Software updating device, software updating method and software update processing program

The software update device with dual storage units in ECUs allows seamless updates by prohibiting powertrain output during updates, addressing the challenges of engine stoppage and battery drain in existing methods, enhancing convenience and efficiency.

JP2025172889APending Publication Date: 2025-11-26NISSAN MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025144870
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-03-18
Filing Date
2025-09-01
Publication Date
2025-11-26

AI Technical Summary

Technical Problem

Existing software update methods for vehicle ECUs require stopping the engine or connecting to an external battery, which can lead to malfunctions or battery drain, reducing convenience and increasing equipment needs.

Method used

A software update device with a controller that uses two storage units in each ECU to download and install update software while the vehicle is running, prohibiting powertrain output during the update process to prevent malfunctions and battery drain.

Benefits of technology

Enables software updates without stopping vehicle operation, reducing the risk of malfunctions and battery drain by allowing updates to be performed while the vehicle is traveling, thus improving convenience and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025172889000001_ABST
    Figure 2025172889000001_ABST
Patent Text Reader

Abstract

To provide a software updating device, a software updating method and a software update processing program that execute an update process on software that operates devices mounted on a vehicle.SOLUTION: A software updating device includes a controller which controls devices by acquiring software and applying the software to the devices. The controller has a first storage unit for storing acquired first software and a second storage unit for storing acquired second software. The controller executes an update process by changing the software to be applied to the device from the first software to the second software in a condition where a driving force is not output by a power train of the vehicle.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a software update device, a software update method, and a software update processing program. [Background technology]

[0002] Previously, when updating the software of a vehicle's ECU (Electronic Control Unit) via a wired connection, it was necessary to connect the ECU to an external battery during the update process to prevent the battery from running out due to a drop in battery voltage.

[0003] In response to this, JP2010-19175A discloses a data writing system that identifies a vehicle to be rewritten with an ECU program (software) by wireless communication, and transmits and receives write data and performs the write operation. This data writing system requires the engine to be running as a prerequisite for data writing, so that the battery does not run out during the data writing operation. Summary of the Invention

[0004] While updating the ECU software, the functions of the devices controlled by the ECU are stopped. Therefore, as in the technology described in Patent Document 1, if the engine or other components are running during the software update, there is a risk of an unexpected accident occurring if, for example, the brake function is stopped. Therefore, it is necessary to stop the operation of the powertrain, such as the engine, during the software update to prevent the engine or other components from malfunctioning.

[0005] However, if the engine is stopped for a long time to perform a software update, there is a risk that the battery will run out. To prevent this, it is possible to perform the software update while connecting to an external battery, but this requires equipment such as a high-voltage battery, which reduces convenience.

[0006] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a software update device, a software update method, and a software update processing program that improve convenience during update work while preventing malfunctions of the engine, etc. during software updates. [Means for solving the problem]

[0007] According to one aspect of the present invention, there is provided a software update device that performs an update process for software that operates a device mounted on a vehicle. The software update device includes a controller that acquires software and applies the software to the device to control the device. The controller has a first storage unit that stores the acquired first software and a second storage unit that stores the acquired second software. The controller then performs the software update process by changing the software applied to the device from the first software to the second software when no driving force is output by the vehicle's powertrain. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a schematic diagram of a software update system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a flowchart illustrating software update control according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0010] An embodiment of the present invention will be described with reference to Figures 1 and 2. Figure 1 is a schematic diagram showing the configuration of a software update system 100 and a software update device 110 according to an embodiment of the present invention.

[0011] As shown in FIG. 1, the software update system 100 is made up of a software update device 110 mounted on a vehicle 1 and an external server 2, and the software update device 110 is made up of a controller 10 and a detection unit 3.

[0012] The controller 10 includes a gateway 11 that acquires software from an external server 2, and an electronic control unit (ECU) 12 that controls each device mounted on the vehicle 1.

[0013] The gateway 11 is capable of communicating with the external server 2 and the electronic control unit 12, obtains update software from the external server 2, and transmits the obtained update software to the electronic control unit 12 to be updated. The gateway 11 also obtains control information of each device from the electronic control unit 12, and obtains the driving force output state of the powertrain from the detection unit 3, which will be described later.

[0014] The gateway 11 is composed of a computer equipped with a central processing unit (CPU), a read only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface), and performs overall control of the software update device 110. The gateway 11 executes a specific program to perform processing for controlling the software update device 110. The gateway 11 performs software update control, which will be described later, together with the electronic control unit 12, for example.

[0015] The electronic control unit (ECU) 12 is a controller that controls each device mounted on the vehicle 1, such as a BCM (Body Control Module), VDC (Vehicle Dynamics Control), or HEVC (Hybrid Electric Vehicle Control). Each electronic control unit 12 is composed of a computer equipped with a central processing unit (CPU), read-only memory (ROM), random access memory (RAM), and input / output interface (I / O interface). The BCM controls the operating elements of the vehicle body 1, including the engine starter and door locks of the vehicle 1. The VDC controls the brakes and engine output of the vehicle 1 and controls the attitude of the vehicle 1 to prevent skidding of the vehicle 1. If the vehicle 1 is a hybrid vehicle, the HEVC controls the engine and motor, which are the driving sources, to achieve highly efficient driving.

[0016] The electronic control unit 12 can communicate with the gateway 11 and constantly transmits control information for each device as a signal to the gateway 11. Each electronic control unit 12 acquires software including a specific program from the gateway 11 and controls the target device by applying the acquired software to the device. The electronic control unit 12 also performs software update control, which will be described later, together with the gateway 11.

[0017] Each electronic control unit 12 also includes two storage units 121, 122 that store software acquired from the gateway 11. The electronic control unit 12 applies the software stored in one storage unit (first storage unit) 121 to the device. The electronic control unit 12 also updates the software by changing the software applied to the device to the software stored in the other storage unit (second storage unit) 122. Details of the software update process will be described later.

[0018] The detection unit 3 includes a crank angle sensor that detects engine operation, an accelerator pedal sensor, etc., and detects the driving force output state of the powertrain of the vehicle 1. The driving force output state of the powertrain detected by the detection unit 3 is transmitted to the gateway 11 as a signal.

[0019] Next, the software update process will be described.

[0020] As described above, each electronic control unit 12 includes two storage units 121 and 122. When the electronic control unit 12 acquires software (first software) transmitted from the gateway 11, the software is stored in one of the storage units (first storage unit) 121, and the electronic control unit 12 applies the software to the device. Note that the first software may not be acquired from the gateway 11, but may be already stored in the first storage unit 121 in the initial state.

[0021] Next, when the electronic control unit 12 acquires the update software (second software) transmitted from the gateway 11, the update software is stored in the other storage unit (second storage unit) 122. While the electronic control unit 12 acquires and stores the second software, the first software is applied to the device.

[0022] In this way, by providing two storage units 121 and 122 in each electronic control unit 12, the electronic control unit 12 can acquire (download) and store (install) update software while the first software is applied to the device. In other words, update software can be acquired and stored without stopping the operation of the controlled device.

[0023] When the update software (second software) is acquired and stored, the electronic control unit 12 changes the software applied to the device from the first software to the second software. This updates the software applied to the device. Hereinafter, the process of changing the software applied to the device from the first software to the second software will be referred to as a software update process (activation).

[0024] However, if a driving force is being output from a powertrain such as an engine during the software update process, there is a risk of an unexpected accident occurring, for example, when the brake function is stopped, etc. Therefore, in this embodiment, the software update process is performed while no driving force is being output from a powertrain such as an engine.

[0025] Specifically, the gateway 11 executes the software update process after the detection unit 3 detects that the powertrain of the vehicle 1 is not outputting driving force, and prohibits the powertrain from outputting driving force during the software update process. For example, when the detection unit 3 detects that the engine speed is 0 and the engine is off, or that the transmission is in neutral (N) or parking (P), the software update process is started and the powertrain is prohibited from outputting driving force. The powertrain is prohibited from outputting driving force until the software update process is complete, and then the powertrain is permitted to output driving force once activation is complete.

[0026] In this way, the software update process is performed while the powertrain of the vehicle 1 is not outputting driving force, thereby preventing malfunction of the powertrain, such as the engine, during activation. Furthermore, with the first software applied to the device, the electronic control unit 12 acquires (downloads) and stores (installs) the update software, and the output of driving force by the powertrain is prohibited only during activation. That is, since the output of driving force by the powertrain is permitted while the electronic control unit 12 acquires and stores the update software, the update software can be acquired and stored while the vehicle 1 is running. Furthermore, since the engine, etc., can be operated while acquiring and storing the update software, the time the engine, etc. is stopped for the software update is shortened compared to when the engine, etc., is stopped while acquiring and storing the update software. Therefore, the battery can be prevented from running down during the software update.

[0027] It should be noted that the detection of the driving force output state of the powertrain of the vehicle 1 does not necessarily have to be performed by the detection unit 3. For example, without providing the detection unit 3, the gateway 11 may be configured to be able to directly receive the ignition switch signal and detect the driving force output state of the powertrain.

[0028] 2 is a flowchart illustrating software update control according to an embodiment of the present invention. Note that all of the following controls are executed by the controller 10 (gateway 11, electronic control unit 12). Also, in the initial state, it is assumed that first software is stored in the first storage unit 121 of the electronic control unit 12, and that the first software is applied to the controlled device.

[0029] In step S101, the gateway (GW) 11 acquires update software (second software) from the external server 2, and then transmits the update software to the electronic control unit 12 to be updated.

[0030] In step S102, the electronic control unit 12 acquires (downloads) the update software (second software) from the gateway 11.

[0031] Next, in step S103, the electronic control unit 12 stores (installs) the update software (second software) in the second storage unit 122. Even while the second software is being acquired and stored in steps S102 and S103, the first software is being applied to the devices controlled by the electronic control unit 12. That is, even while the electronic control unit 12 is acquiring and storing the second software, devices including the engine are not stopped.

[0032] In step S104, the gateway 11 acquires a signal indicating the driving force output state of the powertrain (PT) of the vehicle 1, detected by the detection unit 3, and executes the process of step S105 if the powertrain is not outputting driving force. As described above, a state in which the powertrain is not outputting driving force refers to, for example, when the engine speed is 0 and the engine is off, or when the transmission is in neutral (N) or parking (P). On the other hand, if the powertrain is outputting driving force, the gateway 11 repeats the process of step S104 until the powertrain is not outputting driving force.

[0033] If the powertrain is in a state where driving force is being output in step S104, and the vehicle 1 is in a state where stopping the output of driving force by the powertrain will not cause any problems, the output of driving force may be stopped. For example, if the vehicle 1 is in a state where stopping the output of driving force by the powertrain will not cause any problems, the gateway 11 sends a command to the electronic control unit 12 to stop the output of driving force by the powertrain. Upon receiving the command to stop the output of driving force, the electronic control unit 12 stops the output of driving force by the powertrain. Whether or not the state where stopping the output of driving force by the powertrain will not cause any problems can be determined by the gateway 11, for example, from the control information received from each electronic control unit 12.

[0034] If the driving force is not being output by the powertrain, in step S105, the gateway 11 allows the electronic control unit 12 to perform software update processing (activation).

[0035] Subsequently, in step S106, the gateway 11 prohibits the powertrain from outputting driving force.

[0036] In step S107, the electronic control unit 12 changes the software applied to the device controlled by the electronic control unit 12 that is the software update target from the first software to the second software. As a result, the software applied to the device is updated from the first software to the second software. Preferably, during the software update process, the driver is notified by a display device or the like that the update process is in progress.

[0037] When the software update is complete, in step S108, the gateway 11 permits the powertrain to output driving force.

[0038] In this way, while the software update process is being performed, the gateway 11 prohibits the powertrain from outputting driving force, thereby more reliably preventing the powertrain, such as the engine, from malfunctioning during activation.

[0039] To more reliably prevent malfunction of the powertrain, it is preferable to prohibit the powertrain from outputting driving force during activation, but this is not necessarily limited to this. Because the software update process in this embodiment does not include acquiring or storing updated software, the software update process is completed in a short time. Therefore, if the software update process is started while the powertrain is not outputting driving force, it is not necessary to perform the process of prohibiting the powertrain from outputting driving force during activation. In other words, the processes of steps S106 and S108 may be omitted.

[0040] In step S108, when the output of driving force by the powertrain is permitted, the gateway 11 ends the software update control.

[0041] The next time the software is updated again, the update software transmitted from the gateway 11 to the electronic control unit 12 is stored (overwritten) in the first storage unit 121. The software to be applied to the device is changed from the second software stored in the second storage unit 122 to the update software stored in the first storage unit 121, thereby executing another software update.

[0042] The processing shown in FIG. 2 is configured as a program to be executed by the controller 10, which is a computer, and these programs are stored in a storage medium.

[0043] According to the software updating device 110 of the above embodiment, the following effects can be obtained.

[0044] In the software update device 110, the electronic control unit 12 (controller 10) has a first storage unit 121 that stores first software and a second storage unit 122 that stores second software. Therefore, update software (second software) can be acquired and stored in the second storage unit 122 while the first software stored in the first storage unit 121 is applied to the device. Therefore, update software can be acquired and stored even while the vehicle 1 is traveling. Meanwhile, the controller 10 executes the software update process while no driving force is being output by the powertrain of the vehicle 1. Thus, while the vehicle 1 can travel while the update software is being acquired and stored, the software update process is executed while no driving force is being output by the powertrain of the vehicle 1. Therefore, it is possible to provide a software update device 110 that prevents malfunctions of the engine, etc., during software update and improves the convenience of update work.

[0045] Furthermore, because update software can be acquired and stored while the first software stored in the first storage unit 121 is applied to the device, it is only necessary to stop the output of driving force from the powertrain, such as the engine, during activation. In other words, because the engine can be operated while the update software is acquired and stored, the time the engine is stopped for the software update is shorter than when the engine is stopped while the update software is acquired and stored. This makes it possible to prevent the battery from running out during the software update.

[0046] In the software update device 110, the controller 10 permits execution of the software update process when the detection unit 3 detects that no driving force is being output by the powertrain of the vehicle 1. In this way, since execution of the software update process is permitted only after detecting that no driving force is being output by the powertrain, it is possible to more reliably prevent malfunctions of the engine, etc., during the software update.

[0047] In the software update device 110, the controller 10 prohibits the powertrain of the vehicle 1 from outputting driving force while the software update process (activation) is being executed. This more reliably prevents the powertrain, such as the engine, from malfunctioning during activation.

[0048] In the software update device 110, the controller 10 prohibits the powertrain of the vehicle 1 from outputting driving force while the software update process (activation) is being performed, and permits the powertrain to output driving force once the update process is completed. In this way, the powertrain is prohibited from outputting driving force only during activation, thereby shortening the time the engine and other components are stopped for the software update. This makes it possible to prevent the battery from running out during the software update.

[0049] In this embodiment, the electronic control unit (ECU) 12 is a BCM, a VDC, or a HEVC, but the type of electronic control unit 12 is not limited to these, and the number of electronic control units is not limited to these, as long as they control the equipment installed in the vehicle 1.

[0050] Furthermore, the software update control including the software update process of this embodiment may be executed simultaneously for a plurality of electronic control units 12, or may be executed at different times for each electronic control unit 12.

[0051] Furthermore, in this embodiment, the gateway 11 performs overall control of the software update device 110, and the electronic control unit 12 performs control of each device mounted on the vehicle 1. However, the subject of each control may be either the gateway 11 or the electronic control unit 12. For example, the prohibition of the output of driving force by the powertrain during activation may be directly performed by the electronic control unit 12 without going through a command from the gateway 11. Furthermore, the gateway 11, rather than the electronic control unit 12, may perform a change in software to be applied to the devices (software update process).

[0052] Although the embodiments of the present invention have been described above, the above embodiments merely illustrate some of the application examples of the present invention, and it is not intended that the technical scope of the present invention be limited to the specific configurations of the above embodiments.

[0053] This application claims priority based on Japanese Patent Application No. 2020-048340, filed with the Japan Patent Office on March 18, 2020, the entire contents of which are incorporated herein by reference.

Claims

1. A software update device that performs an update process for software that operates equipment mounted on a vehicle, a controller that acquires the software and applies the software to the device to control the device; The controller a first storage unit that stores the acquired first software; a second storage unit that stores the acquired second software; executing the software update process by changing the software applied to the device from the first software to the second software while the driving force is not being output by the powertrain of the vehicle; Software update device.

2. 2. The software update device according to claim 1, a detection unit that detects a driving force output state of a powertrain of the vehicle; the controller permits execution of the software update process when the detection unit detects that a driving force is not being output by a powertrain of the vehicle. Software update device.

3. 3. The software update device according to claim 1, the equipment includes a powertrain of the vehicle; The controller prohibits a powertrain of the vehicle from outputting driving force while the software update process is being executed. Software update device.

4. 4. The software update device according to claim 3, the controller permits the powertrain of the vehicle to output driving force when the software update process is completed; Software update device.

5. A method for updating software that operates a device mounted on a vehicle, comprising: applying the first software stored in the first storage unit to the device; acquiring second software and storing the second software in a second storage unit; and executing the software update process by changing the software applied to the device from the first software to the second software while the driving force is not being output by the powertrain of the vehicle. How to update software.

6. A software update processing program for realizing an update process of software that operates a device mounted on a vehicle, Applying the first software stored in the first storage unit to the device; acquiring second software and storing the second software in a second storage unit; executing a software update process by changing software applied to the device from the first software to the second software in a state in which driving force is not output by a powertrain of the vehicle; A software update processing program that enables the controller to achieve the above.