Control device, method, program, and vehicle

The control device facilitates efficient vehicle software updates by switching between wireless and wired methods, addressing the challenges of convenience and stability in existing update technologies.

JP7722525B2Active Publication Date: 2025-08-13TOYOTA JIDOSHA KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024096363
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-08-13
Estimated Expiration
2041-04-27

Smart Images

  • Figure 0007722525000001
    Figure 0007722525000001
  • Figure 0007722525000002
    Figure 0007722525000002
  • Figure 0007722525000003
    Figure 0007722525000003
Patent Text Reader

Abstract

To provide a control device that, from the start of update of a predetermined delivery package until the completion of the update, can reduce the time required for the completion of the update while ensuring convenience for a user.SOLUTION: A control device included in a vehicle executes wireless update processing of updating a program of an electronic control unit included in the vehicle based on update data received from a center by using wireless communication, and after the start of the wireless update processing and before the completion of the wireless update processing, when wired update processing of updating the program of the electronic control unit is started by using wired communication, takes over the progress of the wireless update processing and executes the wired update processing.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an update control system including a vehicle equipped with an on-board control device that updates software in one or more electronic control units, an information processing terminal capable of wired communication with the on-board control device, and a center capable of communicating with the on-board control device via a wireless network. [Background technology]

[0002] Conventionally, two known methods for updating software in electronic control units are a method in which the vehicle is brought to a maintenance workshop and the update is performed via a wired connection (wired update), and a method in which the vehicle is updated from a remote location via wireless communication with an update center without having to be brought to a maintenance workshop (wireless update) (for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-004245 Summary of the Invention [Problem to be solved by the invention]

[0004] The wired update is expected to provide stable communication because it is a wired connection. However, it takes time to complete the update. Therefore, the vehicle must be brought into a repair shop for the wired update. While the vehicle is in the repair shop, the user cannot use the vehicle, which can be a detriment to the user's convenience.

[0005] On the other hand, with wireless updates, as long as communication with the update center is possible, the user can download a distribution package, which is a collection of update data, regardless of location, even while using the vehicle. However, with wireless updates, there is a risk of communication conditions becoming unstable. For example, there is a risk of communication conditions becoming unstable when driving through an area where communication with the update center is not possible.

[0006] The present disclosure has been made in consideration of the above-mentioned problems, and aims to provide a control device, etc. that can shorten the time it takes to complete an update process related to a specified distribution package while ensuring user convenience from the start to the completion of the update process. [Means for solving the problem]

[0007] In order to solve the above problem, one aspect of the disclosed technology is a control device provided in a vehicle, which executes a wireless update process to update a program of an electronic control unit provided in the vehicle based on update data received from a center using wireless communication, and if a wired update process is started to update the program of the electronic control unit using wired communication after the wireless update process has been started but before the wireless update process is completed, the control device takes over the progress of the wireless update process and executes the wired update process. [Effects of the Invention]

[0008] According to the present disclosure, it is possible to shorten the time required to complete update processing while ensuring user convenience. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a block diagram showing the overall configuration of a system according to an embodiment of the present invention. [Figure 2] Block diagram showing the general configuration of the center [Figure 3] Block diagram showing the general configuration of an on-board control device [Figure 4] Center functional block diagram [Figure 5] Functional block diagram of the on-board control device [Figure 6] 1 is a memory map showing an example of data stored in the storage unit of the center. [Figure 7] An example of the data structure of a vehicle database [Figure 8] 1 is a memory map showing an example of data stored in a storage unit of an on-vehicle control device; [Figure 9]10 is a flowchart showing details of a control process executed by an on-vehicle control device. [Figure 10] Flowchart showing the details of the OTA inquiry process [Figure 11] Flowchart showing details of wired inquiry processing [Figure 12] Flowchart showing details of update control processing [Figure 13] 1 is a flowchart showing details of a center-side control process executed at a center. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0011] [Overall configuration of the update control system] The configuration of the update control system according to the present disclosure will be described. Fig. 1 is a block diagram showing the overall configuration of the update control system. The update control system includes a center 1, a maintenance workshop 2, and a vehicle 3.

[0012] The center 1 is a server for managing software updates of electronic control units provided in the vehicles 3 (more precisely, the center 1 is a center system including such a server, but for ease of explanation, it will be described below as a server). The center 1 is capable of wireless communication with the vehicles 3. The center 1 is also capable of at least wired communication (Internet, dedicated line communication, etc.) with the maintenance workshop 2 (more precisely, a predetermined server, information processing terminal, etc., possessed by the maintenance workshop 2).

[0013] The maintenance workshop 2 is a workshop for maintaining the vehicle 3. The maintenance workshop 2 has an in-factory network to which an information processing terminal for maintenance work (hereinafter referred to as a maintenance work terminal), not shown, is connected. The maintenance work terminal is capable of communicating with the center 1 via the in-factory network. In addition, an entered vehicle 3 can be connected to the in-factory network or the maintenance work terminal via a wired connection, and an update process can be executed to update the software of the electronic control unit of the vehicle 3 based on a predetermined operation by a mechanic. Hereinafter, the update process performed in a wired environment at the maintenance workshop will be referred to as a wired update. In addition, in this embodiment, the sequences constituting the update process include at least a sequence of "inquiring about whether an update is required," a sequence of "downloading a distribution package," and a sequence of "writing update data."

[0014] The vehicle 3 is capable of wireless communication with the center 1, and can execute the update process using this wireless communication. Hereinafter, the update process using wireless communication between the vehicle 3 and the center 1 will be referred to as a wireless update (note that a service that provides such wireless updates will be referred to as an OTA service). It is also possible to execute the wired update by bringing the vehicle 3 into the maintenance workshop 2. Hereinafter, a state in which the vehicle 3 is not connected by wire and a wired update is not possible but a wireless update is possible will be referred to as a first state. A state in which the vehicle 3 is connected by wire at the maintenance workshop 2 and a wired update is possible will be referred to as a second state.

[0015] [Configuration of Center 1] Fig. 2 is a block diagram showing a schematic configuration of the center 1. As shown in Fig. 2, the center 1 includes a processor 11, a RAM 12, a storage device 13, and a communication device 14. The storage device 13 includes a readable / writable storage medium such as a hard disk or SSD, and stores various programs and data required for the processing according to this embodiment. In the center 1, the processor 11 executes a program read from the storage device 13 using the RAM 12 as a work area, thereby performing predetermined control processing. The communication device 14 is a device that communicates with the maintenance shop 2 and the vehicle 3 via a network.

[0016] [About the configuration of vehicle 3] FIG. 3 is a block diagram showing a schematic configuration of the vehicle 3. As shown in FIG. 3, the vehicle 3 includes at least an on-board control device 31, a communication module 32, a plurality of electronic control units (ECUs) 33a to 33d, and a diagnostic connector 36. The on-board control device 31 is connected to the communication module 32, the electronic control units 33a to 33d, and the diagnostic connector 36 via a bus 35. The on-board control device 31 can wirelessly communicate with the center 1 via the communication module 32. The on-board control device 31 controls the software update process of each electronic control unit 33 while transmitting and receiving predetermined data to and from the center 1. That is, the on-board control device 31 has a software update function via wireless update. The communication module 32 is a communication device that can wirelessly connect to a predetermined network (such as a telephone network or the Internet). Furthermore, the on-board control device 31 can perform the wired update via the diagnostic connector 36 while the vehicle is in the maintenance shop 2. That is, the on-board control device 31 has a function of updating software via a wired update.

[0017] The on-board control device 31 also includes a microcomputer 45 having a processor 41, a RAM 42, a ROM 43, and a storage device 44, and a communication device 46. In the on-board control device 31, the processor 41 of the microcomputer 45 executes a predetermined process by reading a program from the ROM 43 and using the RAM 42 as a work area. Specifically, the processor 41 executes a process related to the software update function via the wireless update or the software update function via a wired update. The communication device 46 is a device that communicates with the communication module 32, the electronic control units 33a to 33d, and the diagnostic connector 36 (or a maintenance work terminal connected to the diagnostic connector 36 via a wired connection) via the bus 35.

[0018] The electronic control units 33a to 33d control the operation of each part of the vehicle 3. It goes without saying that the number of electronic control units 33 in Fig. 3 is just an example.

[0019] [Center 1 functional block diagram] 4 is a functional block diagram of the center 1. The center 1 includes a storage unit 16, a communication unit 17, and a control unit 18. The communication unit 17 and the control unit 18 are realized by the processor 11 shown in FIG. 2 executing a program stored in the storage unit 13 using the RAM 12, and the storage unit 16 is realized by the storage unit 13 shown in FIG. 2.

[0020] The storage unit 16 stores programs and data used in the processing according to this embodiment.

[0021] The control unit 18 uses the communication unit 17 to transmit and receive predetermined data to and from the on-board control device 31, and executes wireless update processing. The control unit 18 also uses the communication unit 17 to transmit and receive predetermined data to and from the maintenance shop 2, and executes wired update processing.

[0022] [Functional block diagram of the on-board control device 31] FIG. 5 is a functional block diagram of the on-board control device 31 shown in FIG.

[0023] The on-board control device 31 includes a storage unit 47, a communication unit 48, and a control unit 49. The storage unit 47 is realized by the storage device 44 shown in Fig. 3. The communication unit 48 and the control unit 49 are realized by the processor 41 shown in Fig. 3 executing a program stored in the ROM 43 using the RAM 42.

[0024] The storage unit 47 stores various programs and data for executing the software update process.

[0025] The control unit 49 has a wired update control unit 491 and an OTA master 492. The wired update control unit 491 performs control related to the above-mentioned wired update, and the OTA master 492 performs control related to the above-mentioned wireless update.

[0026] In the second state, the wired update control unit 491 performs control relating to the wired update based on instructions (diagnosis communication commands, etc.) from the maintenance work terminal.

[0027] Here, a supplementary explanation will be given regarding the wired connection of the vehicle 3 in the maintenance workshop 2. In this embodiment, any connection may be used as long as the vehicle 3 (on-board control device 31) is wired to the maintenance workshop 2 and can communicate with the center 1. For example, the following connection may be considered. First, the on-board control device 31 may be connected to the in-plant network of the maintenance workshop 2 via the diagnostic connector 36. In this case, the control unit 49 may receive an instruction from the maintenance work terminal connected to the in-plant network, and based on the instruction, the control unit 49 may communicate with the center 1 via the in-plant network and execute a wired update process. For example, based on an instruction from the maintenance work terminal, the control unit 49 may transmit data to the center 1 to inquire about the availability of an update (hereinafter referred to as an update inquiry). If an update is available, the control unit 49 may download a distribution package (a collection of update data; details will be described later) from the center 1. Furthermore, based on an instruction from the maintenance work terminal, the control unit 49 may update the software of a specific electronic control unit 33 using the downloaded distribution package. Another possible connection mode is to connect the maintenance work terminal directly to the on-board control device 31 via the diagnostic connector 36. In this case, for example, the maintenance work terminal may be the main driver of the update process. For example, the following process may be considered: First, based on an instruction from the maintenance work terminal, the control unit 49 transmits information about the vehicle 3, such as configuration information of the vehicle 3, to the maintenance work terminal. The maintenance work terminal (acting on behalf of the control unit 49) makes an update inquiry to the center 1, including the relevant information. If an update is available, the control unit 49 downloads a distribution package to the maintenance work terminal and transmits it to the storage unit 47. Then, based on an instruction from the maintenance work terminal, the control unit 49 executes a process to update the software of a specific electronic control unit 33. Alternatively, when the maintenance work terminal is directly connected to the on-board control device 31 via the diagnostic connector 36, the maintenance work terminal may function as a repeater. In other words, the communication between the control unit 49 and the center 1 may be relayed by the wired maintenance work terminal.

[0028] In addition, the wired connection of the vehicle 3 in the maintenance workshop 2 is not limited to the above and may be any connection mode as long as the control unit 49 is capable of performing the wired update in the second state.

[0029] Next, in the first state, the OTA master 492 wirelessly communicates with the center 1 via the communication unit 48 and executes various controls related to the wireless update. Specifically, the control unit 49 inquires about an update, and if an update is available, downloads a distribution package related to the update from the center 1 via wireless communication. Then, the OTA master 492 updates the software of the electronic control unit 33 based on the downloaded distribution package.

[0030] In this embodiment, the following control process is performed using the above configuration: That is, if the state of the vehicle 3 switches between a first state and a second state during the period from the start of the update process for applying a predetermined distribution package to the completion of the process, the progress of the update process before the switch is taken over, and the update process in the state after the switch is continued.

[0031] The processing according to this embodiment will be described in detail below.

[0032] [Data used at Center 1] First, we will explain the data used in the processing at the center 1. Fig. 6 is a memory map showing an example of data stored in the storage unit 16 of the center 1. The storage unit 16 stores an update control program 101, a vehicle database 102, and a distribution package 103. Although not shown, the storage unit 16 also stores various other data required for processing related to update control, as appropriate.

[0033] The update control program 101 is a program for controlling the software update process according to this embodiment in the center 1.

[0034] The vehicle database 102 is a database of vehicles 3 for which update control is managed by the center 1. FIG. 7 shows an example of the data configuration of the vehicle database 102. The vehicle database 102 is a database that includes at least the following items: vehicle identification number (VIN) 111, update history 112, and update progress status 113. The vehicle identification number 111 is a number for identifying each individual vehicle 3. The update history 112 records the history of completed update processes for a specific vehicle 3. The update history 112 is used to determine whether there are any updates to be applied to a specific vehicle 3. The update progress status 113 is data that indicates how far the process has progressed in the update process for applying a specific distribution package 103 (i.e., one update process). In other words, it is data that indicates the progress of the process from the start of the update process for applying a certain distribution package 103 to the completion of the update process.

[0035] The distribution package 103 is a collection of update data for updating the software of the electronic control unit 33. The distribution package 103 may include multiple pieces of update data for updating the software of one or more electronic control units 33. In other words, the distribution package 103 can be said to be data in which one or more pieces of update data are packaged together. For example, if there are three electronic control units 33 to be updated in one update process (hereinafter referred to as target ECUs), the update data for each of these units is distributed together as one distribution package 103.

[0036] The distribution package 103 also includes three types of data: OTA data 104, wired update data 105, and common data 106. The OTA data 104 is data used only in the wireless update. The wired update data 105 is data used only in the wired update. For example, the OTA data 104 is predetermined update data in a format and content suitable for a wireless update, and the wired update data 105 is predetermined update data in a format and content suitable for a wired update. The common data 106 is data used in common for both the wireless update and the wired update. Therefore, the content transmitted to the vehicle 3 as the distribution package 103 may change depending on whether the vehicle 3 is in a first state or a second state. In other words, when the vehicle 3 is in the second state, the wired update data 105 and the common data 106 are transmitted, and the wired update process is performed using these data. Furthermore, when the vehicle 3 is in the first state, the OTA data 104 and the common data 106 are transmitted, and a wireless update process is performed using these. Note that, for the sake of convenience, only one distribution package 103 is shown in Fig. 6, but a plurality of distribution packages 103 may be stored in the storage unit 16 of the center 1.

[0037] [Data used by the on-board control device 31] Next, a description will be given of data used in the on-board control device 31. Fig. 7 is a memory map showing an example of data stored in the storage unit 47 of the on-board control device 31. The storage unit 47 of the on-board control device 31 stores at least an update control program 121, a wired update program 122, an OTA program 123, an update environment flag 124, an update in progress flag 125, progress status data 126, and update work data 127.

[0038] The update control program 121 is a program for controlling the entire update control process according to this embodiment in the on-board control device 31. Specifically, the update control program 121 is a program for controlling switching between the execution of a wired update program 122 and an OTA program 123, which will be described below.

[0039] The wired update program 122 is a program for executing update processing related to the wired update, and the OTA program 123 is a program for executing update processing related to the wireless update.

[0040] The update environment flag 124 is a flag for determining whether the state of the vehicle 3 is the first state or the second state.

[0041] The updating in progress flag 125 is a flag for indicating whether an update process is currently in progress. In this embodiment, after the update process for applying a predetermined distribution package 103 is started, the updating in progress flag 125 is set to on until the update process is completed, and is set to off once the update process is completed. For example, if the distribution package 103 is in a state of being downloaded, the updating in progress flag 125 is set to on. Also, if there are three target ECUs in the predetermined distribution package 103, and the update of two of them has been completed but the remaining one has not yet been completed, the updating in progress flag 125 is set to on. Once the update of all three target ECUs to be updated has been completed, the updating in progress flag 125 is set to off.

[0042] The progress status data 126 is data for more specifically indicating how far the update process has progressed when the update process is being executed (updating flag 125 is on). For example, data indicating how far the sequences constituting the update process have progressed, how much data has been downloaded if the download of distribution package 103 is not complete, and how much memory block the update data has been written to is stored.

[0043] The update work data 127 is data that is temporarily stored for use in the update process, and specifically, the distribution package 103 downloaded from the center 1 is stored.

[0044] [Details of the process executed by the control unit 49 of the vehicle 3] Next, the processing executed by the control unit 49 of the vehicle 3 will be described. FIG. 9 is a flowchart showing details of the control processing executed by the control unit 49 of the vehicle 3. In FIG. 9, in step S1, the control unit 49 refers to the update in progress flag 125 to determine whether or not the update processing is currently being executed. If the result of this determination is that the update processing is not being executed (NO in step S1), then in step S2, the control unit 49 determines whether or not the vehicle 3 is in a second state, that is, a state in which a wired update is possible. This is determined, for example, by detecting whether or not a predetermined cable is connected to the diagnostic connector 36. Alternatively, this determination may be made based on whether or not a diagnostic communication command has been transmitted (from the maintenance work terminal).

[0045] If the result of the determination in step S2 is that the vehicle 3 is not in the second state (NO in step S2), the control unit 49 executes OTA inquiry processing in step S3. On the other hand, if the vehicle 3 is in the second state (YES in step S2), the control unit 49 executes wired inquiry processing in step S4. The processing in steps S3 and S4 will be described in detail below.

[0046] 10 is a flowchart showing details of the OTA inquiry process in step S3. In this process, a process for making the update inquiry to the center 1 using wireless communication is executed (an "update inquiry" sequence). In this process, the control unit 49 executes the OTA program 123. As a result, in this process, the control unit 49 functions as the OTA master 492.

[0047] 10, first, in step S11, the OTA master 492 determines whether or not it is time to make an update inquiry. This timing may be any timing, but in this embodiment, the update inquiry is made once every 10 days. Therefore, the OTA master 492 determines whether or not it is time to make an update inquiry by determining whether or not 10 days or more have passed since the previous update inquiry. If the result of this determination is that it is not time to make an update inquiry (NO in step S11), the OTA master 492 ends the OTA inquiry process. On the other hand, if it is time to make an update inquiry (YES in step S11), in step S12, the OTA master 492 makes an update inquiry to the center 1 using wireless communication.

[0048] Next, in step S13, the OTA master 492 determines whether the content of the response from the center 1 to the update inquiry indicates that an update is available. If the result of this determination is that there is no update (NO in step S13), the OTA master 492 ends the OTA inquiry process. On the other hand, if there is an update (YES in step S13), the OTA master 492 sets the updating flag 125 to ON in step S14. Then, in step S15, the OTA master 492 starts processing related to the wireless update. Specifically, it starts the sequence of "downloading a distribution package." This concludes the description of the OTA inquiry process.

[0049] 11 is a flowchart showing the details of the wired inquiry process in step S4. In this process, a process is executed to make the update inquiry to the center 1 using wired communication. In this process, the control unit 49 executes the wired update program 122. As a result, in this process, the control unit 49 functions as the wired update control unit 491.

[0050] 11, first, in step S21, the wired update control unit 491 determines whether or not an instruction to make an update inquiry has been sent from the maintenance work terminal. If the result of this determination is that an instruction to make an update inquiry has not been sent (NO in step S21), then in step S22, the wired update control unit 491 determines whether or not an instruction to end the work by the maintenance worker has been sent from the maintenance work terminal. If the result of this determination is that an instruction to end the work has been sent (YES in step S22), the wired update control unit 491 ends the wired inquiry processing. On the other hand, if the instruction to end the work has not been sent (NO in step S22), the wired update control unit 491 returns to step S21 and repeats the processing.

[0051] On the other hand, if the result of the judgment in step S21 above is that an instruction to make an update inquiry is sent from the maintenance work terminal (YES in step S21), then in step S23, the wired update control unit 491 makes an update inquiry to the center 1 using the wired communication.

[0052] Next, in step S24, the wired update control unit 491 determines whether the content of the response from the center 1 to the above inquiry indicates that an update is available. If the result of this determination is that there is no update (NO in step S24), the wired update control unit 491 ends the wired inquiry process. On the other hand, if there is an update (YES in step S24), in step S25 the wired update control unit 491 sets the updating in progress flag 125 to ON. Then, in step S26, the wired update control unit 491 starts processing related to the wired update. Specifically, it starts the sequence of "downloading a distribution package." This concludes the description of the wired inquiry process.

[0053] 9, next, a process when it is determined in step S1 that update processing is currently in progress (YES in step S1) will be described. In this case, in step S5, the control unit 49 executes update control processing. In this process, processing for continuing execution of either the processing related to the wired update or the processing related to the wireless update is performed depending on the state of the vehicle 3.

[0054] Fig. 12 is a flowchart showing the details of the update control process. In Fig. 12, first, in step S31, the control unit 49 references the update environment flag 124 to determine whether the vehicle 3 is currently in the first state. If the result of this determination is that the vehicle 3 is in the first state (YES in step S31), it can be said that a wireless update is being performed. In this case, in step S32, the control unit 49 determines whether the state of the vehicle 3 has switched from the first state to the second state. For example, if it is detected that a predetermined cable has been connected to the diagnostic connector 36 or if it is detected that a diagnostic communication command has been transmitted from the maintenance work terminal, the control unit 49 determines that the state has switched from the first state to the second state.

[0055] If the result of the determination in step S32 is that the state has switched from the first state to the second state (YES in step S32), then in step S34, the control unit 49 executes processing to switch the control of the update process from wireless update to wired update. The switching processing may, for example, be as follows: First, the control unit 49 generates data indicating the progress of the update process at that time and stores it in the storage unit 47 as progress status data 126. This data may indicate, for example, how far the update process sequence has progressed, or, if the download of the distribution package 103 is in progress, how far the download has progressed. Next, the control unit 49 transmits a switching notification to the center 1 indicating that the state of the vehicle 3 has switched from the first state to the second state (the center 1, upon receiving this notification, performs control such as changing the content of the distribution package 103 to be transmitted from the center 1). Next, the control unit 49 switches the control program to be executed. Specifically, the processing based on the OTA program 123 currently being executed is terminated. Next, the control unit 49 sets data indicating the second state in the update environment flag 124. Furthermore, the control unit 49 starts the wired update program 122. Then, based on the progress status data 126, the control unit 49 executes the wired update process from the state in which the progress status of the update process has been inherited. In other words, based on the progress status data 126, the update process is resumed in the wired update environment. Thereafter, the update control process ends.

[0056] Note that any switching control method may be used, not limited to the above, as long as it is possible to switch from wireless update control to wired update control while keeping the progress of the update control.

[0057] On the other hand, if the state has not been switched from the first state to the second state (NO in step S32), the update process continues in the current environment. In this case, since the first state remains, the process related to the wireless update continues. For example, if the "download distribution package" sequence has not yet finished, the download process continues, and once the "download distribution package" sequence has finished, the "write update data" sequence is executed next. Note that in the process related to the wireless update, the control unit 49 functions as the OTA master 492.

[0058] Next, a case will be described where the result of the determination in step S31 above indicates that the current state of the vehicle 3 is not the first state (NO in step S31). In this case, it can be said that processing related to a wired update is being executed. In this case, in step S35, the control unit 49 determines whether the state of the vehicle 3 has switched from the second state to the first state. For example, if it is detected that the cable connected to the diagnostic connector 36 has become disconnected, or if a command indicating the end of work is sent from the maintenance work terminal, the control unit 49 determines that the state has switched from the second state to the first state.

[0059] If the result of the determination in step S35 is that the state has switched from the second state to the first state (YES in step S35), in step S36, the control unit 49 executes processing to switch control of the update process from wired update to wireless update. The switching processing may, for example, be as follows: First, the control unit 49 generates data indicating the progress of the update process at that time and stores it in the storage unit 47 as progress status data 126. Next, the control unit 49 transmits a switching notification to the center 1 indicating that the state of the vehicle 3 has switched from the second state to the first state. Next, the control unit 49 ends the processing based on the currently executing wired update program 122. Next, the control unit 49 sets the update environment flag 124 to data indicating the first state. Furthermore, the control unit 49 starts the OTA program 123. Then, the control unit 49 executes processing related to the wireless update from a state in which the progress status of the update process has been inherited, based on the progress status data 126. That is, based on the progress status data 126, the update process is resumed in an over-the-air update environment.

[0060] Note that any switching control method may be used, not limited to the above, as long as it is possible to switch from wired update control to wireless update control while maintaining the progress of the update.

[0061] On the other hand, if the state has not been switched from the second state to the first state (NO in step S35), the update process continues in the current environment in step S33. In this case, since the second state continues, the process related to the wired update continues. In the process related to the wired update, the control unit 49 functions as the wired update control unit 491.

[0062] This concludes the description of the update control process.

[0063] Returning to FIG. 9, next, in step S6, the control unit 49 determines whether the update process by wired update or wireless update has been completed. If the update process has not been completed (NO in step S6), the process returns to step S1, and the process is repeated. On the other hand, if the update process has been completed (YES in step S6), the control unit 49 sets the updating in progress flag 125 to OFF in step S7. In the following step S8, the control unit 49 transmits an update completion notification indicating that the update process has been completed to the center 1. Thereafter, the process returns to step S1, and the process is repeated.

[0064] [Processing at Center 1] Next, the control processing executed in the center 1 will be described. FIG. 13 is a flowchart showing the details of the center-side control processing executed in the center 1. In FIG. 13, first, in step S51, the control unit 18 of the center 1 determines whether or not there has been an update inquiry such as that described above from a predetermined on-board control device 31. If the result of this determination shows that there has been an update inquiry (YES in step S51), then in step S52, the control unit 18 determines whether or not there is an update to be applied (more precisely, a distribution package 103 to be applied) for the vehicle 3 that has sent the update inquiry. For example, the control unit 18 refers to the update history 112 of the vehicle database 102 to determine whether or not there is an update to be applied for the vehicle 3. If the result of this determination shows that there is no update to be applied (NO in step S52), the control unit 18 transmits to the vehicle 3 that there is no update, and then proceeds to step S54, which will be described later. On the other hand, if there is an update to be applied (YES in step S52), in step S53, the control unit 18 transmits a message indicating that there is an update for the vehicle 3 that has sent the update inquiry, and starts update processing according to the state of the vehicle 3 (first state or second state). Here, the state of the vehicle 3 can be determined by the following method. For example, when the control unit 49 of the on-board control device 31 sends the update inquiry, the data it transmits to the center 1 may include information indicating its own state. Then, the control unit 18 of the center 1 may determine the state of the vehicle 3 that has sent the update inquiry based on the information. As a result, if the state of the vehicle 3 is the first state, the control unit 18 determines to perform a wireless update and starts transmitting the OTA data 104 and the common data 106. On the other hand, if the state is the second state, the control unit 18 determines to perform a wired update and starts transmitting the wired update data 105 and the common data 106.

[0065] Next, in step S54, the control unit 18 determines whether or not the above-described switching notification has been received from a predetermined on-board control device 31. If the result of this determination is that the switching notification has been received (YES in step S54), in step S55, the control unit 18 performs processing to switch the update control for the sender of the switching notification between wired update and wireless update. Specifically, first, the control unit 18 stores the progress status of the update processing for the sender of the switching notification in the update progress status 113. Next, the control unit 18 changes the content of the distribution package 103 to be transmitted according to the content of the switching notification. That is, if the content of the switching notification indicates a switch from the first state to the second state, the control unit 18 transmits the wired update data 105 and the common data 106, or switches control so that processing related to the wired update is performed. Conversely, if the content of the switching notification indicates a switch from the second state to the first state, the control unit 18 transmits the OTA data 104 and the common data 106, or switches control so that processing related to the wireless update is performed. Additionally, the control unit 18 performs a process of appropriately switching between control related to wired update and control related to wireless update according to the content of the switching notification. Then, the control unit 18 grasps the progress status before the switching based on the update progress status 113, and executes a process to take over and resume the update process. As a result, the update process for the sender of the switching notification is continued in the state after the switching.

[0066] On the other hand, if the result of the determination in step S54 above is that the switching notification has not been received (NO in step S54), then in step S56, the control unit 18 determines whether or not a notification of update process completion has been received from a predetermined vehicle 3. If a notification of update process completion has been received (YES in step S56), in step S57, the control unit 18 performs a setting indicating that the update process has been completed for the vehicle 3 that sent the notification of update process completion. Specifically, the control unit 18 sets information indicating "update completed" in the update progress status 113. Furthermore, the control unit 18 sets information related to the update process that has just been completed in the update history 112. In addition, the control unit 18 also appropriately executes a process for terminating the update control for the vehicle 3. Thereafter, the process returns to step S51 above, and the process is repeated.

[0067] On the other hand, if the result of the determination in step S56 above is that a notification of completion of the update process has not been received from the specified vehicle 3 (NO in step S56), the process in step S57 above is skipped, and the process returns to step S51 above and is repeated.

[0068] This concludes the description of the center side control process.

[0069] As described above, in this embodiment, even if the state of the vehicle 3 switches between a first state in which wireless update is possible and a second state in which wired update is possible between the start and completion of the update process related to a predetermined distribution package 103, the progress of the update process before the switch can be carried over and the update process can be continued in the state after the switch. If the state is one in which wireless update is possible, the user can download the distribution package 103 from anywhere, even while using the vehicle 3. Furthermore, in the case of a wired update, the download of the distribution package 103 can be performed in a stable communication environment. Therefore, the time until the update process is completed can be shortened while ensuring user convenience.

[0070] [Variations] In the above disclosure, an example has been given of a case in which both the "download distribution package" sequence and the "write update data" sequence are performed in the second state in which a wired update is possible. In other embodiments, control may be performed so that only the "download distribution package" sequence is performed in the second state. That is, in the second state, the maintenance workshop 2 downloads the distribution package 103 from the center 1 and stores this data in the storage unit 47 of the on-board control device 31. The "write update data" sequence may be performed in the first state after the vehicle is released from the maintenance workshop 2. Furthermore, with regard to the "download distribution package," for example, the distribution package may be downloaded to the maintenance work terminal in advance, and the downloaded distribution package 103 may be transferred to the storage unit 47 as background processing while a maintenance work process other than the update process is being performed.

[0071] Furthermore, the system may be configured so that the user can specify whether to update electronic control units 33 designated as target ECUs in a given distribution package 103 via wireless or wired update for each electronic control unit 33. For example, assume that there are three target ECUs: electronic control units A, B, and C. In such a case, if the user wants to ensure that the update process for electronic control unit B is completed more reliably, the user may be allowed to specify that electronic control unit B should be updated via wired update and the other electronic control units should be updated wirelessly. This makes it possible to have a mechanic at the maintenance shop 2 update electronic control unit B, while the other electronic control units can be updated wirelessly, thereby enabling more flexible response to user needs.

[0072] The above describes one embodiment of the disclosed technology, but the present disclosure can be understood as not only a control device, but also a method executed by a computer of the control device, a control program for that method, a computer-readable non-transitory recording medium storing the control program, a vehicle equipped with the control device, etc. [Industrial Applicability]

[0073] The disclosed technology can be used in an update control system that includes a vehicle equipped with a control device, an information processing terminal capable of wired communication with the vehicle, and a center capable of communicating with the control device. [Explanation of symbols]

[0074] 1 Center 2. Repair shop 3 vehicles 11 processors 12 RAM 13 Storage device 14. Communications equipment 31 On-board control device 32 Communication Module 33 Electronic Control Unit 35 Bus 36 Diagnostic connector 41 processors 42 RAM 43 ROM 44 Storage device 45 Microcomputer 46 Communication Equipment

Claims

1. A control device provided in a vehicle, performing a wireless update process for updating a program of an electronic control unit provided in the vehicle based on update data managed by a center received via wireless communication; a control device that, when a wired update process that updates the program of the electronic control unit based on the update data received via wired communication becomes available to be started after the wireless update process has been started but before the wireless update process is completed, terminates the wireless update process and starts the wired update process while continuing the progress of the wireless update process, thereby continuing the process of updating the program of the electronic control unit.

2. The control device according to claim 1 , wherein the update data includes data used in the wireless update process and data used in the wired update process.

3. A control device as described in claim 1, which determines that the wired update process is in a state where it can be started when a specified terminal capable of receiving the update data from the center is connected via a wired connection.

4. 2. The control device according to claim 1, wherein when the wired update process is completed, the control device notifies the center that the update of the program in the electronic control unit has been completed.

5. The control device according to claim 1 , wherein, when the wireless update process is resumed while the wired update process is being executed, the control device resumes the wireless update process while taking over the progress of the wired update process.

6. The control device according to claim 1 , wherein when switching from the wireless update process to the wired update process, a predetermined notification is sent to the center.

7. A vehicle comprising the control device according to claim 1.

8. A method executed by a computer of a control device provided in a vehicle, executing a wireless update process for updating a program of an electronic control unit provided in the vehicle based on update data managed by a center received via wireless communication; a step of determining whether a wired update process for updating the program of the electronic control unit based on the update data received via wired communication can be started after the wireless update process is started and before the wireless update process is completed; When the wired update process can be started, terminating the wireless update process and starting the wired update process while continuing the progress of the wireless update process, thereby continuing the process of updating the program of the electronic control unit.

9. A program to be executed by a computer of a control device provided in a vehicle, executing a wireless update process for updating a program of an electronic control unit provided in the vehicle based on update data managed by a center received via wireless communication; a step of determining whether a wired update process for updating the program of the electronic control unit based on the update data received via wired communication can be started after the wireless update process is started and before the wireless update process is completed; When the wired update process can be started, the program causes the computer to execute the steps of: terminating the wireless update process, taking over the progress of the wireless update process, and starting the wired update process, thereby continuing the process of updating the program of the electronic control unit.

Citation Information

Patent Citations

  • Storage device, communication system, storage method and computer program

    JP2019153159A

  • Electronic controller and session establishing program

    JP2019200789A

  • Program update device, program update system, program update method and program update program

    JP2020004245A

  • Vehicle electronic control system, program update notification control method, and program update notification control program

    JP2020027621A

  • Vehicular sound processing apparatus and vehicular apparatus

    US20130121502A1