Software Update Device, Software Update Method, and Software Update Processing Program

The software update device addresses the issue of false warnings during vehicle software updates by prohibiting warning outputs during the update process, ensuring that drivers are not misled by temporary communication interruptions.

JP7699102B2Active Publication Date: 2025-06-26NISSAN MOTOR CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022507926
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-03-18
Publication Date
2025-06-26
Estimated Expiration
2040-03-18

AI Technical Summary

Technical Problem

During software updates for electronic control units in vehicles, temporary resets cause communication interruptions, leading to false abnormality detections and unnecessary warnings for drivers.

Method used

A software update device with a controller that acquires and applies software updates, temporarily prohibits warnings during the update process by masking storage areas and preventing failure code recordings, even if abnormalities are detected.

Benefits of technology

Prevents unnecessary warnings during software updates by suppressing abnormality notifications during the update process, thereby reducing driver anxiety and avoiding misunderstandings about update failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007699102000001
    Figure 0007699102000001
  • Figure 0007699102000002
    Figure 0007699102000002
Patent Text Reader

Abstract

Provided is a software update device for executing a process of updating software for actuating equipment mounted to a vehicle. This software update device is provided with a controller that acquires software and controls equipment by applying the software to the equipment. The controller acquires software for updating, executes a software update process by applying the software to the equipment, and causes a warning device to output a warning when abnormality relating to the equipment has occurred. Further, the controller prohibits the warning device from outputting the warning during execution of the software update process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a software update device, a software update method, and a software update processing program.

Background Art

[0002] JP2018-97764A discloses an in-vehicle data update device in which an in-vehicle control unit receives update data from an external server and updates (performs an update process) an update target unit using the update data.

Summary of the Invention

[0003] By the way, when performing an update process of software of an electronic control unit (ECU (Electronic Control Unit)) mounted on a vehicle, in order to update the content of software rewriting, the hardware of the electronic control unit is temporarily reset. At this time, since communication with other in-vehicle devices is temporarily interrupted, it is determined that an abnormality has occurred, a failure code is recorded in the control unit of the vehicle, and a warning is notified to the driver or the like. For this reason, there is a risk of giving the driver or the like a misunderstanding that the software update process has failed or that a failure has occurred in the vehicle, causing anxiety to the driver or the like.

[0004] The present invention has been made in view of the above problems, and an object thereof is to provide a software update device, a software update method, and a software update processing program that prevent the output of unnecessary warnings caused by software update processing. Means for Solving the Problems

[0005] According to one aspect of the present invention, there is provided a software update device that executes an update process of software for operating a device mounted on a vehicle. This software update device includes a controller that acquires software and controls the device by applying the software to the device. The controller acquires software for update, executes a software update process by applying the software to the device, and causes a warning device to output a warning when an abnormality related to the device occurs. Further, the controller If an abnormality related to the machine is detected during the execution of the update process prohibits the warning device from outputting a warning.

Brief Description of the Drawings

[0006]

Figure 1

Figure 2

Modes for Carrying Out the Invention

[0007] Hereinafter, embodiments of the present invention will be described with reference to the drawings and the like.

[0008] An embodiment of the present invention will be described with reference to FIGS. 1 and 2. FIG. 1 is a schematic configuration diagram of a software update system 100 and a software update device 110 according to an embodiment of the present invention.

[0009] As shown in FIG. 1, the software update system 100 includes a software update device 110 mounted on a vehicle 1 and an external server 2, and the software update device 110 includes a controller 10 and a warning device 3. The vehicle 1 is, for example, an electric vehicle (EV).

[0010] The controller 10 includes a gateway 11 that acquires software from the external server 2 and an electronic control unit 12 that controls each device mounted on the vehicle 1.

[0011] The gateway 11 can communicate with the external server 2 and the electronic control unit 12, obtain the software for update from the external server 2, and transmit the obtained software for update to the electronic control unit 12 to be updated. Further, the gateway 11 can communicate with a warning device 3 to be described later. The gateway 11 obtains the control information of each device from the electronic control unit 12, and detects the occurrence of an abnormality related to each device from the control information. The gateway 11 has a storage area for recording a failure code when an abnormality occurs, and when detecting the occurrence of an abnormality in each device, records the failure code corresponding to the abnormality in the storage area. When a failure code is recorded in the storage area, the gateway 11 outputs a warning by the warning device 3 based on the recorded failure code.

[0012] In addition, the gateway 11 is composed of a computer including a central processing unit (CPU), a read-only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface), and performs integrated control of the software update device 110. The gateway 11 executes a process for controlling the software update device 110 by executing a specific program. The gateway 11 performs software update control to be described later together with, for example, the electronic control unit 12.

[0013] The electronic control unit (ECU) 12 is a controller that controls each device mounted on the vehicle 1, such as a BCM (Body Control Module), VDC (Vehicle Dynamics Control), HEVC (Hybrid Electric Vehicle Control), etc. Each electronic control unit 12 is composed of a computer equipped with a central processing unit (CPU), a read-only memory (ROM), a random access memory (RAM), and an input / output interface (I / O interface). The BCM controls the operating elements of the vehicle body of the vehicle 1, including the engine starter and door lock of the vehicle 1. The VDC controls the brakes and engine output of the vehicle 1, and controls the attitude of the vehicle 1 to prevent the vehicle 1 from skidding, etc. The HEVC controls the engine and motor, which are the drive sources, when the vehicle 1 is a hybrid vehicle, and realizes highly efficient operation.

[0014] The electronic control unit 12 can communicate with the gateway 11 and constantly transmits the control information of each device to the gateway 11 as a signal. Each electronic control unit 12 acquires software including a specific program from the gateway 11 and controls the target device by applying the acquired software to the device to be controlled. In addition, the electronic control unit 12 performs software update control, which will be described later, together with the gateway 11.

[0015] In addition, each electronic control unit 12 is provided with two storage units 121 and 122 that store the software acquired from the gateway 11 respectively. The electronic control unit 12 updates the software by applying the software stored in one storage unit (the first storage unit) 121 to the device and changing the software to be applied to the device to the software stored in the other storage unit (the second storage unit) 122. The details of the software update process will be described later.

[0016] The warning device 3 is, for example, a warning light of the vehicle 1, and when an abnormality occurs in each device mounted on the vehicle 1, the warning device 3 notifies the driver or the like of the abnormality. The warning device 3 can communicate with the gateway 11. When the gateway 11 detects the occurrence of an abnormality in the in-vehicle device, the gateway 11 records a failure code corresponding to the abnormality in the storage area, and outputs a warning by, for example, lighting the warning light which is the warning device 3. Note that the warning device 3 is not limited to the warning light, and may be, for example, an alarm by voice or the like.

[0017] Next, the software update process will be described.

[0018] As described above, each electronic control unit 12 includes two storage units 121 and 122. When the electronic control unit 12 acquires the software (first software) transmitted from the gateway 11, the software is stored in one storage unit (first storage unit) 121, and the electronic control unit 12 applies the software to the device. Note that the first software may be stored in the first storage unit 121 in the initial state instead of being acquired from the gateway 11.

[0019] Next, when the electronic control unit 12 acquires the update software (second software) transmitted from the gateway 11, the update software is stored in the other storage unit (second storage unit) 122. While the electronic control unit 12 acquires and stores the second software, the first software is applied to the device.

[0020] In this way, by providing two storage units 121 and 122 in each electronic control unit 12, the electronic control unit 12 can acquire (download) and store (install) the update software in a state where the first software is applied to the device. That is, the update software can be acquired and stored without stopping the operation of the device to be controlled.

[0021] When the software for update (second software) is acquired and stored, the electronic control unit 12 changes the software applied to the device from the first software to the second software. Thereby, the software applied to the device is updated. Hereinafter, the process of changing the software applied to the device from the first software to the second software is referred to as software update process (activation).

[0022] By the way, when the software update process of the electronic control unit 12 is carried out, in order to update the rewritten content of the software, the hardware of the electronic control unit 12 is temporarily reset. At this time, since the communication between the electronic control unit 12 to be updated temporarily and the electronic control unit 12 that controls other in-vehicle devices is interrupted, it is determined that an abnormality has occurred in the device, and a failure code is recorded in the storage area of the gateway 11. Therefore, a warning is notified to the driver or the like by the warning device 3. Therefore, there is a possibility that the driver or the like may be given a misunderstanding that the software update process has failed or a failure has occurred in the vehicle 1, which may cause the driver or the like to feel uneasy. In addition, since the software update processes of the respective electronic control units 12 are not always executed simultaneously, a plurality of warnings may be notified sequentially. In this case, there is a possibility that the driver or the like may be made more uneasy. Therefore, in the present embodiment, the output of the warning by the warning device 3 is prohibited during the execution of the software update process.

[0023] Specifically, during the execution of the software update process, the gateway 11 does not record a failure code in the storage area even if it detects the occurrence of an abnormality related to the device. Thereby, the output of the warning during the execution of the software update process is prohibited.

[0024] As described above, since the output of the warning by the warning device 3 is prohibited during the execution of the software update process, it is possible to prevent the output of unnecessary warnings caused by the software update process.

[0025] In addition, if an abnormality of the device not caused by the software update process is detected after the output of the warning is prohibited, and the abnormality has not been resolved even after the software update process is completed, a failure code is recorded and a warning is output after the update process is completed.

[0026] FIG. 2 is a flowchart for explaining software update control according to an embodiment of the present invention. Note that the following controls are all executed by the controller 10 (gateway 11, electronic control unit 12). Also, in the initial state, the first software is stored in the first storage unit 121 of the electronic control unit 12, and it is assumed that the first software is applied to the device to be controlled.

[0027] In step S101, when the gateway (GW) 11 acquires the software for update (second software) from the external server 2, the gateway 11 transmits the software for update to the electronic control unit 12 to be updated.

[0028] In step S102, the electronic control unit 12 acquires (downloads) the software for update (second software) from the gateway 11.

[0029] Next, in step S103, the electronic control unit 12 stores (installs) the software for update (second software) in the second storage unit 122. During the acquisition and storage of the second software in steps S102 and S103, since the first software is applied to the device to be controlled by the electronic control unit 12, the device to be controlled by the electronic control unit 12 is not stopped. Therefore, for example, even when the vehicle 1 is running, the software for update can be acquired and stored. In addition, since the activation of the software for update can be executed in a short time, it is also possible to perform the acquisition, storage, and update process of the software with the ignition switch turned on (including when the vehicle 1 is running).

[0030] In step S104, when the electronic control unit 12 starts the software update process, the gateway 11 prohibits the output of a warning by the warning device 3.

[0031] The software update process is executed by the electronic control unit 12 changing the software applied to the device to be controlled from the first software to the second software. As a result, the software applied to the device is updated from the first software to the second software. Preferably, during the software update process, the driver is notified by a display device or the like (not shown) that the update process is in progress.

[0032] Also, the prohibition of the warning output is performed, for example, by masking the storage area of the gateway 11. As a result, even if the gateway 11 detects the occurrence of an abnormality related to the device, a failure code is not recorded in the storage area, so the output of a warning by the warning device 3 is prohibited.

[0033] In step S104, the update process may be permitted only when no abnormality is detected before starting the software update process. For example, the gateway 11 detects whether an abnormality of the device has occurred in the electronic control unit 12 before software update, and transmits the detection result to the electronic control unit 12. The electronic control unit 12 executes the update process only when no abnormality is detected. On the other hand, when an abnormality of the device is detected before the software update process is executed, the electronic control unit 12 prohibits the software update process until the abnormality is resolved. That is, since the output of a warning is prohibited during the software update process, a warning is not output even for an abnormality not caused by the update process. Therefore, by resolving the abnormality before starting the software update process for an abnormality not caused by the software update process, it is surely prevented that the response to the abnormality is delayed until after the software update process. Note that the above permission or prohibition of the software update process may be executed by the gateway 11.

[0034] In step S104, when the software update process is started, in step S105, the gateway 11 temporarily resets the hardware (HW) of the electronic control unit 12 to be updated to update the rewritten content of the software. When the hardware of the electronic control unit 12 is reset, the communication between the electronic control unit 12 to be updated temporarily and the electronic control unit 12 that controls other in-vehicle devices is interrupted. The gateway 11 detects this communication interruption as the occurrence of an abnormality related to the device. However, since the storage area of the gateway 11 is masked, a failure code is not recorded in the storage area. Therefore, no warning is output either.

[0035] Subsequently, in step S106, when the software update process is completed, in step S107, the gateway 11 releases the prohibition of warning output (permits warning output) and ends the software update control.

[0036] In this way, during the execution of the software update process, the output of warnings by the warning device 3 is prohibited, so that the output of unnecessary warnings caused by the software update process can be prevented.

[0037] Also, after the warning output is prohibited, if the gateway 11 detects the occurrence of a device abnormality not caused by the software update process between steps S104 and S107, if the abnormality has not been resolved after the update process is completed, a warning will be output after the prohibition of warning output is released.

[0038] Note that it is preferable that the prohibition of warning output is released immediately after the software update process is completed, but it is not necessarily limited to this. For example, the warning output may be permitted after a certain period of time has elapsed.

[0039] After the software update process is completed, when the software is further updated next time, the update software transmitted from the gateway 11 to the electronic control unit 12 is stored (overwritten) in the first storage unit 121. By changing the software applied to the device from the second software stored in the second storage unit 122 to the update software stored in the first storage unit 121, the re-update of the software is executed.

[0040] Note that the process shown in FIG. 2 is configured as a program for causing the controller 10, which is a computer, to execute, and these programs are described in a storage medium.

[0041] According to the software update device 110 of the above-described embodiment, the following effects can be obtained.

[0042] In the software update device 110, the gateway 11 (controller 10) causes the warning device 3 to output a warning when an abnormality related to the device occurs, and prohibits the warning device 3 from outputting a warning during the execution of the software update process. Since the output of the warning is prohibited during the execution of the software update process, in order to update the rewritten content of the software, even if the hardware of the electronic control unit 12 is temporarily reset and the communication with other electronic control units 12 is interrupted, no warning is output. Therefore, it is possible to prevent the output of unnecessary warnings caused by the software update process.

[0043] In the software update device 110, the gateway 11 (controller 10) prohibits the output of a warning during the execution of the software update process, and permits the output of a warning after the software update process is completed. Thereby, it is possible to prevent the output of unnecessary warnings caused by the software update process, and to warn a driver or the like about an abnormality of the device that is not caused by the software update process after the software update process.

[0044] In the software update device 110, when an abnormality occurs in a device, the gateway 11 (controller 10) records a failure code corresponding to the abnormality in the storage area of the gateway 11 (controller 10), and based on the recorded failure code, causes the warning device 3 to output a warning. On the other hand, during the execution of the software update process, the gateway 11 (controller 10) does not record a failure code even if an abnormality occurs in the device. Therefore, during the execution of the software update process, no warning is output by the warning device 3. Accordingly, it is possible to prevent the output of unnecessary warnings caused by the software update process.

[0045] In the software update device 110, the electronic control unit 12 (controller 10) has a first storage unit 121 that stores the first software and a second storage unit 122 that stores the second software. Therefore, it is possible to acquire the update software (second software) in a state where the first software stored in the first storage unit 121 is applied to the device and store it in the second storage unit 122. Accordingly, it is possible to acquire and store the update software without stopping the device controlled by the electronic control unit 12 to be updated, and the convenience during the software update operation is improved.

[0046] The software update device 110 includes a plurality of electronic control units 12 that control respective ones of a plurality of devices, and the plurality of electronic control units 12 each execute a software update process. And the gateway 11 (controller 10) prohibits the output of a warning by the warning device 3 during the execution of the software update process. In this way, by prohibiting the output of warnings during the execution of the software update process of each electronic control unit 12, it is possible to prevent a plurality of warnings caused by the software update process of each electronic control unit 12 from being sequentially notified and making the driver or the like more anxious.

[0047] In addition, in the present embodiment, the electronic control unit 12 is the BCM, VDC, and HEVC. However, as long as it controls the devices mounted on the vehicle 1, the type of the electronic control unit 12 is not limited to these, and the number is also not limited to this.

[0048] Also, the software update control including the software update process of the present embodiment may be executed simultaneously for several or a plurality of electronic control units 12, or may be executed at different times for each electronic control unit 12.

[0049] In addition, in the present embodiment, the gateway 11 executes the integrated control of the software update device 110, and the electronic control unit 12 executes the control of each device mounted on the vehicle 1. However, the main body of each control may be either the gateway 11 or the electronic control unit 12. For example, the change of the software applied to the device (software update process) may be executed by the gateway 11 instead of the electronic control unit 12.

[0050] In addition, in the present embodiment, when an abnormality related to a device occurs, a failure code corresponding to the abnormality is recorded in the storage area of the gateway 11, and a warning is output to the warning device 3 based on the recorded failure code. However, the warning output method is not limited to this. For example, when the occurrence of an abnormality in a device is detected, a warning may be directly output to the warning device 3 without recording the failure code.

[0051] In addition, in the present embodiment, during the execution of the software update process, even if an abnormality related to a device occurs, the storage area of the gateway 11 is masked and the failure code is not recorded, thereby prohibiting the output of a warning during the execution of the update process. However, the warning prohibition method is not necessarily limited to this. For example, in the case where a warning is directly output to the warning device 3 without recording the failure code when the occurrence of an abnormality in a device is detected as described above, the warning output prohibition also directly prohibits the warning device 3 from outputting a warning.

[0052] Also, in the present embodiment, the electronic control unit 12 is configured to have two storage units 121 and 122, but it is not necessarily limited to this. As described above, since the software for update can be acquired and stored without stopping the in-vehicle device, it is preferable that the electronic control unit 12 has two storage units 121 and 122. However, the electronic control unit 12 may be configured to have only one storage unit. In this case, the software update process is performed by overwriting the software stored in the storage unit with the update software. Also, in this case, the output of a warning is prohibited during the acquisition and storage of the update software.

[0053] As described above, the embodiments of the present invention have been described. However, the above embodiments merely show a part of the application examples of the present invention, and are not intended to limit the technical scope of the present invention to the specific configurations of the above embodiments.

Claims

1. A software update device that executes a software update process for software of an electronic control unit that operates equipment mounted on a vehicle, a plurality of electronic control units that acquire the software and control the equipment by applying the software to the equipment, a gateway that detects a disconnection of communication between the electronic control units and notifies a driver of a warning by a warning device, and a warning device, The electronic control unit, a first storage unit that stores the acquired first software, a second storage unit that stores the acquired second software, The electronic control unit, executes the software update process by changing the software to be applied to the equipment from the first software to the second software, The gateway, even if a disconnection of communication between the electronic control units is detected during the execution of the update process, does not execute notification of a warning to the driver by the warning device, Software update device.

2. The software update device according to claim 1, wherein the gateway executes notification of a warning by the warning device after the update process is completed. Software update device.

3. The software update device according to claim 1 or 2, wherein the gateway permits execution of the update process when no abnormality related to the equipment has occurred before the execution of the software update process. Software update device.

4. The software update device according to any one of claims 1 to 3, The gateway, when an abnormality related to the equipment occurs, records a failure code corresponding to the abnormality in a storage area of the gateway, and based on the recorded failure code, executes notification of a warning by the warning device, during the execution of the update process, when an abnormality related to the equipment occurs, does not record the failure code and does not execute notification of a warning by the warning device. Software update device.

5. The software update device according to any one of claims 1 to 3, The gateway, acquires a plurality of the software from the outside and transmits the software to an electronic control unit that controls the corresponding equipment respectively. Each of the plurality of the electronic control units acquires the software for update from the gateway, and executes an update process of the software by applying the software to the device. The gateway detects the occurrence of an abnormality related to the device. Software update device.

6. The software update device according to claim 5, wherein the gateway detects the occurrence of an abnormality related to the device before the execution of the update process, and transmits the detection result to the electronic control unit. The electronic control unit prohibits the software update process until the abnormality is resolved. Software update device.

7. The software update device according to any one of claims 1 to 6, wherein the warning device is a warning lamp of the vehicle. The gateway executes notification of a warning by the warning device by lighting the warning lamp. Software update device.

8. A method for updating software of an electronic control unit that operates a device mounted on a vehicle, wherein the electronic control unit that acquires software for update and performs an update process of the software by applying the software to the device stores the acquired first software in a first storage unit. stores the acquired second software in a second storage unit. executes the software update process by changing the software to be applied to the device from the first software to the second software. The gateway that detects a disconnection of communication between the electronic control units and notifies the driver of a warning by a warning device does not execute notification of a warning to the driver by the warning device even if a disconnection of communication between the electronic control units is detected during the execution of the update process. Software update method.

9. A software update process program for realizing a software update process of an electronic control unit that operates a device mounted on a vehicle, wherein the electronic control unit that acquires software for update and performs an update process of the software by applying the software to the device acquires first software and stores it in a first storage unit. acquires second software and stores it in a second storage unit. Executing an update process of the software by changing the software applied to the machine from the first software to the second software; To realize; In a gateway that, when detecting a disconnection of communication between the electronic control units, notifies a driver of a warning by a warning device; Even if a disconnection of communication between the electronic control units is detected during the execution of the update process, not executing notification of a warning to the driver by the warning device; To realize; A software update process program for this purpose.

Citation Information

Patent Citations

  • Control device for vehicle and method of controlling same

    JP2008195130A

  • Program rewriting device and program rewriting method

    JP2016188022A

  • On-vehicle updating device, on-vehicle updating system and updating method for communication device

    JP2018020718A