center
The center manages software updates by determining update needs and sending notifications to ECUs, addressing incomplete update issues and ensuring continuous update processes.
Patent Information
- Application Number
- JP2022109205
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-06
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2042-07-06
Smart Images

Figure 0007732408000001 
Figure 0007732408000002 
Figure 0007732408000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a center that manages software updates for electronic control units mounted on vehicles through communication via a network. [Background technology]
[0002] Vehicles are equipped with multiple electronic control units (ECUs) for controlling the vehicle's operation. Each ECU includes a processor, a temporary storage unit such as RAM, and a non-volatile memory such as flash ROM. The processor executes software stored in the non-volatile memory to realize the control functions of the ECU. The software stored in each ECU is rewritable, and updating to a newer version of the software can improve the functionality of each ECU or add new vehicle control functions.
[0003] A known technology for updating software in an electronic control unit is OTA (Over The Air) technology, in which an in-vehicle communication device connected to an in-vehicle network is wirelessly connected to a communication network such as the Internet, and a device (OTA master) responsible for updating the vehicle's software downloads software from a server such as a center via wireless communication and installs the downloaded software in the electronic control unit, thereby updating or adding software to the electronic control unit. See, for example, Patent Document 1. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-326689 Summary of the Invention [Problem to be solved by the invention]
[0005] When the software update of the electronic control unit is completed, the vehicle notifies the center that the update is complete. The center then receives this notification and sends back to the vehicle a receipt notification (response), which allows the electronic control unit to complete the software update process.
[0006] However, if the electronic control unit does not receive the receipt notification from the center, for example, because it is out of range of wireless communication, the software update process of the electronic control unit remains in an incomplete state. Therefore, there is a problem that the electronic control unit that has not received the receipt notification cannot execute the next software update process.
[0007] The present disclosure has been made in consideration of the above-mentioned problems, and aims to provide a center that can prevent an electronic control unit from entering a state where it is unable to perform the next software update process. [Means for solving the problem]
[0008] In order to solve the above problem, one aspect of the disclosed technology is a center that manages software updates for an electronic control unit installed in a vehicle through communication via a network, the center comprising: a communication unit that receives information from the vehicle that can be received when the electronic control unit is in a state where a software update is possible and is used to determine whether or not a software update is required for the electronic control unit; and a control unit that uses the information to determine whether or not a software update is required for the electronic control unit, and if the communication unit has not received the information when making the determination, the control unit causes the communication unit to send a notification to the vehicle to put the electronic control unit into a state where a software update is possible. [Effects of the Invention]
[0009] According to the present disclosure, it is possible to provide a center that can prevent the electronic control unit from entering a state where it is unable to execute the next software update process. [Brief explanation of the drawings]
[0010] [Figure 1] Overall configuration diagram of a network system including a center according to this embodiment. [Figure 2] Electronic control unit functional block diagram [Figure 3A] Flowchart of control process executed by the center [Figure 3B] Flowchart of control process executed by the center [Figure 4A] Process flowchart of control executed by a vehicle [Figure 4B] Process flowchart of control executed by a vehicle DETAILED DESCRIPTION OF THE INVENTION
[0011] <Embodiment> [composition] Fig. 1 is a block diagram showing the overall configuration of a network system according to an embodiment of the present disclosure. The network system shown in Fig. 1 is a system for updating software of multiple electronic control units 40a, 40b, and 40c mounted on a vehicle, and includes a center 10 located outside the vehicle and an in-vehicle network 20 established within the vehicle.
[0012] (1) Center The center 10 can communicate with the multiple electronic control units 40a, 40b, and 40c included in the in-vehicle network 20 via the network 70 and the communication module 50. The center 10 can control and manage software updates for the multiple electronic control units 40a, 40b, and 40c by transmitting update data for the software of the multiple electronic control units 40a, 40b, and 40c and receiving notifications indicating the progress of the software update process between the center 10 and the multiple electronic control units 40a, 40b, and 40c. The center 10 functions as a so-called server.
[0013] The center 10 includes a communication unit 11, a storage unit 12, a determination unit 13, and a control unit 14. The center 10 typically includes a central processing unit (CPU), a random access memory (RAM), a storage device equipped with a readable and writable storage medium such as a hard disk drive (HDD) or a solid state drive (SSD), and a communication device for communicating with the plurality of electronic control units 40a, 40b, and 40c via a network 70. In the center 10, the CPU executes a program read from the storage device using the RAM as a working area, thereby performing predetermined processing related to the software update.
[0014] The communication unit 11 transmits and receives data, information, requests, and the like to and from the electronic control units 40a, 40b, and 40c. The communication unit 11 receives a software update confirmation request from the electronic control units 40a, 40b, and 40c. The update confirmation request is information transmitted, for example, when the power or ignition is turned on in the vehicle, and is information for requesting the center 10 to confirm whether or not update data is available for the electronic control units 40a, 40b, and 40c based on vehicle configuration information. Upon receiving the update confirmation request, the communication unit 11 transmits information indicating the availability of update data to the electronic control units 40a, 40b, and 40c. The communication unit 11 also receives software version notifications from the electronic control units 40a, 40b, and 40c. Upon receiving the version notification, the communication unit 11 transmits a notification indicating the availability of a software update to the electronic control units 40a, 40b, and 40c based on the reception status of the version notification. The communication unit 11 also receives a distribution package transmission request (download request) from the electronic control units 40a, 40b, and 40c. When the communication unit 11 receives a distribution package download request, it transmits the distribution package including software update data to the electronic control unit to be updated (hereinafter referred to as the "target electronic control unit").
[0015] The storage unit 12 stores information related to software update processing for one or more electronic control units installed in the vehicle. As information related to the software update processing, the storage unit 12 stores at least update management information that associates, for each vehicle identification information (vehicle ID) that identifies the vehicle, information indicating software available in the electronic control units 40a, 40b, and 40c, and software update data for the electronic control units 40a, 40b, and 40c. The information indicating the software available in the electronic control units 40a, 40b, and 40c may, for example, be a combination of the latest version information for each software in the electronic control units 40a, 40b, and 40c. The storage unit 12 also stores software versions notified from the electronic control units 40a, 40b, and 40c. As information related to the software update processing, the storage unit 12 may store a status indicating the status of software updates being performed in the vehicle.
[0016] The determination unit 13 determines whether there are any electronic control units 40a, 40b, and 40c to which a software version notification has not been sent. Then, based on the result of the determination, the determination unit 13 causes the communication unit 11 to send a notification indicating whether a software update is available or a reset notification. The processing of this determination unit 13 will be described later.
[0017] When the communication unit 11 receives an update check request from the electronic control units 40a, 40b, and 40c, the control unit 14 determines whether or not there is software update data for the electronic control units 40a, 40b, and 40c identified by the vehicle ID included in the update check request, based on the update management information (such as the version of the electronic control unit) stored in the storage unit 12. If there is software update data for the electronic control units 40a, 40b, and 40c, the control unit 14 generates and transmits a distribution package including the update data to the electronic control unit that made the update check request.
[0018] (2) In-vehicle network The in-vehicle network 20 includes a plurality of electronic control units 40a, 40b, and 40c, and a communication module 50. Among these, the electronic control unit 40a is an electronic control unit having an OTA master function. The OTA master function may be configured as a standalone unit independent of the electronic control units. The electronic control units 40a, 40b, and 40c and the communication module 50 are connected via a bus 60.
[0019] The communication module 50 is a DCM unit that has the function of controlling communication between the center 10 and the vehicle, and is a communication device for connecting the in-vehicle network 20 to the center 10. The communication module 50 is wirelessly connected to the center 10 via the network 70, and performs vehicle authentication by the electronic control units 40a, 40b, and 40c, downloads update data, and the like.
[0020] The multiple electronic control units 40a, 40b, and 40c are devices (ECUs: Electronic Control Units) that control the operation of various parts of the vehicle. The multiple electronic control units 40a, 40b, and 40c can wirelessly communicate with the center 10 via the bus 60, the communication module 50, and the network 70. While FIG. 1 illustrates an example in which the in-vehicle network 20 includes three electronic control units 40a, 40b, and 40c, the number of electronic control units is not particularly limited. For example, a display device (HMI) may be connected to the bus 60 to display various information, such as a display indicating that update data is available during software update processing for the electronic control units 40a, 40b, and 40c, a consent request screen for requesting consent for the software update from the vehicle user or administrator, and a display of the results of the software update.
[0021] The OTA master function of the electronic control unit 40a is a function that manages the OTA status, controls the update sequence, which is the flow of the software update process, and performs software updates on the target electronic control units to be updated. The OTA master function can control the software updates of the target electronic control units among the electronic control units 40a, 40b, and 40c.
[0022] The electronic control unit 40a having this OTA master function typically includes a CPU, RAM, ROM (Read-Only Memory), a storage device, and a communication device for communicating with the center 10 via the network 70. In the electronic control unit 40a, the CPU executes a program read from the ROM using the RAM as a work area, thereby performing predetermined processing related to software updates. As shown in FIG. 2, the electronic control units 40a, 40b, and 40c each include a communication unit 41, a storage unit 42, and a control unit 43 as functional blocks for performing the predetermined processing.
[0023] The communication unit 41 transmits and receives data, information, requests, etc. to and from the center 10. For example, when the vehicle is powered on, the communication unit 41 transmits a software update confirmation request to the center 10. The update confirmation request includes, for example, a vehicle ID for identifying the vehicle. The communication unit 41 also transmits information about the current version of the software of the electronic control unit. ofThe vehicle ID and the current version of the software of the electronic control units 40a, 40b, and 40c are compared with the latest version of the software held by the center 10 for each vehicle ID to determine whether or not there is update data for the software of the electronic control units 40a, 40b, and 40c. In addition, the communication unit 41 receives a notification indicating the presence or absence of update data or a reset notification from the center 10 in response to the update confirmation request. If there is software update data, the communication unit 41 transmits a download request for a distribution package of the software update data to the center 10, and receives (downloads) the distribution package transmitted from the center 10 under the control of the control unit 43. In addition, the communication unit 41 transmits the software update status to the center 10.
[0024] The memory unit 42 stores a program for executing software updates of the electronic control unit (a program for controlling the OTA master function), various data used when executing software updates, as well as software update data downloaded from the center 10.
[0025] The control unit 43 determines whether or not there is software update data and manages the status related to the software update based on the response from the center 10 to the update confirmation request and version notification received by the communication unit 41. The control unit 43 also decrypts and verifies the authenticity of the distribution package that the communication unit 41 receives (downloads) from the center 10 and stores in the storage unit 42. The control unit 43 also controls the software update process (various verifications, installation, activation, etc.) using the update data received (downloaded) from the center 10. Specifically, the control unit 43 installs update software based on the update data and activates the installed update software.
[0026] [control] Next, the control executed in the network system according to this embodiment will be described with further reference to Figures 3A, 3B, 4A, and 4B. Figures 3A and 3B are processing flowcharts of the control executed by the center 10. The processing of Figure 3A and the processing of Figure 3B are connected by a connector X. Figures 4A and 4B are processing flowcharts of the control executed by each of the electronic control units 40a, 40b, and 40c. The processing of Figure 4A and the processing of Figure 4B are connected by connectors Y and Z.
[0027] (1) Center control (Step S301) The center 10 determines whether a software update confirmation request has been received from the electronic control unit 40a having the OTA master function or from all of the electronic control units 40a, 40b, and 40c (hereinafter referred to as "vehicles"). If an update confirmation request has been received from the vehicle (step S301, Yes), the process proceeds to step S302. If an update confirmation request has not been received from the vehicle (step S301, No), the process proceeds to step S308.
[0028] (Step S302) The center 10 determines whether or not a software update is available for the vehicle that sent the update check request. The center 10 may also send a receipt notification to the vehicle in response to the software update check request. When it is determined whether or not a software update is available, the process proceeds to step S303.
[0029] (Step S303) The center 10 determines whether or not a software version notification has been received from the vehicle. If a version notification has been received from the vehicle (step S303, Yes), the process proceeds to step S304. If a version notification has not been received from the vehicle (step S303, No), the process proceeds to step S305.
[0030] (Step S304) The center 10 stores (updates) the software version notified from the vehicle in the storage unit 12. The center 10 may transmit a receipt notification to the vehicle in response to the software version notification. Once the software version is stored, the process proceeds to step S305.
[0031] (Step S305) The center 10 determines whether or not there is an electronic control unit (ECU) for which the software version notification has not been received among the vehicles that have sent the update confirmation request. If there is an electronic control unit (ECU) for which the software version notification has not been received (step S305, Yes), the center 10 307 If there is no electronic control unit (ECU) for which the version notification has not been received (step S305, No), the process proceeds to step S 306 Processing proceeds to.
[0032] (Step S306) The center 10 notifies the vehicle of the presence or absence of a software update determined in step S302. When the notification of the presence or absence of a software update is transmitted to the vehicle, the process proceeds to step S308.
[0033] (Step S307) The center 10 sends a reset notification to the vehicle. When the reset notification is sent to the vehicle, the process proceeds to step S308.
[0034] (Step S308) In response to the notification that a software update is available, the center 10 determines whether or not a download request has been received from the vehicle. If a download request has been received from the vehicle (step S308, Yes), the process proceeds to step S309. If a download request has not been received from the vehicle (step S308, No), the process proceeds to step S310.
[0035] (Step S309) The center 10 transmits the software update data to the vehicle. The center 10 may also transmit a receipt notification to the vehicle in response to the download request. Once the software update data has been transmitted to the vehicle, the process proceeds to step S310.
[0036] (Step S310) The center 10 determines whether or not a notification indicating that the software update has been completed has been received from the vehicle. If an update completion notification has been received from the vehicle (step S310, Yes), the process proceeds to step S311. If an update completion notification has not been received from the vehicle (step S310, No), the current process flow ends. Thereafter, the process returns to step S301.
[0037] (Step S311) The center 10 transmits an update completion receipt notice to the vehicle, which notice indicates that the center 10 has received the software update completion notice. When the update completion receipt notice has been transmitted to the vehicle, the process proceeds to step S312.
[0038] (Step S312) The center 10 stores (updates) the status "update completed" as the status related to the software update in the storage unit 12. When the update completed status is stored, the current processing flow ends. After that, the processing returns to step S301.
[0039] (2) Vehicle control (Step S401) The vehicle determines whether the ignition has been switched from off to on (IG has been switched from off to on) (whether the vehicle power has been turned on). If the ignition has been switched from off to on (step S401, Yes), the process proceeds to step S402, and if the ignition has not been switched from off to on (step S401, No), the process proceeds to step S408.
[0040] (Step S402) The vehicle (electronic control unit 40a having the OTA master function or all of the electronic control units 40a, 40b, and 40c) transmits a software update confirmation request to the center 10. When the update confirmation request is transmitted from the vehicle, the process proceeds to step S403.
[0041] (Step S403) The vehicle transmits a notification (version notification) regarding the software versions of all electronic control units 40a, 40b, and 40c to the center 10. At this time, electronic control units whose software update status is stuck at "updating" cannot transmit a version notification. Therefore, only electronic control units (ECUs) with an updating status can transmit a version notification. Once the version notification has been transmitted, the process proceeds to step S404.
[0042] (Step S404) The vehicle determines whether or not a reset notification has been received from the center 10. This reset notification enables the vehicle to determine that there is an electronic control unit for which the update is incomplete. If a reset notification has been received (step S404, Yes), the process proceeds to step S405, and if a reset notification has not been received (step S404, No), the process proceeds to step S406.
[0043] (Step S405) The vehicle resets the software update status of all electronic control units (ECUs) 40a, 40b, and 40c. That is, the status of electronic control units that are stopped during an update is released. Once the status of all electronic control units 40a, 40b, and 40c has been reset, the process proceeds to step S402.
[0044] (Step S406) The vehicle determines whether or not it has received a notification regarding the availability of a software update from the center 10. If it has received the update availability notification (step S406, Yes), the process proceeds to step S407, and if it has not received the update availability notification (step S406, No), the process proceeds to step S402.
[0045] (Step S407) The vehicle determines whether or not there is a software update based on the update availability notification received from the center 10. If there is a software update (step S407, Yes), the process proceeds to step S408, and if there is no software update (step S407, No), the current process flow ends. After that, the process returns to step S401.
[0046] (Step S408) The vehicle inquires of the user or the like regarding the software update and determines whether or not the software update has been authorized by the user or the like. If the software update authorization has been received from the user or the like (step S408, Yes), the process proceeds to step S409. If the software update authorization has not been received (step S409, No), the process proceeds to step S409. 408 If the answer is YES, the process flow ends. After that, the process returns to step S401.
[0047] (Step S409) The vehicle transmits a software download request to the center 10. When the download request is transmitted, the process proceeds to step S410.
[0048] (Step S410) In response to the download request, the vehicle determines whether or not software update data has been received from the center 10. If update data has been received (step S410, Yes), the process proceeds to step S411, and if update data has not been received (step S410, No), the process proceeds to step S415.
[0049] (Step S411) The vehicle performs a download process of the update data in the target electronic control unit. The vehicle also sets the software update status to "updating." Once the update data download process is performed and the status is set to "updating," the process proceeds to step S412.
[0050] (Step S412) The target electronic control unit of the vehicle then installs the downloaded update data. Once the update data installation process is complete, the process proceeds to step S413.
[0051] (Step S413) The target electronic control unit of the vehicle then activates the installed update data. Once the update data activation process is complete, the process proceeds to step S414.
[0052] (Step S414) When the activation process of the update data is completed in the target electronic control unit, the vehicle transmits an update completion notice notifying the center 10 that the software update has been completed. Once the update completion notice has been transmitted, the process proceeds to step S415.
[0053] (Step S415) In response to the update completion notification, the vehicle determines whether or not it has received an update completion receipt notification from the center 10. If it has received an update completion receipt notification (step S415, Yes), the process proceeds to step S416, and if it has not received an update completion receipt notification (step S415, No), the process flow ends. Thereafter, the process returns to step S401.
[0054] (Step S416) The vehicle changes the software update status of the target electronic control unit from "updating" to "update completed," i.e., cancels the currently set updating status. When the currently updated status of the target electronic control unit is canceled, this processing flow ends. After that, the processing returns to step S401.
[0055] <Effects> As described above, according to the center 10 according to an embodiment of the present disclosure, if there is an electronic control unit for which software version information has not been transmitted during the configuration synchronization process executed, such as when the ignition is turned on, the center 10 determines that there is an electronic control unit for which the software update process remains incomplete. In this case, a reset notification is sent to the vehicle to cancel the incomplete software update process, and the status of the electronic control unit is reset. This prevents the electronic control unit from becoming unable to execute the next software update process. [Industrial Applicability]
[0056] The disclosed technology can be used in a center that manages, via network communication, a network system for updating software in an electronic control unit mounted on a vehicle. [Explanation of symbols]
[0057] 10 Center 11, 41 Communications Department 12, 42 Storage section 13 Judgment section 14, 43 Control section 20 In-vehicle network 40a, 40b, 40c Electronic control unit (ECU) 50 Communication Module 60 Bus 70 Network
Claims
[Claim 1] A center that manages software updates for an electronic control unit mounted on a vehicle through communication via a network, a communication unit that receives information used to determine whether or not a software update for the electronic control unit is required from the vehicle; a control unit that determines whether or not a software update for the electronic control unit is required using the information; a determination unit that determines whether or not the vehicle that transmitted the information has an electronic control unit for which the current version of software has not been notified, When the control unit determines whether or not a software update is required, if the determination unit determines that the vehicle that sent the information has an electronic control unit that has not been notified of the current version of the software, the center causes the communication unit to send a notification to the vehicle to put the electronic control unit into a state where a software update is possible.
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Vehicle information communication system, vehicle information communication method, vehicle information communication program, and center device
JP2020027670A