Control apparatus, control method, and storage medium
The control device addresses user annoyance from frequent permission inquiries by displaying a permission acceptance image only for the first software update, thereby reducing user consent frequency and improving user experience.
Patent Information
- Application Number
- JP2023193075
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2043-11-13
AI Technical Summary
Frequent permission inquiries for software updates on in-vehicle devices can be bothersome for users.
A control device that displays a permission acceptance image only for the first software update out of two types, allowing users to accept the installation before proceeding, thereby reducing the frequency of user consent.
Reduces the frequency of user consent for software updates by limiting permission inquiries to only the first update, enhancing user experience by minimizing bothersome prompts.
Smart Images

Figure 2025080073000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a control device, a control method, and a storage medium for displaying information related to software updates for on-board devices mounted in a vehicle. [Background technology]
[0002] Vehicles are equipped with various in-vehicle devices that operate by executing software. Over-the-air (OTA) technology is known that updates the software of the in-vehicle devices with software downloaded from outside the vehicle via wireless communication. Patent Document 1 describes an OTA technology that updates the software of the in-vehicle devices through three phases: downloading, installing, and activating the update software. In the above conventional technology, user permission is requested before the start of each phase. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2022-163396 A Summary of the Invention [Problem to be solved by the invention]
[0004] If permission inquiries are made too frequently, the user may feel bothered. [Means for solving the problem]
[0005] A control device that solves the above problem includes a control unit that controls a display unit that displays information regarding software updates of on-board equipment mounted in a vehicle, and the control unit is configured to cause the display unit to display a permission acceptance image indicating that the permission operation for executing the installation by the user of the vehicle has been accepted before starting installation of the update software into the on-board equipment, only in the case of the first update out of two types of software updates, the first update and the second update.
[0006] A control method for solving the above problem is a control method for controlling a display unit that displays information regarding software updates of in-vehicle equipment mounted in a vehicle, and only in the case of the first update out of two types of software updates, the first update and the second update, a permission acceptance image indicating that a permission operation to execute the installation by the user of the vehicle has been accepted is displayed on the display unit before installation of the update software into the in-vehicle equipment is started.
[0007] The storage medium that solves the above problem is a storage medium that stores a program executed by a control device that controls a display unit that displays information regarding software updates of on-board equipment installed in a vehicle, and the program causes the control device to execute the following: only in the case of the first update out of two types of software updates, the first update and the second update, before starting installation of the update software into the on-board equipment, a permission acceptance image indicating that the permission operation for executing the installation by the user of the vehicle has been accepted.
[0008] The first update in the above-mentioned control device, control method, and storage medium is a software update in which the execution of the installation involves temporarily suspending the functions of the in-vehicle equipment, and the second update is a software update in which the execution of the installation does not involve temporarily suspending the functions of the in-vehicle equipment. Effect of the Invention
[0009] The above control device, control method, and storage medium have the effect of reducing the frequency of user consent for software updates. [Brief description of the drawings]
[0010] [Figure 1] 1 is a diagram illustrating a schematic configuration of a control device and a vehicle according to a first embodiment. [Diagram 2] This is a sequence diagram showing the processing steps of the installation phase. [Diagram 3] FIG. 13 is a diagram showing a display example of a permission acceptance image. [Figure 4] FIG. 13 is a diagram showing a display example of a guide image. [Diagram 5] FIG. 11 is a sequence diagram showing a process flow relating to display of a permission-accepting image in the second embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] (First embodiment) Hereinafter, a first embodiment of a control device, a control method, and a storage medium will be described in detail with reference to FIGS.
[0012] <Configuration of the control device and vehicle> As shown in FIG. 1, a vehicle 10 is equipped with on-board devices such as an OTA master 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18. These on-board devices are connected to each other via an on-board network 19 so that they can communicate with each other. The OTA master 11 manages software updates for the on-board devices including itself. The DCM 12 is a data communication module, and provides a wireless communication function with the outside of the vehicle via a mobile communication network 20. In this embodiment, the DCM 12 records the results of self-diagnosis performed by each on-board device of the vehicle 10 and transmits the results to a data center or the like outside the vehicle. The ADAS 13 is an advanced driving assistance system, and provides advanced driving assistance functions such as an automatic braking device and a sudden acceleration prevention device. The PCU 14 is a power control unit, and is an on-board device that controls power in the vehicle. The engine ECU 15 is an electronic control unit for engine control. The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a human machine interface, and includes an input device for receiving an operation by a passenger and a display device for displaying information to the passenger by image and sound. The HMI 18 may be configured to include a navigation function for guiding a driving route and an entertainment function for playing music and video. Each of these in-vehicle devices includes a storage module 21 in which software is stored, and a processor 22 for executing the software. The OTA master 11 further includes a data storage 23 for storing update software acquired from outside the vehicle.
[0013] Furthermore, the vehicle 10 is provided with a power switch 24 for switching the power of the vehicle 10 between on and off. The drive system of the vehicle 10 starts in response to switching from power off to power on, and stops in response to switching from power on to power off.
[0014] The vehicle 10 is connected to the OTA server 30 via the mobile communication network 20. The OTA server 30 is a server device that distributes update software for in-vehicle devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing the update software, and a processor 32 that executes the programs for distribution. The OTA server 30 can communicate with an information terminal 40 of a user of the vehicle 10 via the mobile communication network 20. An example of the information terminal 40 is a smartphone. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes software stored in the storage device 41. The HMI 43 includes an input device that accepts user operations and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as information confirmation and remote operation of the vehicle 10 owned by the user.
[0015] <Software update overview> Next, an overview of software update of the in-vehicle devices in the vehicle 10 will be described. The in-vehicle devices that are the subject of software update include the OTA master 11, the DCM 12, the ADAS 13, the PCU 14, the engine ECU 15, the transmission ECU 16, the brake ECU 17, and the HMI 18. The software update is performed through a download phase, an install phase, and an activate phase.
[0016] In the download phase, update software is transmitted from the OTA server 30 to the vehicle 10. The OTA master 11 stores the update software received from the OTA server 30 in the data storage 23. The download phase includes a series of processes related to downloading, such as judging whether downloading can be performed and verifying the update data. The update software may be transmitted from the OTA server 30 to the OTA master 11 by transmitting compressed data obtained by compressing the update software, or by transmitting divided data obtained by dividing the update software or the compressed data. Also, update software for multiple in-vehicle devices may be transmitted together.
[0017] In the installation phase, the update software is installed in the in-vehicle device to be updated. In the installation phase, the OTA master 11 writes the update software to the storage module 21 of the in-vehicle device to be updated. The installation phase includes a series of processes related to the installation, such as judging whether the installation can be performed, transferring the update data, and verifying the update software. If the update data includes the update software itself, in the installation phase, the OTA master 11 transfers the update data to the in-vehicle device to be updated. If the update data includes compressed data, difference data, or divided data of the update software, a process of generating the update software from the update data is performed. The generation process may be performed by the OTA master 11 or by the in-vehicle device to be updated. The generation of the update software can be performed by decompressing the compressed data and assembling the difference data or divided data. Note that the update software is disabled when the installation phase is completed.
[0018] In the activation phase, the update software is activated, i.e., the update software is enabled, in the in-vehicle device to be updated. The activation phase includes a series of processes related to activation, such as determining whether activation can be performed, checking the consistency of the update software, and verifying the results of the activation.
[0019] <Installation Phase Procedure> Next, the processing procedure of the installation phase will be described with reference to Figures 2 to 4. The in-vehicle devices to be updated for software include devices equipped with a single-bank storage module 21 and devices equipped with a dual-bank storage module 21. The single-bank storage module 21 has only one storage area for storing the software executed by the processor 32. In the case of an in-vehicle device equipped with a single-bank storage module 21, the updated software is written into the same storage area as the storage area in which the pre-update software is stored. Therefore, the execution of the installation may accompany the temporary suspension of the functions of the in-vehicle device. In contrast, the dual-bank storage module 21 has two storage areas. One of the two storage areas is disabled and the other is enabled. The processor 22 reads and executes the software from the enabled storage area. In the case of an in-vehicle device equipped with a dual-bank storage module 21, the updated software is written into the disabled storage area, i.e., into a storage area different from the storage area in which the pre-update software is stored. Therefore, the installation can be executed while the pre-update software is running.
[0020] Due to such hardware constraints, there are in-vehicle devices whose functions are temporarily suspended during installation. In the present embodiment, the HMI 18 that provides an entertainment function is equipped with a single-bank storage module 21. In contrast, in-vehicle devices that need to maintain their functions even during installation are equipped with a dual-bank storage module 21. Specifically, the OTA master 11, the DCM 12, the ADAS 13, the PCU 14, the engine ECU 15, the transmission ECU 16, and the brake ECU 17 are equipped with the dual-bank storage module 21.
[0021] In addition, even in an HMI 18 equipped with a single bank storage module 21, depending on the type of software, installation may be performed without pausing the function. For example, software updates for adding types of UI (user interface) of the HMI 18 that can be selected by the user can be installed without pausing the function of the HMI 18.
[0022] In the following description, a software update that involves temporary suspension of the functions of the in-vehicle device to be installed is referred to as a first update. A software update that does not involve temporary suspension of the functions of the in-vehicle device to be installed is referred to as a second update. Whether the software update is performed as a first update or a second update is determined based on the type of the in-vehicle device and the software. Campaign information that the OTA server 30 distributes to each vehicle 10 when updating the software includes update type information indicating whether the current software update is the first update or the second update.
[0023] 2, when the installation phase starts, the OTA master 11 performs an update type determination as to whether the current software update is a first update or a second update (S20). In this embodiment, the OTA master 11 performs the update type determination based on the update type information in the campaign information.
[0024] When the OTA master 11 determines in S20 that the current update is the first update, it determines whether or not to display a permission acceptance image on the HMI 18 (S22). The permission acceptance image is an image indicating that a permission operation for installation execution by a user is being accepted. For example, the OTA master 11 performs the determination based on, for example, the driving status of the vehicle 10. Specifically, the OTA master 11 determines whether the vehicle 10 is driving or stopped based on the vehicle speed, the brake operation status, the shift position, and the like. Then, when the vehicle 10 is stopped, the OTA master 11 determines that the display of the permission acceptance image is permitted. In addition, the OTA master 11 may determine whether or not to display the permission acceptance image based on the position of the vehicle 10. For example, when it is confirmed that the vehicle 10 is stopped at a parking place registered in advance, the OTA master 11 determines that the display of the permission acceptance image is permitted. The position information of the vehicle 10 can be acquired from the HMI 18 that provides a navigation function. If the OTA master 11 determines in S22 that the display is permitted, it instructs the HMI 18 to display a permission acceptance image (S24). The HMI 18 displays the permission acceptance image in response to the instruction (S26).
[0025] Fig. 3 shows an example of the permission acceptance image. The permission acceptance image displays a button to select whether to start the installation or to do it later. The permission acceptance image also displays information indicating that the functions of the in-vehicle device will be temporarily stopped when the installation starts. For example, in the case of Fig. 3, the entertainment function provided by the HMI 18 is displayed as an example of the function to be temporarily stopped.
[0026] When the user performs the operation to permit installation on the HMI 18 displaying the permission acceptance image (S28), the HMI 18 notifies the OTA master 11 that the permission operation has been performed (S30). In response to the notification, the OTA master 11 instructs the in-vehicle device to be updated to perform installation (S32). In addition, the OTA master 11 instructs the HMI 18 to display a guide image (S34). The in-vehicle device to be updated performs installation in response to the instruction (S36). The HMI 18 displays the guide image in response to the instruction (S38). If the in-vehicle device to be updated by the first update is the HMI 18, the HMI 18 displays the guide image in parallel with the installation.
[0027] Fig. 4 shows an example of the display of the guide image in the case of the first update. The guide image displays information indicating that the installation is in progress and information indicating the progress of the installation. Furthermore, the guide image in the case of the first update displays information indicating the contents of the functions of the in-vehicle device that will be temporarily stopped as the installation is performed. In the case of Fig. 4, the entertainment function provided by the HMI 18 is displayed as an example of the function that will be temporarily stopped.
[0028] When the installation is complete, the in-vehicle device notifies the OTA master 11 of the completion of the installation (S40). In response to the notification, the OTA master 11 instructs the HMI 18 to stop displaying the guidance image. In response to the instruction, the HMI 18 stops displaying the guidance image. With this, the installation phase is completed and the process moves to the activation phase.
[0029] On the other hand, if the OTA master 11 determines in S20 of Fig. 2 that the current update is the second update, the processes of S22 to S30 are skipped and the process of S32 is performed. Specifically, after determining the update type (S22), the OTA master 11 instructs the in-vehicle device to execute installation (S32) and instructs the HMI 18 to display a guide image. The guide image displayed on the HMI 18 in this case is the guide image in the case of the first update illustrated in Fig. 4, with information indicating the contents of the functions of the in-vehicle device to be temporarily stopped removed.
[0030] <Actions and Effects of the Embodiment> In the case of the first update, when the installation starts, the functions of the in-vehicle device become temporarily unavailable. In the case of such a first update, the OTA master 11 causes the HMI 18 to display a permission acceptance image before the installation starts. The permission acceptance image is an image indicating that the permission operation for the execution of the installation by the user of the vehicle 10 is being accepted. Then, the OTA master 11 instructs the in-vehicle device to execute the installation in response to the user's permission operation for the installation. Therefore, the user can select a time when the temporary suspension of the functions of the in-vehicle device can be tolerated to execute the installation of the update software.
[0031] In the case of the second update, the installation can be performed while maintaining the functions of the in-vehicle device to be updated, and therefore the functions of the vehicle 10. Therefore, in the case of the second update, even if the installation is performed, no change occurs in the functions of the vehicle 10. In the case of such a second update, the OTA master 11 executes the installation without displaying a permission acceptance image on the HMI 18. Therefore, in the case of the second update, the installation is automatically executed without the user's permission.
[0032] In this embodiment, the OTA master 11 is a control device and corresponds to a control unit that controls a display unit that displays information related to software updates of in-vehicle devices mounted on the vehicle 10. The HMI 18 corresponds to a display unit that displays information related to software updates of in-vehicle devices mounted on the vehicle 10. The OTA server 30 corresponds to a server outside the vehicle that distributes update software.
[0033] This embodiment provides the following advantages. (1) The OTA master 11 displays the permission acceptance image on the HMI 18 only in the case of the first update in which the execution of the installation involves the temporary suspension of the functions of the in-vehicle device. In the case of the second update in which the execution of the installation does not involve the temporary suspension of the functions of the in-vehicle device, the OTA master 11 automatically executes the installation without the user's permission. Therefore, while the user can select the timing of the installation in cases in which the suspension of the functions is involved, the installation can be executed without the user's permission in cases in which the suspension of the functions is not involved. Therefore, this embodiment has the effect of reducing the frequency of user permission in software updates.
[0034] (2) The OTA master 11 determines whether the software update is a first update or a second update. Specifically, the OTA master 11 determines the update type based on update type information acquired from an OTA server 30 outside the vehicle that distributes update software. Then, the OTA master 11 determines the processing procedure of the installation phase by itself based on the update type determination result. Therefore, the OTA master 11 can switch the processing procedure of the installation phase between the first update and the second update without relying on instructions from outside.
[0035] (3) When the software update is the second update, the OTA master 11 executes the installation of the update software in the in-vehicle device without waiting for the user's permission operation. When the in-vehicle device function is not temporarily stopped, the installation is executed automatically, reducing the burden on the user.
[0036] (4) When the software update is the first update, the OTA master 11 executes installation of the update software in the in-vehicle device in response to the user's permission operation. Therefore, the user can select a time when the user can tolerate temporary suspension of the in-vehicle device functions to execute the installation.
[0037] (5) When the software update is the first update, the OTA master 11 causes the HMI 18 to display information indicating the contents of the functions of the in-vehicle device that are temporarily stopped during the execution of the installation. This makes it easy for the user to understand that the functions of the in-vehicle device are temporarily stopped due to the execution of the installation.
[0038] (6) After the download of the update software is completed, the OTA master 11 causes the HMI 18 to display the permission acceptance image at a time determined by the driving conditions of the vehicle 10 and the position of the vehicle 10. Therefore, the permission acceptance image can be displayed when the user is in a situation where it is easy for him to check and operate the image on the HMI 18, such as when the vehicle 10 is parked.
[0039] Second embodiment Next, a second embodiment of the control device, the control method, and the storage medium will be described in detail with reference to Fig. 5. In this embodiment, the same components as those in the above embodiment are denoted by the same reference numerals, and detailed description thereof will be omitted.
[0040] In the first embodiment, the display control of information related to software updates on the HMI 18 installed in the vehicle 10 was performed by the OTA master 11 mounted on the same vehicle 10. In the present embodiment, the information related to software updates is displayed on an information terminal 40 owned by the user of the vehicle 10. Then, the OTA server 30 in the data center controls the display of the information terminal 40.
[0041] When the OTA master 11 of the vehicle 10 completes the download of the update software, it notifies the OTA server 30 of the completion (S50). The OTA server 30 performs an update type determination in response to the notification (S52). The OTA server 30 performs the update type determination based on, for example, campaign information that it has distributed to the vehicle 10.
[0042] When the OTA server 30 determines that the current software update is the first update, it instructs the information terminal 40 owned by the user of the vehicle 10 to display a permission acceptance image (S54). The information terminal 40 displays the permission acceptance image in response to the instruction (S56). The permission acceptance image displayed by the information terminal 40 conforms to that shown in FIG. 3. After that, when the user performs an operation to permit installation (S58), the information terminal 40 notifies the OTA server 30 that the installation has been permitted (S60). In response to the notification, the OTA server 30 notifies the OTA master 11 of the vehicle 10 that the installation has been permitted to be performed (S62). In response to the notification, the OTA master 11 instructs the in-vehicle device to be updated to perform the installation (S64). The in-vehicle device starts the installation in response to the instruction (S66).
[0043] Next, the OTA master 11 notifies the OTA server 30 that the installation has started (S68). In response to the notification, the OTA server 30 instructs the information terminal 40 to display a guide image (S70). In response to the instruction, the information terminal 40 displays the guide image (S72). The content of the guide image displayed on the information terminal 40 at this time conforms to that shown in FIG.
[0044] When the installation is complete, the in-vehicle device notifies the OTA server 30 via the OTA master 11 that the installation is complete (S74, S76). In response to the notification, the OTA server 30 instructs the information terminal 40 to stop displaying the guide image (S78). In response to the instruction, the information terminal 40 stops displaying the guide image. This completes the installation phase processing, and the process moves to the activation phase.
[0045] 5, if the OTA server 30 determines that the current update is the second update, it skips the processes of S54 to S60 and notifies the OTA master 11 that the execution of the installation is permitted (S62). Then, the process of the installation phase from S62 onwards is performed in the same manner as in the case of the first update.
[0046] The control device, control method, and storage medium of this embodiment provide the same functions and effects as those of embodiment 1. In this embodiment, the OTA server 30 corresponds to the control unit and the control device, and the information terminal 40 corresponds to the display unit.
[0047] (Other embodiments) The above embodiment can be modified as follows: The present embodiment and the following modifications can be combined with each other to the extent that there is no technical contradiction.
[0048] In the first embodiment, the OTA master 11 determines the timing for displaying the permission acceptance image on the HMI 18 based on the driving conditions and the position of the vehicle 10. The timing for displaying the permission acceptance image may be determined in other ways. For example, the permission acceptance image may be displayed in response to the completion of downloading.
[0049] In the case of the second update, whether or not user consent to the installation may be switched by a setting. If the user is allowed to switch this setting, it is possible to meet the user's desire to reduce the frequency of user consent and the user's desire to check the progress of the software update in detail. In addition, in some countries and regions, laws and regulations may require user consent to perform installation regardless of whether it is the first update or the second update. In addition, whether or not user consent is required to perform installation may change due to amendments to laws and regulations. If the manufacturer or dealer of the vehicle 10 is allowed to switch the setting, it is easy to respond to differences in laws and regulations between countries and regions and amendments to laws and regulations.
[0050] In addition to the display control of the HMI 18 of the vehicle 10 by the OTA master 11 in the first embodiment, the display control of the information terminal 40 by the OTA server 30 in the second embodiment may be performed. In this case, both the OTA master 11 and the OTA server 30 correspond to control devices. Also, both the HMI 18 of the vehicle 10 and the information terminal 40 correspond to display devices. In this case, the installation in the first update is permitted to be performed when the user performs an authorization operation on either the HMI 18 or the information terminal 40.
[0051] The permission acceptance image in Fig. 3 and the guidance image in Fig. 4 may display information indicating that the functions of the in-vehicle device will be temporarily suspended due to the execution of the installation, rather than information indicating the specific contents of the functions to be temporarily suspended. In this case, too, even if the functions of the in-vehicle device cannot be used, the user is unlikely to feel anxious or suspicious because it can be assumed that the cause is the installation.
[0052] The display examples of the images shown in Figures 3 and 4 are configured to display information within the images using characters. Information may be displayed within these images using methods of expression other than characters, such as still images or videos.
[0053] The guide image for the first update may not display information regarding the temporary suspension of the functions of the in-vehicle device due to the execution of the installation. In this case, the display content of the guide image for both the first update and the second update may be the same. Furthermore, in both the first update and the second update, the guide image may not be displayed during the execution of the installation.
[0054] In the first embodiment, the OTA master 11 that manages the software updates controls the display of information related to the software updates. However, the management of the software updates and the display control of information related to the software updates may be performed by different in-vehicle devices.
[0055] The display control of the HMI 18 of the vehicle 10 in the first embodiment may be performed by the OTA server 30. Moreover, the display control of the information terminal 40 in the second embodiment may be performed by the OTA master 11. Furthermore, the on-vehicle device that is the target of the software update may control the display of information related to the software update.
[0056] The update type determination in S20 in Fig. 2 may be performed before the start of the installation phase. For example, the OTA master 11 may perform the update type determination at the time of receiving campaign information from the OTA server 30.
[0057] The update type determination in S20 in FIG. 2 may be performed in a manner different from the above embodiment. For example, the update type determination can be performed in the following manner. Classification information of the in-vehicle device and the type of software to be updated in the first update and the second update is stored in advance in the storage module 21 of the OTA master 11. When updating software, the OTA master 11 acquires the type of in-vehicle device and the type of software to be updated from campaign information or the in-vehicle device to be updated. Then, the OTA master 11 refers to the classification information stored in the storage module 21 and determines whether the acquired type is classified as the first update or the second update. Similarly, the update type determination performed by the OTA server 30 in S52 in FIG. 5 can be performed in a different manner.
[0058] The control device and control unit may be configured as a circuit including one or more processors operating according to a computer program, one or more dedicated hardware circuits such as dedicated hardware for performing at least some of the various processes, or a combination of these. Dedicated hardware can be, for example, an ASIC, which is an application specific integrated circuit. The processor includes a CPU and memory such as RAM and ROM, and the memory stores program code or instructions configured to cause the CPU to perform the processes. The memory, i.e., the storage medium, includes any available medium accessible by a general-purpose or dedicated computer.
[0059] The term "at least one" as used herein means "one or more" of the desired options. As an example, the term "at least one" as used herein means "only one option" or "both of two options" if the number of options is two. As another example, the term "at least one" as used herein means "only one option" or "any combination of two or more options" if the number of options is three or more. [Explanation of symbols]
[0060] 10...vehicle, 11...OTA master, 12...DCM, 13...ADAS, 14...PCU, 15...engine ECU, 16...transmission ECU, 17...brake ECU, 18...HMI, 19...in-vehicle network, 20...mobile communication network, 21...storage module, 22...processor, 30...OTA server, 31...storage device, 32...processor, 40...information terminal, 41...storage device, 42...processor, 43...HMI.
Claims
1. The vehicle includes a control unit that controls a display unit that displays information about software updates for an in-vehicle device mounted in the vehicle, the control unit, only in the case of the first update among the two types of software updates, the first update and the second update, causes the display unit to display a permission acceptance image indicating that a permission operation for execution of the installation by a user of the vehicle has been accepted before starting installation of the update software into the in-vehicle device; The control device, wherein the first update is a software update that suspends the function of the in-vehicle device when the installation is performed, and the second update is a software update that does not suspend the function of the in-vehicle device when the installation is performed.
2. The control device according to claim 1, wherein, when the software update is the first update, the control unit causes the display unit to display at least one of information indicating that a function of the in-vehicle equipment will be temporarily suspended during execution of the installation and information indicating the content of the function of the in-vehicle equipment that will be temporarily suspended during execution of the installation.
3. The control device according to claim 1 , wherein the control unit causes the display unit to display the permission acceptance image at a time determined based on at least one of a driving status of the vehicle and a position of the vehicle after the download of the update software is completed.
4. A method for controlling a display unit that displays information regarding software updates for an in-vehicle device mounted in a vehicle, comprising: displaying, on the display unit, a permission acceptance image indicating that a permission operation for execution of the installation by a user of the vehicle has been accepted, before starting installation of the update software into the in-vehicle device, only in the case of the first update among the two types of software updates, i.e., the first update and the second update; A control method in which the first update is a software update that involves temporary suspension of functions of the in-vehicle device when the installation is performed, and the second update is a software update that does not involve temporary suspension of functions of the in-vehicle device when the installation is performed.
5. A storage medium storing a program executed by a control device that controls a display unit that displays information about software updates of an in-vehicle device mounted in a vehicle, the program causes the control device to execute the following: only in the case of the first update among the two types of software updates, i.e., a first update and a second update, before starting installation of the update software into the in-vehicle device, display on the display unit a permission acceptance image indicating that a permission operation for execution of the installation by a user of the vehicle has been accepted; A storage medium in which the first update is a software update that suspends the functions of the in-vehicle device when the installation is performed, and the second update is a software update that does not suspend the functions of the in-vehicle device when the installation is performed.
Citation Information
Patent Citations
Vehicle electronic control system, data repeating device, distribution control method of campaign information and distribution control program of campaign information
JP2021081780A
Center, OTA master, system, method, program, and vehicle
JP2023002193A
Software update device, software update system, and software update method
WO2016190377A1
Software updating device, software updating system, and software updating method
WO2023007577A1
OTA master, update control method, update control program, and OTA center
JP2022163396A