Server, program, and software update method
The system improves ECU software update convenience by displaying detailed information on both user and vehicle displays, ensuring seamless continuation and efficient user consent across devices.
Patent Information
- Application Number
- JP2025107951
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-08-22
AI Technical Summary
Existing software update methods for vehicle control units (ECUs) often require user consent but lack flexibility in obtaining it, especially when updates occur at inconvenient times or locations, potentially compromising user convenience.
A server-based system that displays detailed information on both a user's terminal and the vehicle's display, with higher granularity on the terminal to ensure comprehensive understanding, allowing seamless continuation of the update consent process across devices.
Enhances user convenience by allowing detailed review of update information on a familiar device, reducing the need for redundant viewing and improving the efficiency of obtaining user consent during ECU software updates.
Smart Images

Figure 2025123571000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a server, a program, and a software update method. [Background technology]
[0002] Research and development is underway on OTA (Over The Air) technology, which wirelessly updates software (vehicle control programs) stored in a vehicle control device (ECU: Electronic Control Unit). For example, Japanese Patent Application Laid-Open Publication No. 2017-149323 (Patent Document 1) discloses a vehicle control system that can safely update software without impairing user convenience. When a portable device determines that the vehicle's electronic key is located inside the vehicle, it transmits a signal to a server requesting the download of update software. The ECU updates the software by downloading the update software transmitted from the server via the portable device. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-149323 Summary of the Invention [Problem to be solved by the invention]
[0004] When updating software on personal computers, smartphones, and other electrical devices, it is common to require the user's permission beforehand. Similarly, when updating ECU software, it is conceivable that the user's permission would also need to be obtained in advance.
[0005] Software updates for electrical devices are primarily performed at the user's home. In contrast, software updates for ECUs can be performed at the user's home or while the user is out. Regardless of the user's situation when updating software, it is desirable to provide the user with appropriate data for obtaining user consent without compromising user convenience.
[0006] The present disclosure has been made to solve the above-mentioned problems, and one of the purposes of the present disclosure is to improve user convenience in updating ECU software. [Means for solving the problem]
[0007] (1) A server according to one embodiment of the present disclosure transmits data for updating software of a vehicle control device via wireless communication. The server includes a memory storing a program and a processor that executes the program. The processor sets first data to be displayed on an in-vehicle display to obtain user consent for the software update, and second data to be displayed on a user terminal to obtain user consent for the software update. The information granularity of the second data is higher than that of the first data.
[0008] (2) The amount of character information contained in the second data is greater than the amount of character information contained in the first data.
[0009] (3) The second data includes video information, and the first data does not include video information. (4) When a user partially views the second data using a user terminal and then further views the first data using an in-vehicle display, the processor sets the first data displayed on the in-vehicle display to a continuation of the second data that was partially viewed using the user terminal.
[0010] (5) When a user partially views the first data using the in-vehicle display and then further views the second data using the user terminal, the processor sets the second data displayed on the user terminal to a continuation of the first data that was partially viewed using the in-vehicle display.
[0011] (6) When a user partially views the first data using the in-vehicle display and then further views the second data using the user terminal, the processor sets the portion of the first data that the user has already viewed using the in-vehicle display as the second data to be displayed on the user terminal.
[0012] (7) According to another aspect of the present disclosure, a program causes a computer to execute the program for wirelessly updating software in a vehicle control device. When executed by the computer, the program causes the computer to execute the following steps: setting first data to be displayed on an in-vehicle display to obtain user consent for the software update; setting second data to be displayed on a user terminal to obtain user consent for the software update; and displaying corresponding data of the first data and the second data on at least one of the in-vehicle display and the user terminal. The information granularity of the second data is higher than the information granularity of the first data.
[0013] (8) According to yet another aspect of the present disclosure, a software update method wirelessly updates software in a vehicle control device. The software update method includes the steps of setting first data to be displayed on an in-vehicle display to obtain user consent for the software update and second data to be displayed on a user terminal to obtain user consent for the software update, and displaying corresponding data of the first data and the second data on at least one of the in-vehicle display and the user terminal. The information granularity of the second data is higher than the information granularity of the first data. [Effects of the Invention]
[0014] According to the present disclosure, it is possible to improve the convenience for users in updating software of an ECU. [Brief explanation of the drawings]
[0015] [Figure 1] 1 is a diagram illustrating a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 2] FIG. 1 is a block diagram showing a typical configuration example of an OTA center. [Figure 3] 1 is a block diagram showing a typical configuration example of a vehicle; [Figure 4] FIG. 1 is a block diagram showing a typical configuration example of a user terminal. [Figure 5] FIG. 2 is a diagram showing an example of a data structure of license information according to the present embodiment. [Figure 6] FIG. 10 is a diagram showing another example of the data structure of license information in the present embodiment. [Figure 7] 10 is a flowchart showing a first example of a processing procedure for obtaining user permission for a software update. [Figure 8] 10 is a flowchart showing a second example of the processing procedure for obtaining user permission for software update. [Figure 9] 10 is a flowchart showing a third example of a processing procedure for obtaining user permission for a software update. [Figure 10] 10 is a flowchart showing a fourth example of the processing procedure for obtaining user permission for software update. DETAILED DESCRIPTION OF THE INVENTION
[0016] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and description thereof will not be repeated.
[0017] [Embodiment Mode] <System configuration> 1 is a diagram illustrating a schematic configuration of an information processing system according to an embodiment of the present disclosure. The information processing system 100 includes an OTA center 1, a vehicle 2, and a user terminal 3. The OTA center 1 is connected to the vehicle 2 and the user terminal 3 via a wired or wireless network NW so that they can communicate with each other.
[0018] The OTA center 1 is a server that provides software for an ECU (see FIG. 3) installed in a vehicle 2. The OTA center 1 is managed, for example, by a vehicle manufacturer that manufactures the vehicle itself (VP: Vehicle Platform). The configuration of the OTA center 1 will be described with reference to FIG. 2.
[0019] Vehicle 2 is managed by a user. The user is typically an individual, but may also be, for example, a corporation (such as a transportation business operator) that conducts business using vehicle 2. In this embodiment, vehicle 2 is an autonomous driving vehicle. In this case, OTA center 1 may be managed by the manufacturer of the autonomous driving system (ADS) (see FIG. 3) installed in the VP instead of or in addition to the vehicle manufacturer. However, vehicle 2 may also be a vehicle that is not compatible with autonomous driving and can only be manually driven. The configuration of vehicle 2 will be described with reference to FIG. 3.
[0020] The user terminal 3 is a terminal operated by the user of the vehicle 2. The user terminal 3 may be a mobile terminal or a fixed terminal. Mobile terminals include, for example, smartphones, tablets, notebook PCs (Personal Computers), and wearable devices (such as smart watches). Fixed terminals include, for example, desktop PCs. The configuration of the user terminal 3 will be described with reference to FIG. 4.
[0021] 1, due to space limitations, only one vehicle 2 is shown, but the number of vehicles 2 is arbitrary. Typically, the information processing system 100 includes a large number of vehicles 2. The same applies to the user terminals 3.
[0022] 2 is a block diagram showing a typical configuration example of the OTA center 1. The OTA center 1 includes a server 11, an input device 12, a display 13, and a communication device 14. The server 11 includes a processor 111, a memory 112, a storage 113, and a network interface 114. The components of the OTA center 1 are connected to each other via a communication bus.
[0023] The storage 113 is a rewritable nonvolatile memory such as a hard disk drive (HDD), a solid state drive (SSD), or a flash memory. The storage 113 stores a system program 51 including an operating system (OS), a control program 52 including computer-readable code necessary for control calculations, an update program 53 for updating the control program of the vehicle 2, and license information 54 (described later) for obtaining user permission for downloading, installing, etc., of the update program 53. The processor 111 is, for example, a central processing unit (CPU) or a micro-processing unit (MPU). The processor 111 performs various processes by reading the system program 51 and the control program 52, expanding them into the memory 112, and executing them. The network interface 114 controls data communication between the server 11 and other devices (such as the vehicle 2 and the user terminal 3) via the communication device 14.
[0024] The input device 12 is a keyboard, a mouse, etc., and receives input from the operator of the server 11. The display 13 displays various information to the operator of the server 11.
[0025] 2 shows an example in which the server 11 includes one processor 111, the server 11 may include multiple processors. That is, the server 11 includes one or more processors. The same applies to the memory 112 and the storage 113.
[0026] In this specification, the term "processor" is not limited to a processor in the narrow sense that executes processing using a stored program, but may also include hardwired circuits such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). Therefore, the term "processor" can also be interpreted as a processing circuitry whose processing is predefined by computer-readable code and / or hardwired circuitry.
[0027] 3 is a block diagram showing a typical configuration example of a vehicle 2. The vehicle 2 includes a central ECU 21, multiple discrete ECUs 22, an advanced driver-assistance system (ADAS) 23, an ADS 24, a sensor group 25, an input device 26, an in-vehicle display 27, and a data communication module (DCM) 28. The discrete ECUs 22 are ECUs divided by function, such as a brake ECU, a steering ECU, a motor-generator ECU, and a body ECU. The discrete ECUs 22 may be controllers storing software for implementing the functions of the ADAS 23 and / or the ADS 24. The components of the vehicle 2 are connected to each other via a wired in-vehicle network such as a controller area network (CAN) or in-vehicle Ethernet (registered trademark).
[0028] The basic configurations of the central ECU 21 and the individual ECUs 22 are similar to that of the server 11. The storage 223 of the individual ECU 22 stores software (a system program 71 and a control program 72) executed by the processor 221 of the individual ECU 22. The individual ECU 22 controls the corresponding systems in response to signals from the sensor group 25 and the like so that the vehicle 2 is in a desired state. These systems may include a brake system, a steering system, a powertrain system, a body system, and the like, although none of these are shown.
[0029] The processor 211 of the central ECU 21 controls the update process of the software stored in the storage 223 of the individual ECU 22. The central ECU 21 receives (downloads) the software from the OTA center 1 via the DCM 28, and stores (installs) the downloaded software in the storage 223 of the individual ECU 22 at an appropriate time. Then, the central ECU 21 validates (activates) the installed software at an appropriate time.
[0030] The ADAS 23 includes, for example, an adaptive cruise control (ACC), an auto speed limiter (ASL), a lane keeping assist (LKA), a pre-crash safety (PCS), and a lane departure alert (LDA). The ADS 24 is configured to be able to perform autonomous driving of the vehicle 2.
[0031] The sensor group 25 includes sensors configured to detect the external conditions of the vehicle 2. The sensor group 25 further includes sensors (none of which are shown) configured to detect information according to the traveling state of the vehicle 2, as well as steering operations, accelerator operations, and braking operations. Specifically, the sensor group 25 may include, for example, a camera, radar, a LIDAR (Laser Imaging Detection and Ranging), a vehicle speed sensor, an acceleration sensor, a yaw rate sensor, and a steering sensor (none of which are shown).
[0032] The input device 26 is, for example, a touch panel provided on a multi-information display (MID). The input device 26 may also be a physical switch or button. The in-vehicle display 27 is, for example, an MID. The in-vehicle display 27 may also be an instrument panel. The DCM 28 is an in-vehicle communication module. The DCM 28 is configured to enable bidirectional data communication between the central ECU 21 and the server 11.
[0033] 4 is a block diagram showing a typical configuration example of the user terminal 3. The user terminal 3 includes a processing unit 31, an input device 32, a display 33, and a communication device 34. The input device 32 and the display 33 are integrally configured as, for example, a touch panel display. However, the input device 32 may be a dedicated input device (such as a keyboard or mouse), and the display 33 may be a stationary monitor. The other configuration of the user terminal 3 is the same as that of the server 11 (see FIG. 2).
[0034] <User License> The software update of the individual ECU 22 may be performed at the user's home or while the user is out. In this embodiment, information for obtaining the user's permission is presented to the user prior to the software update of the individual ECU 22. Hereinafter, this information will be referred to as "license information." The license information includes, but is not limited to, information regarding the software license agreement. The license information may include information explaining the contents of the software update, or may include information (a so-called manual) explaining how to use the vehicle 2 after the software update. The license information corresponds to the "data" (first data and second data) according to the present disclosure.
[0035] It is desirable to provide license information to users appropriately without impairing user convenience. While license information can be displayed on the in-vehicle display 27 or the user terminal 3, the user terminal 3 is considered more suitable than the in-vehicle display 27. Many users use the user terminal 3 to search for and view various information (text information, video information, etc.) on a daily basis, and are familiar with operating the user terminal 3. In addition, in many cases, the user terminal 3 is also easy to operate, with scrolling and pinching operations being easy.
[0036] The present inventors have noticed that if license information is displayed in the same manner on the user terminal 3 and the in-vehicle display 27, this uniformity may result in reduced user convenience. Therefore, in this embodiment, a configuration is adopted in which the information granularity of the license information is changed between the user terminal 3 and the in-vehicle display 27. More specifically, the OTA center 1 sets the information granularity of the license information displayed on the user terminal 3 to be higher than the information granularity of the license information displayed on the in-vehicle display 27. High information granularity refers to a state in which various information elements are included in one piece of information.
[0037] Fig. 5 is a diagram showing an example of the data structure of the license information 54 in this embodiment. Fig. 6 is a diagram showing another example of the data structure of the license information 54 in this embodiment. The license information 54 (see Fig. 2) stored in the storage 113 of the server 11 includes a header (metadata) 81 and a body (data body) 82. The header 81 may include the creator of the data, the creation date, the title, tags, the data type, the data length, etc. The body 82 includes the license information.
[0038] In the example shown in FIG. 5, the license information 54 includes text information for obtaining user permission for a software update. The amount of information (amount of description) of the text information displayed on the user terminal 3 is greater than the amount of information displayed on the in-vehicle display 27. As a specific example, the entire text information (e.g., items and detailed explanations of each item) is displayed on the user terminal 3, whereas particularly important parts of the text information (e.g., only the items, or items and simple explanations of each item) are extracted and displayed on the in-vehicle display 27. This is an example of high information granularity in the license information 54 displayed on the user terminal 3.
[0039] 6, the license information 54 displayed on the user terminal 3 includes video information in addition to text information. The video information may be an animation that visually explains the contents of the software update, an animation that explains the procedures required for the software update (preparation, precautions, etc.), or a video manual on how to use the vehicle 2 after the software update. On the other hand, the license information 54 displayed on the in-vehicle display 27 includes text information but does not include video information. This is another example of license information 54 displayed on the user terminal 3 with high information granularity.
[0040] As described above, in this embodiment, the license information 54 displayed on the user terminal 3 has higher information granularity than the in-vehicle display 27. In other words, the amount of information in the license information 54 displayed on the user terminal 3 is greater than the amount of information in the license information 54 displayed on the in-vehicle display 27. This allows the user to approve a software update after checking the details of the license information 54 on the user terminal 3. This improves user convenience.
[0041] <Processing flow> 7 is a flowchart showing a first example of a processing procedure for obtaining user permission for a software update. The processing shown in this flowchart is executed when a predetermined condition is met (for example, when new software to be updated is registered in the OTA center 1). In the figure, the left side shows processing executed by the vehicle 2, the center shows processing executed by the OTA center 1, and the right side shows processing executed by the user terminal 3. Hereinafter, step will be abbreviated as S.
[0042] First, the OTA center 1 transmits license information to the vehicle 2 to be displayed on the in-vehicle display 27, and also transmits license information to the user terminal 3 to be displayed on the display 33 of the user terminal 3 (S111). The OTA center 1 may transmit the license information to the vehicle 2 and the user terminal 3 at different times, or may transmit the license information at substantially the same time. The OTA center 1 may transmit the license information to the vehicle 2 in response to a request from the vehicle 2, and may transmit the license information to the user terminal 3 in response to a request from the user terminal 3. As described with reference to FIGS. 5 and 6, the information granularity of the license information displayed on the display 33 of the user terminal 3 is higher than the information granularity of the license information displayed on the in-vehicle display 27.
[0043] In this example, the user performs an operation to view the license information on the user terminal 3. In response to this, the user terminal 3 displays the license information on the display 33 (S311).
[0044] Before the user performs an operation to grant permission for a software update, the user may interrupt the viewing of the license information due to an emergency, etc. In this case, the user terminal 3 transmits the interrupted portion of the license information (information indicating how far the license information has been viewed) to the OTA center 1 (S312). Upon receiving the interrupted portion of the license information, the OTA center 1 records it in the storage 113 (S112).
[0045] The user resumes viewing the license information, for example, at a time that is convenient for the user. In this example, a situation is assumed in which the user resumes viewing the license information using the user terminal 3. When the user terminal 3 receives a user operation to resume viewing, it transmits a request to resume viewing to the OTA center 1 (S313). In response to the request from the user terminal 3, the OTA center 1 transmits the interruption point recorded in S112 to the user terminal 3 (S113). In response, the user terminal 3 displays the license information from the interruption point (S314).
[0046] Thereafter, upon receiving a user operation permitting the software update, the user terminal 3 transmits the user's consent to the OTA center 1 (S315). Accordingly, although not shown, a series of processes for updating the software (the aforementioned download, installation, and activation) are executed in the vehicle 2.
[0047] In this way, when a user interrupts viewing of license information and then resumes viewing, it is preferable to continue viewing the license information from the interrupted point, which eliminates the need for the user to re-view the license information that was already viewed before the interruption, further improving user convenience.
[0048] 8 is a flowchart showing a second example of a processing procedure for obtaining user permission for a software update. In this example, a situation is assumed in which the user resumes viewing the license information on the vehicle 2 (on-board display 27) after interrupting viewing the license information on the user terminal 3. The processing up to S122 is the same as the corresponding processing in FIG. 7.
[0049] When the vehicle 2 receives a user operation to resume browsing, it notifies the OTA center 1 of a request to resume browsing (S221). In response to the request from the vehicle 2, the OTA center 1 transmits the interruption point recorded in S122 to the vehicle 2 (S123). The vehicle 2 displays the license information from the interruption point on the in-vehicle display 27 (S222). Thereafter, when the vehicle 2 receives a user operation to permit the software update, it transmits the user's consent to the OTA center 1 (S223).
[0050] 9 is a flowchart showing a third example of the processing procedure for obtaining user permission for a software update. Although detailed description will not be repeated, as shown in FIG. 9, contrary to FIG. 8, the license information may be viewed first in vehicle 2, and then the viewing of the license information may be handed over to user terminal 3.
[0051] In this way, when a user interrupts viewing of the license information and then resumes viewing, it is preferable to resume the license information from the interrupted point, even if the terminal used to view the license information is changed before and after the interruption (in other words, regardless of whether the license information is viewed in the vehicle 2 or the user terminal 3). This eliminates the need for the user to re-view the license information that they have already viewed before the interruption, as in FIG. 7, thereby further improving user convenience.
[0052] 10 is a flowchart showing a fourth example of the processing procedure for obtaining user permission for a software update. In FIG. 10, as in FIG. 9, when viewing of the license information is interrupted in the vehicle 2, the OTA center 1 records the interruption point (S142). Then, the user resumes viewing of the license information using the user terminal 3. When the user terminal 3 accepts a user operation to resume viewing, it transmits a request to resume viewing to the OTA center 1 (S341). The OTA center 1 receives the request from the user terminal 3.
[0053] In this example, although the interruption point is recorded in S142, the OTA center 1 sends a command to the user terminal 3 to view the license information from the beginning (S143). The user terminal 3 displays the license information from the beginning in accordance with the command (S342). After that, upon receiving a user operation to authorize the software update, the user terminal 3 transmits the user's authorization to the OTA center 1 (S343).
[0054] In this way, when the user interrupts viewing the license information using the vehicle 2 and then resumes viewing using the user terminal 3, the OTA center 1 may cause all of the license information to be displayed from the beginning on the user terminal 3. This allows the user to view the entire license information using the user terminal 3, which the user is familiar with and has excellent operability. This allows the user to carefully and efficiently view the license information.
[0055] As described above, in this embodiment, the information granularity of the license information is set so that the license information is displayed in a display format appropriate for the terminal, taking into account the operational proficiency and / or operability of each terminal. Specifically, the information granularity of the license information displayed on the user terminal 3 is set higher than the information granularity of the license information displayed on the in-vehicle display 27. This allows the user, when using the user terminal 3, to approve a software update after checking the license information in detail. On the other hand, when using the in-vehicle display 27, the user can approve a software update after checking the license information briefly. Therefore, this embodiment can improve user convenience.
[0056] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0057] 1 OTA center, 11 server, 111 processor, 112 memory, 113 storage, 114 network interface, 12 input device, 13 display, 14 communication device, 2 vehicle, 21 central ECU, 22 individual ECU, 211, 221 processor, 212, 222 memory, 213, 223 storage, 214, 224 network interface, 23 ADAS, 24 ADS, 25 sensor group, 26 input device, 27 in-vehicle display, 3 user terminal, 31 arithmetic processing unit, 311 processor, 312 memory, 313 storage, 314 network interface, 32 input device, 33 display, 34 communication device, 51, 61, 71 system program, 52, 62, 72 control program, 53 update program, 54 license information, 81 header, 82 body, 100 information processing system.
Claims
1. A server that transmits data for updating software of a vehicle control device via wireless communication, A memory in which a program is stored; a processor that executes the program, the processor sets first data to be displayed on an in-vehicle display to obtain user consent regarding the software update, and second data to be displayed on a user terminal to obtain user consent regarding the software update; The information granularity of the second data is higher than the information granularity of the first data.
2. The server according to claim 1 , wherein an amount of character information included in the second data is greater than an amount of character information included in the first data.
3. the second data includes video information; The server according to claim 1 , wherein the first data does not include the video information.
4. The server according to any one of claims 1 to 3, wherein when the user views the second data partway using the user terminal and then further views the first data using the in-vehicle display, the processor sets the first data displayed on the in-vehicle display to be a continuation of the second data that was partway viewed using the user terminal.
5. The server according to any one of claims 1 to 3, wherein when the user views the first data partway using the in-vehicle display and then further views the second data using the user terminal, the processor sets the second data displayed on the user terminal to be a continuation of the first data that was partway viewed using the in-vehicle display.
6. A server as described in any one of claims 1 to 3, wherein when the user views the first data partway using the in-vehicle display and then further views the second data using the user terminal, the processor also sets the part of the first data that the user has already viewed using the in-vehicle display to the second data displayed on the user terminal.
7. A program executed by a computer to update software of a vehicle control device via wireless communication, When executed by the computer, the computer setting first data to be displayed on an in-vehicle display to obtain user consent regarding the software update, and second data to be displayed on a user terminal to obtain user consent regarding the software update; and displaying corresponding data of the first data and the second data on at least one of the in-vehicle display and the user terminal; The information granularity of the second data is higher than the information granularity of the first data.
8. A software update method for updating software of a vehicle control device via wireless communication, comprising: setting first data to be displayed on an in-vehicle display to obtain user consent regarding the software update, and second data to be displayed on a user terminal to obtain user consent regarding the software update; displaying corresponding data of the first data and the second data on at least one of the in-vehicle display and the user terminal; A software update method, wherein the information granularity of the second data is higher than the information granularity of the first data.
Citation Information
Patent Citations
Vehicle control system
JP2017149323A