Control System

The control system simplifies storage and processing in electronic control devices by using a program management device for wireless updates, reducing complexity and ensuring program integrity and security through separate storage of update and old programs.

JP7771860B2Active Publication Date: 2025-11-18DENSO CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022077735
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-10
Publication Date
2025-11-18
Estimated Expiration
2042-05-10

AI Technical Summary

Technical Problem

Existing control systems with multiple electronic control devices require complex configurations and processing due to the need for each device to store and switch between two programs, complicating the storage and processing devices.

Method used

A control system with a program management device that wirelessly updates programs for multiple electronic control devices, using a non-volatile memory to store update and old programs separately, eliminating the need for each device to store two programs and switch execution sides.

Benefits of technology

This configuration simplifies the storage and processing requirements in each electronic control device, reducing complexity and enabling efficient program updates while ensuring program integrity and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007771860000001
    Figure 0007771860000001
  • Figure 0007771860000002
    Figure 0007771860000002
  • Figure 0007771860000003
    Figure 0007771860000003
Patent Text Reader

Abstract

To provide a control system capable of suppressing complications in the configuration of a memory device in each ECU and processing of a processor.SOLUTION: A control system includes a plurality of ECUs 101 to 10x, an OTA control device 20, and a non-volatile memory 30. Each ECU has a processor 11 and a memory device 12 in which a program can be executed by the processor 11 is stored. The OTA control device performs radio communication with an OTA server 40 to receive an update program for each ECU and also performs update processing on the program stored in the memory device of each ECU to the update program. In the non-volatile memory 30, the received update program and the old program before update in each ECU are stored for each of the plurality of ECUs.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a control system including a plurality of electronic control devices whose programs can be rewritten via wireless communication. [Background technology]

[0002] One example of technology for rewriting programs via wireless communication is a mobile terminal disclosed in Patent Document 1. The mobile terminal stores software data executed on the device in duplicate as primary data and secondary data, and executes and uses either the primary data or secondary data. The mobile terminal also acquires differential data for updating the primary data and secondary data from a data server via wireless communication. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 5167936 Summary of the Invention [Problem to be solved by the invention]

[0004] Incidentally, a control system may be configured with multiple electronic control devices that can rewrite programs. Each electronic control device may also be equipped with a storage device that stores two programs in case of program rewrite failure. In this case, the control system requires each of the multiple electronic control devices to have a storage device that can store two programs and a processing device that can switch the side on which the program to be executed is stored. This creates a problem in that the control system requires a complicated configuration of the storage device and processing by the processing device in each electronic control device.

[0005] One disclosed object is to provide a control system that can prevent the configuration of the storage device in each electronic control device and the processing of the processing device from becoming complicated. [Means for solving the problem]

[0006] The control system disclosed herein comprises: A control system including a plurality of electronic control devices (101 to 10x), a program management device (20, 30) capable of wirelessly communicating with an external server provided outside the control system and managing programs in each electronic control device; Each electronic control device has a processing device (11) and a storage device (12) in which a program executable by the processing device is stored, The program management device an update processing device (20) that performs wireless communication with an external server to receive update programs for each electronic control device and updates the programs stored in the storage devices of each electronic control device to the update programs; It has a plurality of memory areas (31 to 3x) corresponding to each of a plurality of electronic control devices. a program storage device (30); 、 Each storage area has an update program area (320) in which received update programs for updating the programs stored in the storage device of the corresponding electronic control unit are stored, and an old program area (310) in which the old program before the update in the corresponding electronic control unit is stored. are.

[0007] In this way, the control system includes a program management device having an update processing device that performs program update processing and a program storage device in which received update programs and old programs before the update are stored for each of the electronic control devices. Therefore, each electronic control device does not need to have two programs stored in the storage device, and the processing device does not need to switch between the programs it is executing. Therefore, the control system can prevent the configuration of the storage device and the processing of the processing device in each electronic control device from becoming complicated.

[0008] The various aspects disclosed in this specification employ different technical means to achieve their respective objectives. The reference numerals in parentheses in the claims and in this section are intended to exemplify correspondences with the following embodiments and are not intended to limit the technical scope. The objectives, features, and advantages disclosed in this specification will become more apparent by reference to the following detailed description and the accompanying drawings. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a block diagram showing a schematic configuration of a control system according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating a storage area in a memory device of an ECU according to an embodiment. [Figure 3] FIG. 2 is a diagram illustrating a storage area in a nonvolatile memory according to an embodiment. [Figure 4] 10 is a flowchart showing a rewriting process of the control system according to the embodiment. [Figure 5] 4 is a flowchart showing a startup process of the control system according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0011] <Control system configuration> As shown in FIG. 1, the control system includes a plurality of ECUs 101 to 10x, an OTA control device 20, and a non-volatile memory 30. The plurality of ECUs 101 to 10x and the OTA control device 20 are connected via communication lines. The ECUs 101 to 10x are configured to be able to communicate with each other and with the OTA control device 20 in accordance with a predetermined communication standard. The OTA control device 20 and the non-volatile memory 30 are also connected via communication lines. In FIG. 1, the first ECU 101 is referred to as 1ECU, the second ECU 102 as 2ECU, and the xth ECU 10x as xECU. The OTA control device 20 is referred to as OTAECU. The non-volatile memory 30 is referred to as NVM.

[0012] The control system is configured to be mountable on a vehicle. Examples of vehicles that can be used include engine automobiles powered by an engine, electric vehicles powered only by a motor, and hybrid cars powered by both an engine and a motor. The control system can also be mounted on moving objects such as aircraft, in addition to vehicles. ECU is an abbreviation for Electronic Control Unit. OTA is an abbreviation for Over The Air. OTA is a technology that downloads update programs from an external server via wireless communication and uses the downloaded update programs to update or add programs used in electronic control units.

[0013] The control system performs various controls in the vehicle by operating a plurality of ECUs 101 to 10x. The control system is configured to be capable of wireless communication with an OTA server 40 provided outside the control system. The control system is configured to be capable of updating the programs used in each of the ECUs 101 to 10x by wirelessly communicating with the OTA server 40. In FIG. 1, the OTA server 40 is written as OTAS. The OTA server 40 corresponds to an external server.

[0014] The outside of the control system can also be said to be the outside of the vehicle in which the control system is installed. Program update can also be said to be reprogramming or updating. Program update also includes rewriting at least a part of an existing program with an update program, which is a new program, or adding an update program to an existing program. Update programs can also be said to be new programs. Existing programs are programs stored in each memory device 12 of each ECU 101 to 10x. Existing programs can also be said to be old programs. In particular, old programs refer to programs stored in the target area 120b of each memory device 12.

[0015] The OTA server 40 includes a server-side processor, a server-side memory device, a server-side communication device, etc. The server-side memory device stores update programs to be distributed to each of the ECUs 101 to 10x. The update programs are data for updating the old programs stored in the memory devices 12 of each of the ECUs 101 to 10x. The old programs and update programs include various commands, various setting values, etc.

[0016] The server-side processor is configured to be able to wirelessly communicate with the control system via a server-side communication device. The server-side processor wirelessly sends update requests for program updates and transmits update programs. The server-side communication device wirelessly communicates with the OTA control device 20 of the control system.

[0017] <ECU101~10x> The ECUs 101 to 10x will be described with reference to FIGS. 1 and 2. Each of the ECUs 101 to 10x corresponds to an electronic control device. In this embodiment, the first ECU 101, the second ECU 102, and the xth ECU 10x are included in a control system. to However, the control system may include a plurality of ECUs. Each of the ECUs 101 to 10x corresponds to an electronic control device.

[0018] As shown in FIG. 1, each of the ECUs 101 to 10x has a processor 11 and a memory device 12 in which programs executable by the processor 11 are stored. In addition to these components, each of the ECUs 101 to 10x also has a communication interface and the like. As such, the ECUs 101 to 10x have the same basic configuration. The ECUs 101 to 10x differ in the processing content and control targets. Therefore, the ECUs 101 to 10x have different programs stored in their memory devices 12. Therefore, in the following, when it is not necessary to distinguish between the ECUs 101 to 10x, the first ECU 101 will be used for explanation. In FIG. 1, the processor is referred to as PRC and the memory device is referred to as MED.

[0019] In the first ECU 101, the processor 11 executes a program stored in the memory device 12. The processor 11 executes the program to perform various calculations and control the controlled object. The processor 11 may be a CPU (Central Processing Unit) or the like. The processor 11 corresponds to a processing device.

[0020] The memory device 12 stores programs. The memory device 12 is a non-volatile memory. The memory device 12 may also include a volatile memory in addition to the non-volatile memory. Examples of non-volatile memory that can be used include mask ROM, PROM, EPROM, EEPROM (registered trademark), and flash memory. ROM is an abbreviation for Read Only Memory. PROM is an abbreviation for Programmable ROM. EPROM is an abbreviation for Erasable ROM. EEPROM is an abbreviation for Electrically Erasable Programmable ROM. Examples of volatile memory that can be used include DRAM and SRAM. DRAM is an abbreviation for Dynamic RAM. SRAM is an abbreviation for Static RAM. The memory device 12 corresponds to a storage device.

[0021] 2, the memory device 12 includes a plurality of storage areas 121 to 133 as areas for storing programs. In the memory device 12, programs are divided and stored in the plurality of storage areas 121 to 133. The storage areas 121 to 124 are non-target areas 120a that are not to be rewritten. The storage areas 125 to 133 are target areas 120b that are to be rewritten.

[0022] The non-target area 120a includes, for example, a startup control program area 121, a rewrite program area 122, a communication control program area 123, and a setting value area 124. The rewrite program area 122 stores a program for rewriting the program stored in the target area 120b.

[0023] The target area 120b includes, for example, an input control program area 125, a basic control program area 126, an output control program area 127, and a basic control setting value area 128. The target area 120b also includes an application A control program area 129, an application A setting value area 130, an application B control program area 131, and an application B setting value area 132. For example, the input control program area 125 and the application A control program area 129 store various commands that are part of the program. On the other hand, the basic control setting value area 128 and the application A setting value area 130 store various setting values ​​that are part of the program. The memory areas 125 to 132 can be said to be updatable areas. The programs stored in the memory areas 125 to 132 correspond to the programs in the claims. do It can also be considered as.

[0024] Furthermore, target area 120b includes program version information area 133. Program version information area 133 does not store programs, but rather stores version information of the programs stored in target area 120b. That is, in the drawings, programs in program version information area 133 are referred to as PR.

[0025] <Program management device> As shown in Fig. 1, the program management device includes an OTA control device 20 and a non-volatile memory 30. The OTA control device 20 has a processor 21, a memory device 22 that stores programs executable by the processor 21, and a communication device 23. Note that in Fig. 1, the communication device is written as COM. The program management device is capable of wireless communication with an OTA server 40, and manages the programs in each of the ECUs 101 to 10x.

[0026] In the OTA control device 20, the processor 21 executes a program stored in the memory device 22. By executing the program, the processor 21 performs various calculations and controls program rewriting, etc. The memory device 22 stores the program. The memory device 22 is a non-volatile memory. The memory device 22 may also include a volatile memory in addition to the non-volatile memory. The communication device 23 is a device for wireless communication with the OTA server 40. The OTA control device 20 communicates wirelessly with the OTA server 40 via the communication device 23.

[0027] The OTA control device 20 communicates wirelessly with the OTA server 40 via the communication device 23 and receives an update program for each of the ECUs 101 to 10x. The OTA control device 20 stores the received update program in the update program area 320 of the nonvolatile memory 30. At this time, the OTA control device 20 may encrypt the received update program and store it in the nonvolatile memory 30. This allows the control system to ensure confidentiality of the update program and strengthen security. The update program is transmitted to each of the corresponding ECUs 101 to 10x. In this case, upon receiving the encrypted update program, each of the ECUs 101 to 10x decrypts the program to make it executable by the processor 11. Each of the ECUs 101 to 10x decrypts the update program and writes it to the target area 120b.

[0028] Furthermore, the OTA control device 20 performs an update process to update the programs stored in the memory device 12 of each of the ECUs 101 to 10x. The update process can also be called a rewriting process. The update programs for each of the ECUs 101 to 10x are new programs for each of the programs stored in the memory device 12 of each of the ECUs 101 to 10x. The OTA control device 20 corresponds to an update processing device.

[0029] The nonvolatile memory 30 stores the received update program and the old program before update for each of the ECUs 101 to 10x for each of the ECUs 101 to 10x. The nonvolatile memory 30 includes storage areas 31 to 3x corresponding to the ECUs 101 to 10x, respectively. The first storage area 31 is a storage area corresponding to the first ECU 101. The second storage area 32 is a storage area corresponding to the second ECU 102. The xth storage area 3x is a storage area corresponding to the xth ECU 10x. In FIG. 1, the first storage area 31 is denoted as 1PRG, the second storage area 32 is denoted as 2PRG, and the xth storage area 3x is denoted as xPRG. The nonvolatile memory 30 corresponds to a program storage device.

[0030] 3 shows, as an example, the first storage area 31 of the nonvolatile memory 30. The first storage area 31 has an old program area 310 and an update program area 320. The old program area 310 has storage areas 311 to 313 similar to the storage areas 125 to 133 of the target area 120b. 1 9. Each of the storage areas 311 to 318 stores the same program as the corresponding storage area 125 to 132. Furthermore, storage area 319 stores version information of the programs stored in storage areas 311 to 318.

[0031] The update program area 320 is an area where update programs for updating the programs in the storage areas 125 to 132 are stored. Some of the programs in the storage areas 125 to 132 do not need to be updated. Naturally, there are no update programs corresponding to programs that do not need to be updated. Therefore, the update program area 320 may also include old program identical areas 321, 322. The old program identical areas 321, 322 are areas in which no programs are stored.

[0032] Update program area 320 has memory areas 326-328 in which update programs are stored, and memory area 329 in which version information of the update programs is stored. Memory areas 326-328 store update programs corresponding to the programs in memory areas 316-318 in old program area 310. Memory areas 326-328 also store update programs corresponding to memory areas 130-132 in target area 120b. In this embodiment, each of memory areas 130-132 corresponds to an update target area. Memory area 329 stores version information of the update programs stored in memory areas 326-328.

[0033] In this way, the update program is a differential program from the old program. Therefore, the update program is not stored in the same areas 321 and 322 as the old program, but is stored in memory areas 326 to 328. The update program can also be said to be a program that rewrites part of the old program. This allows the control system to reduce the storage area of ​​non-volatile memory 30.

[0034] Furthermore, the non-volatile memory 30 stores program rewrite completion information 330. The program rewrite completion information is stored in a storage area different from the old program area 310 and the update program area 320. The program rewrite completion information 330 is provided for each of the ECUs 101 to 10x. The program rewrite completion information 330 is information for managing how much of the update target area in the target ECU the program update has been completed to. The program rewrite completion information 330 associates each update target area with the update completion information. The processor 21 updates the program rewrite completion information 330 based on the update completion information from the target ECU. The target ECU is any one of the ECUs 101 to 10x. Note that the non-volatile memory 30 may also store programs stored in the non-target area 120a in each of the ECUs 101 to 10x. Therefore, the control system may have a function for updating (restoring) the program in the non-target area 120a.

[0035] <Control system processing operations> The rewriting process of the control system will be described with reference to FIG.

[0036] In step S10, an update request is received. Processor 21 receives the program update request from OTA server 40 via communication device 23. The update request may specify the ECUs whose programs are to be updated. The ECUs whose programs are to be updated may be all ECUs 101 to 10x, or may be a part of all ECUs 101 to 10x.

[0037] In step S11, the processor 21 receives the update program from the OTA server 40 via the communication device 23. The update program includes information that can identify the ECUs 101 to 10x that are the storage destinations of the update program.

[0038] In step S12, the update program is stored in the nonvolatile memory. The processor 21 stores the received update program in the nonvolatile memory 30. The processor 21 stores the received update program in the update program area 320 corresponding to the ECUs 101 to 10x as the storage destination. The processor 21 also divides the update program and stores it in each storage area of ​​the update program area 320. The update program stored in the nonvolatile memory 30 can also be said to be the latest available program.

[0039] In step S13, the update target area of ​​the target ECU is updated by processor 21. Processor 21 rewrites one of the update target areas of the target ECU with the update program (update processing).

[0040] In step S14, update completion information is transmitted. When the update target area is updated with the update program, processor 11 transmits the update completion information to processor 21. The transmission of the update completion information corresponds to issuing an update completion notification.

[0041] In step S15, the program rewrite completion information is updated. The processor 21 performs an update process on the update target area, and upon receiving update completion information for the update process, updates the program rewrite completion information 330. That is, the processor 21 associates the update completion information with the update target area that was the target of the update process performed in step S13 and stores the information in the program rewrite completion information 330. The processor 21 updates the program rewrite completion information 330 every time it receives update completion information.

[0042] In step S16, it is determined whether or not all of the update target areas of the target ECU have been rewritten. The processor 21 determines whether or not all of the update target areas of the target ECU have been rewritten, by referring to the program rewriting completion information 330 corresponding to the target ECU. If update completion information is associated with all of the update target areas in the program rewriting completion information 330, the processor 21 determines that the rewriting is complete, and proceeds to step S17. If update completion information is not associated with some of the update target areas in the program rewriting completion information 330, the processor 21 does not determine that the rewriting is complete, and returns to step S13. In this way, the control system rewrites multiple update target areas with the update program in order by repeatedly executing steps S13 to S16. That is, the processor 21 performs the update process for each update target area. The target ECU here is one of the ECUs whose programs are to be updated.

[0043] In step S17, it is determined whether or not rewriting of all ECUs has been completed. When rewriting of all update target areas in all ECUs that are the target of program update has been completed, processor 21 determines that rewriting of all ECUs has been completed and ends the flowchart of Fig. 4. When rewriting of some update target areas in all ECUs that are the target of program update has not been completed, processor 21 does not determine that rewriting of all ECUs has been completed and returns to step S11. In this way, processor 21 performs update processing on ECUs that are the target of program update in order.

[0044] Next, the startup process of the control system will be described with reference to Fig. 5. For example, when the ignition switch is switched from off to on, the processor 21 starts the process shown in the flowchart of Fig. 5. The processor 21 may start the process shown in the flowchart of Fig. 5 only when the ignition switch is switched on for the first time after the update process.

[0045] In step S20, it is determined whether the program rewriting completion information indicates that rewriting has been completed in all areas. The processor 21 refers to the program rewriting completion information 330 corresponding to all ECUs 101 to 10x. The processor 21 determines whether the program rewriting completion information 330 indicates that rewriting has been completed in all areas. In other words, the processor 21 determines whether the update process for the ECUs 101 to 10x has been completed. If the processor 21 determines that the program rewriting completion information 330 indicates that rewriting has been completed in all areas, the process proceeds to step S21, and if the processor 21 determines that rewriting has not been completed, the process proceeds to step S25.

[0046] It should be noted that an update target area in which rewriting has not been completed can be considered to have failed in the update process. That is, the processor 21 determines that the update has failed if update completion information has not been received. Therefore, it can also be said that the processor 21 determines whether the update process has failed (update failure determination). It should be noted that the update process fails, for example, when the supply of operating power to the OTA control device 20 or each of the ECUs 101 to 10x is stopped during the update process.

[0047] If processor 21 determines that rewriting has been completed in all areas, it considers the update process to be successful and proceeds to step S21. On the other hand, if processor 21 determines that rewriting has not been completed, it considers the update process to have failed and proceeds to step S25.

[0048] The processor 21 determines whether an update has failed based on the program rewrite completion information 330, and therefore can identify the ECU for which the update process has failed and the update program for which the update process has failed. Furthermore, the processor 21 determines that the update has failed when update completion information is not received despite the fact that update processing has been performed on the update target area. Therefore, the processor 21 can identify the update target area for which the update has failed.

[0049] In step S21, it is determined whether the version information matches. The processor 21 determines whether the version information of the update programs managed in the nonvolatile memory 30 matches the version information of the programs managed in each of the ECUs 101 to 10x. At this time, the processor 21 acquires a combination of the version information of the update programs stored in the storage area 329 in each of the storage areas 31 to 3x. The processor 21 also acquires a combination of the version information of the programs stored in the program version information area 133 in each of the ECUs 101 to 10x. The processor 21 then compares the two combinations to determine whether they match.

[0050] If processor 21 determines that they match, it considers that the validity (appropriateness) of the program version in each of ECUs 101-10x has been ensured, and proceeds to step S22. If processor 21 determines that they do not match, it considers that the validity of the program version in each of ECUs 101-10x has not been ensured, and proceeds to step S23.

[0051] In step S22, normal control of each ECU is executed. At this time, processor 21 transmits execution permission to each of ECUs 101 to 10x. Processor 11 of each of ECUs 101 to 10x executes the program stored in memory device 12 on the condition that execution permission has been received from processor 21. In this way, each of ECUs 101 to 10x executes normal control. Note that normal control is control performed by each processor 11 executing the program stored in memory device 12.

[0052] In this way, the control system verifies the validity (appropriateness) of the program version in each of the ECUs 101 to 10x. Then, the control system permits normal control in each of the ECUs 101 to 10x only when the validity of the program version is confirmed. This allows the control system to ensure the integrity of the entire vehicle and strengthen security.

[0053] Furthermore, the processor 21 may compare the update program stored in the nonvolatile memory 30 with the program stored in the memory device 12 to determine whether an appropriate program is stored in the memory device 12. It can also be said that the processor 21 confirms the identity of the update program stored in the nonvolatile memory 30 with the program stored in the memory device 12. In other words, the processor 21 checks whether the program in the memory device 12 has been tampered with. A hash calculation or the like can be used as a method for determining whether the program has been tampered with, but is not particularly limited to such a method. When the processor 21 determines whether the program has been tampered with using a hash calculation, for example, the processor 21 receives from the OTA server 40 the plaintext of the update program and a hash value obtained by hashing the plaintext with a hash function. The processor 21 then compares the received hash value with a hash value obtained by hashing the received plaintext, thereby determining whether the program has been tampered with.

[0054] The processor 21 may permit each of the ECUs 101 to 10x to perform normal control on the condition that an appropriate program is stored in the memory device 12. This allows the control system to verify the contents of the program update, thereby ensuring the integrity of the program and enhancing security.

[0055] In step S23, processor 21 issues a program rewrite request to the ECU where the version information of the program stored in memory device 12 does not match the version information of the update program managed in nonvolatile memory 30.

[0056] In step S24, the ECU with the mismatch is rewritten with the latest program that can be used. Processor 21 reads, from non-volatile memory 30, an update program corresponding to the ECU for which it has determined that the program version information is mismatched. Processor 21 then rewrites the program stored in memory device 12 of that ECU with the read update program. In this way, processor 21 performs update processing on the program with the mismatched version information to the update program. This allows the control system to maintain an appropriate combination of program versions for each of ECUs 101 to 10x.

[0057] In step S25, it is determined whether or not the storage of the latest program has been completed. The processor 21 determines whether or not the latest program is stored in the non-volatile memory 30. This is because if the update has failed, the update process is performed again using the latest program. Note that the latest program is the latest version of the program.

[0058] The processor 21 acquires version information of each program from the OTA server 40. The processor 21 compares the acquired version information with the version information of the update program stored in each storage area 329. Note that in this case, the comparison is performed with the version information stored in the storage area 329 corresponding to the ECU for which the update process has failed, rather than with all storage areas 329 corresponding to all ECUs 101 to 10x.

[0059] If the acquired total version information matches the version information in the total storage area 329, the processor 21 determines that the latest program is stored in the non-volatile memory 30, and proceeds to step S26. If the acquired version information does not match the version information in the storage area 329, the processor 21 determines that the latest program is not stored in the non-volatile memory 30, and proceeds to step S27. In other words, the processor 21 determines that a program with mismatched version information is not stored in the non-volatile memory 30. Note that the fact that the latest program is not stored in the non-volatile memory 30 means that reception of the update program has not been completed.

[0060] In step S26, the rewriting is resumed from the incomplete area. If the determination in step S20 is NO, the processor 21 can identify the update target area where the update process has failed, i.e., the incomplete area. The processor 21 obtains the update program corresponding to the incomplete area from the non-volatile memory 30 and performs the update process again. This allows the control system to perform the update process again without all ECUs 101 to 10x having two copies of the program. Therefore, the cost of the control system can be expected to be lower than when all ECUs 101 to 10x have two copies of the program. Furthermore, since the control system resumes the rewriting from the incomplete area, program recovery in the event of a failure can be quickly performed, and the recovery time can be shortened. Note that if the determination in step S20 is NO, the processor 21 may perform step S26 instead of step S25.

[0061] In step S27, a distribution request is made and the download is performed again. If the processor 21 determines that the update has failed and that the latest program is not stored in the nonvolatile memory 30, the processor 21 makes a distribution request for an update program to the OTA server 40 and receives the update program. Here, the processor 21 requests the distribution of the update program for which the update process has failed.

[0062] In this way, the control system requests the OTA server 40 to deliver the update program and receives the update program only when storage of the update program in the nonvolatile memory 30, i.e., reception of the update program, has not been completed. This allows the control system to reduce the number of communications with the OTA server 40.

[0063] <Effects> As described above, the control system includes a program management device having an OTA control device 20 that performs a program update process, and a nonvolatile memory 30 in which the received update program and the old program before the update are stored for each of the plurality of ECUs 101-10x. Therefore, each of the ECUs 101-10x does not need to have two programs in the memory device 12, and it is not necessary to switch the program side that the processor 11 executes. Therefore, the control system can prevent the configuration of the memory device 12 and the processing of the processor 11 in each of the ECUs 101-10x from becoming complicated.

[0064] Although the preferred embodiments of the present disclosure have been described above, the present disclosure is not limited to the above embodiments and various modifications are possible without departing from the spirit and scope of the present disclosure.

[0065] Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and modifications within the scope of equivalents. In addition, although various combinations and forms are shown in the present disclosure, other combinations and forms including only one element, more, or less than one element are also within the scope and spirit of the present disclosure.

[0066] This specification discloses the following technical ideas and combinations thereof.

[0067] Technical thought 1 A control system including a plurality of electronic control devices (101 to 10x), a program management device (20, 30) capable of wirelessly communicating with an external server provided outside the control system and managing programs in each electronic control device; Each electronic control device has a processing device (11) and a storage device (12) in which a program executable by the processing device is stored, The program management device an update processing device (20) that performs wireless communication with an external server to receive update programs for each electronic control device and updates the programs stored in the storage devices of each electronic control device to the update programs; The control system includes a program storage device (30) in which the received update program and the old program before the update in each electronic control device are stored for each of the plurality of electronic control devices.

[0068] Technical thought 2 The update program is a program that is different from the old program, In the control system according to Technical Idea 1, when the update processing device receives the update program, it encrypts the received update program and stores it in the program storage device.

[0069] Technical thought 3 The control system described in Technical Idea 1 or 2, in which the update processing device compares the update program stored in the program storage device with the program stored in the storage device and determines whether an appropriate program is stored in the storage device.

[0070] Technical thought 4 A control system described in any one of technical ideas 1 to 3, in which the update processing device performs an update failure determination to determine whether the update process has failed, and if it determines that the update has failed, obtains an update program from the program storage device and performs the update process again.

[0071] Technical thought 5 The storage device stores a program divided into a plurality of storage areas, and at least a part of the storage areas is a program update target area; The update processing device performs update processing for each update target area, the processing device notifies the update processing device of update completion every time the update target area is updated; The control system according to Technical Idea 4, wherein the update processing device determines that the update has failed if there is no update completion notification, identifies the update target area for which the update has failed, and performs the update process again starting from the update target area for which the update has failed.

[0072] technical thought 6 A control system according to Technical Idea 4 or 5, in which the update processing device determines that the update has failed and, if reception of the update program has not been completed, requests an external server to distribute the update program and receives the update program.

[0073] Technical thought 7 Each processing device executes the program stored in the storage device when execution is permitted by the update processing device, A control system described in any one of technical ideas 1 to 6, in which the update processing device compares the combination of versions of each update program stored in the program storage device with the combination of versions of each program stored in each storage device, and allows execution only if the two combinations match.

[0074] Technical thought 8 The control system according to Technical Idea 7, wherein the update processing device performs an update process for the program with the mismatched versions to an update program when the two combinations do not match. [Explanation of symbols]

[0075] 101 to 10x... ECU, 11... processor, 12... memory device, 20... OTA control device, 21... processing device, 22... memory device, 23... communication device, 30... non-volatile memory, 31... first storage area, 32... second storage area, 3x... xth storage area, 40... OTA server,

Claims

1. A control system including a plurality of electronic control devices (101 to 10x), a program management device (20, 30) capable of wireless communication with an external server provided outside the control system and managing programs in each electronic control device; Each electronic control device has a processing device (11) and a storage device (12) in which the program executable by the processing device is stored, The program management device an update processing device (20) that performs wireless communication with the external server to receive update programs for each electronic control device and performs update processing of the program stored in the storage device of each electronic control device to the update program; a program storage device (30) having a plurality of storage areas (31 to 3x) corresponding to the plurality of electronic control devices, Each memory area has an update program area (320) in which the received update program for updating the program stored in the memory device of the corresponding electronic control device is stored, and an old program area (310) in which the old program before the update in the corresponding electronic control device is stored.

2. the update program is a differential program from the old program, 2. The control system according to claim 1, wherein, upon receiving the update program, the update processing device encrypts the received update program and stores the encrypted program in the program storage device.

3. 3. The control system according to claim 1, wherein the update processing device compares the update program stored in the program storage device with the program stored in the storage device, and determines whether the appropriate program is stored in the storage device.

4. 3. The control system according to claim 1, wherein the update processing device performs an update failure determination to determine whether the update processing has failed, and if it determines that the update has failed, obtains the update program from the program storage device and performs the update processing again.

5. the storage device stores the program divided into a plurality of storage areas, and at least a part of the storage areas is an area to be updated for the program; the update processing device performs the update processing for each of the update target regions, the processing device notifies the update processing device of update completion every time the update target area is updated; The control system according to claim 4 , wherein the update processing device determines that the update has failed when the update completion notification is not received, identifies the update target area for which the update has failed, and performs the update process again from the update target area for which the update has failed.

6. 5. The control system according to claim 4, wherein, if the update processing device determines that the update has failed and reception of the update program has not been completed, the update processing device requests the external server to distribute the update program and receives the update program.

7. each processing device executes the program stored in the storage device when execution is permitted by the update processing device; 3. The control system according to claim 1, wherein the update processing device compares a combination of versions of each update program stored in the program storage device with a combination of versions of each program stored in each storage device, and grants the permission for execution only if the two combinations match.

8. 8. The control system according to claim 7, wherein, when the two combinations do not match, the update processing device performs the update process on the update program for the program with the mismatched versions.

9. A control system as described in Claim 6, wherein each memory area stores program rewrite completion information which is information that manages the extent to which the program update has been completed for the update target area in the corresponding electronic control device, and is used to determine whether all update processing for the electronic control device to be updated has been completed.

Citation Information

Patent Citations

  • Nenryodenchi

    JP1976067936A

  • Onboard computer system

    JP2010195111A

  • Software update system, communication device, software update method

    JP2014016952A

  • On-vehicle electronic control device program rewriting system and on-vehicle relay device

    JP2014182571A

  • In-vehicle updating apparatus, program, and method of updating program or data

    JP2019105946A