 is pressed (step SB5 / Yes), the central ECU 10 determines whether a permission operation for permitting the image authentication ECU 60 to update its program has been accepted on the first setting screen 200 (step SB6). If the permission operation has been accepted (step SB6 / Yes), upon detecting that an occupant has exited the vehicle 3, the central ECU 10 instructs the area B-ECU 40 to lock the doors (step SB7). In response to the instruction from the central ECU 10, the area B-ECU 40 controls the door lock mechanism 47 to lock the doors of the vehicle 3. The central ECU 10 then permits the image authentication ECU 60 to update its program (step SB8).
[0115] If the central ECU 10 does not receive the permission operation for permitting the image authentication ECU 60 program update on the first setting screen 200 (step SB6 / No), it does not permit the image authentication ECU 60 program update (step SB9 ) and ends this processing flow.
[0116] Next, the operation of the central ECU 10 when receiving a response from the key authentication ECU 50 indicating that communication with the portable device 5 is not possible in the determination of step SB3 will be described.
[0117] When receiving a response from the key authentication ECU 50 that communication with the portable device 5 is not possible (step SB3 / No), the central ECU 10 causes the touch panel 16 to display the second setting screen 250 (step SB10 ).
[0118] Next, the central ECU 10 determines whether the decision button 215 is pressed (step SB11 ). When the decision button 215 is not pressed (step SB11 / No), the central ECU 10 waits until the decision button 215 is pressed.
[0119] When the decision button 280 is pressed (step SB11 / Yes), the central ECU 10 determines whether a permission operation for permitting the image authentication ECU 60 to update the program has been accepted on the second setting screen 250 (step SB12). The central ECU 10 determines whether the radio button 261 in the first display field 260 has been selected, and whether the permission operation has been accepted.
[0120] If the central ECU 10 determines that the radio button 263 of the first display field 260 is selected and a rejection operation is accepted (step SB12 / No), it does not permit the image authentication ECU 60 to perform a program update (step SB9 ) and ends this processing flow.
[0121] When the central ECU 10 receives selection of the radio button 261 in the first display field 260 and determines that a permission operation has been received (step SB12 / Yes), it determines whether a setting for locking the doors when exiting the vehicle has been received (step SB13 ).
[0122] Upon receiving a selection of radio button 271 in second display field 270, central ECU 10 determines that the vehicle 3 doors are locked upon exiting the vehicle (step SB13 / Yes). In this case, central ECU 10 instructs region B-ECU 40 to lock the doors (step SB14). Region B-ECU 40 controls door lock mechanism 47 in accordance with the instruction from central ECU 10, locking the vehicle 3 doors. Central ECU 10 then authorizes image authentication ECU 60 to perform a program update (step SB17).
[0123] Furthermore, upon receiving a selection of radio button 273 in second display field 270, central ECU 10 determines that the vehicle 3 door locks have been unlocked upon exit (step SB13 / No). In this case, central ECU 10 transmits an instruction to disable driving device 31 to zone A-ECU 30 (step SB15) and does not instruct zone B-ECU 40 to lock the door locks. Consequently, the vehicle 3 door locks remain unlocked even after the occupant exits the vehicle (step SB16). Subsequently, central ECU 10 authorizes image authentication ECU 60 to perform a program update (step SB17).
[0124] [4. Operation of the Central ECU in the Third Embodiment]
[0125] Next, a third embodiment will be described. The configuration of the vehicle control system 1 is the same as that of the first embodiment described above, and therefore, the description of the configuration of the vehicle control system 1 will be omitted.
[0126] The central ECU 10 of the third embodiment also inquires the key authentication ECU 50 about the communication status with the portable device 5 when downloading the update program for the image authentication ECU 60 from the server device 300. The central ECU 10 of the third embodiment changes the operation when the program update of the image authentication ECU 60 fails, based on the communication status between the key authentication ECU 50 and the portable device 5.
[0127] The central ECU 10 executes the first action when the communication status between the key authentication ECU 50 and the portable device 5 is enabled and the program update of the image authentication ECU 60 fails.
[0128] As a first action, the central ECU 10 sends a failure notification to the portable device 5 held by the driver, the owner of the vehicle 3, as a first notification destination, indicating that the image authentication ECU 60 program update has failed. Furthermore, if the portable device 5 is a smartphone serving as a digital key, the failure notification is sent to the smartphone's registered email address or IP address. This failure notification includes guidance that the portable device 5 needs to unlock the vehicle 3 and start the driving source, such as the engine, installed in the vehicle 3.
[0129] Furthermore, when the central ECU 10 is unable to communicate with the portable device 5 and the program update of the image authentication ECU 60 fails, the central ECU 10 executes the second action.
[0130] As a second operation, the central ECU 10 transmits a failure notification indicating that the program update of the image authentication ECU 60 has failed to a second notification target, wherein the second notification target is the contact information of a portable device owned by a loading service provider or the owner of the vehicle 3, that is, the driver's family.
[0131] Figure 8 1 is a diagram showing an example of the contact destination table 115 in which emergency contact destinations are registered.
[0132] The second notification destination is registered in the contact destination table 115 .
[0133] As the second notification destination, the phone number of the loading service provider company providing the loading service, the email address and phone number of the family of the owner of the vehicle 3, etc. are registered. In addition, when the portable device 5 is a smartphone used as a digital key, the phone number and email address of the owner of the vehicle 3 can also be registered in advance as the first notification destination.
[0134] If communication with the portable device 5 is lost and the image authentication ECU 60 program update fails, the central ECU 10 sends an email containing a failure notification to the email address of the loading service provider or the registered family member's mobile phone. Alternatively, the central ECU 10 may call the loading service provider's phone number or the registered family member's mobile phone to notify the failure, for example, using a voice synthesized by voice synthesis software.
[0135] Furthermore, when the central ECU 10 sends a program update failure notification to the second notification destination, it sends the failure notification including the vehicle 3 location information obtained from the GNSS sensor 15. Including the vehicle 3 location information makes it easier for the loading service provider or the user to locate the vehicle 3.
[0136] Furthermore, if the image authentication ECU 60 program update fails, the central ECU 10 instructs the region B-ECU 40 to unlock the vehicle 3 doors, forcibly unlocking the vehicle 3 doors. There are also cases where a passenger exits the vehicle 3 without the portable device 5. In this case, it is also possible that the image authentication ECU 60 program update failure could prevent the door locks from being unlocked using image authentication. Therefore, the central ECU 10 instructs the region B-ECU 40 to forcibly unlock the vehicle 3 doors.
[0137] Furthermore, the central ECU 10 transmits a prohibition instruction to the area A-ECU 30 to prohibit the driving of the driving device 31. Since the doors of the vehicle 3 remain unlocked, the prohibition instruction is transmitted to the area A-ECU 30 to prevent the vehicle 3 from traveling in order to prevent theft.
[0138] Furthermore, the central ECU 10 continues to supply power from the battery 33 to the TCU 14, maintaining a state in which external communication is possible via the TCU 14. Then, for example, the central ECU 10 causes the touch panel 16 to display the phone number of the loading service provider or the phone number registered as the second notification destination. When the occupant selects a phone number through a touch operation, the central ECU 10 calls the selected phone number, enabling a call.
[0139] Furthermore, the registration of the first and second notification targets can be changed by a touch operation on the touch panel 16 by a passenger or the like. In other words, the notification targets registered as the first and second notification targets can be changed by a touch operation. For example, the phone number of another load service company can be registered as the second notification target, and the email address or phone number of a smartphone held by a passenger, the owner of the vehicle 3, can be registered as the first notification target instead of the mobile device 5.
[0140] Figure 9 and Figure 10 1 is a flowchart showing the operation of the central ECU 10 according to the third embodiment. Figure 9 and Figure 10 The flowchart shown explains the operation of the central ECU 10 .
[0141] The central ECU 10 determines whether an update program has been downloaded from a server (not shown) (step SC1 ). If no update program has been downloaded (step SC1 / No), the central ECU 10 waits until the update program is downloaded from the server.
[0142] When there is a downloaded update program (step SC1 / Yes), the central ECU 10 determines whether the downloaded update program is an update program of the program executed by the image authentication ECU 60 (step SC2 ).
[0143] When the downloaded update program is not the update program for the image authentication ECU 60 (step SC2 / No), the central ECU 10 ends this processing flow and executes another processing flow.
[0144] If the downloaded update program is an update program for the image authentication ECU 60 (step SC2 / Yes), the central ECU 10 inquires the key authentication ECU 50 whether the communication status with the portable device 5 is in a communication-enabled state. If the central ECU 10 receives a reply from the key authentication ECU 50 that the communication with the portable device 5 is in a communication-enabled state (step SC3 / Yes), the touch panel 16 displays Figure 3The first setting screen 200 is shown (step SC4). When the passenger permits the program update, the passenger selects the radio button 151 and presses the decision button 155. When the passenger does not permit the program update, the passenger selects the radio button 153 and presses the decision button 155.
[0145] The central ECU 10 determines whether a permission operation is received (step SC5 ). If a rejection operation is received but a permission operation is not received (step SC5 / No), the central ECU 10 does not allow the image authentication ECU 60 to update the second program (step SC6 ).
[0146] When receiving the permission operation (step SC5 / Yes), the central ECU 10 permits the image authentication ECU 60 to update the program (step SC7 ).
[0147] The central ECU 10 then determines whether the image authentication ECU 60 program update was successful (step SC8). If the image authentication ECU 60 program update was unsuccessful (step SC8 / No), the central ECU 10 notifies the portable device 5 that key authentication by the portable device 5 is required (step SC9). At this point, the central ECU 10 notifies the portable device 5 that the image authentication ECU 60 program update failed.
[0148] If the program update of the image authentication ECU 60 is successful (step SC8 / Yes), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC10 ). At this time, the central ECU 10 may also send a guidance instructing the portable device 5 to perform face authentication.
[0149] The image authentication ECU 60, in response to instructions from the central ECU 10, causes the camera 65 to capture images and extracts the passenger's facial image from the captured image. The image authentication ECU 60 extracts facial features from the image captured by the camera 65 and authenticates the user based on a comparison of the extracted features with those stored in the second memory 61.
[0150] Next, refer to Figure 10 The flowchart shown here will explain the operation when a response indicating that communication with the portable device 5 is not possible is received from the key authentication ECU 50 in the determination of step SC3 .
[0151] The central ECU 10 causes the touch panel 16 to display Figure 3 The first setting screen 200 is shown (step SC11). When the passenger permits program updating, the passenger selects radio button 151 and presses decision button 155. When the passenger does not permit program updating, the passenger selects radio button 153 and presses decision button 155.
[0152] The central ECU 10 determines whether a permission operation is received (step SC12). If a rejection operation is received but no permission operation is received (step SC12 / No), the central ECU 10 does not allow the image authentication ECU 60 to update the second program (step SC21) and ends this processing flow.
[0153] When receiving the permission operation (step SC12 / Yes), the central ECU 10 permits the image authentication ECU 60 to update the program (step SC13 ) Thereafter, the central ECU 10 determines whether the program update of the image authentication ECU 60 is successful (step SC14 ).
[0154] If the program update of the image authentication ECU 60 is successful (step SC14 / Yes), the central ECU 10 instructs the image authentication ECU 60 to perform image authentication (step SC15) in the same manner as step SC10. At this time, the central ECU 10 may also send a guidance instructing the mobile device 5 to perform face authentication.
[0155] If the image authentication ECU 60 program update fails (step SC14 / No), the central ECU 10 obtains the vehicle 3's location information from the GNSS sensor 15 (step SC16). The central ECU 10 then refers to the contact destination table 115 and notifies the notification destination registered as the second notification destination of the failure to update the image authentication ECU 60 program (step SC17). This notification destination can be a loading service provider or the contact information of the vehicle 3 owner's family members registered in the contact destination table 115.
[0156] Next, the central ECU 10 instructs the zone B-ECU 40 to release the door locks (step SC18 ), thereby forcibly unlocking the doors.
[0157] Next, the central ECU 10 controls the area A-ECU 30 to maintain power supply to the TCU 14, thereby activating the TCU 14. For example, if the central ECU 10 selects the phone number of a company providing an onboarding service by touching the touch panel 16, the central ECU 10 calls the selected number via the TCU 14.
[0158] Furthermore, the central ECU 10 transmits an instruction to prohibit the driving of the driving device 31 to the zone A-ECU 30 (step SC20 ).
[0159] The above-described embodiment is a preferred embodiment of the present invention, but the present invention is not limited thereto and various modifications can be made without departing from the spirit of the present invention.
[0160] For example, Figure 1 The structure of the vehicle control system 1 shown in Figure 2 The structure of the central ECU 10 shown in FIGURE 1 illustrates a functional structure, and its specific implementation is not particularly limited. Specifically, it is not necessary to install hardware corresponding to each functional unit. Alternatively, a single processor executing a program can implement the functions of multiple functional units. Furthermore, in the above-described embodiments, a portion of the functions implemented by software can be implemented by hardware, and vice versa.
[0161] in addition, Figure 4 、 Figure 7 、 Figure 9 as well as Figure 10 The processing units in the flowchart shown are units divided according to the main processing contents in order to facilitate understanding of the processing of the central ECU 10. The present invention is not limited to Figure 4 、 Figure 7 、 Figure 9 as well as Figure 10 The method of dividing the processing units shown in the flowcharts and the name restrictions are not applicable. Furthermore, depending on the processing content, the processing of the central ECU 10 may be divided into more processing units, or a single processing unit may be divided to include more processing. Furthermore, the processing order of the flowcharts is not limited to the example shown.
[0162] [5. Structure supported by the above-mentioned embodiment]
[0163] The above-mentioned embodiment is a specific example of the following structure.
[0164] (Structure 1)
[0165] A vehicle control system, wherein the vehicle control system comprises: a first control device, which obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device, which obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; a locking mechanism, which locks the doors of the vehicle; an acceptance device, which accepts an operation; and an update management device, which, when the communication status between the first control device and the portable device is non-communicable and an update program for updating the program executed by the second control device is obtained, causes the vehicle-mounted display device installed in the vehicle to display a setting screen, the setting screen accepting a setting of whether to permit execution of the program update of the second control device and a setting of whether the vehicle needs to be locked after getting off the vehicle, and the update management device controls the second control device and the locking mechanism according to the setting accepted by the setting screen.
[0166] When the vehicle control system of Configuration 1 receives an update program for updating the program executed by the second control unit, a setting screen is displayed on the vehicle display device to accept settings for whether to allow the second control unit program update and whether to lock the vehicle after exiting the vehicle. The second control unit and locking mechanism are controlled according to the settings accepted on the setting screen. Thus, the user can set whether to allow the second control unit program update and whether to lock the vehicle after exiting the vehicle. By accepting responses from the occupant to problems that may arise during the vehicle program update, user convenience can be improved.
[0167] (Structure 2)
[0168] According to the vehicle control system of Configuration 1, when the program update of the second control device fails, the update management device displays a predetermined guidance on the setting screen.
[0169] The vehicle control system of Configuration 2 displays a predetermined guidance on the setting screen when the program update of the second control device fails. Therefore, the occupant can be made aware of the failure of the program update of the second control device.
[0170] (Structure 3)
[0171] According to the vehicle control system of structure 1 or 2, the update management device is provided with a getting-off detection unit for detecting when an occupant gets off the vehicle. When the acceptance device accepts an operation of locking the vehicle after selecting to get off, when the getting-off detection unit detects the occupant getting off the vehicle, the update management device sends an indication signal indicating the locking of the vehicle door to the locking mechanism, and after sending the indication signal, executes a program update of the second control device.
[0172] When the update management device of Structure 3 receives an operation to lock the vehicle after exiting the vehicle, it executes the program update of the second control device while the vehicle doors are locked. Therefore, the program update of the second control device can be executed while preventing the vehicle from being stolen.
[0173] (Structure 4)
[0174] According to the vehicle control system of structure 1 or 2, the vehicle control system includes a drive source control device for controlling a drive source mounted on the vehicle, and the update management device includes a get-off detection unit for detecting when an occupant gets off the vehicle. When the acceptance device accepts an operation that does not require locking the vehicle after selecting to get off, and when the get-off detection unit detects that the occupant has gotten off the vehicle, the update management device sends an indication signal to the drive source control device indicating that driving of the drive source is prohibited.
[0175] According to the vehicle control system of Configuration 4, when an operation is received to select that the vehicle does not need to be locked after exiting the vehicle, if the occupant's exiting the vehicle is detected, the drive source control device is instructed to prohibit driving the drive source. Therefore, even if the vehicle is unlocked, the drive source is not driven and the vehicle does not travel, thereby preventing vehicle theft.
[0176] (Structure 5)
[0177] According to the vehicle control system of configuration 4, the update management device does not send an instruction signal for instructing the locking of the vehicle doors to the locking mechanism, and executes the program update of the second control device in a state where the vehicle doors are unlocked.
[0178] According to the vehicle control system of Configuration 5, when an operation is received in which the user selects that the vehicle does not need to be locked after exiting the vehicle, the locking mechanism is not sent an instruction signal for locking the vehicle doors. Therefore, even if the program update of the second control device is executed while the vehicle doors are unlocked, the program update of the second control device fails and the second control device does not operate, thereby preventing the occupants from being unable to board the vehicle.
[0179] (Structure 6)
[0180] A control method for a vehicle control system, the vehicle control system comprising: a first control device that obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; a locking mechanism that locks the doors of the vehicle; an acceptance device that accepts an operation; and an update management device that manages updates of programs executed by the first control device and the second control device, wherein the control method includes the following processing: when the communication status between the first control device and the portable device is non-communicable and an update program for updating the program executed by the second control device is obtained, causing an on-board display device mounted on the vehicle to display a setting screen, the setting screen accepting a setting of whether to permit execution of the program update of the second control device and a setting of whether to lock the vehicle after getting off the vehicle, and controlling the second control device and the locking mechanism according to the settings accepted by the setting screen.
[0181] In the vehicle control system control method of Configuration 6, when an update program for updating a program executed by a second control unit is obtained, a setting screen is displayed on the vehicle display device, which accepts settings for whether to permit the second control unit program update and whether to lock the vehicle after exiting the vehicle. The second control unit and the locking mechanism are controlled according to the settings accepted on the setting screen. Thus, the user can set whether to permit the second control unit program update and whether to lock the vehicle after exiting the vehicle. Therefore, by accepting responses from the occupant to problems that may arise during the vehicle program update, user convenience can be improved.
[0182] Description of Reference Numerals
[0183] 1…Vehicle Control System, 3…Vehicle, 3a…First Communication Line, 3b…First Communication Line, 4a…Second Communication Line, 4b…Second Communication Line, 5…Portable Device, 10…Central ECU, 11…ICB, 12…Speaker, 13…Microphone, 14…TCU, 15…GNSS Sensor, 16…Touch Panel, 17…Display, 18…Touch Sensor, 19…In-Vehicle Connectivity Link, 20…DMC, 30…Area A-ECU, 31…Drive Unit, 33…Battery, 40…Area B-ECU, 41…Lamp Body, 43…Window Motor, 45…Door Sensor, 47…Door Lock Mechanism, 49…Weight Sensor, 50…Key Authentication ECU, 51…First Memory, 53…First Processor, 55…LF / RF Antenna, 60…Image Authentication ECU, 61… 1…Second memory, 63…Second processor, 65…Camera, 110…Third memory, 111…Third program, 113…Map data, 115…Contact target table, 130…Third processor, 131…Information acquisition unit, 133…Get-off detection unit, 135…Program update unit, 137…Determination unit, 150…Permission request screen, 151…Radio button, 153…Radio button, 155…Decision button, 200…First setting screen, 211…Radio button, 213…Radio button, 215…Decision button, 250…Second setting screen, 260…First display field, 261…Radio button, 263…Radio button, 270…Second display field, 271…Radio button, 273…Radio button, 280…Decision button, 300…Server device, 350…Network.
Claims
1. A vehicle control system comprising: a first control device that obtains first authentication information through wireless communication with the portable device and controls locking and unlocking of the vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on the image captured by the camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; a locking mechanism that locks the doors of the vehicle; an acceptance device, which accepts operations; as well as An update management device, which, when the communication status between the first control device and the portable device is non-communicable and an update program for updating the program executed by the second control device is obtained, causes the vehicle-mounted display device installed in the vehicle to display a setting screen, and the setting screen accepts settings for whether to permit the execution of the program update of the second control device and whether the vehicle needs to be locked after getting off the vehicle. The update management device controls the second control device and the locking mechanism according to the settings accepted by the setting screen.
2. The vehicle control system according to claim 1, wherein: When the program update of the second control device fails, the update management device displays a predetermined guidance on the setting screen.
3. The vehicle control system according to claim 1 or 2, wherein: The update management device includes a vehicle getting-off detection unit for detecting when a passenger gets off the vehicle. In the case where the acceptance device accepts the operation of locking the vehicle after the passenger chooses to get off the vehicle, when the getting off detection unit detects the passenger getting off the vehicle, the update management device sends an instruction signal to the locking mechanism to instruct the passenger to lock the vehicle door, and after sending the instruction signal, executes the program update of the second control device.
4. The vehicle control system according to claim 1 or 2, wherein: The vehicle control system includes a drive source control device for controlling a drive source mounted on the vehicle. The update management device includes a vehicle getting-off detection unit for detecting when a passenger gets off the vehicle. When the acceptance device accepts an operation that selects not to lock the vehicle after getting off, and the getting off detection unit detects the occupant getting off the vehicle, the update management device sends an instruction signal to the drive source control device to instruct the drive source to be prohibited.
5. The vehicle control system according to claim 4, wherein: The update management device does not send an instruction signal to the locking mechanism to instruct locking of the vehicle doors, and executes program update of the second control device in a state where the vehicle doors are unlocked.
6. A control method for a vehicle control system, the vehicle control system comprising: a first control device that obtains first authentication information through wireless communication with a portable device and controls locking and unlocking of a vehicle based on the obtained first authentication information; a second control device that obtains second authentication information based on an image captured by a camera and controls locking and unlocking of the vehicle based on the obtained second authentication information; a locking mechanism that locks a door of the vehicle; an acceptance device, which accepts operations; and an update management device for managing updates of programs executed by the first control device and the second control device, wherein the control method includes the following processing: When the communication state between the first control device and the portable device is not communicable and an update program for updating the program executed by the second control device is obtained, a setting screen is displayed on the vehicle-mounted display device of the vehicle, and the setting screen accepts a setting of whether to permit the execution of the program update of the second control device and whether the vehicle needs to be locked after getting off the vehicle. The second control device and the locking mechanism are controlled according to the setting accepted on the setting screen.
Citation Information
Patent Citations
Program rewriting system
JP2006082648A