Vehicle and software update system
The system addresses user inconvenience in vehicle ECU software updates by integrating user terminal battery power display and HMI device consent mechanisms, ensuring seamless and power-efficient updates.
Patent Information
- Application Number
- JP2025190421
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-11-11
- Publication Date
- 2026-01-29
AI Technical Summary
Existing software update systems for vehicle ECUs via user terminals can be inconvenient for users, particularly when the user terminal's battery power is low, leading to potential interruptions during the update process.
The system includes a vehicle with a communication unit that interacts with a user terminal to display the battery power level, allowing users to consent to software downloads through the user terminal, and optionally an HMI device, ensuring the update process is user-friendly by considering battery power levels.
This approach enhances user convenience by allowing software updates to be managed efficiently, reducing the risk of user terminal power depletion during the update process and improving overall user experience.
Smart Images

Figure 2026015439000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to vehicles and software update systems. [Background technology]
[0002] Japanese Patent Application Laid-Open Publication No. 2017-149323 (Patent Document 1) discloses a technology for updating software of an ECU (Electronic Control Unit) mounted on a vehicle by OTA (Over The Air). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-149323 Summary of the Invention [Problem to be solved by the invention]
[0004] A vehicle can download new software (data) for its onboard ECU by wirelessly communicating with an external server (for example, an OTA center). Then, the target ECU (the ECU whose software is to be updated) in the vehicle installs and activates the software, thereby updating the software.
[0005] When updating software (control programs) using such OTA technology, the software is downloaded from an OTA center via onboard communication equipment (for example, a communication module such as a DCM (Data Communication Module)) or a terminal owned by the user (user terminal: for example, a mobile terminal such as a smartphone).
[0006] When updating software for an in-vehicle ECU, it is preferable to inquire whether the user agrees to the update (downloading of software), and then execute the software update when the user agrees. The target (device) through which the user performs the consent operation in response to the inquiry about consent to the update includes an HMI (Human Machine Interface) device or a user terminal mounted on the vehicle. When the update is performed using software downloaded via a user terminal, if the consent operation is performed using the HMI device, there is a concern that this will be inconvenient for the user, even if the user has the user terminal at hand.
[0007] An object of the present disclosure is to improve user convenience when updating software for an in-vehicle ECU via a user terminal. [Means for solving the problem]
[0008] (1) A vehicle disclosed herein is a vehicle equipped with an ECU that allows software updates. The vehicle includes a communication unit capable of communicating with a user terminal, and a first operation unit for accepting the download when software distributed from a server is downloaded to the vehicle via the user terminal, and a control unit that requests the user terminal to display the amount of power stored in the battery of the user terminal on a display unit of the user terminal.
[0009] According to this configuration, the vehicle's transmitter can communicate with the user terminal and can download software distributed from the server to the vehicle via the user terminal. When downloading software distributed from the server to the vehicle via the user terminal, the vehicle's control unit requests the user terminal to display a first operation unit for consenting to the download and the amount of power stored in the battery of the user terminal on the display unit of the user terminal. When downloading software via the user terminal, consent to the download is requested from the user terminal, so consent can be performed using the user terminal at hand, improving user convenience. Furthermore, the user can consent by operating the first operation unit after taking into account the amount of power stored in the battery displayed on the display unit of the user terminal, thereby reducing the possibility of the user terminal running out of power during software download.
[0010] (2) Preferably, in (1), the vehicle further includes an HMI device, and the control unit may be configured to display a second operation unit for accepting the download on a display unit of the HMI device when a predetermined condition is met.
[0011] According to this configuration, when a predetermined condition is met, the control unit displays a second operation unit on the display unit of the HMI device for consenting to the download. The user can consent to the download by operating the second operation unit displayed on the display unit of the HMI device, further improving user convenience and facilitating the software update process. The predetermined condition may be, for example, when the software stored in the memory unit of the user terminal is not transmitted to the vehicle and the installation is not completed.
[0012] (3) Preferably, in (2), when the second operating unit is operated and the download is approved, if the amount of power stored in the battery of the user terminal is equal to or greater than a first predetermined value, the control unit executes the download without requesting approval from the user terminal, and if the amount of power stored in the battery of the user terminal is less than the first predetermined value, the control unit may request approval from the user terminal.
[0013] According to this configuration, when a user operates the second operation unit displayed on the HMI device and consents to the download, if the amount of power stored in the user terminal is less than a first predetermined value, a request for consent to the download is made to the user terminal. As a result, when the amount of power stored in the user terminal is less than the first predetermined value and is insufficient to download the software, the user is prompted to operate the user terminal to consent, which motivates the user to confirm the amount of power stored in the user terminal and then consent. Furthermore, when a user operates the second operation unit displayed on the HMI device and consents to the download, if the amount of power stored in the user terminal is equal to or greater than the first predetermined value, the download is performed without requesting consent from the user terminal, thereby preventing any loss of user convenience.
[0014] (4) The software update system disclosed herein includes a server that distributes software, a vehicle equipped with an ECU, and a user terminal that can communicate with the server and the vehicle, and updates the software of the ECU. When downloading software to the vehicle via the user terminal, the software update system executes the download when the user operates the user terminal to consent to the download.
[0015] According to this configuration, the software update system can download software distributed from the server to the vehicle via a user terminal that can communicate with the server and the vehicle, thereby updating the software of the ECU installed in the vehicle. When downloading software to the vehicle via the user terminal, the software update system executes the download when the user operates the user terminal and agrees to the download. When downloading software via the user terminal, the download is executed when the user operates the user terminal and agrees to the download, so that the agreement operation can be performed using the user terminal at hand, improving user convenience.
[0016] (5) Preferably, in (4), the user terminal may display a first operation unit for accepting the download and the amount of charge in the battery of the user terminal on a display unit of the user terminal.
[0017] According to this configuration, the first operation unit for accepting the download and the battery charge of the user terminal are displayed on the display unit of the user terminal, so the user can operate the first operation unit to accept the download after taking into consideration the battery charge displayed on the display unit of the user terminal, thereby reducing the possibility of the user terminal running out of power while downloading software.
[0018] (6) Preferably, in (4) or (5), the vehicle includes an HMI device. The software update system may be configured to display a second operation unit for accepting the download on the HMI device when a predetermined condition is met.
[0019] According to this configuration, when a predetermined condition is met, a second operation unit for accepting the download is displayed on the display unit of the HMI device. The user can accept the download by operating the second operation unit displayed on the display unit of the HMI device, which further improves user convenience and expedites the software update process. The predetermined condition may be, for example, when the software stored in the memory unit of the user terminal has not been transmitted to the vehicle for a predetermined period of time, when the capacity of the memory unit of the user terminal falls below a predetermined value, etc.
[0020] (7) Preferably, in (6), when the second operation unit is operated and the download is approved, if the amount of power stored in the battery of the user terminal is equal to or greater than a first predetermined value, the download is executed without the user operating the user terminal, and if the amount of power stored in the user terminal is less than the first predetermined value, the download is executed when the user operates the user terminal and approves the download.
[0021] According to this configuration, when a user operates the second operation unit displayed on the MHI device and consents to the download, if the amount of power stored in the user terminal is less than a first predetermined value, the download is executed when the user consents to the download by operating the user terminal. As a result, if the amount of power stored in the user terminal is less than the first predetermined value and is insufficient to download the software, the download is executed when the user consents to the download by operating the user terminal, which motivates the user to confirm the amount of power stored in the user terminal and then perform the consent operation. Furthermore, when a user operates the second operation unit displayed on the MHI device and consents to the download, if the amount of power stored in the user terminal is equal to or greater than the first predetermined value, the download is executed without the user having to operate the user terminal, which prevents any loss of convenience for the user.
[0022] (8) Preferably, in (4) or (5), the vehicle includes an HMI device. If the vehicle has a communication unit capable of communicating with a server, the amount of power stored in the battery of the user terminal may not be displayed on the HMI device. If the vehicle does not have a communication unit capable of communicating with a server, the amount of power stored in the user terminal may be displayed on the HMI device.
[0023] According to this configuration, if the vehicle has a communication unit capable of communicating with the server, the HMI device does not display the amount of power stored in the user terminal. If the vehicle can communicate with the server, the vehicle may download software distributed from the server without going through the user terminal and perform a software update process. Therefore, if the vehicle has a communication unit capable of communicating with the server, not displaying the amount of power stored in the user terminal on the HMI device eliminates the need to exchange information about the amount of power stored in the user terminal between the vehicle and the user terminal, thereby reducing the communication load. Furthermore, if the vehicle does not have a communication unit capable of communicating with the server, the amount of power stored in the user terminal is displayed on the HMI device. If the vehicle does not have a communication unit capable of communicating with the server, software is downloaded via the user terminal. Therefore, by displaying the amount of power stored in the user terminal on the HMI device, the amount of power stored in the user terminal can be easily confirmed when consenting to the download, and the possibility of the user terminal running out of power during software download can be reduced. [Effects of the Invention]
[0024] According to the present disclosure, it is possible to improve user convenience when updating software for an in-vehicle ECU via a user terminal. [Brief explanation of the drawings]
[0025] [Figure 1] 1 is a diagram illustrating a configuration of a software update system according to an embodiment of the present disclosure. [Figure 2] 1 is a diagram for explaining an overview of a software update method according to an embodiment of the present invention; [Figure 3]FIG. 2 is a diagram schematically illustrating a part of a sequence executed in the software update system of the present embodiment. [Figure 4] FIG. 10 is a diagram illustrating an example of a display screen displayed on a touch panel display of a user terminal. [Figure 5] FIG. 2 is a diagram illustrating an example of a display screen displayed on a touch panel display of an HMI device. [Figure 6] FIG. 10 is a diagram illustrating an example of a display screen displayed on a touch panel display of a user terminal. [Figure 7] FIG. 10 is a diagram schematically illustrating a part of the sequence of a software update system according to a first modification. [Figure 8] FIG. 10 is a diagram schematically illustrating a part of the sequence of a software update system according to a second modification. [Figure 9] FIG. 2 is a diagram illustrating an example of a display screen displayed on a touch panel display of an HMI device. DETAILED DESCRIPTION OF THE INVENTION
[0026] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present disclosure will be described in detail with reference to the accompanying drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals and their description will not be repeated.
[0027] Fig. 1 is a diagram showing the configuration of a software update system according to this embodiment. Referring to Fig. 1, this software update system includes a vehicle 100, a vehicle 200, user terminals 300 and 300a, and an OTA center 500. Note that "OTA" is an abbreviation for "Over The Air."
[0028] Each of the vehicles 100 and 200 is, for example, an electric vehicle (BEV: Battery Electric Vehicle) that does not have an internal combustion engine. The vehicle 100 has an OTA access function (a function for directly communicating wirelessly with the OTA center 500), but the vehicle 200 does not have the OTA access function. The vehicle 100 can communicate wirelessly directly with the OTA center 500, but the vehicle 200 cannot communicate with the OTA center 500 unless it goes through another communication device (i.e., a communication device other than the communication device provided in the vehicle 200 itself). The vehicle 200 communicates wirelessly with the OTA center 500 via the user terminal 300 (via the user terminal 300). In addition to directly communicating wirelessly with the OTA center 500, the vehicle 100 is also capable of communicating wirelessly with the OTA center 500 via the user terminal 300a.
[0029] Since the user terminal 300 and the user terminal 300a have the same configuration, the following description will focus on the user terminal 300. The user terminal 300 is configured to be portable by a user. The user terminal 300 is a mobile terminal carried and operated by the user (vehicle manager) of the vehicle 200. In this embodiment, a smartphone equipped with a touch panel display (display unit) is used as the user terminal 300. A smartphone has a built-in computer and a speaker function. However, the user terminal 300 is not limited to this, and any terminal portable by the user of the vehicle 200 can be used as the user terminal 300. For example, a laptop, a tablet terminal, a portable game console, a wearable device (smart watch, smart glasses, smart gloves, etc.), etc. can also be used as the user terminal 300.
[0030] The user terminal 300 includes a processor 310, a memory 320, and a communication module 330. The processor 310 includes, for example, a CPU (Central Processing Unit). The memory 320 includes, for example, a non-volatile memory such as a flash memory. The communication module 330 includes a communication I / F (interface) for directly communicating wirelessly with the OTA center 500. The communication module 330 also includes a communication I / F for directly communicating wirelessly with the vehicle 200. This enables data exchange between the vehicle 200 and the OTA center 500 via the user terminal 300. For example, in response to a request from the vehicle 200, the user terminal 300 specifies the address of the OTA center 500 and accesses the communication network NW, thereby enabling data exchange (communication) between the vehicle 200 (ECU 210) and the OTA center 500 via the user terminal 300.
[0031] Application software (hereinafter referred to as a "mobile app") for using services provided by the OTA center 500 is installed in the user terminal 300. The mobile app associates the identification information (terminal ID) of the user terminal 300 with the identification information (vehicle ID) of the vehicle 200 and registers it in the OTA center 500. Furthermore, the user terminal 300 can exchange information with the OTA center 500 via the mobile app.
[0032] The user terminal 300a is a mobile terminal carried and operated by the user of the vehicle 100. The identification information (terminal ID) of the user terminal 300a is associated with the identification information (vehicle ID) of the vehicle 100 and registered with the OTA center 500, and the user terminal 300a can exchange information with the OTA center 500 via a mobile app. The touch panel displays of the user terminals 300 and 300a function as an input device and a display device. The user terminal 300 and the user terminal 300a have the same functions, and the user terminal 300 may be associated with the vehicle 100 and carried and operated by the user of the vehicle 100, or the user terminal 300a may be associated with the vehicle 200 and carried and operated by the user of the vehicle 200.
[0033] The OTA center 500 is a server that provides a vehicle software update service using OTA technology. The OTA center 500 is configured to perform remote updates of vehicle ECU software from the center via a communication section. The OTA center 500 distributes software for the vehicle ECU. "ECU" stands for Electronic Control Unit.
[0034] The OTA center 500 includes a processor 510, a memory 520, and a communication module 530. The processor 510 includes, for example, a CPU. The memory 520 includes, for example, a non-volatile memory such as a flash memory. The communication module 530 is connected to a communication network NW by wire and communicates with each of a plurality of vehicles (including the vehicle 100) and a plurality of mobile terminals (including the user terminal 300) via the communication network NW. The communication network NW is, for example, a wide area network constructed by the Internet and wireless base stations. The communication network NW may also include a mobile phone network.
[0035] Vehicle 100 includes OTA master 110 and multiple ECUs (including ECUs 121 and 122). Vehicle 200 includes multiple ECUs (including ECUs 210, 221, and 222). OTA master 110 includes a built-in computer and functions as an on-board diagnostic device. Each vehicle may include any number of ECUs. Each on-board ECU includes a built-in computer that includes at least one processor and at least one memory. Each on-board ECU may include multiple microcomputers (microcomputers) in the form of a main microcomputer and a sub-microcomputer.
[0036] In vehicle 100, OTA master 110 and each ECU are connected via a communication bus, and are configured to be able to communicate with each other via wired communication. In vehicle 200, ECUs are connected via a communication bus, and are configured to be able to communicate with each other via wired communication. The communication method between the control devices in each vehicle is not particularly limited, and may be, for example, CAN (Controller Area Network) or Ethernet (registered trademark).
[0037] The OTA master 110 includes a processor 111, a memory 112, and a communication module 113. The processor 111 includes, for example, a CPU. The memory 112 includes, for example, a non-volatile memory such as a flash memory. The communication module 113 includes a communication I / F (interface) for directly performing wireless communication with the OTA center 500. For example, the communication module 113 specifies the address of the OTA center 500 and accesses the communication network NW, thereby establishing wireless communication between the vehicle 100 (communication module 113) and the OTA center 500. The communication module 113 may include a TCU (Telematics Control Unit) and / or DCM (Data Communication Module) that perform wireless communication.
[0038] In the vehicle 200, the ECU 210 includes a processor 211 and a memory 212. The processor 211 includes, for example, a CPU. The memory 212 includes, for example, a non-volatile memory such as a flash memory. The vehicle 200 further includes a communication device 290. The ECU 210 communicates with devices outside the vehicle through the communication device 290. The communication device 290 includes a communication I / F (interface) for direct wireless communication with the user terminal 300. The communication device 290 and the user terminal 300 may perform short-range communication such as a wireless local area network (LAN), near field communication (NFC), or Bluetooth (registered trademark). The communication device 290 may directly communicate with the user terminal 300 located inside or within the vicinity of the vehicle. While the vehicle 200 is stopped, the user terminal 300 inside or outside the vehicle and the ECU 210 may exchange information with each other via the communication device 290. Furthermore, while the vehicle 200 is traveling, the user terminal 300 inside the vehicle and the ECU 210 may exchange information with each other via the communication device 290. The ECU 210 can communicate with the OTA center 500 via the user terminal 300 by requesting the user terminal 300 to communicate with the OTA center 500 as described above.
[0039] In the vehicle 100, the OTA master 110 is capable of communicating with the user terminal 300a through the communication device 190 in addition to the communication module 113. The communication device 190 includes a communication I / F (interface) for direct wireless communication with the user terminal 300a. The communication device 190 and the user terminal 300a may perform short-range communication using a technique such as wireless LAN, NFC, or Bluetooth (registered trademark). The communication device 190 may also directly communicate with the user terminal 300a located inside the vehicle or within a range surrounding the vehicle. While the vehicle 100 is stopped, the user terminal 300a located inside or outside the vehicle and the OTA master 110 may exchange information with each other via the communication device 190. Furthermore, while the vehicle 100 is traveling, the user terminal 300a located inside the vehicle and the OTA master 110 may exchange information with each other via the communication device 190. The OTA master 110 can communicate with the OTA center 500 via the user terminal 300a by requesting the user terminal 300a to communicate with the OTA center 500 as described above.
[0040] As described above, the OTA master 110 of the vehicle 100 and the ECU 210 of the vehicle 200 are each configured to be able to wirelessly communicate with the OTA center 500. Each of the vehicles 100 and 200 can communicate with the OTA center 500 whether the vehicle is stopped or moving. The OTA master 110 and the ECU 210 each manage in-vehicle information, receive campaigns, and manage software update sequences. Hereinafter, when there is no need to distinguish between the OTA master 110 and the ECU 210, they will be referred to as "update masters." The OTA master 110 corresponds to the update master of the vehicle 100, and the ECU 210 corresponds to the update master of the vehicle 200.
[0041] Each of the vehicles 100, 200 is an autonomous vehicle configured to be capable of autonomous driving. Each of the vehicles 100, 200 is configured to be capable of both manned and unmanned driving. Each of the vehicles 100, 200 is configured to be capable of autonomous driving without a driver, but can also be driven manually by a user (manned driving). Each of the vehicles 100, 200 can also perform autonomous driving (e.g., auto cruise control) while manned. The level of autonomous driving may be fully autonomous (level 5) or conditional autonomous driving (e.g., level 4).
[0042] Vehicles 100 and 200 are respectively equipped with driving devices 130 and 230 and ADS (Autonomous Driving Systems) 140 and 240. In vehicle 100, ECU 121 is configured to control driving device 130. In vehicle 200, ECU 221 is configured to control driving device 230.
[0043] Each of the driving devices 130, 230 includes an accelerator, a brake, and a steering device. The accelerator includes, for example, a motor generator (hereinafter referred to as "MG") that rotates the drive wheels of the vehicle, a PCU (Power Control Unit) that drives the MG, and a battery that supplies the PCU with power to drive the MG.
[0044] Each of the ADSs 140, 240 includes a recognition sensor (e.g., at least one of a camera, millimeter-wave radar, and LIDAR) that recognizes the external environment of the vehicle, and executes processing related to autonomous driving based on information sequentially acquired by the recognition sensor. The ADSs 140, 240 cooperate with the ECUs 121, 221, respectively, to generate a driving plan (information indicating future vehicle behavior) according to the external environment of the vehicle. The ADSs 140, 240 then request the ECUs 121, 221, respectively, to control various actuators included in the driving devices 130, 230 so as to drive the vehicles 100, 200 according to the driving plan.
[0045] The vehicles 100 and 200 are equipped with start switches 150 and 250 and HMI (Human Machine Interface) devices 170 and 270, respectively.
[0046] Each of the activation switches 150, 250 is a switch that allows a user to activate a vehicle system (a control system of the vehicle 100, 200), and is installed, for example, inside the vehicle cabin. The activation switch is generally called a "power switch" or an "ignition switch." The user operates the activation switch 150, 250 to switch the vehicle system (including each ECU mounted on the vehicle) on (operating) or off (stopped). Turning the activation switch 150, 250 on activates a vehicle system that is in a stopped state, and the vehicle system enters an operating state (hereinafter also referred to as "IG on"). Turning the activation switch 150, 250 off while the vehicle system is operating switches the vehicle system to a stopped state (hereinafter also referred to as "IG off").
[0047] The ON operation of the start switches 150, 250 is an operation for switching the vehicle state from IG OFF to IG ON. When the user turns on the start switches 150, 250, a startup request is input to each on-board ECU. That is, each on-board ECU accepts the startup request from the user. On the other hand, the OFF operation of the start switches 150, 250 is an operation for switching the vehicle state from IG ON to IG OFF. When the user turns off the start switches 150, 250, a shutdown request is input to each on-board ECU. That is, each on-board ECU accepts the shutdown request from the user. However, the OFF operation of the start switches 150, 250 is prohibited when the vehicle is running.
[0048] Each of the HMI devices 170 and 270 includes an input device and a display device. Each of the HMI devices 170 and 270 may include a touch panel display that functions as an input device and a display device. Each of the HMI devices 170 and 270 may also include an input device and a display device of a car navigation system.
[0049] FIG. 2 is a diagram for explaining an overview of a software update method using OTA. Referring to FIG. 2 together with FIG. 1, the process related to the software update is performed in the following steps: configuration synchronization, campaign notification and application acceptance, download, installation, activation, and software update completion notification. The process described below is performed by the OTA center 500 and each vehicle (including vehicles 100 and 200) that receives software distribution from the OTA center 500. The number of vehicles that receive software distribution from the OTA center 500 may be around 50, or may be between 100 and 1000, or may be 1000 or more.
[0050] A vehicle in the IG-on state repeatedly performs configuration synchronization every time a preset time has elapsed. A vehicle in the IG-on state also performs configuration synchronization when a configuration synchronization request is received from the OTA center 500. The configuration synchronization process by the vehicle includes transmitting vehicle configuration information to the OTA center 500. The vehicle configuration information includes, for example, hardware information (information indicating the hardware model number, ECU identifier, etc.) and software information (information indicating the software model number, etc.) for each ECU included in the vehicle.
[0051] When the OTA center 500 receives the vehicle configuration information from the vehicle, it checks for currently occurring campaigns (software updates). If a campaign applicable to the vehicle exists, the OTA center 500 transmits an consent request signal to the vehicle user requesting consent to the download of new software (software updates) related to the campaign. The consent request signal includes information about the campaign (campaign information). The campaign information may include at least one of campaign attribute information (information indicating the purpose of the software update and vehicle functions that may be affected by the update), a list of campaign-target vehicles, information about campaign-target ECUs (e.g., software information before and after the update), and information about notifications to the user before and after the update. Note that the campaign to be notified may be a newly occurring campaign or a campaign that has not been applied before. Hereinafter, the transmission of the consent request signal is also referred to as a "campaign notification."
[0052] When the vehicle receives the campaign notification (acceptance request signal), it prompts the user to input whether or not to accept the application of the campaign. For example, the vehicle may display a message such as "New software has been found. Do you want to apply it to this vehicle?" on the in-vehicle HMI device (HMI device 170, 270) or the user terminal 300, 300a, and prompt the user to input either "accept" or "reject." If the user inputs "accept," the vehicle executes the download process described below. On the other hand, if the user inputs "reject," the vehicle does not execute the download process. In this case, the OTA center 500 terminates the software update process without proceeding to the download phase.
[0053] In this embodiment, the OTA center 500 and the vehicle update master (for example, the OTA master 110 or the ECU 210) execute the process related to downloading in the following procedure.
[0054] The vehicle's update master requests a distribution package including new software from the OTA center 500. The update master then downloads (receives and stores) the distribution package from the OTA center 500. In addition to the new software (for example, a set of update data for each ECU that is the target of the campaign), the distribution package may also include package attribute information (information indicating the update category, the number of update data in the distribution package, the installation order for each ECU, etc.) and update data attribute information (such as an identifier for the target ECU and verification data for verifying the validity of the update data). The target ECU is the ECU that is the target of a software update. For example, the target ECU may be ECU 121 or 221, and the software to be updated may be an autonomous driving control program.
[0055] Through the above-described download process, the distribution package is stored in a storage device (for example, memory 112 or 212) provided in the update master. After the download is complete, the update master verifies the authenticity of the downloaded distribution package. If the verification result is "normal," the update master notifies the OTA center 500 of the software update status (download complete). This notification means that the download was successful.
[0056] If the download is successful, the vehicle performs the installation. The update master requests at least one target ECU (for example, ECU 121 or 221) to output the target ECU's status and DTC (Diagnostic Trouble Code). The update master determines whether installation can be performed for each target ECU based on the target ECU's status and DTC. The update master then transfers the new software (update data) to target ECUs that can be installed. Upon receiving the update data, the target ECU installs the update data (writes it to non-volatile memory).
[0057] When the transfer of the update data from the update master to the target ECU is complete, the target ECU sends a transfer completion notification to the update master. Then, upon receiving the transfer completion notification, the update master requests the target ECU to perform integrity verification. Upon receiving this request, the target ECU performs verification using integrity verification data (verification data) and sends the verification results to the update master. The update master stores the verification results (installation completed / failed / cancelled) for each target ECU. When integrity verification for all target ECUs is complete and all verification results are "normal," the update master notifies the OTA center 500 of the software update status (installation completed). This notification means that the installation was successful.
[0058] If the download and installation are successful, the vehicle enters a state waiting for activation. When the vehicle's startup switch (e.g., startup switch 150 or 250) is then turned off, the update master displays a predetermined message on the in-vehicle HMI device or user terminal 300, 300a, requesting the user to input either "accept" or "reject." If the user inputs "accept," the update master activates the installed software. If the update master fails to activate the software, the update master requests the OTA center 500 to roll back the software. Upon receiving a rollback request from the vehicle, the OTA center 500 distributes rollback software to the vehicle. The update master can then use the rollback software to revert (roll back) the software that failed to be activated to its original version. If the user inputs "reject," the update master cancels the software update process without executing the activation, and the vehicle system is shut down.
[0059] If the update master is successfully activated, the update master displays the results of the software update on the in-vehicle HMI device or the user terminal 300, 300a. The update master then notifies the OTA center 500 of the software update status (software update complete). This notification means that the OTA software update was successful. When this notification is made, the vehicle's control system is shut down and the IG is turned off. After that, when the vehicle's start switch is turned on, the vehicle system is turned on. This causes the update program (new version of software) to start in the target ECU. Note that the software to be updated is not limited to a driving assistance control program such as the above-mentioned autonomous driving control program, and can be any program.
[0060] In this way, when the distribution package (software) is downloaded and the software of the target ECU is updated, the user is prompted to input whether or not to accept the software update process (whether or not to accept the application of the campaign). In this case, if the software (distribution package) distributed from the OTA center 500 is downloaded via the user terminal 300, 300a, and the consent operation is performed using the in-vehicle HMI device, there is a concern that this will be troublesome for the user, even though the user terminal 300, 300a is in hand. In this embodiment, by displaying whether or not the update process is accepted (permission), convenience for the user is improved when the software of the in-vehicle ECU is updated via the user terminal 300, 300a.
[0061] 3 is a diagram showing a schematic diagram of a part of a sequence executed in the software update system of this embodiment. This sequence is processed in the OTA center 500, the user terminal 300 or the user terminal 300a, and the update master (OTA master 110, ECU 210). This processing is realized by one or more processors in each device reading and executing a program stored in one or more memories.
[0062] 3 is a sequence executed when software is downloaded via the user terminal 300 or the user terminal 300a. In the vehicle 100, it is possible to download software distributed from the OTA center 500 using the communication module 113 of the OTA master 110 (without going through the user terminal 300a), or to download software via the user terminal 300a. In the vehicle 100, the sequence of FIG. 3 is executed, for example, when the user sets the vehicle 100 to download software via the user terminal 300a, or when the vehicle 100 receives a notification (instruction) from the OTA master 110 to receive a campaign notification via the user terminal 300a depending on the communication environment, etc.
[0063] 3, when the configuration synchronization process is completed and an applicable campaign exists, in step (hereinafter, step is abbreviated as "S") 11, the OTA center 500 transmits campaign information (consent request signal) to the user terminal 300, 300a. In the configuration synchronization process, vehicle configuration information is transmitted from the update master (OTA master 110 or ECU 210) to the OTA center 500 via the user terminal 300, 300a. Upon receiving the campaign information, the user terminal 300, 300a transmits the received campaign information to the update master (S21). Upon receiving the campaign information, the update master transmits an consent request to the user terminal 300, 300a (S31). This consent request requests the user terminal 300, 300a to consent to the download of the distribution package (software) distributed from the OTA center 500, and notifies (instructs) the user terminal 300, 300a to display a message indicating whether or not to consent to the download of the distribution package (whether or not to consent to the application of the campaign). Note that the update master (OTA master 110, ECU 210) corresponds to an example of the "control unit" of the present disclosure.
[0064] When the user terminal 300, 300a receives the consent request, the user terminal 300, 300a displays an operation unit (operation buttons) for consenting to the download on the touch panel display 340. FIG. 4 is a diagram showing an example of a display screen displayed on the touch panel display 340 of the user terminal 300, 300a. As shown in FIG. 4, the touch panel display 340 displays an operation unit for consenting to the software download along with a message about the vehicle software update process. In FIG. 4, a "Yes" button 341 is the operation unit (operation button) for consenting to the download and corresponds to an example of a "first operation unit" in the present disclosure. When the "Yes" button 341 is operated by the user, the software download (software update process) is executed. When the user operates a "No" button 342 displayed on the touch panel display 340, the software download (software update process) is not executed, and this sequence ends.
[0065] 4, the touch panel display 340 displays a charge amount 343 of the battery of the user terminal 300, 300a. The charge amount 343 indicates the current charge amount of the battery and may, for example, display the SOC (State of Charge) of the battery of the user terminal 300, 300a. The charge amount 343 is displayed on the touch panel display 340 by the user terminal 300, 300a in response to an approval request transmitted from the update master. The approval request transmitted from the update master may also include an instruction to display the charge amount 343 of the battery of the user terminal 300, 300a on the touch panel display 340, and the charge amount 343 may be displayed on the touch panel display 340 in accordance with this instruction.
[0066] 3, when the user operates the "Yes" button 341 on the touch panel display 340 to approve the download (software update process), the user terminal 300, 300a transmits a distribution package transmission request to the OTA center 500 (S23). Upon receiving the distribution package transmission request, the OTA center 500 transmits the distribution package (software) to the user terminal 300, 300a (S12).
[0067] Next, the user terminal 300, 300a saves the distribution package transmitted (distributed) from the OTA center 500 in the memory 320 and downloads it (S24). When the download of the distribution package is completed in the user terminal 300, 300a, the user terminal 300, 300a transmits the downloaded distribution package to the update master (S25). When the distribution package is transmitted from the user terminal 300, 300a, the update master downloads (receives and stores) the distribution package as described above, and after completion, verifies the authenticity of the distribution package, etc., and then transfers the new software (update data) to the target ECU and installs the update data (S32).
[0068] In the next step S33, the update master determines whether a predetermined condition is met. The predetermined condition may be, for example, A) when the download is not complete even after a predetermined time has elapsed since the update master started receiving the distribution package (when part of the distribution package downloaded by the user terminal 300, 300a is not sent to the update master (when the update master cannot receive it)), or B) when the installation is not complete even after a predetermined time has elapsed since the update master started receiving the distribution package. If the predetermined condition is not met, a negative determination is made in S33, and the system enters a state of waiting for activation, and then the activation process is executed.
[0069] If the predetermined condition is met, a positive determination is made in S33, and an operation unit (operation buttons) for accepting the software download is displayed on the touch panel display 610 of the HMI device 170, 270 (S34). FIG. 5 is a diagram showing an example of a display screen displayed on the touch panel display 610 of the HMI device 170, 270. As shown in FIG. 5, the touch panel display 610 displays an operation unit for accepting the software download along with a message about the vehicle software update process. In FIG. 5, a "Yes" button 611 is the operation unit (operation button) for accepting the download and corresponds to an example of a "second operation unit" in the present disclosure. When the "Yes" button 611 on the touch panel display 610 is operated by the user to accept the download (software transmission), the update master determines in S35 whether the stored power amount Sa of the battery of the user terminal 300, 300a is less than a predetermined value α. The stored power amount Sa may be the battery's SOC. The predetermined value α corresponds to an example of a "first predetermined value" in the present disclosure. When the "No" button 612 displayed on the touch panel display 610 is operated by the user, this sequence ends without transmitting software from the user terminal 300, 300a to the update master.
[0070] 3, when the stored power amount Sa is less than the predetermined value α (Sa<α), a positive determination is made in S35, and the update master transmits an approval request to the user terminal 300, 300a (S36). When the user terminal 300, 300a receives the approval request, the user terminal 300, 300a displays, on the touch panel display 340, an operation unit (operation buttons) for approving the software download (transmission of software from the user terminal 300, 300a to the update master) (S26). FIG. 6 is a diagram showing an example of a display screen displayed on the touch panel display 340 of the user terminal 300, 300a. As shown in FIG. 6, the touch panel display 340 displays, together with a message about the vehicle software update process, an operation unit for approving the software download (an operation unit for approving the transmission of software stored in the memory of the user terminal 300, 300a to the update master). In FIG. 6, a "Yes" button 351 is the operation unit for approving the download (an operation unit for approving the transmission of software). When the "Yes" button 351 is operated by the user, the user terminal 300, 300a transmits the software (distribution package) stored in the memory 320 to the update master (S27). When the "No" button 352 displayed on the touch panel display 340 is operated by the user, this sequence ends without transmitting the software (distribution package) from the user terminal 300, 300a to the update master.
[0071] 3, if the stored power amount Sa is equal to or greater than the predetermined value α (Sa≧α), a negative determination is made in S35, and the update master transmits a transmission request to the user terminal 300, 300a (S37). Upon receiving the transmission request, the user terminal 300, 300a transmits the software (distribution package) stored in memory 320 to the update master (S27). Upon receiving the software (distribution package) from the user terminal 300, 300a, the update master installs the update data in the same manner as in S32 (S38). The update master then enters a state of waiting for activation, and the activation process is then executed.
[0072] According to this embodiment, the update master (OTA master 110, ECU 210) can communicate with the user terminals 300, 300a via the communication devices 190, 290, and can download software (distribution package) distributed from the OTA center 500 via the user terminals 300, 300a. When downloading software distributed from the OTA center 500 via the user terminals 300, 300a, the update master requests consent to the download from the user terminals 300, 300a (S31). When downloading software via the user terminals 300, 300a, consent to the download is requested from the user terminals 300, 300a, so that consent can be given using the user terminals 300, 300a that the users have at hand, improving user convenience.
[0073] According to this embodiment, the consent request (S31) may include a "Yes" button 341 (first operation unit) for consenting to the download and a request to display the amount of power stored in the battery of the user terminal 300, 300a on the touch panel display 340 of the user terminal 300, 300a. The user can give consent by operating the "Yes" button 341 after taking into consideration the amount of power stored 343 displayed on the touch panel display 340 of the user terminal 300, 300a, thereby reducing the possibility of the power of the user terminal 300, 300a running out during the software download.
[0074] According to this embodiment, when a predetermined condition is met, for example, if the download is not completed even after a predetermined time has elapsed since the update master started receiving the distribution package, or if the installation is not completed even after a predetermined time has elapsed since the update master started receiving the distribution package, the update master displays a "Yes" button 611 (second operation unit) for consenting to the download on the touch panel display 610 of the HMI device 170, 270. The user can consent to the download by operating the "Yes" button 611 displayed on the touch panel display 610, thereby improving user convenience and facilitating the software update process.
[0075] According to this embodiment, when the user operates the "Yes" button 611 (second operation unit) displayed on the HMI device 170, 270 and consents to the download, if the stored power amount Sa of the user terminal 300, 300a is less than the predetermined value α, a request for consent to the download is made to the user terminal 300, 300a (S36, S26). As a result, when the stored power amount Sa is less than the predetermined value α and is not sufficient to download the software, the user is prompted to operate the user terminal 300, 300a to consent, which motivates the user to confirm the stored power amount Sa of the user terminal 300, 300a and then consent. Furthermore, when the user operates the "Yes" button 611 displayed on the MHI device 170, 270 and consents to the download, if the stored power amount Sa is equal to or greater than the predetermined value α, the download is executed without requesting consent to the download from the user terminal 300, 300a (S37), thereby preventing any loss of convenience for the user.
[0076] (Variation 1) 7 is a diagram schematically illustrating a part of the sequence of the software update system according to Modification 1. In the above-described embodiment, in S33, the update master (OTA master 110, ECU 210) determines whether or not a predetermined condition is met. In Modification 1, whether or not the predetermined condition is met is determined by the user terminal 300, 300a. The sequence in FIG. 7 replaces S33 in FIG. 6 with S25a, and adds a step of S25b.
[0077] 7, when the user terminal 300, 300a transmits the downloaded distribution package to the update master (S25), the update master transfers the new software to the target ECU and installs the update data (S32), as described above. After transmitting the downloaded distribution package to the update master (S25), the user terminal 300, 300a determines in S25a whether a predetermined condition is met. The predetermined condition may be, for example, a) when the download is not completed at the update master even after a predetermined time has elapsed since the distribution package was transmitted (when a portion of the distribution package downloaded by the user terminal 300, 300a is not transmitted to the update master (the update master cannot receive it)), or b) when the download is not completed at the update master even after a predetermined time has elapsed since the distribution package was transmitted (when a portion of the distribution package downloaded by the user terminal 300, 300a is not transmitted to the update master (the update master cannot receive it)), and the capacity of the storage area (memory 320) of the user terminal 300, 300a is less than a predetermined amount. If the predetermined condition is not met, a negative determination is made in S25a, and the activation process is then waited for, after which the activation process is executed.
[0078] If the predetermined condition is met, a positive determination is made in S25a, and the user terminal 300, 300a sends an approval request to the update master (S25b). Upon receiving the approval request, the update master displays an operation unit (operation buttons) for approving the software download on the touch panel display 610 of the HMI device 170, 270 (S34). The subsequent steps are the same as those in the above embodiment, and therefore will not be described again.
[0079] According to this first modification, when a predetermined condition is met—for example, when a portion of the distribution package downloaded by the user terminal 300, 300a is not sent to the update master even after a predetermined time has elapsed since the distribution package was transmitted, or when a portion of the distribution package downloaded by the user terminal 300, 300a is not sent to the update master even after a predetermined time has elapsed since the distribution package was transmitted, and the storage capacity of the user terminal 300, 300a falls below a predetermined amount—the user terminal requests that a “Yes” button 611 (second operation unit) for accepting the download be displayed on the touch panel display 610 of the HMI device 170, 270. The user can accept the download by operating the “Yes” button 611 displayed on the touch panel display 610, thereby improving user convenience and facilitating the software update process. Note that the first modification also provides the same advantageous effects as the above-described embodiment.
[0080] (Variation 2) 8 is a diagram schematically illustrating a part of the sequence of the software update system according to Modification 2. In Modification 2, S20a, S20b, and S30a are added before S21 in the sequence of the above embodiment (FIG. 3).
[0081] 8, when the user terminal 300, 300a receives the campaign information, it determines whether the update master is the OTA master 110 (S20a). Information about the update master (information about whether it is the OTA master 110 or the ECU 210) is included in the vehicle configuration information transmitted from the update master during the configuration synchronization process. If the update master is the ECU 210, a negative determination is made in S20a, and the user terminal 300, 300a transmits the campaign information and information about the battery state of charge (SOC) of the user terminal 300, 300a to the update master (ECU 210) (S20b).
[0082] When the update master (ECU 210) receives the campaign information and the information on the amount of stored power, it displays the amount of stored power in the battery of the user terminal 300, 300a on the touch panel display 610 of the HMI device 270 (S30a). Fig. 9 is a diagram showing an example of a display screen displayed on the touch panel display 610 of the HMI device 270. As shown in Fig. 9, the touch panel display 610 displays the amount of stored power 623 in the battery of the user terminal 300, 300a together with a message about the vehicle software update process.
[0083] If the update master is the OTA master 110, a positive determination is made in S20a, and the user terminal 300, 300a transmits campaign information to the update master (OTA master 110) (S21). The subsequent sequence is the same as the sequence in the above embodiment (FIG. 3), and therefore a description thereof will be omitted.
[0084] According to this modification 2, if a vehicle (for example, vehicle 100) has a communication unit (OTA master 110, communication module 113) capable of communicating with the OTA center 500, the amount of stored power in the user terminal 300, 300a is not displayed on the HMI device 170. If the vehicle can communicate with the OTA center 500, the vehicle may download software distributed from the OTA center 500 without going through the user terminal 300, 300a, and perform a software update process. Therefore, if the vehicle has a communication unit capable of communicating with the OTA center 500, by not displaying the amount of stored power in the user terminal 300, 300a on the HMI device 170, it is not necessary to exchange information about the amount of stored power in the user terminal 300, 300a between the vehicle and the user terminal 300, 300a, thereby reducing the communication load. Furthermore, if the vehicle (for example, vehicle 200) does not have a communication unit capable of communicating with the OTA center 500, the amount of power stored in the user terminal 300, 300a is displayed on the HMI device 270. If the vehicle does not have a communication unit capable of communicating with the OTA center 500, software is downloaded via the user terminal 300, 300a. Therefore, by displaying the amount of power stored in the user terminal 300, 300a on the HMI device 270, the amount of power stored in the user terminal 300, 300a can be easily confirmed when consenting to the download, and the possibility of the user terminal running out of power during software download can be reduced.
[0085] In the above, various information is displayed on the touch panel display 340, but the display is not limited to one having a touch panel function, and may be a device (such as a PC) that has an operation unit separate from the display.
[0086] Furthermore, it is not essential that the vehicle be configured to be capable of autonomous driving. The vehicle may be an xEV (electric vehicle) other than a BEV. The vehicle may be a PHEV (plug-in hybrid vehicle) or HEV (hybrid vehicle) equipped with an internal combustion engine (for example, a gasoline engine, a biofuel engine, or a hydrogen engine). The vehicle is not limited to a four-wheeled passenger car, but may be a bus or truck, or a three-wheeled xEV. The vehicle may have a flight function. The vehicle may be a vehicle used in MaaS (Mobility as a Service). The vehicle may be a multi-purpose vehicle customized according to the user's purpose of use. The vehicle may be a mobile store vehicle, a robotaxi, an automated guided vehicle (AGV), or agricultural machinery. The vehicle may be an unmanned or single-seater small BEV (for example, a BEV for last-mile travel, an electric wheelchair, or an electric skater).
[0087] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0088] 31 receiving unit, 32 memory unit, 34 transmitting unit, 35 control unit, 110 OTA master, 121, 122, 210, 221, 222 ECU, 100, 200 vehicle, 111, 211, 310, 510 processor, 112, 212, 320, 520 memory, 113, 330, 530 communication module, 130, 230 driving device, 140, 240 ADS, 150, 250 start switch, 170, 270 HMI device, 190, 290 communication device, 300, 300a user terminal, 340 touch panel display, 500 OTA center.
Claims
1. A vehicle equipped with an ECU that allows software updates, a communication unit capable of communicating with a user terminal; an HMI device; a control unit that requests the user terminal to display a first operation unit on a display unit of the user terminal for consenting to the download of the software distributed from the server, the control unit displays a second operation unit for accepting the download on a display unit of the HMI device; When the second operation unit is operated and the download is approved, the control unit requests the user terminal to approve the download.
2. 2. The vehicle of claim 1, wherein the control unit requests the user terminal to consent to the download when the amount of stored power in the battery of the user terminal is less than a first predetermined value, and performs the download without requesting the user terminal to consent to the download when the amount of stored power in the battery of the user terminal is equal to or greater than the first predetermined value.
3. a server that distributes software; A vehicle equipped with an ECU, a user terminal capable of communicating with the server and the vehicle, the software update system updating software of the ECU, the user terminal displays a first operation unit for consenting to the download on a display unit of the user terminal, and when the user operates the user terminal to consent to the download of the software, executes the download; the vehicle includes an HMI device; displaying a second operation unit on the HMI device for accepting the download; A software update system that executes the download when the second operation unit is operated to approve the download and then the user terminal is operated to approve the download.
4. After the second operation unit is operated and the download is approved, If the amount of stored power in the battery of the user terminal is less than a first predetermined value, when the user operates the user terminal and the user agrees to the download, the download is performed; 4. The software update system according to claim 3, wherein, when the amount of stored power in the user terminal is equal to or greater than the first predetermined value, the download is performed without any operation of the user terminal.
5. a server that distributes software; A vehicle equipped with an ECU, a user terminal capable of communicating with the server and the vehicle, the software update system updating software of the ECU, the vehicle includes an HMI device; A software update system in which the vehicle displays the amount of charge stored in the battery of the user terminal on the HMI device.
6. When the vehicle does not have a communication unit capable of communicating with the server, the amount of stored power of the user terminal is displayed on the HMI device; The software update system according to claim 5 , wherein, when the vehicle is equipped with a communication unit capable of communicating with the server, the amount of power stored in the user terminal is not displayed on the HMI device.
Citation Information
Patent Citations
Mobile terminal with browser function
JP2003087863A
Terminal, terminal system, and program
JP2014209330A
On-vehicle update device, update system, and portable communication device
JP2018100002A
Software update device, software update system, and software update method
JP2020176974A
Mobile terminal and control method thereof
US20130174137A1