Electronic control device, reprogramming execution method, and reprogramming execution program
The reprogramming method addresses the inefficiency of ECU restarts by defining machine and function states in a manifest file, allowing seamless reprogramming without interruptions, enhancing operational efficiency.
Patent Information
- Application Number
- JP2022073343
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-27
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2042-04-27
AI Technical Summary
Existing reprogramming methods for electronic control units (ECUs) require restarting the ECU during the start and end of the process, leading to waiting times that disrupt service provision or work efficiency, especially in wireless and wired reprogramming scenarios.
A reprogramming method that defines machine states and function groups in a manifest file, allowing for state transitions without restarting the ECU, by distinguishing between applications that can operate during vehicle operation and those that cannot, and managing these states through a master ECU to perform reprogramming efficiently.
Enables reprogramming of ECUs without restarting, reducing downtime and improving efficiency in both wireless and wired reprogramming scenarios by managing state transitions effectively.
Smart Images

Figure 0007715674000001 
Figure 0007715674000002 
Figure 0007715674000003
Abstract
Description
Technical Field
[0001] The present invention relates to an electronic control device, a reprogramming execution method, and a reprogramming execution program.
Background Art
[0002] For example, in an in-vehicle electronic control device (hereinafter referred to as an ECU (Electronic Control Unit)), an update program can be reprogrammed for the purpose of improving functions or fixing defects. In this case, a master ECU that functions as an update master for managing the execution of reprogramming executes reprogramming by instructing the reprogramming target ECU that functions as the target of writing the update program (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] At the start of reprogramming, it is necessary to restart the reprogramming target ECU and start the reprogramming target ECU in a machine state dedicated to reprogramming. Restart is also referred to as reboot. Also, at the end of reprogramming, it is necessary to restart the reprogramming target ECU and start the reprogramming target ECU in the normal state. However, in the mechanism of restarting the reprogramming target ECU at the start and end of reprogramming, in wireless reprogramming where the user performs reprogramming by wireless communication, the time for the reprogramming target ECU to restart becomes the waiting time for service provision. Also, in reprogramming where a dealer operator performs reprogramming by wired communication, the time for the reprogramming target ECU to restart becomes the waiting time for the work.
[0005] The present invention has been made in view of the above circumstances, and an object thereof is to provide an electronic control device, a reprogramming execution method, and a reprogramming execution program capable of appropriately performing reprogramming without restarting an electronic control device to be reprogrammed.
Means for Solving the Problems
[0006] According to the invention described in claim 1, a manifest file acquisition unit (5a) acquires a manifest file. An update program acquisition unit (5b) acquires an update program. A reprogramming execution unit (5c) performs reprogramming by instructing the writing of the update program to an electronic control device to be reprogrammed. In the manifest file, at least a normal state and a reprogramming state in which only an application involved in reprogramming is started are defined as machine states conforming to the standards of a predetermined in-vehicle software platform standard specification, and a first group to which an application that can be reprogrammed while a vehicle drive mechanism is operating belongs is defined as a function group conforming to the standards of the in-vehicle software platform standard specification, a second group to which an application not involved in reprogramming belongs is defined, and start states and stop states are defined for each of the first group and the second group. The reprogramming execution unit performs reprogramming according to the machine state and function group defined in the manifest file.
[0007] Instructions for state transitions to the normal state or reprogramming state defined as machine states in the manifest file are given, and instructions for state transitions to the start state or stop state for each of the first group and the second group defined as function groups in the manifest file are given. By giving instructions for state transitions to the normal state or reprogramming state and instructions for state transitions to the start state or stop state for each of the first group and the second group, reprogramming can be appropriately performed. Thereby, reprogramming can be appropriately performed without restarting the electronic control device to be reprogrammed.
[0008] The present disclosure includes the following inventions in addition to the invention described in the claims. [1] A manifest file acquisition unit (5a) that acquires a manifest file, An update program acquisition unit (5b) that acquires an update program, A repro execution unit (5c) that performs repro by instructing the writing of the update program to an electronic control device to be repro-targeted, and In the manifest file, as machine states conforming to the standards of a predetermined in-vehicle software platform standard specification, at least a normal state and a repro state in which only an app involved in repro is started are defined. As a function group conforming to the standards of the in-vehicle software platform standard specification, a first group to which an app that can be reprogrammed while the vehicle drive mechanism is operating belongs is defined, and a second group to which an app not involved in repro belongs is defined. For each of the first group and the second group, a start state and a stop state are defined, The repro execution unit is an electronic control device that performs repro in accordance with the machine state and the function group defined in the manifest file.
[0009] [2] The repro execution unit acquires the update program from the distribution source of the update program by wireless communication, and cannot stop functions other than the repro function. When a state transition of the function group is necessary, it instructs an app belonging to the first group to transition to the stop state and starts repro as described in [1].
[0010] [3] The repro execution unit is an electronic control device that instructs an app belonging to the first group to transition to the start state after completing repro as described in [2].
[0011] [4] The repro execution unit acquires the update program from the distribution source of the update program by wireless communication, and when functions other than the repro function cannot be stopped and the state transition of the function group is unnecessary, starts repro without instructing the state transition to the apps belonging to the first group. The electronic control device according to any one of [1] to [3].
[0012] [5] The repro execution unit acquires the update program from the distribution source of the update program by wireless communication, and when functions other than the repro function can be stopped, instructs the state transition to the repro state and instructs the state transition to the stop state to the apps belonging to the second group to start repro. The electronic control device according to any one of [1] to [4].
[0013] [6] When the repro execution unit acquires the update program from the distribution source of the update program by wired communication, it instructs the state transition to the repro state and instructs the state transition to the stop state to the apps belonging to the second group to start repro. The electronic control device according to any one of [1] to [5].
[0014] [7] In the manifest file, a restart state is defined as the machine state in addition to the normal state and the repro state. The repro execution unit instructs the state transition to the restart state after completing repro. The electronic control device according to [5] or [6].
[0015] [8] When the repro execution unit cancels without completing repro, it instructs the state transition to the normal state and instructs the state transition to the startup state to the apps belonging to the second group. The electronic control device according to [5] or [6].
[0016] [9] The above-mentioned specified in-vehicle software platform standard specification is an electronic control device described in any one of [1] to [8] of the standards defined by AUTOZAR.
Brief Description of Drawings
[0017]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Embodiments for Carrying Out the Invention
[0018] Hereinafter, an embodiment will be described with reference to the drawings. As shown in FIG. 1, the master ECU 1 mounted on the vehicle functions as an update master that manages the execution of reprogramming for purposes such as improving functions and fixing defects. The master ECU 1 is communicably connected to a plurality of ECUs via the in-vehicle network 2, and integrally manages the plurality of ECUs by instructing the plurality of ECUs to perform operations or acquiring the operating states from the plurality of ECUs. The in-vehicle network 2 is, for example, CAN (Controller Area Network) (registered trademark), Ethernet (registered trademark), LIN, CXPI (Clock Extension Peripheral Interface) (registered trademark), FLEXRAY (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), or the like.
[0019] The master ECU 1 identifies the reprogramming target ECU 3 that functions as a reprogramming target from among the plurality of ECUs, and performs reprogramming by instructing the reprogramming target ECU 3 to write the update program. The master ECU 1 is connected to a DCM (Data Communication Module) 4 that functions as a data communication device. The DCM 4 can receive the distribution package transmitted from the OTA center by wirelessly connecting to the OTA center via a communication network. When the DCM 4 receives the distribution package transmitted from the OTA center, it transfers the received distribution package to the master ECU 1. When the distribution package is transferred from the DCM 4, the master ECU 1 extracts the update program from the transferred distribution package, and performs reprogramming by instructing the reprogramming target ECU 3 to write the extracted update program.
[0020] Further, the master ECU 1 can transfer a distribution package from a reprogramming tool by being connected to the reprogramming tool (not shown) by wire. When the distribution package is transferred from the reprogramming tool, the master ECU 1 extracts an update program from the transferred distribution package and performs reprogramming by instructing the reprogramming target ECU 3 to write the extracted update program.
[0021] The master ECU 1 includes a control unit 5 and a storage 6. The control unit 5 is composed of a microcomputer having a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), and an I / O (Input / Output). The control unit 5 executes a process corresponding to the control program by executing the control program stored in a non-transitory tangible storage medium, and controls the overall operation of the master ECU 1. The control program executed by the control unit 5 includes a reprogramming execution program.
[0022] The storage 6 is a non-volatile memory mainly composed of, for example, a NOR type flash memory or a NAND type flash memory, and is shared by a plurality of applications executed by the control unit 5. That is, a plurality of applications respectively access the storage 6 to perform data writing and data reading. In the present embodiment, a configuration in which the storage 6 is built in the master ECU 1 is illustrated, but it is also applicable to a configuration in which the storage 6 is arranged outside the master ECU 1. Further, a configuration in which the storage 6 is shared by a plurality of applications executed by the control unit 5 is illustrated, but the storage 6 may be shared by an application executed by a control unit of another ECU that is communicably connected to the master ECU 1 for data communication.
[0023] The control unit 5 includes a manifest file acquisition unit 5a, an update program acquisition unit 5b, and a repro execution unit 5c. Each of these units 5a to 5c constitutes the above-described repro execution program. When performing wireless repro, the manifest file acquisition unit 5a acquires the manifest file when the manifest file transmitted from the OTA center is received by the DCM4 and the received manifest file is transferred from the DCM4. When performing wired repro, the manifest file acquisition unit 5a acquires the manifest file when the manifest file is transferred from the repro tool. The manifest file is a data group in which various information necessary for the master ECU 1 to perform repro is stored, and may be referred to as specification data.
[0024] In the Adaptive Platform of AUTOSAR (hereinafter referred to as AP (Adaptive Platform)), the EM (Execution Management) controls the startup and termination of applications and services based on the instructions of the SM (State management). According to the specifications of the AP, as machine states, three states, namely, "startup state", "shutdown state", and "restart state" are essential, and a new machine state can be defined by adding a state definition to the manifest file. A function group is a group of application processes at the user level that are functionally consistent, and a group consisting of a new state and arbitrary applications can be defined by adding an entry to the manifest file. By adding an entry to the manifest file, it is also possible to manage how to transition the machine state and function group and which applications to start or stop during repro.
[0025] In this embodiment, as machine states, in addition to the above-described "startup state", "shutdown state", and "restart state", a "repro state" in which only apps involved in repro are started and a "normal state" are defined, and the state transitions as shown in FIG. 2. In the "repro state", only the apps necessary for performing repro operate, and apps related to vehicle driving and navigation do not operate. When the EM startup is completed from "off", the state transitions to the "startup state". When the registration service startup is completed from the "startup state", the state transitions to the "normal state". When the operating conditions are satisfied from the "normal state", the state transitions to the "repro state". When the operating conditions are satisfied from the "repro state", the state transitions to the "normal state". When the reset condition is satisfied from the "normal state" or the "repro state", the state transitions to the "restart state". When the reset is released from the "restart state", the state transitions to "off".
[0026] In this embodiment, as function groups, a "first group" to which apps that can be reprogrammed while the vehicle drive mechanism is starting up belong and a "second group" to which apps not involved in reprogramming belong are defined. The first group and the second group are each defined with a startup state and a stop state. When the vehicle drive mechanism is starting up, for an engine-driven vehicle, it means ignition on, and for a motor-driven vehicle, it means motor on. When the vehicle drive mechanism is stopped, for an engine-driven vehicle, it means ignition off, and for a motor-driven vehicle, it means motor off. Alternatively, when the vehicle drive mechanism is starting up, for example, it indicates that the vehicle is in motion. The apps included in the first group are apps that do not affect vehicle driving, such as music and video playback apps. When the vehicle drive mechanism is stopped, for example, it indicates that the vehicle is stopped. The apps included in the second group are apps that are not necessary for performing reprogramming, such as apps related to vehicle driving and music and video playback apps.
[0027] When performing wireless reprogramming, the update program acquisition unit 5b acquires the update program by extracting the update program from the distribution package transferred from DCM4. When performing wired reprogramming, the update program acquisition unit 5b acquires the update program by extracting the update program from the distribution package transferred from the reprogramming tool. When the acquired update program is obtained by the update program acquisition unit 5b, the reprogramming execution unit 5c performs reprogramming by instructing the writing of the acquired update program to the ECU 3 to be reprogrammed.
[0028] As use cases for the reprogramming execution unit 5c to perform reprogramming, as shown in FIG. 3, use cases 1 to 4 are assumed. Use case 1 is a case where wireless reprogramming is performed while the vehicle drive mechanism is running, and installation, update, and uninstallation of applications are performed. In use case 1, the update target is the startup screen, and no screen switching between the startup screen and the non-startup screen is performed, and state transition of the function group is required. In use case 1, the state transition to the stop state is instructed to the applications belonging to the first group to start reprogramming, and after the reprogramming is completed, the state transition to the startup state is instructed to the applications belonging to the first group. For example, during vehicle driving, a situation where reprogramming of an application unrelated to vehicle driving is performed is assumed. In this case, the application to be reprogrammed migrates to the stop state by state transition and is updated, and migrates to the startup state when the reprogramming is completed.
[0029] Use case 2 is a case where wireless reprogramming is performed while the vehicle drive mechanism is running, and firmware update is performed. In use case 2, the update target is the non-startup screen, and screen switching between the startup screen and the non-startup screen is performed at the next switching from startup to stop or from stop to startup of the vehicle drive mechanism, and state transition of the function group is not required. In use case 2, reprogramming is started without instructing state transition to the applications belonging to the first group. For example, during vehicle driving, a situation where reprogramming of a non-operating application is performed is assumed. In this case, since the application to be reprogrammed is a non-operating application, state transition is not required.
[0030] Use Case 3 is the case where wireless reprogramming is performed while the vehicle drive mechanism is stopped to update the firmware. In Use Case 3, the update target is the non-operating surface, and it is necessary to restart and perform the surface switching between the operating surface and the non-operating surface, and the state transition of the function group is required. In Use Case 3, an instruction for state transition to the reprogramming state is given, an instruction for state transition to the stop state is given to the application belonging to the second group to start reprogramming, and an instruction for state transition to restart is given after the reprogramming is completed. For example, a situation where reprogramming of an application on the non-operating surface in the stopped state is assumed. In the reprogramming state, applications other than those necessary for the reprogramming are stopped.
[0031] Use Case 4 is the case where wired reprogramming is performed while the vehicle drive mechanism is stopped to update the firmware. In Use Case 4, the update target is the non-operating surface, and it is necessary to restart and perform the surface switching between the operating surface and the non-operating surface, and the state transition of the function group is required. In Use Case 4, an instruction for state transition to the reprogramming state is given, an instruction for state transition to the stop state is given to the application belonging to the second group to start reprogramming, and an instruction for state transition to restart is given after the reprogramming is completed.
[0032] Next, the operations of the above-described configuration will be described with reference to FIGS. 4 to 17. Here, the wireless reprogramming execution process by the wireless reprogramming application and the wired reprogramming execution process by the wired reprogramming application will be described. The control unit 5 executes the wireless reprogramming application to perform the wireless reprogramming execution process. The control unit 5 executes the wired reprogramming application to perform the wired reprogramming execution process.
[0033] (1-1) Wireless reprogramming execution process (see FIGS. 4 to 6) When the start condition of the wireless reprogramming execution process is satisfied, the wireless reprogramming application starts the wireless reprogramming execution process. When the wireless reprogramming application starts the wireless reprogramming execution process, it acquires the manifest file (corresponding to the manifest file acquisition procedure in S1) and acquires the update program (corresponding to the update program acquisition procedure in S2). Thereafter, the wireless reprogramming application executes the reprogramming execution procedure according to the acquired manifest file.
[0034] The wireless reprogramming application determines whether functions other than the reprogramming function can be stopped (S3). If the wireless reprogramming application determines that functions other than the reprogramming function cannot be stopped and are non-stopable due to, for example, the vehicle drive mechanism being in operation or the vehicle speed being equal to or higher than a predetermined value (S3: NO), it determines whether to perform a screen switching between the startup screen and the non-startup screen after reprogramming is completed, and determines whether a state transition of the function group is necessary (S4). The wireless reprogramming application determines whether a state transition of the function group is necessary based on, for example, a manifest file or a campaign notification. Note that although steps S3 and S4 are shown as conditional branches in the wireless reprogramming application, this is a branch for convenience in explaining the operation of the wireless reprogramming application. Depending on the nature of the update program, it is determined in which state of the above use cases 1 to 4 the update should be performed. Therefore, step S3 is a step of checking the state of the vehicle drive mechanism or the vehicle speed, and step S4 is a step of determining the state transition of the function group.
[0035] If the wireless reprogramming application determines that it does not perform a screen switching between the startup screen and the non-startup screen after reprogramming is completed, that is, if it determines that a state transition of the function group is necessary (S4: YES), it identifies that it corresponds to the above-described use case 1. When the wireless reprogramming application identifies that it corresponds to use case 1, it instructs the applications belonging to the first group to perform a state transition to the stopped state (S5) and starts reprogramming (S6). When the wireless reprogramming application starts reprogramming, it determines whether reprogramming is completed and also determines whether it has been canceled without completing reprogramming (S7, S8).
[0036] Alternatively, if the wireless reprogramming application determines that it does not perform a screen switching between the startup screen and the non-startup screen after reprogramming is completed, that is, if it determines that a state transition of the function group is necessary (S4: YES), it instructs the applications belonging to the first group to perform a state transition to the stopped state (S5) and starts reprogramming (S6). When the wireless reprogramming application starts reprogramming, it determines whether reprogramming is completed and also determines whether it has been canceled without completing reprogramming (S7, S8).
[0037] When the wireless reprogramming application determines that the reprogramming has been completed without cancellation (S7: YES), it instructs the applications belonging to the first group to transition to the startup state (S9) and ends the wireless reprogramming execution process. When the wireless reprogramming application determines that the reprogramming has been cancelled without completion (S8: YES), it performs a rollback to return to the state before the start of the reprogramming (S10), instructs the applications belonging to the first group to transition to the startup state (S9), and ends the wireless reprogramming execution process.
[0038] When the wireless reprogramming application determines that it is necessary to perform a screen switch between the startup screen and the non-startup screen after the reprogramming is completed, that is, when it determines that the state transition of the function group is not necessary (S4: NO), it identifies that it corresponds to the above-described use case 2. When the wireless reprogramming application identifies that it corresponds to use case 2, it starts the reprogramming without instructing the applications belonging to the first group to perform a state transition (S11). When the wireless reprogramming application starts the reprogramming, it determines whether the reprogramming has been completed and also determines whether the reprogramming has been cancelled without completion (S12, S13).
[0039] Alternatively, when the wireless reprogramming application determines that it is necessary to perform a screen switch between the startup screen and the non-startup screen after the reprogramming is completed, that is, when it determines that the state transition of the function group is not necessary (S4: NO), it starts the reprogramming without instructing the applications belonging to the first group to perform a state transition (S11). When the wireless reprogramming application starts the reprogramming, it determines whether the reprogramming has been completed and also determines whether the reprogramming has been cancelled without completion (S12, S13).
[0040] When the wireless reprogramming application determines that the reprogramming has been completed without cancellation (S12: YES), it ends the wireless reprogramming execution process. When the wireless reprogramming application determines that the reprogramming has been cancelled without completion (S13: YES), it performs a rollback to return to the state before the start of the reprogramming (S14) and ends the wireless reprogramming execution process.
[0041] When the wireless reprogramming application determines that it is possible to stop functions other than the reprogramming function, for example, because the vehicle drive mechanism is stopped or the vehicle speed is less than a predetermined value (S3: YES), it identifies that it corresponds to Use Case 3 described above. When the wireless reprogramming application identifies that it corresponds to Use Case 3, it instructs a state transition to the reprogramming state (S15), instructs a state transition to the stop state to the applications belonging to the second group (S16), and starts reprogramming (S17). When the wireless reprogramming application starts reprogramming, it determines whether reprogramming is completed and also determines whether reprogramming is canceled without being completed (S18, S19).
[0042] Alternatively, when the wireless reprogramming application determines that it is possible to stop functions other than the reprogramming function, for example, because the vehicle drive mechanism is stopped or the vehicle speed is less than a predetermined value (S3: YES), it instructs a state transition to the reprogramming state (S15), instructs a state transition to the stop state to the applications belonging to the second group (S16), and starts reprogramming (S17). When the wireless reprogramming application starts reprogramming, it determines whether reprogramming is completed and also determines whether reprogramming is canceled without being completed (S18, S19).
[0043] When the wireless reprogramming application determines that reprogramming is completed without being canceled (S18: YES), it instructs a state transition to the restart state (S20) and ends the wireless reprogramming execution process. When the wireless reprogramming application determines that reprogramming is canceled without being completed (S19: YES), it performs a rollback to return to the state before the start of reprogramming (S21), instructs a state transition to the normal state (S22), instructs a state transition to the startup state to the applications belonging to the second group (S23), and ends the wireless reprogramming execution process.
[0044] (1-2) Wired reprogramming execution process (see Fig. 7) When the start condition of the wired reprogramming process is satisfied, the wired reprogramming application starts the wired reprogramming process. When the wired reprogramming application starts the wired reprogramming process, it acquires a manifest file (corresponding to the manifest file acquisition procedure in S31) and acquires an update program (corresponding to the update program acquisition procedure in S32). The wired reprogramming application instructs a state transition to the reprogramming state (S33), instructs a state transition to the stopped state to the applications belonging to the second group (S34), and starts the reprogramming (S35). When the wired reprogramming application starts the reprogramming, it determines whether the reprogramming is completed and determines whether the reprogramming is canceled without being completed (S36, S37). When the wired reprogramming application determines that the reprogramming is completed without being canceled (S36: YES), it instructs a state transition to the restart state (S38) and ends the wired reprogramming process.
[0045] When the wired reprogramming application determines that the reprogramming is canceled without being completed (S37: YES), it performs a rollback to return to the state before the start of the reprogramming (S39), instructs a state transition to the normal state (S40), instructs a state transition to the startup state to the applications belonging to the second group (S41), and ends the wired reprogramming process.
[0046] The processing flows in each of the above-described use cases 1 to 4 will be described with reference to FIGS. 8 to 17. Here, a case where application X and application Y belong to the first group and application Y and application Z belong to the second group is exemplified.
[0047] (2-1) In the case of use case 1 (see FIGS. 8 to 9) The wireless reprogramming application acquires the manifest file, acquires the update program, determines that functions other than the reprogramming function cannot be stopped and are non-stop, and when it determines that a state transition of the function group is necessary, it notifies the SM of a state transition instruction to the stop state for the first group (t1). When the SM is notified of a state transition instruction to the stop state for the first group from the wireless reprogramming application, it notifies the EM of a state transition execution instruction (t2). When the EM is notified of a state transition execution instruction from the SM, it notifies the stop instruction to application X and application Y belonging to the first group (t3, t4), and notifies the SM of a response to the state transition execution instruction (t5). Application X and application Y stop when they are notified of the stop instruction from the EM. When the SM is notified of a response to the state transition execution instruction from the EM, it notifies the wireless reprogramming application of a response to the state transition instruction (t6).
[0048] When the wireless reprogramming application is notified of a response to the reprogramming instruction from the UCM, it notifies the SM of a state transition instruction to the start state for the first group (t9). When the SM is notified of a state transition instruction to the start state for the first group from the wireless reprogramming application, it notifies the EM of a state transition execution instruction (t10). When the EM is notified of a state transition execution instruction from the SM, it notifies the start instruction to application X and application Y belonging to the first group (t11, t12), and notifies the SM of a response to the state transition execution instruction (t13). Application X and application Y start when they are notified of the start instruction from the EM. When the SM is notified of a response to the state transition execution instruction from the EM, it notifies the wireless reprogramming application of a response to the state transition instruction (t14).
[0049] When the wireless reprogramming application is notified of a response to the reprogramming instruction from the UCM, it notifies the SM of a state transition instruction to the start state for the first group (t9). When the SM is notified of a state transition instruction to the start state for the first group from the wireless reprogramming application, it notifies the EM of a state transition execution instruction (t10). When the EM is notified of a state transition execution instruction from the SM, it notifies the start instruction to application X and application Y belonging to the first group (t11, t12), and notifies the SM of a response to the state transition execution instruction (t13). Application X and application Y start when they are notified of the start instruction from the EM. When the SM is notified of a response to the state transition execution instruction from the EM, it notifies the wireless reprogramming application of a response to the state transition instruction (t14).
[0050] On the one hand, if the wireless reprogramming application notifies the UCM of a reprogramming instruction (t7) and cancels it without completing the reprogramming, it notifies the UCM of a rollback instruction to return to the state before the start of the reprogramming (t15). When the UCM is notified of the rollback instruction from the wireless reprogramming application, it starts the rollback. When the UCM completes the rollback, it notifies the wireless reprogramming application of the response to the rollback instruction (t16). When the wireless reprogramming application is notified of the response to the rollback instruction from the UCM, it notifies the SM of the state transition instruction to the startup state for the first group (t9) and performs the operations after t9 described above.
[0051] (2-2) In the case of Use Case 2 (see FIGS. 10 to 11) The wireless reprogramming application obtains the manifest file, obtains the update program, determines that functions other than the reprogramming function are not stoppable and non-stoppable, and determines that no state transition of the function group is necessary, and then notifies the UCM of the reprogramming instruction (t21). When the UCM is notified of the reprogramming instruction from the wireless reprogramming application, it starts the reprogramming. When the UCM completes the reprogramming, it notifies the wireless reprogramming application of the response to the reprogramming instruction (t22).
[0052] On the one hand, if the wireless reprogramming application notifies the UCM of a reprogramming instruction (t21) and cancels it without completing the reprogramming, it notifies the UCM of a rollback instruction to return to the state before the start of the reprogramming (t23). When the UCM is notified of the rollback instruction from the wireless reprogramming application, it starts the rollback. When the UCM completes the rollback, it notifies the wireless reprogramming application of the response to the rollback instruction (t24).
[0053] (2-3) In the case of Use Case 3 (see FIGS. 12 to 14) When the wireless reprogramming application acquires the manifest file, acquires the update program, and determines that functions other than the reprogramming function can be stopped, it notifies the SM of the state transition instruction to the reprogramming state (t31). When the SM is notified of the state transition instruction to the reprogramming state from the wireless reprogramming application, it makes a state transition to the reprogramming state and notifies the wireless reprogramming application of the response to the state transition instruction (t32).
[0054] When the wireless reprogramming application is notified of the response to the state transition instruction from the SM, it notifies the SM of the state transition instruction to the stopped state for the second group (t33). When the SM is notified of the state transition instruction to the stopped state for the second group from the wireless reprogramming application, it notifies the EM of the state transition execution instruction (t34). When the EM is notified of the state transition execution instruction from the SM, it notifies the application Y and application Z belonging to the second group of the stop instruction (t35, t36), and notifies the SM of the response to the state transition execution instruction (t37). The application Y and application Z stop when they are notified of the stop instruction from the EM. When the SM is notified of the response to the state transition execution instruction from the EM, it notifies the wireless reprogramming application of the response to the state transition instruction (t38).
[0055] When the wireless reprogramming application is notified of the response to the state transition instruction from the SM, it notifies the UCM of the reprogramming instruction (t39). When the UCM is notified of the reprogramming instruction from the wireless reprogramming application, it starts reprogramming. When the UCM completes the reprogramming, it notifies the wireless reprogramming application of the response to the reprogramming instruction (t40).
[0056] When the wireless reprogramming application is notified of the response to the reprogramming instruction from the UCM, it notifies the SM of the state transition instruction to the restart state (t41). When the SM is notified of the state transition instruction to the restart state from the wireless reprogramming application, it performs the restart.
[0057] On one hand, when the wireless reprogramming application notifies the UCM of the reprogramming instruction (t39) and cancels it without completing the reprogramming, it notifies the SM of the state transition instruction to the normal state (t42). When the SM receives the state transition instruction to the normal state from the wireless reprogramming application, it makes a state transition to the normal state and notifies the wireless reprogramming application of the response to the state transition instruction (t43).
[0058] When the wireless reprogramming application receives the response to the state transition instruction from the SM, it notifies the SM of the state transition instruction to the startup state for the second group (t44). When the SM receives the state transition instruction to the startup state for the second group from the wireless reprogramming application, it notifies the EM of the state transition execution instruction (t45). When the EM receives the state transition execution instruction from the SM, it notifies the app Y and app Z belonging to the second group of the startup instruction (t46, t47) and notifies the SM of the response to the state transition execution instruction (t48). The app Y and app Z start up when they receive the startup instruction from the EM. When the SM receives the response to the state transition execution instruction from the EM, it notifies the wireless reprogramming application of the response to the state transition instruction (t49).
[0059] (2-4) In the case of use case 4 (see FIGS. 15 to 17) The wired reprogramming application performs the same processing as the wireless reprogramming application in the case of use case 3 described above. That is, the wired reprogramming application performs t51 to t69 similar to t31 to t49.
[0060] As described above, according to this embodiment, the following operational effects can be obtained. In the master ECU 1, state transitions to the normal state and the repro state defined as machine states in the manifest file are instructed, and state transitions to the start state and the stop state are individually instructed for each of the first group and the second group defined as function groups in the manifest file. By instructing state transitions to the normal state and the repro state and individually instructing state transitions to the start state and the stop state for each of the first group and the second group, repro can be appropriately implemented. As a result, repro can be appropriately implemented without restarting the ECU 3 to be reprogrammed.
[0061] In the master ECU 1, when wireless repro is performed while the vehicle drive mechanism is operating and installation, update, and uninstallation of applications are carried out, a state transition to the stop state is instructed to the applications belonging to the first group to start repro, and a state transition to the start state is instructed to the applications belonging to the first group after repro is completed. Repro can be appropriately implemented in a situation where wireless repro is performed while the vehicle drive mechanism is operating and installation, update, and uninstallation of applications are carried out.
[0062] In the master ECU 1, when wireless repro is performed while the vehicle drive mechanism is operating and firmware update is carried out, repro is started without instructing a state transition to the applications belonging to the first group. Repro can be appropriately implemented in a situation where wireless repro is performed while the vehicle drive mechanism is operating and firmware update is carried out.
[0063] In the master ECU 1, when wireless repro is performed while the vehicle drive mechanism is stopped and firmware update is carried out, a state transition to the repro state is instructed, a state transition to the stop state is instructed to the applications belonging to the second group to start repro, and a state transition to restart is instructed after repro is completed. Repro can be appropriately implemented in a situation where wireless repro is performed while the vehicle drive mechanism is stopped and firmware update is carried out.
[0064] In the master ECU 1, when performing a wired repro and updating the firmware while the vehicle drive mechanism is stopped, it is configured to instruct a state transition to the repro state, instruct the apps belonging to the second group to perform a state transition to the stop state to start the repro, and instruct a state transition to restart after the repro is completed. In a situation where a wired repro is performed while the vehicle drive mechanism is stopped and the firmware is updated, the repro can be appropriately performed.
[0065] Although the present disclosure has been described based on embodiments, it is understood that the present disclosure is not limited to such embodiments or structures. The present disclosure also includes various modifications and variations within an equivalent range. In addition, various combinations and forms, and further other combinations and forms including only one, more, or less than one element thereof, fall within the scope and spirit of the present disclosure.
[0066] The control unit and its method described in the present disclosure may be realized by a dedicated computer configured by a processor and a memory programmed to execute one or more functions embodied by a computer program. Alternatively, the control unit and its method described in the present disclosure may be realized by a dedicated computer configured by a processor constituted by one or more dedicated hardware logic circuits. Or, the control unit and its method described in the present disclosure may be realized by one or more dedicated computers constituted by a combination of a processor and a memory programmed to execute one or more functions and a processor constituted by one or more hardware logic circuits. Also, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by a computer.
Description of Reference Numerals
[0067] In the drawings, 1 is a master ECU (Electronic Control Unit), 3 is an ECU to be reprogrammed, 5 is a control unit, 5a is a manifest file acquisition unit, 5b is an update program acquisition unit, and 5c is a repro execution unit.
Claims
1. A manifest file acquisition unit (5a) that acquires a manifest file, An update program acquisition unit (5b) that acquires an update program, A repro execution unit (5c) that executes repro by instructing the writing of the update program to an electronic control device to be repro'd, and comprising: In the manifest file, as machine states conforming to the standards of a predetermined in-vehicle software platform standard specification, at least a normal state and a repro state in which only apps involved in repro are started are defined, and as a function group conforming to the standards of the in-vehicle software platform standard specification, a first group to which apps that can be repro'd while the vehicle drive mechanism is running belong is defined, a second group to which apps not involved in repro belong is defined, and start states and stop states are defined for each of the first group and the second group. The repro execution unit is an electronic control device that executes repro in accordance with the machine state and the function group defined in the manifest file.
2. The repro execution unit acquires the update program from the distribution source of the update program by wireless communication, cannot stop functions other than the repro function, and when a state transition of the function group is necessary, instructs the apps belonging to the first group to transition to the stop state and starts repro. The electronic control device according to Claim 1.
3. The repro execution unit is the electronic control device according to Claim 2, which instructs the apps belonging to the first group to transition to the start state after completing repro.
4. The repro execution unit acquires the update program from the distribution source of the update program by wireless communication, cannot stop functions other than the repro function, and when a state transition of the function group is not necessary, starts repro without instructing the apps belonging to the first group to perform a state transition. The electronic control device according to Claim 1.
5. The repro execution unit acquires the update program from the distribution source of the update program by wireless communication, and when functions other than the repro function can be stopped, instructs a transition to the repro state, instructs the apps belonging to the second group to transition to the stop state, and starts repro. The electronic control device according to Claim 1.
6. When the repro execution unit acquires the update program from the distribution source of the update program by wire communication, it instructs a state transition to the repro state and instructs a state transition to the stop state to the applications belonging to the second group to start repro. The electronic control device according to claim 1.
7. In the manifest file, in addition to the normal state and the repro state as the machine states, a restart state is defined. The repro execution unit instructs a state transition to the restart state after completing repro. The electronic control device according to claim 5 or 6.
8. When the repro execution unit cancels without completing repro, it instructs a state transition to the normal state and instructs a state transition to the startup state to the applications belonging to the second group. The electronic control device according to claim 5 or 6.
9. The predetermined in-vehicle software platform standard specification is the standard specification defined by AUTOZAR. The electronic control device according to claim 1.
10. In an electronic control device (1) that performs repro by instructing the writing of an update program to the electronic control device to be reprogrammed, a manifest file acquisition procedure for acquiring a manifest file, an update program acquisition procedure for acquiring the update program, and a repro execution procedure for performing repro according to the machine state and function group defined in the manifest file. In the manifest file, as machine states conforming to the specifications of a predetermined in-vehicle software platform standard specification, at least a normal state and a repro state in which only applications involved in repro are started are defined. As a function group conforming to the specifications of the in-vehicle software platform standard specification, a first group to which applications that can be reprogrammed while the vehicle drive mechanism is running belongs is defined, and a second group to which applications not involved in repro belong is defined. A repro execution method in which a startup state and a stop state are defined for each of the first group and the second group.
11. In the control unit (5) of the electronic control device (1) that performs repro by instructing the writing of an update program to the electronic control device to be reprogrammed, a manifest file acquisition procedure for acquiring a manifest file, an update program acquisition procedure for acquiring the update program, Execute a reprocedure execution procedure for performing repro in accordance with the machine state and function group defined in the manifest file, In the manifest file, as machine states conforming to the standards of a predetermined in-vehicle software platform standard specification, at least a normal state and a repro state in which only an app involved in repro is started are defined. As function groups conforming to the standards of the in-vehicle software platform standard specification, a first group to which an app that can be reprogrammed while the vehicle drive mechanism is running belongs is defined, a second group to which an app not involved in repro belongs is defined, and a repro execution program in which a start state and a stop state are defined for each of the first group and the second group.
Citation Information
Patent Citations
Data transmission system, data transmission method, intelligent vehicle and device
CN112673609A
On-vehicle program update device
JP2014106875A
Information update device and information update method
JP2019074800A
Vehicle electronic control system, screen display control method for progress display, and screen display control program for progress display
JP2021009658A
Vehicle control device and program updating system
WO2018139296A1