Software update master device, software update program, and software update method
The software update master device on vehicles manages user information to differentiate consent requirements, facilitating efficient software updates by allowing automatic updates before market release, addressing the challenge of undefined users.
Patent Information
- Application Number
- JP2025170366
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-08
- Publication Date
- 2026-01-14
- Estimated Expiration
- 2043-04-20
AI Technical Summary
Existing software update systems require user consent for vehicles both before and after market release, despite the difficulty in defining a user before market release, leading to unnecessary consent requirements.
A software update master device on the vehicle manages user information and distinguishes between two types of campaign notifications: one requiring consent and one not requiring consent, allowing differentiated update processes based on user registration status.
Enables efficient software updates by reducing the need for consent before market release and allowing automatic updates, optimizing the update process for vehicles in production versus post-market vehicles.
Smart Images

Figure 2026004559000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a software update master device, a software update program, and a software update method. [Background technology]
[0002] The software update system described in Patent Document 1 includes an update server that distributes software and a vehicle. The vehicle includes a master device and multiple control devices. The update server sends a campaign notification to the master device when updating the software of the control devices. The master device receives the campaign notification and, if consent to the software update is obtained from the vehicle user, executes processing related to the software update of the control devices. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-109039 Summary of the Invention [Problem to be solved by the invention]
[0004] As disclosed in Patent Document 1, when updating software in a vehicle control device, it is necessary to obtain consent from the vehicle user before the software update is completed. Here, in a situation after the vehicle has been released to the market, the vehicle owner can be defined as the vehicle's user. Therefore, the software update can be performed by the vehicle owner consenting to the update as the user. On the other hand, in a situation before the vehicle has been released to the market, it is not possible to define who should be the vehicle's user. Therefore, it is not necessarily desirable to require the same consent for software updates as when a user has been defined. However, in an update system such as that disclosed in Patent Document 1, consent from the user is required even before the vehicle has been released to the market, just as it is required after the vehicle has been released to the market. [Means for solving the problem]
[0005] A software update master device for solving the above problems is mounted on a vehicle, is capable of wireless communication with an update server, and stores user information indicating whether a specific user is registered for the vehicle. When a campaign notification that notifies the vehicle that software of a control device mounted on the vehicle is updatable and that requires consent as a condition for updating to the new software is defined as a first campaign notification, and a campaign notification that requires consent in a manner different from that of the first campaign notification as a condition for updating to the new software or that does not require consent as a condition for updating to the new software is defined as a second campaign notification, the software update master device acquires both the first campaign notification and the second campaign notification from the update server, and and when it is determined that the specific user is registered for the vehicle, after the first campaign notification is acquired and the update condition corresponding to the first campaign notification is satisfied, performing an update to the new software by acquiring the new software corresponding to the first campaign notification from the update server; and when it is determined that the specific user is not registered for the vehicle, after the second campaign notification is acquired and the update condition corresponding to the second campaign notification is satisfied, performing an update to the new software by acquiring the new software corresponding to the second campaign notification from the update server.
[0006] A software update program for solving the above problems is applied to a master device that is mounted on a vehicle and capable of wireless communication with an update server, and stores user information indicating whether a specific user is registered for the vehicle. When a campaign notification that notifies the vehicle that software in a control device mounted on the vehicle is updatable and which requires consent as a condition for updating to the new software is defined as a first campaign notification, and a campaign notification that requires consent in a manner different from that of the first campaign notification as a condition for updating to the new software or which does not require consent as a condition for updating to the new software is defined as a second campaign notification, the master device acquires both the first campaign notification and the second campaign notification from the update server. and determining whether the specific user is registered for the vehicle; and, when it is determined that the specific user is registered for the vehicle, updating to the new software by acquiring the new software corresponding to the first campaign notification from the update server after the first campaign notification is acquired and if the update condition corresponding to the first campaign notification is satisfied; and when it is determined that the specific user is not registered for the vehicle, updating to the new software by acquiring the new software corresponding to the second campaign notification from the update server after the second campaign notification is acquired and if the update condition corresponding to the second campaign notification is satisfied.
[0007] A software update method for solving the above problem is applied to a master device that is mounted on a vehicle and capable of wireless communication with an update server, and stores user information indicating whether a specific user is registered for the vehicle. When a campaign notification that notifies the vehicle that software in a control device mounted on the vehicle is updatable and that requires consent as a condition for updating to the new software is defined as a first campaign notification, and a campaign notification that requires consent in a manner different from that of the first campaign notification as a condition for updating to the new software or that does not require consent as a condition for updating to the new software is defined as a second campaign notification, the master device acquires both the first campaign notification and the second campaign notification from the update server. and determining whether the specific user is registered for the vehicle; and when it is determined that the specific user is registered for the vehicle, after the first campaign notification is acquired and if the update condition corresponding to the first campaign notification is satisfied, updating to the new software by acquiring the new software corresponding to the first campaign notification from the update server; and when it is determined that the specific user is not registered for the vehicle, after the second campaign notification is acquired and if the update condition corresponding to the second campaign notification is satisfied, updating to the new software by acquiring the new software corresponding to the second campaign notification from the update server. [Effects of the Invention]
[0008] According to the above configuration, for example, by using the first campaign notification and the second campaign notification differently for vehicles before they are released to the market and before specific users have been determined, and for vehicles after they are released to the market and after specific users have been determined, it is possible to use different methods of consent regarding software updates before and after they are released to the market. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a schematic configuration diagram of an update system according to the first embodiment. [Figure 2] FIG. 2 is a flowchart showing acquisition control according to the first embodiment. [Figure 3] FIG. 3 is a flowchart showing the first update control according to the first embodiment. [Figure 4] FIG. 4 is a flowchart showing the second update control according to the first embodiment. [Figure 5] FIG. 5 is a schematic configuration diagram of an update system according to the second embodiment. [Figure 6] FIG. 6 is a flowchart showing request control according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] First Embodiment <Outline of update system configuration> A first embodiment of the present invention will be described below with reference to Figures 1 to 4. First, the schematic configuration of the update system US will be described.
[0011] As shown in FIG. 1, the update system US includes a plurality of vehicles 100. Note that FIG. 1 illustrates only one representative vehicle 100. The vehicle 100 may be, for example, a vehicle before it is released to the market, or a vehicle after it has been released to the market. Here, "before it is released to the market" refers to, for example, the timing before the vehicle 100 is delivered to a specific user, i.e., a purchaser. Therefore, the vehicle 100 before it is released to the market may be managed in a production factory or a dealership. Furthermore, "after it is released to the market" refers to, for example, the timing after the vehicle 100 is delivered to a purchaser. Therefore, the vehicle 100 after it is released to the market is managed by the purchaser.
[0012] The vehicle 100 includes a central ECU 10, a powertrain ECU 20, a multimedia ECU 30, an advanced driving assistance ECU 40, and a DCM 50. The vehicle 100 also includes a first external bus 61, a second external bus 62, a third external bus 63, and a fourth external bus 64. "ECU" is an abbreviation for Electronic Control Unit. "DCM" is an abbreviation for Data Communication Module.
[0013] The central ECU 10 controls the entire vehicle 100. The central ECU 10 includes a CPU 11, a ROM 12, a RAM 13, a storage 14, and an internal bus 15. The internal bus 15 connects the CPU 11, the ROM 12, the RAM 13, and the storage 14 so that they can communicate with each other. The ROM 12 is a non-volatile memory that can only be read. The ROM 12 stores various programs and various data in advance. The ROM 12 also stores a master program 12A, which is executed during software updates, as one of the various programs. The RAM 13 is a volatile memory. The RAM 13 temporarily stores various programs and various data. The CPU 11 uses the RAM 13 as a work area to read the programs in the ROM 12 and executes various processes. The CPU 11 also executes various processes as a master device by reading the master program 12A. In this embodiment, the central ECU 10 is an example of a master device.
[0014] The storage 14 can store various programs and various data. The storage 14 is an electrically rewritable nonvolatile memory. For example, the storage 14 is a NAND flash memory.
[0015] The storage 14 stores user information IU in advance. The user information IU is information indicating whether or not a specific user has been registered for the vehicle 100. An example of the specific user is the purchaser of the vehicle 100. In this embodiment, the specific user is registered when the vehicle 100 is handed over to the purchaser at the dealership. Therefore, if a specific user has not been registered for the vehicle 100, the specific user is registered before the vehicle 100 is released on the market. On the other hand, if a specific user has been registered for the vehicle 100, the specific user is registered after the vehicle 100 is released on the market.
[0016] The storage 14 pre-stores vehicle configuration information IV. The vehicle configuration information IV includes software information and vehicle identification information. Here, the software information is information indicating the software for each ECU and the version of that software. Furthermore, the vehicle identification information is information indicating the type and identification number of the vehicle 100.
[0017] The DCM 50 is connected to the central ECU 10 via a first external bus 61. The DCM 50 is capable of wireless communication with devices external to the vehicle 100 via a communication network NW. Therefore, the central ECU 10 is capable of wireless communication with devices external to the vehicle 100 via the first external bus 61 and the DCM 50.
[0018] The powertrain ECU 20 can communicate with the central ECU 10 via a second external bus 62. The powertrain ECU 20 executes various processes for controlling an engine, a transmission, and the like (not shown). The powertrain ECU 20 includes a CPU 21, a ROM 22, a RAM 23, a storage 24, and an internal bus 25. The internal bus 25 interconnects the CPU 21, the ROM 22, the RAM 23, and the storage 24 so that they can communicate with one another. The ROM 22 is a so-called Erasable Programmable Read Only Memory (EPROM). The ROM 22 stores various programs and various data in advance. The ROM 22 also stores a control program 22A in advance as one of the various programs. The control program 22A stored in the ROM 22 is updatable. The RAM 23 is a volatile memory. The RAM 23 temporarily stores various programs and various data. The CPU 21 uses the RAM 23 as a work area to execute various processes by reading programs from the ROM 22. Furthermore, the CPU 21 reads out the control program 22A to execute various processes for controlling the engine, transmission, etc. In this embodiment, the powertrain ECU 20 is an example of a control device in which software is updated.
[0019] The storage 24 can store various programs and various data. The storage 24 is an electrically rewritable nonvolatile memory. For example, the storage 24 is a NOR flash memory.
[0020] The multimedia ECU 30 can communicate with the central ECU 10 via a third external bus 63. The multimedia ECU 30 controls a navigation device, an audio device, and the like (not shown). The internal configuration of the multimedia ECU 30 is similar to that of the powertrain ECU 20. The advanced driving assistance ECU 40 can communicate with the central ECU 10 via a fourth external bus 64. The advanced driving assistance ECU 40 executes various applications to realize various driving assistance functions. The various applications include an application for following a preceding vehicle traveling ahead of the vehicle 100 while maintaining a constant distance from the preceding vehicle, and an application for automatically applying the brakes to mitigate damage to the vehicle 100 in the event of a collision. The internal configuration of the advanced driving assistance ECU 40 is similar to that of the powertrain ECU 20. The vehicle 100 includes various ECUs, such as a steering ECU, a brake ECU, and a body ECU (not shown). These various ECUs can communicate with the central ECU 10 via the buses.
[0021] As shown in Fig. 1, the vehicle 100 includes a device group made up of multiple devices. Examples of these devices are a secondary battery 71 and a display 76. The secondary battery 71 supplies power to the central ECU 10, the powertrain ECU 20, the multimedia ECU 30, the advanced driver assistance ECU 40, the DCM 50, and the like. Note that Fig. 1 representatively illustrates only the power path connecting the secondary battery 71 and the central ECU 10 and the power path connecting the secondary battery 71 and the powertrain ECU 20.
[0022] The display 76 can display various types of information. The display 76 is a so-called touch panel display. Therefore, the user of the vehicle 100 can input various types of information via the display 76. In other words, the display 76 functions as both an output device that outputs information to the user and an input device that receives information from the user.
[0023] The central ECU 10 outputs a control signal to the display 76 to display various information on the display 76. The central ECU 10 also acquires information input by the user of the vehicle 100 from the display 76.
[0024] As shown in FIG. 1, the update system US includes an update server 200. The update server 200 includes an execution unit 210, a storage unit 220, and a communication unit 230. The communication unit 230 is capable of wireless communication with devices external to the update server 200 via a communication network NW. The storage unit 220 includes a read-only ROM, a readable / writable volatile RAM, and a readable / writable non-volatile storage. The storage unit 220 stores various programs and various data in advance. The storage unit 220 also stores an update program 220A, which is executed when updating software, as one of the various programs. The execution unit 210 executes various processes in the software update method by reading the update program 220A from the storage unit 220. An example of the execution unit 210 is a CPU.
[0025] The execution unit 210 of the update server 200 can acquire the user information IU and the vehicle configuration information IV from the central ECU 10 of the vehicle 100 at a specific timing. As will be described later, the specific timing is the timing when the system of the vehicle 100 is started up. The execution unit 210 of the update server 200 can acquire the user information IU and the vehicle configuration information IV for each vehicle 100 from the central ECU 10 of multiple vehicles 100.
[0026] The storage unit 220 of the update server 200 stores setting information IS related to the campaign notification NC. Here, the campaign notification NC notifies the vehicle 100 that the software of the control device installed in the vehicle 100 is available for updating. The setting information IS includes information such as the type and identification number of the vehicle 100 that is the target of the campaign notification NC. The setting information IS also includes information for specifying whether the campaign notification NC is targeted at vehicles 100 to which a specific user is registered or at vehicles 100 to which no specific user is registered. Hereinafter, a campaign notification NC whose setting information IS indicates that it is targeted at vehicles 100 to which a specific user is registered will be referred to as a first campaign notification NC1. A campaign notification NC whose setting information IS indicates that it is targeted at vehicles 100 to which no specific user is registered will be referred to as a second campaign notification NC2. Note that this setting information IS is determined by the campaign notification NC creation manager entering it into the update server 200 when creating a new campaign notification NC.
[0027] <Acquisition Control> Next, the acquisition control executed by the update server 200 and the central ECU 10 of the vehicle 100 will be described with reference to Fig. 2. This acquisition control is a control for the update server 200 to acquire user information IU and vehicle configuration information IV. The acquisition control is also executed in parallel between one update server 200 and the central ECU 10 of multiple vehicles 100. In this embodiment, the central ECU 10 of the vehicle 100 starts the acquisition control every time the system of the vehicle 100 is started.
[0028] 2, when the CPU 11 of the central ECU 10 starts acquisition control, it executes the process of step S10A. In step S10A, the CPU 11 of the central ECU 10 transmits the user information IU and the vehicle configuration information IV to the update server 200. When the execution unit 210 of the update server 200 acquires the user information IU and the vehicle configuration information IV, the execution unit 210 of the update server 200 proceeds to the process of step S10B.
[0029] In step S10B, the execution unit 210 of the update server 200 determines whether a request for a software update has occurred for the vehicle 100, based on the vehicle configuration information IV. For example, if the version of the control program 22A stored in the storage unit 220 is newer than the version of the control program 22A of the vehicle 100, the execution unit 210 of the update server 200 determines that a request for a software update has occurred for the vehicle 100. The execution unit 210 of the update server 200 executes update control, which will be described later, on the condition that a request for a software update has occurred for the vehicle 100. After step S10B, the execution unit 210 of the update server 200 ends the current acquisition control.
[0030] <Update control when a specific user is registered> Next, referring to Fig. 3, update control when a specific user is registered will be described. This update control is control related to software update of the vehicle 100. Note that, hereinafter, update control when a specific user is registered will be referred to as first update control. This first update control is executed between the update server 200 and the vehicle 100 in which the specific user is registered. Furthermore, the first update control is executed in parallel between one update server 200 and the central ECUs 10 of multiple vehicles 100. Below, processing when updating the control program 22A will be described as an example of software update.
[0031] In this embodiment, when the execution unit 210 of the update server 200 determines during acquisition control that a request for software update has occurred for a vehicle 100 in which a specific user is registered, it starts the first update control following the acquisition control.
[0032] As shown in FIG. 3, when the execution unit 210 of the update server 200 starts the first update control, it executes the process of step S11. In step S11, the execution unit 210 of the update server 200 transmits the first campaign notification NC1 of the first campaign notification NC1 and the second campaign notification NC2 as the campaign notification NC. Therefore, the execution unit 210 of the update server 200 transmits the first campaign notification NC1 to the vehicle 100 in which a specific user is registered. Here, the first campaign notification NC1 is a campaign notification NC that requires acceptance as a condition for updating to new software. The campaign notification NC also includes information indicating the type of software to be updated. Note that in the example described here, the information indicating the type of software to be updated is information indicating that the software to be updated is the control program 22A of the powertrain ECU 20. When the CPU 11 of the central ECU 10 acquires the campaign notification NC, the CPU 11 of the central ECU 10 proceeds to the process of step S16.
[0033] In step S16, the CPU 11 of the central ECU 10 confirms with the specific user of the vehicle 100 whether or not the specific user consents to the download of a new control program 22A to update the control program 22A. Specifically, the CPU 11 of the central ECU 10 outputs a control signal to the display 76 to display on the display 76 an option for consenting to the download of the control program 22A. If consent is not obtained from the specific user of the vehicle 100, the CPU 11 of the central ECU 10 periodically displays an option for consenting to the download of the control program 22A. On the other hand, if consent is obtained from the specific user of the vehicle 100, the CPU 11 of the central ECU 10 proceeds to step S21.
[0034] In step S21, the CPU 11 of the central ECU 10 transmits a request signal for requesting transmission of a new control program 22A to the update server 200. When the execution unit 210 of the update server 200 receives the request signal, the execution unit 210 of the update server 200 proceeds to step S22.
[0035] In step S22, the execution unit 210 of the update server 200 transmits a new control program 22A to the central ECU 10 as new software corresponding to the campaign notification NC. In other words, the CPU 11 of the central ECU 10 downloads the new control program 22A from the update server 200. At this time, the CPU 11 of the central ECU 10 stores the new control program 22A in the storage 14 of the central ECU 10. After step S22, the CPU 11 of the central ECU 10 advances the process to step S26.
[0036] In step S26, the CPU 11 of the central ECU 10 confirms with the specific user of the vehicle 100 whether or not the specific user consents to the installation and activation of the new control program 22A in order to update the control program 22A. Specifically, the CPU 11 of the central ECU 10 outputs a control signal to the display 76 to display on the display 76 an option for consenting to the installation and activation of the control program 22A. If consent is not obtained from the specific user of the vehicle 100, the CPU 11 of the central ECU 10 periodically displays an option for consenting to the installation and activation of the control program 22A. On the other hand, if consent is obtained from the specific user of the vehicle 100, the CPU 11 of the central ECU 10 proceeds to step S30.
[0037] In step S30, the CPU 11 of the central ECU 10 determines whether a predetermined start condition is satisfied. Here, an example of the start condition is that the system of the vehicle 100 is in an off state. The off state of the system of the vehicle 100 refers to a state in which power is not supplied to each ECU except for the central ECU 10. Therefore, a state in which the vehicle 100 is running and an accessory on state in which each device of the vehicle 100 can be used are the on state. A state in which the vehicle 100 cannot run is the off state. If the CPU 11 of the central ECU 10 determines in step S30 that the start condition is not satisfied, the CPU 11 of the central ECU 10 executes the process of step S30 again.
[0038] On the other hand, if the CPU 11 of the central ECU 10 determines in step S30 that the start condition is satisfied, the CPU 11 of the central ECU 10 proceeds to step S31. That is, the CPU 11 of the central ECU 10 proceeds to step S31 on the condition that consent is obtained in step S16, consent is obtained in step S26, and the start condition is satisfied in step S30. Therefore, the update condition corresponding to the first campaign notification NC1 is that consent is obtained in step S16, consent is obtained in step S26, and the start condition is satisfied in step S30.
[0039] In step S31, the CPU 11 of the central ECU 10 installs the new control program 22A stored in the storage 14 into the ROM 22 of the powertrain ECU 20. After step S31, the CPU 11 of the central ECU 10 advances the process to step S32.
[0040] In step S32, the CPU 11 of the central ECU 10 activates the installed control program 22A. The term "activate" here refers to making the installed control program 22A executable by switching the reference address or the like for executing the control program 22A. After step S32, the CPU 11 of the central ECU 10 ends the current first update control.
[0041] <Update control when user is not registered> Next, update control when a specific user is not registered will be described with reference to Fig. 4. Note that, hereinafter, update control when a specific user is not registered will be referred to as second update control. This second update control is executed between the update server 200 and a vehicle 100 in which a specific user is not registered. Furthermore, the second update control is executed in parallel between one update server 200 and the central ECUs 10 of multiple vehicles 100.
[0042] In this embodiment, when the execution unit 210 of the update server 200 determines in the acquisition control that a request for software update has occurred for a vehicle 100 for which a specific user is not registered, the execution unit 210 of the update server 200 starts the second update control following the acquisition control.
[0043] As shown in FIG. 4, when the execution unit 210 of the update server 200 starts the second update control, it executes the process of step S61. In step S61, the execution unit 210 of the update server 200 transmits the second campaign notification NC2 of the first campaign notification NC1 and the second campaign notification NC2 as the campaign notification NC. Therefore, the execution unit 210 of the update server 200 transmits the second campaign notification NC2 to vehicles 100 to which no specific user is registered. In this embodiment, the second campaign notification NC2 is a campaign notification NC that does not require acceptance as a condition for updating to new software. As described above, the first campaign notification NC1 is a campaign notification NC that requires acceptance as a condition for updating to new software. In the first update control, an update to new software requires acceptance twice in total, through the processes of steps S16 and S26. Therefore, the update condition corresponding to the second campaign notification NC2 requires acceptance fewer times than the update condition corresponding to the first campaign notification NC1. When the CPU 11 of the central ECU 10 receives the campaign notification NC, the CPU 11 of the central ECU 10 advances the process to step S71.
[0044] In step S71, the CPU 11 of the central ECU 10 transmits a request signal for requesting transmission of a new control program 22A to the update server 200. When the execution unit 210 of the update server 200 receives the request signal, the execution unit 210 of the update server 200 proceeds to step S72.
[0045] In step S72, the execution unit 210 of the update server 200 transmits a new control program 22A to the central ECU 10 as new software corresponding to the campaign notification NC. In other words, the CPU 11 of the central ECU 10 downloads the new control program 22A from the update server 200. At this time, the CPU 11 of the central ECU 10 stores the new control program 22A in the storage 14 of the central ECU 10. After step S72, the CPU 11 of the central ECU 10 advances the process to step S80.
[0046] In step S80, the CPU 11 of the central ECU 10 determines whether a predetermined start condition is satisfied. Here, one example of the start condition is that the system of the vehicle 100 is in an off state. If the CPU 11 of the central ECU 10 determines in step S80 that the start condition is not satisfied, the CPU 11 of the central ECU 10 executes the process of step S80 again.
[0047] On the other hand, if the CPU 11 of the central ECU 10 determines in step S80 that the start condition is satisfied, the CPU 11 of the central ECU 10 proceeds to step S81. That is, the CPU 11 of the central ECU 10 proceeds to step S81 on the condition that the start condition is satisfied in step S80. Therefore, the update condition corresponding to the second campaign notification NC2 is that the start condition is satisfied in step S80.
[0048] In step S81, the CPU 11 of the central ECU 10 installs the new control program 22A stored in the storage 14 into the ROM 22 of the powertrain ECU 20. After step S81, the CPU 11 of the central ECU 10 advances the process to step S82.
[0049] In step S82, the CPU 11 of the central ECU 10 activates the installed control program 22A. After step S82, the CPU 11 of the central ECU 10 ends the current second update control.
[0050] <Operation of this embodiment> Assume that a specific user is registered for a certain vehicle 100, and a request for updating the control program 22A of the powertrain ECU 20 in the vehicle 100 has occurred. In this case, as shown in FIG. 3 , the update server 200 and the central ECU 10 of the vehicle 100 execute a first update control. In step S11, the execution unit 210 of the update server 200 transmits a first campaign notification NC1, which requires consent as a condition for updating to new software. Then, in step S22, the CPU 11 of the central ECU 10 downloads the new control program 22A from the update server 200, on the condition that consent to execution of the download has been obtained from the specific user in step S16. Furthermore, in step S31 and step S32, the CPU 11 of the central ECU 10 installs and activates the new control program 22A, on the condition that consent to execution of installation, etc. has been obtained from the specific user in step S26.
[0051] On the other hand, suppose that no specific user is registered for the same vehicle 100 as above, and a request for updating the control program 22A of the powertrain ECU 20 in the vehicle 100 occurs. In this case, as shown in FIG. 4 , the update server 200 and the central ECU 10 of the vehicle 100 execute the second update control. In step S61, the execution unit 210 of the update server 200 transmits a second campaign notification NC2 that does not require consent as a condition for updating to new software. Then, in step S72, the CPU 11 of the central ECU 10 downloads the new control program 22A from the update server 200 without obtaining consent for downloading, for example, as in step S16. Furthermore, in steps S81 and S82, the CPU 11 of the central ECU 10 installs and activates the new control program 22A without obtaining consent for installation and activation, for example, as in step S26. That is, in the second update control, the update server 200 and the central ECU 10 automatically execute the software update.
[0052] <Effects of this embodiment> (1-1) In this embodiment, the execution unit 210 of the update server 200 can transmit campaign notifications NC with different methods of consent, namely, a first campaign notification NC1 and a second campaign notification NC2. This makes it possible to use the first campaign notification NC1 and the second campaign notification NC2 differently for a vehicle 100 after it has been released to the market and a vehicle 100 before it is released to the market. As a result, it is possible to use different methods of consent regarding software updates before and after the vehicle 100 is released to the market.
[0053] (1-2) In step S11 of the first update control, the execution unit 210 of the update server 200 transmits a first campaign notification NC1 to vehicles 100 in which a specific user is registered. Meanwhile, in step S61 of the second update control, the execution unit 210 of the update server 200 transmits a second campaign notification NC2 to vehicles 100 in which a specific user is not registered. According to this configuration, the first campaign notification NC1 is transmitted to vehicles 100 in which a specific user is registered, in other words, vehicles 100 that have been released on the market. Meanwhile, the second campaign notification NC2 is transmitted to vehicles 100 in which a specific user is not registered, in other words, vehicles 100 that have not yet been released on the market. This enables software updates in vehicles 100 in which they have not yet been released on the market to be performed under update conditions corresponding to the second campaign notification NC2, which differs from the first campaign notification NC1 transmitted to vehicles 100 that have been released on the market.
[0054] (1-3) Generally, the vehicle 100 is managed by the purchaser after it is released to the market. On the other hand, the vehicle 100 before it is released to the market is managed in the production factory or in a dealership. In other words, the vehicle 100 before it is released to the market is likely to be managed by the manufacturer of the vehicle 100 and its affiliated companies. Therefore, the vehicle 100 before it is released to the market is less likely to require consent for software updates than the vehicle 100 after it is released to the market.
[0055] In this embodiment, the update conditions corresponding to the second campaign notification NC2 require fewer consents than the update conditions corresponding to the first campaign notification NC1, which reduces the effort required for consent when updating software for a vehicle 100 before it is released to the market, i.e., when updating software for a vehicle 100 that does not require consent.
[0056] (1-4) In this embodiment, the second campaign notification NC2 is a campaign notification NC that does not require consent as a condition for updating to new software. In other words, the number of times consent is required as a condition for updating corresponding to the second campaign notification NC2 is zero. This eliminates the need for consent when updating software on a vehicle 100 before it is released to the market.
[0057] Second Embodiment A second embodiment of the present invention will be described below with reference to FIGS. 5 and 6. In the second embodiment, the configuration of the update system US is partially different from that of the first embodiment. Also, the second embodiment differs from the first embodiment in that, in addition to acquisition control, first update control, and second update control, request control, which will be described later, is executed. Furthermore, the second embodiment differs from the first embodiment in the execution conditions for the second update control. Note that the description of the second embodiment will focus on the differences from the first embodiment, and the same components as those in the first embodiment will be denoted by the same reference numerals, and their description will be omitted or simplified.
[0058] <Outline of update system configuration> As shown in FIG. 5, the update system US includes an external tool 300. The external tool 300 is an operation tool used by an operator in, for example, a production factory to inspect and maintain the vehicle 100. An example of the external tool 300 is a so-called tablet terminal. The external tool 300 includes an execution unit 310, a memory unit 320, a communication unit 330, and a display 340. The communication unit 330 is capable of wired communication with the vehicle 100 via a connection cable (not shown). The memory unit 320 includes a ROM, a RAM, and a storage. The memory unit 320 stores various programs and various data in advance. The execution unit 310 executes various processes by reading programs from the memory unit 220. An example of the execution unit 310 is a CPU.
[0059] The display 340 can display various types of information. The display 340 is a so-called touch panel display. Therefore, for example, a worker or the like can input various types of information via the display 340. In other words, the display 340 functions as both an output device that outputs information to a worker or the like and an input device that receives information from a worker or the like.
[0060] <Request Control> Next, the request control executed by the external tool 300, the central ECU 10 of the vehicle 100, and the update server 200 will be described with reference to Figure 6. This request control is a control for requesting the execution of the second update control. In this embodiment, the execution unit 310 of the external tool 300 starts the request control on the condition that the external tool 300 and the central ECU 10 of the vehicle 100 can communicate with each other via a connection cable (not shown).
[0061] As shown in FIG. 6, when the execution unit 310 of the external tool 300 starts request control, it executes processing in step S91. In step S91, the execution unit 310 of the external tool 300 confirms with the operator operating the external tool 300 whether or not to consent to the execution of the software update. Specifically, the execution unit 310 of the external tool 300 outputs a control signal to the display 340, thereby displaying on the display 340 an option for whether or not to consent to the execution of the software update. If consent is not obtained from the operator, the execution unit 310 of the external tool 300 displays an option for whether or not to consent to the execution of the software update at regular intervals. On the other hand, if consent is obtained from the operator, the execution unit 310 of the external tool 300 proceeds to processing in step S92.
[0062] In step S92, the execution unit 310 of the external tool 300 transmits an instruction signal to the central ECU 10 of the vehicle 100 to cause the central ECU 10 of the vehicle 100 to transmit a request signal in step S93, which will be described later. When the central ECU 10 of the vehicle 100 receives the instruction signal, the central ECU 10 of the vehicle 100 proceeds to step S93.
[0063] In step S93, the central ECU 10 of the vehicle 100 transmits a request signal for requesting the second update control to the update server 200 together with the vehicle configuration information IV. When the execution unit 210 of the update server 200 receives the request signal, the execution unit 210 of the update server 200 associates the vehicle configuration information IV with the request signal and stores the associated information in the storage unit 220. Therefore, when the update server 200 receives a request signal from a certain vehicle 100 even if it does not receive a request signal again, it determines that the request signal has already been received for that vehicle 100. Thereafter, the execution unit 210 of the update server 200 ends the current request control.
[0064] <Second update control> The execution unit 210 of the update server 200 starts the second update control when it has already received a request signal in the request control from a vehicle 100 in which a specific user is not registered and it has determined in the acquisition control that a request for software update has occurred for the vehicle 100. Note that the request control may be executed after the acquisition control has been executed, or the acquisition control may be executed after the request control has been executed.
[0065] As shown in FIG. 4, when the execution unit 210 of the update server 200 starts the second update control, it executes the process of step S61. Note that the process from step S61 onward in the second embodiment is the same as the process from step S61 onward in the first embodiment. That is, as in the first embodiment, the CPU 11 of the central ECU 10 proceeds to step S81 on the condition that the start condition is satisfied in step S80. Also, as described above, the execution unit 210 of the update server 200 starts the second update control on the condition that a request signal is received in step S93 of the request control. In other words, the execution unit 210 of the update server 200 proceeds to the process from step S61 onward on the condition that consent is obtained from the external tool 300. Therefore, the update condition corresponding to the second campaign notification NC2 is that the start condition is satisfied in step S80 and consent is obtained from the external tool 300. In the second embodiment, the process of step S61 is a process of transmitting a second campaign notification NC2 that requires consent in a manner different from that of the first campaign notification NC1 as a condition for updating to new software.
[0066] <Effects of this embodiment> In addition to the above advantages (1-1) to (1-3), the present embodiment also provides the following advantage (2-1).
[0067] (2-1) In this embodiment, the update condition corresponding to the second campaign notification NC2 includes obtaining consent from the external tool 300. With this configuration, even if a specific user is not registered for the vehicle 100, i.e., consent from a specific user cannot be obtained, software can be updated in accordance with consent from the external tool 300. Furthermore, by requiring consent from the external tool 300, a separate device not installed in the vehicle 100, the possibility of an unrelated person who does not have the authority to give consent giving consent can be reduced. Furthermore, since the vehicle 100 is not yet on the market, it is likely to be located in a production factory or a dealership, and therefore, even if the external tool 300 needs to be connected to the vehicle 100, it is not a significant effort.
[0068] <Example of change> This embodiment can be modified as follows: This embodiment and the following modifications can be combined and implemented within the scope of technical compatibility.
[0069] In the first embodiment, the first update control may be changed. For example, the method for confirming consent in step S16 may be changed. As a specific example, the CPU 11 of the central ECU 10 may output a control signal to a personal terminal owned by a specific user of the vehicle 100, thereby displaying an option for whether or not to consent to the execution of software download on the display of the personal terminal. An example of a personal terminal is a so-called smartphone. Similarly, the method for confirming consent in step S26 may be changed.
[0070] For example, the content of the confirmation of consent in step S16 may be changed. As a specific example, instead of consenting to the download of the new control program 22A, the CPU 11 of the central ECU 10 may confirm with a specific user of the vehicle 100 whether or not the specific user consents to the download, installation, and activation. In this case, the processing of step S26 can be omitted.
[0071] For example, the content of the confirmation of consent in step S26 may be changed. As a specific example, instead of consenting to the installation and activation of the new control program 22A, the CPU 11 of the central ECU 10 may confirm with the specific user of the vehicle 100 whether or not the specific user consents to the download. In this case, after step S31 and before step S32, the CPU 11 of the central ECU 10 may confirm with the specific user of the vehicle 100 whether or not the specific user consents to the activation. In this way, the number of times consent is required as an update condition corresponding to the first campaign notification NC1 may be changed. Furthermore, the timing for confirming consent as an update condition corresponding to the first campaign notification NC1 may be changed.
[0072] For example, the start condition in step S30 may be changed. As a specific example, the start condition may be that the system of the vehicle 100 is in an off state and the processing time of step S30 is a predetermined scheduled time. Note that the scheduled time may be set by a specific user of the vehicle 100.
[0073] In the first embodiment, the second update control may be changed. For example, the start conditions in step S80 may be changed, similar to step S30 above. Note that the start conditions in step S80 may be the same as or different from the start conditions in step S30.
[0074] In the first embodiment, the third update control may be executed instead of the first update control and the second update control. For example, the execution unit 210 of the update server 200 starts the third update control each time a software update request is issued for the target vehicle 100. The execution unit 210 of the update server 200 then transmits a first campaign notification NC1 and a second campaign notification NC2 to the central ECU 10 of the vehicle 100. In other words, the CPU 11 of the central ECU 10 acquires both the first campaign notification NC1 and the second campaign notification NC2. The CPU 11 of the central ECU 10 then determines whether a specific user is registered for the vehicle 100 corresponding to the central ECU 10. If the CPU 11 of the central ECU 10 determines that a specific user is registered for the vehicle 100, the CPU 11 of the central ECU 10 executes the processes from step S16 onward in the first update control. In other words, when a specific user is registered for the vehicle 100 corresponding to the central ECU 10, the CPU 11 of the central ECU 10 updates to new software after receiving the first campaign notification NC1 and when the update condition corresponding to the first campaign notification NC1 is satisfied. On the other hand, when the CPU 11 of the central ECU 10 determines that a specific user is not registered for the vehicle 100, the CPU 11 of the central ECU 10 executes the processing from step S71 onwards in the second update control. In other words, when a specific user is not registered for the vehicle 100 corresponding to the central ECU 10, the CPU 11 of the central ECU 10 updates to new software after receiving the second campaign notification NC2 and when the update condition corresponding to the second campaign notification NC2 is satisfied.
[0075] According to this configuration, a vehicle 100 in which a specific user is registered, in other words, a vehicle 100 after it has been released to the market, is updated to new software when the update conditions corresponding to the first campaign notification NC1 are satisfied. On the other hand, a vehicle 100 in which a specific user is not registered, in other words, a vehicle 100 before it has been released to the market, is updated to new software when the update conditions corresponding to the second campaign notification NC2 are satisfied. In this way, the CPU 11 of the central ECU 10 uses the first campaign notification NC1 and the second campaign notification NC2 differently depending on whether the vehicle 100 is released to the market. This makes it possible to use different methods of consenting to software updates before and after the vehicle 100 is released to the market.
[0076] In the second embodiment, the first update control may be changed. For example, as described above, the number of times that consent is required as an update condition corresponding to the first campaign notification NC1 may be changed. In this case, the total number of times that consent is required as an update condition corresponding to the first campaign notification NC1 may be one. Here, in the second embodiment, the update condition corresponding to the second campaign notification NC2 includes obtaining consent from the external tool 300. The total number of times that consent is required as an update condition corresponding to the second campaign notification NC2 is one. Therefore, the number of times that consent is required as an update condition corresponding to the second campaign notification NC2 may be the same as the number of times that consent is required as an update condition corresponding to the first campaign notification NC1.
[0077] In the first and second embodiments described above, the update system US may be modified. For example, the master device is not limited to the central ECU 10. As a specific example, instead of the central ECU 10, the CPU of the multimedia ECU 30 may function as the master device by reading out the master program 12A stored in the ROM. In other words, the master device is not limited to the central ECU 10, and an ECU mounted on the vehicle 100 may be used.
[0078] For example, the control device is not limited to the powertrain ECU 20. As a specific example, the multimedia ECU 30 may be used as the control device instead of the powertrain ECU 20. In other words, the control device is not limited to the powertrain ECU 20, and an ECU mounted on the vehicle 100 may be used.
[0079] In the second embodiment above, the update system US may be modified. For example, the communication unit 330 of the external tool 300 may be capable of wireless communication with the vehicle 100 .
[0080] For example, the external tool 300 may be an operating tool used by an operator in a dealership. In this case, the request control may be executed when the target vehicle 100 is located inside the dealership. [Explanation of symbols]
[0081] NC1…First campaign notification NC2…Second Campaign Notification NW: communication network US…Update System 10...Central ECU 11...CPU 12...ROM 12A...Master Program 13...RAM 14…Storage 20...Powertrain ECU 21...CPU 22...ROM 22A...Control program 30...Multimedia ECU 40...Advanced driver assistance ECU 50…DCM 71…Secondary battery 76...Display 100...Vehicle 200...Update server 210...Executive Department 220...Storage section 220A…Update Program 230…Communications Department 300...External tool
Claims
1. It is installed in the vehicle and can communicate wirelessly with the update server. storing user information indicating whether a specific user is registered with the vehicle; a campaign notification notifying that software of the control device mounted on the vehicle can be updated, the campaign notification requiring acceptance as a condition for updating to the new software, the first campaign notification; When the campaign notification requires consent in a manner different from that of the first campaign notification as a condition for updating to the new software, or does not require consent as a condition for updating to the new software, the second campaign notification is set as the second campaign notification. acquiring both the first campaign notification and the second campaign notification from the update server; determining whether the specific user is registered with the vehicle; when it is determined that the specific user is registered with the vehicle, after the first campaign notification is acquired and if the update condition corresponding to the first campaign notification is satisfied, acquiring new software corresponding to the first campaign notification from the update server, thereby updating to the new software; when it is determined that the specific user is not registered for the vehicle, after the second campaign notification is acquired and the update condition corresponding to the second campaign notification is satisfied, acquiring new software corresponding to the second campaign notification from the update server, thereby updating to the new software; Run Software update master device.
2. The present invention is applied to a master device that is mounted on a vehicle and is capable of wireless communication with an update server, storing user information indicating whether a specific user is registered with the vehicle; a campaign notification notifying that software of the control device mounted on the vehicle can be updated, the campaign notification requiring acceptance as a condition for updating to the new software, the first campaign notification; When the campaign notification requires consent in a manner different from that of the first campaign notification as a condition for updating to the new software, or does not require consent as a condition for updating to the new software, the second campaign notification is set as the second campaign notification. The master device acquiring both the first campaign notification and the second campaign notification from the update server; determining whether the specific user is registered with the vehicle; when it is determined that the specific user is registered with the vehicle, after the first campaign notification is acquired and if the update condition corresponding to the first campaign notification is satisfied, acquiring new software corresponding to the first campaign notification from the update server, thereby updating to the new software; when it is determined that the specific user is not registered for the vehicle, after the second campaign notification is acquired and the update condition corresponding to the second campaign notification is satisfied, acquiring new software corresponding to the second campaign notification from the update server, thereby updating to the new software; Run Software updates.
3. The present invention is applied to a master device that is mounted on a vehicle and is capable of wireless communication with an update server, storing user information indicating whether a specific user is registered with the vehicle; a campaign notification notifying that software of the control device mounted on the vehicle can be updated, the campaign notification requiring acceptance as a condition for updating to the new software, the first campaign notification; When the campaign notification requires consent in a manner different from that of the first campaign notification as a condition for updating to the new software, or does not require consent as a condition for updating to the new software, the second campaign notification is set as the second campaign notification. The master device: acquiring both the first campaign notification and the second campaign notification from the update server; determining whether the specific user is registered with the vehicle; when it is determined that the specific user is registered with the vehicle, after the first campaign notification is acquired and if the update condition corresponding to the first campaign notification is satisfied, acquiring new software corresponding to the first campaign notification from the update server, thereby updating to the new software; when it is determined that the specific user is not registered for the vehicle, after the second campaign notification is acquired and the update condition corresponding to the second campaign notification is satisfied, acquiring new software corresponding to the second campaign notification from the update server, thereby updating to the new software; Run How to update your software.
Citation Information
Patent Citations
Center device, data delivery system, and restriction implementation program
JP2020135722A
Vehicle electronic control system, data repeating device, distribution control method of campaign information and distribution control program of campaign information
JP2021081780A
Server, update management method and update management program
JP2022015221A
Vehicle electronic control system, data relay device, campaign information delivery control method, and campaign information delivery control program
US20210149660A1
Center, update management method, and update management program
JP2022109039A