Controller, control method, and program

The control device addresses the issue of aborted software updates by displaying suspension information on a vehicle's display unit, helping users understand the update status and facilitating resumption.

JP2025088315AActive Publication Date: 2025-06-11TOYOTA JIDOSHA KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2023202944
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-06-11
Estimated Expiration
2043-11-30

AI Technical Summary

Technical Problem

Software update processing for in-vehicle devices may be aborted due to various factors, leaving users confused about the status of the update when they return to their vehicle.

Method used

A control device that controls a display unit to show suspension information when software update processing is hindered during a power-off operation, allowing users to understand the update status and take necessary actions.

Benefits of technology

Facilitates user understanding of software update suspension and provides clear guidance on how to resume the update process, enhancing user experience and clarity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025088315000001_ABST
    Figure 2025088315000001_ABST
Patent Text Reader

Abstract

To allow a user to easily recognize the situation when software update on in-vehicle equipment is suspended.SOLUTION: In software update in which software on in-vehicle equipment is updated in response to a predetermined operation to turn of the in-vehicle equipment, when the predetermined operation is performed but a situation hampering execution of the update process is occurring, the OTA master 11 causes an HMI 18 to display suspension information indicating that the update process is not being executed. A user can recognize that the update process has been suspended from the suspension information displayed on the HMI 18.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a control device, a control method, and a program for controlling a display unit that displays information regarding software updates of in-vehicle devices mounted on a vehicle.

Background Art

[0002] Various in-vehicle devices that operate by executing software are mounted on a vehicle. As seen in Patent Document 1, an OTA (Over The Air) technology is known in which the software of an in-vehicle device is updated by software downloaded from outside the vehicle via wireless communication, thereby adding or changing the functions of the vehicle.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] After the power-off operation of the vehicle, software update processing may be executed. On the other hand, the software update processing may be aborted due to various factors. If the update processing is aborted while the user of the vehicle has gotten out of the vehicle, the user may be confused and unable to grasp the situation when getting in the vehicle next time.

Means for Solving the Problems

[0005] The control device for solving the above problems is a control device that controls a display unit for displaying information related to software update of in-vehicle devices mounted on a vehicle. In software update in which update processing of the software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, it is configured to cause the display unit to display suspension information indicating that the update processing has not been executed.

[0006] The control method for solving the above problems is a control method for a display unit that displays information related to software update of in-vehicle devices mounted on a vehicle. In software update in which update processing of the software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, it causes the display unit to display suspension information indicating that the update processing has not been executed.

[0007] The program for solving the above problems is a program executed by a control device that controls a display unit for displaying information related to software update of in-vehicle devices mounted on a vehicle. In software update in which update processing of the software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, it is configured to cause the control device to execute causing the display unit to display suspension information indicating that the update processing has not been executed.

Advantages of the Invention

[0008] The above control device, control method, and program have an effect of facilitating the user's understanding of the situation when the software update of the in-vehicle device is suspended.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Mode for Carrying Out the Invention

[0010] (First Embodiment) Hereinafter, the first embodiment of the control device, vehicle, control method, and program will be described in detail with reference to FIGS. 1 to 5.

[0011] <Configuration of Control Device and Vehicle> First, referring to FIG. 1, the configuration of the control device and the vehicle according to this embodiment will be described. As shown in FIG. 1, the vehicle 10 is equipped with in-vehicle devices such as an OTA master 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18. These in-vehicle devices are communicably connected to each other via an in-vehicle network 19. The OTA master 11 is in charge of managing software updates for the in-vehicle devices including itself. The DCM 12 is a data communication module (Data Communication Module) that provides a wireless communication function with the outside of the vehicle via a mobile communication network 20. In the case of this embodiment, the DCM 12 is responsible for recording the results of self-diagnostics performed by each in-vehicle device of the vehicle 10 and transmitting them to an external data center or the like. The ADAS 13 is an advanced driving assistance system (Advanced Driving Assistant System) that provides advanced driving assistance functions such as an automatic braking device and a sudden acceleration prevention device. The PCU 14 is a power control unit (Power Control Unit) that performs power control inside the vehicle. The engine ECU 15 is an electronic control unit (Electronic Control Unit) for engine control. The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a human machine interface (Human Machine Interface). The HMI 18 includes an input device that receives operations from passengers and a display device that displays information to passengers by means of images and sounds. The HMI 18 may be configured to include a navigation function for guiding a driving route and an entertainment function for playing music and videos. Each of these in-vehicle devices has a storage module 21 in which software is stored and a processor 22 that executes the software. The OTA master 11 further has a data storage 23 that stores updated software acquired from the outside of the vehicle.

[0012] Vehicle 10 has multiple power modes. The multiple power modes include a power mode for driving and a power mode for parking. For each power mode, it is determined which in-vehicle devices are to have their power turned on. When setting the power mode for driving, the power of the in-vehicle devices necessary for the driving of vehicle 10 and the provision of services during driving is turned on. In the case of this embodiment, when setting the power mode for driving, the power of all the in-vehicle devices shown in FIG. 1 is turned on. When setting the power mode for parking, the power is turned on only for the in-vehicle devices that need to operate even when vehicle 10 is parked. The in-vehicle devices whose power is turned on in each power mode can be changed according to the environment and user settings.

[0013] Vehicle 10 is provided with a power switch 24 for switching between the power mode for driving and the power mode for parking. The switching from the power mode for driving to the power mode for parking is performed in response to the switching of the power switch 24 from on to off. The switching from the power mode for parking to the power mode for driving is performed in response to the switching of the power switch 24 from off to on. The power switch 24 may be called an ignition switch in a conventional vehicle that uses only an engine as a drive source. Also, in a vehicle capable of electric driving such as a BEV or PHEV, the power switch 24 may be called a Ready switch.

[0014] Also, vehicle 10 is provided with a power switch 24 for switching between turning on and turning off the power of vehicle 10. The drive system of vehicle 10 starts in response to the switching from off to on of the power, and stops in response to the switching from on to off of the power.

[0015] Vehicle 10 is connected to an OTA server 30 via a mobile communication network 20. The OTA server 30 is a server device that distributes updated software for in-vehicle devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing the updated software, and a processor 32 that executes the program for distribution.

[0016] The OTA server 30 can communicate with the information terminal 40 of the user of the vehicle 10 via the mobile communication network 20. Examples of the information terminal 40 include smartphones. The information terminal 40 may be a tablet terminal or a PC terminal. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes the software stored in the storage device 41. The HMI 43 includes an input device that receives the user's operation and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as information confirmation and remote operation of the vehicle 10 owned by the user.

[0017] <Overview of Software Update> Next, an overview of the software update of in-vehicle devices in the vehicle 10 will be described. The in-vehicle devices subject to software update include the OTA master 11, DCM 12, ADAS 13, PCU 14, engine ECU 15, transmission ECU 16, brake ECU 17, and HMI 18. The software update is performed through a download phase, an install phase, and an activate phase.

[0018] In the download phase, the updated software is transmitted from the OTA server 30 to the vehicle 10. The OTA master 11 stores the updated software received from the OTA server 30 in the data storage 23. The download phase includes a series of processes related to download, such as determining whether to execute the download and verifying the update data. The transmission of the updated software from the OTA server 30 to the OTA master 11 may be performed by transmitting compressed data obtained by compressing the updated software, or by transmitting divided data obtained by dividing the updated software or the compressed data. Also, the updated software of a plurality of in-vehicle devices may be transmitted together.

[0019] In the installation phase, update software is installed on the in-vehicle device to be updated. In the installation phase, the OTA master 11 installs the update software on the storage module 21 of the in-vehicle device to be updated based on the update data downloaded to the data storage 23. The installation phase includes a series of processes related to installation, such as determining whether installation can be executed, transferring update data, and verifying the update software. When the update data includes the update software itself, in the installation phase, the OTA master 11 transfers the update data to the in-vehicle device to be updated. When the update data includes compressed data, differential data, or split data of the update software, a generation process of the update software from the update data is performed. The generation process may be performed by the OTA master 11 or by the in-vehicle device to be updated. The generation of the update software can be performed by decompressing the compressed data or assembling the differential data or split data. Note that at the end of the installation phase, the update software is invalidated.

[0020] In the activation phase, activation of the update software, that is, validation of the update software, is performed on the in-vehicle device to be updated. The activation phase includes a series of processes related to activation, such as determining whether activation can be executed, checking the integrity of the update software, and verifying the execution result of activation.

[0021] Depending on the hardware configuration and software type of the in-vehicle device, etc., software update processing may be executed in response to a power-off operation of the vehicle 10. In the case of this embodiment, the update processing includes the processing of both the installation phase and the activation phase. The update processing may be processing that includes only one of the installation phase and the activation phase.

[0022] When the download phase is completed, the OTA master 11 asks the user through the HMI 18 whether the update process may be executed after the next power-off operation. If the user permits the execution of the update process in response to this query, the OTA master 11 starts the update process when an operation to turn off the power of the vehicle 10 is then performed. Here, the in-vehicle device that starts the update process is an in-vehicle device that turns off the power in response to an operation to turn off the power of the vehicle 10. In the case of the present embodiment, the operation to turn off the power of the vehicle 10 corresponds to a predetermined operation to turn off the power of the in-vehicle device on which the software update is to be executed.

[0023] Depending on the situation, the execution of the update process may be prevented when the power-off operation of the vehicle 10 is performed. The situation where the execution of the update process is prevented is, for example, a situation where the power of the in-vehicle device to be updated cannot be turned off even after the power-off operation of the vehicle 10. Specific examples of such situations include the following situations (A) to (C).

[0024] Situation (A) is a situation where the execution of software update processing is hindered in relation to the slip-down prevention control of the vehicle 10 parked on a slope road. When the vehicle 10 is parked on a slope road with a large gradient, the vehicle 10 may slip down due to insufficient effectiveness of the parking brake or the like. Some vehicles 10 perform control to suppress the slip-down of the vehicle 10 by operating the hydraulic brake or steering when detecting the start of movement of the vehicle 10 while parked on a slope road. The slip-down prevention control is executed when the vehicle 10 is parked on a slope road that satisfies a predetermined condition. An example of the predetermined condition is that the gradient of the slope road on which the vehicle 10 is parked is equal to or greater than a predetermined value. When the slip-down prevention control is being executed, the in-vehicle devices related to the execution continue to operate even after the power-off operation of the vehicle 10. When the slip-down prevention control is being executed, the software update processing of the in-vehicle devices related to the execution may not be executable. Also, to complete the installation and activation in the update processing, it is necessary to turn off the power of the in-vehicle device once and restart the in-vehicle device. On the other hand, when the slip-down prevention control is being executed, since the power of the in-vehicle devices related to the slip-down prevention control cannot be turned off even after the power-off operation of the vehicle 10, the update processing may not be executable in some cases. The in-vehicle devices related to the execution of slip-down prevention are in-vehicle devices that monitor the movement of the parked vehicle 10, in-vehicle devices that perform braking or steering of the vehicle 10, and the like. In the case of FIG. 1, the ADAS 13 and the brake ECU 17 are in-vehicle devices related to the execution of the slip-down prevention control.

[0025] Situation (B) is a situation where the execution of update processing is hindered in relation to the emergency notification system of the vehicle 10. The emergency notification system is a system that monitors the parked vehicle 10 and notifies the outside when an abnormality occurs. During the operation of the emergency notification system, the in-vehicle devices related to the operation of the system continue to operate and cannot be powered off even after the power-off operation of the vehicle 10, so software updates cannot be executed. In the case of FIG. 1, the DCM 12 and the ADAS 13 are in-vehicle devices related to the operation of the emergency notification system. Note that whether to operate the emergency notification system or not can be switched by the user.

[0026] Situation (C) is a situation where the execution of the update process is prevented in relation to the power supply setting of the HMI 18 during the period when the power supply of the vehicle 10 is off. The HMI 18 is configured to be able to switch the power supply setting after the power off operation of the vehicle 10 to the following first state and second state. The first state is a sleep state where, after the power off operation of the vehicle 10, the screen dims, but a part of the functions continues to operate and display can be performed according to an external command or the like. The second state is a shutdown state where the power supply of the HMI 18 itself is turned off in response to the power off operation of the vehicle 10 and display cannot be performed. The HMI 18 is configured such that the user can switch such power supply settings. In the case of the present embodiment, during the software update process in response to the power off operation of the vehicle 10, information related to the update is displayed on the HMI 18. When the power supply setting of the HMI 18 is in the second state (shutdown state), the information display during the update process cannot be performed. Therefore, when the power supply setting of the HMI 18 is in the second state, the update process in response to the power off operation of the vehicle 10 is not executed.

[0027] <Display control of information according to update process> The OTA master 11 executes display control of information to be displayed on the HMI 18 during the update process. The details of the display control will be described below.

[0028] FIG. 2 shows the processing procedure of the display control routine executed by the OTA master 11 for display control of information according to the update process. The OTA master 11 starts this routine in response to the user's permission to execute the update process.

[0029] After starting this routine, the OTA master 11 waits until a power off operation of the vehicle 10 is performed and the update process is started (S10). When the update process is started (S10: YES), the OTA master 11 causes the HMI 18 to display guidance information indicating that the update process is in progress (S11). Thereafter, when the update process is completed (S13: YES), the OTA master 11 causes the HMI 18 to display guidance information indicating that the update process has been completed (S14), and then ends the processing of this routine.

[0030] On the other hand, if the execution of the above update process is interrupted due to a situation where the execution of the update process is hindered (S12: YES), the OTA master 11 causes the HMI 18 to display suspension information indicating that the update process has not been executed (S15). After that, the OTA master 11 waits for the above situation to be resolved and the update process to resume (S16). When the update process resumes (S16: YES), the OTA master 11 returns the process to S11. In this case, the OTA master 11 causes the HMI 18 to display guidance information indicating that the update process is being executed in S11 of FIG. 2. By viewing this guidance information after seeing the suspension information, the user can grasp that the suspended update process has become executable. Thus, in the present embodiment, when the situation that hinders the execution of the update process is resolved after the display of the suspension information, the information to be displayed on the HMI 18 is changed from the suspension information to guidance information indicating that the update process is executable.

[0031] Note that when the power-off operation of the vehicle 10 is performed, there may be a situation where a situation that already hinders the execution of the update process has occurred. In such a case, the OTA master 11 causes the HMI 18 to display suspension information without starting the update process.

[0032] FIG. 3 shows an example of an image for displaying guidance information indicating that the update process is being executed. In the image of FIG. 3, information indicating the progress of the update process is displayed together with the guidance information indicating that the update process is being executed. Further, in the image of FIG. 3, information for alerting the user that the power-on operation of the vehicle 10 cannot be performed until the update process is completed is displayed.

[0033] FIG. 4 shows an example of an image for displaying guidance information indicating that the update process has been completed. In the image of FIG. 4, information notifying that the functions of the updated in-vehicle devices have become available is displayed together with the guidance information indicating that the update process has been completed. Further, in the image of FIG. 4, operation buttons for confirming the detailed information of the software update are displayed.

[0034] FIG. 5 shows an example of an image that displays suspension information indicating that the update process is not being executed. In the image of FIG. 5, operation buttons for displaying more detailed information are shown together with the suspension information. When this operation button is operated, more detailed suspension information is displayed on the HMI 18. The information displayed at this time includes information indicating the reason for suspending the update process and information indicating the user operations required to resume the update process. For example, in the case of situation (A), the fact that the vehicle is stopped on a steep slope is preventing the execution of the update process, and the fact that the update process can be resumed by stopping the vehicle 10 again on a flat place is displayed on the HMI 18 as detailed suspension information. In the case of situation (B), the fact that the emergency notification system is operating is preventing the execution of the update process, and the fact that the update process can be resumed by stopping the operation of the emergency notification system is displayed on the HMI 18 as detailed suspension information. In the case of situation (C), the fact that the power setting of the HMI 18 is in the shutdown state is preventing the execution of the update process, and the fact that the update process can be resumed by switching the power setting to the standby state is displayed on the HMI 18 as detailed suspension information.

[0035] <Operations and Effects of the Embodiment> The operations and effects of this embodiment will be described. The OTA master 11 starts the update process in response to a power-off operation of the vehicle 10. When the OTA master 11 starts the update process, it causes the HMI 18 to display guidance information indicating that the update process is in progress. Further, when the update process is completed, the OTA master 11 causes the HMI 18 to display guidance information indicating that the update process has been completed.

[0036] There are cases where the execution of the update process may be aborted because a situation that hinders the execution of the update process has occurred. In this case, the OTA master 11 causes the HMI 18 to display abort information indicating that the update process has not been executed. The user can confirm from this display that the update process has been aborted. Also, when the update process is aborted, the OTA master 11 causes the HMI 18 to display information indicating the reason for the abort of the update process and the operations required of the user to resume the update process. By operating according to the displayed information, the user can resume the update process.

[0037] According to the above-described embodiment, the following effects can be obtained. (1) The OTA master 11 performs software update of in-vehicle devices so as to execute the software update process of in-vehicle devices in response to a predetermined operation of turning off the power of the in-vehicle devices. When a situation occurs in which the execution of the update process is hindered when the predetermined operation is performed, the OTA master 11 causes the HMI 18 to display abort information indicating that the update process has not been executed. Therefore, it becomes easy for the user to grasp the situation when the software update of the in-vehicle device is aborted.

[0038] (2) When the situation that hinders the execution of the update process is resolved after the display of the abort information, the OTA master 11 changes the information to be displayed on the HMI 18 from the abort information to guidance information indicating that the update process can be executed. Therefore, it becomes easy for the user to grasp the situation when the update process that has once been aborted becomes executable.

[0039] (3) The detailed abort information that the OTA master 11 causes to be displayed on the HMI 18 includes information indicating the content of the situation that hinders the execution of the update process and information indicating a method for resolving the situation. Therefore, it becomes easy for the user to resume the update process.

[0040] (Second Embodiment) Next, a second embodiment of the control device, control method, and program will be described in detail with reference to FIG. 6. In this embodiment, components common to the above embodiment are denoted by the same reference numerals, and detailed descriptions thereof are omitted.

[0041] In the case of the first embodiment, the OTA master 11 caused the HMI 18 installed in the vehicle 10 to display information regarding the update process. In the case of this embodiment, information regarding the update process is displayed on the HMI 43 of the information terminal 40 owned by the user of the vehicle 10. And the OTA server 30 of the data center performs the display control.

[0042] FIG. 6 shows the flow of processing related to the display control of information regarding the update process in this embodiment. In the case of FIG. 6, the update process of in-vehicle devices is started in response to the power-off operation of the vehicle 10 (S20). The vehicle 10 notifies the OTA server 30 that the update process has been started (S21). In response to the notification, the OTA server 30 instructs the information terminal 40 to display guidance information indicating that the update process is in progress (S22). The information terminal 40 starts displaying the guidance information in response to the instruction (S23). At this time, an image according to FIG. 3 is displayed on the information terminal 40.

[0043] In the case of FIG. 6, thereafter, a situation that hinders the execution of the update process occurs in the vehicle 10 and the update process is aborted. At this time, the vehicle 10 notifies the OTA server 30 that the update process has been aborted (S24). In response to the notification, the OTA server 30 instructs the information terminal 40 to display abort information (S25). The information terminal 40 switches the information to be displayed from the above guidance information to the abort information in response to the instruction (S26). As a result, an image according to FIG. 5 is displayed on the information terminal 40.

[0044] After that, in the vehicle 10, the update process is resumed (S28). At this time, the vehicle 10 notifies the OTA server 30 of the resumption of the update process (S27). In response to the notification, the OTA server 30 instructs the information terminal 40 to display information indicating that the update process is in progress (S29). In response to the instruction, the information terminal 40 switches the information to be displayed from the suspension information to the guidance information indicating that the update process is in progress (S30).

[0045] In the case of FIG. 6, thereafter, the update process continues until completion. When the update process is completed, the vehicle 10 notifies the OTA server 30 of the completion of the update process (S31). In response to the notification, the OTA server 30 instructs the information terminal 40 to display guidance information indicating the completion of the update process (S32). In response to the instruction, the information terminal 40 switches the information to be displayed to the guidance information indicating the completion of the update process (S33).

[0046] In the case of this embodiment, the user can confirm information regarding the update process on the information terminal 40. Also in the case of this embodiment, the same operations and effects as those of the first embodiment can be achieved. The display control of information on the information terminal 40 in this embodiment may be executed together with the display control of information on the HMI 18 of the vehicle 10 in the first embodiment.

[0047] (Other Embodiments) The above embodiment can be implemented with the following modifications. The above embodiment and the following modification examples can be implemented in combination with each other within a technically consistent range.

[0048] · When resuming a suspended update process, user permission may be requested. In this case, when the situation that hinders the execution of the update process is resolved, for example, an image as shown in FIG. 7 may be displayed on the HMI 18 or the information terminal 40, and the user may be asked whether to resume the update process. When such an image is displayed, the user can confirm that the update process that was once suspended can now be executed. Therefore, the image for asking the user whether to resume the update process includes guidance information indicating that the update process can be executed.

[0049] · The display examples of each image shown in FIGS. 3 to 5 and FIG. 7 were configured to display information using characters. Those images may be configured to display information using expressions other than characters, such as still images and moving images.

[0050] · The suspension information may not include one or both of the information indicating the content of the situation preventing the execution of the update process and the information indicating the method for resolving the situation. The suspension information only needs to include at least the information indicating that the update process has not been executed.

[0051] · The OTA master 11 that manages software updates has been performing display control of information related to software updates. The management of software updates and the display control of information related to software updates may be performed by different in-vehicle devices. For example, the display control of the information of the HMI 18 in the first embodiment may be performed by the in-vehicle device that is the target of software update.

[0052] · In the above embodiment, the case where the power supply of the in-vehicle device that executes the software update process is configured to turn off in conjunction with the off operation of the power switch 24 of the vehicle 10 has been described. There may be a case where the in-vehicle device is configured to turn off the power supply in response to other operations. For example, the vehicle 10 may have three power modes corresponding to the following IG (Ignition) on state, ACC (Accessory power) on state, and vehicle power off state, respectively. The IG on state is a state where the vehicle engine is operating and the power supplies of a plurality of ECUs are on. The ACC on state is a state where only the power supplies of some ECUs are on compared to the IG on state. The vehicle power off state is a state where almost all ECUs are powered off. In this case, it is conceivable to start the software update process of the in-vehicle device whose power supply turns off in response to the switching operation from the IG on state to the ACC on state. If the suspension information is also displayed when a situation occurs where the execution of the update process is hindered when the switching operation from the IG on state to the ACC on state is performed, the effect of facilitating the user's understanding of the situation can be obtained. Thus, the display of the suspension information in the above embodiment may be performed in the following cases. That is, in the software update in which the software update process of the in-vehicle device is executed in response to a predetermined operation for turning off the power supply of the in-vehicle device, when a situation occurs where the execution of the update process is hindered when the predetermined operation is performed.

[0053] · The control device can be configured as a circuit including one or more processors that operate according to a computer program, one or more dedicated hardware circuits such as dedicated hardware for executing at least a part of various processes, or a combination thereof. Examples of the dedicated hardware include, for example, an ASIC (Application Specific Integrated Circuit) which is an integrated circuit for a specific purpose. The processor includes a CPU and memories such as a RAM and a ROM, and the memories store program codes or instructions configured to cause the CPU to execute processes. The memory, that is, the storage medium, includes any available medium that can be accessed by a general-purpose or dedicated computer.

[0054] (Supplementary Note) [Supplementary Note 1] A control device that controls a display unit for displaying information on software update of in-vehicle devices mounted on a vehicle. In software update where the update process of the software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which the execution of the update process is hindered when the predetermined operation is performed, the control device causes the display unit to display suspension information indicating that the update process has not been executed.

[0055] [Supplementary Note 2] The control device according to Supplementary Note 1, wherein the predetermined operation is an operation for turning off the power of the vehicle. [Supplementary Note 3] The control device according to Supplementary Note 1 or Supplementary Note 2, wherein when the situation is resolved after the suspension information is displayed on the display unit, the information to be displayed on the display unit is changed from the suspension information to guidance information indicating that the update process can be executed.

[0056] [Supplementary Note 4] The control device according to any one of Supplementary Notes 1 to 3, wherein the situation is a situation in which the power of the in-vehicle device cannot be turned off even after the predetermined operation is performed. [Supplementary Note 5] The control device according to any one of Supplementary Notes 1 to 4, wherein the situation is a situation in which the vehicle is stopped on a slope that satisfies a predetermined condition.

[0057] [Supplementary Note 6] The control device according to Supplementary Note 5, wherein the in-vehicle device is an electronic control unit for brake control that executes a process related to a brake operation after the predetermined operation is performed while the vehicle is stopped on a slope that satisfies the predetermined condition.

[0058] [Supplementary Note 7] The control device according to any one of Supplementary Notes 1 to 6, wherein the situation is a situation in which the emergency notification system of the vehicle is operating. [Supplementary Note 8] The display unit is configured to be able to switch between a first state in which display can be performed even after the predetermined operation and a second state in which display cannot be performed after the predetermined operation, and the situation is a situation in which the display unit is set to the second state. The control device according to any one of Supplementary Notes 1 to 7.

[0059] [Appendix 9] The control device according to Appendix 8, wherein the display unit is configured to be switchable between the first state and the second state by a user of the vehicle. [Appendix 10] The control device according to any one of Appendices 1 to 9, wherein the suspension information includes information indicating the content of the situation.

[0060] [Appendix 11] The control device according to any one of Appendices 1 to 10, wherein the suspension information includes information indicating a method for eliminating the situation. [Appendix 12] A control method for a display unit that displays information related to software update of in-vehicle devices mounted on a vehicle. In software update in which update processing of the software of the in-vehicle device is executed in response to a predetermined operation of turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, a control method for causing the display unit to display suspension information indicating that the update processing has not been executed.

[0061] [Appendix 13] The control method according to Appendix 12, wherein the predetermined operation is an operation of turning off the power of the vehicle. [Appendix 14] The control method according to Appendix 13, when the situation is resolved after the suspension information is displayed on the display unit, changing the information to be displayed on the display unit from the suspension information to guidance information indicating that the update processing can be executed.

[0062] [Appendix 15] The control method according to any one of Appendices 12 to 14, wherein the situation is a situation in which the power of the in-vehicle device cannot be turned off even after the predetermined operation is performed. [Appendix 16] The control method according to any one of Appendices 12 to 15, wherein the situation is a situation in which the vehicle is stopped on a slope that satisfies a predetermined condition.

[0063] [Appendix 17] The in-vehicle device is an electronic control unit for brake control that executes processing related to a brake operation after the predetermined operation is performed in a state where the vehicle is stopped on a slope that satisfies the predetermined condition. The control method according to Appendix 16.

[0064] [Appendix 18] The control method according to any one of Appendices 12 to 17, wherein the situation is a situation where the emergency notification system of the vehicle is operating. [Appendix 19] The display unit is configured to be able to switch between a first state in which display can be performed even after the predetermined operation and a second state in which display cannot be performed after the predetermined operation, and the situation is a situation where the display unit is set to the second state. The control method according to any one of Appendices 12 to 18.

[0065] [Appendix 20] The control method according to Appendix 19, wherein the display unit is configured to be switchable between the first state and the second state by a user of the vehicle. [Appendix 21] The control method according to any one of Appendices 12 to 20, wherein the suspension information includes information indicating the content of the situation.

[0066] [Appendix 22] The control method according to any one of Appendices 12 to 21, wherein the suspension information includes information indicating a method for eliminating the situation. A program executed by a control device that controls a display unit for displaying information related to software update of in-vehicle devices mounted on a vehicle. In software update in which update processing of the software of the in-vehicle device is executed in response to a predetermined operation of turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, the control device is caused to display suspension information indicating that the update processing has not been executed on the display unit.

[0067] [Appendix 24] The program according to Appendix 23, wherein the predetermined operation is an operation of turning off the power of the vehicle. [Appendix 25] When the situation is resolved after the suspension information is displayed on the display unit, the control device is caused to change the information to be displayed on the display unit from the suspension information to guidance information indicating that the update processing can be executed, according to the program according to Appendix 23 or Appendix 24.

[0068] [Supplementary Note 26] A program according to any one of Supplementary Notes 23 to 26, wherein the situation is a situation where the in-vehicle device cannot be turned off even after the predetermined operation has been performed. [Supplementary Note 27] A program according to any one of Supplementary Notes 23 to 26, wherein the situation is a situation where the vehicle is stopped on a slope that satisfies a predetermined condition.

[0069] [Supplementary Note 28] A program according to Supplementary Note 27, wherein the in-vehicle device is an electronic control unit for brake control that executes processing related to a brake operation after the predetermined operation is performed in a state where the vehicle is stopped on a slope that satisfies the predetermined condition.

[0070] [Supplementary Note 29] A program according to any one of Supplementary Notes 23 to 28, wherein the situation is a situation where the vehicle's emergency notification system is operating. [Supplementary Note 30] The display unit is configured to be able to switch between a first state in which display can be performed even after the predetermined operation and a second state in which display cannot be performed after the predetermined operation, and the situation is a situation where the display unit is set to the second state. A program according to any one of Supplementary Notes 23 to 29.

[0071] [Supplementary Note 31] A program according to Supplementary Note 30, wherein the display unit is configured to be switchable between the first state and the second state by a user of the vehicle. [Supplementary Note 32] A program according to any one of Supplementary Notes 23 to 31, wherein the suspension information includes information indicating the content of the situation.

[0072] [Supplementary Note 33] A program according to any one of Supplementary Notes 23 to 32, wherein the suspension information includes information indicating a method for resolving the situation. [Supplementary Note 34] A storage medium storing a program according to any one of Supplementary Notes 23 to 33.

Explanation of Signs

[0073] 10 Vehicle 11 OTA Master 12 DCM 13 ADAS 14 PCU 15 Engine ECU 16 Transmission ECU 17 Brake ECU 18 HMI 19 In-vehicle network 20 Mobile communication network 21 Memory module 22 Processor 30 OTA server 31 Memory device 32 Processor 40 Information terminal 41 Memory device 42 Processor 43 HMI

Claims

1. A control device for controlling a display unit that displays information related to software update of in-vehicle devices mounted on a vehicle, in a software update in which an update process of the software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which the execution of the update process is prevented when the predetermined operation is performed, causing the display unit to display suspension information indicating that the update process has not been executed Control device.

2. The control device according to claim 1, wherein the predetermined operation is an operation for turning off the power of the vehicle.

3. The control device according to claim 1, when the situation is resolved after the display of the suspension information on the display unit, causing the information displayed on the display unit to be changed from the suspension information to guidance information indicating that the update process can be executed.

4. The control device according to claim 1, wherein the situation is a situation in which the power of the in-vehicle device cannot be turned off even after the predetermined operation is performed.

5. The control device according to claim 1, wherein the situation is a situation in which the vehicle is stopped on a slope that satisfies a predetermined condition.

6. The control device according to claim 5, wherein the in-vehicle device is an electronic control unit for brake control that executes a process related to a brake operation after the predetermined operation is performed in a state where the vehicle is stopped on a slope that satisfies the predetermined condition.

7. The control device according to claim 1, wherein the situation is a situation in which an emergency notification system of the vehicle is operating.

8. The display unit is configured to be switchable between a first state in which display can be performed even after the predetermined operation and a second state in which display cannot be performed after the predetermined operation, The situation is a situation in which the display unit is set to the second state The control device according to claim 1.

9. The control device according to claim 8, wherein the display unit is configured to be switchable between the first state and the second state by a user of the vehicle.

10. The control device according to claim 1, wherein the suspension information includes information indicating the content of the situation.

11. The control device according to claim 1, wherein the suspension information includes information indicating a method for resolving the situation.

12. A control method for a display unit that displays information related to software update of in-vehicle devices mounted on a vehicle, In software update where update processing of software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, stop information indicating that the update processing has not been executed is displayed on the display unit. Control method.

13. A program executed by a control device that controls a display unit for displaying information related to software update of an in-vehicle device mounted on a vehicle, in software update where update processing of software of the in-vehicle device is executed in response to a predetermined operation for turning off the power of the in-vehicle device, when a situation occurs in which execution of the update processing is hindered when the predetermined operation is performed, causing the control device to display stop information indicating that the update processing has not been executed on the display unit. Program.

Citation Information

Patent Citations

  • Server apparatus, program providing system, program providing method, and program

    JP2013002958A

  • Software update apparatus

    JP2017097620A

  • Software update system and server

    JP2018045515A

  • Software update unit, software update method, software update system

    JP2018063659A

  • Control system, movable object, control method, and program

    JP2022108390A