Electronic control device, software update method, software update program, and electronic control system
The electronic control unit optimizes software updates in virtual machines by using a hypervisor-managed system with selective distribution based on safety levels and hypervisor compatibility, addressing the time-consuming issue in vehicle-mounted virtual machines.
Patent Information
- Application Number
- JP2021178152
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-11-27
- Filing Date
- 2021-10-29
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-10-29
AI Technical Summary
The challenge of updating software in virtual machines mounted on vehicles is the time-consuming process due to the large number of virtual machines created by virtualization technology, which is critical for ensuring vehicle safety.
An electronic control unit with a hypervisor-managed virtual machine that includes a file acquisition unit, storage unit, determination unit, and distribution unit to selectively distribute software update files based on safety levels and hypervisor compatibility, optimizing the update process.
This approach reduces the time required for software updates in virtual machines by minimizing unnecessary distribution processes and communication volume, enhancing the efficiency and security of the update process.
Smart Images

Figure 0007707864000001 
Figure 0007707864000002 
Figure 0007707864000003
Abstract
Description
Technical Field
[0001] The present invention relates to an electronic control device, and mainly relates to an electronic control device for a vehicle, a method implemented by the electronic control device, a program executable by the electronic control device, and an electronic control system including the electronic control device.
Background Art
[0002] In automobiles, various electronic control devices connected by an in-vehicle network are mounted. With the development of recent autonomous driving technologies, the functions required of automobiles are becoming more complex, and the number of electronic control devices mounted on automobiles is increasing. Therefore, it has been proposed to apply virtualization technology that can suppress the total number of electronic control devices by integrating multiple functions into one electronic control device.
[0003] For example, Patent Document 1 discloses constructing a plurality of virtual ECUs using a virtualization operating system such as a hypervisor in an in-vehicle computer. According to the technology described in Patent Document 1, it is possible to efficiently use physical resources by aggregating the physical resources required for the operation of terminal devices connected to the in-vehicle computer via the ECU.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Here, the inventor of the present invention has found the following problems. Since the electronic control unit mounted on a vehicle includes those that control vehicle operations such as running and steering, it is desirable to always update to the latest software to ensure vehicle safety. However, even if the number of electronic control units is suppressed by virtualization technology, if there are a large number of virtual machines formed by virtualizing the electronic control units, it may take time to update all of these virtual machines.
[0006] Therefore, an object of the present invention is to shorten the time required for updating the software of virtual machines.
Means for Solving the Problem
[0007] An electronic control unit according to an aspect of the present disclosure is an electronic control unit having a virtual machine managed by a hypervisor, including a file acquisition unit (141) that acquires a file for updating software, and a storage unit (130, 144) that stores the file. The first virtual machine (140) which is the virtual machine has a determination unit (146) that determines whether to distribute the file to the second virtual machine based on a first safety level indicating the safety of the first virtual machine and a second safety level indicating the safety of a second virtual machine (150, 160, 230) connected to the first virtual machine, and a distribution unit (147) that distributes the file to the second virtual machine when the determination unit determines to distribute the file to the second virtual machine.
[0008] A software update method according to another aspect of the present disclosure is a software update method executed by an electronic control device having virtual machines managed by a hypervisor. The method includes: obtaining a file for updating software (S101); saving the file in a storage unit (130, 144) (S103); determining whether to distribute the file to a second virtual machine based on a first safety level indicating the safety of a first virtual machine (140) which is the virtual machine and a second safety level indicating the safety of a second virtual machine (150, 160, 230) connected to the first virtual machine (S106); and distributing the file to the second virtual machine when it is determined to distribute the file to the second virtual machine (S109).
[0009] A software update program according to another aspect of the present disclosure is a software update program executable by an electronic control device having virtual machines managed by a hypervisor. The program includes: obtaining a file for updating software (S101); saving the file in a storage unit (130, 144) (S103); determining whether to distribute the file to a second virtual machine based on a first safety level indicating the safety of a first virtual machine (140) which is the virtual machine and a second safety level indicating the safety of a second virtual machine (150, 160, 230) connected to the first virtual machine (S106); and distributing the file to the second virtual machine when it is determined to distribute the file to the second virtual machine (S109).
[0010] An electronic control system according to another aspect of the present disclosure is an electronic control system having a first electronic control device (10) and a second electronic control device (20), wherein the first electronic control device having a first virtual machine (140) includes a file acquisition unit (141) that acquires a file for software update, and a storage unit (130, 144) that stores the file. The first virtual machine includes a determination unit (146) that determines whether to distribute the file to the second virtual machine based on a first safety level indicating the safety of the first virtual machine and a second safety level indicating the safety of a second virtual machine (230) connected to the first virtual machine, and a distribution unit (147) that distributes the file to the second virtual machine when the determination unit determines to distribute the file to the second virtual machine. The second virtual machine includes an update unit (231) that updates the second virtual machine using the file by accessing the storage unit or using the file distributed by the distribution unit.
[0011] Note that the numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention.
Effects of the Invention
[0012] The electronic control device, software update method, software update program, and electronic control system of the present disclosure can shorten the time required for updating the software of the virtual machine.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Modes for Carrying Out the Invention
[0014] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0015] Note that the present invention means the invention described in the claims or the section of means for solving the problems, and is not limited to the following embodiments. Also, at least the terms in parentheses mean the terms described in the claims or the section of means for solving the problems, and are not limited to the following embodiments either.
[0016] The configurations and methods described in the dependent claims of the claims are arbitrary configurations and methods in the invention described in the independent claim of the claims. The configurations and methods in the embodiments corresponding to the configurations and methods described in the dependent claims, as well as the configurations and methods described only in the embodiments without being described in the claims, are arbitrary configurations and methods in the present invention. Even when the description in the claims is broader than the description in the embodiments, the configurations and methods described in the embodiments are also arbitrary configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In any case, by describing in the independent claim of the claims, the essential configurations and methods of the present invention are obtained.
[0017] The effects described in the embodiments are the effects in the case of having the configurations of the embodiments as examples of the present invention, and are not necessarily the effects of the present invention.
[0018] When there are a plurality of embodiments, the configurations disclosed in each embodiment are not limited to each embodiment alone, and can be combined across embodiments. For example, the configuration disclosed in one embodiment may be combined with another embodiment. Also, the configurations disclosed in each of the plurality of embodiments may be collected and combined.
[0019] The problems described as the problems to be solved by the invention are not well-known problems, but are discoveries made independently by the inventor, and are facts that affirm the inventiveness of the invention together with the configuration and method of the present invention.
[0020] 1. Configuration common to each embodiment Using FIG. 1, the electronic control device of each embodiment and the electronic control system including the electronic control device will be described. The electronic control device and the electronic control system of each embodiment assume an in-vehicle device and an in-vehicle system mounted on a vehicle which is a "mobile body", but are not limited thereto.
[0021] Here, the "mobile body" refers to an object that can move, and the moving speed is arbitrary. Also, the case where the mobile body is stopped is of course included. For example, it includes automobiles, motorcycles, bicycles, pedestrians, ships, airplanes, and things mounted on these, and is not limited thereto. Also, "mounted" includes not only the case of being directly fixed to the mobile body, but also the case of not being fixed to the mobile body but moving together with the mobile body. For example, the case of being held by a person riding on the mobile body, and the case of being mounted on a load placed on the mobile body.
[0022] The electronic control system 1 is a system composed of a plurality of "electronic control units" (hereinafter referred to as ECUs: Electronic Control Unit). FIG. 1 shows an electronic control system 1 including two ECUs (ECU10 and ECU20), but it may be composed of any number of ECUs. ECU10 and ECU20 are connected via an in-vehicle network such as CAN (Controller Area Network) or LIN (Local Interconnect Network), Ethernet (registered trademark), or a wireless communication network.
[0023] Here, the "electronic control device" may be configured as a so-called information processing device mainly composed of semiconductor devices and having a CPU (Central Processing Unit) and a volatile memory unit such as a RAM (Random Access Memory). In this case, the information processing device may further have a non-volatile memory unit such as a flash memory, a network interface unit connected to a communication network, etc. Furthermore, such an information processing device may be a packaged semiconductor device (element) or a configuration in which each semiconductor device is wired and connected on a wiring board.
[0024] ECU10 is, for example, an ECU based on a platform capable of dynamic function expansion called Adaptive Platform (hereinafter referred to as AP) in AUTOSAR (AUTomotive Open System ARchitecture). AP is mainly a platform suitable for ECUs for autonomous driving. Also, ECU20 is, for example, an ECU based on a platform optimized for static functions called Classic Platform (hereinafter referred to as CP) in AUTOSAR. CP is mainly a platform suitable for ECUs for vehicle control.
[0025] Both the ECU 10 and the ECU 20 that make up the electronic control system 1 have one or more virtual machines managed by a hypervisor. The configurations of the ECU 10, the ECU 20, and the virtual machines installed in each ECU will be described below. In the figures, the virtual machine is abbreviated as VM (Virtual Machine).
[0026] (1) Regarding the ECU 10 The ECU 10 includes a hypervisor (HV) 110 and a hypervisor 120, a plurality of virtual machines (140, 150, 160) managed by these hypervisors, and a physical storage 130 which is hardware.
[0027] The hypervisor 110 and the hypervisor 120 are software for virtualizing the ECU 10. In the example of FIG. 1, the first virtual machine 140 and the second virtual machine 150 are built on the hypervisor 110, and the third virtual machine 160 is built on the hypervisor 120. The virtual machines built on the hypervisor are virtually "connected" to each other.
[0028] Here, "connection" between virtual machines means a state in which data can be exchanged between virtual machines. In addition to the case where virtual machines realized on the same hardware are virtually connected, it also includes the case where virtual machines realized on different hardware are connected via a network or the like. Also, the state where data can be exchanged does not necessarily mean that data can actually be exchanged. For example, even if one virtual machine is temporarily stopped due to some trouble or is in a sleep state, it is a state where data can be exchanged.
[0029] The actual storage (corresponding to the "storage unit") 130 is a hardware memory, which can be a volatile memory such as SRAM or DRAM, a ROM, a flash memory, or a non-volatile memory such as a hard disk. The virtual storage of the first virtual machine 140 to the third virtual machine 160, which will be described later, is realized by virtualizing the storage area of the actual storage 130. The actual storage 130 is a storage area managed by the hypervisor of the ECU 10. In FIG. 1, one actual storage 130 is shown, but the actual storage 130 may be realized by a plurality of storages.
[0030] The actual storage 130 stores the updated files processed by the file splitting unit 145, which will be described later. The area of the actual storage 130 where the updated files are stored may be a shared storage area shared by a plurality of virtual machines, or may be an area of a virtual storage realized by virtualizing the storage area of the actual storage 130. However, since the shared storage area is shared by a plurality of virtual machines, there is a risk of low security. Therefore, when storing the updated files in the shared storage area, it is desirable that each virtual machine can access the shared storage area only when updating the software of the virtual machine using the updated files stored in the shared storage area. That is, when not updating using the updated files stored in the shared storage area, access from the virtual machine to the shared storage area is restricted.
[0031] (i) Regarding the first virtual machine 140
[0032] The first virtual machine 140 managed by the hypervisor 110 includes a file acquisition unit 141, a distribution control unit 142, an update unit 143, and a virtual storage 144.
[0033] The file acquisition unit 141 acquires files from a server device provided outside the vehicle control system 1 using OTA (Over The Air) or wired communication. The files acquired by the file acquisition unit 141 include update files for updating the software of the virtual machines, and may be, for example, a group of update files including a plurality of update files for updating a plurality of virtual machines. The files may further include information for identifying the virtual machines to be updated. The file acquisition unit 141 transfers the acquired group of update files to the distribution control unit 142. The file acquisition unit 141 is also referred to as an OTA client. The update files for updating the software of the virtual machines are not only those for updating the software that realizes the virtual machines, but may also be those for updating applications and software installed on the virtual machines.
[0034] The distribution control unit 142 performs a series of processes necessary to distribute the files transferred from the file acquisition unit 141 to the virtual machines to be updated. The distribution control unit 142 realizes a file splitting unit 145, a determination unit 146, a distribution unit 147, and an update instruction unit 148. The distribution control unit 142, for example, executes part or all of the functions referred to as UCM (Update and Configuration Management) master in AUTOSAR.
[0035] The file splitting unit 145 performs a parsing process of splitting the group of update files transferred from the file acquisition unit 141 into update files for each virtual machine. The parsed update files are stored in the actual storage 130.
[0036] The determination unit 146 determines the virtual machines to be updated among the plurality of virtual machines connected to the first virtual machine 140. Whether a virtual machine is an update target can be determined based on the information for identifying the virtual machines to be updated included in the files acquired by the file acquisition unit 141. In the following embodiments, a case where all the virtual machines shown in FIG. 1 are virtual machines to be updated will be described.
[0037] The determination unit 146 further determines whether to distribute the update file to the virtual machine to be updated. The method for the determination unit 146 to determine whether to distribute the update file to the virtual machine to be updated will be described later in Embodiments 1 and 2.
[0038] When determining whether to distribute the virtual machine to be updated and the update file, the determination unit 146 may perform a search process of querying information about the virtual machine for each virtual machine. For example, the determination unit 146 transmits a search signal for querying information about the hypervisor that manages the virtual machine, the ECU on which the virtual machine is mounted, or the functions and configurations of the ECU to the virtual machine connected to the first virtual machine 140.
[0039] When the software update is completed in all the virtual machines to be updated, the determination unit 146 notifies the file acquisition unit 141 that the update is completed.
[0040] When the determination unit 146 determines to distribute the update file, the distribution unit 147 distributes the update file split by the file splitting unit 145 to the virtual machine by sending it via the communication network. The distribution unit 147 may receive a distribution instruction from the determination unit 146 and distribute the update file to the virtual machine. In the present disclosure, "distributing" the update file includes not only transmitting the update file via the communication network but also moving the storage area of the update file to an area accessible by a specific virtual machine.
[0041] The update instruction unit 148 instructs the software update of each virtual machine to be updated. For the virtual machine determined by the determination unit 146 to distribute the update file, the update instruction unit 148 instructs to update the software of the virtual machine using the update file distributed by the distribution unit 147. For the virtual machine determined by the determination unit 146 not to distribute the update file, the update instruction unit 148 instructs to update the software of the virtual machine using the update file stored in the actual storage 130 by accessing the actual storage 130.
[0042] The update instruction of the update instruction unit 148 may indicate an address indicating the storage destination of the update file. For example, by indicating the address of the storage destination of the update file, the update instruction can indirectly instruct to update the software of the virtual machine using the update file. Also, by indicating the address of the actual storage 130 that stores the update file, the update instruction can indirectly instruct to update the software of the virtual machine using the update file stored in the actual storage 130 by accessing the actual storage 130. The update instruction may further include information indicating whether to distribute the update file to the virtual machine.
[0043] The update unit 143 updates the software of the first virtual machine 140 based on the instruction from the update instruction unit 148. When the update process of the software of the first virtual machine 140 is completed, the update unit 143 notifies the distribution control unit 142 that the update is completed. The update unit 143 and the update units 151, 161, 231 of other virtual machines described later execute part or all of the functions referred to as UCM subordinate in AUTOSAR, for example.
[0044] The virtual storage 144 is a storage area virtually provided to the first virtual machine 140 by virtualizing the storage area of the physical storage 130. Therefore, a file stored in the virtual storage 144 is also regarded as a file stored in the physical storage 130. The same applies to the virtual storage 152 of the second virtual machine 150 and the virtual storage 162 of the third virtual machine 160 described below.
[0045] (ii) Regarding the second virtual machine 150 and the third virtual machine 160 The second virtual machine 150 is a virtual machine managed by the hypervisor 110, similar to the first virtual machine 140. The second virtual machine 150 has an update unit 151 and a virtual storage 152.
[0046] The third virtual machine 160 is a virtual machine managed by the hypervisor 120, different from the first virtual machine 140 and the second virtual machine 150. The third virtual machine 160 has an update unit 161 and a virtual storage 162.
[0047] Based on the update instruction from the update instruction unit 148 of the first virtual machine 140, the update units 151 and 161 perform software updates for their respective virtual machines. When the software update process is completed, the update units 151 and 161 notify the distribution control unit 142 of the first virtual machine 140 that the update is complete.
[0048] The virtual storages 152 and 162 are storage areas virtually provided to the second virtual machine 150 and the third virtual machine 160, respectively. When an update file is distributed from the distribution unit 147 of the first virtual machine 140, the update file is stored in the respective virtual storages 152 and 162.
[0049] As described above, the second virtual machine 150 and the third virtual machine 160 are virtually connected to the first virtual machine 140, and data can be exchanged between these virtual machines.
[0050] (2) Regarding ECU20 ECU20 includes a hypervisor 210, a physical storage 220 which is hardware, and a fourth virtual machine 230 managed by the hypervisor 210.
[0051] ECU10 and ECU20 are connected by an in-vehicle network, and the first virtual machine 140 of ECU10 and the fourth virtual machine 230 of ECU20 are virtually connected via the in-vehicle network.
[0052] The hypervisor 210 is software for virtualizing ECU20. The fourth virtual machine 230 is constructed on the hypervisor 210.
[0053] The physical storage 220 is a hardware memory like the physical storage 130 of ECU10, which can be a volatile memory such as SRAM or DRAM, a non-volatile memory such as ROM, flash memory, or a hard disk.
[0054] The fourth virtual machine 230 of ECU20 has an update unit 231 and a virtual storage 232, similar to the second virtual machine 150 and the third virtual machine 160 described above.
[0055] The update unit 231 updates the software of the fourth virtual machine 230 based on an update instruction from the update instruction unit 148 of the first virtual machine 140, and notifies the distribution control unit 142 of the first virtual machine 140 that the update is completed when the software update process is completed.
[0056] The virtual storage 232 is a storage area virtually provided in the physical storage 220. When an update file is distributed from the distribution unit 147, the update file may be stored in the virtual storage 232.
[0057] (3) Parentheses Above, the configurations of the electronic control unit and the electronic system common to Embodiments 1 and 2 have been described. Note that FIG. 1 shows an example where ECU 10 has two hypervisors (110, 120) and ECU 20 has one hypervisor (210). However, the number of hypervisors is merely an example and is not limited thereto. That is, ECU 10 may have only one hypervisor, and ECU 20 may have two or more hypervisors. Also, the number of virtual machines built on the hypervisor is arbitrary.
[0058] In addition, although a configuration has been described in which only the first virtual machine 140 has the functions of the file acquisition unit and the distribution control unit, other virtual machines may also have these functions, similar to the first virtual machine 10.
[0059] 2. Embodiment 1 In this embodiment, a configuration will be described in which it is determined whether to distribute an update file to a virtual machine to be updated according to whether the hypervisor of the virtual machine to be updated satisfies a predetermined condition.
[0060] (1) Configuration of the First Virtual Machine 140 The determination unit 146 in this embodiment determines whether a hypervisor (corresponding to the "first hypervisor") 110 that manages the first virtual machine 140 (corresponding to the "first virtual machine") having the distribution control unit 142 is "the same" as a hypervisor (corresponding to the "second hypervisor") that manages the virtual machine to be updated (corresponding to the "second virtual machine"). If it is determined that the hypervisors are the same, the determination unit 146 determines not to distribute the update file to the virtual machine to be updated. On the other hand, if it is determined that the hypervisors are different, the determination unit 146 determines to distribute the update file to the virtual machine to be updated.
[0061] Here, "the same" includes cases where the hypervisors are common, as well as cases where the hypervisors are different but have the same functions and actions.
[0062] The determination unit 146 determines whether the hypervisor 110 that manages the hypervisor and the virtual machine to be updated is the same based on the response signals from the virtual machines for the search signals sent to the update units of the respective virtual machines. Therefore, the response signals in the present embodiment include information that can identify the hypervisor that manages each virtual machine, for example, the identification ID of the hypervisor.
[0063] Note that the determination unit 146 may also send a search signal to the update unit 143 of the first virtual machine 140 in the same manner as the update units of other virtual machines. In this case, the determination unit 146 naturally determines that the hypervisor 110 and the hypervisor that manages the first virtual machine 140, which is the virtual machine to be updated, are the same based on the response signal from the update unit 143.
[0064] In the example of FIG. 1, both the hypervisor that manages the first virtual machine 140 and the hypervisor that manages the second virtual machine 150 are the hypervisor 110 and are the same. Therefore, the determination unit 146 determines not to distribute the update file to the second virtual machine 150.
[0065] The hypervisor 110 that manages the first virtual machine 140 and the hypervisor 120 that manages the third virtual machine 160 are different hypervisors. Therefore, the determination unit 146 determines to distribute the update file to the third virtual machine 160.
[0066] Similarly, the hypervisor 110 that manages the first virtual machine 140 and the hypervisor 210 that manages the fourth virtual machine 230 are different hypervisors. Therefore, the determination unit 146 determines to distribute the update file to the fourth virtual machine 230.
[0067] In the following embodiments, a configuration is described in which the determination unit 146 determines whether the hypervisor 110 and the hypervisor that manages the virtual machine to be updated are the same based on the response signal. However, the determination unit 146 may determine the hypervisor regardless of the response signal. For example, in an in-vehicle system, when it is previously known which hypervisor each virtual machine is managed by, it is assumed that the file acquisition unit 141 and the distribution control unit 142 have information on the virtual machines and the hypervisors that manage each virtual machine in advance. In such a case, the determination unit 146 may determine whether the hypervisor 110 and the hypervisor that manages the virtual machine to be updated are the same based on an instruction from the file acquisition unit 141 or information held by the distribution control unit 142 without using the response signal.
[0068] Note that, in this embodiment, a case where the two hypervisors (110, 120) of the ECU 10 are different hypervisors is described as an example. However, when the hypervisors 110 and 120 are provided on one host OS, the determination unit 146 may determine that the hypervisors 110 and 120 are the same. When a plurality of hypervisors are provided on one host OS, the guest OSs constructed on each hypervisor can access the same area in the actual storage 130. In this case, the hypervisors 110 and 120 have the same functions and operations in that they construct guest OSs that can access the same area. Thus, when the functions and operations of the hypervisors 110 and 120 are the same, the determination unit 146 may determine that the two hypervisors are "the same".
[0069] The distribution unit 147 distributes the update file only to the virtual machines for which the determination unit 146 has determined to distribute the update file when the hypervisor 110 and the hypervisor that manages the virtual machine to be updated are different. Therefore, the distribution unit 147 of this embodiment distributes the update file to the third virtual machine 160 and the fourth virtual machine 230.
[0070] The update instruction unit 148 instructs the update unit of the virtual machine to be updated to update the software of the virtual machine. The update instruction unit 148 instructs the update unit 143 of the first virtual machine 140 and the update unit 151 of the second virtual machine 150 to update the software of the second virtual machine 150 by accessing the actual storage 130 and using the update file stored in the actual storage 130. In addition, the update instruction unit 148 instructs the update unit 161 of the third virtual machine 160 and the update unit 231 of the fourth virtual machine 230 to update the software of each virtual machine using the update file delivered by the delivery unit 147.
[0071] (2) Configuration of the second virtual machine 150 When the update unit 151 of the second virtual machine 150 receives an update instruction from the update instruction unit 148, it accesses the actual storage 130, refers to the update file stored in the actual storage 130, and uses the update file to update the software of the second virtual machine 150.
[0072] (3) Configuration of the third virtual machine 160 The virtual storage 162 of the third virtual machine 160 stores the update file delivered from the delivery unit 147. When the update unit 161 of the third virtual machine 160 receives an update instruction from the update instruction unit 148, it uses the update file stored in the virtual storage 162 to update the software of the third virtual machine 160.
[0073] (4) Configuration of the fourth virtual machine 230 The actual storage 220 or the virtual storage 232 of the fourth virtual machine 230 stores the update file delivered from the delivery unit 147. The storage destination of the update file may be either the actual storage 220 or the virtual storage 232. When the update unit 231 of the fourth virtual machine 230 receives an update instruction from the update instruction unit 148, it updates the software of the fourth virtual machine 230 using the update files stored in the actual storage 220 or the virtual storage 232.
[0074] (5) Operation of the electronic control system 1 Next, the operation regarding the update of the software of the virtual machine will be described with reference to FIGS. 2 to 4. FIG. 2 is a diagram showing the operation of the entire electronic control system 1. FIG. 3 shows the operation of the distribution control unit 142 of the first virtual machine 140, and FIG. 4 shows the operation of the update unit included in each virtual machine. The reference numerals shown in FIG. 2 correspond to those shown in FIGS. 3 and 4, and the same reference numerals indicate the same processing.
[0075] Note that the operations of the distribution control unit 142 and the update unit shown in FIGS. 3 and 4 are also regarded as the operations of each electronic control device (ECU10, ECU20). Further, the operations of each electronic control device not only show a software update method executed by the electronic control device but also show the processing procedures of a software update program executable by the electronic control device. And these processes are not limited to the order shown in FIGS. 2 to 4. That is, the order may be changed as long as there are no restrictions such as using the result of the previous step in a certain step. The same applies to FIG. 7 of Embodiment 2.
[0076] First, the operation of the distribution control unit 142 will be mainly described with reference to FIGS. 2 and 3. The distribution control unit 142 receives the update file group transferred from the file acquisition unit 141 (FIGS. 2 and 3: S101). This update file group is a file for updating the software of the virtual machine, and is a file acquired by the file acquisition unit 141 from a server device outside the electronic control system 1. The file splitting unit 145 of the distribution control unit 142 performs a parsing process of splitting the update file group received in S101 into update files for each virtual machine (FIGS. 2 and 3: S102). The file splitting unit 145 stores the updated file split in S102 in the actual storage 130 (FIGS. 2 and 3: S103). The determination unit 146 of the distribution control unit 142 transmits a search signal for the content of inquiring information about the virtual machine to each virtual machine in order to determine whether to distribute the updated file to the virtual machine to be updated (FIGS. 2 and 3: S104).
[0077] The determination unit 146 receives the response signals transmitted from the update units (143, 151, 161, 231) of the first to fourth virtual machines (FIGS. 2 and 3: S105).
[0078] Based on the response signal received in S105, the determination unit 146 determines whether to distribute the updated file to the virtual machine to be updated (FIGS. 2 and 3: S106). As described above, when the hypervisor 110 that manages the first virtual machine 140 and the hypervisor that manages the virtual machine to be updated are the same, the determination unit 146 of the present embodiment determines not to distribute the updated file, and when the hypervisors are different, it determines to distribute the updated file.
[0079] Here, when it is determined in S106 not to distribute the updated file, the update instruction unit 148 of the distribution control unit 142 transmits an update instruction instructing to update the software of the virtual machine by accessing the actual storage 130 (FIGS. 2 and 3: S107). On the other hand, when it is determined in S106 to distribute the updated file, the update instruction unit 148 of the distribution control unit 142 transmits an update instruction instructing to update the software of the virtual machine using the updated file distributed by the distribution unit 147 (FIGS. 2 and 3: S108). The distribution unit 147 of the distribution control unit 142 distributes the updated file to the virtual machine determined to distribute the updated file in S106, that is, the virtual machine determined that the first hypervisor and the hypervisor that manages the virtual machine to be updated are the same (FIGS. 2 and 3: S109). The distribution unit 147 of the present embodiment distributes the updated file to the third virtual machine 160 and the fourth virtual machine 230.
[0080] The update unit of each virtual machine performs an update process (S110). The update process in the update unit will be described later.
[0081] The distribution control unit 142 receives an update completion notification indicating that the update process has been completed from the update unit of each virtual machine for which the update process in S110 has been completed (FIGS. 2 and 3: S111).
[0082] When the distribution control unit 142 receives a notification indicating that the update process has been completed from the update unit of each virtual machine, it notifies the file acquisition unit 141 that the update process of each virtual machine has been completed (FIGS. 2 and 3: S112).
[0083] Next, with reference to FIGS. 2 and 4, the operation of the update unit of each virtual machine will be mainly described. The update units (143, 151, 161, 231) of the first to fourth virtual machines receive the search signal transmitted from the determination unit 146 in S104 (S201). Each update unit transmits a response signal to the query of the search signal to the determination unit 146 (S202).
[0084] Next, the update unit receives the update instruction transmitted from the update instruction unit 148 in S107 and S108 (S203). Here, when the update instruction received in S203 is an update instruction by accessing the actual storage (S204: Yes), that is, when it is the update instruction transmitted from the update instruction unit 148 in S107, the virtual machine is updated using the update file stored in the actual storage 130 (S110). In the example of the present embodiment, the update unit 143 of the first virtual machine 140 and the update unit 151 of the second virtual machine 150 receive the update instruction of S107. Therefore, the update unit 143 and the update unit 151 access the actual storage 130 and update the first virtual machine 140 and the second virtual machine 150, respectively, using the update file stored in the actual storage 130 (S110).
[0085] On the other hand, if the update instruction received in S203 is not an update instruction by accessing the actual storage (S204: No), that is, in the case of the update instruction transmitted from the update instruction unit 148 in S108, the update unit receives the update file distributed in S109 (S205). In the example of the present embodiment, the update unit 161 of the third virtual machine 160 and the update unit 231 of the fourth virtual machine 230 receive the update instruction in S108 and further receive the update file distributed in S109 (S205). Then, the update unit 161 and the update unit 231 update the software of the virtual machine using the update file received in S205 (S110).
[0086] When the update process of S110 is completed, each update unit of the virtual machine transmits an update completion notification indicating that the update process is completed to the distribution control unit 142 (S206).
[0087] (6) Parentheses According to the above configuration, the virtual machine that performs distribution control of the update file for updating the software of the virtual machine distributes the update file only to the virtual machines managed by a hypervisor different from the hypervisor that manages the virtual machine, and does not distribute the update file to the virtual machines managed by the same hypervisor. As a result, the distribution process of the update file for some virtual machines can be omitted, so that the load on the distribution process can be reduced and the time required to update the software of the virtual machine can be shortened. Furthermore, by omitting the distribution process of the update file for some virtual machines, the communication volume between ECUs can be suppressed, so that the load and congestion of the communication line can be reduced.
[0088] (7) Modification Example 1 of Embodiment 1 In FIG. 1, a configuration in which the ECU 10 has two hypervisors (hypervisor 110 and hypervisor 120) was described. For example, when an ECU is equipped with a plurality of microprocessors like a dual processor, a configuration in which one ECU includes a plurality of hypervisors is assumed.
[0089] However, each ECU constituting the electronic control system 1 may all be single processors, and all ECUs may be equipped with only one hypervisor. In such a case, a configuration in which each ECU constituting the electronic control system 1 includes a plurality of hypervisors is not assumed. Therefore, the determination unit 146 determines whether the ECU having the virtual machine having the distribution control unit 142 and the ECU having the virtual machine to be updated are the same, thereby determining whether the hypervisor 110 managing the first virtual machine 140 and the hypervisor managing each virtual machine are the same.
[0090] For example, the determination unit 146 transmits a search signal for inquiring about the device ID of the ECU on which the virtual machine is mounted to each virtual machine. Then, based on the response signals from the respective virtual machines, the determination unit 146 determines whether the ECU 10 having the first virtual machine 140 and the ECU having the virtual machine to be updated are the same. Here, when the determination unit 146 determines that they are the same ECU, it determines that the hypervisor 110 managing the first virtual machine 140 and the hypervisor to be updated are the same.
[0091] According to this modification example, by determining the ECU, it is possible to determine whether the hypervisor managing the virtual machine that performs distribution control of the update file and the hypervisor managing the virtual machine to be updated are the same, and it becomes easy to determine whether to distribute the update file to the virtual machine to be updated.
[0092] (8) Modification Example 2 of Embodiment 1 In the above-described embodiments, the description was made on the premise that the hypervisor 110 included in the ECU 10 and the hypervisor 210 included in the ECU 20 are different. However, a common hypervisor may manage virtual machines across ECUs.
[0093] In this Modification 2, the hypervisor 110 included in the ECU 10 and the hypervisor 210 included in the ECU 20 are the same hypervisor, and the first virtual machine 140 and the fourth virtual machine 230 are managed by the same hypervisor. Since the hypervisor 110 that manages the first virtual machine 140 and the hypervisor 210 that manages the fourth virtual machine 230 are the same, the determination unit 146 of this Modification 2 determines not to distribute the update file to the fourth virtual machine 230.
[0094] Since the update file is not distributed to the fourth virtual machine 230, the update unit 231 of the fourth virtual machine 230 accesses the actual storage 130 included in the ECU 10 and updates the software of the fourth virtual machine 230 using the update file stored in the actual storage 130.
[0095] 3. Embodiment 2 In this embodiment, a configuration for determining whether to distribute an update file based on the safety level indicating the safety of the virtual machine that performs distribution control of the update file and the safety level indicating the safety of the virtual machine to be updated will be mainly described as the difference from Embodiment 1.
[0096] (1) Configuration of ECU 10 FIG. 5 is a diagram showing the actual storage 130 of the ECU 10 of this embodiment. The actual storage 130 of this embodiment has five safety-level storage areas.
[0097] The safety level in this embodiment is, for example, a safety level set based on the Automotive Safety Integrity Level (ASIL). ASIL is an index defined in the ISO 26262 standard and classified according to the functional safety of vehicles. ASIL has levels of ASIL-A, ASIL-B, ASIL-C, and ASIL-D in ascending order of safety level. Furthermore, when specific functional safety does not need to be applied, quality management called QM (Quality Management) is applied. QM indicates a safety level lower than ASIL-A. ASIL and QM are assigned to hardware and software respectively.
[0098] In the example shown in FIG. 5, the actual storage 130 has storage areas for QM, ASIL-A, ASIL-B, ASIL-C, and ASIL-D respectively. The storage area of the actual storage 130 used by the virtual machine of the ECU 10 corresponds to the safety level of the virtual machine itself or each component of the virtual machine. For example, when the safety level of the virtual machine is ASIL-A, the storage area of the actual storage 130 used by the virtual machine is the storage area for ASIL-A among the storage areas shown in FIG. 5. Even if the safety level of the virtual machine is ASIL-A, if a highly independent component of the virtual machine is ASIL-B, the component may use the storage area for ASIL-B.
[0099] Each virtual machine or the components of the virtual machine cannot access the storage area of the actual storage 130 with a safety level higher than its own safety level. For example, a virtual machine with a safety level of ASIL-B cannot access the storage areas for ASIL-C and ASIL-D.
[0100] In the following embodiments, a configuration for determining whether to distribute an update file is described using a safety level indicating the safety of a virtual machine. Here, the safety level indicating the safety of a virtual machine may be the safety level of the virtual machine assigned to the virtual machine, or may be the safety level assigned to a specific configuration of the virtual machine. For example, the safety level assigned to the distribution control unit 142 of the first virtual machine 140 may be used as the safety level regarding the first virtual machine 140, and the safety level assigned to the update unit 151 of the second virtual machine 150 may be used as the safety level of the second virtual machine 150.
[0101] As another example, the safety level of a virtual machine may be, for example, a value equal to the lowest safety level among the safety levels assigned to each configuration of the virtual machine. In this case, in the first virtual machine 140, when the safety levels of the file acquisition unit 141, the distribution control unit 142, and the virtual storage 144 are ASIL-C and the safety level of the update unit 143 is ASIL-B, the safety level regarding the first virtual machine 140 is ASIL-B.
[0102] Hereinafter, the present embodiment will be described on the assumption that the safety level of the first virtual machine 140 is ASIL-B, the safety level of the second virtual machine 150 is ASIL-A, the safety level of the third virtual machine is ASIL-C, and the safety level of the fourth virtual machine is QM.
[0103] (2) Configuration of the First Virtual Machine 140 The determination unit 146 of the present embodiment transmits a search signal for inquiring about the safety level of each virtual machine to each virtual machine. Then, a response signal indicating the safety level of each virtual machine is received from each virtual machine.
[0104] The determination unit 146 determines whether to distribute the update file to the virtual machine to be updated based on the safety level A (corresponding to the "first safety level") indicating the safety regarding the first virtual machine 140 having the distribution control unit 142 and the safety level B (corresponding to the "second safety level") indicating the safety regarding the virtual machine to be updated.
[0105] FIG. 6 shows how the determination unit 146 determines whether to distribute or not distribute an update file based on the safety level A of the first virtual machine 140 and the safety level B of the virtual machine to be updated.
[0106] FIG. 6 shows an example of determining whether to distribute an update file based on the safety levels A and B of the virtual machine itself. As described above, the safety level A may be the safety level assigned to the distribution control unit 142 of the first virtual machine 140, and the safety level B may be the safety level assigned to the update unit of the virtual machine to be updated.
[0107] FIG. 6 shows that when the safety level A of the first virtual machine 140 is "higher than" the safety level B of the virtual machine to be updated, the determination unit 146 determines to distribute the update file to the virtual machine to be updated. As described above, when the safety level A of the first virtual machine is higher than the safety level B of the virtual machine to be updated, the update unit of the virtual machine to be updated cannot access the storage area of the actual storage 130 used by the first virtual machine 140. Therefore, when the update unit of the virtual machine to be updated cannot access the storage area of the actual storage 130 used by the first virtual machine 140, the determination unit 146 determines to distribute the update file.
[0108] Here, "higher than" includes both cases where the value is the same as the comparison target and cases where it is not.
[0109] Note that in the table of FIG. 6, an example of determining to distribute the update file is shown only when the storage area of the actual storage 130 used by the first virtual machine 140 cannot be accessed. However, a configuration may be adopted in which the update file is also distributed when the safety level A is equal to the safety level B.
[0110] The determination unit 146 can identify the safety level of the virtual machine to be updated based on the response signals from each virtual machine for the search signals sent to the update units of the respective virtual machines. Therefore, the response signals in this embodiment include information indicating the safety level of each virtual machine.
[0111] Note that the determination unit 146 may also send a search signal to the update unit 143 of the first virtual machine 140 in the same manner as the update units of other virtual machines. In this case, the determination unit 146 naturally determines that the safety level of the first virtual machine 140 is the same as the safety level of the virtual machine to be updated based on the response signal from the update unit 143.
[0112] In the example of this embodiment, the safety level (ASIL-B) of the first virtual machine 140 is higher than the safety levels (ASIL-A) of the second virtual machine 150 and (QM) of the fourth virtual machine 230. Therefore, the determination unit 146 determines to distribute the update file to the second virtual machine 150 and the fourth virtual machine 230. On the other hand, since the safety level (ASIL-B) of the first virtual machine 140 is lower than the safety level (ASIL-C) of the third virtual machine 160, the determination unit 146 determines not to distribute the update file to the third virtual machine 160.
[0113] The update instruction unit 148 instructs the second virtual machine 150 and the fourth virtual machine 230 to update the software of the virtual machine using the update file distributed by the distribution unit 147. On the other hand, the update instruction unit 148 instructs the first virtual machine 140 and the third virtual machine 160 to update the software of the virtual machine using the update file stored in the actual storage 130 by accessing the ASIL-B storage area of the actual storage 130.
[0114] (3) Configuration of the Second Virtual Machine 150 The virtual storage 152 of the second virtual machine 150 stores the update file distributed by the distribution unit 147. When the update unit 151 of the second virtual machine 150 receives an update instruction from the update instruction unit 148, it updates the software of the second virtual machine 150 using the update file stored in the virtual storage 152. Note that the virtual storage 152 is a region obtained by virtualizing the ASIL-A storage region corresponding to the safety level of the second virtual machine 150 among the storage regions of the actual storage 130.
[0115] (4) Configuration of the third virtual machine 160 The update unit 161 of the third virtual machine 160 accesses the ASIL-B storage region of the actual storage 130, refers to the update file stored in the actual storage 130, and updates the software of the third virtual machine 160 using the update file.
[0116] (5) Configuration of the fourth virtual machine 230 The actual storage 220 or the virtual storage 232 of the fourth virtual machine 230 stores the update file distributed from the distribution unit 147. The storage destination of the update file may be either the actual storage 220 or the virtual storage 232. When the update unit 231 of the fourth virtual machine 230 receives an update instruction from the update instruction unit 148, it updates the software of the fourth virtual machine 230 using the update file stored in the actual storage 220 or the virtual storage 232.
[0117] (6) Operations of the virtual machines included in the electronic control system 1 and the ECUs 10 and 20 FIG. 7 shows the operation of the entire electronic control system 1 of the present embodiment. The operations of the distribution control unit 142 and the update unit of the first virtual machine 140 of the present embodiment are the same as those in FIGS. 3 and 4 of the first embodiment, and will be described with reference to FIGS. 3 and 4.
[0118] The processes of S101 to S112 shown in FIG. 7 are the same as those of the electronic control system 1 of Embodiment 1 shown in FIG. 2. However, in S106 of this embodiment, the determination method of whether the determination unit 146 of the first virtual machine 140 distributes the update file to the virtual machine to be updated is different from that of Embodiment 1. In S106 of this embodiment, the determination unit 146 determines whether to distribute the update file to the virtual machine to be updated based on the safety level of the first virtual machine 140 and the safety level of the virtual machine to be updated. As described above, in this embodiment, since the safety level of the first virtual machine 140 is higher than the safety levels of the second virtual machine 150 and the fourth virtual machine 230, the determination unit 146 determines to distribute the update file to the second virtual machine 150 and the fourth virtual machine 230. Also, since the safety level of the first virtual machine 140 is lower than the safety level of the third virtual machine 160, the determination unit 146 determines not to distribute the update file to the third virtual machine 160.
[0119] The update instruction unit 148 of the distribution control unit 142 instructs the update unit 143 of the first virtual machine 140 and the update unit 161 of the third virtual machine 160 to update the software of the virtual machine by accessing the ASIL-B storage area of the actual storage 130 (FIG. 7, FIG. 3: S107). The update instruction unit 148 further instructs the update unit 151 of the second virtual machine 150 and the update unit 231 of the fourth virtual machine 230 to update the software of the virtual machine using the update file distributed by the distribution unit 147 (FIG. 7, FIG. 3: S108). The distribution unit 147 of the distribution control unit 142 distributes the update file to the second virtual machine 150 and the fourth virtual machine 230 (FIG. 7, FIG. 3: S109).
[0120] The update unit 143 of the first virtual machine 140 receives the update instruction transmitted from the update instruction unit 148 in S107 (S203). Since this update instruction is an update instruction by accessing the actual storage (S204: Yes), the update unit 143 accesses the ASIL-B storage area of the actual storage 130, and updates the first virtual machine 140 using the update file stored in the actual storage 130 (FIG. 7, FIG. 4: S110). Similarly, when the update unit 161 of the third virtual machine 160 receives the update instruction transmitted from the update instruction unit 148 in S107 (S203, S204: Yes), it accesses the ASIL-B storage area of the actual storage 130, and updates the third virtual machine 160 using the update file stored in the actual storage 130 (FIG. 7, FIG. 4: S110).
[0121] On the other hand, the update unit 151 of the second virtual machine 150 receives the update instruction transmitted from the update instruction unit 148 in S108 (S203). Since this update instruction is not an update instruction by accessing the actual storage (S204: No), the update unit 151 further receives the update file distributed from the distribution unit 147 (S205). The update unit 151 updates the second virtual machine 150 using the update file distributed from the distribution unit 147 based on the update instruction (FIG. 7, FIG. 4: S110). Similarly, the update unit 231 of the fourth virtual machine 230 receives the update instruction transmitted from the update instruction unit 148 in S108 (S203, S204: No), and receives the update file distributed from the distribution unit 147 (S205). Then, the update unit 231 updates the fourth virtual machine 230 using the update file distributed from the distribution unit 147 based on the update instruction (FIG. 7, FIG. 4: S110).
[0122] (7) Parentheses According to the above configuration, the virtual machine that controls the distribution of update files for updating the software of the virtual machine distributes the update files only to virtual machines having a security level higher than the security level of the virtual machine, and does not distribute the update files to virtual machines having a security level equal to or lower than the security level of the virtual machine. Thereby, since the distribution process of the update files for some virtual machines can be omitted, the load associated with the distribution process can be reduced, and the time required to update the software of the virtual machine can be shortened.
[0123] (8) Modification Example 1 of Embodiment 2 In the above-described Embodiment 2, a configuration in which the update file is distributed only when the security level of the first virtual machine 140 is higher than the security level of the virtual machine to be updated has been described. However, a configuration in which the update file is distributed as long as the security level of the first virtual machine 140 is different from the security level of the virtual machine to be updated may be employed.
[0124] FIG. 8 shows how the determination unit 146 of this Modification Example 1 determines whether to distribute or not distribute the update file based on the security level A of the first virtual machine 140 and the security level B of the virtual machine to be updated.
[0125] In the example shown in FIG. 8, when the security level A of the first virtual machine 140 is different from the security level B of the virtual machine to be updated, the determination unit 146 determines to distribute the update file to the virtual machine to be updated. On the other hand, when the security level A of the first virtual machine 140 is equal to the security level B of the virtual machine to be updated, the determination unit 146 determines not to distribute the update file to the virtual machine to be updated.
[0126] Similar to the above-described Embodiment 2, when the safety level of the first virtual machine 140 is ASIL-B, the safety level of the second virtual machine 150 is ASIL-A, the safety level of the third virtual machine is ASIL-C, and the safety level of the fourth virtual machine is QM, the safety levels of the first virtual machine 140 and the second to fourth virtual machines are all different. Therefore, the determination unit 146 determines to distribute the update file to all of the second to fourth virtual machines. Then, it is determined not to distribute the update file only to the first virtual machine itself.
[0127] In this modified example, by limiting the virtual machines that can access the storage area of the actual storage used by the virtual machine that performs the update file distribution control to the virtual machines to be updated having the same safety level and restricting access from virtual machines having different safety levels, the security of the actual storage can be ensured.
[0128] (9) Modified Example 2 of the Second Embodiment Although the above-described Embodiments 1 and 2 have been described as different embodiments, in this modified example, the features of Embodiment 1 are applied to Embodiment 2.
[0129] The determination unit 146 of this modified example determines whether to distribute the update file to the virtual machine to be updated based on whether the hypervisor 110 that manages the first virtual machine 140 is the same as the hypervisor that manages the virtual machine to be updated, in addition to the safety level of the first virtual machine 140 and the safety level of the virtual machine to be updated.
[0130] For example, when the hypervisor 110 that manages the first virtual machine 140 is different from the hypervisor that manages the virtual machine to be updated and the safety level of the first virtual machine 140 is higher than the safety level of the virtual machine to be updated, the determination unit 146 determines to distribute the update file to the virtual machine to be updated.
[0131] Alternatively, the determination unit 146 may select either the determination method described in Embodiment 1 or the determination method described in Embodiment 2, and determine whether to distribute the update file to each virtual machine.
[0132] 4. Modification Examples of Electronic Control Devices and Electronic Control Systems In this section, modification examples of the configurations of the electronic control device and the electronic control system common to Embodiments 1 and 2 will be described.
[0133] In the above-described example, for instance, the case where the ECU 10 is an ECU based on the AP and the ECU 20 is an ECU based on the CP has been described. However, each virtual machine constructed in the ECU may have a platform such as the AP or the CP.
[0134] FIG. 9 is a diagram for explaining an example in which each virtual machine has its own platform (hereinafter, PF). In FIG. 9, the description of each function realized by the distribution control unit 142 is omitted. Similar to FIG. 1, the distribution control unit 142 realizes a file division unit 145, a determination unit 146, a distribution unit 147, and an update instruction unit 148.
[0135] In FIG. 9, the first virtual machine 140 has the first PF 1401, the second virtual machine 150 has the second PF 1501, the third virtual machine 160 has the third PF 1601, and the fourth virtual machine 230 has the fourth PF 2301. FIG. 9 further shows applications (1402, 1502, 1602, 2302) operating on the PF of each virtual machine.
[0136] In addition to AP and CP, there are various types of PF in PF, and as the first to fourth PFs (1401, 1501, 1601, 2301), any PF can be applied. For example, by applying the first PF1401 as AP, the second PF1501 as CP, and the third PF1601 as a PF other than AP and CP, a plurality of virtual machines with different PFs may coexist in one ECU. By mixing a plurality of virtual machines with different PFs in one ECU in this way, it becomes possible to integrate a plurality of functions into one ECU, and as a result, it becomes possible to reduce the total number of ECUs.
[0137] In the case of such a configuration, the OS of the virtual machine may be provided, for example, between the hypervisor and the PF, or configured to be integrated with the hypervisor or included in the PF.
[0138] The update unit of each virtual machine updates the software of the virtual machine. However, in the configuration of FIG. 9, the update unit may update the PF or the application operating on the PF as an update of the software of the virtual machine. For example, the update unit 143 updates the first PF1401 or the first application 1402.
[0139] Note that FIG. 9 illustrates that the file acquisition unit 141 is included in the first application 1402, and the distribution control unit 142 and the update unit 143 are included in the first PF1041. However, the software included in the first PF1401 may implement some or all of the functions of the file acquisition unit 141, or the first application 1402 may implement some or all of the functions of the distribution control unit 142 and the update unit 143. Similarly, the second to fourth applications (1502, 1602, 2302) may implement some or all of the functions of their respective update units (151, 161, 231).
[0140] FIG. 9 further shows a configuration in which the actual storage 130 of the ECU 10 has three storage areas, namely, a shared storage area 131, a software storage area 132, and a distribution file storage area 133.
[0141] The shared storage area 131 is an area for storing the update file that the file acquisition unit 141 has acquired and that the file splitting unit 145 has parsed. The software storage area 132 is an area for storing software that constitutes a virtual machine, such as the first to third PF1401, 1501, 1601 and the first to third applications 1402, 1502, 1602. The distribution file storage area 133 is an area for storing the update file distributed from the distribution unit 147. By virtualizing the distribution file storage area 133, virtual storage is constructed for each virtual machine.
[0142] In this modification example, the update unit instructed to update the software of the virtual machine using the update file stored in the actual storage 130 accesses the shared storage area 131 and uses the update file stored in the shared storage area 131 to update the software of the virtual machine, that is, the software stored in the software storage area 132. On the other hand, the update unit instructed to update the software of the virtual machine using the update file distributed by the distribution unit 147 uses the update file distributed from the distribution unit 147 and stored in the distribution file storage area 133 to update the software stored in the software storage area 132.
[0143] The actual storage 220 of the ECU 20 has a software storage area 222 and a distribution file storage area 223, similar to the actual storage 130. However, in the ECU 20, since there is no need to store the updated files acquired by the file acquisition unit, the actual storage 220 does not have a storage area corresponding to the shared storage area 131. The software storage area 222 and the distribution file storage area 223 store the software that constitutes the virtual machine and the updated files distributed from the distribution unit 147, respectively, similar to the software storage area 132 and the distribution file storage area 133.
[0144] Note that FIG. 9 illustrates the actual storage 130 as including all of the shared storage area 131, the software storage area 132, and the distribution file storage area 133. However, the actual storage 130 may be realized by a plurality of different storages. For example, although the software storage area 132 of this modification example is a non-volatile memory, the shared storage area 131 and the distribution file storage area 133 may be either non-volatile memory or volatile memory. Therefore, the shared storage area 131 and the distribution file storage area 133 may be respectively provided in the storage area of the actual storage 130 that is volatile memory, and the software storage area 132 may be provided in the storage area of the actual storage 130 that is non-volatile memory.
[0145] 5. Application to Domain Architecture Next, a configuration example when applying the electronic control system 1 in Embodiments 1 and 2 to the domain architecture will be described. The domain architecture classifies a plurality of ECUs into groups called domains according to their functions, roles, or network connections, and arranges a domain controller ECU (hereinafter, DC-ECU) that manages and controls a plurality of ECUs belonging to the same domain for each domain. In the domain architecture, since the ECUs can be organized and integrated according to functions and networks, in a system composed of a large number of ECUs such as an in-vehicle system, not only does it become easier to update the ECUs in the future, but it is also possible to suppress the increasing total number of ECUs.
[0146] (1) Overview of Domain Architecture FIG. 10 is a diagram schematically showing a domain architecture. The domain architecture shown in FIG. 10 has DC-ECUs 30A and 30B, a gateway ECU (hereinafter referred to as GW-ECU) 40, and ECUs 50A, 51A, 50B, and 51B.
[0147] Furthermore, the domain architecture shown in FIG. 10 has two domains. The first domain 2A has DC-ECU 30A and ECUs 50A and 51A, and the second domain 2B has DC-ECU 30B and ECUs 50B and 51B. As described above, domains are classified according to the functions and networks of ECUs. In the case of an in-vehicle system, for example, there are a domain for controlling the drive system of a vehicle, a domain for controlling autonomous driving, a domain for controlling entertainment devices such as an in-vehicle TV and an in-vehicle computer, and the like.
[0148] DC-ECU 30A controls ECUs 50A and 51A belonging to the first domain 2A, and DC-ECU 30B controls ECUs 50B and 51B belonging to the second domain 2B. For example, when the first domain 2A is a domain for controlling autonomous driving, DC-ECU 30A controls ECUs 50A and 51A such as a camera ECU, a radar ECU, a lidar ECU, a locator ECU, or an ECU equipped with various autonomous driving applications. DC-ECU 30A further has a sensor fusion application for integrating sensor information output from ECUs 50A and 51A, and may provide the output from the sensor fusion application to ECUs 50A and 51A.
[0149] GW-ECU 40 is an ECU that functions as a gateway device in an in-vehicle network. GW-ECU 40 is connected to a plurality of buses and is connected to other ECUs via each bus. GW-ECU 40 relays, for example, communication between domains. GW-ECU 40 further has a function as a gateway between the outside of the vehicle and the domain.
[0150] In FIG. 10, DC-ECU 30A, GW-ECU 40, ECU 50A, and 51A are described as different ECUs, but the functions of each of the above-described ECUs may be integrated into other ECUs. For example, some of the functions of ECU 50A and 51A may be integrated into DC-ECU 30A. In this case, the functions integrated into DC-ECU 30A may be realized by a virtual machine installed in DC-ECU 30A.
[0151] (2) Example of Application of Domain Architecture to Electronic Control System 1 In the above-described embodiment, the electronic control system 1 having ECU 10 and ECU 20 has been described. Here, when the domain architecture of FIG. 10 is applied to the electronic control system 1, ECU 10 that acquires an update file and distributes the update file to other virtual machines is preferably configured as DC-ECU 30A and 30B (corresponding to the "domain controller") in FIG. 10. In this case, DC-ECU 30A and 30B of the domain architecture each issue an update instruction to the ECUs belonging to the same domain and perform distribution of the update file as necessary. Therefore, DC-ECU 30A and 30B do not issue an update instruction or perform distribution of the update file to the virtual machines of the ECUs belonging to different domains.
[0152] For example, when ECU 10 is configured as DC-ECU 30A, it does not issue an update instruction or perform distribution of the update file to the ECUs (DC-ECU 30B, ECU 50B, 51B) included in the second domain 2B. And the ECUs that access the actual storage 130 of ECU 10 are limited to the ECUs belonging to the same domain, that is, the first domain 2A. Similarly, ECU 10 configured as DC-ECU 30B does not issue an update instruction or perform distribution of the update file to the ECUs included in the first domain 2A.
[0153] By adopting the domain architecture for the electronic control system 1, the communication between ECUs can be limited within the same or related domains, thus suppressing the communication volume of the entire vehicle network, and ultimately enhancing the responsiveness of the vehicle network.
[0154] Furthermore, by restricting access from ECUs in different domains, for example, even when an ECU belonging to one domain is under an external attack, unauthorized access to different domains can be prevented.
[0155] As another example, the ECU 10 may be configured as the GW-ECU 40 (corresponding to a "gateway device") in FIG. 10. In this case, the ECU 20 is configured as the DC-ECU 30A, 30B or the ECU 50A,B, 51A,B. In this case, only the actual storage 130 of the GW-ECU 40 will be accessed by ECUs belonging to various domains. Therefore, similar to the case where the ECU 10 is configured as a DC-ECU, even when an ECU belonging to one domain is under an external attack, unauthorized access to different domains can be prevented.
[0156] 6. Summary Above, the features of the electronic control device in each embodiment of the present invention and the electronic control system equipped with the electronic control device have been described.
[0157] Since the terms used in each embodiment are illustrative, they may be replaced with synonymous terms or terms including synonymous functions.
[0158] The block diagrams used in the description of the embodiments classify and organize the configuration of the device by function. Each block indicating a function is realized by an arbitrary combination of hardware or software. Also, since it shows the functions, such block diagrams can also be understood as a disclosure of a method invention and an invention of a program for realizing the method.
[0159] Regarding the processing, flow, and functional blocks that can be understood as those described in each embodiment, the order may be changed as long as there are no restrictions such as being related to using the results of other steps in the previous stage in one step.
[0160] The terms first, second, up to N (N is an integer), used in each embodiment and the claims are used to distinguish two or more configurations or methods of the same kind, and do not limit the order or superiority.
[0161] Although the electronic control device in each embodiment is assumed to be an in-vehicle electronic control device that constitutes in-vehicle equipment mounted on a vehicle, the electronic control device of the present invention is applied to any electronic control system unless specifically limited in the claims.
[0162] Also, examples of the form of the device of the present invention include the following. Examples of the form of parts include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of the form of semi-finished products include electronic control units (ECUs (Electric Control Units)) and system boards. Examples of the form of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. In addition, it includes devices having communication functions, etc., such as video cameras, still cameras, and car navigation systems.
[0163] Also, necessary functions such as antennas and communication interfaces may be added to each device.
[0164] In addition, the present invention can be realized not only by dedicated hardware having the configurations and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as a memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute this program.
[0165] Programs stored in non-transitory physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memories, CD / BDs, etc.) or internal storage devices (RAM, ROM, etc.)) can be provided to dedicated or general-purpose hardware via a communication line from a server with or without passing through the recording media. As a result, the latest functions can always be provided through program upgrades.
Industrial Applicability
[0166] Although the electronic control device of the present invention has been mainly described as an in-vehicle electronic control device mounted on an automobile, it can be applied to all moving bodies such as motorcycles, ships, railways, and airplanes. Further, it is applicable not only to moving bodies but also to all products including microcomputers.
Explanation of Reference Numerals
[0167] 1 Electronic control system, 10 Electronic control device, 110 Hypervisor, 120 Hypervisor, 130 Actual storage, 140 First virtual machine, 141 File acquisition unit, 144 Virtual storage, 146 Determination unit, 147 Distribution unit, 148 Update instruction unit, 150 Second virtual machine, 160 Third virtual machine, 210 Hypervisor, 230 Fourth virtual machine
Claims
1. An electronic control device having a virtual machine managed by a hypervisor, comprising: a file acquisition unit (141) that acquires a file for updating software; a storage unit (130, 144) that stores the file; and a first virtual machine (140) that is the virtual machine includes: a determination unit (146) that determines whether to distribute the file to a second virtual machine (150, 160, 230) based on a first safety level indicating the safety of the first virtual machine and a second safety level indicating the safety of the second virtual machine connected to the first virtual machine; a distribution unit (147) that distributes the file to the second virtual machine when the determination unit determines to distribute the file to the second virtual machine; The electronic control device (10) having the above.
2. The first virtual machine further includes: an update unit that updates the software of the first virtual machine using the file by accessing the storage unit. The electronic control device according to claim 1.
3. The determination unit determines to distribute the file to the second virtual machine when the first safety level is higher than the second safety level. The electronic control device according to claim 1.
4. The determination unit determines to distribute the file to the second virtual machine when the first safety level is different from the second safety level. The electronic control device according to claim 1.
5. The first virtual machine further includes an update instruction unit (148) that instructs the update of the second virtual machine, and the update instruction unit: when the determination unit determines to distribute the file to the second virtual machine, instructs to update the software of the second virtual machine using the file distributed by the distribution unit; when the determination unit determines not to distribute the file to the second virtual machine, instructs to update the software of the second virtual machine using the file by accessing the storage unit. The electronic control device according to claim 1.
6. The first safety level and the second safety level are Automotive Safety Integrity Level (ASIL). The electronic control device according to claim 1.
7. The storage unit is a storage unit (130) managed by the hypervisor. The first virtual machine and the second virtual machine are accessible to the storage unit only when updating using the file stored in the storage unit. The electronic control device according to claim 1.
8. The determination unit further determines whether a first hypervisor (110) that manages the first virtual machine and a second hypervisor (110, 120, 210) that manages the second virtual machine are the same, and determines whether to distribute the file to the second virtual machine. The electronic control device according to claim 1.
9. The first virtual machine has a platform (1401), and an application (1402) operating on the platform, The electronic control device according to claim 1.
10. The electronic control device further has the second virtual machines (150, 160), and the second virtual machine has a second platform (1501, 1601) different from the first platform that is the platform. The electronic control device according to claim 9.
11. The electronic control device is mounted on a moving body. The electronic control device according to any one of claims 1 to 10.
12. A software update method executed by an electronic control device having a virtual machine managed by a hypervisor, the method comprising: obtaining a file for updating software (S101); storing the file in a storage unit (130, 144) (S103); determining whether to distribute the file to a second virtual machine based on a first safety level indicating the safety of a first virtual machine (140) that is the virtual machine and a second safety level indicating the safety of a second virtual machine (150, 160, 230) connected to the first virtual machine (S106); and distributing the file to the second virtual machine when it is determined to distribute the file to the second virtual machine (S109). obtaining a file for updating software (S101); storing the file in a storage unit (130, 144) (S103); determining whether to distribute the file to a second virtual machine based on a first safety level indicating the safety of a first virtual machine (140) that is the virtual machine and a second safety level indicating the safety of a second virtual machine (150, 160, 230) connected to the first virtual machine (S106); distributing the file to the second virtual machine when it is determined to distribute the file to the second virtual machine (S109); Software update method.
13. A software update program executable by an electronic control device having a virtual machine managed by a hypervisor, the program comprising: obtaining a file for updating software (S101); storing the file in a storage unit (130, 144) (S103); obtaining a file for updating software (S101); storing the file in a storage unit (130, 144) (S103); Based on a first safety level indicating the safety of the first virtual machine (140) which is the virtual machine, and a second safety level indicating the safety of the second virtual machines (150, 160, 230) connected to the first virtual machine, it is determined whether to distribute the file to the second virtual machines (S106), When it is determined to distribute the file to the second virtual machines, the file is distributed to the second virtual machines (S109), A software update program that causes the electronic control device to execute processing.
14. An electronic control system having a first electronic control device (10) and a second electronic control device (20), The first electronic control device having the first virtual machine (140) A file acquisition unit (141) that acquires a file for updating software, A storage unit (130, 144) that stores the file, is provided, and the first virtual machine A determination unit (146) that determines whether to distribute the file to the second virtual machines based on a first safety level indicating the safety of the first virtual machine and a second safety level indicating the safety of the second virtual machine (230) included in the second electronic control device, A distribution unit (147) that distributes the file to the second virtual machines when the determination unit determines to distribute the file to the second virtual machines, has The second virtual machine has an update unit (231) that updates the second virtual machine using the file by accessing the storage unit or using the file distributed by the distribution unit, Electronic control system (1).
15. The electronic control system has domains (2A, 2B) including the first electronic control device and the second electronic control device, The first electronic control device is a domain controller (30A, 30B) that controls the electronic control devices included in the domain, The electronic control system according to claim 14.
16. The electronic control system has domains (2A, 2B) including the second electronic control device, The first electronic control device is a gateway device (40) connected to a plurality of buses, The second electronic control device is a domain controller (30A, 30B) that controls an electronic control device included in the domain and connected to the gateway device via one of the plurality of buses, or the electronic control device (50A, 51A, 50B, 51B) controlled by the domain controller. The electronic control system according to claim 14.
Citation Information
Patent Citations
Information processing apparatus and interface access method
JP2013161299A
On-vehicle computer, on-vehicle communication system, computer execution method, and computer program
JP2020173561A