In-vehicle network management system and in-vehicle network management method
By generating the latest vehicle configuration information through the configuration management department and the update management department, and setting up the relay processing of messages through the relay management department, the problem of inappropriate relay processing caused by hardware changes and software updates in the vehicle network is solved, and the stable operation of the vehicle network is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SUMITOMO ELECTRIC INDUSTRIES LTD
- Filing Date
- 2024-11-06
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies make it difficult to properly configure packet relay processing in vehicular networks, especially when hardware configurations change or software is updated, and cannot effectively adjust relay processing to adapt to the latest network conditions.
The configuration management department monitors changes in hardware configuration and updates the latest vehicle configuration information generated and provided by the management department. Based on this information, the relay management department sets up relay processing for messages, including generating topology mapping tables and vehicle configuration tables, to ensure the appropriateness of relay processing.
It enables the automatic and simple generation of the latest vehicle configuration information and appropriate message relay processing settings when hardware configuration changes or software is updated, ensuring the stable operation of the vehicle network.
Smart Images

Figure CN122139341A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to an in-vehicle network management system and an in-vehicle network management method.
[0002] This application claims priority from Japanese Application No. 2023-192674 filed on November 13, 2023, the disclosure of which is incorporated herein in its entirety. BACKGROUND
[0003] In Patent Literature 1 (International Publication No. 2020 / 179123), a management device is disclosed as follows. That is, the management device is provided with: a detection section that detects addition of a functional section to a network including one or a plurality of in-vehicle functional sections; an acquisition section that acquires functional section information including information related to a network configuration of a layer lower than an application layer, with respect to each of a new functional section added by the detection section and the in-vehicle functional sections; and a generation section that generates configuration information of a new network including the new functional section, based on each of the functional section information acquired by the acquisition section.
[0004] PRIOR ART DOCUMENTS
[0005] PATENT LITERATURE
[0006] Patent Literature 1: International Publication No. 2020 / 179123
[0007] NON-PATENT LITERATURE
[0008] Non-Patent Literature 1: “ST-OTA-4 OTA Software Update Vehicle System Requirement Definition Book Ver. 1.2”, JasPar OTA Technical WG, January 13, 2023 SUMMARY
[0009] The vehicle network management system disclosed herein includes: an update management unit for updating software (i.e., target software) in the vehicle network that is subject to update processing; a configuration management unit for monitoring the hardware configuration in the vehicle network; and a relay management unit for setting up relay processing for packets in the vehicle network. When the hardware configuration changes, the configuration management unit sends connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit. When the hardware configuration changes, the update management unit sends vehicle configuration information in the vehicle network after the hardware configuration change to the relay management unit. The vehicle configuration information indicates the correspondence between the target software, the vehicle device carrying the target software, and the version of the target software. When the target software is updated, the update management unit sends the vehicle configuration information in the vehicle network containing the updated target software to the relay management unit.
[0010] One aspect of this disclosure can be implemented not only as an in-vehicle network management system with such a characteristic processing unit, but also as a program for causing a computer to perform the steps of that characteristic processing. Furthermore, one aspect of this disclosure can be implemented as a part or all of a semiconductor integrated circuit that implements the in-vehicle network management system. Attached Figure Description
[0011] Figure 1 This is a diagram illustrating an example of the configuration of an in-vehicle network management system according to an embodiment of the present disclosure.
[0012] Figure 2 This is a diagram illustrating the configuration of a relay device according to an embodiment of the present disclosure.
[0013] Figure 3 This is a diagram illustrating an example of an update list stored in the storage unit of a relay device according to an embodiment of the present disclosure.
[0014] Figure 4 This diagram illustrates an example of an inhibition list stored in the storage unit of a relay device according to an embodiment of the present disclosure.
[0015] Figure 5 This is a diagram showing an example of a topology mapping table generated by the configuration management unit in a relay device according to an embodiment of the present disclosure.
[0016] Figure 6 This is a diagram showing an example of a vehicle configuration table generated by the update management unit in the relay device of an embodiment of this disclosure.
[0017] Figure 7 This is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure.
[0018] Figure 8 This is a diagram illustrating an example of an updated topology mapping table for a configuration management unit in a relay device according to an embodiment of this disclosure.
[0019] Figure 9 This is a diagram showing an example of a vehicle configuration table generated by the update management unit in the relay device of an embodiment of this disclosure.
[0020] Figure 10 This is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure.
[0021] Figure 11 This is a diagram showing an example of an updated update list in the update management unit of a relay device according to an embodiment of the present disclosure.
[0022] Figure 12 This is a diagram illustrating an example of an updated suppression list in the update management unit of a relay device according to an embodiment of this disclosure.
[0023] Figure 13 This is a diagram showing an example of a vehicle configuration table generated by the update management unit in the relay device of an embodiment of this disclosure.
[0024] Figure 14 This is a diagram showing an example of a vehicle configuration table generated by the update management unit in the relay device of an embodiment of this disclosure.
[0025] Figure 15 This is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure.
[0026] Figure 16 This is a diagram illustrating an example of an updated topology mapping table for a configuration management unit in a relay device according to an embodiment of this disclosure.
[0027] Figure 17 This is a diagram illustrating an example of an updated suppression list in the update management unit of a relay device according to an embodiment of this disclosure.
[0028] Figure 18 This diagram illustrates an example of the timing of a change in the relay processing settings in an embodiment of the present disclosure's vehicle network management system.
[0029] Figure 19 This diagram illustrates an example of the timing of a change in the relay processing settings in an embodiment of the present disclosure's vehicle network management system. Detailed Implementation
[0030] In recent years, with the increasing popularity of car sharing and the expectation of improved processing power for in-vehicle devices, there has been a demand for customizing in-vehicle networks by adding applications. This necessitates technologies that can add or remove various applications from the in-vehicle network according to user needs.
[0031] [The problem this disclosure aims to solve]
[0032] A technology that exceeds the technology described in Patent Document 1 and Non-Patent Document 1, and is expected to enable the proper setting of message relay processing in vehicle networks.
[0033] The purpose of this disclosure is to provide an in-vehicle network management system and method that can appropriately configure the relay processing of messages in an in-vehicle network.
[0034] [The Effects of This Disclosure]
[0035] According to this disclosure, it is possible to appropriately configure the relay processing of messages in the vehicular network.
[0036] [Description of embodiments of this disclosure]
[0037] First, the contents of the embodiments of this disclosure will be described.
[0038] (1) The vehicle network management system according to the present disclosure includes: an update management unit for updating software, i.e., target software, which is the object of update processing in the vehicle network; a configuration management unit for monitoring the hardware configuration in the vehicle network; and a relay management unit for setting up relay processing of packets in the vehicle network. When the hardware configuration changes, the configuration management unit sends connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit. When the hardware configuration changes, the update management unit sends vehicle configuration information in the vehicle network after the hardware configuration change to the relay management unit. The vehicle configuration information indicates the correspondence between the target software, the vehicle device equipped with the target software, and the version of the target software. When the target software is updated, the update management unit sends the vehicle configuration information in the vehicle network containing the updated target software to the relay management unit.
[0039] With this configuration, in vehicular networks where hardware configuration changes or software updates occur, the connection configuration information of the vehicular network after the hardware configuration change and the vehicle configuration information of the vehicular network including the updated software can be provided to the relay management unit. Therefore, the relay processing of packets in the vehicular network can be configured based on the latest hardware and software configurations. Thus, the relay processing of packets in the vehicular network can be configured appropriately.
[0040] (2) In (1) above, the update management unit may generate the vehicle configuration information based on the update list of the vehicle-mounted device carrying the object software, and update the update list when the vehicle-mounted device carrying the object software is added to the vehicle network.
[0041] With this configuration, for example, when the vehicle device added to the vehicle network is equipped with target software, it is possible to configure the relay processing of messages in the vehicle network to which the vehicle device has been added, based on the latest software configuration that includes the software.
[0042] (3) In (2) above, the update management unit may obtain application information indicating the version of the object software mounted on the vehicle device from the vehicle device shown in the update list, and generate the vehicle configuration information based on the obtained application information.
[0043] Based on this configuration, application information can be obtained from the vehicle-mounted device through communication with the device, and the latest vehicle configuration information in the vehicle network can be generated. Therefore, compared with the configuration of application information received by the user, vehicle configuration information can be generated automatically and simply.
[0044] (4) In any of (1) to (3) above, the update management unit performs a process to suppress the shutdown of the vehicle device carrying the object software to be updated in the update process based on the suppression list of the vehicle device that needs to run in the update process of the object software, and the update management unit updates the suppression list when the vehicle device carrying the object software is added to the vehicle network.
[0045] With this configuration, for example, when an onboard device added to a vehicle network carries target software, the onboard device's operating state can be maintained during software update processing. Therefore, for example, software update processing can be performed during periods when the vehicle's power is off.
[0046] (5) In (4) above, the update management unit may also perform a process of shutting down the relay device that needs to relay messages related to the update process, based on the suppression list.
[0047] With this configuration, for example, when the vehicle-mounted device that sends and receives messages related to update processing with the update management department via a relay device is equipped with target software, the relay device is kept running during the software update process, and the software update process can be performed while the vehicle's power is off.
[0048] (6) The vehicle network management method of the present disclosure is a vehicle network management method in a vehicle network management system. The vehicle network management system includes an update management unit for updating software (i.e., object software) that is the object of update processing in the vehicle network, a configuration management unit for monitoring the hardware configuration in the vehicle network, and a relay management unit for setting relay processing of messages in the vehicle network. The vehicle network management method includes the following steps: when the hardware configuration changes, the configuration management unit sends connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit; when the hardware configuration changes, the update management unit sends vehicle configuration information in the vehicle network after the hardware configuration change to the relay management unit, wherein the vehicle configuration information indicates the correspondence between the object software, the vehicle device carrying the object software, and the version of the object software; and when the object software is updated, the update management unit sends the vehicle configuration information in the vehicle network containing the updated object software to the relay management unit.
[0049] In this way, in vehicular networks where hardware configurations have changed or software updates have been performed, the connection configuration information of the vehicular network after the hardware configuration changes and the vehicle configuration information of the vehicular network including the updated software can be provided to the relay management unit. Therefore, the relay processing of packets in the vehicular network can be configured based on the latest hardware and software configurations. Thus, the relay processing of packets in the vehicular network can be configured appropriately.
[0050] The embodiments of this disclosure will now be described using the accompanying drawings. It should be noted that identical or equivalent parts in the drawings are labeled with the same reference numerals, and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined arbitrarily.
[0051] [Composition and Basic Movements]
[0052] Figure 1This is a diagram illustrating an example of the configuration of an in-vehicle network management system according to an embodiment of the present disclosure. (Refer to...) Figure 1 The vehicle network management system 301 includes a relay device 101, vehicle ECUs 111A, 111B, and 111C (which serve as vehicle ECUs, Electronic Control Units) 111, and an external communication device 151. The vehicle network management system 301 is mounted on a vehicle 1. The vehicle ECU 111 is an example of a vehicle-mounted device. The relay device 101, vehicle ECUs 111A, 111B, and 111C, and the external communication device 151 constitute a vehicle network 31A, which serves as a vehicle network 31.
[0053] The repeater device 101 has communication ports PA1, PA2, PA3, PA4, and PB, which serve as communication ports PA. Communication ports PA and PB are terminals that can be connected to Ethernet (registered trademark) cables 32.
[0054] The on-board ECU 111 and the external communication device 151 are connected to the relay device 101 via Ethernet cable 32. More specifically, the on-board ECUs 111A, 111B, and 111C are connected to communication ports PA1, PA2, and PA3 in the relay device 101 via Ethernet cables 32, respectively. The external communication device 151 is connected to communication port PB in the relay device 101 via Ethernet cable 32.
[0055] The external communication device 151 is, for example, a TCU (Telematics Communication Unit). The external communication device 151 is capable of wireless communication with an external OTA (Over-The-Air) server (not shown) of the vehicle 1.
[0056] Vehicle ECU111 includes, for example, autonomous driving ECU, engine ECU, sensors, navigation devices, human-machine interfaces, and cameras.
[0057] The vehicle ECUs 111A, 111B, and 111C are equipped with applications 112A, 112B, and 112C, respectively, which are application programs 112. Application program 112 is an example of object software. Application program 112 is software that becomes the object of update processing in the vehicle network 31 and is updated periodically or irregularly using OTA technology.
[0058] Application 112 generates messages containing various data by performing application-layer processing. For example, application 112 in the vehicle ECU 111, which is a temperature sensor, generates messages containing temperature data representing the external temperature of the vehicle 1 at a predetermined period.
[0059] The relay device 101 is, for example, a gateway device, capable of relaying messages sent and received in the vehicle network 31. The relay device 101 performs relay processing on messages exchanged between vehicle ECUs 111 and messages exchanged between vehicle ECUs 111 and external communication devices 151, according to the Ethernet communication standard.
[0060] The relay device 101 updates the application 112 in the vehicle network 31, monitors the hardware configuration of the vehicle network 31, and sets up relay processing. More specifically, the relay device 101 receives update data for the application 112 from an external OTA server of the vehicle 1 via an external communication device 151, and uses the received update data to update the application 112. In addition, the relay device 101 changes the relay processing settings when the hardware configuration of the vehicle network 31 changes or when the application 112 is updated.
[0061] It should be noted that the in-vehicle network 31 is not limited to the relay of messages according to the Ethernet communication standard. For example, it can also be constructed according to communication standards such as CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), and LIN (Local Interconnect Network).
[0062] Furthermore, the vehicle network management system 301 is not limited to having three vehicle ECUs 111, but may also have one, two, or four or more vehicle ECUs 111. Additionally, the vehicle network management system 301 is not limited to having one application program 112 mounted on one vehicle ECU 111, but may also have two or more application programs 112 mounted on one vehicle ECU 111. Furthermore, the vehicle network management system 301 is not limited to having one relay device 101, but may also have multiple relay devices 101.
[0063] [Topic]
[0064] In conventional vehicle communication systems, for example, when an in-vehicle ECU 111 equipped with application 112 is installed on the in-vehicle network 31, it is sometimes impossible to properly update application 112. Furthermore, in conventional vehicle communication systems, even after application 112 has been updated, it is sometimes impossible to configure appropriate relay processing to correspond to the latest update status of application 112.
[0065] Therefore, the vehicle network management system 301 according to the embodiments of this disclosure solves the above-mentioned problems through the following configuration.
[0066] (Relay device)
[0067] Figure 2 This is a diagram illustrating the configuration of a relay device according to an embodiment of this disclosure. (Refer to...) Figure 2 The relay device 101 includes a relay unit 11, an update management unit 12, a configuration management unit 13, a relay management unit 14, and a storage unit 15. The update management unit 12 includes an update unit 12A, a generation unit 12B, and a transmission unit 12C. The update management unit 12 is an example of an update management device. A portion or all of the relay unit 11, update management unit 12, configuration management unit 13, and relay management unit 14 are implemented, for example, by a processing circuit including one or more processors. The storage unit 15 is, for example, a non-volatile memory included in the aforementioned processing circuit.
[0068] The relay unit 11 performs relay processing of messages in the vehicle network 31. More specifically, the relay unit 11 receives messages from the vehicle ECU 111 via the corresponding communication port PA, and sends the received messages to the destination vehicle ECU 111 via the corresponding communication port PA.
[0069] The update management unit 12 updates the application 112. More specifically, the update unit 12A in the update management unit 12 receives update data from the OTA server via the external communication device 151 and the relay unit 11, and performs update processing to update the application 112 using the received update data.
[0070] The configuration management unit 13 monitors the hardware configuration of the vehicle network 31. For example, the configuration management unit 13 detects changes in the vehicle network 31 caused by the addition or removal of vehicle devices.
[0071] Figure 3 This is a diagram illustrating an example of an update list stored in the storage unit of a relay device according to an embodiment of this disclosure. (See also...) Figure 3 The storage unit 15 stores an updated list L1 representing the IDs of the vehicle ECUs 111 equipped with the application 112, namely the ECUIDs. The ECUIDs of the vehicle ECUs 111A, 111B, and 111C are “ecu001”, “ecu002”, and “ecu003”, respectively.
[0072] Figure 4 This diagram illustrates an example of an inhibition list stored in the storage unit of a relay device according to an embodiment of this disclosure. (See also...) Figure 4The storage unit 15 stores a suppression list L2 that represents the correspondence between the ID of the application 112, i.e., the application ID, and the ID of the vehicle device that needs to run in the update process of the application 112, i.e., the device ID.
[0073] For example, update list L1 and suppression list L2 are generated by update management unit 12 and stored in storage unit 15. Update management unit 12 communicates with each vehicle ECU 111 via relay unit 11 to obtain the ECUID of the vehicle ECU 111 equipped with application 112, and generates update list L1 and suppression list L2 containing the obtained ECUID. Update management unit 12 stores the generated update list L1 and suppression list L2 in storage unit 15.
[0074] Figure 5 This is a diagram illustrating an example of a topology mapping table generated by the configuration management unit in a relay device according to an embodiment of this disclosure. (Refer to...) Figure 5 The management unit 13 generates a topology mapping table T1 that represents the correspondence between the IDs of relay devices (relay device IDs), communication ports (PAs) (port IDs), and the IDs of devices connected to communication ports (PAs) (connection node IDs) in the vehicular network 31. Topology mapping table T1 is an example of the connection configuration information representing the hardware configuration in the vehicular network 31. The relay device ID of relay device 101 is set to "esw001". Furthermore, the port IDs of communication ports PA1, PA2, PA3, and PA4 are set to "A1", "A2", "A3", and "A4", respectively.
[0075] For example, the configuration management unit 13 obtains the ECUID of each vehicle ECU 111 by communicating with each vehicle ECU 111 via the relay unit 11, and generates a topology mapping table T1 based on the obtained ECUID. The configuration management unit 13 outputs the generated topology mapping table T1 to the update management unit 12 and the relay management unit 14. In addition, the configuration management unit 13 stores the generated topology mapping table T1 in the storage unit 15.
[0076] Figure 6 This is a diagram illustrating an example of a vehicle configuration table generated by the update management unit in the relay device according to an embodiment of this disclosure. (See also...) Figure 6 The generation unit 12B in the update management unit 12 generates a vehicle configuration table T2 that represents the correspondence between the application ID of application 112, the ECUID of the vehicle ECU 111 equipped with application 112, and the version of application 112. Vehicle configuration table T2 is an example of vehicle configuration information. The application IDs of applications 112A, 112B, and 112C are set to "app001", "app002", and "app003", respectively.
[0077] For example, the generation unit 12B communicates with the vehicle ECU 111 represented by the update list L1 via the relay unit 11 to obtain application information representing the application ID and version of the application 112 from the vehicle ECU 111, and generates a vehicle configuration table T2 based on the obtained application information. The sending unit 12C in the update management unit 12 outputs the vehicle configuration table T2 generated by the generation unit 12B to the relay management unit 14.
[0078] The relay management unit 14 configures the relay processing of messages in the vehicular network 31. For example, the relay management unit 14 selects the relay processing settings in the relay unit 11 based on the topology mapping table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12. For example, as a selection of relay processing settings, the relay management unit 14 selects the mapping relationship between message type, receiving port ID, and sending port ID.
[0079] More specifically, the storage unit 15 stores a configuration table T3 that represents the correspondence between message types, receiving port IDs, and sending port IDs. For example, the storage unit 15 stores multiple configuration tables T3 with different settings for relay processing.
[0080] The relay management unit 14 selects a setting table T3 from multiple setting tables T3 in the storage unit 15, based on the topology correspondence table T1 and the vehicle configuration table T2, that represents the setting content to be used in the relay processing of the relay unit 11 in the vehicle network 31. The relay management unit 14 outputs the selected setting table T3 to the relay unit 11.
[0081] The relay unit 11 receives the configuration table T3 from the relay management unit 14 and performs relay processing according to the received configuration table T3.
[0082] When the hardware configuration of the vehicle network 31 changes or the application program 112 is updated, the relay management unit 14 changes the relay processing settings of the relay unit 11. Specific examples of changing the relay processing settings of the relay unit 11 will be described below.
[0083] (Example 1 of relay processing configuration change)
[0084] (1) Changes in settings corresponding to changes in hardware configuration
[0085] Figure 7 This is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Figure 7 and Figure 1 Compared to the vehicle network 31A shown, a vehicle network 31B is shown where the vehicle ECU 111D is connected to the communication port PA4 in the relay device 101 via an Ethernet cable 32. (See reference...) Figure 7The hardware configuration of the vehicle network 31 changes as it connects to the relay device 101 via the vehicle ECU 111D. Figure 1 The vehicle network 31A shown is changed to vehicle network 31B, which is vehicle network 31.
[0086] In the vehicle ECU 111D, compared to vehicle ECUs 111A, 111B, and 111C, a PnP (Plug and Play) terminal unit 113 replaces the application program 112. When the vehicle ECU 111D is connected to the relay device 101 via Ethernet cable 32, the PnP terminal unit 113 in the vehicle ECU 111D sends connection information, including the ECUID of the vehicle ECU 111D and information indicating that the application program 112 is not included in the vehicle ECU 111D, to the relay device 101. The ECUID of the vehicle ECU 111D is set to "ecu004".
[0087] Refer again Figure 2 The relay unit 11 receives connection information from the PnP terminal unit 113 via communication port PA4, and outputs the received connection information to the configuration management unit 13. In addition, the relay unit 11 outputs port information indicating the port ID of the communication port PA4 through which the connection information is transmitted to the configuration management unit 13.
[0088] When the hardware configuration in the vehicle network 31 changes, the configuration management unit 13 outputs a topology mapping table T1 representing the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information and port information from the relay unit 11, and updates the topology mapping table T1 in the storage unit 15 based on the received connection information and port information.
[0089] Figure 8 This is a diagram illustrating an example of an updated topology mapping table for a configuration management unit in a relay device according to an embodiment of this disclosure. (Refer to...) Figure 8 The management section 13 will contain the contents of the storage section 15. Figure 5 The topology correspondence table T1 shown is updated to include a topology correspondence table T1 with the added correspondence representing the connection relationship of the vehicle ECU111D.
[0090] The configuration management unit 13 outputs the updated topology mapping table T1 and connection information to the update management unit 12. Furthermore, the configuration management unit 13 outputs the updated topology mapping table T1 to the relay management unit 14.
[0091] Refer again Figure 2The update management unit 12 receives connection information and topology mapping table T1 from the configuration management unit 13, and identifies, based on the received connection information and topology mapping table T1, that the application 112 is not installed in the vehicle ECU 111D added to the vehicle network 31. In this case, the update management unit 12 does not update the update list L1 and suppression list L2 in the storage unit 15.
[0092] When the hardware configuration of the vehicle network 31 changes, the update management unit 12 outputs the vehicle configuration table T2 of the vehicle network 31B after the hardware configuration change to the relay management unit 14.
[0093] For example, the update management unit 12 performs the OTA host processing described on page 58 of Non-Patent Document 1, and generates a vehicle configuration table T2 in the vehicle network 31B based on the update list L1. More specifically, the update management unit 12 obtains application information from the vehicle ECU 111 shown in the update list L1 in the storage unit 15, and generates a vehicle configuration table T2 in the vehicle network 31B based on the obtained application information. It should be noted that since the application program 112 is not installed in the vehicle ECU 111D, the vehicle configuration table T2 in the vehicle network 31B is the same as the vehicle configuration table T2 in the vehicle network 31A before the vehicle ECU 111D is connected to the relay device 101. The update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14.
[0094] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects the configuration table T3 in the storage unit 15, which represents the configuration content to be used for relay processing of the relay unit 11 in the vehicle network 31B.
[0095] For example, the relay management unit 14 selects a configuration table T3 containing records of the receiving port ID and sending port ID of messages originating from the vehicle ECU 111D and records of the receiving port ID and sending port ID of messages destined for the vehicle ECU 111D as the configuration table T3 representing the relay processing settings of the relay unit 11 in the vehicle network 31B. The relay management unit 14 outputs a configuration change request containing the selected configuration table T3 to the relay unit 11.
[0096] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the relay processing settings according to the setting table T3 included in the received setting change request.
[0097] (2) Settings changes corresponding to application updates
[0098] Subsequently, the update management unit 12 receives, for example, update data from the OTA server via the external communication device 151 and the relay unit 11 for updating the version of application 112A from "1.0" to "2.0". The update management unit 12 uses the received update data to perform update processing for application 112A.
[0099] For example, as an update process, the update management unit 12 performs the OTA host processing described on pages 61 and 62 of Non-Patent Document 1, namely the installation process, and the OTA host processing described on page 63 of Non-Patent Document 1, namely the activation process.
[0100] As part of the installation process, the update management unit 12 sends an installation request containing update data to the vehicle ECU 111A via the relay unit 11.
[0101] The vehicle ECU 111A receives an installation request from the relay device 101 and installs the update program based on the update data contained in the received installation request. When the vehicle ECU 111A completes the installation of the update program, it sends an installation completion notification to the relay device 101.
[0102] The update management unit 12 in the relay device 101 performs a process to suppress the shutdown of the vehicle ECU 111A equipped with the application 112A based on the suppression list L2. More specifically, the update management unit 12 receives an installation completion notification from the vehicle ECU 111A via the relay unit 11, and obtains the device ID corresponding to the application 112A by referring to the suppression list L2 in the storage unit 15. The update management unit 12 then sends a shutdown suppression request to the vehicle ECU 111A represented by the obtained device ID via the relay unit 11.
[0103] The vehicle ECU 111A receives a shutdown suppression request from the relay device 101 and, in response to the received shutdown suppression request, sends a shutdown suppression response to the relay device 101. Then, the vehicle ECU 111A continues to operate even after the ignition power to the vehicle 1 is disconnected, in accordance with the shutdown suppression request. On the other hand, vehicle ECUs 111B, 111C, and 111D cease operation when the ignition power to the vehicle 1 is disconnected.
[0104] The update management unit 12 receives a shutdown suppression response from the vehicle ECU 111A via the relay unit 11 and waits for the ignition power to the vehicle 1 to be disconnected. Then, if the ignition power to the vehicle 1 is disconnected, the update management unit 12 performs an activation process. More specifically, as part of the activation process, the update management unit 12 sends an activation request to the vehicle ECU 111A via the relay unit 11. The activation request is an example of a message related to the update process.
[0105] The vehicle ECU 111A receives an activation request from the relay device 101 and activates the installed update program according to the received activation request, thereby updating the application program 112A. When the vehicle ECU 111A completes the activation of the update program, it sends an activation completion notification to the relay device 101. The activation completion notification is an example of a message related to the update process.
[0106] When the application 112A is updated, the update management unit 12 in the relay device 101 outputs the vehicle configuration table T2 in the vehicle network 31B containing the updated application 112A to the relay management unit 14.
[0107] Figure 9 This is a diagram illustrating an example of a vehicle configuration table generated by the update management unit in the relay device according to an embodiment of this disclosure. (See also...) Figure 9 Upon receiving an activation completion notification from the vehicle ECU 111A via the relay unit 11, the update management unit 12 retrieves application information from the vehicle ECU 111 shown in the update list L1 in the storage unit 15. Based on the retrieved application information, it generates a vehicle configuration table T2 indicating that the version of application 112A has been changed to 2.0. The update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14.
[0108] Refer again Figure 2 Based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the storage unit 15 that represents the setting content to be used for relay processing of the relay unit 11 in the vehicle network 31B. The relay management unit 14 outputs a setting change request containing the selected setting table T3 to the relay unit 11.
[0109] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the relay processing settings according to the setting table T3 included in the received setting change request.
[0110] When the relay management department 14 completes the setting change of the relay processing in the relay department 11, it outputs a change completion notification to the update management department 12.
[0111] The update management unit 12 receives the change completion notification from the relay management unit 14 and performs the process of stopping the vehicle ECU 111A. In addition, the update management unit 12 performs the process of notifying the user that the update of application 112A has been completed.
[0112] Subsequently, when the ignition power of vehicle 1 is turned on, the updated application 112A in the on-board ECU 111A begins to run.
[0113] (Example 2 of relay processing configuration change)
[0114] (1) Changes in settings corresponding to changes in hardware configuration
[0115] Figure 10 This is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Figure 10 It shows the relationship with Figure 7 The in-vehicle network 31B shown also includes an in-vehicle network 31C that serves as application 112D, which is integrated into the in-vehicle ECU 111D. (See reference...) Figure 10 The hardware configuration of the vehicle network 31 changes as it connects to the relay device 101 via the vehicle ECU 111D. Figure 1 The vehicle network 31A shown is changed to vehicle network 31C.
[0116] When the vehicle ECU 111D is connected to the relay device 101 via Ethernet cable 32, the PnP terminal 113 in the vehicle ECU 111D sends connection information, including the ECUID of the vehicle ECU 111D and the application ID of the application 112D installed in the vehicle ECU 111D, to the relay device 101.
[0117] Refer again Figure 2 The relay unit 11 receives connection information from the PnP terminal unit 113 via communication port PA4, and outputs the received connection information to the configuration management unit 13. In addition, the relay unit 11 outputs port information indicating the port ID of the communication port PA4 through which the connection information is transmitted to the configuration management unit 13.
[0118] When the hardware configuration of the vehicle network 31 changes, the configuration management unit 13 outputs a topology mapping table T1 representing the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information and port information from the relay unit 11, and based on the received connection information and port information, updates the topology mapping table T1 in the storage unit 15. Figure 5 The topology mapping table T1 shown is updated to Figure 8 The topology mapping table T1 is shown. The configuration management unit 13 outputs the updated topology mapping table T1 and connection information to the update management unit 12. In addition, the configuration management unit 13 outputs the updated topology mapping table T1 to the relay management unit 14.
[0119] When the vehicle ECU 111 equipped with application 112 is added to the vehicle network 31, the update management unit 12 updates the update list L1 and suppression list L2 in the storage unit 15. More specifically, the update management unit 12 receives connection information and topology mapping table T1 from the configuration management unit 13, and identifies, based on the received connection information and topology mapping table T1, that the application 112D is equipped on the vehicle ECU 111D added to the vehicle network 31. In this case, the update management unit 12 updates the update list L1 and suppression list L2 in the storage unit 15.
[0120] Figure 11 This is a diagram showing an example of an updated list of the update management unit in a relay device according to an embodiment of this disclosure. (Refer to...) Figure 11 The update management unit 12 adds the ECUID of the vehicle ECU 111E to the update list L1 in the storage unit 15.
[0121] Figure 12 This is a diagram illustrating an example of an updated suppression list in the update management unit of a relay device according to an embodiment of this disclosure. (Refer to...) Figure 12 The management unit 12 updates the suppression list L2 in the storage unit 15 by adding the application ID of application 112D, namely "app004", to the correspondence between the application ID of application 112D and the ECUID of vehicle ECU 111E.
[0122] When the hardware configuration of the vehicle network 31 changes, the update management unit 12 outputs the vehicle configuration table T2 in the vehicle network 31C after the hardware configuration change to the relay management unit 14.
[0123] For example, the update management unit 12 performs the OTA host processing described on page 58 of Non-Patent Document 1, and generates the vehicle configuration table T2 in the vehicle network 31C based on the update list L1.
[0124] Figure 13 This is a diagram illustrating an example of a vehicle configuration table generated by the update management unit in the relay device according to an embodiment of this disclosure. (See also...) Figure 13 The update management unit 12 obtains application information from the vehicle ECU 111 shown in the update list L1 in the storage unit 15. Based on the obtained application information, it generates a vehicle configuration table T2 containing the correspondence between the application ID of the application 112D, the ECUID of the vehicle ECU 111D, and the version of the application 112D. The update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14.
[0125] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects the configuration table T3 in the storage unit 15, which represents the configuration content to be used for relay processing of the relay unit 11 in the vehicle network 31C.
[0126] For example, the relay management unit 14 selects a setting table T3 containing records of the receiving port ID and sending port ID of messages originating from the vehicle ECU 111D and records of the receiving port ID and sending port ID of messages destined for the vehicle ECU 111D as the setting table T3 representing the relay processing settings of the relay unit 11 in the vehicle network 31C. The relay management unit 14 outputs a setting change request containing the selected setting table T3 to the relay unit 11.
[0127] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the relay processing settings according to the setting table T3 included in the received setting change request.
[0128] (2) Settings changes corresponding to application updates
[0129] Refer again Figure 2 Subsequently, the update management unit 12 receives, for example, update data from the OTA server via the external communication device 151 and the relay unit 11 for updating the versions of applications 112A and 112D from "1.0" to "2.0". The update management unit 12 uses the received update data to perform update processing for applications 112A and 112D.
[0130] As part of the installation process, the update management unit 12 sends an installation request containing update data to the vehicle ECUs 111A and 111D via the relay unit 11.
[0131] The vehicle ECUs 111A and 111D receive installation requests from the relay device 101 and install the update program based on the update data contained in the received installation request. When the installation of the update program is completed, the vehicle ECUs 111A and 111D send an installation completion notification to the relay device 101.
[0132] The update management unit 12 in the relay device 101 performs a process to suppress the shutdown of the vehicle ECUs 111A and 111D equipped with applications 112A and 112D based on the suppression list L2. More specifically, the update management unit 12 receives an installation completion notification from the vehicle ECUs 111A and 111D via the relay unit 11, and obtains the device ID corresponding to application 112A and the device ID corresponding to application 112D by referring to the suppression list L2 in the storage unit 15. The update management unit 12 then sends a shutdown suppression request to the vehicle ECUs 111A and 111D indicated by the obtained device IDs via the relay unit 11.
[0133] Vehicle ECUs 111A and 111D receive shutdown suppression requests from relay device 101 and, in response to the received shutdown suppression requests, send shutdown suppression responses to relay device 101. Then, vehicle ECUs 111A and 111D continue operating even after the ignition power to vehicle 1 is disconnected, in accordance with the shutdown suppression requests. On the other hand, vehicle ECUs 111B and 111C cease operation when the ignition power to vehicle 1 is disconnected.
[0134] The update management unit 12 receives shutdown suppression responses from the vehicle ECUs 111A and 111D via the relay unit 11 and waits for the ignition power to the vehicle 1 to be disconnected. Then, if the ignition power to the vehicle 1 is disconnected, the update management unit 12 performs an activation process. More specifically, as an activation process, the update management unit 12 sends an activation request to the vehicle ECUs 111A and 111D via the relay unit 11.
[0135] Vehicle ECUs 111A and 111D receive activation requests from relay device 101, and activate the installed update program according to the received activation request, thereby updating application programs 112A and 112D. When the vehicle ECUs 111A and 111D complete the activation of the update program, they send an activation completion notification to relay device 101.
[0136] When the update management unit 12 in the relay device 101 updates the application programs 112A and 112D, it outputs the vehicle configuration table T2 in the vehicle network 31C containing the updated application program 112A to the relay management unit 14.
[0137] Figure 14 This is a diagram illustrating an example of a vehicle configuration table generated by the update management unit in the relay device according to an embodiment of this disclosure. (See also...) Figure 14Upon receiving an activation completion notification from the vehicle ECUs 111A and 111D via the relay unit 11, the update management unit 12 retrieves application information from the vehicle ECUs 111 shown in the update list L1 in the storage unit 15. Based on the retrieved application information, the update management unit 12 generates a vehicle configuration table T2 indicating that the versions of the applications 112A and 112D have been changed to 2.0. The update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14.
[0138] Refer again Figure 2 Based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the storage unit 15 that represents the setting content to be used for relay processing of the relay unit 11 in the vehicle network 31C. The relay management unit 14 outputs a setting change request containing the selected setting table T3 to the relay unit 11.
[0139] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the relay processing settings according to the setting table T3 included in the received setting change request.
[0140] When the relay management department 14 completes the setting change of the relay processing in the relay department 11, it outputs a change completion notification to the update management department 12.
[0141] The update management unit 12 receives the change completion notification from the relay management unit 14 and stops the vehicle ECUs 111A and 111D. Additionally, the update management unit 12 notifies the user that the updates to applications 112A and 112D have been completed.
[0142] Subsequently, when the ignition power of vehicle 1 is turned on, the updated applications 112A and 112D in the on-board ECUs 111A and 111D begin to run.
[0143] (Example 3 of relay processing configuration change)
[0144] (1) Changes in settings corresponding to changes in hardware configuration
[0145] Figure 15 This is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Figure 15 It shows the relationship with Figure 10 The vehicle network 31C shown is different from the vehicle network 31D, where relay device 102 is connected to relay device 101 and vehicle ECU 111D is connected to relay device 102. Like relay device 101, relay device 102 is also capable of relaying messages sent and received in the vehicle network 31.
[0146] Reference Figure 10The relay device 102 includes a PnP terminal 114 and communication ports PC1 and PC2, which serve as communication ports (PCs). Communication port PA4 in relay device 101 and communication port PC1 in relay device 102 are connected via Ethernet cable 32. The vehicle ECU 111D is connected to communication port PC2 in relay device 102 via Ethernet cable 32. By connecting relay device 102, which is connected to relay device 101, with vehicle ECU 111D attached, the hardware configuration of the vehicle network 31 changes. Figure 1 The vehicle network 31A shown is changed to vehicle network 31D.
[0147] When the relay device 102 is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal 113 in the vehicle ECU 111D sends connection information, including the ECUID of the vehicle ECU 111D and the application ID of the application 112D installed in the vehicle ECU 111D, to the relay device 101 via the relay device 102.
[0148] When the relay device 102 is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 114 in the relay device 102 sends relay connection information, including the relay device ID of the relay device 102, to the relay device 101.
[0149] Refer again Figure 2 The relay unit 11 receives connection information and relay connection information from the PnP terminal units 113 and 114 via communication port PA4, and outputs the received connection information and relay connection information to the configuration management unit 13. In addition, the relay unit 11 outputs port information indicating the port ID of the communication port PA4 through which the connection information and relay connection information are transmitted to the configuration management unit 13.
[0150] When the hardware configuration in the vehicle network 31 changes, the configuration management unit 13 outputs a topology mapping table T1 representing the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information, relay connection information, and port information from the relay unit 11, and updates the topology mapping table T1 in the storage unit 15 based on the received connection information, relay connection information, and port information.
[0151] Figure 16 This diagram illustrates an example of an updated topology mapping table for the management unit within a relay device according to an embodiment of this disclosure. The relay device ID of relay device 102 is set to "esw002". The port IDs of communication ports PC1 and PC2 are set to "C1" and "C2", respectively.
[0152] Reference Figure 16 The management section 13 will contain the contents of the storage section 15.Figure 5 The topology correspondence table T1 shown is updated to include a topology correspondence table T1 with the added correspondence between the relay device 102 and the vehicle ECU 111D.
[0153] The configuration management unit 13 outputs the updated topology mapping table T1 and connection information to the update management unit 12. Furthermore, the configuration management unit 13 outputs the updated topology mapping table T1 to the relay management unit 14.
[0154] The update management unit 12 receives connection information and topology mapping table T1 from the configuration management unit 13, and identifies, based on the received connection information and topology mapping table T1, that the application 112D is mounted on the vehicle ECU 111D added to the vehicle network 31. In this case, the update management unit 12 updates the update list L1 and the suppression list L2 in the storage unit 15.
[0155] More specifically, such as Figure 11 As shown, the update management unit 12 adds the ECUID of the vehicle ECU 111E to the update list L1 in the storage unit 15.
[0156] Figure 17 This is a diagram illustrating an example of an updated suppression list in the update management unit of a relay device according to an embodiment of this disclosure. (Refer to...) Figure 17 The update management unit 12 adds the correspondence between "app004", which is the application ID of application 112D, the relay device ID of relay device 102, and the ECUID of vehicle ECU 111E to the suppression list L2 in the storage unit 15.
[0157] Refer again Figure 2 If the hardware configuration of the vehicle network 31 changes, the update management unit 12 outputs the vehicle configuration table T2 in the vehicle network 31D after the hardware configuration change to the relay management unit 14.
[0158] For example, the update management unit 12 performs the OTA host processing described on page 58 of Non-Patent Document 1, and generates the vehicle configuration table T2 in the vehicle network 31D based on the update list L1. More specifically, the update management unit 12 obtains application information from the vehicle ECU 111 shown in the update list L1 in the storage unit 15, and generates a vehicle configuration table T2 based on the obtained application information. Figure 13 The vehicle configuration table T2 is shown. The update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14.
[0159] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects the configuration table T3 in the storage unit 15, which represents the configuration content to be used for relay processing of the relay unit 11 in the vehicle network 31D.
[0160] For example, the relay management unit 14 selects a setting table T3 containing records of the receiving port ID and sending port ID of messages originating from the vehicle ECU 111D and records of the receiving port ID and sending port ID of messages destined for the vehicle ECU 111D as the setting table T3 representing the relay processing settings of the relay unit 11 in the vehicle network 31C. The relay management unit 14 outputs a setting change request containing the selected setting table T3 to the relay unit 11.
[0161] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the relay processing settings according to the setting table T3 included in the received setting change request.
[0162] (2) Settings changes corresponding to application updates
[0163] Subsequently, the update management unit 12 receives, for example, update data from the OTA server via the external communication device 151 and the relay unit 11 for updating the versions of applications 112A and 112D from "1.0" to "2.0". The update management unit 12 uses the received update data to perform update processing for applications 112A and 112D.
[0164] As part of the installation process, the update management unit 12 sends an installation request containing update data to the vehicle ECU 111A via the relay unit 11, and to the vehicle ECU 111D via the relay unit 11 and the relay device 102.
[0165] The vehicle ECUs 111A and 111D receive installation requests from the relay device 101 and install the update program based on the update data contained in the received installation request. When the installation of the update program is completed, the vehicle ECUs 111A and 111D send an installation completion notification to the relay device 101.
[0166] The update management unit 12 in relay device 101, based on the suppression list L2, performs shutdown processing to suppress the vehicle ECUs 111A and 111D carrying applications 112A and 112D, and the relay device 102 that needs to relay messages related to the update processing of application 112D. More specifically, the update management unit 12 receives installation completion notifications from the vehicle ECUs 111A and 111D via the relay unit 11, and obtains the device ID corresponding to application 112A and the device ID corresponding to application 112D by referring to the suppression list L2 in the storage unit 15. The update management unit 12 then sends shutdown suppression requests to the relay device 102 and the vehicle ECUs 111A and 111D represented by the obtained device IDs via the relay unit 11.
[0167] The relay device 102 and the vehicle ECUs 111A and 111D receive a shutdown suppression request from the relay device 101. In response to the received shutdown suppression request, they send a shutdown suppression response back to the relay device 101. Then, the relay device 102 and the vehicle ECUs 111A and 111D continue to operate even after the ignition power to the vehicle 1 is disconnected, in accordance with the shutdown suppression request. On the other hand, the vehicle ECUs 111B and 111C stop operating when the ignition power to the vehicle 1 is disconnected.
[0168] The update management unit 12 receives shutdown suppression responses from the relay device 102 and the vehicle ECUs 111A and 111D via the relay unit 11, and waits for the ignition power of the vehicle 1 to be disconnected. Then, if the ignition power of the vehicle 1 is disconnected, the update management unit 12 performs an activation process. More specifically, as an activation process, the update management unit 12 sends an activation request to the vehicle ECU 111A via the relay unit 11, and sends an activation request to the vehicle ECU 111D via the relay unit 11 and the relay device 102.
[0169] Vehicle ECUs 111A and 111D receive activation requests from relay device 101 and update application programs 112A and 112D by activating the installed update program. Upon completion of the update program activation, vehicle ECUs 111A and 111D send an activation completion notification to relay device 101.
[0170] When the update management unit 12 in the relay device 101 updates the applications 112A and 112D, it outputs the vehicle configuration table T2 in the vehicle network 31C containing the updated application 112D to the relay management unit 14. More specifically, when the update management unit 12 receives an activation completion notification from the vehicle ECUs 111A and 111D via the relay unit 11, it retrieves application information from the vehicle ECUs 111 shown in the update list L1 in the storage unit 15. Based on the retrieved application information, the update management unit 12 generates... Figure 14The vehicle configuration table T2 is shown. The update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14.
[0171] Based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a configuration table T3 from multiple configuration tables T3 in the storage unit 15 that represents the configuration content to be used for relay processing of the relay unit 11 in the vehicle network 31C. The relay management unit 14 outputs a configuration change request containing the selected configuration table T3 to the relay unit 11.
[0172] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the relay processing settings according to the setting table T3 included in the received setting change request.
[0173] When the relay management department 14 completes the setting change of the relay processing in the relay department 11, it outputs a change completion notification to the update management department 12.
[0174] The update management unit 12 receives a change completion notification from the relay management unit 14 and proceeds to stop the relay device 102 and the vehicle ECUs 111A and 111D. Additionally, the update management unit 12 notifies the user that the updates to applications 112A and 112D have been completed.
[0175] Subsequently, when the ignition power of vehicle 1 is turned on, the updated applications 112A and 112D in the on-board ECUs 111A and 111D begin to run.
[0176] [Execution process]
[0177] Figure 18 This diagram illustrates an example of the timing of a change in the relay processing settings in an embodiment of the present disclosure's vehicle network management system. Figure 18 This indicates the timing of the aforementioned "setting changes corresponding to changes in hardware configuration".
[0178] Reference Figure 18 First, when the vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal 113 in the vehicle ECU 111D sends the connection information to the relay device 101 (step S11).
[0179] Next, the relay unit 11 in the relay device 101 outputs the connection information and port information received from the PnP terminal unit 113 to the configuration management unit 13 (step S12).
[0180] Next, the management unit 13 updates the topology mapping table T1 based on the connection information and port information received from the relay unit 11 (step S13).
[0181] Next, the configuration management unit 13 outputs the updated topology correspondence table T1 and connection information to the update management unit 12 (step S14).
[0182] In addition, the management unit 13 outputs the updated topology correspondence table T1 to the relay management unit 14 (step S15).
[0183] Next, the update management unit 12 identifies, for example, that the application 112D is mounted on the vehicle ECU 111D added to the vehicle network 31 based on the connection information and topology correspondence table T1 received from the configuration management unit 13, and updates the update list L1 and the suppression list L2 (step S16).
[0184] Next, the update management unit 12 obtains application information from the vehicle ECU 111 shown in the update list L1, and generates the vehicle configuration table T2 based on the obtained application information (step S17).
[0185] Next, the update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14 (step S18).
[0186] Next, based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects the configuration table T3 in the storage unit 15 that represents the configuration content to be used for relay processing of the relay unit 11 in the vehicle network 31 (step S19).
[0187] Next, the relay management unit 14 outputs a setting change request containing the selected setting table T3 to the relay unit 11 (step S20).
[0188] Next, the relay unit 11 changes the relay processing settings according to the setting table T3 included in the setting change request received from the relay management unit 14 (step S21).
[0189] Figure 19 This diagram illustrates an example of the timing of a change in the relay processing settings in an embodiment of the present disclosure's vehicle network management system. Figure 19 This indicates the timing of the aforementioned "setting changes corresponding to application updates".
[0190] Reference Figure 19 First, the update management unit 12 receives update data of application 112 from the OTA server via external communication device 151 and relay unit 11 (step S31).
[0191] Next, the update management unit 12 sends an installation request containing update data to the vehicle ECU 111 (step S32).
[0192] Next, the vehicle ECU 111 installs the update program based on the update data contained in the received installation request (step S33).
[0193] Next, the vehicle ECU 111 sends an installation completion notification to the relay device 101 (step S34).
[0194] Next, the update management unit 12 in the relay device 101 sends a shutdown suppression request to the vehicle ECU 111 (step S35).
[0195] Next, the vehicle ECU 111 sends a shutdown suppression response to the relay device 101 as a response to the received shutdown suppression request (step S36).
[0196] Next, the update management unit 12 waits for the ignition power of vehicle 1 to be disconnected. When the ignition power of vehicle 1 is disconnected, it sends an activation request to the vehicle ECU 111 (step S37).
[0197] Next, the vehicle ECU 111 updates the application 112 by activating the installed update program according to the received activation request (step S38).
[0198] Next, the vehicle ECU 111 sends an activation completion notification to the relay device 101 (step S39).
[0199] Next, the update management unit 12 in the relay device 101 obtains application information from the vehicle ECU 111 shown in the update list L1, and generates the vehicle configuration table T2 based on the obtained application information (step S40).
[0200] Next, the update management unit 12 outputs the generated vehicle configuration table T2 to the relay management unit 14 (step S41).
[0201] Next, the relay management unit 14 selects the setting table T3 from the multiple setting tables T3 in the storage unit 15 based on the topology correspondence table T1 and the vehicle configuration table T2, which represents the setting content that should be used for the relay processing of the relay unit 11 in the vehicle network 31C (step S42).
[0202] Next, the relay management unit 14 outputs a setting change request containing the selected setting table T3 to the relay unit 11 (step S43).
[0203] Next, the relay unit 11 changes the relay processing settings according to the setting table T3 included in the setting change request received from the relay management unit 14 (step S44).
[0204] Next, the relay management department 14 outputs a change completion notification to the update management department 12 (step S45).
[0205] Next, the update management unit 12 performs the process of stopping the vehicle ECU 111 (step S46).
[0206] Next, when the ignition power of vehicle 1 is turned on, the updated application 112 in the vehicle ECU 111 starts running (step S47).
[0207] It should be noted that in the vehicle network management system 301 of the present disclosure, the update management unit 12, the configuration management unit 13, and the relay management unit 14 are configured to be located in the relay device 101, but this is not a limitation. At least one of the update management unit 12, the configuration management unit 13, and the relay management unit 14 may also be located in a device different from the relay device 101. For example, when the update management unit 12 is located in... Figure 15 When the vehicle network 31D shown is installed in a device different from the relay device 101, the update management unit 12 also performs a process to suppress the shutdown of the relay device 101 based on the suppression list L2.
[0208] Furthermore, in the vehicle network management system 301 of this disclosure, the update management unit 12 is configured to update the update list L1 and the suppression list L2 when a vehicle ECU 111 equipped with application 112 is added to the vehicle network 31, but is not limited to this. The update management unit 12 may also be configured not to update the update list L1 and the suppression list L2 even when a vehicle ECU 111 equipped with application 112 is added to the vehicle network 31. In this case, the update management unit 12 updates the application 112 of the vehicle ECU 111 in the initial vehicle network 31, but does not update the application 112 of the vehicle ECU 111 added to the vehicle network 31. The update of the application 112 of the vehicle ECU 111 added to the vehicle network 31 can be performed by a unit other than the update management unit 12 in the vehicle network management system 301, or by the user of the vehicle 1 or the maintenance personnel of the vehicle 1.
[0209] Furthermore, in the vehicle network management system 301 of the embodiments of this disclosure, the update management unit 12 is configured to obtain application information from the vehicle ECU 111 shown in the update list L1 and generate a vehicle configuration table T2 based on the obtained application information, but is not limited thereto. The update management unit 12 may also be configured to receive application information from the user of the vehicle network management system 301 and generate a vehicle configuration table T2 based on the received application information.
[0210] Furthermore, in the vehicle network management system 301 of this disclosure, the update management unit 12 is configured to suppress the shutdown of the relay device 102, which needs to communicate during the update process of the application 112, but it is not limited to this. The update management unit 12 may also be configured not to suppress the shutdown of the relay device 102. More specifically, the update management unit 12 updates the application 112 mounted on the vehicle ECU 111 connected to the relay device 101, but does not update the application 112 mounted on the vehicle ECU 111 connected to the relay device 101 via the relay device 102. The update of the application 112 mounted on the vehicle ECU 111 connected to the relay device 101 via the relay device 102 can be performed by a unit other than the update management unit 12 in the vehicle network management system 301, or by the user of the vehicle 1 or the maintenance personnel of the vehicle 1. In this case, the update management unit 12 does not suppress the shutdown of the relay device 102.
[0211] Furthermore, in the vehicle network management system 301 of the embodiments of this disclosure, the update management unit 12 is configured to receive update data from the OTA server via the external communication device 151 and the relay unit 11, but it is not limited to this. The update management unit 12 may also be configured to receive update data from the OTA server via wired communication.
[0212] The above embodiments should be considered illustrative and not restrictive in all respects. The scope of this disclosure is defined not by the foregoing description but by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.
[0213] Each process (function) in the above-described embodiments is implemented by a processing circuit including one or more processors. Besides the one or more processors, the processing circuit may also be composed of an integrated circuit combining one or more memories, various analog circuits, and various digital circuits. The one or more memories store programs (commands) that cause the one or more processors to execute the above processes. The one or more processors may execute the above processes according to the programs read from the one or more memories, or they may execute the above processes according to logic circuits designed to pre-execute the above processes. The processors may be various processors suitable for computer control, such as CPUs (Central Processing Units), GPUs (Graphics Processing Units), DSPs (Digital Signal Processors), FPGAs (Field Programmable Gate Arrays), and ASICs (Application Specific Integrated Circuits). It should be noted that physically separate processors may also cooperate to execute the above processes. For example, the processors located on multiple physically separate computers can also cooperate with each other via networks such as LAN (Local Area Network), WAN (Wide Area Network), and the Internet to execute the aforementioned processes. The programs can be installed into the memory from external server devices via the aforementioned network, or they can be transferred from recording media such as CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disk Read Only Memory), and semiconductor memory, and installed into the memory.
[0214] The above description includes the following features.
[0215] [Postscript 1]
[0216] An update management device, comprising: The update department updates the software (object software) in the vehicle network that becomes the object of the update process. The generation unit generates vehicle configuration information indicating the correspondence between the object software, the vehicle device equipped with the object software, and the version of the object software, when the object software is updated by the update unit or when the hardware configuration in the vehicle network changes; and The sending unit sends the vehicle configuration information generated by the generating unit to the relay management unit, which is configured to perform relay processing of messages in the vehicle network.
[0217] [Postscript 2]
[0218] An update management device, wherein, Equipped with processing circuitry, When the processing circuit updates the software (i.e., the object software) in the vehicular network that is the object of the update process, or when the hardware configuration of the vehicular network changes, it generates vehicle configuration information representing the correspondence between the object software, the vehicular device equipped with the object software, and the version of the object software. The processing circuit sends the generated vehicle configuration information to the relay management unit, which is configured to perform relay processing of messages in the vehicle network.
[0219] [Explanation of reference numerals in the attached figures]
[0220] 1 vehicle
[0221] 11th Relay Unit
[0222] 12 Update Management Department
[0223] 12A Update Department
[0224] 12B Production Department
[0225] 12C Transmission Unit
[0226] 13 constitute the management department
[0227] 14 Relay Management Department
[0228] 15 Storage Department
[0229] 31, 31A, 31B, 31C, 31D vehicle-mounted networks
[0230] 32 Ethernet cable
[0231] 101 and 102 relay devices
[0232] 111, 111A, 111B, 111C, 111D vehicle ECU
[0233] Applications 112, 112A, 112B, 112C, and 112D
[0234] 113, 114 PnP Terminals
[0235] 151External communication device
[0236] 301 Vehicle Network Management System
[0237] PA, PA1, PA2, PA3, PA4, PB communication ports
[0238] L1 Update List
[0239] L2 inhibition list
[0240] T1 Topology Correspondence Table
[0241] T2 vehicle composition table.
Claims
1. A vehicle network management system, comprising: The update management department updates the software (i.e., object software) in the vehicle network that becomes the object of the update process. The management unit monitors the hardware configuration of the in-vehicle network; and The relay management department configures the relay processing of packets in the vehicle network. When the hardware configuration changes, the configuration management unit sends connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit. When the hardware configuration changes, the update management unit sends the vehicle configuration information in the vehicular network after the hardware configuration change to the relay management unit. The vehicle configuration information represents the correspondence between the target software, the vehicular device equipped with the target software, and the version of the target software. When the object software is updated, the update management unit sends the vehicle configuration information in the vehicular network, which includes the updated object software, to the relay management unit.
2. The vehicle network management system according to claim 1, wherein, The update management unit generates the vehicle configuration information based on the update list representing the in-vehicle devices equipped with the object software. When the vehicle-mounted device equipped with the object software is added to the vehicle network, the update management unit updates the update list.
3. The vehicle network management system according to claim 2, wherein, The update management unit obtains application information indicating the version of the object software installed on the vehicle device from the vehicle device shown in the update list, and generates the vehicle configuration information based on the obtained application information.
4. The vehicle network management system according to any one of claims 1 to 3, wherein, The update management unit performs a process to suppress the shutdown of the vehicle device carrying the object software to be updated during the update process, based on a suppression list indicating the vehicle devices that need to run during the update process of the object software. When the vehicle-mounted device equipped with the object software is added to the vehicle network, the update management unit updates the suppression list.
5. The vehicle network management system according to claim 4, wherein, Based on the suppression list, the update management unit also performs a process to shut down relay devices that need to relay messages related to the update process.
6. A vehicle network management method, which is a vehicle network management method in a vehicle network management system, wherein the vehicle network management system comprises an update management unit for updating software (i.e., target software) that is the object of update processing in the vehicle network, a configuration management unit for monitoring the hardware configuration in the vehicle network, and a relay management unit for setting relay processing of packets in the vehicle network, wherein... The in-vehicle network management method includes the following steps: When the hardware configuration changes, the configuration management unit sends connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit. When the hardware configuration changes, the update management unit sends the vehicle configuration information in the vehicular network after the hardware configuration change to the relay management unit. The vehicle configuration information represents the correspondence between the target software, the vehicular device equipped with the target software, and the version of the target software. and When the object software is updated, the update management unit sends the vehicle configuration information in the vehicular network, which includes the updated object software, to the relay management unit.