Control System

The control system synchronizes control device updates by preparing all devices for software changes before shutdown and synchronized restart, addressing software inconsistencies in vehicle control systems.

JP7679802B2Active Publication Date: 2025-05-20TOYOTA JIDOSHA KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022108367
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-05
Publication Date
2025-05-20
Estimated Expiration
2042-07-05

AI Technical Summary

Technical Problem

Existing vehicle control systems face software inconsistencies when updating multiple control devices due to asynchronous shutdowns during Over-The-Air (OTA) updates, leading to potential functional discrepancies among devices.

Method used

A control system design that ensures all control devices prepare for and complete software updates before shutdown, switching execution storage areas only after a synchronized shutdown, using ring-type or star-type communication to verify readiness and prevent inconsistencies.

Benefits of technology

This approach minimizes software inconsistencies by ensuring all control devices update consistently, reducing the likelihood of software discrepancies during the transition to new software versions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007679802000001
    Figure 0007679802000001
  • Figure 0007679802000002
    Figure 0007679802000002
  • Figure 0007679802000003
    Figure 0007679802000003
Patent Text Reader

Abstract

To suppress inconsistency of software among control devices in updating the software on a plurality of control devices.SOLUTION: In the case where each of ECUs 10, 20, 30 updates a control program in a state in which an update version of the control program has been installed in a memory area other than an execution memory area of each of the ECUs 10, 20, 30 included in a control system, each of the ECUs 10, 20, 30 prepares to switch the execution memory area, and all of the ECUs 10, 20, 30 are shut down when all the ECUs 10, 20, 30 have completed the switching preparation. In the case where all the ECUs 10, 20, 30 which have completed the switching preparation are shut down, each of the ECUs 10, 20, 30 sets, at the next startup, the memory area with the update version of the control program installed therein, as the execution memory area.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to a control system, a control device, a control program update method, and a program. [Background technology]

[0002] Conventionally, a vehicle equipped with a control system including a plurality of control devices is known. Each of the plurality of control devices is implemented with software for controlling, for example, an actuator mounted on the vehicle. After the vehicle is supplied to the market, an update program (an updated version of a control program) may be provided to the vehicle, for example, by OTA (Over The Air). The vehicle can update the software of the control system using the provided update program. By updating the software in at least one control device included in the control system, the functions of the vehicle are updated (for example, modified or added). However, for control performed in cooperation with a plurality of control devices (for example, control of a driving assistance system such as automatic driving control), it is required that the versions of the control programs executed in those control devices are consistent.

[0003] JP 2019-144670 A (Patent Document 1) discloses a technology in which each execution unit included in a control system obtains an identifier contained in a control program to be executed by the other execution unit from the other execution unit, and determines whether the control program to be executed by the other execution unit has been changed based on the identifier. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2019-144670 A Summary of the Invention [Problem to be solved by the invention]

[0005] By checking the identifier of the control program to be executed by each control device, it is possible to check whether a software inconsistency has occurred between the control devices. However, it is desirable to prevent a software inconsistency before it occurs. Also, from the viewpoint of user convenience, it is desirable to simultaneously update the control programs (software) in multiple control devices when each control device is started up.

[0006] Updating vehicle software using OTA involves steps such as downloading (sending new software to the vehicle), installing (writing the new software into the control device), and activating (enabling the new software written into the control device). After going through these steps and completing activation of the new software, multiple control devices are shut down all at once, and then started up all at once, updating the software in each control device to the new software.

[0007] However, multiple control devices do not necessarily shut down at the same time at the desired timing. If only some of the control devices shut down before activation is complete due to a momentary power outage or the like, the control devices that have not yet completed activation will start up with the software before the update, while the other control devices that have completed activation will start up with the new software (the updated software). In such cases, software inconsistencies may occur between the control devices.

[0008] The present disclosure has been made to solve the above-mentioned problems, and has an object to suppress software inconsistencies between multiple control devices when updating software in the control devices. [Means for solving the problem]

[0009] According to an embodiment of a first aspect of the present disclosure, there is provided a control system as described below. (Article 1) The control system includes a plurality of control devices. Each of the plurality of control devices has a storage unit including a plurality of storage areas, and is configured to execute a control program stored in an execution storage area, which is one of the plurality of storage areas. When each of the plurality of control devices updates the control program in a state in which an updated version of the control program is installed in a storage area other than the execution storage area of ​​each of the plurality of control devices, each of the plurality of control devices prepares to switch the execution storage area, and all of the plurality of control devices are shut down based on the fact that all of the plurality of control devices are in a state in which they are ready to switch. When all of the plurality of control devices are shut down in a state in which they are ready to switch, each of the plurality of control devices sets the storage area in which the updated version of the control program is installed as the execution storage area at the time of the next startup.

[0010] Hereinafter, the execution memory area is also referred to as an “active surface.” Moreover, the memory area in which an updated version of the control program stored in the execution memory area is installed is also referred to as a “write surface.”

[0011] In the above control system, among the processes related to activation, the process related to preparation for switching the active surface is executed before shutdown, and the process related to switching the active surface is executed at startup after shutdown. In order to update the software (control program), it is necessary to prepare for switching the active surface (i.e., prepare to set the writing surface as the active surface) after installing the new software (updated version of the control program). In the process related to the switching preparation, the control device is set to a switching preparation complete state (i.e., a state in which the control device operates normally even if the active surface is switched from the storage area currently set as the active surface to the writing surface). In the control device in the switching preparation complete state, there are no tasks remaining to be executed by the control program before the update, and the execution of the control program before the update is unnecessary. For this reason, the control device in the switching preparation complete state can smoothly update the software after shutdown by simply switching the active surface at the next startup (setting the writing surface as the active surface).

[0012] In the above control system, when all of the multiple control devices are shut down in a switching preparation complete state, each of the control devices switches the active side at the next startup. It is unlikely that any of the control devices will shut down due to a momentary power interruption or the like during the short period immediately after startup (the period during which the active side is switched). Therefore, according to the above control system, it is possible to suppress software inconsistencies between the multiple control devices when updating software in those control devices.

[0013] The control system described in the above paragraph 1 may have the configuration described in any one of paragraphs 2 to 7 below.

[0014] (2) The control system according to the first aspect further has the following feature: If at least one of the plurality of control devices is shut down before it is ready to switch, none of the plurality of control devices will switch the execution memory area at the next startup.

[0015] Preparation for switching tends to take longer than switching the active side. Therefore, there is a possibility that one of the control devices will shut down due to a momentary power interruption or the like during preparation for switching the active side. In this regard, according to the above-mentioned configuration, if at least one of the multiple control devices shuts down due to a momentary power interruption or the like before it becomes ready to switch, none of the multiple control devices will switch the active side at the next startup. Therefore, software inconsistencies are less likely to occur between the control devices.

[0016] (3) The control system according to 1 or 2 further has the following features: Each of the control devices is configured to transmit a ready signal indicating that the control device is ready to switch when preparation for switching the execution storage area is complete. The control devices are configured to exchange the ready signals between the control devices by ring-type communication.

[0017] According to the above configuration, one of the control devices can know that the other control device has become ready to switch based on the preparation completion signal received from the other control device. In addition, the ring-type communication makes it easier to suppress communication congestion between the control devices.

[0018] (4) The control system according to 1 or 2 further has the following features: Each of the control devices is configured to transmit a ready signal indicating that the control device is ready to switch when preparation for switching the execution storage area is complete. The control devices are configured to exchange the ready signals between the control devices by star-type communication.

[0019] According to the above configuration, a specific control device among the multiple control devices can know that the other control devices have become ready to switch based on the ready signal received from the other control devices. In addition, the other control devices can directly transmit the ready signal to the specific control device through star-type communication. This makes it easier for the specific control device to know the state of the other control devices at an early stage.

[0020] (Item 5) The control system according to any one of items 1 to 4 further has the following features. The multiple control devices include a first control device, a second control device, and a third control device. The first control device is configured to receive a shutdown request from a user. When the first control device receives the shutdown request, if an updated version of the control program has been installed in all of the first to third control devices, the first control device transmits a switching instruction to each of the second control device and the third control device, and then starts preparations for switching the execution storage area. When the second control device and the third control device receive the switching instruction, each starts preparations for switching the execution storage area.

[0021] According to the above configuration, the process for preparing to switch the active surface is started in response to a request from a user, which makes it easier to execute the process for updating the software at a timing that does not impair user convenience.

[0022] (Item 6) The control system described in item 5 further has the following feature: When the first control device updates the control program in a state in which an updated version of the control program is not installed in either the second control device or the third control device, the first control device identifies whether the updated version of the control program is installed in the second control device or the third control device. After identifying the first control device, the first control device transmits a switching instruction to the control device in which the updated version of the control program is installed, and does not transmit a switching instruction to the control device in which the updated version of the control program is not installed.

[0023] According to the above configuration, a switching instruction is not sent to a control device in which the new software has not been installed, thereby reducing unnecessary communication.

[0024] (Item 7) The control system according to item 5 or 6 further has the following features. Each of the multiple control devices is configured to control a vehicle. The vehicle includes a start-up switch for a user to start up the vehicle system. When the user turns off the start-up switch, a shutdown request is input to the first control device. Each of the multiple control devices starts up in response to the user turning on the start-up switch.

[0025] According to the above configuration, in response to the user's operation of the vehicle start switch, the process related to preparation for switching the active surface is started and each control device is started after shutdown. This makes it easier to execute the process for software update at a timing that does not impair user convenience.

[0026] The vehicle may be an xEV, which uses electricity as all or part of its power source. Examples of xEV include BEV (electric vehicle), PHEV (plug-in hybrid vehicle), HEV (hybrid vehicle), FCEV (fuel cell vehicle), etc.

[0027] According to an embodiment of the second aspect of the present disclosure, there is provided a control device as described below. (Clause 8) The control device includes a storage unit including a plurality of storage areas, a setting unit that sets one of the plurality of storage areas as an execution storage area, an execution unit that executes a control program stored in the execution storage area, and a writing unit that installs an update program, which is an update of the control program, in one of the plurality of storage areas. The plurality of storage areas include a first storage area and a second storage area. When the first storage area is set as the execution storage area and the update program is installed in the second storage area, and the plurality of control devices including the control device update the control program, the setting unit prepares to switch the execution storage area to the second storage area. Then, the control device shuts down based on the fact that all of the plurality of control devices have reached a switching preparation completion state. The setting unit switches the execution storage area from the first storage area to the second storage area at the next startup of the control device that was shut down in the switching preparation completion state.

[0028] In the above control device, as in the above-mentioned control system, when software is updated in a plurality of control devices, it is possible to suppress software inconsistencies between the control devices.

[0029] According to an embodiment of a third aspect of the present disclosure, there is provided a control program update method as described below.

[0030] (Clause 9) The control program update method includes installing an updated version of the control program stored in an execution memory area of ​​each of the multiple control devices in a memory area other than the execution memory area of ​​each of the multiple control devices; each of the multiple control devices in which the updated version of the control program is installed preparing to switch its execution memory area; shutting down all of the multiple control devices based on the fact that all of the multiple control devices have completed preparation to switch their execution memory areas; and all of the multiple control devices that have been shut down in a switching preparation state switching their execution memory areas to the memory area in which the updated version of the control program is installed at the next startup.

[0031] In the above control program update method, as in the above control system, when software is updated in a plurality of control devices, it is possible to suppress software inconsistencies between the control devices.

[0032] According to another aspect, there is provided a program for causing a computer to execute the method according to claim 9. In one aspect, there is provided a computer device including a storage device for storing the program, and a processor for executing the program stored in the storage device. In another aspect, there is provided a computer device for distributing the program. Effect of the Invention

[0033] According to the present disclosure, when updating software in a plurality of control devices, it is possible to suppress software inconsistencies between the control devices. [Brief description of the drawings]

[0034] [Figure 1] 1 is a diagram showing a configuration of a vehicle according to an embodiment of the present disclosure. [Diagram 2] 2 is a diagram for explaining the configuration and function of each control device included in a control system according to an embodiment of the present disclosure. FIG. [Diagram 3]11 is a flowchart showing a process for preparing to switch an active surface in an activation method according to an embodiment of the present disclosure. [Figure 4] 11 is a flowchart showing a process for switching an active surface in an activation method according to an embodiment of the present disclosure. [Diagram 5] 11 is a diagram for explaining an example of an operation after installation of each control device included in a control system according to an embodiment of the present disclosure is completed. FIG. [Figure 6] FIG. 6 shows a first modified example of the embodiment shown in FIG. [Figure 7] FIG. 6 shows a second modified example of the embodiment shown in FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0035] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present disclosure will now be described in detail with reference to the accompanying drawings, in which the same or corresponding parts are designated by the same reference characters and will not be described repeatedly.

[0036] FIG. 1 is a diagram showing a configuration of a vehicle 100 according to this embodiment. Referring to FIG. 1, the vehicle 100 is, for example, an electric vehicle (BEV) that does not include an internal combustion engine. The vehicle 100 includes ECUs 10, 20, and 30, a start switch 50, a driving device 61, an ADS (Autonomous Driving System) 62, and an HMI (Human Machine Interface) 70. Each of the ECUs 10, 20, and 30, the driving device 61, the ADS 62, and the HMI 70 receives power from a power source (for example, an on-board battery) not shown. "ECU" means an electronic control unit.

[0037] The start switch 50 is a switch that allows the user to start the vehicle system (the control system of the vehicle 100), and is installed, for example, in the passenger compartment of the vehicle 100. The start switch is generally called a "power switch" or an "ignition switch." The user operates the start switch 50 to switch the vehicle system on (operating) / off (stopped). When the start switch 50 is turned on, the vehicle system (including the ECUs 10, 20, 30) that is in a stopped state starts up, and the vehicle system goes into an operating state (hereinafter also referred to as "IG on"). When the start switch 50 is turned off while the vehicle system is operating, the vehicle system goes into a stopped state (hereinafter also referred to as "IG off").

[0038] The on operation of the start switch 50 is an operation to switch the state of the vehicle 100 from IG off to IG on. When the user turns on the start switch 50, a start request is input to each of the ECUs 10, 20, and 30. That is, each of the ECUs 10, 20, and 30 accepts the start request from the user. On the other hand, the off operation of the start switch 50 is an operation to switch the state of the vehicle 100 from IG on to IG off. When the user turns off the start switch 50, a shutdown request is input to each of the ECUs 10, 20, and 30. That is, each of the ECUs 10, 20, and 30 accepts the shutdown request from the user. However, the off operation of the start switch 50 is prohibited when the vehicle 100 is running.

[0039] The HMI 70 includes an input device and a display device. The HMI 70 may include a touch panel display. The HMI 70 may include at least one of an IVI (In-Vehicle Infotainment) system, a meter panel, a head-up display, and a steering switch.

[0040] The OTA center 1000 is configured to utilize OTA (Over The Air) technology to remotely update vehicle-mounted ECU software from the center via a communication section. The ECU 10 functions as an OTA master. Specifically, the ECU 10 performs wireless communication with the OTA center 1000. The ECU 10 manages in-vehicle information, receives campaigns, and manages software update sequences. The ECU 10 controls each ECU having an OTA function as an in-vehicle diagnostic device. In the vehicle 100, the ECUs 10, 20, and 30 have the OTA function. In addition to the ECUs 10, 20, and 30, the vehicle 100 may further include an ECU (not shown) that does not have the OTA function.

[0041] The vehicle 100 is an autonomous vehicle configured to be capable of autonomous driving. The vehicle 100 according to this embodiment is configured to be capable of both manned and unmanned driving. The vehicle 100 is configured to be capable of autonomous driving without a driver, but can also be driven manually by a user (manned driving). The vehicle 100 can also perform autonomous driving (e.g., auto cruise control) while being manned. The level of autonomous driving may be fully autonomous (level 5) or conditionally autonomous (e.g., level 4).

[0042] The ECUs 20 and 30 are configured to control a driving device 61. The driving device 61 includes an accelerator device, a brake device, and a steering device. The accelerator device includes, for example, a motor generator (hereinafter, referred to as "MG") that rotates the drive wheels of the vehicle 100, a PCU (Power Control Unit) that drives the MG, and a battery that supplies the PCU with power to drive the MG. The MG functions as a driving motor for the vehicle 100. The brake device includes, for example, a braking device provided on each wheel of the vehicle 100, and an actuator that drives the braking device. The steering device includes, for example, an EPS (Electric Power Steering) and an actuator that drives the EPS.

[0043] The ADS 62 includes a recognition sensor (e.g., at least one of a camera, a millimeter wave radar, and a lidar) that recognizes the external environment of the vehicle 100, and executes processing related to autonomous driving based on information sequentially acquired by the recognition sensor. Specifically, the ADS 62 generates a driving plan (information indicating the future behavior of the vehicle 100) according to the external environment of the vehicle 100 in cooperation with the ECUs 20 and 30. Then, the ADS 62 requests the ECUs 20 and 30 to control various actuators included in the driving device 61 so as to drive the vehicle 100 according to the driving plan.

[0044] In this embodiment, the ADS 62 is built into the vehicle 100. However, the present invention is not limited to this, and the ADS 62 may be an autonomous driving kit that is detachable from the vehicle 100. A sensor unit (including a recognition sensor) of the autonomous driving kit may be attached to the rooftop of the vehicle 100.

[0045] The OTA software update (update of vehicle software using OTA) in this embodiment is performed in the following steps: configuration synchronization, campaign notification and application consent, download, installation, activation, and software update completion notification.

[0046] The vehicle 100 starts configuration synchronization, for example, when the start switch 50 is turned on. The configuration synchronization process by the vehicle 100 includes transmitting vehicle configuration information to the OTA center 1000. The vehicle configuration information includes, for example, hardware information (information indicating the hardware model number, ECU identifier, etc.) and software information (information indicating the software model number, etc.) for each ECU included in the vehicle 100. The vehicle configuration information may further include an RXSWIN for each approval target. The RXSWIN is an identification number capable of identifying software that constitutes the functional type approval.

[0047] When the OTA center 1000 receives the vehicle configuration information from the vehicle 100, it checks any campaigns currently occurring, and if there is a campaign applicable to the vehicle 100, it transmits information about that campaign (campaign information) to the vehicle 100 in response to receiving the vehicle configuration information. The campaign information includes, for example, campaign attribute information (information indicating the purpose of the software update and vehicle functions that may be affected by the update), a list of campaign target vehicles, information about the campaign target ECU (for example, software information before and after the update), and information about notifications to the user before and after the update.

[0048] When the vehicle 100 receives the campaign information, it requests the user to input whether or not to accept the application of the campaign. Specifically, the vehicle 100 displays a message such as "New software has been found. Do you want to apply it to this vehicle?" on the HMI 70 and requests the user to input either "accept" or "reject." If the user inputs "accept" to the HMI 70, the vehicle 100 executes the download. On the other hand, if the user inputs "reject" to the HMI 70, the vehicle 100 does not execute the process after the download.

[0049] In the vehicle 100, the ECU 10, which is an OTA master, executes a process related to downloading, for example, in the procedure described below. The ECU 10 requests a distribution package including new software from the OTA center 1000. Then, the ECU 10 executes downloading (receiving and storing) the distribution package while performing wireless communication with the OTA center 1000. In addition to the new software (for example, a set of update data for each ECU that is the target of the campaign), the distribution package may also include package attribute information (information indicating the update category, the number of update data in the distribution package, the installation order of each ECU, etc.) and update data attribute information (identifier of the target ECU, verification data for verifying the validity of the update data, etc.). The target ECU is an ECU that is the target of a software update other than the OTA master.

[0050] Through the above-described download process, the distribution package is stored in a storage (not shown) provided in the ECU 10. During the download, the HMI 70 notifies the user of the progress of the download. After the download is completed, the ECU 10 verifies the authenticity of the downloaded distribution package. If the result of the verification is "normal", the ECU 10 notifies the OTA center 1000 of the software update status (download completed). This notification means that the download was successful.

[0051] If the download is successful, the vehicle 100 executes the installation. Specifically, the ECU 10 requests each target ECU (e.g., ECUs 20 and 30) to output the state of the target ECU and a DTC (Diagnostic Trouble Code). The ECU 10 judges whether or not the installation can be executed for each target ECU based on the state and DTC of each target ECU. Then, the ECU 10 transfers the new software (update data) to the target ECUs that can execute the installation. The target ECU that receives the update data executes the installation of the update data (writing it into a non-volatile memory). Also, the ECU 10 (OTA master) itself executes the installation of its own update data included in the distribution package, just like the target ECU. During the installation, the HMI 70 notifies the user of the progress of the installation.

[0052] When the transfer of the update data from ECU 10 to the target ECU is completed, the target ECU transmits a transfer completion notification to ECU 10. Then, upon receiving the transfer completion notification, ECU 10 requests the target ECU to perform integrity verification. Upon receiving this request, the target ECU performs verification using integrity verification data (verification data) and transmits the verification result to ECU 10. ECU 10 stores the verification result (installation completed / failed / cancelled) for each target ECU. When the integrity verification for all target ECUs is completed and all verification results are "normal", ECU 10 notifies the OTA center 1000 of the software update status (installation completed). This notification means that the installation was successful.

[0053] If the download and subsequent installation are successful, the vehicle 100 performs activation (enabling the installed software). The activation method according to this embodiment will be described later. If the configuration check after activation is successful, the vehicle 100 causes the HMI 70 to display the results of the software update. The HMI 70 displays, for example, a software update completion screen indicating the success of the update. After that, the ECU 10 notifies the OTA center 1000 of the software update status (software update completion). The fact that this notification is given means that the OTA software update is successful.

[0054] In this embodiment, an in-vehicle terminal (HMI 70) is used as the user terminal, but terminals other than an in-vehicle terminal can also be used as the user terminal. For example, the user terminal may be a laptop, a tablet terminal, a smartphone, a wearable device (smart watch, smart glasses, etc.), or a portable terminal such as an electronic key. Any terminal possessed by the user can be used as the user terminal. Furthermore, the method of notifying the user is not limited to display, and may be audio.

[0055] FIG. 2 is a diagram for explaining the configuration and function of the ECUs 10, 20, and 30. Referring to FIG. 2, the ECUs 10, 20, and 30 include processors 11, 21, and 31 and memories 12, 22, and 32, respectively. Each of the processors 11, 21, and 31 is, for example, a CPU (Central Processing Unit). Each of the memories 12, 22, and 32 is, for example, a non-volatile memory such as a flash memory. The memories 12, 22, and 32 include first storage areas 121, 221, and 321 and second storage areas 122, 222, and 322, respectively. In this embodiment, the ECUs 10, the ECUs 20, and the ECUs 30 correspond to examples of the "first control device," the "second control device," and the "third control device" according to the present disclosure, respectively. Also, each of the memories 12, 22, and 32 functions as the "storage unit" according to the present disclosure.

[0056] The ECU 10 includes a communication module 15 for communicating with a device outside the vehicle. The ECU 10 may wirelessly communicate with a device outside the vehicle (e.g., an OTA center 1000) via a mobile phone network. The communication module 15 may include a telematics control unit (TCU) and / or a data communication module (DCM) for wireless communication. Furthermore, the communication module 15 may include a communication I / F (interface) for wired communication with a device outside the vehicle. The ECU 10 may communicate with a scan tool (a dedicated tool for performing wired software updates) via a data link connector (DLC) (not shown).

[0057] The ECUs 10, 20, and 30 are connected via a communication bus and configured to be able to communicate with each other via wires. The communication method between the ECUs is not particularly limited, and may be, for example, a Controller Area Network (CAN) or Ethernet (registered trademark).

[0058] Immediately after the above-mentioned installation is completed in each of the ECUs 10, 20, 30, each of the ECUs 10, 20, 30 is in a state shown in FIG. 2, for example. The first storage areas 121, 221, 321 each store a control program (old software). In the above-mentioned installation, the processors 11, 21, 31 install an update program (new software) that is an updated version of the control program stored in the first storage areas 121, 221, 321 in the second storage areas 122, 222, 322, respectively. The control programs (old software and new software) stored in each of the first storage area 121 and the second storage area 122 are, for example, programs for the processor 11 to integrally control a plurality of ECUs (for example, ECUs 20, 30). The control programs (old software and new software) stored in each of the first storage area 221 and the second storage area 222 are, for example, programs for the processor 21 to perform the above-mentioned automatic driving control. The control programs (old software and new software) stored in the first storage area 321 and the second storage area 322, respectively, are, for example, programs that allow the processor 31 to perform the automatic driving control described above.

[0059] The processors 11, 21, and 31 respectively set either the first storage area 121, 221, and 321 or the second storage area 122, 222, and 322 as active surfaces P1, P2, and P3 (execution storage areas). In the state shown in FIG. 2, the first storage areas 121, 221, and 321 are respectively set as active surfaces P1, P2, and P3. The processors 11, 21, and 31 respectively execute the control programs stored in the active surfaces P1, P2, and P3 (the first storage areas 121, 221, and 321). In the state shown in FIG. 2, each of the second storage areas 122, 222, and 322 corresponds to a write surface (i.e., a storage area in which an updated version of the control program stored in the active surfaces P1, P2, and P3 is installed).

[0060] Each of the processors 11, 21, and 31 executes activation after installation is complete. In this embodiment, the processors 11, 21, and 31 each execute the activation-related process by dividing it into a process related to preparation for switching the active planes P1, P2, and P3 (hereinafter also referred to as "ACV preparation process") and a process related to switching the active planes P1, P2, and P3 (hereinafter also referred to as "ACV switching process"). Each of the processors 11, 21, and 31 executes the ACV preparation process before shutdown, and executes the ACV switching process at startup after shutdown.

[0061] In the ACV preparation process, the processors 11, 21, and 31 respectively put the ECUs 10, 20, and 30 into a ready-to-switch state. The ready-to-switch state is a state in which the ECUs operate normally even if the ACV switching process described below is performed. Each of the processors 11, 21, and 31, for example, completes a task to be executed by the old software and closes all tasks related to the old software.

[0062] In the ACV switching process, the processors 11, 21, and 31 switch the active planes P1, P2, and P3 from the first storage areas 121, 221, and 321 to the second storage areas 122, 222, and 322, respectively. That is, the processors 11, 21, and 31 set the second storage areas 122, 222, and 322 as the active planes P1, P2, and P3, respectively.

[0063] When the ECUs 10, 20, and 30 in the state shown in FIG. 2 update the control program, the processors 11, 21, and 31 prepare to switch the active surfaces P1, P2, and P3 to the second storage areas 122, 222, and 322 (ACV preparation process). The ACV preparation process is started based on the user turning off the start switch 50. After that, based on all of the ECUs 10, 20, and 30 being in a switching preparation completion state, each of the ECUs 10, 20, and 30 is shut down. Then, the ECUs 10, 20, and 30 that have been shut down in the switching preparation completion state perform a process to switch the active surfaces P1, P2, and P3 from the first storage areas 121, 221, and 321 to the second storage areas 122, 222, and 322 (ACV switching process) at the next startup. Each of the ECUs 10, 20, and 30 is started in response to the user turning on the start switch 50.

[0064] In this embodiment, each of the processors 11, 21, and 31 functions as a "setting unit," an "executing unit," and a "writing unit" according to the present disclosure. More specifically, each of the processors 11, 21, and 31 executes a series of processes shown in FIG. 3 and FIG. 4 described later. The functions of each of these units may be embodied by a program stored in a storage device (for example, memory 12, 22, and 32 or a storage device not shown) and the processors 11, 21, and 31 that execute the program. Alternatively, the functions of each of these units may be embodied by dedicated hardware (electronic circuits). Also, similar functions may be realized by functional division between software and hardware. Note that the number of processors and memories included in each ECU is arbitrary. At least one of the ECUs 10, 20, and 30 may include multiple processors or multiple memories. The ECU may include multiple microcomputers (microcomputers) in the form of a main microcomputer and a sub-microcomputer.

[0065] 3 is a flowchart showing a process (ACV preparation process) for preparing to switch the active side in the activation method according to this embodiment. The process shown in this flowchart is executed when the start switch 50 is turned off when each of the OTA master and the target ECU is in the installation completion state. "S" in the flowchart indicates a step.

[0066] In this embodiment, the ECU 10 is the OTA master, and the ECUs 20 and 30 are the target ECUs. When the start switch 50 is turned off in the installation completion state shown in FIG. 2, the ECU 10 (OTA master) starts a series of processes S11 to S19 described below. Note that the switching flags used in the series of processes described below are stored in advance in storage devices (for example, memories 12, 22, and 32 or storage not shown) provided in each of the ECUs 10, 20, and 30. The switching flag being ON means that the ACV switching process is permitted when the ECU is started. The switching flag being OFF means that the ACV switching process is prohibited when the ECU is started. The initial value of the switching flag is "OFF".

[0067] 1 and 2 as well as Fig. 3, in S11, the ECU 10 transmits a switching instruction to the target ECUs (ECUs 20 and 30). In this embodiment, when the ECU 10 receives a shutdown request from a user, if an update program (an updated version of the control program) is installed in all of the ECUs 10, 20, and 30, the process of S11 is executed and the ECU 10 transmits a switching instruction to each of the ECUs 20 and 30.

[0068] Next, the ECU 10 starts the ACV preparation process (preparation for switching the active surface) described above in S12, and determines whether the ACV preparation process is completed in S13. While it is determined in S13 that the ACV preparation process is "not completed" (NO in S13), the ECU 10 continues to execute the ACV preparation process (S12).

[0069] When the target ECU (ECU 20, 30) receives the above-mentioned switching instruction (S11) from ECU 10, it starts a series of processes from S21 to S27. In S21, the target ECU starts the above-mentioned ACV preparation process (preparation for switching the active surface), and in S22, it determines whether the ACV preparation process is completed. While it is determined in S22 that the ACV preparation process is "not completed" (NO in S22), the target ECU continues to execute the ACV preparation process (S21). In this way, when each of ECUs 20, 30 receives the above-mentioned switching instruction, it starts preparation for switching the active surface.

[0070] When the ACV preparation process by the ECU 10 is completed (YES in S13), the ECU 10 transmits a signal (individual preparation completion notification) indicating that the ECU (ECU 10) is ready to switch in S14. Hereinafter, the individual preparation completion notification transmitted by the ECU 10 in S14 is referred to as a "first preparation completion signal." Although details will be described later, in this embodiment, the ECUs 10, 20, and 30 exchange individual preparation completion notifications between the ECUs by ring-type communication (see FIG. 5). The ECU 10 transmits the first preparation completion signal to the ECU 20.

[0071] When the ACV preparation process by any of the target ECUs (ECU 20 or 30) is completed (YES in S22), the target ECU transmits a signal (individual preparation completion notification) indicating that the target ECU has completed preparation for switching in S23.

[0072] In detail, if the ECU 20 has already received the first preparation completion signal in S23, it immediately transmits an individual preparation completion notification to the ECU 30. On the other hand, if the ECU 20 has not received the first preparation completion signal in S23, it waits for the first preparation completion signal and transmits an individual preparation completion notification to the ECU 30 after receiving the first preparation completion signal. Hereinafter, the individual preparation completion notification transmitted by the ECU 20 in S23 is referred to as a "second preparation completion signal."

[0073] If the ECU 30 has already received the second ready signal in S23, the ECU 30 immediately transmits an individual ready notification to the ECU 10. On the other hand, if the ECU 30 has not received the second ready signal in S23, the ECU 30 waits for the second ready signal and transmits an individual ready notification to the ECU 10 after receiving the second ready signal. Hereinafter, the individual ready notification transmitted by the ECU 30 in S23 is referred to as a "third ready signal."

[0074] After transmitting the first preparation completion signal, the ECU 10 judges in S15 whether all of the ECUs 10, 20, and 30 have completed the switching preparation. The ECU 10 performs the judgment in S15 based on, for example, whether the ECU 10 has received the third preparation completion signal. The fact that the ECU 10 has received the third preparation completion signal means that all of the ECUs 10, 20, and 30 have completed the switching preparation.

[0075] If any of the ECUs 10, 20, 30 is not ready to switch (NO in S15), the ECU 10 determines in S16 whether any of the target ECUs (ECU 20 or 30) has been shut down during preparation for activation due to a momentary power interruption, etc. While the determinations in both S15 and S16 are NO, the processes in S15 and S16 are repeated.

[0076] If any of the target ECUs is shut down before all of the ECUs 10, 20, and 30 are ready to switch, the answer in S16 is YES and the process proceeds to S19. Then, the ECU 10 is shut down in S19. In this case, the switching flag of the ECU 10 at the time of shutdown is OFF.

[0077] The ECU 10 may determine YES in S16 when it does not receive the third preparation completion signal from the ECU 30 even after a predetermined time has elapsed since it transmitted the first preparation completion signal (S14). Alternatively, the ECU 10 may transmit a confirmation signal to each target ECU, and when there is no response from any target ECU, it may determine YES in S16. Note that the method of checking whether an ECU has been shut down is not limited to the above and any method may be adopted.

[0078] When all of the ECUs 10, 20, and 30 have completed the switching preparation (YES in S15), the ECU 10 transmits a signal (an all-ECU preparation notification) indicating that all of the ECUs 10, 20, and 30 have completed the switching preparation in S17. The all-ECU preparation notification transmitted by the ECU 10 in S17 corresponds to a shutdown instruction. The ECU 10 transmits the all-ECU preparation notification (shutdown instruction) to each of the ECUs 20 and 30 in S17.

[0079] After transmitting the all-ECU preparation completion notification, the ECU 10 turns on the switching flag in S18. Then, the ECU 10 shuts down in S19. In this case, the switching flag of the ECU 10 is on at the time of shutdown. When the process of S19 is executed, the series of processes from S11 to S19 ends.

[0080] After transmitting the individual preparation completion notification in S23, the target ECU (ECU 20, 30) judges in S24 whether all of the ECUs 10, 20, 30 have completed the switching preparation. For example, if the target ECU receives the all-ECU preparation completion notification (S17), the target ECU judges YES in S24, and if the target ECU does not receive the all-ECU preparation completion notification (S17), the target ECU judges NO in S24. If any of the ECUs 10, 20, 30 has not completed the switching preparation (NO in S24), the target ECU judges in S25 whether the other ECUs have shut down during preparation for activation due to a momentary power interruption or the like. When the ECU 20 executes the process of S25, the ECUs 10, 30 correspond to the "other ECUs". When the ECU 30 executes the process of S25, the ECUs 10, 20 correspond to the "other ECUs". The target ECU may determine YES in S25 if it does not receive an all-ECU preparation completion notification (S17) from the ECU 10 even after a predetermined time has elapsed since it transmitted the individual preparation completion notification in S23. However, any method may be used as a method for checking whether the ECU has been shut down (a method for determining in S25).

[0081] While both S24 and S25 are judged as NO, the processes of S24 and S25 are repeated. Then, if any ECU shuts down before all of the ECUs 10, 20, and 30 are ready to switch (YES in S25), the process proceeds to S27. Then, the target ECU shuts down in S27. In this case, the switching flag of the target ECU (ECU 20, 30) at the time of shutdown is OFF.

[0082] When all of the ECUs 10, 20, 30 have completed preparation for switching (YES in S24), the target ECUs (ECUs 20, 30) turn on their switching flags in S26. The target ECUs then shut down in S27. In this case, the switching flags of the target ECUs (ECUs 20, 30) are on at the time of shutdown. When the process of S27 is executed, the series of processes from S21 to S27 ends.

[0083] Fig. 4 is a flowchart showing a process (ACV switching process) for switching the active side in the activation method according to this embodiment. The process shown in this flowchart is executed by each of the ECUs 10, 20, 30 that is started when the start switch 50 is turned on. The series of processes shown in Fig. 4 by each of the ECUs 10, 20, 30 are executed in parallel. An ECU (ECU 10, ECU 20, or ECU 30) that is started in response to the turn-on operation of the start switch 50 and executes the series of processes shown in Fig. 4 is hereinafter referred to as the "starting ECU."

[0084] 1 and 2, and FIG. 4, the start-up ECU determines in S31 whether or not the switching flag of the ECU is ON. If the switching flag is ON (YES in S31), the start-up ECU executes the above-mentioned ACV switching process in S32. For example, the ECU 10 switches the active surface P1 from the first storage area 121 to the second storage area 122. As a result, the second storage area 122 is set as the active surface P1. The ECU 20 also switches the active surface P2 from the first storage area 221 to the second storage area 222. As a result, the second storage area 222 is set as the active surface P2. The ECU 30 also switches the active surface P3 from the first storage area 321 to the second storage area 322. As a result, the second storage area 322 is set as the active surface P3.

[0085] After executing the ACV switching process, the start-up ECU turns off the switching flag in S33. Then, in S34, the start-up ECU starts the update program (new software) stored in the new active side switched in S32. When the process of S34 is executed, the series of processes shown in FIG. 4 ends.

[0086] On the other hand, when the switching flag is OFF (NO in S31), the start ECU starts the control program (old software) stored in the active side in S35 without executing the ACV switching process. For example, when any of the ECUs 10, 20, and 30 is shut down during preparation for activation due to a momentary power interruption or the like, the switching flag is not turned ON by the process (S18, S26) shown in FIG. 3, so NO is determined in S31. In this case, each of the ECUs 10, 20, and 30 is in the installation completion state, so the process shown in FIG. 3 is executed again when the start switch 50 is next turned off. Also, NO is determined in S31 when the update program is not installed in the start ECU. In this case, the process shown in FIG. 3 is not executed for the start ECU. When the process of S35 is executed, the series of processes shown in FIG. 4 ends.

[0087] As described above, in the control system (control system for the vehicle 100) according to this embodiment, all of the ECUs 10, 20, and 30 are shut down based on the fact that all of the ECUs 10, 20, and 30 are in a switching preparation completed state (S15, S19, S24, and S27 in FIG. 3). When all of the ECUs 10, 20, and 30 are shut down in a switching preparation completed state, each of the ECUs 10, 20, and 30 executes the series of processes shown in FIG. 4 at the next startup and sets the storage area (second storage area 122, 222, and 322) in which the updated version of the control program is installed as the active surface (S32). On the other hand, in the series of processes shown in FIG. 3, when at least one of the ECUs 10, 20, and 30 is shut down before it is in a switching preparation completed state, all of the ECUs 10, 20, and 30 are shut down with the switching flags of the ECUs 10, 20, and 30 remaining OFF (S16, S19, S25, and S27). In this case, the next time each ECU is started, a NO determination is made in S31 of FIG. 4, and therefore none of the ECUs 10, 20, and 30 switch the active plane.

[0088] Fig. 5 is a diagram for explaining an example of an operation after the installation of each of the ECUs 10, 20, and 30 is completed. With reference to Fig. 5, when the start switch 50 is turned off in a state in which an update program (an updated version of the control program) is installed in a storage area other than the active surface of each of the ECUs 10, 20, and 30, the ECU 10 (OTA master) transmits a switching instruction to each of the ECU 20 (first target ECU) and the ECU 30 (second target ECU).

[0089] When the ECU 10 completes the ACV preparation process, the ECU 10 transmits a first preparation complete signal to the ECU 20. Thereafter, when the ECU 20 completes the ACV preparation process, the ECU 20 transmits a second preparation complete signal to the ECU 30. Further thereafter, when the ECU 30 completes the ACV preparation process, the ECU 30 transmits a third preparation complete signal to the ECU 10. In this manner, the ECUs 10, 20, and 30 exchange preparation complete signals between the ECUs by one-way ring-type communication.

[0090] When the ECU 10 receives the third preparation completion signal, the ECU 10 transmits an all-ECU preparation completion notification (shutdown instruction) to each of the ECUs 20, 30. As a result, the switching flags of each of the ECUs 10, 20, 30 are turned ON. After that, all of the ECUs 10, 20, 30 are shut down.

[0091] When the start switch 50 is turned on after all of the ECUs 10, 20, 30 have been shut down in the switching preparation completed state as described above, an update program (a new version of software) is started in each of the ECUs 10, 20, 30.

[0092] As described above, the control program update method according to this embodiment includes the processes shown in Fig. 2 to Fig. 4. Specifically, prior to the series of processes shown in Fig. 3, each of the ECUs 10, 20, and 30 installs an updated version of the control program stored in the execution storage area (first storage area 121, 221, and 321) of each of the ECUs 10, 20, and 30 into a storage area (second storage area 122, 222, and 322) other than the execution storage area of ​​each of the ECUs 10, 20, and 30 (see Fig. 2). Thereafter, in the series of processes shown in Fig. 3, each of the ECUs 10, 20, and 30 in which the updated version of the control program is installed prepares to switch the execution storage area. Also, in the series of processes shown in Fig. 3, all of the ECUs 10, 20, and 30 are shut down based on the completion of preparations for switching the execution storage area of ​​all of the ECUs 10, 20, and 30. Then, all of the ECUs 10, 20, and 30 that were shut down in the switching preparation state by the series of processes shown in Figure 3 will switch their execution memory areas to the memory areas (second memory areas 122, 222, 322) in which the updated version of the control program is installed by the series of processes shown in Figure 4 at the next startup.

[0093] In the above control program update method, when all of the multiple control devices (ECUs 10, 20, 30) are shut down in a state where they are ready to switch, each of the control devices switches the active side at the next startup. It is unlikely that any of the control devices will shut down due to a momentary power interruption or the like during the short period immediately after startup (the period during which the active side is switched). Therefore, the above control program update method makes it possible to suppress software inconsistencies between the multiple control devices when updating software in those control devices.

[0094] In the above embodiment, the ECUs 10, 20, and 30 exchange the preparation complete signal between the ECUs by ring-type communication. The ring-type communication makes it easier to prevent communication congestion between the ECUs. However, the present invention is not limited to this, and the ECUs 10, 20, and 30 may exchange the preparation complete signal between the ECUs by star-type communication.

[0095] Fig. 6 is a diagram showing a first modified example of the embodiment shown in Fig. 5. With reference to Fig. 6, in this modified example, when the ECU 20 completes the ACV preparation process after the ECU 10 transmits a switching instruction, the ECU 20 transmits a second preparation completion signal to the ECU 10. Furthermore, when the ECU 30 completes the ACV preparation process, the ECU 30 transmits a third preparation completion signal to the ECU 10. In this manner, the ECUs 10, 20, and 30 exchange preparation completion signals between the ECUs by star-shaped communication with the ECU 10 at the center (base).

[0096] When the ECU 10 receives both the second and third preparation completion signals, the ECU 10 transmits an all-ECU preparation completion notification (shutdown instruction) to each of the ECUs 20 and 30. As a result, the switching flags of each of the ECUs 10, 20, and 30 are turned ON. After that, all of the ECUs 10, 20, and 30 are shut down.

[0097] According to the method of the first modification, all of the ECUs 10, 20, 30 can be shut down on the basis that all of the ECUs 10, 20, 30 have reached the switching preparation completion state.

[0098] In the above embodiment, all of the multiple control devices (ECUs 10, 20, 30) having the OTA function are targets of software updates by OTA (OTA targets). However, this is not limited to the above, and some of the multiple control devices having the OTA function may be targets of OTA updates.

[0099] FIG. 7 is a diagram showing a second modified example of the embodiment shown in FIG. 5. Referring to FIG. 7, in this modified example, in S11 of FIG. 3, the ECU 10 (OTA master) identifies an OTA target. The ECU 10 may identify an OTA target based on a distribution package (for example, an identifier of the target ECU or a difference in update data) received from the OTA center 1000. When a series of processes from S11 to S19 is started in a state in which an update version of the control program is not installed in either the ECU 20 or the ECU 30, the ECU 10 identifies which of the ECU 20 and the ECU 30 has an update version of the control program installed. Then, the ECU 10 transmits a switching instruction to the target ECU that is an OTA target (i.e., an ECU in which an update version of the control program is installed), and does not transmit a switching instruction to an ECU that is not an OTA target (i.e., an ECU in which an update version of the control program is not installed). In the example shown in FIG. 7, each of the ECUs 10 and 20 is an OTA target, and the ECU 30 (another ECU) is not an OTA target.

[0100] When the ECU 10 completes the ACV preparation process after transmitting the switching instruction, the ECU 10 transmits a first preparation completion signal to the ECU 20 (target ECU). When the ECU 20 then completes the ACV preparation process, the ECU 20 transmits a second preparation completion signal to the ECU 10. When the ECU 10 receives the second preparation completion signal, the ECU 10 transmits an all-ECU preparation completion notification (shutdown instruction) to the ECU 20. This causes the switching flags of the ECUs 10 and 20 to turn ON. Then, the ECUs 10 and 20 are shut down. The ECU 30 that is not an OTA target may be shut down together with the ECUs 10 and 20, or may be shut down in response to an OFF operation of the start switch 50.

[0101] According to the configuration of the second modification, a switching instruction is not sent to a control device in which new software has not been installed, thereby reducing unnecessary communication.

[0102] The configuration of a LAN (Local Area Network) connecting ECUs can be changed as appropriate according to the communication form. Any of a bus type, a ring type, and a star type network topology may be adopted as the LAN configuration. In addition, the control device (ECU) that transmits the switching instruction and the shutdown instruction is not limited to the OTA master, and may be a representative device selected from among multiple target ECUs. The number of ECUs with an OTA function in a vehicle is not limited to three, and may be four or more and less than ten, or may be ten or more.

[0103] The control program to be updated is not limited to a driving assistance control program such as the above-mentioned automatic driving control program, and may be any program. It is not essential that the vehicle is configured to be capable of automatic driving.

[0104] The vehicle may be an xEV other than a BEV. The vehicle may be a PHEV or HEV equipped with an internal combustion engine (for example, a gasoline engine, a biofuel engine, or a hydrogen engine). The vehicle is not limited to a four-wheeled passenger car, but may be a bus or a truck, or may be a three-wheeled xEV. The on-board battery may be configured to be contact-chargeable, or may be configured to be contactlessly charged (wirelessly charged) while parked or running, or may be configured to be battery-replaceable. The vehicle may be equipped with a solar panel. The vehicle may be equipped with a flying function. The vehicle may be a Mobility as a Service (MaaS) vehicle. The MaaS vehicle is a vehicle managed by a MaaS operator. The vehicle may be a multi-purpose vehicle customized according to the user's purpose of use. The vehicle may be a mobile store vehicle, a robotaxi, an automated guided vehicle (AGV), or an agricultural machine. The vehicle may be an unmanned or one-seater small BEV (for example, a BEV for the last mile).

[0105] The above-described various modifications may be implemented in any combination. The embodiments disclosed herein should be considered to be illustrative and not restrictive in all respects. The scope of the present invention is defined by the claims, not by the description of the embodiments described above, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]

[0106] 10,20,30 ECU, 11,21,31 processor, 12,22,32 memory, 50 start switch, 100 vehicle, 121,221,321 first memory area, 122,222,322 second memory area, 1000 OTA center, P1,P2,P3 active surface.

Claims

1. A control system including a plurality of control devices, each of the plurality of control devices includes a storage unit including a plurality of storage areas, and is configured to execute a control program stored in an execution storage area that is one of the plurality of storage areas; When an update of the control program is installed in the storage area other than the execution storage area of ​​each of the plurality of control devices and each of the plurality of control devices updates the control program, each of the plurality of control devices prepares to switch the execution storage area, and all of the plurality of control devices are shut down based on the completion of the switching preparation state of all of the plurality of control devices; When all of the plurality of control devices are shut down in the switching preparation completed state, each of the plurality of control devices sets the storage area in which the updated version of the control program is installed as the execution storage area at the next startup, if at least one of the plurality of control devices is shut down before the switching preparation is completed, none of the plurality of control devices will switch the execution storage area at the next startup, each of the plurality of control devices is configured to transmit a preparation completion signal indicating that the control device has reached the preparation completion state for switching when preparation for switching the execution storage area is completed; A control system, wherein the plurality of control devices are configured to exchange the ready signal among themselves through ring-type communication.

2. A control system including a plurality of control devices, each of the plurality of control devices includes a storage unit including a plurality of storage areas, and is configured to execute a control program stored in an execution storage area that is one of the plurality of storage areas; When an update of the control program is installed in the storage area other than the execution storage area of ​​each of the plurality of control devices and each of the plurality of control devices updates the control program, each of the plurality of control devices prepares to switch the execution storage area, and all of the plurality of control devices are shut down based on the completion of the switching preparation state of all of the plurality of control devices; When all of the plurality of control devices are shut down in the switching preparation completed state, each of the plurality of control devices sets the storage area in which the updated version of the control program is installed as the execution storage area at the next startup, if at least one of the plurality of control devices is shut down before the switching preparation is completed, none of the plurality of control devices will switch the execution storage area at the next startup, each of the plurality of control devices is configured to transmit a preparation completion signal indicating that the control device has reached the preparation completion state for switching when preparation for switching the execution storage area is completed; A control system, wherein the plurality of control devices are configured to exchange the ready signal among themselves through star-type communication.

3. A control system including a plurality of control devices, each of the plurality of control devices includes a storage unit including a plurality of storage areas, and is configured to execute a control program stored in an execution storage area that is one of the plurality of storage areas; When an update of the control program is installed in the storage area other than the execution storage area of ​​each of the plurality of control devices and each of the plurality of control devices updates the control program, each of the plurality of control devices prepares to switch the execution storage area, and all of the plurality of control devices are shut down based on the completion of the switching preparation state of all of the plurality of control devices; When all of the plurality of control devices are shut down in the switching preparation completed state, each of the plurality of control devices sets the storage area in which the updated version of the control program is installed as the execution storage area at the next startup, the plurality of control devices include a first control device, a second control device, and a third control device; The first control device accepts a shutdown request from a user, when the first control device receives the shutdown request, if an updated version of the control program has been installed in all of the first to third control devices, the first control device transmits a switching instruction to each of the second control device and the third control device, and then starts preparations for switching the execution storage area; A control system in which, upon receiving the switching instruction, each of the second control device and the third control device starts preparations for switching the execution memory area.

4. 4. The control system of claim 3, wherein when the first control device updates the control program when an updated version of the control program is not installed in either the second control device or the third control device, the first control device determines whether the updated version of the control program is installed in the second control device or the third control device, and sends the switching instruction to the control device in which the updated version of the control program is installed and does not send the switching instruction to the control device in which the updated version of the control program is not installed.

5. Each of the plurality of control devices is configured to control a vehicle; the vehicle includes an activation switch for allowing a user to activate a vehicle system; When a user turns off the startup switch, the shutdown request is input to the first control device, The control system according to claim 3 , wherein each of the plurality of control devices is activated in response to a user turning on the activation switch.

Citation Information

Patent Citations

  • Controller for automobile

    JP2010198307A

  • Electronic control device

    JP2013254263A

  • Vehicle electronic control unit, program update check method and update check program

    JP2019144670A

  • Electronic control device

    JP2019168834A

  • Control device, control method, and computer program

    WO2019187535A1