Electronic control device, reproduction method and reproduction program
The electronic control device addresses the issue of system failure due to power outages during reprogramming by managing and updating startup mode and surface information, enabling normal restarts.
Patent Information
- Application Number
- JP2022106143
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-06-30
- Publication Date
- 2025-11-12
- Estimated Expiration
- 2042-06-30
AI Technical Summary
In ECUs with multiple software areas, a power outage during reprogramming can lead to a discrepancy in software versions, causing the system to fail to restart properly when power is restored.
An electronic control device with a startup mode information storage unit and a repro progress management unit that updates and manages startup mode and surface information to ensure normal system restart by referencing these information types after a power outage.
Ensures the system can be restarted normally even if a power outage occurs during reprogramming by using the stored information to guide the restart process.
Smart Images

Figure 0007768850000001 
Figure 0007768850000002 
Figure 0007768850000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an electronic control device, a reproducibility method, and a reproducibility program. [Background technology]
[0002] For example, an on-board electronic control unit (hereinafter referred to as an ECU (Electronic Control Unit)) is configured to be able to update its software (hereinafter sometimes referred to as "software") for purposes such as improving functionality and repairing defects. Software updates are also called reprogramming or reprocessing. When a master ECU that manages the reprocessing process instructs the reprocessing target ECU to write update data, it writes the update data into its software area and rewrites the software area. In this case, a reprocessing target ECU that has multiple software areas can rewrite the non-working areas while the vehicle is being controlled by the software in the working areas (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2020-27628 Summary of the Invention [Problem to be solved by the invention]
[0004] In a reprogramming target ECU that has multiple software areas, if a power outage occurs during reprogramming, a discrepancy in the software version may occur. If a discrepancy in the software version occurs, there is a risk that the system will not be able to restart properly when the power is restored.
[0005] The present invention has been made in consideration of the above-mentioned circumstances, and its purpose is to provide an electronic control device, a reprogramming method, and a reprogramming program that can restart the system normally when the power is restored, even if a power outage occurs during reprogramming in a configuration with multiple software areas. [Means for solving the problem]
[0006] According to the invention described in claim 1, the startup mode information storage unit (9) stores startup mode information indicating whether the system will start in normal mode or repro mode when started. The startup surface information storage unit (10) stores startup surface information indicating which of multiple surfaces will start when started in normal mode. The repro progress management unit (14) manages the progress of repro. The information update unit (15) updates at least one of the startup mode information and the startup surface information according to the progress of repro. The repro progress management unit starts the system based on the startup mode information and the startup surface information.
[0007] At least one of the startup mode information and the startup surface information is updated according to the progress of the reprogramming, and the system is started based on the startup mode information and the startup surface information. Even if a power outage occurs during the reprogramming, when the system is restarted after the power is restored, the system can be restarted normally by referencing the startup mode information and the startup surface information immediately before the power outage. This allows the system to be restarted normally when the power is restored, even if a power outage occurs during the reprogramming.
[0008] In addition to the inventions set forth in the claims, the present disclosure includes the following inventions. [1] An electronic control device (1, 21, 41) having a plurality of software areas capable of storing software, a startup mode information storage unit (9) for storing startup mode information indicating whether the system should be started in normal mode or repro mode when started; a startup screen information storage unit (10) for storing startup screen information indicating which of the multiple screens will be started when the device is started in the normal mode; A repro progress management unit (14) that manages the progress of repro; an information update unit (15) that updates at least one of the startup mode information and the startup screen information according to the progress of repro; The reproduction progress management unit is an electronic control device that starts up the system based on the start-up mode information and the start-up screen information.
[0009] [2] The repro progress management unit starts up in either the normal mode or the repro mode based on the startup mode information, and when started up in the normal mode, determines the startup surface based on the startup surface information [1] An electronic control device described in.
[0010] [3] When a reprocessing request in the normal mode occurs while the reprocessing progress management unit is running in the normal mode, the non-operating side is rewritten, The electronic control device according to [1] or [2], wherein the information update unit updates the startup surface information after completing the rewriting of the non-operational surface.
[0011] [4] When a request to transition to the reproductive mode occurs while the reproductive progress management unit is running in the normal mode, the information update unit updates the startup mode information after the transition to the reproductive mode is completed, The electronic control device according to any one of [1] to [3], wherein the reproduction progress management unit restarts the system after updating the startup mode information.
[0012] [5] The information update unit updates the startup surface information after the rewriting is completed when the repro progress management unit rewrites the non-operational surface while the repro mode is running. [1] An electronic control device described in any one of [3] to [4]. [Brief explanation of the drawings]
[0013] [Figure 1] Functional block diagram showing the first embodiment [Figure 2] Diagram explaining startup in normal mode [Figure 3] Diagram explaining boot flag updates [Figure 4] Diagram explaining startup in normal mode [Figure 5] Diagram explaining boot flag updates [Figure 6] A diagram explaining how to start up in repro mode [Figure 7] A diagram explaining how to update the repro software flag [Figure 8] Flowchart showing system startup processing [Figure 9] Flowchart showing system startup processing [Figure 10] Flowchart showing system startup processing [Figure 11] Flowchart showing system startup processing [Figure 12] Flowchart showing a repro mode transition request determination process [Figure 13] A functional block diagram showing a modification of the first embodiment. [Figure 14] FIG. 10 illustrates a second embodiment and explains startup in normal mode. [Figure 15] A diagram explaining how to start up in repro mode [Figure 16] FIG. 10 illustrates a third embodiment and explains startup in normal mode. [Figure 17] A diagram explaining how to start up in repro mode DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, several embodiments will be described with reference to the drawings. In the following embodiments, the same parts as those in the preceding embodiments will not be described. (First embodiment)
[0015] A first embodiment will be described with reference to FIGS. 1 to 13. As shown in FIG. 1, an ECU 1 mounted on a vehicle is connected to a master ECU 3 that manages the execution of reprogramming via a communication network, such as a CAN bus 2 (Controller Area Network) (registered trademark). The master ECU 3 performs integrated management of the ECUs 1 by issuing operation instructions to the ECUs 1 and acquiring operation states from the ECUs 1. Any number of ECUs 1 are connected to the master ECU 3 via the CAN bus 2, and the master ECU 3 performs integrated management of any number of ECUs 1. The ECUs 1 that are managed integratedly by the master ECU 3 include, for example, a powertrain ECU, a body ECU, a cockpit ECU, a chassis ECU, and a safety ECU.
[0016] The master ECU 3 is connected to a DCM (Data Communication Module) 4 that functions as a data communication device. The DCM 4 is wirelessly connected to an OTA center via a communication network, enabling it to receive distribution packages transmitted from the OTA center. When the DCM 4 receives a distribution package transmitted from the OTA center, it transfers the received distribution package to the master ECU 3. When the master ECU 3 transfers a distribution package from the DCM 4, it extracts update data from the transferred distribution package and instructs the ECU 1 to write the extracted update data. When the master ECU 3 instructs the ECU 1 to write the update data, the ECU 1 writes the update data to the software area and rewrites the software area.
[0017] The communication network may be a communication network based on a communication standard such as Ethernet (registered trademark) or FlexRay (registered trademark), or a communication network that is not based on a specific communication standard. The communication network connecting the DCM 4 and the master ECU 3 may be a different type of communication network from the communication network connecting the master ECU 3 and the ECUs 1. Furthermore, when multiple ECUs 1 are connected to the master ECU 3, the communication networks connecting the master ECU 3 and the multiple ECUs 1 may be different types of communication networks.
[0018] The ECU 1 includes a control unit 5 and a storage 6 as a storage medium. The control unit 5 is configured by a microcomputer having a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), and I / O (Input / Output). The control unit 5 executes a control program stored in a non-transitory physical storage medium to perform processing corresponding to the control program and control the overall operation of the ECU 1. The control program executed by the control unit 5 includes a reproduction execution program.
[0019] The storage 6 is a nonvolatile memory mainly made of, for example, a NOR flash memory or a NAND flash memory. The storage 6 includes a flag storage area 7 and a software storage area 8. The software storage area 8 has a two-sided configuration with two storage areas, side A and side B.
[0020] The flag storage area 7 comprises a repro software flag storage area 9 and a boot flag storage area 10. The repro software flag storage area 9 stores a repro software flag (corresponding to boot mode information) that indicates whether the system will start in normal mode or repro mode when started up. When the repro software flag is on, it indicates that the system will start up in repro mode when started up, and when the repro software flag is off, it indicates that the system will start up in normal mode when started up. The boot flag storage area 10 stores a boot flag (corresponding to boot side information) that indicates which side, A or B, the system will start up on when started up in normal mode. When the boot flag is on, it indicates that the system will start up on side A, and when the boot flag is off, it indicates that the system will start up on side B.
[0021] The software storage area 8 includes an A-side normal software storage area 11, a B-side normal software storage area 12, and a repro mode repro software storage area 13. The A-side normal software storage area 11 and the B-side normal software storage area 12 store A-side normal software and B-side normal software that are activated in normal mode, respectively. The A-side normal software and the B-side normal software include repro mode transition software and normal activation repro software, respectively. One of the A-side normal software storage area 11 and the B-side normal software storage area 12 can overwrite the other while the ECU 1 is operating normally. In other words, the A-side normal software can overwrite the B-side while the ECU 1 is operating normally, and the B-side normal software can overwrite the A-side while the ECU 1 is operating normally. The repro mode repro software storage area 13 stores repro mode repro software that is activated in repro mode.
[0022] The control unit 5 includes a reprocessing progress management unit 14 and a flag update unit 15 (corresponding to an information update unit). When the ECU 1 is started, the reprocessing progress management unit 14 reads the reprocessing software flag and boot flag from the storage 6 using an IPL (Initial Program Loader), notifies the software storage area 8 of a load request depending on the on / off status (e.g., data value) of the read flag, and loads the required software from the software storage area 8. The IPL is a program that is automatically loaded and executed when the system is started. The flag update unit 15 updates the reprocessing software flag and boot flag according to the progress of reprocessing. That is, the control unit 5 updates the reprocessing software flag and boot flag according to the progress of reprocessing through cooperation between the reprocessing progress management unit 14 and the flag update unit 15, and manages the progress of reprocessing. The following description will be given with reference to FIGS. 2 to 6.
[0023] If the repro software flag is off and the boot flag is on, the control unit 5 notifies storage 6 of a load request for the repro mode transition software and normal startup repro software contained in the normal software for side A, as shown in Figure 2, and loads the repro mode transition software and normal startup repro software contained in the normal software for side A from storage 6, expands them on RAM, and starts up with the normal software for side A. The control unit 5 executes the repro mode transition software expanded on RAM, making it possible to write the repro software flag, and executes the normal startup repro software expanded on RAM, making it possible to read and write the boot flag.
[0024] When the control unit 5 starts up with the normal software for side A, it updates the boot flag according to the progress of reprogramming using the normal startup reprogramming software, as shown in Figure 3. The control unit 5 keeps the reprogramming software flag off and the boot flag on until it has completed rewriting side B. When it has completed rewriting side B, the control unit 5 updates the boot flag from on to off, disabling the software for side A and enabling the software for side B. Once the control unit 5 has enabled the software for side B, the control unit 5 will start up with the normal software for side B when the system is restarted.
[0025] That is, the control unit 5 keeps the repro software flag off and the boot flag on until rewriting of the B side is complete, so that if a power outage occurs while rewriting the B side and the system is restarted when power is restored, the control unit 5 starts up with the normal software for the A side. Alternatively, even if a problem occurs and a power outage occurs while the system is running with the normal software for the A side, the control unit 5 starts up with the normal software for the A side when the system is restarted when power is restored. Once rewriting of the B side is complete, the control unit 5 updates the boot flag from on to off, disabling the software for the A side and enabling the software for the B side, so that if a power outage occurs after rewriting of the B side is complete and the system is restarted when power is restored, the control unit 5 starts up with the normal software for the B side. Alternatively, the control unit 5 starts up with the normal software for the B side when the system is started up after a normal shutdown.
[0026] If the repro software flag and boot flag are off, the control unit 5 notifies storage 6 of a load request for the repro mode transition software and normal startup repro software contained in the normal software for side B, as shown in Figure 4, loads the repro mode transition software and normal startup repro software contained in the normal software for side B from storage 6, expands them on RAM, and starts up with the normal software for side B. The control unit 5 executes the repro mode transition software expanded on RAM, making it possible to write the repro software flag, and executes the normal startup repro software expanded on RAM, making it possible to read and write the boot flag.
[0027] When the control unit 5 starts up with the normal software for side B, it updates the boot flag according to the progress of reprogramming using the normal startup reprogramming software, as shown in Figure 5. The control unit 5 keeps the reprogramming software flag and the boot flag off until it has completed rewriting side A. When the control unit 5 has completed rewriting side A, it updates the boot flag from off to on, disabling the software for side B and enabling the software for side A. When the control unit 5 has enabled the software for side A, the control unit 5 will start up with the normal software for side A when the system is restarted.
[0028] That is, the control unit 5 keeps the repro software flag and the boot flag off until the rewriting of side A is complete, so that if a power outage occurs while rewriting side A and the system is restarted when power is restored, the control unit 5 starts up with the normal software for side B. Alternatively, even if a problem occurs and a power outage occurs while the system is running with the normal software for side B, the control unit 5 starts up with the normal software for side B when the system is restarted when power is restored. Once the control unit 5 completes the rewriting of side A, it updates the boot flag from off to on, disabling the software for side B and enabling the software for side A, so that if a power outage occurs after rewriting side A is complete and the system is restarted when power is restored, the control unit 5 starts up with the normal software for side A. Alternatively, the control unit 5 starts up with the normal software for side A when the system is started up after a normal shutdown.
[0029] If the repro software flag is on, the control unit 5 notifies the storage 6 of a load request for the repro mode repro software, loads the repro mode repro software from the storage 6, expands it on RAM, and starts up the repro mode repro software, as shown in Fig. 6. The control unit 5 executes the repro mode repro software expanded on RAM, making it possible to write the repro software flag and to read and write the boot flag.
[0030] When the control unit 5 starts up with the repro mode repro software, it updates the repro software flag according to the progress of repro by the repro mode repro software, as shown in Figure 7. When a request to transition to repro mode occurs, the control unit 5 keeps the repro software flag off until the request to transition to repro mode is completed. When the request to transition to repro mode is completed, the control unit 5 updates the repro software flag from off to on, and keeps the repro software flag on until rewriting of either the A side or B side software is completed. When the control unit 5 completes rewriting of either the A side or B side software, it updates the repro software flag from on to off. When the control unit 5 updates the repro software flag from on to off, the control unit 5 starts up with either the A side normal software or the B side normal software when the system is restarted.
[0031] That is, when a request to transition to repro mode occurs, the control unit 5 keeps the repro software flag off until the request to transition to repro mode is completed, so that if a power outage occurs while either the A-side or B-side regular software is running and the system is restarted upon power recovery, either the A-side or B-side regular software will be started. When the request to transition to repro mode is completed, the control unit 5 updates the repro software flag from off to on, and keeps the repro software flag on until rewriting of either the A-side or B-side is completed, so that if a power outage occurs while rewriting either the A-side or B-side and the system is restarted upon power recovery, the repro software will be started in repro mode. When the control unit 5 completes rewriting of either the A-side or B-side, the control unit 5 updates the repro software flag from on to off, so that if a power outage occurs after rewriting of either the A-side or B-side is completed and the system is restarted upon power recovery, either the A-side regular software or the B-side regular software will be started.
[0032] Next, the operation of the above-described configuration will be described with reference to Figures 8 to 12. As processes performed by the control unit 5, the system startup process and the repro mode transition request determination process will be described in order.
[0033] (1) System startup processing (see Figures 8 to 11) When the start condition of the system startup process is met, for example, by turning on the power, the control unit 5 starts the system startup process and starts the IPL (S1). The control unit 5 references the repro software flag and determines whether the repro software flag is on or not (S2). If the control unit 5 determines that the repro software flag is not on but off (S2: NO), it references the boot flag and determines whether the boot flag is on or not (S3).
[0034] When the control unit 5 determines that the boot flag is on (S3: YES), it notifies the storage 6 of a load request for the repro mode transition software and normal startup repro software included in the normal software for side A, and loads the repro mode transition software and normal startup repro software included in the normal software for side A from the storage 6 and expands them on RAM (S4). The control unit 5 starts the repro mode transition software and normal startup repro software (S5, equivalent to the startup procedure), and proceeds to the B side rewrite process in normal mode (S6).
[0035] When the control unit 5 starts the B side rewriting process in normal mode, it determines whether a reprocessing request has occurred (S21) and whether a system shutdown instruction has occurred (S22). When the control unit 5 determines whether a reprocessing request has occurred (S21: YES), it starts rewriting the B side (S23) and determines whether rewriting the B side has been completed (S24). When the control unit 5 determines that rewriting the B side has been completed (S24: YES), it updates the boot flag from on to off, disables the software on the A side, and enables the software on the B side (A25, corresponding to the information update procedure), ends the B side rewriting process in normal mode, returns to the system startup process, and ends the system startup process. When the control unit 5 determines whether a system shutdown instruction has occurred (S22: YES), it ends the B side rewriting process in normal mode without starting the B side rewriting, returns to the system startup process, and ends the system startup process.
[0036] When the control unit 5 determines that the boot flag is off and not on (S3: NO), it notifies the storage 6 of a load request for the repro mode transition software and normal startup repro software contained in the normal software for side B, and loads the repro mode transition software and normal startup repro software contained in the normal software for side B from the storage 6 and expands them on RAM (S7). The control unit 5 starts the repro mode transition software and normal startup repro software (S8, corresponding to the startup procedure), and proceeds to the A side rewrite process in normal mode (S9).
[0037] When the control unit 5 starts the A side rewriting process in normal mode, it determines whether a repro request has occurred (S31) and whether a system shutdown instruction has occurred (S32). When the control unit 5 determines whether a repro request has occurred (S31: YES), it starts rewriting the A side (S33) and determines whether the A side rewriting has been completed (S34). When the control unit 5 determines that the A side rewriting has been completed (S34: YES), it updates the boot flag from OFF to ON, disables the B side software, and enables the A side software (A35, corresponding to the information update procedure), ends the A side rewriting process in normal mode, returns to the system startup process, and ends the system startup process. When the control unit 5 determines whether a system shutdown instruction has been occurred (S32: YES), it ends the B side rewriting process in normal mode without starting the A side rewriting, returns to the system startup process, and ends the system startup process.
[0038] On the other hand, if the control unit 5 determines that the repro software flag is on (S2: YES), it notifies the storage 6 of a load request for the repro mode repro software, loads the repro mode repro software from the storage 6, and expands it on RAM (S10). The control unit 5 starts the repro mode repro software (S11, corresponding to the start-up procedure), and proceeds to rewrite processing in repro mode (S12).
[0039] When the control unit 5 starts the rewrite process in repro mode, it determines whether or not preparations to start repro have been completed (S41). When the control unit 5 determines that preparations to start repro have been completed (S41: YES), it references the boot flag and identifies which of side A or side B is the side to be rewritten (S42). When the control unit 5 determines that the boot flag is on, it identifies side A as the side to be rewritten, and when it determines that the boot flag is off, it identifies side B as the side to be rewritten.
[0040] The control unit 5 starts rewriting the identified rewriting target surface (S43) and determines whether or not the rewriting of the rewriting target surface is completed (S44). When the control unit 5 determines that the rewriting of the rewriting target surface is completed (S44: YES), it determines whether or not the rewriting target surface on which the software rewriting has been completed is a non-operating surface (S45).
[0041] When the control unit 5 determines that the rewrite target side on which the software has been rewritten is the working side and not the non-working side (S45: NO), it ends the rewrite process in repro mode and returns to the system startup process.When the control unit 5 determines that the rewrite target side on which the software has been rewritten is the non-working side (S45: YES), it updates the on / off state of the boot flag, disables the software on the working side and enables the software on the non-working side (A46, corresponding to the information update procedure), ends the rewrite process in repro mode, returns to the system startup process, and ends the system startup process.
[0042] (2) Repro mode transition request determination process (see Figure 12) The control unit 5 executes the repro mode transition software to perform the repro mode transition request determination process. When the control unit 5 starts the repro mode transition request determination process, it determines whether a request to transition to repro mode has occurred (S51) and whether a system shutdown instruction has occurred (S52). When the control unit 5 determines that a request to transition to repro mode has occurred (S51: YES), it determines whether the request to transition to repro mode has been completed (S53). When the control unit 5 determines that the request to transition to repro mode has been completed (S53: YES), it updates the repro software flag from off to on (S54, corresponding to the information update procedure), restarts the system (S55), and ends the repro mode transition request determination process. When the control unit 5 determines that a system shutdown instruction has occurred (S52: YES), it ends the repro mode transition request determination process without updating the repro software flag from off to on. In addition, when the control unit 5 restarts the system in step S55 after updating the repro software flag from off to on in step S54, as described with reference to FIG. 8, it determines in step S2 that the repro software flag is on and notifies the storage 6 of a request to load the repro mode repro software.
[0043] As described above, according to the first embodiment, the following advantageous effects can be obtained. In the ECU 1, the repro software flag and the boot flag are updated according to the progress of repro, and the system is started up based on the repro software flag and the boot flag. Even if a power outage occurs during repro, when the system is restarted after power is restored, the system can be restarted normally by referring to the repro software flag and the boot flag immediately before the power outage. As a result, even if a power outage occurs during repro, the system can be restarted normally when the system is restarted after power is restored.
[0044] In ECU1, when a reprogramming request occurs in normal mode while the system is running in normal mode, the non-working side is rewritten and the boot flag is updated after the reprogramming of the non-working side is completed. When the system is restarted, the software on the side that has been reprogrammed can be started.
[0045] In ECU1, when a request to transition to repro mode occurs while the system is running in normal mode, the repro software flag is updated after the transition to repro mode is completed, and the system is restarted after the repro software flag is updated. When the system is restarted, it can start in repro mode.
[0046] In ECU1, if you rewrite the non-operational side while running in repro mode, the boot flag will be updated after the rewrite is complete. When you restart the system, you can start the software on the side that has been rewritten.
[0047] In the above embodiment, the case where software stored in the software storage area 8 of the storage 6 of the ECU 1 is updated has been described. However, the target of reproducibility is not limited to the ECU 1, and the master ECU itself, which manages the ECU 1 in an integrated manner, may also be used. As shown in FIG. 13 , the master ECU 21 includes a control unit 22 and a storage 23 as a storage medium. The control unit 22 includes a reproducibility progress management unit 24, a flag update unit 25, and an integrated management unit 26. The integrated management unit 26 issues operational instructions to the ECU 1 and acquires operational status from the ECU 1. In addition, the integrated management unit 16 issues instructions to the master ECU 3 itself and acquires operational status from the master ECU 3. The storage 23 includes a flag storage area 27 and a software storage area 28. The flag storage area 27 is equivalent to the flag storage area 7 described above and includes a reproducibility software flag storage area 29 and a boot flag storage area 30. The software storage area 28 is the same as the software storage area 8 described above, and includes an A-side normal software storage area 31, a B-side normal software storage area 32, and a repro mode repro software storage area 33.
[0048] The master ECU 21 is connected to the DCM 4, which functions as a data communication device. When the DCM 4 receives a distribution package transmitted from the OTA center, it transfers the received distribution package to the master ECU 21. When the distribution package is transferred from the DCM 4, the master ECU 21 extracts update data from the transferred distribution package and writes the extracted update data.
[0049] According to this configuration, the master ECU 21, which manages the ECU 1 in an integrated manner, updates the reprogramming software flag and boot flag according to the progress of the reprogramming, and starts the system based on the reprogramming software flag and boot flag. Even if a power outage occurs during reprogramming, when the system is restarted after power is restored, the system can be restarted normally by referring to the reprogramming software flag and boot flag immediately before the power outage. This allows the system to be restarted normally when the power is restored, even if a power outage occurs during reprogramming.
[0050] (Second embodiment) The second embodiment will be described with reference to FIGS. 14 and 15. The second embodiment has a configuration including multiple storages. The ECU 41 includes a control unit 42, a first storage 43, and a second storage 44. The control unit 42, like the control unit 5 described in the first embodiment, includes a repro progress management unit and a flag update unit. The first storage 43 includes a flag storage area 7 and a software storage area 45. The software storage area 45 includes an A-side normal software storage area 46, a B-side normal software storage area 47, and a repro mode repro software storage area 48. The second storage 44 includes a software storage area 49. The software storage area 49 includes an A-side normal software storage area 50 and a B-side normal software storage area 51. The A-side normal software stored in the A-side normal software storage area 46 of the first storage 43 and the A-side normal software stored in the A-side normal software storage area 50 of the second storage 44 may be software that cooperates to realize a single application, or may be software that realizes separate applications. The B-side normal software stored in the B-side normal software storage area 47 of the first storage 43 and the B-side normal software stored in the B-side normal software storage area 51 of the second storage 44 may be software that cooperates to realize a single application, or may be software that realizes separate applications.
[0051] As shown in Figure 14, if the repro software flag is off and the boot flag is on, the control unit 42 notifies the first storage 43 and second storage 44 of a load request for the repro mode transition software and normal startup repro software contained in the normal software for side A, loads the repro mode transition software and normal startup repro software contained in the normal software for side A from the first storage 43 and second storage 44, expands them on RAM, and starts up with the normal software for side A.
[0052] If the repro software flag is off and the boot flag is off, the control unit 42 notifies the first storage 43 and the second storage 44 of a load request for the repro mode transition software and the normal startup repro software contained in the normal software for the B side, loads the repro mode transition software and the normal startup repro software contained in the normal software for the B side from the first storage 43 and the second storage 44, expands them on RAM, and starts up with the normal software for the B side.
[0053] As shown in FIG. 15, if the repro software flag is on, the control unit 42 notifies the first storage 43 of a load request for the repro mode repro software, loads the repro mode repro software from the first storage 43, expands it on RAM, and starts up the repro mode repro software.
[0054] In the second embodiment, the software arrangement differs from that in the first embodiment, and the control unit 42 performs the same processes as the system startup process and repro mode transition request determination process described in the first embodiment. Note that, although the above example illustrates a configuration with two storages 43, 44, the same applies to a configuration with three or more storages.
[0055] As described above, according to the second embodiment, even in a configuration having multiple storages 43, 44, it is possible to obtain the same effects as in the first embodiment, and even if a power outage occurs during reprogramming, the system can be restarted normally when power is restored.
[0056] (Third embodiment) The third embodiment will be described with reference to FIGS. 16 and 17. The first embodiment is configured such that one storage has multiple storage areas for software for the same side. The software for the same side is divided by core or virtual machine. The ECU 61 has a control unit 62 and a storage 63. The control unit 62, like the control unit 5 described in the first embodiment, has a repro progress management unit and a flag update unit. The storage 63 has a flag storage area 7 and a software storage area 64. The software storage area 64 has a normal software storage area 65 for side 1A, a normal software storage area 66 for side 1B, a normal software storage area 67 for side 2A, a normal software storage area 68 for side 2B, and a repro mode repro software storage area 69.
[0057] As shown in Figure 16, if the repro software flag is off and the boot flag is on, the control unit 62 notifies the storage 63 of a load request for the repro mode transition software and normal startup repro software contained in the normal software for side A, loads the repro mode transition software and normal startup repro software contained in the normal software for side A1 and side A2 from the storage 63, expands them on RAM, and starts up with the normal software for side A1 and side A2.
[0058] If the repro software flag is off and the boot flag is off, the control unit 62 notifies the storage 63 of a load request for the repro mode transition software and normal startup repro software contained in the normal software for the B side, loads the repro mode transition software and normal startup repro software contained in the normal software for the first B side and the normal software for the second B side from the storage 63, expands them on RAM, and starts up with the normal software for the first B side and the normal software for the second B side.
[0059] As shown in FIG. 17, if the repro software flag is on, the control unit 62 notifies the storage 63 of a load request for the repro mode repro software, loads the repro mode repro software from the storage 63, expands it on RAM, and starts up the repro mode repro software.
[0060] In the third embodiment, the software layout is also different from that in the first embodiment, and the control unit 62 performs the same processes as the system startup process and repro mode transition request determination process described in the first embodiment. Note that, although the above example shows a configuration with two storage areas for software for the same side, the same applies to a configuration with three or more storage areas for software for the same side.
[0061] As described above, according to the third embodiment, even in a configuration in which one storage 63 has multiple storage areas for software for the same surface, it is possible to obtain the same effects as the first embodiment, and even if a power outage occurs during repro, the system can be restarted normally when power is restored.
[0062] (Other embodiments) Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and modifications within the scope of equivalents. In addition, various combinations and forms, as well as other combinations and forms including only one element, more than one element, or less than one element, are also within the scope and spirit of the present disclosure.
[0063] In the above embodiment, a configuration was described in which the ECU to be reprogrammed has software areas on multiple surfaces, but the present invention can also be applied to a configuration in which the ECU to be reprogrammed has a software area on one surface. In the case of an ECU to be reprogrammed that has a software area on one surface, the boot flag storage area 10 is deleted or the boot flag is set to a fixed value. The operation based on the reprogramming software flag is as explained in the above embodiment.
[0064] In a reprogramming target ECU that has one software area, if a power outage occurs during reprogramming, the system may not start up in the mode it should be started in. In other words, there is a risk that the system will not be able to restart properly when the power is restored. The startup mode information storage unit stores startup mode information that indicates whether the system will start up in normal mode or reprogramming mode when it starts up. The reprogramming progress management unit manages the progress of reprogramming. The information update unit updates the startup mode information according to the progress of reprogramming. The reprogramming progress management unit starts up the system based on the startup mode information.
[0065] The startup mode information is updated as the reprogramming progresses, and the system is started based on the startup mode information. Even if a power outage occurs during reprogramming, the system can be restarted successfully when the power is restored by referencing the startup mode information immediately before the power outage. This allows the system to be restarted successfully when the power is restored, even if a power outage occurs during reprogramming.
[0066] The control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit and the method described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to perform one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible storage medium. [Explanation of symbols]
[0067] In the drawing, 1, 21, 41, and 61 are ECUs (electronic control units), 5, 22, 42, and 62 are control units, 9 and 29 are repro software flag storage areas (startup mode information storage units), 10 and 30 are boot flag storage areas (startup surface information storage units), 14 and 24 are repro progress management units, and 15 and 25 are flag update units (information update units).
Claims
1. An electronic control device (1, 21, 41, 61) having a plurality of software areas capable of storing software, a startup mode information storage unit (9, 29) for storing startup mode information indicating whether the system is to be started in a normal mode or a repro mode when the system is started; a startup screen information storage unit (10, 30) for storing startup screen information indicating which of the plurality of screens will be started when the device is started in the normal mode; a reproductive progress management unit (14, 24) for managing the progress of reproductive work; an information update unit (15, 25) that updates at least one of the start mode information and the start screen information according to the progress of repro; The reproduction progress management unit is an electronic control device that starts up the system based on the start-up mode information and the start-up screen information.
2. The electronic control device according to claim 1, wherein the repro progress management unit starts up in either the normal mode or the repro mode based on the start-up mode information, and when started up in the normal mode, determines the start-up screen based on the start-up screen information.
3. When a reprocessing request in the normal mode occurs while the reprocessing progress management unit is running in the normal mode, the non-operating side is rewritten, The electronic control device according to claim 1 , wherein the information updating unit updates the startup surface information after completing rewriting of the non-operational surface.
4. When a request to transition to the reproductive mode occurs while the reproductive progress management unit is running in the normal mode, the information update unit updates the startup mode information after the transition to the reproductive mode is completed, The electronic control device according to claim 1 , wherein the reproduction progress management unit restarts the system after updating the startup mode information.
5. 2. The electronic control device according to claim 1, wherein when the reproductive progress management unit rewrites a non-operating surface while the electronic control device is running in the reproductive mode, the information update unit updates the operating surface information after the rewriting is completed.
6. A control unit (5, 22, 42, 62) of an electronic control device (1, 21, 41, 61) includes: a startup mode information storage unit (9, 29) having software areas in a plurality of faces capable of storing software, and storing startup mode information indicating whether the system is to be started in a normal mode or a repro mode at startup; and a startup surface information storage unit (10, 30) storing startup surface information indicating which of the plurality of surfaces the system is to be started on at startup in the normal mode, an information update procedure for updating at least one of the startup mode information and the startup screen information according to the progress of repro; A repro implementation method that performs a startup procedure for starting up the system based on the startup mode information and the startup screen information.
7. A control unit (5, 22, 42, 62) of an electronic control device (1, 21, 41, 61) includes: a startup mode information storage unit (9, 29) having a plurality of software areas capable of storing software, and storing startup mode information indicating whether the system is to be started in a normal mode or a repro mode at startup; and a startup surface information storage unit (10, 30) storing startup surface information indicating which of the plurality of surfaces the system is to be started on at startup in the normal mode. an information update procedure for updating at least one of the startup mode information and the startup screen information according to the progress of repro; A repro implementation program that executes a startup procedure for starting up the system based on the startup mode information and the startup screen information.
Citation Information
Patent Citations
Electronic control system for vehicle, method for determining download of distribution package, and program for determining download of distribution package
JP2020027628A
Vehicle control device and vehicle control method
JP2020052960A
On-vehicle update device, update processing program, and program update method
JP2020062936A