Vehicle system
The vehicle system addresses the challenge of users missing software update information by transmitting update notifications to both the vehicle and associated information terminals, ensuring reliable communication and timely software updates.
Patent Information
- Application Number
- JP2025067195
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-06-26
- Estimated Expiration
- 2041-07-28
AI Technical Summary
During software updates using Over The Air (OTA) technology, vehicle users and administrators may fail to recognize information sent via email as reliable, due to the overwhelming number of emails they receive.
A vehicle system that includes a vehicle equipped with an electronic control unit, a software update control center, and an information terminal. The system ensures that information regarding software updates is transmitted to the information terminal and simultaneously notifies the vehicle, which then displays this notification on its display device, thereby making users aware of the reliability of the information.
The system effectively ensures that vehicle users and administrators recognize information related to software updates as reliable, preventing missed updates and ensuring timely software improvements or additions.
Smart Images

Figure 2025096586000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a vehicle system for controlling software updates of an electronic control unit mounted on a vehicle, etc.
Background Art
[0002] Vehicles are equipped with a plurality of electronic control units (ECUs: Electronic Control Unit) for controlling the operation of the vehicle. The electronic control unit includes a processor, a temporary storage unit such as a RAM, and a non-volatile memory which is a non-volatile storage unit such as a flash ROM. The processor realizes the control function of the electronic control unit by executing software stored in the non-volatile memory. The software stored in each electronic control unit is rewritable, and by updating to a newer version of the software, the functions of each electronic control unit can be improved or new vehicle control functions can be added.
[0003] As a technology for updating the software of an electronic control unit, an in-vehicle communication device connected to an in-vehicle network is wirelessly connected to a communication network such as the Internet, and a device responsible for the software update process of the vehicle downloads software from a server via wireless communication, writes the downloaded software to the electronic control unit for installation, and performs an activation to enable the installed software, thereby updating and adding the software of the electronic control unit. The OTA (Over The Air) technology is known. For example, refer to Patent Document 1.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] When performing software updates using OTA, processes such as notifying vehicle users and administrators of the software update and requesting their approval are carried out. These notifications and approval requests are made to vehicle users and administrators through information terminals such as in-vehicle navigation devices installed in the vehicle and smartphones capable of wireless communication with the vehicle.
[0006] Information terminals such as smartphones can receive a large number of various emails. Generally, the owner of the information terminal selects and checks only the necessary and reliable emails from among the large number of emails. However, it is a very difficult task to determine whether an email is truly necessary and reliable based only on the email title and the sender's address, etc. For this reason, there is a possibility that information sent by email, etc., to the information terminal owned by a vehicle user or administrator during software updates using OTA may not be recognized by the user or administrator as reliable information that they need.
[0007] The present disclosure has been made in view of the above problems, and an object thereof is to provide a vehicle system that can make a vehicle user or administrator aware that information sent by email, etc., to the information terminal owned by the vehicle user or administrator during software updates using OTA is reliable information.
Means for Solving the Problems
[0008] To solve the above problems, one aspect of the disclosed technology is a system including a vehicle equipped with an electronic control unit, a center that controls software updates of the electronic control unit, and an information terminal associated with the vehicle. The vehicle includes a first communication unit that communicates between a display device and the center, and the center includes a second communication unit that communicates between the vehicle and the information terminal. When the center transmits information regarding software updates to the information terminal, the center notifies the vehicle that the information regarding software updates has been transmitted, and the vehicle displays the notification received from the center on the display device.
Advantages of the Invention
[0009] According to the vehicle system of the present disclosure, etc., it is possible to make users and administrators of the vehicle aware that information transmitted by email or the like to an information terminal owned by them during software updates using OTA is reliable information.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6A
Figure 6B
Figure 7
Embodiments for Carrying Out the Invention
[0011] When performing software updates for the electronic control units in a vehicle, if the display device mounted on the vehicle cannot sufficiently display information regarding the software update, the system according to the present disclosure transmits information regarding the software update to an information terminal associated with the vehicle via email or the like, and also transmits a notification indicating that information regarding the software update has been sent to the information terminal to the vehicle. The vehicle then causes the display device to display the notification received from the center. This allows vehicle users, administrators, etc. to notice, by viewing the content displayed on the display device, that emails or the like sent to their own information terminals are reliable information. Hereinafter, an embodiment of the present disclosure will be described in detail with reference to the drawings.
[0012] <Embodiment> [System Configuration] FIG. 1 is a block diagram showing the overall configuration of a network system according to an embodiment of the present disclosure. The network system shown in FIG. 1 is a system for updating the software of a plurality of electronic control units (ECUs) 50a to 50d mounted on a vehicle, and includes a center 10 outside the vehicle, an in-vehicle network 90 constructed inside the vehicle, and an information terminal 95 associated with the vehicle.
[0013] (1) Center The center 10 can communicate with the OTA master 30 described below provided in the in-vehicle network 90 via the network 100, and perform operations such as sending notifications about software updates to vehicle users, administrators, etc., explanations about software updates, sending update data for the software of the electronic control units 50a to 50d and information defining the update process procedures, and receiving notifications indicating the progress status of the software update process, thereby controlling and managing the software updates of the plurality of electronic control units 50a to 50d connected to the OTA master 30. This center 10 has a function as a so-called server. Also, the center 10 can communicate with the information terminal 95 via the network 100 and send notifications about software updates to the electronic control units 50a to 50d to vehicle users, administrators, etc., and explanations about the software updates.
[0014] Figure 2 is a block diagram showing the schematic configuration of the center 10 in Figure 1. As shown in Figure 2, the center 10 includes a CPU (Central Processing Unit) 11, a RAM (Random Access Memory) 12, a storage device 13, and a communication device 14. The storage device 13 is a device equipped with a readable and writable storage medium such as a hard disk drive (HDD) or a solid state drive (SSD), and stores programs for executing software update management, information used for software update control and update management, and update data for the software of each electronic control unit. In the center 10, the CPU 11 executes a predetermined process related to software update by executing the program read from the storage device 13 using the RAM 12 as a work area. The communication device 14 is a device for communicating with the OTA master 30 and the information terminal 95 via the network 100.
[0015] FIG. 3 is a functional block diagram of the center 10 shown in FIG. 2. The center 10 shown in FIG. 3 includes a storage unit 16, a communication unit 17, a control unit 18, an acquisition unit 19, and a processing unit 20. The storage unit 16 is realized by the storage device 13 shown in FIG. 2. The communication unit 17, the control unit 18, the acquisition unit 19, and the processing unit 20 are realized by the CPU 11 shown in FIG. 2 executing a program stored in the storage device 13 using the RAM 12.
[0016] The storage unit 16 stores information related to software update processing of one or more electronic control units mounted on the vehicle. As information related to software update processing, the storage unit 16 stores, for each vehicle identification information (vehicle ID) that identifies the vehicle, update management information associating information indicating software available in the electronic control units 50a to 50d, and software update data of the electronic control units 50a to 50d, at least. As information indicating software available in the electronic control units 50a to 50d, for example, a combination of the latest version information of the software of each of the plurality of electronic control units 50a to 50d is defined. As information related to software update processing, the storage unit 16 can store an update status indicating the update state of the software being executed in the vehicle. Also, as information related to software update processing, the storage unit 16 can store information related to an update sequence indicating the procedure of software update processing for giving a control instruction to the OTA master 30. Further, the storage unit 16 can store information related to the display device 70 mounted on the vehicle acquired by the acquisition unit 19 described later.
[0017] The communication unit 17 functions as a transmitting unit and a receiving unit that transmits and receives data, information, notifications, requests, etc. between the OTA master 30 (vehicle) and the information terminal 95. The communication unit 17 receives a software update confirmation request from the OTA master 30 (receiving unit). The update confirmation request is information transmitted from the OTA master 30 to the center 10 when, for example, the power or ignition is turned on in the vehicle (hereinafter referred to as "power ON"), and is information for requesting the center 10 to confirm whether there is update data for the electronic control units 50a to 50d based on the vehicle configuration information described later. Further, the communication unit 17 transmits information indicating the presence or absence of update data to the OTA master 30 in response to the update confirmation request received from the OTA master 30 (transmitting unit). Also, the communication unit 17 receives a transmission request (download request) for a distribution package from the OTA master 30 (receiving unit). Further, when the communication unit 17 receives a download request for a distribution package (receiving unit), it transmits a distribution package including software update data for the electronic control units 50a to 50d generated by the control unit 18 described later to the OTA master 30 (transmitting unit). Also, the communication unit 17 transmits, based on an instruction from the processing unit 20, notifications about software updates, explanations about software updates, requests for consent to software updates, etc. (hereinafter collectively referred to as "information regarding software updates") to the vehicle and the information terminal 95 for the vehicle user, administrator, etc. (transmitting unit). Also, the communication unit 17 can receive a request for retransmission of information regarding the display device 70 mounted on the vehicle and information regarding software updates from the vehicle (receiving unit).
[0018] When the communication unit 17 receives an update confirmation request from the OTA master 30, the control unit 18 determines whether there is software update data for the electronic control units 50a to 50d mounted on the vehicle specified by the vehicle ID included in the update confirmation request based on the update management information stored in the storage unit 16. The determination result as to whether there is update data by the control unit 18 is transmitted to the OTA master 30 by the communication unit 17. When the control unit 18 determines that there is software update data for the electronic control units 50a to 50d, when it receives a download request for a distribution package from the OTA master 30, it generates one or more distribution packages including the corresponding update data stored in the storage unit 16. Further, the control unit 18 controls the software update process of the electronic control units 50a to 50d based on an update approval notice from the user or administrator of the vehicle, etc., received from the information terminal 95 as a response to the information regarding the software update transmitted by the processing unit 20.
[0019] The acquisition unit 19 acquires information regarding the display device 70 mounted on the vehicle from the vehicle via the communication unit 17. The information regarding the display device 70 includes at least information indicating whether it is possible to display on the screen of the display device 70 information (such as the content of control changes) that should be explained in advance to the user or administrator of the vehicle, etc., during software update using OTA. Being able to display on the screen typically means that all the information that should be explained in advance can be presented to the user or administrator of the vehicle, etc., through the screen display. This information regarding the display device 70 may be acquired by the center 10 from the vehicle each time the vehicle is powered on, or may be acquired in advance by other means.
[0020] When the processing unit 20 performs software update using OTA, it performs a process of transmitting information regarding the software update based on the display device 70 mounted on the vehicle. More specifically, if the display device 70 is capable of displaying a screen of information that should be explained in advance to the vehicle user, administrator, etc. during software update using OTA, the processing unit 20 processes to transmit the information regarding the software update to the vehicle (OTA master 30). On the other hand, if the display device 70 is not capable of displaying a screen of information that should be explained in advance to the vehicle user, administrator, etc. during software update using OTA, the processing unit 20 processes to transmit the information regarding the software update to the information terminal 95. The transmission of the information regarding the software update may be performed, for example, by an email transmitted by the center 10 via the communication unit 17, or by a cloud-type email. When transmitting the information regarding the software update to the information terminal 95, the processing unit 20 transmits a notification to the vehicle (OTA master 30) indicating that the information regarding the software update has been transmitted to the information terminal 95. This notification is preferably in a form that can be displayed even on a simple display device 70. Also, it may be performed at any time among simultaneously with, before, and after the transmission of the information regarding the software update to the information terminal 95. Thus, the processing unit 20 operates as a so-called human machine interface (HMI) functional unit. Note that the notification from the center 10 to the vehicle may be such that the OTA master 30 acquires it and controls the display device 70 to perform display based on this notification, or the display device 70 may directly receive it without going through the OTA master 30 and perform the display based on the notification by itself.
[0021] (2) Information Terminal The information terminal 95 is a device such as a smartphone or a personal computer owned by a vehicle user or administrator. The information terminal 95 of the present embodiment is provided with a function of receiving information regarding software updates transmitted by the center 10 or the like and browsing the content of the information. The information terminal 95 can be associated with the vehicle by being registered and managed in the vehicle, and is used as a human machine interface (HMI) for performing specific operations related to the vehicle (for example, locking and unlocking operations of the vehicle door or remote parking operation) and displaying information. The number of information terminals 95 associated with the vehicle is not limited to one and may be plural.
[0022] (3) In-vehicle network The in-vehicle network 90 includes an OTA master 30, a plurality of electronic control units 50a to 50d, a display device 70, and a communication module 80. The OTA master 30 and the communication module 80 are connected via a bus 60a. The OTA master 30 and the electronic control units 50a and 50b are connected via a bus 60b. The OTA master 30 and the electronic control units 50c and 50d are connected via a bus 60c. The OTA master 30 and the display device 70 are connected via a bus 60d.
[0023] The OTA master 30 can wirelessly communicate with the center 10 via the network 100 through the bus 60a and the communication module 80. Also, the OTA master 30 can communicate with the electronic control units 50a to 50d and the display device 70 via the buses 60b to 60d. This OTA master 30 is a device that manages the OTA state and controls the update sequence, which is the flow of software update processing, to perform software updates on the electronic control units to be updated (hereinafter referred to as "target electronic control units"). The OTA master 30 controls the software updates of the target electronic control units among the electronic control units 50a to 50d based on the update data obtained from the center 10 and the like. Also, the OTA master 30 can control appropriate screen displays on the display device 70 based on information and notifications regarding software updates received from the center 10. The OTA master 30 may also be referred to as a central gateway (CGW).
[0024] Figure 4 is a block diagram showing the schematic configuration of the OTA master 30 in FIG. 1. As shown in FIG. 4, the OTA master 30 includes a CPU 31, a RAM 32, a ROM (Read-Only Memory) 33, a storage device 34, and a communication device 36. The CPU 31, the RAM 32, the ROM 33, and the storage device 34 constitute a microcomputer 35. In the OTA master 30, the CPU 31 executes a predetermined process related to software update by using the program read from the ROM 33 with the RAM 32 as a work area. The communication device 36 is a device for communicating with each of the communication module 80, the electronic control units 50a to 50d, and the display device 70 via the buses 60a to 60d shown in FIG. 1.
[0025] FIG. 5 is a functional block diagram of the OTA master 30 shown in FIG. 4. The OTA master 30 shown in FIG. 5 includes a storage unit 37, a communication unit 38, and a control unit 39. The storage unit 37 is realized by the storage device 34 shown in FIG. 4. The communication unit 38 and the control unit 39 are realized by the CPU 31 shown in FIG. 4 executing a program stored in the ROM 33 using the RAM 32.
[0026] The storage unit 37 stores a program (control program for the OTA master 30) for executing software updates for the plurality of electronic control units 50a to 50d, various data used when executing software updates, and update data of software downloaded from the center 10. Further, the storage unit 37 can store information regarding the type of non-volatile memory mounted on each of the plurality of electronic control units 50a to 50d. Further, the storage unit 37 can store information regarding the display device 70.
[0027] The communication unit 38 functions as a transmission unit and a reception unit that transmit and receive data, information, notifications, requests, etc. to and from the center 10. For example, when the vehicle is powered on, the communication unit 38 transmits a software update confirmation request to the center 10 (transmission unit). The update confirmation request includes, for example, a vehicle ID for identifying the vehicle and information on the current versions of the software of the electronic control units 50a to 50d connected to the in-vehicle network 90. The vehicle ID and the current versions of the software of the electronic control units 50a to 50d are used to determine whether there is software update data for the electronic control units 50a to 50d by comparing with the latest versions of the software held by the center 10 for each vehicle ID. Also, the communication unit 38 receives a notification indicating the presence or absence of update data from the center 10 as a response to the update confirmation request (reception unit). When there is software update data for the electronic control units 50a to 50d, the communication unit 38 transmits a download request for a distribution package including the software update data, etc. to the center 10 (transmission unit) and receives (downloads) the distribution package transmitted from the center 10 (reception unit). Also, the communication unit 38 transmits the software update status transmitted by the electronic control units 50a to 50d to the center 10 (transmission unit). Further, based on an instruction from the control unit 39, the communication unit 38 can cause the display device 70 to display information on software updates, notifications regarding the transmission of such information, and the software update status. Also, the communication unit 38 can transmit information regarding the display device 70 to the center 10 (transmission unit).
[0028] Based on the response from the center 10 to the update confirmation request received by the communication unit 38, the control unit 39 determines whether there is update data for the software of the electronic control units 50a to 50d. Also, the control unit 39 verifies the authenticity of the update data received (downloaded) by the communication unit 38 from the center 10 in the distribution package and stored in the storage unit 37. Further, the control unit 39 uses the update data downloaded from the center 10 to control the software update process (such as installation and activation) of the electronic control units 50a to 50d. Specifically, the control unit 39 transfers the downloaded update data to the target electronic control unit and causes the target electronic control unit to install the updated software based on the update data. After the completion of the installation, the control unit 39 instructs the target electronic control unit to activate the installed updated software.
[0029] The plurality of electronic control units 50a to 50d are devices (ECUs) for controlling the operations of various parts of the vehicle. In FIG. 1, an example is shown in which the in-vehicle network 90 includes four electronic control units 50a to 50d, but the number of electronic control units is not particularly limited. Also, the number of buses connecting the electronic control units 50a to 50d to the OTA master 30 is not particularly limited.
[0030] The display device 70 is a human-machine interface (HMI) used to perform various displays, such as indicating that there is update data during the software update process of the electronic control units 50a to 50d, displaying explanations about software updates, notifying that information regarding software updates has been sent to the information terminal 95, displaying a consent request screen for requesting consent from the vehicle user or administrator for software updates, and displaying the results and status of software updates. As the display device 70, typically, the display device of a car navigation system can be used, but it is not particularly limited as long as it can display the information necessary during the software update process. For example, simple HMI devices such as meters that cannot present information regarding software updates are also included in the display device 70. In this embodiment, the case where the display device 70 receives the information and notifications transmitted from the center 10 via the OTA master 30 has been described, but the display device 70 may receive directly from the communication module 80 without going through the OTA master 30, or directly via another communication device (not shown) instead of the communication module 80. In addition, in the bus 60d shown in FIG. 1, in addition to the display device 70, an electronic control unit or the like may be further connected.
[0031] The communication module 80 is a unit having a function of controlling the communication between the center 10 and the vehicle, and is a communication device for connecting the in-vehicle network 90 to the center 10. The communication module 80 is wirelessly connected to the center 10 via the network 100, and vehicle authentication by the OTA master 30, download of update data, etc. are performed. This communication module 80 may be included in the OTA master 30.
[0032] In addition, a vehicle including the in-vehicle network 90 may be provided with an input unit such as a switch (not shown) that can request (resending request) the center 10 to resend information regarding software update to the information terminal 95. This switch is used when a vehicle user or administrator, etc., who has recognized a notification indicating that information regarding software update displayed on the display device 70 has been sent to the information terminal 95, wants to receive the information regarding software update again on the information terminal 95. Therefore, the switch is preferably provided near the display device 70 or on the steering wheel or the like. Also, it may be possible to directly request the information terminal 95 to resend the information regarding software update. In this way, information transmitted in response to an action taken by a user, administrator, etc. can give the user, administrator, etc. a sense of security, safety, and reliability.
[0033] [Overview of Software Update Process] The OTA master 30 transmits a software update confirmation request to the center 10, for example, when the vehicle power is turned on. The update confirmation request includes a vehicle ID for identifying the vehicle and vehicle configuration information regarding the status (system configuration) of the hardware and software of the electronic control units 50a to 50d connected to the in-vehicle network 90. The vehicle configuration information can be created by obtaining the identification number of the electronic control unit (ECU_ID) and the identification number of the software version of the electronic control unit (ECU_Software_ID) from the electronic control units 50a to 50d connected to the in-vehicle network 90. The vehicle ID and the current software versions of the electronic control units 50a to 50d are used to determine whether there is software update data for the electronic control units 50a to 50d by comparing with the latest software versions held by the center 10 for each vehicle ID. As a response to the update confirmation request received from the OTA master 30, the center 10 transmits a notification indicating the presence or absence of update data, information regarding software update, etc. to the OTA master 30 and / or the information terminal 95. If there is software update data for the electronic control units 50a to 50d, the OTA master 30 transmits a download request for the distribution package to the center 10. In response to the download request received from the OTA master 30, the center 10 transmits a distribution package including update data, etc. to the OTA master 30. The distribution package may include, in addition to the update data, verification data for verifying the authenticity of the update data, the number and type information of the update data, various control information used during software update, etc.
[0034] The OTA master 30 determines whether there is update data for the software of the electronic control units 50a to 50d based on the response to the update confirmation request received from the center 10. Further, the OTA master 30 verifies the authenticity of the distribution package received from the center 10 and stored in the storage device 13. Further, the OTA master 30 transfers the update data downloaded with the distribution package to the target electronic control unit and causes the target electronic control unit to install the update data. After the completion of the installation, the OTA master 30 instructs the target electronic control unit to perform activation to enable the installed updated version of the software.
[0035] In addition, in the approval request process, the center 10 causes the output device to output information explaining software updates, a notice indicating that approval is required for software updates, and a notice prompting an input indicating approval of the software update. As the output device, a display device 70 provided in the in-vehicle network 90, an information terminal 95, or the like can be used. For example, if it is possible to display on the screen of the display device 70 information that should be explained in advance to vehicle users, administrators, etc. in the approval request process, the display device 70 is used as the output device. When using the display device 70 as the output device, the OTA master 30 can display information regarding software updates, an approval request screen for requesting approval of software updates from the user or administrator, a notice prompting a specific input operation such as pressing an approval button when the user or administrator approves, etc. on the display device 70. If it is not possible to display on the screen of the display device 70 information that should be explained in advance to vehicle users, administrators, etc. in the approval request process, the information terminal 95 is used as the output device. When using the information terminal 95 as the output device, information regarding software updates, an approval request for requesting approval of software updates from the user or administrator, a notice prompting a specific input operation such as pressing an approval button when the user or administrator approves, etc. can be displayed on the display screen of the information terminal 95. When the center 10 receives an input indicating approval from the user or administrator via the OTA master 30 and / or the information terminal 95, it instructs the OTA master 30 to execute the above-described installation and activation control processes, and updates the software of the target electronic control unit.
[0036] Here, when the non-volatile memory of the target electronic control unit is a single-bank memory having one storage area for storing data such as software, in principle, installation and activation are performed continuously. Therefore, before the execution of the installation, a commitment request process for software update is performed. Note that even for a target electronic control unit with a single-bank memory, depending on the information regarding the update sequence instructed from the center 10, it may be required to temporarily stop the update process, that is, hold (wait) the activation in the state of completion of installation. Also, when the non-volatile memory of the target electronic control unit is a dual-bank memory having two storage areas for storing data such as software, at least, a commitment request process for software update is performed after the execution of the installation and before the execution of the activation. Note that when the non-volatile memory of the target electronic control unit is a dual-bank memory, the commitment request process for software update before the execution of the installation may or may not be performed.
[0037] The software update process consists of a phase in which the OTA master 30 downloads update data from the center 10 (download phase), a phase in which the OTA master 30 transfers the downloaded update data to the target electronic control unit and installs updated software based on the update data in the storage area of the target electronic control unit (installation phase), and a phase in which the target electronic control unit activates the installed updated software (activation phase).
[0038] Download is a process in which the OTA master 30 receives and stores in the storage unit 37 the update data for updating the software of the electronic control unit transmitted by the distribution package from the center 10. Regarding the reception of the update data by download, in the download phase, it includes not only the execution of the download but also the control of a series of processes related to the download, such as the determination of the executability of the download and the verification of the update data.
[0039] The update data transmitted from the center 10 to the OTA master 30 may include the update software (all data or differential data) of the electronic control unit, the compressed data obtained by compressing the update software, or the split data obtained by splitting the update software or the compressed data. Further, the update data may include the ECU_ID (or serial number) of the target electronic control unit and the ECU_Software_ID of the target electronic control unit before the update. The update data is downloaded as the above-described distribution package, and the distribution package includes the update data of a single electronic control unit or a plurality of electronic control units.
[0040] Installation is a process in which the OTA master 30 writes the update software (updated program) to the non-volatile memory of the target electronic control unit based on the update data downloaded from the center 10. In the installation phase, it includes not only the execution of the installation but also the control of a series of processes related to the installation, such as determination of whether the installation can be executed, transfer of the update data, and verification of the update software.
[0041] When the update data includes the update software itself (all data), in the installation phase, the OTA master 30 transfers the update data (update software) to the target electronic control unit. Also, when the update data includes the compressed data of the update software, or differential data, or split data, the OTA master 30 may transfer the update data to the target electronic control unit, and the target electronic control unit may generate the update software from the update data, or the OTA master 30 may generate the update software from the update data and then transfer the update software to the target electronic control unit. Here, the generation of the update software can be performed by decompressing the compressed data or assembling (integrating) the differential data or split data.
[0042] The installation of the updated software can be performed by the target electronic control unit based on the installation request from the OTA master 30. For a specific target electronic control unit that has received the update data, it may autonomously perform the installation without receiving an explicit instruction from the OTA master 30.
[0043] Activation is a process in which the target electronic control unit activates the updated software installed in its non-volatile memory. In the activation phase, it includes a series of controls related to activation, such as not only the execution of activation, but also the determination of whether activation can be executed, the request for approval from the vehicle user or administrator for activation, and the verification of the execution result.
[0044] The activation of the updated software can be performed by the target electronic control unit based on the activation request from the OTA master 30. For a specific target electronic control unit that has received the update data, it may autonomously perform activation after the completion of installation without receiving an explicit instruction from the OTA master 30.
[0045] Note that the software update process can be performed continuously or in parallel for each of the multiple target electronic control units.
[0046] Also, the "software update process" in this specification includes not only the process of continuously performing all of download, installation, and activation, but also the process of performing only a part of download, installation, and activation.
[0047] [Processing] Next, with further reference to FIGS. 6A, 6B, and 7, the software update process executed in the network system according to this embodiment will be described.
[0048] FIG. 6A and FIG. 6B are flowcharts for explaining the procedure of the transmission process of information regarding software updates performed by the center 10. The process of FIG. 6A and the process of FIG. 6B are connected by connectors X and Y.
[0049] (Step S601) The center 10 determines whether there is software that needs to be updated in the vehicle. This determination can be made based on, for example, the current version of the software of each electronic control unit 50a to 50d mounted on the vehicle obtained from the vehicle configuration information included in the update confirmation request transmitted from the OTA master 30, and the latest version of each software stored in the storage unit 16 of the center 10. If there is software that needs to be updated in the target vehicle (Step S601, Yes), the process proceeds to Step S602. On the other hand, if there is no software that needs to be updated in the target vehicle (Step S601, No), this process ends.
[0050] (Step S602) The center 10 determines whether the display device 70 mounted on the vehicle targeted for software update satisfies a predetermined condition. Here, the predetermined condition is the condition that, when performing software update using OTA, it is possible to display on the screen of the display device 70 information (such as the content of control changes) that should be explained in advance to the vehicle user, administrator, etc. The determination of whether this condition is satisfied is made based on the information regarding the display device 70 acquired by the acquisition unit 19. If the display device 70 satisfies the predetermined condition (Step S602, Yes), the process proceeds to Step S604. On the other hand, if the display device 70 does not satisfy the predetermined condition (Step S602, No), the process proceeds to Step S603.
[0051] (Step S603) Center 10 determines whether there is an information terminal 95 associated with the vehicle to be updated with software. Since the information terminal 95 associated with the vehicle is usually pre-registered in the storage unit of the vehicle or an external management facility that manages the vehicle, etc., the determination can be made based on this registration information. If there is an information terminal 95 associated with the vehicle (step S603, yes), the process proceeds to step S605. On the other hand, if there is no information terminal 95 associated with the vehicle (step S603, no), this process ends without performing the software update process.
[0052] (Step S604) Center 10 transmits information regarding software update (such as an explanation of the software update content and a request for commitment to software update) to the vehicle (OTA master 30). On the vehicle that has received this information, a screen display based on the information regarding software update is performed on the display device 70. When the information regarding software update is transmitted to the vehicle, the process proceeds to step S607.
[0053] (Step S605) Center 10 transmits information regarding software update (such as an explanation of the software update content and a request for commitment to software update) to the information terminal 95. When it is determined in step S603 that there are multiple information terminals 95 associated with the vehicle, the information may be transmitted to all terminals, or the information may be transmitted to some terminals (for example, the one closest to the vehicle). On the information terminal 95 that has received this information, a screen display based on the information regarding software update is performed. On the screen, the content of the information is displayed in text format, and various forms can be used, such as an address that links to a web page on which the content of the information is described and a start button for an application that can present the content of the information. When the information regarding software update is transmitted to the information terminal 95, the process proceeds to step S606.
[0054] (Step S606) The center 10 transmits a notification indicating that it has sent information regarding software update to the information terminal 95 to the vehicle (OTA master 30). This notification has a smaller amount of information compared to the information regarding software update, and can be displayed on a simple HMI device such as a meter that cannot present the information regarding software update. Examples of the notification include a message containing a character string that can identify an event that the vehicle (OTA master 30) has caused by itself. Such a notification increases the probability that the vehicle user or administrator, etc. will notice that the information regarding software update received by the information terminal 95 by e-mail or the like in step S605 is important and reliable information. When the notification indicating that the information regarding software update has been sent to the information terminal 95 is sent to the vehicle, the process proceeds to step S607.
[0055] (Step S607) As a response to the information regarding software update, the center 10 determines whether it has received an update approval notification from the vehicle (OTA master 30) or the information terminal 95. By receiving the update approval notification, the center 10 can determine that the vehicle user or administrator, etc. has understood the software update content and given consent to the update. The process proceeds to step S608 only when an update approval notification is received from the vehicle (OTA master 30) or the information terminal 95 (step S607, Yes). Note that when an update approval notification cannot be received from the vehicle (OTA master 30) or the information terminal 95, this process may be terminated without performing the software update process with a time limit set.
[0056] (Step S608) The center 10 executes a process (download, install, activate) to update the software of the target electronic control unit mounted on the vehicle. Thereby, the transmission process of the information regarding this software update is completed.
[0057] FIG. 7 is a flowchart for explaining an example of software update control processing executed by the center 10, the OTA master 30, and the target electronic control unit. This FIG. 7 is an example of a software update sequence after the transmission process of information related to the software update (FIGS. 6A and 6B) is performed in the download phase in order to obtain permission for downloading in the software update process.
[0058] Note that the transmission process of information related to software update (FIGS. 6A and 6B) may be performed not only in the download phase described in this embodiment but also in the installation phase in order to obtain permission for installation in the software update process, or may be performed in the activation phase in order to obtain permission for activation in the software update process.
[0059] (Step S701) The center 10 determines whether there is a download request for the distribution package from the OTA master 30. Only when there is a download request (Step S701, Yes), the process proceeds to Step S702.
[0060] (Step S702) The OTA master 30 downloads the update data. More specifically, the OTA master 30 receives a distribution package including the update data transmitted from the center 10. The OTA master 30 stores the received distribution package in the storage unit 37. When the download of the update data is performed, the process proceeds to Step S703.
[0061] (Step S703) The OTA master 30 executes the installation of software based on the update data in the target electronic control unit. More specifically, the OTA master 30 instructs the installation of the update software, which is a process of transferring the update data included in the distribution package to the target electronic control unit and writing the update data to a data storage area, based on the information included in the distribution package. When the installation of the update software is executed, the process proceeds to step S704.
[0062] (Step S704) The OTA master 30 activates the update software installed in the target electronic control unit. More specifically, the OTA master 30 instructs the target electronic control unit, which has written the update software to its data storage area, to activate the update software based on information included in the distribution package. The target electronic control unit restarts when a specific input operation, such as turning the power off, is performed, and executes the update software. When the update software activation process is executed, this software update control process ends.
[0063] <Actions and Effects> As described above, according to the network system according to an embodiment of the present disclosure, when performing a software update of an electronic control unit mounted on a vehicle, if the display device 70 mounted on the vehicle cannot adequately display information related to the software update, the center 10 transmits the information related to the software update by e-mail or the like to the information terminal 95 linked to the vehicle. Together with this transmission, the center 10 transmits a notification to the vehicle (OTA master 30) that the information related to the software update has been transmitted to the information terminal 95, and the notification received from the center 10 is displayed on the display device 70 on the vehicle side.
[0064] Through this process, when users or administrators of the vehicle view the content displayed on the display device 70, they can notice that information such as an email sent to their information terminal 95 is reliable information. Therefore, it is possible to avoid a situation where information sent to the information terminal 95 owned by users or administrators of the vehicle by email or the like during software updates using OTA cannot be perceived by the users or administrators as information that they do not notice or that has the necessary reliability. And after determining that users or administrators of the vehicle understand the software update content and have obtained consent for the update, it is possible to execute a process of updating the software of the target electronic control unit mounted on the vehicle.
[0065] As described above, although one embodiment of the disclosed technology has been explained, the present disclosure can be regarded as a system including a center and a vehicle, a method executed by a center including a processor and a memory, a program, a computer-readable non-transitory storage medium storing the program, an OTA master communicable with the center, or a vehicle equipped with the OTA master, and the like.
Industrial Applicability
[0066] The disclosed technology can be used in a network system for updating the software of an electronic control unit mounted on a vehicle.
Explanation of Signs
[0067] 10 Center 11, 31 CPU 12, 32 RAM 13, 34 Storage Device 14, 36 Communication Device 16, 37 Storage Unit 17, 38 Communication Unit 18, 39 Control Unit 19 Acquisition Unit 20 Processing Unit 30 OTA Master 33 ROM 35 Microcomputer 50a to 50d Electronic Control Units (ECUs) 60a to 60d Buses 70 Display device 80 Communication module 90 In-vehicle network 95 Information terminal 100 Network
Claims
1. A system including a vehicle equipped with an electronic control unit, a center that controls software updates of the electronic control unit, and an information terminal that is linked to the vehicle, The vehicle is A display device; a first communication unit that communicates with the center, the center includes a second communication unit that communicates with the vehicle and the information terminal; when the center transmits the information regarding the software update to the information terminal, the center notifies the vehicle that the information regarding the software update has been transmitted; The vehicle displays the notification received from the center on the display device.
2. 2. The system according to claim 1, wherein the center transmits the information regarding the software update to the information terminal when the display device mounted on the vehicle cannot display the information regarding the software update.
3. The system according to claim 1 or 2, wherein the vehicle further comprises a switch for instructing the center to resend information regarding the software update.
4. 4. The system according to claim 1, further comprising a control unit configured to control the software update process based on an update acceptance notification received from an information transmission destination in response to the information on the software update.
5. The vehicle further includes a transmission unit that transmits information related to the display device to the center, The system according to claim 1 , wherein the center further comprises an acquisition unit that acquires information about the display device from the vehicle.
Citation Information
Patent Citations
Vehicle information communication system
JP2020027626A
Center device, data distribution system and distribution control program
JP2020132042A
Software update device, software update system, and software update method
JP2020176974A
Vehicle control system
JP2017149323A