On-vehicle network management system and on-vehicle network management method
The in-vehicle network management system effectively configures message relay processing by integrating update, configuration, and relay management units to handle changes in hardware configurations and software updates, ensuring optimal network operation.
Patent Information
- Application Number
- JP2023192674
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-23
AI Technical Summary
Existing in-vehicle network management systems struggle to appropriately configure message relay processing, especially when hardware configurations change or software updates occur.
The system includes an update management unit, a configuration management unit, and a relay management unit that work together to update target software, monitor hardware configurations, and set up message relay processing. When hardware configurations change, the units exchange necessary information to ensure relay processing is set based on the latest configurations.
This approach allows for appropriate configuration of message relay processing in in-vehicle networks, ensuring seamless operation even with changes in hardware configurations or software updates.
Smart Images

Figure 2025079848000001_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an in-vehicle network management system and an in-vehicle network management method. [Background technology]
[0002] In recent years, with the spread of car sharing and the demand for improved processing power of in-vehicle devices installed in vehicles, there is a demand for customizing in-vehicle networks by adding applications to the in-vehicle network. Thus, there is a demand for technology that enables users to add or remove various applications to or from the in-vehicle network according to their needs.
[0003] For example, Patent Document 1 (International Publication No. 2020 / 179123) discloses the following management device. That is, the management device includes a detection unit that detects the addition of a functional unit to a network including one or more in-vehicle functional units, an acquisition unit that acquires functional unit information including a new functional unit that is the functional unit whose addition is detected by the detection unit and information regarding the network configuration of a layer lower than the application layer of the in-vehicle functional unit, and a generation unit that generates configuration information of a new network that is the network further including the new functional unit based on each of the functional unit information acquired by the acquisition unit. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] International Publication No. 2020 / 179123 [Non-patent literature]
[0005] [Non-Patent Document 1] “ST-OTA-4 OTA Software Update Vehicle System Requirements Specification Ver.1.2”, JasPar OTA Technology Working Group, January 13, 2023 Summary of the Invention [Problem to be solved by the invention]
[0006] There is a need for a technology that goes beyond the technology described in Patent Document 1 and Non-Patent Document 1 and that is capable of appropriately setting the relay processing of messages in an in-vehicle network.
[0007] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide an in-vehicle network management system and an in-vehicle network management method that are capable of appropriately configuring message relay processing in an in-vehicle network. [Means for solving the problem]
[0008] The in-vehicle network management system of the present disclosure includes an update management unit that updates target software, which is software that is subject to update processing in an in-vehicle network, a configuration management unit that monitors the hardware configuration in the in-vehicle network, and a relay management unit that sets up message relay processing in the in-vehicle network, and when the hardware configuration changes, the configuration management unit transmits connection configuration information indicating the hardware configuration after the change to the update management unit and the relay management unit, and when the hardware configuration changes, the update management unit transmits to the relay management unit the vehicle configuration information in the in-vehicle network after the hardware configuration change, which indicates the correspondence between the target software, the in-vehicle device in which the target software is installed, and the version of the target software, and when the update management unit updates the target software, it transmits the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit.
[0009] One aspect of the present disclosure may be realized not only as a management device having such a characteristic processing unit, but also as a management method having such characteristic processing steps, or as a program for causing a computer to execute such steps. Furthermore, one aspect of the present disclosure may be realized as a semiconductor integrated circuit that realizes part or all of the management device. Effect of the Invention
[0010] According to the present disclosure, it is possible to appropriately configure the relay processing of messages in an in-vehicle network. [Brief description of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating an example of a configuration of an in-vehicle network management system according to an embodiment of the present disclosure. [Diagram 2] FIG. 2 is a diagram illustrating a configuration of a relay device according to an embodiment of the present disclosure. [Diagram 3] FIG. 3 is a diagram illustrating an example of an update list stored in a storage unit in the relay device according to the embodiment of the present disclosure. [Figure 4] FIG. 4 is a diagram illustrating an example of an inhibition list stored in a storage unit in the relay device according to the embodiment of the present disclosure. [Diagram 5] FIG. 5 is a diagram illustrating an example of a topology correspondence table created by a configuration management unit in the relay device according to the embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in the relay device according to the embodiment of the present disclosure. [Figure 7] FIG. 7 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram illustrating an example of a topology correspondence table after being updated by the configuration management unit in the relay device according to the embodiment of the present disclosure. [Figure 9]FIG. 9 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in the relay device according to the embodiment of the present disclosure. [Figure 10] FIG. 10 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. [Figure 11] FIG. 11 is a diagram illustrating an example of an update list after an update by an update management unit in the relay device according to the embodiment of the present disclosure. [Figure 12] FIG. 12 is a diagram illustrating an example of the inhibition list after being updated by the update management unit in the relay device according to the embodiment of the present disclosure. [Figure 13] FIG. 13 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in the relay device according to the embodiment of the present disclosure. [Figure 14] FIG. 14 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in the relay device according to the embodiment of the present disclosure. [Figure 15] FIG. 15 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. [Figure 16] FIG. 16 is a diagram illustrating an example of a topology correspondence table after being updated by the configuration management unit in the relay device according to the embodiment of the present disclosure. [Figure 17] FIG. 17 is a diagram illustrating an example of the inhibition list after being updated by the update management unit in the relay device according to the embodiment of the present disclosure. [Figure 18] FIG. 18 is a diagram illustrating an example of a sequence for changing settings of a relay process in the in-vehicle network management system according to an embodiment of the present disclosure. [Figure 19] FIG. 19 is a diagram illustrating an example of a sequence for changing settings of a relay process in the in-vehicle network management system according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] First, the contents of the embodiments of the present disclosure will be listed and described.
[0013] (1) An in-vehicle network management system according to an embodiment of the present disclosure includes an update management unit that updates target software, which is software that is subject to update processing in an in-vehicle network, a configuration management unit that monitors a hardware configuration in the in-vehicle network, and a relay management unit that sets up relay processing of messages in the in-vehicle network, wherein, when the hardware configuration changes, the configuration management unit transmits connection configuration information indicating the hardware configuration after the change to the update management unit and the relay management unit, and, when the hardware configuration changes, the update management unit transmits to the relay management unit vehicle configuration information in the in-vehicle network after the hardware configuration change, the vehicle configuration information indicating a correspondence between the target software, an in-vehicle device in which the target software is installed, and a version of the target software, and, when an update of the target software is performed, the update management unit transmits to the relay management unit the vehicle configuration information in the in-vehicle network including the updated target software.
[0014] With this configuration, in an in-vehicle network where the hardware configuration changes or the software is updated, connection configuration information in the in-vehicle network after the hardware configuration has changed and vehicle configuration information in the in-vehicle network including the updated software can be provided to the relay management unit, so that the relay processing of messages in the in-vehicle network can be set based on the latest hardware configuration and the latest software configuration. Therefore, the relay processing of messages in the in-vehicle network can be set appropriately.
[0015] (2) In the above (1), the update management unit may create the vehicle configuration information based on an update list indicating the in-vehicle device in which the target software is installed, and the update management unit may update the update list when the in-vehicle device in which the target software is installed is added to the in-vehicle network.
[0016] With this configuration, for example, when the target software is installed in an in-vehicle device added to an in-vehicle network, the message relay processing in the in-vehicle network to which the in-vehicle device has been added can be configured based on the latest software configuration including the target software.
[0017] (3) In (2) above, the update management unit may obtain app information indicating the version of the target software installed in the in-vehicle device from the in-vehicle device indicated in the update list, and create the vehicle configuration information based on the obtained app information.
[0018] With this configuration, application information can be obtained from the in-vehicle device by communicating with the in-vehicle device, and the latest vehicle configuration information can be created in the in-vehicle network. Therefore, compared to a configuration in which application information is received from a user, for example, vehicle configuration information can be created automatically and easily.
[0019] (4) In any of (1) to (3) above, the update management unit may perform a process of suppressing shutdown of the in-vehicle device on which the target software to be updated in the update process is installed, based on an inhibition list indicating the in-vehicle devices that need to operate in the update process of the target software, and the update management unit may update the inhibition list when the in-vehicle device on which the target software is installed is added to the in-vehicle network.
[0020] With this configuration, for example, when the target software is installed in an in-vehicle device added to an in-vehicle network, the operating state of the in-vehicle device can be maintained during the software update process, so that the software update process can be performed while the vehicle power is off.
[0021] (5) In the above (4), the update management unit may further perform processing for inhibiting, based on the inhibition list, a shutdown of a relay device that needs to relay a message related to the update processing.
[0022] With this configuration, for example, when the target software is installed in an in-vehicle device that sends and receives messages regarding update processing with the update management unit via a relay device, the relay device can be maintained in an operating state during the software update processing, and the software update processing can be performed during the period when the vehicle's power is turned off.
[0023] (6) An in-vehicle network management method according to an embodiment of the present disclosure is an in-vehicle network management method in an in-vehicle network management system including an update management unit that updates target software, which is software that is subject to update processing in an in-vehicle network, a configuration management unit that monitors a hardware configuration in the in-vehicle network, and a relay management unit that sets relay processing of messages in the in-vehicle network, and includes a step in which, when the hardware configuration has changed, the configuration management unit transmits connection configuration information indicating the hardware configuration after the change to the update management unit and the relay management unit; a step in which, when the hardware configuration has changed, the update management unit transmits to the relay management unit vehicle configuration information in the in-vehicle network after the change in hardware configuration, the vehicle configuration information indicating a correspondence between the target software, an in-vehicle device in which the target software is installed, and a version of the target software; and a step in which, when the update management unit updates the target software, the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit.
[0024] With this method, in an in-vehicle network where the hardware configuration changes or the software is updated, connection configuration information in the in-vehicle network after the hardware configuration has changed and vehicle configuration information in the in-vehicle network including the updated software can be provided to the relay management unit, so that the relay processing of messages in the in-vehicle network can be set based on the latest hardware configuration and the latest software configuration, thereby allowing the relay processing of messages in the in-vehicle network to be set appropriately.
[0025] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and the description thereof will not be repeated. In addition, at least some of the embodiments described below may be arbitrarily combined.
[0026] [Configuration and basic operation] Fig. 1 is a diagram showing an example of a configuration of an in-vehicle network management system according to an embodiment of the present disclosure. With reference to Fig. 1, an in-vehicle network management system 301 includes a relay device 101, in-vehicle ECUs 111A, 111B, and 111C which are in-vehicle ECUs (Electronic Control Units) 111, and an external communication device 151. The in-vehicle network management system 301 is mounted on a vehicle 1. The in-vehicle ECU 111 is an example of an in-vehicle device. The relay device 101, the in-vehicle ECUs 111A, 111B, and 111C, and the external communication device 151 configure an in-vehicle network 31A which is an in-vehicle network 31.
[0027] The relay device 101 includes communication ports PA1, PA2, PA3, and PA4, which are communication ports PA, and a communication port PB. The communication ports PA and PB are terminals to which an Ethernet (registered trademark) cable 32 can be connected.
[0028] The in-vehicle ECU 111 and the external communication device 151 are connected to the relay device 101 via an Ethernet cable 32. More specifically, the in-vehicle ECUs 111A, 111B, and 111C are connected to communication ports PA1, PA2, and PA3 in the relay device 101, respectively, via the Ethernet cable 32. The external communication device 151 is connected to a communication port PB in the relay device 101 via the Ethernet cable 32.
[0029] The external communication device 151 is, for example, a TCU (Telematics Communication Unit). The external communication device 151 is capable of wireless communication with an OTA (Over The Air) server (not shown) outside the vehicle 1.
[0030] The in-vehicle ECU 111 is, for example, an automatic driving ECU, an engine ECU, a sensor, a navigation device, a human-machine interface, a camera, and the like.
[0031] The in-vehicle ECUs 111A, 111B, and 111C are respectively equipped with applications 112A, 112B, and 112C that are the application 112. The application 112 is an example of target software. The application 112 is software that is subject to an update process in the in-vehicle network 31, and is updated periodically or irregularly using OTA technology.
[0032] The application 112 generates messages including various data by performing processing of the application layer. For example, the application 112 in the in-vehicle ECU 111, which is a temperature sensor, generates messages including temperature data indicating the outside air temperature of the vehicle 1 at a predetermined period.
[0033] The relay device 101 is, for example, a gateway device, and is capable of relaying messages transmitted and received in the in-vehicle network 31. The relay device 101 performs relay processing of messages exchanged between the in-vehicle ECUs 111 and messages exchanged between the in-vehicle ECUs 111 and the external communication device 151 in accordance with the Ethernet communication standard.
[0034] The relay device 101 updates the application 112 in the in-vehicle network 31, monitors the hardware configuration in the in-vehicle network 31, and sets the relay process. More specifically, the relay device 101 receives update data for the application 112 from an OTA server outside the vehicle 1 via the external communication device 151, and updates the application 112 using the received update data. In addition, when the hardware configuration in the in-vehicle network 31 changes or when the application 112 is updated, the relay device 101 changes the settings of the relay process.
[0035] In addition, the in-vehicle network 31 is not limited to a configuration in which messages are relayed according to the Ethernet communication standard, but may be a configuration in which messages are relayed according to communication standards such as CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), and LIN (Local Interconnect Network).
[0036] Furthermore, the in-vehicle network management system 301 is not limited to a configuration including three in-vehicle ECUs 111, but may be a configuration including one, two, or four or more in-vehicle ECUs 111. Furthermore, the in-vehicle network management system 301 is not limited to a configuration including one application 112 mounted on one in-vehicle ECU 111, but may be a configuration including two or more applications 112 mounted on one in-vehicle ECU 111. Furthermore, the in-vehicle network management system 301 is not limited to a configuration including one relay device 101, but may be a configuration including multiple relay devices 101.
[0037] [Problem] In a conventional in-vehicle communication system, for example, when an in-vehicle ECU 111 equipped with an application 112 is retrofitted to an in-vehicle network 31, it may not be possible to appropriately update the application 112. Further, in a conventional in-vehicle communication system, when the application 112 is updated, it may not be possible to perform appropriate relay processing setting according to the latest update status of the application 112.
[0038] Therefore, the in-vehicle network management system 301 according to the embodiment of the present disclosure solves the above problems with the following configuration.
[0039] (Relay device) FIG. 2 is a diagram showing the configuration of a relay device according to an embodiment of the present disclosure. Referring to FIG. 2, the relay device 101 includes a relay unit 11, an update management unit 12, a configuration management unit 13, a relay management unit 14, and a storage unit 15. The update management unit 12 includes an update unit 12A, a creation unit 12B, and a transmission unit 12C. The update management unit 12 is an example of an update management device. A part or all of the relay unit 11, the update management unit 12, the configuration management unit 13, and the relay management unit 14 are realized by, for example, a processing circuit (Circuitry) including one or more processors. The storage unit 15 is, for example, a non-volatile memory included in the above processing circuit.
[0040] The relay unit 11 performs relay processing of messages in the in-vehicle network 31. More specifically, the relay unit 11 receives a message from the in-vehicle ECU 111 via the corresponding communication port PA, and transmits the received message to the destination in-vehicle ECU 111 via the corresponding communication port PA.
[0041] The update management unit 12 updates the application 112. More specifically, the update unit 12A in the update management unit 12 receives update data from the OTA server via the external communication device 151 and the relay unit 11, and performs an update process of updating the application 112 using the received update data.
[0042] The configuration management unit 13 monitors the hardware configuration in the in-vehicle network 31. For example, the configuration management unit 13 detects a change in the in-vehicle network 31 caused by the addition or removal of an in-vehicle device.
[0043] Fig. 3 is a diagram showing an example of an update list stored in a storage unit in a relay device according to an embodiment of the present disclosure. Referring to Fig. 3, the storage unit 15 stores an update list L1 indicating an ECU ID that is an ID of the in-vehicle ECU 111 in which the application 112 is installed. The ECU IDs of the in-vehicle ECUs 111A, 111B, and 111C are assumed to be "ecu001", "ecu002", and "ecu003", respectively.
[0044] 4 is a diagram showing an example of an inhibition list stored in a storage unit in a relay device according to an embodiment of the present disclosure. Referring to Fig. 4, storage unit 15 stores inhibition list L2 indicating a correspondence relationship between an application ID, which is an ID of application 112, and a device ID, which is an ID of an in-vehicle device that needs to operate in an update process of application 112.
[0045] For example, the update list L1 and the inhibition list L2 are created by the update management unit 12 and stored in the storage unit 15. The update management unit 12 acquires the ECU ID of the in-vehicle ECU 111 in which the application 112 is installed by communicating with each in-vehicle ECU 111 via the relay unit 11, and creates the update list L1 and the inhibition list L2 including the acquired ECU ID. The update management unit 12 stores the created update list L1 and inhibition list L2 in the storage unit 15.
[0046] 5 is a diagram illustrating an example of a topology correspondence table created by a configuration management unit in a relay device according to an embodiment of the present disclosure. With reference to FIG. 5, the configuration management unit 13 creates a topology correspondence table T1 indicating a correspondence relationship between a relay device ID, which is an ID of a relay device in the in-vehicle network 31, a port ID, which is an ID of a communication port PA, and a connection node ID, which is an ID of a device connected to the communication port PA. The topology correspondence table T1 is an example of connection configuration information indicating a hardware configuration in the in-vehicle network 31. The relay device ID of the relay device 101 is assumed to be "esw001". Also, the port IDs of the communication ports PA1, PA2, PA3, and PA4 are assumed to be "A1", "A2", "A3", and "A4", respectively.
[0047] For example, the configuration management unit 13 acquires the ECU ID of each in-vehicle ECU 111 by communicating with each in-vehicle ECU 111 via the relay unit 11, and creates a topology correspondence table T1 based on the acquired ECU ID. The configuration management unit 13 outputs the created topology correspondence table T1 to the update management unit 12 and the relay management unit 14. In addition, the configuration management unit 13 stores the created topology correspondence table T1 in the storage unit 15.
[0048] Fig. 6 is a diagram showing an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. With reference to Fig. 6, creation unit 12B in update management unit 12 creates vehicle configuration table T2 indicating a correspondence relationship between the application ID of application 112, the ECU ID of in-vehicle ECU 111 in which application 112 is installed, and the version of application 112. Vehicle configuration table T2 is an example of vehicle configuration information. It is assumed that application IDs of applications 112A, 112B, and 112C are "app001", "app002", and "app003", respectively.
[0049] For example, the creation unit 12B communicates with the in-vehicle ECU 111 indicated in the update list L1 via the relay unit 11 to obtain app information indicating the app ID and version of the application 112 from the in-vehicle ECU 111, and creates the vehicle configuration table T2 based on the obtained app information. The transmission unit 12C in the update management unit 12 outputs the vehicle configuration table T2 created by the creation unit 12B to the relay management unit 14.
[0050] The relay management unit 14 sets relay processing of messages in the in-vehicle network 31. For example, the relay management unit 14 selects settings for relay processing in the relay unit 11 based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12. For example, the relay management unit 14 selects the correspondence relationship between the type of message, the receiving port ID, and the transmitting port ID as the selection of the relay processing setting.
[0051] More specifically, the storage unit 15 stores a setting table T3 indicating the correspondence relationship between the type of message, the receiving port ID, and the transmitting port ID. For example, the storage unit 15 stores a plurality of setting tables T3 each having different settings for relay processing.
[0052] The relay management unit 14 selects a setting table T3 indicating setting contents to be used for relay processing of the relay unit 11 in the in-vehicle network 31 from among the multiple setting tables T3 in the storage unit 15 based on the topology correspondence table T1 and the vehicle configuration table T2. The relay management unit 14 outputs the selected setting table T3 to the relay unit 11.
[0053] The relay unit 11 receives the setting table T3 from the relay management unit 14 and performs relay processing in accordance with the received setting table T3.
[0054] When the hardware configuration of the in-vehicle network 31 is changed or when the application 112 is updated, the relay management unit 14 changes the settings of the relay processing of the relay unit 11. A specific example of changing the settings of the relay processing of the relay unit 11 will be described below.
[0055] (Example 1 of changing relay process settings) (1) Changing settings in response to changes in hardware configuration Fig. 7 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Compared to the in-vehicle network 31A illustrated in Fig. 1, Fig. 7 illustrates an in-vehicle network 31B in which an in-vehicle ECU 111D is connected to a communication port PA4 in a relay device 101 via an Ethernet cable 32. Referring to Fig. 7, the in-vehicle ECU 111D is connected to the relay device 101, whereby the hardware configuration of the in-vehicle network 31 changes, and the in-vehicle network 31A illustrated in Fig. 1 changes to the in-vehicle network 31B, which is the in-vehicle network 31.
[0056] Compared to the in-vehicle ECUs 111A, 111B, and 111C, the in-vehicle ECU 111D is equipped with a PnP (Plug and Play) terminal unit 113 instead of the application 112. When the in-vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information including the ECU ID of the in-vehicle ECU 111D and information indicating that the application 112 is not installed in the in-vehicle ECU 111D to the relay device 101. The ECU ID of the in-vehicle ECU 111D is assumed to be "ecu004".
[0057] 2 again, the relay unit 11 receives connection information from the PnP terminal unit 113 via the communication port PA4, and outputs the received connection information to the configuration management unit 13. In addition, the relay unit 11 outputs to the configuration management unit 13 port information indicating the port ID of the communication port PA4 through which the connection information has passed.
[0058] When the hardware configuration in the in-vehicle network 31 changes, the configuration management unit 13 outputs a topology correspondence table T1 indicating the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information and port information from the relay unit 11, and updates the topology correspondence table T1 in the storage unit 15 based on the received connection information and port information.
[0059] 8 is a diagram illustrating an example of a topology correspondence table after being updated by a configuration management unit in a relay device according to an embodiment of the present disclosure. Referring to Fig. 8, the configuration management unit 13 updates the topology correspondence table T1 illustrated in Fig. 5 in the storage unit 15 to a topology correspondence table T1 to which a correspondence indicating a connection relationship of the in-vehicle ECU 111D is added.
[0060] The configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12. In addition, the configuration management unit 13 outputs the updated topology correspondence table T1 to the relay management unit .
[0061] 2 again, the update management unit 12 receives the connection information and the topology correspondence table T1 from the configuration management unit 13, and recognizes, based on the received connection information and the topology correspondence table T1, that the application 112 is not installed in the in-vehicle ECU 111D that has been added to the in-vehicle network 31. In this case, the update management unit 12 does not update the update list L1 and the inhibition list L2 in the storage unit 15.
[0062] When the hardware configuration in the in-vehicle network 31 is changed, the update management unit 12 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31B after the hardware configuration is changed.
[0063] For example, the update management unit 12 executes the process of the OTA master described on page 58 of Non-Patent Document 1, and creates a vehicle configuration table T2 in the in-vehicle network 31B based on the update list L1. More specifically, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1 in the storage unit 15, and creates a vehicle configuration table T2 in the in-vehicle network 31B based on the acquired application information. Since the application 112 is not mounted on the in-vehicle ECU 111D, the vehicle configuration table T2 in the in-vehicle network 31B is the same as the vehicle configuration table T2 in the in-vehicle network 31A before the in-vehicle ECU 111D is connected to the relay device 101. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0064] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from among the multiple setting tables T3 in the memory unit 15, which indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31B.
[0065] For example, the relay management unit 14 selects a setting table T3 including records of the receiving port IDs and transmitting port IDs of messages whose sender is the in-vehicle ECU 111D and records of the receiving port IDs and transmitting port IDs of messages addressed to the in-vehicle ECU 111D as the setting table T3 indicating the setting contents of the relay processing of the relay unit 11 in the in-vehicle network 31B. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0066] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0067] (2) Changing settings in response to application updates Thereafter, the update management unit 12 receives update data for updating, for example, the version of the application 112A from "1.0" to "2.0" from the OTA server via the external communication device 151 and the relay unit 11. The update management unit 12 performs an update process for updating the application 112A using the received update data.
[0068] For example, as an update process, the update management unit 12 executes an installation process, which is an OTA master process described on pages 61 and 62 of Non-Patent Document 1, and an activation process, which is an OTA master process described on page 63 of Non-Patent Document 1.
[0069] As an installation process, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECU 111A via the relay unit 11.
[0070] The in-vehicle ECU 111A receives an installation request from the relay device 101, and installs the update program based on the update data included in the received installation request. When the in-vehicle ECU 111A completes the installation of the update program, the in-vehicle ECU 111A transmits an installation completion notification to the relay device 101.
[0071] The update management unit 12 in the relay device 101 performs processing to inhibit shutdown of the in-vehicle ECU 111A on which the application 112A is mounted, based on the inhibition list L2. More specifically, the update management unit 12 receives an installation completion notification from the in-vehicle ECU 111A via the relay unit 11, and refers to the inhibition list L2 in the storage unit 15 to acquire a device ID corresponding to the application 112A. The update management unit 12 transmits a shutdown inhibition request via the relay unit 11 to the in-vehicle ECU 111A indicated by the acquired device ID.
[0072] The in-vehicle ECU 111A receives a shutdown prevention request from the relay device 101, and transmits a shutdown prevention response to the relay device 101 as a response to the received shutdown prevention request. Then, in accordance with the shutdown prevention request, the in-vehicle ECU 111A continues to operate even after the ignition power of the vehicle 1 is turned off. On the other hand, the in-vehicle ECUs 111B, 111C, and 111D stop operating when the ignition power of the vehicle 1 is turned off.
[0073] The update management unit 12 receives the shutdown prevention response from the in-vehicle ECU 111A via the relay unit 11, and waits for the ignition power of the vehicle 1 to be turned off. Then, when the ignition power of the vehicle 1 is turned off, the update management unit 12 executes an activation process. More specifically, as the activation process, the update management unit 12 transmits an activation request to the in-vehicle ECU 111A via the relay unit 11. The activation request is an example of a message related to the update process.
[0074] The in-vehicle ECU 111A receives an activation request from the relay device 101, and updates the application 112A by activating the installed update program in accordance with the received activation request. When the in-vehicle ECU 111A completes the activation of the update program, the in-vehicle ECU 111A transmits an activation completion notification to the relay device 101. The activation completion notification is an example of a message related to the update process.
[0075] When the update management unit 12 in the relay device 101 updates the application 112A, the update management unit 12 outputs to the relay management unit 14 the vehicle configuration table T2 in the in-vehicle network 31B including the updated application 112A.
[0076] 9 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. With reference to FIG. 9, when the update management unit 12 receives an activation completion notification from the in-vehicle ECU 111A via the relay unit 11, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1 in the storage unit 15, and creates a vehicle configuration table T2 indicating that the version of the application 112A has been changed to 2.0 based on the acquired application information. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0077] 2 again, the relay management unit 14 selects a setting table T3 indicating setting contents to be used for relay processing of the relay unit 11 in the in-vehicle network 31B from among the multiple setting tables T3 in the storage unit 15, based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0078] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0079] When relay management unit 14 completes the change of the settings of the relay process in relay unit 11, relay management unit 14 outputs a change completion notification to update management unit 12.
[0080] The update management unit 12 performs a process of stopping the in-vehicle ECU 111A upon receiving the change completion notification from the relay management unit 14. In addition, the update management unit 12 performs a process of notifying the user that the update of the application 112A has been completed.
[0081] Thereafter, when the ignition power of the vehicle 1 is turned on, the updated application 112A in the in-vehicle ECU 111A starts operating.
[0082] (Example 2 of changing relay process settings) (1) Changing settings in response to changes in hardware configuration Fig. 10 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Fig. 10 illustrates an in-vehicle network 31C in which an application 112D, which is the application 112, is further installed in an in-vehicle ECU 111D, as compared with the in-vehicle network 31B illustrated in Fig. 7. Referring to Fig. 10, when the in-vehicle ECU 111D is connected to the relay device 101, the hardware configuration in the in-vehicle network 31 changes, and the in-vehicle network 31A illustrated in Fig. 1 changes to an in-vehicle network 31C.
[0083] When the in-vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits to the relay device 101 connection information including the ECU ID of the in-vehicle ECU 111D and the application ID of the application 112D mounted on the in-vehicle ECU 111D.
[0084] 2 again, the relay unit 11 receives connection information from the PnP terminal unit 113 via the communication port PA4, and outputs the received connection information to the configuration management unit 13. In addition, the relay unit 11 outputs to the configuration management unit 13 port information indicating the port ID of the communication port PA4 through which the connection information has passed.
[0085] When the hardware configuration in the in-vehicle network 31 changes, the configuration management unit 13 outputs a topology correspondence table T1 indicating the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information and port information from the relay unit 11, and updates the topology correspondence table T1 shown in FIG. 5 in the storage unit 15 to the topology correspondence table T1 shown in FIG. 8 based on the received connection information and port information. The configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12. In addition, the configuration management unit 13 outputs the updated topology correspondence table T1 to the relay management unit 14.
[0086] When the in-vehicle ECU 111 on which the application 112 is installed is added to the in-vehicle network 31, the update management unit 12 updates the update list L1 and the inhibition list L2 in the storage unit 15. More specifically, the update management unit 12 receives the connection information and the topology correspondence table T1 from the configuration management unit 13, and recognizes that the in-vehicle ECU 111D added to the in-vehicle network 31 is equipped with the application 112D based on the received connection information and the topology correspondence table T1. In this case, the update management unit 12 updates the update list L1 and the inhibition list L2 in the storage unit 15.
[0087] 11 is a diagram illustrating an example of an update list after an update by the update manager in the relay device according to the embodiment of the present disclosure. With reference to FIG. 11, the update manager 12 adds the ECU ID of the in-vehicle ECU 111E to the update list L1 in the storage unit 15.
[0088] 12 is a diagram illustrating an example of the inhibition list after updating by the update management unit in the relay device according to the embodiment of the present disclosure. Referring to FIG. 12, the update management unit 12 adds a correspondence relationship between “app004”, which is the application ID of the application 112D, and the ECU ID of the in-vehicle ECU 111E to the inhibition list L2 in the storage unit 15.
[0089] When the hardware configuration in the in-vehicle network 31 is changed, the update management unit 12 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31C after the hardware configuration is changed.
[0090] For example, the update management unit 12 executes the OTA master process described on page 58 of Non-Patent Document 1, and creates a vehicle configuration table T2 in the in-vehicle network 31C based on the update list L1.
[0091] 13 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. Referring to FIG. 13, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1 in the storage unit 15, and creates a vehicle configuration table T2 including a correspondence relationship between the application ID of the application 112D, the ECU ID of the in-vehicle ECU 111D, and the version of the application 112D based on the acquired application information. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0092] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from among the multiple setting tables T3 in the memory unit 15, which indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31C.
[0093] For example, the relay management unit 14 selects a setting table T3 including records of the receiving port IDs and transmitting port IDs of messages whose sender is the in-vehicle ECU 111D and records of the receiving port IDs and transmitting port IDs of messages addressed to the in-vehicle ECU 111D as the setting table T3 indicating the setting contents of the relay processing of the relay unit 11 in the in-vehicle network 31C. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0094] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0095] (2) Changing settings in response to application updates 2 again, thereafter, the update management unit 12 receives update data for updating, for example, the versions of the applications 112A and 112D from "1.0" to "2.0" from the OTA server via the external communication device 151 and the relay unit 11. The update management unit 12 performs an update process for updating the applications 112A and 112D using the received update data.
[0096] As an installation process, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECUs 111A and 111D via the relay unit 11.
[0097] The in-vehicle ECUs 111A and 111D receive an installation request from the relay device 101 and install the update program based on the update data included in the received installation request. When the in-vehicle ECUs 111A and 111D complete the installation of the update program, they transmit an installation completion notification to the relay device 101.
[0098] The update management unit 12 in the relay device 101 performs a process of inhibiting shutdown of the in-vehicle ECUs 111A, 111D on which the applications 112A, 112D are installed, based on the inhibition list L2. More specifically, the update management unit 12 receives an installation completion notification from the in-vehicle ECUs 111A, 111D via the relay unit 11, and refers to the inhibition list L2 in the storage unit 15 to acquire a device ID corresponding to the application 112A and a device ID corresponding to the application 112D. The update management unit 12 transmits a shutdown inhibition request via the relay unit 11 to the in-vehicle ECUs 111A, 111D indicated by the acquired device IDs.
[0099] The in-vehicle ECUs 111A and 111D receive a shutdown prevention request from the relay device 101, and transmit a shutdown prevention response to the relay device 101 as a response to the received shutdown prevention request. Then, in accordance with the shutdown prevention request, the in-vehicle ECUs 111A and 111D continue to operate even after the ignition power of the vehicle 1 is turned off. On the other hand, the in-vehicle ECUs 111B and 111C stop operating when the ignition power of the vehicle 1 is turned off.
[0100] The update management unit 12 receives the shutdown prevention response from the in-vehicle ECUs 111A, 111D via the relay unit 11, and waits for the ignition power of the vehicle 1 to be turned off. Then, when the ignition power of the vehicle 1 is turned off, the update management unit 12 executes an activation process. More specifically, as the activation process, the update management unit 12 transmits an activation request to the in-vehicle ECUs 111A, 111D via the relay unit 11.
[0101] The in-vehicle ECUs 111A and 111D each receive an activation request from the relay device 101, and update the applications 112A and 112D by activating the installed update program in accordance with the received activation request. When the in-vehicle ECUs 111A and 111D each complete the activation of the update program, they each transmit an activation completion notification to the relay device 101.
[0102] When the update management unit 12 in the relay device 101 updates the applications 112A and 112D, the update management unit 12 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31C including the updated application 112A.
[0103] 14 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. With reference to FIG. 14, when the update management unit 12 receives an activation completion notification from the in-vehicle ECUs 111A and 111D via the relay unit 11, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1 in the storage unit 15. Based on the acquired application information, the update management unit 12 creates a vehicle configuration table T2 indicating that the versions of the applications 112A and 112D have been changed to 2.0. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0104] 2 again, the relay management unit 14 selects a setting table T3 indicating setting contents to be used for relay processing of the relay unit 11 in the in-vehicle network 31C from among the multiple setting tables T3 in the storage unit 15, based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0105] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0106] When relay management unit 14 completes the change of the settings of the relay process in relay unit 11, relay management unit 14 outputs a change completion notification to update management unit 12.
[0107] The update management unit 12 performs a process of stopping the in-vehicle ECUs 111A and 111D upon receiving the change completion notification from the relay management unit 14. In addition, the update management unit 12 performs a process of notifying the user that the updates of the applications 112A and 112D have been completed.
[0108] Thereafter, when the ignition power of the vehicle 1 is turned on, the updated applications 112A, 112D in the in-vehicle ECUs 111A, 111D start operating.
[0109] (Example 3 of changing relay process settings) (1) Changing settings in response to changes in hardware configuration Fig. 15 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Compared to the in-vehicle network 31C illustrated in Fig. 10, Fig. 15 illustrates an in-vehicle network 31D in which a relay device 102 is connected to a relay device 101 and an in-vehicle ECU 111D is connected to the relay device 102. The relay device 102, like the relay device 101, can relay messages transmitted and received in the in-vehicle network 31.
[0110] 10, the relay device 102 includes a PnP terminal unit 114 and communication ports PC1 and PC2 which are communication ports PC. A communication port PA4 in the relay device 101 and a communication port PC1 in the relay device 102 are connected via an Ethernet cable 32. An in-vehicle ECU 111D is connected to a communication port PC2 in the relay device 102 via the Ethernet cable 32. When the relay device 102 to which the in-vehicle ECU 111D is connected is connected to the relay device 101, the hardware configuration in the in-vehicle network 31 changes, and the in-vehicle network 31A shown in FIG. 1 changes to an in-vehicle network 31D.
[0111] When the relay device 102 is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information including the ECU ID of the in-vehicle ECU 111D and the application ID of the application 112D mounted on the in-vehicle ECU 111D to the relay device 101 via the relay device 102.
[0112] When the relay device 102 is connected to the relay device 101 via the Ethernet cable 32 , the PnP terminal unit 114 in the relay device 102 transmits relay connection information including the relay device ID of the relay device 102 to the relay device 101 .
[0113] 2 again, the relay unit 11 receives connection information and relay connection information from the PnP terminal units 113 and 114 via the communication port PA4, and outputs the received connection information and relay connection information to the configuration management unit 13. In addition, the relay unit 11 outputs to the configuration management unit 13 port information indicating the port ID of the communication port PA4 through which the connection information and the relay connection information have passed.
[0114] When the hardware configuration in the in-vehicle network 31 changes, the configuration management unit 13 outputs a topology correspondence table T1 indicating the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information, relay connection information, and port information from the relay unit 11, and updates the topology correspondence table T1 in the storage unit 15 based on the received connection information, relay connection information, and port information.
[0115] 16 is a diagram illustrating an example of a topology correspondence table after being updated by the configuration management unit in the relay device according to the embodiment of the present disclosure. The relay device ID of the relay device 102 is assumed to be "esw002". The port IDs of the communication ports PC1 and PC2 are assumed to be "C1" and "C2", respectively.
[0116] 16, the configuration management unit 13 updates the topology correspondence table T1 shown in FIG. 5 in the storage unit 15 to a topology correspondence table T1 to which a correspondence indicating a connection relationship between the relay device 102 and the in-vehicle ECU 111D has been added.
[0117] The configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12. In addition, the configuration management unit 13 outputs the updated topology correspondence table T1 to the relay management unit .
[0118] The update management unit 12 receives the connection information and the topology correspondence table T1 from the configuration management unit 13, and recognizes, based on the received connection information and the topology correspondence table T1, that the application 112D is installed in the in-vehicle ECU 111D that has been added to the in-vehicle network 31. In this case, the update management unit 12 updates the update list L1 and the inhibition list L2 in the storage unit 15.
[0119] More specifically, the update management unit 12 adds the ECU ID of the in-vehicle ECU 111E to an update list L1 in the storage unit 15, as shown in FIG.
[0120] 17 is a diagram illustrating an example of the inhibition list after updating by the update management unit in the relay device according to the embodiment of the present disclosure. Referring to FIG. 17, the update management unit 12 adds, to the inhibition list L2 in the storage unit 15, a correspondence relationship between the application ID “app004” of the application 112D, the relay device ID of the relay device 102, and the ECU ID of the in-vehicle ECU 111E.
[0121] Referring back to FIG. 2, when the hardware configuration in the in-vehicle network 31 is changed, the update management unit 12 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31D after the hardware configuration is changed.
[0122] For example, the update management unit 12 executes the OTA master process described on page 58 of Non-Patent Document 1, and creates a vehicle configuration table T2 in the in-vehicle network 31D based on the update list L1. More specifically, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1 in the storage unit 15, and creates the vehicle configuration table T2 shown in Fig. 13 based on the acquired application information. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0123] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from among the multiple setting tables T3 in the memory unit 15, which indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31D.
[0124] For example, the relay management unit 14 selects a setting table T3 including records of the receiving port IDs and transmitting port IDs of messages whose sender is the in-vehicle ECU 111D and records of the receiving port IDs and transmitting port IDs of messages addressed to the in-vehicle ECU 111D as the setting table T3 indicating the setting contents of the relay processing of the relay unit 11 in the in-vehicle network 31C. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0125] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0126] (2) Changing settings in response to application updates Thereafter, the update management unit 12 receives update data for updating the versions of the applications 112A and 112D, for example, from "1.0" to "2.0", from the OTA server via the external communication device 151 and the relay unit 11. The update management unit 12 performs an update process for updating the applications 112A and 112D using the received update data.
[0127] As an installation process, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECU 111A via the relay unit 11, and transmits the request to the in-vehicle ECU 111D via the relay unit 11 and the relay device 102.
[0128] The in-vehicle ECUs 111A and 111D receive an installation request from the relay device 101 and install the update program based on the update data included in the received installation request. When the in-vehicle ECUs 111A and 111D complete the installation of the update program, they transmit an installation completion notification to the relay device 101.
[0129] The update management unit 12 in the relay device 101 performs a process of inhibiting shutdown of the in-vehicle ECUs 111A and 111D on which the applications 112A and 112D are installed and the relay device 102 that needs to relay a message related to the update process of the application 112D, based on the inhibition list L2. More specifically, the update management unit 12 receives an installation completion notification from the in-vehicle ECUs 111A and 111D via the relay unit 11, and refers to the inhibition list L2 in the storage unit 15 to acquire a device ID corresponding to the application 112A and a device ID corresponding to the application 112D. The update management unit 12 transmits a shutdown inhibition request via the relay unit 11 to the relay device 102 and the in-vehicle ECUs 111A and 111D indicated by the acquired device IDs.
[0130] The relay device 102 and the in-vehicle ECUs 111A and 111D receive a shutdown prevention request from the relay device 101, and transmit a shutdown prevention response to the relay device 101 as a response to the received shutdown prevention request. Then, in accordance with the shutdown prevention request, the relay device 102 and the in-vehicle ECUs 111A and 111D continue to operate even after the ignition power of the vehicle 1 is turned off. On the other hand, the in-vehicle ECUs 111B and 111C stop operating when the ignition power of the vehicle 1 is turned off.
[0131] The update management unit 12 receives a shutdown prevention response from the relay device 102 and the in-vehicle ECUs 111A and 111D via the relay unit 11, and waits for the ignition power of the vehicle 1 to be turned off. When the ignition power of the vehicle 1 is turned off, the update management unit 12 executes an activation process. More specifically, as the activation process, the update management unit 12 transmits an activation request to the in-vehicle ECU 111A via the relay unit 11, and transmits an activation request to the in-vehicle ECU 111D via the relay unit 11 and the relay device 102.
[0132] The in-vehicle ECUs 111A and 111D each receive an activation request from the relay device 101 and update the applications 112A and 112D by activating the installed update program. When the in-vehicle ECUs 111A and 111D each complete the activation of the update program, they each transmit an activation completion notification to the relay device 101.
[0133] When the update management unit 12 in the relay device 101 updates the applications 112A and 112D, the update management unit 12 outputs a vehicle configuration table T2 in the in-vehicle network 31C including the updated application 112D to the relay management unit 14. More specifically, when the update management unit 12 receives an activation completion notification from the in-vehicle ECUs 111A and 111D via the relay unit 11, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1 in the storage unit 15. The update management unit 12 creates a vehicle configuration table T2 shown in FIG. 14 based on the acquired application information. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0134] The relay management unit 14 selects a setting table T3 indicating setting contents to be used for relay processing of the relay unit 11 in the in-vehicle network 31C from among the multiple setting tables T3 in the storage unit 15, based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0135] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0136] When relay management unit 14 completes the change of the settings of the relay process in relay unit 11, relay management unit 14 outputs a change completion notification to update management unit 12.
[0137] The update management unit 12 receives the change completion notification from the relay management unit 14 and performs a process of stopping the relay device 102 and the in-vehicle ECUs 111A and 111D. In addition, the update management unit 12 performs a process of notifying the user that the updates of the applications 112A and 112D have been completed.
[0138] Thereafter, when the ignition power of the vehicle 1 is turned on, the updated applications 112A, 112D in the in-vehicle ECUs 111A, 111D start operating.
[0139] [Operation flow] 18 is a diagram showing an example of a sequence of changing the settings of relay processing in the in-vehicle network management system according to the embodiment of the present disclosure. FIG 18 shows the sequence of the above-mentioned "changing the settings in response to a change in the hardware configuration."
[0140] 18, first, when the in-vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information to the relay device 101 (step S11).
[0141] Next, relay unit 11 in relay device 101 outputs the connection information and port information received from PnP terminal unit 113 to configuration management unit 13 (step S12).
[0142] Next, the configuration management unit 13 updates the topology correspondence table T1 based on the connection information and port information received from the relay unit 11 (step S13).
[0143] Next, the configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12 (step S14).
[0144] Furthermore, the configuration management unit 13 outputs the updated topology correspondence table T1 to the relay management unit 14 (step S15).
[0145] Next, based on the connection information received from the configuration management unit 13 and the topology correspondence table T1, the update management unit 12 recognizes that, for example, an application 112D is installed in an in-vehicle ECU 111D that has been added to the in-vehicle network 31, and updates the update list L1 and the inhibition list L2 (step S16).
[0146] Next, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1, and creates a vehicle configuration table T2 based on the acquired application information (step S17).
[0147] Next, the update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14 (step S18).
[0148] Next, based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from among the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31 (step S19).
[0149] Next, the relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11 (step S20).
[0150] Next, the relay unit 11 changes the settings of the relay process in accordance with the setting table T3 included in the setting change request received from the relay management unit 14 (step S21).
[0151] 19 is a diagram showing an example of a sequence of changing the settings of relay processing in the in-vehicle network management system according to the embodiment of the present disclosure. FIG 19 shows the sequence of the above-mentioned "changing the settings in response to an application update."
[0152] 19, first, the update management unit 12 receives update data of the application 112 from the OTA server via the external communication device 151 and the relay unit 11 (step S31).
[0153] Next, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECU 111 via (step S32).
[0154] Next, the in-vehicle ECU 111 installs the update program based on the update data included in the received installation request (step S33).
[0155] Next, the in-vehicle ECU 111 transmits an installation completion notification to the relay device 101 (step S34).
[0156] Next, the update management unit 12 in the relay device 101 transmits a shutdown prevention request to the in-vehicle ECU 111 (step S35).
[0157] Next, the in-vehicle ECU 111 transmits a shutdown prevention response to the relay device 101 as a response to the received shutdown prevention request (step S36).
[0158] Next, the update management unit 12 waits for the ignition power of the vehicle 1 to be turned off, and when the ignition power of the vehicle 1 is turned off, transmits an activation request to the in-vehicle ECU 111 (step S37).
[0159] Next, in accordance with the received activation request, the in-vehicle ECU 111 updates the application 112 by activating the installed update program (step S38).
[0160] Next, the in-vehicle ECU 111 transmits an activation completion notification to the relay device 101 (step S39).
[0161] Next, the update management unit 12 in the relay device 101 acquires application information from the in-vehicle ECU 111 indicated by the update list L1, and creates a vehicle configuration table T2 based on the acquired application information (step S40).
[0162] Next, the update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14 (step S41).
[0163] Next, based on the topology correspondence table T1 and the vehicle configuration table T2, the relay management unit 14 selects a setting table T3 from among the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31C (step S42).
[0164] Next, the relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11 (step S43).
[0165] Next, the relay unit 11 changes the settings of the relay process in accordance with the setting table T3 included in the setting change request received from the relay management unit 14 (step S44).
[0166] Next, the relay management unit 14 outputs a change completion notification to the update management unit 12 (step S45).
[0167] Next, the update management unit 12 performs a process of stopping the in-vehicle ECU 111 (step S46).
[0168] Next, when the ignition power of the vehicle 1 is turned on, the updated application 112 in the in-vehicle ECU 111 starts operating (step S47).
[0169] In the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12, the configuration management unit 13, and the relay management unit 14 are configured to be provided in the relay device 101, but this is not limiting. At least one of the update management unit 12, the configuration management unit 13, and the relay management unit 14 may be provided in a device other than the relay device 101. For example, in the in-vehicle network 31D shown in FIG. 15, when the update management unit 12 is provided in a device other than the relay device 101, the update management unit 12 further performs a process of inhibiting shutdown of the relay device 101 based on the inhibition list L2.
[0170] In addition, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to update the update list L1 and the inhibition list L2 when the in-vehicle ECU 111 on which the application 112 is installed is added to the in-vehicle network 31, but this is not limited thereto. The update management unit 12 may be configured not to update the update list L1 and the inhibition list L2 even when the in-vehicle ECU 111 on which the application 112 is installed is added to the in-vehicle network 31. In this case, the update management unit 12 updates the application 112 installed in the in-vehicle ECU 111 in the initial in-vehicle network 31, but does not update the application 112 installed in the in-vehicle ECU 111 added to the in-vehicle network 31. The update of the application 112 installed in the in-vehicle ECU 111 added to the in-vehicle network 31 may be performed by a unit other than the update management unit 12 in the in-vehicle network management system 301, or may be performed by a user of the vehicle 1 or a maintenance company of the vehicle 1.
[0171] In addition, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to acquire application information from the in-vehicle ECU 111 indicated by the update list L1 and create the vehicle configuration table T2 based on the acquired application information, but this is not limited to the above. The update management unit 12 may be configured to accept application information from a user of the in-vehicle network management system 301 and create the vehicle configuration table T2 based on the accepted application information.
[0172] In addition, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to perform a process of suppressing a shutdown of the relay device 102 that needs to communicate in the update process of the application 112, but this is not limited thereto. The update management unit 12 may be configured not to perform a process of suppressing a shutdown of the relay device 102. More specifically, the update management unit 12 updates the application 112 mounted on the in-vehicle ECU 111 connected to the relay device 101, while not updating the application 112 mounted on the in-vehicle ECU 111 connected to the relay device 101 via the relay device 102. The update of the application 112 mounted on the in-vehicle ECU 111 connected to the relay device 101 via the relay device 102 may be performed by a unit other than the update management unit 12 in the in-vehicle network management system 301, or may be performed by a user of the vehicle 1 or a maintenance company of the vehicle 1. In this case, the update management unit 12 does not perform a process of suppressing a shutdown of the relay device 102.
[0173] In addition, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to receive update data from the OTA server via the external communication device 151 and the relay unit 11, but this is not limited to the above. The update management unit 12 may be configured to receive update data from the OTA server via wired communication.
[0174] The above-described embodiments should be considered as illustrative and not restrictive in all respects. The scope of the present invention is defined by the claims, not the above description, and is intended to include all modifications within the meaning and scope of the claims.
[0175] Each process (each function) of the above-mentioned embodiment is realized by a processing circuit (circuitry) including one or more processors. The above-mentioned processing circuit may be composed of an integrated circuit or the like in which one or more memories, various analog circuits, and various digital circuits are combined in addition to the above-mentioned one or more processors. The above-mentioned one or more memories store programs (instructions) that cause the above-mentioned one or more processors to execute each of the above-mentioned processes. The above-mentioned one or more processors may execute each of the above-mentioned processes according to the programs read from the above-mentioned one or more memories, or may execute each of the above-mentioned processes according to a logic circuit designed in advance to execute each of the above-mentioned processes. The above-mentioned processors may be various processors suitable for computer control, such as a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and an ASIC (Application Specific Integrated Circuit). The above-mentioned physically separated processors may execute each of the above-mentioned processes in cooperation with each other. For example, the processors mounted on each of a plurality of physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, etc. The program may be installed in the memory from an external server device or the like via the network, or may be distributed in a state stored in a recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disc Read Only Memory), or a semiconductor memory, and installed in the memory from the recording medium.
[0176] The above description includes the following additional features. [Appendix 1] An update unit that updates target software that is a target of an update process in an in-vehicle network; a creating unit that creates the vehicle configuration information indicating a correspondence relationship between the target software, an in-vehicle device in which the target software is installed, and a version of the target software when the update unit updates the target software or when a hardware configuration in the in-vehicle network changes; a transmission unit that transmits the vehicle configuration information created by the creation unit to a relay management unit that sets a message relay process in the in-vehicle network.
[0177] [Appendix 2] An update management device, A processing circuit is provided, The processing circuitry includes: When target software, which is software that is subject to an update process in an in-vehicle network, is updated, or when a hardware configuration in the in-vehicle network is changed, creating the vehicle configuration information indicating a correspondence relationship between the target software, an in-vehicle device in which the target software is installed, and a version of the target software; The update management device transmits the created vehicle configuration information to a relay management unit that sets relay processing of messages in the in-vehicle network. [Explanation of symbols]
[0178] 1 vehicle 11 Relay Section 12 Update Management Department 12A Update section 12B Creation Department 12C Transmitter 13 Configuration Management Department 14 Relay Management Department 15 Storage section 31, 31A, 31B, 31C, 31D In-vehicle network 32 Ethernet cable 101,102 Relay device 111,111A,111B,111C,111D Automotive ECU 112, 112A, 112B, 112C, 112D Applications 113,114 PnP terminal unit 151 External communication device 301 In-vehicle network management system PA, PA1, PA2, PA3, PA4, PB communication ports L1 Update List L2 Suppression List T1 Topology Equivalent Table T2 Vehicle Configuration Table
Claims
1. an update management unit that updates target software that is a target of an update process in an in-vehicle network; a configuration management unit that monitors a hardware configuration in the in-vehicle network; a relay management unit that sets a relay process for a message in the in-vehicle network, when the hardware configuration is changed, the configuration management unit transmits connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit; when the hardware configuration has changed, the update management unit transmits to the relay management unit vehicle configuration information in the in-vehicle network after the change in the hardware configuration, the vehicle configuration information indicating a correspondence relationship between the target software, an in-vehicle device in which the target software is installed, and a version of the target software; An in-vehicle network management system, wherein when the target software is updated, the update management unit transmits the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit.
2. the update management unit creates the vehicle configuration information based on an update list indicating the in-vehicle device in which the target software is installed; The in-vehicle network management system according to claim 1 , wherein the update management unit updates the update list when the in-vehicle device on which the target software is installed is added to the in-vehicle network.
3. 3. The in-vehicle network management system according to claim 2, wherein the update management unit acquires app information indicating the version of the target software installed in the in-vehicle device from the in-vehicle device indicated in the update list, and creates the vehicle configuration information based on the acquired app information.
4. the update management unit performs a process of suppressing shutdown of the in-vehicle device in which the target software to be updated in the update process is installed, based on an inhibition list indicating the in-vehicle device that needs to operate in the update process of the target software; The in-vehicle network management system according to claim 1 , wherein the update management unit updates the inhibition list when the in-vehicle device on which the target software is installed is added to the in-vehicle network.
5. The in-vehicle network management system according to claim 4 , wherein the update management unit further performs a process of suppressing a shutdown of a relay device that needs to relay a message related to the update process, based on the suppression list.
6. An in-vehicle network management method in an in-vehicle network management system including an update management unit that updates target software that is a target of an update process in an in-vehicle network, a configuration management unit that monitors a hardware configuration in the in-vehicle network, and a relay management unit that sets a relay process of a message in the in-vehicle network, the method comprising: a step of the configuration management unit transmitting, when the hardware configuration has changed, connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit; a step of transmitting, when the hardware configuration has changed, vehicle configuration information in the in-vehicle network after the change in the hardware configuration, the vehicle configuration information indicating a correspondence relationship between the target software, an in-vehicle device in which the target software is installed, and a version of the target software, to the relay management unit by the update management unit; an update management unit that updates the target software and then transmits the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit when the update management unit updates the target software.
Citation Information
Patent Citations
Management device, vehicle communication system, vehicle, vehicle communication management device, vehicle communication management program
WO2020179123A1