Mobile body control device, mobile body control method, and program
A dual-bank ROM memory system in vehicle control devices ensures reliable data integrity by backing up unique information during software updates, addressing operational issues and enhancing safety and sustainability.
Patent Information
- Application Number
- JP2024051652
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-12-04
- Estimated Expiration
- 2044-03-27
AI Technical Summary
Existing vehicle control systems face issues where loss of setting information can lead to improper operation or sensor malfunction, necessitating dealer intervention, impacting traffic safety and sustainable transportation systems.
Implementing a mobile object control device with a rewritable dual-bank ROM memory system that backs up unique information to a separate bank during software updates, ensuring reliable data integrity by verifying and updating information before and after updates.
Ensures continued normal operation by preventing loss of unique information, enhancing reliability and contributing to improved traffic safety and sustainable transportation systems.
Smart Images

Figure 0007780568000001 
Figure 0007780568000002 
Figure 0007780568000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a mobile object control device, a mobile object control method, and a program. [Background technology]
[0002] Conventionally, technologies for supporting software updates have been proposed for control devices mounted on moving bodies such as vehicles. For example, Patent Document 1 discloses a configuration in which setting values and learning values used for software are stored in different banks of the same memory component or in one of two areas of different memory components, and after writing updated software to the other, the setting values and learning values stored in one area are copied to the other, so that the setting values and learning values can continue to be used for control even after the software update. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2022-049975 Summary of the Invention [Problem to be solved by the invention]
[0004] However, if the setting information is lost for some reason, the vehicle will no longer be able to operate based on the original settings. For example, in the case of a vehicle, this may result in a situation where accessories cannot be used properly or where proper detection using sensors cannot be performed. If such a situation occurs, the vehicle will need to be taken to a dealer. The present application aims to solve the above-mentioned problems by improving the reliability of the unique information of moving objects and enabling continued normal operation, thereby further improving traffic safety and contributing to the development of sustainable transportation systems. [Means for solving the problem]
[0005] One aspect of the present disclosure is a mobile object control device including a processor and a memory in which software used by the processor is stored, wherein the memory is a rewritable dual-bank ROM, and a software update unit writes the software to one of the banks and writes a new version of the software to an available bank, and executes an update process for the software; The mobile control device controls and a backup control unit that writes the unique information of the mobile unit to the other bank of the memory when the software is not written to the other bank of the memory. The backup control unit determines whether the unique information of the other bank matches the unique information of the other memory at the start of the software update process, and if they match, deletes the unique information of the other bank. It is a mobile object control device. Another aspect of the present disclosure is a mobile body control device comprising a processor and a memory in which software used by the processor is stored, the memory being a rewritable dual-bank ROM, wherein the software is written to one of the banks and a new version of the software is written to the free bank, and the device comprises a software update unit that executes the software update process; another memory in which unique information of a mobile body controlled by the mobile body control device is written; and a backup control unit that writes the unique information to the other bank if the software is not written to the other bank of the memory, wherein the backup control unit determines, at the start of the software update process, whether the unique information of the other bank matches the unique information of the other memory, and if they do not match, performs a reliability judgment to determine the reliability of the data for the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, the device updates the unique information of the other memory to the unique information of the other bank.
[0006] Another aspect of the present disclosure is a mobile body control method executed by a mobile body control device including a processor, a memory in which software used by the processor is stored, and another memory in which unique information of the mobile body is written, the memory being a rewritable dual-bank ROM, the method including: a software update step of writing the software to one of the banks and writing a new version of the software to an available bank to perform an update process of the software; and a backup step of writing the unique information to the other bank of the memory when the software is not written to the other bank. In the backup step, at the start of the software update process, it is determined whether the unique information of the other bank matches the unique information of the other memory, and if they match, the unique information of the other bank is deleted. A mobile object control method. Another aspect of the present disclosure is a mobile body control method executed by a mobile body control device having a processor, a memory in which software used by the processor is stored, and another memory in which unique information of the mobile body is written, wherein the memory is a rewritable dual-bank ROM, and the method includes a software update step in which the software is written to one of the banks and a new version of the software is written to the available bank, and an update process for the software is performed; and a backup step in which, if the software is not written to the other bank of the memory, the unique information is written to the other bank, and in the backup step, at the start of the software update process, it is determined whether the unique information of the other bank matches the unique information of the other memory, and if they do not match, a reliability judgment is made to determine the reliability of the data for the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, the unique information of the other memory is updated to the unique information of the other bank.
[0007] Another aspect of the present disclosure is a mobile object control device including a processor and a rewritable dual-bank ROM in which software used by the processor is stored, the memory having one of the banks into which the software is written and the other memory having unique information of the mobile object written, at least a part of which is configured to include a software update unit that writes a new version of the software to an available bank and executes a software update process for the software, and a software update unit that writes the unique information to the other bank of the memory when the software is not written to the other bank of the memory. At the start of the software update process, it is determined whether the unique information of the other bank matches the unique information of the other memory, and if they match, the unique information of the other bank is deleted. This is a program that functions as a backup control unit. Another aspect of the present disclosure is a program that causes at least a portion of a mobile body control device, which has a processor and a rewritable dual-bank ROM in which software used by the processor is stored, with the software written in one of the banks and the other memory in which the mobile body's unique information is written, to function as a software update unit that writes a new version of the software to the available bank and executes the software update process, and a backup control unit that, if the software is not written in the other bank of the memory, writes the unique information to the other bank, and, if they do not match, performs a reliability judgment to determine the reliability of the data for the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, updates the unique information of the other memory to the unique information of the other bank. [Effects of the Invention]
[0008] According to one aspect of the present invention, it is possible to improve the reliability of the unique information of a moving body, thereby enabling normal operation to continue. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a configuration diagram of a mobile object control device. [Figure 2] FIG. 2 is a diagram for explaining the writing of software and unique information by a supplier. [Figure 3] FIG. 3 is a diagram illustrating the backup of specific information in the manufacturing process. [Figure 4] FIG. 4 is a diagram illustrating the software update process and the backup process of the specific information. [Figure 5] FIG. 5 is a diagram illustrating the software update process and the backup process of the specific information. DETAILED DESCRIPTION OF THE INVENTION
[0010] [1. Configuration of mobile control device] The configuration of a mobile body control device 1 of this embodiment will be described with reference to Fig. 1. The mobile body control device 1 includes a central ECU 2 that performs overall control and information processing of a mobile body 100. In this embodiment, a case where the mobile body 100 is a vehicle is exemplified, but the mobile body 100 is not limited to a vehicle and may be an aircraft, a ship, or the like. The central ECU 2 is connected to communication lines including communication lines L1 to L3. The central ECU 2 is connected to multiple ECUs for controlling the operation of the mobile object 100 via the communication lines, and realizes the function of a gateway that manages the exchange of communication data. Of the multiple ECUs, Fig. 1 shows an area ECU that controls the operation of functions (door locks and security) that can be operated while the mobile object 100 is stopped, along with its peripheral configuration. The area ECU includes a first microcomputer 10 and a second microcomputer 20.
[0011] The communication line is a bus that performs communication conforming to standards such as CAN (Controller Area Network, registered trademark), CAN FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), Ethernet (registered trademark), FlexRay (registered trademark), etc. Note that any of the communication lines L1 to L3 may be a communication line that performs communication conforming to a different standard.
[0012] The central ECU 2 writes software (programs) to be executed by each ECU to multiple ECUs connected via communication lines and to other ECUs connected via these ECUs. Writing software includes updating software already written in an ECU and writing new software to an ECU. That is, the central ECU 2 also functions as an OTA (Over The Air) manager that executes OTA management. The OTA management includes, for example, a process of downloading updated software for each ECU included in the vehicle 100 from an external server and a control related to software update processing.
[0013] The mobile object 100 includes a communication unit 5 that performs wireless communication with the mobile object management server 310 and the like via the communication network 300, and a display 6 that functions as a notification unit that notifies the user of the mobile object 100 of various information. The communication unit 5 and the display 6 are connected to the mobile object control device 1, but may also be provided by the mobile object control device 1.
[0014] An in-vehicle device 200 mounted on the moving body 100 is also connected to the moving body control device 1 via a communication line L3. The in-vehicle device 200 includes configurations related to functions that operate while the moving body 100 is stopped, and in this embodiment includes a door lock module 201 and a security module 202. The door lock module 201 and the security module 202 are connected to at least one of the first microcomputer 10 and the second microcomputer 20 via the communication line L3.
[0015] The first microcomputer 10 and the second microcomputer 20 execute the control and processing assigned to the area ECU. The first microcomputer 10 has a first processor 11, a first memory 12, a first communication circuit 13, etc. The first processor 11 executes first software stored in the first memory 12, thereby locking / unlocking the door lock module 201 and activating / deactivating the headlights / wipers of the vehicle 100.
[0016] The second microcomputer 20 has a second processor 21, a second memory 22, a second communication circuit 23, etc., and the second processor 21 executes second software stored in the second memory 22 to control the power supply of the in-vehicle device 200 and configure the security module 202, etc. The control and processing assigned to each microcomputer 10, 20 may be changed as appropriate. Furthermore, the area ECU is not limited to having two microcomputers 10, 20, but may have one or three or more microcomputers.
[0017] The moving object 100 includes an SS (start / stop) switch 7 that can instruct switching of the IG (IGNITION) of the moving object 100 between on (power on state) and off (power off state). 1, an operation signal of the SS switch 7 (on / off state of the SS switch 7) is input to the second microcomputer 20 via an input circuit 30. The first microcomputer 10 is also connected to the IG relay 8 via an input circuit 31, and the IG relay 8 is turned on and off by a control signal output from the second microcomputer 20 via an output circuit 35, thereby switching the IG of the moving object 100 between on and off. The on / off detection signal of the IG relay 8 (on / off state of the IG relay 8) is input to the first microcomputer 10 via the input circuit 31 and also input to the second microcomputer 20 via the input circuit 32.
[0018] The first memory 12 and the second memory 22 are code flash memories of the area ECU, and are configured as rewritable nonvolatile memories. 2, the first software and the second software are written into these memories 12 and 22 by a supplier that manufactures the area ECU, etc. In this description, the first software and the second software will be referred to as "software" unless there is a need to distinguish between them.
[0019] In this embodiment, a rewritable dual-bank ROM (two-side ROM) is applied to the first memory 12 and the second memory 22. As shown in Fig. 2, software is written to one of the banks (banks 12a and 22a on side A in this example) of each memory 12, 22. Therefore, the other bank (banks 12b and 22b on side B in this example) becomes a free area (free bank).
[0020] Furthermore, areas 12c and 22c of the memories 12 and 22 store programs for the boot (bootstrap) processes of the microcomputers 10 and 20. The first processor 11 and the second processor 21 execute the programs for the boot processes of the microcomputers 10 and 20, thereby functioning as the software update unit and backup control unit of the present disclosure.
[0021] 1, the area ECU includes a rewritable nonvolatile memory 40 that constitutes a data flash memory of the area ECU. Equipment function data Da, authentication data Db, calibration data Dc, user customization data Dd, and other data De of the moving object 100 are written into the nonvolatile memory 40 by a supplier that manufactures the area ECU, as shown in FIG.
[0022] The equipment function data Da is data indicating the equipment (including specifications) of the mobile body 100. This equipment function data Da makes it possible to identify the equipment and specifications of the mobile body 100, which differ for each destination, and the equipment and specifications that are uniquely set for the mobile body 200. The authentication data Db is data used for predetermined authentication. The calibration data Dc is data used to incorporate predetermined parts into the mobile body 100 and data used to set external sensors and the like equipped on the mobile body 100.
[0023] The user customized data Dd is data indicating the content customized by the user (passenger) of the vehicle 100. The user customized data Dd is rewritten as appropriate each time the user customizes the vehicle 100. The other data De is data whose content is not particularly limited. Of the data Da to De written in the nonvolatile memory 40, the equipment function data Da, the authentication data Db, and the calibration data Dc are data unique to the moving object 100, and are basically data that will not be changed. The equipment function data Da, authentication data Db, and calibration data Dc are examples of "mobile object specific information" in the present disclosure. Hereinafter, for convenience of explanation, the equipment function data Da, authentication data Db, and calibration data Dc will be referred to as "specific information Du" when there is no need to particularly distinguish them.
[0024] However, if the unique information Du written in the nonvolatile memory 40 is lost for some reason, the mobile object control device 1 and the like will no longer be able to perform control based on the unique information Du. Therefore, in this embodiment, as shown in Figure 3, during the manufacturing process of the mobile body 100, at the first startup (the first time the power is turned on, for example, when the IG is turned on by the SS switch 7), the second microcomputer 20 of the area ECU reads out the unique information Du and writes the unique information Du to bank 22b on side B, which is an empty bank of the second memory 22.
[0025] In this embodiment, the case will be described in which the second microcomputer 20 backs up the unique information Du by writing the unique information Du to an empty bank in the second memory 22, but the first microcomputer 10 may back up the unique information Du by writing the unique information Du to the first memory 12. Furthermore, the second microcomputer 20 and the first microcomputer 10 may each back up the unique information Du by writing the unique information Du to an empty bank in the second memory 22 and the first memory 12, respectively.
[0026] In this way, by automatically backing up the unique information Du when the moving object 100 is started, it is possible to prevent the unique information Du from being lost. The free bank in the second memory 22 is an area that is used when updating the second software. Therefore, when performing a software update process, the software is updated and a backup process is performed to back up the unique information Du in the free bank that becomes free after the update. The software update process and the backup process will be described below. The software update process is an example of a software update step of the present disclosure, and the backup process corresponds to an example of a backup control step of the present disclosure.
[0027] [2. Software update timing] The mobile object control device 1 performs wireless communication with the mobile object management server 310 via the communication network 300 using the communication unit 5, thereby updating the first software and the second software through OTA management. The first software is updated by the first processor 11 executing a boot process program stored in the area 12c of the first memory 12. The second software is updated by the second processor 21 executing a boot process program stored in the area 22c of the second memory 22.
[0028] [3. Operation of mobile control device during software update] 4 and 5 show the software update process sequence in chronological order along the time axis t. The first software and second software are updated at the same time using similar processes. The first software update is performed using the same process as the second software update, except that the unique information Du is backed up during the update. In this description, when there is no need to distinguish between the first software and the second software, they will be referred to as software. Also, when there is no need to distinguish between the first microcomputer 10 and the second microcomputer 20, they will be referred to as microcomputers. When there is no need to distinguish between the first memory 12 and the second memory 22, they will be referred to as memories.
[0029] As shown in Figure 4, when the mobile control device 1 recognizes the IG ON operation of the SS switch 7 at time t1, it starts the OTA sequence and executes the following steps: configuration synchronization → download of reproduction data (data of the new version of software) from the mobile management server 310 → erasure of software → installation (installation on the dual-sided ROM microcomputer).
[0030] 4 shows an example in which the mobile object control device 1 performs a software update by OTA when it recognizes that the SS switch 7 has been turned on, but the software may be updated at other times. For example, when the mobile object control device 1 receives a software update instruction signal transmitted from another ECU via the communication line 41, it may perform the software update process by OTA, i.e., configuration synchronization → download of reproduction data (data on new version of software) from the mobile object management server 310 → erasure of software → installation (dual ROM microcomputer installation).
[0031] 4 and 5, symbols C1 to C8 indicate the status of the second memory 22 at appropriate times in the OTA sequence, together with the non-volatile memory 40. Symbol C1 indicates a situation in which the area of the second memory 22 where the old version of software before the update is stored is bank 22a on side A, and unique information Du is backed up in bank 22b on side B. When updating software, it is necessary to erase unused banks, i.e., bank 22b different from bank 22a where the valid, active old version of software is stored.
[0032] Immediately before erasing the unused bank, the second microcomputer 20 performs a process of confirming whether the unique information Du written in the bank 22b matches the unique information Du written in the nonvolatile memory 40. In this case, if the second microcomputer 20 determines that the unique information Du matches, it determines that the unique information Du in the nonvolatile memory 40 is highly reliable. If it determines that the unique information Du does not match, it checks the reliability of each piece of unique information Du, and if it determines that the unique information Du written in the nonvolatile memory 40 is low-reliability information and the unique information Du written in the bank 22b is highly reliable information, it rewrites the unique information Du written in the bank 22b with the unique information Du written in the nonvolatile memory 40. This makes it possible to prevent the unreliable unique information Du from remaining in the nonvolatile memory 40. Note that a wide range of known processes such as CRC, check sub, parity, and MD can be applied to check the reliability.
[0033] Next, the microcontroller erases the unused banks and starts writing the new version of the software to the unused banks. After the writing is complete, the microcontroller waits for the IG to be turned off. Symbol C2 shows the state after the unused banks have been erased, and symbol C3 shows the state after the new version of the software has been written. At time t2, the microcomputer starts the activation process when it recognizes the IG-off operation of the SS switch 2. The activation process includes confirming the user's permission to activate, turning off the IG, activating the software, and resetting the microcomputer.
[0034] The microcontroller confirms permission for activation (such as confirming whether to update to the new version of the software), and if permission is confirmed, turns off the IG (including a setting that prohibits powering on again), activates the new version of the software, and resets itself. Code C4 shows the situation where the new version of the software has been written to side B and the activation process has been completed, and the new version of the software will become effective when the microcontroller is restarted (equivalent to restarting the processor).
[0035] In FIG. 5, symbol C5 indicates a situation in which the software that the microcomputer starts when the IG is turned on has switched from the old version of the software stored on side A to the new version stored on side B. Next, when the vehicle 100 is stopped or the IG is off (power off), the second microcomputer 20 starts a process of deleting the old version of the software written in the unused bank (erasing the unused bank) and writing the unique information Du to the unused bank. Reference symbol C6 shows a state in which the bank 22a on the AQ side in which the old version of the software was written has been erased. Reference symbol C7 shows a state in which the unique information Du of the nonvolatile memory 40 is written to the bank 22a on the A side, which is an empty bank.
[0036] When the mobile body 100 is neither stopped nor in an IG off state (power off state), the second microcontroller 20 postpones erasing of unused banks and backup processing until the mobile body 100 is in either a stopped state or an IG off state (power off state). In this way, it is possible to erase unused banks and perform backup processing in situations where the amount of processing is low, such as when the vehicle 100 is stopped or when the IG is off (power off state), thereby preventing the processing load from concentrating when the vehicle 100 is traveling.
[0037] At time t3, when the microcomputer recognizes that the SS switch 7 has been turned on, it confirms that the software update from the old version to the new version has been completed and that the backup of the unique information Du to an unused bank has been completed. Reference symbol C8 indicates the state in which the backup process of the unique information Du to an unused bank has been completed.
[0038] As described above, the mobile object control device 1 of this embodiment is equipped with a first memory 12 and a second memory 22 each consisting of a rewritable dual-bank ROM, and executes software update processing by writing software to one of the banks of the memories 12, 22 and writing a new version of the software to the free bank. Furthermore, if software is not written to the other bank of the second memory 22, the mobile object control device 1 executes processing to write the unique information Du of the mobile object 100 written to the non-volatile memory 40 to the other bank of the second memory 22.
[0039] According to this configuration, the free bank of the dual-bank ROM is used as a backup area for the unique information Du, thereby preventing the unique information Du from being lost and improving the reliability of the unique information Du. The improved reliability of the unique information Du allows normal operation to continue. This ultimately contributes to further improving traffic safety and the development of a sustainable transportation system. The non-volatile memory 40 is an example of another memory in the present disclosure.
[0040] Furthermore, when the mobile object control device 1 detects that no software has been written to the other bank of the second memory 22 at the time of startup of the mobile object 100, it writes the unique information Du to the other bank. This allows the free bank of the dual-bank ROM to be used as a backup area for the unique information Du at the time of startup of the mobile object 100. This makes it possible to prevent the unique information Du from being lost after startup, improving the reliability of the unique information Du.
[0041] Furthermore, the software update process includes a process for deleting the old version of the software, and after the old version of the software is deleted, the mobile object control device 1 writes the unique information Du to the bank from which the old version of the software has been deleted. This allows the unique information Du to be backed up in an empty bank that is switched over by the software update.
[0042] Furthermore, at the start of the software update process, the mobile object control device 1 determines whether the unique information Du of the free bank matches the unique information Du of the nonvolatile memory 40, and if they match, deletes the unique information Du of the free bank. This makes it possible to ensure an area for writing the new version of software after confirming that the unique information Du of the nonvolatile memory 40 is highly reliable.
[0043] Furthermore, if the mobile object control device 1 does not match, the backup control unit performs a reliability determination to determine the reliability of the data for the unique information Du of the empty bank and the unique information Du of the non-volatile memory 40, and if the reliable data is the unique information Du of the empty bank, it updates the unique information Du of the non-volatile memory 40 to the unique information Du of the previous empty bank. This makes it possible to avoid a situation where unreliable unique information Du remains in the non-volatile memory 40, improving the reliability of the unique information Du.
[0044] Furthermore, the software update process includes an activation process for the new version of the software, and after the activation process is completed and the old version of the software is deleted, the mobile object control device 1 writes the unique information Du of the nonvolatile memory 40 to the bank from which the old version of the software was deleted. This allows the unique information Du to be backed up in an available bank after the software is updated, and makes it possible to back up the unique information Du while minimizing downtime of the mobile object 100.
[0045] Furthermore, the deletion of the old version of the software is performed when the mobile body 100 is stopped or when the mobile body 100 is powered off, so the software is deleted in a situation where the processing volume is low, and the processing load is not concentrated when the mobile body 100 is moving.
[0046] 4. Other Embodiments The above embodiment is merely one embodiment of the present invention, and any modifications and applications are possible without departing from the spirit of the present invention.
[0047] The configuration of the mobile body control device 1 shown in Fig. 1 is an example, and the configuration may be changed as appropriate. Also, Fig. 1 is a schematic diagram showing the configuration of the mobile body control device 1 divided according to the main processing content in order to facilitate understanding of the present invention, and the mobile body control device 1 may be divided according to other divisions. Furthermore, the processing of each component may be executed by one hardware unit or by multiple hardware units. Furthermore, the processing of each component may be executed by one program or by multiple programs.
[0048] 5. Configurations supported by the above embodiments The above embodiment is a specific example of the following configuration.
[0049] (Configuration 1) A mobile body control device comprising a processor and a memory in which software used by the processor is stored, wherein the memory is a rewritable dual-bank ROM, in which the software is written to one of the banks and a new version of the software is written to the free bank, and the mobile body control device comprises: a software update unit that executes the software update process; another memory in which unique information of the mobile body is written; and a backup control unit that writes the unique information to the other bank of the memory if the software is not written to the other bank. According to the mobile object control device of configuration 1, the free bank of the dual bank ROM is used as a backup area for the unique information, which prevents the unique information from being lost and improves the reliability of the unique information.Since the reliability of the unique information is improved, normal operation can be continued.
[0050] (Configuration 2) A mobile body control device according to configuration 1, wherein the backup control unit writes the unique information to the other bank when it detects that the software is not written to the other bank at the time of startup of the mobile body. According to the mobile object control device of configuration 2, when the mobile object is started up, the free bank of the dual bank ROM can be used as a backup area for the unique information, improving the reliability of the unique information.
[0051] (Configuration 3) A mobile control device according to configuration 1 or 2, wherein the software update process includes a process of deleting an older version of the software, and the backup control unit writes the unique information to the bank from which the older version of the software was deleted after the older version of the software has been deleted. According to the mobile object control device of configuration 3, the unique information can be backed up in a free bank that is switched over by a software update.
[0052] (Configuration 4) A mobile control device described in any one of configurations 1 to 3, wherein the backup control unit determines whether the unique information of the other bank matches the unique information of the other memory at the start of the software update process, and if they match, deletes the unique information of the other bank. According to the mobile object control device of configuration 4, after it is confirmed that the unique information in the other memory is highly reliable, an area for writing the new version of software can be secured.
[0053] (Configuration 5) In the case where there is no match, the backup control unit performs a reliability determination to determine the reliability of the data for the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, updates the unique information of the other memory to the unique information of the other bank. A mobile control device as described in Configuration 4. According to the mobile object control device of configuration 5, it is possible to prevent unreliable unique information from remaining in other memories, thereby improving the reliability of the unique information.
[0054] (Configuration 6) A mobile control device according to Configuration 3, wherein the software update process includes an activation process for the new version of the software, and the backup control unit writes the unique information of the other memory to the bank from which the old version of the software was deleted after the activation process is completed and the old version of the software is deleted. According to the mobile object control device of configuration 6, after updating the software, the unique information can be backed up in an empty bank, and the unique information can be backed up while minimizing the downtime of the mobile object.
[0055] (Configuration 7) The mobile object control device according to Configuration 3 or 6, wherein the deletion of the old version of the software is executed when the mobile object is stopped or when the mobile object is in a power-off state. According to the mobile object control device of configuration 7, it is possible to prevent the processing load from being concentrated when the mobile object is traveling.
[0056] (Configuration 8) A mobile body control method executed by a mobile body control device having a processor, a memory in which software used by the processor is stored, and another memory in which unique information of the mobile body is written, wherein the memory is a rewritable dual-bank ROM, and the mobile body control method performs a software update step in which the software is written to one of the banks and a new version of the software is written to the available bank, and an update process of the software is performed, and a backup step in which, if the software is not written to the other bank of the memory, the unique information is written to the other bank. By executing the mobile body control method of configuration 8 by a mobile body control device, the same effects as those of the mobile body control device of configuration 1 can be obtained.
[0057] (Configuration 9) A program that causes at least a part of a mobile control device having a processor and a rewritable dual-bank ROM in which software used by the processor is stored, with the software written to one of the banks and the other memory in which the mobile device's unique information is written, to function as a software update unit that writes a new version of the software to an available bank and performs an update process for the software, and a backup control unit that writes the unique information to the other bank of the memory when the software is not written to the other bank. By executing the program of configuration 9 by the mobile body control device, the same effects as those of the mobile body control device of configuration 1 can be obtained. [Explanation of symbols]
[0058] 1...mobile object control device, 2...central ECU, 5...communication unit, 6...display, 7...SS switch, 8...IG relay, 10...first microcomputer, 11...first processor, 12...first memory, 13...first communication circuit, 20...second microcomputer, 21...second processor, 22...second memory, 23...second communication circuit, 30, 32, 33...input circuit, 35...output circuit, 40...non-volatile memory (other memory), 100...mobile object, 121...old version of first software, 122...new version of first software, 200...in-vehicle device, 221...old version of second software, 222...new version of second software, 300...communication network, 310...mobile object management server, Da...equipment function data, Db...authentication data, Dc...calibration data, Dd...user customization data, De...other data, Du...unique information.
Claims
1. A mobile object control device including a processor and a memory in which software used by the processor is stored, the memory is a rewritable dual-bank ROM, and the software is written in one of the banks; a software update unit that writes a new version of the software into an available bank and executes an update process for the software; Another memory in which unique information of a moving body controlled by the moving body control device is written; a backup control unit that writes the unique information to the other bank of the memory when the software is not written to the other bank; Equipped with The backup control unit determines whether the unique information of the other bank matches the unique information of the other memory at the start of the software update process, and if they match, deletes the unique information of the other bank. Mobile control device.
2. A mobile object control device including a processor and a memory in which software used by the processor is stored, the memory is a rewritable dual-bank ROM, and the software is written in one of the banks; a software update unit that writes a new version of the software into an available bank and executes an update process for the software; Another memory in which unique information of a moving body controlled by the moving body control device is written; a backup control unit that writes the unique information to the other bank of the memory when the software is not written to the other bank; Equipped with The backup control unit determines whether the unique information of the other bank matches the unique information of the other memory at the start of the software update process, and if they do not match, performs a reliability determination to determine the reliability of data for the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, updates the unique information of the other memory to the unique information of the other bank. Mobile control device.
3. The backup control unit writes the unique information to the other bank when detecting that the software is not written to the other bank at the time of starting up the mobile body. The mobile object control device according to claim 1 or 2.
4. the software update process includes a process of deleting an old version of the software; After the old version of the software is deleted, the backup control unit writes the unique information to the bank from which the old version of the software has been deleted. The mobile object control device according to claim 1 or 2.
5. If they do not match, the backup control unit performs a reliability determination to determine the reliability of the data regarding the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, updates the unique information of the other memory to the unique information of the other bank. The mobile object control device according to claim 1 .
6. the software update process includes an activation process of the new version of the software; After the activation process is completed and the old version of the software is deleted, the backup control unit writes the unique information of the other memory to the bank from which the old version of the software has been deleted. The mobile object control device according to claim 3 .
7. The removal of the old version of the software is performed when the mobile device is stopped or when the mobile device is in a power-off state. The mobile object control device according to claim 6.
8. A mobile object control method executed by a mobile object control device including a processor, a memory in which software used by the processor is stored, and another memory in which unique information of the mobile object is written, the memory is a rewritable dual-bank ROM, and the software is written in one of the banks; a software update step of writing a new version of the software to an available bank and executing an update process for the software; a backup step of writing the unique information to the other bank of the memory when the software is not written to the other bank of the memory; In the backup step, at the start of the software update process, it is determined whether the unique information of the other bank matches the unique information of the other memory, and if they match, the unique information of the other bank is deleted. A mobile object control method.
9. A mobile object control method executed by a mobile object control device including a processor, a memory in which software used by the processor is stored, and another memory in which unique information of the mobile object is written, the memory is a rewritable dual-bank ROM, and the software is written in one of the banks; a software update step of writing a new version of the software to an available bank and executing an update process for the software; a backup step of writing the unique information to the other bank of the memory when the software is not written to the other bank of the memory; In the backup step, at the start of the software update process, it is determined whether the unique information of the other bank and the unique information of the other memory match, and if they do not match, a reliability determination is made to determine the reliability of data for the unique information of the other bank and the unique information of the other memory, and if the reliable data is the unique information of the other bank, the unique information of the other memory is updated to the unique information of the other bank. A mobile object control method.
10. At least a part of a mobile body control device including a processor and a rewritable dual-bank ROM in which software used by the processor is stored, the software being written in one of the banks, and the other memory in which information specific to the mobile body is written, a software update unit that writes a new version of the software into an available bank and executes an update process for the software; a backup control unit that, when the software is not written in the other bank of the memory, writes the unique information to the other bank, and, at the start of the software update process, determines whether the unique information of the other bank matches the unique information of the other memory, and, if they match, deletes the unique information of the other bank; A program that makes it work.
11. At least a part of a mobile body control device including a processor and a rewritable dual-bank ROM in which software used by the processor is stored, the software being written in one of the banks, and the other memory in which information specific to the mobile body is written, a software update unit that writes a new version of the software into an available bank and executes an update process for the software; a backup control unit that, when the software is not written in the other bank of the memory, writes the unique information to the other bank, and, at the start of the software update process, determines whether the unique information of the other bank matches the unique information of the other memory, and, if they do not match, performs a reliability determination to determine the reliability of the unique information of the other bank and the unique information of the other memory, and, when the reliable data is the unique information of the other bank, updates the unique information of the other memory to the unique information of the other bank; A program that makes it work.
Citation Information
Patent Citations
Method and program for processing program updating, and information processing terminal
JP2005332301A
On-vehicle update device, update processing program, and method of updating program
JP2020152154A
Onboard apparatus, software updating method, software updating program, and vehicle
JP2022049975A
Device for vehicle
JP2022114165A