In-vehicle device, program, and program update method

The in-vehicle device with a control unit proxies part of the update process for the update device, addressing the inefficiency in updating vehicle control programs by simplifying the update process and ensuring smooth operation.

JP7690912B2Active Publication Date: 2025-06-11AUTONETWORKS TECH LTD +2
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022036515
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-09
Publication Date
2025-06-11
Estimated Expiration
2042-03-09

AI Technical Summary

Technical Problem

Existing systems for updating control programs in vehicles do not consider the process for updating the communication device (update device) itself, leading to inefficiencies and potential complications during the update process.

Method used

An in-vehicle device with a control unit that proxies part of the update process for the update device, allowing the update device to update its own program efficiently by delegating processing tasks to the in-vehicle device.

Benefits of technology

Enables efficient program updates for the update device by simplifying the update process and ensuring smooth operation, even if the update process fails, by allowing for rollback instructions to be issued.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007690912000001
    Figure 0007690912000001
  • Figure 0007690912000002
    Figure 0007690912000002
  • Figure 0007690912000003
    Figure 0007690912000003
Patent Text Reader

Abstract

To provide an on-vehicle device and the like in which an updating device for performing a process to update a program of the on-vehicle ECU can perform the updating process of the program efficiently when the updating device performs a process for updating a program applied to the update itself.SOLUTION: An on-vehicle device according to an embodiment is communicatively connected with an updating device which performs a process for updating a program of an on-vehicle ECU installed on a vehicle with an updating program acquired from an external server outside of the vehicle. The on-vehicle device includes a control unit for performing a process for updating a program of the updating device. When the updating device is included in the updating object by the updating program, the control unit substitutes at least a part of the process for the update performed by the updating device.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an in-vehicle device, a program, and a method for updating a program.

Background Art

[0002] Vehicles are equipped with an ECU (Electronic Control Unit) for controlling in-vehicle devices such as a drive control system for engine control and a body system for air conditioner control. The ECU includes an arithmetic processing unit such as an MPU, a rewritable non-volatile storage unit such as an EEPROM, and a communication unit for communicating with other ECUs, and controls the in-vehicle devices by reading and executing a control program stored in the storage unit. Further, a communication device (update device) having a wireless communication function is mounted on the vehicle, and communicates with a program providing device connected to an external network via the communication device, and downloads a control program of the ECU from the program providing device. ) can be received and the control program of the ECU can be updated (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in Patent Document 1, there is a problem that no consideration is given to the process for updating the control program itself applied to the communication device (update device).

[0005] An object of the present disclosure is to provide an in-vehicle device or the like that can efficiently perform a program update process when an update device that performs a process of updating a program of an in-vehicle ECU performs a process of updating a program applied to the update itself.

Means for Solving the Problems

[0006] An in-vehicle device according to an aspect of the present disclosure is an in-vehicle device communicably connected to an update device that performs a process for updating a program of an in-vehicle ECU mounted on a vehicle by an update program acquired from an external server outside the vehicle. The in-vehicle device includes a control unit that performs a process for updating the program in the update device. When the update device is included in an update target by the update program, the control unit proxies at least a part of the process for updating performed by the update device.

Advantages of the Invention

[0007] According to an aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that can efficiently perform a program update process when an update device that performs a process for updating a program of an in-vehicle ECU performs a process for updating a program applied to the update itself.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Mode for Carrying Out the Invention

[0009] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. Also, at least a part of the embodiments described below may be arbitrarily combined.

[0010] (1) An in-vehicle device according to an aspect of the present disclosure is an in-vehicle device communicably connected to an update device that performs processing for updating a program of an in-vehicle ECU mounted on a vehicle with an update program acquired from an external server outside the vehicle, and includes a control unit that performs processing for updating the program in the update device. When the update device is included in the update target by the update program, the control unit proxies at least a part of the processing performed by the update device.

[0011] In this aspect, the control unit of the in-vehicle device (proxy ECU) proxies the processing of the update device, and the update device can be instructed by the in-vehicle device (proxy ECU) to perform processing related to the update of the update device itself (own device). The update device can perform processing related to the update of the program for itself based on an instruction from the in-vehicle device (proxy ECU). That is, when the update device updates itself (the update device itself), there is a concern that the processing content such as judgment branching becomes complicated during the update. By having the in-vehicle device (proxy ECU) take charge of the program update (application of the update program, etc.) in the update device, the program update process in the update device can be smoothly performed.

[0012] (2) The in-vehicle device according to one aspect of the present disclosure, the processing to be delegated includes an activation process of applying the update program acquired by the update device to the update device itself.

[0013] In this aspect, when the update device is the target of update, it can be activated based on an instruction from the in-vehicle device (delegated ECU), so that the processing related to the update can be smoothly performed.

[0014] (3) The in-vehicle device according to one aspect of the present disclosure, the processing to be delegated includes a rollback process according to the result of the activation process.

[0015] In this aspect, in response to an activation instruction from the in-vehicle device (delegated ECU), after the update device performs the activation process, the in-vehicle device (delegated ECU) performs processing such as operation confirmation (abnormality detection sequence) on the update device after the activation process (after applying the update program). If the in-vehicle device (delegated ECU) detects an abnormality in the update device after the activation process, it transmits (outputs) a rollback instruction to the update device. The update device that has acquired the rollback instruction from the in-vehicle device (delegated ECU) performs a rollback process of returning to the original program before applying the update program. Therefore, even if the activation process fails, the update device can execute the original program, and if the update device has a function of controlling the vehicle, the control related to the vehicle can be continued.

[0016] (4) In the storage unit of the update device according to one aspect of the present disclosure, information for specifying the in-vehicle device as the delegated ECU that performs the delegated processing is stored in advance.

[0017] In this aspect, the in-vehicle device (proxy ECU) is specified by an ECU-ID, an IP address, etc., or a CAN-ID (which may substantially identify the in-vehicle device by a message ID) for communicating with the in-vehicle device (proxy ECU). Regardless of the in-vehicle ECU targeted for the update program, by pre-determining in a single ECU (proxy ECU) the in-vehicle device that proxies the processing of the update device (fixing the proxy ECU), the update device does not need to determine (select) each time the ECU that becomes the in-vehicle device proxying the processing of the update device, and can quickly start the update processing of the update device. Also, since it suffices to give only one ECU the function of being the in-vehicle device (proxy ECU) that proxies the processing of the update device, it is possible to save memory in other in-vehicle ECUs.

[0018] (5) The in-vehicle device according to one aspect of the present disclosure, wherein the control unit acquires an instruction signal indicating an instruction to perform the processing to be proxied from the update device, and starts the processing to be proxied according to the acquired instruction signal.

[0019] In this aspect, the control unit of the in-vehicle device (proxy ECU) proxies the processing performed by the update device only when it acquires an instruction signal (proxy instruction signal) indicating an instruction to perform the processing to be proxied by the in-vehicle device (proxy ECU) from the update device. The update device performs the update processing of the in-vehicle ECU by itself when it is not the update target, and can have the in-vehicle device (proxy ECU) proxy the update processing only when it is the update target. The in-vehicle device (proxy ECU) does not proxy the processing of the update device unnecessarily because it does not proxy the update device every time the update device acquires the update program, but proxies the update device only when the update device is the update target, and can perform the update processing efficiently.

[0020] (6) The in-vehicle device according to one aspect of the present disclosure, wherein the processing to be delegated includes processing for updating the program of the in-vehicle ECU, the updating device has a relay function for relaying data transmitted and received between in-vehicle ECUs, and when the updating device is included in the update target by the update program, the control unit varies the processing for updating the program of the in-vehicle ECU according to whether the updating device maintains the relay function.

[0021] In this aspect, when the update device is included in the update target by the update program, that is, during the process of updating the program of the update device itself, the control unit of the in-vehicle device (delegated ECU) determines whether the update device maintains the relay function, and varies the processing for updating the program of the in-vehicle ECU according to the determination result. Therefore, even when the processing delegated by the control unit includes the processing for updating the program of the in-vehicle ECU, different processing can be performed on the in-vehicle ECU to be updated according to whether the relay function by the update device is maintained, and appropriate delegated processing corresponding to the update processing for the update device can be performed. That is, when the update device maintains the relay function, the in-vehicle device (delegated ECU) can directly instruct the in-vehicle ECU to perform the activation process or the rollback process. Since the in-vehicle device (delegated ECU) can cause the update device and the in-vehicle ECU to execute the activation process or the rollback process simultaneously, the processing related to the update can be quickly performed in one step.

[0022] (7) In the in-vehicle device according to one aspect of the present disclosure, the external server-side communication line and the in-vehicle ECU-side communication line are connected to the update device and are connected to the external server-side communication line.

[0023] In this aspect, since the in-vehicle device (proxy ECU) is connected to the communication line on the external server side, it can acquire the update program transmitted from the external server without going through the update device. The in-vehicle device (proxy ECU) connected to the communication line on the external server side in this way may also function as a device provided between the external server and the update device, such as an out-vehicle communication device that communicates with the external server or a security device that monitors unauthorized communication.

[0024] (8) The in-vehicle device according to one aspect of the present disclosure outputs a request signal to the update device, requesting the update device to start the proxy process based on the update program acquired from the external server without going through the update device.

[0025] In this aspect, since the in-vehicle device (proxy ECU) acquires the update program without going through the update device, it is independent (separate) from the process by the update device, and it is possible to determine whether the update device is the update target. As a result, when the update device is the update target, the update device can transmit an instruction signal (proxy instruction signal) indicating an instruction to perform the process to be proxied to the in-vehicle device (proxy ECU) in response to the request signal from the in-vehicle device (proxy ECU). Since the in-vehicle device (proxy ECU) acquires the update program earlier than the update device, it is possible to determine whether the update device is the update target. When the update device is the update target, after instructing the in-vehicle ECU to perform the activation process, the update device can transmit an instruction signal (proxy instruction signal) indicating an instruction to perform the process to be proxied to the in-vehicle device (proxy ECU) based on the request signal. Therefore, there is no need for the update device itself to determine whether to transmit the proxy instruction signal to the in-vehicle device (proxy ECU), and the in-vehicle device (proxy ECU) can quickly take over the process.

[0026] (9) In the in-vehicle device according to one aspect of the present disclosure, an out-vehicle communication device for wirelessly communicating with the external server is connected to the communication line on the external server side and is included in the out-vehicle communication device.

[0027] In this aspect, the in-vehicle device may be included in the out-vehicle communication device, that is, it may be configured as a part of the out-vehicle communication device. By incorporating the in-vehicle device into the out-vehicle communication device in this way, these devices can be housed in the same housing, enabling weight reduction and size reduction compared to a configuration where the out-vehicle communication device and the in-vehicle device are separate entities.

[0028] (10) A program according to an aspect of the present disclosure is communicably connected to a computer that performs a process for updating a program of an in-vehicle ECU mounted on a vehicle by an update program acquired from an external server outside the vehicle. The computer performs a process for updating the program in the update device, and when the update device is included in an update target by the update program, executes a process for proxying at least a part of the update process performed by the update device.

[0029] In this aspect, the update device can smoothly perform the program update process in the update device by having the in-vehicle device (proxy ECU) take charge of the program update (such as application of the update program) in the update device itself.

[0030] (11) A program update method according to an aspect of the present disclosure is communicably connected to a computer that performs a process for updating a program of an in-vehicle ECU mounted on a vehicle by an update program acquired from an external server outside the vehicle. The computer performs a process for updating the program in the update device, and when the update device is included in an update target by the update program, executes a process for proxying at least a part of the update process performed by the update device.

[0031] In this aspect, the update device can smoothly perform the program update process in the update device by having the in-vehicle device (proxy ECU) take charge of the program update (such as application of the update program) in the update device itself.

[0032] [Details of Embodiments of the Present Invention] The present invention will be specifically described based on the drawings showing its embodiments. The update device 3 according to the embodiment of the present disclosure will be described below with reference to the drawings. Note that the present invention is not limited to these examples, and is defined by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0033] (Embodiment 1) Hereinafter, the embodiments will be described with reference to the drawings. FIG. 1 is a schematic diagram showing the configuration of an in-vehicle update system S according to Embodiment 1. FIG. 2 is a block diagram illustrating the physical configuration of the proxy ECU 2. The in-vehicle update system S includes an off-vehicle communication device 1 and an update device 3 mounted on a vehicle C, and transmits an update program acquired from an external server S1 (program providing device, OTA server) connected via an off-vehicle network N to an in-vehicle ECU 4 (Electronic Control Unit) mounted on the vehicle C. Further, the in-vehicle update system S includes an in-vehicle ECU-side communication line (in-vehicle communication line 51) connecting the update device 3 and the in-vehicle ECU, and an external server-side communication line (off-vehicle communication line 52) connecting the update device 3 and the off-vehicle communication device. An in-vehicle device (proxy ECU 2) that proxies the processing of the update device 3 is connected to the off-vehicle communication line 52.

[0034] The external server S1 is a computer such as a server connected to an off-vehicle network N such as the Internet or a public switched telephone network, and includes a storage unit S11 such as a RAM (Random Access Memory), a ROM (Read Only Memory), or a hard disk, and corresponds to an off-vehicle program providing device. A program or data for controlling the in-vehicle ECU 4 created by the manufacturer of the in-vehicle ECU 4 or the like is stored in the storage unit S11 of the external server S1. The program or data is transmitted to the vehicle C as an update program and used to update the program or data of the in-vehicle ECU 4 mounted on the vehicle C as described later. The external server S1 (program providing device) configured in this way is also referred to as an OT A (Over The Air) server.

[0035] The proxy ECU 2 is connected to the vehicle exterior communication line 52 and can acquire an update program transmitted from the external server S1 without going through the update device 3. The proxy ECU 2 determines whether the update device 3 is an update target based on the acquired update program. When the update device 3 is an update target, the proxy ECU 2 outputs a request signal requesting the update device 3 to start the process of acting as an agent. The proxy ECU 2 gives an activation instruction to the update device 3, checks the operation of the update device 3 after the activation process, and gives a rollback instruction when detecting a malfunction according to the proxy instruction signal transmitted from the update device 3.

[0036] The update device 3 functions as an OTA master that transmits the update program acquired from the external server S1 to the in-vehicle ECU 4 to be updated and transmits an activation instruction for applying the transmitted update program to the in-vehicle ECU 4. When applying the update program (activation process) to itself, the update device 3 functioning as an OTA master transmits a proxy instruction signal indicating an instruction for the proxy ECU 2 to perform the process of acting as an agent for the update device 3, and performs the activation process or the rollback process according to the instruction of the proxy ECU 2. The in-vehicle ECU 4 mounted on the vehicle C acquires the update program transmitted wirelessly from the external server S1 via the update device 3, and updates (reprograms) the program executed by its own ECU by applying the update program (activation process) according to the activation instruction.

[0037] Hereinafter, the program will be described as including program code containing control statements and the like for the in-vehicle ECU 4 to perform processing, and an external file in which data to be referred to when executing the program code is described. When transmitting the update program, the external file in which these program codes and data are described is transmitted from the external server S1 as, for example, an encrypted archive file. When transmitting the update program, the external server S1 generates a package including the update program, and transmits the generated package to the vehicle C. The package includes, for example, package information (campaign information) that is information regarding program update, information regarding the in-vehicle ECU 4 to be updated (target information), and the update program to be applied to the in-vehicle ECU 4 to be updated.

[0038] The vehicle C is equipped with an out-vehicle communication device 1, an update device 3, a display device (not shown), and a plurality of in-vehicle ECUs 4 for controlling various in-vehicle devices. The out-vehicle communication device 1 and the update device 3 are communicably connected by a harness such as a serial cable. The update device 3 and the in-vehicle ECU 4 are communicably connected by an in-vehicle network 5 compatible with a communication protocol such as CAN (Control Area Network) or Ethernet (registered trademark).

[0039] The out-vehicle communication device 1 includes an out-vehicle communication unit (not shown) and an input / output I / F (not shown) (interface) for communicating with the update device 3. The out-vehicle communication unit is a communication device for performing wireless communication using a protocol of mobile communication such as LTE (registered trademark), 4G, 5G, WiFi (registered trademark), and performs data transmission and reception with the external server S1 via an antenna 11 connected to the out-vehicle communication unit. The communication between the out-vehicle communication device 1 and the external server S1 is performed via an out-vehicle network N such as a public switched telephone network or the Internet.

[0040] The input / output I / F of the vehicle external communication device 1 is a communication interface for, for example, serial communication with the update device 3. The vehicle external communication device 1 and the update device 3 communicate with each other via a harness such as a serial cable connected between the input / output I / Fs. In the present embodiment, the vehicle external communication device 1 is a separate device from the update device 3, and these devices are communicably connected by the input / output I / F or the like, but it is not limited thereto. The vehicle external communication device 1 may be incorporated in the update device 3 as a component part of the update device 3. Alternatively, the vehicle external communication device 1 and the update device 3 may be connected by an in-vehicle network 5 such as CAN.

[0041] The proxy ECU 2 includes a control unit 20, a storage unit 21, and an in-vehicle communication unit 22. The proxy ECU 2 functions as, for example, a security device that monitors unauthorized communication except when a proxy instruction signal is transmitted from the update device 3. Note that the proxy ECU 2 may be incorporated in the vehicle external communication device 1 as a component part of the vehicle external communication device 1.

[0042] The control unit 20 of the proxy ECU 2 is configured by a CPU (Central Processing Unit) or an MPU (Micro Processing Unit) or the like, and reads and executes a control program P (program product) and data stored in advance in the storage unit to perform various control processes, arithmetic processes, and the like.

[0043] The storage unit 21 of the proxy ECU 2 is composed of a volatile memory element such as a RAM (Random Access Memory) or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory. The control program of the proxy ECU 2 is stored in the storage unit 21. Also, the update program acquired from the external server S1 is stored in the storage unit 21. The control program P (program product) stored in the storage unit 21 may store the control program P (program product) read from the recording medium 211 readable by the update device 3. Also, it may be the one that downloads the control program P from an external computer (not shown) connected to a communication network (not shown) and stores it in the storage unit. Also, the storage unit 21 of the proxy ECU 2 may store a flag value or a setting file indicating that it is an ECU having the function it proxies.

[0044] The in-vehicle communication unit 22 is an input / output interface using a communication protocol such as CAN or Ethernet (registered trademark). The control unit communicates with the vehicle exterior communication device 1 or the update device 3 connected to the vehicle exterior communication line 52 via the in-vehicle communication unit 22.

[0045] The update device 3 includes a control unit, storage units (first storage unit, second storage unit), an input / output I / F, and an in-vehicle communication unit (all not shown in the figure). The update device 3 is configured to acquire the update program (package) received by the vehicle exterior communication device 1 from the external server S1 by wireless communication from the vehicle exterior communication device 1 and transmit the update program to a predetermined in-vehicle ECU 4 (the in-vehicle ECU 4 to be updated) via the in-vehicle network 5. That is, the update device 3 functions as an OTA master (reprogram master) that controls the program update in the in-vehicle ECU 4 to be updated.

[0046] The update device 3 is, for example, a gateway (in-vehicle relay device) that integrates a plurality of bus (segment) systems such as the in-vehicle ECU 4 of the control system, the in-vehicle ECU 4 of the safety system, and the in-vehicle ECU 4 of the body system, and relays communication between these in-vehicle ECUs 4. That is, each of the in-vehicle communication lines 51 that make up these plurality of buses (segments) is connected to the update device 3, and the in-vehicle network 5 is configured by the plurality of in-vehicle communication lines 51 (segments) aggregated by the update device 3. The update device 3 functions as a CAN gateway in the relay of the CAN protocol and functions as a layer 2 switch or a layer 3 switch in the relay of the TCP / IP protocol. In addition to relaying communication, the update device 3 may also be a PLB (Power Lan Box) that functions as a power distribution device that distributes and relays the power output from a power supply device such as a secondary battery and supplies power to in-vehicle devices such as actuators connected to the device itself. Alternatively, the update device 3 may be configured as a functional part of a body ECU that controls the entire vehicle C. Alternatively, the update device 3 may be an integrated ECU configured by a central control device such as a vehicle computer and perform overall control of the vehicle C.

[0047] The control unit of the update device 3 is configured by a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), etc., and reads and executes the control program and data of the update device 3 stored in advance in the storage unit to perform various control processes and arithmetic processes, etc.

[0048] The storage unit of the update device 3 is composed of two storage areas, namely, a first storage unit and a second storage unit. Each of the first storage unit and the second storage unit is composed of a volatile memory element such as a RAM (Random Access Memory), or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory. The first storage unit and the second storage unit store in advance a control program and data to be referred to during processing. The control program is to be updated by an update program acquired from an external server S1. The control program stored in the storage unit (the first storage unit, the second storage unit) may store a control program (program product) read from a recording medium readable by the update device 3. Note that the control program may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit. Further, the storage unit of the update device 3 may store an ECU-ID, an IP address, etc. for specifying the proxy ECU, or a CAN-ID (which may substantially specify the in-vehicle device by a message ID) for communicating with the in-vehicle device (proxy ECU), etc.

[0049] In the storage unit (first storage unit, second storage unit) of the update device 3, information regarding the versions of two programs (control programs of the update device 3), namely the current version and the old version, and information regarding the area (operation aspect) in which the control program currently being executed (applied) is stored are stored. That is, when the control program stored in the first storage unit (first aspect) is being executed at present, the first storage unit stores that the operation aspect is the first storage unit (first aspect). In this case, the non-operation aspect is stored as the second storage unit (second aspect). The current version of the control program is stored in the first storage unit which is the operation aspect. The old version of the control program is stored in the second storage unit which is the non-operation aspect. Or, the second storage unit which is the non-operation aspect may be a storage area with free capacity and not store the old version of the control program or the like. By being in a state where the non-operation aspect is a storage area with free capacity or stores the old version of the control program or the like, it is possible to ensure a state where it can be reverted to the old version by writing the new version of the control program to the non-operation aspect during an update.

[0050] Similar to the input / output I / F of the vehicle exterior communication device 1, the input / output I / F of the update device 3 is, for example, a communication interface for serial communication. Through the input / output I / F, the update device 3 is communicably connected to the display device and the IG switch (not shown).

[0051] The in-vehicle communication unit of the update device 3 is an input / output interface using a communication protocol such as CAN or Ethernet (registered trademark), and the control unit communicates with in-vehicle devices such as the in-vehicle ECU 4 or other relay devices connected to the in-vehicle network 5 via the in-vehicle communication unit. A plurality of (four in this embodiment) in-vehicle communication units are provided, and three of the four in-vehicle communication units are each connected to an in-vehicle side communication line 51 (segment) constituting the in-vehicle network 5. By providing a plurality of in-vehicle communication units in this way, the in-vehicle network 5 is divided into a plurality of segments, and for example, according to the functions of the in-vehicle ECU 4 (control system function, safety system function, body system function), each in-vehicle ECU 4 is connected to each segment. Among the four in-vehicle communication units, an out-vehicle side communication line 52 is connected to the in-vehicle communication unit to which the in-vehicle side communication line is not connected, and the in-vehicle communication unit communicates with the out-vehicle communication device 1 or the proxy ECU 2 via the out-vehicle side communication line 52.

[0052] The in-vehicle ECU 4 includes a control unit, a storage unit, and an in-vehicle communication unit (not shown), similar to the proxy ECU 2. The storage unit is composed of a volatile memory element such as a RAM (Random Access Memory) or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, and stores the program or data of the in-vehicle ECU 4. Note that the storage unit of the in-vehicle ECU 4 is composed of two storage areas, a first storage area and a second storage area, similar to the storage unit of the update device 3. This program or data is the target to be updated by the update program transmitted from the program providing device and relayed by the update device 3. The in-vehicle communication unit of the in-vehicle ECU 4 is composed of, for example, a CAN transceiver or an Ethernet PHY unit, similar to the update device 3, and communicates with the update device 3 via the in-vehicle communication unit.

[0053] FIG. 3 is an explanatory diagram illustrating vehicle configuration information. The update device 3 communicates with all in-vehicle ECUs 4 mounted on the vehicle C (own vehicle) periodically, cyclically, or constantly, and acquires information regarding these in-vehicle ECUs 4. For example, when the IG switch is turned on, turned off, or at a predetermined timing, the update device 3 constantly requests all in-vehicle ECUs 4 or specific in-vehicle ECUs 4 mounted on the vehicle C to transmit the configuration information of their own ECUs and the update history of the configuration information. The update device 3 acquires the configuration information and the update history transmitted from each of the in-vehicle ECUs 4, aggregates these configuration information, etc., and stores the aggregated configuration information and the update history as vehicle configuration information.

[0054] The update device 3 may also acquire and aggregate the configuration information and the update history respectively spontaneously transmitted from each of the in-vehicle ECUs 4 without requesting the in-vehicle ECUs 4 to transmit the configuration information and the update history, and store them in the storage unit. Alternatively, the update device 3 may transmit an update program to the in-vehicle ECUs 4 and change the configuration information (vehicle configuration information) based on the transmitted update program each time the transmission is completed. The update device 3 generates vehicle configuration information in, for example, a table format by aggregating the information regarding each of these multiple in-vehicle ECUs 4 acquired from the in-vehicle ECUs 4, and stores it in the storage unit of its own device. The storage unit for storing the vehicle configuration information may store it redundantly in the first storage unit, the second storage unit, or both the first storage unit and the second storage unit.

[0055] As an example, the vehicle configuration information stored in a table format includes, as management items (fields), for example, the manufacturing number (serial number) of in-vehicle ECU 4, the ECU part number (model number), the Software part number, the current version of the program, the old version, the operation aspect, the status (reprogram status), the segment number, and the update target (campaign number). It is managed in association with an ECU-ID such as a serial number set so as not to duplicate in each in-vehicle ECU 4. In the management items of the ECU-ID, an identification number such as a serial number for uniquely identifying these in-vehicle ECUs 4 is stored in all the in-vehicle ECUs 4 mounted on vehicle C. Further, the vehicle configuration information may include, as management items (fields), the MAC (Media Access Control) address and the IP address of the in-vehicle ECU 4.

[0056] The manufacturing number (serial number) is a number assigned at the time of manufacturing the in-vehicle ECU 4, and is composed of a lot number indicating a production base or the like and a serial number at the time of manufacturing, and is a unique number that can uniquely identify the ECU. The ECU part number (model number) is a number for specifying the type of the in-vehicle ECU 4, and is, for example, a part number. The Software part number is a number for specifying the type of software of the update program (control program P to be updated). The update device 3 may identify the in-vehicle ECU 4 to be updated among the in-vehicle ECUs 4 mounted on the own vehicle by comparing the manufacturing number or the ECU part number included in the target information acquired from the external server S1 with the manufacturing number or the ECU part number included in the vehicle configuration information.

[0057] The current version is the version number of the program currently being executed (applied) by the in-vehicle ECU 4, and is the version number of the program stored in the operating area. The old version is the version number of the program that the in-vehicle ECU 4 previously executed (applied), and is the version number of the program stored in the non-operating area (memory area other than the operating area). The operating area is information that identifies any memory area (1st area: the first memory unit or 2nd area: the second memory unit) in which the program currently being executed (applied) by the in-vehicle ECU 4 is stored. These operation areas and version information are stored so as to be used when rolling back from the newly written program to the old version program at the time of update.

[0058] The status management item stores status information (reprogram status) regarding the application of the update program in the corresponding in-vehicle ECU 4 (ECU-ID of the same record). The update device 3 may communicate with the in-vehicle ECU 4 that is the destination of the activation instruction and update the status (status management item) of each individual in-vehicle ECU 4 by acquiring the status information (reprogram status) of the in-vehicle ECU 4. Thereby, the update device 3 can aggregate, store, and manage the status information (reprogram status) of each in-vehicle ECU 4 after the activation process. The update device 3 may refer to or update these data at the time of installation of the new version program, activation, and rollback process during update.

[0059] The segment number management item stores the number of the in-vehicle communication line 51 (segment) to which the corresponding in-vehicle ECU 4 is connected. The number of the in-vehicle communication line 51 (segment) corresponds to the number (communication port number) of each of the plurality of in-vehicle communication units provided in the update device 3. Thereby, the update device 3 can identify each individual in-vehicle ECU 4 directly connected to each in-vehicle communication unit 22 in the device via the in-vehicle communication line 51 (segment).

[0060] In the management items of the update target (campaign number), for example, the campaign number is stored in the in-vehicle ECU 4 that is the target of the current update (campaign). For example, when performing a group update in which a plurality of in-vehicle ECUs 4 are updated simultaneously, it is necessary to determine the consistency based on the set of versions of the plurality of in-vehicle ECUs 4 that are the update targets (campaign targets). On the other hand, in all the in-vehicle ECUs 4 mounted on the vehicle C, by storing the campaign number in the field of the in-vehicle ECU 4 that is the target of the current update (campaign), the in-vehicle ECU 4 that is the update target can be efficiently specified. As shown in the illustration in this embodiment, the field of the in-vehicle ECU 4 that is not the update target may be, for example, blank (store a null value). Further, information (ECU part number, software version, etc.) regarding a plurality of in-vehicle ECUs 4 in which the campaign number is stored in the update target field may be extracted and list management, etc. may be performed in a separate table.

[0061] FIG. 4 is an explanatory diagram illustrating the state transitions of the update device 3, the in-vehicle ECU 4 to be updated, the proxy ECU 2, etc. in the update process of the program according to Embodiment 1. In the update device 3 and the in-vehicle ECU 4 to be updated, the state before storing the update program and the state after storing are shown with the display forms reversed.

[0062] In the state before storing the update program (before rewriting), the update device 3 and the in-vehicle ECU 4 are executing the control program P stored on the operating surface. The update device 3 stores the update program for its own device acquired from the external server S1 on the non-operating surface of its own device, and transmits the update program for the in-vehicle ECU 4 to the in-vehicle ECU 4, whereby the update program is stored on the non-operating surfaces of the update device 3 and the in-vehicle ECU 4.

[0063] The update device 3 transmits a proxy instruction to the proxy ECU 2 and transmits an activation instruction to the in-vehicle ECU 4 to be updated. The proxy ECU 2 that has responded to the proxy instruction starts a processing sequence and transmits an activation instruction to the update device 3. After transmitting the activation instruction, the proxy ECU 2 detects whether there is an operational defect in the update device 3 that has performed the activation process.

[0064] When the proxy ECU 2 detects an operational defect in the update device 3 after the activation process (operational defect: present), the proxy ECU 2 transmits a rollback instruction to the update device 3. The update device 3 that has received the rollback instruction from the proxy ECU 2 performs a rollback process by executing the original program before applying the update program. The update device 3 that has performed the rollback process and executed the original program before applying the update program transmits a rollback instruction to the in-vehicle ECU 4 to be updated. Note that when the update device 3 also maintains a communication relay function during the update process, the proxy ECU 2 may transmit a rollback instruction to the in-vehicle ECU 4 via the relay function of the update device 3.

[0065] The update device 3 that has received the rollback instruction from the proxy ECU 2 performs a rollback process by executing the original program before applying the update program. As a result, the update device 3 and the in-vehicle ECU 4 execute the original program before the update program is applied.

[0066] By performing the activation process and rollback process in the update device 3 by the proxy ECU 2 in this way, the update device 3 and the in-vehicle ECU 4 to be updated are subject to the activation process and rollback process in two stages. On the other hand, a series of processes related to the program update to these update device 3 and in-vehicle ECU 4 are performed during a period when the vehicle C is prohibited from being in an activated state, such as during a period when engine start or traction motor drive is prohibited. By performing this during the prohibited period, it is possible to prevent engine start or the like from being performed in a state where a temporary inconsistency (version difference) occurs between the applied programs. When performing a series of processes related to the update program during a period when the vehicle C is prohibited from being in an activated state, the update device 3 may temporarily invalidate the on signal output from the IG switch via the input / output I / F or the like, for example, by performing mask processing or the like.

[0067] FIG. 5 is an explanatory diagram illustrating the flow (sequence) of processing by the update device 3, the in-vehicle ECU 4 to be updated, the proxy ECU 2, etc. according to Embodiment 1. When performing processing related to program update in the update device 3 (OTA master) and the in-vehicle ECU 4 to be updated using the update program, the processing sequences of the external server S1 (OTA server), the update device 3 (OTA master), the in-vehicle ECU 4 to be updated (target ECU), and the proxy ECU 2 will be described.

[0068] The update device 3 acquires the update program from the external server S1 (S01). The update device 3 accesses the external server S1, for example, using the identification number (VIN: Vehicle Identification Number) of the vehicle C (own vehicle) on which the device itself is mounted, and acquires a package including the update program applied to the own vehicle from the external server S1. The package includes, for example, package information (campaign information) which is information related to program update, information related to the update device 3 and the in-vehicle ECU 4 to be updated (target information), and the update program applied to the update device 3 and the in-vehicle ECU 4 which are the targets of the program update.

[0069] The update device 3 stores the update program for its own device (S02). The update device 3 stores the update program for its own device in a storage area (storage unit) that is a non-operating surface. The update device 3 includes a first storage unit and a second storage unit as storage areas for storing programs. For example, if the program currently being executed is in the first storage unit, the first storage unit corresponds to the operating surface. In this case, in the second storage unit, which is a non-operating surface, a program of an earlier version (old version) than the program currently being executed is stored as a backup. The update device 3 stores the update program for its own device acquired from the external server S1 in the second storage unit, which is a non-operating surface. As a result, the program currently being executed can maintain the state of being stored in the first storage unit without being overwritten.

[0070] The proxy ECU 2 acquires the update program from the external server S1 (S03). As described above, the proxy ECU 2 is connected to the same vehicle exterior communication line 52 as the vehicle exterior communication device 1. When the update program is transmitted from the external server to the update device 3 via the vehicle exterior communication line 52, the proxy ECU 2 can also receive the update program without passing through the update device 3. For example, when the update program from the external server is transmitted using multicast, a plurality of communication nodes including the proxy ECU 2 and the update device 3 may acquire the update program simultaneously. In this way, the proxy ECU 2 acquires the update program by checking the communication between the vehicle exterior communication device 1 and the update device 3 when the update device 3 acquires the update program. Note that in this embodiment, the proxy ECU 2 is assumed to receive the update program without passing through the update device 3, but it is not limited to this, and the proxy ECU 2 may acquire the update program from the update device 3.

[0071] The proxy ECU 2 transmits a request signal to the update device 3 (S04). The proxy ECU 2 determines whether the update device 3 is a target for update based on the acquired update program, and when the update device 3 is a target for update, outputs a request signal to the update device 3, requesting the update device 3 to start the process of proxying itself.

[0072] The update device 3 outputs (transmits) the update program for the in-vehicle ECU 4 to be updated to the in-vehicle ECU 4 (S05). The update device 3 identifies the in-vehicle ECU 4 to be updated based on the target information acquired from the external server S1, and transmits the update program for the identified in-vehicle ECU 4 to the in-vehicle ECU 4.

[0073] The in-vehicle ECU 4 to be updated stores (receives) the update program acquired from the update device 3 (S06). Similar to the update device 3, the in-vehicle ECU 4 to be updated stores the acquired update program on the non-operating side, thereby avoiding overwriting the program currently being executed (stored on the operating side).

[0074] The update device 3 transmits a proxy instruction signal to the proxy ECU 2 (S07). When the update device 3 has acquired (received) a request signal from the proxy ECU 2, the update device 3 transmits a proxy instruction signal indicating an instruction to perform the process of proxying the update device 3 to the proxy ECU 2 that transmitted the request signal.

[0075] The proxy ECU 2 that has responded to the proxy instruction signal from the update device 3 starts, for example, a processing routine for proxying the update device 3 using the proxy instruction signal as a trigger. As a result, the proxy ECU 2 functions as an activation instruction unit that gives an activation instruction to the update device 3, an abnormality detection unit, and a recovery control unit for the update device 3 that has performed the activation process.

[0076] The update device 3 outputs (transmits) an activation instruction to the in-vehicle ECU 4 to be updated (S08). The update device 3 outputs an activation instruction to each of the in-vehicle ECUs 4 to be updated, causing these in-vehicle ECUs 4 to execute the activation process.

[0077] The in-vehicle ECU 4 to be updated performs an activation process in response to the activation instruction output from the update device 3 (S09). The in-vehicle ECU 4 that has acquired (received) the activation instruction output from the update device 3 performs an activation process of applying the update program by restarting the storage area in which the update program is stored as an operation surface.

[0078] The proxy ECU 2 outputs (transmits) an activation instruction to the update device 3 (S10). The update device 3 performs an activation process in response to the activation instruction output from the proxy ECU 2 (S11). The update device 3 that has acquired (received) the activation instruction output from the proxy ECU 2 performs an activation process of applying the update program by restarting the storage area in which the update program is stored as an operation surface.

[0079] The proxy ECU 2 performs an operation confirmation (detection of operation failure) process on the update device 3 that has performed the activation process (S12). The proxy ECU 2 (abnormality detection unit) monitors, for example, the presence or absence of a periodic spontaneous transmission frame transmitted from the update device 3 after the activation process. When the spontaneous transmission frame is received, it is determined that the update device 3 after the activation process is normal, and when it cannot be received, it is determined to be abnormal (detection of operation failure). Alternatively, the proxy ECU 2 may send a test signal for detecting an operation failure to the update device 3 after the activation process and perform an operation confirmation (detection of operation failure) of the update device 3 based on whether or not a response signal to the test signal is received. That is, the proxy ECU 2 may determine that it is normal when a response signal to the test signal is received from the update device 3 after the activation process, and determine that it is abnormal (detection of operation failure) when it cannot be received.

[0080] The proxy ECU 2 outputs (transmits) a normal notification or a rollback instruction to the update device 3 according to the operation confirmation result (S13). When the operation confirmation result is normal, the proxy ECU 2 outputs (transmits) a normal notification to the update device 3. When the operation confirmation result of the proxy ECU 2 (recovery control unit) is abnormal (operation failure is detected), the proxy ECU 2 outputs (transmits) a rollback instruction to the update device 3. The rollback instruction corresponds to an abnormality notification indicating that the activation process (application of the update program) in the update device 3 has failed.

[0081] The update device 3 performs a rollback process based on the rollback instruction output from the proxy ECU 2 (S14). The update device 3 that has received the rollback instruction output from the proxy ECU 2 performs a rollback process by restarting to execute the program (original program) that was being executed before applying the update program (activation process). The original program is stored (backed up) as a backup in a storage area (non-operation area) different from the storage area (operation area) where the update program is stored. The update device 3 can perform a rollback process by restarting with the storage area where the original program is stored as the operation area, making the storage area where the update program is stored the non-operation area.

[0082] The update device 3 outputs (transmits) a rollback instruction to the in-vehicle ECU 4 to be updated (S15). When the update device 3 performs a rollback process on itself, it also outputs a rollback instruction to the in-vehicle ECU 4 to be updated, thereby eliminating the occurrence of inconsistencies due to differences in program versions, etc. between the update device 3 and the in-vehicle ECU 4.

[0083] When the update device 3 does not perform a rollback process on itself, that is, even when the activation process of the update device 3 is completed normally, if the activation process fails in any one of the in-vehicle ECUs 4 to be updated, the update device 3 outputs (sends) a rollback instruction to all the in-vehicle ECUs 4 to be updated. In this case, the update device 3 further performs a rollback process on itself. Thereby, it is possible to eliminate inconsistencies caused by differences in program versions and the like in the update device 3 and the in-vehicle ECU 4.

[0084] The in-vehicle ECU 4 to be updated performs a rollback process in response to the rollback instruction output from the update device 3 (S16). Similar to the update device 3, the in-vehicle ECU 4 to be updated performs a rollback process to return to the execution environment of the original program by switching the correspondence relationship between the operating surface and the non-operating surface in the storage area where the update program is stored and the storage area where the original program is stored and then restarting.

[0085] The update device 3 outputs (sends) the processing result regarding the update program to the external server S1 (S17). As a result of the processing regarding the update program, the update device 3 outputs (sends) to the external server S1 an update success notification indicating that the application of the update program to the update device 3 and the in-vehicle ECU 4 to be updated has been successful, or an update failure notification indicating that the application of the update program has failed and a rollback has occurred. The update device 3 may output the processing result regarding the update program to a display device and cause the display device to display the processing result. The update device 3 may modify the vehicle configuration information regarding the update device 3 and the in-vehicle ECU 4 to be updated based on the processing result of the update program.

[0086] In this embodiment, the proxy ECU 2 is assumed to proxy the program update process in the update device 3, but it is not limited thereto, and the proxy ECU 2 may proxy all of the program update processes in the update device 3 and the in-vehicle ECU 4 to be updated.

[0087] FIG. 6 is a flowchart illustrating the processing of the control unit 20 of the proxy ECU 2 and the control unit of the update device 3 according to Embodiment 1. The control unit of the update device 3 constantly performs the following processing, for example, when the vehicle C is in a stopped state (IG switch is off).

[0088] The control unit of the update device 3 acquires an update program from the external server S1 (S101). The control unit of the update device 3 stores the update program for its own device (S102). The control unit of the update device 3 acquires a package including the update program for its own device and the in-vehicle ECU 4 from the external server S1, and stores the update program for its own device in a non-operating storage area. For example, when the first storage unit 231 is the operating surface and the program currently being executed is stored, the control unit of the update device 3 stores the update program for its own device in the second storage unit 232 which is the non-operating surface.

[0089] The control unit 20 of the proxy ECU 2 acquires an update program from the external server S1 (S103). When the control unit 20 of the proxy ECU 2 determines that the update device 3 is the update target based on the acquired update program, it transmits a request signal to the update device 3 (S104). The control unit of the update device 3 receives the request signal from the proxy ECU 2 (S105).

[0090] The control unit of the update device 3 outputs (transmits) the update program for the in-vehicle ECU 4 to the in-vehicle ECU 4 to be updated (S106). The control unit of the update device 3 identifies the in-vehicle ECU 4 to be updated based on the target information included in the package acquired from the external server S1, and transmits the update program for the identified in-vehicle ECU 4 to the in-vehicle ECU 4.

[0091] The control unit of the update device 3 transmits an agency instruction signal to the proxy ECU 2 (S107), and the proxy ECU 2 receives the agency instruction signal from the update device 3 (S108). Then, the control unit of the update device 3 may stop the power supply to the in-vehicle communication unit 22 connected to the in-vehicle communication line 51 (segment) where the in-vehicle ECU 4 to be updated is not connected, thereby reducing the power consumption by the in-vehicle communication unit 22. A relay for controlling the supply and cut-off of power to each in-vehicle communication unit 22 provided in the update device 3 is provided, and the control unit of the update device 3 turns off the relay. Thereby, the power supply to the in-vehicle communication unit 22 connected to the in-vehicle communication line 51 (segment) where the in-vehicle ECU 4 to be updated is not connected may be stopped. Since the update process of the program needs to be performed during the engine stop period and consumes the power of a power storage device such as a lead battery, the power consumption can be reduced by stopping the energization of the in-vehicle communication unit 22.

[0092] The control unit of the update device 3 outputs (transmits) an activation instruction to the in-vehicle ECU 4 to be updated (S109). The control unit of the update device 3 outputs an activation instruction to each in-vehicle ECU 4 to be updated, and causes these in-vehicle ECUs 4 to execute the activation process.

[0093] The control unit 20 of the proxy ECU outputs an activation instruction to the update device 3 (S110), and the control unit of the update device 3 acquires (receives) the activation instruction from the proxy ECU 2 (S111). The control unit of the update device 3 performs an activation process in response to the activation instruction (S112). The control unit of the update device 3 executes (applies) the update program by performing the activation process, and upgrades the version of the control program P to be executed by the device itself. By executing the update program, the control unit of the update device 3 outputs predetermined data (frame or message) periodically or cyclically by broadcast or multicast, for example.

[0094] The proxy ECU 2 determines whether it has received predetermined data periodically transmitted from the update device 3 that has performed the activation process (applied the update program), and based on the determination result, determines whether an operation failure has occurred in the update device 3 after the activation process. Alternatively, the proxy ECU 2 may transmit a test signal to the update device 3 that has performed the activation process (applied the update program), and based on the presence or absence of a response from the update device 3, determine whether an operation failure has occurred in the update device 3 after the activation process. If the proxy ECU 2 determines that an operation failure has occurred in the update device 3 after the activation process, it outputs (transmits) a rollback instruction to the update device 3 (S113). If the proxy ECU 2 determines that no operation failure has occurred in the update device 3 after the activation process, it outputs (transmits) a normal notification to the update device 3.

[0095] The control unit of the update device 3 determines whether it has acquired (received) a rollback instruction from the proxy ECU 2 (S114). If the control unit of the update device 3 has acquired a rollback instruction from the proxy ECU 2 (S114: YES), it performs a rollback process (S115). When the control unit of the update device 3 has acquired a rollback instruction from the proxy ECU 2, it performs a rollback process by restarting to execute the program (original program) that was being executed before applying the update program (activation process).

[0096] When the rollback instruction is not obtained from the proxy ECU 2 (S114: NO), the control unit of the update device 3 determines whether the activation process of all in-vehicle ECUs 4 to be updated has been performed normally (S1141). When the control unit of the update device 3 does not obtain the rollback instruction from the proxy ECU 2, it determines that the application (activation process) of the update program in its own device has been completed normally. Alternatively, when the control unit of the update device 3 obtains a normal notification from the proxy ECU 2, it may also determine that the application (activation process) of the update program in its own device has been completed normally. Then, the control unit of the update device 3 determines whether the application (activation process) of the update program in all in-vehicle ECUs 4 to be updated has been completed normally. The control unit of the update device 3 may determine whether the activation process of each of these in-vehicle ECUs 4 has been completed normally based on, for example, whether response data to the test communication data transmitted to each of the in-vehicle ECUs 4 to be updated has been received.

[0097] When it is determined that the activation process of all in-vehicle ECUs 4 to be updated has not been performed normally, that is, when it is determined that the activation process has not been performed normally for any one of the in-vehicle ECUs 4 among the in-vehicle ECUs 4 to be updated (S1141: NO), or after performing the rollback process of its own device (S115), a rollback instruction is output (transmitted) to the in-vehicle ECUs 4 to be updated (S116). The in-vehicle ECUs 4 to be updated perform the rollback process in response to the rollback instruction output from the update device 3.

[0098] When it is determined that the activation process of all in-vehicle ECUs 4 to be updated has been performed normally (S1141: YES), or after an instruction to roll back is output to the in-vehicle ECU 4 to be updated (S116), the control unit of the update device 3 outputs (transmits) the processing result regarding the update program to the external server S1 (S117). The control unit of the update device 3 may output the processing result regarding the update program to the external server S1 and the display device, and further correct the vehicle configuration information regarding the update device 3 and the in-vehicle ECU 4 to be updated based on the processing result. Also, after the processing unit of the update device 3 outputs (transmits) the update program for the in-vehicle ECU 4 to be updated to the in-vehicle ECU 4 to be updated, it determines whether the activation process of all in-vehicle ECUs 4 to be updated has been performed normally. If the activation process has been performed normally, a proxy instruction signal may be transmitted to the proxy ECU 2.

[0099] (Embodiment 2) FIG. 7 is a schematic diagram illustrating the configuration of the in-vehicle update system S according to Embodiment 2. The proxy ECU according to Embodiment 2 is connected to the in-vehicle communication line 51. Also, the update device 3 according to Embodiment 1 does not hold a communication relay function during the update of its own device, and the proxy ECU 2 and the in-vehicle ECU 4 could not communicate, but it is not limited to this. The update device 3 according to the present embodiment holds a communication relay function during the update of its own device, and the in-vehicle ECU 4 connected to another in-vehicle communication line 51 (segment) different from the in-vehicle communication line 51 (segment) to which the proxy ECU 2 and the proxy ECU are connected can communicate via the relay function.

[0100] FIG. 8 is an explanatory diagram illustrating the state transition of the update device 3, the in-vehicle ECU 4 to be updated, the proxy ECU 2, etc. in the program update process according to Embodiment 2. When the proxy ECU 2 detects an operation failure in the update device 3 after the activation process (operation failure: yes), the proxy ECU 2 transmits an instruction to roll back to the update device 3 and also transmits an instruction to roll back to the in-vehicle ECU 4 via the relay function of the update device 3. As shown in FIG. 8, according to the present embodiment, it is possible to roll back the update device 3 and the in-vehicle ECU 4 by a one-step rollback instruction by the proxy ECU 2.

[0101] FIG. 9 is an explanatory diagram illustrating the processing flow (sequence) by the update device 3, the in-vehicle ECU 4 to be updated, the proxy ECU 2, etc. according to Embodiment 2. S21 to S32 are the same processes as S01, S02, and S05 to S14 in FIG. 5. The proxy ECU 2 outputs a rollback instruction to the update device 3 (S31), and at the same time as or after the output, outputs a rollback instruction to the in-vehicle ECU 4 (S33). The in-vehicle ECU 4 performs a rollback process in response to the rollback instruction output from the proxy ECU 2 (S34). The update device 3 outputs (transmits) the processing result regarding the update program to the external server S1 (S35).

[0102] FIG. 10 is a flowchart illustrating the processing of the control unit 20 of the proxy ECU 2 and the control unit of the update device 3 according to Embodiment 1. S201 to S211 are the same processes as S101, S102, and S106 to S114 in FIG. 6. The control unit 20 of the proxy ECU 2 outputs a rollback instruction to the update device 3 (S210), and then outputs a rollback instruction to the in-vehicle ECU 4 via the relay function of the update device 3 (S213).

[0103] When the control unit of the update device 3 does not acquire a rollback instruction from the proxy ECU 2 (S211: NO), it determines whether the activation process of all the in-vehicle ECUs 4 to be updated has been performed normally (S2111). When it is determined that the activation process of all the in-vehicle ECUs 4 to be updated has been performed normally (S2111: YES), the control unit of the update device 3 outputs (transmits) the processing result regarding the update program to the external server S1 (S214). When it is determined that the activation process of all the in-vehicle ECUs 4 to be updated has not been performed normally, that is, when it is determined that the activation process has not been performed normally for any one of the in-vehicle ECUs 4 to be updated (S2111: NO), the processing unit of the update device 3 outputs a rollback instruction to the in-vehicle ECU 4 (S2112), and outputs (transmits) the processing result regarding the update program to the external server S1 (S214).

[0104] According to the above processing, if the activation process of the update device 3 is not performed normally, the proxy ECU 2 outputs a rollback instruction to the update device 3 and the in-vehicle ECU 4. If the activation process of the update device 3 is performed normally and the activation process of the in-vehicle ECU 4 is not performed normally, the update device 3 outputs a rollback instruction to the in-vehicle ECU 4. Thereby, it is possible to efficiently perform the rollback process according to the situation.

[0105] The embodiments disclosed this time should be considered as illustrative in all respects and not restrictive. The technical features described in each embodiment can be combined with each other, and the scope of the present invention is intended to include all modifications within the scope of the claims and the scope equivalent to the claims.

[0106] Regarding the embodiments including the above Embodiment 1 or 2, the following supplementary notes are further disclosed.

[0107] (Supplementary Note 1) An in-vehicle update system including an update device that performs processing for updating a program of an in-vehicle ECU mounted on a vehicle with an update program acquired from an external server outside the vehicle, and an in-vehicle device communicably connected to the update device, wherein the in-vehicle device includes a control unit that performs processing for updating a program in the update device, and when the update device is included in an update target by the update program, the control unit is an in-vehicle update system that proxies at least a part of the processing for updating performed by the update device.

[0108] In this aspect, the update device can smoothly perform the program update process in the update device by having the in-vehicle device (proxy ECU) take charge of the program update (application of the update program, etc.) in the self-device.

Explanation of Signs

[0109] C Vehicle S In-vehicle update system S1 External server (OTA server) S11 Memory unit N External vehicle network 1 External vehicle communication device 2 Agent ECU (in-vehicle device) 20 Control unit 21 Memory unit 211 Recording medium 22 In-vehicle communication section P Control program (program product) 3 Update device (OTA master) 4 In-vehicle ECU 5 In-vehicle network 51 In-vehicle side communication line (segment) 52 Out-vehicle side communication line

Claims

1. An in-vehicle device communicably connected to an update device that performs a process for updating a program of an in-vehicle ECU mounted on a vehicle by an update program acquired from an external server outside the vehicle, comprising a control unit that performs a process for updating a program in the update device, wherein the control unit, when the update device is included in an update target by the update program, proxies at least a part of the process performed by the update device In-vehicle device.

2. The process to be proxied includes an activate process of applying the update program acquired by the update device to the update device itself The in-vehicle device according to claim 1.

3. The process to be proxied includes a rollback process according to the result of the activate process The in-vehicle device according to claim 1 or claim 2.

4. In the storage unit of the update device, information for specifying the in-vehicle device as a proxy ECU that performs the process to be proxied is stored in advance The in-vehicle device according to any one of claims 1 to 3.

5. The control unit, acquires an instruction signal indicating an instruction to perform the process to be proxied from the update device, and starts the process to be proxied according to the acquired instruction signal The in-vehicle device according to any one of claims 1 to 4.

6. The process to be proxied includes a process for updating the program of the in-vehicle ECU, the update device has a relay function for relaying data transmitted and received between in-vehicle ECUs, the control unit, when the update device is included in an update target by the update program, varies the process for updating the program of the in-vehicle ECU according to whether the update device maintains the relay function The in-vehicle device according to any one of claims 1 to 5.

7. The update device is connected to a communication line on the external server side and a communication line on the in-vehicle ECU side, connected to the communication line on the external server side The in-vehicle device according to any one of claims 1 to 6.

8. The control unit, acquires the update program from an external server without going through the update device, and outputs a request signal to request the update device to start the process to be proxied based on the acquired update program The in-vehicle device according to claim 7.

9. A vehicle external communication device for wireless communication with an external server is connected to the communication line on the external server side, included in the vehicle external communication device The in-vehicle device according to claim 7 or claim 8.

10. A computer communicably connected to an update device that performs a process for updating a program of an in-vehicle ECU mounted on a vehicle with an update program acquired from an external server outside the vehicle, performs a process for updating the program in the update device, and when the update device is included in an update target by the update program, substitutes at least a part of the process for updating performed by the update device A program for causing the process to be executed.

11. A computer communicably connected to an update device that performs a process for updating a program of an in-vehicle ECU mounted on a vehicle with an update program acquired from an external server outside the vehicle, performs a process for updating the program in the update device, and when the update device is included in an update target by the update program, substitutes at least a part of the process for updating performed by the update device A method for updating a program for causing the process to be executed.

Citation Information

Patent Citations

  • Management device

    JP2010170304A

  • Relaying apparatus and method and program for relaying

    JP2017097851A

  • On-vehicle update system, on-vehicle update device and gateway

    JP2018076040A

  • Update control system for program and update control method for program

    JP2018081470A

  • On-vehicle communication system, domain master, and firmware updating method

    JP2018120422A