Vehicle
The vehicle's locking mechanism during software updates addresses power disruptions by ensuring continuous power supply, preventing malfunctions and ensuring a seamless update process.
Patent Information
- Application Number
- JP2024063479
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-10
- Publication Date
- 2025-10-23
AI Technical Summary
Existing software update systems in vehicles risk malfunction due to power disruption when users disconnect the power cable during updates, causing interruptions in the update process.
A vehicle equipped with a power supply unit, storage unit, and control unit that locks the power supply access during software updates, preventing the power cable from being disconnected by locking the opening/closing mechanism until the update is complete.
Prevents power disruptions during software updates, reducing the risk of malfunctions and ensuring a smooth update process by maintaining power supply to the control device.
Smart Images

Figure 2025160723000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to vehicles. [Background technology]
[0002] Patent Document 1 discloses an update system that updates software of an in-vehicle device using update data received via wireless communication. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-157004 Summary of the Invention [Problem to be solved by the invention]
[0004] The update system receives power from a battery to perform software updates, so if the user disconnects the cable from the battery terminal during a software update, cutting off the power supply to the update system, which could cause problems with the software update process. [Means for solving the problem]
[0005] A vehicle for solving the above problem is a vehicle that updates software used in on-board equipment using update data received via wireless communication, and is equipped with a power supply unit, a storage unit that stores the power supply unit, and a control unit, wherein the storage unit has an opening, an opening / closing body that opens and closes the opening, and a locking mechanism that locks the opening / closing body in a state in which the opening / closing body closes the opening, and the control unit is capable of receiving power from the power supply unit to update the software and switching the locking mechanism between a locked state in which the opening / closing body is locked and an unlocked state in which the opening / closing body is not locked, and the gist of the vehicle is that the switching from the locked state to the unlocked state is not performed while the software is being updated. [Effects of the Invention]
[0006] According to the above configuration, the opening and closing mechanism remains locked during the software update, preventing the user from disconnecting the power cable from the power supply device. This reduces the risk of malfunctions during the software update process due to the power supply to the control device being cut off. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a schematic diagram showing the configuration of a vehicle according to an embodiment. [Figure 2] FIG. 2 is a schematic diagram showing the configuration of the control device of the vehicle of FIG. [Figure 3] FIG. 3 is a flowchart showing the flow of processing executed by the control device of the vehicle of FIG. DETAILED DESCRIPTION OF THE INVENTION
[0008] An embodiment of a vehicle will be described below with reference to FIGS. <Vehicle 10 Configuration> As shown in FIG. 1, vehicle 10 includes a master ECU 20 and an ECU 30. "ECU" is an abbreviation for Electronic Control Unit. Master ECU 20 manages updates to software used in on-board equipment. ECU 30 is an example of on-board equipment of vehicle 10. Hereinafter, a device that manages updates to software used in on-board equipment may be referred to as an update device. Master ECU 20 constitutes a part of a control device 80, which will be described later. On-board equipment is equipment that operates using updatable software, such as a device that controls the driving force of a vehicle, a device that controls the braking force of a vehicle, an on-board navigation device, etc.
[0009] The master ECU 20 includes a storage device 21, a RAM 22, and a processing device 23. The storage device 21 stores a program for managing software updates and update data for updating the software of the in-vehicle devices. The storage device 21 includes a data storage 21a for storing update data acquired from an external source. The processing device 23 executes the program read from the storage device 21 using the RAM 22 as a working area, thereby updating the software of the in-vehicle devices, as will be described later.
[0010] The vehicle 10 includes a DCM 50. "DCM" is an abbreviation for Data Communication Module. The master ECU 20 can wirelessly communicate with a server 200 located outside the vehicle 10 via the DCM 50 and a communication network 100. An example of the communication network 100 is a mobile communication network.
[0011] Server 200 is a device that distributes update data. Server 200 includes a storage device 210 that stores a program for distributing the update data, and a processing device 220 that executes the distribution program. Server 200 also includes a communication device 230. Communication device 230 is configured to be able to perform wireless communication via communication network 100.
[0012] The DCM 50 receives the update data from the server 200 by wireless communication via the communication network 100. The master ECU 20 receives the update data from the DCM 50. The master ECU 20 stores the update data in the data storage 21a.
[0013] The ECU 30 includes a storage device 31. The storage device 31 stores software used by the ECU 30. The storage device 31 is a non-volatile memory. The storage device 31 pre-stores various programs as software. The software includes firmware, operating software, and application software. The firmware and operating software are software for performing basic control of the hardware that constitutes the in-vehicle equipment. The application software is software for enabling the in-vehicle equipment to perform specific functions.
[0014] The ECU 30 includes a RAM 32 and a processing unit 33. The processing unit 33 executes a program read from the storage unit 31 using the RAM 32 as a working area. The vehicle 10 includes a power supply device 40 configured to be able to supply power to the master ECU 20. A battery and a DC-DC converter that charges the battery are examples of elements that make up the power supply device 40. A cable connected to the terminals of the battery and a cable connecting the battery and the DC-DC converter are examples of power cables of the power supply device 40.
[0015] The master ECU 20 receives power from the power supply device 40 and executes a process for updating the software of the ECU 30. It is more preferable that the power supply device 40 is capable of supplying power to the storage device 31 in addition to the master ECU 20. In this embodiment, the power supply device 40 is capable of supplying power to the storage device 31. The power supply device 40 is provided inside an engine compartment 70 of the vehicle 10. The engine compartment 70 is an example of an accommodation section.
[0016] The engine compartment 70 includes an opening 71 and an engine hood 72. The engine hood 72 is an example of an opening / closing body that opens and closes the opening 71. The engine hood 72 is configured to be switchable between an open state and a closed state. When the engine hood 72 is in the open state, the opening 71 is open. Therefore, a user can access the inside of the engine compartment 70 and remove power cables of the power supply device 40, such as a cable connected to a battery terminal and a cable between the battery and a DC-DC converter. When the engine hood 72 is in the closed state, the opening 71 is closed by the engine hood 72. Therefore, a user cannot access the inside of the engine compartment 70 and cannot remove power cables of the power supply device 40. The engine compartment 70 includes a locking mechanism 60 that is configured to lock the engine hood 72 in a state that closes the opening of the opening 71.
[0017] The locking mechanism 60 is configured to be switchable between a locked state in which the engine hood 72 is locked and an unlocked state in which the engine hood 72 is not locked. The locking mechanism 60 includes an actuator 63. The master ECU 20 is configured to be able to switch the locking mechanism 60 between the locked state and the unlocked state by controlling the actuator 63.
[0018] The vehicle 10 includes a hood lock switch 61. When a user turns on the hood lock switch 61, the hood lock switch 61 generates an unlock signal for unlocking the lock mechanism 60. When the hood lock switch 61 is turned on and the lock mechanism 60 is in a locked state, the vehicle 10 is configured to be able to switch the lock mechanism 60 to an unlocked state.
[0019] The vehicle 10 is equipped with a lock sensor 62 that outputs a signal for determining whether the lock mechanism 60 is in a locked state or an unlocked state. This signal is transmitted from the lock sensor 62 to the master ECU 20. If the signal from the lock sensor 62 indicates that the lock mechanism 60 is in a locked state, the master ECU 20 sets a flag corresponding to the locked state. If the signal from the lock sensor 62 indicates that the lock mechanism 60 is in an unlocked state, the master ECU 20 sets a flag corresponding to the unlocked state. The flag indicating the state of the lock mechanism 60 is stored in the storage device 21 of the master ECU 20.
[0020] In this embodiment, whether the lock mechanism 60 is in a locked state or an unlocked state is stored and maintained by software based on flag operation. However, the storage and maintenance of whether the lock mechanism 60 is in a locked state or an unlocked state may be performed by other in-vehicle devices other than the master ECU 20.
[0021] <Software Update Overview> The following describes an overview of updating the software of the ECU 30 in the vehicle 10. The software update is performed through a download phase, an installation phase, and an activation phase.
[0022] In the download phase, update data is transmitted from the server 200 to the vehicle 10. The master ECU 20 stores the update data received from the server 200 in the data storage 21a. The download phase includes a series of processes related to the download, such as determining whether the download can be performed and verifying the update data. The transmission of update data from the server 200 to the master ECU 20 may be performed by transmitting compressed data obtained by compressing the update program. Alternatively, the server 200 may transmit divided data obtained by dividing the update program or compressed data to the master ECU 20. Alternatively, the server 200 may transmit update programs for multiple in-vehicle devices collectively to the master ECU 20.
[0023] In the installation phase, the update program is installed in the ECU 30. In the installation phase, the master ECU 20 installs the update program in the storage device 31 of the ECU 30 based on the update data downloaded to the data storage 21a. The installation phase includes a series of processes related to the installation, such as determining whether or not the installation can be performed, transferring the update data, and verifying the update program. If the update data includes the update program itself rather than compressed data of the update program, the master ECU 20 transfers the update data to the ECU 30 in the installation phase. When the installation phase is complete, the update program is disabled.
[0024] When the update data includes compressed data, differential data, or divided data of the update program, a process for generating the update program from the update data is performed. The generation process may be performed by the master ECU 20 or the ECU 30. The update program can be generated by decompressing the compressed data and assembling the differential data or divided data.
[0025] In the activation phase, the update program is activated, i.e., the update program is enabled, in ECU 30. The activation phase includes a series of processes related to activation, such as determining whether activation can be performed, checking the consistency of the update program, and verifying the results of activation.
[0026] <Outline of processing executed by the control device 80> As shown in FIG. 2, the vehicle 10 includes a control device 80 that controls the actuator 63. The control device 80 is configured to be able to switch the lock mechanism 60 between a locked state and an unlocked state. In one example, the control device 80 includes a hood lock switch 61, a master ECU 20, and a logic circuit 65. The hood lock switch 61 is always connected to a power source. For example, the hood lock switch 61 is connected to the high potential (+B) of the power supply device 40.
[0027] A logic circuit 65 is connected to the output side of the hood lock switch 61. When the hood lock switch 61 is turned on, the hood lock switch 61 outputs an H (high) level signal. This signal is input to a logic gate 64 of the logic circuit 65. When the hood lock switch 61 is not turned on, the hood lock switch 61 outputs an L (low) level signal.
[0028] The logic gate 64 is a NAND gate that performs a negative logical product (NAND) operation. When at least one L-level signal is input to the logic gate 64, the logic gate 64 outputs an H-level signal. When only H-level signals are input to the logic gate 64, the logic gate 64 outputs an L-level signal. The signal output by the logic gate 64 is input to the actuator 63 of the locking mechanism 60. When an L-level signal is input, the actuator 63 operates to switch the locking mechanism 60 from the locked state to the unlocked state. When an H-level signal is input, the actuator 63 does not operate to switch the locking mechanism 60 from the locked state to the unlocked state.
[0029] The master ECU 20 always outputs an H-level signal to the logic gate 64 except during a software update. Therefore, only an H-level signal is input to the logic gate 64 when the hood lock switch 61 is turned on except during a software update. In other words, the logic gate 64 outputs an L-level signal when the hood lock switch 61 is turned on except during a software update. As a result, the lock mechanism 60 is switched from the locked state to the unlocked state.
[0030] During a software update of the ECU 30, the master ECU 20 outputs an L-level signal to the logic gate 64, indicating that the software is being updated. Therefore, when a software update is in progress, even if the hood lock switch 61 outputs an H-level signal in response to an ON operation of the hood lock switch 61, the logic gate 64 does not output an L-level signal. In other words, the logic circuit 65 disables the unlock signal during a software update. Therefore, the control device 80 cannot switch the lock mechanism 60 from a locked state to an unlocked state during a software update.
[0031] In this embodiment, the control to disable the unlock signal during a software update is configured to be performed by hardware via the logic circuit 65, but this control may be performed by software, specifically by the master ECU 20.
[0032] The control device 80 includes, in addition to the logic circuit 65 that outputs an unlock signal to the actuator 63, a circuit 66 that outputs a lock signal that switches the lock mechanism 60 from an unlocked state to a locked state. In one example, the circuit 66 is a circuit that outputs the lock signal from the master ECU 20 to the actuator 63.
[0033] In this disclosure, the period defined as software updating (hereinafter sometimes referred to as the update period) may be any period from the download phase to the completion of the activation phase. In other words, the period during which the lock mechanism 60 does not switch from the locked state to the unlocked state even when the hood lock switch 61 is turned on may be any of the above periods. For example, the update period is any of the download phase, the install phase, and the activate phase. In another example, the update period is any of the download phase and the install phase, the install phase and the activate phase, or the download phase and the activate phase. In another example, the update period is any of the download phase, the install phase, and the activate phase.
[0034] 3 shows a flow of a series of processes executed in the vehicle 10. This series of processes is executed by the control device 80. First, when a software update is started (S100: YES), the master ECU 20 refers to the state of the lock mechanism 60 using a flag stored in the storage device 21 (S110). When the lock mechanism 60 is in an unlocked state (S110: YES), the master ECU 20 performs control to switch the lock mechanism 60 to a locked state (S120). That is, when the lock mechanism 60 is in an unlocked state at the start of the software update, the master ECU 20 switches the lock mechanism 60 from the unlocked state to the locked state. When the lock mechanism 60 is in a locked state (S110: NO), the control device 80 executes the process of S130. When a software update is in progress (S100: YES), the control device 80 does not perform control to switch the lock mechanism 60 from the locked state to the unlocked state (S140), even when the hood lock switch 61 is turned on (S130: YES). If the software update is complete (S150: YES), the state in which control for switching the lock mechanism 60 from the locked state to the unlocked state is not performed is ended.
[0035] <Actions and Effects of the Embodiment> The operation and effects of this embodiment will be described. (1) During a software update, the vehicle 10 does not switch the lock mechanism 60 from a locked state to an unlocked state, even if the hood lock switch 61 is turned on. Therefore, the user cannot unlock the engine hood 72 during a software update. Therefore, the user cannot remove the power cable of the power supply device 40. This prevents problems from occurring during a software update due to a stop in the power supply to the master ECU 20. This makes it less likely that anomalies will occur during the software update. Abnormalities during the update are expected to occur during the update, such as a software update being stopped midway, or a problem occurring during the update that leaves an abnormality in the program.
[0036] (2) If the lock mechanism 60 is in the unlocked state when the software update starts, the control device 80 switches the lock mechanism 60 to the locked state. Therefore, even if the lock mechanism 60 of the engine compartment 70 is in the unlocked state when the software update starts, the vehicle 10 can prevent the user from removing the power supply cable of the power supply device 40 during the software update.
[0037] (3) The control device 80 can switch the locking mechanism 60 from a locked state to an unlocked state based on an unlock signal generated in response to a user operation. In the vehicle 10, the unlock signal is disabled during a software update. Therefore, even if the control device 80 generates an unlock signal based on a user operation, the locking mechanism 60 cannot be switched from a locked state to an unlocked state. This prevents the user from disconnecting the power cable from the power supply device 40 during a software update.
[0038] <Example of change> This embodiment can be modified as follows: This embodiment and the following modifications can be combined and implemented within the scope of technical compatibility.
[0039] The storage section that stores the power supply device 40 may be the passenger compartment or the trunk of the vehicle 10. If the storage section is the passenger compartment, the opening / closing member that opens and closes the opening for the user to get in and out is an access door. If the storage section is a trunk, the opening / closing member that opens and closes the opening of the trunk is a trunk hood. If the storage section is the passenger compartment, a mechanism is provided that locks the access door to a state that closes the opening of the passenger compartment. If the storage section is a trunk, a mechanism is provided that locks the trunk hood to a state that closes the opening of the trunk. If the locking mechanism is in an unlocked state when the user performs an operation to open the access door or trunk hood, the control device 80 may execute processing to switch the locking mechanism to a locked state.
[0040] The housing that houses the power supply device 40 may be a case that houses the power supply device 40. In this case, the opening / closing member is a lid that opens and closes the case. Examples of the case include a case that houses both a battery and a DC-DC converter, or a case that houses either a battery or a DC-DC converter.
[0041] For example, the vehicle 10 may be able to generate an unlock signal in response to an operation performed from outside the vehicle 10. For example, if the vehicle 10 is equipped with an electronic key system, the unlock signal may be generated in response to the electronic key being authenticated by the vehicle 10 and the operation of a key-opening switch provided on an access door. Even in this case, for example, if the storage unit is the passenger compartment, the vehicle 10 may be configured not to execute a process to switch the lock mechanism of the access door from a locked state to an unlocked state during a software update.
[0042] In the above embodiment, an example has been described in which the power supply device 40 is capable of supplying power to both the master ECU 20 and the storage device 31. In this case, it is possible to prevent abnormalities in the update process due to a stop in the supply of power to the master ECU 20, and it is also possible to prevent abnormalities in the update process due to a stop in the supply of power to the storage device 31. Note that the power supply device 40 only needs to be capable of supplying power to the master ECU 20. In one example, it is not necessary for the power supply device 40 to be capable of supplying power to the ECU 30.
[0043] In the above embodiment, an example has been described in which the master ECU 20 executes the process of updating the software of the ECU 30. However, in one example, the process of updating the software used in the ECU 30 may be executed by the ECU 30 instead of the master ECU 20.
[0044] Some storage devices have one data storage area for storing software, while others have two data storage areas for storing software. Storage device 31, for example, has one data storage area for storing software. The data storage area is sometimes called a memory bank. In this case, storage device 31 is sometimes called a single bank. In this case, when update data is written to storage device 31, storage device 31 cannot retain the software before the update. For this reason, if an error occurs during the software update process in the installation phase or activation phase, an error may remain in the program.
[0045] In this case, the update period preferably includes the install phase and the activate phase. With this configuration, when the storage device 31 has one data storage area, it is possible to prevent the supply of power to the master ECU 20 from being stopped during the install phase and the activate phase, and to prevent an abnormality from remaining in the program due to such a stop.
[0046] The storage device 31 may have two data storage areas. When the storage device 31 has two data storage areas, the storage device 31 is sometimes referred to as a dual bank. In this case, one of the two data storage areas is designated as the storage area to be read, and software stored in the storage area to be read is executed. While the program in the storage area to be read is being executed, the storage device 31 can write updated data in the background to the other storage area that is not to be read.
[0047] In the activation phase, the storage device 31 activates the updated software by switching the storage area from which the program is read. Therefore, even if the storage device 31 has two data storage areas, copies of the old and new program data may not exist between the time when the storage area from which the program is read is switched. If an error occurs during the software update process, the error may remain in the program.
[0048] In this case, the update period is preferably a period that includes the activation phase. With this configuration, when the storage device 31 has two data storage areas, it is possible to prevent the supply of power to the master ECU 20 from being stopped during the activation phase and to prevent the program from remaining abnormal due to the stoppage. Therefore, it is possible to prevent the program from remaining abnormal.
[0049] The number of on-board devices to be subject to software updates and the number of update devices are arbitrary. For example, the vehicle 10 may have multiple on-board devices to be subject to software updates. For example, one update device may update the software of each of the multiple on-board devices, or one update device may update the software of multiple on-board devices.
[0050] The number of power supply devices that supply power to the update device and the number of storage units are arbitrary. For example, the vehicle 10 may be equipped with multiple power supply devices. For example, the vehicle 10 may be equipped with multiple storage units that store batteries. The control device 80 may perform a process to switch the locking mechanism of each of the multiple storage units between a locked state and an unlocked state.
[0051] The number of control devices that execute the software update process and the process of switching the state of the locking mechanism 60 is arbitrary. For example, the software update process and the process of switching the state of the locking mechanism 60 are each executed by separate control devices. For example, one process is executed by multiple control devices working together. [Explanation of symbols]
[0052] 10...vehicle, 20...master ECU, 30...ECU, 40...power supply device, 50...DCM, 60...locking mechanism, 70...engine compartment, 71...opening, 72...engine hood, 80...control device, 100...communication network, 200...server
Claims
1. A vehicle that updates software used in on-board equipment using update data received by wireless communication, a power supply; a housing portion that houses the power supply device; a control device; The storage section is An opening; an opening / closing body that opens and closes the opening; a locking mechanism that locks the opening / closing body in a state in which the opening is closed, The control device a process of receiving power from the power supply device and updating the software; A vehicle capable of executing a process for switching the locking mechanism between a locked state in which the opening / closing body is locked and an unlocked state in which the opening / closing body is not locked, and wherein switching from the locked state to the unlocked state is not executed while the software is being updated.
2. The control device The vehicle of claim 1 , wherein if the locking mechanism is in the unlocked state at the start of the software update, the locking mechanism is switched from the unlocked state to the locked state.
3. The control device The vehicle according to claim 1 , wherein the switching from the locked state to the unlocked state can be performed based on a signal generated in response to a user operation, and the signal is disabled during the software update.
4. The storage section is The vehicle according to claim 1 , wherein the vehicle is located in one of an engine room, a trunk room, and a passenger compartment of the vehicle.
Citation Information
Patent Citations
Reprogramming master
JP2020009483A
Vehicle control device, vehicle control method, and program
JP2020062909A
Control system, mobile object, control method, and program
JP2022099192A
Software update control device, vehicle, program and software update control method
JP2023135559A
Software update control apparatus, vehicle, computer-readable storage medium, and software update control method
US20230297363A1