Server, program and software update method

The server system in the patent addresses the challenge of obtaining user permissions for ECU updates by determining the update type and displaying license information appropriately, ensuring safe and convenient software updates.

JP7726156B2Active Publication Date: 2025-08-20TOYOTA JIDOSHA KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022136858
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-08-30
Publication Date
2025-08-20
Estimated Expiration
2042-08-30

AI Technical Summary

Technical Problem

Existing systems lack appropriate methods to obtain user permission for software updates in vehicle control units (ECUs) based on the type of function being updated and the user's authority, potentially compromising safety and convenience.

Method used

A server system that determines the type of software update (safety or convenience-related) and transmits license information to either the vehicle or user terminal for authorization, ensuring that updates requiring administrator permission are validated through the vehicle and updates for other functions are authorized through the user's familiar device.

Benefits of technology

Ensures safe and convenient software updates by obtaining appropriate user permissions, preventing updates during vehicle operation, and optimizing the display of license information based on function type and user authority.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007726156000001
    Figure 0007726156000001
  • Figure 0007726156000002
    Figure 0007726156000002
  • Figure 0007726156000003
    Figure 0007726156000003
Patent Text Reader

Abstract

To properly obtain permission to update software for control devices of vehicles.SOLUTION: A server 1 updates the software of an ECU in a vehicle 2 via wireless communication. The server 1 includes a memory 112 in which a program is stored and a processor 111 that executes the program. The processor 111 controls whether to send license information to obtain permission to update the software to a user with manager authority of the vehicle 2 to the vehicle 2 or to a user terminal 3 that can be operated by the user, depending on contents of the software update.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a server, a program, and a software update method. [Background technology]

[0002] Research and development is underway on OTA (Over The Air) technology, which wirelessly updates software (vehicle control programs) stored in a vehicle control device (ECU: Electronic Control Unit). For example, Japanese Patent Application Laid-Open Publication No. 2017-149323 (Patent Document 1) discloses a vehicle control system that can safely update software without impairing user convenience. When a portable device determines that the vehicle's electronic key is located inside the vehicle, it transmits a signal to a server requesting the download of update software. The ECU updates the software by downloading the update software transmitted from the server via the portable device. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-149323 Summary of the Invention [Problem to be solved by the invention]

[0004] When updating software on personal computers, smartphones, and other electrical devices, it is common to require the user's permission. It is also possible to obtain the user's permission in advance for updating ECU software. It is desirable to obtain permission from the user appropriately.

[0005] The present disclosure has been made to solve the above-mentioned problems, and one of the purposes of the present disclosure is to appropriately obtain permission to update software in an ECU. [Means for solving the problem]

[0006] (1) A server according to one aspect of the present disclosure wirelessly updates software in a vehicle control device. The server includes a memory that stores a program and a processor that executes the program. The processor controls whether to transmit license information to the vehicle to obtain permission to update the software from a user with administrator authority over the vehicle, or to transmit the license information to a user terminal that the user can operate, depending on the content of the software update.

[0007] (2) If the software update target is a function related to the vehicle's safety, the processor sends license information to the vehicle, but if the software update target is another function, the processor sends license information to the user terminal.

[0008] (3) The safety-related functions include at least one of the vehicle's driving function, autonomous driving function, security function, and charging function.

[0009] (4) Other features include features related to the convenience and / or comfort of the vehicle. (5) The convenience and / or comfort-related features include at least one of the vehicle's HMI (human-machine interface) features, communication features, air conditioning features, navigation features, and audio-visual features.

[0010] In the above configurations (1) to (5), if the software update target is a function related to vehicle safety, license information is transmitted to the vehicle. This makes it possible to reliably obtain permission from a user with administrator authority. On the other hand, if the software update target is another function, such as a function related to vehicle convenience and / or comfort, license information is transmitted to a user terminal. This makes it possible to improve user convenience. Therefore, according to the above configurations (1) to (5), permission to update the ECU software can be obtained appropriately.

[0011] (6) If the software update target is a function registered by the user, the processor transmits license information to the vehicle.

[0012] According to the above configuration (6), it is possible to fulfill the desire of the user to ensure that he or she gives permission for functions other than those related to the safety of the vehicle.

[0013] (7) There is another user under the supervision of the user, and if the software update target is a function registered to be used by another user, the processor transmits license information to a terminal that can be operated by the other user.

[0014] According to the above configuration (7), for license information relating to a function registered as being primarily used by another user, the license of the other user who will be most affected by the update of the function can be obtained.

[0015] (8) If the amount of software update data is greater than a predetermined amount, the processor transmits license information to the vehicle, whereas if the amount of software update data is less than the predetermined amount, the processor transmits license information to the user terminal.

[0016] Generally, when the amount of update data is small, the software update may be limited to relatively minor functional improvements, whereas when the amount of update data is large, the software update is likely to include major functions. Therefore, in the configuration of (8) above, when the amount of update data is larger than the reference amount, license information is transmitted to the vehicle, thereby ensuring the authorization of the user with administrator authority. On the other hand, when the amount of update data is smaller than the reference amount, license information is transmitted to the user terminal, thereby improving user convenience.

[0017] (9) The license information is configured so that a user's operation to authorize a software update is not accepted while the vehicle is in motion.

[0018] According to the above configuration (9), a user operation to authorize a software update is not accepted while the vehicle is moving. In other words, the user operation is accepted only while the vehicle is stopped. This allows the software update authorization to be obtained under safer conditions.

[0019] (10) According to another aspect of the present disclosure, there is provided a program for causing a computer to execute the program to wirelessly update software in a vehicle control device. When executed by the computer, the program causes the computer to execute a step of transmitting license information for obtaining a license for the software update from a user who has administrator authority for the vehicle. The transmitting step includes a step of controlling whether to transmit the license information to the vehicle or to a user terminal that the user can operate, depending on the content of the software update.

[0020] (11) According to yet another aspect of the present disclosure, a software update method updates software in a vehicle control device via wireless communication. The software update method includes transmitting license information for obtaining permission for the software update from a user who has administrator authority for the vehicle. The transmitting step includes controlling whether to transmit the license information to the vehicle or to a user terminal that the user can operate, depending on the content of the software update.

[0021] According to the program of (10) or the method of (11), similarly to the configuration of (1), it is possible to properly obtain permission to update the software of the ECU. [Effects of the Invention]

[0022] According to the present disclosure, permission to update software in an ECU can be appropriately obtained. [Brief explanation of the drawings]

[0023] [Figure 1] 1 is a diagram illustrating a schematic configuration of an information processing system according to an embodiment of the present disclosure. [Figure 2] FIG. 1 is a block diagram showing a typical configuration example of an OTA center. [Figure 3] 1 is a block diagram showing a typical configuration example of a vehicle; [Figure 4] FIG. 1 is a block diagram showing a typical configuration example of a user terminal. [Figure 5] 10 is a flowchart showing a first embodiment of a processing procedure for obtaining a user's permission for software update. [Figure 6] 10 is a flowchart showing a second embodiment of the processing procedure for obtaining user permission for software update. [Figure 7] 10 is a flowchart showing a third embodiment of the processing procedure for obtaining user permission for software update. [Figure 8] 10 is a flowchart showing a fourth embodiment of the processing procedure for obtaining user permission for software update. [Figure 9] 10 is a flowchart showing a fifth embodiment of the processing procedure for obtaining user permission for software update. [Figure 10] 10 is a flowchart showing a sixth embodiment of the processing procedure for obtaining user permission for software update. DETAILED DESCRIPTION OF THE INVENTION

[0024] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and description thereof will not be repeated.

[0025] [Embodiment Mode] <System configuration> 1 is a diagram illustrating a schematic configuration of an information processing system according to an embodiment of the present disclosure. The information processing system 100 includes an OTA center 1, a vehicle 2, and a user terminal 3. The OTA center 1 is connected to the vehicle 2 and the user terminal 3 via a wired or wireless network NW so that they can communicate with each other.

[0026] The OTA center 1 is a server that provides software for an ECU (see FIG. 3) installed in a vehicle 2. The OTA center 1 is managed, for example, by a vehicle manufacturer that manufactures the vehicle itself (VP: Vehicle Platform). The configuration of the OTA center 1 will be described with reference to FIG. 2.

[0027] Vehicle 2 is managed by a user. In other words, the user has administrative authority over vehicle 2. In this embodiment, an example is assumed in which the user is an individual (or a small number of people). However, the user may also be, for example, a corporation (such as a transportation business operator) that conducts business using vehicle 2. The configuration of vehicle 2 will be described with reference to FIG. 3.

[0028] The user terminal 3 is a terminal that can be operated by the user of the vehicle 2. The user terminal 3 may be a mobile terminal or a fixed terminal. Mobile terminals include, for example, smartphones, tablets, notebook PCs (Personal Computers), and wearable devices (such as smart watches). Fixed terminals include, for example, desktop PCs. The configuration of the user terminal 3 will be described with reference to FIG. 4.

[0029] 1, due to space limitations, only one vehicle 2 is shown, but the number of vehicles 2 is arbitrary. Typically, the information processing system 100 includes a large number of vehicles 2. The same applies to the user terminals 3.

[0030] 2 is a block diagram showing a typical configuration example of the OTA center 1. The OTA center 1 includes a server 11, an input device 12, a display 13, and a communication device 14. The server 11 includes a processor 111, a memory 112, a storage 113, and a network interface 114. The components of the OTA center 1 are connected to each other via a communication bus.

[0031] The storage 113 is a rewritable nonvolatile memory such as a hard disk drive (HDD), a solid state drive (SSD), or a flash memory. The storage 113 stores a system program 51 including an operating system (OS), a control program 52 including computer-readable code necessary for control calculations, an update program 53 for updating the control program of the vehicle 2, and license information 54 (described later) for obtaining a user's license for downloading, installing, etc., of the update program 53. The processor 111 is, for example, a central processing unit (CPU) or a micro-processing unit (MPU). The processor 111 performs various processes by reading the system program 51 and the control program 52, expanding them into the memory 112, and executing them. The network interface 114 controls data communication between the server 11 and other devices (such as the vehicle 2 and the user terminal 3) via the communication device 14.

[0032] The input device 12 is a keyboard, a mouse, etc., and receives input from the operator of the server 11. The display 13 displays various information to the operator of the server 11.

[0033] 2 shows an example in which the server 11 includes one processor 111, the server 11 may include multiple processors. That is, the server 11 includes one or more processors. The same applies to the memory 112 and the storage 113.

[0034] In this specification, the term "processor" is not limited to a processor in the narrow sense that executes processing using a stored program, but may also include hardwired circuits such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). Therefore, the term "processor" can also be interpreted as a processing circuitry whose processing is predefined by computer-readable code and / or hardwired circuitry.

[0035] FIG. 3 is a block diagram showing a typical configuration example of vehicle 2. In this embodiment, vehicle 2 is an autonomous vehicle. Vehicle 2 is also a vehicle that can be charged (plug-in charging or contactless charging) using power supplied from a charging device external to the vehicle. However, vehicle 2 may also be a vehicle that is not compatible with autonomous driving and can only be driven manually. Vehicle 2 may also be a vehicle that is not compatible with plug-in charging or contactless charging.

[0036] The vehicle 2 includes a central ECU 21, multiple discrete ECUs 22, an Advanced Driver-Assistance Systems (ADAS) 23, an ADS 24, a sensor group 25, an input device 26, an in-vehicle display 27, a Data Communication Module (DCM) 28, and a user authentication device 29. The discrete ECUs 22 are ECUs divided by function, such as a brake ECU, a steering ECU, a motor-generator ECU, and a body ECU. The discrete ECUs 22 may be controllers storing software for implementing the functions of the ADAS 23 and / or the ADS 24. The components of the vehicle 2 are connected to one another via a wired in-vehicle network such as a Controller Area Network (CAN) or in-vehicle Ethernet (registered trademark).

[0037] The basic configurations of the central ECU 21 and the individual ECUs 22 are similar to the configuration of the server 11. The storage 223 of the individual ECU 22 stores software (a system program 71 and a control program 72) executed by the processor 221 of the individual ECU 22. The individual ECU 22 controls the system corresponding to the individual ECU 22 in response to signals from the sensor group 25 and the like so that the vehicle 2 is in a desired state. Although none of the systems are shown in the figures, these systems may include a brake system, a steering system, a powertrain system, a body system, and the like.

[0038] The processor 211 of the central ECU 21 controls the update process of the software stored in the storage 223 of the individual ECU 22. The central ECU 21 receives (downloads) the software from the OTA center 1 via the DCM 28, and stores (installs) the downloaded software in the storage 223 of the individual ECU 22 at an appropriate time. Then, the central ECU 21 validates (activates) the installed software at an appropriate time.

[0039] The ADAS 23 includes, for example, an adaptive cruise control (ACC), an auto speed limiter (ASL), a lane keeping assist (LKA), a pre-crash safety (PCS), and a lane departure alert (LDA). The ADS 24 is configured to be able to perform autonomous driving of the vehicle 2.

[0040] The sensor group 25 includes sensors configured to detect the external conditions of the vehicle 2. The sensor group 25 further includes sensors (none of which are shown) configured to detect information according to the traveling state of the vehicle 2, as well as steering operations, accelerator operations, and braking operations. Specifically, the sensor group 25 may include, for example, a camera, radar, a LIDAR (Laser Imaging Detection and Ranging), a vehicle speed sensor, an acceleration sensor, a yaw rate sensor, and a steering sensor (none of which are shown).

[0041] The input device 26 is, for example, a touch panel provided on a multi-information display (MID). The input device 26 may also be a physical switch or button. The in-vehicle display 27 is, for example, an MID. The in-vehicle display 27 may also be an instrument panel that uses display technology such as liquid crystal or organic EL (Electro Luminescence). The DCM 28 is an in-vehicle communication module. The DCM 28 is configured to enable bidirectional data communication between the central ECU 21 and the server 11.

[0042] The user authentication device 29 authenticates whether a person in the vehicle cabin (typically in the driver's seat) is a pre-registered user with administrative authority for the vehicle 2. The user authentication device 29 includes, for example, a camera (not shown) capable of face authentication by image processing. The method of biometric authentication by the user authentication device 29 is not particularly limited, and may be voice authentication, fingerprint authentication, vein authentication, iris authentication, or the like.

[0043] 4 is a block diagram showing a typical configuration example of the user terminal 3. The user terminal 3 includes a processing unit 31, an input device 32, a display 33, and a communication device 34. The input device 32 and the display 33 are integrally configured as, for example, a touch panel display. However, the input device 32 may be a dedicated input device (such as a keyboard or mouse), and the display 33 may be a stationary monitor. The other configuration of the user terminal 3 is the same as that of the server 11 (see FIG. 2).

[0044] <User License> It is desirable to obtain permission from the user prior to updating the software of the individual ECU 22. In this embodiment, information for obtaining the user's permission is presented to the user. Hereinafter, this information will be referred to as "license information." The license information includes, but is not limited to, information regarding the software license agreement. The license information may include information explaining the contents of the software update, or may include information (a so-called manual) explaining how to use the vehicle 2 after the software update.

[0045] While it is conceivable to display the license information on the in-vehicle display 27 or on the user terminal 3 (display 33), in this embodiment, the display destination of the license information is controlled depending on the contents of the software update. More specifically, it is considered that for many users, it is easier to view the license information on the user terminal 3, which they are familiar with. On the other hand, if the software update targets a major function of the vehicle 2, it is important to reliably obtain permission from a user who has administrator authority for the vehicle 2 (in other words, the owner of the vehicle 2), and use of the vehicle 2 is suitable for this purpose. In view of these circumstances, in this embodiment, the display destination of the license information is set depending on the contents of the software update, in other words, the functions to be updated in the software or the amount of update data for the software.

[0046] <Processing flow> Six embodiments (first to sixth embodiments) will be described in detail below with reference to the flowcharts.

[0047] <First Example> 5 is a flowchart showing a first embodiment of a processing procedure for obtaining user permission for a software update. The series of processes shown in this flowchart are executed by the server 11 of the OTA center 1 when new software to be updated is registered in the server 11. The steps in the flowchart are basically realized by software processing, but some or all of them may be realized by hardware processing. Hereinafter, steps are abbreviated as S. This also applies to other flowcharts described later.

[0048] In this embodiment, it is assumed that the software development company (typically a vehicle manufacturer) has registered in advance what functions the newly updated software is related to (what functions it is classified into).

[0049] In S11, the server 11 determines whether the software update target is a function related to the safety of the vehicle 2. The safety-related function includes, for example, at least one of the vehicle 2's driving function, autonomous driving function, security function, and charging function. The driving function includes functions realized by the brake system, steering system, powertrain system (none of which are shown), etc. The autonomous driving function includes functions realized by the ADS24. The security function includes functions realized by the body system (not shown) (such as an alarm function, immobilizer function, keyless function, remote starter function, etc.). The charging function includes functions realized by a charging system (not shown) for plug-in charging or wireless charging.

[0050] If the software update target is a function related to the safety of the vehicle 2 (YES in S11), the server 11 generates license information to be displayed on the in-vehicle display 27 and transmits it to the vehicle 2 (S12). On the other hand, if the software update target is not a function related to the safety of the vehicle 2 (NO in S11), the server 11 generates license information to be displayed on the display 33 of the user terminal 3 and transmits it to the user terminal 3 (S13).

[0051] In this way, license information regarding the main functions related to the safety of the vehicle 2 is transmitted to the vehicle 2. In the vehicle 2, a user with administrator authority for the vehicle 2 (the owner of the vehicle 2, so to speak) can be authenticated using the user authentication device 29. This allows the functions related to the safety of the vehicle 2 to be updated with the permission of the user with administrator authority. Meanwhile, license information regarding other functions (in other words, functions additional to the running, autonomous driving, security, etc. of the vehicle 2) is transmitted to the user terminal 3. This allows the user to view the license information using the user terminal 3 that the user is familiar with, thereby improving user convenience.

[0052] Regardless of whether the license information is sent to the vehicle 2 or the user terminal 3, it is preferable not to accept a user operation to authorize a software update while the vehicle 2 is traveling. As an example, while the vehicle 2 is traveling (including when the vehicle 2 is in a state where it can be driven, such as when ReadyON), the authorization button displayed on the in-vehicle display 27 or the display 33 may be grayed out, and the authorization button may only be pressed while the vehicle 2 is stopped (when ReadyOFF, parked, etc.). This allows the software update authorization to be obtained under safer conditions.

[0053] <Second Example> The functions for which license information is set to be transmitted to the vehicle 2 are not limited to functions related to the safety of the vehicle 2, and may include functions that are registered (selected) in advance by the user.

[0054] 6 is a flowchart showing a second embodiment of the processing procedure for obtaining user permission for a software update. As in the example shown in FIG. 5, in S21, the server 11 determines whether the software update target is a function related to the safety of the vehicle 2. If the software update target is a function related to the safety of the vehicle 2 (YES in S21), the server 11 generates license information to be displayed on the in-vehicle display 27 and transmits it to the vehicle 2 (S23).

[0055] If the software update target is not a function related to the safety of the vehicle 2 (NO in S21), the server 11 proceeds to the process in S22 and determines whether the software update target is a pre-registered function. If the software update target is a function pre-registered by the user (YES in S22), the server 11 generates license information to be displayed on the in-vehicle display 27 and transmits it to the vehicle 2 (S23). On the other hand, if the software update target is not a pre-registered function (NO in S22), the server 11 generates license information to be displayed on the display 33 of the user terminal 3 and transmits it to the user terminal 3 (S24).

[0056] There may be users who want to ensure that they grant permission for functions other than those related to the safety of the vehicle 2. Such users can pre-register functions that require their permission. Therefore, not only license information for functions related to the safety of the vehicle 2, but also license information for functions pre-registered by the user may be transmitted to the vehicle 2. This allows the software update process to proceed with functions other than those related to the safety of the vehicle 2 after obtaining permission from a user with administrator authority.

[0057] <Third Example> In the first and second embodiments, it has been explained that the license information is in principle transmitted to the user terminal 3. However, the default transmission destination of the license information may be the vehicle 2.

[0058] FIG. 7 is a flowchart showing a third embodiment of a processing procedure for obtaining user consent for a software update. In S31, the server 11 determines whether the software update target is a function related to the convenience and / or comfort of the vehicle 2. The function related to the convenience and / or comfort includes, for example, at least one of an HMI (Human Machine Interface) function, a communication function, an air conditioning function, a navigation function, and an audio-visual (AV) function of the vehicle 2. The HMI function is realized by the input device 26 and the in-vehicle display 27. The communication function is a so-called connected function (a function related to communication between the vehicle 2 and the OTA center 1 or between the vehicle 2 and another vehicle) and is realized by the DCM 28. The air conditioning function is realized by an air conditioning system (such as a heat pump air conditioner or an electric heater) not shown. The navigation function is realized by a navigation system not shown. The audio-visual function is realized by an in-vehicle audio system (not shown).

[0059] If the software update target is a function related to the convenience and / or comfort of the vehicle 2 (YES in S31), the server 11 generates license information to be displayed on the display 33 of the user terminal 3 and transmits it to the user terminal 3 (S33). On the other hand, if the software update target is not a function related to the convenience and / or comfort of the vehicle 2 (NO in S31), the server 11 generates license information to be displayed on the in-vehicle display 27 and transmits it to the vehicle 2 (S32).

[0060] In this way, license information for functions related to the convenience and / or comfort of the vehicle 2 is transmitted to the vehicle 2. This allows the user to view the license information using the user terminal 3 that the user is familiar with, thereby improving user convenience. On the other hand, license information for other functions is transmitted to the vehicle 2. This allows functions other than those related to convenience and / or comfort to be updated with the permission of a user with administrator authority.

[0061] <Fourth Example> The first and third embodiments may be combined.

[0062] 8 is a flowchart showing a fourth embodiment of the processing procedure for obtaining user permission for a software update. In S41, the server 11 determines whether the software update target is a function related to the safety of the vehicle 2. If the software update target is a function related to the safety of the vehicle 2 (YES in S41), the server 11 generates license information to be displayed on the in-vehicle display 27 and transmits it to the vehicle 2 (S43).

[0063] If the software update target is not a function related to the safety of the vehicle 2 (NO in S41), the server 11 proceeds to S42 and determines whether the software update target is a function related to the convenience and / or comfort of the vehicle 2. If the software update target is a function related to the convenience and / or comfort of the vehicle 2 (YES in S42), the server 11 generates license information to be displayed on the display 33 of the user terminal 3 and transmits it to the user terminal 3 (S44).

[0064] If the software update target is not a function related to the convenience and / or comfort of the vehicle 2 (NO in S42), the server 11 transmits the license information to a device desired by the user that has been registered in advance (S45). That is, if the user has registered the vehicle 2, the server 11 transmits the license information to the vehicle 2, and if the user has registered the user terminal 3, the server 11 transmits the license information to the user terminal 3.

[0065] As described above, according to the fourth embodiment, similarly to the first and third embodiments, license information for functions related to the safety of the vehicle 2 is transmitted to the vehicle 2. This makes it possible to reliably obtain the license of a user with administrator authority. On the other hand, license information for functions related to the convenience and / or comfort of the vehicle 2 is transmitted to the user terminal 3. This makes it possible to improve user convenience. Furthermore, license information for functions that do not fall into any of the above categories is transmitted to a device registered in advance. This allows the user to select whether to prioritize the reliability of the license or the improvement of convenience.

[0066] Fifth Example The vehicle 2 can be used not only by a user with administrator authority (e.g., a parent), but also by a standard user (e.g., a child) who is supervised by the user and does not have administrator authority. Some software is primarily used by the standard user. Permission from the standard user may be obtained for updates to such software. The standard user corresponds to the "other user" in this disclosure.

[0067] 9 is a flowchart showing a fifth embodiment of the processing procedure for obtaining user permission for a software update. In S51, the server 11 determines whether the software update target is a function related to the safety of the vehicle 2. If the software update target is a function related to the safety of the vehicle 2 (YES in S51), the server 11 generates license information to be displayed on the in-vehicle display 27 and transmits it to the vehicle 2 (S53). As a result, the permission of a user with administrator authority is obtained.

[0068] If the software update target is not a function related to the safety of the vehicle 2 (NO in S51), the server 11 proceeds to S52 and determines whether the software update target is a function that has been pre-registered as being used by a standard user. If the software update target is a function for a standard user (YES in S52), the server 11 generates license information to be displayed on a terminal (not shown) used by the standard user and transmits it to the terminal (S55). As a result, the license of the standard user without administrator authority is obtained.

[0069] On the other hand, if the software update target is not a function for a standard user (NO in S52), the server 11 generates license information to be displayed on the user terminal 3 of the user with administrator authority and transmits it to the user terminal 3 (S54). As a result, the license of the user with administrator authority is obtained.

[0070] As described above, according to the fifth embodiment, license information for functions related to the safety of the vehicle 2 is transmitted to the vehicle 2. This makes it possible to reliably obtain the license of a user with administrator authority. License information for functions that have been pre-registered as being primarily used by standard users is transmitted to the standard user's terminal. This makes it possible to obtain the license of the standard user who will be most affected by the update of the function. Furthermore, license information for functions that do not fall into any of the above categories is transmitted to the user terminal 3. This improves convenience for users with administrator authority.

[0071] Sixth Example In the first to fifth embodiments, examples have been described in which the destination of the license information is determined depending on the function to be updated in the software. In the fifth embodiment, an example will be described in which the destination of the license information is determined depending on the amount of update data for the software.

[0072] 10 is a flowchart showing a sixth embodiment of the processing procedure for obtaining user permission for a software update. In S61, the server 11 determines whether the amount of software update data (the data size of the software transmitted from the server 11 to the vehicle 2) is a predetermined reference amount. If the amount of update data is greater than the reference amount (YES in S61), the server 11 generates license information for display on the in-vehicle display 27 and transmits it to the vehicle 2 (S62). On the other hand, if the amount of update data is equal to or less than the reference amount (NO in S61), the server 11 generates license information for display on the display 33 of the user terminal 3 and transmits it to the user terminal 3 (S63).

[0073] Generally, when the amount of update data is large (such as a so-called major update), it is highly likely that the software update will include major functions. In contrast, when the amount of update data is small (such as the periodic distribution of security patches), the software update may only include relatively minor functional improvements. Therefore, when the amount of update data is larger than the standard amount, license information can be sent to the vehicle 2, ensuring that the software is updated only after obtaining permission from a user with administrator authority. On the other hand, when the amount of update data is smaller than the standard amount, license information can be sent to a user terminal 3 that the user is familiar with, thereby improving user convenience.

[0074] As described above, in this embodiment, if the software update target is a function related to the safety of the vehicle 2, or if the amount of update data is greater than the reference amount, license information is transmitted to the vehicle 2. This makes it possible to reliably obtain the permission of the user (owner) who has administrator authority for the vehicle 2. On the other hand, if the software update target is a function related to the convenience and / or comfort of the vehicle 2, or if the amount of update data is equal to or less than the reference amount, license information is transmitted to the user terminal 3. This allows the user to view the license information using the user terminal 3 that the user is familiar with, thereby improving user convenience.

[0075] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]

[0076] 1 OTA center, 11 server, 111 processor, 112 memory, 113 storage, 114 network interface, 12 input device, 13 display, 14 communication device, 2 vehicle, 21 central ECU, 22 individual ECU, 211, 221 processor, 212, 222 memory, 213, 223 storage, 214, 224 network interface, 23 ADAS, 24 ADS, 25 sensor group, 26 input device, 27 in-vehicle display, 28 DMC, 29 user authentication device, 3 user terminal, 31 processing unit, 311 processor, 312 memory, 313 storage, 314 network interface, 32 input device, 33 display, 34 communication device, 51, 61, 71 system program, 52, 62, 72 control program, 53 update program, 54 license information, 100 information processing system.

Claims

1. A server that updates software of a vehicle control device via wireless communication, A memory in which a program is stored; a processor that executes the program, The processor: controlling whether to transmit license information for obtaining permission to update the software from a user having administrator authority for the vehicle to the vehicle or to transmit the license information to a user terminal operable by the user, depending on the content of the software update; If the software update target is a function related to the safety of the vehicle, transmitting the license information to the vehicle; If the software update target is another function, the server transmits the license information to the user terminal.

2. The server according to claim 1 , wherein the safety-related function includes at least one of a driving function, an autonomous driving function, a security function, and a charging function of the vehicle.

3. The server of claim 1 , wherein the other functions include functions related to the vehicle's convenience and / or comfort.

4. 4. The server according to claim 3, wherein the functions related to convenience and / or comfort include at least one of an HMI (human-machine interface) function, a communication function, an air conditioning function, a navigation function, and an audio-visual function of the vehicle.

5. 5. The server according to claim 1, wherein the processor transmits the license information to the vehicle when the software update target is a function registered by the user.

6. There are other users who are under the supervision of the user; A server described in any one of claims 1 to 4, wherein the processor transmits the license information to a terminal that can be operated by the other user if the software update target is a function that is registered to be used by the other user.

7. The server according to claim 1 , wherein the license information is configured so as not to accept an operation by the user to permit the software update while the vehicle is running.

8. A server that updates software of a vehicle control device via wireless communication, A memory in which a program is stored; a processor that executes the program, The processor: controlling whether to transmit license information for obtaining permission to update the software from a user having administrator authority for the vehicle to the vehicle or to transmit the license information to a user terminal operable by the user, depending on the content of the software update; a server that determines a destination of the license information depending on whether the software update target is a function registered by the user.

9. A server that updates software of a vehicle control device via wireless communication, A memory in which a program is stored; a processor that executes the program, The processor: controlling whether to transmit license information for obtaining permission to update the software from a user having administrator authority for the vehicle to the vehicle or to transmit the license information to a user terminal operable by the user, depending on the content of the software update; If the amount of software update data is greater than a predetermined amount, the license information is transmitted to the vehicle; If the amount of update data is smaller than the predetermined amount, the server transmits the license information to the user terminal.

10. A program executed by a computer to update software of a vehicle control device via wireless communication, causing the computer to execute, when the execution is executed by the computer, a step of transmitting license information for obtaining a license for updating the software from a user having administrator authority for the vehicle; the transmitting step includes a step of controlling whether the license information is transmitted to the vehicle or to a user terminal operable by the user, depending on the update content of the software; The control step includes a step of sending the license information to the vehicle if the software update target is a function related to the safety of the vehicle, and sending the license information to the user terminal if the software update target is another function.

11. A program executed by a computer to update software of a vehicle control device via wireless communication, comprising: causing the computer to execute, when the execution is executed by the computer, a step of transmitting license information for obtaining a license for updating the software from a user having administrator authority for the vehicle; the transmitting step includes a step of controlling whether the license information is transmitted to the vehicle or to a user terminal operable by the user, depending on the update content of the software; The control step includes a step of determining a destination of the license information depending on whether the software update target is a function registered by the user.

12. A program executed by a computer to update software of a vehicle control device via wireless communication, comprising: causing the computer to execute, when the execution is executed by the computer, a step of transmitting license information for obtaining a license for updating the software from a user having administrator authority for the vehicle; the transmitting step includes a step of controlling whether the license information is transmitted to the vehicle or to a user terminal operable by the user, depending on the update content of the software; The control step includes a step of transmitting the license information to the vehicle when the amount of update data for the software is greater than a predetermined amount, and transmitting the license information to the user terminal when the amount of update data is smaller than the predetermined amount.

13. A software update method for updating software of a vehicle control device via wireless communication with a computer, comprising: transmitting, from the computer, license information for obtaining a license for updating the software from a user having administrative authority for the vehicle; the transmitting step includes a step of controlling, by the computer, whether to transmit the license information to the vehicle or to a user terminal operable by the user, depending on the update content of the software; A software update method, wherein the controlling step includes a step of sending the license information to the vehicle if the software update target is a function related to the safety of the vehicle, and sending the license information to the user terminal if the software update target is another function.

14. A software update method for updating software of a vehicle control device via wireless communication with a computer, comprising: transmitting, from the computer, license information for obtaining a license for updating the software from a user having administrative authority for the vehicle; the transmitting step includes a step of controlling, by the computer, whether to transmit the license information to the vehicle or to a user terminal operable by the user, depending on the update content of the software; A software update method, wherein the controlling step includes a step of sending the license information to the vehicle when the amount of update data for the software is greater than a predetermined amount, and sending the license information to the user terminal when the amount of update data is smaller than the predetermined amount.

15. A software update method for updating software of a vehicle control device via wireless communication with a computer, comprising: transmitting, from the computer, license information for obtaining a license for updating the software from a user having administrative authority for the vehicle; the transmitting step includes a step of controlling, by the computer, whether to transmit the license information to the vehicle or to a user terminal operable by the user, depending on the update content of the software; A software update method, wherein the controlling step includes a step of sending the license information to the vehicle when the amount of update data for the software is greater than a predetermined amount, and sending the license information to the user terminal when the amount of update data is smaller than the predetermined amount.

Citation Information

Patent Citations

  • Vehicle control system

    JP2017149323A

  • Update supporting system, update support program, and update support method

    JP2018206051A

  • Program update system and vehicle management server

    JP2021077319A