Software update control device, vehicle, program, and software update control method

The software update control device optimizes vehicle notification systems by recognizing occupants and adjusting display times and modes based on past notification receipt, gaze, and screen operation, improving efficiency and reducing power consumption.

JP7754755B2Active Publication Date: 2025-10-15HONDA MOTOR CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022040833
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-15
Publication Date
2025-10-15
Estimated Expiration
2042-03-15

AI Technical Summary

Technical Problem

Existing vehicle software update systems fail to account for varying occupants, leading to inefficient and potentially annoying notifications, which can disrupt the driving experience and increase power consumption.

Method used

A software update control device that recognizes vehicle occupants through imaging, adjusts notification modes based on past notification receipt, gaze direction, and operation of display screens, optimizing the display time and mode of update information.

Benefits of technology

Enhances the efficiency of software update notifications by reducing annoyance for informed occupants and minimizing power consumption by adjusting display times and modes accordingly.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007754755000001
    Figure 0007754755000001
  • Figure 0007754755000002
    Figure 0007754755000002
  • Figure 0007754755000003
    Figure 0007754755000003
Patent Text Reader

Abstract

To provide a software update control device, a vehicle, a program and a software update control method capable of appropriately notifying an occupant in a vehicle of update of software according to the occupant.SOLUTION: A software update control device 200 is mounted on a vehicle and controls software update of on-vehicle equipment through a communication section 209. An ECU 202 has: an acquisition section 210 which acquires information representing a recognition result of an occupant in a vehicle recognized through imaging the same in the vehicle; and a notification control section 220 which controls notification of update information related to software update. The notification control section 220 determines whether or not the occupant in the vehicle has received the update information on the basis of the information representing the recognition result of the occupant in the vehicle and changes a form of notification of the update information according to a determination result of whether or not the occupant in the vehicle has received the update information in the past.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a software update control device, a vehicle, a program, and a software update control method. [Background technology]

[0002] In recent years, efforts to provide access to sustainable transportation systems that take into consideration vulnerable traffic participants have been gaining momentum. To achieve this, we are focusing on research and development into preventive safety technologies to further improve traffic safety and convenience. Patent Document 1 describes setting up a method to guide users about ECU reprogramming. [Prior art document] [Patent Documents] [Patent Document 1] JP 2012-13443 A Summary of the Invention [Problem to be solved by the invention]

[0003] However, in preventive safety technology, since the occupants of a vehicle may not be limited to a specific user, there are problems with performing processing assuming a specific user. To solve the above problem, the present application aims to appropriately notify the occupants of a vehicle about software updates. This will ultimately contribute to the development of sustainable transportation systems. [Means for solving the problem]

[0004] In a first aspect of the present invention, there is provided a software update control device. The software update control device is mounted on a vehicle and controls software updates of on-board devices via a communication unit. The software update control device includes an acquisition unit that acquires information indicating a recognition result of an occupant in the vehicle, the recognition result being obtained by capturing an image of the occupant in the vehicle. The software update control device includes a notification control unit that controls notification of update information related to the software update. The notification control unit determines, based on the information indicating the recognition result of the occupant in the vehicle, whether or not the occupant in the vehicle has previously received a notification of the update information, and changes the mode of notification of the update information depending on the determination result of whether or not the occupant in the vehicle has previously received a notification of the update information.

[0005] When the power of the vehicle is turned off, the notification control unit may determine whether the occupants in the vehicle have previously received notification of the update information based on information indicating the recognition result of the occupants in the vehicle recognized at the latest timing before the power of the vehicle was turned off.

[0006] When the notification control unit determines that a passenger in the vehicle has received a notification of the update information in the past, it may shorten the time for displaying the notification of the update information compared to when it determines that the passenger in the vehicle has not received a notification of the update information in the past.

[0007] The acquisition unit may further acquire line-of-sight information indicating a line-of-sight direction of the passenger in the vehicle identified by capturing an image of the passenger in the vehicle. The notification control unit may determine, based on the line-of-sight information, whether the passenger in the vehicle is looking at a display screen on which the notification of the update information is displayed, and may extend a time period for displaying the notification of the update information when it determines that the passenger in the vehicle is looking at the display screen on which the notification of the update information is displayed.

[0008] The acquisition unit may further acquire operation information indicating whether a display screen on which the notification of the update information is displayed has been operated. The notification control unit may determine whether the display screen has been operated based on the operation information, and if it determines that the display screen has been operated, may extend a time period for displaying the notification of the update information.

[0009] The update information may be information that is notified when a predetermined condition for starting the software update is not satisfied when a power source of the vehicle is turned off. The notification control unit may determine whether the predetermined condition is satisfied when the power source of the vehicle is turned off, and when the predetermined condition is not satisfied, determine whether a notification of the update information has been received in the past, and change a mode of notifying the update information depending on a result of determining whether a passenger in the vehicle has received a notification of the update information in the past.

[0010] The notification control unit may determine whether the software update will be performed while the vehicle is traveling. When it is determined that the software update will be performed, the acquisition unit may start acquiring information indicating a recognition result of an occupant in the vehicle.

[0011] The information indicating the recognition result of the vehicle occupant may further include information indicating whether the vehicle occupant is a driver. The notification control unit may determine whether the driver of the vehicle has previously received a notification of the update information based on the information indicating the recognition result of the vehicle occupant, and may change a mode of notification of the update information depending on a determination result of whether the driver of the vehicle has previously received a notification of the update information.

[0012] In a second aspect of the present invention, there is provided a vehicle, the vehicle including the software update control device described above.

[0013] In a third aspect of the present invention, there is provided a program that causes a computer to function as the software update control device described above.

[0014] In a fourth aspect of the present invention, there is provided a software update control method. The software update control method controls a software update of an in-vehicle device via a communication unit. The software update control method includes a step of acquiring information indicating a recognition result of an occupant in the vehicle, the occupant being recognized by capturing an image of the occupant in the vehicle. The software update control method includes a step of controlling notification of update information related to the software update. The step of controlling notification of update information related to the software update includes a step of determining, based on the information indicating the recognition result of the occupant in the vehicle, whether or not the occupant in the vehicle has received notification of the update information in the past, and a step of changing a mode of notification of the update information depending on a result of determining whether or not the occupant in the vehicle has received notification of the update information in the past.

[0015] The above summary of the invention does not list all of the features of the present invention, and subcombinations of these features may also be inventions. [Brief explanation of the drawings]

[0016] [Figure 1] 1 illustrates a schematic diagram of an update system 10 according to an embodiment. [Figure 2] 2 shows a schematic diagram of a system configuration of a control system 200. [Figure 3] 10 is a diagram illustrating an example of a time chart relating to a software update process. [Figure 4] An example of update information 300 displayed on the IVI 299 is shown. [Figure 5] An example of update information 400 displayed on the IVI 299 is shown. [Figure 6] An example of update information 500 displayed on the IVI 299 is shown. [Figure 7] 10 shows in table form the data structure of history information used by notification control unit 220 to change the display time of update information. [Figure 8]10 is a flowchart showing a processing procedure for updating identification information of current passengers in the vehicle 20. [Figure 9] 10 is a flowchart showing a processing procedure relating to notification control of update information. [Figure 10] 2 illustrates an example computer 2000 in which multiple embodiments of the present invention may be implemented in whole or in part. DETAILED DESCRIPTION OF THE INVENTION

[0017] The present invention will be described below through embodiments of the invention, but the following embodiments do not limit the scope of the invention according to the claims. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.

[0018] 1 schematically shows an update system 10 according to one embodiment. The update system 10 includes a vehicle 20 and a server 70. The vehicle 20 includes a control system 200. The control system 200 is responsible for controlling the vehicle 20 and communicating with the server 70 via a communication network 90. ​​The communication network 90 includes an IP network such as the Internet, a P2P network, a dedicated line including a VPN, a virtual network, a mobile communication network, and the like.

[0019] In the vehicle 20, a control system 200 includes a plurality of ECUs (Electronic Control Units) that control the vehicle 20. A server 70 controls reprogramming of the ECUs included in the control system 200. For example, the server 70 transmits update software to the control system 200 via a communication network 90, and the control system 200 receives the update software transmitted via the communication network 90 by wireless communication. The control system 200 reprograms the ECUs by rewriting software that controls the ECUs included in the control system 200 with the update software. Reprogramming is performed for the purpose of upgrading the functions of the ECUs included in the control system 200, etc. In this way, the control system 200 reprograms the ECUs by updating the ECU software via OTA (Over The Air). In this embodiment, rewriting the software of a device such as an ECU with update software is referred to as a "software update."

[0020] The control system 200 notifies the occupants of the vehicle 20 of the update information by displaying the update information related to the software update to the occupants of the vehicle 20. The control system 200 recognizes the current occupants in the vehicle 20 by recognizing an image captured inside the vehicle 20. The control system 200 also stores history information indicating the number of times update information has been notified to each occupant in the past.

[0021] When displaying new update information, the control system 200 determines, based on history information, whether or not the occupant of the current vehicle 20 has previously viewed the update information. If the control system 200 determines that the occupant of the vehicle 20 has previously viewed the update information, the control system 200 shortens the display time of the update information compared to when the control system 200 determines that the occupant of the vehicle 20 has not previously viewed the update information. A occupant who has previously viewed the update information can easily understand what the update information is by simply displaying the update information for a short time. The control system 200 can display the update information for only a short time for a occupant who has previously viewed the update information. Therefore, the notification of the update information can be optimized according to the occupant's experience with software updates.

[0022] 2 is a schematic diagram illustrating a system configuration of the control system 200. The control system 200 includes a communication unit 209 including a TCU 201 and an antenna 211, an ECU 202, an ECU 204, an ECU 205, an MID 298, an IVI 299, and an imaging device 297. The ECU 202, the ECU 204, and the ECU 205 may include a computer including a processor and memories such as a volatile memory and a non-volatile memory. In FIG. 2, the FI 291 and the battery 292 are devices included in the vehicle 20. The FI 291 and the battery 292 are examples of controlled devices of the vehicle 20.

[0023] The ECU 202 is connected to the TCU 201, the ECU 204, the ECU 205, the MID 298, the IVI 299, and the imaging device 297 via an in-vehicle communication network 280. The ECU 202 communicates with the TCU 201, the ECU 204, the ECU 205, the MID 298, the IVI 299, and the imaging device 297 via the in-vehicle communication network 280. The ECU 202 comprehensively controls the TCU 201, the ECU 204, the ECU 205, the MID 298, the IVI 299, and the imaging device 297. The in-vehicle communication network 280 may be configured to include, for example, a communication line conforming to a CAN (Controller Area Network) and a communication line conforming to Ethernet (registered trademark).

[0024] The TCU 201 is a telematics control unit. The TCU 201 is mainly responsible for mobile communication. The TCU 201 transmits and receives data to and from the server 70 under the control of the ECU 202. The TCU 201 receives update software transmitted from the server 70 via mobile communication under the control of the ECU 202.

[0025] The MID 298 is a multi-information display. The IVI 299 is, for example, an in-vehicle infotainment device (IVI). The MID 298 and the IVI 299 have a function to display update information.

[0026] The ECU 204 and the ECU 205 are ECUs serving as in-vehicle devices that control the vehicle 20. The ECU 204 and the ECU 205 control various devices provided in the vehicle 20. For example, the ECU 204 controls the FI 291, which is a fuel injection device. The ECU 205 controls the battery 292, which is a high-voltage battery.

[0027] In this embodiment, a system configuration in which the control system 200 includes the TCU 201, the ECU 202, the ECU 204, the ECU 205, the MID 298, and the IVI 299 is exemplified, but the system configuration of the control system 200 is not limited to the example of this embodiment. Also, in this embodiment, the ECU 202 is an ECU that controls software updates. That is, the ECU 202 functions as a software update control device that controls software updates. Note that the targets of the software updates may be the ECU 202 and the ECU 205. However, the TCU 201, the ECU 202, the MID 298, and the IVI 299 may also be targets of the software updates.

[0028] The following describes a functional configuration related to software updates of the ECU 202. The ECU 202 controls software updates of in-vehicle devices via the communication unit 209. The ECU 202 includes an acquisition unit 210, a notification control unit 220, and an update control unit 240.

[0029] The acquisition unit 210 acquires information indicating the recognition result of the occupants in the vehicle 20, which is recognized by capturing an image of the occupants in the vehicle 20. The imaging device 297 recognizes the image obtained by capturing an image of the inside of the vehicle 20, and transmits information indicating the recognition result of the occupants in the vehicle 20 to the ECU 202. The imaging device 297 may include, for example, a driver's monitor camera (DMC).

[0030] The notification control unit 220 controls notification of update information related to software updates. For example, the notification control unit 220 controls display of the update information on the IVI 299. The notification control unit 220 may also control display of the update information on the MID 298. The update information may be notified via an in-vehicle device other than the IVI 299 and the MID 298.

[0031] The notification control unit 220 determines whether or not the passenger in the vehicle 20 has received a notification of update information based on the information indicating the recognition result of the passenger in the vehicle 20, and changes the mode of notification of the update information depending on the determination result of whether or not the passenger in the vehicle 20 has received a notification of update information in the past. For example, when the notification control unit 220 determines that the passenger in the vehicle 20 has received a notification of update information in the past, the notification control unit 220 shortens the time for displaying the notification of the update information compared to when it is determined that the passenger in the vehicle 20 has not received a notification of update information in the past. This makes it possible to optimize the mode of notification of the update information depending on whether or not the passenger in the actual vehicle 20 has received a notification of update information in the past.

[0032] The acquisition unit 210 may further acquire gaze information indicating the gaze direction of a passenger in the vehicle 20, which is identified by capturing an image of the passenger in the vehicle 20. The notification control unit 220 may determine, based on the gaze information, whether or not the passenger in the vehicle 20 is looking at a display screen on which a notification of update information is displayed, and may extend the time for displaying the notification of update information when it is determined that the passenger in the vehicle 20 is looking at the display screen on which the notification of update information is displayed. The acquisition unit 210 may acquire the gaze information from the imaging device 297. The imaging device 297 identifies the facial orientation and eye position of the passenger in the vehicle 20 by analyzing an image obtained by capturing an image of the inside of the vehicle 20, identifies the gaze direction of the passenger based on the identified facial orientation and eye position of the passenger, and transmits gaze information indicating the identified gaze direction to the ECU 202.

[0033] The acquisition unit 210 may further acquire operation information indicating whether or not the display screen on which the update information notification is displayed has been operated. The notification control unit 220 may determine whether or not the display screen has been operated based on the operation information, and may extend the time for which the update information notification is displayed if it determines that the display screen has been operated.

[0034] When the power of the vehicle 20 is turned off, the notification control unit 220 may determine whether the passengers in the vehicle 20 have previously received notification of update information based on information indicating the recognition results of the passengers in the vehicle 20 recognized at the latest timing before the power of the vehicle 20 was turned off.

[0035] The notification control unit 220 may determine whether or not a software update will be performed while the vehicle 20 is traveling. When it is determined that a software update will be performed, the acquisition unit 210 may start acquiring information indicating the recognition result of the occupants in the vehicle 20.

[0036] The update information is information that is notified when a predetermined condition for starting a software update is not met when the power of the vehicle 20 is turned off. The power source of the vehicle 20 may be an ignition (IG) power source of the vehicle 20. When the power of the vehicle 20 is turned off, the notification control unit 220 determines whether the predetermined condition is met, and if the predetermined condition is not met, determines whether a notification of the update information has been received in the past, and changes the mode of notification of the update information depending on the result of the determination of whether the passengers in the vehicle 20 have received a notification of the update information in the past.

[0037] The information indicating the recognition result of the occupant in the vehicle 20 acquired by the acquisition unit 210 may include information indicating whether or not the occupant in the vehicle 20 is the driver of the vehicle 20. For example, if the imaging device 297 includes a driver's monitor camera, the information transmitted by the driver's monitor camera to the ECU 202 may include information indicating that the recognized occupant is the driver of the vehicle 20. The notification control unit 220 determines whether or not the driver in the vehicle 20 has previously received a notification of update information based on the information indicating the recognition result of the occupant in the vehicle 20, and changes the mode of notification of the update information depending on the determination result as to whether or not the driver in the vehicle 20 has previously received a notification of update information. This makes it possible to optimize the mode of notification of the update information depending on whether or not the actual driver of the vehicle 20 has previously received a notification of update information.

[0038] The update control unit 240 is responsible for controlling software updates. For example, the update control unit 240 controls a process of downloading update software from the server 70, a process of writing the downloaded update software to an ECU to be updated, and a process of activating an ECU to be updated.

[0039] Here, software update is described. Here, software update processing is described for a case where the internal memory for storing firmware of the update target ECU, which is the subject of the software update, is a single-bank memory (so-called single-sided ROM). In this case, since the update target ECU has a single program storage area for storing firmware, update software cannot be written to the program storage area while the update target ECU is operating according to a program stored in the program storage area. Therefore, when the program storage area of ​​the update target ECU is a single-bank memory, software update is performed when the power system of the vehicle 20 is turned off. When performing a software update of the update target ECU, the ECU 202 transfers update software to the update target ECU, writes the transferred update software to the program storage area of ​​the update target ECU, and activates the update software. Activating the update software includes, for example, setting ECU startup parameters so that the update software is loaded at ECU startup and control based on the update software is initiated.

[0040] Next, we will explain the software update process when the internal memory of the update target ECU is a double-bank memory (so-called dual-sided ROM). In this case, since the update target ECU has two program storage areas for storing firmware, update software can be written to the second program storage area while the update target ECU is operating according to the program stored in the first program storage area. For example, update software can be written to the second program storage area of ​​the update target ECU even while the vehicle 20 is running. Therefore, the ECU 202 transfers the update software to the update target ECU and instructs the update target ECU to write the update software to the second program storage area. After writing the update software to the second program storage area of ​​the update target ECU is complete, the ECU 202 instructs the update target ECU to activate the update software written to the second program storage area. Activating the update software includes, for example, setting startup parameters for the update target ECU so that the update software stored in the second program storage area is loaded and control based on the update software is initiated when the update target ECU is started. For example, activating the update software includes enabling the second program storage area as a program read area and disabling the first program storage area as a program read area. In this way, "ECU software update" is a concept that includes writing the update software to the program storage area of ​​the ECU. Also, "ECU software update" is a concept that includes activating the update software written to the program storage area.

[0041] Figure 3 shows an example of a time chart related to the software update process. Figure 3 shows the operation state of the IG power supply, the execution state of the update-related process, the power supply state, and the running state of the vehicle 20. The device to be updated for the software is assumed to be the ECU 205. The ECU 205 is also assumed to have an internal memory that is a double-bank memory.

[0042] Assume that vehicle 20 is traveling at the start of the time chart in Fig. 3. At time t1, ECU 202 is notified by server 70 that an update program for ECU 205 is available, and starts downloading the update software while vehicle 20 is traveling. When the download is complete at time t2, update control unit 240 starts writing the update program to ECU 205, which is the target of the software update. When writing of the update software to ECU 205 is completed at time t3, notification control unit 220 causes IVI 299 to display a notification indicating that writing of the update software has been completed by time t4. An example of this notification is shown in Fig. 4.

[0043] Thereafter, at time t5, when an occupant of vehicle 20 performs an operation to turn off the IG power supply, the power state of the IG power supply becomes a state in which specific in-vehicle devices are activated when the IG is off. At this time, notification control unit 220 determines whether vehicle 20 is in a state in which a software update of ECU 205 can be performed, and causes IVI 299 to display update information according to the determination result. If predetermined conditions for performing a software update of ECU 205 are satisfied, notification control unit 220 determines that vehicle 20 is in a state in which a software update of ECU 205 can be performed. If the predetermined conditions are not satisfied, notification control unit 220 determines that vehicle 20 is not in a state in which a software update of ECU 205 can be performed. The predetermined conditions may include a condition that vehicle 20 is stopped. The predetermined conditions may include a condition that the state of charge of a battery provided in vehicle 20 is higher than a predetermined value required to perform a software update of ECU 205. The state of charge of the battery may include either the state of charge of a low-voltage battery provided in the vehicle 20 or the state of charge of a high-voltage battery that supplies power for running.

[0044] In the example of FIG. 3, it is assumed that the vehicle 20 is not in a state where a software update of the ECU 205 can be performed. In this case, the notification control unit 220 causes the IVI 299 to display a notification indicating that a software update will not be performed from time t5 to time t6. An example of this notification is shown in FIG. 5. At time t6, the IG power supply state becomes a completely stopped state. In other words, the power supply is completely shut down.

[0045] Here, the notification control unit 220 determines whether or not the occupant of the vehicle 20 has previously seen a notification indicating that a software update will not be performed. If the occupant of the vehicle 20 has previously seen a notification indicating that a software update will not be performed, the notification control unit 220 shortens the time for which the IVI 299 displays the notification indicating that a software update will not be performed, compared to when the occupant of the vehicle 20 has not previously seen a notification indicating that a software update will not be performed. In other words, if the occupant of the vehicle 20 has previously seen a notification indicating that a software update will not be performed, the notification control unit 220 shortens the period from time t5 to time t6.

[0046] 4 shows an example of update information 300 displayed on IVI 299. Update information 300 is information notified when writing of update software is completed. Update information 300 is update information related to "writing of update software completed." Notification control unit 220 causes IVI 299 to display update information 300 when update software downloaded from server 70 is written to ECU 205. Update information 300 includes information 301 indicating that preparation for software update is completed and information 302 indicating that software update will start when IG power is turned off.

[0047] It should be noted that the notification control unit 220 does not perform control to change the display time of the update information 300 depending on whether or not the passengers in the vehicle 20 have previously viewed the update information.

[0048] FIG. 5 shows an example of update information 400 displayed on IVI 299. Update information 400 is information notified when it is determined that a software update will not be performed when the IG power supply is turned off. When a passenger performs an operation to turn off the IG power supply and it is determined that vehicle 20 is not in a state in which a software update of ECU 205 can be performed, notification control unit 220 causes IVI 299 to display update information 400. Update information 400 includes information 401 indicating that the system of vehicle 20 will be shut down without performing a software update, and information 402 indicating that a system update will be attempted the next time the IG power supply is turned off. When displaying update information 400, notification control unit 220 controls to change the display time depending on whether a passenger in vehicle 20 has previously viewed the update information.

[0049] 6 shows an example of update information 500 displayed on IVI 299. Update information 500 is information that is notified when it is determined that update software should be activated when the IG power supply is turned off. Update information 500 is update information related to "activation execution." When the occupant turns off the IG power supply and it is determined that vehicle 20 is in a state where update software for ECU 205 can be activated, notification control unit 220 causes IVI 299 to display update information 500.

[0050] The update information 500 includes wait time information 510, which is the time until the update of ECU 204 begins, message information 520 for the passenger, a UI button 530 for obtaining an update execution instruction from the passenger to execute the update, and a UI button 540 for obtaining an update postponement instruction from the passenger not to execute the update.

[0051] The wait time information 510 includes information indicating the time remaining until the update control unit 240 automatically starts updating the ECU 204. The notification control unit 220 counts down the remaining time in the wait time information 510 as time passes. The message information 520 is information for notifying the user that a system update will start and that the user should stop the vehicle 20 in a safe place.

[0052] The update control unit 240 acquires the operation of the position of the UI button 530 as an instruction to perform an update from the passenger. When the update control unit 240 acquires the instruction to perform an update, the update control unit 240 starts activating the ECU 205. When the update control unit 240 acquires the operation of the display position of the UI button 540 as an instruction to postpone an update from the passenger. When the update control unit 240 acquires the instruction to postpone an update, the update control unit 240 puts the IG power supply into a terminated state without activating the ECU 205.

[0053] It should be noted that the notification control unit 220 does not perform control to change the display time of the update information 500 depending on whether or not the passengers in the vehicle 20 have previously viewed the update information.

[0054] 7 shows in table format the data structure of history information used by the notification control unit 220 to change the display time of update information. The history information is information that manages the number of times update information has been notified to passengers of the vehicle 20 in the past. The history information associates a person ID, a notification type ID, and the number of notifications.

[0055] The person ID in the history information is information for identifying a person. The person ID may be information that is assigned by the imaging device 297 to each person recognized by the imaging device 297, for example.

[0056] The notification type ID of the history information is information for identifying the type of update information. The notification type ID is information for identifying update information for which the display time is to be adjusted by the notification control unit 220. For example, the notification type ID includes information for identifying update information 400 shown in FIG. 4.

[0057] The number of notifications of history information indicates the number of times that the notification control unit 220 has notified the person identified by the person ID of the update information identified by the notification type ID.

[0058] 8 is a flowchart showing a processing procedure for updating the identification information of the current occupant in the vehicle 20. The processing in FIG. 8 is periodically executed by the ECU 202. The processing in FIG. 8 can also be executed while the vehicle 20 is traveling.

[0059] In S600, the notification control unit 220 determines whether update software for the ECU 205 is present. For example, the notification control unit 220 determines that update software for the ECU 205 is present when the update software for the ECU 205 downloaded from the server 70 is transferred to the ECU 205. For example, the notification control unit 220 may determine that update software for the ECU 205 is present at time t3 in FIG. 3 . Note that the notification control unit 220 may determine that update software for the ECU 205 is present when the update software for the ECU 205 is downloaded from the server 70. For example, the notification control unit 220 may determine that update software for the ECU 205 is present at time t2 in FIG. 3 . The notification control unit 220 may determine that update software for the ECU 205 is present when a notification indicating that update software for the ECU 205 is present is received from the server 70 before the update software for the ECU 205 is downloaded from the server 70.

[0060] In S602, the acquisition unit 210 acquires the recognition result of the occupant recognized by the imaging device 297 from the image of the inside of the vehicle 20 captured by the imaging device 297 by requesting the recognition result of the occupant from the imaging device 297. For example, when the imaging device 297 is able to recognize the occupant from the image of the inside of the vehicle 20, the imaging device 297 transmits the recognition result including the person ID of the recognized occupant to the ECU 202. When the imaging device 297 is unable to recognize the occupant from the image of the inside of the vehicle 20, the imaging device 297 transmits to the ECU 202 a recognition result indicating that the occupant could not be recognized. The acquisition unit 210 acquires the recognition result transmitted from the imaging device 297 to the ECU 202 as the recognition result of the current occupant.

[0061] In S604, the notification control unit 220 determines whether or not the occupant of the vehicle 20 has been recognized. For example, the notification control unit 220 determines that the occupant of the vehicle 20 has been recognized if a person ID is included in the recognition result acquired by the acquisition unit 210. If it is determined that the occupant of the vehicle 20 has been recognized, in S606 the notification control unit 220 stores the person ID included in the recognition result acquired in S602 as identification information of the current occupant in the vehicle 20, and ends the processing. If it is determined that the occupant of the vehicle 20 has not been recognized, in S608 the notification control unit 220 deletes the stored identification information of the occupant, and ends the processing.

[0062] 9 is a flowchart showing a processing procedure relating to notification control of update information. The processing in FIG. 9 is started when an operation to turn off the IG power supply is detected.

[0063] In S700, the notification control unit 220 determines whether or not preparations for activation of the ECU 205 are complete. For example, the notification control unit 220 determines that preparations for activation of the ECU 205 are complete when writing of the update software to the ECU 205 is complete. If preparations for activation are not complete, the process ends.

[0064] If the preparation for activation is complete, the notification control unit 220 determines whether or not a predetermined condition for executing activation is satisfied in S702. For example, the notification control unit 220 determines that the predetermined condition for executing activation is satisfied when the vehicle 20 is stopped and the state of charge of the battery included in the vehicle 20 is higher than a predetermined value required for performing a software update of the ECU 205.

[0065] If the predetermined condition for executing activation is not satisfied, the notification control unit 220 determines whether or not the passenger has been recognized in S704. For example, the notification control unit 220 determines that the passenger has been recognized if the identification information of the current passenger is stored.

[0066] If the occupant is recognized, in S706, the notification control unit 220 determines whether the current occupant in the vehicle 20 has previously viewed the update information 400. For example, the notification control unit 220 refers to the history information to determine whether the current occupant in the vehicle 20 has previously viewed the update information 400. Specifically, the notification control unit 220 acquires, from the history information, the identification information of the current occupant and the number of notifications associated with the notification type of the update information 400, and if the acquired number of notifications is greater than a predetermined number, determines that the current occupant in the vehicle 20 has previously viewed the update information 400. The predetermined number may be a value of 0 or greater. The predetermined number may be a value of 1 or greater.

[0067] If the current occupants of the vehicle 20 have previously viewed the update information, the notification control unit 220 notifies the update information 400 in the first mode in S708. The notification control unit 220 causes the update information 400 to be displayed on the IVI 299. The first mode is a display mode in which the update information is displayed for a first display time. After the notification of the update information in S708 is completed, the notification control unit 220 updates the notification count in the history information in S712 and ends the process.

[0068] While the update information 400 is being displayed in S708, the acquisition unit 210 may acquire line-of-sight information indicating the line-of-sight direction of the passengers in the vehicle 20 from the imaging device 297, and the notification control unit 220 may determine whether the passengers in the vehicle 20 are looking at the display screen of the IVI 299 based on the line-of-sight information acquired from the imaging device 297. When the notification control unit 220 determines that the passengers in the vehicle 20 are looking at the display screen on which the notification of the update information is displayed, the notification control unit 220 may extend the time for which the notification of the update information 400 is displayed.

[0069] Furthermore, while the update information 400 is being displayed in S708, the acquisition unit 210 acquires operation information indicating whether or not the display screen displaying the notification of the update information has been operated from the IVI 299. The notification control unit 220 determines whether or not the display screen of the IVI 299 has been operated based on the operation information, and may extend the time for which the notification of the update information 400 is displayed if it determines that the display screen of the IVI 299 has been operated.

[0070] If it is determined in S706 that the current occupant in the vehicle 20 has not previously viewed the update information, then in S710 the notification control unit 220 notifies the update information 400 in the second mode. The second mode is a display mode in which the update information is displayed for a second display time. The second display time is shorter than the first display time. Once the notification of the update information in S710 is complete, in S712 the notification control unit 220 updates the number of notifications in the history information. Specifically, the notification control unit 220 updates the identification information of the current occupant and the number of notifications associated with the notification type of the update information 400. Once the processing of S712 is complete, the processing ends.

[0071] If it is determined in S704 that the passenger could not be recognized, in S714 the notification control unit 220 notifies the update information 400 in the second mode, and ends the process.

[0072] If it is determined in S702 that the predetermined conditions for executing activation are not satisfied, in S720 the notification control unit 220 notifies the passenger of the update information 500 and ends the processing. The notification control unit 220 notifies the passenger of the update information 500 in a specific notification mode regardless of whether the passenger has seen the update information 500 before. In other words, the notification control unit 220 does not perform control to change the notification mode of the update information 500 depending on whether the passenger has seen the update information 500 before.

[0073] 8 and 9, when an operation to turn off the IG power supply is detected, the notification control unit 220 determines whether to perform control to change the notification mode of the update information 400, based on the identification information of the occupant of the vehicle 20 recognized latest before the operation to turn off the IG power supply is detected. Alternatively, a form may be adopted in which, when an operation to turn off the IG power supply is detected, the processing of S602 in Fig. 8 is performed between S702 and S704 in Fig. 9.

[0074] As described above, the control system 200 according to this embodiment recognizes passengers in the vehicle 20 through image recognition, and shortens the time for displaying the update information when it is determined that the recognized passenger has previously viewed the update information. This makes it possible to optimize the display of the update information depending on whether or not the passenger in the vehicle 20 has received a notification of the update information. This makes it possible to ensure that passengers who have not previously viewed the update information can fully understand the notification content. On the other hand, it is possible to ensure that passengers who have previously viewed the update information do not find the notification annoying. Furthermore, shortening the display time of the update information shortens the time until the power supply system of the vehicle 20 is shut down. This reduces the power consumption of the vehicle 20.

[0075] As another method for changing the manner in which update information is notified, a method for changing the color in which the update information is displayed can be employed. As another method for changing the manner in which update information is notified, a method for changing the brightness in which the update information is displayed can be employed. As a method for notifying update information, in addition to displaying the update information, a method for notifying the update information by sound can be employed. In this case, as a method for changing the manner in which update information is notified, a method for changing the time for which sound related to the update information is played and / or a method for changing the volume of the sound related to the update information can be employed. In addition to changing the time for which the update information is displayed, the notification control unit 220 may apply any combination of changing the color in which the update information is displayed, changing the brightness in which the update information is displayed, changing the time for which sound related to the update information is played, and changing the volume of the sound related to the update information.

[0076] Vehicle 20 is an example of a vehicle that is a transportation device. The vehicle may be a car equipped with an internal combustion engine, an electric car, a fuel cell vehicle (FCV), or the like. The vehicle includes a bus, a truck, a two-wheeled vehicle, or the like. The vehicle may be a saddle-ride vehicle or the like, or may be a motorcycle. In addition to vehicles, transportation devices include aircraft, including unmanned aerial vehicles, ships, and other equipment. The transportation device may be any equipment that transports people or goods. The transportation device is an example of a mobile object. The mobile object is not limited to a transportation device, and may be any mobile equipment.

[0077] 10 shows an example of a computer 2000 in which multiple embodiments of the present invention may be embodied in whole or in part. A program installed on the computer 2000 may cause the computer 2000 to function as a system or each part of a system, such as a control system according to an embodiment, or an apparatus or each part of an apparatus, such as an ECU 202, to perform operations associated with the system or each part of the system or the apparatus or each part of the apparatus, and / or to perform a process or steps of the process according to an embodiment. Such a program may be executed by the CPU 2012 to cause the computer 2000 to perform specific operations associated with some or all of the processing procedures and blocks of the block diagrams described herein.

[0078] The computer 2000 according to this embodiment includes a CPU 2012 and a RAM 2014, which are interconnected by a host controller 2010. The computer 2000 also includes a ROM 2026, a flash memory 2024, a communication interface 2022, and an input / output chip 2040. The ROM 2026, the flash memory 2024, the communication interface 2022, and the input / output chip 2040 are connected to the host controller 2010 via the input / output controller 2020.

[0079] The CPU 2012 operates according to programs stored in the ROM 2026 and RAM 2014, thereby controlling each unit.

[0080] The communication interface 2022 communicates with other electronic devices via a network. The flash memory 2024 stores programs and data used by the CPU 2012 in the computer 2000. The ROM 2026 stores a boot program and the like executed by the computer 2000 upon activation, and / or programs dependent on the hardware of the computer 2000. The input / output chip 2040 may also connect various input / output units such as a keyboard, mouse, and monitor to the input / output controller 2020 via input / output ports such as a serial port, a parallel port, a keyboard port, a mouse port, a monitor port, a USB port, an HDMI (registered trademark) port, etc.

[0081] The programs are provided via a computer-readable storage medium such as a CD-ROM, a DVD-ROM, or a memory card, or via a network. The RAM 2014, the ROM 2026, or the flash memory 2024 are examples of computer-readable storage media. The programs are installed in the flash memory 2024, the RAM 2014, or the ROM 2026 and executed by the CPU 2012. Information processing described in these programs is read by the computer 2000, and causes cooperation between the programs and the various types of hardware resources described above. An apparatus or a method may be configured by implementing operations or processing of information in accordance with the use of the computer 2000.

[0082] For example, when communication is performed between the computer 2000 and an external device, the CPU 2012 may execute a communication program loaded into the RAM 2014 and instruct the communication interface 2022 to perform communication processing based on the processing described in the communication program. Under the control of the CPU 2012, the communication interface 2022 reads transmission data stored in a transmission buffer processing area provided in a recording medium such as the RAM 2014 or flash memory 2024, transmits the read transmission data to a network, and writes received data received from the network to a reception buffer processing area or the like provided on the recording medium.

[0083] The CPU 2012 may also cause all or a necessary portion of a file or database stored on a recording medium such as the flash memory 2024 to be read into the RAM 2014, and perform various types of processing on the data on the RAM 2014. The CPU 2012 then writes the processed data back to the recording medium.

[0084] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and subjected to information processing. The CPU 2012 may perform various types of processing on data read from the RAM 2014, including various types of operations, information processing, conditional judgment, conditional branching, unconditional branching, information search / replacement, etc., as described herein and specified by the instruction sequences of the programs, and write the results back to the RAM 2014. The CPU 2012 may also search for information in a file, database, etc. on the recording medium. For example, if multiple entries each having an attribute value of a first attribute associated with an attribute value of a second attribute are stored on the recording medium, the CPU 2012 may search for an entry that matches a condition specified by the attribute value of the first attribute from among the multiple entries, read the attribute value of the second attribute stored in the entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.

[0085] The above-described programs or software modules may be stored in a computer-readable storage medium on or near the computer 2000. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can be used as the computer-readable storage medium. The programs stored in the computer-readable storage medium may be provided to the computer 2000 via a network.

[0086] A program installed in computer 2000 and causing computer 2000 to function as ECU 202 may act on CPU 2012 or the like to cause computer 2000 to function as each unit of ECU 202. When the information processing described in these programs is read into computer 2000, it functions as each unit of ECU 202, which is a specific means formed by software and the various hardware resources described above working together. These specific means then perform calculations or processing of information according to the intended use of computer 2000 in this embodiment, thereby constructing a specific ECU 202 according to the intended use.

[0087] Various embodiments have been described with reference to block diagrams. In the block diagrams, each block may represent (1) a stage of a process where an operation is performed or (2) a portion of an apparatus responsible for performing the operation. Particular stages and portions may be implemented by dedicated circuitry, programmable circuitry provided with computer-readable instructions stored on a computer-readable storage medium, and / or a processor provided with computer-readable instructions stored on a computer-readable storage medium. Dedicated circuitry may include digital and / or analog hardware circuitry, and may include integrated circuits (ICs) and / or discrete circuits. Programmable circuitry may include reconfigurable hardware circuitry including logical AND, logical OR, logical XOR, logical NAND, logical NOR, and other logic operations, flip-flops, registers, memory elements such as field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), and the like.

[0088] A computer-readable storage medium may include any tangible device capable of storing instructions that are executed by an appropriate device, such that the computer-readable storage medium with instructions stored thereon constitutes at least a portion of an article of manufacture containing instructions that can be executed to provide means for performing the operations specified in a process or block diagram. Examples of computer-readable storage media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, etc. More specific examples of computer-readable storage media may include floppy disks, diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), Blu-ray disc, memory stick, integrated circuit card, etc.

[0089] The computer readable instructions may include either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk®, JAVA®, C++, etc., and conventional procedural programming languages ​​such as the “C” programming language or similar programming languages.

[0090] The computer-readable instructions may be provided to a processor or programmable circuitry of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, either locally or over a wide-area network (WAN) such as a local area network (LAN), the Internet, etc., and executed to provide means for performing the operations specified in the process steps or block diagrams described. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, etc.

[0091] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. It is clear from the claims that such modifications and improvements can also be included within the technical scope of the present invention.

[0092] It should be noted that the execution order of each process, such as operations, procedures, steps, and stages, in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not specifically stated as "before," "prior to," etc., and that the processes can be performed in any order unless the output of a previous process is used in a subsequent process. Even if the operational flow in the claims, specifications, and drawings is described using "first," "next," etc. for convenience, this does not mean that the processes must be performed in this order. [Explanation of symbols]

[0093] 10 Update System 20 vehicles 70 servers 90 Communication Network 200 Control System 201 TCU 202 ECU 204 ECU 205 ECU 209 Communications Department 210 Acquisition Department 211 Antenna 220 Notification control section 240 Update control section 280 In-Vehicle Communication Network 291 FI 292 Battery 297 Imaging Device 298 MID 299 IVI 300 Update information 301 Information 302 Information 400 Update information 401 Information 402 Information 500 Update information 510 Wait time information 520 Message Information 530 UI Buttons 540 UI buttons 2000 Computer 2010 Host Controller 2012 CPU 2014 RAM 2020 Input / Output Controller 2022 Communication Interface 2024 flash memory 2026 ROM 2040 Input / Output Chip

Claims

1. A software update control device that is mounted on a vehicle and controls software updates of on-board devices via a communication unit, an acquisition unit that acquires information indicating a recognition result of the occupant in the vehicle recognized by capturing an image of the occupant in the vehicle; a notification control unit that controls notification of update information regarding the software update; Equipped with The notification control unit determines whether or not the passenger in the vehicle has previously received the notification of the update information based on information indicating the recognition result of the passenger in the vehicle, and when it is determined that the passenger in the vehicle has previously received the notification of the update information, the notification control unit shortens the time for displaying the notification of the update information compared to when it is determined that the passenger in the vehicle has not previously received the notification of the update information. Software update control device.

2. When the power supply of the vehicle is turned off, the notification control unit determines whether the occupant in the vehicle has previously received a notification of the update information based on information indicating a recognition result of the occupant in the vehicle that was recognized latest before the power supply of the vehicle was turned off. The software update control device according to claim 1 .

3. The acquisition unit further acquires line-of-sight information indicating a line-of-sight direction of the occupant in the vehicle identified by capturing an image of the occupant in the vehicle, The notification control unit determines whether or not a passenger in the vehicle is looking at a display screen on which the notification of the update information is displayed, based on the line-of-sight information, and when determining that the passenger in the vehicle is looking at the display screen on which the notification of the update information is displayed, extends a time period for displaying the notification of the update information. The software update control device according to claim 1 or 2.

4. the acquiring unit further acquires operation information indicating whether or not a display screen on which the notification of the update information is displayed has been operated; The notification control unit determines whether the display screen has been operated based on the operation information, and when it determines that the display screen has been operated, extends a time period for displaying the notification of the update information. The software update control device according to claim 1 or 3.

5. the update information is information to be notified when a predetermined condition for starting the software update is not satisfied when the power source of the vehicle is turned off, The notification control unit determines whether the predetermined condition is satisfied when the power supply of the vehicle is turned off, and determines whether the notification of the update information has been received in the past when the predetermined condition is not satisfied. The software update control device according to any one of claims 1 to 4.

6. The notification control unit determines whether the software update is to be performed while the vehicle is running, The acquisition unit starts acquiring information indicating a recognition result of the occupant in the vehicle when it is determined that the software update is to be performed. The software update control device according to any one of claims 1 to 5.

7. The information indicating the recognition result of the occupant in the vehicle further includes information indicating whether the occupant in the vehicle is a driver, The notification control unit determines whether or not a driver in the vehicle has previously received a notification of the update information based on information indicating a recognition result of the occupant in the vehicle, and when it is determined that the driver in the vehicle has previously received a notification of the update information, shortens the time for displaying the notification of the update information compared to when it is determined that the driver in the vehicle has not previously received a notification of the update information. The software update control device according to any one of claims 1 to 6.

8. A vehicle comprising the software update control device according to any one of claims 1 to 7.

9. A program for causing a computer to function as the software update control device according to any one of claims 1 to 7.

10. A software update control method for controlling software update of an in-vehicle device via a communication unit, comprising: acquiring information indicating a recognition result of an occupant in a vehicle recognized by capturing an image of the occupant in the vehicle; controlling notification of update information regarding the software update; Equipped with The step of controlling notification of update information regarding the software update includes: determining whether the occupant in the vehicle has received notification of the update information in the past based on information indicating a recognition result of the occupant in the vehicle; a step of shortening a time for displaying the notification of the update information when it is determined that the passenger in the vehicle has received the notification of the update information in the past, compared to when it is determined that the passenger in the vehicle has not received the notification of the update information in the past; A software update control method comprising:

Citation Information

Patent Citations

  • Download method and download system

    JP2003271387A

  • Methods and devices for updating a client

    JP2016515745A

  • Electronic control device, method for controlling execution of rewriting, and program for controlling execution of rewriting

    JP2020027640A