Update system

The system maintains software version consistency among slave ECUs by storing and periodically updating a consistency table, addressing the issue of initialization-induced inconsistencies in existing update systems.

JP2025078313AActive Publication Date: 2025-05-20TOYOTA JIDOSHA KK
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023190784
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-08
Publication Date
2025-05-20
Estimated Expiration
2043-11-08

AI Technical Summary

Technical Problem

In existing update systems, the initialization of data in the master ECU's consistency table can lead to inconsistent software versions among slave ECUs, making it difficult to determine their correspondence accurately.

Method used

A system where the master ECU stores a consistency table and updates it during software installation, and periodically checks against a server's matching table to ensure consistency, restoring the table if initialization occurs.

Benefits of technology

Ensures accurate determination of software version consistency among slave ECUs by maintaining a reliable consistency table, even after data initialization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025078313000001_ABST
    Figure 2025078313000001_ABST
Patent Text Reader

Abstract

To properly execute a determination regarding the consistency of associations between software versions.SOLUTION: An update system includes a server, a master ECU mounted on a vehicle, and a plurality of slave ECUs. When software on a slave ECU is updated, the master ECU stores a consistency table corresponding to the software, as a first consistency table in the master ECU, and stores a second consistency table on the server (S21). When the second consistency table acquired from the server does not match the first consistency table in the master ECU, the master ECU stores the second consistency table as a first consistency table (S44). When a combination of version numbers of software stored in the slave ECU does not match a combination of version numbers specified in the first consistency table, the master ECU determines that the association does not maintain consistency.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an update system. [Background technology]

[0002] The update system includes a server and a vehicle. The vehicle includes a master ECU and a plurality of slave ECUs. The master ECU executes software updates for the plurality of slave ECUs. Specifically, the master ECU downloads new software from the server. Then, the master ECU installs the new software in the slave ECUs. Then, the master ECU instructs the slave ECUs to activate the new software. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2023-053358 A Summary of the Invention [Problem to be solved by the invention]

[0004] In an update system such as that of Patent Document 1, for example, the data of some ECUs may be initialized, causing the software of the ECU to be downgraded. As a result, the correspondence between the software versions of the multiple slave ECUs may become inconsistent. In this regard, in an update system such as that of Patent Document 1, it is possible to determine whether the correspondence between the software versions of the multiple slave ECUs is consistent by, for example, referring to a consistency table stored in the master ECU. However, if the data of the consistency table stored in the master ECU is initialized, there is a risk that it will not be possible to properly determine whether the correspondence between the software versions of the multiple slave ECUs is consistent. [Means for solving the problem]

[0005] An update system for solving the above problem includes a server, a master ECU mounted on a vehicle and capable of communicating with the server, and a plurality of slave ECUs mounted on the vehicle and whose software is updated by the master ECU, each of the plurality of slave ECUs storing software for the slave ECU and a version number indicating a version of the software, and when data specifying combinations of version numbers that are allowable for combinations of the version numbers corresponding to the software of the plurality of slave ECUs is a consistency table, when the master ECU updates the software of the slave ECU, the master ECU stores the consistency table corresponding to the software as a first consistency table in the master ECU, and when the software of the slave ECU is updated, the server storing the matching table corresponding to the version number of the slave ECU in the master ECU as a second matching table; acquiring the second matching table from the server at a predetermined timing; and, if the acquired second matching table and the first matching table stored in the master ECU do not match, storing the acquired second matching table in the master ECU as the first matching table; acquiring the version numbers corresponding to the current software stored in the slave ECU from the multiple slave ECUs; and, if the combination of the acquired version numbers and the combination of the version numbers specified in the first matching table do not match, determining that the correspondence between the software versions for the multiple slave ECUs is not consistent. Effect of the Invention

[0006] According to the above configuration, even if the data of the first matching table stored in the master ECU is initialized, the first matching table does not match the second matching table acquired from the server, and the second matching table is stored as the first matching table. This restores the data of the first matching table in the master ECU. As a result, even if the data of the first matching table stored in the master ECU is initialized, it is possible to appropriately determine whether the correspondence between the software versions of the multiple slave ECUs is consistent by referring to the first matching table. [Brief description of the drawings]

[0007] [Figure 1] FIG. 1 is a schematic diagram of an update system. [Diagram 2] FIG. 2 is a sequence diagram showing the registration control and the table check control. [Diagram 3] FIG. 3 is a sequence diagram showing the consistency check control. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0008] <Outline of update system configuration> An embodiment of the present invention will now be described with reference to Figures 1 to 3. First, a schematic configuration of an update system US will be described.

[0009] As shown in Fig. 1, the update system US includes a plurality of vehicles 100. The vehicles 100 are, for example, automobiles owned by users. Note that Fig. 1 illustrates only one representative vehicle 100. In this embodiment, the vehicle 100 is a vehicle equipped with an engine and a motor generator as a driving source, that is, a so-called hybrid vehicle.

[0010] The vehicle 100 includes a master ECU 10, a plurality of slave ECUs 20, a DCM 50, a first external bus 61, a second external bus 62, and a display 71. The first external bus 61 connects the master ECU 10 and the DCM 50 so that they can communicate with each other. The second external bus 62 connects the master ECU 10 and the plurality of slave ECUs 20 so that they can communicate with each other. The display 71 can display various information. In this embodiment, the display 71 is located near the driver's seat of the vehicle 100. Note that "ECU" is an abbreviation for Electronic Control Unit. Also, "DCM" is an abbreviation for Data Communication Module.

[0011] The master ECU 10 manages software updates in the slave ECU 20. The master ECU 10 includes an execution device 11 and a storage device 12. An example of the execution device 11 is a CPU. The storage device 12 includes a ROM that can only be read, a volatile RAM that can be read and written, and a non-volatile storage that can be read and written. The storage device 12 stores various programs and various data in advance. Specifically, the storage device 12 stores a matching table TM and a vehicle identification number VIN in advance as various data. The vehicle identification number VIN is a number for identifying the vehicle 100. Therefore, the vehicle identification number VIN stored in the storage device 12 of the master ECU 10 is a number that is predetermined for the vehicle 100 equipped with the master ECU 10. The matching table TM will be described in detail later. The execution device 11 executes the programs stored in the storage device 12 to realize various processes described later. The master ECU 10 can wirelessly communicate with devices outside the vehicle 100 via the DCM 50 and the communication network NW.

[0012] The slave ECU 20 is managed for software updates by the master ECU 10. The slave ECU 20 includes an execution device 21 and a storage device 22. An example of the execution device 21 is a CPU. The storage device 22 includes a ROM, a RAM, and a storage. The storage device 22 stores various programs and various data in advance. Specifically, the storage device 22 stores a version number NV in advance as various data. The version number NV will be described in detail later. The execution device 21 executes the programs stored in the storage device 22 to realize various processes described later. In this embodiment, the vehicle 100 includes four slave ECUs 20. An example of the four slave ECUs 20 is a hybrid ECU, an engine ECU, a motor ECU, and a battery ECU.

[0013] As shown in FIG. 1, the update system US includes a server 200. The server 200 includes an execution device 210, a storage device 220, and a communication device 230. The communication device 230 is capable of communicating with devices external to the server 200 via a communication network NW. An example of the execution device 210 is a CPU. The storage device 220 includes a ROM, a RAM, and storage. The storage device 220 stores various programs and various data in advance. The execution device 210 executes the programs stored in the storage device 220 to realize various processes described below.

[0014] <Update control> Next, a description will be given of the update control executed by the master ECU 10 of the vehicle 100. The update control is control related to software updates in the slave ECU 20 of the vehicle 100. In this embodiment, the master ECU 10 starts the update control when, for example, both of the following conditions (1) and (2) are satisfied.

[0015] Condition (1): The update device and the master ECU 10 are connected via a cable. Condition (2): An operation for requesting software update in the slave ECU 20 has been executed in the update device.

[0016] Here, the update device is a device for updating software in the slave ECU 20. For example, the update device is installed in a factory that performs maintenance on the vehicle 100. An example of the update device is a personal computer.

[0017] When the master ECU 10 starts the update control, first, the execution unit 11 of the master ECU 10 acquires the new software, the version number NV corresponding to the software, and the consistency table TM corresponding to the software from the update unit. Next, the execution unit 11 of the master ECU 10 installs the new software and the version number NV in the storage device 22 of the slave ECU 20 to be updated. Then, the execution unit 11 of the master ECU 10 instructs the slave ECU 20 to be updated to activate the new software. In addition, the execution unit 11 of the master ECU 10 stores the acquired consistency table TM in the storage device 12 as a first consistency table TM1. In other words, when the master ECU 10 updates the software of the slave ECU 20, it stores the acquired consistency table TM in the storage device 12 as the first consistency table TM1. As a result, the software and the version number NV in the slave ECU 20 to be updated are updated every time the update control is executed. Moreover, every time the update control is executed, the first consistency table TM1 in the master ECU 10 is updated.

[0018] Here, the version number NV is a numerical value indicating the version of the software corresponding to the version number NV. Furthermore, the version number NV is a numerical value that increases every time the software corresponding to the version number NV is updated. Moreover, the consistency table TM specifies combinations of the version numbers NV for a plurality of slave ECUs 20 that indicate the correspondence between the software versions when the software is normally stored in the plurality of slave ECUs 20. In other words, the consistency table TM specifies combinations of the version numbers NV that are allowed for combinations of the version numbers NV of a plurality of slave ECUs 20.

[0019] <Registration Control> Next, the registration control executed by the master ECU 10 of the vehicle 100 and the server 200 will be described with reference to Fig. 2. The registration control is a control for registering the consistency table TM acquired in the update control in the server 200. In this embodiment, the master ECU 10 starts the registration control every time the update control is completed. In other words, the master ECU 10 starts the registration control when the software of the slave ECU 20 is updated.

[0020] 2, when the execution unit 11 of the master ECU 10 starts the registration control, it executes the process of step S11. In step S11, the execution unit 11 of the master ECU 10 transmits the consistency table TM acquired in the update control and the vehicle identification number VIN stored in the storage device 12 to the server 200. Then, when the server 200 acquires the consistency table TM and the vehicle identification number VIN, the execution unit 210 of the server 200 advances the process to step S21.

[0021] In step S21, the execution unit 210 of the server 200 registers the matching table TM acquired in step S11. Specifically, the execution unit 210 stores the matching table TM acquired in step S11 in the storage device 220 as the second matching table TM2. At this time, the execution unit 210 stores the second matching table TM2 in the storage device 220 in association with the vehicle identification number VIN acquired in step S11. Therefore, in the registration control, the master ECU 10 transmits the matching table TM to the server 200, thereby storing it as the second matching table TM2 in the server 200. After step S21, the execution unit 210 ends the current registration control.

[0022] Next, the table check control executed by the master ECU 10 of the vehicle 100 and the server 200 will be described with reference to Fig. 2. The table check control is a control for checking the first consistency table TM1 stored in the storage device 12 of the master ECU 10. In this embodiment, the master ECU 10 starts the table check control at predetermined regular intervals. An example of the regular interval is one month. The regular interval corresponds to a predetermined timing.

[0023] 2, when the execution unit 11 of the master ECU 10 starts the table check control, it executes the process of step S41. In step S41, the execution unit 11 of the master ECU 10 transmits a request signal for requesting the second consistency table TM2 and the vehicle identification number VIN stored in the storage device 12 to the server 200. Then, when the server 200 receives the request signal and the vehicle identification number VIN, the execution unit 210 of the server 200 advances the process to step S42.

[0024] In step S42, the execution unit 210 of the server 200 transmits the second matching table TM2 stored in the storage device 220 to the master ECU 10. Specifically, the execution unit 210 of the server 200 transmits the second matching table TM2 linked to the vehicle identification number VIN acquired in step S41 to the master ECU 10. Then, when the master ECU 10 acquires the second matching table TM2, the execution unit 11 of the master ECU 10 advances the process to step S43.

[0025] In step S43, the execution unit 11 of the master ECU 10 determines whether the second matching table TM2 acquired in step S42 matches the first matching table TM1 stored in the storage device 12. If the execution unit 11 determines in step S43 that the second matching table TM2 acquired in step S42 matches the first matching table TM1 stored in the storage device 12, the execution unit 11 ends the current table check control. On the other hand, if the execution unit 11 determines in step S43 that the second matching table TM2 acquired in step S42 does not match the first matching table TM1 stored in the storage device 12, the execution unit 11 advances the process to step S44.

[0026] In step S44, the execution unit 11 of the master ECU 10 updates the first matching table TM1. Specifically, the execution unit 11 stores the second matching table TM2 acquired in step S42 in the storage device 12 as the first matching table TM1. That is, the first matching table TM1 is updated. After step S44, the execution unit 11 ends the current table check control.

[0027] <Validation control> Next, the consistency check control executed by the master ECU 10 and the multiple slave ECUs 20 will be described with reference to Fig. 3. The consistency check control is a control for determining whether or not the correspondence relationship between the software versions of the multiple slave ECUs 20 is consistent. In this embodiment, the slave ECU 20 starts the consistency check control when a request is made to start the system of the vehicle 100. An example of a case where a request is made to start the system of the vehicle 100 is when the main switch of the vehicle 100 is turned ON.

[0028] 3, when the execution unit 21 of the slave ECU 20 starts the consistency check control, it executes the process of step S61. In step S61, the execution unit 21 of the slave ECU 20 transmits the version number NV corresponding to the current software stored in the storage device 22 to the master ECU 10. Each of the execution units 21 of the four slave ECUs 20 transmits the version number NV to the master ECU 10. Then, when the master ECU 10 acquires a total of four version numbers NV, the execution unit 11 of the master ECU 10 advances the process to step S71.

[0029] In step S71, the execution unit 11 of the master ECU 10 determines whether the combination of version numbers NV acquired in step S61 matches the combination of multiple version numbers NV defined in the first matching table TM1. If the execution unit 11 determines in step S71 that the combination of version numbers NV acquired in step S61 matches the combination of multiple version numbers NV defined in the first matching table TM1, the execution unit 11 determines that the correspondence relationships between the software versions of the multiple slave ECUs 20 are consistent (S71: YES). Then, the execution unit 11 proceeds to step S81.

[0030] In step S81, the execution unit 11 of the master ECU 10 starts the system of the vehicle 100. Specifically, the execution unit 11 allows the execution of various controls related to the running of the vehicle 100 by the multiple slave ECUs 20. After step S81, the execution unit 11 of the master ECU 10 ends the current consistency check control.

[0031] On the other hand, if the execution unit 11 determines in step S71 that the combination of version numbers NV acquired in step S61 does not match the combination of multiple version numbers NV defined in the first matching table TM1, the execution unit 11 determines that the correspondence relationships between the software versions of the multiple slave ECUs 20 are not consistent (S71: NO), and the execution unit 11 proceeds to step S91.

[0032] In step S91, the execution device 11 of the master ECU 10 notifies the user of the vehicle 100 that the correspondence between the software versions of the multiple slave ECUs 20 is not consistent. Specifically, the execution device 11 outputs a control signal to the display 71 to display on the display 71 that the correspondence between the software versions of the multiple slave ECUs 20 is not consistent. In addition, the execution device 11 outputs a control signal to the display 71 to display on the display 71 the slave ECU 20 whose software is assumed to have been downgraded. Here, the slave ECU 20 whose software is assumed to have been downgraded is the slave ECU 20 whose version number NV was different in step S71. Furthermore, in step S91, the execution device 11 prohibits the execution of various controls related to the running of the vehicle 100 by the multiple slave ECUs 20. After step S91, the execution device 11 ends the current consistency check control.

[0033] <Action of this embodiment> In the update control, the master ECU 10 stores the acquired consistency table TM in the storage device 12 as the first consistency table TM1. Then, as shown in Fig. 2, in steps S11 and S21 of the registration control, the master ECU 10 transmits the consistency table TM acquired in the update control to the server 200, thereby storing it in the server 200 as the second consistency table TM2. Then, when it is time to execute the table check control, the master ECU 10 starts the table check control. In steps S41 and S42 of the table check control, the master ECU 10 acquires the second consistency table TM2 from the server 200. Furthermore, in steps S43 and S44, when the acquired second consistency table TM2 and the first consistency table TM1 stored in the storage device 12 do not match, the master ECU 10 stores the acquired second consistency table TM2 in the storage device 12 as the first consistency table TM1. 3, in step S61 of the consistency check control, the master ECU 10 acquires a total of four version numbers NV from the four slave ECUs 20. In step S71, the execution unit 11 of the master ECU 10 determines whether the combination of version numbers NV acquired in step S61 matches the combination of multiple version numbers NV defined in the first consistency table TM1. Here, the master ECU 10 determines that the correspondence relationship of the software versions for the multiple slave ECUs 20 is consistent when the combination of version numbers NV acquired matches the combination of multiple version numbers NV defined in the first consistency table TM1. On the other hand, the master ECU 10 determines that the correspondence relationship of the software versions for the multiple slave ECUs 20 is not consistent when the combination of version numbers NV acquired does not match the combination of multiple version numbers NV defined in the first consistency table TM1.

[0034] <Effects of this embodiment> (1) According to this embodiment, even if the first consistency table TM1 stored in the storage device 12 of the master ECU 10 is initialized after the registration control, the table check control is executed to restore the data of the first consistency table TM1 in the storage device 12. This allows the master ECU 10 to refer to the correct first consistency table TM1 in the consistency check control. As a result, the master ECU 10 can appropriately determine whether the correspondence between the software versions of the multiple slave ECUs 20 is consistent.

[0035] <Example of change> This embodiment can be modified as follows: This embodiment and the following modifications can be combined with each other to the extent that there is no technical contradiction.

[0036] In the above embodiment, the update control may be changed. For example, in update control, the execution unit 11 of the master ECU 10 may download new software, a version number NV corresponding to the software, and a consistency table TM corresponding to the software from the server 200.

[0037] In the above embodiment, the table check control may be changed. For example, the execution timing of the table check control may be changed. As a specific example, the specified cycle may be a period shorter than one month or a period longer than one month. As a specific example, the execution unit 11 of the master ECU 10 may execute the table check control when a request is made to start up the system of the vehicle 100. In this case, the execution unit 11 may execute the consistency check control after executing the table check control.

[0038] In the above embodiment, the consistency check control may be changed. For example, the processes of steps S81 to S91 may be omitted. As a specific example, from the viewpoint of only determining whether the correspondence relationship between the software versions of the multiple slave ECUs 20 is consistent, the processes of steps S81 to S91 may be omitted. [Explanation of symbols]

[0039] NW...communication network US...update system 10...master ECU 11...execution device 12...storage device 20...slave ECU 21...execution device 22...storage device 50...DCM 71...display 100...vehicle 200...server 210...execution device 220...storage device 230...communication device

Claims

[Claim 1] a server; a master ECU that is mounted on a vehicle and capable of communicating with the server; and a plurality of slave ECUs that are mounted on the vehicle and whose software is updated by the master ECU, Each of the plurality of slave ECUs stores software of the slave ECU and a version number indicating a version of the software, When data defining a combination of version numbers that is permitted for the combination of version numbers corresponding to software of a plurality of the slave ECUs is a consistency table, The master ECU is When updating software of the slave ECU, storing the consistency table corresponding to the software as a first consistency table in the master ECU; When updating software of the slave ECU, transmitting the consistency table corresponding to the software to the server and storing the consistency table in the server as a second consistency table; acquiring the second matching table from the server at a predetermined timing; storing the acquired second consistency table as the first consistency table in the master ECU when the acquired second consistency table and the first consistency table stored in the master ECU do not match; obtaining from a plurality of the slave ECUs the version numbers corresponding to the current software stored in the slave ECUs; determining that the correspondence relationship between the software versions of the slave ECUs is not consistent when the acquired combination of the version numbers does not match the combination of the version numbers defined in the first consistency table; is feasible Update system.

Citation Information

Patent Citations

  • Firmware update system

    JP2013250923A

  • Electronic control unit system, and software consistency check system in electronic control unit system

    JP2019159399A

  • On-vehicle system and ecu

    JP2020123253A

  • Vehicle and software update method

    JP2021105924A

  • Vehicle management system, center device, data management method, and data management program

    JP2023053358A