Software update system, work machine and software update method
The software update system reliably updates multiple components of work machines to maintain interlocked functions by storing and updating software offline, addressing network disconnection issues.
Patent Information
- Application Number
- JP2021141277
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-08-31
- Publication Date
- 2025-08-27
- Estimated Expiration
- 2041-08-31
AI Technical Summary
Work machines may become unable to perform functions that rely on interlocking of multiple components due to network disconnection during software updates, leaving some components updated and others untouched.
A software update system that includes a receiving unit, memory unit, and update unit to store and update multiple components independently, ensuring all components are updated before network reconnection.
Ensures reliable function realization by updating all components together, preventing disruption of interlocked functions during network disconnection.
Smart Images

Figure 0007730277000001 
Figure 0007730277000002 
Figure 0007730277000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a software update system, a work machine, and a software update method. [Background technology]
[0002] A work machine is equipped with components for controlling the work machine or monitoring its status. The components are configured using microcomputers or the like, and perform their functions by executing software. For this reason, the software for the components is sometimes updated to expand the component's functionality, etc. Patent Document 1 discloses a technique for updating software for components of a work machine. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-41114 Summary of the Invention [Problem to be solved by the invention]
[0004] Incidentally, some functions implemented in work machines are realized by the interlocking of multiple components. To realize such functions in a work machine, it is necessary to update the software for each of the multiple components.
[0005] Incidentally, software to be installed on a work machine is received via a network. However, a work machine is not necessarily in an environment where it can always connect to a network, and may not be able to connect to the network for several days. Therefore, when updating multiple components using the procedure described in Patent Document 1, there is a possibility that the work machine will be disconnected from the network with some of the multiple components updated and the rest left untouched. In this case, the work machine will be unable to perform functions that are realized by the interlocking of multiple components until it is able to connect to the network again and the remaining components are updated.
[0006] An object of the present disclosure is to provide a software update system, a work machine, and a software update method that can increase the reliability of updating multiple components in order to realize functions that are achieved by multiple components working together. [Means for solving the problem]
[0007] According to one aspect of the present disclosure, a software update system is a software update system that updates a plurality of components provided on a work machine, and includes a receiving unit that receives data from a server, the data including first software used to update a first component that is one of the plurality of components, and second software used to update a second component that is one of the plurality of components and that is for realizing functions related to the first software; a memory unit that stores the received first software and second software; and an update unit that updates the first component and the second component based on the first software and the second software after the first software and the second software have been stored in the memory unit. [Effects of the Invention]
[0008] According to the above aspect, the software update system can increase the reliability of updating multiple components, since it realizes a function that is realized by multiple components working together. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a configuration diagram of a software update system according to a first embodiment. [Figure 2] 1 is a perspective view showing the appearance of a work machine according to a first embodiment. [Figure 3] 2 is a diagram showing the imaging ranges of a plurality of cameras provided on the work machine according to the first embodiment. FIG. [Figure 4] FIG. 2 is a diagram showing the internal configuration of a driver's cab according to the first embodiment. [Figure 5] 1 is a schematic block diagram showing the hardware configuration of a control system of a work machine according to a first embodiment. [Figure 6] FIG. 2 is a block diagram showing a configuration of a gateway function controller according to the first embodiment. [Figure 7] FIG. 2 is a block diagram showing a configuration of a component management server according to the first embodiment. [Figure 8] FIG. 2 is a block diagram showing the configuration of a software management server according to the first embodiment. [Figure 9] FIG. 4 is a diagram illustrating an example of a software table according to the first embodiment. [Figure 10] FIG. 2 is a sequence diagram showing a method for updating software of a component in the software update system according to the first embodiment. [Figure 11] 10 is a flowchart showing a part number confirmation process of the gateway function controller according to the first embodiment. [Figure 12] 10 is a flowchart showing a standalone software update process performed by a gateway function controller according to the first embodiment. [Figure 13] 10 is a flowchart showing a plurality of software update processes performed by a gateway function controller according to the first embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] First Embodiment FIG. 1 is a configuration diagram of a software update system 1 according to the first embodiment. The software update system 1 manages the software product numbers of components 200 equipped on multiple work machines 100. The software update system 1 includes multiple work machines 100, a component management server 300, a software management server 500, and a developer terminal 700. Software is data used to realize the functions of hardware. Software may include programs and setting data. Note that the software product number is a unique identifier used to identify the software. The software product number is expressed, for example, by a combination of multiple numbers or letters.
[0011] Each work machine 100 includes a gateway function controller 201 and two or more components 200. The gateway function controller 201 is also an example of a component 200. The gateway function controller 201 is connected to the internal network of the work machine 100 and an external network. The internal network is a network that connects the components 200 inside the work machine 100 with each other. The external network is a wide area network (WAN) that connects the work machine 100 with devices external to the work machine. Each component 200 performs a function for controlling the work machine 100 or monitoring the status of the work machine 100. Each component 200 and the gateway function controller 201 are connected to each other via the internal network of the work machine 100. This allows some components 200 to receive calculation results from other components 200 via the internal network and perform further calculations. In FIG. 1 , a hydraulic excavator is shown as the work machine 100, but other work machines, such as a bulldozer, a dump truck, or a wheel loader, may also be used.
[0012] The component management server 300 stores the part numbers of the hardware and software of the components 200 equipped in multiple work machines 100, and provides the work machines 100 with data for updating the software of the components 200. Specifically, the component management server 300 provides the work machines 100 with package data including difference data between the software before and after the update of the components 200 via an external network. Note that when multiple components 200 need to be updated to achieve a predetermined function, the component management server 300 includes multiple pieces of difference data used to update the multiple components 200 in one piece of package data.
[0013] The software management server 500 associates with the hardware product number of the component 200 and stores multiple pieces of software with different product numbers that can be applied to the component 200 related to the product number. The software management server 500 also generates difference data for software updates and transmits it to the component management server 300. The hardware product number is a unique identifier for identifying the component 200. The hardware product number is expressed, for example, by a combination of multiple numbers or letters.
[0014] The developer terminal 700 is a terminal operated by a software developer. The developer uses the developer terminal 700 to develop software and transmits the developed software from the developer terminal 700 to the software management server 500. When the developer creates software for multiple components 200 that work together to achieve a predetermined function, the developer associates product number information indicating the product numbers of each component to which the software can be applied with data for the multiple pieces of software and transmits the associated information to the software management server 500.
[0015] <Configuration of work machine 100> FIG. 2 is a perspective view showing the appearance of the work machine 100. As shown in FIG. The work machine 100 is a work machine and includes a hydraulically operated work implement 130, a revolving body 120 that supports the work implement 130, and a running body 110 that supports the revolving body 120.
[0016] The running body 110 supports the work machine 100 so that it can travel. The running body 110 includes two endless tracks 111 provided on the left and right, and two travel motors 112 for driving the endless tracks 111, respectively. The rotating body 120 is supported by the running body 110 so as to be able to rotate around a rotation center. The work implement 130 is hydraulically driven. The work implement 130 is supported on the front part of the rotating body 120 so that it can be driven in the vertical direction. The operator's cab 140 is a space where an operator sits and operates the work machine 100. The operator's cab 140 is provided on the left front part of the rotating body 120. Here, the portion of the revolving unit 120 to which the work implement 130 is attached is referred to as the front portion. Furthermore, with respect to the revolving unit 120, the portion opposite the front portion is referred to as the rear portion, the left portion as the left portion, and the right portion as the right portion.
[0017] <Configuration of rotating body 120> The swing body 120 includes an engine 121 , a hydraulic pump 122 , a control valve 123 , a swing motor 124 , and a fuel injection device 125 . The engine 121 is a prime mover that drives the hydraulic pump 122 . The hydraulic pump 122 is a variable displacement pump driven by the engine 121. The hydraulic pump 122 supplies hydraulic oil via a control valve 123 to each actuator (a boom cylinder 131C, an arm cylinder 132C, a bucket cylinder 133C, a traveling motor 112, and a swing motor 124). The control valve 123 controls the flow rate of the hydraulic oil supplied from the hydraulic pump 122 . The swing motor 124 is driven by hydraulic oil supplied from a hydraulic pump 122 via a control valve 123 to swing the swing body 120 . The fuel injector 125 injects fuel into the engine 121 .
[0018] The revolving unit 120 is provided with a plurality of cameras 206 that capture images of the surroundings of the work machine 100. Figure 3 is a diagram showing the imaging ranges of the plurality of cameras 206 provided on the work machine 100 according to the first embodiment. Specifically, the revolving unit 120 is provided with a left rear camera 206A that images a left rear range Ra of the periphery of the revolving unit 120, a rear camera 206B that images a rear range Rb of the periphery of the revolving unit 120, a right rear camera 206C that images a right rear range Rc of the periphery of the revolving unit 120, and a right front camera 206D that images a right front range Rd of the periphery of the revolving unit 120. Note that the imaging ranges of the multiple cameras 206 may partially overlap each other. The imaging ranges of the multiple cameras 206 cover the entire circumference of the work machine 100 excluding the left front range Re that is visible from the cab 140. Note that, although the cameras 206 according to the first embodiment capture images of the left rear, rear, right rear, and right front of the revolving unit 120, other embodiments are not limited to this. For example, the number and imaging ranges of the cameras 206 according to other embodiments may differ from the examples shown in FIGS. 2 and 3.
[0019] <Configuration of work machine 130> As shown in FIG. 2, the work machine 130 includes a boom 131, an arm 132, a bucket 133, a boom cylinder 131C, an arm cylinder 132C, and a bucket cylinder 133C.
[0020] The base end of the boom 131 is attached to the rotating body 120 via a boom pin. The arm 132 connects the boom 131 and the bucket 133. The base end of the arm 132 is attached to the tip of the boom 131 via an arm pin. The bucket 133 includes a blade for digging up earth and sand and a storage section for storing the excavated earth and sand. The base end of the bucket 133 is attached to the tip of the arm 132 via a bucket pin.
[0021] The boom cylinder 131C is a hydraulic cylinder for operating the boom 131. A base end of the boom cylinder 131C is attached to the revolving body 120. A tip end of the boom cylinder 131C is attached to the boom 131. The arm cylinder 132C is a hydraulic cylinder for driving the arm 132. A base end of the arm cylinder 132C is attached to the boom 131. A tip end of the arm cylinder 132C is attached to the arm 132. The bucket cylinder 133C is a hydraulic cylinder for driving the bucket 133. A base end of the bucket cylinder 133C is attached to the arm 132. A tip end of the bucket cylinder 133C is attached to a link member connected to the bucket 133.
[0022] <Configuration of the driver's cab 140> FIG. 4 is a diagram showing the internal configuration of the operator's cab 140 according to the first embodiment. In the cab 140, a driver's seat 142, an operating device 143, and a monitor component 202 are provided.
[0023] The operation device 143 is a device for driving the traveling body 110, the revolving body 120, and the work machine 130 through manual operation by an operator. The operation device 143 includes a left operation lever 143LO, a right operation lever 143RO, a left foot pedal 143LF, a right foot pedal 143RF, a left travel lever 143LT, and a right travel lever 143RT.
[0024] The left operating lever 143LO is provided on the left side of the driver's seat 142. The right operating lever 143RO is provided on the right side of the driver's seat 142.
[0025] The left operation lever 143LO is an operation mechanism for performing the swing operation of the swing unit 120 and the excavation / dumping operation of the arm 132. Specifically, when the operator of the work machine 100 tilts the left operation lever 143LO forward, the arm 132 performs the dumping operation. When the operator of the work machine 100 tilts the left operation lever 143LO rearward, the arm 132 performs the excavation operation. When the operator of the work machine 100 tilts the left operation lever 143LO to the right, the swing unit 120 swings to the right. When the operator of the work machine 100 tilts the left operation lever 143LO to the left, the swing unit 120 swings to the left. Note that in other embodiments, when the left operation lever 143LO is tilted forward or backward, the swing unit 120 may swing to the right or left, and when the left operation lever 143LO is tilted left or right, the arm 132 may perform the excavation or dumping operation.
[0026] The right operating lever 143RO is an operating mechanism for performing an excavation / dumping operation of the bucket 133 and a raising / lowering operation of the boom 131. Specifically, when the operator of the work machine 100 tilts the right operating lever 143RO forward, a lowering operation of the boom 131 is performed. Conversely, when the operator of the work machine 100 tilts the right operating lever 143RO rearward, a raising operation of the boom 131 is performed. Conversely, when the operator of the work machine 100 tilts the right operating lever 143RO to the right, a dumping operation of the bucket 133 is performed. Conversely, when the operator of the work machine 100 tilts the right operating lever 143RO to the left, an excavation operation of the bucket 133 is performed. Note that in other embodiments, when the right operating lever 143RO is tilted in the forward / backward direction, the bucket 133 may perform a dumping operation or an excavation operation, and when the right operating lever 143RO is tilted in the left / right direction, the boom 131 may perform a raising or lowering operation.
[0027] The left foot pedal 143LF is located on the left side of the floor in front of the driver's seat 142. The right foot pedal 143RF is located on the right side of the floor in front of the driver's seat 142. The left travel lever 143LT is pivotally supported by the left foot pedal 143LF, and is configured so that tilting the left travel lever 143LT and pressing down the left foot pedal 143LF are linked. The right travel lever 143RT is pivotally supported by the right foot pedal 143RF, and is configured so that tilting the right travel lever 143RT and pressing down the right foot pedal 143RF are linked.
[0028] The left foot pedal 143LF and left travel lever 143LT correspond to the rotational drive of the left crawler belt of the traveling body 110. Specifically, when the operator of the work machine 100 pushes the left foot pedal 143LF or the left travel lever 143LT forward, the left crawler belt rotates in the forward direction. Conversely, when the operator of the work machine 100 pushes the left foot pedal 143LF or the left travel lever 143LT backward, the left crawler belt rotates in the reverse direction.
[0029] The right foot pedal 143RF and the right traveling lever 143RT correspond to the rotational drive of the right crawler belt of the traveling body 110. Specifically, when the operator of the work machine 100 pushes the right foot pedal 143RF or the right traveling lever 143RT forward, the right crawler belt rotates in the forward direction. Conversely, when the operator of the work machine 100 pushes the right foot pedal 143RF or the right traveling lever 143RT backward, the right crawler belt rotates in the reverse direction.
[0030] <Control system configuration> FIG. 5 is a schematic block diagram showing the hardware configuration of the control system of the work machine 100 according to the first embodiment. The work machine 100 includes a gateway function controller 201, a monitor component 202, a control controller 203, an engine controller 204, and a periphery monitoring component 205. The gateway function controller 201, the monitor component 202, the control controller 203, the engine controller 204, the periphery monitoring component 205, and the camera 206 are connected to one another via an in-vehicle network. Specifically, the gateway function controller 201, the monitor component 202, the control controller 203, and the engine controller 204 are connected via a first network N1 such as a Controller Area Network (CAN), and the gateway function controller 201, the camera 206, and the periphery monitoring component 205 are connected via a second network N2 such as Ethernet (registered trademark).
[0031] The gateway function controller 201 , the monitor component 202 , the control controller 203 , the engine controller 204 , the periphery monitoring component 205 and the camera 206 are all examples of components 200 provided in the work machine 100 .
[0032] The gateway function controller 201 converts the communication protocols of the first network N1 and the second network N2 into each other's, and relays communication between the component 200 connected to the first network N1 and the component 200 connected to the second network N2. The monitor component 202 is provided in the cab 140 and controls the display. The control controller 203 acquires various data related to the hydraulic equipment that controls the operation of the work implement 130 using sensors (not shown), and outputs control signals for controlling the hydraulic equipment in accordance with the operation of the operation device 143. In other words, the control controller 203 controls the drive of the boom cylinder 131C, arm cylinder 132C, bucket cylinder 133C, travel motor 112, swing motor 124, etc. The engine controller 204 acquires various data related to the engine 121 using sensors (not shown) and controls the engine 121 by instructing the fuel injection device 125 on the amount of fuel injection. The periphery monitoring component 205 generates an overhead image based on an image captured by the camera 206, and causes the monitor component 202 to display the overhead image.
[0033] <Configuration of gateway function controller 201> FIG. 6 is a block diagram showing the configuration of the gateway function controller 201 according to the first embodiment. The gateway function controller 201 comprises a first board 210 and a second board 220 which are physically separated.
[0034] The first board 210 includes a first processor 211, a first main memory 213, a first storage 215, and a first interface 217. The first processor 211 retrieves a program from the first storage 215, loads it into the first main memory 213, and executes a predetermined process according to the program. The first storage 215 stores two copies of the same software, including the program, as main software and backup software. The main software is software used to perform its functions under normal circumstances. The backup software is software used to restore the main software when an abnormality occurs in the main software. In other words, the first board 210 executes its functions by executing the main software. Furthermore, if an abnormality occurs due to, for example, a software update error and the main software cannot be executed, the first board 210 restores the main software by copying the backup software to the main software and executes the restored main software. The first board 210 is an example of a component 200. The first interface 217 is connected to a plurality of components 200 for controlling the work machine 100 via a first network N1, which is an internal network. Examples of the components 200 connected to the first board 210 include a monitor component 202, a control controller 203, and an engine controller 204. Basic operational control regarding the operation of the work machine 100 is performed by the components 200 connected to the first network N1.
[0035] The second board 220 includes a second processor 221, a second main memory 223, a second storage 225, and a second interface 227. The second processor 221 retrieves a program from the second storage 225, loads it into the second main memory 223, and executes predetermined processing in accordance with the program. The second interface 227 is connected to a plurality of components 200 for expanding the functions of the work machine 100 via a second network N2, which is an internal network. Examples of the components 200 connected to the second board 220 include a periphery monitoring component 205 and a camera 206, a machine guidance component that displays and controls a guidance monitor to provide guidance to the operator on the positional relationship between the design surface of the construction site and the work machine 100, a payload component that measures the volume of soil excavated by the work implement 130, and a communication component that controls communication equipment for communicating with external servers and the like and acquires data from various sensors of the work machine. The components 200 connected to the second network N2 provide the work machine 100 and the operator with expanded information, such as information to improve the functions of the work machine. Second board 220 may be an example of a component of a work machine.
[0036] The first interface 217 and the second interface 227 are connected to each other so that they can communicate with each other. Furthermore, the first board 210 and the second board 220 store connection information that indicates the route to each component 200 included in the work machine 100. The connection information may be, for example, a routing table. The connection information is updated by the exchange of information between the first board 210 and the second board 220 every time a component 200 is attached to or removed from the work machine 100.
[0037] In other embodiments, the first substrate 210 or the second substrate 220 may include a custom LSI (Large Scale Integrated Circuit) such as a PLD (Programmable Logic Device) in addition to or instead of the above configuration. Examples of PLDs include PAL (Programmable Array Logic), GAL (Generic Array Logic), CPLD (Complex Programmable Logic Device), and FPGA (Field Programmable Gate Array). In this case, some or all of the functions realized by the first substrate 210 or the second substrate 220 may be realized by the integrated circuit.
[0038] Examples of the first storage 215 and the second storage 225 include a magnetic disk, a magneto-optical disk, an optical disk, a semiconductor memory, etc. The first storage 215 and the second storage 225 may be internal media directly connected to a bus line, or may be external media connected to the gateway function controller 201 via the first interface 217 or a communication line. In at least one embodiment, the first storage 215 and the second storage 225 are non-transitory tangible storage media. The computational resources of the second substrate 220 are greater than the computational resources of at least one component 200. Preferably, the computational resources of the second substrate 220 are greater than the computational resources of the first substrate 210. Computational resources are resources used in calculations in a computer. Computational resources are resources that provide computation time or storage capacity of a computer. Examples of computational resources include a CPU, main memory, and storage. Preferably, the capacity of the second main memory 223 is greater than the capacity of the first main memory 213. Preferably, the capacity of the second storage 225 is greater than the capacity of the first storage 215.
[0039] The first processor 211 functions as an input unit 2111 , an access unit 2112 , an update unit 2113 , and an output unit 2114 by executing a program stored in the first storage 215 .
[0040] The input unit 2111 receives an input of an instruction to acquire software for the component 200 from the second substrate 220. The input unit 2111 also receives an input of an instruction to update software for the component 200 from the second substrate 220.
[0041] The access unit 2112 acquires current software from the component 200 in accordance with a software acquisition instruction received from the second substrate 220. The current software refers to software that is stored in the component 200 and is being executed to perform its functions when accessed by the access unit 2112. The access unit 2112 also outputs software to the component 200 in accordance with a software update instruction received from the second substrate 220. The component 200 that receives the software rewrites the software.
[0042] The update unit 2113 acquires the main system software from the first storage 215 in accordance with the software update instruction received from the second substrate 220. The update unit 2113 also rewrites the backup system software and the main system software in accordance with the software update instruction received from the second substrate 220.
[0043] The output unit 2114 outputs the software acquired by the access unit 2112 or the update unit 2113 to the second board 220.
[0044] The second processor 221 executes a program stored in the second storage 225 to function as a receiving unit 2211, an output unit 2212, an input unit 2213, an access unit 2214, a software generating unit 2215, and a transmitting unit 2216. In addition, a storage area for a backup software storage unit 2251 is secured in the second storage 225.
[0045] The receiving unit 2211 receives an instruction to update the software of the component 200 along with a package file containing difference data of the software of the component 200 from the component management server 300. The receiving unit 2211 also receives an instruction to check the product number of the software of the component.
[0046] When the component 200 to be updated is connected to the first board 210, or when the component 200 to be updated is the first board 210, the output unit 2212 outputs a software acquisition instruction to the first board 210. The output unit 2212 also outputs a software update instruction to the first board 210.
[0047] The input unit 2213 receives input of the software of the component 200 to be updated from the first board 210.
[0048] When the component 200 to be updated is connected to the second board 220, the access unit 2214 acquires software from the component 200. The access unit 2214 also outputs the software generated by the software generation unit 2215 to the component 200 to be updated. The component 200 that receives the software rewrites the software. In other words, the access unit 2214 is an example of an update unit that updates the component 200 based on the received software.
[0049] The software generation unit 2215 generates updated software by applying the differential data received by the receiving unit 2211 to the current software input to the input unit 2213 or the current software acquired by the access unit 2214. For example, the differential data holds a combination of an offset, which is the number of bits from the beginning of the file, and a post-change value for each change. In this case, the software generation unit 2215 identifies the relevant part of the current software based on the offset of the differential data, and rewrites the pre-change value indicated by the differential data for the relevant part with the post-change value. In this way, the software generation unit 2215 can generate updated software from the current software and the differential data.
[0050] The transmitting unit 2216 transmits a response to the request received by the receiving unit 2211 to the component management server 300 .
[0051] <Configuration of the component management server 300> FIG. 7 is a block diagram showing the configuration of the component management server 300 according to the first embodiment. The component management server 300 includes a processor 310, a main memory 330, a storage 350, and an interface 370. The processor 310 obtains a program from the storage 350, loads it into the main memory 330, and executes predetermined processing in accordance with the program. A communication device (not shown) having a communication function via a wide area communication network is connected to the interface 370, and the interface 370 is communicatively connected to the second board 220 of the gateway function controller 201 and the software management server 500 via the communication device.
[0052] The programs stored in storage 350 may be for implementing some of the functions performed by component management server 300. In another embodiment, component management server 300 may include a custom LSI such as a PLD in addition to or instead of the above configuration. In this case, some or all of the functions implemented by component management server 300 may be implemented by the integrated circuit.
[0053] Examples of storage 350 include a magnetic disk, a magneto-optical disk, an optical disk, and a semiconductor memory. Storage 350 may be an internal medium directly connected to a bus line, or an external medium connected to component management server 300 via interface 370 or a communication line. Alternatively, a program may not be stored in storage 350, but may be delivered to component management server 300 via a communication line, and executed by processor 310. In at least one embodiment, storage 350 is a non-transitory tangible storage medium.
[0054] The processor 310 executes a program stored in the storage 350 to provide a differential data receiving unit 311, an update target identifying unit 312, a product number checking unit 313, an update instruction sending unit 314, and a table updating unit 315. In addition, a storage area for a component table 351 is secured in the storage 350.
[0055] The component table 351 stores the part numbers of the hardware and software of the components 200 provided in each of the multiple work machines 100. In other words, the component table 351 stores the machine ID of the work machine 100, and the hardware and software part numbers of the components in association with each other.
[0056] The differential data receiving unit 311 receives, from the software management server 500, the differential data of the software and the product number of the software to which the differential data is to be applied.
[0057] The update target identification unit 312 refers to the component table 351 and identifies the component 200 related to the software product number received by the difference data receiving unit 311 and the work machine 100 equipped with that component 200.
[0058] The product number confirmation unit 313 transmits a confirmation request for the software product number of the component 200 to be updated to the work machine 100 identified by the update target identification unit 312. The product number confirmation unit 313 receives the confirmation result of the software product number from the work machine 100.
[0059] The update instruction sending unit 314 sends a software update instruction to the work machine 100 when the confirmation result received from the work machine 100 by the product number confirmation unit 313 matches the software product number received from the software management server 500 by the differential data receiving unit 311. The software update instruction includes the differential data received by the differential data receiving unit 311, a gateway script to be executed by the gateway function controller 201, and a component script to be executed by the component 200 to be updated. The gateway script describes the procedure by which the gateway function controller 201 processes the differential data included in the update instruction. The component script describes the procedure by which the updated program is installed.
[0060] The table update unit 315 determines whether or not the software has been updated based on the confirmation result that the product number confirmation unit 313 receives from the work machine 100 after the software update instruction has been issued. If the table update unit 315 determines that the software has been updated, it updates the component table 351.
[0061] <Configuration of Software Management Server 500> FIG. 8 is a block diagram showing the configuration of the software management server 500 according to the first embodiment. The software management server 500 includes a processor 510, a main memory 530, a storage 550, and an interface 570. The processor 510 obtains a program from the storage 550, loads the program into the main memory 530, and executes predetermined processing in accordance with the program. The interface 570 is connected to the component management server 300 so as to be able to communicate with the component management server 300.
[0062] The programs stored in storage 550 may be for implementing some of the functions to be performed by software management server 500. In another embodiment, software management server 500 may include a custom LSI such as a PLD in addition to or instead of the above configuration. In this case, some or all of the functions implemented by software management server 500 may be implemented by the integrated circuit.
[0063] Examples of storage 550 include a magnetic disk, a magneto-optical disk, an optical disk, and a semiconductor memory. Storage 550 may be an internal medium directly connected to a bus line, or an external medium connected to software management server 500 via interface 570 or a communication line. Alternatively, the program may be distributed to software management server 500 via a communication line, and processor 510 may execute the program. In at least one embodiment, storage 550 is a non-transitory tangible storage medium.
[0064] The processor 510 executes a program stored in the storage 550 to provide a software recording unit 511, a differential data generating unit 512, and a differential data transmitting unit 513. In addition, a storage area for a software table 551 is secured in the storage 550.
[0065] The software table 551 associates with the hardware part number of the component 200 and stores a plurality of software programs with different part numbers that are applicable to the component 200 related to the part number. That is, the software table 551 stores the hardware part number of the component, the software entity, and the software part number of the software in association with each other. FIG. 9 is a diagram showing an example of a software table according to the first embodiment. The software table 551 stores the hardware part number indicating the image display component, the software part number indicating the image display component application, and the software entity in association with each other. Furthermore, in the example shown in FIG. 9, the software table 551 stores the hardware part number indicating the machine guidance component, the software part number indicating the machine guidance component application, and the software entity in association with each other.
[0066] Software recording unit 511 receives input of the software entity, the software product number, and the hardware product number of component 200 to which the software is applied from a server administrator or software developer, and records this in software table 551. The administrator or developer operates developer terminal 700 to send the software entity, the software product number, and the hardware product number of component 200 to which the software is applied to software management server 500. Furthermore, when software recording unit 511 receives input of product number information indicating the hardware product numbers of multiple components 200 that work together to realize a predetermined function from developer terminal 700, it records the received product number information in storage 550.
[0067] The differential data generating unit 512 generates differential data between the software newly recorded in the software table 551 and software with a different product number that is applied to the hardware to which the software is to be applied.
[0068] The differential data transmission unit 513 associates the differential data generated by the differential data generation unit 512 with the software product number to which the differential data is to be applied, and transmits the associated data to the component management server 300. If the differential data transmission unit 513 has received product number information for multiple components 200 from the developer terminal 700, it also transmits the product number information to the component management server 300.
[0069] How to update the software FIG. 10 is a sequence diagram showing a method for updating software of the component 200 in the software update system 1 according to the first embodiment. When the developer updates the software of the component 200, the developer operates the developer terminal 700 to associate the software entity, the product number of the software, and the hardware product number of the component 200 to which the software applies, and transmits them to the software management server 500. The software recording unit 511 of the software management server 500 associates the received software entity, software product number, and hardware product number, and records them in the software table 551 (step S1). The software product number received by the software recording unit 511 is the updated product number, which is the software product number after the update. At this time, if product number information is received from the developer terminal 700, the software recording unit 511 records the received product number information in the storage 550.
[0070] The differential data generation unit 512 acquires from the software table 551 the software entity and software product number associated with the hardware product number received in step S1 (step S2). The differential data generation unit 512 generates differential data for each software product number by calculating the difference between the software received in step S1 and each piece of software acquired in step S2 (step S3). If the software stored in the component 200 is always the latest version, differential data may be generated only for the latest software among the software acquired in step S2. The differential data transmission unit 513 associates the differential data generated in step S3 with the hardware product number received in step S1, the update product number received in step S1, and the target product number, which is the software product number acquired in step S2, and transmits the data to the component management server 300 (step S4). If product number information has been received from the developer terminal 700 in step S1, the differential data transmission unit 513 also transmits the product number information to the component management server 300.
[0071] The difference data receiving unit 311 of the component management server 300 receives the difference data, software product number, and hardware product number from the software management server 500 (step S4). The update target identifying unit 312 references the component table 351 and identifies the work machine 100 that is equipped with the component 200 related to the received hardware product number (step S5). Note that multiple work machines 100 that are equipped with the component 200 related to the hardware product number may be identified. Next, the product number confirmation unit 313 transmits a confirmation request for the software product number of the component to be updated to the gateway function controller 201 of the identified work machine 100 (step S6). That is, the confirmation request for the software product number includes the hardware product number of the component 200 to be updated.
[0072] The gateway function controller 201 receives a request to confirm the software product number from the component management server 300 (step S6). The gateway function controller 201 executes product number confirmation processing for the component 200 and transmits the identified software product number to the component management server 300 (step S7). The software product number is written as a constant in the software entity, and is identified, for example, by executing a product number confirmation command possessed by the software. Details of the product number confirmation processing by the gateway function controller 201 will be described later.
[0073] The product number confirmation unit 313 of the component management server 300 receives the software product number from the work machine 100 (step S7). If the software product number received in step S7 matches the target product number received in step S4, the update instruction transmission unit 314 transmits to the gateway function controller 201 of that work machine 100 an instruction to update the software of the component to be updated and a package file to be used for the update (step S8). The software update instruction includes the difference data received in step S4, a gateway script to be executed by the gateway function controller 201, and a component script to be executed by the component 200 to be updated. The gateway script includes the hardware product number of the component to which the difference data will be applied.
[0074] In addition, if the data received in step S4 by the component management server 300 includes product number information indicating the hardware product numbers of multiple components 200, the update instruction sending unit 314 generates a package file that includes, in addition to the differential data, gateway script, and component script related to the multiple components 200 indicated by the product number information, the hardware product number information of each component 200 required to realize the function, and update order information indicating the update order of the components 200.
[0075] The gateway function controller 201 receives the software update instruction and package file from the component management server 300 (step S8). Once the gateway function controller 201 has completed receiving the package file, it executes software update processing for the components 200 in accordance with the gateway script included in the package file (step S9). The gateway script may describe that after the key of the work machine 100 is turned off, individual components 200 are woken up by a function such as Wake-on-LAN to execute software update processing. This is to prevent the components 200 from becoming inoperable due to an update while the work machine 100 is in operation. The gateway script may also describe that after the key is turned on, the software update processing is executed when the operation of the work machine 100 is locked by a lock lever (a lever that blocks the flow paths of all hydraulic circuits for the work implement, swing, and travel) of the work machine 100. Details of the software update processing by the gateway function controller 201 will be described later.
[0076] A predetermined time after the differential data receiving unit 311 of the component management server 300 has transmitted the update instruction in step S9, the part number confirmation unit 313 transmits a confirmation request for the software part number of the component to be updated to the gateway function controller 201 of the work machine 100 that transmitted the update instruction (step S10). The predetermined time is sufficiently longer than the calculation time required for the process of applying the differential data to the software. Note that in another embodiment, the gateway function controller 201 of the work machine 100 may transmit a completion notification to the component management server 300 after completing the update, and the part number confirmation unit 313 may transmit a confirmation request for the software part number of the component to be updated to the gateway function controller 201 of the work machine 100 that transmitted the completion notification.
[0077] The gateway function controller 201 receives a request to confirm the software product number from the component management server 300. The gateway function controller 201 executes product number confirmation processing for the component 200 and transmits the identified software product number to the component management server 300 (step S11). Note that since the software product number is written as a constant in the software entity, if the software update processing in step S9 has been completed normally, the software product number is also updated accordingly.
[0078] The product number confirmation unit 313 of the component management server 300 receives the software product number from the work machine 100 (step S11). If the software product number received in step S11 matches the updated product number received in step S4, the table update unit 315 updates the software product number of the component 200 stored in the component table 351 to the software product number received in step S11 (step S12).
[0079] 10 shows only one example of processing, and does not prevent software from being updated by other processing. For example, a software update system 1 according to another embodiment may not perform the processing of steps S6, S7, S10, S11, and S12. In another embodiment, the software product number may be stored in a main memory or storage (not shown) of the component 200. In this case, the gateway function controller 201 may transmit a component number confirmation request for the component 200 to the component 200 in steps S7 and S11, and the component 200 may acquire the software product number stored in the main memory or storage and transmit it to the gateway function controller 201.
[0080] <<Gateway function controller 201 product number confirmation process>> Here, we will explain the operation of the gateway function controller 201 in the software update process. When the receiving unit 2211 of the second board 220 of the gateway function controller 201 receives a confirmation request for the software product number from the component management server 300 in step S6 or step S10, the gateway function controller 201 executes product number confirmation processing.
[0081] FIG. 11 is a flowchart showing the part number confirmation process of the gateway function controller 201 according to the first embodiment. The receiving unit 2211 determines whether the component 200 whose software product number is to be confirmed, i.e., the component 200 related to the hardware product number included in the confirmation request, is connected to the second board 220 (step S31). If the component 200 to be confirmed is connected to the second board 220 (step S31: YES), the accessing unit 2214 acquires the software product number from the component 200 to be confirmed via the second network N2 (step S32).
[0082] On the other hand, if the component 200 to be checked is not connected to the second board 220 (step S31: NO), the output unit 2212 outputs a request to check the software product number to the first board 210 (step S33). The input unit 2111 of the first board 210 receives a confirmation request for the software product number from the second board 220 (step S34). Next, the access unit 2112 acquires the software product number from the component 200 to be confirmed via the first network N1 (step S35). The output unit 2114 outputs the acquired software product number to the second board 220 (step S36). The input unit 2213 of the second board 220 receives the software product number from the component 200 to be checked from the first board 210 (step S37).
[0083] The transmitting section 2216 of the second board 220 transmits the software product number from the component 200 to be checked, identified in step S32 or step S37, to the component management server 300 (step S38). This allows the gateway function controller 201 to notify the software product number of the component 200 in response to a confirmation request from the component management server 300.
[0084] 11 shows only one example of processing, and does not preclude product number confirmation by other processing. Furthermore, the gateway function controller 201 according to other embodiments may not perform product number confirmation processing. Furthermore, in other embodiments, the software product number may be stored in a main memory or storage (not shown) of the component 200. In this case, the second board 220 may transmit a component number confirmation request for the component 200 to the component 200 in steps S32 and S37, and the component 200 may acquire the software product number stored in the main memory or storage and transmit it to the second board.
[0085] <<Software update process of gateway function controller 201>> In step S8, the receiving unit 2211 of the second board 220 of the gateway function controller 201 receives the software update instruction and the package file from the component management server 300. When reception of the package file is complete, the receiving unit 2211 records the received package file in the second storage 225. The second storage 225 is an example of a storage unit that stores the package file. Then, the gateway function controller 201 executes the gateway script included in the package file to perform the software update process.
[0086] Fig. 12 is a flowchart showing a standalone software update process by the gateway function controller 201 according to the first embodiment. That is, the example shown in the flowchart in Fig. 12 represents a procedure when a package file contains only data used to update one component 200.
[0087] In order to communicate with the component 200 whose software is to be updated, i.e., the component 200 related to the hardware product number described in the gateway script, the receiving unit 2211 refers to the connection information to determine whether the component 200 is connected to the second board 220 (step S61). If the component 200 to be updated is connected to the second board 220 (step S61: YES), the accessing unit 2214 acquires the current software from the component 200 to be updated via the second network N2 (step S62).
[0088] On the other hand, if the component 200 to be updated is connected to the first board 210, or if the component 200 to be updated is the first board 210 (step S61: NO), the output unit 2212 outputs a software acquisition instruction to the first board 210 (step S63). The input unit 2111 of the first substrate 210 receives a software acquisition instruction from the second substrate 220 (step S64). The update unit 2113 determines whether the component 200 to be updated is the first substrate 210 itself (step S65). If the component 200 to be updated is the first substrate 210 itself (step S65: YES), the update unit 2113 acquires the main system software from the first storage 215 (step S66). On the other hand, if the component 200 to be updated is not the first substrate 210 itself (step S65: NO), the access unit 2112 acquires the current software from the component 200 to be updated via the first network N1 (step S67). Note that the component 200 may transmit information about the current software to the first substrate in multiple batches. This allows the component 200, which has limited computational resources and cannot transmit the current software to the first substrate in a single transmission, to transmit the current software information to the first substrate by transmitting the information in multiple batches. The output unit 2114 outputs the software acquired in step S66 or step S67 to the second board 220 (step S68). The input unit 2213 of the second board 220 receives the software of the component 200 to be updated from the first board 210 (step S69).
[0089] The software generation unit 2215 then generates updated software by applying the difference data included in the package file received from the component management server 300 to the software acquired in step S62 or step S69 in accordance with the gateway script (step S70). The software generation unit 2215 associates the generated software with the hardware product number of the component 200 and records it in the standby software storage unit (step S71). In order to transmit the generated software to the component 200 to be updated, the software generation unit 2215 references the connection information to determine whether the component 200 to be updated is connected to the second board 220 (step S72).
[0090] If the component 200 to be updated is connected to the second board 220 (step S72: YES), the access unit 2214 outputs the software generated in step S70 and the component script included in the package file to the component 200 to be updated via the second network N2. As a result, the component 200 executes the component script to rewrite the software stored therein with the software generated in step S70 (step S73).
[0091] On the other hand, if the component 200 to be updated is connected to the first board 210, or if the component 200 to be updated is the first board 210 (step S72: NO), the output unit 2212 outputs a software update instruction to the first board 210 (step S74). The software update instruction includes the software generated in step S70 and the component script included in the update instruction. The input unit 2111 of the first substrate 210 receives a software update instruction from the second substrate 220 (step S75). The update unit 2113 determines whether the component 200 to be updated is the first substrate 210 itself (step S76). If the component 200 to be updated is the first substrate 210 itself (step S76: YES), the update unit 2113 rewrites the standby software stored in the first storage 215 with the software included in the update instruction (step S77). When the rewriting of the standby software is complete, the update unit 2113 rewrites the primary software stored in the first storage 215 with the software included in the update instruction (step S78).
[0092] On the other hand, if the component 200 to be updated is not the first board 210 itself (step S76: NO), the access unit 2112 outputs the software and component script included in the package file to the component 200 to be updated via the first network N1. As a result, the component 200 executes the component script to rewrite the software stored therein with the software included in the package file (step S79). This allows the gateway function controller 201 to update the software of the component 200 based on the difference data.
[0093] Fig. 13 is a flowchart showing a plurality of software update processes by the gateway function controller 201 according to the first embodiment. That is, the example shown in the flowchart in Fig. 13 represents a procedure when a package file contains data used to update a plurality of components 200 that realize functions related to each other.
[0094] The receiving unit 2211 determines whether the hardware part number of each component 200 to be updated satisfies the update conditions based on the hardware part number information included in the package file (step S81). The receiving unit 2211 may determine whether the update conditions are met based on the hardware part number of the component 200 acquired in step S7, or may receive the hardware part number again from the component 200 and determine whether the update conditions are met. For example, the receiving unit 2211 compares the hardware part number information included in the package file with the hardware part number of each component 200 to be updated, and determines that the update conditions are met if they match.
[0095] If at least one component 200 does not satisfy the update condition indicated by the hardware product number information (step S81: NO), the receiving unit 2211 deletes the received package file (step S82) and does not update any of the components 200 related to the update instruction. For example, even if only one of three components 200 to be updated does not satisfy the update condition and the remaining two do, the gateway function controller 201 does not update all of the three components 200.
[0096] On the other hand, if all components 200 satisfy the update condition (step S81: YES), the receiving unit 2211 determines whether any of the multiple components 200 indicated by the update order information included in the package file have not yet been updated (step S83). For example, information about the components 200 for which updates have been completed is recorded in the second storage 225 in step S87 (described later). Therefore, if any of the multiple components 200 indicated by the update order information has not been recorded as a component 200 for which updates have been completed, the receiving unit 2211 determines that there is a component 200 for which updates have not yet been completed. If there is any component 200 for which updates have not yet been completed (step S83: YES), the output unit 2212 determines the component 200 with the earliest update order as the component 200 to be updated (step S84). Then, the processing of steps S61 to S70 shown in FIG. 12 is performed for the component 200 to be updated, thereby updating the software (step S85).
[0097] The access unit 2214 determines whether the update of the component 200 to be updated has been completed normally (step S86). For example, the access unit 2214 determines whether a notification indicating abnormal completion or interruption of the update has been received from the component 200. The access unit 2214 is an example of a detection unit that detects interruption of the update of the component 200. If the update of the component 200 to be updated has not been completed normally (step S86: NO), the gateway function controller 201 interrupts the update processing and ends the processing without updating any component 200 that is later in the update order than the component 200 to be updated that was determined in step S84.
[0098] On the other hand, if the update is completed successfully (step S86: YES), the fact that the update of the component 200 determined in step S84 has been completed is recorded in the second storage 225 (step S87). This makes it possible to identify the component 200 for which the update has been completed even if the update process is interrupted due to a power outage. Then, the process returns to step S83, and the process moves to update of the next component 200. If it is determined in step S83 that there is no component for which the update has not been completed (step S83: NO), the receiving unit 2211 deletes the package file recorded in the second storage 225 (step S82) and ends the update process.
[0099] 13 shows only one example of processing, and does not preclude confirmation of part numbers by other processing. For example, in another embodiment, the gateway function controller 201 may execute update processing of a plurality of components 200 by parallel processing without using update order information.
[0100] Here, updating of the multiple components 200 will be described using a specific example. Before being updated, the perimeter monitoring component 205 of the work machine 100 had the function of generating a bird's-eye image, as if viewed from above, with the work machine 100 at the center, based on an image captured by the camera 206. In contrast, a software update of the perimeter monitoring component 205 will enable it to realize a function of detecting obstacles that exist within a predetermined distance from the work machine 100. Furthermore, a software update of the monitor component 202 will enable it to realize a function of marking the position of a detected obstacle on the bird's-eye image. Furthermore, a software update of the control controller 203 will enable it to realize a function of restricting the operation of hydraulic equipment (e.g., the travel motor 112, swing motor 124, boom cylinder 131C, arm cylinder 132C, bucket cylinder 133C, etc.) when an obstacle is detected. In other words, the software of the monitor component 202 and the control controller 203 is software related to the software of the perimeter monitoring component 205. The software of the periphery monitoring component 205 is an example of first software, and the software of the monitor component 202 and the controller 203 is an example of second software.
[0101] The component management server 300 receives the software for the periphery monitoring component 205, the monitor component 202, and the control controller 203 from the software management server 500 and generates respective difference data. The component management server 300 then generates a package file including each difference data, hardware product number information for each component 200, and update order information. In this case, the update order indicated by the update order information is, for example, the periphery monitoring component 205, the control controller 203, and the monitor component 202.
[0102] The gateway function controller 201 of the work machine 100 receives the package file from the component management server 300. If communication is interrupted for some reason before reception of the package file is complete, the work machine 100 will not update the software. Therefore, if, for example, the work machine 100 starts up in the middle of receiving a package file and then moves out of communication range, it is possible to prevent a situation in which only some of the components 200 are updated and others remain in an outdated state.
[0103] On the other hand, when reception of the package file is complete, if the hardware part number of each component 200 does not satisfy the update condition indicated by the hardware part number information, the component 200 is not updated. This prevents a situation in which some of the components 200 cannot be updated and only some of the components 200 are updated.
[0104] If the update conditions indicated by the hardware product number information are satisfied, the gateway function controller 201 updates the components 200 in the order indicated by the update order information. At this time, the update process may be interrupted for some reason during the update. For example, if the work machine 100 is started during the update, the gateway function controller 201 interrupts the update work and operates each component 200. In this case, information about the components 200 for which the update has been completed in step S86 is recorded in the second storage 225. Therefore, by performing the process again from step S81, the receiving unit 2211 can identify the components 200 for which the update has been interrupted in steps S83 and S84 and resume the update process. The receiving unit 2211 is an example of a determining unit that, when an interruption of the update is detected, determines the components 200 for which the update has not been completed. Furthermore, because the package file has already been recorded in the second storage 225, the update process can be resumed even if the work machine 100 has moved out of communication range when the update is resumed.
[0105] Actions and Effects In this way, the software update system 1 according to the first embodiment receives data including the first software used to update the first component and the second software used to update the second component from the server, stores the data in the storage unit, and then updates the first component and the second component based on the first software and the second software. This allows the software update system 1 to resume an update of multiple components 200 even if the update is stopped midway, and to realize a function realized by the multiple components 200 working together. In particular, when the function realized by the second software uses a calculation result obtained by the function realized by the first software, the software update system 1 according to the first embodiment can prevent the function of the second software from becoming unavailable without being updated by the first software.
[0106] Other Embodiments Although one embodiment has been described in detail above with reference to the drawings, the specific configuration is not limited to the above, and various design modifications are possible. That is, in other embodiments, the order of the above-described processes may be changed as appropriate. Furthermore, some processes may be executed in parallel.
[0107] The gateway function controller 201 according to the first embodiment generates software for all of the components 200 of the work machine 100 on the second board 220 mounted on the work machine 100. On the other hand, in another embodiment, if any of the components 200 has sufficient computational resources, the component 200 may autonomously generate new software from differential data and autonomously update its own software. In still another embodiment, the component management server 300 may transmit to the gateway function controller 201 a package file containing the new software itself to be used for the update, rather than differential data. In this case, for example, instead of the processing of steps S2 to S4 in the sequence diagram shown in FIG. 10 , the software management server 500 associates the target part numbers, which are the hardware part number, software entity, update part number, and software part number, received in step S1, and transmits them to the component management server 300. 12, the gateway function controller 201 records the new software to be used for the update received from the component management server 300 in the standby software storage unit in association with the hardware product number of the component 200. The update instruction includes the new software to be used for the update, a gateway script to be executed by the gateway function controller 201, and a component script to be executed by the component 200 to be updated. The gateway script describes the procedure for processing the new software.
[0108] The gateway function controller 201 according to the first embodiment comprises a first board 210 and a second board 220 which are physically separate. In contrast, the gateway function controller 201 according to other embodiments may be mounted on a single board. Furthermore, the gateway function controller 201 according to other embodiments may comprise one board having two processors. Furthermore, in other embodiments, the gateway function controller 201 may comprise three or more boards. Furthermore, in other embodiments, the roles of the multiple boards that the gateway function controller 201 comprises may be different from those in the above-described embodiments.
[0109] In another embodiment, the software management server 500 and the component management server 300 may not be separate entities, but may be realized by a single device. [Explanation of symbols]
[0110] 1...Software update system 100...Work machine 110...Traveling body 111...Crawler 112...Travel motor 120...Swinging body 121...Engine 122...Hydraulic pump 123...Control valve 124...Swing motor 125...Fuel injection device 130...Work machine 131...Boom 131C...Boom cylinder 132...Arm 132C...Arm cylinder 133...Bucket 133C...Bucket cylinder 140...Operator's cab 142...Operator's seat 143...Operation device 200...Component 201...Gateway function controller 202...Monitor component 203...Control controller 204...Engine controller 205...Periphery monitoring component 206...Camera 210...First board 211...First processor 2111...Input unit 2112...Access unit 2113...Update unit 2114...Output unit 213...First main memory 215...First storage 217...First interface 220...Second board 221...Second processor 2211...Receiving unit 2212...Output unit 2213...Input unit 2214...Access unit 2215...Software generation unit 2216...Transmitting unit 223...Second main memory 225...Second storage 2251...Backup software storage unit 227...Second interface 300...Component management server 311...Differential data receiving unit 312...Update target specifying unit 313...Product number confirmation unit 314...Update instruction transmitting unit 315...Table updating unit 500...Software management server 511...Software recording unit 512...Differential data generation unit 513...Differential data transmitting unit 700...Developer terminal
Claims
1. A software update system for updating a plurality of components provided in a work machine, comprising: the plurality of components include a controller having a communication device for communicating with a server, a first component, and a second component; The controller Obtaining current software from the first component; Obtaining current software from the second component; receiving, from the server, difference data of the software of the first component and difference data of the software of the second component; generating first software by applying the difference data of the software of the first component received from the server to the acquired current software of the first component; generating second software by applying the difference data of the software of the second component received from the server to the acquired current software of the second component; storing the first software and the second software; updating the first component and the second component based on the first software and the second software after the first software and the second software are stored; Software update system.
2. the first component includes a periphery monitoring component that monitors the periphery using an imaging device provided in the work machine, the second component includes a monitor component that performs display control of a monitor provided on the work machine, and a hydraulic component that performs hydraulic control of hydraulic equipment provided on the work machine, the first software includes software for realizing a function of detecting obstacles around the work machine using the imaging device, the second software includes software of the monitor component for displaying on the monitor a display relating to the detection of an obstacle by the first software, and software of the hydraulic component for controlling an output of the hydraulic device when the first software detects an obstacle; The controller enables functions related to obstacle detection functions of the perimeter monitoring component, the monitor component, and the hydraulic component based on the first software and the second software. The software update system of claim 1 .
3. The controller receiving update order information indicating an update order of the plurality of components from the server; The plurality of components are updated in the order indicated by the update order information.
3. The software update system according to claim 1 or 2.
4. When there is a component among the plurality of components for which updating has failed, the controller does not update a component that is indicated in the update order information to be updated after the failed component. The software update system of claim 3 .
5. The controller updates the second component with the second software after the first component has been updated with the first software. The software update system according to any one of claims 1 to 4.
6. The controller updates the monitor component last among the plurality of components. The software update system of claim 2 .
7. The controller Detecting an interruption of the update of the first component and the second component based on the first software and the second software; When the interruption of the update is detected, determining which of the first component and the second component has not been updated; When the update of the component determined to be incomplete becomes resumable, the component determined to be incomplete is updated based on the stored first software or the stored second software. The software update system according to any one of claims 1 to 6.
8. The controller receiving product number information indicating conditions for product numbers of the first component and the second component that can be updated by the first software and the second software; When the part numbers of the first component and the second component satisfy the condition indicated by the part number information, the first component and the second component are updated. The software update system according to any one of claims 1 to 7.
9. The car body and a work machine attached to the vehicle body; a controller having a communication device for communicating with a server, a plurality of components including a first component and a second component; A software update system according to at least one of claims 1 to 8; A work machine comprising:
10. 1. A software update method for updating a plurality of components provided in a work machine, comprising: the plurality of components include a controller having a communication device for communicating with a server, a first component, and a second component; The controller: Obtaining current software from the first component; Obtaining current software from the second component; receiving, from the server, difference data of the software of the first component and difference data of the software of the second component; generating first software by applying the difference data of the software of the first component received from the server to the acquired current software of the first component; generating second software by applying the difference data of the software of the second component received from the server to the acquired current software of the second component; storing the received first software and second software; updating the first component and the second component based on the first software and the second software after the first software and the second software are stored; How to update software.
Citation Information
Patent Citations
Control device and its program
JP2004118586A
Image forming apparatus and program updating method
JP2004194298A
Software management device
JP2006011647A
Image processing apparatus and information processing apparatus
JP2016178499A
Construction machine and program rewriting system equipped with the same
JP2017041114A