On-vehicle device, update method, and update program

JP2024154953A5Pending Publication Date: 2025-10-06AUTONETWORKS TECH LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023069206
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-04-20
Publication Date
2025-10-06

AI Technical Summary

Technical Problem

The existing in-vehicle relay device requiring two CPUs results in a high number of parts and increased product cost.

Method used

An in-vehicle device with logically separated first and second logical areas, where data exchange is restricted, and an inter-area communication unit facilitates data transfer between these areas, allowing for software updates without redundant hardware.

Benefits of technology

Ensures security while reducing the number of device parts and maintaining operational efficiency during software updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To ensure the security while suppressing the number of parts of an on-vehicle device.SOLUTION: An on-vehicle device comprises: a storage unit that includes a first logical region and a second logical region; first software that is stored in the first logical region and that can transmit and receive data to and from an on-vehicle network; second software that is stored in the second logical region and which is restricted from transmitting and receiving data to and from the on-vehicle network; an updating unit that updates the second software; and an inter-region communication unit that can exchange data with the first logical region and that can exchange data with the second logical region. The inter-region communication unit receives, from a data communication unit, update data that is received by the data communication unit, which is implemented by the first software, from the on-vehicle network, and delivers the update data to the updating unit. The updating unit updates the second software on the basis of the update data.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to an in-vehicle device, an update method, and an update program. [Background technology]

[0002] A vehicle is equipped with a variety of on-board devices, such as control system ECUs (Electronic Control Units) that control the engine, transmission, etc., body system ECUs that control the headlights, power windows, etc., and information system ECUs for navigation devices, multimedia devices, etc.

[0003] Patent Document 1 discloses an in-vehicle relay device including a first CPU (Central Processing Unit) and a second CPU. The first CPU is separated from an in-vehicle network 2 inside the vehicle, and communication with the outside of the vehicle is performed by the first CPU. The second CPU is provided separately from the outside of the vehicle and is communicatively connected to the in-vehicle network. The in-vehicle relay device disclosed in Patent Document 1 improves security by providing multiple layers of defense against attacks on the in-vehicle network from outside the vehicle using the physically separated first and second CPUs. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2022-173923 A Summary of the Invention [Problem to be solved by the invention]

[0005] However, the vehicle-mounted relay device disclosed in Patent Document 1 requires two CPUs, which results in a large number of parts and increases the product cost. [Means for solving the problem]

[0006] An in-vehicle device according to one embodiment of the present disclosure is an in-vehicle device connected to an in-vehicle network, and comprises: a memory unit including a first logic area and a second logic area which are logically separated from each other and in which data transmission and reception is restricted; first software stored in the first logic area and capable of transmitting and receiving data to the in-vehicle network; second software stored in the second logic area and in which data transmission and reception to the in-vehicle network is restricted; an update unit which updates the second software; and an inter-area communication unit which is capable of transmitting and receiving data to and from the first logic area and which is also capable of transmitting and receiving data to and from the second logic area, wherein the inter-area communication unit receives update data from the in-vehicle network by a data communication unit realized by executing the first software by a processor, and passes the received update data to the update unit, and the update unit updates the second software based on the update data passed from the inter-area communication unit. Effect of the Invention

[0007] According to the present disclosure, it is possible to ensure security while reducing the number of parts in an in-vehicle device. [Brief description of the drawings]

[0008] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of an in-vehicle network according to the first embodiment. [Diagram 2] FIG. 2 is a block diagram showing an example of a hardware configuration of the ECU according to the first embodiment. [Diagram 3] FIG. 3 is a block diagram showing an example of the configuration of a nonvolatile memory mounted in the ECU according to the first embodiment. [Figure 4] FIG. 4 is a diagram showing a configuration of partitions in the nonvolatile memory according to the first embodiment. [Diagram 5] FIG. 5 is a diagram for explaining an example of a data flow in the ECU according to the first embodiment. [Figure 6]FIG. 6 is a diagram for explaining another example of the data flow in the ECU according to the first embodiment. [Figure 7] FIG. 7 is a diagram for explaining an example of a data flow when updating the first software in the ECU according to the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the update of the first software in the ECU according to the first embodiment. [Figure 9] FIG. 9 is a diagram for explaining an example of a data flow when updating the second software in the ECU according to the first embodiment. [Figure 10] FIG. 10 is a diagram for explaining the update of the second software in the ECU according to the first embodiment. [Figure 11] FIG. 11 is a sequence diagram showing a data flow in an in-vehicle network when updating the second software in the ECU according to the first embodiment. [Figure 12] FIG. 12 is a flowchart showing an example of the operation of the ECU when the ECU according to the first embodiment updates the second software. [Figure 13] FIG. 13 is a block diagram showing an example of the configuration of a nonvolatile memory mounted in an ECU according to the second embodiment. [Figure 14] FIG. 14 is a diagram showing a configuration of partitions in a nonvolatile memory according to the second embodiment. [Figure 15] FIG. 15 is a diagram showing the operating state of software when the execution target of the first application software and the second application software is switched. [Figure 16] FIG. 16 is a block diagram showing an example of the configuration of a nonvolatile memory mounted on an ECU according to the third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] <Overview of the embodiment of the present disclosure> Below, an overview of the embodiments of the present disclosure will be listed and described.

[0010] (1) The in-vehicle device according to the present embodiment is an in-vehicle device connected to an in-vehicle network, and includes a storage unit including a first logic area and a second logic area that are logically separated from each other and in which data transmission and reception are restricted, a first software stored in the first logic area and capable of transmitting and receiving data to the in-vehicle network, a second software stored in the second logic area and in which data transmission and reception to the in-vehicle network are restricted, an update unit that updates the second software, and an inter-area communication unit that is capable of transmitting and receiving data to and from the first logic area and is also capable of transmitting and receiving data to and from the second logic area, the inter-area communication unit receives update data from the in-vehicle network by a data communication unit that is realized by a processor executing the first software, and transfers the received update data to the update unit, and the update unit updates the second software based on the update data transferred from the inter-area communication unit. This allows the first software and the second software to be mounted in the in-vehicle device without making the hardware of the in-vehicle device redundant, thereby reducing the number of parts of the in-vehicle device. Furthermore, security can be ensured by placing the first software and the second software in a first logical area and a second logical area, which are logically separated, and allowing data to be exchanged between the first software and the second software only via the inter-area communication unit.

[0011] (2) In the above (1), the update unit may be realized by the processor executing update software stored in the second logic area. This ensures higher security by disposing the update software in the second logic area where direct data transmission from the vehicle network is restricted.

[0012] (3) In the above (2), the update unit may be capable of updating the first software. In this way, even when updating the first software, data is exchanged via the inter-area communication unit, so that high security can be ensured.

[0013] (4) In the above (1), the update unit may include a first update unit that updates the first software and a second update unit that updates the second software, and the first update unit may be realized by the processor executing the first update software stored in the first logic area, and the second update unit may be realized by the processor executing the second update software stored in the second logic area. This eliminates the need to exchange data via an inter-area communication unit when updating the first software, and reduces the processing load. When updating the second software, update data is exchanged via an inter-area communication unit, and therefore high security can be ensured.

[0014] (5) In the above (4), the first update unit may receive, from the data communication unit, the first update data that the data communication unit has received from the in-vehicle network, and update the first software based on the received first update data. This prevents the first update unit from directly receiving the first update data from the in-vehicle network, thereby improving security.

[0015] (6) In any one of (1) to (5) above, the storage unit may include a first storage unit and a second storage unit that are physically separated, the inter-area communication unit may include a first inter-area communication unit that is realized by the processor executing first management software stored in the first storage unit and a second inter-area communication unit that is realized by the processor executing second management software stored in the second storage unit, the first inter-area communication unit may operate while the second inter-area communication unit is stopped, and the second inter-area communication unit may operate while the first inter-area communication unit is stopped. In this way, by switching between the operation of the first inter-area communication unit and the operation of the second inter-area communication unit, the period during which the operation of the inter-area communication unit is stopped can be shortened or eliminated.

[0016] (7) In the above (6), the first inter-area communication unit may operate while the second management software is being updated, and the second inter-area communication unit may operate while the first management software is being updated. This makes it possible to shorten or eliminate a period during which the operation of the inter-area communication unit is stopped while the first management software or the second management software is being updated.

[0017] (8) In the above (6) or (7), the storage unit may include a third logical area that is logically separated from each of the first logical area and the second logical area and in which data transfer to and from each of the first logical area and the second logical area is restricted, and the first management software and the second management software may be stored in the third logical area. This allows the first management software and the second management software to be logically separated from the first software and the second software, thereby further enhancing security.

[0018] (9) In any one of (6) to (8) above, the first logic area may include a first partial area of ​​the first storage unit and a first partial area of ​​the second storage unit, the second logic area may include a second partial area of ​​the first storage unit and a second partial area of ​​the second storage unit, and two pieces of the first software are stored in each of the first partial area of ​​the first storage unit and the first partial area of ​​the second storage unit, and the first software stored in the first partial area of ​​the second storage unit may be stopped while the first software stored in the first partial area of ​​the first storage unit is being executed, and the first software stored in the first partial area of ​​the first storage unit may be stopped while the first software stored in the first partial area of ​​the second storage unit is being executed. This may shorten or eliminate a period during which the first software is stopped.

[0019] (10) In the above (9), the first software stored in the first partial area of ​​the second storage unit may be executed while the first software stored in the first partial area of ​​the first storage unit is being updated, and the first software stored in the first partial area of ​​the second storage unit may be executed while the first software stored in the first partial area of ​​the second storage unit is being updated. This makes it possible to shorten or eliminate a period during which the first software is stopped while the first software is being updated.

[0020] (11) In the above (9), two pieces of the second software may be stored in each of the second partial area of ​​the first storage unit and the second partial area of ​​the second storage unit, and the second software stored in the second partial area of ​​the second storage unit may be stopped while the second software stored in the second partial area of ​​the first storage unit is being executed, and the second software stored in the second partial area of ​​the first storage unit may be stopped while the second software stored in the second partial area of ​​the second storage unit is being executed. This makes it possible to shorten or eliminate a period during which the second software is stopped.

[0021] (12) In the above (11), the second software stored in the second partial area of ​​the second storage unit may be executed while the second software stored in the second partial area of ​​the first storage unit is being updated, and the second software stored in the second partial area of ​​the first storage unit may be executed while the second software stored in the second partial area of ​​the second storage unit is being updated. This makes it possible to shorten or eliminate a period during which the second software is stopped while the second software is being updated.

[0022] (13) In any one of (1) to (12) above, the data communication unit may have a first defense function for defending against external attacks, and the data transmission / reception unit realized by executing the second software by a processor may have a second defense function for defending against external attacks. This makes it possible to ensure high security by the first defense function and the second defense function. In particular, in the second software, two-stage defense functions, the first defense function and the second defense function, are activated when receiving data from an in-vehicle network, so that an even higher level of security can be ensured.

[0023] (14) An update method according to the present embodiment is an update method for updating software in an in-vehicle device connected to an in-vehicle network, and includes the steps of: receiving update data from the in-vehicle network by a data communication unit that is realized by a processor executing first software stored in a first logic area provided in a storage unit and capable of transmitting and receiving data to and from the in-vehicle network, by an inter-area communication unit capable of transmitting and receiving data to and from the first logic area; transferring the update data to an update unit that updates second software that is stored in a second logic area provided in a storage unit and logically separated from the first logic area and has limited data transmission and reception to and from the in-vehicle network, by the inter-area communication unit; and updating the second software based on the update data transferred from the inter-area communication unit. This allows the first software and the second software to be mounted in the in-vehicle device without redundant hardware configuration of the in-vehicle device, thereby reducing the number of parts of the in-vehicle device. Furthermore, security can be ensured by placing the first software and the second software in a first logical area and a second logical area, which are logically separated, and enabling data exchange between the first software and the second software only via the inter-area communication unit.

[0024] (15) The update program according to the present embodiment is an update program for updating software in an in-vehicle device connected to an in-vehicle network, and causes a computer including a storage unit including a first logic area and a second logic area, which are logically separated from each other and in which data exchange is restricted, to execute the following steps: receiving update data received from the in-vehicle network by a data communication unit realized by a processor executing a first software stored in the first logic area and capable of transmitting and receiving data to the in-vehicle network, via an inter-area communication unit capable of transmitting and receiving data to and from the first logic area; and updating second software stored in the second logic area and in which data exchange is restricted to the in-vehicle network, based on the update data received from the inter-area communication unit. This allows the first software and the second software to be mounted on the in-vehicle device without making the hardware of the in-vehicle device redundant, thereby reducing the number of parts of the in-vehicle device. Furthermore, security can be ensured by arranging the first software and the second software in the first logic area and the second logic area, which are logically separated from each other, and enabling data exchange between the first software and the second software only by the inter-area communication unit.

[0025] The present disclosure can be realized not only as an in-vehicle device having the above-described characteristic configuration, an update method having steps corresponding to characteristic processing in the in-vehicle device, and an update program for causing the in-vehicle device to execute the characteristic processing, but also as an in-vehicle system including the in-vehicle device, or as a semiconductor integrated circuit in part or in whole of the in-vehicle device.

[0026] <Details of the embodiment of the present disclosure> Hereinafter, the details of the embodiments of the present invention will be described with reference to the drawings. Note that at least some of the embodiments described below may be combined in any desired manner.

[0027] [1. First embodiment] [1-1. In-vehicle network] 1 is a block diagram showing an example of a configuration of an in-vehicle network according to the first embodiment. The in-vehicle network 100 includes a plurality of ECUs 200A, 200B, 200C, . . . and an external communication device 300.

[0028] The in-vehicle network 100 is configured by ECUs 200A, 200B, 200C, . . . , an external communication device 300, and a communication line (communication bus) connecting them.

[0029] The multiple ECUs 200A, 200B, 200C, etc. are disposed in various parts of the vehicle. The ECUs 200A, 200B, 200C, etc. individually control the hardware of the various parts of the vehicle and monitor the status of the hardware of the various parts of the vehicle. For example, the ECUs 200A, 200B, 200C, etc. are ECUs for a control system, a body system, and an information system. In the following description, the ECUs 200A, 200B, 200C, etc. are collectively referred to as "ECU 200".

[0030] Each of the ECUs 200A, 200B, 200C, ... is connected to another via a communication bus 500 such as a CAN (Controller Area Network) bus. The ECU 200 can transmit a frame. The frame is a message that complies with the above-mentioned communication protocol.

[0031] Although not shown, the vehicle may include a relay ECU that relays frames between multiple ECUs 200. For example, the relay ECU is connected to multiple communication buses and can relay frames between the communication buses.

[0032] The ECU 200 uses a communication protocol for transmitting and receiving messages periodically or aperiodically. The communication protocol is, for example, CAN or CAN FD (CAN with Flexible Data Rate). In another example, the communication protocol is Ethernet.

[0033] Fig. 1 shows an in-vehicle network 100 in a case where the ECU 200 and the external communication device 300 use a CAN protocol. That is, the in-vehicle network 100 shown in Fig. 1 has a bus-type network topology. In a case where the ECU 200 and the external communication device 300 use an Ethernet protocol, the network topology of the in-vehicle network 100 becomes a star-type.

[0034] The external communication device 300 is connected to a communication bus 500. The external communication device 300 can transmit and receive frames between the ECUs 200A, 200B, 200C, etc. via the communication bus 500. The external communication device 300 is, for example, a TCU (Telematics Control Unit) and can communicate with devices outside the vehicle. The external communication device 300 includes a wireless communication interface for a mobile communication system such as a fifth generation mobile communication system (5G) or a fourth generation mobile communication system (4G). The external communication device 300 can transmit and receive packets of, for example, TCP / IP (Transmission Control Protocol / Internet Protocol). The external communication device 300 can connect to a base station (not shown) of a mobile communication network and communicate with devices connected to the Internet via the base station. Specifically, the external communication device 300 can communicate with a server 400. The external communication device 300 relays communication between the ECUs 200A, 200B, 200C and the server 400.

[0035] The server 400 stores update data used to update software for the ECU 200 in the ECU 200. In response to a request from the ECU 200, the server 400 transmits the update data to a vehicle (i.e., the external communication device 300) in which the ECU 200 is mounted. The server 400 is a so-called OTA (Over The Air) server.

[0036] [1-2.ECU hardware configuration] 2 is a block diagram showing an example of a hardware configuration of an ECU according to the first embodiment. The ECU 200 includes a processor 201, a nonvolatile memory 202, a volatile memory 203, and a communication interface (hereinafter also referred to as a "communication I / F") 204. The processor 201, the nonvolatile memory 202, the volatile memory 203, and the communication I / F 204 are connected to each other by a bus 205 which is a communication line. The processor 201, the nonvolatile memory 202, the volatile memory 203, and the communication I / F 204 can transmit data to each other via the bus 205. The ECU 200 is an example of an "on-vehicle device."

[0037] The volatile memory 203 is a semiconductor memory such as a static random access memory (SRAM) or a dynamic random access memory (DRAM).

[0038] FIG. 3 is a block diagram showing an example of the configuration of a nonvolatile memory mounted in the ECU according to the first embodiment.

[0039] Data can be rewritten in the non-volatile memory 202. That is, the non-volatile memory 202 is, for example, a flash memory, a hard disk, etc. The non-volatile memory 202 is an example of a "storage unit."

[0040] In a specific example, the non-volatile memory 202 is a dual bank memory. That is, the non-volatile memory 202 includes a first bank 202A and a second bank 202B that are physically separated from each other. The first bank 202A and the second bank 202B are assigned different memory areas (address spaces). The first bank 202A and the second bank 202B can operate independently of each other. That is, the first bank 202A and the second bank 202B can write and read data independently of each other. The first bank 202A is an example of a "first storage unit" and the second bank 202B is an example of a "second storage unit".

[0041] The non-volatile memory 202 stores a first application software 211, a first update software 221, a second application software 212, a second update software 222, and management software 230A, 230B, which are computer programs, and data used to execute these software. Hereinafter, "application software" will also be referred to as "APP" and "software" will also be referred to as "SW." Functions of the ECU 200, which will be described later, are realized by the processor 201 executing the first application software 211, the first update software 221, the second application software 212, the second update software 222, and management software 230A, 230B.

[0042] The first APP 211 is, for example, application software for realizing a function of one ECU. The second APP 212 is, for example, application software for realizing a function of an ECU different from the first APP 211. That is, the ECU 200 is an ECU that integrates the functions of two ECUs. The first APP 211 and the second APP 212 operate on an operating system or a hypervisor (management SWs 230A, 230B described later). For example, the first APP 211 is software for controlling headlights, and the second APP 212 is an ECU for controlling door mirrors.

[0043] In the first embodiment, the first APP 211, the first update SW 221, the second APP 212, the second update SW 222, and the management SW 230A are stored in the first bank 202A. The management SW 230B is stored in the second bank 202B. The management SW 230A is an example of the "first management software." The management SW 230B is an example of the "second management software."

[0044] The management SW 230A and the management SW 230B are, for example, different versions of the same software. For example, the management SW 230A is the latest version of the software, and the management SW 230B is an old version of the software. Only one of the management SWs 230A and 230B is executed at the same time. For example, the new version of the management SW 230A is executed, and the old version of the management SW 230B is stopped. When a new version of the management SW is released, the stopped management SW 230B is updated. The management SW 230A continues to operate while the management SW 230B is being updated. When the update of the management SW 230B is completed, the operating target is switched from the management SW 230A (old version of the software) to the management SW 230B (latest version of the software). This makes it possible to shorten or eliminate the stop period of the management SW due to the update.

[0045] Returning to FIG. 2, the processor 201 is, for example, a CPU (Central Processing Unit). However, the processor 201 is not limited to a CPU. The processor 201 may be a GPU (Graphics Processing Unit). In a specific example, the processor 201 is a multi-core processor. The processor 201 may be a single-core processor. The processor 201 is configured to be able to execute a computer program. However, the processor 201 may be, for example, an ASIC (Application Specific Integrated Circuit) or a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0046] The communication I / F 204 is a communication interface that complies with the above-mentioned communication protocol for the in-vehicle network. The communication I / F 204 is, for example, a CAN interface. The communication I / F 204 may be an Ethernet interface.

[0047] The communication I / F 204 is connected to the bus 500. The communication I / F 204 enables the ECU 200 to communicate with other ECUs 200 and the external communication device 300. The communication I / F 204 enables the ECU 200 to communicate with the server 400 via the external communication device 300.

[0048] [1-3. Non-volatile memory logic area]

[0049] The non-volatile memory 202 includes a memory protection unit (MPU) (not shown). One or more logical regions (partitions) can be created in the non-volatile memory 202. The MPU restricts data exchange between the partitions.

[0050] The management SWs 230A and 230B are, for example, an operating system (OS) or a hypervisor. The management SWs 230A and 230B support data exchange between partitions, that is, inter-partition communication.

[0051] FIG. 4 is a diagram showing a configuration of partitions in the nonvolatile memory according to the first embodiment.

[0052] The non-volatile memory 202 includes a first logic area 251 and a second logic area 252. The first logic area 251 and the second logic area 252 are logically separated from each other. Data exchange between the first logic area 251 and the second logic area 252 is restricted by the MPU. Each of the first logic area 251 and the second logic area 252 is a partition.

[0053] The non-volatile memory 202 further includes a third logic area 253. The third logic area 253 is a partition logically separated from each of the first logic area 251 and the second logic area 252. Data exchange between the third logic area 253 and the first logic area 251 is restricted by the MPU, and data exchange between the third logic area 253 and the second logic area 252 is also restricted by the MPU.

[0054] The first logic area 251, the second logic area 252, and the third logic area 253 are created by a function of the management software 230A. The first logic area 251 is created in the above-mentioned first bank 202A. The second logic area 252 is created in the first bank 202A. In other words, the first logic area 251 is a partial area of ​​the first bank 202A, and the second logic area 252 is another partial area of ​​the first bank 202A.

[0055] The third logic area 253 is provided across the first bank 202A and the second bank 202B. A part of the third logic area 253 is created in the first bank 202A, and another part of the third logic area 253 is created in the second bank 202B. In other words, the third logic area 253 includes a part of the area of ​​the first bank 202A and a part of the area of ​​the second bank 202B.

[0056] The first logic area 251 stores a first APP 211 and a first updated SW 221. The second logic area 252 stores a second APP 212 and a second updated SW 222. By storing the first APP 211 and the second APP 212 in different logic areas, it is possible to prevent interference between the first APP 211 and the second APP 212.

[0057] The management SW 230A and 230B are stored in the third logic area 253. More specifically, the management SW 230A is stored in an area of ​​the first bank 202A in the third logic area 253, and the management SW 230B is stored in an area of ​​the second bank 202B in the third logic area 253.

[0058] [1-4.ECU Functions] Next, the functions of the ECU 200 will be described.

[0059] The ECU 200 has the functions of an update unit 240, a data communication unit 243, an inter-area communication unit 244A, and a data transmission / reception unit 245.

[0060] The processor 201 executes the first APP 211 to implement a data communication unit 243. The data communication unit 243 transmits and receives data (frames) to and from the in-vehicle network 100. That is, the data communication unit 243 can transmit and receive frames to and from another ECU 200, and can transmit and receive frames to and from the external communication device 300.

[0061] The data communication unit 243 is a function that is realized by executing the first APP 211 stored in the first logic area 251, and is a function that belongs to the first logic area 251.

[0062] The processor 201 executes the second APP 212 to implement a data transfer unit 245. The data transfer unit 245 can transfer data only to the inter-area communication unit 244A.

[0063] The data transmission / reception unit 245 is a function that is realized by executing the second APP 212 stored in the second logic area 252, and is a function that belongs to the second logic area 252.

[0064] An inter-area communication unit 244A is implemented by the processor 201 executing the management SW 230A. The inter-area communication unit 244A is a function of the management SW 230A that created the first logic area 251, the second logic area 252, and the third logic area 253, and is a function that is implemented by inter-partition communication.

[0065] As described above, while the management SW 230A is being executed by the processor 201, the management SW 230B is not executed by the processor 201. In other words, the management SW 230B is in a stopped state. In the figure, the diagonal hatching indicates a stopped state.

[0066] The inter-area communication unit 244A can receive data from the data communication unit 243 by the inter-partition communication function of the management SW 230A. That is, the inter-area communication unit 244A can move data from the first logic area 251 to the third logic area 253. Furthermore, the inter-area communication unit 244A can hand over data to the data communication unit 243 by the inter-partition communication function of the management SW 230A. That is, the inter-area communication unit 244A can move data from the third logic area 253 to the first logic area 251.

[0067] The data communication unit 243 can only exchange data with the inter-area communication unit 244A. Data exchange between the first logic area 251 and the second logic area 252 by the data communication unit 243 (i.e., by the first APP 211) and data exchange between the first logic area 251 and the third logic area 253 are restricted (prohibited) by the MPU. That is, the data communication unit 243 cannot move data from the first logic area 251 to the second logic area 252, and cannot move data from the second logic area 252 to the first logic area 251. Furthermore, the data communication unit 243 cannot move data from the first logic area 251 to the third logic area 253, and cannot move data from the third logic area 253 to the first logic area 251, without relying on the inter-area communication unit 244A.

[0068] The inter-area communication unit 244A can deliver data to the data transfer unit 245 by the inter-partition communication function of the management SW 230A. That is, the inter-area communication unit 244A can move data from the third logic area 253 to the second logic area 252. Furthermore, the inter-area communication unit 244A can receive data from the data transfer unit 245 by the inter-partition communication function of the management SW 230A. That is, the inter-area communication unit 244A can move data from the second logic area 252 to the third logic area 253.

[0069] The data transfer unit 245 can transfer data only to the inter-area communication unit 244A. Data exchange between the second logic area 252 and the first logic area 251 by the data transfer unit 245 (i.e., by the second APP 212) and data exchange between the second logic area 252 and the third logic area 253 are restricted (prohibited) by the MPU. That is, the data transfer unit 245 cannot move data from the second logic area 252 to the first logic area 251, and cannot move data from the first logic area 251 to the second logic area 252. Furthermore, the data transfer unit 245 cannot move data from the second logic area 252 to the third logic area 253, and cannot move data from the third logic area 253 to the second logic area 252, without relying on the inter-area communication unit 244A.

[0070] The data communication unit 243 has a first defense function that defends against external attacks. The first defense function is realized by the data communication unit 243 executing a first defense process. When the communication protocol used by the ECU 200 is CAN, the first defense process is, for example, a filtering function that determines that frames other than those including a specific CAN ID are abnormal frames. When the communication protocol used by the ECU 200 is Ethernet, the first defense process is, for example, a firewall and packet filtering.

[0071] The data transmission / reception unit 245 has a second defense function for defending against external attacks. The second defense function is realized by the data transmission / reception unit 244 executing a second defense process. The second defense process is, for example, a filtering function for detecting the above-mentioned abnormal frame when the communication protocol used by the ECU 200 is CAN. The second defense process is, for example, a firewall and packet filtering when the communication protocol used by the ECU 200 is Ethernet.

[0072] FIG. 5 is a diagram for explaining an example of a data flow in the ECU according to the first embodiment.

[0073] For example, consider the case where the second APP 212 is software for controlling door mirrors. When a user (driver) presses a switch to instruct folding of the door mirrors, (a frame including) command data for folding the door mirrors is transmitted from the external ECU 200 to the in-vehicle network 100.

[0074] The data communication unit 243 receives the command data and executes the first defense process. If an abnormality is detected in the command data, the command data is discarded, and an abnormality process such as notifying the user of the abnormality is executed.

[0075] If there is no abnormality in the command data, the inter-area communication unit 244 A receives the command data from the data communication unit 243 and passes the command data to the data transfer unit 245 .

[0076] The data transmission / reception unit 245 receives the command data and executes the second defense process. If an abnormality is detected in the command data, the command data is discarded and abnormality processing is executed.

[0077] If there is no abnormality in the command data, the command data is interpreted by (the processor 201 executing) the second APP 212, and the door mirrors are folded down.

[0078] FIG. 6 is a diagram for explaining another example of the data flow in the ECU according to the first embodiment.

[0079] An inter-area communication unit 244B is implemented by the processor 201 executing the management SW 230B. The inter-area communication unit 244B is a function implemented by inter-partition communication of the management SW 230B.

[0080] It should be noted that while the management SW 230B is being executed by the processor 201, the management SW 230A is not executed by the processor 201. In other words, the management SW 230A is in a stopped state.

[0081] The inter-area communication unit 244B has the same function as the inter-area communication unit 244A. That is, the inter-area communication unit 244B can move data from the first logic area 251 to the third logic area 253 by the inter-partition communication function of the management SW 230B. The inter-area communication unit 244A can move data from the third logic area 253 to the first logic area 251 by the inter-partition communication function of the management SW 230B.

[0082] The inter-area communication unit 244B can move data from the third logic area 253 to the second logic area 252 by the inter-partition communication function of the management SW 230B. The inter-area communication unit 244B can move data from the second logic area 252 to the third logic area 253 by the inter-partition communication function of the management SW 230B.

[0083] When a user (driver) presses a switch to instruct folding of the door mirrors, (a frame including) command data for folding the door mirrors is transmitted from the external ECU 200 to the in-vehicle network 100.

[0084] The data communication unit 243 receives the command data and executes the first defense process. If an abnormality is detected in the command data, the command data is discarded and an abnormality process is executed.

[0085] If there is no abnormality in the command data, the inter-area communication unit 244 B receives the command data from the data communication unit 243 and passes the command data to the data transfer unit 245 .

[0086] The data transmission / reception unit 245 receives the command data and executes the second defense process. If an abnormality is detected in the command data, the command data is discarded and abnormality processing is executed.

[0087] If there is no abnormality in the command data, the command data is interpreted by (the processor 201 executing) the second APP 212, and the door mirrors are folded down.

[0088] 4, a description will be given of the updating section 240. The updating section 240 includes a first updating section 241 and a second updating section 242.

[0089] The processor 201 executes the first update SW 221 to realize the first update unit 241. The first update unit 241, like the above-mentioned data communication unit 243, cannot exchange data with the second logic area 252. The first update unit 241 can exchange data with the third logic area 253 only with the inter-area communication unit 244A.

[0090] The processor 201 executes the second update SW 222 to implement the second update unit 242. The second update unit 242, like the above-mentioned data communication unit 243, cannot exchange data with the first logic area 251. The second update unit 242 can exchange data with the third logic area 253 only with the inter-area communication unit 244A.

[0091] The first update unit 241 updates the first APP 211. The second update unit 242 updates the second APP 212.

[0092] FIG. 7 is a diagram for explaining an example of data flow when updating a first APP in an ECU according to the first embodiment, and FIG. 8 is a diagram for explaining updating a first APP in an ECU according to the first embodiment.

[0093] 7, when updating the first APP 211, update data (first update data) for updating the first APP 211 is transmitted from the server 400 to the external communication device 300. The external communication device 300 divides the update data into a plurality of frames, for example, and transmits each frame to the target ECU 200.

[0094] The data communication unit 243 receives each frame, i.e., update data, transmitted from the external communication device 300, and executes a first defense process. If an abnormality is detected in the frame, the frame is discarded and an abnormality process is executed.

[0095] If there is no abnormality in the frames, the data communication unit 243 combines the data included in each frame to restore the update data. The data communication unit 243 passes the update data to the first update unit 241. The first update unit 241 receives the update data from the data communication unit 243.

[0096] 8, the first update unit 241 uses the received update data to update the first APP 211. When the update is completed, the updated first APP 211 is restarted.

[0097] FIG. 9 is a diagram for explaining an example of a data flow when updating a second APP in an ECU according to the first embodiment, and FIG. 10 is a diagram for explaining an update of a second APP in an ECU according to the first embodiment.

[0098] 9, when updating the second APP 212, update data for updating the second APP 212 (second update data) is transmitted from the server 400 to the external communication device 300. The external communication device 300 divides the update data into a plurality of frames, for example, and transmits each frame to the target ECU 200.

[0099] The data communication unit 243 receives each frame, i.e., update data, transmitted from the external communication device 300, and executes a first defense process. If an abnormality is detected in the frame, the frame is discarded and an abnormality process is executed.

[0100] If there is no abnormality in the frames, the data communication unit 243 combines the data contained in each frame to restore the update data. The inter-area communication unit 244A receives the update data from the data communication unit 243 and passes the update data to the data transfer unit 245.

[0101] The data transmission / reception unit 245 receives the update data and executes the second defense process. If an abnormality is detected in the update data, the update data is discarded and abnormality processing is executed.

[0102] If there is no abnormality in the update data, the second update unit 242 receives the update data from the data transfer unit 245.

[0103] In this example, the update data is passed from the inter-area communication unit 244A to the second update unit 242 via the data transfer unit 245, but is not limited to this. For example, the update data may be passed directly from the inter-area communication unit 244A to the second update unit 242. In this case, the second update unit 242 may have a defense function.

[0104] 10, the second update unit 242 uses the received update data to update the second APP 212. When the update is completed, the updated second APP 212 is restarted.

[0105] [1-5. ECU operation] Hereinafter, a description will be given of the operation of the ECU according to the first embodiment. Fig. 11 is a sequence diagram showing a data flow in the in-vehicle network when the second APP is updated in the ECU according to the first embodiment.

[0106] When the update data for the second APP 212 is released, the server 400 stores the update data. The server 400 transmits the update data for the second APP 212 to the external communication device 300 in response to a request from, for example, the ECU 200 (step S11).

[0107] When the external communication device 300 receives the update data, it divides the data into, for example, a plurality of frames, and transmits each frame to the target ECU 200 (step S12).

[0108] The processor 201 receives a frame transmitted from the external communication device 300 by the function of the first APP 211. The processor 201 executes a first defense process (step S13).

[0109] If there is no abnormality in the frames, the processor 201 restores the update data from the data included in each frame. The processor 201 transfers the update data from the first APP 211 to the management SW 230A (or 230B) by the inter-partition communication function of the management SW 230A (or 230B) (step S14).

[0110] Furthermore, the processor 201 transfers the update data from the management SW 230A (or 230B) to the second APP 212 by the inter-partition communication function of the management SW 230A (or 230B) (step S15).

[0111] The processor 201 executes the second defense process by the function of the second APP 212 (step S16).

[0112] If there is no abnormality in the update data, the processor 201 transfers the update data from the second APP 212 to the second update SW 222 (step S17).

[0113] The processor 201 executes an update process of the second APP 212 using the update data by the function of the second update SW 222 (step S18), thereby updating the second APP 212 (step S19).

[0114] When the update of the second APP 212 is completed, the processor 201 restarts the second APP 212 (step S20).

[0115] FIG. 12 is a flowchart showing an example of the operation of the ECU when the ECU according to the first embodiment updates the second APP.

[0116] For example, the processor 201 determines whether or not new update data for the second APP 212 exists, i.e., whether or not the server 400 can provide new update data, by querying the server 400 or by receiving a notification from the server 400 (step S101).

[0117] If new update data does not exist (NO in step S101), the processor 201 executes step S101 again.

[0118] If new update data exists (YES in step S101), the processor 201 requests, for example, the server 400 to download the update data. The server 400 downloads the update data in response to, for example, the request. The exterior communication device 300 receives the update data, divides it into a plurality of frames, and transmits the divided data to the ECU 200.

[0119] The processor 201 receives update data (frame) by the function of the first APP 211 (step S102).

[0120] The processor 201 executes a first defense process when receiving a frame (step S103). The processor 201 determines whether or not an abnormality is detected by the first defense process (step S104). If an abnormality is detected (NO in step S104), the processor 201, for example, discards the received frame and executes abnormality processing. In this case, the processor 201 returns to step S101.

[0121] If no abnormality is detected by the first protection process (YES in step S104), the processor 201 performs inter-area communication of the update data by the inter-partition communication function of the management SW 230A (or 230B) (step S105). That is, the processor 201 transfers the update data from the first APP 211 stored in the first logic area 251 to the management SW 230A (or 230B) stored in the third logic area 253, and further transfers the update data from the management SW 230A (or 230B) to the second APP 212 stored in the second logic area 252.

[0122] When the second APP 212 receives update data, the processor 201 executes the second defense process (step S106). The processor 201 determines whether or not an abnormality is detected by the second defense process (step S107). If an abnormality is detected (NO in step S107), the processor 201, for example, discards the received frame and executes abnormality processing. In this case, the processor 201 returns to step S101.

[0123] If no abnormality is detected by the second protection process (YES in step S107), the processor 201 transfers the update data from the second APP 212 to the second update SW 222. Furthermore, the processor 201 updates the second APP 212 using the update data by the function of the second update SW 222 (step S108).

[0124] When the update is completed, the processor 201 restarts the second APP 212 (step S109).

[0125] [2. Second embodiment] FIG. 13 is a block diagram showing an example of the configuration of a nonvolatile memory mounted in an ECU according to the second embodiment.

[0126] In the second embodiment, the first APP 211A is stored in the first bank 202A, and the first APP 211B is stored in the second bank 202B.

[0127] The first APP211A and the first APP211B are, for example, different versions of the same software. For example, the first APP211A is the latest version of the software, and the first APP211B is an old version of the software. Only one of the first APP211A and 211B is executed at the same time. For example, the new version of the first APP211A is executed, and the old version of the first APP211B is stopped. When a new version of the first APP is released, the stopped first APP211B is updated. The first APP211A continues to operate even while the first APP211B is being updated. When the update of the first APP211B is completed, the operation target is switched from the first APP211A (old version of the software) to the first APP211B (latest version of the software). This makes it possible to shorten or eliminate the period during which the first APP is stopped due to the update.

[0128] Furthermore, a second APP 212A is stored in the first bank 202A, and a second APP 212B is stored in the second bank 202B.

[0129] Like the first APP 211A, 211B, the second APP 212A and the second APP 212B are, for example, different versions of the same software. Only one of the second APP 212A and 212B is executed at the same time. When a new version of the second APP is released, the stopped second APP 212B is updated. The second APP 212A continues to operate even while the second APP 212B is being updated. When the update of the second APP 212B is completed, the operating target is switched from the second APP 212A (old version software) to the second APP 212B (latest version software). This makes it possible to shorten or eliminate the period during which the second APP is stopped due to the update.

[0130] Other configurations of the ECU according to the second embodiment are the same as those of the ECU 200 according to the first embodiment, and therefore will not be described.

[0131] FIG. 14 is a diagram showing a configuration of partitions in a nonvolatile memory according to the second embodiment.

[0132] A data communication unit 243A is implemented by the processor 201 executing the first APP 211A. The first APP 211A is the same software as the first APP 211 described above, and the data communication unit 243A has the same function as the data communication unit 243 described above.

[0133] A data sending / receiving unit 245A is implemented by the processor 201 executing the second APP 212A. The second APP 212A is the same software as the second APP 212 described above, and the data sending / receiving unit 245A has the same function as the data sending / receiving unit 245 described above.

[0134] As indicated by the diagonal hatching in FIG. 14, the first APP 211B is in a stopped state, and the second APP 212B is in a stopped state.

[0135] FIG. 15 is a diagram showing the operating state of software when the execution target of the first APP and the second APP is switched.

[0136] For example, when the first APP 211B is updated to a new version, the execution target is switched from the first APP 211A to the first APP 211B. That is, the first APP 211A is stopped, and the first APP 211B is started. The processor 201 executes the first APP 211B, thereby realizing the data communication unit 243B.

[0137] For example, when the second APP 212B is updated to a new version, the execution target is switched from the second APP 212A to the second APP 212B. That is, the second APP 212A is stopped, and the second APP 212B is started. The processor 201 executes the second APP 212B, thereby realizing the data transfer unit 245B.

[0138] [3. Third embodiment] FIG. 16 is a block diagram showing an example of the configuration of a nonvolatile memory mounted on an ECU according to the third embodiment.

[0139] In the third embodiment, the first update SW 221 is not stored in the first logic area 251, and instead of the second update SW 222, the update SW 223 is stored in the second logic area 252. Note that other configurations of the ECU according to the third embodiment are the same as the configurations of the ECU 200 according to the second embodiment, so the same components are denoted by the same reference numerals and description thereof will be omitted.

[0140] The update SW 223 is software for updating each of the first APPs 211A and 211B and the second APPs 212A and 212B.

[0141] A more specific description will be given below. The processor 201 executes the update SW 223 to implement an update unit 246. The update unit 246 can update each of the first APPs 211A and 211B and the second APPs 212A and 212B.

[0142] When updating the second APP 212B, update data for updating the second APP 212B (second update data) is transmitted from the server 400 to the external communication device 300. The external communication device 300 divides the update data into a plurality of frames, for example, and transmits each frame to the target ECU 200.

[0143] The data communication unit 243A receives each frame, i.e., update data, transmitted from the external communication device 300, and executes a first defense process. If an abnormality is detected in the frame, the frame is discarded and an abnormality process is executed.

[0144] If there is no abnormality in the frames, the data communication unit 243A combines the data contained in each frame to restore the update data. The inter-area communication unit 244A receives the update data from the data communication unit 243A, and passes the update data to the data transfer unit 245A.

[0145] The data transmission / reception unit 245A receives the update data and executes the second protection process. If an abnormality is detected in the update data, the update data is discarded and abnormality processing is executed.

[0146] If there is no abnormality in the update data, the update unit 246 receives the update data from the data transfer unit 245A.

[0147] In this example, the update data is passed from the inter-area communication unit 244A to the update unit 246 via the data transfer unit 245, but this is not limiting. For example, the update data may be passed directly from the inter-area communication unit 244A to the update unit 246. In this case, the update unit 246 may have a defense function.

[0148] The update unit 246 updates the second APP 212B using the received update data. When the update is completed, the second APP 212A is stopped, and the updated second APP 212B is started.

[0149] When updating the first APP 211B, update data for updating the first APP 211B (first update data) is transmitted from the server 400 to the external communication device 300. The external communication device 300 divides the update data into a plurality of frames, for example, and transmits each frame to the target ECU 200.

[0150] The data communication unit 243A receives each frame, i.e., update data, transmitted from the external communication device 300, and executes a first defense process. If an abnormality is detected in the frame, the frame is discarded and an abnormality process is executed.

[0151] If there is no abnormality in the frames, the data communication unit 243A combines the data contained in each frame to restore the update data. The inter-area communication unit 244A receives the update data from the data communication unit 243A, and passes the update data to the data transfer unit 245A.

[0152] The data transmission / reception unit 245A receives the update data and executes the second protection process. If an abnormality is detected in the update data, the update data is discarded and abnormality processing is executed.

[0153] If there is no abnormality in the update data, the update unit 246 receives the update data from the data transfer unit 245A.

[0154] The update unit 246 updates the first APP 211B using the received update data.

[0155] Here, data communication between the first logic area 251 and the second logic area 252 is restricted. Therefore, for example, the update unit 246 can divide the new first APP 211B into a plurality of data and send each data to the first logic area 251 via the inter-area communication unit 244A. In the first logic area 251, the new first APP 211B can be created by combining the sent data. As a result, the first APP 211B is updated.

[0156] When the update is completed, the first APP 211A is stopped, and the updated first APP 211B is started.

[0157] [4. Additional Notes] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is defined by the claims rather than the above-described embodiments, and includes the meaning equivalent to the claims and all modifications within the scope thereof. [Explanation of symbols]

[0158] 100 In-vehicle Network 200, 200A, 200B, 200C, ... ECU 201 Processor 202 Non-volatile memory 202A 1st Bank 202B 2nd Bank 203 Volatile Memory 204 Communication Interface (Communication I / F) 205 Bus 211, 211A, 211B First application software (first APP) 212, 212A, 212B Second application software (second APP) 221 1st update software (1st update SW) 222 Second Update Software (Second Update SW) 223 Update software (update SW) 230A Management Software (Management SW, 1st Management Software) 230B Management software (management SW, second management software) 240 Update Department 241 1st update part 242 2nd update part 243, 243A, 243B Data Communication Department 244A,244B Inter-area communication department 245, 245A, 245B Data exchange section 246 Update Department 251 First logical domain 252 Second logical domain 253 Third Logic Area 300 External communication device 400 Servers 500 Communication Bus

Claims

1. An in-vehicle device connected to an in-vehicle network, a storage unit including a first logic area and a second logic area which are logically separated from each other and in which data transmission and reception is restricted; First software stored in the first logic area and capable of transmitting and receiving data to and from the in-vehicle network; Second software stored in the second logic area and restricted in transmitting and receiving data to and from the in-vehicle network; an update unit that updates the second software; an inter-area communication unit capable of transmitting and receiving data to and from the first logic area and capable of transmitting and receiving data to and from the second logic area; Equipped with The inter-area communication unit receives, from the data communication unit, update data that a data communication unit implemented by a processor executing the first software has received from the in-vehicle network, and transfers the received update data to the update unit. The update unit updates the second software based on the update data delivered from the inter-area communication unit. In-vehicle device.

2. the update unit is realized by the processor executing update software stored in the second logic area, The in-vehicle device according to claim 1 .

3. The update unit is capable of updating the first software. The vehicle-mounted device according to claim 2 .

4. the update unit includes a first update unit that updates the first software and a second update unit that updates the second software; the first update unit is realized by the processor executing first update software stored in the first logic area, the second update unit is realized by the processor executing second update software stored in the second logic area; The in-vehicle device according to claim 1 .

5. The first update unit receives, from the data communication unit, the first update data received by the data communication unit from the in-vehicle network, and updates the first software based on the received first update data. The vehicle-mounted device according to claim 4.

6. the storage unit includes a first storage unit and a second storage unit that are physically separated from each other; the inter-area communication unit includes a first inter-area communication unit that is realized by the processor executing first management software stored in the first storage unit, and a second inter-area communication unit that is realized by the processor executing second management software stored in the second storage unit, the first inter-area communication unit operates while the second inter-area communication unit is stopped; The second inter-area communication unit operates while the first inter-area communication unit is stopped. The in-vehicle device according to claim 1 .

7. the first inter-area communication unit operates while the second management software is being updated; the second inter-area communication unit operates while the first management software is being updated; The vehicle-mounted device according to claim 6.

8. the storage unit includes a third logic area that is logically separated from each of the first logic area and the second logic area and in which data transmission to and from each of the first logic area and the second logic area is restricted; the first management software and the second management software are stored in the third logic area; The vehicle-mounted device according to claim 6.

9. the first logical area includes a first partial area of ​​the first storage unit and a first partial area of ​​the second storage unit; the second logical area includes a second partial area of ​​the first storage unit and a second partial area of ​​the second storage unit; two pieces of the first software are stored in each of the first partial area of ​​the first storage unit and the first partial area of ​​the second storage unit; While the first software stored in the first partial area of ​​the first storage unit is being executed, the first software stored in the first partial area of ​​the second storage unit is stopped, While the first software stored in the first partial area of ​​the second storage unit is being executed, the first software stored in the first partial area of ​​the first storage unit is stopped. The vehicle-mounted device according to claim 6.

10. while the first software stored in the first partial area of ​​the first storage unit is being updated, the first software stored in the first partial area of ​​the second storage unit is being executed; While the first software stored in the first partial area of ​​the second storage unit is being updated, the first software stored in the first partial area of ​​the first storage unit is executed. The in-vehicle device according to claim 9.

11. two pieces of the second software are stored in each of the second partial area of ​​the first storage unit and the second partial area of ​​the second storage unit; While the second software stored in the second partial area of ​​the first storage unit is being executed, the second software stored in the second partial area of ​​the second storage unit is stopped, While the second software stored in the second partial area of ​​the second storage unit is being executed, the second software stored in the second partial area of ​​the first storage unit is stopped. The in-vehicle device according to claim 9.

12. while the second software stored in the second partial area of ​​the first storage unit is being updated, the second software stored in the second partial area of ​​the second storage unit is being executed; While the second software stored in the second partial area of ​​the second storage unit is being updated, the second software stored in the second partial area of ​​the first storage unit is executed. The in-vehicle device according to claim 11.

13. the data communication unit has a first defense function for defending against an external attack, the data transmission / reception unit realized by the processor executing the second software has a second defense function for defending against external attacks; The in-vehicle device according to any one of claims 1 to 12.

14. 1. An update method for updating software in an in-vehicle device connected to an in-vehicle network, comprising: a step of receiving, by an inter-area communication unit capable of transmitting and receiving data to and from the first logic area, update data received from the in-vehicle network by a data communication unit realized by a processor executing first software stored in a first logic area provided in a storage unit and capable of transmitting and receiving data to and from the in-vehicle network; a step of the inter-area communication unit transferring the update data to an update unit that updates second software, the second software being stored in a second logic area that is provided in a storage unit and logically separated from the first logic area, and in which transmission and reception of data to and from the in-vehicle network is restricted; updating the second software based on the update data delivered from the inter-area communication unit by the update unit; Including, How to update.

15. An update program for updating software in an in-vehicle device connected to an in-vehicle network, comprising: A computer including a storage unit including a first logic area and a second logic area which are logically separated from each other and in which data transmission and reception is restricted, receiving update data received from the in-vehicle network by a data communication unit that is realized by a processor executing first software that is stored in the first logic area and that is capable of transmitting and receiving data to and from the in-vehicle network, via an inter-area communication unit that is capable of transmitting and receiving data to and from the first logic area; updating second software, which is stored in the second logic area and has a restriction on data transmission / reception to / from the in-vehicle network, based on the update data received from the inter-area communication unit; To execute Updates.