Update control device, update control method, and update control program

The update control device resolves the ambiguity in using update files from multiple communication methods by determining common and differential files, ensuring efficient and reliable updates for vehicle electronic control units.

JP7771892B2Active Publication Date: 2025-11-18DENSO CORP
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022127474
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-08-09
Publication Date
2025-11-18
Estimated Expiration
2042-08-09

AI Technical Summary

Technical Problem

When update files for electronic control units in vehicles are acquired via multiple communication methods, there is no clear specification on which file to use, leading to potential conflicts and inefficiencies in the update process.

Method used

An update control device that manages updates by acquiring files via both wireless and wired communication, determining common and differential files, and instructing the appropriate update files for electronic control units based on delivery status and instructions.

Benefits of technology

Ensures appropriate execution of updates, reduces processing load on communication networks, and minimizes rollback processes by using the correct update files.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007771892000001
    Figure 0007771892000001
  • Figure 0007771892000002
    Figure 0007771892000002
  • Figure 0007771892000003
    Figure 0007771892000003
Patent Text Reader

Abstract

To appropriately control an update process when update files are acquired almost simultaneously via wired communication and wireless communication.SOLUTION: An update control device includes: a first acquisition unit 101 for acquiring a first group of update files via wireless communication; a second acquisition unit 102 for acquiring a second group of update files via wired communication; a discrimination unit 107 for discriminating between common files and difference files when the second group of update files is acquired after the first group of update files is acquired and before update using one or more files included in the first group of update files is completed; a determination unit 108 that determines an applicable update file, which is a file used to update an ECU, according to whether the common files and / or difference files included in the first group of update files are delivered to the ECU and update instructions are given; a delivery unit 105 that delivers the applicable update file to the ECU; and an instruction unit 106 that instructs the ECU to update the ECU using the applicable update file.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an update control device that mainly controls software updates for electronic control devices mounted on vehicles, and a method and program implemented by the update control device. [Background technology]

[0002] Automobiles are equipped with various electronic control units connected via an in-vehicle network. With the recent development of autonomous driving technology, the functions required of automobiles are becoming more complex, and the number of electronic control units installed in automobiles is increasing.

[0003] As the number of electronic control units increases, when software updates for the electronic control units become necessary, the process of updating the software for each electronic control unit also becomes more complicated. For example, Patent Document 1 discloses that an on-board device is provided with an on-board update device that acts as a gateway, and the on-board update device distributes update programs to each on-board ECU. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2020-142565 Summary of the Invention [Problem to be solved by the invention]

[0005] Here, the present inventors have found the following problems as a result of detailed investigation. When updating an electronic control unit installed in a vehicle, it is assumed that the update file is acquired via a communication means consisting of a wireless communication method, or via a communication means consisting of a wired communication method when the vehicle is parked in a parking lot or in a repair shop. When update files can be acquired via multiple communication methods, it is possible that an update file acquired via one communication method may be acquired via another communication method while an update is being performed using the update file acquired via the other communication method. In this way, when multiple update files are acquired via different communication methods, it has not been specified until now which update file to use to update the electronic control unit.

[0006] SUMMARY OF THE INVENTION Therefore, an object of the present invention is to provide a device that controls the execution of update processing of an electronic control unit appropriately when update files are simultaneously acquired via wireless communication and wired communication. [Means for solving the problem]

[0007] An update control device according to one aspect of the present disclosure is an update control device that manages updates of an electronic control device mounted on a mobile body, and includes a first acquisition unit (101) that acquires a first update file group including one or more files for updating the electronic control device via wireless communication from outside the mobile body, and a second acquisition unit (102) that acquires a second update file group including one or more files for updating the electronic control device via wired communication from outside the mobile body, and when the second acquisition unit acquires the second update file group after the first acquisition unit acquires the first update file group and before an update using the one or more files included in the first update file group is completed, The electronic control device includes a determination unit (107) that determines common files, which are files common to both the first update file group and the second update file group, and differential files, which are files not common to the first update file group and the second update file group; a determination unit (108) that determines an applicable update file, which is a file to be used to update the electronic control device, depending on whether the common files and / or the differential files included in the first update file group have been delivered to the electronic control device and whether an update instruction has been issued; a delivery unit (105) that delivers the applicable update file to the electronic control device; and an instruction unit (106) that instructs the electronic control device to update the electronic control device using the applicable update file.

[0008] It should be noted that the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. [Effects of the Invention]

[0009] According to the above configuration, when update files are acquired almost simultaneously via wireless communication and wired communication, it is possible to appropriately execute the update process of the electronic control unit. Furthermore, by controlling the update process of the electronic control unit, it is possible to suppress the rollback process that is required after the update process. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of an electronic control system according to a first embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the configuration of an update control device according to each embodiment. [Figure 3] FIG. 2 is a diagram illustrating the operation of the update control device of each embodiment. [Figure 4] FIG. 2 is a diagram illustrating the operation of the update control device of each embodiment. [Figure 5] FIG. 2 is a diagram illustrating the operation of the update control device of each embodiment. [Figure 6] FIG. 10 is a diagram illustrating an example of the configuration of an electronic control system according to a second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0012] The present invention refers to the inventions described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks refer to the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.

[0013] The configurations and methods recited in the dependent claims are optional configurations and methods in the inventions recited in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods recited in the dependent claims, as well as the configurations and methods recited only in the embodiments without being recited in the claims, are optional configurations and methods in the present invention. The configurations and methods recited in the embodiments when the recitation of the claims is broader than the recitation of the embodiments are also optional configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In either case, by being recited in the independent claims, they become essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention has.

[0015] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in multiple embodiments may be collected and combined.

[0016] The problem described in the section on the problem to be solved by the invention is not a publicly known problem, but was discovered independently by the inventor, and this fact, together with the configuration and method of the present invention, affirms the inventive step of the invention.

[0017] 1. First embodiment (1) Electronic Control System S An electronic control system S equipped with an update control device 10 of this embodiment will be described using Figure 1. In the embodiment described below, the electronic control system S and the update control device 10 are described as an example of an on-vehicle system and an on-vehicle device that are "mounted" on a vehicle, which is a "moving body," but the present invention is not limited to this.

[0018] Here, "mobile body" refers to an object that can move at any speed. It also naturally includes cases where the moving body is stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and objects mounted on these vehicles. Furthermore, "mounted" includes not only cases where the device is directly fixed to the mobile body, but also cases where the device is not fixed to the mobile body but moves with the mobile body. For example, cases where the device is carried by a person riding on the mobile body, or cases where the device is mounted on cargo placed on the mobile body, are included.

[0019] The electronic control system S is a system configured from a plurality of electronic control devices (hereinafter referred to as ECUs (Electronic Control Units)). FIG. 1 shows the electronic control system S including two ECUs (ECU 20a, ECU 20b) in addition to the update control device 10, but the system may be configured from any number of ECUs. The ECUs are connected to each other via a communication network. The communication network may be, for example, an in-vehicle network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN), Ethernet (registered trademark), or a wireless communication network. In the following description, the ECUs 20a and 20b will be referred to as the ECUs 20 or simply as ECU 20, except when it is necessary to distinguish between them.

[0020] (2) About the update control device 10 (a) Configuration of the update control device 10 The update control device 10 is a device that manages updates of each ECU 20 that constitutes the electronic control system S. An example configuration of the update control device 10 will be described using FIG. 2. The update control device 10 includes a first update file acquisition unit 101, a second update file acquisition unit 102, a storage unit 103, a control unit 104, a distribution unit 105, and an instruction unit 106. The control unit 104 controls the operations of the first update file acquisition unit 101, the second update file acquisition unit 102, the storage unit 103, the distribution unit 105, and the instruction unit 106. The control unit 104 further implements a determination unit 107 and a decision unit 108.

[0021] 2, the update control device 10 may have functions other than those related to update control. For example, like the ECU 20 described later, the update control device 10 may have an update unit for updating the ECU that is the update control device.

[0022] The update control device 10 can be configured with a general-purpose CPU (Central Processing Unit), a volatile storage unit such as RAM, a non-volatile memory such as ROM, flash memory, or a hard disk, various interfaces, and an internal bus connecting these. Software can be executed on this hardware to perform the functions of the functional blocks shown in Fig. 2. Of course, the update control device 10 can also be realized by dedicated hardware such as an LSI.

[0023] In this embodiment, the update control device 10 is assumed to be in the form of an ECU as a semi-finished product, but is not limited to this. For example, components may be in the form of a semiconductor circuit or a semiconductor module, semi-finished products may be in the form of an electronic control device, an electronic control unit, or a system board, and finished products may be in the form of a server, a workstation, a personal computer (PC), a tablet, a smartphone, a mobile phone, or a navigation system. Note that the update control device 10 may be configured as a single ECU or multiple ECUs.

[0024] The first update file acquisition unit 101 (corresponding to the "first acquisition unit") acquires an update file group including one or more files for updating the ECU 20 from outside the vehicle via wireless communication. For example, the first update file acquisition unit 101 acquires the update file group transmitted from a server device or the like via wireless communication such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, 5G, or DSRC (Dedicated Short Range Communication). Alternatively, the first update file acquisition unit 101 may acquire the update file group via an ECU having a communication function such as a TCU (Telematics Control Unit). Hereinafter, the update file group acquired by the first update file acquisition unit 101 will be referred to as the "first update file group."

[0025] When the update control device 10 itself has a communication function and the first update file acquisition unit 101 acquires a group of update files from outside the vehicle without going through a TCU or the like, the first update file acquisition unit 101 is referred to as an OTA (Over The Air) client in the AUTOSAR (AUTomotive Open System ARchitecture) specification.

[0026] The second update file acquisition unit 102 (corresponding to the "second acquisition unit") acquires an update file group including one or more files for updating the ECU 20 via wired communication from outside the vehicle. For example, when the vehicle is in a repair shop, the second update file acquisition unit 101 acquires the update file group from a dedicated device by connecting via OBD (On Board Device). Alternatively, when the vehicle is parked in a parking lot, the second update file acquisition unit 102 may acquire the update file group by connecting the vehicle to a wired LAN (Local Area Network) or the Internet. Hereinafter, the update file group acquired by the second update file acquisition unit 102 will be referred to as the second update file group.

[0027] The update file group includes one or more update files for updating the software installed in each ECU 20. Alternatively, the update file group may include split files obtained by splitting one update file into multiple files. The update file group may further include information for identifying the ECUs that install the software to be updated and information indicating the order in which the update files are to be executed. Hereinafter, an ECU that is updated using an update file is referred to as an update target ECU.

[0028] The update file may be a file for updating software that runs on an OS (Operating System) installed in the ECU 20, or may be a file for updating software that is middleware (for example, an OS) that runs the ECU 20. As described above, the update file updates software installed in the ECU 20, but in the following description, the update file will be described as updating the ECU 20.

[0029] The storage unit 103 is a non-volatile memory such as a ROM, a flash memory, or a hard disk, and stores the update files acquired by the first update file acquisition unit 101 and the second update file acquisition unit 102. If the update control device 10 itself is an ECU to be updated, the storage unit 103 may further store software to be updated by the update files.

[0030] The control unit 104 implements a determination unit 107 and a decision unit 108. The control unit 104 has a function of controlling the distribution of update files and update instructions, and is called a UCM (Update and Configuration Management) master in the AUTOSAR specification.

[0031] When the second update file acquisition unit 102 acquires the second update file group after the first update file acquisition unit 101 has "acquired" the first update file group and before the update of the ECU 20 using the update files included in the first update file group is completed, the determination unit 107 determines the common files and difference files between the first update file group and the second update file group. Here, a common file is a file that is commonly included in both the first update file group and the second update file group. In contrast, a difference file is a file that is not common to the first update file group and the second update file group.

[0032] "Acquired" includes not only acquiring all of the update file group, but also acquiring enough of the update file group to be able to identify its contents, such as acquiring a list of the files included in the update file group.

[0033] For example, if the update files included in the first update file group and the second update file group are both files for updating ECU 20a and the versions of these files are the same, the update files included in the first update file group and the second update file group are common files.

[0034] In contrast, for example, if the update files included in the first update file group and the second update file group are both files for updating the ECU 20a, but the update files included in the first update file group are version [1.0] while the update files included in the second update file group are version [1.1], these update files are not common to the first update file group and the second update file group. Therefore, both the files of version [1.0] and [1.1] are difference files.

[0035] As another example, there is a case where the first update file group includes an update file for ECU 20a, while the second update file group does not include an update file for ECU 20a. In this case, the update file for updating ECU 20a included in the first update file group is a differential file because it is not common to the first update file group and the second update file group. In this example, the second update file group does not include a differential file, but it goes without saying that there is a case where only the second update file group includes a differential file, or where either the first update file group or the second update file group includes both a common file and a differential file.

[0036] The determination unit 107 further determines whether the update of the ECU 20 using the update files included in the first update file group has been completed, depending on whether a signal indicating that the update using the update files has been completed has been received from the update-target ECU 20. Alternatively, when the second update file acquisition unit 102 acquires the second update file group, the determination unit 107 may transmit a signal to the update-target ECU 20 inquiring about the update status, and determine whether the update of the ECU 20 using the update files included in the first update file group has been completed, based on the signal indicating the update status transmitted from the ECU 20. At this time, the ECU 20 may transmit to the update control device 10 information indicating the update status of the ECU 20, as well as version information of the software installed in the ECU 20.

[0037] The determination unit 108 determines an update file (corresponding to an "applicable update file") to be used to update the ECU 20, depending on the update status of the common file and the difference file determined by the determination unit 107. Details of the processing by the determination unit 108 will be described later.

[0038] The distribution unit 105 "distributes" the update file to be used for updating the ECU determined by the determination unit 108 from among the update files stored in the storage unit 103 to the update target ECU 20. When distributing the update file group to the ECU 20, the files included in the update file group may be divided into several files, and the divided files may be distributed to the ECU 20 sequentially.

[0039] "Distributing" includes not only direct distribution of a file from the update control device to the electronic control device, but also indirect distribution via another electronic control device and moving the area in memory where the file is stored. The file to be distributed may be the entire file or part of a divided file.

[0040] The instruction unit 106 instructs the update target ECU 20 to update the ECU using the update file determined by the determination unit 108. For example, after the distribution unit 105 distributes the update file to the update target ECU 20, the instruction unit 106 instructs the update of the ECU when the instruction unit 106 receives a signal from the update target ECU 20 indicating that the update file has been acquired.

[0041] Furthermore, when it is necessary to stop the update process after instructing the update target ECU 20 to perform an update, the instruction unit 106 instructs the update target ECU 20 to stop the update. Alternatively, when it is necessary to perform a so-called rollback process, in which the ECU 20 returns to the state before the update after the ECU 20 completes the update based on the update instruction from the instruction unit 106, the instruction unit 106 instructs the ECU 20 to perform a rollback. That is, the instruction unit 106 is an instruction unit that in addition to instructing the update, also instructs the ECU 20 to stop the update and perform the rollback process.

[0042] It should be noted that, when there are multiple update target ECUs 20, the instruction unit 106 is assumed to issue update instructions to the update target ECUs 20 in order, starting with the update target ECUs 20 for which delivery of the update file has been completed. However, the instruction unit 106 may issue update instructions to all update target ECUs 20 simultaneously. In electronic control systems, particularly in-vehicle systems, multiple ECUs may operate in conjunction with one another. If the software versions installed in the multiple ECUs are different, malfunctions may occur, so it is desirable to update the ECUs at the same time. Therefore, in such cases, the instruction unit 106 issues update instructions to all update target ECUs 20 simultaneously after the update file has been delivered to all update target ECUs 20, so that the updates to the multiple linked ECUs 20 are executed at the same time.

[0043] Alternatively, the instruction unit 106 may issue update instructions to each update target ECU 20 so that the updates are executed in a predetermined order. For example, if the update file group includes information indicating the order in which the updates are to be executed, the instruction unit 106 issues update instructions so that the updates of the update target ECUs 20 are executed in the specified order. To execute the updates in the specified order, for example, the instruction unit 106 issues update instructions sequentially in the order in which the updates are to be executed, or issues update instructions by specifying the time at which the updates are to be executed. Even if the order in which the updates are to be executed is not specified, the instruction may be issued in order of files that can be easily rolled back in the event of an update failure, for example.

[0044] In this embodiment, the functions and operations of the distribution unit 105 and the instruction unit 106 are described, focusing on a case where the second update file acquisition unit 102 acquires the second update file group after the first update file acquisition unit 101 acquires the first update file group and before the update of the ECU using the update files included in the first update file group is completed. However, even if the first update file acquisition unit 101 and the second update file acquisition unit 102 acquire the update file groups at timings different from those in this embodiment, the distribution unit 105 distributes the update files to the update target ECU 20, and the instruction unit 106 instructs the update target ECU 20 to perform the update.

[0045] For example, when the first update file acquisition unit 101 acquires the first update file group and the second update file acquisition unit 102 does not acquire the second update file group, the distribution unit 105 distributes the update files included in the first update file group to the update target ECU 20. Then, the instruction unit 106 instructs the update target ECU 20 to update using the update files distributed by the distribution unit 105.

[0046] As another example, if the second update file acquisition unit 102 acquires a second update file group after the update using the update files included in the first update file group acquired by the first update file acquisition unit 101 is completed, the distribution unit 105 may distribute the update files included in the second update file group to the ECU 20 to be updated, and the instruction unit 106 may instruct the ECU 20 to be updated using the files distributed by the distribution unit 105.

[0047] (b) Processing of the decision unit 108 Next, a description will be given of a process performed by the determination unit 108 to determine the update file to be used for updating the update target ECU 20. The determination unit 108 determines the update file to be used for updating the update target ECU 20 depending on whether the common file and / or the difference file included in the first update file group has been delivered to the update target ECU 20 and whether an update instruction using the common file and / or the difference file has been issued.

[0048] First, a case where a common file is included in the first update file group and the second update file group will be described. The determination unit 108 determines whether the common file included in the first update file group has been distributed from the distribution unit 105 to the update target ECU 20. Here, if the common file included in the first update file group (corresponding to the "first common file") has not yet been distributed, the determination unit 108 determines the common file included in the second update file group (corresponding to the "second update file") as the update file to be used for updating the update target ECU 20. On the other hand, if the common file included in the first update file group has already been distributed, the determination unit 108 determines the common file included in the first update file group as the update file to be used for updating the update target ECU 20.

[0049] As described above, a common file is a file that is common to the first update file group and the second update file group. After the common file included in the first update file group has been distributed, it is preferable to update the ECU 20 using the common file of the first update file group that has already been distributed. This is because if the ECU 20 were to be updated using the common file of the second update file, a file with the same content (i.e., the common file) would have to be transmitted again, which would unnecessarily use the resources of the in-vehicle communication network.

[0050] In contrast, before the delivery of the common files included in the first update file group, it is preferable to update the ECU 20 using the common files included in the second update file group. If the update of the ECU 20 is not completed for some reason, a signal notifying the sender of the update files that the update is not completed may be transmitted, or the sender device receiving the signal notifying the sender of the update that the update is not completed may retransmit the update file group to the update control device 10. If the sender of the update file group is a server device, it is necessary to transmit and receive signals via wireless communication and retransmit the update file group, consuming wireless communication network resources. On the other hand, if the sender of the update file group is a device connected to the electronic control system S via a wired connection, it is possible to reacquire the update file group without consuming wireless communication network resources. Furthermore, it may be possible to immediately detect a malfunction that caused the update to be not completed using a device connected to the electronic control system S via OBD. Therefore, before the delivery of the common files included in the first update file group, the ECU 20 is updated using the common files included in the second update file group.

[0051] If the file size of the common file is large, it may happen that the common file is divided into several files, and the distribution unit 105 transmits the divided common files to the update target ECU 20. In this case, the determination unit 108 may determine the update file to be used for updating the ECU 20 based on the distribution status of each of the divided common files.

[0052] For example, a case will be described in which a common file included in a first update file group is split into two files (common file a and common file b), one of which, common file a, has already been delivered to ECU 20, while the other, common file b, has not yet been delivered. In this case, determination unit 108 determines common file a, which has already been delivered to ECU 20, as the update file to be used for the ECU update, but does not determine common file b, which has not yet been delivered, as the update file to be used for the ECU update. Then, of the common files included in the second update file group, a file corresponding to common file b is determined as the update file to be used for the ECU update. According to this example, the update of ECU 20 is performed using the common file included in the first update file group and the common file included in the second update file group.

[0053] It should be noted that a difference file, which will be described later, may also be divided into a plurality of files, and the distribution unit 105 may transmit the divided difference files to the ECU 20 in sequence.

[0054] Next, a case will be described in which the first update file group includes only common files, i.e., does not include difference files, and the second update file group includes difference files in addition to common files. In this case, as described above, which common file of the first update file group and the second update file group is used to update the ECU 20 is determined depending on whether the common file included in the first update file group has not yet been distributed. Furthermore, the determination unit 108 determines the difference file included in the second update file group as the update file to be used to update the ECU.

[0055] In contrast, a case will be described in which the first update file group includes a difference file in addition to a common file, and the second update file group includes only the common file but no difference file. As in the above example, which common file of the first update file group and the second update file group is used to update the ECU 20 is determined based on whether or not the common file included in the first update file group has not yet been distributed. Then, the determination unit 108 does not determine the difference file included in the first update file group as the update file to be used to update the ECU.

[0056] However, if the delivery unit 105 has already delivered the difference files included in the first update file group to the ECU 20 and the instruction unit 106 has already issued an instruction to update using the difference files, it is possible that the update using the difference files has already started in the ECU 20. In this case, the instruction unit 106 issues an instruction to stop the update using the difference files. Alternatively, after the update of the ECU 20 using the difference files is completed, the instruction unit 106 issues an instruction to restore the state before the update using the difference files was executed.

[0057] Next, a case where the first update file group and the second update file group each include a difference file will be described. Hereinafter, the difference file included in the first update file group will be referred to as the first difference file, and the difference file included in the second update file group will be referred to as the second difference file.

[0058] Before the distribution unit 105 distributes the first difference file, the determination unit 108 determines the second difference file as the update file. Then, the distribution unit 105 distributes the determined second difference file, and the instruction unit 106 instructs the update using the second difference file. Note that the determination unit 108 does not determine the first difference file as the update file to be used for updating the ECU 20. Therefore, the distribution unit 105 does not distribute the first difference file to the ECU 20. As a result, the update using the first difference file is not performed in the ECU 20.

[0059] After the distribution unit 105 distributes the first difference file, but before the instruction unit 106 issues an instruction to update using the first difference file, the determination unit 108 determines the second difference file as the update file. Then, the distribution unit 105 distributes the determined second difference file, and the instruction unit 106 issues an instruction to update using the second difference file. Note that the determination unit 108 does not determine the first difference file as the update file to be used for updating the ECU 20. Therefore, the instruction unit 106 does not issue an instruction to update using the first difference file. As a result, the update using the first difference file is not performed in the ECU 20.

[0060] Instead of instructing not to update using the first difference file, the instructing unit 106 may instruct to discard the first difference file.

[0061] After distribution unit 105 distributes the first difference file and instruction unit 106 has issued an instruction to update using the first difference file, determination unit 108 determines the second difference file as the update file. Then, distribution unit 105 distributes the determined second difference file, and instruction unit 106 instructs to update using the second difference file. Instruction unit 106 further instructs to stop the update using the first difference file. As a result, the update using the first difference file is not performed in ECU 20.

[0062] Alternatively, after the distribution unit 105 distributes the first differential file and the instruction unit 106 has issued an instruction to update using the first differential file, the update using the first differential file may have progressed to some extent. In this case, after the update using the first differential file is completed, the instruction unit 106 instructs a rollback process to restore the state to the state before the update using the first differential file was executed.

[0063] Generally, the latest update files are stored in devices connected to the electronic control system S via wired communication. Furthermore, because some update files may be provided only from devices connected via OBD at a repair shop or the like, it is generally desirable to perform updates using files included in the update file group acquired via wired communication. Therefore, if the second update file group includes a difference file, the determination unit 108 determines the difference file as the update file to be used for the ECU update. On the other hand, update files provided from devices connected via wireless communication may not necessarily be files that require updating. Furthermore, because the update file is provided via wireless communication, it may be a file disguised as an external attack. In particular, a file that is not included in the update file group provided via wired communication, such as OBD connection, but is included only in the update file group provided via wireless communication, may not be a legitimate update file. Therefore, if the first update file group includes a difference file, the determination unit 108 does not determine the difference file as the update file to be used for the ECU update.

[0064] Note that a specific update file may be provided only via either wireless communication or wired communication. For example, an update file for the ECU 20a is always acquired via wireless communication and never via wired communication. In such a case, the update file for the ECU 20a acquired via wireless communication is always a differential file that is different from the update file acquired via wired communication. Therefore, applying this embodiment may result in an inappropriate update of the ECU 20a. Therefore, it is desirable to assign a flag to such an update file indicating that it is provided only via wireless communication, so that the update is not stopped or a rollback process is not performed even if the determination unit 108 determines that the update file is a differential file.

[0065] (3) About ECU20 Each ECU 20 constituting the electronic control system S includes an update unit 201 that executes software updates and a storage unit 202.

[0066] The update unit 201 performs update processing using an update file based on instructions from the update control device 10. The update unit 201 is also called a UCM subordinate in the AUTOSAR specification.

[0067] When the software update process is completed, the update unit 201 transmits an update completion notification indicating that the update has been completed to the update control device 10. Furthermore, when the software update process fails, the update unit 201 transmits an update failure notification indicating that the update has failed to the update control device 10.

[0068] Furthermore, when the update unit 201 receives a rollback instruction from the update control device 10, it performs a rollback process to return the software to the state before the update.

[0069] The storage unit 202 is a non-volatile memory such as a ROM, flash memory, or hard disk, and stores the software and update files installed in each ECU. Although not shown in Fig. 1, the storage unit 202 may have multiple storage areas.

[0070] Each ECU 20 in this embodiment is, for example, an ECU based on a platform that allows dynamic function expansion, called an Adaptive Platform (hereinafter, AP) in the AUTOSAR specification. The AP is a platform that is primarily suitable for ECUs for autonomous driving. Alternatively, these ECUs may be, for example, ECUs based on a platform that optimizes static functions, called a Classic Platform (hereinafter, CP) in the AUTOSAR specification. Note that the CP is a platform that is primarily suitable for ECUs for vehicle control.

[0071] (4) Operation of the update control device 10 The operation of the update control device 10 will be described using Figures 3 to 5. The operations shown in Figures 3 to 5 not only show the update control method executed by the update control device 10, but also show the processing procedure of an update control program that can be executed by the update control device 10. These processes are not limited to the order shown in Figures 3 to 5. In other words, the order may be changed as long as there are no constraints, such as a relationship in which a certain step uses the result of the previous step.

[0072] The first update file acquisition unit 101 of the update control device 10 acquires a first group of update files from outside the vehicle via wireless communication (S101). If the update of the ECU 20 using the update file group acquired in S101 has been completed, the process ends (S102: Y). On the other hand, if the update of the ECU 20 has not been completed (S102: N), the second update file acquisition unit 102 determines whether or not the update file group has been acquired from outside the vehicle via wired communication (S103). If the second update file acquisition unit 102 has acquired the update file group in S103 (S103: Y), the judgment unit 107 judges the common files and difference files included in the update file groups acquired by the first update file acquisition unit 101 and the second update file acquisition unit 102 (S104). In S104, when the determination unit 107 determines that the common file is included in the first updated file group and the second updated file group (S105: Y), the series of processes shown in FIG. 4 is performed (A s ).

[0073] FIG. 4 shows the process when the determining unit 107 determines the common files included in the first updated file group and the second updated file group in S104 of FIG. The determination unit 107 determines whether the common file included in the first update file group has not yet been delivered to the ECU 20 or has already been delivered (S201). Here, if the common file included in the first update file group has not yet been distributed (S201: Y), the determination unit 108 determines the common file included in the second update file group as the update file to be used for updating the ECU 20 (S202). Next, the distribution unit 105 distributes the common files included in the determined second update file group to the ECU 20 (S203). After delivering the update file to ECU 20, if a signal indicating that the update file has been acquired is received from ECU 20 (S204: Y), instruction unit 106 instructs updating of the ECU using the common file delivered in S203 (S205).

[0074] In contrast, if the result of the determination in S201 is that the common files included in the first update file group have already been distributed, the determination unit 108 determines the common files included in the first update file group as the update files to be used to update the ECU 20 (S206). If the instruction unit 106 has not issued an update instruction using the common file included in the first update file group (S207: N), the instruction unit 106 issues an update instruction using the common file included in the first update file group (S208).

[0075] 3, the operation of the update control device 10 will be described. When the series of processes shown in Fig. 4 is completed, or when it is determined that the files included in the first update file group and the second update file group are not common files, the process proceeds to S106. In S104, when the determination unit 107 determines that the differential files are included in the first update file group and the second update file group (S106: Y), the series of processes shown in FIG. 5 are performed (B s ).

[0076] FIG. 5 shows the process when the determining unit 107 determines the difference files included in the first update file group and / or the second update file group in S104 of FIG. If the difference file is included in the second update file group (S301: Y), the determination unit 108 determines the difference file included in the second update file group as the update file to be used for updating the ECU 20 (S302). Next, the distribution unit 105 distributes the difference files included in the determined second update file group to the ECU 20 (S303). After delivering the difference file to ECU 20, if a signal indicating that the difference file has been acquired is received from ECU 20 (S304: Y), instruction unit 106 instructs updating of the ECU using the difference file delivered in S303 (S305). Furthermore, if the differential file is included in the first update file group (S306: Y) and the instruction unit 106 has issued an update instruction using the differential file included in the first update file group (S307: Y), the instruction unit 106 will instruct to stop updating using the differential file included in the first update file group (S308).

[0077] In addition, instead of S308 shown in Figure 5, the instruction unit 106 may issue a rollback instruction to return to the state before the update using the differential file included in the first update file group was performed after the update using the differential file is completed.

[0078] Then, when the series of processes shown in FIG. 5 is completed, or when it is determined that the files included in the first update file group and the second update file group are not difference files, the update control device 10 ends the process.

[0079] Although not shown in FIG. 3, when determining the update status of the first update file group in S102, the update control device 10 may send a signal to the update target ECU 20 to inquire about the update status.

[0080] According to this embodiment, when update files are acquired simultaneously via wireless communication and wired communication, it is possible to update the ECU using the appropriate update file. Furthermore, by performing an update using an update file for which distribution or an update instruction has been completed, depending on the type of update file, the processing load on the communication network can be reduced. Furthermore, by preventing an ECU from being updated using an unnecessary update file, it is possible to suppress rollback processing for unnecessary update files.

[0081] (5) Variations In the above-described embodiment, an example has been described in which the control unit 104 controls the update of the ECU 20 when the second update file acquisition unit 102 acquires the second update file group after the first update file acquisition unit 101 acquires the first update file group and before the update of the ECU using the update files included in the first update file group is completed. However, in the update control device 10, the control unit 104 may also control the update of the ECU 20 when the second update file acquisition unit 102 acquires the second update file group after the update using the first update file group acquired by the first update file acquisition unit 101 is completed.

[0082] When the second update file acquisition unit 102 acquires the second update file group after the update using the first update file group acquired by the first update file acquisition unit 101 is completed, the determination unit 107 determines the common files and difference files included in the first update file group and the second update file group, as in the first embodiment.

[0083] If the first update file group and the second update file group include a common file, the determination unit 108 determines the common file of the first update file group as the file to be used for updating the ECU 20. However, because the update of the common file of the first update file group has already been completed, the update control device 10 does not perform any further update processing on the ECU 20.

[0084] If the second update file group includes a difference file, the determination unit 108 determines the difference file of the second update file group as the file to be used for updating the ECU 20. In this case, the distribution unit 105 distributes the difference file of the second update file group to the update target ECU 20, and the instruction unit 106 instructs the update target ECU 20 to update using the difference file distributed by the distribution unit 105.

[0085] On the other hand, if the first update file group includes a difference file, the instruction unit 106 instructs a rollback process, i.e., a return to the state before the update using the difference file of the first update file group that has already been updated.

[0086] However, if time has passed between the time the first update file acquisition unit 101 acquires the update file group and the time the second update file acquisition unit 102 acquires the update file group, the contents of the files included in these update file groups may be completely different. Therefore, even if a difference file included in the first update file group is, for example, a legitimate update file rather than a file disguised as an external attack, this modified example may cause the rollback process to return the file to its pre-update state. Therefore, it is desirable to apply this modified example only when the time between the time the first update file acquisition unit 101 acquires the update file group and the time the second update file acquisition unit 102 acquires the update file group is within a predetermined period.

[0087] 2. Second embodiment In the above-described embodiment, it is assumed that each ECU 20 constituting the electronic control system S is different hardware, and that the update control device 10 and each ECU 20 are different hardware. However, the update control device 10 and each ECU 20 are not limited to being different hardware.

[0088] An example of an electronic control system S of this embodiment will be described with reference to Fig. 6. Fig. 6 illustrates two ECUs 100a and 100b as ECUs that constitute the electronic control system S. Each of the ECUs 100a and 100b that constitute the electronic control system S has a virtual machine (abbreviated as VM (Virtual Machine) in the drawing).

[0089] The ECU 100a includes a virtual machine 11, a virtual machine 20a, a hypervisor (abbreviated as HV (Hypervisor) in the drawings) 110, and a real storage 120. The hypervisor 110 is software that virtualizes the ECU 100a. In the example of FIG. 6, the virtual machines 11 and 20a are built on the hypervisor 110. The virtual machines built on the hypervisor 110 are virtually connected to each other.

[0090] Although omitted in Fig. 6, the virtual machine 11 of this embodiment realizes each component of the update control device 10 shown in Fig. 2. The functions and operations of each component of the virtual machine 11 are the same as those of the first embodiment. That is, the virtual machine 11 of this embodiment functions as the update control device 10 of the first embodiment described above.

[0091] The ECU 100b is an ECU connected to the ECU 100a via a communication network, and includes a virtual machine 20b, a hypervisor 210, and a real storage 220. Similar to the ECU 100a, the hypervisor 210 is software that virtualizes the ECU 100b, and the virtual machine 20b is built on the hypervisor 210.

[0092] Both the real storages 120 and 220 are hardware memories, and are volatile memories such as SRAM and DRAM, or non-volatile memories such as ROM, flash memory, or hard disks. The storage unit 103 of the virtual machine 11 and the storage unit 202a of the virtual machine 20a are virtual memories realized by virtualizing the storage area of ​​the real storage 120. The same is true for the storage unit 202b.

[0093] Furthermore, the virtual machines 20a and 20b of this embodiment implement update units (201a and 201b) and storage units (202a and 202b), respectively, similar to the ECUs 20a and 20b of the respective embodiments. The update units 201a and 201b and storage units 202a and 202b of this embodiment have the same functions and operations as those of the first embodiment. That is, the virtual machines 20a and 20b of this embodiment function as the ECUs 20a and 20b of the above-described embodiments.

[0094] As described above, the storage unit 103 of the virtual machine 11 and the storage unit 202a of the virtual machine 20a are virtual memories on the same real storage 120. Therefore, when the distribution unit 105 distributes the update file stored in the storage unit 103 to the virtual machine 20a, the distribution does not have to be via a network. Instead, the distribution unit 105 distributes the update file stored in the storage unit 103 to the storage unit 202, thereby distributing the update file to the virtual machine 20a.

[0095] 3. Summary The features of the update control device in each embodiment of the present invention have been described above.

[0096] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.

[0097] The block diagrams used to explain the embodiments classify and organize the device configuration by function. The blocks representing each function can be realized by any combination of hardware or software. Furthermore, because they represent functions, the block diagrams can also be understood as disclosures of method inventions and program inventions that realize the methods.

[0098] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints, such as one step utilizing the results of another step that precedes it.

[0099] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.

[0100] The update control device of each embodiment is assumed to be a device for controlling the update of an electronic control device that constitutes an on-board system installed in a vehicle, but the update control device of the present invention is applicable to a device that controls the update of any electronic control device, except as specifically limited in the claims.

[0101] Examples of the form of the device of the present invention include the following. Examples of the component include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include an electronic control unit (ECU) and a system board. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.

[0102] Furthermore, necessary functions such as an antenna and a communication interface may be added to each device.

[0103] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also by a combination of a program for realizing the present invention recorded on a recording medium such as a memory or hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute the program.

[0104] A program stored in a non-transitory physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]

[0105] Although the present disclosure has been described as an update control device for an on-board electronic control device mounted mainly on an automobile, it can be applied to any moving object, such as a motorcycle, a ship, a train, an airplane, etc. Furthermore, it is not limited to moving objects, but can be applied to any product that includes a microcomputer. [Explanation of symbols]

[0106] 10, 11 Update control device, 101 First update file acquisition unit, 102 Second update file acquisition unit, 105 Distribution unit, 106 Instruction unit, 107 Determination unit, 108 Decision unit

Claims

1. An update control device that manages updates to an electronic control device mounted on a mobile object, a first acquisition unit (101) that acquires a first update file group including one or more files for updating the electronic control device via wireless communication from outside the mobile body; a second acquisition unit (102) that acquires a second update file group including one or more files for updating the electronic control unit from outside the mobile body via wired communication; a determination unit (107) that, when the second acquisition unit acquires the second update file group after the first acquisition unit acquires the first update file group and before the update using the one or more files included in the first update file group is completed, determines a common file that is a file common to both the first update file group and the second update file group, and a difference file that is a file not common to the first update file group and the second update file group; a determination unit (108) that determines an applicable update file, which is a file to be used to update the electronic control device, depending on whether the common file and / or the difference file included in the first update file group has been delivered to the electronic control device and whether an update instruction has been issued; a distribution unit (105) that distributes the application update file to the electronic control device; an instruction unit (106) that instructs the electronic control device to update the electronic control device using the applicable update file; An update control device (10, 11) comprising:

2. When the common file included in the first update file group is defined as a first common file and the common file included in the second update file group is defined as a second common file, The determination unit If the first common file has not yet been distributed, the second common file is determined to be the update file to be applied; If the first common file has been distributed, determine the first common file as the update file to be applied. The update control device according to claim 1 .

3. The determination unit further determines the difference file included in the second update file group as the update file to be applied. The update control device according to claim 2.

4. the determination unit does not determine the difference file included in the first update file group as the update file to be applied. The update control device according to claim 2.

5. After the difference files included in the first update file group have been distributed and after an update instruction using the difference files included in the first update file group has been issued, the instruction unit further instructs stopping the update using the difference file included in the first update file group.

5. The update control device according to claim 4.

6. After the difference files included in the first update file group have been distributed and after an update instruction using the difference files included in the first update file group has been issued, the instruction unit further instructs, after completing the update of the electronic control device using the difference files included in the first update file group, to restore the state before the update using the difference files included in the first update file group was performed.

5. The update control device according to claim 4.

7. When the difference file included in the first update file group is a first difference file and the difference file included in the second update file group is a second difference file, and the first difference file has not yet been distributed, the determination unit determines the second difference file as the update file to be applied. The update control device according to claim 1 .

8. When the difference file included in the first update file group is set as a first difference file and the difference file included in the second update file group is set as a second difference file, and the first difference file has been distributed and an update instruction using the first difference file has not yet been issued, the determination unit determines the second difference file as the update file to be applied. The update control device according to claim 1 .

9. When the difference file included in the first update file group is set as a first difference file and the difference file included in the second update file group is set as a second difference file, after the first difference file has been distributed and after an update instruction using the first difference file has been issued, the determination unit determines the second difference file as the update file to be applied; the instruction unit further instructs stopping the update using the first difference file. The update control device according to claim 1 .

10. When the difference file included in the first update file group is set as a first difference file and the difference file included in the second update file group is set as a second difference file, after the first difference file has been distributed and after an update instruction using the first difference file has been issued, the determination unit determines the second difference file as the update file to be applied; the instruction unit further instructs, after the update of the electronic control device using the first difference file is completed, to restore the electronic control device to a state before the update using the first difference file is executed. The update control device according to claim 1 .

11. An update control method executed by an update control device that manages updates of an electronic control device mounted on a mobile object, comprising: acquiring a first update file group including one or more files for updating the electronic control device from outside the mobile body via wireless communication; acquiring a second update file group including one or more files for updating the electronic control unit from outside the mobile body via wired communication; when the second update file group is acquired after the first update file group is acquired and before the update using the one or more files included in the first update file group is completed, determining common files that are files common to both the first update file group and the second update file group, and difference files that are files not common to the first update file group and the second update file group, determining an applicable update file to be used to update the electronic control device according to whether the common file and / or the difference file included in the first update file group has been delivered to the electronic control device and whether an update instruction has been issued; Delivering the application update file to the electronic control device; instructing the electronic control unit to update the electronic control unit using the applied update file; Update control method.

12. An update control method that can be executed by an update control device that manages updates of an electronic control device mounted on a mobile object, comprising: acquiring a first update file group including one or more files for updating the electronic control device from outside the mobile body via wireless communication; acquiring a second update file group including one or more files for updating the electronic control unit from outside the mobile body via wired communication; when the second update file group is acquired after the first update file group is acquired and before the update using the one or more files included in the first update file group is completed, determining common files that are files common to both the first update file group and the second update file group, and difference files that are files not common to the first update file group and the second update file group, determining an applicable update file to be used to update the electronic control device according to whether the common file and / or the difference file included in the first update file group has been delivered to the electronic control device and whether an update instruction has been issued; Delivering the application update file to the electronic control device; instructing the electronic control unit to update the electronic control unit using the applied update file; Update control program.

Citation Information

Patent Citations

  • Program update management device

    JP2007334471A

  • On-vehicle update device, update processing program and method of updating program

    JP2020142565A

  • On-vehicle update device, update processing method, and update processing program

    JP2021138368A

  • On-vehicle relay device, information processing method, and program

    JP2021166335A

  • Power tool system and upgrading method for the same

    US20200233658A1