Electronic control device, software update method, software update program, and electronic control system

The electronic control unit efficiently manages software updates in vehicle systems by determining communication availability and instructing only communicable update units, thus preventing errors and resource wastage in the update process.

JP7683458B2Active Publication Date: 2025-05-27DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021178075
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-11-27
Filing Date
2021-10-29
Publication Date
2025-05-27
Estimated Expiration
2041-10-29

AI Technical Summary

Technical Problem

In vehicle electronic control systems, software updates for virtual machines controlling vehicle operations can fail if communication is lost between the update management function and the update function, leading to incorrect error determinations, prolonged update times, and resource wastage.

Method used

An electronic control unit with a file acquisition unit and an update management unit that determines communication availability between update units, receives files for software updates, and instructs only the communicable update units to perform the updates, thereby avoiding unnecessary resource consumption and error retrials.

Benefits of technology

This solution ensures that software updates are efficiently executed even when communication is lost with some update units, preventing system-wide error determinations and reducing the time and resources required for updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007683458000001
    Figure 0007683458000001
  • Figure 0007683458000002
    Figure 0007683458000002
  • Figure 0007683458000003
    Figure 0007683458000003
Patent Text Reader

Abstract

To provide an electronic control device configured to prevent entire update processing from being determined as an error when there is an update unit which cannot communicate with an update management unit for managing update of software, a software update method, and an electronic control system.SOLUTION: An electronic control device having a first virtual machine includes a file acquisition unit which acquires a file for updating software, and an update management unit for managing update of the software. The update management unit includes: a determination unit which determines whether communications between the update management unit and a first update unit for updating software of a first virtual machine and / or between the update management unit and a second update unit for updating software of a second virtual machine connected to the first virtual machine are enabled; a receiving unit which receives the file from the file acquisition unit; and an update instruction unit which issues an instruction to an update unit of the first and second update units which is determined to be communicably connected by the determination unit, to update software using the file received by the receiving unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an electronic control device, and mainly relates to an electronic control device for a vehicle, a method implemented by the electronic control device, a program executable by the electronic control device, and an electronic control system including the electronic control device.

Background Art

[0002] In automobiles, various electronic control devices connected by an in-vehicle network are installed. With the development of recent autonomous driving technologies, the functions required of automobiles are becoming more complex, and the number of electronic control devices installed in automobiles is increasing. Therefore, it has been proposed to apply virtualization technology that can suppress the total number of electronic control devices by integrating multiple functions into one electronic control device.

[0003] For example, Patent Document 1 discloses constructing a plurality of virtual ECUs using a virtualization operating system such as a hypervisor in an in-vehicle computer. According to the technology described in Patent Document 1, by aggregating the physical resources required for the operation of terminal devices connected to the in-vehicle computer via the ECU in the in-vehicle computer, efficient use of the physical resources becomes possible.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Here, the inventor of the present invention has found the following problems. Since virtual machines that virtualize electronic control units include those that control vehicle operations such as driving and steering, it is desirable to always update to the latest software to ensure vehicle safety. Therefore, each virtual machine is provided with a function to execute software updates for the virtual machine. However, when communication cannot be established between the update management function that manages software updates in multiple virtual machines and the update function, and updates for some virtual machines cannot be executed, the update management function may determine that an error has occurred in the entire update process and retry the entire update process for the in-vehicle system or electronic control unit. As a result, it takes time to complete the update process and unnecessary resources are consumed.

[0006] Therefore, an object of the present invention is to prevent a determination that an error has occurred in the entire update process even when there is an update function that cannot communicate with the update management function, and to prevent an increase in the time required for the update process and the consumption of resources.

Means for Solving the Problem

[0007] An electronic control unit according to an aspect of the present disclosure is an electronic control unit having a first virtual machine (130), and includes a file acquisition unit (131) that acquires a file for updating software from outside the electronic control unit, and an update management unit (132) that manages the update of the software. The update management unit includes a determination unit (135) that determines whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine; a reception unit (137) that receives the file from the file acquisition unit; and an update instruction unit (139) that instructs software update using the file received by the reception unit to the update unit determined by the determination unit to be communicable among the first update unit and the second update unit.

[0008] A software update method according to another aspect of the present disclosure is a software update method executed by an electronic control device (10) having a first virtual machine (130). The electronic control device includes a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, and an update management unit (132) that manages the update of the software. A determination is made as to whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine (S104). The file is received from the file acquisition unit (S106), and an instruction to update the software using the file received from the file acquisition unit is given to the update unit determined to be capable of communication among the first update unit and the second update units (S108).

[0009] A software update program according to another aspect of the present disclosure is a software update program executable by an electronic control device (10) having a first virtual machine (130). The electronic control device includes a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, and an update management unit (132) that manages the update of the software. A determination is made as to whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine (S104). The file is received from the file acquisition unit (S106), and an instruction to update the software using the file received from the file acquisition unit is given to the update unit determined to be capable of communication among the first update unit and the second update units (S108).

[0010] An electronic control system according to another aspect of the present disclosure includes a first electronic control device (10) having a first virtual machine (130) and a second electronic control device (20) having a second virtual machine (230). The first virtual machine includes a file acquisition unit (131) that acquires a file for software update from outside the first electronic control device, and an update management unit (132) that manages the software update. The update management unit includes a determination unit (135) that determines whether communication is possible between the update management unit and a second update unit (231) that updates the software of the second virtual machine, a reception unit (137) that receives the file from the file acquisition unit, and an update instruction unit (139) that instructs the second update unit capable of communication to update the software using the file received by the reception unit. The second update unit of the second virtual machine updates the software of the second virtual machine using the file based on the instruction of the update instruction unit.

[0011] Note that the numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention.

Effects of the Invention

[0012] According to the electronic control device, software update method, software update program, and electronic control system of the present disclosure, even when there is an update unit that cannot communicate with the update management unit in the electronic control device or the electronic control system, the update unit capable of communication can perform the software update process of the virtual machine.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Modes for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0015] Note that the present invention means the invention described in the claims or the section of means for solving the problems, and is not limited to the following embodiments. Also, at least the phrases in parentheses mean the phrases described in the claims or the section of means for solving the problems, and are not limited to the following embodiments either.

[0016] The configurations and methods described in the dependent claims of the claims are arbitrary configurations and methods in the invention described in the independent claim of the claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, and the configurations and methods described only in the embodiments without being described in the claims are arbitrary configurations and methods in the present invention. The configurations and methods described in the embodiments when the description of the claims is broader than the description of the embodiments are also arbitrary configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In any case, by describing in the independent claim of the claims, the essential configurations and methods of the present invention are obtained.

[0017] The effects described in the embodiments are the effects when having the configurations of the embodiments as examples of the present invention, and are not necessarily the effects of the present invention.

[0018] When there are a plurality of embodiments, the configurations disclosed in each embodiment are not limited to each embodiment alone, and can be combined across embodiments. For example, the configuration disclosed in one embodiment may be combined with another embodiment. Also, the configurations disclosed in each of the plurality of embodiments may be collected and combined.

[0019] The problems described as the problems to be solved by the invention are not well-known problems, but are findings uniquely made by the inventor, and are facts affirming the inventiveness of the invention together with the configuration and method of the present invention.

[0020] 1. Embodiment 1 Using FIG. 1, an electronic control device of Embodiment 1 and an electronic control system including the electronic control device will be described. Note that the electronic control device and the electronic control system of each embodiment assume an in-vehicle device and an in-vehicle system "mounted" on a vehicle which is a "mobile body", but are not limited thereto.

[0021] Here, the "mobile body" refers to an object that can move, and the moving speed is arbitrary. Also, the case where the mobile body is stopped is of course included. For example, it includes automobiles, motorcycles, bicycles, pedestrians, ships, airplanes, and things mounted on these, and is not limited thereto. Also, "mounted" includes not only the case of being directly fixed to the mobile body, but also the case of not being fixed to the mobile body but moving together with the mobile body. For example, the case of being held by a person riding on the mobile body, and the case of being mounted on a load placed on the mobile body can be mentioned.

[0022] The electronic control system 1 is a system composed of a plurality of "electronic control units" (hereinafter referred to as ECU: Electronic Control Unit). FIG. 1 shows an electronic control system 1 including two ECUs (ECU10 and ECU20), but it is composed of an arbitrary number of ECUs. ECU10 and ECU20 are connected via in-vehicle networks such as CAN (Controller Area Network) and LIN (Local Interconnect Network), Ethernet (registered trademark), and wireless communication networks.

[0023] Here, the "electronic control device" may be configured as a so-called information processing device mainly composed of semiconductor devices and having a CPU (Central Processing Unit) and a volatile memory unit such as a RAM (Random Access Memory). In this case, the information processing device may further have a non-volatile memory unit such as a flash memory and a network interface unit connected to a communication network or the like. Furthermore, such an information processing device may be a packaged semiconductor device (element) or may have a configuration in which each semiconductor device is wired and connected on a wiring board.

[0024] ECU10 is, for example, an ECU based on a platform capable of dynamic function expansion, called Adaptive Platform (hereinafter referred to as AP) in AUTOSAR (AUTomotive Open System ARchitecture). AP is mainly a platform suitable for ECUs for autonomous driving. Also, ECU20 is, for example, an ECU based on a platform that optimizes static functions, called Classic Platform (hereinafter referred to as CP) in AUTOSAR. CP is mainly a platform suitable for ECUs for vehicle control.

[0025] The ECU 10 and ECU 20 that make up the electronic control system 1 both have one or more virtual machines managed by a hypervisor. The configurations of the ECU 10, ECU 20, and the virtual machines installed in each ECU will be described below. In the figures, the virtual machine is abbreviated as VM (Virtual Machine).

[0026] (1) Regarding ECU 10 The ECU 10 includes a hypervisor (HV) 110, a plurality of virtual machines (VM) (130, 150, 160) managed by the hypervisor, and a physical storage 120 that is hardware.

[0027] The hypervisor 110 is software that virtualizes the ECU 10. In the example of FIG. 1, the first virtual machine 130 to the third virtual machine 160 are constructed on the hypervisor 110. The virtual machines constructed on the hypervisor 110 are virtually "connected" to each other.

[0028] Here, "connection" between virtual machines means a state in which data can be exchanged between virtual machines. In addition to the case where virtual machines realized on the same hardware are virtually connected, it also includes the case where virtual machines realized on different hardware are connected via a network or the like. Also, the state where data can be exchanged does not necessarily mean that data can actually be exchanged. For example, even if one virtual machine is temporarily stopped due to some trouble or is in a sleep state, it is a state where data can be exchanged.

[0029] The physical storage 120 is a hardware memory, which is a volatile memory such as SRAM or DRAM, a ROM, a flash memory, or a non-volatile memory such as a hard disk. The virtual storage of the first virtual machine 130 to the third virtual machine 160 described later is realized by virtualizing the storage area of the physical storage 120. In FIG. 1, one physical storage 120 is shown, but the physical storage 120 may be realized by a plurality of storages.

[0030] The actual storage 120 stores the updated files that have been split by the parsing processing unit 138 described later. The area for storing the updated files may be a storage area shared by a plurality of virtual machines, or may be an area of a virtual storage realized by virtualizing the actual storage 120.

[0031] (i) Regarding the first virtual machine 130

[0032] The first virtual machine 130 managed by the hypervisor 110 includes a file acquisition unit 131, an update management unit 132, an update unit 133, and a virtual storage 134.

[0033] The file acquisition unit 131 acquires files from a server device provided outside the ECU 10 using OTA (Over The Air) or wired communication. The files acquired by the file acquisition unit 131 include update files for updating the software of the virtual machine, and may be, for example, a group of update files including a plurality of update files for updating a plurality of virtual machines. The files may further include information for identifying the virtual machines to be updated with the software. The file acquisition unit 131 is also referred to as an OTA client. The update files for updating the software of the virtual machine are not only those for updating the software that realizes the virtual machine, but may also be those for updating applications and software installed on the virtual machine.

[0034] When the file acquisition unit 131 acquires a file from the server device, it instructs the update management unit 132, which will be described later, to transmit the communication status between the update management unit 132 and the update unit that executes the update of each virtual machine. Hereinafter, the transmission instruction of the communication status from the file acquisition unit 131 to the update management unit 132 is referred to as a communication status request. This communication status request may indirectly instruct the transmission of the communication status by instructing the update of the software of each virtual machine. Then, based on the determination result of the communication status notified from the determination result notification unit 136 of the update management unit 132 in response to the communication status request, the file acquisition unit 131 selects the file to be transferred to the update management unit 132 from the files acquired from the server device, and transfers the selected file to the update management unit 132. The determination result transmitted from the update management unit 132 includes information for specifying the update unit that can communicate with the update management unit 132. The file acquisition unit 131 transfers only the files necessary for the update unit that can communicate with the update management unit 132 to update the software of the virtual machine to the update management unit 132. That is, in the present embodiment, the file acquisition unit 131 selects and transfers the files used by the update unit that can communicate with the update management unit 132 to update the software of the virtual machine.

[0035] The example of FIG. 1 shows a state where the update management unit 132 can communicate with the update unit 133 of the first virtual machine 130, the update unit 151 of the second virtual machine, and the update unit 231 of the fourth virtual machine 230, and cannot communicate with the update unit 161 of the third virtual machine 160. Therefore, the file acquisition unit 131 transfers only the files necessary for updating the software of the first virtual machine 130, the second virtual machine 150, and the fourth virtual machine 230 to the update management unit 132.

[0036] The update management unit 132 manages software updates for the first virtual machine 130 and each virtual machine connected to the first virtual machine 130. FIG. 2 shows the functions realized by the update management unit 132. The update management unit 132 realizes a communication availability determination unit 135, a determination result notification unit 136, a reception unit 137, a parsing processing unit 138, an update instruction unit 139, and a distribution unit 140. The update management unit 132 executes, for example, part or all of the functions referred to as the UCM (Update and Configuration Management) master in AUTOSAR.

[0037] The communication availability determination unit 135 (corresponding to the "determination unit") determines whether communication is possible between the update management unit 132 and an update unit that performs software update processing for each virtual machine. For example, the communication availability determination unit 135 transmits a search signal to each update unit and, when a response signal is received from the update unit at the transmission destination, determines that communication is possible with that update unit. The communication availability determination unit 135 may determine whether communication is possible by using a function called service discovery, which searches for available services and establishes communication.

[0038] The communication availability determination unit 135 transmits a search signal to each update unit, for example, at the timing when a communication status request is received from the file acquisition unit 131. In this case, the communication availability determination unit 135 can determine the latest communication availability status between the update management unit 132 and the update units of each virtual machine. However, in addition to or instead of the timing when a communication status request is received, the communication availability determination unit 135 may periodically transmit a search signal to each update unit to determine whether communication with the update unit is possible. The communication availability determination unit 135 may further transmit a search signal at the timing when the ECU 10 is booted. The determination result in the communication availability determination unit 135 is recorded in the actual storage 120.

[0039] In the example of FIG. 1, some abnormality has occurred in the communication network between the update management unit 132 and the update unit 161, and the search signal transmitted by the communication availability determination unit 135 does not reach the update unit 161. As a result, since the communication availability determination unit 135 cannot receive the response signal from the update unit 161, it determines that communication with the update unit 161 is impossible. On the other hand, since the search signal transmitted by the communication availability determination unit 135 reaches the update units 133, 151, and 231, these update units can transmit a response signal to the communication availability determination unit 135. The communication availability determination unit 135 that has received the response signal determines that communication between the update management unit 132 and the update units 133, 151, and 231 is possible.

[0040] The determination result notification unit 136 (corresponding to the "notification unit") notifies the file acquisition unit 131 of the determination result by the communication availability determination unit 135. For example, as the determination result by the communication availability determination unit 135, the determination result notification unit 136 notifies the file acquisition unit 131 of one or more of the identification information of the virtual machines having update units for which communication is possible, the identification information of the virtual machines having update units for which communication is impossible, and the information indicating the number of virtual machines for which communication is possible or impossible.

[0041] The reception unit 137 receives the file transferred from the file acquisition unit 131. As described above, the file received by the reception unit 137 is a file for updating the software of the first virtual machine 130, the second virtual machine 150, and the fourth virtual machine 230, and does not include a file for updating the software of the third virtual machine 160.

[0042] The parsing processing unit 138 performs parsing processing to divide the update file group included in the file received by the reception unit 137 into update files for each virtual machine. The parsed update files are stored in the actual storage 120.

[0043] The update instruction unit 139 instructs the update unit, which the communication availability determination unit 135 has determined to be capable of communication, to update the software of the virtual machine. For example, the update instruction unit 139 instructs to update the software of the virtual machine using the update file distributed by the distribution unit 140 described later. Alternatively, the update instruction by the update instruction unit 139 may be to instruct to update the software of the virtual machine using the update file stored in the actual storage 120 by accessing the actual storage 120. When the update unit can access the actual storage 120, even if the update file is not distributed, the software of the virtual machine can be updated by referring to the update file stored in the actual storage 120. On the other hand, the update instruction unit 139 does not instruct the update unit that the communication availability determination unit 135 has determined to be incapable of communication, which is the update unit 161 in this embodiment, to update the software of the virtual machine.

[0044] For example, when the update unit 133 can access the storage area of the actual storage 120 where the update file is stored, the update unit 133 can update the software of the first virtual machine 130 by referring to the update file stored in the actual storage 120. Therefore, the update instruction unit 139 instructs the update unit 133, which can update the software of the virtual machine without distributing the update file, to access the actual storage 120 and update the software of the virtual machine using the stored update file.

[0045] The distribution unit 140 distributes the update file split by the parsing processing unit 138 to the update unit determined by the communication availability determination unit 135 to be capable of communication. In the example of FIG. 1, the update file is distributed to the update unit 151 and the update unit 231. Here, the distribution of the update file includes not only transmitting the update file via the communication network but also moving the storage area of the update file to an area accessible by a specific virtual machine.

[0046] In the following embodiments, the distribution unit 140 is configured to distribute update files to the update unit 151 and the update unit 231. However, if these update units can access the actual storage 120 in the same manner as the update unit 133, it is not always necessary to distribute the update files.

[0047] The update unit 133 (corresponding to the "first update unit") updates the software of the first virtual machine 130 based on an instruction from the update instruction unit 139. As described above, the update unit 133 accesses the actual storage 120 and uses the update file stored in the actual storage 120 to update the software of the first virtual machine 130. When the update process is completed, the update unit 133 notifies the update management unit 132 that the update has been completed. The update unit 133 and the update units 151, 161, 231 of other virtual machines described later execute part or all of a function called UCM subordinate in AUTOSAR, for example.

[0048] The virtual storage 134 is a storage area virtually provided for the first virtual machine 130 by virtualizing the storage area of the actual storage 120. Therefore, a file stored in the virtual storage 134 is also regarded as a file stored in the actual storage 120. The same applies to the virtual storage 152 and the virtual storage 162 described below.

[0049] (ii) Regarding the second virtual machine 150 and the third virtual machine 160 The second virtual machine 150 and the third virtual machine 160 are virtual machines managed by the hypervisor 110, similar to the first virtual machine 130. The second virtual machine 150 has an update unit 151 and a virtual storage 152, and the third virtual machine 160 has an update unit 161 and a virtual storage 162.

[0050] When the update units 151 and 161 (corresponding to the "second update unit") receive a search signal from the update management unit 132, they transmit a response signal thereto. The update units 151 and 161 further perform software updates for the virtual machines based on an update instruction from the update instruction unit 139. When the software update process is completed, the update units 151 and 161 notify the update management unit 132 of the first virtual machine 130 that the update has been completed. However, in the example of FIG. 1, since the update unit 161 cannot receive a search signal, it does not transmit a response signal. Further, since the update unit 161 does not receive an update instruction from the update instruction unit 139, it does not perform a software update process.

[0051] The virtual storages 152 and 162 are storage areas virtually provided in the second virtual machine 150 and the third virtual machine 160, respectively. When an update file is distributed from the distribution unit 140 of the first virtual machine 130, the update file is stored in the respective virtual storages 152 and 162.

[0052] As described above, the second virtual machine 150 and the third virtual machine 160 (corresponding to the "second virtual machine") are virtually connected to the first virtual machine 130.

[0053] (2) Regarding the ECU 20 The ECU 20 includes a hypervisor 210, a physical storage 220 that is hardware, and a fourth virtual machine 230 managed by the hypervisor 210.

[0054] The ECU 10 and the ECU 20 are connected by an in-vehicle network, and the first virtual machine 130 of the ECU 10 and the fourth virtual machine 230 (corresponding to the "second virtual machine") of the ECU 20 are virtually connected via the in-vehicle network.

[0055] The hypervisor 210 is software that virtualizes the ECU 20. The fourth virtual machine 230 is constructed on the hypervisor 210.

[0056] The actual storage 220 is a hardware memory, similar to the actual storage 120 of the ECU 10, and can be a volatile memory such as SRAM or DRAM, a ROM, a flash memory, or a non-volatile memory such as a hard disk.

[0057] The fourth virtual machine 230 of the ECU 20 has an update unit 231 and a virtual storage 232, similar to the second virtual machine 150 and the third virtual machine 160 described above.

[0058] When the update unit 231 (corresponding to the "second update unit") receives a search signal from the update management unit 132, it sends a response signal thereto. The update unit 231 further updates the software of the fourth virtual machine 230 based on an update instruction from the update instruction unit 139, and notifies the update management unit 132 of the first virtual machine 130 that the update is complete when the software update process is completed.

[0059] The virtual storage 232 is a storage area virtually provided in the actual storage 220. When an update file is delivered from the delivery unit 140, the update file is stored in the virtual storage 232.

[0060] (3) Operation of the electronic control system 1 Next, with reference to FIGS. 3 to 5, the operation related to the software update of the virtual machine will be described. FIG. 3 is a diagram showing the overall operation of the electronic control system 1. FIG. 4 shows the operation of the update management unit 132, and FIG. 5 shows the operation of the update unit of each virtual machine. The reference numerals shown in FIG. 3 correspond to those shown in FIGS. 4 and 5, and the same reference numerals indicate the same processing.

[0061] Note that the operations of the update management unit 132 and the update unit shown in FIGS. 4 and 5 are also considered to be the operations of each electronic control unit (ECU10, ECU20). Further, the operations of each electronic control unit not only indicate a software update method executed by the electronic control unit, but also indicate a processing procedure of a software update program executable by the electronic control unit. And these processes are not limited to the order shown in FIGS. 3 to 5. That is, the order may be changed as long as there are no restrictions such as using the result of the previous step in a certain step. The same applies to FIG. 7 described later.

[0062] First, with reference to FIGS. 3 and 4, the operation of the update management unit 132 will be mainly described. The update management unit 132 receives a communication status request from the file acquisition unit 131 (FIGS. 3 and 4: S101). This communication status request is transmitted to the update management unit 132 when the file acquisition unit 131 acquires a file for updating the software of the virtual machine from a server device external to the ECU10. The communication availability determination unit 135 of the update management unit 132 transmits a search signal to the update unit 133 of the first virtual machine 130 itself and the update units of the virtual machines connected to the first virtual machine 130 (FIGS. 3 and 4: S102).

[0063] The communication availability determination unit 135 receives a response signal from the update units of the virtual machines that have received the search signal in S102 (FIGS. 3 and 4: S103). In the example of FIG. 3, the communication availability determination unit 135 receives response signals from the update unit 133, the update unit 151, and the update unit 231 that have received the search signal in S102. However, the communication availability determination unit 135 does not receive a response signal from the update unit 161 that cannot receive the search signal in S102.

[0064] The communication availability determination unit 135 determines whether communication is possible between the update management unit 132 and the update units of the virtual machines based on the response signal received in S103 (FIGS. 3 and 4: S104). Here, although not described in FIGS. 3 and 4, the determination result by the communication availability determination unit 135 may be recorded in the actual storage 120 or the virtual storage 134.

[0065] The determination result notification unit 136 transmits the determination result in S104 to the file acquisition unit 131 (FIGS. 3 and 4: S105). The determination result of the present embodiment indicates that the update management unit 132 can communicate with the update unit 133, the update unit 151, and the update unit 231.

[0066] The reception unit 137 receives the update file group transmitted from the file acquisition unit 131 (FIGS. 3 and 4: S106). This update file is a file selected and transferred by the file acquisition unit 131 for the update unit capable of communicating with the update management unit 132 to update the software based on the determination result transmitted in S105. Therefore, the update file group received by the reception unit 137 in S106 includes only the update files for updating the software of the first virtual machine 130, the second virtual machine 150, and the fourth virtual machine 230.

[0067] The parsing processing unit 138 performs a parsing process of splitting the update file group received in S106 into update files for each virtual machine (FIGS. 3 and 4: S107). The update instruction unit 139 instructs the update units determined by the communication availability determination unit 135 to be capable of communicating with the update management unit 132, that is, the update units 133, 151, and 231, to update the software of the virtual machine (FIGS. 3 and 4: S108). The distribution unit 140 distributes the update files split in S107 to the update unit 151 and the update unit 231 (FIGS. 3 and 4: S109).

[0068] Here, each update unit that has received an update instruction from the update instruction unit 139 in S108 updates the software of the virtual machine. The update unit 130 of the first virtual machine 130 updates the software of the first virtual machine 130 using the update file stored in the actual storage 120. Also, the update unit 151 and the update unit 231 each receive the update file distributed from the distribution unit 140 in S109 and update the software of their respective virtual machines using the received update file (FIG. 3: S110).

[0069] When the update management unit 132 receives a completion notification indicating that the update process is complete from the update unit of each virtual machine for which the update process in S110 has been completed (FIGS. 3 and 4: S111).

[0070] When the update management unit 132 receives a notification indicating that the update process is complete from the update unit of each virtual machine, it notifies the file acquisition unit 131 that the update process of each virtual machine is complete (FIGS. 3 and 4: S112).

[0071] Next, the operation of the update unit of each virtual machine will be mainly described with reference to FIG. 5. The update unit of each virtual machine receives the search signal transmitted from the update management unit 132 in S102 (S201). Then, the update unit of each virtual machine that has received the search signal in S201 transmits a response signal to the communication availability determination unit 135 (S202).

[0072] The update unit receives an update instruction for the software of the virtual machine from the update instruction unit 139 (S203). In S203, the update unit that receives the update instruction from the update instruction unit 139 is the update unit that has received the search signal in S201 and transmitted the response signal in S202, that is, the update units 133, 151, and 231. Here, if the update instruction received in S203 is not an update instruction by accessing the actual storage, the update unit further receives the update file transmitted from the distribution unit 140 (S204). As described above in the description of FIG. 3, the update unit updates the software of the virtual machine based on the update instruction received in S203 (FIGS. 3 and 5: S110). When the update process in S110 is completed, the update unit of each virtual machine notifies the update management unit 132 that the update process is complete (S205).

[0073] Note that in FIGS. 3 to 5, after the communication availability determination unit 135 receives a communication status request from the file acquisition unit 131 in S101, it performs a process of transmitting a search signal to each update unit in S102. However, the communication availability determination unit 135 may be configured to periodically perform the processes of S101 to S103, and when receiving a communication status request (S101), transmit the determination result stored in the actual storage 120 (S105).

[0074] (4) Parentheses If it is found that communication between the update management unit 132 and the update unit cannot be established after the start of the software update process of the virtual machine, it is determined that an error has occurred in the entire update process, and the update process may be retried.

[0075] On the contrary, according to the present embodiment, before starting a series of processes related to software update, the update management unit 132 determines the communication availability with the update unit, thereby preventing the determination that an error has occurred in the entire update process and further preventing the entire update process from being retried. Furthermore, since transfer and division processing are performed only on necessary update files, it is possible to suppress the use of unnecessary resources while shortening the time required for the update.

[0076] (5) Modification Example 1 of Embodiment 1 In Embodiment 1, it is assumed that the file acquisition unit 131 passively acquires an update file group from a server device outside the ECU10. However, the file acquisition unit 131 may request the server device for an update file for updating the software of a specific virtual machine and acquire only the necessary update files from the server device.

[0077] Before acquiring a file from the server device, the file acquisition unit 131 of this modification example transmits a communication status request to the update management unit 132. Then, when the file acquisition unit 131 receives a determination result from the update management unit 132, it transmits information indicating a virtual machine having an update unit capable of communicating with the update management unit 132 to the server device. The file acquisition unit 131 may transfer the determination result received from the update management unit 132 to the server device as it is.

[0078] When the server device receives the determination result from the update management unit 132 in the file acquisition unit 131, it transmits only the update file for updating the software of the virtual machine having an update unit capable of communicating with the update management unit 132 to the file acquisition unit 131. That is, in the above-described example, the server device transmits only the update files for updating the software of the first virtual machine 130, the second virtual machine 150, and the fourth virtual machine 230 to the file acquisition unit 131. Then, the file acquisition unit 131 that has acquired the update file from the server device transfers the update file to the update management unit 132.

[0079] According to this modification example, since the file acquisition unit 131 acquires only the necessary update files from the server device, the communication volume between the file acquisition unit 131 and the server device can be suppressed. Further, also in this modification example, since transfer and division processing are performed only on the necessary update files, it is possible to suppress the use of unnecessary resources while shortening the time required for the update.

[0080] (6) Modification Example 2 of Embodiment 1 In Embodiment 1, the communication availability determination unit 135 determines whether communication is possible between the update management unit 132 and the update unit that performs the software update process of each virtual machine. In addition to this, the communication availability determination unit 135 of this modification example also determines whether software updates are associated between virtual machines.

[0081] The communication availability determination unit 135 determines whether software updates are "associated" between virtual machines. In this modified example, the communication availability determination unit 135 determines whether the software update of the third virtual machine 160 (corresponding to the "second virtual machine") for which communication is determined to be impossible is "associated" with the software updates of the second virtual machine 150 (corresponding to the "third virtual machine") and the fourth virtual machine 230 (corresponding to the "third virtual machine"). For example, when it is a condition to perform software updates simultaneously to achieve the stability of the overall system operation, or when the operations and functions are coordinated between virtual machines, it is determined that the software updates are associated. Here, "associated" means that, either temporally or functionally, one update depends on the other update, one update is a prerequisite for the other update, or one update and the other update are coordinated. Note that the determination of whether they are associated may be made by the communication availability determination unit 135 autonomously determining the content of the software to be updated, or it may be transmitted to the communication availability determination unit 135 in a predefined format (file or packet). For example, when using each package called VehiclePackage or SoftwarePackage in the AUTOSAR specification for software updates, association information between each software or each machine is described in a procedure file called a manifest included in those packages. In such a configuration, the communication availability determination unit 135 refers to the association information to determine whether software updates are associated between virtual machines. Also, needless to say, the location where the association information is described is not limited to those defined in the AUTOSAR specification, but may also be in a file format or packet format that can be understood by the communication availability determination unit 135.

[0082] In the example of FIG. 1, for example, if the fourth virtual machine 230 is the virtual machine that controls the sensor and the third virtual machine 160 is the virtual machine that aggregates the data output from the sensor, since the fourth virtual machine 230 and the third virtual machine 160 are functionally coordinated and it is desirable to perform software updates simultaneously, the communication availability determination unit 135 determines that the software update of the third virtual machine 160 (corresponding to the "second virtual machine") and the software update of the fourth virtual machine 230 (corresponding to the "third virtual machine") are associated with each other.

[0083] The update instruction unit 139 instructs the update unit of the virtual machine, for which the communication availability determination unit 135 has determined that communication is possible, to update the software of the virtual machine. However, even for the update unit for which the communication availability determination unit 135 has determined that communication is possible, if it is the update unit of the virtual machine associated with the software update of the virtual machine for which communication has been determined to be impossible, the software update is not instructed. In this modification example, although the update unit 231 of the fourth virtual machine 230 has been determined to be able to communicate with the update management unit 132 of the first virtual machine 130, since it has been determined that the software update is associated with the third virtual machine 160 for which communication has been determined to be impossible, the update unit 231 that updates the software of the fourth virtual machine 230 is not instructed to perform a software update.

[0084] Note that it is desirable for the determination by the communication availability determination unit 135 to be made before the file acquisition unit 131 receives the update file from the outside or before the reception unit 137 receives the update file from the file acquisition unit 131. Thereby, the communication volume between the file acquisition unit 131 and the server device can be suppressed. Alternatively, the processing amount in the first virtual machine 130 can be reduced.

[0085] Further, the parsing processing unit 138 and the distribution unit 140 may divide the update file and distribute the divided update file based on the determination result of the communication availability determination unit 135 in this modification example.

[0086] According to this modification example, since it collectively determines the feasibility of software updates for virtual machines associated with software updates, it is possible to reduce malfunctions caused by the existence of virtual machines with updated software and those without updated software. For example, when coordinated operations between different virtual machines are required, it is expected that the software versions operating on the virtual machines match. In this case, it is possible to prevent problems due to compatibility issues caused by the existence of virtual machines with updated software and those without updated software.

[0087] 2. Embodiment 2 In Embodiment 1, the file acquisition unit 131 was described as having a configuration in which it transfers only the update files to be sent to the update unit capable of communicating with the update management unit 132 based on the determination result transmitted from the update management unit 132. In this embodiment, the difference from Embodiment 1 will be mainly described for the configuration in which the file acquisition unit 131 also transfers the update files to be sent to the update unit that cannot communicate with the update management unit 132 to the update management unit 132.

[0088] Similar to Embodiment 1, the file acquisition unit 131 of this embodiment transmits a communication status request to the update management unit 132. Then, the update management unit 132 that has received the communication status request from the file acquisition unit 131 transmits a search signal to each update unit and determines whether communication is possible between the update management unit 132 and each update unit based on the response signal. Then, the update management unit 132 transmits the determination result to the file acquisition unit 131.

[0089] Here, the file acquisition unit 131 transfers all the update files for the virtual machines to be updated to the update management unit 132. That is, in the example shown in FIG. 1, it transfers to the update management unit 132 including the update files for updating the software of the update unit 161 that cannot communicate, for the third virtual machine 160.

[0090] The receiving unit 137 of the update management unit 132 receives the update file group transferred from the file acquisition unit 131. As described above, the files received by the receiving unit 137 are update files for updating the software of all virtual machines to be updated, and include update files for updating the software of all of the first virtual machine 130 to the fourth virtual machine 230.

[0091] The parsing processing unit 138 performs parsing processing to divide the update file group included in the file received by the receiving unit 137 into update files for each virtual machine. The parsed update files are stored in the actual storage 120.

[0092] The update instruction unit 139 instructs the update units determined by the communication availability determination unit 135 to be communicable to update the software of the virtual machines. Also in this embodiment, the update instruction unit 139 gives update instructions to the update unit 133, the update unit 151, and the update unit 231, and does not give an update instruction to the update unit 161.

[0093] The distribution unit 140 distributes the update files divided by the parsing processing unit 138 to the update units determined by the communication availability determination unit 135 to be communicable. Also in this embodiment, the distribution unit 140 distributes update files to the update unit 151 and the update unit 231.

[0094] When the update management unit 132 receives an update completion notification from each update unit, it transmits an update completion notification indicating that the update has been completed to the file acquisition unit 131.

[0095] As described above, the file acquisition unit 131 has received a determination result indicating that communication between the update management unit 132 and the update unit 161 is impossible. Therefore, even if the update completion notification does not include information indicating that the update of the virtual machine 160 having the update unit 161 has been completed, it is not determined that an error has occurred in the entire update process in the electronic control system 1.

[0096] In this embodiment, among the update files included in the update file group transferred from the file acquisition unit 131, the update files for updating the third virtual machine 160 are not transmitted from the distribution unit 140. However, in the future, when the communication between the update management unit 132 and the update unit 161, which could not communicate before, is restored, the update management unit 132 can transmit the update files stored in the actual storage 120 to the update unit 161 without requesting the file acquisition unit 131 to transmit the update files for updating the software of the third virtual machine 160.

[0097] 3. Embodiment 3 When the communication between the update management unit 132 and the update unit 161 is impossible, the software of the virtual machine 160 having the update unit 161 cannot be updated to the latest state, which is not desirable from the viewpoints of security and safety. Therefore, when there is an update unit that cannot communicate with the update management unit 132, the virtual machine having the update unit or the vehicle equipped with the electronic control device is restarted to attempt to restore communication.

[0098] (1) Regarding the update management unit 132 FIG. 6 shows the update management unit 132 of this embodiment. In addition to each function of the update management unit 132 shown in FIG. 2, the update management unit 132 further includes a restart request unit 141.

[0099] When the communication availability determination unit 135 determines that the communication between the update management unit 132 and the update unit 161 is impossible, the restart request unit 141 notifies the user of the vehicle of a vehicle restart request. This restart request may be notified, for example, by visually displaying it on the screen of the navigation device mounted on the vehicle, or by voice. Also, the vehicle restart request may be a request to turn on and off the ACC power, IG power, and +B power of the vehicle.

[0100] Alternatively, the restart request unit 141 may notify a restart request for a virtual machine having an update unit for which communication with the update management unit 132 is impossible. In the example of FIG. 1, the restart request unit 141 notifies a restart request for the third virtual machine 160. Note that restarting the virtual machine does not require restarting the entire vehicle. Therefore, when notifying a restart request for a virtual machine, the restart request unit 141 may notify a restart request to the hypervisor that manages the virtual machine.

[0101] The restart request unit 141 may notify a restart request when a predetermined condition is satisfied. For example, when there are a predetermined number or more of update units for which communication with the update management unit 132 is impossible, or when communication with an update unit that performs software update whose update deadline ends within a predetermined period is impossible, a restart request is notified. Alternatively, when communication with an update unit that updates a function of software that is likely to affect safe driving of the vehicle is impossible, the restart request unit 141 may notify a restart request.

[0102] Note that even when a restart request is notified from the restart request unit 141, there are cases where restart is possible depending on the status of the vehicle or the virtual machine, and cases where it is desirable to maintain the operation of the vehicle or the virtual machine. Therefore, whether to restart the vehicle or the virtual machine is optional.

[0103] (2) Operation of the update management unit 132 FIG. 7 shows the operation of the update management unit 132 of the present embodiment. Since the reference numerals common to FIG. 4 represent the same processes as in FIG. 4, the description thereof is omitted. The update management unit 132 determines whether communication with each update unit is possible in S104. Here, when it is determined that there is an update unit for which communication is impossible, the restart request unit 141 notifies a restart request for the vehicle or the virtual machine having the update unit for which communication is impossible (S121).

[0104] (3) Parentheses According to this embodiment, when there is an update unit that cannot communicate with the update management unit 132, communication recovery can be achieved by notifying a vehicle equipped with the ECU 10 or a virtual machine having the update unit to restart.

[0105] (4) Modification Example of Embodiment 3 In this modification example, as a predetermined condition described in Embodiment 3, an example using the communication availability determination unit 135 described in Modification Example 2 of Embodiment 1 will be described.

[0106] As described in Modification Example 2 of Embodiment 1, the communication availability determination unit 135 determines whether software updates are "associated" among virtual machines. In this modification example, the communication availability determination unit 135 determines whether the software update of the third virtual machine 160 (corresponding to the "second virtual machine") for which communication is determined to be impossible is "associated" with the software updates of the second virtual machine 150 (corresponding to the "third virtual machine") and the fourth virtual machine 230 (corresponding to the "third virtual machine"). In the example of FIG. 1, it is assumed that the communication availability determination unit 135 determines that the software update of the third virtual machine 160 is associated with the software update of the fourth virtual machine 230. Also, it is assumed that the communication availability determination unit 135 determines that the software update of the third virtual machine 160 is not associated with the software update of the second virtual machine 150.

[0107] When the communication availability determination unit 135 determines that communication between the update management unit 132 and the update unit 161 of the third virtual machine 160 is impossible and that the software update of the third virtual machine 160 is associated with the software update of the fourth virtual machine 230, the restart request unit 141 notifies the third virtual machine 160 and the fourth virtual machine 230 to restart. Further, when the communication availability determination unit 135 determines that communication between the update management unit 132 and the update unit 161 of the third virtual machine 160 is not possible, and determines that the software update of the third virtual machine 160 is not associated with the software update of the second virtual machine 150, the restart request unit 141 notifies a restart request for the third virtual machine 160 and does not notify a restart request for the second virtual machine 150.

[0108] In addition, when it is determined that the software update of the third virtual machine 160 is associated with the software update of the fourth virtual machine 230, and the electronic control unit having the third virtual machine 160 and the electronic control unit having the fourth virtual machine 230 are different electronic control units, the restart request unit 141 may notify a vehicle restart request. In the example of FIG. 1, since the ECU 10 has the third virtual machine 160 and the ECU 2 has the fourth virtual machine 230 and they are different electronic control units, the restart request unit 141 notifies a vehicle restart request. In this case, it is desirable to further condition that the vehicle is stopped or parked.

[0109] According to this modification example, since the target of the restart request is determined based on whether the software updates are associated, the restart can be performed within a necessary and sufficient range for stable operation.

[0110] Instead of associating software updates, the scope for notifying the restart request may be determined based on the differences between the hypervisors on which the virtual machines are built. For example, in the example of FIG. 1, if it is determined that communication with the update unit 161 of the third virtual machine 160 is not possible, and communication with the update unit 151 of the second virtual machine 150 built on the same hypervisor HV110 is possible, the restart request unit 141 may notify the restart request for the third virtual machine 160. On the other hand, if it is determined that communication with the update unit 161 of the third virtual machine 160 is not possible and communication with the update unit 151 of the second virtual machine 150 built on the same hypervisor HV110 is also not possible, the restart request unit 141 may notify the restart requests for all the virtual machines built on the same hypervisor HV110.

[0111] Also, after the restart based on the restart request, the operations shown in Embodiment 1 are performed again. In this case, the restart operation and the software update of the virtual machine without restart may be executed in parallel.

[0112] 4. Modifications of the electronic control device and the electronic control system In this section, modifications of the configurations of the electronic control device and the electronic control system common to Embodiments 1 to 3 will be described.

[0113] In the above example, for example, the case where the ECU10 is an ECU based on the AP and the ECU20 is an ECU based on the CP has been described. However, each virtual machine built in the ECU may have a platform such as an AP or a CP. FIG. 8 is a diagram for explaining an example in which each virtual machine has its own platform (hereinafter, PF).

[0114] In FIG. 8, the first virtual machine 130 has a first PF 1301, the second virtual machine 150 has a second PF 1501, the third virtual machine 160 has a third PF 1601, and the fourth virtual machine 230 has a fourth PF 2301. FIG. 8 further shows applications (1302, 1502, 1602, 2302) operating on the PF of each virtual machine respectively.

[0115] In addition to the AP and CP, there are various types of PF in the PF, and as the first to fourth PF (1301, 1501, 1601, 2301), any PF can be applied. For example, by applying the first PF 1301 as the AP, the second PF 1501 as the CP, and the third PF 1601 as a PF other than the AP and CP, a plurality of virtual machines with different PFs may coexist in one ECU. By mixing a plurality of virtual machines with different PFs in one ECU in this way, it becomes possible to integrate a plurality of functions into one ECU, and thus it becomes possible to reduce the total number of ECUs.

[0116] In the case of such a configuration, the OS of the virtual machine may be configured to be provided between, for example, the hypervisor and the PF, or to be integrated with the hypervisor, or to be included in the PF.

[0117] The update unit of each virtual machine updates the software of the virtual machine. However, in the configuration of FIG. 8, the update unit may update the PF or the application operating on the PF as the update of the software of the virtual machine. For example, the update unit 133 updates the first PF 1301 or the first application 1302.

[0118] Note that FIG. 8 illustrates the file acquisition unit 131 as being included in the first application 1302, and the update management unit 132 and the update unit 133 as being included in the first PF 1301. However, the software included in the first PF 1301 may implement some or all of the functions of the file acquisition unit 131, or the first application 1302 may implement some or all of the functions of the update management unit 132 and the update unit 133. Similarly, the second to fourth applications (1502, 1602, 2302) may implement some or all of the functions of their respective update units (151, 161, 231).

[0119] FIG. 8 further shows a configuration in which the actual storage 120 of the ECU 10 has three storage areas, namely, a shared storage area 121, a software storage area 122, and a distribution file storage area 123.

[0120] The shared storage area 121 is an area for storing the update files acquired by the file acquisition unit 131 and parsed by the parsing unit 138 of the update unit 133. The software storage area 122 is an area for storing the software that constitutes the virtual machine, such as the first to third PFs 1301, 1501, 1601, and the first to third applications 1302, 1502, 1602. The distribution file storage area 123 is an area for storing the update files distributed from the distribution unit 140. By virtualizing the distribution file storage area 123, virtual storage is constructed for each virtual machine.

[0121] In this modification, the update unit 133 of the first virtual machine 130 accesses the shared storage area 121 and uses the update files stored in the shared storage area 121 to update the software of the virtual machine, that is, the software stored in the software storage area 122. On the other hand, the update unit instructed to update the software of the virtual machine using the update files distributed by the distribution unit 140 uses the update files distributed from the distribution unit 140 and stored in the distribution file storage area 123 to update the software stored in the software storage area 122.

[0122] Although not shown in FIG. 8, the actual storage 220 of the ECU 20 may have a software storage area and a distribution file storage area (not shown), similar to the actual storage 120. However, in the ECU 20, since it is not necessary to store the update file acquired by the file acquisition unit, the actual storage 220 may not have a storage area corresponding to the shared storage area 121. The software storage area and the distribution file storage area of the actual storage 220 store the software constituting the virtual machine and the update file distributed from the distribution unit 140, respectively, similar to the software storage area 122 and the distribution file storage area 123.

[0123] Note that FIG. 8 shows the actual storage 120 as including all of the shared storage area 121, the software storage area 122, and the distribution file storage area 123, but the actual storage 120 may be realized by a plurality of different storages. For example, although the software storage area 122 of this modification example is a non-volatile memory, the shared storage area 121 and the distribution file storage area 123 may be either a non-volatile memory or a volatile memory. Therefore, the shared storage area 121 and the distribution file storage area 123 may be respectively provided in the storage area of the actual storage 120 that is a volatile memory, and the software storage area 122 may be provided in the storage area of the actual storage 120 that is a non-volatile memory.

[0124] 5. Application to Domain Architecture Next, a configuration example when applying the electronic control system 1 in each embodiment to the domain architecture will be described. The domain architecture classifies a plurality of ECUs into groups called domains according to their functions, roles, or network connections, and arranges domain controller ECUs (hereinafter, DC-ECUs) that manage and control a plurality of ECUs belonging to the same domain for each domain. In the domain architecture, since ECUs can be organized and integrated according to functions and networks, in a system composed of a large number of ECUs such as an in-vehicle system, not only does it facilitate future ECU update work, but it is also possible to suppress the increasing total number of ECUs.

[0125] (1) Overview of Domain Architecture FIG. 9 is a diagram schematically showing the domain architecture. The domain architecture shown in FIG. 9 has DC-ECUs 30A, 30B, a gateway ECU (hereinafter, GW-ECU) 40, and ECUs 50A, 51A, 50B, 51B.

[0126] Furthermore, the domain architecture shown in FIG. 9 has two domains. The first domain 2A has DC-ECU 30A and ECUs 50A, 51A, and the second domain 2B has DC-ECU 30B and ECUs 50B, 51B. As described above, domains are classified according to the functions and networks of ECUs. In the case of an in-vehicle system, for example, a domain that controls the drive system of a vehicle, a domain that controls autonomous driving, a domain that controls entertainment devices such as an in-vehicle TV and an in-vehicle computer, etc. can be mentioned.

[0127] The DC-ECU 30A controls the ECUs 50A and 51A belonging to the first domain 2A, and the DC-ECU 30B controls the ECUs 50B and 51B belonging to the second domain 2B. For example, when the first domain 2A is a domain that controls autonomous driving, the DC-ECU 30A controls the ECUs 50A and 51A such as a camera ECU, a radar ECU, a lidar ECU, a locator ECU, or an ECU equipped with various autonomous driving applications. The DC-ECU 30A further has a sensor fusion application that integrates the sensor information output from the ECUs 50A and 51A, and may provide the output from the sensor fusion application to the ECUs 50A and 51A.

[0128] The GW-ECU 40 is an ECU that functions as a gateway device in the in-vehicle network. The GW-ECU 40 is connected to a plurality of buses and is connected to other ECUs via each bus. The GW-ECU 40 relays, for example, communication between domains. The GW-ECU 40 further has a function as a gateway between the outside of the vehicle and the domain.

[0129] In addition, in FIG. 9, the DC-ECU 30A, the GW-ECU 40, the ECUs 50A and 51A are described as different ECUs, but the functions of each of the above-described ECUs may be integrated into other ECUs. For example, a part of the functions of the ECUs 50A and 51A may be integrated into the DC-ECU 30A. In this case, the functions integrated into the DC-ECU 30A may be realized by a virtual machine installed in the DC-ECU 30A.

[0130] (2) Application Example of Domain Architecture to the Electronic Control System 1 In the above-described embodiments, the electronic control system 1 having the ECUs 10 and 20 has been described. Here, when applying the domain architecture of FIG. 9 to the electronic control system 1, the ECU 10 that acquires the update file is preferably configured as the DC-ECUs 30A and 30B in FIG. 9. In this case, the DC-ECUs 30A and 30B of the domain architecture each issue an update instruction to the ECUs belonging to the same domain and perform distribution of the update file as necessary. Therefore, the DC-ECUs 30A and 30B do not issue an update instruction or perform distribution of the update file to the virtual machines of the ECUs belonging to different domains.

[0131] For example, when the ECU 10 is configured as the DC-ECU 30A, it does not issue an update instruction or perform distribution of the update file to the ECUs (DC-ECU 30B, ECUs 50B, 51B) included in the second domain 2B. Similarly, the ECU 10 configured as the DC-ECU 30B does not issue an update instruction or perform distribution of the update file to the ECUs included in the first domain 2A.

[0132] As another example, the ECU 10 may be configured as the GW-ECU 40 in FIG. 9. In this case, the ECU 20 is configured as the DC-ECUs 30A, 30B or the ECUs 50A,B, 51A,B.

[0133] By using the domain architecture for the electronic control system 1, communication between the ECUs can be limited within the same or related domains, so that the communication volume of the in-vehicle network as a whole can be suppressed, and as a result, it is possible to improve the responsiveness in the in-vehicle network.

[0134] 6. Summary The features of the electronic control device in each embodiment of the present invention and the electronic control system including the electronic control device have been described above.

[0135] Since the terms used in each embodiment are illustrative, they may be replaced with synonymous terms or terms including synonymous functions.

[0136] The block diagrams used in the description of the embodiments classify and organize the configuration of the device by function. Each block indicating a function is realized by any combination of hardware or software. Also, since it shows functions, such block diagrams can also be understood as disclosures of method inventions and inventions of programs that implement such methods.

[0137] Regarding the processing, flow, and functional blocks that can be understood as methods described in each embodiment, the order may be changed as long as there are no restrictions such as being related to using the results of other steps in the previous stage in one step.

[0138] The terms first, second, up to N (N is an integer), used in each embodiment and the claims are used to distinguish two or more configurations or methods of the same type, and do not limit the order or superiority.

[0139] Although it is premised that the electronic control device of each embodiment is an electronic control device that constitutes an in-vehicle device mounted on a vehicle, the electronic control device of the present invention is applied to any electronic control system unless particularly limited in the claims.

[0140] Also, examples of the form of the device of the present invention include the following. Examples of the form of components include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of the form of semi-finished products include electronic control units (ECUs (Electric Control Units)) and system boards. Examples of the form of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. In addition, it includes devices having communication functions, etc., such as video cameras, still cameras, and car navigation systems.

[0141] Also, necessary functions such as antennas and communication interfaces may be added to each device.

[0142] In addition, the present invention can be realized not only by dedicated hardware having the configurations and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as a memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing the program.

[0143] A program stored in a non-transitory physical recording medium of dedicated or general-purpose hardware (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) can be provided to the dedicated or general-purpose hardware via the recording medium or without passing through the recording medium via a communication line from a server. As a result, it is possible to always provide the latest functions through program upgrades.

Industrial Applicability

[0144] Although the electronic control device of the present invention has been mainly described as an in-vehicle electronic control device mounted on an automobile, it can be applied to all moving bodies such as motorcycles, ships, railways, and airplanes. Further, it is applicable not only to moving bodies but also to all products including microcomputers.

Explanation of Reference Numerals

[0145] 1 Electronic control system, 10, 20 Electronic control device, 130 First virtual machine, 131 File acquisition unit, 132 Update management unit, 133 Update unit, 135 Update permission determination unit, 136 Notification unit, 137 Reception unit, 139 Update instruction unit, 140 Distribution unit, 141 Restart request unit, 150 Second virtual machine, 151 Update unit, 160 Third virtual machine, 161 Update unit, 230 Fourth virtual machine, 231 Update unit

Claims

An electronic control device having a first virtual machine (130), comprising: a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device; an update management unit (132) that manages the update of the software; and the update management unit includes: a determination unit (135) that determines whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine; a notification unit (136) that notifies the file acquisition unit of the determination result of the determination unit; a reception unit (137) that receives, from the file acquisition unit, the file selected by the file acquisition unit based on the notification from the notification unit; and an update instruction unit (139) that instructs software update using the file received by the reception unit to the update unit determined by the determination unit to be communicable among the first update unit and the second update unit. An electronic control device (10).

2. The file acquisition unit selects the file to be used for software update by the update unit determined by the determination unit to be communicable among the first update unit and the second update unit, and transmits the file to the reception unit. The electronic control device according to claim 1.

3. When the determination unit determines that communication with the second update unit is impossible, the update instruction unit does not instruct the second update unit to update software using the file received by the reception unit. The electronic control device according to claim 1.

4. An electronic control device having a first virtual machine (130), comprising: a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device; an update management unit (132) that manages the update of the software; and the update management unit includes: a determination unit (135) that determines whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine; a reception unit (137) that receives the file from the file acquisition unit; ​ ​ An update instruction unit (139) that instructs software update using the file received by the reception unit to the update unit determined to be communicable by the determination unit among the first update unit and the second update unit; Furthermore, the first virtual machine is connected to a third virtual machine, Furthermore, the determination unit determines whether or not the software update of the second virtual machine is associated with the software update of the third virtual machine, When the determination unit determines that communication with the second update unit is impossible and determines that the software update of the second virtual machine is associated with the software update of the third virtual machine, The update instruction unit does not instruct software update using the file received by the reception unit to the second update unit and a third update unit that updates the software of the third virtual machine, Electronic control device (10).

5. Before the file acquisition unit receives the file from the outside, or before the reception unit receives the file from the file acquisition unit, the determination unit makes a determination. The electronic control device according to claim 4.

6. An electronic control device having a first virtual machine (130), A file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, An update management unit (132) that manages the software update, Between the update management unit and the first update unit (133) that updates the software of the first virtual machine, and / or Between the update management unit and a second update unit that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine, A determination unit (135) that determines whether communication is possible; A reception unit (137) that receives the file from the file acquisition unit; A parse processing unit (138) that divides the file received by the reception unit; An update instruction unit (139) that instructs software update using the file received by the reception unit to the update unit determined to be communicable by the determination unit among the first update unit and the second update unit; A distribution unit (140) that distributes the file divided by the parse processing unit to the second update unit capable of communication; Electronic control device (10).

7. An electronic control device having a first virtual machine (130), comprising: a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device; an update management unit (132) that manages the update of the software; and the update management unit: between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine, a determination unit (135) that determines whether communication is possible; a reception unit (137) that receives the file from the file acquisition unit; an update instruction unit (139) that instructs software update using the file received by the reception unit to the update unit determined to be communicable by the determination unit among the first update unit and the second update unit; a restart request unit (141) that notifies a restart request for a vehicle on which the electronic control device is mounted or the second virtual machine when the determination unit determines that communication with the second update unit is impossible; and further, the first virtual machine is connected to a third virtual machine; further, the determination unit determines whether the update of the software of the second virtual machine is associated with the update of the software of the third virtual machine; when the determination unit determines that communication with the second update unit is impossible and determines that the update of the software of the second virtual machine is associated with the update of the software of the third virtual machine, the restart request unit notifies a restart request for the second virtual machine and the third virtual machine; an electronic control device (10).

8. When the electronic control device having the second virtual machine and the electronic control device having the third virtual machine are different electronic control devices, the restart request unit notifies a restart request for the vehicle. The electronic control device according to claim 7.

9. The determination unit makes a determination when an instruction to transmit a communication status between the update management unit and the first update unit and / or the second update unit is received from the file acquisition unit. The electronic control device according to claim 1, 4, 6, or 7.

10. The electronic control device is mounted on a moving body. The electronic control device according to any one of claims 1 to 6.

11. A software update method executed by an electronic control device (10) having a first virtual machine (130), comprising: The electronic control device includes: A file acquisition unit (131) that acquires a file for updating software from outside the electronic control device; An update management unit (132) that manages the update of the software; and has Between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or Between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine, Determine whether communication is possible (S104); Notify the file acquisition unit of the determination result as to whether communication is possible (S105); Receive, from the file acquisition unit, the file selected by the file acquisition unit based on the notification of the determination result (S106); Instruct software update using the file received from the file acquisition unit to the update unit determined to be communicable among the first update unit and the second update unit (S108); A software update method. **Claim 12** A software update method executed by an electronic control device (10) having a first virtual machine (130), comprising: The electronic control device includes: A file acquisition unit (131) that acquires a file for updating software from outside the electronic control device; An update management unit (132) that manages the update of the software; and has Between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or Between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine, Determine whether communication is possible (S104); Determine whether the software update of the second virtual machine is associated with the software update of a third virtual machine connected to the first virtual machine; Receive the file from the file acquisition unit (S106); Instruct software update using the file received from the file acquisition unit to the update unit determined to be communicable among the first update unit and the second update unit (S108); When it is determined that communication with the second update unit is impossible and it is determined that the software update of the second virtual machine and the software update of the third virtual machine are associated with each other, do not instruct the second update unit and the third update unit that updates the software of the third virtual machine to perform a software update using the received file. Software update method.

13. A software update method executed by an electronic control device (10) having a first virtual machine (130), wherein the electronic control device has a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, and an update management unit (132) that manages the software update, and determines whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine (S104), receives the file from the file acquisition unit (S106), divides the received file (S107), instructs a determined update unit capable of communication among the first update unit and the second update unit to perform a software update using the file received from the file acquisition unit (S108), distributes the divided file to the second update unit capable of communication (S109), Software update method.

14. A software update method executed by an electronic control device (10) having a first virtual machine (130), wherein the electronic control device has a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, and an update management unit (132) that manages the software update, and determines whether communication is possible between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine (S104), receives the file from the file acquisition unit (S106), divides the received file (S107), Determine whether the update of the software of the second virtual machine is associated with the update of the software of the third virtual machine connected to the first virtual machine, Receive the file from the file acquisition unit (S106), Instruct the update unit determined to be communicable among the first update unit and the second update unit to update the software using the file received from the file acquisition unit (S108), When it is determined that communication with the second update unit is impossible and it is determined that the update of the software of the second virtual machine is associated with the update of the software of the third virtual machine, notify the restart request of the second virtual machine and the third virtual machine (S121), Software update method.

15. A software update program executable on an electronic control device (10) having a first virtual machine (130), The electronic control device includes, A file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, An update management unit (132) that manages the update of the software, And has, The software update program includes, Between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or, Between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine, Determine whether communication is possible (S104), Notify the determination result of whether communication is possible to the file acquisition unit (S105), Receive from the file acquisition unit the file selected by the file acquisition unit based on the notification of the determination result (S106), Instruct the update unit determined to be communicable among the first update unit and the second update unit to update the software using the file received from the file acquisition unit (S108), A software update program that causes the electronic control device to execute the process.

16. A software update program executable on an electronic control device (10) having a first virtual machine (130), The electronic control device includes, A file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, An update management unit (132) that manages the update of the software having The software update program between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine determines whether communication is possible (S104), determines whether the update of the software of the second virtual machine is associated with the update of the software of a third virtual machine connected to the first virtual machine, receives the file from the file acquisition unit (S106), instructs the update unit determined to be capable of communication among the first update unit and the second update unit to update the software using the file received from the file acquisition unit (S108), when it is determined that communication with the second update unit is impossible and it is determined that the update of the software of the second virtual machine is associated with the update of the software of the third virtual machine does not instruct the second update unit and a third update unit that updates the software of the third virtual machine to update the software using the received file, A software update program that causes the electronic control device to execute the process

17. A software update program executable on an electronic control device (10) having a first virtual machine (130), the electronic control device comprising a file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, an update management unit (132) that manages the update of the software having The software update program between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine determines whether communication is possible (S104), receives the file from the file acquisition unit (S106), divides the received file (S107), Of the first update unit and the second update unit, for the update unit determined to be capable of communication, instruct software update using the file received from the file acquisition unit (S108), Distribute the divided file to the second update unit capable of communication (S109), A software update program that causes the electronic control device to execute the process.

18. A software update program executable on an electronic control device (10) having a first virtual machine (130), The electronic control device is A file acquisition unit (131) that acquires a file for updating software from outside the electronic control device, An update management unit (132) that manages the update of the software, And has The software update program is Between the update management unit and a first update unit (133) that updates the software of the first virtual machine, and / or Between the update management unit and a second update unit (151, 161, 231) that updates the software of a second virtual machine (150, 160, 230) connected to the first virtual machine, Determine whether communication is possible (S104), Determine whether the update of the software of the second virtual machine is associated with the update of the software of a third virtual machine connected to the first virtual machine, Receive the file from the file acquisition unit (S106), Of the first update unit and the second update unit, for the update unit determined to be capable of communication, instruct software update using the file received from the file acquisition unit (S108), When it is determined that communication with the second update unit is impossible and it is determined that the update of the software of the second virtual machine is associated with the update of the software of the third virtual machine, notify a restart request for the second virtual machine and the third virtual machine (S121), A software update program that causes the electronic control device to execute the process.

19. An electronic control system having a first electronic control device (10) having a first virtual machine (130) and a second electronic control device (20) having a second virtual machine (230), The first virtual machine is A file acquisition unit (131) that acquires a file for updating software from outside the first electronic control device, An update management unit (132) that manages the update of the software, The update management unit A determination unit (135) that determines whether communication is possible between the update management unit and a second update unit (231) that updates the software of the second virtual machine, A notification unit (136) that notifies the file acquisition unit of the determination result of the determination unit, A reception unit (137) that receives, from the file acquisition unit, the file selected by the file acquisition unit based on the notification from the notification unit, An update instruction unit (139) that instructs the second update unit with which communication is possible to update the software using the file received by the reception unit, The second update unit of the second virtual machine Updates the software of the second virtual machine using the file based on the instruction of the update instruction unit, An electronic control system (1).

20. An electronic control system having a first electronic control device (10) having a first virtual machine (130), a second electronic control device (20) having a second virtual machine (230), and a third electronic control device having a third virtual machine, The first virtual machine A file acquisition unit (131) that acquires, from outside the first electronic control device, a file for updating software, An update management unit (132) that manages the update of the software, The update management unit A determination unit (135) that determines whether communication is possible between the update management unit and a second update unit (231) that updates the software of the second virtual machine, and further determines whether the update of the software of the second virtual machine and the update of the software of the third virtual machine are associated, A reception unit (137) that receives the file from the file acquisition unit, An update instruction unit (139) that, when the determination unit determines that communication with the second update unit is possible, instructs the second update unit to update the software using the file received by the reception unit, When the determination unit determines that communication with the second update unit is impossible and determines that the update of the software of the second virtual machine and the update of the software of the third virtual machine are associated, The update instruction unit does not instruct the second update unit and the third update unit that updates the software of the third virtual machine to update the software using the file received by the reception unit. The second virtual machine has a second update unit that updates the software of the second virtual machine using the file based on an instruction from the update instruction unit. The third virtual machine has a third update unit that updates the software of the third virtual machine using the file based on an instruction from the update instruction unit. Electronic control system (1).

21. An electronic control system including a first electronic control device (10) having a first virtual machine (130) and a second electronic control device (20) having a second virtual machine (230), wherein the first virtual machine has a file acquisition unit (131) that acquires a file for updating software from outside the first electronic control device, and an update management unit (132) that manages the update of the software. The update management unit has a determination unit (135) that determines whether communication is possible between the update management unit and a second update unit (231) that updates the software of the second virtual machine, a reception unit (137) that receives the file from the file acquisition unit, a parsing processing unit (138) that divides the file received by the reception unit, an update instruction unit (139) that instructs the second update unit capable of communication to update the software using the file received by the reception unit, and a distribution unit (140) that distributes the file divided by the parsing processing unit to the second update unit capable of communication. The second update unit of the second virtual machine updates the software of the second virtual machine using the file based on an instruction from the update instruction unit. Electronic control system (1).

22. An electronic control system including a first electronic control device (10) having a first virtual machine (130), a second electronic control device (20) having a second virtual machine (230), and a third electronic control device having a third virtual machine, wherein the first virtual machine has a file acquisition unit (131) that acquires a file for updating software from outside the first electronic control device, and an update management unit (132) that manages the update of the software. The update management unit Determine whether communication is possible between the update management unit and a second update unit (231) that updates the software of the second virtual machine, and further determine whether the update of the software of the second virtual machine and the update of the software of the third virtual machine are associated, a determination unit (135); a reception unit (137) that receives the file from the file acquisition unit; an update instruction unit (139) that, when the determination unit determines that communication with the second update unit is possible, instructs the second update unit to update the software using the file received by the reception unit; a restart request unit (141) that, when the determination unit determines that communication with the second update unit is impossible, notifies a request to restart the vehicle on which the electronic control device is mounted or the second virtual machine; and has, when the determination unit determines that communication with the second update unit is impossible and determines that the update of the software of the second virtual machine and the update of the software of the third virtual machine are associated, the restart request unit notifies a request to restart the second virtual machine and the third virtual machine, the second virtual machine has the second update unit that updates the software of the second virtual machine using the file based on the instruction of the update instruction unit, the third virtual machine has the third update unit that updates the software of the third virtual machine using the file based on the instruction of the update instruction unit, Electronic control system (1).

Citation Information

Patent Citations

  • Control apparatus installed on working vehicle

    JP2010260441A

  • Onboard electronic control device

    JP2018092241A

  • Virtual machine monitor, and update method of software and firmware

    JP2020107355A

  • On-vehicle computer, on-vehicle communication system, computer execution method, and computer program

    JP2020173561A