Control device, vehicle, control method, and program
The control device addresses the challenge of varying function restrictions during software updates by displaying specific confirmation images based on the update procedure, ensuring user awareness and convenience.
Patent Information
- Application Number
- JP2023201729
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2043-11-29
AI Technical Summary
During the activation process of software updates for in-vehicle devices, some vehicle functions are restricted, and it is desirable to confirm with the user before starting the activation process. Additionally, the timing of function restrictions varies depending on the type of in-vehicle device and software update procedure, necessitating an appropriate confirmation screen based on the execution timing of the activation process.
A control device that manages a display unit to show different confirmation images based on the software update procedure. When performing a first update procedure, a first confirmation image is displayed before the activation process, and when performing a second update procedure, a second confirmation image is displayed, both images providing information on function restrictions and estimated times.
Ensures that an appropriate confirmation screen is displayed according to the execution timing of the activation process, enhancing user convenience by allowing them to determine whether to proceed with the activation process based on the displayed information.
Smart Images

Figure 2025087226000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a control device, a vehicle, a control method, and a program for performing display control of information related to software update of in-vehicle devices.
Background Art
[0002] Vehicles are equipped with various in-vehicle devices that operate by executing software. There is known an OTA (Over The Air) technology for updating the software of in-vehicle devices with software downloaded from outside the vehicle via wireless communication. As described in Patent Document 1, software update is performed through an installation process of writing the downloaded updated software into a storage module of the in-vehicle device and an activation process of activating the installed updated software.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When the activation process is carried out, some functions of the vehicle may be restricted. Therefore, it is desirable to confirm with the user before starting the activation process. On the other hand, it is conceivable to carry out the activation process at different timings depending on the type of in-vehicle device and the type of software. In such a case, the timing at which vehicle function restriction occurs changes depending on the execution timing of the activation process. Therefore, it is desired that an appropriate confirmation screen be displayed according to the execution timing of the activation process.
Means for Solving the Problems
[0005] The control device for solving the above problems is a control device that controls a display unit that displays information related to software update of in-vehicle devices mounted on a vehicle having a plurality of switchable power modes. When the software update is performed by a first update procedure in which an activate process for activating the updated software installed in the in-vehicle device is performed in accordance with the switching of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activate process. When the software update is performed by a second update procedure in which the activate process is performed in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activate process.
[0006] The vehicle for solving the above problems is equipped with the above control device. The control method for solving the above problems is a control method for a display unit that displays information related to software update of in-vehicle devices mounted on a vehicle. When the software update is performed by a first update procedure in which an activate process for activating the updated software installed in the in-vehicle device is performed in accordance with the switching of the power mode in a first switching pattern, the first confirmation image is displayed on the display unit before the start of the activate process. When the software update is performed by a second update procedure in which the activate process is started in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activate process.
[0007] The program for solving the above problems is a program executed by a control device that controls a display unit for displaying information related to software update of in-vehicle devices mounted on a vehicle. When the software update is performed in a first update procedure in which an activate process for activating the updated software installed in the in-vehicle device is performed in accordance with the switching of the power mode in a first switching pattern, a process of causing the display unit to display a first confirmation image before the start of the activate process, and when the software update is performed in a second update procedure in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, a process of causing the display unit to display a second confirmation image different from the first confirmation image before the start of the activate process are executed by the control device.
Effect of the Invention
[0008] The above control device, vehicle, control method, and program have an effect that an appropriate confirmation screen can be displayed according to the execution timing of the activate process.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Modes for Carrying Out the Invention
[0010] (First Embodiment) Hereinafter, a first embodiment of a control device, a vehicle, a control method, and a program will be described in detail with reference to FIGS. 1 to 13.
[0011] <Configuration of Control Device and Vehicle> First, with reference to FIG. 1, the configuration of the control device and the vehicle according to the present embodiment will be described. As shown in FIG. 1, the vehicle 10 is equipped with in-vehicle devices such as an OTA master 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18. These in-vehicle devices are communicably connected to each other via an in-vehicle network 19. The OTA master 11 is in charge of managing software updates for the in-vehicle devices including itself. The DCM 12 is a data communication module (Data Communication Module) that provides a wireless communication function with the outside of the vehicle via a mobile communication network 20. In the case of the present embodiment, the DCM 12 is responsible for recording the results of self-diagnostics performed by each in-vehicle device of the vehicle 10 and transmitting them to an external data center or the like. The ADAS 13 is an advanced driving assistance system (Advanced Driving Assistant System) that provides advanced driving assistance functions such as an automatic braking device and a sudden acceleration prevention device. The PCU 14 is a power control unit (Power Control Unit) that performs power control inside the vehicle. The engine ECU 15 is an electronic control unit (Electronic Control Unit) for engine control. The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a human machine interface (Human Machine Interface). The HMI 18 includes an input device that receives operations from passengers and a display device that displays information to passengers by images or sounds. The HMI 18 may be configured to include a navigation function for guiding a driving route and an entertainment function for playing music and videos. Each of these in-vehicle devices has a storage module 21 in which software is stored and a processor 22 that executes the software. The OTA master 11 further has a data storage 23 that stores updated software acquired from the outside of the vehicle.
[0012] Vehicle 10 has a plurality of power modes. The plurality of power modes include a power mode for driving and a power mode for parking. For each power mode, it is determined which in-vehicle devices are to have their power turned on. When the power mode for driving is set, the power of the in-vehicle devices necessary for the driving of vehicle 10 and the provision of services during driving is turned on. In the case of the present embodiment, when the power mode for driving is set, the power of all the in-vehicle devices shown in FIG. 1 is turned on. When the power mode for parking is set, only the in-vehicle devices that need to operate even when vehicle 10 is parked have their power turned on. The in-vehicle devices whose power is turned on in each power mode can be changed according to the environment and user settings.
[0013] Vehicle 10 is provided with a power switch 24 for switching between the power mode for driving and the power mode for parking. The switching from the power mode for driving to the power mode for parking is performed in response to the switching of the power switch 24 from on to off. The switching from the power mode for parking to the power mode for driving is performed in response to the switching of the power switch 24 from off to on. The power switch 24 may be called an ignition switch in a conventional vehicle that uses only an engine as a drive source. Also, in a vehicle capable of electric driving such as a BEV or PHEV, the power switch 24 may be called a Ready switch.
[0014] Vehicle 10 is connected to an OTA server 30 via a mobile communication network 20. The OTA server 30 is a server device that distributes updated software for in-vehicle devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing the updated software, and a processor 32 that executes the program for distribution.
[0015] The OTA server 30 can communicate with the information terminal 40 of the user of the vehicle 10 via the mobile communication network 20. Examples of the information terminal 40 include smartphones. The information terminal 40 may be a tablet terminal or a PC terminal. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes the software stored in the storage device 41. The HMI 43 includes an input device that receives the user's operation and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as information confirmation and remote operation of the vehicle 10 owned by the user.
[0016] <Overview of Software Update> Next, an overview of the software update of in-vehicle devices in the vehicle 10 will be described. The in-vehicle devices subject to software update include the OTA master 11, DCM 12, ADAS 13, PCU 14, engine ECU 15, transmission ECU 16, brake ECU 17, and HMI 18. The software update is performed through a download phase, an install phase, and an activate phase.
[0017] In the download phase, updated software is transmitted from the OTA server 30 to the vehicle 10. The OTA master 11 stores the updated software received from the OTA server 30 in the data storage 23. The download phase includes a series of processes related to downloading, such as determining whether to execute the download and verifying the update data. The transmission of the updated software from the OTA server 30 to the OTA master 11 may be performed by transmitting compressed data obtained by compressing the updated software or by transmitting divided data obtained by dividing the updated software or the compressed data. Also, the updated software of a plurality of in-vehicle devices may be transmitted together.
[0018] In the installation phase, the update software is installed on the in-vehicle device to be updated. In the installation phase, the OTA master 11 installs the update software on the storage module 21 of the in-vehicle device to be updated based on the update data downloaded to the data storage 23. The installation phase includes a series of processes related to installation, such as determining whether installation can be executed, transferring update data, and verifying the update software. When the update data includes the update software itself, in the installation phase, the OTA master 11 transfers the update data to the in-vehicle device to be updated. When the update data includes compressed data, differential data, or split data of the update software, a generation process of the update software from the update data is performed. The generation process may be performed by the OTA master 11 or by the in-vehicle device to be updated. The generation of the update software can be performed by decompressing the compressed data and assembling the differential data or split data. Note that at the end of the installation phase, the update software is invalidated.
[0019] In the activation phase, activation of the update software, that is, validation of the update software, is performed on the in-vehicle device to be updated. The activation phase includes a series of processes related to activation, such as determining whether activation can be executed, checking the integrity of the update software, and verifying the execution result of activation.
[0020] <Two software update procedures> There are two software update procedures for the in-vehicle device, namely the first update procedure and the second update procedure. In both the first update procedure and the second update procedure, software updates are performed using common procedures until the installation phase is completed. In the first update procedure and the second update procedure, the timing for starting the activation process in the activation phase is different. The activation process is a process of validating the update software installed on the storage module 21 of the in-vehicle device to be updated.
[0021] In the case of the first update procedure, activation processing is performed in response to the switching of the power switch 24 from on to off. That is, in the first update procedure, activation processing is performed in response to the switching from the driving power mode to the parking power mode. When software update is performed in the first update procedure, it is prohibited to switch the power switch 24 back to on during the period from the start to the completion of the activation processing. In other words, when software update is performed in the first update procedure, switching to the driving power mode is prohibited during the period from the start to the completion of the activation processing.
[0022] On the other hand, in the case of the second update procedure, activation processing is performed in response to the switching of the power switch 24 from off to on. That is, in the second update procedure, activation processing is performed in response to the switching from the parking power mode to the driving power mode. Specifically, in the second update procedure, activation processing is started in response to the switching of the power switch 24 from off to on. Then, after waiting for the completion of the activation processing, the power mode is switched from the parking power mode to the driving power mode.
[0023] Whether to perform software update in the first update procedure or the second update procedure is classified according to, for example, the type of in-vehicle device, the hardware configuration, and the type of software. It may be determined whether to perform software update in the first or second update procedure according to environmental conditions, user settings, combinations of other in-vehicle devices that perform activation processing simultaneously, and the like.
[0024] When performing software update in the first update procedure, it is necessary to supply power to the in-vehicle device during activation processing even when the vehicle 10 is parked. Therefore, it is necessary to connect a dedicated power line for power supply during parking to the in-vehicle device that performs software update in the first update procedure. Therefore, it is basically desirable to perform software update of the in-vehicle device in the second update procedure that does not require a dedicated power line.
[0025] However, for some in-vehicle devices, it is desirable to perform software updates using the first update procedure rather than the second update procedure. In the case of the first update procedure, when the power switch 24 is switched from on to off and then switched back on again, the activation process has already been completed. Therefore, in this case, the in-vehicle device to be updated can start operating immediately after the power switch 24 is switched from off to on. In contrast, in the case of the second update procedure, the activation process starts after the power switch 24 is switched from off to on. Therefore, in order for the user to start driving the vehicle 10, even if the power switch 24 is switched from off to on, the in-vehicle device to be updated cannot start operating until the activation process is completed. Therefore, it is desirable to perform software updates on in-vehicle devices that are required to start operating immediately after the power switch 24 of the vehicle 10 is switched from off to on using the first update procedure.
[0026] In the case of this embodiment, the DCM 12, the ADAS 13, and the PCU 14 are classified as in-vehicle devices that perform software updates using the first update procedure. The communication function provided by the DCM 12 is used to report abnormalities occurring in the vehicle 10 to the outside. Further, in the case of this embodiment, the DCM 12 plays a role of recording the results of self-diagnostics of each in-vehicle device. It is desirable that functions of the DCM 12 such as reporting of abnormalities and recording of self-diagnosis results can be used immediately after the power switch 24 is switched from off to on. Also, the ADAS 13 needs to perform driving support from the time when the vehicle 10 starts driving. Further, while the operation of the PCU 14 is stopped, power cannot be supplied to the drive system, so the vehicle 10 cannot start driving. Thus, the DCM 12, the ADAS 13, and the PCU 14 are in-vehicle devices that are required to start operating immediately after the power switch 24 is switched from off to on.
[0027] In addition, depending on the hardware configuration of the memory module 21 installed in the in-vehicle device, software updates may be required in the first update procedure. In the case of this embodiment, among the in-vehicle devices other than the above-described DCM 12, ADAS 13, and PCU 14, the in-vehicle devices equipped with the single-bank memory module 21 are classified as in-vehicle devices that perform software updates in the first update procedure. And, among the in-vehicle devices other than the DCM 12, ADAS 13, and PCU 14, the in-vehicle devices equipped with the dual-bank memory module 21 are classified as in-vehicle devices that perform software updates in the second update procedure.
[0028] Fig. 2 shows the configuration of the in-vehicle device D1 equipped with the single-bank memory module 21A. The memory module 21A of this in-vehicle device D1 has only one storage area B for storing the software executed by the processor 32. In the case of such an in-vehicle device D1, the updated software is installed in the same storage area B as the storage area B storing the software before the update. Therefore, it is necessary to stop the operation of the in-vehicle device D1 even during the installation. Further, for recovery in the case of activation failure, it is necessary to reinstall the software before the update in the storage area B. Such reinstallation for recovery takes a long time. Further, when the software before the update is not backed up, it is necessary to redownload the software before the update. Thus, in the case of the in-vehicle device D1 equipped with the single-bank memory module 21A, considering recovery in the case of failure, it may take a very long time from the start of activation until the operation can be started. Therefore, in the case of this embodiment, the in-vehicle device D1 equipped with the single-bank memory module 21A performs software updates in the first update procedure. Also, in the case of this embodiment, the in-vehicle devices that perform software updates in the first update procedure have their power turned on and off in conjunction with the on / off of the power switch 24 of the vehicle 10.
[0029] Fig. 3 shows the configuration of the in-vehicle device D2 equipped with the dual-bank memory module 21B. The dual-bank memory module 21B has two memory areas B1 and B2. One of the two memory areas B1 and B2 is invalidated, and the other is activated. The processor 22 reads and executes software from the activated memory area. In the case of such an in-vehicle device D2, the updated software is installed in the invalidated memory area, that is, a memory area different from the memory area where the software before the update was stored. Then, after the installation, activation is performed by switching the memory area to be activated. If the activation fails, by switching the memory area to be activated again, it is possible to recover to the state before the update in a short time. Therefore, in the case of the in-vehicle device D2 equipped with the dual-bank memory module 21B, even if recovery in case of failure is expected, not much time is required from the start of activation until the operation can be started. Therefore, in the case of this embodiment, the software update is performed according to the second update procedure, limited to the in-vehicle device D2 equipped with the dual-bank memory module 21B.
[0030] Note that in many in-vehicle devices, there may be a case where a plurality of software providing different functions are installed. And among those plurality of software, there may be ones that need to be executed immediately after the switching of the power switch 24 from off to on, and ones that do not need to be executed immediately. In the case of software that needs to be executed immediately after the switching of the power switch 24 from off to on, if the update is performed according to the second update procedure, there is a possibility that the execution will not be in time. Therefore, even for the same in-vehicle device, depending on the type of software to be updated, it may be possible to distinguish whether to update according to the first update procedure or the second update procedure.
[0031] The OTA master 11 determines which of the first update procedure and the second update procedure will be used for software update at least until the start of the activation phase. For example, the OTA master 11 makes the determination based on the campaign information. In this case, the campaign information includes information indicating whether the update procedure of the software update is the first update procedure or the second update procedure. Also, the above determination may be made in the following manner. First, classification information on the types of in-vehicle devices or software to be updated by the first update procedure and the types of in-vehicle devices or software to be updated by the second update procedure is stored in advance in the storage module 21 of the OTA master 11. When performing software update, the OTA master 11 acquires the type of the in-vehicle device or software to be updated from the campaign information or the in-vehicle device to be updated. Then, the OTA master 11 refers to the classification information stored in the storage module 21 and determines which update procedure the acquired type is classified into for software update.
[0032] <Activation process in the first update procedure> Next, with reference to FIGS. 4 to 8, the details of the activation process in the first update procedure will be described. The storage module 21 of the OTA master 11 stores a program for managing software update and a program for controlling the display of information related to software update. The processes of the OTA master 11 shown in FIG. 4 and FIG. 9 described later are processes performed when the processor 22 of the OTA master 11 reads and executes those programs.
[0033] FIG. 4 shows the flow of the activation phase process when software update is performed by the first update procedure. When the installation phase is completed, the OTA master 11 instructs the HMI 18 to display a first pre-confirmation image for confirming with the user the execution of the activation process (S10). The HMI 18 displays a first pre-confirmation image as illustrated in FIG. 5 in response to the instruction (S11).
[0034] Fig. 5 shows an example of the display of the first pre-check image. The first pre-check image includes a reception display for a selection operation of whether or not to execute the activation process. Specifically, the first pre-check image displays a button for selecting to permit the execution of the activation process and a button for selecting to postpone the execution of the activation process. Note that the operations of these buttons are disabled during the running of the vehicle 10 and are enabled only when the vehicle is parked.
[0035] Also, within the first pre-check image, information on the function restrictions of the vehicle 10 associated with the execution of the activation process is displayed. Specifically, during the activation process, it is displayed as function restriction information that the power switch 24 cannot be switched on again. This function restriction information indicates that it is impossible to switch to the power mode for driving. Further, within the first pre-check image, information on the estimated time of the activation process is displayed. The estimated time of the activation process here is an estimated value of the required time from when the power switch 24 is switched from off to on until the activation process is completed and the power switch 24 can be switched on again. The OTA master 11 obtains the estimated time from, for example, campaign information. The OTA master 11 may calculate the estimated time based on the data size of the updated software, the type of in-vehicle device to be updated, etc.
[0036] Furthermore, within the first pre-check image, information such as a reminder to the user in response to the execution of the activation process is displayed. Examples of the information such as a reminder include that it is necessary to turn off the power switch 24 for software update, that the activation should be performed in a safe place, and that some of the functions of the vehicle 10 are disabled when the power switch 24 is turned on next time.
[0037] When the user performs an operation to select permission to execute the activation process on the HMI 18 on which the first pre - confirmation image is displayed (S12), the HMI 18 notifies the OTA master 11 that permission to execute the activation process has been granted (S13). When the OTA master 11 confirms the permission to execute the activation process, and then when the power switch 24 can be switched from on to off, it instructs the HMI 18 to display the first final confirmation image (S14). The HMI 18 displays the first final confirmation image as illustrated in FIG. 6 in response to the instruction (S15). The OTA master 11 determines that the power switch 24 can be switched from on to off, for example, on the conditions that the vehicle 10 is stopped, the parking shift operation is being performed, the parking brake is actuated, etc.
[0038] FIG. 6 shows an example of the display of the first final confirmation image. Inside the first final confirmation image, similar to the first pre - confirmation image, information on the function restrictions of the vehicle 10 associated with the execution of the activation process is displayed. Specifically, information indicating that when the power switch 24 is switched off, it becomes impossible to switch the power switch 24 back on and drive the vehicle 10 until the activation process is completed is displayed in the first final image. Also, information on the estimated time of the activation process is displayed inside the first final confirmation image. Inside the first final confirmation image, information indicating that after confirming it is a safe location, the power switch 24 should be switched off, it is also possible to resume driving, and in that case, the software update will resume with the display of the first final confirmation image at the next stop, etc. is also displayed. Furthermore, a reception display for pausing the software update is also displayed inside the first final confirmation image. The processing of the activation phase continues if the user does not select to pause the software update in the first final confirmation image. On the other hand, if the user selects to pause the software update in the first final confirmation image, the processing of the activation phase is temporarily stopped. And the processing of the activation phase resumes when the power of the vehicle 10 can be switched off next time.
[0039] If the processing of the activation phase continues and then the user switches the power switch 24 from on to off (S16), the OTA master 11 starts the activation process (S17). Along with this, the OTA master 11 instructs the HMI 18 to display a first guidance image as illustrated in FIG. 7 (S18). The HMI 18 displays the first guidance image in response to the instruction (S19).
[0040] As shown in FIG. 7, information indicating that it is impossible to switch the power switch 24 to on and information on the estimated time until the power switch 24 can be switched to on are displayed in the first guidance image. The OTA master 11 calculates the estimated time for displaying the information in the first guidance image by subtracting the time elapsed from the start of the activation process to the present from the predicted value of the time required from the start to the completion of the activation process. The HMI 18 temporarily dims the screen in response to locking the vehicle 10 or the elapse of a certain period of time, but displays the first guidance image again in response to unlocking the vehicle 10 or operating the HMI 18.
[0041] When the activation process is completed, the OTA master 11 instructs the HMI 18 to display a first completion notification image as illustrated in FIG. 8 (S20). The HMI 18 displays the first completion notification image in response to the instruction (S21). As shown in FIG. 8, information indicating that the software update has been completed and information indicating that the power switch 24 can be switched to on are displayed in the first completion notification image.
[0042] <Activation Process in the Second Update Procedure> Next, with reference to FIGS. 9 to 11, the details of the activation process in the second update procedure will be described. FIG. 9 shows the flow of the processing of the activation phase when software update is performed in the second update procedure.
[0043] In this case, when the installation phase of the OTA master 11 is completed, it instructs the HMI 18 to display a second pre-confirmation image for the user to confirm the execution of the activation process (S30). The HMI 18 displays a second pre-confirmation image as illustrated in FIG. 10 in response to the instruction (S31).
[0044] FIG. 10 shows an example of the display of the second pre-confirmation image. Similar to the first pre-confirmation image, the second pre-confirmation image includes a reception display for a selection operation of whether or not to execute the activation process. Also, it is displayed on the second pre-confirmation image that the activation process will be performed when the power switch 24 is switched on next. Further, within the second pre-confirmation image, information on the estimated time from when the power switch 24 is switched from off to on until the activation process is completed is displayed.
[0045] When the user performs an operation to select permission to execute the activation process on the HMI 18 on which the second pre-confirmation image is displayed (S32), the HMI 18 notifies the OTA master 11 that permission to execute the activation process has been granted (S33). When the OTA master 11 confirms the permission to execute the activation process, it then instructs the HMI 18 to display a second final confirmation image when the vehicle 10 becomes in a state where it can switch the power from on to off (S34). The HMI 18 displays a second final confirmation image as illustrated in FIG. 11 in response to the instruction (S35).
[0046] FIG. 11 shows an example of the display of the second final confirmation image. Information indicating that the preparation for the activation process is complete and information indicating that the software update will resume when the power switch 24 is switched from off to on next are displayed within the second final confirmation image.
[0047] Thereafter, when the power switch 24 is switched from on to off and then back to on, the OTA master 11 starts the activation process (S36). In addition, the OTA master 11 instructs the HMI 18 to display a second guidance image as illustrated in FIG. 12 (S37). The HMI 18 displays the second guidance image in response to the instruction (S38).
[0048] As shown in FIG. 12, information indicating that the software update is in progress and information on the estimated time until the completion of the update are displayed in the second guidance image. The OTA master 11 calculates the estimated time for displaying the information in the second guidance image by subtracting the time elapsed from the start to the present of the activation process from the predicted value of the time required from the start to the completion of the activation process.
[0049] When the activation process is completed, the OTA master 11 instructs the HMI 18 to display a second completion notification image as illustrated in FIG. 13 (S39). The HMI 18 displays the second completion notification image in response to the instruction (S40). As shown in FIG. 13, information indicating that the software update has been completed is displayed in the second completion notification image. In addition, information indicating that the function restriction associated with the activation process has been lifted is displayed in the second completion notification image. For example, if the running of the vehicle 10 was prohibited during the execution of the activation process, information indicating that the vehicle 10 can now run is displayed in the second completion notification image.
[0050] <Actions and Effects of the Embodiment> The OTA master 11 controls the display of the HMI 18 that displays information regarding software updates of in-vehicle devices mounted on the vehicle 10. The software update of the in-vehicle devices is performed according to the first update procedure or the second update procedure. In the first update procedure, an activation process for activating the updated software installed in the in-vehicle device is carried out in response to the switching from the driving power mode to the parking power mode. In the second update procedure, the activation process is carried out in response to the switching from the parking power mode to the driving power mode. When the software update is performed according to the first update procedure, the OTA master 11 causes the HMI 18 to display the first pre-check image and the first final check image before the start of the activation process. On the other hand, when the software update is performed according to the second update procedure, the OTA master 11 causes the HMI 18 to display a second pre-check image and a second final check image, which are different from the first pre-check image and the first final check image respectively, before the start of the activation process.
[0051] When the software update is performed according to the first update procedure and the second update procedure, the timing at which the functions of the vehicle 10 are restricted due to the activation process and the content of the restriction are different. Therefore, simply notifying the user of the execution of the activation process may cause unexpected function restrictions and confuse the user. In the case of the present embodiment, the user can confirm whether the software update is performed according to the first update procedure or the second update procedure based on the difference in the check images displayed on the HMI 18 before the start of the activation process.
[0052] According to the control device, vehicle, control method, and program of the present embodiment described above, the following effects can be obtained. (1) The check images displayed on the HMI 18 before the start of the activation process are different when the software update is performed according to the first update procedure and the second update procedure. Therefore, the present embodiment has the effect that an appropriate check screen can be displayed according to the execution timing of the activation process.
[0053] (2) The user can determine whether to perform the activation process after checking the execution timing. Therefore, the convenience for the user is improved. (3) If the execution timing of the activation process is different, the timing and content of the function restrictions of the vehicle 10 associated with the execution are different. In response to this, the OTA master 11 causes the information on the function restrictions of the vehicle 10 associated with the execution of the activation process to be displayed in the first pre-final confirmation image. In addition, the OTA master 11 causes information different from the information to be displayed in the first pre-final confirmation image to be displayed in the second pre-final confirmation image as the information on the function restrictions. Therefore, the function restrictions of the vehicle 10 associated with the execution of the activation process can be accurately notified to the user.
[0054] (4) The OTA master 11 causes the information on the period during which the functions of the vehicle 10 are restricted due to the execution of the activation process to be displayed in the first pre-final confirmation image. In addition, the OTA master 11 causes the information on a period different from the period during which the information is displayed in the first pre-final confirmation image to be displayed in the second pre-confirmation image as the information on the period during which the functions of the vehicle 10 are restricted. Therefore, the period during which the functions of the vehicle 10 are restricted due to the execution of the activation process can be accurately notified to the user.
[0055] (5) The OTA master 11 causes the information on the estimated time until the power switch 24 can be switched on again after being switched from on to off to be displayed in the first pre-final confirmation image. Therefore, the user can determine whether to perform the activation process after checking the period during which the power switch 24 cannot be turned on due to the execution of the activation process.
[0056] (6) The OTA master 11 causes the information on the estimated time from when the power switch 24 is switched from off to on until the activation process is completed to be displayed in the second pre-confirmation image. Therefore, when the user drives the vehicle 10 next time, the user can determine whether to perform the activation process after checking the period during which function restrictions occur due to the activation process.
[0057] (7) The first pre-final confirmation image and the second pre-confirmation image include a reception display for a selection operation to permit or not permit the start of the activation process. Therefore, the user can determine whether to perform the activation process while checking the timing of the activation process, the content and timing of the function restrictions associated with its implementation.
[0058] (8) During the implementation of the activation process in the first update procedure and during the implementation of the activation process in the second update procedure, the content of the function restrictions of the vehicle 10 caused by the influence is different. Therefore, just knowing that the activation process is in progress, the user may not be able to grasp the situation. In contrast, when software update is performed in the first update procedure, the OTA master 11 causes the first guidance image to be displayed on the HMI 18 during the implementation of the activation process. Also, when software update is performed in the second update procedure, the OTA master 11 causes a second guidance image different from the first guidance image to be displayed on the HMI 18 during the implementation of the activation process. Therefore, it is easier for the user to grasp the influence caused by the activation process.
[0059] (9) The OTA master 11 causes information indicating that it is impossible to switch the power switch 24 to on, that is, it is impossible to switch to the power mode for driving, to be displayed in the first guidance image. Further, the OTA master 11 causes information on the estimated time until the power switch 24 can be switched to on to be displayed in the first guidance image. It becomes easier for the user to grasp the situation.
[0060] (10) The OTA master 11 causes information on the estimated time until the completion of the activation process to be displayed in the second guidance image. Therefore, the user can grasp when the functions of the updated software will be available.
[0061] (11) When the software update is performed according to the first update procedure and the second update procedure, the functions of the vehicle 10 whose restrictions are released in response to the completion of the activation process are different. On the other hand, when the software update is performed according to the first update procedure, the OTA master 11 causes the HMI 18 to display the first completion notification image after the activation process is completed. Further, when the software update is performed according to the second update procedure, the OTA master 11 causes the HMI 18 to display a second completion notification image different from the first completion notification image after the activation process is completed. Specifically, the OTA master 11 causes the first completion notification image to display that the power switch 24 can be switched on, while the second completion notification image displays that the functions of the in-vehicle devices restricted with the implementation of the activation process can be used. Therefore, it is easy for the user to grasp the functions of the vehicle 10 whose restrictions are released in response to the completion of the activation process.
[0062] (12) The DCM 12, ADAS 13, and PCU 14 are required to start operating immediately after the power switch 24 is switched from off to on. In the present embodiment, the software updates of the DCM 12, ADAS 13, and PCU 14 are performed according to the first update procedure in which the activation process is performed while the power switch 24 is off. Therefore, it is possible to avoid the time from when the power switch 24 is switched from off to on until the DCM 12, ADAS 13, and PCU 14 start operating from becoming longer due to the activation process. As described above, in the case of the present embodiment, the in-vehicle devices for which the software update is performed according to the first update procedure and the in-vehicle devices for which the software update is performed according to the second update procedure are classified according to the functions of the in-vehicle devices.
[0063] (13) The in-vehicle device D1 equipped with the single-bank memory module 21A takes a longer time for the activation process than the in-vehicle device D2 equipped with the dual-bank memory module 21B. Therefore, when the activation process is started after switching the power switch 24 from off to on, the functions of the in-vehicle device D1 may become unavailable for a long time until the completion of the process. In contrast, in the case of this embodiment, among the in-vehicle devices other than the DCM12, ADAS13, and PCU14, the in-vehicle device D1 equipped with the single-bank memory module 21A performs software update according to the first update procedure. On the other hand, among the in-vehicle devices other than the above, the in-vehicle device D2 equipped with the dual-bank memory module 21B performs software update according to the second update procedure. Therefore, by implementing the activation process, it is possible to avoid a long-term function limitation of the in-vehicle device after switching the power switch 24 from off to on.
[0064] (14) When the software update is performed according to the first update procedure, the OTA master 11 starts the activation process of the in-vehicle device in response to the power switch 24 being switched from on to off. Also, when the software update is performed according to the second update procedure, the OTA master 11 starts the activation process of the in-vehicle device in response to the power switch 24 being switched from off to on. Thus, in the case of this embodiment, the OTA master 11 that manages the software update performs display control of information. Therefore, it is possible to accurately display information according to the progress of the software update.
[0065] (15) When the installation phase is completed, the OTA master 11 causes the HMI 18 to display the first pre- / second confirmation image. Further, when the vehicle 10 subsequently becomes in a state where the power switch 24 can be switched from on to off, the OTA master 11 causes the HMI 18 to display the first / second final confirmation image. Therefore, it is easy for the user to confirm that the activation process will be executed thereafter.
[0066] <Corresponding relationship> In the case of this embodiment, the first pre-check image and the first final check image correspond to the first check image, and the second pre-check image and the second final check image correspond to the second check image. Also, in the case of this embodiment, the HMI 18 installed in the vehicle 10 corresponds to the display unit, and the OTA master 11 mounted on the vehicle 10 corresponds to the control device.
[0067] Also, in the case of this embodiment, the power mode for driving corresponds to the first power mode and the power mode in which the vehicle 10 can travel. Also, the power mode for parking corresponds to the second power mode and the power mode in which the vehicle 10 cannot travel. Then, the switching from the driving power mode to the parking power mode corresponds to the switching of the power mode of the first switching pattern, and the switching from the parking power mode to the driving power mode corresponds to the switching of the power mode of the second switching pattern. Further, the processes of S10 and S14 in FIG. 4 correspond to the first display process, the process of S18 corresponds to the third display process, and the process of S20 corresponds to the fifth display process. Also, the processes of S30 and S34 in FIG. 9 correspond to the second display process, the process of S37 corresponds to the fourth display process, and the process of S39 corresponds to the sixth display process.
[0068] (Second Embodiment) Next, a second embodiment of the control device, the control method, and the program will be described in detail with reference to FIGS. 14 and 15 together. In this embodiment, for the components common to the above embodiment, the same reference numerals are given and the detailed description thereof is omitted.
[0069] In the case of the first embodiment, the OTA master 11 mounted on the same vehicle 10 performs the display control of the information regarding the software update for the HMI 18 installed in the vehicle 10. In the case of this embodiment, the information regarding the software update is displayed on the HMI 43 of the information terminal 40 owned by the user of the vehicle 10. And the OTA server 30 of the data center performs the display control.
[0070] <Activation Process in the First Update Procedure> Figure 14 shows the process flow of the activation phase when software update is performed in the first update procedure in the case of this embodiment. As shown in Figure 14, when the installation phase is completed, the OTA master 11 notifies the OTA server 30 (S50). When the OTA server 30 confirms the completion of the installation phase, it instructs the information terminal 40 to display the first pre-confirmation image (S51). The information terminal 40 displays the first pre-confirmation image on its HMI 43 according to the instruction (S52). The first pre-confirmation image displayed on the HMI 43 of the information terminal 40 conforms to Figure 5.
[0071] When the user of the information terminal 40 performs an operation to select permission to execute the activation process (S53), the information terminal 40 notifies the OTA server 30 that the execution of the activation process has been permitted (S54). Furthermore, the OTA server 30 notifies the OTA master 11 of the vehicle 10 that the execution of the activation process has been permitted (S55).
[0072] After that, when the OTA master 11 becomes in a state where the power switch 24 can be switched from on to off, it notifies the OTA server 30 of this state (S56). The OTA server 30 instructs the information terminal 40 to display the first final confirmation image according to this notification (S57). The information terminal 40 displays the first final confirmation image on its HMI 43 according to the instruction (S58). The first final confirmation image displayed on the HMI 43 of the information terminal 40 conforms to Figure 6.
[0073] After that, when the power switch 24 is switched from on to off, the OTA master 11 starts the activation process (S59). Also, the OTA master 11 notifies the OTA server 30 of the start of the activation process (S60). When the OTA server 30 confirms the start of the activation process, it instructs the information terminal 40 to display the first guidance image (S61). The information terminal 40 displays the first guidance image on its HMI 43 according to the instruction (S62). The first guidance image displayed on the HMI 43 of the information terminal 40 conforms to Figure 7.
[0074] When the activation process of the OTA master 11 is completed, it notifies the OTA server 30 of this (S63). When the OTA server 30 confirms the completion of the activation process, it instructs the information terminal 40 to display the first completion notification image (S64). The information terminal 40 displays the first completion notification image on its own HMI43 in response to the instruction (S65). The first completion notification image displayed on the HMI43 of the information terminal 40 conforms to FIG. 8.
[0075] <Activation process in the second update procedure> FIG. 15 shows the flow of the activation phase processing when software update is performed in the second update procedure in the case of this embodiment. As shown in FIG. 15, when the installation phase of the OTA master 11 is completed, it notifies the OTA server 30 of this (S70). When the OTA server 30 confirms the completion of the installation phase, it instructs the information terminal 40 to display the second pre - confirmation image (S71). The information terminal 40 displays the first pre - confirmation image on its own HMI43 in response to the instruction (S72). The first pre - confirmation image displayed on the HMI43 of the information terminal 40 conforms to FIG. 10.
[0076] When the user of the information terminal 40 performs an operation to select permission to execute the activation process (S73), the information terminal 40 notifies the OTA server 30 that the execution of the activation process has been permitted (S74). The OTA server 30 notifies the OTA master 11 of the vehicle 10 that the execution of the activation process has been permitted (S75).
[0077] When the OTA master 11 subsequently becomes in a state where the power switch 24 can be switched from on to off, it notifies the OTA server 30 of this (S76). The OTA server 30 instructs the information terminal 40 to display the second final confirmation image in response to the notification (S77). The information terminal 40 displays the second final confirmation image on its own HMI43 in response to the instruction (S78). The second final confirmation image displayed on the HMI43 of the information terminal 40 conforms to FIG. 11.
[0078] After the power switch 24 is switched from on to off and then switched back on, the OTA master 11 starts the activation process (S79). Also, the OTA master 11 notifies the OTA server 30 of the start of the activation process (S80). When the OTA server 30 confirms the start of the activation process, it instructs the information terminal 40 to display a second guidance image (S81). In response to the instruction, the information terminal 40 displays the second guidance image on its HMI 43 (S82). The second guidance image displayed on the HMI 43 of the information terminal 40 conforms to FIG. 12.
[0079] When the activation process is completed, the OTA master 11 notifies the OTA master 11 of the completion (S83). When the OTA server 30 confirms the completion of the activation process, it instructs the information terminal 40 to display a second completion notification image (S84). The information terminal 40 displays the second completion notification image on its HMI 43 in response to the instruction (S85). The first completion notification image displayed on the HMI 43 of the information terminal 40 conforms to FIG. 13.
[0080] In the case of this embodiment, the HMI 43 of the information terminal 40 corresponds to the display unit, and the OTA server 30 corresponds to the control device, respectively. This embodiment exhibits the same or similar actions and effects as the first embodiment.
[0081] (Other Embodiments) The above embodiment can be implemented with the following modifications. The above embodiment and the following modification examples can be implemented in combination with each other within a technically non - conflicting range.
[0082] · Along with the display control of the HMI 18 of the vehicle 10 by the OTA master 11 in the first embodiment, the display control of the information terminal 40 by the OTA server 30 in the second embodiment may be performed. In this case, both the OTA master 11 and the OTA server 30 correspond to the control device.
[0083] · The display control of the HMI 18 of the vehicle 10 in the first embodiment may be performed by the OTA server 30. ·The OTA master 11 may perform the display control of the information terminal 40 in the second embodiment.
[0084] ·The in-vehicle device that is the target of software update may perform the display control of the information regarding the software update. ·The display examples of the respective images shown in FIGS. 5 to 8 and FIGS. 10 to 13 were configured to display information in the images using characters. Information may be displayed in these images using expression methods other than characters, such as still images and moving images.
[0085] ·The configurations of the respective images of the first completion notification image (FIG. 8) and the second completion notification image (FIG. 13) can be changed as appropriate. In the above embodiment, information indicating that the power switch 24 can be switched on was displayed in the first completion notification image, but this display may be omitted. Also, in the above embodiment, information indicating that the functions of the in-vehicle devices restricted due to the execution of the activation process became available, specifically, information indicating that the vehicle 10 became drivable, was displayed in the second completion notification image, but this display may be omitted. Assume that the user knows the content of the function restrictions during the activation process in each case when the software update is performed in the first update procedure and when it is performed in the second update procedure. In this case, if the user knows whether the software update was performed in the first update procedure or the second update procedure, the user can know the functions of the vehicle 10 that are released from the restrictions and become available in response to the completion of the activation process. Therefore, the first completion notification image and the second completion notification image are preferably configured so that the user can understand that they notify the completion of the activation process and can distinguish between the two images. If the first completion notification image and the second completion notification image are configured in this way, it is less likely that unexpected function restrictions will occur due to the activation process and the user will be confused.
[0086] ·A common completion image may be displayed after the completion of the activation process regardless of whether the software update is performed in the first update procedure or the second update procedure. · You may choose not to display the completion image after the activation process is completed.
[0087] · The configurations of the first guidance image (Fig. 7) and the second guidance image (Fig. 12) can be changed as appropriate. For example, you may omit the display of the estimated time information until the activation process is completed in the first / second guidance image, or omit the display of the information indicating that the power switch 24 cannot be switched on in the first guidance image. The first guidance image and the second guidance image only need to be configured so that the user can understand that the activation process is in progress and can distinguish between the two images.
[0088] · Even when software updates are performed according to either the first update procedure or the second update procedure, you may choose to display a common guidance image during the execution of the activation process. · You may choose not to display the guidance image during the execution of the activation process.
[0089] · The configurations of the first pre-confirmation image (Fig. 5) and the second pre-confirmation image (Fig. 10) can be changed as appropriate. For example, you may omit the display of the estimated time information of the activation process in the first / second pre-confirmation image. Also, as information on function restrictions associated with the execution of the activation process, you may display information different from the examples shown, or omit the display of the function restriction information. Furthermore, when the activation process is automatically executed without obtaining user permission, or when user permission is obtained before the completion of the installation phase, etc., you may omit the reception display of the selection operation for whether to permit the start of the activation process. In any case, it only needs to be configured as different images so that the user can recognize that it notifies the execution of the activation process in advance and can distinguish between the first pre-confirmation image and the second pre-confirmation image. The same applies to the first final confirmation image (Fig. 6) and the second final confirmation image (Fig. 11).
[0090] ·In the above embodiment, the first / second pre-check images were displayed at the completion of the installation phase, and the first / second final check images were displayed when the power switch 24 could be switched from on to off. It is also possible to display only one of the first / second pre-check images and the first / second final check images.
[0091] ·The OTA master 11 that manages software updates performed display control of information related to software updates. Another in-vehicle device may perform the management of software updates and the display control of information related to software updates.
[0092] ·In the above embodiment, the activation process was carried out either when switching from the driving power mode to the parking power mode or when switching from the parking power mode to the driving power mode. When the power mode of the vehicle 10 includes power modes other than the above two, the activation process may be carried out in response to the switching of the power mode in switching patterns other than the above. If the switching patterns of the power mode for carrying out the activation process are different, the timing of carrying out the activation process is different, so there will be differences in the tolerance and content of the function restrictions of the vehicle 10 associated with its implementation. Therefore, it is desirable to display different confirmation images for each switching pattern of the power mode for carrying out the activation process. Examples of power modes other than the driving and parking power modes include power modes that provide functions during parking that cannot be provided in normal parking power modes such as entertainment functions and external power supply functions for the vehicle. Also, as multiple power modes, it may be configured to include power modes corresponding to the following IG (Ignition) on state, ACC (Accessory power) on state, and vehicle power off state, respectively. The IG on state is a state in which the vehicle engine is operating and the power supplies of a plurality of ECUs are on. The ACC on state is a state in which only the power supplies of some ECUs are on compared to the IG on state. The vehicle power off state is a state in which almost all ECUs are powered off.
[0093] · The control device can be configured as one or more processors operating according to a computer program, one or more dedicated hardware circuits such as dedicated hardware for executing at least a part of various processes, or a combination of these. Examples of the dedicated hardware include, for example, an ASIC which is an application-specific integrated circuit. The processor includes a CPU and memories such as RAM and ROM, and the memories store program codes or instructions configured to cause the CPU to execute processes. The memory, that is, the storage medium, includes any available medium accessible by a general-purpose or dedicated computer.
[0094] <Supplementary Notes> [Supplementary Note 1] A control device for controlling a display unit that displays information regarding software update of in-vehicle equipment mounted on a vehicle having a plurality of switchable power modes, wherein when the software update is performed by a first update procedure in which an activate process for activating the updated software installed in the in-vehicle equipment is performed in response to switching of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activate process; and when the software update is performed by a second update procedure in which the activate process is performed in response to switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activate process.
[0095] [Supplementary Note 2] The control device according to Supplementary Note 1, wherein information on function limitation of the vehicle associated with the execution of the activate process is displayed in the first confirmation image, and information different from the information displayed in the first confirmation image is displayed in the second confirmation image as the information on function limitation.
[0096] [Appendix 3] Information on the period during which the functions of the vehicle are restricted due to the activation process is displayed in the first confirmation image, and information on a period different from the period during which information is displayed in the first confirmation image is displayed in the second confirmation image as information on the period during which the functions of the vehicle are restricted. The control device according to Appendix 1 or Appendix 2.
[0097] [Appendix 4] The first confirmation image and the second confirmation image include a reception display for a selection operation of whether to permit the start of the activation process. The control device according to any one of Appendices 1 to 3.
[0098] [Appendix 5] Based on the type of in-vehicle device to be software-updated, it is determined whether the software update is performed according to the first update procedure or the second update procedure. The control device according to any one of Appendices 1 to 4.
[0099] [Appendix 6] Based on the type of software to be software-updated, it is determined whether the software update is performed according to the first update procedure or the second update procedure. The control device according to any one of Appendices 1 to 5.
[0100] [Appendix 7] The in-vehicle device for which the software update is performed according to the first update procedure and the in-vehicle device for which the software update is performed according to the second update procedure are classified according to the functions of the in-vehicle device. The control device according to any one of Appendices 1 to 6.
[0101] [Appendix 8] When the software update is performed according to the first update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the first switching pattern, and when the software update is performed according to the second update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the second switching pattern. The control device according to any one of Appendices 1 to 7.
[0102] [Appendix 9] The switching of the power mode in the first switching pattern is a switch from the first power mode in which the vehicle can run to the second power mode in which the vehicle cannot run, and the switching of the power mode in the second switching pattern is a switch from the second power mode to the first power mode. The control device according to any one of Appendices 1 to 8.
[0103] [Appendix 10] The switching of the power mode in the first switching pattern is performed in response to the switching of the vehicle's power switch from on to off, and the switching of the power mode in the second switching pattern is performed in response to the switching of the power switch from off to on. The control device according to Appendix 9.
[0104] [Appendix 11] Information on the estimated time from when the power mode is switched to the second power mode until the power mode can be switched to the first power mode is displayed in the first confirmation image. The control device according to Appendix 9 or Appendix 10.
[0105] [Appendix 12] Information on the estimated time from when the switching of the power mode from the second power mode to the first power mode is instructed until the activation process is completed is displayed in the second confirmation image. The control device according to any one of Appendices 9 to 11.
[0106] [Appendix 13] When the software update is performed in the first update procedure, a first guidance image is displayed on the display unit during the execution of the activation process, and when the software update is performed in the second update procedure, a second guidance image different from the first guidance image is displayed on the display unit during the execution of the activation process. The control device according to any one of Appendices 9 to 12.
[0107] [Appendix 14] Information indicating that the power mode cannot be switched to the first power mode is displayed in the first guidance image. The control device according to Appendix 13. [Appendix 15] The control device according to Appendix 13 or Appendix 14, which displays information on the predicted time until the power mode can be switched to the first power mode in the first guidance image.
[0108] [Appendix 16] The control device according to any one of Appendices 13 to 15, which displays information on the predicted time until the completion of the activation process in the second guidance image. [Appendix 17] When the software update is performed in the first update procedure, the control device according to any one of Appendices 9 to 16, which displays a first completion notification image on the display unit after the completion of the activation process; and when the software update is performed in the second update procedure, the control device displays a second completion notification image different from the first completion notification image on the display unit after the completion of the activation process.
[0109] [Appendix 18] The control device according to Appendix 17, which displays information indicating that the power mode can be switched to the first power mode in the first completion notification image. [Appendix 19] The control device according to Appendix 17 or Appendix 18, which displays information indicating that the functions of the in-vehicle device restricted due to the implementation of the activation process have become available in the second completion notification image.
[0110] [Appendix 20] The in-vehicle device in which the software update is performed in the first update procedure is equipped with a single-bank memory module in which the updated software is installed in the storage area storing the software before the update; and the in-vehicle device in which the software update is performed in the second update procedure is equipped with a dual-bank memory module in which the updated software is installed in a storage area different from the storage area storing the software before the update. The control device according to any one of Appendices 9 to 19.
[0111] [Appendix 21] The data communication module for out-of-vehicle communication is the in-vehicle device in which the software update is performed in the second update procedure. The control device according to any one of Appendices 9 to 20. [Appendix 22] The advanced driving assistance system is the control device described in any one of Appendices 9 to 21, which is the in-vehicle device in which the software update is performed in the second update procedure.
[0112] [Appendix 23] The power control unit of the vehicle is the control device described in any one of Appendices 9 to 22, which is the in-vehicle device in which the software update is performed in the second update procedure. [Appendix 24] The display unit is the control device described in any one of Appendices 1 to 23 installed in the vehicle.
[0113] [Appendix 25] The display unit is the control device described in any one of Appendices 1 to 23 provided in an information terminal independent of the vehicle. [Appendix 26] The control device is the control device described in any one of Appendices 1 to 25, which is a server device independent of the vehicle.
[0114] [Appendix 27] A vehicle equipped with the control device described in any one of Appendices 1 to 25. [Appendix 28] A control method for a display unit that displays progress information of software update of an in-vehicle device mounted on a vehicle having a plurality of switchable power modes. When the software update is performed in a first update procedure in which an activate process for activating the updated software installed in the in-vehicle device is performed in accordance with a switch of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activate process. When the software update is performed in a second update procedure in which the activate process is performed in accordance with a switch of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activate process.
[0115] [Appendix 29] The control method according to Appendix 28, wherein information on function limitation of the vehicle associated with the execution of the activate process is displayed in the first confirmation image, and information different from the information displayed in the first confirmation image is displayed in the second confirmation image as the information on function limitation.
[0116] [Appendix 30] Information on the period during which the functions of the vehicle are restricted due to the execution of the activation process is displayed in the first confirmation image, and information on a period different from the period during which information is displayed in the first confirmation image is displayed in the second confirmation image as information on the period during which the functions of the vehicle are restricted. The control method described in Appendix 28 or Appendix 29.
[0117] [Appendix 31] The first confirmation image and the second confirmation image include a reception display for a selection operation of whether to permit the start of the activation process. The control method described in any one of Appendices 28 to 30.
[0118] [Appendix 32] Based on the type of in-vehicle device to be updated with software, it is determined whether the software update is performed according to the first update procedure or the second update procedure. The control method described in any one of Appendices 28 to 31.
[0119] [Appendix 33] Based on the type of software to be updated with software, it is determined whether the software update is performed according to the first update procedure or the second update procedure. The control method described in any one of Appendices 28 to 32.
[0120] [Appendix 34] The in-vehicle device in which the software update is performed according to the first update procedure and the in-vehicle device in which the software update is performed according to the second update procedure are classified according to the functions of the in-vehicle device. The control method described in any one of Appendices 28 to 33.
[0121] [Appendix 35] When the software update is performed according to the first update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the first switching pattern, and when the software update is performed according to the second update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the second switching pattern. The control method described in any one of Appendices 28 to 34.
[0122] [Appendix 36] The switching of the power mode in the first switching pattern is a switching from the first power mode in which the vehicle can run to the second power mode in which the vehicle cannot run, and the switching of the power mode in the second switching pattern is a switching from the second power mode to the first power mode. The control method according to any one of Appendices 28 to 35.
[0123] [Appendix 37] The switching of the power mode in the first switching pattern is performed in response to the switching of the vehicle power switch from on to off, and the switching of the power mode in the second switching pattern is performed in response to the switching of the power switch from off to on. The control method according to Appendix 36.
[0124] [Appendix 38] Information on the estimated time from when the power mode is switched to the second power mode until the power mode can be switched to the first power mode is displayed in the first confirmation image. The control method according to Appendix 36 or Appendix 37.
[0125] [Appendix 39] Information on the estimated time from when the switching of the power mode from the second power mode to the first power mode is instructed until the activation process is completed is displayed in the second confirmation image. The control method according to any one of Appendices 36 to 38.
[0126] [Appendix 40] When the software update is performed in the first update procedure, a first guidance image is displayed on the display unit during the execution of the activation process, and when the software update is performed in the second update procedure, a second guidance image different from the first guidance image is displayed on the display unit during the execution of the activation process. The control method according to any one of Appendices 36 to 39.
[0127] [Appendix 41] Information indicating that it is impossible to switch the power mode to the first power mode is displayed in the first guidance image. The control method according to Appendix 40. [Appendix 42] The control method according to Appendix 40 or Appendix 41, which displays information on the predicted time until the power mode can be switched to the first power mode in the first guidance image.
[0128] [Appendix 43] The control method according to any one of Appendices 40 to 42, which displays information on the predicted time until the activation process is completed in the second guidance image. [Appendix 44] When the software update is performed in the first update procedure, the first completion notification image is displayed on the display unit after the activation process is completed; when the software update is performed in the second update procedure, a second completion notification image different from the first completion notification image is displayed on the display unit after the activation process is completed. The control method according to any one of Appendices 36 to 43.
[0129] [Appendix 45] The control method according to Appendix 44, which displays information indicating that the power mode can be switched to the first power mode in the first completion notification image. [Appendix 46] The control method according to Appendix 44 or Appendix 45, which displays information indicating that the functions of the in-vehicle device restricted due to the implementation of the activation process have become available in the second completion notification image.
[0130] [Appendix 47] The in-vehicle device in which the software update is performed in the first update procedure is equipped with a single-bank memory module in which the updated software is installed in the storage area storing the software before the update; the in-vehicle device in which the software update is performed in the second update procedure is equipped with a dual-bank memory module in which the updated software is installed in a storage area different from the storage area storing the software before the update. The control method according to any one of Appendices 36 to 46.
[0131] [Appendix 48] The data communication module for out-of-vehicle communication is the in-vehicle device in which the software update is performed in the second update procedure. The control method according to any one of Appendices 36 to 47.
[0132] [Appendix 49] The advanced driving assistance system is a control method described in any one of Appendices 36 to 48, which is the in-vehicle device in which the software update is performed in the second update procedure. [Appendix 50] The power control unit of the vehicle is a control method described in any one of Appendices 36 to 49, which is the in-vehicle device in which the software update is performed in the second update procedure.
[0133] [Appendix 51] The display unit is a control method described in any one of Appendices 28 to 50, which is installed in the vehicle. [Appendix 52] The display unit is a control method described in any one of Appendices 28 to 51, which is provided in an information terminal independent of the vehicle.
[0134] [Appendix 53] A program executed by a control device that controls a display unit that displays progress information of software update of an in-vehicle device mounted on a vehicle having a plurality of switchable power modes. When the software update is performed in a first update procedure in which an activate process for activating the updated software installed in the in-vehicle device is performed in accordance with a switch of the power mode in a first switching pattern, a first display process for causing the display unit to display a first confirmation image before the start of the activate process; and when the software update is performed in a second update procedure in which the activate process is performed in accordance with a switch of the power mode in a second switching pattern different from the first switching pattern, a second display process for causing the display unit to display a second confirmation image different from the first confirmation image before the start of the activate process, and causing the control device to execute the program.
[0135] [Appendix 54] The first display process is a process of displaying information on function limitation of the vehicle associated with the execution of the activate process in the first confirmation image, and the second display process is a process of displaying, in the second confirmation image, information different from the information displayed in the first confirmation image as the information on function limitation, which is the program described in Appendix 53.
[0136] [Appendix 55] The first display process is a process of displaying, within the first confirmation image, information on a period during which the functions of the vehicle are restricted as a result of performing the activation process, and the second display process is a process of displaying, within the second confirmation image, information on a period different from the period during which information is displayed within the first confirmation image, as information on a period during which the functions of the vehicle are restricted. The program according to Appendix 53 or Appendix 54.
[0137] [Appendix 56] The first display process is a process of displaying, within the first confirmation image, a reception display for a selection operation of whether to permit the start of the activation process, and the second display process is a process of displaying the reception display within the second confirmation image. The program according to any one of Appendices 53 to 55.
[0138] [Appendix 57] A process of causing the control device to execute a process of determining, based on the type of in-vehicle device to be subjected to software update, whether the software update is to be performed according to the first update procedure or the second update procedure. The program according to any one of Appendices 53 to 56.
[0139] [Appendix 58] A process of causing the control device to execute a process of determining, based on the type of software to be subjected to software update, whether the software update is to be performed according to the first update procedure or the second update procedure. The program according to any one of Appendices 53 to 57.
[0140] [Appendix 59] When the software update is performed according to the first update procedure, a process of starting the activation process of the in-vehicle device in response to the switching of the power mode in the first switching pattern, and when the software update is performed according to the second update procedure, a process of starting the activation process of the in-vehicle device in response to the switching of the power mode in the second switching pattern. The program according to any one of Appendices 53 to 58 to be executed by the control device.
[0141] [Appendix 60] The switching of the power mode in the first switching pattern is a switch from the first power mode in which the vehicle can run to the second power mode in which the vehicle cannot run, and the switching of the power mode in the second switching pattern is a switch from the second power mode to the first power mode. The program according to any one of Appendices 53 to 59.
[0142] [Appendix 61] The switching of the power mode in the first switching pattern is performed in response to the switching of the vehicle's power switch from on to off, and the switching of the power mode in the second switching pattern is performed in response to the switching of the power switch from off to on. The program according to Appendix 60.
[0143] [Appendix 62] The first display process is a process of displaying information on the expected time from when the power mode is switched to the second power mode until the power mode can be switched to the first power mode in the first confirmation image. The program according to Appendix 60 or Appendix 61.
[0144] [Appendix 62] The second display process is a process of displaying information on the expected time from when the switching of the power mode from the second power mode to the first power mode is instructed until the activation process is completed in the second confirmation image. The program according to any one of Appendices 60 to 62.
[0145] [Appendix 63] When the software update is performed in the first update procedure, a third display process of displaying a first guidance image on the display unit during the execution of the activation process, and when the software update is performed in the second update procedure, a fourth display process of displaying a second guidance image different from the first guidance image on the display unit during the execution of the activation process, are executed by the control device. The program according to any one of Appendices 53 to 62.
[0146] [Supplementary Note 64] The third display process is the program described in Supplementary Note 63, which is a process of displaying information indicating that it is impossible to switch the power mode to the first power mode within the first guidance image.
[0147] [Supplementary Note 65] The third display process is the program described in Supplementary Note 63 or Supplementary Note 64, which is a process of displaying information on the estimated time until the power mode can be switched to the first power mode within the first guidance image.
[0148] [Supplementary Note 66] The fourth display process is the program described in any one of Supplementary Notes 63 to 65, which is a process of displaying information on the estimated time until the completion of the activation process within the second guidance image.
[0149] [Supplementary Note 67] When the software update is performed in the first update procedure, a fifth display process of displaying a first completion notification image on the display unit after the completion of the activation process, and when the software update is performed in the second update procedure, a sixth display process of displaying a second completion notification image different from the first completion notification image on the display unit after the completion of the activation process, are executed by the control device, which is the program described in any one of Supplementary Notes 53 to 66.
[0150] [Supplementary Note 68] The fifth display process is the program described in Supplementary Note 67, which is a process of displaying information indicating that the power mode has become switchable to the first power mode within the first completion notification image.
[0151] [Supplementary Note 69] The sixth display process is the program described in Supplementary Note 67 or Supplementary Note 68, which is a process of displaying information indicating that the functions of the in-vehicle device restricted due to the implementation of the activation process have become available within the second completion notification image.
[0152] [Supplementary Note 70] A storage medium storing the program described in any one of Supplementary Notes 53 to 69.
Explanation of Reference Signs
[0153] 10 Vehicles 11 OTA Master (Control Device, In-Vehicle Device) 12 DCM (In-Vehicle Device) 13 ADAS (In-Vehicle Device) 14 PCU (In-Vehicle Device) 15 Engine ECU (In-Vehicle Device) 16 Transmission ECU (In-Vehicle Device) 17 Brake ECU (In-Vehicle Device) 18 HMI (In-Vehicle Device) 19 In-Vehicle Network 20 Mobile Communication Network 21 Memory Module 22 Processor 23 Data Storage 24 Power Switch 30 OTA Server 31 Storage Device 32 Processor 40 Information Terminal 41 Storage Device 42 Processor 43 HMI B, B1, B2 Memory Areas
Claims
1. A control device for controlling a display unit that displays information related to software update of in-vehicle equipment mounted on a vehicle having a plurality of switchable power modes, when the software update is performed by a first update procedure in which an activate process for activating the updated software installed in the in-vehicle equipment is performed in accordance with switching of the power mode in a first switching pattern, causing a first confirmation image to be displayed on the display unit before the start of the activate process; when the software update is performed by a second update procedure in which the activate process is performed in accordance with switching of the power mode in a second switching pattern different from the first switching pattern, causing a second confirmation image different from the first confirmation image to be displayed on the display unit before the start of the activate process; A control device that performs the above.
2. Displaying information on the vehicle's function restrictions associated with the implementation of the activate process within the first confirmation image, and displaying information different from the information displayed within the first confirmation image as information on the vehicle's function restrictions within the second confirmation image The control device according to claim 1.
3. Displaying information on the period during which the vehicle's functions are restricted due to the implementation of the activate process within the first confirmation image, and displaying information on a period different from the period for which information is displayed within the first confirmation image as information on the period during which the vehicle's functions are restricted within the second confirmation image. The control device according to claim 1.
4. The control device according to claim 1, wherein the first confirmation image and the second confirmation image include a reception display for a selection operation of whether to permit the start of the activate process.
5. The control device according to claim 1, determining whether the software update is performed by the first update procedure or the second update procedure based on the type of the in-vehicle equipment to be the target of the software update.
6. The control device according to claim 1, determining whether the software update is performed by the first update procedure or the second update procedure based on the type of the software to be the target of the software update.
7. The control device according to claim 1, wherein the in-vehicle equipment for which the software update is performed by the first update procedure and the in-vehicle equipment for which the software update is performed by the second update procedure are classified according to the functions of the in-vehicle equipment.
8. When the software update is performed in the first update procedure, start the activation process of the in-vehicle device in response to the switching of the power mode in the first switching pattern. When the software update is performed in the second update procedure, start the activation process of the in-vehicle device in response to the switching of the power mode in the second switching pattern. The control device according to claim 1, which performs the above.
9. The switching of the power mode in the first switching pattern is a switching from a first power mode in which the vehicle can run to a second power mode in which the vehicle cannot run. The switching of the power mode in the second switching pattern is a switching from the second power mode to the first power mode. The control device according to claim 1.
10. The switching of the power mode in the first switching pattern is performed in response to the switching of the vehicle's power switch from on to off. The switching of the power mode in the second switching pattern is performed in response to the switching of the power switch from off to on. The control device according to claim 9.
11. The control device according to claim 9, which displays information on the expected time from when the power mode is switched to the second power mode until the power mode can be switched to the first power mode in the first confirmation image.
12. The control device according to claim 9, which displays information on the expected time from when the switching of the power mode from the second power mode to the first power mode is instructed until the activation process is completed in the second confirmation image.
13. When the software update is performed in the first update procedure, display a first guidance image on the display unit during the execution of the activation process. When the software update is performed in the second update procedure, display a second guidance image different from the first guidance image on the display unit during the execution of the activation process. The control device according to claim 9, which performs the above.
14. The control device according to claim 13, which displays information indicating that the power mode cannot be switched to the first power mode in the first guidance image.
15. The control device according to claim 13, which displays information on the expected time until the power mode can be switched to the first power mode in the first guidance image.
16. The control device according to claim 13, which causes information on the estimated time until completion of the activation process to be displayed in the second guidance image.
17. When the software update is performed in the first update procedure, causing a first completion notification image to be displayed on the display unit after completion of the activation process; When the software update is performed in the second update procedure, causing a second completion notification image different from the first completion notification image to be displayed on the display unit after completion of the activation process; The control device according to claim 9, which performs the above.
18. The control device according to claim 17, which causes information indicating that the power mode has been switched to the first power mode to be displayed in the first completion notification image.
19. The control device according to claim 17, which causes information indicating that the functions of the in-vehicle device restricted with the implementation of the activation process have become available to be displayed in the second completion notification image.
20. The in-vehicle device in which the software update is performed in the first update procedure includes a single-bank storage module in which the updated software is installed in a storage area storing the software before update, The in-vehicle device in which the software update is performed in the second update procedure includes a dual-bank storage module in which the updated software is installed in a storage area different from the storage area storing the software before update The control device according to claim 9 or 10.
21. The data communication module for vehicle-to-vehicle communication is the in-vehicle device in which the software update is performed in the second update procedure according to claim 9.
22. The advanced driving assistance system is the in-vehicle device in which the software update is performed in the second update procedure according to claim 9.
23. The power control unit of the vehicle is the in-vehicle device in which the software update is performed in the second update procedure according to claim 9.
24. The display unit is the control device according to claim 1, which is installed in the vehicle.
25. The display unit is the control device according to claim 1, which is provided in an information terminal independent of the vehicle.
26. The control device is the control device according to claim 1, which is a server device independent of the vehicle.
27. A vehicle including the control device according to claim 1.
28. A control method for a display unit that displays progress information of software update of in-vehicle equipment mounted on a vehicle having a plurality of switchable power modes, when the software update is performed by a first update procedure in which an activate process for activating the updated software installed in the in-vehicle equipment is performed in accordance with switching of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activate process, when the software update is performed by a second update procedure in which the activate process is performed in accordance with switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activate process Control method.
29. A program executed by a control device that controls a display unit that displays progress information of software update of in-vehicle equipment mounted on a vehicle having a plurality of switchable power modes, a first display process for displaying a first confirmation image on the display unit before the start of the activate process when the software update is performed by a first update procedure in which an activate process for activating the updated software installed in the in-vehicle equipment is performed in accordance with switching of the power mode in a first switching pattern, a second display process for displaying a second confirmation image different from the first confirmation image on the display unit before the start of the activate process when the software update is performed by a second update procedure in which the activate process is performed in accordance with switching of the power mode in a second switching pattern different from the first switching pattern, A program for causing the control device to execute.
Citation Information
Patent Citations
Electronic control device, electronic control system for vehicle, method for controlling execution of activation, and program for controlling execution of activation
JP2020027632A
Electronic control device, method for controlling execution of rewriting, and program for controlling execution of rewriting
JP2020027640A
Electronic control system for vehicle, and method and program for controlling execution of self holding of power source
JP2020027643A
High voltage connector assembly and electric compressor include the same
KR1020210004206A
OTA master, update control method, update control program, and OTA center
JP2022163396A