Updating system
The update device optimizes software updates in mobile objects by using context-dependent authentication methods to balance speed and security, ensuring timely updates without compromising safety.
Patent Information
- Application Number
- JP2024022675
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-19
- Publication Date
- 2025-08-29
AI Technical Summary
The challenge of software updates in mobile objects, such as vehicles, is the need to balance security and efficiency, as stringent authentication procedures increase update time while lowering security levels compromise safety.
An update device that determines whether to use a first or second authentication method based on predetermined conditions, such as location or purpose, allowing for faster updates with appropriate security levels depending on the context.
This approach enables efficient software updates by minimizing time and maintaining security, particularly in factory environments where prompt responses are needed.
Smart Images

Figure 2025126476000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an update device. [Background technology]
[0002] BACKGROUND ART In a vehicle manufacturing process, a technology for remotely controlling a vehicle to operate unmanned is known (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2017-538619 Summary of the Invention [Problem to be solved by the invention]
[0004] If a defect occurs during the vehicle manufacturing process, it may become necessary to update the software that controls the vehicle. This software update requires a specific authentication procedure, which increases the time required for the software update. On the other hand, lowering the security level of the authentication conditions makes it difficult to ensure the security of the software. This problem is not limited to vehicles, but is common to any mobile object. [Means for solving the problem]
[0005] The present disclosure can be realized in the following forms.
[0006] (1) According to one aspect of the present disclosure, there is provided an update device for updating software stored in a mobile object, the update device including a determination unit for determining whether the software can be updated, the determination unit acquiring update target information that is information relating to at least one of the software and the mobile object, determining whether the update can be performed using a first method if the update target information satisfies a predetermined condition, and determining whether the update can be performed using a second method that has a higher security level than the first method if the update target information does not satisfy the predetermined condition. According to this embodiment, in a first case where the update target information satisfies a predetermined condition, the control device determines whether or not to update using a first method, and in a second case where the update target information does not satisfy the predetermined condition, the control device determines whether or not to update using a second method that has a higher security level than the first method. Therefore, in the first case, the control device can easily determine whether or not to update using the first method, which has a lower security level than the second method, thereby preventing an increase in the time required for updating software. Furthermore, in the second case, the control device can determine whether or not to update using the second method, which has a higher security level than the first method, thereby preventing a decrease in security level compared to a configuration in which the control device always determines whether or not to update using the first method. (2) In the above embodiment, the predetermined condition may include that the moving object is located within a predetermined area. According to this form of control device, the predetermined condition includes that the moving body is located within a predetermined area, so that the first method and the second method can be appropriately used depending on whether the moving body is located within the predetermined area or not. (3) In the above embodiment, the predetermined condition may include that the software is software that is used when the moving object is present within a predetermined area. According to this form of control device, the software includes software that is used when a moving body is present within a predetermined area, so that the first method and the second method can be appropriately used depending on whether the software is software that is used when a moving body is present within a predetermined area or not. (4) In the above embodiment, the predetermined condition may include that the software is stored in a predetermined device. According to this form of control device, the predetermined condition includes that the software is stored in the predetermined device, so that the first method and the second method can be easily used depending on whether the software is stored in the predetermined device or not. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a conceptual diagram showing the configuration of a system according to a first embodiment. [Figure 2] 1 is a block diagram showing a configuration of a system according to a first embodiment. [Figure 3] 4 is a flowchart showing a processing procedure for vehicle travel control in the first embodiment. [Figure 4] 10 is a flowchart showing the procedure of an update process in the first embodiment. [Figure 5] 10 is a flowchart showing the procedure of an update process in the second embodiment. [Figure 6] FIG. 10 is a block diagram showing the configuration of a system according to a third embodiment. [Figure 7] 10 is a flowchart showing a processing procedure for vehicle travel control in a third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] A. First embodiment: A-1. System Configuration: 1 is a conceptual diagram showing the configuration of a system 10 according to a first embodiment. The system 10 includes one or more vehicles 100 as moving objects, a server device 200, one or more external sensors 300, and a process control device 400 that controls the manufacturing of the vehicles 100 in a factory FC.
[0009] In this disclosure, a "mobile body" refers to an object that can move, such as a vehicle or an electric vertical take-off and landing aircraft (a so-called flying car). A vehicle may be a vehicle that runs on wheels or a vehicle that runs on tracks, such as a passenger car, truck, bus, motorcycle, automobile, tank, or construction vehicle. Vehicles include electric vehicles (BEVs: Battery Electric Vehicles), gasoline-powered vehicles, hybrid vehicles, and fuel cell vehicles. When a mobile body is something other than a vehicle, the terms "vehicle" and "car" in this disclosure may be appropriately replaced with "mobile body," and the term "traveling" may be appropriately replaced with "moving."
[0010] The vehicle 100 is configured to be capable of traveling in an unmanned manner. "Unmanned driving" refers to driving without the driver's control. Driving operation refers to operations related to at least one of "running," "turning," and "stopping" of the vehicle 100. Unmanned driving is achieved by automatic or manual remote control using a device located outside the vehicle 100, or by autonomous control of the vehicle 100. A vehicle 100 traveling in an unmanned manner may have a driver on board who does not operate the vehicle. A driver who does not operate the vehicle may, for example, simply be seated in the vehicle 100, or a person who is riding in the vehicle 100 and performing work other than driving operations, such as assembly, inspection, or operating switches. Driving in which a driver controls the vehicle is sometimes called "manned driving."
[0011] In this specification, "remote control" includes "full remote control," in which all of the vehicle 100's operations are completely determined from outside the vehicle 100, and "partial remote control," in which some of the vehicle 100's operations are determined from outside the vehicle 100. Furthermore, "autonomous control" includes "full autonomous control," in which the vehicle 100 autonomously controls its own operations without receiving any information from devices external to the vehicle 100, and "partial autonomous control," in which the vehicle 100 autonomously controls its own operations using information received from devices external to the vehicle 100. In the following description, control for driving the vehicle 100 achieved by remote control or autonomous control is also referred to as "driving control." Driving control corresponds to "mobility control" in this disclosure.
[0012] In this embodiment, the system 10 is used in a factory FC that manufactures vehicles 100. The reference coordinate system of the factory FC is a global coordinate system GC. That is, any position in the factory FC is expressed by X, Y, and Z coordinates in the global coordinate system GC. The factory FC has a first location PL1 and a second location PL2. The first location PL1 and the second location PL2 are connected by a road TR along which the vehicle 100 can travel. A plurality of external sensors 300 are installed along the road TR in the factory FC. The position of each external sensor 300 in the factory FC is adjusted in advance. The vehicle 100 moves from the first location PL1 to the second location PL2 along the road TR in an unmanned operation.
[0013] The external sensor 300 is a sensor located outside the vehicle 100, and acquires information about the vehicle 100. In this embodiment, the external sensor 300 is a sensor that captures the vehicle 100 from outside the vehicle 100. Specifically, the external sensor 300 is configured by a camera. The camera as the external sensor 300 captures an image including the vehicle 100, and outputs the captured image as a detection result. The external sensor 300 is equipped with a communication device (not shown), and can communicate with other devices such as the server device 200 via wired communication or wireless communication.
[0014] 2 is a block diagram showing the configuration of the system 10 of the first embodiment. The vehicle 100 includes a vehicle control device 110 for controlling each part of the vehicle 100, an actuator group 120 including one or more actuators that are driven under the control of the vehicle control device 110, and a communication device 130 for communicating via wireless communication with external devices such as a server device 200. The actuator group 120 includes an actuator of a drive device for accelerating the vehicle 100, an actuator of a steering device for changing the traveling direction of the vehicle 100, and an actuator of a braking device for decelerating the vehicle 100. In addition, the vehicle 100 may include various sensors (not shown) such as a vehicle speed sensor and a yaw rate sensor.
[0015] The vehicle control device 110 is configured by a computer including a processor 111, a memory 112, an input / output interface 113, and an internal bus 114. The processor 111, the memory 112, and the input / output interface 113 are connected via the internal bus 114 to enable bidirectional communication. The input / output interface 113 is connected to an actuator group 120 and an interface. The processor 111 executes a program PG1 stored in the memory 112 to realize various functions, including the function of a vehicle control unit 115. In this embodiment, the processor 111 functions as the vehicle control unit 115, a determination unit 116, a permission unit 117, and an update unit 118.
[0016] The vehicle control unit 115 controls the actuator group 120 to cause the vehicle 100 to run. The vehicle control unit 115 controls the actuator group 120 using a running control signal received from the server device 200 to cause the vehicle 100 to run. The running control signal is a control signal for causing the vehicle 100 to run. In this embodiment, the running control signal includes the acceleration and steering angle of the vehicle 100 as parameters. In other embodiments, the running control signal may include the speed of the vehicle 100 as a parameter instead of or in addition to the acceleration of the vehicle 100.
[0017] The determination unit 116 determines whether software stored in the vehicle 100 can be updated. In this embodiment, the determination unit 116 determines whether the software can be updated by determining whether authentication information output from the terminal device 500 satisfies authentication conditions. The terminal device 500 is a device operated by a user to update software stored in the vehicle 100. In this embodiment, the program PG1 stored in the memory 112 of the vehicle 100 corresponds to the "software." Note that the "software" is not limited to the program PG1, but also includes software pre-stored in the memory 112 and software downloaded from the server device 200 and stored in the memory 112 as needed, such as software that realizes various functions for a parts assembly process or an inspection process executed in the manufacturing process of the vehicle 100. Multiple terminal devices 500 may be installed in the factory FC, or only one terminal device 500 may be installed. Note that the terminal device 500 is not limited to a stationary device as shown in FIG. 1, but may also be a mobile terminal such as a smartphone.
[0018] When performing a software update, the terminal device 500 outputs authentication information to the vehicle 100 that is the target of the update. "Authentication information" refers to information used to determine whether or not the software can be updated in the update process described below. The authentication information includes, for example, a login password for the software update application, a user ID that identifies the user who executes the update process, a device ID that identifies the terminal device 500 that executes the update process, and information that specifies the software to be updated.
[0019] When it is determined that the authentication information satisfies the authentication conditions, the permission unit 117 permits the terminal device 500 to update the software. When the software update is permitted, the update unit 118 updates the software in response to a software update request from the terminal device 500. That is, when it is determined that the authentication information satisfies the authentication conditions, the update unit 118 updates the software. Note that the processor 111 does not necessarily have to include the permission unit 117.
[0020] As described above, the vehicle control device 110 of this embodiment functions as the determination unit 116, the permission unit 117, and the update unit 118, and updates the software stored in the vehicle 100 when the authentication information satisfies the authentication conditions. In other words, the vehicle control device 110 of this embodiment corresponds to the "update device" in the present disclosure.
[0021] The server device 200 is configured by a computer including a processor 201, a memory 202, an input / output interface 203, and an internal bus 204. The processor 201, the memory 202, and the input / output interface 203 are connected via the internal bus 204 to enable bidirectional communication. A communication device 205 is connected to the input / output interface 203 to communicate with various devices external to the server device 200. The communication device 205 can communicate with the vehicle 100 via wireless communication, and can communicate with each external sensor 300 and the process control device 400 via wired communication or wireless communication.
[0022] The processor 201 executes the program PG2 stored in the memory 202 to realize various functions including the function of the remote control unit 210. In this embodiment, the processor 201 functions as the remote control unit 210 and a corresponding unit 211.
[0023] The remote control unit 210 acquires the detection results from the external sensor 300, generates a driving control signal that instructs the control content of the actuator group 120 of the vehicle 100 using the detection results, and transmits the driving control signal to the vehicle 100, thereby causing the vehicle 100 to drive by remote control. The processing procedure for driving control realized by remote control in this embodiment will be described later. The remote control unit 210 may generate and output not only driving control signals but also control signals for controlling actuators that operate various accessories provided in the vehicle 100 and various equipment such as wipers, power windows, and lamps. In other words, the remote control unit 210 may operate these various equipment and accessories by remote control.
[0024] The response unit 211 responds to an inquiry when it receives an inquiry from the determination unit 116 during update processing, which will be described later. The processing of the response unit 211 when it receives an inquiry from the determination unit 116 will be described later.
[0025] The process control device 400 is a device for managing the manufacturing process of the vehicle 100. The process control device 400 is configured with a computer. The process control device 400 acquires information from various facilities in the factory FC, generates information about the manufacturing process of the vehicle 100, which is the product, and manages the information for each vehicle 100. In the following description, the information about the product manufacturing process is referred to as process information. In this embodiment, the process information includes information indicating when, where, which worker is scheduled to perform what work on which product; information indicating when, where, which worker performed what work on which product; and information indicating the progress of the work. The process control device 400 includes a communication device (not shown) and transmits the process information to the server device 200 via wired or wireless communication. Note that the functions of the process control device 400 may be implemented in the same device as the server device 200. Furthermore, the system 10 does not necessarily have to include the process control device 400.
[0026] A-2. Driving control: 3 is a flowchart showing the processing procedure for driving control of the vehicle 100 in the first embodiment. In step S1, the remote control unit 210 acquires vehicle position information of the vehicle 100 using the detection results output from the external sensor 300. The vehicle position information is position information that forms the basis for generating a driving control signal. In this embodiment, the vehicle position information includes the position and orientation of the vehicle 100 in the global coordinate system GC of the factory FC. Specifically, in step S1, the remote control unit 210 acquires the vehicle position information using a captured image acquired from a camera, which is the external sensor 300.
[0027] In detail, in step S1, the remote control unit 210, for example, detects the outer shape of the vehicle 100 from the captured image, calculates the coordinates of the positioning point of the vehicle 100 in the coordinate system of the captured image, i.e., the local coordinate system, and converts the calculated coordinates into coordinates in the global coordinate system GC, thereby acquiring the position of the vehicle 100. The outer shape of the vehicle 100 contained in the captured image can be detected, for example, by inputting the captured image into a detection model DM that utilizes artificial intelligence. The detection model DM is prepared, for example, inside or outside the system 10 and pre-stored in the memory 202 of the server device 200. The detection model DM can be, for example, a trained machine learning model that has been trained to achieve either semantic segmentation or instance segmentation. For example, a convolutional neural network (hereinafter, CNN) trained by supervised learning using a training dataset can be used as this machine learning model. The training dataset includes, for example, a plurality of training images including the vehicle 100, and labels indicating whether each region in the training images represents the vehicle 100 or a region other than the vehicle 100. During CNN training, it is preferable to update the CNN parameters using backpropagation (backpropagation) to reduce the error between the output result of the detection model DM and the label. Furthermore, the remote control unit 210 can acquire the orientation of the vehicle 100 by estimating the orientation based on the orientation of the movement vector of the vehicle 100 calculated from the positional changes of feature points of the vehicle 100 between frames of captured images, for example, using an optical flow method.
[0028] In step S2, the remote control unit 210 determines a target position to which the vehicle 100 should next head. In this embodiment, the target position is represented by X, Y, and Z coordinates in the global coordinate system GC. A reference route RR, which is the route the vehicle 100 should travel, is stored in advance in the memory 202 of the server device 200. The route is represented by nodes indicating the departure point, nodes indicating passing points, nodes indicating the destination, and links connecting the nodes. The remote control unit 210 uses the vehicle position information and the reference route RR to determine a target position to which the vehicle 100 should next head. The remote control unit 210 determines a target position on the reference route RR that is ahead of the current location of the vehicle 100.
[0029] In step S3, the remote control unit 210 generates a travel control signal for driving the vehicle 100 toward the determined target position. The remote control unit 210 calculates the travel speed of the vehicle 100 from the change in the position of the vehicle 100 and compares the calculated travel speed with the target speed. When the travel speed is lower than the target speed, the remote control unit 210 determines an acceleration such that the vehicle 100 accelerates. When the travel speed is higher than the target speed, the remote control unit 210 determines an acceleration such that the vehicle 100 decelerates. Furthermore, when the vehicle 100 is located on the reference route RR, the remote control unit 210 determines a steering angle and acceleration such that the vehicle 100 does not deviate from the reference route RR. When the vehicle 100 is not located on the reference route RR, in other words, when the vehicle 100 has deviated from the reference route RR, the remote control unit 210 determines a steering angle and acceleration such that the vehicle 100 returns to the reference route RR.
[0030] In step S4, the remote control unit 210 transmits the generated driving control signal to the vehicle 100. The remote control unit 210 repeats, at a predetermined cycle, obtaining the position of the vehicle 100, determining the target position, generating the driving control signal, and transmitting the driving control signal.
[0031] In step S5, vehicle control unit 115 receives the driving control signal transmitted from server device 200. In step S6, vehicle control unit 115 controls actuator group 120 using the received driving control signal, thereby causing vehicle 100 to drive at the acceleration and steering angle indicated in the driving control signal. Vehicle control unit 115 repeats receiving the driving control signal and controlling actuator group 120 at a predetermined cycle. According to system 10 in this embodiment, vehicle 100 can be driven by remote control, and vehicle 100 can be moved without using transportation equipment such as a crane or conveyor.
[0032] A-3. Update process: 4 is a flowchart showing the procedure of the update process in the first embodiment. The "update process" is a process of updating software stored in the vehicle 100 in response to a request from the terminal device 500. The terminal device 500 outputs the above-mentioned authentication information when a predetermined start operation is input by the user, and the update process starts when the authentication information is output from the terminal device 500.
[0033] In step S102, the determination unit 116 acquires the authentication information output from the terminal device 500.
[0034] In step S104, the determination unit 116 determines whether the vehicle 100 is in an environment in which software can be updated. The "environment in which software can be updated" refers to an environment that has been set in advance as an environment in which executing a software update will not interfere with the control of the vehicle 100. For example, if an environment in which "the vehicle 100 is stopped and the software to be updated is not in use" is set, the determination unit 116 determines that the vehicle 100 is in an environment in which software can be updated if the current environment of the vehicle 100 matches this case. If it is determined that the vehicle 100 is not in an environment in which software can be updated (step S104: No), in step S120, the permission unit 117 does not permit the software update, and the update process ends.
[0035] If it is determined that the vehicle 100 is in an environment where an update is possible (step S104: Yes), in step S106, the determination unit 116 determines whether or not the vehicle 100 can make the determination in step S108, which will be described later. As will be described later, in this embodiment, the determination is made in step S108 using the location information of the vehicle 100. The "location information of the vehicle 100" is information related to the vehicle 100 that is the target of update, and corresponds to the "information to be updated" in this disclosure. In step S106, if the vehicle 100 is aware of its own location information, the determination unit 116 determines that the vehicle 100 can make the determination in step S108. "If the vehicle 100 is aware of its own location information" refers to, for example, a case where the vehicle 100 has received and stored the location information of the vehicle 100 together with a traveling control signal, or a case where the vehicle 100 is equipped with a location sensor such as a GPS sensor and the location information of the vehicle 100 is detected by the location sensor.
[0036] If it is determined that the determination can be made on the vehicle 100 side (step S106: Yes), in step S108, the determination unit 116 determines whether the vehicle 100 is located within a factory FC. "Inside the factory FC" corresponds to the "predetermined area" in this disclosure. Also, "the vehicle 100 being located within the factory FC" corresponds to the "predetermined condition" in this disclosure.
[0037] If it is determined that the determination is not possible on the vehicle 100 side (step S106: No), in step S110, the determination unit 116 makes an inquiry to the server device 200. When the inquiry is received, the response unit 211 in the server device 200 responds to the determination unit 116 with the above-mentioned vehicle position information. Alternatively, the response unit 211 may respond to the determination unit 116 with the result of determining whether or not the vehicle 100 is located within the factory FC using the vehicle position information, instead of the vehicle position information. Thereafter, the determination unit 116 executes the above-mentioned step S108.
[0038] If it is determined that the vehicle 100 is located within a factory FC (step S108: Yes), in step S112, the determination unit 116 determines whether the authentication information satisfies a first authentication condition. Here, "determining whether the authentication information satisfies the first authentication condition" corresponds to the determination by the "first method" in the present disclosure. In the present embodiment, the determination unit 116 determines whether the login password is correct as the first authentication condition. Note that instead of determining whether the login password is correct, the determination unit 116 may determine whether the user of the terminal device 500 has software update authority or whether the terminal device 500 has been approved as a device that can perform software updates. "If it is determined that the vehicle 100 is located within a factory FC" corresponds to the "first case" in the present disclosure.
[0039] If it is determined that the first authentication condition is satisfied (step S112: Yes), in step S116, the permission unit 117 permits the terminal device 500 to update the software, and in step S118, the update unit 118 updates the software in accordance with the update content of the software by the terminal device 500. Thereafter, the update process ends.
[0040] If it is determined that the first authentication condition is not satisfied (step S112: No), the permission unit 117 disallows the software update in step S120, after which the update process ends.
[0041] If it is determined in step S108 that the vehicle 100 is not located within a factory FC (step S108: No), in step S114, the determination unit 116 determines whether the authentication information satisfies a second authentication condition. Here, "determining whether the authentication information satisfies the second authentication condition" corresponds to a determination using a "second method" in the present disclosure. In the present embodiment, the determination unit 116 determines, as the second authentication condition, whether the login password is correct, whether the user of the terminal device 500 has software update authority, and whether the terminal device 500 has been approved as a device that performs software updates. In other words, the second authentication condition has more requirements to be satisfied than the first authentication condition. For this reason, the second authentication condition can be said to have a higher security level than the first authentication condition, and the second method using the second authentication condition has a higher security level than the first method using the first authentication condition. "If it is determined that the vehicle 100 is not located within a factory FC" corresponds to the "second case" in the present disclosure.
[0042] If it is determined that the second authentication condition is met (step S114: Yes), the above-mentioned steps S116 and S118 are executed, and then the update process ends.
[0043] If it is determined that the second authentication condition is not satisfied (step S112: No), the above-mentioned step S120 is executed, and then the update process ends.
[0044] As described above, in this embodiment, when it is determined that the vehicle 100 is located within the factory FC, authentication is performed using the first authentication condition, which has a lower security level than the second authentication condition when it is determined that the vehicle 100 is not located within the factory FC. This is because when the vehicle 100 is located within the factory FC, it is considered that only workers at the factory FC or the like are attempting to perform a software update, and the security risk is lower than when the vehicle 100 is located outside the factory FC. That is, in general, the determination unit 116 appropriately uses the first method, which uses the first authentication condition, and the second method, which uses the second authentication condition, depending on predetermined conditions related to the security risk of the software update. In addition, when the vehicle 100 is located within the factory FC and a software update is being performed, it is considered that an attempt is being made to resolve some kind of defect that occurred during the manufacturing process of the vehicle 100, and a prompt response is required.
[0045] According to the system 10 of the first embodiment described above, when it is determined that the vehicle 100 is located within a factory FC, it is determined whether a first authentication condition is satisfied as an authentication condition. When it is determined that the vehicle 100 is not located within a factory FC, it is determined whether a second authentication condition, which has a higher security level than the first authentication condition, is satisfied as an authentication condition. Therefore, when it is determined that the vehicle 100 is located within a factory FC, authentication can be easily performed using the first authentication condition, which has a lower security level than the second authentication condition, thereby preventing an increase in the time required for software updates. Furthermore, when it is determined that the vehicle 100 is not located within a factory FC, authentication can be performed using the second authentication condition, which has a higher security level than the first authentication condition, thereby preventing a decrease in security level compared to a configuration in which authentication is always performed using the first authentication condition.
[0046] Furthermore, the first authentication condition and the second authentication condition can be used appropriately depending on whether the vehicle 100 is located inside the factory FC.
[0047] B. Second embodiment: Fig. 5 is a flowchart showing the procedure of the update process in the second embodiment. As shown in Fig. 5, the system 10 of the second embodiment differs from the system 10 of the first embodiment in that the system 10 executes step S108a instead of step S108 in the update process. The device configuration of the system 10 of the second embodiment and other procedures in the update process are the same as those of the system 10 of the first embodiment, so the same configurations and procedures are denoted by the same reference numerals and detailed description thereof will be omitted.
[0048] In step S106 shown in FIG. 5, the determination unit 116 determines whether the determination in step S108a, which will be described later, can be performed on the vehicle 100 side. As will be described later, in this embodiment, in step S108a, a determination is performed according to the purpose of the software to be updated. The "purpose of the software to be updated" is information related to the software to be updated, and corresponds to "update target information" in this disclosure. In step S106 of this embodiment, if the software for controlling the vehicle 100 is stored in the memory 112 of the vehicle 100 in a manner that enables its purpose to be determined, the determination unit 116 determines that the determination in step S108a can be performed on the vehicle 100 side. "If the software for controlling the vehicle 100 is stored in a manner that enables its purpose to be determined" refers to, for example, a case where a database that manages the purpose of each piece of software is stored in the memory 112 in advance, or a case where the extension of each piece of software is predetermined according to the purpose of each piece of software.
[0049] If it is determined that the determination can be made on the vehicle 100 side (step S106: Yes), in step S108a, the determination unit 116 determines whether the software to be updated is intended for use in a factory. Here, "the software to be updated is intended for use in a factory" means that the software is used when the vehicle 100 is located within the factory FC and is not used when the vehicle 100 is located outside the factory FC. More specifically, "software that is used when the vehicle 100 is located within the factory FC and is not used when the vehicle 100 is located outside the factory FC" corresponds to software that realizes various functions for a part assembly process and an inspection process that are executed in the manufacturing process of the vehicle 100, and does not include functions that can be used by a user of the vehicle 100 after the vehicle 100 is shipped, such as software that realizes an object detection function using an on-board sensor.
[0050] For example, if the database indicates that the software to be updated is intended for factory use, or if the extension of the software to be updated is the same as a predetermined extension indicating that the software is intended for factory use, the determination unit 116 determines that the software is intended for factory use. "The software to be updated is intended for factory use" corresponds to the "predetermined condition" in this disclosure.
[0051] If it is determined that the determination cannot be made on the vehicle 100 side (step S106: No), in step S110, the determination unit 116 makes an inquiry to the server device 200. When receiving the inquiry, the response unit 211 in the server device 200 responds to the determination unit 116 with the purpose of the software to be updated. The response unit 211, for example, refers to a pre-stored database that manages the purpose of each piece of software, to identify the purpose of the software to be updated, and responds to the determination unit 116 with the identified purpose. Note that the response unit 211 may respond to the determination unit 116 with the result of determining whether the purpose is for a factory, instead of the purpose of the software to be updated. Thereafter, the determination unit 116 executes the above-mentioned step S108a.
[0052] If it is determined that the intended use of the software to be updated is for a factory (step S108a: Yes), the determination unit 116 executes step S112 described above. "If it is determined that the intended use of the software to be updated is for a factory" corresponds to the "first case" in the present disclosure. On the other hand, if it is determined that the intended use of the software to be updated is not for a factory (step S108a: No), the determination unit 116 executes step S114 described above. "If it is determined that the intended use of the software to be updated is not for a factory" corresponds to the "second case" in the present disclosure.
[0053] As described above, in this embodiment, when it is determined that the software to be updated is intended for use in a factory, authentication is performed under the first authentication condition, which has a lower security level than the second authentication condition that is used when it is determined that the software to be updated is not intended for use in a factory. This is because when the software to be updated is intended for use in a factory, the software to be updated will not be used by the user of the vehicle 100, and therefore the software update can be said to have little impact on the user of the vehicle 100. Furthermore, when an attempt is made to update factory software, it is considered that an attempt is being made to resolve some kind of defect that occurred during the manufacturing process of the vehicle 100, and a prompt response is required.
[0054] According to the system 10 of the second embodiment described above, when it is determined that the use of the software to be updated is for factory use, it is determined whether or not the first authentication condition is satisfied as an authentication condition, and when it is determined that the use of the software to be updated is not for factory use, it is determined whether or not the second authentication condition, which has a higher security level than the first authentication condition, is satisfied as an authentication condition. Therefore, it is possible to appropriately use the first authentication condition and the second authentication condition depending on whether the use of the software to be updated is for factory use.
[0055] C. Third embodiment: 6 is a block diagram showing the configuration of a system 10v in the third embodiment. In this embodiment, the system 10v differs from the first embodiment in that it does not include a server device 200. Furthermore, the vehicle 100v in this embodiment can travel by autonomous control of the vehicle 100v. The other configurations are the same as those in the first embodiment unless otherwise specified.
[0056] In this embodiment, the processor 111v of the vehicle control device 110v executes a program PG1 stored in the memory 112v, thereby functioning as a vehicle control unit 115v, a determination unit 116, a permission unit 117, and an update unit 118. The vehicle control unit 115v generates a driving control signal using vehicle position information, and outputs the generated driving control signal to operate the actuator group 120, thereby enabling the vehicle 100v to drive by autonomous control. In this embodiment, in addition to the program PG1, a detection model DM and a reference route RR are pre-stored in the memory 112v.
[0057] The vehicle control device 110v of this embodiment functions as a determination unit 116, a permission unit 117, and an update unit 118, similar to the vehicle control device 110 of the first embodiment, and updates software stored in the vehicle 100 when the authentication information satisfies the authentication conditions. That is, the vehicle control device 110v of this embodiment corresponds to the "update device" in the present disclosure.
[0058] In this embodiment, since the system 10v does not have the server device 200, if it is determined in the update process that the vehicle 100 is not capable of making the determination (step S106: No), the determination unit 116 may determine whether the authentication information satisfies the second authentication condition without executing the above-described step S110. Even with this configuration, if the vehicle 100 is capable of making the determination (step S106: Yes) and the vehicle 100 is located in a factory FC (step S108: Yes), the software can be updated if the first authentication condition, which has a lower security level than the second authentication condition, is satisfied, thereby achieving the same effect as the above-described embodiment.
[0059] FIG. 7 is a flowchart showing a processing procedure for controlling the traveling of the vehicle 100v in the third embodiment. In step S11, the processor 111v acquires vehicle position information using the detection results output from the camera, which is the external sensor 300. In step S11 in this embodiment, the processor 111v acquires vehicle position information using a captured image and vehicle speed, similar to step S1 in FIG. 3. In step S12, the processor 111v determines a target position to which the vehicle 100v should next head. In step S13, the processor 111v generates a traveling control signal for causing the vehicle 100v to travel toward the determined target position. In step S14, the processor 111v controls the actuator group 120 using the generated traveling control signal, thereby causing the vehicle 100v to travel in accordance with parameters represented in the traveling control signal. The processor 111v repeats the acquisition of vehicle position information, determination of the target position, generation of the traveling control signal, and control of the actuator group 120 at a predetermined cycle. According to the system 10v of this embodiment, the vehicle 100v can be driven by autonomous control of the vehicle 100v without remotely controlling the vehicle 100v using the server device 200. Furthermore, similar to the above embodiment, the system 10v of this embodiment can appropriately use the first authentication condition and the second authentication condition, thereby suppressing an increase in the time required for software update while suppressing a decrease in the security level.
[0060] D. Other Embodiments: (D1) In the above embodiment, the determination unit 116, the permission unit 117, and the update unit 118 are included in the vehicle control device 110, but the present disclosure is not limited to this. The determination unit 116, the permission unit 117, and the update unit 118 may be included in the server device 200. In such a configuration, the server device 200 corresponds to the "update device" in the present disclosure. Note that, when the server device 200 functions as the update device, steps S106 and S110 in the update process may not be executed, and step S108 may be executed if the determination in step S104 is "Yes."
[0061] (D2) In the above embodiment, the determination unit 116 determines whether the vehicle 100 is located within the factory FC using the location information of the vehicle 100, but the present disclosure is not limited to this. The determination unit 116 may also determine whether the vehicle 100 is located within the factory FC using the process information described above. For example, the determination unit 116 may determine whether the vehicle 100 is located within the factory FC depending on whether the vehicle 100 is located in a process earlier than a predetermined process. More specifically, when the process information of the vehicle 100 is used to identify that the vehicle 100 is located in a process earlier than the final inspection process, the determination unit 116 may determine that the vehicle 100 is located within the factory FC. On the other hand, when the process information of the vehicle 100 is used to identify that the vehicle 100 is located in a process later than the final inspection process, the determination unit 116 may determine that the vehicle 100 is not located within the factory FC. Furthermore, in this embodiment, if the process information is not stored in the memory 112 of the vehicle 100, in the above-described step S110, the determination unit 116 may inquire about the process information from the process control device 400 instead of the server device 200, and acquire the process information from the process control device 400. This embodiment also achieves the same effects as the above-described embodiment.
[0062] (D3) In the above embodiment, the vehicle 100 may include a first control device storing software for a factory and a second control device storing software for a purpose other than a factory. In this embodiment, when the software to be updated is stored in the first control device, the determination unit 116 may determine that the software is for a factory and perform authentication under a first authentication condition. On the other hand, when the software to be updated is stored in the second control device, the determination unit 116 may determine that the software is not for a factory and perform authentication under a second authentication condition. According to this embodiment, software for different purposes is stored in different control devices, which facilitates software management and facilitates the determination in step S108a in the update process of the second embodiment. In this embodiment, the "first control device executing software for a factory" corresponds to the "predetermined device" in this disclosure.
[0063] Furthermore, the vehicle 100 may include, in the vehicle control device 110, a first memory storing factory software and a second memory storing software for uses other than factory use. In this configuration, when the software to be updated is stored in the first memory, the determination unit 116 may determine that the software is for factory use and perform authentication under the first authentication condition. On the other hand, when the software to be updated is stored in the second memory, the determination unit 116 may determine that the software is not for factory use and perform authentication under the second authentication condition. This configuration also facilitates software management because software for different uses is stored in different memories, making it easier to perform the determination in step S108a in the update process of the second embodiment. Note that in this configuration, the "first memory storing factory software" corresponds to the "predetermined device" in this disclosure.
[0064] (D4) In each of the above embodiments, the external sensor 300 is a camera. However, the external sensor 300 does not have to be a camera and may be, for example, a distance measuring device. The distance measuring device may be, for example, a LiDAR (Light Detection and Ranging). In this case, the detection result output by the external sensor 300 may be three-dimensional point cloud data representing the vehicle 100. In this case, the server device 200 or the vehicle 100 may acquire vehicle position information by template matching using the three-dimensional point cloud data as the detection result and reference point cloud data prepared in advance.
[0065] (D5) In the first embodiment, the processes from obtaining vehicle position information to generating a driving control signal are executed by the server device 200. However, at least a part of the processes from obtaining vehicle position information to generating a driving control signal may be executed by the vehicle 100. For example, the following forms (1) to (3) may be used.
[0066] (1) The server device 200 may acquire vehicle position information, determine a target position to which the vehicle 100 should next head, and generate a route from the current location of the vehicle 100 indicated in the acquired vehicle position information to the target position. The server device 200 may generate a route to a target position between the current location and the destination, or may generate a route to the destination. The server device 200 may transmit the generated route to the vehicle 100. The vehicle 100 may generate a driving control signal so that the vehicle 100 drives on the route received from the server device 200, and control the actuator group 120 using the generated driving control signal.
[0067] (2) Server device 200 may acquire vehicle position information and transmit the acquired vehicle position information to vehicle 100. Vehicle 100 may determine a target position to which vehicle 100 should next head, generate a route from the current location of vehicle 100 indicated in the received vehicle position information to the target position, generate a driving control signal so that vehicle 100 travels on the generated route, and control actuator group 120 using the generated driving control signal.
[0068] (3) In the above embodiments (1) and (2), the vehicle 100 may be equipped with an internal sensor, and detection results output from the internal sensor may be used for at least one of generating a route and generating a driving control signal. The internal sensor is a sensor equipped in the vehicle 100. The internal sensor may include, for example, a sensor that detects the motion state of the vehicle 100, a sensor that detects the operating state of each part of the vehicle 100, and a sensor that detects the environment around the vehicle 100. Specifically, the internal sensor may include, for example, a camera, LiDAR, millimeter-wave radar, an ultrasonic sensor, a GPS sensor, an acceleration sensor, a gyro sensor, and the like. For example, in the above embodiment (1), the server device 200 may acquire the detection results of the internal sensor and reflect the detection results of the internal sensor in the route when generating a route. In the above embodiment (1), the vehicle 100 may acquire the detection results of the internal sensor and reflect the detection results of the internal sensor in the driving control signal when creating a driving control signal. In the above embodiment (2), the vehicle 100 may acquire the detection results of the internal sensor and reflect the detection results of the internal sensor in the route when generating a route. In the above embodiment (2), the vehicle 100 may acquire the detection result of the internal sensor, and may reflect the detection result of the internal sensor in the driving control signal when creating the driving control signal.
[0069] (D6) In the third embodiment, the vehicle 100v may be equipped with an internal sensor, and detection results output from the internal sensor may be used for at least one of generating a route and generating a driving control signal. For example, the vehicle 100v may acquire the detection results of the internal sensor and, when generating a route, reflect the detection results of the internal sensor in the route. The vehicle 100v may acquire the detection results of the internal sensor and, when creating a driving control signal, reflect the detection results of the internal sensor in the driving control signal.
[0070] (D7) In the above embodiment in which the vehicle 100 can travel by autonomous control, the vehicle 100 acquires vehicle position information using the detection results of the external sensor 300. Alternatively, the vehicle 100 may be equipped with an internal sensor, and the vehicle 100 may acquire vehicle position information using the detection results of the internal sensor, determine a target position to which the vehicle 100 should next travel, generate a route from the current location of the vehicle 100 represented in the acquired vehicle position information to the target position, generate a driving control signal for traveling along the generated route, and control the actuators of the vehicle 100 using the generated driving control signal. In this case, the vehicle 100 can travel without using any of the detection results of the external sensor 300. The vehicle 100 may acquire a target arrival time or congestion information from outside the vehicle 100 and reflect the target arrival time or congestion information in at least one of the route and the driving control signal. Furthermore, all of the functional configurations of the system 10 may be provided in the vehicle 100. In other words, the processing realized by the system 10 in the present disclosure may be realized by the vehicle 100 alone.
[0071] (D8) In the first embodiment described above, the server device 200 automatically generates the driving control signal to be transmitted to the vehicle 100. However, the server device 200 may generate the driving control signal to be transmitted to the vehicle 100 in accordance with the operation of an external operator located outside the vehicle 100. For example, the external operator may operate a control device including a display that displays an image output from the external sensor 300, a steering wheel for remotely controlling the vehicle 100, an accelerator pedal, a brake pedal, and a communication device for communicating with the server device 200 via wired or wireless communication, and the server device 200 may generate the driving control signal in accordance with the operation applied to the control device.
[0072] (D9) In each of the above embodiments, the vehicle 100 may be configured to be capable of moving by unmanned driving, and may be in the form of a platform having the configuration described below, for example. Specifically, the vehicle 100 may be equipped with at least a control device that controls the traveling of the vehicle 100 and actuators such as a drive device, a steering device, and a braking device in order to perform the three functions of "running," "turning," and "stopping" by unmanned driving. When the vehicle 100 acquires information from the outside for unmanned driving, the vehicle 100 may further be equipped with a communication device. In other words, the vehicle 100 that can move by unmanned driving may not be equipped with at least some of the interior parts such as a driver's seat and a dashboard, may not be equipped with at least some of the exterior parts such as bumpers and fenders, and may not be equipped with a body shell. In this case, the remaining parts such as the body shell may be attached to the vehicle 100 before the vehicle 100 is shipped from the factory FC, or the remaining parts such as the body shell may be attached to the vehicle 100 after the vehicle 100 is shipped from the factory FC without the remaining parts such as the body shell being attached to the vehicle 100. Each part may be attached from any direction, such as the upper side, lower side, front side, rear side, right side, or left side of the vehicle 100, and may be attached from the same direction or from different directions. Note that the position of the platform configuration may also be determined in the same way as for the vehicle 100 in the first embodiment.
[0073] (D10) The vehicle 100 may be manufactured by combining multiple modules. A module refers to a unit composed of one or more parts grouped according to the configuration or function of the vehicle 100. For example, the platform of the vehicle 100 may be manufactured by combining a front module that forms the front portion of the platform, a central module that forms the center portion of the platform, and a rear module that forms the rear portion of the platform. The number of modules that form the platform is not limited to three, but may be two or less, or four or more. In addition to or instead of the platform, parts of the vehicle 100 that are different from the platform may be modularized. The various modules may include any exterior parts such as a bumper or a grille, or any interior parts such as a seat or a console. Any type of mobile object, not limited to the vehicle 100, may be manufactured by combining multiple modules. Such a module may be manufactured, for example, by joining multiple parts using welding or fasteners, or by integrally molding at least a portion of the module as a single part by casting. The molding method of integrally molding at least a portion of the module as a single part is also called gigacasting or megacasting. By using Gigacast, each part of a moving body that has conventionally been formed by joining multiple parts can be formed as a single part. For example, the front module, center module, and rear module described above may be manufactured using Gigacast.
[0074] (D11) Transporting vehicle 100 using the unmanned driving of vehicle 100 is also called "self-propelled transport." The configuration for realizing self-propelled transport is also called a "vehicle remote-controlled autonomous transport system." The production method for producing vehicle 100 using self-propelled transport is also called "self-propelled production." In self-propelled production, for example, at a factory FC where vehicle 100 is manufactured, at least a portion of the transport of vehicle 100 is realized by self-propelled transport.
[0075] (D12) In each of the above embodiments, some or all of the functions and processes implemented by software may be implemented by hardware. Furthermore, some or all of the functions and processes implemented by hardware may be implemented by software. Hardware for implementing the various functions in each of the above embodiments may be implemented by various circuits, such as integrated circuits or discrete circuits.
[0076] The present disclosure is not limited to the above-described embodiments and can be realized in various configurations without departing from the spirit thereof. For example, the technical features in the embodiments corresponding to the technical features in each aspect described in the Summary of the Invention section can be appropriately replaced or combined to solve some or all of the above-described problems or achieve some or all of the above-described effects. Furthermore, if a technical feature is not described as essential in this specification, it can be appropriately deleted. [Explanation of symbols]
[0077] 10, 10v...system, 100, 100v...vehicle, 110, 110v...vehicle control device, 111, 111v...processor, 112, 112v...memory, 113...input / output interface, 114...internal bus, 115, 115v...vehicle control unit, 116...determination unit, 117...permission unit, 118...update unit, 120...actuator group, 130...communication device, 200...server device, 201...processor, 202...memory, 203...input / output interface, 204...internal bus, 205...communication device, 210...remote control unit, 300...external sensor, 400...process control device, 500...terminal device, DM...detection model, FC...factory, GC...global coordinate system, PG1...program, PG2...program, PL1...first location, PL2...second location, RR...reference route, TR...track
Claims
1. An update device for updating software stored in a mobile object, comprising: a determination unit that determines whether the software can be updated, the determination unit acquires update target information that is information relating to at least one of the software and the mobile object; determining whether the update is possible or not by a first method in a first case where the update target information satisfies a predetermined condition; In a second case where the update target information does not satisfy the predetermined condition, whether or not the update is possible is determined by a second method having a higher security level than the first method. Update device.
2. 2. The update device according to claim 1, the predetermined condition includes that the moving object is located within a predetermined area; Update device.
3. 2. The update device according to claim 1, the predetermined condition includes that the software is software to be used when the moving object is present within a predetermined area; Update device.
4. 4. The update device according to claim 1 or claim 3, the predetermined condition includes that the software is stored in a predetermined device; Update device.
Citation Information
Patent Citations
Vehicle control software update system
JP2021084516A
Center, OTA master, method, program, and vehicle
JP2023005670A
Method for operating a vehicle and method for operating a manufacturing system
JP2017538619A