Software update system, software update device, software update method and program

The software update system addresses the issue of non-conforming date and time information in logs by reacquiring and regenerating logs after power loss, ensuring accurate data transmission and reliable software update processes in vehicles.

JP7769083B1Active Publication Date: 2025-11-12HONDA MOTOR CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024214300
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-12-09
Publication Date
2025-11-12
Estimated Expiration
2044-12-09

AI Technical Summary

Technical Problem

Existing software update systems for vehicle electronic control units (ECUs) fail to accurately capture date and time information during power loss, resulting in logs with non-conforming data formats, which complicates the software update process and hinders effective communication with server devices.

Method used

A software update system and method that includes a date and time information acquisition unit to reacquire and regenerate logs after power restoration, ensuring date and time information conforms to the required format before transmission to the server device, thereby preventing the inclusion of non-conforming data.

Benefits of technology

Ensures that software update logs contain accurate date and time information, facilitating effective communication and management of software update processes even after power loss, enhancing the reliability and efficiency of software updates in vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007769083000001_ABST
    Figure 0007769083000001_ABST
Patent Text Reader

Abstract

A better software update system, a better software update device, a better software update method, and a program for causing a computer to execute the better software update method are provided. [Solution] In the software update system 10, when it is determined that the software update process has failed due to a loss of power, the date and time information acquisition unit 74 acquires date and time information after the power is restored, the log generation unit 76 generates a log based on the date and time information acquired by the date and time information acquisition unit after the power is restored, and the log transmission unit 78 transmits the log generated based on the date and time information acquired by the date and time information acquisition unit after the power is restored to the server device 14.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a software update system, a software update device, a software update method, and a program. [Background technology]

[0002] Japanese Patent Application Laid-Open Publication No. 2018-037022 discloses an in-vehicle update system that acquires an update program via a wireless communication device and updates the software of an electronic control unit of a vehicle using the acquired update program. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2018-037022 Summary of the Invention [Problem to be solved by the invention]

[0004] There is a demand for a better software updating system, a better software updating device, a better software updating method, and a program that causes a computer to execute a better software updating method.

[0005] The present disclosure aims to solve the above-mentioned problems. [Means for solving the problem]

[0006] A first aspect of the present disclosure is a software update system comprising a vehicle and a server device capable of communicating with the vehicle via a network, the software update system comprising: an update processing unit that executes a software update process on an electronic control unit provided in the vehicle; an update failure determination unit that determines whether the software update process has failed due to a loss of a power source that supplies power to the electronic control unit; a date and time information acquisition unit that acquires date and time information; a log generation unit that generates a log including information related to the software update process and the date and time information acquired by the date and time information acquisition unit; and a log transmission unit that transmits the log generated by the log generation unit to the server device, wherein when it is determined that the software update process has failed due to a loss of the power source, the date and time information acquisition unit acquires the date and time information after the power source is restored, the log generation unit generates the log based on the date and time information acquired by the date and time information acquisition unit after the power source is restored, and the log transmission unit transmits the log generated based on the date and time information acquired by the date and time information acquisition unit after the power source is restored to the server device.

[0007] A second aspect of the present disclosure is a software update system comprising a vehicle and a server device capable of communicating with the vehicle via a network, the software update system comprising: an update processing unit that executes a software update process on an electronic control unit provided in the vehicle; a date and time information acquisition unit that acquires date and time information; a log generation unit that generates a log including information related to the software update process and the date and time information acquired by the date and time information acquisition unit; and a log transmission unit that transmits the log generated by the log generation unit to the server device, wherein before transmitting the log, the log transmission unit determines whether the date and time information included in the log includes a predetermined numerical value, and if it is determined that the date and time information included in the log includes the predetermined numerical value, the log transmission unit does not transmit the log, the date and time information acquisition unit re-acquires the date and time information, the log generation unit re-generates the log including the date and time information re-acquired by the date and time information acquisition unit, and the log transmission unit transmits the log re-generated by the log generation unit to the server device.

[0008] A third aspect of the present disclosure is a software update device in a software update system according to the first aspect, comprising the update processing unit, the update failure determination unit, the date and time information acquisition unit, the log generation unit, and the log transmission unit.

[0009] A fourth aspect of the present disclosure is a software update device in a software update system according to the second aspect, comprising the update processing unit, the date and time information acquisition unit, the log generation unit, and the log transmission unit.

[0010] A fifth aspect of the present disclosure is a software update method for performing a software update process on an electronic control unit provided in a vehicle, the method including: an update processing step of executing the software update process by an update processing unit; an update failure determination step of determining by an update failure determination unit whether or not the software update process has failed due to a loss of a power source that supplies power to the electronic control unit; a date and time information acquisition step of acquiring date and time information by a date and time information acquisition unit; a log generation step of generating by a log generation unit a log including information about the software update process and the date and time information acquired by the date and time information acquisition unit; and a log generation step of logging the log generated by the log generation unit. and a log sending step in which a sending unit sends the log to a server device, wherein if it is determined that the software update process has failed due to the loss of power, in the date and time information acquisition step, the date and time information acquisition unit acquires the date and time information after the power supply is restored, in the log generation step, the log generation unit generates the log based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored, and in the log sending step, the log sending unit transmits the log generated based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored to the server device.

[0011] A sixth aspect of the present disclosure is a program that causes a computer to execute the software update method according to the fifth aspect. [Effects of the Invention]

[0012] According to the present disclosure, it is possible to provide a better software update system, a better software update device, a better software update method, and a program for causing a computer to execute the better software update method. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a schematic diagram illustrating a software update system according to an embodiment. [Figure 2]FIG. 2 is a flow diagram of a software update process in one embodiment. [Figure 3] FIG. 3 is a flowchart showing a software update process performed by the software update device according to an embodiment. [Figure 4] FIG. 4 is a flowchart showing a software update process performed by the software update device according to an embodiment. [Figure 5] FIG. 5 is a flowchart showing a campaign application process performed by the server device in one embodiment. [Figure 6] 6A and 6B are diagrams illustrating the operation of the software update device. DETAILED DESCRIPTION OF THE INVENTION

[0014] Traditionally, software updates for electronic control units (hereinafter referred to as ECUs) installed in vehicles have been carried out at dealerships, etc. In recent years, vehicles that can update their ECU software using wireless communication over the air (OTA) have become available on the market, making it possible to update the ECU software of such vehicles without having to be brought to a dealership, etc.

[0015] In the OTA software update process, the ECU may need to be rebooted during the software activation process. Therefore, software activation is performed while the vehicle is parked with the engine, drive motor, and other driving sources stopped.

[0016] During software activation, the power supply that supplies power to the ECU may be lost, for example, when the vehicle battery is removed. If the power supply is lost, the software activation is aborted. If the software activation is aborted, a log containing information indicating that the software update process has failed is generated, and the log is sent to a server device that manages the software update.

[0017] The log contains date and time information. However, in the past, if the software update process failed due to a loss of power, the process to obtain the date and time information was not performed, and the log contained date and time information that did not conform to the format.

[0018] For example, date and time information that conforms to the format indicating 14:17 on October 31, 2024, is expressed as a 12-digit number such as "202410311417." An example of date and time information that does not conform to the format is "000000000000." This is the initial value of the date and time information, and since the date and time information is not acquired, the initial value is not updated and the initial value is included in the log.

[0019] According to the present disclosure, even if the software update process fails due to a loss of power, it is possible to prevent the log from containing date and time information that does not conform to the format.

[0020] [One embodiment] A software update system, a software update device, a software update method, and a program according to an embodiment will be described below with reference to the accompanying drawings. The program (computer program, computer software) according to this embodiment may also be referred to as a computer program product. The computer program product is not limited to a computer program stored on a storage medium, but also includes a computer program transmitted, distributed, or downloaded via the Internet, etc.

[0021] [Software Update System Configuration] 1 is a schematic diagram showing a software update system 10 according to one embodiment. The software update system 10 includes a vehicle 12 and a server device 14. The server device 14 is capable of communicating with the vehicle 12 via a network 16.

[0022] The vehicle 12 is equipped with a plurality of ECUs 18. Each ECU 18 performs control to realize the driving function and other functions of the vehicle 12. Each ECU 18 has a calculation unit 20 and a memory unit 22. The calculation unit 20 is, for example, a processor such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit). At least a part of the calculation unit 20 may be realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). At least a part of the calculation unit 20 may be realized by an electronic circuit including discrete devices.

[0023] The memory unit 22 is a computer-readable, non-transitory, tangible storage medium. The memory unit 22 is composed of a volatile memory (not shown) and a non-volatile memory (not shown). The volatile memory is, for example, a random access memory (RAM). The non-volatile memory is, for example, a read-only memory (ROM), a flash memory, etc. Data, etc., are stored in the volatile memory. Programs, tables, maps, etc., are stored in the non-volatile memory, for example. At least a portion of the memory unit 22 may be provided in the above-mentioned processor, integrated circuit, etc. At least a portion of the memory unit 22 may be mounted on a device connected to the vehicle 12 via the network 16.

[0024] The vehicle 12 includes a software update device 24. The software update device 24 may be configured, for example, by a CGW-ECU (Central GateWay-Electronic Control Unit). The software update device 24 includes a calculation unit 26 and a storage unit 28. The calculation unit 26 is, for example, a processor such as a CPU or a GPU. The calculation unit 26 includes an information transmission unit 30, an information acquisition unit 32, a display control unit 34, a permission confirmation unit 36, a transmission request unit 38, an update processing unit 40, a discard processing unit 42, an update failure determination unit 72, a date and time information acquisition unit 74, a log generation unit 76, and a log transmission unit 78. The information transmission unit 30, the information acquisition unit 32, the display control unit 34, the permission confirmation unit 36, the transmission request unit 38, the update processing unit 40, the discard processing unit 42, the update failure determination unit 72, the date and time information acquisition unit 74, the log generation unit 76, and the log transmission unit 78 are realized by the calculation unit 26 executing a program stored in the storage unit 28. At least a portion of the information transmitting unit 30, the information acquiring unit 32, the display control unit 34, the permission confirmation unit 36, the transmission request unit 38, the update processing unit 40, the discard processing unit 42, the update failure determination unit 72, the date and time information acquiring unit 74, the log generation unit 76, and the log transmitting unit 78 may be realized by an integrated circuit such as an ASIC or an FPGA. At least a portion of the information transmitting unit 30, the information acquiring unit 32, the display control unit 34, the permission confirmation unit 36, the transmission request unit 38, the update processing unit 40, the discard processing unit 42, the update failure determination unit 72, the date and time information acquiring unit 74, the log generation unit 76, and the log transmitting unit 78 may be realized by an electronic circuit including a discrete device.

[0025] The memory unit 28 is a computer-readable, non-transitory, tangible storage medium. The memory unit 28 is composed of a volatile memory (not shown) and a non-volatile memory (not shown). The volatile memory is, for example, a RAM. The non-volatile memory is, for example, a ROM, a flash memory. Data, etc. are stored, for example, in the volatile memory. Programs, tables, maps, etc. are stored, for example, in the non-volatile memory. At least a portion of the memory unit 28 may be provided in the above-mentioned processor, integrated circuit, etc. At least a portion of the memory unit 28 may be installed in a device connected to the vehicle 12 via the network 16. The memory unit 28 has a campaign information memory unit 44.

[0026] The software update device 24 performs a software update process for the ECU 18. The software update process includes software download, software installation, and software activation.

[0027] Downloading software refers to acquiring update data transmitted from server device 14 via network 16 and storing it in storage unit 28 of software update device 24. Update data is data including programs and the like for the updated software. The update data may also include an installer and the like.

[0028] Installing the software refers to loading update data from the storage unit 28 into the ROM of the ECU 18. The software may be installed by an installer. Alternatively, the software may be installed by copying the update data into the ROM.

[0029] Software activation refers to the process of authenticating the license for installed software. During software activation, executable files used by the software before the update may be rewritten. Once software activation is complete, execution of the software in the ECU 18 is permitted. Activation may be performed by the software update device 24 or each ECU 18.

[0030] The information transmitting unit 30 transmits various information to the server device 14. The information acquiring unit 32 acquires various information transmitted from the server device 14. The display control unit 34 controls the IVI 50 (described later) to display campaign information, downtime consent confirmation information, etc. (described later) on the display unit 58 of the IVI 50. The consent confirmation unit 36 ​​performs a confirmation process to confirm with the user whether or not to perform software update processes such as software download and software activation. The transmission request unit 38 transmits an update data request to the server device 14. The update data request is a signal requesting the server device 14 to transmit update data to the software update device 24. The update processing unit 40 performs update processes for software download, software installation, and software activation. The discard processing unit 42 performs a discard process to discard acquired campaign information stored in the campaign information storage unit 44.

[0031] The update failure determination unit 72 determines whether the software update process has failed. If software activation is canceled due to a loss of power supply that supplies power to the ECU 18, the update failure determination unit 72 determines that the software update process has failed. On the other hand, if software activation is completed, the update failure determination unit 72 determines that the software update process has been successful. The date and time information acquisition unit 74 acquires information on the current year, month, date, and time. The date and time information acquisition unit 74 may acquire date and time information from signals transmitted from artificial satellites used in the Global Positioning System (GPS) or the like. The date and time information acquisition unit 74 may acquire date and time information from signals transmitted from the server device 14.

[0032] The log generation unit 76 generates a result log. When the software update process is completed, when the software update process is interrupted without being completed, or when the software update process fails, the log generation unit 76 generates a result log. The result log includes information about the software update process and date and time information. The log generation unit 76 may also generate an event log. When a predetermined process of the software update process starts or when the predetermined process ends, the event log is generated. The log transmission unit 78 transmits the result log or the event log to the server device 14.

[0033] The software update device 24 and the ECU 18 are connected by a CAN (Controller Area Network) (registered trademark), and can communicate with each other. The communication line connecting the software update device 24 and the ECU 18 is not limited to CAN, but may be Ethernet (registered trademark), or both CAN and Ethernet may be used. Furthermore, a communication line of a standard other than CAN or Ethernet may be used as the communication line.

[0034] The software update device 24 is capable of communicating with a base station 48 connected to the network 16 by cellular communication via a telematics control unit (hereinafter referred to as TCU) 46. The network 16 is, for example, the Internet.

[0035] The software update device 24 is connected to an IVI 50. The IVI 50 includes a calculation unit 52 and a storage unit 54. The calculation unit 52 is, for example, a processor such as a CPU or a GPU.

[0036] The memory unit 54 is a computer-readable, non-transitory, tangible storage medium. The memory unit 54 is composed of a volatile memory (not shown) and a non-volatile memory (not shown). The volatile memory is, for example, a RAM. The non-volatile memory is, for example, a ROM, a flash memory, etc. Data, etc. are stored in the volatile memory, for example. Programs, tables, maps, etc. are stored in the non-volatile memory, for example. At least a portion of the memory unit 54 may be provided in the processor, integrated circuit, etc. described above. At least a portion of the memory unit 54 may be installed in a device connected to the vehicle 12 via the network 16.

[0037] The IVI50 provides information such as route guidance and road traffic information, as well as entertainment through audio, DVD, and TV tuners.

[0038] The IVI 50 has a display unit 58. The display unit 58 is installed on the dashboard of the vehicle 12 or the like. The display unit 58 is a touch panel display. The display unit 58 provides information to the user in the form of images, text, etc., and accepts operational inputs from the user. The screen of the display unit 58 is, but is not limited to, a liquid crystal display, an organic electroluminescence (organic EL), or the like. The touch panel of the display unit 58 is, but is not limited to, a resistive film type, a capacitive type, or the like. Instead of the display unit 58 being a touch panel display, a combination of a display device such as a head-up display and a pointing device such as a motion capture device may be used.

[0039] The vehicle 12 is equipped with a start / stop switch (hereinafter referred to as SSSW) 60. The power mode of the vehicle 12 is switched by the user operating the SSSW 60. If the vehicle 12 is an engine vehicle, the power modes include IG-ON, IG-OFF, ACC-ON, ACC-OFF, and START. If the vehicle 12 is a hybrid vehicle or an electric vehicle, the power modes include IG-ON, IG-OFF, ACC-ON, ACC-OFF, and READY.

[0040] When IG-ON, all electrical equipment on the vehicle 12 can be used. When ACC-ON, some electrical equipment such as the audio can be used. When ACC-OFF, some electrical equipment cannot be used except for some electrical equipment such as the keyless entry system.

[0041] In START, the starter motor is driven to start the engine. After the engine has started, the state transitions to IG-ON. In READY, the drive motor can be driven, and the vehicle 12 can run using the drive motor. When hybrid vehicles and electric vehicles are ready to run, the power mode is IG-ON and READY.

[0042] The vehicle 12 is equipped with a shift position sensor 62. The shift position sensor 62 detects the selected shift position. A parking position (P position), a neutral position (N position), a drive position (D position), a reverse position (R position), etc. can be selected as the shift position.

[0043] The server device 14 has a calculation unit 64 and a storage unit 66. The calculation unit 64 is a processor such as a CPU or a GPU. The calculation unit 64 has an information acquisition unit 68 and a transmission processing unit 70. The information acquisition unit 68 and the transmission processing unit 70 are realized by the calculation unit 64 executing a program stored in the storage unit 66. At least a part of the information acquisition unit 68 and the transmission processing unit 70 may be realized by an integrated circuit such as an ASIC or an FPGA. At least a part of the information acquisition unit 68 and the transmission processing unit 70 may be realized by an electronic circuit including a discrete device.

[0044] The storage unit 66 is a computer-readable, non-transitory, tangible storage medium. The storage unit 66 is composed of a volatile memory (not shown) and a non-volatile memory (not shown). The volatile memory is, for example, a RAM. The non-volatile memory is, for example, a ROM, a flash memory, etc. Data, etc. are stored in the volatile memory. Programs, tables, maps, etc. are stored in the non-volatile memory, for example. At least a portion of the storage unit 66 may be provided in the above-mentioned processor, integrated circuit, etc. At least a portion of the storage unit 66 may be installed in a device connected to the server device 14 via the network 16.

[0045] A plurality of vehicles 12 are registered in the server device 14, and the server device 14 manages the update status of the software of the ECU 18 of each vehicle 12. The server device 14 provides each vehicle 12 with update data for updating the software of the ECU 18 of each vehicle 12.

[0046] [Software update process flow] FIG. 2 is a flow diagram of a software update process in one embodiment.

[0047] When a campaign is registered in the server device 14 (P1), the transmission processing unit 70 transmits a configuration synchronization request to the software update device 24 of the vehicle 12 (P2). The campaign is registered in the server device 14 together with update data for updating the software of the ECU 18 by the software developer of the ECU 18, the manufacturer of the vehicle 12, etc.

[0048] When the information acquisition unit 32 of the software update device 24 acquires a configuration synchronization request (Q1), the information transmission unit 30 transmits configuration synchronization information to the server device 14 (Q2). The configuration synchronization information includes information on the unique identifier assigned to each ECU 18 of the vehicle 12, information on the software version of each ECU 18, etc.

[0049] When the information acquisition unit 68 of the server device 14 acquires the configuration synchronization information (P3), the transmission processing unit 70 transmits campaign information regarding the software update process of each ECU 18 to the software update device 24 (P4).

[0050] The information acquisition unit 32 of the software update device 24 acquires the campaign information (Q3) and stores the campaign information in the campaign information storage unit 44. The display control unit 34 displays the campaign information on the display unit 58 of the IVI 50. The permission confirmation unit 36 ​​performs a confirmation process to confirm with the user whether or not to permit the software download. In this confirmation process, if the user permits the software download (Q4), the transmission request unit 38 transmits an update data request to the server device 14 (Q5).

[0051] When the information acquisition unit 68 of the server device 14 acquires the update data request (P5), the transmission processing unit 70 transmits the update data to the software update device 24 (P6).

[0052] The update processing unit 40 of the software update device 24 acquires the update data and downloads the software by storing the update data in the storage unit 28 (Q6). Thereafter, the update processing unit 40 loads the update data in the storage unit 28 into the ROM of the ECU 18 and installs the software (Q7).

[0053] Before software activation begins, the permission confirmation unit 36 ​​of the software update device 24 performs a confirmation process to confirm with the user whether or not to permit downtime. If the shift position detected by the shift position sensor 62 is "P" when the power mode transitions from IG-ON (or READY) to IG-OFF, the confirmation process is executed. If the user permits downtime in this confirmation process (Q8), the update processing unit 40 of the software update device 24 activates the software in the ECU 18 (Q9). Downtime refers to a time period during which the power mode of the vehicle 12 cannot be set to START mode or READY mode and the vehicle 12 cannot start traveling while the software is being activated.

[0054] When activation of the software of the ECU 18 is completed, the log generation unit 76 of the software update device 24 generates a result log (Q10). The log transmission unit 78 of the software update device 24 transmits the result log to the server device 14 (Q11). After the power mode transitions from IG-OFF to IG-ON (or READY), the result log is transmitted to the server device 14.

[0055] When the information acquisition unit 68 of the server device 14 acquires the result log (P7), the software update is completed.

[0056] [Software update process] 3 and 4 are flowcharts showing the software update process performed by the software update device 24 in one embodiment. This process is executed at a predetermined interval when the power mode is IG-ON (or READY).

[0057] In step S1, the software updating device 24 determines whether or not it has received a configuration synchronization request from the server device 14. If it is determined that it has received a configuration synchronization request (step S1: YES), the process proceeds to step S2.

[0058] In step S2, the information transmitting unit 30 of the software updating device 24 transmits the configuration synchronization information to the server device 14. After that, the process proceeds to step S3.

[0059] In step S3, the information acquisition unit 32 of the software update device 24 acquires the campaign information, and then the process proceeds to step S5.

[0060] If it is determined in the above-mentioned step S1 that a configuration synchronization request has not been acquired (step S1: NO), the process proceeds to step S4. In step S4, the software update device 24 determines whether or not acquired campaign information exists in the campaign information storage unit 44. If it is determined that acquired campaign information exists in the campaign information storage unit 44 (step S4: YES), the process proceeds to step S5.

[0061] In step S5, the display control unit 34 of the software update device 24 displays the campaign information on the display unit 58 of the IVI 50. After that, the process proceeds to step S6.

[0062] In step S6, the permission confirmation unit 36 ​​of the software update device 24 determines whether or not the user has given permission for the software download. If the software download is given permission (step S6: YES), the process proceeds to step S7.

[0063] In step S7, the transmission request unit 38 of the software update device 24 transmits an update data request to the server device 14. Thereafter, the process proceeds to step S8.

[0064] In step S8, the update processing unit 40 of the software update device 24 downloads the software, and then the process proceeds to step S9.

[0065] In step S9, the update processing unit 40 of the software update device 24 installs the software, and then the process proceeds to step S11.

[0066] If it is determined in the above-mentioned step S4 that no acquired campaign information has been stored in the campaign information storage unit 44 (step S4: NO), or if the software download has been rejected in the above-mentioned step S6 (step S6: NO), the process proceeds to step S10. In step S10, the update processing unit 40 of the software update device 24 determines whether or not there is installed software. If it is determined that there is installed software (step S10: YES), the process proceeds to step S11. If it is determined that there is no installed software (step S10: NO), the software update process ends.

[0067] In step S11, the update processing unit 40 of the software update device 24 determines whether the power mode of the vehicle 12 is IG-OFF. If it is determined that the power mode is IG-OFF (step S11: YES), the process proceeds to step S12. If it is determined that the power mode is not IG-OFF (step S11: NO), the software update process ends.

[0068] In step S12, the update processing unit 40 of the software update device 24 determines whether the shift position is in the P position. If it is determined that the shift position is in the P position (step S12: YES), the process proceeds to step S13.

[0069] In step S13, the display control unit 34 of the software update device 24 displays downtime permission confirmation information on the display unit 58 of the IVI 50. Then, the process proceeds to step S14.

[0070] In step S14, the permission confirmation unit 36 ​​of the software updating device 24 determines whether or not the downtime has been permitted by the user. If it is determined that the downtime has been permitted (step S14: YES), the process proceeds to step S15.

[0071] In step S15, the update processing unit 40 of the software update device 24 activates the software, and then the process proceeds to step S16.

[0072] In step S16, the update failure determination unit 72 of the software update device 24 determines whether the software update process has failed. As described above, if software activation is interrupted due to a loss of the power supply that supplies power to the ECU 18, the update failure determination unit 72 determines that the software update process has failed. On the other hand, if software activation is completed, the update failure determination unit 72 determines that the software update process has succeeded.

[0073] In step S16, if it is determined that the software update process has been successful (step S16: NO), the process proceeds to step S17. In step S17, the date and time information acquisition unit 74 of the software update device 24 acquires date and time information. Thereafter, the process proceeds to step S18.

[0074] In step S18, the log generation unit 76 of the software update device 24 generates a result log. Then, the process proceeds to step S19. The result log generated in step S18 includes information indicating that the software update process was successful and the date and time information acquired in step S17.

[0075] In step S19, the discarding unit 42 of the software updating device 24 discards the campaign information stored in the campaign information storage unit 44. Thereafter, the process proceeds to step S26.

[0076] If it is determined in step S16 that the software update has failed (step S16: YES), the process proceeds to step S20. In step S20, the date and time information acquisition unit 74 of the software update device 24 determines whether or not the power supply has been restored. If it is determined that the power supply has been restored (step S20: YES), the process proceeds to step S21. If it is determined that the power supply has not been restored (step S20: NO), the process of step S20 is repeated.

[0077] In step S21, the date and time information acquisition unit 74 of the software update device 24 acquires date and time information, and then the process proceeds to step S22.

[0078] In step S22, log generation unit 76 of software update device 24 generates a result log. Then, the process proceeds to step S26. The result log generated in step S22 includes information indicating that the software update process has failed and the date and time information acquired in step S21.

[0079] If it is determined in the above-mentioned step S12 that the shift position is not the P position (step S12: NO), or if it is determined in the above-mentioned step S14 that the downtime is rejected (step S14: NO), the process proceeds to step S23. In step S23, the display control unit 34 of the software update device 24 causes the display unit 58 to display update impossible information indicating that the software update is impossible. Thereafter, the process proceeds to step S24.

[0080] In step S24, the date and time information acquisition unit 74 of the software update device 24 acquires the date and time information, and then the process proceeds to step S25.

[0081] In step S25, log generation unit 76 of software update device 24 generates a result log. Then, the process proceeds to step S26. The result log generated in step S25 includes information indicating that the software update process is incomplete and the date and time information acquired in step S24.

[0082] In step S26, the log transmission unit 78 of the software update device 24 determines whether the power mode of the vehicle 12 is IG-ON. If it is determined that the power mode is IG-ON (step S26: YES), the process proceeds to step S27. If it is determined that the power mode is not IG-ON (step S26: NO), the process of step S26 is repeated.

[0083] In step S27, the log transmission unit 78 of the software update device 24 transmits the result log to the server device 14. Thereafter, the software update process ends.

[0084] [Campaign application process] 5 is a flowchart showing a campaign application process performed in the server device 14 in one embodiment. This process is executed at predetermined intervals.

[0085] In step S31, the server device 14 determines whether or not the campaign has been registered. If it is determined that the campaign has been registered (step S31: YES), the process proceeds to step S33.

[0086] If it is determined that no campaign is registered (step S31: NO), the process proceeds to step S32. In step S32, server device 14 determines whether there is a campaign for which an update data request has not been obtained. If it is determined that there is a campaign for which an update data request has not been obtained (step S32: YES), the process proceeds to step S33. If it is determined that there is no campaign for which an update data request has not been obtained (step S32: NO), the campaign application process ends.

[0087] In step S33, the transmission processing unit 70 of the server device 14 transmits a configuration synchronization request to the vehicle 12. Thereafter, the process proceeds to step S34.

[0088] In step S34, the information acquisition unit 68 of the server device 14 acquires the configuration synchronization information from the vehicle 12. Thereafter, the process proceeds to step S35.

[0089] In step S35, the transmission processing unit 70 of the server device 14 transmits the campaign information to the vehicle 12. Thereafter, the process proceeds to step S36.

[0090] In step S36, the server device 14 determines whether or not an update data request has been acquired. If it is determined that an update data request has been acquired (step S36: YES), the process proceeds to step S37. If it is determined that an update data request has not been acquired (step S36: NO), the campaign application process ends.

[0091] In step S37, the transmission processing unit 70 of the server device 14 transmits the update data to the vehicle 12. Thereafter, the campaign application process ends.

[0092] [About the operation of the software update device] 6A and 6B are diagrams illustrating the operation of the software updating device 24. Fig. 6A shows the operation of the conventional software updating device 24. Fig. 6B shows the operation of the software updating device 24 in one embodiment.

[0093] If software activation is aborted due to a loss of power supply that supplies power to the ECU 18, the log generator 76 of the software update device 24 generates a result log after the power supply is restored.

[0094] In the conventional software update device 24, after the power is restored, the process of acquiring date and time information is not performed by the date and time information acquisition unit 74. As a result, the date and time information is not updated from the initial value, and the result log generated by the log generation unit 76 includes date and time information that does not conform to the format.

[0095] On the other hand, in the software updating device 24 in one embodiment, after the power is restored, the date and time information acquiring unit 74 acquires the date and time information. Therefore, the date and time information is updated from the initial value, and the result log generated by the log generating unit 76 includes date and time information that conforms to the format.

[0096] Other Embodiments The software update system 10 of the above embodiment may be modified as follows.

[0097] Before transmitting the result log to the server device 14, the log transmission unit 78 of the software update device 24 may determine whether the date and time information included in the result log contains a predetermined value. The predetermined value is, for example, the initial value of the date and time information. The predetermined value may be any value that can determine that the date and time information included in the result log does not conform to the format.

[0098] If the date and time information included in the result log contains a predetermined value, the log sending unit 78 may cancel sending of the result log. The date and time information acquisition unit 74 of the software update device 24 may reacquire the date and time information. The log generation unit 76 of the software update device 24 may regenerate a result log including the date and time information reacquired by the date and time information acquisition unit 74. The log generation unit 76 may transmit the result log regenerated by the log generation unit 76 to the server device 14.

[0099] If the date and time information contained in the event log contains a predetermined numerical value, an event log containing the reacquired date and time information may be regenerated, as described above, and the regenerated event log may be sent to the server device 14.

[0100] The following additional notes are further disclosed regarding the above embodiment.

[0101] (Appendix 1) The software update system (10) of the present disclosure is a software update system including a vehicle (12) and a server device (14) capable of communicating with the vehicle via a network (16), and includes an update processing unit (40) that executes a software update process on an electronic control unit provided in the vehicle, an update failure determination unit (72) that determines whether the software update process has failed due to a loss of a power source that supplies power to the electronic control unit, a date and time information acquisition unit (74) that acquires date and time information, and information related to the software update process and the date and time information acquired by the date and time information acquisition unit. and a log transmission unit (78) that transmits the log generated by the log generation unit to the server device, wherein when it is determined that the software update process has failed due to the loss of the power supply, the date and time information acquisition unit acquires the date and time information after the power supply is restored, the log generation unit generates the log based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored, and the log transmission unit transmits the log generated based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored to the server device.

[0102] (Appendix 2) In the software update system described in Supplementary Note 1, before transmitting the log, the log transmission unit may determine whether the date and time information included in the log includes a predetermined numerical value, and if it is determined that the date and time information included in the log includes the predetermined numerical value, the log transmission unit may not transmit the log, the date and time information acquisition unit may reacquire the date and time information, the log generation unit may regenerate the log including the date and time information reacquired by the date and time information acquisition unit, and the log transmission unit may transmit the log regenerated by the log generation unit to the server device.

[0103] (Appendix 3) The software update system disclosed herein is a software update system comprising a vehicle and a server device capable of communicating with the vehicle via a network, and comprising: an update processing unit that executes a software update process on an electronic control unit provided in the vehicle; a date and time information acquisition unit that acquires date and time information; a log generation unit that generates a log including information related to the software update process and the date and time information acquired by the date and time information acquisition unit; and a log transmission unit that transmits the log generated by the log generation unit to the server device, wherein before transmitting the log, the log transmission unit determines whether the date and time information included in the log includes a predetermined numerical value, and if it is determined that the date and time information included in the log includes the predetermined numerical value, the log transmission unit does not transmit the log, the date and time information acquisition unit re-acquires the date and time information, the log generation unit re-generates the log including the date and time information re-acquired by the date and time information acquisition unit, and the log transmission unit transmits the log re-generated by the log generation unit to the server device.

[0104] (Appendix 4) The software update device (24) of the present disclosure is a software update device in the software update system described in Appendix 1 or 2, and includes the update processing unit, the update failure determination unit, the date and time information acquisition unit, the log generation unit, and the log transmission unit.

[0105] (Appendix 5) The software update device of the present disclosure is a software update device in the software update system described in Supplementary Note 3, and includes the update processing unit, the date and time information acquisition unit, the log generation unit, and the log transmission unit.

[0106] (Appendix 6) The software update method disclosed herein is a software update method for performing a software update process on an electronic control unit provided in a vehicle, and includes an update processing step of executing the software update process by an update processing unit; an update failure determination step of determining whether the software update process has failed due to a loss of a power source that supplies power to the electronic control unit by an update failure determination unit; a date and time information acquisition step of acquiring date and time information by a date and time information acquisition unit; a log generation step of generating a log by a log generation unit that includes information about the software update process and the date and time information acquired by the date and time information acquisition unit; and a log sending step in which a log sending unit sends the obtained log to a server device, wherein if it is determined that the software update process has failed due to the loss of power, in the date and time information acquisition step, the date and time information acquisition unit acquires the date and time information after the power supply is restored, in the log generation step, the log generation unit generates the log based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored, and in the log sending step, the log sending unit transmits to the server device the log generated based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored.

[0107] (Appendix 7) The software update method described in Supplementary Note 6 may further include, before the log sending step, a date and time information determination step of determining whether or not the date and time information included in the log includes a predetermined numerical value by a date and time information determination unit, and if the date and time information included in the log includes the predetermined numerical value, the following steps may be executed: a log sending cancellation step of canceling the sending of the log generated in the log generating step; a date and time information reacquisition step of reacquiring the date and time information by the date and time information acquisition unit; a log regeneration step of regenerating the log including the date and time information reacquired by the date and time information acquisition unit by the log generating unit; and a log retransmission step of transmitting the log regenerated in the log regeneration step to the server device by the log sending unit.

[0108] (Appendix 8) The program disclosed herein causes a computer to execute the software update method described in Supplementary Note 6 or 7.

[0109] Although the present disclosure has been described in detail, the present disclosure is not limited to the individual embodiments described above. Various additions, substitutions, modifications, partial deletions, etc. are possible in these embodiments without departing from the gist of the present disclosure or the spirit of the present disclosure derived from the content of the claims and their equivalents. These embodiments can also be implemented in combination. For example, in the above-described embodiments, the order of each operation and the order of each process are shown as examples and are not limited to these. The same applies when numerical values ​​or mathematical expressions are used in the description of the above-described embodiments. [Explanation of symbols]

[0110] 10...Software update system 12...Vehicle 14...Server device 16...Network 24...software update device 40...update processing unit 72...Update failure determination unit 74...Date and time information acquisition unit 76...Log generation unit 78...Log transmission unit

Claims

1. A software update system including a vehicle and a server device capable of communicating with the vehicle via a network, an update processing unit that executes a software update process on an electronic control unit provided in the vehicle; an update failure determination unit that determines whether the software update process has failed due to a loss of a power source that supplies power to the electronic control device; a date and time information acquisition unit that acquires date and time information; a log generating unit that generates a log including information related to the software update process and the date and time information acquired by the date and time information acquiring unit; a log transmission unit that transmits the log generated by the log generation unit to the server device; Equipped with When it is determined that the software update process has failed due to a loss of power, the date and time information acquisition unit acquires the date and time information after the power supply is restored; the log generation unit generates the log based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored; A software update system, wherein the log transmission unit transmits the log generated based on the date and time information acquired by the date and time information acquisition unit to the server device after the power supply is restored.

2. 2. The software update system according to claim 1, The log transmission unit determines whether or not the date and time information included in the log includes a predetermined numeric value before transmitting the log; If it is determined that the date and time information included in the log includes the predetermined value, The log transmission unit does not transmit the log, the date and time information acquisition unit reacquires the date and time information; the log generation unit regenerates the log including the date and time information reacquired by the date and time information acquisition unit; The log transmission unit transmits the log regenerated by the log generation unit to the server device.

3. A software update system including a vehicle and a server device capable of communicating with the vehicle via a network, an update processing unit that executes a software update process on an electronic control unit provided in the vehicle; a date and time information acquisition unit that acquires date and time information; a log generating unit that generates a log including information related to the software update process and the date and time information acquired by the date and time information acquiring unit; a log transmission unit that transmits the log generated by the log generation unit to the server device; Equipped with The log transmission unit determines whether or not the date and time information included in the log includes a predetermined numeric value before transmitting the log; If it is determined that the date and time information included in the log includes the predetermined value, The log transmission unit does not transmit the log, the date and time information acquisition unit reacquires the date and time information; the log generation unit regenerates the log including the date and time information reacquired by the date and time information acquisition unit; The log transmission unit transmits the log regenerated by the log generation unit to the server device.

4. 3. A software update device in the software update system according to claim 1, A software updating device comprising: the update processing unit; the update failure determination unit; the date and time information acquisition unit; the log generation unit; and the log transmission unit.

5. 4. A software updating device in the software updating system according to claim 3, A software updating device comprising: the update processing unit; the date and time information acquisition unit; the log generation unit; and the log transmission unit.

6. A software update method for performing a software update process on an electronic control device provided in a vehicle, comprising: an update processing step of executing the software update processing by an update processing unit; an update failure determination step of determining whether the software update process has failed due to a loss of a power source that supplies power to the electronic control device, using an update failure determination unit; a date and time information acquisition step of acquiring date and time information by a date and time information acquisition unit; a log generating step of generating, by a log generating unit, a log including information related to the software update process and the date and time information acquired by the date and time information acquiring unit; a log transmission step of transmitting the log generated by the log generation unit to a server device by a log transmission unit; and When it is determined that the software update process has failed due to a loss of power, in the date and time information acquisition step, the date and time information acquisition unit acquires the date and time information after the power supply is restored; In the log generating step, the log generating unit generates the log based on the date and time information acquired by the date and time information acquiring unit after the power supply is restored; A software update method in which, in the log transmission step, the log transmission unit transmits to the server device the log generated based on the date and time information acquired by the date and time information acquisition unit after the power supply is restored.

7. 7. The software update method according to claim 6, The method further includes a date and time information determination step of determining, before the log sending step, whether or not the date and time information included in the log includes a predetermined numeric value by a date and time information determination unit, If the date and time information included in the log includes the predetermined value, a log transmission cancel step of canceling transmission of the log generated in the log generation step; a date and time information reacquisition step of reacquiring the date and time information by the date and time information acquisition unit; a log regeneration step of regenerating, by the log generation unit, the log including the date and time information reacquired by the date and time information acquisition unit; a log retransmission step of transmitting the log regenerated in the log regeneration step to the server device by the log transmission unit; A software update method is performed.

8. A program that causes a computer to execute the software update method according to claim 6 or 7.

Citation Information

Patent Citations

  • Method and device for recording operation information of mobile terminal

    CN110333985A

  • O-vehicle device, information processing device, download propriety determination method, program, and recording medium

    JP2022135545A

  • On-vehicle update system, on-vehicle update device, and communication apparatus update method

    JP2018037022A