Equipment and Systems

The equipment system's control unit manages software updates to prevent unintended events by ensuring authorized updates are applied only to specific operation-related portions and restoring these portions if necessary, maintaining equipment safety and functionality.

JP2026135885APending Publication Date: 2026-08-25RINNAI CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025021685
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

Facility equipment may experience unintended events, such as excessive heating, when specific operation-related parts of the software are rewritten without proper oversight, leading to potential safety issues.

Method used

The equipment system includes a control unit that performs acquisition, determination, and update processes to ensure that only authorized software updates are applied to specific operation-related portions, and includes a copy storage unit to restore these portions if necessary, preventing unintended events.

Benefits of technology

This approach prevents unintended events by ensuring that critical operation-related software portions are not overwritten, thereby maintaining equipment safety and functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026135885000001_ABST
    Figure 2026135885000001_ABST
Patent Text Reader

Abstract

This technology provides a way to prevent unintended events from occurring when equipment performs specific operations. [Solution] The equipment comprises a first software storage unit that stores first software applied to the equipment, and a control unit. The control unit is capable of performing an acquisition process to acquire second software for rewriting at least a portion of the first software, a determination process to determine which portion of the first software the second software rewrites, and an update process to rewrite at least a portion of the first software with the second software. The first software includes a specific operation-related portion relating to a specific operation of the equipment. After acquiring the second software through the acquisition process, if the control unit determines through the determination process that the second software rewrites the specific operation-related portion of the first software, it does not perform the update process with respect to at least the specific operation-related portion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology disclosed in this specification relates to a facility equipment system.

Background Art

[0002] Patent Document 1 discloses a facility equipment system including facility equipment. The facility equipment includes a first software storage unit that stores first software applied to the facility equipment, and a control unit. The control unit is configured to be able to execute an acquisition process of acquiring second software for rewriting at least a part of the first software, and an update process of rewriting the at least a part of the first software with the second software.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Regarding a specific operation-related part of the first software related to a specific operation of facility equipment (for example, the hot water supply operation of a water heater), there may be cases where rewriting is not assumed. Nevertheless, in facility equipment, second software for rewriting the specific operation-related part may be acquired. If the specific operation-related part of the first software is rewritten with the second software and the facility equipment is used as it is, when the facility equipment executes a specific operation, an unintended event (for example, an event where the water heater heats water to an excessively high temperature) may occur. This specification provides a technology capable of suppressing the occurrence of unintended events when the facility equipment executes a specific operation.

Means for Solving the Problems

[0005] In a first aspect of this technology, the equipment system may include equipment. The equipment may include a first software storage unit that stores first software applied to the equipment, and a control unit. The control unit may be configured to perform an acquisition process to acquire second software for rewriting at least a portion of the first software, a determination process to determine which portion of the first software the second software rewrites, and an update process to rewrite at least a portion of the first software with the second software. The first software may include a specific operation-related portion relating to a specific operation of the equipment. If the control unit acquires the second software through the acquisition process and then determines through the determination process that the second software rewrites the specific operation-related portion of the first software, it does not need to perform the update process with respect to at least the specific operation-related portion. If the control unit acquires the second software through the acquisition process and then determines through the determination process that the second software does not rewrite the specific operation-related portion of the first software, it may perform the update process.

[0006] According to the above configuration, if the acquired second software overwrites the specific operation-related portion of the first software, the control unit will refrain from performing the update process with respect to at least the specific operation-related portion. This prevents the specific operation-related portion of the first software from being overwritten. As a result, it is possible to prevent unintended events from occurring when the equipment performs a specific operation.

[0007] In a second aspect of this technology, the equipment system may include equipment. The equipment may include a first software storage unit that stores first software applied to the equipment, a copy storage unit that stores a copy of at least a specific operation-related portion of the first software relating to a specific operation of the equipment, and a control unit. The control unit may be configured to perform an acquisition process to acquire second software for rewriting at least a portion of the first software, an update process to rewrite at least a portion of the first software with the second software, and a restore process to rewrite at least the specific operation-related portion of the first software with the copy stored in the copy storage unit. After performing the update process, the control unit may perform the restore process.

[0008] According to the above configuration, the control unit rewrites the first software with the second software and then restores at least the portion related to the specific operation. This prevents the equipment from being used while the portion related to the specific operation of the first software has been rewritten with the second software. As a result, it is possible to prevent unintended events from occurring when the equipment performs a specific operation.

[0009] In a third aspect of this technology, the equipment system may include equipment. The equipment may include a first software storage unit that stores first software applied to the equipment, a copy storage unit that stores a copy of at least a specific operation-related portion of the first software relating to a specific operation of the equipment, and a control unit. The control unit may be configured to perform an acquisition process to acquire second software for rewriting at least a portion of the first software, a determination process to determine which portion of the first software the second software rewrites, an update process to rewrite at least the portion of the first software with the second software, and a restore process to rewrite at least the specific operation-related portion of the first software with the copy stored in the copy storage unit. If the determination process determines that the second software does not rewrite the specific operation-related portion of the first software, the control unit does not have to perform the restore process after the update process. If the determination process determines that the second software does rewrite the specific operation-related portion of the first software, the control unit may perform the restore process after the update process.

[0010] According to the above configuration, if the acquired second software rewrites the specific operation-related portion of the first software, the control unit rewrites the first software with the second software and then restores at least the specific operation-related portion. This prevents the equipment from being used while the specific operation-related portion of the first software has been rewritten with the second software. As a result, it is possible to prevent unintended events from occurring when the equipment performs a specific operation.

[0011] In a fourth aspect of this technology, in any one of the first to third embodiments described above, the equipment system may further include an external server configured to communicate with the equipment. In the acquisition process, the control unit may acquire the second software supplied from the external server.

[0012] With the above configuration, the control unit acquires the second software via an external server. This prevents the control unit from acquiring unauthorized second software distributed by parties other than legitimate vendors. Furthermore, with the above configuration, the software for the equipment can be centrally managed by an external server, enabling efficient software version control and distribution.

[0013] In a fifth aspect of this technology, in the fourth aspect described above, the equipment system may further include a remote control that allows a user to input instructions to the equipment and relays communication between the external server and the equipment. The remote control may include a remote control storage unit that stores the second software supplied from the external server. In the acquisition process, the control unit may acquire the second software stored in the remote control storage unit.

[0014] Equipment may limit the acquisition of the second software to specific time periods (for example, at night). If the equipment were configured to acquire the second software directly from an external server, the period during which the external server distributes the second software would be concentrated in specific time periods, potentially overloading the external server. In contrast, with the above configuration, the equipment acquires the second software from the external server via a remote control. Therefore, the second software can be distributed from the external server to the remote control at any time period, and the remote control can hold (i.e., store) the second software until it is time for the equipment to acquire it. This prevents the period during which the external server distributes the second software from being concentrated in specific time periods, thus preventing overloading the external server.

[0015] In a sixth aspect of this technology, in the fourth aspect described above, the equipment system may further include a portable terminal that is portable to the user and relays communication between the external server and the equipment. The portable terminal may include a terminal storage unit that stores the second software supplied from the external server. In the acquisition process, the control unit may acquire the second software stored in the terminal storage unit.

[0016] Equipment may limit the acquisition of the second software to specific time periods (for example, at night). If the equipment were configured to acquire the second software directly from an external server, the period during which the external server distributes the second software would be concentrated in specific time periods, potentially overloading the external server. In contrast, with the above configuration, the equipment acquires the second software from the external server via a mobile terminal. Therefore, the second software can be distributed from the external server to the mobile terminal at any time period, and the mobile terminal can hold (i.e., store) the second software until it is time for the equipment to acquire it. This prevents the period during which the external server distributes the second software from being concentrated in specific time periods, thus preventing overloading the external server.

[0017] In a seventh aspect of this technology, in any one of the first to sixth embodiments described above, the equipment may include a heating section. The specific operation of the equipment may include operation using the heating section.

[0018] If the portion of the first software related to operation using the heating unit is overwritten with the second software and the equipment is used in that state, there is a risk that unintended events may occur during operation using the heating unit. With the above configuration, it is suppressed that the equipment is used with the portion of the first software related to operation using the heating unit overwritten with the second software. Therefore, this suppresses the occurrence of unintended events during operation using the heating unit. [Brief explanation of the drawing]

[0019] [Figure 1] It is a diagram schematically showing the configuration of the facility equipment system 200 according to the first embodiment. [Figure 2] It is a diagram schematically showing the configuration of the water heater 2 according to the first embodiment. [Figure 3] It is a diagram schematically showing the configuration of the microcomputer 214 of the water heater 2 according to the first embodiment. [Figure 4] It is a flowchart of the software update management process executed by the microcomputer 214 of the water heater 2 according to the first embodiment. [Figure 5] It is a flowchart of the software update management process executed by the microcomputer 214 of the water heater 2 according to the second embodiment. [Figure 6] It is a flowchart of the software update management process executed by the microcomputer 214 of the water heater 2 according to the third embodiment. [Figure 7] It is a diagram schematically showing a state in which the microcomputer 214 of the water heater 2 according to the third embodiment updates the applied software 252 and then restores the combustion block 260. [Figure 8] It is a flowchart of the software update management process executed by the microcomputer 214 of the water heater 2 according to the fourth embodiment. [Figure 9] It is a flowchart of the software update management process executed by the microcomputer 214 of the water heater 2 according to the fifth embodiment.

Modes for Carrying Out the Invention

[0020] (First Embodiment) As shown in FIG. 1, the facility equipment system 200 includes a water heater 2, a bathroom remote control 202, a kitchen remote control 204, a wireless LAN router 206, a server 208, and a mobile terminal 210.

[0021] The water heater 2 is installed in the home of the user who will be using the water heater 2. The water heater 2 includes a communication interface 212, a microcontroller 214, and an external memory 216. A two-core signal line 218 is connected to the communication interface 212. The water heater 2 can communicate with the kitchen remote control 204 and the bathroom remote control 202 via the signal line 218. That is, the water heater 2 is wired to the kitchen remote control 204 and the bathroom remote control 202. In this embodiment, the signal line 218 also functions as a power line to supply power from the power supply (e.g., commercial power) connected to the water heater 2 to the kitchen remote control 204 and the bathroom remote control 202. Therefore, on the signal line 218, the power for communication is superimposed on the power supply. The microcontroller 214 consists of a CPU, ROM, RAM, etc. The microcontroller 214 includes an internal memory 220 for storing the software of the water heater 2, etc. The external memory 216 is provided separately from the internal memory 220. The external memory 216 includes, for example, non-volatile memory such as EEPROM or flash memory.

[0022] The bathroom remote control 202 is installed, for example, in the bathroom of a user's home. The bathroom remote control 202 comprises an operation unit 222, a display unit 224, a communication interface 226, a microcontroller 228, and a storage unit 230. The operation unit 222 includes, for example, user-operable switches (not shown). The user can input various instructions and information to the bathroom remote control 202 via the operation unit 222. The display unit 224 includes, for example, a display (not shown) that displays various information. A signal line 218 is connected to the communication interface 226. The bathroom remote control 202 can communicate with the water heater 2 and the kitchen remote control 204 via the signal line 218. The microcontroller 228 consists of a CPU, ROM, RAM, etc. The microcontroller 228 controls the bathroom remote control 202. The storage unit 230 includes, for example, non-volatile memory such as EEPROM or flash memory. The memory unit 230 stores various settings related to the water heater 2, such as the setting for the water temperature when filling the bathtub.

[0023] The kitchen remote control 204 is installed, for example, in the kitchen of a user's home. The kitchen remote control 204 comprises an operation unit 232, a display unit 234, a communication interface 236, a wireless module 238, a microcontroller 240, and a memory unit 242. The operation unit 232 includes, for example, user-operable switches (not shown). The user can input various instructions and information to the kitchen remote control 204 via the operation unit 232. The display unit 234 includes, for example, a display (not shown) that displays various information. A signal line 218 is connected to the communication interface 236. The kitchen remote control 204 can communicate with the water heater 2 and the bathroom remote control 202 via the signal line 218. The microcontroller 240 consists of a CPU, ROM, RAM, etc. The microcontroller 240 controls the kitchen remote control 204. The wireless module 238 is an interface for wireless communication. The wireless module 238 can communicate wirelessly with the server 208 via the wireless LAN router 206. The storage unit 242 includes, for example, non-volatile memory such as EEPROM or flash memory. The storage unit 242 stores, for example, various settings related to the water heater 2 (for example, the setting for the water temperature when filling the bathtub).

[0024] Server 208 is managed by the manufacturer that produced the water heater 2. A storage device 244 is connected to server 208. The storage device 244 includes, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). When the manufacturer of the water heater 2 creates update software 256 (see Figure 3) to update the software of the water heater 2, the update software 256 is stored in the storage device 244 as needed.

[0025] The mobile terminal 210 is, for example, a smartphone, tablet, or PC. The mobile terminal 210 is equipped with user-operable switches (not shown) and a display (not shown) that displays various information. The mobile terminal 210 may also be equipped with a touch panel that functions as both a switch and a display. The mobile terminal 210 can communicate wirelessly with the server 208 via the wireless LAN router 206 or using mobile communication such as 4G or 5G. The mobile terminal 210 can also communicate wirelessly with the wireless module 238 of the kitchen remote control 204 via the wireless LAN router 206 or using short-range wireless communication such as Bluetooth®. The mobile terminal 210 has a water heater application installed, provided by the manufacturer of the water heater 2. The water heater application is an application program for receiving various information from the kitchen remote control 204 and the server 208, and for sending various instructions to the kitchen remote control 204 and the server 208. The mobile terminal 210 is equipped with a storage unit (for example, non-volatile memory such as EEPROM or flash memory) for storing the water heater application and the like.

[0026] (Configuration of water heater 2) The water heater 2 shown in Figure 2 can heat water supplied from a water source (not shown), such as a public water supply, and supply the heated water to a desired temperature to a faucet 80 installed in the kitchen or a bathtub (not shown) installed in the bathroom. The water heater 2 can also reheat the water stored in the bathtub. Furthermore, the water heater 2 can supply the heated water to a heating appliance (not shown), such as a panel heater, to provide heating.

[0027] The water heater 2 comprises a burner group 3, a fan 4, a gas-liquid heat exchanger 6, an inlet pipe 7, a hot water outlet pipe 8, and a boiler body 10. The burner group 3 and the gas-liquid heat exchanger 6 are housed inside the boiler body 10. The gas-liquid heat exchanger 6 is positioned above the burner group 3. The fan 4 supplies combustion air from the bottom of the boiler body 10. The combustion gas from the burner group 3 flows from bottom to top inside the boiler body 10, heating the gas-liquid heat exchanger 6. After heating the gas-liquid heat exchanger 6, the combustion exhaust gas is discharged from an exhaust port 10a located at the top of the boiler body 10.

[0028] The gas-liquid heat exchanger 6 is connected to an inlet pipe 7 and a hot water outlet pipe 8. The upstream end of the inlet pipe 7 is connected to a water supply pipe, etc. The downstream end of the hot water outlet pipe 8 is connected to a hot water supply pipe 82 outside the water heater 2. The hot water supply pipe 82 is connected to a faucet 80. The water heater 2 is also equipped with a bypass pipe 9 that bypasses the gas-liquid heat exchanger 6 and connects the inlet pipe 7 and the hot water outlet pipe 8, and a bypass servo 24 that adjusts the opening of the bypass pipe 9 to change the bypass ratio (i.e., the ratio of the flow rate of water supplied to the bypass pipe 9 side to the flow rate of water supplied to the gas-liquid heat exchanger 6 side). Tap water is supplied from the inlet pipe 7 to the gas-liquid heat exchanger 6, heated to a high temperature in the gas-liquid heat exchanger 6, mixed with water from the bypass pipe 9 to adjust the temperature, and then supplied from the hot water outlet pipe 8 to the hot water supply pipe 82.

[0029] The burner group 3 comprises a first burner group 3a, a second burner group 3b, and a third burner group 3c. Fuel gas is supplied to the burner group 3 by a gas supply pipe 11. The gas supply pipe 11 is equipped with, in order from the upstream side, a main gas solenoid valve 12, a gas proportional valve 13, and switching gas solenoid valves 14a, 14b, and 14c. When the main gas solenoid valve 12 is open, fuel gas is supplied to the burner group 3, and when the main gas solenoid valve 12 is closed, the supply of fuel gas to the burner group 3 is cut off. The gas proportional valve 13 adjusts the amount of fuel gas supplied to the burner group 3 by changing its opening degree according to the instruction current output from the microcontroller 214 (see Figure 1). The switching gas solenoid valves 14a, 14b, and 14c are provided corresponding to the first burner group 3a, the second burner group 3b, and the third burner group 3c, respectively. When the switching gas solenoid valves 14a, 14b, and 14c are opened, fuel gas is supplied to the corresponding first burner group 3a, second burner group 3b, and third burner group 3c. When the switching gas solenoid valves 14a, 14b, and 14c are closed, the supply of fuel gas to the corresponding first burner group 3a, second burner group 3b, and third burner group 3c is cut off. By switching each of the switching gas solenoid valves 14a, 14b, and 14c between the open and closed states, the combustion range of the burner group 3 can be switched.

[0030] In the water heater 2 of this embodiment, the combustion rate range of the burner group 3 can be switched in three stages. The first combustion rate range, which has the lowest combustion rate, corresponds to a state where the first burner group 3a is burning, but the second burner group 3b and the third burner group 3c are not burning. The second combustion rate range, which has a higher combustion rate than the first combustion rate range, corresponds to a state where the first burner group 3a and the second burner group 3b are burning, but the third burner group 3c is not burning. The third combustion rate range, which has a higher combustion rate than the second combustion rate range, has the highest combustion rate and corresponds to a state where the first burner group 3a, the second burner group 3b, and the third burner group 3c are all burning. In the water heater 2, the rotation speed of the fan 4 is predetermined according to the current combustion rate range of the burner group 3 and the amount of combustion within that combustion rate range, and the fan 4 rotates at the predetermined rotation speed.

[0031] Near the burner group 3, there is a spark plug 16 for igniting the burner group 3 and a flame rod 17 for detecting the combustion flame of the burner group 3. In addition, there is an igniter 15 that applies a high voltage to the spark plug 16 to generate a spark discharge.

[0032] The inlet pipe 7 is equipped with a flow sensor 18 that detects the flow rate of water supplied to the inlet pipe 7 (= the flow rate of hot water discharged from the outlet pipe 8), a water flow control valve 19 that adjusts the flow rate of water supplied to the inlet pipe 7, and a water supply temperature sensor 25 that detects the temperature of the water supplied to the inlet pipe 7. The outlet pipe 8 is equipped with a heat exchanger outlet temperature sensor 21 that detects the temperature of water flowing in from the gas-liquid heat exchanger 6, and an outlet temperature sensor 23 that detects the temperature of water flowing out to the hot water supply pipe 82. The boiler body 10 is equipped with a boiler body temperature sensor 20 that detects the surface temperature of the boiler body 10, and an acceleration sensor 22 that detects the acceleration of the boiler body 10. The acceleration sensor 22 is a single-axis acceleration sensor that detects the vertical acceleration of the boiler body 10, that is, the acceleration in the direction in which the combustion gas flows inside the boiler body 10.

[0033] (Internal memory configuration of 220) As shown in Figure 3, the internal memory 220 of the microcontroller 214 of the water heater 2 includes a software application area 254 for storing the application software 252 applied to the water heater 2, and a software storage area 258 for storing update software 256 that rewrites at least a part of the application software 252. Normally, the update software 256 is not stored in the software storage area 258. When the microcontroller 214 acquires the update software 256 in the software update management process described later (see Figure 4), the update software 256 is stored in the software storage area 258.

[0034] In the software application area 254, the application software 252 is divided into a part related to the operation using the burner group 3 of the water heater 2 (also called the combustion block 260) and other parts (also called the non-combustion block 262). Specifically, the combustion block 260 is the part related to the control of the fan 4, the main gas solenoid valve 12, the gas proportional valve 13, the switching gas solenoid valves 14a, 14b, 14c, the igniter 15, the spark plug 16, the flame rod 17, the boiler temperature sensor 20, and the acceleration sensor 22 (see Figure 2). The non-combustion block 262 is the part related to the control of the other components of the water heater 2.

[0035] In this embodiment, the addresses of the combustion block 260 and the non-combustion block 262 are separated. Here, the address is an identifier that points to a specific location on the internal memory 220, and this determines the location of each block on the internal memory 220. Furthermore, different label information is assigned to the combustion block 260 and the non-combustion block 262. Here, the label information is information arbitrarily assigned by the software creator. Therefore, the microcontroller 214 can distinguish between the combustion block 260 and the non-combustion block 262 based on at least one of the address and the label information.

[0036] (Software update management process: Figure 4) When power is supplied to the water heater 2, the microcontroller 214 of the water heater 2 periodically (for example, once a day) executes the software update management process shown in Figure 4.

[0037] In S2, the microcontroller 214 of the water heater 2 queries the kitchen remote control 204 for the presence of the update software 256. Upon receiving the query from the water heater 2, the kitchen remote control 204 queries the server 208 for the presence of the update software 256. Upon receiving the query from the kitchen remote control 204, the server 208 checks whether the update software 256 is present in the storage device 244. If the update software 256 is not present in the storage device 244, the server 208 sends an update-free information message to the kitchen remote control 204 indicating that the update software 256 is not present in the storage device 244. The kitchen remote control 204 sends the update-free information received from the server 208 to the water heater 2. If the microcontroller 214 of the water heater 2 receives the update-free information message (i.e., the microcontroller 214 does not acquire the update software 256), the result in S2 is determined to be NO, and the process shown in Figure 4 ends. On the other hand, if the update software 256 is available in the storage device 244, the server 208 transmits the update software 256 stored in the storage device 244 to the kitchen remote control 204. The kitchen remote control 204 transmits the update software 256 received from the server 208 to the water heater 2. In another example, the kitchen remote control 204 may periodically query the server 208 for the availability of the update software 256, and may receive the update software 256 from the server 208 prior to processing S2, and store the received update software 256 in the storage unit 242. In this case, the kitchen remote control 204 may transmit the update software 256 stored in the storage unit 242 to the water heater 2 in response to an inquiry from the water heater 2. As a result, when the microcontroller 214 of the water heater 2 obtains the update software 256, it is determined to be YES in S2, and the process proceeds to S4.

[0038] In S4, the microcontroller 214 identifies which part of the applicable software 252 is the target of the rewrite of the update software 256 acquired in S2 (i.e., the update software 256 stored in the software storage area 258). The update software 256 is accompanied by address and label information that indicates the target of the rewrite. For example, the microcontroller 214 identifies the part of the applicable software 252 with an address that matches the address of the update software 256 as the target of the rewrite. Alternatively, the microcontroller 214 identifies the part of the applicable software 252 with label information that matches the label information of the update software 256 as the target of the rewrite. If there is a part of the update software 256 that does not match the address (or label information) of any part of the applicable software 252, the microcontroller 214 discards that part as having no target for rewrite. After S4, the process proceeds to S6.

[0039] In S6, the microcontroller 214 determines whether the rewrite destination of the update software 256 includes the combustion block 260. For example, if the addresses attached to the update software 256 include an address that matches the address of the combustion block 260, the microcontroller 214 determines that the rewrite destination of the update software 256 includes the combustion block 260 (YES). If the addresses attached to the update software 256 do not include an address that matches the address of the combustion block 260, the microcontroller 214 determines that the rewrite destination of the update software 256 does not include the combustion block 260 (NO). Alternatively, if the label information attached to the update software 256 includes an address that matches the label information of the combustion block 260, the microcontroller 214 determines that the rewrite destination of the update software 256 includes the combustion block 260 (YES). If the label information attached to the update software 256 does not include an address that matches the label information of the combustion block 260, the microcontroller 214 determines that the rewrite destination of the update software 256 does not include the combustion block 260 (NO). If the destination for rewriting the update software 256 includes the combustion block 260 (YES), the process proceeds to S8.

[0040] In S8, the microcontroller 214 discards the update software 256 acquired in S2. That is, the microcontroller 214 erases the update software 256 from the software storage area 258 without rewriting the applied software 252 with the update software 256. After S8, the process shown in Figure 4 is completed.

[0041] If the burnup block 260 is not included as a rewrite destination for the update software 256 in S6 (i.e., NO), the process proceeds to S10. In S10, the microcontroller 214 rewrites the portion of the application software 252 stored in the software application area 254 that corresponds to the rewrite destination for the update software 256 identified in S4, to the corresponding portion of the update software 256. This updates at least a portion of the application software 252. After that, the microcontroller 214 erases the update software 256 from the software retention area 258. After S10, the process shown in Figure 4 is completed.

[0042] According to the process shown in Figure 4, if the destination of the update software 256 includes the combustion block 260, the update software 256 is discarded. This prevents the combustion block 260 of the applied software 252 from being rewritten. As a result, when the water heater 2 performs operation using the burner group 3, it is possible to prevent unintended events (for example, the water being heated to an excessively high temperature in the water heater 2) from occurring. Furthermore, update software 256 that includes the combustion block 260 as a destination has a high probability of improperly rewriting the non-combustion block 262. Therefore, according to the process shown in Figure 4, it is also possible to discard update software 256 that could improperly rewrite the non-combustion block 262.

[0043] (Example 2) This embodiment differs from Embodiment 1 in that the microcontroller 214 of the water heater 2 executes the process shown in Figure 5 instead of the process shown in Figure 4. The process shown in Figure 5 is the same as the process shown in Figure 4, but with S8 replaced by S18. The following explanation will focus on this point.

[0044] If the rewriting destination for the update software 256 in S6 includes the combustion block 260 (YES), then S18 is executed. In S18, the microcontroller 214 excludes the combustion block 260 from the rewriting destinations for the update software 256 identified in S4. For example, the microcontroller 214 prohibits the use of the portion of the update software 256 with an address matching the address of the combustion block 260 for rewriting the applicable software 252 in the subsequent S10. Alternatively, the microcontroller 214 prohibits the use of the portion of the update software 256 with label information matching the label information of the combustion block 260 for rewriting the applicable software 252 in the subsequent S10. After S18, the process proceeds to S10.

[0045] According to the process shown in Figure 5, even if the combustion block 260 is included as a target for rewriting the update software 256, the combustion block 260 is excluded from the rewriting target before the update of the applied software 252 is performed. As a result, the non-combustion block 262 of the applied software 252 is rewritten to the update software 256, but the combustion block 260 is not rewritten to the update software 256. This prevents the combustion block 260 of the applied software 252 from being rewritten. Consequently, when the water heater 2 operates using the burner group 3, unintended events can be prevented from occurring.

[0046] (Example 3) This embodiment differs from Embodiment 1 in that the microcontroller 214 of the water heater 2 executes the process shown in Figure 6 instead of the process shown in Figure 4. The following explanation will focus on the process shown in Figure 6.

[0047] In S32, the microcontroller 214 attempts to acquire the update software 256, similar to S2 in Figure 4. If the microcontroller 214 does not acquire the update software 256, it is determined to be NO in S32, and the process shown in Figure 6 ends. On the other hand, if the microcontroller 214 acquires the update software 256, it is determined to be YES in S32, and the process proceeds to S34.

[0048] In S34, the microcontroller 214 identifies the destination for rewriting the update software 256, similar to S4 in Figure 4. After S34, the process proceeds to S36.

[0049] In S36, the microcontroller 214 overwrites the portion of the application software 252 stored in the software application area 254 that corresponds to the rewrite target of the update software 256 identified in S34 with the corresponding portion of the update software 256. This updates at least a portion of the application software 252. After that, the microcontroller 214 erases the update software 256 from the software storage area 258. After S36, the process proceeds to S38.

[0050] In S38, the microcontroller 214 restores the combustion block 260 of the applied software 252 to its state before the update in S36. As shown in Figure 7, the external memory 216 of this embodiment has a copy 260C of the combustion block 260 of the applied software 252 stored in advance. The copy 260C of the combustion block 260 is stored in the external memory 216, for example, when the water heater 2 is shipped from the factory. Therefore, in S38, the microcontroller 214 rewrites the combustion block 260 of the applied software 252 using the copy 260C of the combustion block 260 stored in the external memory 216. As a result, the combustion block 260 of the applied software 252 is restored to its state before the update in S36. After S38, the process shown in Figure 6 is completed.

[0051] According to the process shown in Figure 6, even if the combustion block 260 of the applied software 252 is overwritten with the update software 256, the combustion block 260 is restored afterward. This prevents the water heater 2 from being used while the combustion block 260 is overwritten with the update software 256. As a result, it is possible to prevent unintended events from occurring when the water heater 2 performs operation using the burner group 3.

[0052] (Example 4) This embodiment differs from Embodiment 1 in that the microcontroller 214 of the water heater 2 executes the process shown in Figure 8 instead of the process shown in Figure 4. The following explanation will focus on the process shown in Figure 8.

[0053] In S52, the microcontroller 214 attempts to acquire the update software 256, similar to S2 in Figure 4. If the microcontroller 214 does not acquire the update software 256, it is determined to be NO in S52, and the process shown in Figure 8 ends. On the other hand, if the microcontroller 214 acquires the update software 256, it is determined to be YES in S52, and the process proceeds to S54.

[0054] In S54, the microcontroller 214 identifies the destination for rewriting the update software 256, similar to S4 in Figure 4. After S54, the process proceeds to S56.

[0055] In S56, the microcontroller 214 overwrites the portion of the application software 252 stored in the software application area 254 that corresponds to the rewrite target of the update software 256 identified in S54 with the corresponding portion of the update software 256. This updates at least a portion of the application software 252. After that, the microcontroller 214 erases the update software 256 from the software storage area 258. After S56, the process proceeds to S58.

[0056] In S58, the microcontroller 214 determines whether the combustion block 260 of the applied software 252 was rewritten with the updated software 256 in S56, that is, whether the target of the update software 256 was the combustion block 260. For example, the microcontroller 214 compares the error detection codes of the combustion block 260 of the applied software 252 stored in the software application area 254 (i.e., the combustion block 260 of the applied software 252 after updating in S56) and the copy 260C of the combustion block 260 previously stored in the external memory 216 (i.e., the combustion block 260 of the applied software 252 before updating in S56). The microcontroller 214 then determines that the combustion block 260 was rewritten with the updated software 256 (YES) if the error detection codes of the two are different, and determines that the combustion block 260 was not rewritten with the updated software 256 (NO) if the error detection codes of the two are the same. If the combustion block 260 has not been rewritten with the update software 256 (NO), the process shown in Figure 8 ends. If the combustion block 260 has been rewritten with the update software 256 (YES), the process proceeds to S60.

[0057] In S60, the microcontroller 214 restores the combustion block 260 of the applied software 252 to its state before it was updated in S56. That is, the microcontroller 214 rewrites the combustion block 260 of the applied software 252 using a copy 260C of the combustion block 260 stored in the external memory 216. This restores the combustion block 260 of the applied software 252 to its state before it was updated in S56. After S60, the process shown in Figure 8 is completed.

[0058] According to the process shown in Figure 8, even if the combustion block 260 of the applied software 252 is overwritten with the update software 256, the combustion block 260 is restored afterward. This prevents the water heater 2 from being used while the combustion block 260 is overwritten with the update software 256. As a result, it is possible to prevent unintended events from occurring when the water heater 2 performs operation using the burner group 3.

[0059] (Example 5) This embodiment differs from Embodiment 1 in that the microcontroller 214 of the water heater 2 executes the process shown in Figure 9 instead of the process shown in Figure 4. The following explanation will focus on the process shown in Figure 9.

[0060] In S72, the microcontroller 214 attempts to acquire the update software 256, similar to S2 in Figure 4. If the microcontroller 214 does not acquire the update software 256, S72 is determined to be NO, and the process shown in Figure 9 ends. On the other hand, if the microcontroller 214 acquires the update software 256, S72 is determined to be YES, and the process proceeds to S74.

[0061] In S74, the microcontroller 214 identifies the destination for rewriting the update software 256, similar to S4 in Figure 4. After S74, the process proceeds to S76.

[0062] In S76, the microcontroller 214 determines whether the combustion block 260 is included in the rewrite destination of the update software 256, similar to S6 in Figure 4.

[0063] If the burnup block 260 is not included as a rewrite destination for the update software 256 in S76 (i.e., NO), the process proceeds to S78. In S78, the microcontroller 214 rewrites the portion of the application software 252 stored in the software application area 254 that corresponds to the rewrite destination for the update software 256 identified in S74 to the corresponding portion of the update software 256. This updates at least a portion of the application software 252. After that, the microcontroller 214 erases the update software 256 from the software retention area 258 and terminates the process shown in Figure 9.

[0064] If the rewrite destination for the update software 256 in S76 is the combustion block 260 (YES), the process proceeds to S80. In S80, the microcontroller 214, as in S78, rewrites the portion of the application software 252 stored in the software application area 254 that corresponds to the rewrite destination for the update software 256 identified in S74 to the corresponding portion of the update software 256. This updates at least a portion of the application software 252. After that, the microcontroller 214 restores the combustion block 260 of the application software 252 to its pre-update state. That is, the microcontroller 214 rewrites the combustion block 260 of the application software 252 using a copy 260C of the combustion block 260 that is pre-stored in the external memory 216. This restores the combustion block 260 of the application software 252 to its pre-update state. The microcontroller 214 also erases the update software 256 from the software storage area 258. After S80, the process shown in Figure 9 is completed.

[0065] According to the process shown in Figure 9, even if the combustion block 260 is included as a target for rewriting the update software 256, the combustion block 260 is restored after the applied software 252 is rewritten with the update software 256. This prevents the water heater 2 from being used while the combustion block 260 has been rewritten with the update software 256. As a result, it is possible to prevent unintended events from occurring when the water heater 2 performs operation using the burner group 3.

[0066] (modified version) (See Figure 1) The water heater 2 may be replaced with a different piece of equipment (for example, a cooking appliance, a clothes dryer, a dishwasher, a bathroom heater / dryer, a tank device, a microbubble generator, or a fuel cell power generator). In this case, the microcontroller 214 of each piece of equipment may be configured to perform software update management processing (see Figures 4, 5, 6, 8, and 9), similar to the microcontroller 214 of the water heater 2.

[0067] (See Figure 1) The water heater 2 may communicate with the server 208 without going through the kitchen remote control 204. For example, the water heater 2 may be able to perform wireless communication with the server 208 via the wireless LAN router 206. In this case, the water heater 2 may obtain the update software 256 by wireless communication with the server 208. Alternatively, the water heater 2 may communicate with the server 208 via the mobile terminal 210. In this case, the mobile terminal 210 may transmit the update software 256 received from the server 208 to the water heater 2 instead of the kitchen remote control 204. The water heater 2 may obtain the update software 256 stored in the storage unit (not shown) of the mobile terminal 210.

[0068] (See Figure 3) The application software 252 may be divided into multiple blocks from a different perspective than in the embodiment. For example, if the equipment is a device equipped with a pump (e.g., a clothes dryer, a dishwasher, a bathroom heater / dryer, a tank device, a microbubble generator), the part of the application software 252 related to operation using the pump may be distinguished as a "pump-related block". In this case, the software update management process described in the embodiment (see Figures 4, 5, 6, 8, and 9) may suppress the pump-related block from being overwritten with the update software 256.

[0069] (See Figure 7) A copy 260C of the combustion block 260 may be stored in a location other than the external memory 216. For example, the copy 260C of the combustion block 260 may be stored separately from the update software 256 in the software storage area 258 of the internal memory 220. Alternatively, the copy 260C of the combustion block 260 may be stored in equipment other than the water heater 2 (for example, the storage device 244 connected to the server 208, the storage unit 242 of the kitchen remote control 204, or the storage unit 230 of the bathroom remote control 202). In this case, when restoring the combustion block 260, the microcomputer 214 of the water heater 2 may communicate with other equipment and obtain a copy 260C of the combustion block 260 from that equipment.

[0070] (See Figure 7) The external memory 216 may store not only a copy 260C of the combustion block 260, but also a copy of the non-combustion block 262. That is, the external memory 216 may have a complete copy of the application software 252 pre-stored in it. In this case, the microcontroller 214 of the water heater 2 may rewrite the application software 252 with the complete copy of the application software 252 pre-stored in the external memory 216 at S38 in Figure 6 (or S60 in Figure 8, S80 in Figure 9). This may restore the entire application software 252 to its state before the update.

[0071] (Features of the example) (See Examples 1 and 2) The equipment system 200 includes a water heater 2 (an example of equipment). The water heater 2 includes an internal memory 220 (an example of a first software storage unit) that stores application software 252 (an example of first software) applied to the water heater 2, and a microcontroller 214 (an example of a control unit). The microcontroller 214 is configured to perform an acquisition process to acquire update software 256 (an example of second software) for rewriting at least a portion of the application software 252, a determination process to determine which portion of the application software 252 the update software 256 will rewrite, and an update process to rewrite at least a portion of the application software 252 with the update software 256. The application software 252 includes a combustion block 260 (an example of a specific operation-related part) relating to the operation of the water heater 2 using the burner group 3 (an example of a specific operation). If the microcontroller 214 acquires the update software 256 through an acquisition process and then determines through a determination process that the update software 256 rewrites the combustion block 260 of the applied software 252, it will not perform the update process, at least with respect to the combustion block 260. If the microcontroller 214 acquires the update software 256 through an acquisition process and then determines through a determination process that the update software 256 does not rewrite the combustion block 260 of the applied software 252, it will perform the update process.

[0072] According to the above configuration, if the acquired update software 256 rewrites the combustion block 260 of the applied software 252, the microcontroller 214 will refrain from executing the update process, at least with respect to the combustion block 260. This prevents the combustion block 260 of the applied software 252 from being rewritten. As a result, it is possible to prevent unintended events from occurring when the water heater 2 operates using the burner group 3.

[0073] (See Example 3) The equipment system 200 includes a water heater 2. The water heater 2 includes an internal memory 220 (example of a first software storage unit) that stores application software 252 (example of a first software) applied to the water heater 2, an external memory 216 (example of a copy storage unit) that stores a copy 260C of the combustion block 260 (example of a specific operation-related part) of the application software 252 related to operation using the burner group 3 of the water heater 2 (example of a specific operation), and a microcontroller 214 (example of a control unit). The microcontroller 214 is configured to perform an acquisition process to acquire update software 256 (example of a second software) for rewriting at least a part of the application software 252, an update process to rewrite at least a part of the application software 252 with the update software 256, and a restoration process to rewrite the combustion block 260 of the application software 252 with a copy 260C of the combustion block 260 stored in the external memory 216. The microcontroller 214 performs an update process, and then performs a restore process afterward.

[0074] According to the above configuration, the microcontroller 214 rewrites the applied software 252 with the updated software 256 and then restores at least the combustion block 260. This prevents the water heater 2 from being used while the combustion block 260 of the applied software 252 is still being rewritten with the updated software 256. As a result, it is possible to prevent unintended events from occurring when the water heater 2 performs operation using the burner group 3.

[0075] (See Examples 4 and 5) The equipment system 200 includes a water heater 2 (an example of equipment). The water heater 2 includes an internal memory 220 (an example of a first software storage unit) that stores application software 252 (an example of first software) applied to the water heater 2, an external memory 216 (an example of a copy storage unit) that stores a copy 260C of the combustion block 260 (an example of a specific operation-related part) of the application software 252 related to operation using the burner group 3 of the water heater 2 (an example of a specific operation), and a microcontroller 214 (an example of a control unit). The microcontroller 214 is configured to perform the following: an acquisition process to acquire update software 256 (an example of second software) for rewriting at least a portion of the applied software 252; a determination process to determine which portion of the applied software 252 the update software 256 will rewrite; an update process to rewrite at least a portion of the applied software 252 with the update software 256; and a restoration process to rewrite the combustion block 260 of the applied software 252 with a copy 260C of the combustion block 260 stored in the external memory 216. If the microcontroller 214 determines through the determination process that the update software 256 does not rewrite the combustion block 260 of the applied software 252, it does not perform the restoration process after the update process. If the microcontroller 214 determines through the determination process that the update software 256 does rewrite the combustion block 260 of the applied software 252, it performs the restoration process after the update process.

[0076] According to the above configuration, if the acquired update software 256 rewrites the combustion block 260 of the applied software 252, the microcontroller 214 rewrites the applied software 252 with the update software 256 and then restores at least the combustion block 260. This prevents the water heater 2 from being used while the combustion block 260 of the applied software 252 has been rewritten with the update software 256. As a result, it is possible to prevent unintended events from occurring when the water heater 2 performs operation using the burner group 3.

[0077] (See Examples 1-5) The equipment system 200 further includes a server 208 configured to communicate with the water heater 2. During the acquisition process, the microcontroller 214 acquires the update software 256 supplied from the server 208.

[0078] With the above configuration, the microcontroller 214 obtains the update software 256 via the server 208. This prevents the microcontroller 214 from obtaining unauthorized update software 256 distributed by parties other than authorized distributors. Furthermore, with the above configuration, the software for the water heater 2 can be centrally managed by the server 208, enabling efficient software version control and distribution.

[0079] (See Examples 1-5) The equipment system 200 further includes a kitchen remote control 204 (example of a remote control) that allows the user to input instructions to the water heater 2 and relays communication between the server 208 and the water heater 2. The kitchen remote control 204 includes a storage unit 242 (example of a remote control storage unit) that stores update software 256 supplied from the server 208. In the acquisition process, the microcomputer 214 acquires the update software 256 stored in the storage unit 242.

[0080] The water heater 2 may limit the acquisition of the update software 256 to specific time periods (for example, at night). If the water heater 2 were configured to acquire the update software 256 directly from the server 208, the period during which the server 208 distributes the update software 256 would be concentrated in specific time periods, potentially overloading the server 208. In contrast, with the above configuration, the water heater 2 acquires the update software 256 from the server 208 via the kitchen remote control 204. Therefore, the update software 256 can be distributed from the server 208 to the kitchen remote control 204 at any time period, and the kitchen remote control 204 can hold (i.e., store) the update software 256 until it is time for the water heater 2 to acquire the update software 256. This prevents the period during which the server 208 distributes the update software 256 from being concentrated in specific time periods, thus preventing overloading the server 208.

[0081] (See modified example) The equipment system 200 further includes a portable terminal 210 that is portable to the user and relays communication between the server 208 and the water heater 2. The portable terminal 210 includes a storage unit (example of a terminal storage unit) that stores the update software 256 supplied from the server 208. In the acquisition process, the microcontroller 214 acquires the update software 256 stored in the storage unit of the portable terminal 210.

[0082] The water heater 2 may limit the acquisition of the update software 256 to specific time periods (for example, at night). If the water heater 2 were configured to acquire the update software 256 directly from the server 208, the period during which the server 208 distributes the update software 256 would be concentrated in specific time periods, potentially overloading the server 208. In contrast, with the above configuration, the water heater 2 acquires the update software 256 from the server 208 via the mobile terminal 210. Therefore, the update software 256 can be distributed from the server 208 to the mobile terminal 210 at any time period, and the update software 256 can be held (i.e., stored) in the mobile terminal 210 until it is time for the water heater 2 to acquire the update software 256. This prevents the period during which the server 208 distributes the update software 256 from being concentrated in specific time periods, thus preventing overloading the server 208.

[0083] (See Examples 1-5) The water heater 2 is equipped with a group of burners 3 (an example of a heating section). The combustion block 260 relates to the operation of the water heater 2 using the group of burners 3.

[0084] If the portion of the applied software 252 related to operation using burner group 3 is overwritten with the updated software 256, and the water heater 2 is used in that state, there is a risk that unintended events may occur during operation using burner group 3. With the above configuration, it is suppressed that the water heater 2 is used while the portion of the applied software 252 related to operation using burner group 3 is overwritten with the updated software 256. Therefore, this suppresses the occurrence of unintended events during operation using burner group 3.

[0085] The technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Furthermore, the technologies illustrated herein or in the drawings can achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself. [Explanation of Symbols]

[0086] 2: Water heater, 3: Burner group, 3a: First burner group, 3b: Second burner group, 3c: Third burner group, 4: Fan, 6: Gas-liquid heat exchanger, 7: Inlet pipe, 8: Outlet pipe, 9: Bypass pipe, 10: Boiler, 10a: Exhaust port, 11: Gas supply pipe, 12: Main gas solenoid valve, 13: Gas proportional valve, 14a: Switching gas solenoid valve, 14b: Switching gas solenoid valve, 14c: Switching gas solenoid valve, 15: Igniter, 16: Spark plug, 17: Flame rod, 18: Flow sensor, 19: Water volume control valve, 20: Boiler temperature sensor, 21: Heat exchanger outlet temperature sensor, 22: Acceleration sensor, 23: Outlet temperature sensor, 24: Bypass servo, 25: Water supply temperature sensor, 80: Faucet, 82: Hot water supply pipe, 200: Equipment system, 202: Bathroom remote control 204: Kitchen remote control, 206: Wireless LAN router, 208: Server, 210: Mobile terminal, 212: Communication interface, 214: Microcontroller, 216: External memory, 218: Signal line, 220: Internal memory, 222: Operation unit, 224: Display unit, 226: Communication interface, 228: Microcontroller, 230: Memory unit, 232: Operation unit, 234: Display unit, 236: Communication interface, 238: Wireless module, 240: Microcontroller, 242: Memory unit, 244: Storage device, 252: Applicable software, 254: Software application area, 256: Update software, 258: Software retention area, 260: Combustion block, 260C: Copy of combustion block, 262: Non-combustion block

Claims

1. A system of equipment including equipment, The aforementioned equipment and machinery are A first software storage unit that stores first software applied to the aforementioned equipment, It includes a control unit, The control unit, An acquisition process for acquiring second software for rewriting at least a part of the first software, A determination process that determines which part of the first software the second software will rewrite, The system is configured to perform an update process that rewrites at least a portion of the first software with the second software, The first software includes a specific operation-related portion relating to the specific operation of the equipment, The control unit, If, after acquiring the second software through the acquisition process, the determination process determines that the second software rewrites the specific operation-related portion of the first software, then the update process is not performed with respect to at least the specific operation-related portion. An equipment system that, after acquiring the second software through the acquisition process, determines through the determination process that the second software does not rewrite the specific operation-related portion of the first software, and then executes the update process.

2. A system of equipment including equipment, The aforementioned equipment and machinery are A first software storage unit that stores first software applied to the aforementioned equipment, A copy storage unit that stores a copy of at least the specific operation-related portion of the first software relating to the specific operation of the equipment, It includes a control unit, The control unit, An acquisition process for acquiring second software for rewriting at least a part of the first software, An update process that rewrites at least a portion of the first software with the second software, The software is configured to perform a restoration process that rewrites at least the specific operation-related portion of the first software with the copy stored in the copy storage unit, The control unit, after executing the update process, then executes the restoration process, in this equipment system.

3. A system of equipment including equipment, The aforementioned equipment and machinery are A first software storage unit that stores first software applied to the aforementioned equipment, A copy storage unit that stores a copy of at least the specific operation-related portion of the first software relating to the specific operation of the equipment, It includes a control unit, The control unit, An acquisition process for acquiring second software for rewriting at least a part of the first software, A determination process that determines which part of the first software the second software will rewrite, An update process that rewrites at least a portion of the first software with the second software, The software is configured to perform a restoration process that rewrites at least the specific operation-related portion of the first software with the copy stored in the copy storage unit, The control unit, If the determination process determines that the second software does not rewrite the specific operation-related portion of the first software, the restoration process is not executed after the update process. If the determination process determines that the second software rewrites the specific operation-related portion of the first software, the equipment system executes the restoration process after the update process.

4. The system further includes an external server configured to communicate with the aforementioned equipment. The equipment system according to any one of claims 1 to 3, wherein in the acquisition process, the control unit acquires the second software supplied from the external server.

5. The system further includes a remote control that allows the user to input instructions to the equipment and relays communication between the external server and the equipment. The remote control includes a remote control storage unit that stores the second software supplied from the external server, The equipment system according to claim 4, wherein in the acquisition process, the control unit acquires the second software stored in the remote control storage unit.

6. The system further includes a portable terminal that is portable to the user and relays communication between the external server and the equipment, The aforementioned mobile terminal includes a terminal storage unit that stores the second software supplied from the external server, The equipment system according to claim 4, wherein in the acquisition process, the control unit acquires the second software stored in the terminal storage unit.

7. The aforementioned equipment includes a heating section, The equipment system according to any one of claims 1 to 3, wherein the specific operation of the equipment includes operation using the heating unit.

Citation Information

Patent Citations

  • Network system for home appliance

    JP2009169524A