Facility system and facility equipment

By integrating downgrade permission information into the firmware of facility equipment systems, the risk of downgrading safety-critical versions during abnormal operations is mitigated, ensuring enhanced safety and reliability.

JP2025089760APending Publication Date: 2025-06-16RINNAI CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023204597
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-04
Publication Date
2025-06-16

AI Technical Summary

Technical Problem

Existing facility equipment systems may inadvertently downgrade firmware during abnormal operations, potentially compromising safety features, especially when the current firmware version is critical for safety modifications.

Method used

Incorporating downgrade permission information within the firmware to control whether a downgrade process can be executed, ensuring that safety-critical firmware versions are not downgraded unless explicitly permitted.

Benefits of technology

This solution enhances the safety of facility equipment systems by preventing unintended downgrades of safety-critical firmware versions, thereby maintaining operational safety and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025089760000001_ABST
    Figure 2025089760000001_ABST
Patent Text Reader

Abstract

To provide technique for enabling improvement of safety of a facility equipment system.SOLUTION: A facility system includes an external server and facility equipment configured to communicate with the external server. The facility equipment includes a control unit. The control unit is configured to execute downgrading that applies an older version of firmware to the facility equipment, the order version of firmware having been applied to the facility equipment before a current version of firmware currently applied to the facility equipment. The current version of firmware includes downgrading permission information indicating whether to allow the control unit to execute downgrading. The control unit executes downgrading in the case where a downgrading request is issued to the control unit and the downgrading permission information indicates permission. The control unit does not execute downgrading in the case where the downgrading request is issued and the downgrading permission information indicates non-permission.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology disclosed in this specification relates to facility systems and facility equipment.

Background Art

[0002] Patent Document 1 discloses a facility system including an external server and facility equipment configured to be communicable with the external server. The facility equipment includes a control unit. The control unit is configured to be able to execute a downgrade process of applying firmware of an old version that was applied to the facility equipment before the current version of the firmware applied to the facility equipment. When a downgrade request for causing the control unit to execute the downgrade process occurs, the control unit executes the downgrade process.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the facility equipment system of Patent Document 1, for example, when there is an abnormality in the operation of the facility equipment, a downgrade request occurs and the downgrade process is executed. As a result, thereafter, the facility equipment can be operated based on the firmware of the old version. However, there may be cases where it is better not to execute the downgrade process even if a downgrade request occurs. For example, this is the case when the current version of the firmware is for the purpose of a modification related to the safety of the facility equipment. This specification provides a technology capable of improving the safety of the facility equipment system.

Means for Solving the Problems

[0005] In a first aspect of the present technology, the facility system includes an external server and facility equipment configured to be communicable with the external server. The facility equipment includes a control unit. The control unit is configured to be capable of executing a downgrade process of applying to the facility equipment firmware of an old version that was applied to the facility equipment before the current version of the firmware applied to the facility equipment. The current version of the firmware includes downgrade permission information indicating whether to permit the control unit to execute the downgrade process. The control unit executes the downgrade process when a downgrade request for causing the control unit to execute the downgrade process occurs and the downgrade permission information indicates permission. The control unit does not execute the downgrade process when the downgrade request occurs and the downgrade permission information indicates non - permission.

[0006] According to the above configuration, for example, a firmware developer can determine the content of the downgrade permission information included in the firmware under development in consideration of the safety of the facility equipment. Therefore, for example, downgrade permission information indicating non - permission can be included in the firmware of a version intended for a modification related to the safety of the facility equipment. Thereby, when the firmware is applied to the facility equipment, it can be suppressed that the firmware of the facility equipment is downgraded to an old version. Therefore, according to the above configuration, the safety of the facility equipment system can be improved.

[0007] In a second aspect of the present technology, in the first aspect above, the facility equipment may further include an abnormality detection unit that detects an abnormality related to the operation of the facility equipment. The downgrade request may include a downgrade request at the time of abnormality that occurs based on the detection of an abnormality by the abnormality detection unit.

[0008] When an abnormality occurs in the operation of the equipment, there may be a problem with the current version of the firmware. In this case, by downgrading the firmware of the equipment to an older version, the abnormality in the operation of the equipment may be resolved. According to the above configuration, an abnormal-time downgrade request is generated based on the detection of an abnormality in the operation of the equipment. At this time, if the downgrade permission / denial information indicates permission, the firmware of the equipment is downgraded to an older version. Thereby, it is possible to attempt to resolve the abnormality in the operation of the equipment. Note that the defect here does not refer to a defect in the firmware itself, but rather a defect that can occur uniquely for each piece of equipment (for example, a defect caused by data loss during firmware download).

[0009] In the third aspect of the present technology, in the above second aspect, when the abnormal-time downgrade request occurs and the downgrade permission / denial information indicates non-permission, the operation of the equipment may be at least partially prohibited.

[0010] When the downgrade permission / denial information indicates non-permission, even if an abnormal-time downgrade request occurs, the firmware of the equipment cannot be downgraded to an older version. In this situation, it is not preferable to operate the equipment normally based on the current version of the firmware from the perspective of safety. According to the above configuration, in this situation, the operation of the equipment can be at least partially prohibited. Thereby, the safety of the equipment system can be improved.

[0011] In a fourth aspect of the present technology, in the second or third aspect described above, the control unit may be configured to be further capable of executing a re-application process of acquiring the current version of the firmware separately from the current version of the firmware applied to the facility equipment and applying the acquired current version of the firmware to the facility equipment. When an abnormality is detected by the abnormality detection unit, the control unit may execute the re-application process. The downgrade request during abnormality may occur after the re-application process by the control unit is completed when an abnormality is detected by the abnormality detection unit. The downgrade request during abnormality may not occur before the re-application process by the control unit is completed even if an abnormality is detected by the abnormality detection unit.

[0012] In the process until the firmware is applied to the facility equipment, if there is an application error (for example, an error related to data writing or reading), the operation of the facility equipment may become abnormal. In this case, without downgrading the firmware of the facility equipment to an older version, the current version of the firmware may be separately acquired and applied to the facility equipment again, and the abnormality related to the operation of the facility equipment may be resolved. According to the above configuration, when an abnormality occurs in the operation of the facility equipment, the re-application process is executed prior to the downgrade process. Thereby, the abnormality caused by the application error can be resolved without downgrading the firmware of the facility equipment.

[0013] In a fifth aspect of the present technology, in any one of the first to fourth aspects described above, the facility system may further include an input unit through which a user can input an execution instruction related to the downgrade process. The downgrade request may include a user downgrade request that occurs based on the input of the execution instruction related to the downgrade process into the input unit.

[0014] There may be cases where a user desires to downgrade the firmware of the equipment. For example, when the current version of the firmware is related to a change in the UI (user interface), and due to this UI change, the user finds it difficult to use the equipment. According to the above configuration, when the user desires to downgrade the firmware of the equipment, the user can generate a user downgrade request by inputting an execution instruction related to the downgrade process into the input unit. At this time, if the downgrade permission / denial information indicates permission, the firmware of the equipment is downgraded to the old version. Thereby, the usability of the equipment can be improved.

[0015] In the sixth aspect of the present technology, in any one of the first to fifth aspects described above, the equipment system may further include a notification unit. The control unit may cause the notification unit to perform notification when the downgrade request occurs and the downgrade permission / denial information indicates non - permission.

[0016] In a situation where a downgrade request occurs, for example, it is expected that there is a problem with the current version of the firmware or the user has instructed a firmware downgrade. Nevertheless, when the downgrade permission / denial information indicates non - permission, the downgrade process is not executed, and thereafter, the firmware of the equipment remains at the current version. According to the above configuration, in such a situation, notification by the notification unit can be performed. Thereby, for example, it is possible to notify that the equipment needs to be inspected / repaired, or to notify that the user's instruction has been rejected. Note that the defect mentioned here is not a defect related to the firmware itself, but a defect that can occur uniquely for each piece of equipment (for example, a defect caused by data loss during firmware download).

[0017] In a seventh aspect of the present technology, the facility equipment includes a control unit. The control unit is configured to be capable of executing a downgrade process of applying firmware of an old version that was applied to the facility equipment prior to the current version of firmware applied to the facility equipment. The current version of firmware includes downgrade permission information indicating whether to permit the control unit to execute the downgrade process. When a downgrade request for causing the control unit to execute the downgrade process occurs and the downgrade permission information indicates permission, the control unit executes the downgrade process. When the downgrade request occurs and the downgrade permission information indicates non - permission, the control unit does not execute the downgrade process.

[0018] According to the above configuration, for example, a firmware developer can determine the content of the downgrade permission information included in the firmware under development in consideration of the safety of the facility equipment. Therefore, for example, downgrade permission information indicating non - permission can be included in the firmware of a version for the purpose of correcting problems related to the safety of the facility equipment. Thereby, when the firmware is applied to the facility equipment, it is possible to suppress the firmware of the facility equipment from being downgraded to an old version. Therefore, according to the above configuration, the safety of the facility equipment system can be improved.

Brief Description of the Drawings

[0019]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

MODE FOR CARRYING OUT THE INVENTION

[0020] (Embodiment) As shown in FIG. 1, the facility system 2 includes a facility device 4 and a server 6. The facility device 4 is installed, for example, in the house of a user who uses the facility device 4. The facility device 4 is, for example, an air conditioner, a heating device, a water heater, a cooking heater, a dishwasher, or a bathroom dryer. The server 6 is managed by the manufacturing company that manufactured the facility device 4.

[0021] The equipment device 4 includes a heat source unit 8, an operation unit 10, a display unit 12, an audio output unit 14, a device communication unit 16, and a device control unit 18. The heat source unit 8 includes, for example, a heat pump, a gas burner, an oil burner, an electric heating device, and / or an induction heating device. The equipment device 4 can perform a predetermined first operation (for example, air conditioning, heating, heating a hot water storage tank, filling a bathtub with hot water, reheating a bathtub, cooking with heating, drying dishes, or drying a bathroom) by operating the heat source unit 8. The operation unit 10 includes, for example, switches operable by the user. The user can switch the on / off of the main power supply of the equipment device 4 or input various instructions and information to the equipment device 4 via the operation unit 10. The display unit 12 includes, for example, a display for displaying various information. The display unit 12 may be a touch panel that also functions as the operation unit 10. The audio output unit 14 includes, for example, a speaker for notifying various information by voice. The device communication unit 16 is an interface for communicating with the outside. The equipment device 4 can be connected to the Internet 100 via the device communication unit 16.

[0022] The device control unit 18 includes a processor 20, a memory 22, and a watchdog timer 24 (also abbreviated as "WDT24"). The memory 22 is a non-volatile memory such as an EEPROM or a flash memory. The processor 20 is configured to control the equipment device 4 by executing processing based on the information stored in the memory 22. The WDT24 detects whether the processor 20 is operating normally. When the WDT24 detects that the processor 20 is not operating normally, the WDT24 outputs a reset signal to the processor 20. When a reset signal is output from the WDT24 to the processor 20, the processor 20 stores a WDT operation flag indicating that the reset signal has been output from the WDT24 in the memory 22, and then executes a restart of the device control unit 18. Note that the WDT operation flag stored in the memory 22 is erased from the memory 22 when a reapplying process (the process of S6 in FIG. 2) or a downgrading process (the process of S10 in FIG. 2) described later is started.

[0023] The memory 22 is provided with a firmware application area 26 and a firmware holding area 28 as areas for storing the firmware of the facility equipment 4. The device control unit 18 is configured to control the facility equipment 4 based on the firmware stored in the firmware application area 26. The firmware stored in the firmware application area 26 can also be said to be the firmware applied to the facility equipment 4. Further, the device control unit 18 can store firmware in the firmware holding area 28 separately from the firmware applied to the facility equipment 4. Also, the memory 22 is provided with a setting area 30 as an area for storing settings related to the facility equipment 4. In the setting area 30, for example, start timer information 32, stop timer information 34, and schedule information 36 are stored.

[0024] Server 6 includes a server communication unit 62, a server control unit 64, and a server storage unit 66. The server communication unit 62 is an interface for communicating with the outside. Server 6 can be connected to the Internet 100 via the server communication unit 62. Therefore, Server 6 can communicate with the facility device 4 via the Internet 100. The server control unit 64 includes a processor (not shown) and a memory (not shown). The processor of the server control unit 64 is configured to control Server 6 by executing processing based on the information stored in the memory. The server storage unit 66 includes, for example, an HDD (Hard Disk Drive) and an SSD (Solid State Drive). Regarding the facility device 4, the server storage unit 66 stores, for example, the current version of the firmware (i.e., the firmware currently applied to the facility device 4), the old version of the firmware (i.e., the firmware that has been applied to the facility device 4 in the past), and the new version of the firmware (the firmware that has never been applied to the facility device 4 in the past). Note that the server 6 of this embodiment manages the version information of the firmware applied to the facility device 4. Therefore, Server 6 can identify each of the firmware stored in the server storage unit 66 as either the current version of the firmware, the old version of the firmware, or the new version of the firmware. Also, for example, when new firmware is created by the manufacturing company of the facility device 4, the firmware is stored in the server storage unit 66 as needed.

[0025] (Automatic start processing) When the start timing specified based on the start timer information 32 arrives, the equipment control unit 18 of the equipment 4 starts the operation of the heat source unit 8 and is configured to be able to execute an automatic start process for starting the aforementioned first operation (for example, air conditioning, heating, boiling of a hot water storage tank, filling a bathtub with hot water, reheating a bathtub, cooking with heating, drying dishes, or drying a bathroom) of the equipment 4. The start timer information 32 includes, for example, the time until the start timing arrives and the time when the start timing arrives. The user can set the start timer information 32 via the operation unit 10. Also, in this embodiment, the function realized by the automatic start process is called the "automatic start function". The user can switch the ON / OFF of the automatic start function via the operation unit 10. When the automatic start function is ON, the execution of the automatic start process by the equipment control unit 18 is permitted. When the automatic start function is OFF, the execution of the automatic start process by the equipment control unit 18 is prohibited.

[0026] (Automatic stop process) While the equipment 4 is performing the aforementioned first operation (for example, air conditioning, heating, boiling of a hot water storage tank, filling a bathtub with hot water, reheating a bathtub, cooking with heating, drying dishes, or drying a bathroom), when the stop timing specified based on the stop timer information 34 arrives, the equipment control unit 18 is configured to be able to execute an automatic stop process for stopping the heat source unit 8 and stopping the first operation of the equipment 4. The stop timer information 34 includes, for example, the time until the stop timing arrives and the time when the stop timing arrives. The user can set the stop timer information 34 via the operation unit 10. Also, in this embodiment, the function realized by the automatic stop process is called the "automatic stop function". The user can switch the ON / OFF of the automatic stop function via the operation unit 10. When the automatic stop function is ON, the execution of the automatic stop process by the equipment control unit 18 is permitted. When the automatic stop function is OFF, the execution of the automatic stop process by the equipment control unit 18 is prohibited.

[0027] (Scheduled operation) The equipment control unit 18 is configured to be able to execute a schedule operation for executing the aforementioned first operation (for example, air conditioning, heating, boiling of a hot water storage tank, filling of a bathtub, reheating of a bathtub, cooking, dish drying, or bathroom drying) in accordance with the schedule information 36. The schedule information 36 is created by alternately combining an operation process in which the facility equipment 4 executes the first operation and a stop process in which the facility equipment 4 does not execute the first operation. The schedule information 36 includes, for example, a cooking schedule for causing a cooking appliance to perform automatic cooking and a heating schedule for causing heating equipment to perform intermittent heating. The user can set the schedule information 36 or instruct the execution of the schedule operation via the operation unit 10.

[0028] (Processing related to firmware update) While power is supplied to the facility equipment 4, the equipment control unit 18 repeatedly executes the process shown in FIG. 2.

[0029] In S2, the equipment control unit 18 determines whether the WDT 24 has activated. Specifically, the equipment control unit 18 determines whether a WDT activation flag is stored in the memory 22. If the WDT 24 has activated (YES), the process proceeds to S4.

[0030] In S4, the equipment control unit 18 determines whether the re-application process (the process of S6) described later has been executed for the current version of the firmware applied to the facility equipment 4. When the equipment control unit 18 of the present embodiment executes the re-application process, it stores a re-application execution flag in the memory 22. The re-application execution flag is erased from the memory 22 when the firmware of the facility equipment 4 is updated to a version different from the current version. Therefore, in S4, the equipment control unit 18 determines whether the re-application execution flag is stored in the memory 22. If the re-application process for the current version of the firmware has not been executed (NO), the process proceeds to S6.

[0031] In S6, the device control unit 18 executes a re-application process. When the re-application process is started, the device control unit 18 requests the server 6 (see FIG. 1) to transmit the firmware of the current version. In response to this request, the server 6 transmits the firmware of the current version stored in the server storage unit 66 to the device control unit 18. The device control unit 18 stores the firmware of the current version transmitted from the server 6 in the firmware holding area 28 of the memory 22. In this way, the device control unit 18 acquires the firmware of the current version from the server 6. After that, the device control unit 18 updates the firmware of the facility device 4 to the firmware of the current version acquired from the server 6. Specifically, the device control unit 18 rewrites the firmware stored in the firmware application area 26 with the firmware stored in the firmware holding area 28 of the memory 22, and then executes a restart. After that, the re-application process ends, and the process returns to S2.

[0032] Even if the re-application process is executed for the firmware of the current version and the WDT 24 still operates, YES is obtained in S2 and YES is obtained in S4. In this case, the process proceeds to S8. In this embodiment, in this situation, it is interpreted that "an abnormal downgrade request has occurred".

[0033] In S8, the device control unit 18 determines whether the downgrade permission information included in the current version of the firmware indicates "permission". The downgrade permission information here refers to information indicating whether to permit downgrading to an older version of the firmware. The content of the downgrade permission information is determined for each version of the firmware by, for example, the developer of the firmware. Also, the content of the downgrade permission information is determined according to a predetermined criterion. The predetermined criterion is, for example, a criterion that assigns "not permitted" to the firmware of a version intended for a modification related to the safety of the equipment 4, and assigns "permitted" to the firmware of a version not related to the safety of the equipment 4. The "modification related to the safety of the equipment 4" here refers to, for example, a modification related to the output control of the heat source unit 8 (see FIG. 1), and more specifically, a modification for a problem such as the hot water temperature of the water heater becoming higher than the temperature set by the user. Also, the "modification not related to the safety of the equipment 4" refers to, for example, a modification related to the design of the image displayed on the display unit 12 (see FIG. 1) or a modification for adding a new function to the equipment 4. When the downgrade permission information indicates "permission" (in the case of YES) in S8, the process proceeds to S10.

[0034] In S10, the device control unit 18 executes a downgrade process. When the downgrade process is started, the device control unit 18 requests the server 6 (see FIG. 1) to transmit the firmware of the old version. In response to this request, the server 6 transmits the firmware of the old version stored in the server storage unit 66 to the device control unit 18. The device control unit 18 stores the firmware of the old version transmitted from the server 6 in the firmware holding area 28 of the memory 22. In this way, the device control unit 18 acquires the firmware of the old version from the server 6. After that, the device control unit 18 updates the firmware of the facility device 4 to the firmware of the old version acquired from the server 6. Specifically, the device control unit 18 rewrites the firmware stored in the firmware application area 26 with the firmware stored in the firmware holding area 28 of the memory 22, and then executes a restart. After that, the downgrade process ends.

[0035] In S8, when the downgrade permission information indicates "not permitted" (in the case of NO), the process proceeds to S12. In S12, the device control unit 18 places a restriction on the operation of the facility device 4 (for example, prohibits the operation of the heat source unit 8). The restriction provided for the facility device 4 can be released, for example, by a maintenance staff member of the facility device 4 when performing repair and inspection. Also in S12, the device control unit 18 causes the voice output unit 14 (see FIG. 1) to notify that the operation of the facility device 4 is restricted and that repair and inspection of the facility device 4 are necessary. At this time, the device control unit 18 may also cause the above notification content to be displayed on the display unit 12 (see FIG. 1). After S12, the process shown in FIG. 2 ends. Note that due to the restriction provided for the facility device 4 in S12, it is also prohibited to execute the process shown in FIG. 2 later. Therefore, after the process shown in FIG. 2 ends after passing through S12, the device control unit 18 does not execute the process shown in FIG. 2 until the restriction is released, for example, by a maintenance staff member of the facility device 4.

[0036] In S2, when the WDT24 is not operating (in the case of NO), the process proceeds to S14. In S14, the device control unit 18 determines whether or not the user has given an instruction to downgrade the firmware of the equipment device 4, for example, via the operation unit 10 (see FIG. 1). If the user has given an instruction to downgrade the firmware of the equipment device 4 (in the case of YES), the process proceeds to S16. In this embodiment, in this situation, it is interpreted that "a user downgrade request has occurred".

[0037] In S16, the device control unit 18 determines whether or not the downgrade permission information included in the current version of the firmware indicates "permission". If the downgrade permission information indicates "permission" (in the case of YES), the process proceeds to S10. If the downgrade permission information indicates "not permitted" (in the case of NO), the process proceeds to S18.

[0038] In S18, the device control unit 18 causes the voice output unit 14 (see FIG. 1) to notify that the instruction to downgrade the firmware of the equipment device 4 has been rejected. At this time, the device control unit 18 may also cause the display unit 12 (see FIG. 1) to display the above notification content.

[0039] After S10, after S18, or when there is no instruction to downgrade the firmware in S14 (in the case of NO in S14), the process proceeds to S20. In S20, the device control unit 18 determines whether or not a new version of the firmware is registered in the server 6 (see FIG. 1) (that is, whether or not a new version of the firmware is stored in the server storage unit 66). When a new version of the firmware is registered in the server 6, the server 6 transmits information indicating that the new version of the firmware has been registered in the server 6 to the device control unit 18. Therefore, the device control unit 18 can determine whether or not a new version of the firmware is registered in the server 6 based on the information received from the server 6. If a new version of the firmware is not registered in the server 6 (in the case of NO), the process shown in FIG. 2 ends. If a new version of the firmware is registered in the server 6 (in the case of YES), the process proceeds to S22.

[0040] In S22, the device control unit 18 executes the upgrade process shown in FIG. 3. Although details will be described later, in the upgrade process, the device control unit 18 upgrades the firmware of the facility device 4 to a new version. After S22, the process shown in FIG. 2 ends.

[0041] (Upgrade Process: FIG. 3) In S32, the device control unit 18 acquires the firmware of the new version. In this embodiment, when the firmware of the new version is registered in the server 6 (see FIG. 1), the server 6 transmits the firmware of the new version to the device control unit 18. The device control unit 18 stores the firmware of the new version transmitted from the server 6 in the firmware holding area 28 of the memory 22 (that is, acquires the firmware of the new version). After S32, the process proceeds to S34.

[0042] In S34, the device control unit 18 specifies the update time Tu required for updating the firmware for the firmware of the new version acquired in S32. The update time Tu here refers to the time for rewriting the firmware stored in the firmware application area 26 with the firmware stored in the firmware holding area 28 by the firmware, and the time for restarting the device control unit 18 thereafter. The update time Tu is expected to be within the range of approximately 1 minute to 5 minutes, although it also depends on the content of the firmware related to the update. After S34, the process proceeds to S36.

[0043] In S36, the device control unit 18 determines whether the current time is a stop time zone in which the heat source unit 8 is expected to stop. While power is being supplied, the device control unit 18 can identify the stop time zone by repeatedly executing the first stop time zone identification process (see FIG. 4), the second stop time zone identification process (see FIG. 6), and the third stop time zone identification process (see FIG. 8), which will be described later. If the current time is not the stop time zone (NO), the process repeatedly executes S36. If the current time is the stop time zone (YES), the process proceeds to S38. Note that if the stop time zone cannot be identified, it is determined as NO in S36.

[0044] In S38, the device control unit 18 determines whether it is possible to complete the firmware update within the stop time zone. Specifically, the device control unit 18 determines whether the remaining time Tr from the current time until the end of the stop time zone is longer than the time obtained by adding an arbitrary margin time Tm to the update time Tu. That is, the device control unit 18 determines whether Tr > Tu + Tm holds. The margin time Tm may be a constant or a variable that varies according to the length of the update time Tu. If it is not possible to complete the firmware update within the stop time zone (NO), the process returns to S36. If it is possible to complete the firmware update within the stop time zone (YES), the process proceeds to S40.

[0045] In S40, the device control unit 18 updates the firmware of the facility device 4 to the new version of the firmware acquired in S32. Specifically, the device control unit 18 rewrites the firmware stored in the firmware application area 26 with the firmware stored in the firmware holding area 28 of the memory 22, and then executes a restart. After S40, the process shown in FIG. 3 ends.

[0046] (First Stop Time Zone Identification Process: FIG. 4) While power is being supplied to the facility device 4, the device control unit 18 repeatedly executes the first stop time zone identification process shown in FIG. 4.

[0047] In S52, the device control unit 18 determines whether the automatic start function is ON. If the automatic start function is OFF (NO), the process shown in FIG. 4 ends. If the automatic start function is ON (YES), the process proceeds to S54.

[0048] In S54, the device control unit 18 determines whether the heat source unit 8 (see FIG. 1) has stopped. If the heat source unit 8 is operating (NO), the process returns to S52. If the heat source unit 8 has stopped (YES), the process proceeds to S56.

[0049] In S56, as shown in FIG. 5, the device control unit 18 specifies, as a stop time zone, the time zone from the present until the start timing specified based on the start timer information 32 (see FIG. 1) arrives. Thereby, it is possible to specify, as a stop time zone, the time zone immediately before the heat source unit 8 is started by the automatic start function. After S56 in FIG. 4, the process proceeds to S58.

[0050] In S58, the device control unit 18 determines whether the heat source unit 8 (see FIG. 1) has started or the automatic start function has become OFF. If the heat source unit 8 has stopped and the automatic start function is ON (NO), the process returns to S56. If the heat source unit 8 has started or the automatic start function has become OFF (YES), the process shown in FIG. 4 ends. Note that when it is determined as NO in S58, S56 and S58 are repeatedly executed, and during that time, the time zone from the present until the start timing arrives is specified as the stop time zone. On the other hand, when it is determined as YES in S58, the stop time zone is not specified in the first stop time zone specifying process.

[0051] (Second stop time zone specifying process: FIG. 6) The device control unit 18 repeatedly executes the second stop time zone specifying process shown in FIG. 6 while power is supplied to the facility device 4.

[0052] In S72, the device control unit 18 determines whether the automatic stop function is ON. If the automatic stop function is OFF (NO), the process shown in FIG. 6 ends. If the automatic stop function is ON (YES), the process proceeds to S74.

[0053] In S74, the device control unit 18 determines whether the heat source unit 8 (see FIG. 1) has stopped due to the automatic stop function. If the heat source unit 8 is operating, or if the heat source unit 8 has stopped without the automatic stop function (NO), the process returns to S72. Here, the case where the heat source unit 8 stops without the automatic stop function means, for example, the case where the heat source unit 8 stops in response to the user instructing the stop of the heat source unit 8 via the operation unit 10. If the heat source unit 8 has stopped due to the automatic stop function (YES), the process proceeds to S76.

[0054] In S76, the device control unit 18 specifies the predicted start timing at which the operation of the heat source unit 8 is expected to start next, based on the operation record of the heat source unit 8 on each day in the past predetermined period. For example, the device control unit 18 stores in the memory 22, as the stop state duration ST, the time elapsed from when the heat source unit 8 stopped due to the automatic stop function until the heat source unit 8 starts operating next in the past predetermined period (for example, the past one month). In this case, the device control unit 18 calculates the average time STm of the stop state duration ST for each day, and specifies as the predicted start timing the timing after the stop timing (that is, the stop timing) by the average time STm. After S76, the process proceeds to S78.

[0055] In S78, as shown in FIG. 7, the device control unit 18 specifies the time period from now until the predicted start timing specified in S76 arrives as the stop time period. After S78 in FIG. 6, the process proceeds to S80.

[0056] In S80, the device control unit 18 determines whether the heat source unit 8 (see FIG. 1) has started. If the heat source unit 8 is stopped (NO), the process returns to S78. If the heat source unit 8 has started (YES), the process shown in FIG. 6 ends. Note that when it is determined as NO in S80, since S78 and S80 are repeatedly executed, during that time, the time period from the present until the predicted start timing arrives is specified as the stop time period. On the other hand, when it is determined as YES in S80, the stop time period is not specified in the second stop time period specifying process. If the heat source unit 8 is stopped and the automatic start function is OFF (NO), the process returns to S78. If the heat source unit 8 has started or the automatic start function is ON (YES), the process shown in FIG. 6 ends. Note that when it is determined as NO in S80, since S78 and S80 are repeatedly executed, during that time, the time period from the present until the predicted start timing arrives is specified as the stop time period. On the other hand, when it is determined as YES in S80, the stop time period is not specified in the second stop time period specifying process.

[0057] Note that when the automatic start function is ON, the second stop time period specifying process may not be executed. This is because when the automatic start function is ON, a more reliable stop time period can be specified by the above-described first stop time period specifying process (see FIG. 4). In other words, this is because the start timing specified based on the start timer information 32 is more reliable than the predicted start timing specified based on the operation results of the heat source unit 8.

[0058] (Third Stop Time Period Specifying Process: FIG. 8) While power is supplied to the facility equipment 4, the device control unit 18 repeatedly executes the third stop time period specifying process shown in FIG. 8.

[0059] In S92, the device control unit 18 determines whether the scheduled operation is being executed. If the scheduled operation is not being executed (NO), the process shown in FIG. 8 ends. If the scheduled operation is being executed (YES), the process proceeds to S94.

[0060] In S94, as shown in FIG. 9, the device control unit 18 specifies, as a stop time zone, the time zone during which a stop process is performed in the scheduled operation. The stop process here includes, for example, a residual heat cooking process in which the heating by a stove or the like of a cooking heater is stopped and the food is left unattended. After S94 in FIG. 8, the process proceeds to S96.

[0061] In S96, the device control unit 18 determines whether or not the scheduled operation has ended. If the scheduled operation is in progress (NO), the process returns to S94. If the scheduled operation has ended (YES), the process shown in FIG. 8 ends. Note that when it is determined as NO in S96, S94 and S96 are repeatedly executed, and during that time, the time zone during which the stop process is performed in the scheduled operation is specified as the stop time zone. On the other hand, when it is determined as YES in S96, the stop time zone is not specified in the third stop time zone specifying process.

[0062] (Processing when updating firmware during timing) During timing, the device control unit 18 may execute firmware update (S40 in FIG. 3). For example, as shown in FIG. 10, the device control unit 18 may execute firmware update while timing the time until the start timing arrives in the automatic start process. In this case, the timing by the device control unit 18 is temporarily interrupted along with the firmware update. In this situation, the device control unit 18 of this embodiment stores the timed time in the memory 22 as the first elapsed time T1 before the firmware update. Then, after the firmware update, the device control unit 18 resumes timing starting from the second elapsed time T2 obtained by adding an arbitrary addition time ΔT to the first elapsed time T1. Thereby, the device control unit 18 can add the elapsed time during which the timing is interrupted (the timing interruption time shown in FIG. 10) to the timing time as the addition time ΔT. In this embodiment, the update time Tu calculated in S34 of FIG. 3 is used as the addition time ΔT. Also, the above processing is similarly performed when the device control unit 18 executes firmware update while timing the time until the stop timing arrives in the automatic stop process, or when the device control unit 18 executes firmware update while timing the duration of the stop process in the scheduled operation.

[0063] (Modification example) The server 6 does not necessarily manage the version information of the firmware applied to the facility device 4. In this case, the device control unit 18 of the facility device 4 may be configured to transmit the version information of the firmware applied to the facility device 4 to the server 6 at the start of the re-application process (the process of S6 in FIG. 2), the downgrade process (the process of S10 in FIG. 2), and the upgrade process (the process of FIG. 3). Then, the server 6 may identify each of the firmware stored in the server storage unit 66 as any one of the current version firmware, the old version firmware, and the new version firmware based on the version information transmitted from the facility device 4.

[0064] The machine control unit 18 may hold the old version of the firmware that has been applied in the past without deleting it from the memory 22. As a result, in the downgrade process (the process of S10 in FIG. 2), the process in which the machine control unit 18 requests the server 6 to transmit the old version of the firmware may be omitted.

[0065] The facility device 4 may be provided with an abnormality detection unit other than the WDT 24 (for example, a temperature sensor that detects the temperature of the machine control unit 18). In S2 of FIG. 2, instead of determining whether the WDT 24 has operated, the machine control unit 18 may determine whether an abnormality has been detected by the above-described abnormality detection unit. For example, the machine control unit 18 may determine whether an excessively high temperature has been detected by a temperature sensor that detects the temperature of the machine control unit 18.

[0066] In S12 of FIG. 2, the machine control unit 18 may not impose a restriction on the operation of the facility device 4. That is, even after S12 is executed, the facility device 4 may be allowed to operate normally.

[0067] In S4 of FIG. 2, the machine control unit 18 may determine whether the reapplication process (the process of S6) for the current version of the firmware has been executed a predetermined number of times (for example, 3 times) or more. As a result, when the WDT 24 still operates even after the reapplication process for the current version of the firmware is executed a predetermined number of times, an abnormal downgrade request may occur.

[0068] After becoming YES in S2 of FIG. 2, the machine control unit 18 may skip S4 and S6 and execute S8. That is, when the WDT 24 operates, the machine control unit 18 may execute the downgrade process without executing the reapplication process.

[0069] Unlike the embodiment, it may be impossible for the user to input an instruction to downgrade the firmware for the facility device 4. In this case, after becoming NO in S2 of FIG. 2, the machine control unit 18 may skip S14, S16, and S18 and execute S20.

[0070] In S12 of FIG. 2, the device control unit 18 may not perform the notification by the voice output unit 14. Further, after the device control unit 18 becomes NO in S16 of FIG. 2, it may skip S18 and execute S20. By these means, even when an abnormal downgrade request (or a user downgrade request) occurs and the downgrade permission information indicates "not permitted", the notification by the voice output unit 14 may not be performed.

[0071] The facility device 4 may not have an automatic start function. In this case, the device control unit 18 may not be able to execute the first stop time zone specifying process.

[0072] The facility device 4 may not have an automatic stop function. In this case, the device control unit 18 may not be able to execute the second stop time zone specifying process.

[0073] The device control unit 18 may not be able to execute the scheduled operation. In this case, the device control unit 18 may not be able to execute the third stop time zone specifying process.

[0074] The stop process in the scheduled operation is not only performed between the operation steps as shown in FIG. 9, but may also be performed immediately after the start of the scheduled operation or immediately before the end of the scheduled operation.

[0075] In S38 of the upgrade process (see FIG. 3), the device control unit 18 may not consider the margin time Tm. Specifically, in S38, the device control unit 18 may determine whether Tr > Tu holds instead of determining whether Tr > Tu + Tm holds.

[0076] In S74 of the second stop time zone identification process shown in FIG. 6, when the heat source unit 8 (see FIG. 1) stops, the device control unit 18 may determine YES regardless of whether it is due to the automatic stop function. Then, in S76 thereafter, the device control unit 18 may identify the predicted start timing at which the operation of the heat source unit 8 is expected to start next based on the operation record of the heat source unit 8 on each day in a past predetermined period.

[0077] Although not shown, the facility device 4 may include a device main body equipped with the heat source unit 8 and a terminal device (for example, a dedicated remote control corresponding to the facility device 4) provided separately from the device main body. In this case, the device control unit 18 described in the embodiment may be a cooperative body of a main body control unit (not shown) that controls the device main body and a terminal control unit (not shown) that controls the terminal device. Therefore, the firmware of the facility device 4 described in the embodiment may be the firmware of the device main body or the firmware of the terminal device.

[0078] The device control unit 18 is configured to update the firmware in the stop time zone specified by the first stop time zone identification process (see FIG. 4), the second stop time zone identification process (see FIG. 6), or the third stop time zone identification process (see FIG. 8) not only in the upgrade process (see FIG. 3), but also in the re-application process (the process of S6 in FIG. 2) and / or the downgrade process (the process of S10 in FIG. 2).

[0079] (Corresponding relationship) In the above embodiment, the facility system 2 is an example of a "facility system". The facility device 4 is an example of a "facility device". The server 6 is an example of an "external server". The device control unit 18 is an example of a "control unit". The WDT 24 is an example of an "abnormality detection unit". The operation unit 10 is an example of an "input unit". The display unit 12 and the voice output unit 14 are examples of a "notification unit".

[0080] The technical elements described in this specification or the drawings exhibit technical utility either individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Further, the technologies exemplified in this specification or the drawings can achieve multiple objectives simultaneously, and achieving one of those objectives by itself has technical utility.

Explanation of Reference Signs

[0081] 2: Facility system, 4: Facility equipment, 6: Server, 8: Heat source unit, 10: Operation unit, 12: Display unit, 14: Audio output unit, 16: Device communication unit, 18: Device control unit, 20: Processor, 22: Memory, 24: Watchdog timer, 26: Firmware application area, 28: Firmware holding area, 30: Setting area, 32: Start timer information, 34: Stop timer information, 36: Schedule information, 62: Server communication unit, 64: Server control unit, 66: Server storage unit, 100: Internet

Claims

1. An equipment system including an external server and equipment configured to be communicable with the external server, The equipment has a control unit, The control unit is configured to be able to execute a downgrade process of applying firmware of an old version that was applied to the equipment before the current version of firmware applied to the equipment, to the equipment, The current version of firmware includes downgrade permission information indicating whether to permit the control unit to execute the downgrade process, The control unit, When a downgrade request for causing the control unit to execute the downgrade process occurs and the downgrade permission information indicates permission, the control unit executes the downgrade process, When the downgrade request occurs and the downgrade permission information indicates non - permission, the control unit does not execute the downgrade process. An equipment system.

2. The equipment further includes an abnormality detection unit that detects an abnormality related to the operation of the equipment, The downgrade request includes an abnormality - time downgrade request that occurs based on an abnormality being detected by the abnormality detection unit. The equipment system according to Claim 1.

3. When the abnormality - time downgrade request occurs and the downgrade permission information indicates non - permission, at least part of the operation of the equipment is prohibited. The equipment system according to Claim 2.

4. The control unit is further configured to be able to execute a reapplying process of acquiring the current version of firmware separately from the current version of firmware applied to the equipment and applying the acquired current version of firmware to the equipment, When an abnormality is detected by the abnormality detection unit, the control unit executes the reapplying process, The downgrade request during the abnormality is a case where an abnormality is detected by the abnormality detection unit, and occurs after the re-application process by the control unit is completed, The facility system according to claim 2, wherein even if an abnormality is detected by the abnormality detection unit, it does not occur before the re-application process by the control unit is completed. **Claim 5** The system further includes an input unit through which a user can input an execution instruction related to the downgrade process, The downgrade request includes a user downgrade request that occurs based on the input of the execution instruction related to the downgrade process into the input unit, for the facility system according to any one of claims 1 to 4. **Claim 6** The system further includes a notification unit, The control unit causes the notification unit to perform notification when the downgrade request occurs and the downgrade permission information indicates non-permission, for the facility system according to any one of claims 1 to 4. **Claim 7** A facility device, comprising a control unit, The control unit is configured to be able to execute a downgrade process of applying firmware of an old version that was applied to the facility device before the current version of firmware applied to the facility device, The current version of firmware includes downgrade permission information indicating permission or non-permission for the control unit to execute the downgrade process, The control unit, when a downgrade request for the control unit to execute the downgrade process occurs and the downgrade permission information indicates permission, executes the downgrade process, The facility device that does not execute the downgrade process when the downgrade request occurs and the downgrade permission information indicates non-permission.

Citation Information

Patent Citations

  • Update method of firmware of air conditioner, air conditioner mounted with update method of firmware, and program

    JP2023018443A