Software update system, vehicle, software update device, and software update method

CN122837872APending Publication Date: 2026-09-29HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202610305451.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-03-27
Filing Date
2026-03-13
Publication Date
2026-09-29

AI Technical Summary

Benefits of technology

[0012]根据本发明的一个方式,能够提高可进行软件的更新的可能性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122837872A_ABST
    Figure CN122837872A_ABST
Patent Text Reader

Abstract

The present application provides a software update system, a vehicle, a software update device, and a software update method, which can improve the possibility of updating software (233). The software update system (1) includes a vehicle (2) having an electronic control unit (23) and a server device (3) capable of communicating with the vehicle, wherein the vehicle includes a software update unit (271) for updating the software of the electronic control unit and a battery (21) for supplying power to the electronic control unit. The software update unit sends first information inquiring whether there is information related to the update of the software to the server device, receives second information containing update software (D1) from the server device, obtains the required time for the activation process of the update software based on the received second information, and determines whether to shift to the activation process based on the obtained required time and the remaining capacity of the battery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a software update system, a vehicle, a software update device, and a software update method. Background Technology

[0002] Previously, techniques for updating software in vehicles equipped with batteries were known. For example, Patent Document 1 discloses a technique that uses a low-voltage battery to update the program when reprogramming can be performed using a low-voltage battery, and uses a high-voltage battery to update the program when reprogramming cannot be performed using a low-voltage battery.

[0003] [Existing technical documents]

[0004] [Patent Literature]

[0005] Patent Document 1: Japanese Patent Application Publication No. 2022-054890 Summary of the Invention

[0006] [The problem the invention aims to solve]

[0007] Typically, software updates in vehicles involve activating the updated software. Previously, the decision to proceed to this activation process was based on whether there was sufficient battery capacity in the vehicle's battery to withstand the activation process. However, the threshold for determining whether to proceed to activation and the required capacity is a threshold corresponding to the fixed time required for activation. Therefore, even if the battery capacity is sufficient relative to the actual time required for activation, it is possible that the battery capacity is below the threshold, resulting in a decision not to proceed to activation and no software update being performed.

[0008] The present invention was made in view of the above circumstances, and its object is to increase the possibility of software updates.

[0009] [Methods used to solve problems]

[0010] One aspect of the present invention is a software update system comprising a vehicle having an electronic control unit and a server device capable of communicating with the vehicle, wherein the vehicle comprises: a software update unit that updates the software of the electronic control unit; and a battery that supplies power to the electronic control unit; the software update unit sending first information to the server device inquiring whether there is information related to the software update, and receiving second information containing the update software from the server device; the software update unit obtaining, based on the received second information, the required time for activation processing of the update software, and determining, based on the obtained required time and the remaining battery power, whether to transfer to the activation processing.

[0011] [Invention Effects]

[0012] According to one aspect of the present invention, the possibility of software updates can be increased. Attached Figure Description

[0013] Figure 1 This is a diagram showing the structure of a software update system.

[0014] Figure 2 This is a diagram showing the structure of the server device.

[0015] Figure 3 This is a diagram showing the structure of the vehicle.

[0016] Figure 4 It is a timing diagram showing the operation of the software update device and the server device.

[0017] Figure 5 This is a flowchart illustrating the actions of the software update department.

[0018] Figure 6 This is a flowchart illustrating the actions of the software update department. Detailed Implementation

[0019] [1. Structure of the software update system]

[0020] Figure 1 This is a diagram showing the structure of software update system 1.

[0021] The software update system 1 includes the vehicle 2 and provides the software 233 (see reference) executed by the ECU (Electronic Control Unit) 23 of the vehicle 2. Figure 3 The server device 3 is connected to the vehicle 2 via a communication network NW. The vehicle 2 downloads update software (hereinafter, marked "D1", representing update software D1) from the server device 3 to update the software 233 of the ECU 23. That is, the software update system 1 can update the software 233 of the vehicle 2 using OTA (Over The Air).

[0022] ECU 23 is an example of an "electronic control unit".

[0023] In the following description, software includes programs executed by a processor and data associated with those programs that are referenced, generated, updated, or deleted. Updating software refers to the process of replacing processor-executed software with a newer version, which can be done by adding, deleting, or overwriting the software. Furthermore, the deletion of part or all of the processor-executed software, the installation of new software, and the deletion, addition, or overwriting of data used during software execution can also be included in software updates.

[0024] Vehicle 2 can be any of the following: a four-wheeled vehicle, a two-wheeled vehicle, or a vehicle other than these. It can also be a large vehicle, a commercial vehicle, or a work vehicle, etc. As an example, a four-wheeled vehicle is illustrated in this embodiment. Vehicle 2 is connected to the communication network NW wirelessly, for example, via a cellular communication base station 4. The specific type of the communication network NW is not limited. For example, the communication network NW can also include a cellular communication network, the Internet, a WAN (Wide Area Network), a LAN (Local Area Network), a public line network, a provider device, a dedicated line, a base station, etc.

[0025] Server device 3 is connected to the communication network NW via a wired or wireless communication line and is a computer communicatively connected to vehicle 2. Server device 3 sends update software D1 to vehicle 2.

[0026] [2. Structure of the server device]

[0027] First, refer to Figure 2 The structure of server device 3 will be described.

[0028] Figure 2 This is a diagram showing the structure of server device 3.

[0029] The server device 3 includes a server control unit 30 and a server communication unit 31.

[0030] The server control unit 30 includes a processor 300 (CPU, Central Processing Unit), a memory 310, and interface circuits for connecting other devices and sensors. The server communication unit 31 is connected to the server control unit 30. The server control unit 30 performs various actions by reading and executing the control program 311 stored in the memory 310.

[0031] Memory 310 is a storage device for storing programs and data. Memory 310 stores control program 311, data processed by processor 300, etc. Memory 310 has non-volatile storage areas. In addition, memory 310 has volatile storage areas that constitute the working area of ​​processor 300. For example, memory 310 includes read-only memory (ROM) and random access memory (RAM).

[0032] The server communication unit 31 has hardware such as communication circuits and communicates with the vehicle 2 under the control of the server control unit 30.

[0033] [3. Vehicle Structure]

[0034] Figure 3 This is a diagram showing the structure of vehicle 2.

[0035] Vehicle 2 is equipped with a battery 21, control circuit 22, multiple ECUs 23, TCU (Telematics Control Unit) 24, touch panel 25, GNSS (Global Navigation Satellite System) unit 26, and software update device 27.

[0036] Battery 21 supplies power to various parts of vehicle 2, including ECU 23 and the devices controlled by ECU 23 (described later). Battery 21 is connected to control circuit 22, and its power supply and charging are controlled by control circuit 22. Control circuit 22 controls the power supply of battery 21 according to the control of software update device 27.

[0037] ECU 23 is an electronic control unit that controls the equipment in vehicle 2 and is connected to software update device 27. Examples of equipment controlled by ECU 23 include devices that operate the windshield wipers of vehicle 2, devices that turn the lights on and off of vehicle 2, and a drive motor that serves as the drive source for vehicle 2. ECU 23 includes a processor 231 (such as a CPU) and a memory 232. The processor 231 reads and executes the software 233 stored in the memory 232, thereby controlling the connected equipment.

[0038] Memory 232 is a storage device for storing programs and data. Memory 232 stores software 233, data processed by processor 231, etc. Memory 232 is a double-bank memory (also known as double-sided ROM). In addition, memory 232 may also have volatile storage areas that constitute the working area of ​​processor 231.

[0039] TCU 24 is a communication device that communicates with devices other than vehicle 2 based on the communication standard of vehicle 2. TCU 24 includes, for example, an antenna, a transmitter, and a receiver, and communicates with server device 3 under the control of software update device 27.

[0040] The touch panel 25 consists of a display and a touch sensor, which accepts touch operations and displays various information.

[0041] The GNSS unit 26 locates the current position of the vehicle 2. The GNSS unit 26 generates position data representing the current position of the vehicle 2 and outputs the generated position data to the software update device 27.

[0042] The software update device 27 is a device for updating the software 233 of the ECU 23. The software update device 27 includes a processor 270 such as a CPU, a memory 280, and interface circuits for connecting other devices and sensors.

[0043] Memory 280 is a storage device for storing programs and data. Memory 280 stores control program 281, home location data 282, home time data 283, relationship data 284, and data processed by processor 270, etc. Memory 280 has non-volatile storage areas. Additionally, memory 280 has volatile storage areas that constitute the working area of ​​processor 270. For example, memory 280 is composed of ROM and RAM.

[0044] Control program 281 is a program that enables processor 270 to perform its functions as a functional unit, as described later.

[0045] Home location data 282 is data representing the home location (hereinafter referred to as home location) of the user of vehicle 2, such as latitude and longitude representing the home location.

[0046] Home time data 283 represents the time (hereinafter referred to as home time) that the user of vehicle 2 is at home, and may represent one or more home times. The home time data can be expressed in terms of a single moment or a time interval. Furthermore, the home time data can be a time set by the vehicle user or a predetermined time.

[0047] Relationship data 284 represents the relationship between the remaining capacity of battery 21 (hereinafter referred to as "home position capacity") when vehicle 2 is at home and the time from the disconnection of the ignition power of vehicle 2 until the next ignition power is turned on (hereinafter referred to as "next turn-on time"). More specifically, relationship data 284 is data showing the tendency of home position capacity and next turn-on time.

[0048] The processor 270 functions as a software update unit 271 by executing the control program 281.

[0049] The software update unit 271 updates the software 233 of the ECU 23. The software update unit 271 performs the following processes: querying for information related to the update of the software 233; downloading the update software D1; installing the update software D1 on the ECU 23; and activating the update software D1 on the ECU 23.

[0050] In addition, the software update department 271 learns the relationship between its own location availability and the next call time. The following is a detailed explanation of this learning process performed by the software update department 271.

[0051] When the ignition power to vehicle 2 is disconnected, software update unit 271 determines whether the position of vehicle 2 is its own position. If the current position indicated by the position data received from GNSS unit 26 is within a specified distance from the own position indicated by its own position data 282, software update unit 271 determines that the position of vehicle 2 is its own position.

[0052] Next, if the software update unit 271 determines that the location of vehicle 2 is its own home location, it determines whether the time when the ignition power of vehicle 2 is disconnected matches the home time. If the time when the ignition power is disconnected matches the home time shown in the home time data 283, the software update unit 271 determines that the time when the ignition power is disconnected is the home time. For example, the home time shows a time period of "19:00 to 07:30". If the time when the ignition power is disconnected is "19:10", the software update unit 271 determines that the time when the ignition power is disconnected matches the home time. On the other hand, if the time when the ignition power is disconnected is "18:45", the software update unit 271 determines that the time when the ignition power is disconnected does not match the home time.

[0053] If the software update unit 271 determines that the time when the ignition power is disconnected coincides with the home time, it obtains the remaining battery level of the battery 21 at the time of the ignition power disconnection as its own home location reserve. Alternatively, the software update unit 271 can obtain the remaining battery level of the battery 21 from the control circuit 22, or it can obtain the remaining battery level of the battery 21 by directly detecting the voltage or current of the battery 21.

[0054] The software update unit 271 determines whether the ignition power supply has been disconnected. If the software update unit 271 determines that the ignition power supply has been disconnected, it obtains the next power-on time by comparing the time when the ignition power supply was most recently disconnected with the time when the ignition power supply was currently connected.

[0055] Next, the software update unit 271 learns the relationship between its own location margin and the next call time based on the obtained location margin and the obtained next call time. In this embodiment, learning the relationship between its own location margin and the next call time means reflecting the obtained location margin and the obtained next call time in the relational data 284. The software update unit 271 uses a prescribed statistical method to reflect the obtained location margin and the obtained next call time in the relational data 284.

[0056] [4. Action]

[0057] Next, refer to Figure 4 The actions of each part of the software update system 1 related to the update of software 233 are explained.

[0058] Figure 4 This is a timing diagram showing the operation of the software update device 27 and the server device 3.

[0059] The software update unit 271 sends an inquiry message to the server device 3 via the TCU 24, asking whether there is any information related to the update of the software 233 (step SA1).

[0060] Asking for information is an example of "first information".

[0061] When the server control unit 30 receives an inquiry message via the server communication unit 31, it sends a first response message to the vehicle 2 (step SA2).

[0062] The first response information is information that indicates a response to information sent from vehicle 2, and it indicates whether there is information related to the update of software 233.

[0063] The software update unit 271 receives the first response information via the TCU 24. If the received first response information indicates that there is a software update 233, the touch panel 25 displays the first screen (step SA3).

[0064] The first screen is a prompt to the user of vehicle 2 asking if they want to update software 233. The user is prompted as needed. For example, in the case of a software update for purposes such as troubleshooting, sometimes the user is not prompted.

[0065] When the software update unit 271 receives an instruction to update software 233 on the first screen, it sends the request information for updating software D1 to the server device 3 via TCU24 (step SA4).

[0066] When the server control unit 30 receives the request information via the server communication unit 31, it sends the second response information to the vehicle 2 (step SA5).

[0067] The second response message is an example of a "second message".

[0068] The second response information will be described in detail here.

[0069] The second response information is information indicating a response to information sent from vehicle 2, including one or more update software D1.

[0070] In addition, the second response information includes information indicating the amount of data in each update software D1.

[0071] In addition, the second response information includes information indicating the application order if it contains multiple update software D1 and specifies the order in which the update software D1 is applied to ECU 23 (hereinafter referred to as the application order).

[0072] When the software update unit 271 receives the second information from the server device 3, that is, when it downloads the update software D1 from the server device 3, it installs the downloaded update software D1 into the target ECU 23 (step SA6).

[0073] If step SA6 is described in detail, the software update unit 271 transmits the update software D1 to the target ECU 23 and instructs the target ECU 23 to write the update software D1 into the memory 232.

[0074] As described above, the memory 232 of the ECU 23 is a double-bank memory. Therefore, the ECU 23 can simultaneously operate according to the software 233 stored in one storage area MA of the memory 232 and write update software D1 to the other storage area MA of the memory 232. Thus, for example, even when the vehicle 2 is in motion, the ECU 23 can write update software D1 to the memory 232.

[0075] Next, at the moment the ignition power to vehicle 2 is disconnected, the software update unit 271 determines whether to transfer to the activation process of the update software D1 (step SA7). This transfer determination is described in detail in the following flowchart.

[0076] If the software update unit 271 determines that the process should be moved to activation, it causes the touch panel 25 to display a second screen (step SA8).

[0077] The second screen asks whether to start the software 233 update.

[0078] Then, if the software update unit 271 displays an instruction to start the software 233 update on the second screen, it instructs the ECU 23 to perform activation processing (step SA9). Furthermore, in this embodiment, a required time for the activation process is set. If the activation process begins, the vehicle 2 cannot be used during the set required time.

[0079] The activation process in ECU 23 will be explained here.

[0080] When ECU 23 receives an instruction to perform activation processing, it performs activation processing for the update software D1. The activation processing for the update software D1 includes the following steps: setting the startup parameters of ECU 23 so that when ECU 23 starts, it loads the written update software D1 and begins to follow the control of the update software D1. For example, the activation processing for the update software D1 includes the following steps: activating the memory area MA containing the update software D1 as a read area and deactivating the memory area MA not containing the update software D1 as a read area.

[0081] In addition, Figure 4 In the shown timing sequence, the software update unit 271 can also skip step SA3 and proceed to step SA4 after receiving the first response information from the server device 3. Furthermore, in the software update system 1, steps SA2, SA3, and SA4 can also be skipped. That is, the software update unit 271 can also be structured to receive the second response information upon receiving an inquiry message.

[0082] Next, refer to Figure 5 as well as Figure 6 The operation of the software update unit 271 involved in the transfer determination of the activation process will be explained.

[0083] First, the actions will be explained when the location of vehicle 2 when the ignition power is disconnected is not its own location, or when the ignition power is disconnected at a time other than home time.

[0084] Figure 5 This is a flowchart illustrating the operation of the software update unit 271. Figure 5 The flowchart describes the actions that begin when the vehicle 2 is not at its home location when the ignition power is disconnected, or when the ignition power is disconnected at a time other than home time.

[0085] The software update unit 271 determines whether the received second information contains multiple update software D1 (step SB1).

[0086] If the software update unit 271 determines that the second information does not contain multiple update software D1 (step SB1: no), it obtains the required time for activation processing based on the second information (step SB2).

[0087] Step SB2 is described in detail.

[0088] The software update unit 271 refers to the information indicating the amount of data contained in the second information to obtain the required time for activation processing. For example, the software update unit 271 uses an algorithm that calculates the required time for activation processing as longer as the amount of data is larger to obtain the required time for activation processing. Furthermore, the required time calculated by this algorithm is a time that does not exceed a predetermined upper limit (e.g., 600 seconds).

[0089] Furthermore, the time required for activation processing is not limited to acquisition based on an algorithm. If the second information includes information indicating the time required for activation processing, the software update unit 271 can obtain the time required for activation processing from the second information.

[0090] The software update unit 271 determines whether the current battery level 21 is above the upper limit of the activation processing time (e.g., 600 seconds) (step SB3).

[0091] If the software update unit 271 determines that the time required for activation processing is greater than the upper limit (step SB3: yes), it determines to move to activation processing (step SB4).

[0092] Furthermore, if step SB4 has been performed, the time required for activation processing obtained in step SB2 is set as the actual time required for activation processing. That is, vehicle 2 cannot be used from the start of activation processing until the time required for activation processing obtained in step SB2 has elapsed.

[0093] On the other hand, if the software update unit 271 determines that the time required for activation processing is less than the upper limit corresponding to the time required for activation processing (step SB3: No), it determines whether to move to activation processing based on the time required for activation processing and the current battery 21 balance (step SB5).

[0094] Step SB5 is described in detail.

[0095] The software update unit 271 obtains the remaining battery level of the battery 21 corresponding to the required time for the activation process obtained in step SB2. The software update unit 271 obtains the remaining battery level of the battery 21 corresponding to the required time for the activation process based on a predetermined algorithm. Furthermore, this predetermined algorithm calculates a larger remaining battery level of the battery 21 the longer the required time for the activation process.

[0096] Next, the software update unit 271 determines whether the remaining battery level of the battery 21 (the remaining battery level of the battery 21 corresponding to the time required for activation processing) is less than or equal to the current remaining battery level of the battery 21. If the software update unit 271 determines that the remaining battery level of the battery 21 is less than or equal to the current remaining battery level of the battery 21, it determines that the process should proceed to activation processing. On the other hand, if the remaining battery level of the battery 21 is greater than or equal to the current remaining battery level of the battery 21, the software update unit 271 determines that the process should not proceed to activation processing.

[0097] Furthermore, if it is determined in step SB5 that the process should proceed to activation, the time required for activation obtained in step SB4 is set as the actual time required for activation.

[0098] Returning to the explanation of step SB1, if the software update unit 271 determines that the received second information contains multiple update software D1s (step SB1: Yes), it obtains the required time for activation processing for each update software D1 contained in the second information (step SB6). Step SB6 is obtained in the same way as step SB2.

[0099] Next, the software update unit 271 determines whether the current remaining amount of battery 21 is above the upper limit corresponding to the required time for activation processing (step SB7).

[0100] If the software update unit 271 determines that the remaining amount is below the upper limit corresponding to the time required for activation processing (step SB7: No), it determines whether the remaining amount of the battery 21 corresponding to the total required time obtained in step SB6 exceeds the current remaining amount of the battery 21 (step SB8).

[0101] If the software update unit 271 determines that the current battery 21's remaining capacity has not been exceeded (step SB8: No), that is, if multiple applications of the update software D1 can be provided with the current battery 21's remaining capacity, it determines to move to the activation process (step SB9).

[0102] If step SB9 has been performed, the total time required for activation processing obtained in step SB6 is set as the actual time required for activation processing.

[0103] Returning to the explanation of step SB8, if the software update unit 271 determines that the current battery 21 has more than enough remaining capacity (step SB8: Yes), it decides on the combination of update software D1 that can be transferred to the activation process (step SB10).

[0104] Example of step SB10.

[0105] In the example described in step SB10, it is assumed that the second information includes first update software D1, second update software D1, and third update software D1. Furthermore, in the example described in step SB10, the required time for the activation process related to the first update software D1 is "A seconds", the required time for the activation process related to the second update software D1 is "B (>A) seconds", and the required time for the activation process related to the third update software D1 is "C (>B) seconds". Additionally, in the example described in step SB10, A seconds + B seconds + C seconds and B seconds + C seconds are considered as required times that cannot be handled with the current remaining battery power of 21.

[0106] In this example, the software update unit 271 decides on either a combination of the first update software D1 and the second update software D1, or a combination of the first update software D1 and the third update software D1, as the update software D1 that can be transferred to the activation process.

[0107] Furthermore, in this example, when the information indicating the application order of the first update software D1 and the second update software D1 is included in the second information, the software update unit 271 determines the following combination. That is, the software update unit 271 determines the combination of the first update software D1 and the second update software D1 as the update software D1 that can be transferred to the activation process, and does not determine the combination of the first update software D1 and the third update software D1.

[0108] The software update unit 271 determines whether to move to the activation process (step SB11).

[0109] Step SB11 is described in detail.

[0110] If the software update unit 271 determines the combination in step SB10, it decides to move to the activation process. On the other hand, if the software update unit 271 cannot determine the combination in step SB10, it decides not to move to the activation process.

[0111] Furthermore, if it is determined in step SB11 that the process should proceed to activation, the total time required for activation corresponding to the combination determined in step SB10 is set as the actual time required for activation. For example, if in step SB10 a combination of first update software D1 and second update software D1 is determined, and the total time required for activation corresponding to this combination is "A seconds + B seconds", then "A seconds + B seconds" is set as the actual time required for activation.

[0112] Returning to the explanation of step SB7, if the software update unit 271 determines that the time required for activation processing is above the upper limit corresponding to the upper limit of the time required for activation processing (step SB7: Yes), it determines whether the total time required for activation processing obtained in step SB6 exceeds the upper limit of the time required for activation processing (step SB12).

[0113] If the software update unit 271 determines that the time required for activation processing does not exceed the upper limit (step SB12: no), it determines to move to activation processing (step SB13).

[0114] If step SB13 has been performed, the total time required for activation processing obtained in step SB6 is set as the actual time required for activation processing.

[0115] If the software update unit 271 determines that the upper limit of the time required for activation processing has been exceeded (step SB12: Yes), it determines the combination of update software D1 that can be transferred to activation processing (step SB14).

[0116] In step SB14, the software update unit 271 determines the combination of update software D1 in a manner that does not exceed the upper limit of the time required for activation processing.

[0117] Next, the software update unit 271 determines that the process should be moved to the activation process (step SB15).

[0118] In addition, if step SB15 has been performed, the total time required for activation processing corresponding to the combination determined in step SB14 is set as the actual time required for activation processing.

[0119] Next, the operation will be explained when the vehicle 2 is at its own location when the ignition power is disconnected and the moment the ignition power is disconnected is at home time.

[0120] Figure 6 This is a flowchart illustrating the operation of the software update unit 271. Figure 6 The flowchart describes the actions that begin when the vehicle 2 is in its home position and the ignition power is disconnected at the time the vehicle is at home.

[0121] The software update unit 271 uses software D1 to obtain the required time for activation processing for each update contained in the second information (step SC1).

[0122] Next, the software update unit 271 obtains the next connection time based on the current remaining battery level of the battery 21 (step SC2).

[0123] Step SC2 is described in detail.

[0124] The software update unit 271 obtains the next connection time by referring to the relationship data 284. As described above, the relationship data 284 is data representing the relationship between the remaining battery capacity of the current location and the next connection time. Therefore, by referring to the relationship data 284, the software update unit 271 can obtain the next connection time corresponding to the current battery capacity of the current battery 21.

[0125] The software update unit 271 determines whether the total time required for activation processing obtained in step SC1 exceeds the obtained next connection time (step SC3).

[0126] If the total time required for activation processing does not exceed the next connection time (step SC3: No), the software update unit 271 determines whether the remaining battery level of the battery 21 corresponding to the total time required for activation processing obtained in step SC1 exceeds the current remaining battery level of the battery 21 (step SC4).

[0127] If the software update unit 271 determines that the current battery level 21 is not exceeded (step SC4: No), it determines to move to the activation process (step SC5).

[0128] In addition, if step SC5 has been performed, the total time required for activation processing obtained in step SC1 is set as the actual time required for activation processing.

[0129] If the software update unit 271 determines that the current battery 21 has more than enough remaining capacity (step SC4: Yes), it decides on the combination of update software D1 that can be transferred to the activation process (step SC6).

[0130] Step SC6 is performed in the same way as step SB10.

[0131] Next, the software update unit 271 determines whether to proceed to the activation process (step SC7).

[0132] Step SC7 is described in detail.

[0133] If the software update unit 271 determines the combination in step SC6, it decides to proceed to the activation process. On the other hand, if the software update unit 271 cannot determine the combination in step SC6, it decides not to proceed to the activation process.

[0134] Furthermore, if it is determined in step SC7 that the process should be moved to activation, the total time required for activation corresponding to the combination determined in step SC6 is set as the actual time required for activation.

[0135] Returning to the explanation of step SC3, if the total time required for activation processing exceeds the next connection time (step SC3: Yes), the software update unit 271 determines the combination of update software D1 that can be transferred to activation processing (step SC8).

[0136] Step SC8 is described in detail.

[0137] In step SC8, the software update unit 271 determines the combination of update software D1 so that the total time required for activation processing does not exceed the next connection time, and activation processing can be performed with the current battery 21 remaining capacity.

[0138] The software update unit 271 determines whether to move to the activation process (step SC9).

[0139] Step SC9 is described in detail.

[0140] If the software update unit 271 determines the combination in step SC8, it decides to proceed to the activation process. On the other hand, if the software update unit 271 cannot determine the combination in step SC8, it decides not to proceed to the activation process.

[0141] Furthermore, if it is determined in step SC8 that the process should proceed to activation, the total time required for activation corresponding to the combination determined in step SC8 is set as the actual time required for activation.

[0142] As described above, in this embodiment, when the vehicle 2 is not at its own location when the ignition power is disconnected, or when the ignition power is disconnected at a time other than home time, the activation processing time can be shortened compared to the upper limit. Furthermore, in this embodiment, when the vehicle 2 is at its own location when the ignition power is disconnected, and the ignition power is disconnected at a time other than home time, the activation processing time can be extended compared to the upper limit, within the range not exceeding the next power-on time.

[0143] [5. Other Implementation Methods]

[0144] The above-described implementation method is merely one approach and can be arbitrarily modified and applied.

[0145] In the above implementation, the "designated location" is exemplified as one's own home. However, the "designated location" is not limited to one's own home; for example, it could be the home of a relative of the user of vehicle 2.

[0146] In the above implementation, "specified time" is exemplified as time spent at home. However, "specified time" is not limited to time spent at home, and can be any period of time during which the vehicle 2 is not used.

[0147] In other embodiments, an upper limit may be set for the activation processing time required for each ECU 23. If there is an ECU 23 whose activation processing time exceeds the upper limit, the activation processing time required for that ECU 23 may be extended. Among the ECUs 23, there are ECUs 23 that operate after the ignition power is disconnected. An example of such an ECU 23 is the ECU 23 that controls the radiator fan. The ECU 23 that controls the radiator fan operates when the ignition power is disconnected while the engine is running under heavy load. Since the start time of the activation processing is delayed, depending on the situation, there may be cases where the end time of the activation processing exceeds the upper limit set for each ECU 23. Therefore, the software update unit 271 determines, for each ECU 23, whether the activation processing time can be extended based on a statistical value of the frequency of ECU 23 operation when the ignition power is disconnected and the actual operation time of the ECU 23. For example, if the frequency of operation is below a threshold and the operation time is also below a threshold, the software update unit 271 determines that the activation processing time of the ECU 23 can be extended. Furthermore, for example, if the frequency of occurrence exceeds a threshold and the operating time also exceeds a threshold, the software update unit 271 determines that the required time for ECU 23 activation processing cannot be extended. Additionally, for example, if the frequency of occurrence exceeds a threshold and the operating time is below a threshold, the software update unit 271 determines that the operating time can be extended if the deviation from the threshold is above a certain value. Furthermore, for example, if the frequency of occurrence is below a threshold and the operating time exceeds a threshold, the software update unit 271 determines that the operating time can be extended if the deviation from the threshold is above a certain value.

[0148] Processors 231, 270, and 300 can be composed of multiple processors or a single processor. These processors can also be hardware programmed to implement the aforementioned functionalities. In this case, these processors are, for example, composed of ASICs (Application Specific Integrated Circuits) or FPGAs (Field Programmable Gate Arrays).

[0149] also, Figure 3 The internal structure of vehicle 2 shown is an example, and the specific installation method is not particularly limited. That is, it is not necessarily necessary to install hardware corresponding to each part separately; of course, it can also be configured so that the functions of each part are implemented by a processor executing a program. In addition, in the above embodiments, a part of the function implemented by software can be made into hardware, or a part of the function implemented by hardware can be implemented by software.

[0150] in addition, Figures 4-6 The steps shown are divided based on the main processing content, and this invention is not limited by the method or name of the division of processing units. Depending on the processing content, it can also be divided into more step units. Alternatively, a single step unit may contain more processes. Furthermore, the order of these steps can be appropriately replaced without affecting the spirit of this invention.

[0151] Furthermore, when implementing the system update method based on the software update device 27 described above using the processor 270, the program executed by the processor 270 can also be configured as a recording medium or a transmission medium for transmitting the program. That is, the control program 281 can also be implemented with the control program 281 recorded on a removable information recording medium. Examples of information recording media include magnetic recording media such as hard disks, optical recording media such as CDs, USB (Universal Serial Bus) memory, SSD (Solid State Drive) and other semiconductor storage devices, but other recording media can also be used.

[0152] [6. Structure supported by the above embodiments]

[0153] The above implementation supports the following structures.

[0154] (Structure 1)

[0155] A software update system includes a vehicle with an electronic control unit and a server device capable of communicating with the vehicle. The vehicle includes: a software update unit that updates the software of the electronic control unit; and a battery that supplies power to the electronic control unit. The software update unit sends first information to the server device inquiring about the availability of information related to the software update, and receives second information from the server device containing the update software. Based on the received second information, the software update unit obtains the required time for activation processing of the update software, and based on the obtained required time and the remaining battery power, determines whether to transfer to the activation processing.

[0156] According to the software update system of Structure 1, the decision to transfer activation processing is based on the time required for the acquired activation process and the remaining battery capacity. Therefore, by determining whether the remaining battery capacity is sufficient relative to the actual time required for activation processing, the likelihood of transferring to activation processing can be increased. Thus, the likelihood of software updates being performed can be increased.

[0157] (Structure 2)

[0158] According to the software update system of Structure 1, wherein the second information includes a plurality of update software, the software update unit obtains the required time for each update software included in the second information, and determines a combination of update software that can be transferred to the activation process based on the obtained required time and the remaining battery capacity, and determines to transfer to the activation process if a combination of update software that can be transferred to the activation process is determined.

[0159] According to the software update system of Structure 2, when a combination of update software that can be transferred to the activation process is determined, the system decides to transfer the software to the activation process, thus increasing the likelihood of transferring the software to the activation process. Therefore, the likelihood of software updates being performed can be further increased.

[0160] (Structure 3)

[0161] According to the software update system of structure 2, the software update unit determines the combination of update software that can be transferred to the activation process based on the order in which the update software is applied.

[0162] According to the software update system of Structure 3, the combination of update software can be determined by considering the order in which the update software is applied, thus enabling software updates to be performed in an appropriate order and further increasing the likelihood of software updates being performed.

[0163] (Structure 4)

[0164] According to the software update system of Structure 1, when the vehicle's position is at a predetermined position within a predetermined time, the software update unit sets the required time based on the remaining battery level and the time until the next time the vehicle's ignition power is turned on.

[0165] According to the software update system of Structure 4, the activation processing time can be set by taking into account the remaining battery power and the time until the next ignition power is turned on. Therefore, if there is a surplus of battery power and time until the next ignition power is turned on, the activation processing time can be set to be longer. Thus, it can reduce the discomfort of vehicle users when the vehicle is unusable due to activation processing, and it can perform a large number of software updates.

[0166] (Structure 5)

[0167] According to the software update system of structure 4, the software update unit learns the relationship between the remaining battery capacity and the time until the next ignition power is turned on when the vehicle is at the specified position within the specified time.

[0168] According to the software update system of Structure 5, the required activation time can be set based on the remaining battery level when the vehicle is in a specified position within a specified time and the tendency of the time until the next ignition power is turned on. Therefore, it is possible to prevent the inappropriate setting of the required activation time for the time until the next ignition power is turned off.

[0169] (Structure 6)

[0170] A vehicle capable of communicating with a server device, comprising: an electronic control unit; a software update unit for updating the software of the electronic control unit; and a battery for supplying power to the electronic control unit. The software update unit sends first information to the server device inquiring about the availability of information related to the software update, and receives second information from the server device containing software for updating. Based on the received second information, the software update unit obtains the required time for activation processing of the software for updating, and determines whether to transfer to the activation process based on the obtained required time and the remaining battery power.

[0171] According to the vehicle of Structure 6, it achieves the same effect as the software update system of Structure 1.

[0172] (Structure 7)

[0173] A software update device is provided in a vehicle capable of communicating with a server device. The software update device includes a software update unit that updates the software of an electronic control unit (ECU) of the vehicle. The software update unit sends first information to the server device inquiring about the availability of information related to the software update, and receives second information from the server device containing the update software. Based on the received second information, the software update unit obtains the required time for activation processing of the update software, and based on the obtained required time and the remaining battery capacity supplying power to the ECU, determines whether to transfer to the activation process.

[0174] The software update device of structure 7 achieves the same effect as the software update system of structure 1.

[0175] (Structure 8)

[0176] A software update method is disclosed for updating the software of an electronic control unit of a vehicle capable of communicating with a server device. In the software update process, the vehicle sends first information to the server device inquiring about the availability of information related to the software update, and receives second information from the server device containing the software for update. Based on the received second information, the vehicle obtains the required time for activation processing of the software update, and based on the obtained required time and the remaining battery capacity supplying power to the electronic control unit, determines whether to transfer to the activation process.

[0177] The software update method according to Structure 8 achieves the same effect as the software update system of Structure 1.

[0178] Explanation of reference numerals in the attached figures

[0179] 1…Software update system, 2…Vehicle, 3…Server device, 4…Base station, 21…Battery, 22…Control circuit, 23…ECU (Electronic Control Unit), 24…TCU, 25…Touch panel, 26…GNSS unit, 27…Software update device, 30…Server control unit, 31…Server communication unit, 231…Processor, 232…Memory, 233…Software, 270…Processor, 271…Software update unit, 280…Memory, 281…Control program, 282…Home location data, 283…Home time data, 284…Relationship data, 300…Processor, 310…Memory, 311…Control program, D1…Update software, MA…Storage area, NW…Communication network.

Claims

1. A software update system comprising a vehicle having an electronic control unit and a server device capable of communicating with the vehicle, wherein, The vehicle has the following features: The software update unit updates the software of the electronic control unit; and The battery supplies power to the electronic control unit. The software update unit sends a first message to the server device inquiring about the availability of information related to the software update, and receives a second message from the server device containing the software for the update. Based on the received second information, the software update unit obtains the required time for the activation process of the update software, and determines whether to transfer to the activation process based on the obtained required time and the remaining battery level.

2. The software update system according to claim 1, wherein, The second information includes multiple software updates. The software update unit obtains the required time for each update software included in the second information, and based on the obtained required time and the remaining battery level, determines the combination of update software that can be transferred to the activation process. If a combination of the update software that can be transferred to the activation process is determined, it is determined that the transfer should be made to the activation process.

3. The software update system according to claim 2, wherein, The software update unit determines the combination of update software that can be transferred to the activation process based on the order in which the update software is applied.

4. The software update system according to claim 1, wherein, If the vehicle's location is at a specified position within a specified time, the software update unit sets the required time based on the remaining battery level and the time until the vehicle's ignition power is turned on next time.

5. The software update system according to claim 4, wherein, The software update unit learns the relationship between the remaining battery capacity and the time until the next ignition power is turned on, assuming the vehicle's position is at the specified location within the specified time.

6. A vehicle capable of communicating with a server device, wherein, This vehicle is equipped with: Electronic Control Department; The software update unit updates the software of the electronic control unit; and The battery supplies power to the electronic control unit. The software update unit sends a first message to the server device inquiring about the availability of information related to the software update, and receives a second message from the server device containing the software for the update. Based on the received second information, the software update unit obtains the required time for the activation process of the update software, and determines whether to transfer to the activation process based on the obtained required time and the remaining battery level.

7. A software update device, wherein the software update device is installed in a vehicle capable of communicating with a server device, wherein, The software update device includes a software update unit that updates the software of the electronic control unit of the vehicle. The software update unit sends a first message to the server device inquiring about the availability of information related to the software update, and receives a second message from the server device containing the software for the update. Based on the received second information, the software update unit obtains the required time for the activation process of the update software, and based on the obtained required time and the remaining battery capacity for supplying power to the electronic control unit, determines whether to transfer to the activation process.

8. A software update method for updating the software of an electronic control unit in a vehicle capable of communicating with a server device, wherein, In the software update, The vehicle sends a first message to the server device inquiring about the availability of information related to the software update, and receives a second message from the server device containing information about the updated software. Based on the received second information, the vehicle obtains the required time for the activation process of the updated software, and based on the obtained required time and the remaining battery capacity for supplying power to the electronic control unit, determines whether to transfer to the activation process.

Citation Information

Patent Citations

  • vehicle

    JP2022054890A