Software Update Device, Update Control Method, Update Control Program, and Server
By adjusting the consent request timing based on the ECU's non-volatile memory type, the software update device ensures synchronized approval processes, addressing the variability in update timing and enhancing update efficiency.
Patent Information
- Application Number
- JP2023100346
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-19
- Publication Date
- 2025-06-18
- Estimated Expiration
- 2040-07-20
AI Technical Summary
The timing for seeking user or administrator approval during software updates for electronic control units (ECUs) varies depending on the specifications of the non-volatile memory, making it challenging to synchronize the approval process with the update process.
A software update device and method that dynamically adjust the timing of the consent request based on the type of non-volatile memory in the ECU, ensuring that approval is sought at appropriate stages of the update process, whether before installation or activation.
This approach allows for flexible timing of user consent during software updates, aligning it with the specific memory type of the ECU, thereby enhancing the efficiency and reliability of the software update process.
Smart Images

Figure 0007694606000001 
Figure 0007694606000002 
Figure 0007694606000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a software update device, an update control method, an update control program, and a server for controlling software updates of an electronic control unit.
Background Art
[0002] Vehicles are equipped with a plurality of electronic control units (ECUs) for controlling the operation of the vehicle. An ECU includes a processor, a temporary storage unit such as a RAM, and a non-volatile storage unit such as a flash ROM, and the processor realizes the control function of the ECU by executing software stored in the non-volatile storage unit. The software stored in each ECU is rewritable, and by updating to a newer version of the software, the functions of each ECU can be improved or new vehicle control functions can be added.
[0003] As a technology for updating the software of an ECU, an in-vehicle communication device connected to an in-vehicle network is wirelessly connected to a communication network such as the Internet, software is downloaded from a server via wireless communication, and the downloaded software is installed to perform program updates and additions to the ECU. The OTA (Over The Air) technology is known (see, for example, Patent Document 1).
[0004] As non-volatile memories (storage units) mounted on an ECU, there are a memory (single-sided memory) having one storage area for storing software and a memory (double-sided memory) having two storage areas for storing software, and they are selectively used according to the specifications of the ECU and the like. An ECU equipped with a double-sided memory can store old and new two versions of a program in two storage areas.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
SUMMARY OF THE INVENTION
PROBLEMS TO BE SOLVED BY THE INVENTION
[0006] The software update process by OTA includes a phase in which a software update device downloads update data from a server, a phase in which the downloaded update data is transferred to an electronic control unit to be updated and the update data is installed in a storage area of the electronic control unit to be updated, and a phase in which the updated software is activated in the electronic control unit to be updated.
[0007] In the ECU equipped with the above-mentioned two-sided memory, while maintaining the current software stored in one storage area, an updated version of the software can be installed in the other storage area. On the other hand, in the ECU equipped with the above-mentioned one-sided memory, the current software stored in the storage area is rewritten by the updated version of the software when the updated version of the software is installed.
[0008] When performing software update by OTA, it is necessary to notify the user or administrator of the vehicle functions changed by the software update and the function restrictions that occur during the software update process, and seek the approval of the user or administrator.
[0009] However, since the timing at which the electronic control unit to be updated is affected is as described above , and it varies depending on the specifications of the non-volatile memory installed in the electronic control unit, there is room for consideration regarding the timing for seeking approval.
[0010] Therefore, an object of the present disclosure is to provide a software update device, an update control method, an update control program, and a server that can change the approval timing at the time of software update according to the specifications of the electronic control unit.
MEANS FOR SOLVING THE PROBLEMS
[0011] The software update device according to the present disclosure controls the software update of an electronic control unit mounted on a vehicle. When the electronic control unit is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installing the updated software, after the updated software is downloaded and before it is installed, a consent request for activating the updated software is executed. When the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installing the updated software , Approval Based on information indicating whether to execute the consent request , Whether to execute the approval request at the timing before installation execution It includes a control unit that controls.
[0012] The update control method according to the present disclosure is executed by a computer including a processor, a memory, and a storage device to control the software update of an electronic control unit. When the electronic control unit is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installing the updated software, after the updated software is downloaded and before it is installed, a consent request for activating the updated software is executed. When the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installing the updated software , Approval Based on information indicating whether to execute the consent request , At the timing before installation execution Execute the consent request.
[0013] The update control program according to the present disclosure is executed by a computer including a processor, a memory, and a storage device to control software updates of an electronic control unit. When the electronic control unit is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installation of the updated software, after the updated software is downloaded and before it is installed, executing a consent request step of requesting consent to activate the updated software; when the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installation of the updated software , Approval Based on information indicating whether to execute the consent request , At the timing before installation execution including the step of executing the consent request.
[0014] When the electronic control unit to be software-updated is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installation of the updated software, the server according to the present disclosure transmits to the vehicle information for executing a consent request for requesting consent to activate the updated software before the updated software is installed. When the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installation of the updated software , At the timing before installation execution It includes a communication unit that transmits to the vehicle information indicating whether to execute the consent request. [Effect of the Invention]
[0015] According to the present disclosure, it is possible to provide a software update device, an update control method, an update control program, and a server that can change the user consent timing at the time of software update according to the specifications of the electronic control unit. [Brief Description of the Drawings]
[0016] , [Figure 1] Block diagram showing the overall configuration of the network system according to the embodiment , [Figure 2] Block diagram showing the schematic configuration of the server shown in FIG. 1 , [Figure 3] Block diagram showing the schematic configuration of the software update device shown in FIG. 1 , [Figure 4A] Block diagram showing the schematic configuration of the electronic control unit , [Figure 4B] Block diagram showing the schematic configuration of the electronic control unit , [Figure 5] Functional block diagram of the server shown in FIG. 1 , [Figure 6] Functional block diagram of the software update device shown in FIG. 1 , [Figure 7] Flowchart showing an example of the control process executed by the server according to the first embodiment , [Figure 8] Flowchart showing an example of the control process executed by the software update device according to the first embodiment , [Figure 9] Flowchart showing the details of the installation / activation process shown in FIG. 8 , [Figure 10] Flowchart showing an example of the control process executed by the server according to the second embodiment , [Figure 11] Flowchart showing an example of the control process executed by the software update device according to the second embodiment
Mode for Carrying Out the Invention
[0017] (First Embodiment) FIG. 1 is a block diagram showing the overall configuration of the network system according to the embodiment, FIG. 2 is a block diagram showing the schematic configuration of the server shown in FIG. 1, and FIG. 3 is a block diagram showing the schematic configuration of the software update device shown in FIG. 1.
[0018] The network system shown in FIG. 1 is a system for updating the software of the electronic control units 13a to 13d mounted on a vehicle, and includes a server 1 (center) and an in-vehicle network 2 mounted on the vehicle.
[0019] The server 1 can communicate with a software update device 11 mounted on the vehicle via a network 5, and manages the software update of the electronic control units 13a to 13d mounted on the vehicle.
[0020] As shown in FIG. 2, the server 1 includes a CPU 21, a RAM 22, a storage device 23, and a communication device 24. The storage device 23 includes a readable and writable storage medium such as a hard disk or an SSD, and stores a program for executing software update management, information used for update management, and update data of the electronic control unit. In the server 1, the CPU 21 executes the control process described later by executing the program read from the storage device 23 using the RAM 22 as a work area. The communication device 24 is a device that communicates with the software update device 11 via a network.
[0021] The in-vehicle network 2 includes a software update device 11 (OTA master), a communication module 12, a plurality of electronic control units 13a to 13d, and a display device 14. The software update device 11 is connected to the communication module 12 via a bus 15a, connected to the electronic control units 13a and 13b via a bus 15b, connected to the electronic control units 13c and 13d via a bus 15c, and connected to the display device 14 via a bus 15d. The software update device 11 can communicate wirelessly with the server 1 via the communication module 12. The software update device 11 controls the software update of the electronic control unit to be updated among the electronic control units 13a to 13d based on the update data acquired from the server 1. The software update device 11 may be referred to as a central gateway. The communication module 12 is a communication device that connects the in-vehicle network 2 and the server 1. The electronic control units 13a to 13d are ECUs that control the operations of each part of the vehicle. The display device 14 (HMI) is used to perform various displays such as displaying that there is update data, displaying a consent request screen for requesting consent from the user or administrator for software update, and displaying the update result during the software update process of the electronic control units 13a to 13d. As the display device 14, typically, the display device of a car navigation system can be used, but it is not particularly limited as long as it can display the information necessary during the program update process. In FIG. 1, four electronic control units 13a to 13d are illustrated, but the number of electronic control units is not particularly limited. Also, in addition to the display device 14, other electronic control units may be further connected to the bus 15d shown in FIG. 1.
[0022] As shown in FIG. 3, the software update device 11 includes a microcomputer 35 including a CPU 31, a RAM 32, a ROM 33, and a storage device 34, and a communication device 36. In the software update device 11, the CPU 31 of the microcomputer 35 reads a program read from the ROM 33 and executes it using the RAM 32 as a work area, thereby executing control processing described later. The communication device 36 is a device that communicates with the communication module 12, the electronic control units 13a to 13d, and the display device 14 via the buses 15a to 15d shown in FIG. 1.
[0023] FIGS. 4A and 4B are block diagrams showing a schematic configuration of the electronic control unit.
[0024] The electronic control unit 13a shown in FIG. 4A includes a CPU 41, a RAM 42, a non-volatile memory 43a, and a communication device 44. The CPU 41 realizes the functions of the electronic control unit 13a by reading a program read from the non-volatile memory 43a and executing it using the RAM 42 as a work area. The non-volatile memory 43a has one storage area 45 for storing software. Hereinafter, the type of the non-volatile memory 43a having this configuration is referred to as "the first type". In addition to the software for realizing the functions of the electronic control unit 13a, version information, parameter data, a boot program for startup, a program for software update, etc. may be stored in the storage area 45. The communication device 44 is a device that communicates with the software update device 11, other electronic control units 13b to 13d connected to the in-vehicle network 2, and the display device 14.
[0025] The electronic control unit 13b shown in FIG. 4B includes a CPU 41, a RAM 42, a non-volatile memory 43b, and a communication device 44, similar to the electronic control unit 13a. However, the non-volatile memory 43b mounted on the electronic control unit 13b has two storage areas 46a and 46b for storing programs. Hereinafter, the type of the non-volatile memory 43b with this configuration is referred to as the "second type". In addition to the software for realizing the functions of the electronic control unit 13a, the storage areas 46a and 46b may store version information, parameter data, a boot program for startup, a program for software update, etc. The CPU 41 of the electronic control unit 13b designates one of the two storage areas 46a and 46b of the non-volatile memory 43b as the storage area to be read (operation aspect), and executes the software stored in the storage area to be read. In the other storage area (non-operation aspect) that is not the read target, update data can be written in the background during the execution of the program in the storage area to be read (operation aspect). At the time of activation in the software update process, the updated software can be activated by switching the storage area to be read by the CPU 41 for the program. As a specific example, assume that the current software is stored in the storage area 46a and the updated software is installed in the storage area 46b. When the activation of the updated software is instructed from the software update device 11, for example, by switching the read start address of the CPU 41 from the head address of the storage area 46a to the head address of the storage area 46b, the storage area to be read (operation aspect) of the CPU 41 is switched, and the updated software installed in the storage area 46b can be executed. In the present disclosure, a configuration called a "one-sided suspend memory" in which one-sided storage area is virtually partitioned into two sides and a program can be written to the other side during the execution of the program on one side is also classified as a second type of memory.
[0026] FIG. 5 is a functional block diagram of the server shown in FIG. 1.
[0027] Server 1 includes a storage unit 26, a communication unit 27, and a control unit 28. The communication unit 27 and the control unit 28 are realized by the CPU 21 shown in FIG. 2 executing a program stored in the storage device 23 using the RAM 22, and the storage unit 26 is realized by the storage device 23 shown in FIG. 2.
[0028] The storage unit 26 stores update management information associating information indicating software that can be used by one or more electronic control units mounted on a vehicle with each vehicle identification information (vehicle ID) for identifying the vehicle, and update data of the software of the electronic control unit. As information indicating software that can be used by the electronic control unit, for example, a combination of the latest version information of the software of each of the plurality of electronic control units is defined.
[0029] The communication unit 27 can receive an update confirmation request for software from the software update device 11. The update confirmation request is, for example, information transmitted from the software update device 11 to the server 1 when the power or ignition is turned on in the vehicle, and is information for requesting the server 1 to confirm whether there is update data for the electronic control unit. Further, the communication unit 27 receives a transmission request (download request) for a distribution package from the software update device 11. When the communication unit 27 receives a download request for the distribution package, it transmits a distribution package including update data of the software of the electronic control unit to the software update device 11. When the communication unit 27 receives an update confirmation request, the control unit 28 determines whether there is update data for the software of the vehicle specified by the vehicle ID included in the update confirmation request based on the update management information stored in the storage unit 26. When the control unit 28 determines that there is update data for the electronic control unit, when it receives a download request for a distribution package from the software update device 11, it generates a distribution package including the update data stored in the storage unit 26.
[0030]
[0031] FIG. 6 is a functional block diagram of the software update device shown in FIG. 1.
[0032] The software update device 11 includes a storage unit 37, a determination unit 38, a communication unit 39, and a control unit 40. The storage unit 37 is realized by the storage device 34 shown in FIG. 3, and the determination unit 38, the communication unit 39, and the control unit 40 are realized by the CPU 31 shown in FIG. 3 executing a program stored in the ROM 33 using the RAM 32.
[0033] The storage unit 37 stores whether the type of the non-volatile memory mounted on each of the electronic control units 13a to 13d is the first type or the second type. Information (type information) regarding the type of the non-volatile memory mounted on the electronic control unit may be created in advance based on the specifications of the electronic control units constituting the in-vehicle network 2 and stored in the storage unit 37 at the time of vehicle manufacture. Alternatively, at the time of software update processing, the communication unit 39 described later may acquire the type of the non-volatile memory of the electronic control unit to be updated through communication within the in-vehicle network 2.
[0034] The determination unit 38 determines, at the time of software update processing, whether the non-volatile memory mounted on the electronic control unit to be updated is a first-type memory having one storage area or a second-type memory having two storage areas. The determination of the type of the non-volatile memory by the determination unit 38 can be performed based on the type information of the non-volatile memory stored in the storage unit 37. As described above, the non-volatile type information stored in the storage unit 37 may be created in advance at the time of vehicle manufacture or the like, or may be created based on the type of the non-volatile memory acquired from the electronic control unit to be updated at the time of software update processing.
[0035] The communication unit 39 transmits a software update check request to the software update device 11, for example, when the power or ignition of the vehicle is turned on. The update check request includes a vehicle ID for identifying the vehicle and the software versions of the electronic control units 13a to 13d connected to the in-vehicle network 2. The vehicle ID and the software versions of the electronic control units 13a to 13d are used to determine whether or not there is update data for the software of the electronic control units by comparing them with the latest software version held by the server 1 for each vehicle ID. Furthermore, the communication unit 39 receives a notification indicating the presence or absence of update data from the server 1 as a response to the update check request. If there is update data for the software of the electronic control units, the communication unit 39 transmits a download request for a distribution package to the server 1 and receives the distribution package transmitted from the server 1. In addition to the update data, the distribution package may include verification data for verifying the authenticity of the update data, the number of update data, the installation order, various control information used during software update, and the like. Furthermore, the type information of the non-volatile memory of the electronic control unit during software update processing is also used. When obtaining the type information from the electronic control unit to be updated, the communication unit 39 obtains the type information by communicating with the electronic control unit to be updated.
[0036] The control unit 40 determines whether or not there is update data for the software of the electronic control unit based on the response to the update confirmation request received by the communication unit 39. The control unit 40 verifies the authenticity of the distribution package that the communication unit 39 received from the server 1 and stored in the storage unit 37. The control unit 40 transfers the one or more downloaded update data to the electronic control unit to be updated, and causes the update data to be installed in the electronic control unit to be updated. After the installation is completed, the control unit 40 instructs the electronic control unit to be updated to activate the installed updated version of the software.
[0037] Here, when the non-volatile memory of the electronic control unit is of the first type, installation and activation are performed continuously. Therefore, before executing the installation, a commitment request process is performed to request the user's or administrator's commitment to the software update. When the non-volatile memory of the electronic control unit is of the second type, at least after the execution of the installation and before the execution of the activation, a commitment request process for the software update is performed. When the non-volatile memory of the electronic control unit is of the second type, a commitment request process for the software update may be performed or omitted before the execution of the installation.
[0038] In the commitment request process, the control unit 40 causes the output device to output a notification indicating that commitment is required for the software update and a notification prompting an input indicating that the software update has been committed. As the output device, a display device 14 provided in the in-vehicle network 2, an audio output device that performs audio notification, or the like can be used. For example, when the display device 14 is used as the output device in the commitment request process, the control unit 40 causes the display device 14 to display a commitment request screen for requesting commitment to the software update, and causes the display device 14 to display a notification prompting a specific input operation such as pressing a commitment button when the user or administrator makes a commitment. Further, in the commitment request process, the control unit 40 causes the display device 14 to display a statement, an icon, or the like notifying that there is software update data of the electronic control unit, or causes the display device 14 to display limitations during the execution of the software update process.
[0039] The control unit 40 performs the commitment request process at a timing according to the memory type of the electronic control unit to be updated. When receiving an input indicating that the user or administrator has made a commitment, the control unit 40 executes the above-described control processes for installation and activation, and updates the software of the electronic control unit to be updated.
[0040] Here, the software update process consists of a phase of downloading update data from Server 1, a phase of transferring the downloaded update data to the electronic control unit to be updated and installing the update data in the storage area of the electronic control unit to be updated, and a phase of activating the updated version of the software installed in the electronic control unit to be updated.
[0041] Downloading is a process of receiving and storing the update data for updating the software of the electronic control unit, which is transmitted from Server 1. In the downloading phase, not only the reception of the update data but also a series of controls related to downloading, such as determining the feasibility of downloading and verifying the update data, are included. Installation is a process of writing the updated version of the program (updated software) to the storage unit of the in-vehicle device in the electronic control unit to be updated based on the downloaded update data. In the installation phase, not only the execution of the installation but also a series of controls related to installation, such as determining the feasibility of installation, transferring the update data, and verifying the updated version of the program, are included. Activation is a process of activating (activating) the installed updated version of the program. The control for activation includes not only the execution of activation but also a series of controls related to activation, such as determining the feasibility of activation and verifying the execution result.
[0042] The update data transmitted from Server 1 to the software update device 11 may include any of the updated software of the electronic control unit, the compressed data obtained by compressing the updated software, and the split data obtained by splitting the updated software or the compressed data. Further, the update data may include an identifier (ECU ID) for identifying the electronic control unit to be updated and an identifier (ECU software ID) for identifying the software before the update. The update data is downloaded as the above-described distribution package, and the distribution package includes the update data for single or multiple electronic control units.
[0043] When the update data includes the update software itself, during the installation phase, the software update device transfers the update data (update software) to the electronic control unit to be updated. Also, when the update data includes compressed data, differential data, or split data of the update software, the software update device 11 may transfer the update data to the electronic control unit to be updated, and the electronic control unit to be updated may generate the update software from the update data, or the software update device 11 may generate the update software from the update data and then transfer the update software to the electronic control unit to be updated. Here, the generation of the update software can be performed by decompressing the compressed data, assembling the differential data or split data.
[0044] The installation of the update software can be performed by the electronic control unit to be updated based on an installation request from the software update device 11. Alternatively, the electronic control unit to be updated that has received the update data may perform the installation autonomously without receiving an explicit instruction from the software update device 11.
[0045] The activation of the update software can be performed by the electronic control unit to be updated based on an activation request from the software update device 11. Alternatively, the electronic control unit to be updated that has received the update data may perform the activation autonomously without receiving an explicit instruction from the software update device 11.
[0046] In addition, the software update process can be performed continuously or in parallel for each of a plurality of electronic control units.
[0047] Also, the "program update process" in this specification includes not only a process that continuously performs all of download, installation, and activation, but also a process that performs only a part of download, installation, and activation.
[0048] FIG. 7 is a flowchart showing an example of control processing executed by the server according to the first embodiment. The control processing shown in FIG. 7 is repeatedly executed, for example, at a predetermined time interval.
[0049] In step S1, the communication unit 27 determines whether it has received an update confirmation request from the software update device 11. If the determination in step S1 is YES, the process proceeds to step S2; otherwise, the process proceeds to step S3.
[0050] In step S2, the communication unit 27 transmits information indicating whether there is software update data for the electronic control unit to the vehicle that has sent the update confirmation request. Whether there is update data can be determined, for example, by the control unit 28 comparing the combination of software versions stored in the update management information associated with the vehicle ID included in the update confirmation request with the combination of the current software versions included in the update confirmation request, and when the combination of the current software versions included in the update confirmation request is older than the combination of the versions stored in the update management information, it can be determined that there is update data. Then, the process proceeds to step S3. In step S3, the communication unit 27 determines whether it has received a download request for the distribution package from the software update device 11. If the determination in step S3 is YES, the process proceeds to step S4; otherwise, the process proceeds to step S1.
[0051] In step S4, the communication unit 27 transmits a distribution package including software update data to the software update device 11. Then, the process proceeds to step S1.
[0052] In step S4, the communication unit 27 transmits a distribution package including software update data to the software update device 11. Then, the process proceeds to step S1.
[0053] FIG. 8 is a flowchart showing an example of control processing executed by the software update device according to the first embodiment. The control processing shown in FIG. 8 is executed, for example, triggered by the vehicle's power or ignition being turned on.
[0054] In step S11, the communication unit 39 transmits an update confirmation request including a combination of the vehicle ID and the version of the software of the electronic control unit to the server 1. Then, the process proceeds to step S12.
[0055] In step S12, the communication unit 39 receives a confirmation result from the server 1. Then, the process proceeds to step S13.
[0056] In step S13, based on the response from the server 1 to the update confirmation request transmitted in step S1, the control unit 40 determines whether there is software update data for the electronic control units 13a to 13d. If the determination in step S13 is YES, the process proceeds to step S14; otherwise, the process ends.
[0057] In step S14, the communication unit 39 executes a download process. More specifically, the communication unit 39 transmits a download request for the distribution package to the server 1, receives the distribution package transmitted in response to the download request, and stores the received distribution package in the storage unit 37. The control unit 40 verifies the authenticity of the update data included in the received distribution package. In step S14, it may also determine whether the download can be executed and notify the server 1 that the download is complete. Then, the process proceeds to step S15.
[0058] In step S15, the determination unit 38 determines the memory type of the non-volatile memory included in the electronic control unit to be updated, and determines the execution timing of the approval request process. When type information including the memory type of the non-volatile memory mounted on each of the electronic control units is stored in the storage unit 37 in advance, the determination unit 38 determines the memory type of the electronic control unit to be updated based on the type information stored in the storage unit. Also, in step S15, the communication unit 39 may perform a process of acquiring the memory type by communicating with the electronic control unit to be updated and storing it in the storage unit 37, and the determination unit 38 may determine the memory type of the electronic control unit to be updated based on the type information stored in the storage unit 37 by the communication unit 39. When at least one of the electronic control units to be updated has a first type of memory, approval before installation is essential, so the determination unit 38 determines to execute the approval request process at least before installation. In this case, the determination unit 38 may determine to execute the approval request process not only before installation but also before activation based on the pre-registered settings and the like. On the other hand, when all of the electronic control units to be updated have a second type of memory, approval before activation is essential, so the determination unit 38 determines to execute the approval request process at least before activation. In this case, the determination unit 38 may determine to execute the approval request process not only before activation but also before installation based on the pre-registered settings and the like. Then, the process proceeds to step S16. After that, the process may be determined to execute the approval request process not only before activation but also before installation based on the pre-registered settings and the like. Then, the process proceeds to step S16.
[0059] In step S16, the control unit 40 executes an installation process and an activation process on the electronic control unit to be updated, and ends the process.
[0060] FIG. 9 is a flowchart showing details of the installation / activation process shown in FIG. 8. It is.
[0061] In step S21, the control unit 40 determines whether a commitment request process approval before the execution of the installation is necessary based on the execution timing of the commitment request process determined by the determination unit 38 in step S15 of FIG. 8. If the determination in step S21 is YES, the process proceeds to step S22; otherwise, the process proceeds to step S24.
[0062] In step S22, the control unit 40 executes a commitment request process for the installation. For example, the control unit 40 displays a message indicating the start of software update of the electronic control unit, requests the user's commitment to the software update, and, if necessary, displays the time required for installing the update data, the restrictions and precautions during installation, and accepts the user's operation input using input means such as a touch panel or operation buttons. Then, the process proceeds to step S23.
[0063] In step S23, the control unit 40 determines whether an operation input indicating approval of the software update (installation) has been made. The operation input indicating approval of the installation can be determined based on, for example, whether buttons such as "Approve" or "Start Update" displayed on the display device 14 have been pressed. Also, if the user does not immediately approve the start of the software update (installation) and wishes to start the software update (installation) later, the user can accept this by pressing a button such as "Do it later". In this case, the control unit 40 determines NO in step S24. If the determination in step S23 is YES, the process proceeds to step S24; otherwise, the process ends.
[0064] In step S24, the control unit 40 transfers the update data to the electronic control unit to be updated and instructs the installation. Then, the process proceeds to step S25. The electronic control unit to be updated writes the update data received from the software update device 11 into the software storage area.
[0065] In step S25, the control unit 40 determines whether or not consent request processing before activation is necessary based on the execution timing of the consent request processing determined by the determination unit 38 in step S15 of Fig. 8. If the determination in step S25 is YES, the process proceeds to step S26, and otherwise the process proceeds to step S27.
[0066] In step S26, the control unit 40 executes a consent request process for activation. For example, the control unit 40 displays a message that the software update of the electronic control unit is ready, and that the program will be updated by performing a specific operation such as turning off the power or ignition, and if necessary, displays the time required for activation and restrictions and precautions during activation, and accepts operation input by the user using an input means such as a touch panel or an operation button. After that, the process proceeds to step S27.
[0067] In step S27, the control unit 40 determines whether or not an operation input to consent to the software update (activation) has been made. For example, the determination can be made based on whether or not a button such as "Accept" or "Update" displayed on the display device 14 is pressed. Also, if the user does not immediately accept the software update (activation) and wishes to perform the software update later, the user can accept this by pressing a button such as "Later", in which case the control unit 40 determines NO in step S27. If the determination in step S27 is YES, the process proceeds to step S28, and otherwise the process is terminated.
[0068] In step S28, the control unit 40 instructs the electronic control unit to be updated to activate the updated software. Then, the process ends. The electronic control unit to be updated restarts and executes the updated software when a specific operation such as turning off the power or ignition is performed. This completes the software update (function update) of the electronic control unit.
[0069] As described above, when the non-volatile memory mounted on the electronic control unit to be updated is a first type of memory, the current software is overwritten by installing the update data, so the electronic control unit to be updated is affected at the stage of installing the update data. Therefore, when the electronic control unit to be updated includes an electronic control unit on which a first type of memory is mounted, it is essential to perform a consent request process for requesting consent before the update data is written, and receiving the consent is a condition for starting the installation. On the other hand, when the non-volatile memory mounted on the electronic control unit to be updated is a second type of memory, the electronic control unit to be updated is affected not at the stage of installing the update data but at the stage of activating the updated software after the installation. Therefore, when all of the electronic control units to be updated are electronic control units on which a second type of memory is mounted, it is essential to cause the display device 14 to display a consent request screen for requesting consent from the user after the installation of the update data and before the activation of the updated software, and it is essential to perform a consent request process for requesting the user's consent for the program update (activation of the update program), and receiving the consent is a condition for starting the activation.
[0070] The software update device 11 according to the present embodiment changes the execution timing of the consent request process at the time of software update according to the type of the non-volatile memory of the electronic control unit to be updated. Therefore, according to the software update device according to the present embodiment, consent can be requested at an appropriate timing according to the specifications of the electronic control unit to be updated.
[0071] Specifically, when the non-volatile memory mounted on at least one of the electronic control units to be updated is a first type of memory, a commitment request screen is displayed on the display screen before the update program is written into the storage area of the non-volatile memory. On the other hand, when all of the non-volatile memories mounted on the electronic control units to be updated are second type of memories, after the update data is installed in the storage area that is not the read target of the non-volatile memory, and before the storage area where the updated software is written is activated, a commitment request display is displayed on the display screen. Therefore, according to the software update device 11 according to the present embodiment, the commitment request process can be performed at an appropriate timing according to the number of storage areas of the non-volatile memory mounted on the electronic control unit to be updated.
[0072] (Modification Example of the First Embodiment) In the above example, an example in which the software update device 11 determines the commitment request process based on the memory type of the electronic control unit stored in the storage unit 37 in advance or the memory type acquired by communication from the electronic control unit to be updated has been described. Since the configuration (type and memory type) of the electronic control units mounted on the vehicle is managed by the server 1, the communication unit 39 of the software update device 11 can obtain the type of the non-volatile memory of the electronic control unit to be updated from the server 1 by communication and store it in the storage unit 37. When configured in this way, in step S4 of FIG. 7, the communication unit 27 of the server 1 includes the update data and information indicating the memory type of the electronic control unit to be updated in the distribution package and transmits it to the vehicle. In the software update device 11, based on the information indicating the memory type of the electronic control unit to be updated included in the distribution package received by the communication unit 39 in step S14 of FIG. 8, the control unit 40 executes the process of step S15, whereby the execution timing of the commitment request process can be determined. obtained and stored in the storage unit 37. When configured in this way, in step S4 of FIG. 7, the communication unit 27 of the server 1 includes the update data and information indicating the memory type of the electronic control unit to be updated in the distribution package and transmits it to the vehicle. In the software update device 11, based on the information indicating the memory type of the electronic control unit to be updated included in the distribution package received by the communication unit 39 in step S14 of FIG. 8, the control unit 40 executes the process of step S15, whereby the execution timing of the commitment request process can be determined.
[0073] (Second Embodiment) In the above-described first embodiment, the software update device 11 includes a storage unit that stores the memory type of the electronic control unit, and the execution timing of the consent request process is controlled based on the memory type of the electronic control unit stored in advance in the storage unit, or the memory type acquired by the software update device 11 from the electronic control unit or the server 1 through communication. In contrast, in this embodiment, the server 1 holds the type of the non-volatile memory mounted on the electronic control unit in the storage unit 26, and transmits instruction information for instructing the execution timing of the consent request process from the server 1 to the vehicle software update device 11. Hereinafter, the description will focus on the differences between this embodiment and the first embodiment.
[0074] FIG. 10 is a flowchart showing an example of control processing executed by the server according to the second embodiment. The control processing shown in FIG. 10 is obtained by replacing step S4 shown in FIG. 7 with step S4'.
[0075] In step S3, when the communication unit 27 receives a download request for the distribution package from the software update device 11, in step S4', the communication unit 27 transmits a distribution package including the update data of the software of the electronic control unit and the instruction information to the software update device 11. The instruction information is information for instructing the execution timing of the consent request process when the software update device 11 performs the software update process, and is generated according to the type of the non-volatile memory mounted on the update target electronic control unit. For example, the instruction information can be generated by the control unit 28 performing the following procedure.
[0076] First, for the vehicle specified by the vehicle ID included in the download request received in step S3, the control unit 28 identifies the electronic control unit determined to have update data in step S2 and its memory type. The types of electronic control units and memory types installed in each vehicle are registered in advance in the storage unit 26 of the server 1 during manufacturing or the like. Therefore, the control unit 28 can obtain the memory type of each of the electronic control units to be updated (i.e., the electronic control units with update data) determined in step S2 based on the pre-registered information. Next, the control unit 28 generates instruction information according to the memory type of the non-volatile memory installed in the electronic control unit to be updated. Specifically, when the electronic control unit to be updated includes an electronic control unit equipped with a first type of memory, the control unit 28 generates information instructing to perform a commitment request process before installation that substantially affects the electronic control unit to be updated. Also, when all of the electronic control units to be updated are electronic control units equipped with a second type of memory, the control unit 28 generates information instructing to perform a commitment request process before activation that substantially affects the electronic control units to be updated. The communication unit 27 includes the instruction information generated by the control unit 28 together with the update data of the electronic control unit to be updated in the distribution package and transmits it to the vehicle that sent the download request.
[0077] FIG. 11 is a flowchart showing an example of control processing executed by the software update device according to the second embodiment. The control processing shown in FIG. 11 is obtained by replacing step S15 shown in the control processing of FIG. 8 with step S15'.
[0078] In the software update device 11, when the communication unit 39 receives a distribution package (step S14), in step S15', the control unit 40 determines the execution timing of the commitment request process based on the instruction information included in the distribution package. In the installation / activation process (FIG. 9) of step S16, the determinations in steps S21 and S25 shown in FIG. 9 are made based on the execution timing determined in step S15.
[0079] If, as in this embodiment, instruction information for instructing the execution timing of the approval request process is generated in the server 1 and transmitted to the vehicle, it is not necessary for the software update device 11 to determine the memory type of the electronic control unit to be updated. Therefore, the control process of the software update device 11 can be made simpler.
[0080] The functions of the server 1 illustrated in the above embodiments can also be realized as an update management method executed by a computer including a processor (CPU), a memory, and a storage device, or an update management program to be executed by the computer, or a computer-readable non-transitory storage medium storing the update management program. Similarly, the functions of the software update device 11 illustrated as an embodiment can also be realized as an update control method executed by an in-vehicle computer including a processor (CPU), a memory, and a storage device, or an update control program to be executed by the in-vehicle computer, or a computer-readable non-transitory storage medium storing the update control program.
[0081] In each of the above embodiments, an example has been described in which, on the vehicle side, the software update device 11 provided in the in-vehicle network controls the program update of all the electronic control units 13a to 13d as a master device. However, instead of providing the software update device 11, any one of the electronic control units 13a to 13d may have the update control function shown in FIGS. 8 and 9 and control the program update of other electronic control units. Further, instead of providing the software update device 11, the update control function shown in FIGS. 8 and 9 may be provided in an external device that can be wired-connected to the in-vehicle network 2, and the program update process of the electronic control units 13a to 13d may be performed using this external device.
Industrial Applicability
[0082] The disclosed technology can be used in a network system for updating the program of an electronic control unit.
Explanation of Reference Numerals
[0083] 1 Server 2 In-vehicle network 5 Network 11 Software update device 13a~13d Electronic control unit 37 Memory unit 38 Judgment unit 39 Communication unit 40 Update unit 48 Display control unit
Claims
1. A software update device for controlling software updates of an electronic control unit mounted on a vehicle, when the electronic control unit is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installation of the updated software, after the updated software is downloaded and before it is installed, execute a commitment request to request a commitment for activating the updated software, when the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installation of the updated software, comprising a control unit that controls whether to execute the commitment request at the timing before installation execution based on information indicating whether to execute the commitment request, A software update device.
2. comprising a determination unit that determines whether the electronic control unit is the first type of electronic control unit or the second type of electronic control unit, The control unit controls the execution timing of the commitment request based on the determination result by the determination unit. The software update device according to claim 1.
3. comprising a storage unit that stores the type of the electronic control unit, The determination unit determines the type of the electronic control unit based on the information stored in the storage unit. The software update device according to claim 2.
4. a communication unit that receives the type of the electronic control unit from a server, and a storage unit that stores the received type of the electronic control unit, The determination unit determines the type of the electronic control unit based on the information stored in the storage unit. The software update device according to claim 2.
5. A communication unit that receives from a server information regarding the execution timing of the commitment request, which is determined based on the type of non-volatile memory included in the electronic control unit. The control unit controls the execution timing of the commitment request based on the received information regarding the execution timing. The software update device according to claim 1. **Claim 6** The control unit causes a display device to display a screen for requesting a commitment to software update in the commitment request. The software update device according to any one of claims 1 to 5. **Claim 7** An update control method executed by a computer including a processor, a memory, and a storage device to control software update of an electronic control unit. When the electronic control unit is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installation of the updated software, after the updated software is downloaded and before it is installed, a commitment request for obtaining a commitment to activate the updated software is executed. When the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installation of the updated software, the commitment request is executed at the timing before installation execution based on information indicating whether to execute the commitment request. Update control method. **Claim 8** An update control program executed by a computer including a processor, a memory, and a storage device to control software update of an electronic control unit. When the electronic control unit is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installation of the updated software, after the updated software is downloaded and before it is installed, performing a consent request step of requesting consent to activate the updated software; When the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installation of the updated software, based on information indicating whether to perform the consent request, performing the consent request step at the timing before installation execution; Update control program. Claim 9 When the electronic control unit to be updated with software is a first type of electronic control unit in which the current software stored in the electronic control unit is rewritten to the updated software by installation of the updated software, transmitting to the vehicle information for causing the vehicle to execute a consent request for requesting consent to activate the updated software before the updated software is installed; When the electronic control unit is a second type of electronic control unit in which the updated software is stored while maintaining the current software stored in the electronic control unit by installation of the updated software, comprising a communication unit that transmits to the vehicle information indicating whether to perform the consent request at the timing before installation execution; Server
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Software update device, update control method, update control program, and server
JP2022020440A
Vehicular electronic control system, progress display screen display control method, and progress display screen display control program
WO2020032194A1