Center, distribution control method, and distribution control program
The center optimizes software updates for vehicle electronic control units by determining the appropriate distribution package type, addressing inefficiencies in coordinating updates across multiple units and enhancing update efficiency.
Patent Information
- Application Number
- JP2024099515
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-06-20
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2041-04-06
AI Technical Summary
Existing software update methods for vehicle electronic control units, particularly those coordinating functions like autonomous driving, face inefficiencies due to the need for coordinated updates across multiple units and the difficulty in extracting individual update data from distribution packages, leading to repetitive operations and reduced efficiency.
A center that determines whether to distribute software updates in packages containing differential data or the latest version data based on the current and latest software versions, optimizing the update process by minimizing redundant operations.
This approach enhances the efficiency of software update processing by reducing the need for repetitive data downloads and user consent requests, thereby improving the overall update process.
Smart Images

Figure 0007715253000001 
Figure 0007715253000002 
Figure 0007715253000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a center or the like that can communicate with an OTA master that controls software updates of an electronic control unit mounted on a vehicle.
Background Art
[0002] A vehicle is equipped with a plurality of electronic control units (ECUs: Electronic Control Unit) for controlling the operation of the vehicle. The electronic control unit includes a processor, a temporary storage unit such as a RAM, and a non-volatile storage unit such as a flash ROM, and the processor realizes the control function of the electronic control unit by executing software stored in the storage unit. The software stored in each electronic control unit can be rewritten, and by updating to a newer version of the software, the functions of each electronic control unit can be improved or new vehicle control functions can be added.
[0003] As a technology for updating the software of an electronic control unit, an in-vehicle communication device connected to an in-vehicle network is wirelessly connected to a communication network such as the Internet, and a device responsible for the software update process of the vehicle downloads software from a center having a server function via wireless communication and installs the downloaded software in the electronic control unit, thereby performing OTA (Over The Air) technology for updating and adding the software of the electronic control unit is known.
[0004] When the vehicle's power supply or ignition is ON, the OTA master, which is the device responsible for the software update process of the vehicle using this OTA technology, can start with the transmission (update confirmation) of the software version information of the electronic control unit to the center via the in-vehicle communication device (for example, refer to Patent Document 1). When the OTA master downloads the update data from the center via OTA, it notifies the user that there is update data by displaying it on the in-vehicle display device or the like, and starts the installation and activation of the update data when the user's consent is received by operating an input device such as a button.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] Among the control functions provided in a vehicle, there are some that are realized by the coordinated operation of multiple electronic control units (or actuators), such as, for example, autonomous driving. In order for the autonomous driving function to operate normally, the control functions of the software of the multiple electronic control units that realize autonomous driving need to be coordinated with each other. When the function of the software of any of the electronic control units that realize autonomous driving is updated, it is necessary to also update the function of the software of the other electronic control units that realize autonomous driving in accordance with this function update. The software of the multiple electronic control units that need to mutually coordinate control functions is usually updated as a set. Also, in order to reduce the amount of data transmitted from the center to the vehicle, the software update data is provided as differential data before and after the update. That is, the software of the multiple electronic control units that need to mutually coordinate control functions is registered at the center in the form of a distribution package that includes the differential data of each software. This distribution package is designed so that it cannot be opened at the center in order to prevent software tampering, etc., and it is difficult to extract only the update data of one software from the distribution package.
[0007] When an electronic control unit is replaced due to a failure or the like, the version of the software of the electronic control unit may change before and after the replacement. If the replaced electronic control unit is one of the multiple electronic control units that need to mutually coordinate control functions, such as an electronic control unit that realizes the autonomous driving function, the software of the replaced electronic control unit needs to download the update data registered as a distribution package of differential data and update it to the latest state. However, if the version of the software of the electronic control unit after replacement is significantly different from the version of the latest software, it may be necessary to repeatedly perform operations such as downloading the distribution package of differential data, installation and activation using the distribution package of differential data, and user consent request processing many times, which may result in a deterioration of the software update efficiency.
[0008] The present disclosure has been made in view of the above problems, and an object thereof is to provide a center or the like that can suppress deterioration in the efficiency of update processing in software update processing of an electronic control unit.
Means for Solving the Problems
[0009] In order to solve the above problems, one aspect of the disclosed technology is a center that distributes update data of software of an electronic control unit to a vehicle including a plurality of electronic control units, the center including a storage unit that stores update management information including the latest version of the software of a first electronic control unit that is an electronic control unit, a reception unit that receives the current version of the software of the electronic control unit from the vehicle, a determination unit that determines whether or not an update of the software of the first electronic control unit is necessary based on the update management information stored in the storage unit and the current version of the software received by the reception unit, and when the determination unit determines that an update of the software of the first electronic control unit is necessary, a control unit that determines either a package including difference data between versions of the software of the first electronic control unit or a package including data of the latest version of the software of the first electronic control unit that needs to be updated as a distribution package based on the software of the first electronic control unit that needs to be updated, and a transmission unit that transmits the distribution package determined by the control unit to the vehicle based on a request from the vehicle.
Effects of the Invention
[0010] According to the center or the like of the present disclosure, based on the software that needs to be updated, it is determined whether to distribute in a package including difference data between versions or in a package including data of the latest version, so that deterioration in the efficiency of software update processing can be suppressed.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7A
Figure 7B
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
[0012] When the center of the present disclosure distributes software update data to the electronic control unit of a vehicle, it determines whether to distribute it in a package including differential data between software versions or in a package including all data of the latest version of the software, based on the software that requires an update. By this method of determining the distribution package of the update data, it is possible to suppress the deterioration of the efficiency of the software update process. Hereinafter, an embodiment of the present disclosure will be described in detail with reference to the drawings.
[0013] [Embodiment] [Configuration of the System] Figure 1 is a block diagram showing the overall configuration of a network system according to an embodiment of the present disclosure. The network system shown in Figure 1 is a system for updating the software of a plurality of electronic control units (ECUs) 50a to 50d mounted on a vehicle, and includes a center 10 outside the vehicle and an in-vehicle network 90 constructed inside the vehicle.
[0014] (1) Center The center 10 can communicate with an OTA master 30, which will be described later, included in the in-vehicle network 90 via the network 100, and perform operations such as transmitting update data for the electronic control units 50a to 50d and receiving notifications indicating the progress of software update processing, thereby managing the software update of the plurality of electronic control units 50a to 50d connected to the OTA master 30. This center 10 has a function as a so-called server.
[0015] Figure 2 is a block diagram showing the schematic configuration of the center 10 in Figure 1. As shown in Figure 2, the center 10 includes a CPU (Central Processing Unit) 11, a RAM (Random Access Memory) 12, a storage device 13, and a communication device 14. The storage device 13 is a device equipped with a readable and writable storage medium such as a hard disk drive (HDD) or a solid state drive (SSD), and stores programs for executing software update management, information used for software update management, and update data for each electronic control unit. In the center 10, the CPU 11 executes a predetermined process related to software update by executing the program read from the storage device 13 using the RAM 12 as a work area. The communication device 14 is a device for communicating with the OTA master 30 via the network 100.
[0016] FIG. 3 is a functional block diagram of the center 10 shown in FIG. 2. The center 10 shown in FIG. 3 includes a storage unit 15, a communication unit 16, a control unit 17, and a determination unit 18. The storage unit 15 is realized by the storage device 13 shown in FIG. 2. The communication unit 16, the control unit 17, and the determination unit 18 are realized by the CPU 11 shown in FIG. 2 executing a program stored in the storage device 13 using the RAM 12.
[0017] The storage unit 15 stores information related to software update processing of one or more electronic control units 50a to 50d mounted on the vehicle. As information related to software update processing, the storage unit 15 stores, for each vehicle identification information (vehicle ID) that identifies the vehicle, at least update management information associating information indicating software available in the electronic control units 50a to 50d and software update data of the electronic control units 50a to 50d. Further, as information related to software update processing, the storage unit 15 stores an update status indicating the update state of the software being executed in the vehicle.
[0018] Among the vehicle management information stored in the memory unit 15, as information indicating software available for the electronic control unit, for the electronic control units (hereinafter referred to as "first electronic control units") that need to mutually match control functions, combinations of the latest versions of the software of a plurality of first electronic control units are defined. Also, as information indicating software available for the electronic control units 50a to 50d, the latest version of the software of the electronic control units (hereinafter referred to as "second electronic control units") that do not need to mutually match control functions is described. An example of the vehicle management information is shown in FIG. 6. In the example of FIG. 6, for the vehicle with the vehicle ID "AB01", the electronic control units ECU-A, ECU-B, and ECU-C are first electronic control units that need to mutually match control functions, and it is defined as the combination of the latest versions that all of these first electronic control units are version 4.0. Also, it is described that the latest version of the electronic control unit ECU-D is 5.0 and the latest version of the electronic control unit ECU-E is 3.0. Note that the vehicle management information may be stored as one piece of information in which the first electronic control units and the second electronic control units are mixed as shown in FIG. 6, or the information of the first electronic control units and the information of the second electronic control units may be stored separately.
[0019] As update data stored in the memory unit 15, differential data between versions of the software of the electronic control unit and all data of the latest version of the software of the electronic control unit can be exemplified. The differential data is generated by packaging the software of all at least one of the first electronic control units. An example of the packaged differential data is shown in FIG. 7A. In the example of FIG. 7A, six packages (1.0 to 6.0) are prepared as differential data packages for the vehicle with vehicle ID_AB01. Package 1.0 includes differential data for updating the software of each of the electronic control units ECU-A, ECU-B, ECU-C, ECU-D, and ECU-E from version 0 to version 1.0. Note that since version 0 means that the software itself does not exist, the differential data of package 1.0 corresponds to all data of the software. It is described that the size (data amount) of the update data by this package 1.0 is 2000 MB. Further, package 2.0 includes differential data for updating the software of each of the electronic control units ECU-D and ECU-E from version 1.0 to version 2.0. Note that since there is no software version update for the electronic control units ECU-A, ECU-B, and ECU-C by package 2.0, the differential data of the software related to these electronic control units is not included in package 2.0. It is described that the size (data amount) of the update data by this package 2.0 is 150 MB. Similarly for packages 3.0 to 6.0, each includes differential data of the software of each electronic control unit with a version update. This differential data package may include the software of the first electronic control units that need to take mutual control function consistency in the same package, and the combination of the software of the first electronic control unit and the software of the second electronic control unit is not particularly limited.
[0020] Also, FIG. 7B shows an example in which all the data of the software of the electronic control unit is packaged respectively. In the example of FIG. 7B, a plurality of packages are prepared as all the data packages for the vehicle with vehicle ID_AB01. For example, for the electronic control unit ECU-D, all the data of the software of each version 1.0 to 5.0 are prepared as packages respectively, and the size (data volume) of the update data is shown for each package. Note that the storage unit 15 does not need to store the packages of all the data for all the versions, and depending on the storage capacity of the storage unit 15, the usage frequency of the versions, etc., for example, only some packages such as only the latest version may be stored. Note that in FIG. 7B, an example in which all the data of a single software is taken as one package is shown, but all the data of a plurality of softwares may be taken as one package. For example, for the software of the electronic control unit ECU-A, all the data of version 1.0 and all the data of version 2.0 may be made into one package, or for the software of the electronic control unit ECU-C, all the data of version 5.0 and all the data of version 3.0 of the software of the electronic control unit ECU-E may be made into one package.
[0021] The communication unit 16 functions as a transmission unit and a reception unit that transmit and receive data, information, requests, etc. to and from the OTA master 30. The communication unit 16 receives a software update confirmation request from the OTA master 30 (reception unit). The update confirmation request is information transmitted from the OTA master 30 to the center 10 when the power or ignition of the vehicle is turned on (hereinafter referred to as "power ON"), and is information for requesting the center 10 to confirm whether there is update data for the electronic control units 50a to 50d based on the vehicle configuration information described later. Further, the communication unit 16 transmits information indicating the presence or absence of update data to the OTA master 30 in response to the update confirmation request received from the OTA master 30 (transmission unit). Further, the communication unit 16 receives a transmission request (download request) for a distribution package from the OTA master 30 (reception unit). Further, when the communication unit 16 receives a download request for a distribution package, it transmits the distribution package determined by the control unit 17 described later to the OTA master 30 based on the software of the electronic control unit that needs to be updated (transmission unit).
[0022] The determination unit 18 acquires the current version (current version) of the software of each of the plurality of electronic control units 50a to 50d mounted on the vehicle specified by the vehicle ID from the vehicle configuration information included in the update confirmation request received by the communication unit 16. Then, the determination unit 18 determines whether or not it is necessary to update the software of at least one electronic control unit based on the update management information stored in the storage unit 15 and the current version of each software acquired from the vehicle. More specifically, it is determined whether or not the current version of each software acquired from the vehicle matches the latest version of each software in the vehicle managed by the center 10 as vehicle management information.
[0023] When the determination unit 18 determines that the software of at least one electronic control unit needs to be updated, the control unit 17 determines whether there is update data for the software that needs to be updated based on the information regarding the software update process stored in the storage unit 15. The determination result as to whether there is update data by the control unit 17 is transmitted to the OTA master 30 by the communication unit 16. Then, when the control unit 17 determines that there is update data for the software of the electronic control units 50a to 50d that need to be updated, and receives a download request for the distribution package from the OTA master 30, the control unit 17 determines a distribution package to be transmitted to the vehicle as update data based on the software of the electronic control units that need to be updated. The method for determining this distribution package will be described later.
[0024] (2) In-vehicle network The in-vehicle network 90 includes an OTA master 30, a plurality of electronic control units 50a to 50d, a display device 70, and a communication module 80. The OTA master 30 and the communication module 80 are connected via a bus 60a. The OTA master 30 and the electronic control units 50a and 50b are connected via a bus 60b. The OTA master 30 and the electronic control units 50c and 50d are connected via a bus 60c. The OTA master 30 and the display device 70 are connected via a bus 60d.
[0025] The OTA master 30 can wirelessly communicate with the center 10 via the network 100 through the bus 60a and the communication module 80. Also, the OTA master 30 can communicate with the electronic control units 50a to 50d and the display device 70 by wire via the buses 60b to 60d. This OTA master 30 is a device that manages the OTA state and controls the software update sequence to perform software updates on the electronic control units to be updated (hereinafter referred to as "target electronic control units"), and controls the software updates of the target electronic control units among the electronic control units 50a to 50d based on update data obtained by communication from the center 10. The OTA master 30 may also be referred to as a central gateway (CGW).
[0026] Figure 4 is a block diagram showing the schematic configuration of the OTA master 30 in Figure 1. As shown in Figure 4, the OTA master 30 includes a CPU 31, a RAM 32, a ROM (Read-Only Memory) 33, a storage device 34, and a communication device 36. The CPU 31, the RAM 32, the ROM 33, and the storage device 34 constitute a microcomputer 35. In the OTA master 30, the CPU 31 executes a program read from the ROM 33 using the RAM 32 as a work area to execute predetermined processes related to software updates. The communication device 36 is a device for communicating with the communication module 80, the electronic control units 50a to 50d, and the display device 70 via the buses 60a to 60d shown in Figure 1.
[0027] Figure 5 is a functional block diagram of the OTA master 30 shown in Figure 4. The OTA master 30 shown in Figure 5 includes a storage unit 37, a communication unit 38, and a control unit 39. The storage unit 37 is realized by the storage device 34 shown in Figure 4. The communication unit 38 and the control unit 39 are realized by the CPU 31 shown in Figure 4 executing a program stored in the ROM 33 using the RAM 32.
[0028] The memory unit 37 stores a program (the control program of the OTA master 30) for executing software updates of the plurality of electronic control units 50a to 50d, various data used when executing software updates, and update data of the software downloaded by the distribution package from the center 10.
[0029] The communication unit 38 functions as a transmission unit and a reception unit that transmit and receive data, information, requests, etc. to and from the center 10. For example, when the vehicle power is turned on, the communication unit 38 transmits a software update confirmation request to the center 10 (transmission unit). The update confirmation request includes, for example, a vehicle ID for identifying the vehicle and information on the current version of the software of the electronic control units 50a to 50d connected to the in-vehicle network 90. The vehicle ID and the current version of the software of the electronic control units 50a to 50d are used to determine whether there is update data for the software of the electronic control units 50a to 50d and which distribution package to adopt if there is update data by comparing with the latest version of the software stored by the center 10 for each vehicle ID. Also, the communication unit 38 receives a notification indicating the presence or absence of update data from the center 10 as a response to the update confirmation request (reception unit). If there is update data for the software of the electronic control units 50a to 50d, the communication unit 38 transmits a download request for the distribution package including the update data to the center 10 (transmission unit) and receives (downloads) the distribution package transmitted from the center 10 (reception unit). Further, the communication unit 38 transmits the software update status transmitted by the electronic control units 50a to 50d to the center 10 (transmission unit).
[0030] Based on the response from the center 10 to the update confirmation request received by the communication unit 38, the control unit 39 determines whether there is software update data for the electronic control units 50a to 50d. Further, the control unit 39 verifies the authenticity of the distribution package received (downloaded) from the center 10 by the communication unit 38 and stored in the storage unit 37. Also, the control unit 39 controls the software update process (installation, activation) of the electronic control units 50a to 50d using the update data received (downloaded) from the center 10. Specifically, the control unit 39 transfers one or more pieces of update data downloaded with the distribution package to the target electronic control unit and causes the target electronic control unit to install the updated software based on the update data. After the installation is completed, the control unit 39 instructs the target electronic control unit to activate the installed updated software.
[0031] The plurality of electronic control units 50a to 50d are devices (ECUs) for controlling the operations of various parts of the vehicle. In FIG. 1, four electronic control units 50a to 50d are illustrated, but the number of electronic control units is not particularly limited. Also, the number of buses connecting the electronic control units to the OTA master 30 is not particularly limited.
[0032] The display device 70 is a human machine interface (HMI) used for performing various displays, such as displaying that there is update data during the software update process of the electronic control units 50a to 50d, displaying a consent request screen for requesting consent from the vehicle user or administrator for software update, and displaying the result of software update. As the display device 70, typically, the display device of a car navigation system can be used, but it is not particularly limited as long as it can display the information necessary during the software update process. Note that in addition to the display device 70, other electronic control units and the like may be further connected to the bus 60d shown in FIG. 1.
[0033] The communication module 80 is a unit with the function of controlling the communication between the center 10 and the vehicle, and is a communication device for connecting the in-vehicle network 90 to the center 10. The communication module 80 is wirelessly connected to the center 10 via the network 100, and vehicle authentication by the OTA master 30, downloading of update data, etc. are performed. Note that this communication module 80 may be included in the OTA master 30 and configured.
[0034] [Overview of Software Update Process] For example, when the vehicle is powered on, the OTA master 30 transmits a software update confirmation request to the center 10. The update confirmation request includes a vehicle ID for identifying the vehicle and vehicle configuration information regarding the state (system configuration) of the electronic control units 50a to 50d connected to the in-vehicle network 90, such as the current versions of the hardware and software of the electronic control units. The vehicle configuration information can be created by obtaining the identification number (ECU_ID) of the electronic control unit and the identification number (ECU_Software_ID) of the software version of the electronic control unit from the electronic control units 50a to 50d connected to the in-vehicle network 90. The vehicle ID and the current versions of the software of the electronic control units 50a to 50d are used to determine whether there is update data for the software of the electronic control units 50a to 50d by comparison with the latest software versions held by the center 10 for each vehicle ID. Also, the OTA master 30 receives a notification indicating the presence or absence of update data from the center 10 as a response to the update confirmation request. If there is update data for the software of the electronic control units 50a to 50d, the OTA master 30 transmits a download request for the distribution package to the center 10 and receives the distribution package transmitted from the center 10. The distribution package may include, in addition to the update data, verification data for verifying the authenticity of the update data, the number of update data, the installation order, the activation order, type information, and various control information used during software update.
[0035] The OTA master 30 determines whether there is software update data for the electronic control units 50a to 50d based on the response from the center 10 to the received update confirmation request. Also, the OTA master 30 verifies the authenticity of the distribution package received from the center 10 and stored in the storage device 13. Further, the OTA master 30 transfers one or more update data downloaded with the distribution package to the target electronic control unit and causes the target electronic control unit to install the update data. After the installation is completed, the OTA master 30 instructs the target electronic control unit to enable the installed updated version of the software.
[0036] In the approval request process, the OTA master 30 causes the output device to output a notification indicating that approval is required for software update and a notification prompting an input indicating that the software update has been approved. As the output device, a display device 70 provided in the in-vehicle network 90, an audio output device that gives an audio notification, etc. can be used. For example, in the approval request process, when using the display device 70 as the output device, the OTA master 30 causes the display device 70 to display an approval request screen for requesting approval of the software update, and causes the display device 70 to display a notification prompting a specific input operation such as pressing an approval button when the user or administrator approves. Also, in the approval request process, the OTA master 30 can cause the display device 70 to display a statement or icon notifying that there is software update data for the electronic control units 50a to 50d, or can cause the display device 70 to display restrictions during the execution of the software update process, etc. When the OTA master 30 receives an input indicating that the user or administrator has approved, it executes the above-described installation and activation control processes to update the software of the target electronic control unit.
[0037] Here, when the non-volatile memory of the electronic control unit is a single-bank memory having one storage area for storing control programs, update data, etc., since installation and activation are performed continuously, before the execution of the installation, a commitment request process for software update is performed. When the non-volatile memory of the electronic control unit is a dual-bank memory having two storage areas for storing control programs, update data, etc., at least after the execution of the installation and before the execution of the activation, a commitment request process for software update is performed. Note that when the non-volatile memory of the electronic control unit is a dual-bank memory, the commitment request process for software update before the execution of the installation may or may not be performed.
[0038] The software update process consists of a phase in which the OTA master 30 downloads update data from the center 10 (download phase), a phase in which the OTA master 30 transfers the downloaded update data to the target electronic control unit and installs the update data in the storage area of the target electronic control unit (installation phase), and a phase in which the target electronic control unit activates the updated version of the software installed (activation phase).
[0039] Downloading is a process in which the OTA master 30 receives and stores in the storage device 34 the update data for updating the software of the electronic control units 50a to 50d transmitted by the distribution package from the center 10. In the download phase, it includes not only the execution of the download but also the control of a series of processes related to the download, such as determining whether the download can be executed, requesting commitment from the vehicle user or administrator for the download, and verifying the update data.
[0040] The update data transmitted from the center 10 to the OTA master 30 may include the update software (all data) of the electronic control units 50a to 50d, the differential data of the update software, the compressed data obtained by compressing the update software, or the split data obtained by splitting the update software, differential data, or compressed data. Further, the update data may include the ECU_ID (or serial number) of the target electronic control unit and the ECU_Software_ID of the electronic control unit before the update. The update data is downloaded as the above-described distribution package, and the distribution package includes the update data of single or multiple electronic control units.
[0041] Installation is a process in which the OTA master 30 writes update software (updated program) to the target electronic control unit based on the update data downloaded from the center 10. In the installation phase, not only the execution of the installation but also a series of process controls related to the installation are included, such as determination of whether the installation can be executed, request for approval from the vehicle user or administrator for the installation, transfer of the update data, and verification of the update software.
[0042] When the update data includes the update software itself (all data), in the installation phase, the OTA master 30 transfers the update data (update software) to the target electronic control unit. Also, when the update data includes the compressed data of the update software, or the differential data, or the split data, the OTA master 30 may transfer the update data to the target electronic control unit, and the target electronic control unit may generate the update software from the update data, or the OTA master 30 may generate the update software from the update data and then transfer the update software to the target electronic control unit. Here, the generation of the update software can be performed by decompressing the compressed data or assembling (integrating) the differential data or split data.
[0043] The installation of the updated software can be performed by the target electronic control unit based on an installation request (or instruction) from the OTA master 30 (or the center 10). Alternatively, the target electronic control unit that has received the update data may autonomously perform the installation without receiving an explicit instruction from the OTA master 30.
[0044] Activation is a process in which the target electronic control unit activates the installed updated software. In the activation phase, it includes a series of controls related to activation, such as not only the execution of activation, but also the determination of whether activation can be executed, the request for approval from the vehicle user or administrator for activation, and the verification of the execution result.
[0045] The activation of the updated software can be performed by the target electronic control unit based on an activation request (or instruction) from the OTA master 30 (or the center 10). Alternatively, the target electronic control unit that has received the update data may autonomously perform the activation after the completion of installation without receiving an explicit instruction from the OTA master 30.
[0046] Note that the software update process can be performed continuously or in parallel for each of the plurality of electronic control units.
[0047] Also, the "software update process" in this specification includes not only a process that continuously performs all of download, installation, and activation, but also a process that performs only a part of download, installation, and activation.
[0048] [Processing] Next, with further reference to FIGS. 8 to 12, the processing executed in the network system according to this embodiment will be described.
[0049] FIG. 8 is a flowchart for explaining an example of the distribution control process executed by each component of the center 10. The distribution control process shown in FIG. 8 is started when the center 10 receives an update confirmation request transmitted by the OTA master 30.
[0050] (Step S801) The communication unit 16 determines whether there is a software update confirmation request from the OTA master 30. If there is an update confirmation request (Yes in step S801), the process proceeds to step S802. If there is no update confirmation request (No in step S801), the process proceeds to step S804.
[0051] (Step S802) The control unit 17 checks whether there is software that needs to be updated. This check is performed based on the current version of the software of each electronic control unit 50a to 50d mounted on the vehicle, which the determination unit 18 has obtained from the vehicle configuration information included in the update confirmation request, and the latest version of each software stored in the storage unit 15. After checking whether there is software that needs to be updated, the process proceeds to step S803.
[0052] (Step S803) Based on the update management information stored in the storage unit 15, the control unit 17 determines whether there is software update data for the electronic control units 50a to 50d mounted on the vehicle included in the update confirmation request, and transmits information indicating the presence or absence of the update data to the OTA master 30 based on the determination result. After transmitting the presence or absence of the update data, the process proceeds to step S804.
[0053] (Step S804) The communication unit 16 determines whether there is a download request for the distribution package from the OTA master 30. If there is a download request (Yes in step S804), the process proceeds to step S805. If there is no download request (No in step S804), the process proceeds to step S801.
[0054] (Step S805) The control unit 17 determines whether the electronic control unit (ECU) having software that needs to be updated (hereinafter referred to as "software to be updated") is a first electronic control unit that needs to take mutual control function consistency or a second electronic control unit that does not need to take mutual control function consistency. If the electronic control unit having the software to be updated is the first electronic control unit (Step S805, First ECU), the process proceeds to Step S806. If the electronic control unit having the software to be updated is the second electronic control unit (Step S805, Second ECU), the process proceeds to Step S807.
[0055] (Step S806) The control unit 17 executes a process of determining a distribution package of software update data for the first electronic control unit (distribution package determination process for the first ECU). When the execution of the distribution package determination process for the first ECU ends, the process proceeds to Step S808.
[0056] (Step S807) The control unit 17 executes a process of determining a distribution package of software update data for the second electronic control unit (distribution package determination process for the second ECU). When the execution of the distribution package determination process for the second ECU ends, the process proceeds to Step S808.
[0057] (Step S808) The communication unit 16 transmits the distribution package determined by the control unit 17 to the OTA master 30. When the distribution package is transmitted, the process proceeds to Step S801.
[0058] Referring to FIG. 9, the distribution package determination process for the first ECU shown in Step S806 of FIG. 8 will be described. FIG. 9 is a flowchart for explaining an example of the distribution package determination process for the first ECU executed by the control unit 17 of the center 10.
[0059] (Step S901) The control unit 17 determines whether the version difference of the software to be updated exceeds a predetermined value. The version difference of the software to be updated is the difference between the latest version of the software stored in the storage unit 15 and the current version of the software acquired from the vehicle. This determination is made to determine whether the current version of the software is significantly different from the latest version (the divergence between the two versions is large). For example, when the latest version is 4.0 and the current version is 3.0, the version difference of the software is 1.0. The predetermined value can be set based on the update efficiency such as the data volume and update time when comparing the case of performing a one-time version upgrade using all data and the case of performing a step-by-step version upgrade using differential data. If the version difference of the software to be updated exceeds the predetermined value (step S901, yes), the process proceeds to step S902. If the version difference of the software to be updated is less than or equal to the predetermined value (step S901, no), the process proceeds to step S903.
[0060] (Step S902) The control unit 17 determines a package that includes at least all the data of the latest version of the software to be updated (that is, the all-data package) as the distribution package. When the distribution package is determined, the distribution package determination process for the first ECU ends.
[0061] (Step S903) The control unit 17 determines a package that includes the differential data between the versions of all the software of the first electronic control unit (that is, the differential data package) as the distribution package. When the distribution package is determined, the distribution package determination process for the first ECU ends.
[0062] Here, with reference to FIGS. 6, 7A, 7B, and 11, a specific example of the distribution package determination process for the first ECU will be described. It is assumed that the predetermined value of the version difference is 2.0. In FIG. 11(a), the current versions 3.0 of the software of the first electronic control units ECU-A, ECU-B, and ECU-C that require updates are not different by more than the predetermined value from the latest version 4.0 (see FIG. 6). Therefore, the center 10 transmits the differential data package 6.0 (see FIG. 7A) as the distribution package to the OTA master 30 in response to the download request. In FIG. 11(b), the current version 3.0 of the software of the first electronic control unit ECU-C that requires updates is not different by more than the predetermined value from the latest version 4.0. Therefore, the center 10 transmits the differential data package 6.0 as the distribution package to the OTA master 30 in response to the download request. In FIG. 11(c), the current version 1.0 of the software of the first electronic control unit ECU-C that requires updates has a version difference exceeding the predetermined value from the latest version 4.0. Therefore, the center 10 transmits the entire data package of the latest version 4.0 of the software of the first electronic control unit ECU-C (see FIG. 7B) as the distribution package to the OTA master 30 in response to the download request.
[0063] Next, with reference to FIG. 10, the distribution package determination process for the second ECU shown in step S807 of FIG. 8 will be described. FIG. 10 is a flowchart for explaining an example of the distribution package determination process for the second ECU executed by the control unit 17 of the center 10.
[0064] (Step S1001) The control unit 17 determines whether the size of all the data of the software to be updated exceeds a predetermined size. The size (data volume) of all the data of the software is stored in advance in the storage unit 15 (see FIG. 7B). When there are multiple software to be updated, it is the value obtained by summing up all the data of the multiple ones. The predetermined size is a value set based on whether the vehicle can download all the data of the software to be updated. For example, it can be any value equal to or less than the capacity of the data storage area available for download in the storage unit 37 of the vehicle. When the size of all the data of the software to be updated exceeds the predetermined size (step S1001, yes), the process proceeds to step S1004. When the size of all the data of the software to be updated is equal to or less than the predetermined size (step S1001, no), the process proceeds to step S1002.
[0065] (Step S1002) The control unit 17 determines whether the estimated time until the update of the software to be updated is shorter for the update process using all the data or for the update process using differential data. The time until the completion of the software update can be estimated based on, for example, the congestion of the communication bandwidth, the current version of the software, and the processing capabilities of the electronic control unit and the type of non-volatile memory. When the estimated time until the update of the software to be updated is shorter for the update process using all the data (step S1002, all data), the process proceeds to step S1003. When the estimated time until the update of the software to be updated is shorter for the update process using differential data (step S1002, differential data), the process proceeds to step S1004.
[0066] (Step S1003) The control unit 17 determines a package (i.e., all-data package) that includes at least all the data of the latest version of the software to be updated as the distribution package. When the distribution package is determined, the distribution package determination process for this second ECU ends.
[0067] (Step S1004) The control unit 17 determines a package (i.e., a differential data package) that includes at least differential data between versions of the software to be updated as a distribution package. When the distribution package is determined, the distribution package determination process for the second ECU ends.
[0068] Here, with reference to FIGS. 6, 7A, 7B, and 12, a specific example of the distribution package determination process for the second ECU will be described. Assume that the predetermined size is 550 MB. In FIG. 12(a), all the data required to upgrade the software of the second electronic control unit ECU-E of the current version 2.0 to the latest version 3.0 (see FIG. 6) = 600 MB (see FIG. 7B) exceeds the predetermined size. Therefore, the center 10 transmits, as a response to the download request, the differential data package 5.0 with a size of 190 MB (see FIG. 7A) to the OTA master 30 as the distribution package. In FIG. 12(b), all the data required to upgrade the software of the second electronic control unit ECU-D of the current version 3.0 to the latest version 5.0 (see FIG. 6) = 540 MB (see FIG. 7B) is below the predetermined size. Here, in this example, it is assumed that it takes less time to update the version step by step from 3.0 → 4.0 → 5.0 with differential data than to update directly from 3.0 → 5.0 with all the data. Therefore, in this assumption, the center 10 transmits, as a response to the download request, the differential data packages 5.0 and 6.0 (see FIG. 7A) to the OTA master 30 as the distribution packages. In FIG. 12(c), all the data required to upgrade the software of the second electronic control unit ECU-D of the current version 1.0 to the latest version 5.0 = 540 MB is below the predetermined size. Here, in this example, it is assumed that it takes less time to update directly from 1.0 → 5.0 with all the data than to update the version step by step from 1.0 → 2.0 → 3.0 → 4. → 5.0 with differential data. Therefore, in this assumption, the center 10 transmits, as a response to the download request, the entire data package of the latest version 5.0 of the software of the second electronic control unit ECU-D (see FIG. 7B) to the OTA master 30 as the distribution package.
[0069] In the above embodiment, in step S805, it was described that the electronic control unit (ECU) having the software to be updated is either the first electronic control unit or the second electronic control unit. However, there may be a case where the software of the first electronic control unit and the software of the second electronic control unit are both targets for update at the same time. In such a case, the first ECU delivery package determination process (FIG. 9) and the second ECU delivery package determination process (FIG. 10) may be executed in parallel, and the extracted packages may be determined as one delivery package.
[0070] FIG. 13 is a flowchart for explaining an example of software update control processing executed by each component of the OTA master 30. The software update control processing shown in this FIG. 13 is executed, for example, when the vehicle power is turned on.
[0071] (Step S1301) The communication unit 38 transmits a confirmation request to the center 10 to check whether there is update data for the software of the electronic control units 50a to 50d. This confirmation request includes the vehicle ID and the current version of the software of the electronic control units 50a to 50d. When the confirmation request is transmitted to the center 10, the process proceeds to step S1302.
[0072] (Step S1302) The communication unit 38 receives a confirmation result for the confirmation request of the update data from the center 10. When the confirmation result is received, the process proceeds to step S1303.
[0073] (Step S1303) Based on the confirmation result for the confirmation request of the update data received by the communication unit 38, the control unit 39 determines whether there is update data for at least one of the electronic control units 50a to 50d. If there is at least one update data for the software (step S1303, yes), the process proceeds to step S1304. If there is no update data for the software at all (step S1303, no), this software update control process ends.
[0074] (Step S1304) The control unit 39 downloads the update data. More specifically, the communication unit 38 transmits a download request for a distribution package including the update data to the center 10, and receives the distribution package transmitted from the center 10 in response to the download request. The communication unit 38 stores the received distribution package in the storage unit 37. Once the update data has been downloaded, the process proceeds to step S1305.
[0075] (Step S1305) The control unit 39 executes an installation process for the target electronic control unit. More specifically, the control unit 39 transfers the update data included in the distribution package to the target electronic control unit and instructs it to install the update data. The target electronic control unit writes the update data received from the OTA master 30 to a data storage area. Once the installation process has been executed, the process proceeds to step S1306.
[0076] (Step S1306) The control unit 39 executes activation processing for the target electronic control unit. More specifically, the control unit 39 instructs the target electronic control unit, which has written the update data to its data storage area, to activate the updated software. The target electronic control unit restarts and executes the updated software when a specific input operation, such as turning the power off, is performed. Once the activation processing is executed, the software update control processing ends.
[0077] <Effects> As described above, according to the network system according to an embodiment of the present disclosure, the center 10 stores in advance, as update data, a package including difference data between versions of software of an electronic control unit (first electronic control unit) and a package including data of the latest version of software of the electronic control unit (first electronic control unit, second electronic control unit). Then, based on the current version of the software of the electronic control units 50a to 50d mounted on the vehicle received from the vehicle (OTA master 30) and the latest version of the software stored by itself, the center 10 dynamically changes the package specification of the update data of the software that needs to be updated. As a result, the degree of freedom in the distribution method of the update data is improved, and it is possible to suppress the deterioration of the efficiency of the software update process.
[0078] In addition, the center 10 preferably determines which of the package including the difference data between versions and the package including the data of the latest version is to be the distribution package based on the version difference of the software that needs to be updated, the data amount of the update data, the estimated time until the update is completed, and the like. Therefore, it is possible to effectively suppress the deterioration of the efficiency of the software update process.
[0079] As described above, an embodiment of the present disclosure technology has been described. However, the present disclosure can be regarded not only as a center but also as a distribution control method, a distribution control program, or a computer-readable non-temporary storage medium storing the distribution control program, which is executed by a center including a processor, a memory, and a storage device.
Industrial Applicability
[0080] The present disclosure technology can be used in a network system for updating the software of an electronic control unit.
Explanation of Signs
[0081] 10 Center 11, 31 CPU 12, 32 RAM 13. 34 Memory device 14. 36 Communication device 15. 37 Memory section 16. 38 Communication section 17. 39 Control section 18 Judgment section 30 OTA master 33 ROM 35 Microcomputer 50a - 50d Electronic control unit (ECU) 60a - 60d Bus 70 Display device 80 Communication module 90 In - vehicle network 100 Network
Claims
1. A center that distributes update data for software of the electronic control units to a vehicle equipped with a plurality of electronic control units, a storage unit that stores update management information including the latest version of the software of a first electronic control unit which is one of the electronic control units, a receiving unit that receives the current version of the software of the electronic control units from the vehicle, a determination unit that determines whether an update of the software of the first electronic control unit is necessary based on the update management information stored in the storage unit and the current version of the software received by the receiving unit, a control unit that, when the determination unit determines that an update of the software of the first electronic control unit is necessary, determines either a package including difference data between versions of the software of the first electronic control unit or a package including data of the latest version of the software of the first electronic control unit that needs to be updated as a distribution package based on the software of the first electronic control unit that needs to be updated, a transmission unit that transmits the distribution package determined by the control unit to the vehicle based on a request from the vehicle. A center comprising:
2. The center according to claim 1, wherein the control unit determines a package including data of the latest version of the software of the first electronic control unit that needs to be updated as the distribution package when a difference between the current version of the software of the first electronic control unit that needs to be updated and the latest version of the software of the first electronic control unit that needs to be updated exceeds a predetermined value.
3. The update management information further includes the latest version of the software of a second electronic control unit which is an electronic control unit different from the first electronic control unit, and the determination unit determines whether an update of the software of the second electronic control unit is necessary based on the update management information stored in the storage unit and the current version of the software received by the receiving unit. When the determination unit determines that the software of the second electronic control unit needs to be updated, the control unit determines, based on the software of the second electronic control unit that needs to be updated, either a package including difference data between versions of the software of the second electronic control unit or a package including data of the latest version of the software of the second electronic control unit that needs to be updated as a distribution package. The center according to claim 1 or 2.
4. When the data amount of the package including only the latest version of the software of the second electronic control unit that needs to be updated exceeds the capacity of the data storage area of the vehicle, the control unit determines the package including the difference data between the versions of the software of the second electronic control unit as the distribution package. The center according to claim 3.
5. When the data amount of the package including the data of the latest version of the software of the second electronic control unit that needs to be updated is equal to or less than the capacity of the data storage area provided in the vehicle, the control unit determines the package with less expected time until the software update is completed as the distribution package. The center according to claim 4.
6. When the data amount of the package including the data of the latest version of the software of the second electronic control unit that needs to be updated is equal to or less than the capacity of the data storage area provided in the vehicle, the control unit determines the package with less data amount as the distribution package. The center according to claim 4.
7. A distribution control method executed by a computer of a center that includes a processor, a memory, and a storage device and distributes update data of software of electronic control units to a vehicle equipped with a plurality of electronic control units, storing update management information including the latest version of the software of the first electronic control unit, which is the electronic control unit; receiving the current version of the software of the electronic control unit from the vehicle; determining whether the software of the first electronic control unit needs to be updated based on the update management information and the current version of the software; When it is determined that the software of the first electronic control unit needs to be updated, based on the software of the first electronic control unit that needs to be updated, a package including the differential data between versions of the software of the first electronic control unit and a package including the data of the latest version of the software of the first electronic control unit that needs to be updated are determined as the distribution package; Based on the request from the vehicle, the determined distribution package is transmitted to the vehicle, including a distribution control method.
8. A distribution control program executed by a computer of a center that includes a processor, a memory, and a storage device and distributes update data of software of electronic control units to a vehicle equipped with a plurality of electronic control units, Storing update management information including the latest version of the software of the first electronic control unit, which is the electronic control unit; Receiving the current version of the software of the electronic control unit from the vehicle; Based on the update management information and the current version of the software, determining whether the software of the first electronic control unit needs to be updated; When it is determined that the software of the first electronic control unit needs to be updated, based on the software of the first electronic control unit that needs to be updated, a package including the differential data between versions of the software of the first electronic control unit and a package including the data of the latest version of the software of the first electronic control unit that needs to be updated are determined as the distribution package; Based on the request from the vehicle, causing the computer to execute the step of transmitting the determined distribution package to the vehicle, a distribution control program.
Citation Information
Patent Citations
Driverless automobile vehicle-mounted terminal upgrading method, equipment, device and storage medium
CN109032653A
Software updating device and software updating method
JP2016170740A
Software updating system
JP2017010098A
Control device, program update system, and program update method
JP2018180948A
Relay device, program update system, and program update method
JP2018181377A