In-vehicle device, computer program, and program update method
The in-vehicle device prioritizes relay device updates and includes abnormality detection to maintain bus communication integrity, addressing communication disruptions during program updates.
Patent Information
- Application Number
- JP2022062541
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-04
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2042-04-04
AI Technical Summary
Existing systems fail to prevent communication disruption between buses connected by a relay device after a program update, particularly when an abnormality occurs during the update process.
An in-vehicle device prioritizes updating the relay device and its ECUs to ensure normal operation, incorporating an abnormality detection mechanism to maintain communication integrity during and after the update process.
Prevents communication failure between buses by ensuring the relay device and its ECUs remain operational, allowing accurate program updates and rollbacks when necessary.
Smart Images

Figure 0007794060000001 
Figure 0007794060000002 
Figure 0007794060000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an in-vehicle device, a computer program, and a program update method. [Background technology]
[0002] A vehicle is equipped with an ECU (Electronic Control Unit) for controlling in-vehicle devices such as drive control systems (e.g., engine control) and body systems (e.g., air conditioning control). The ECU includes a processing unit such as an MPU, a rewritable nonvolatile storage unit such as an EEPROM, and a communication unit for communicating with other ECUs, and controls the in-vehicle devices by reading and executing control programs stored in the storage unit. The vehicle is also equipped with a communication device with wireless communication capabilities, and can communicate with a program provider connected to a network outside the vehicle via the communication device, download (receive) a control program for the ECU from the program provider, and update the control program for the ECU (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-97851 Summary of the Invention [Problem to be solved by the invention]
[0004] It is assumed that two buses are connected to a relay device, and the control program update targets the relay device and the devices connected to the two buses. In such a case, if an abnormality occurs, such as an incorrect update of the relay device, communication between the two buses may become impossible after the update.
[0005] However, the communication device of Patent Document 1 does not consider the above-mentioned problems at all and is unable to solve them.
[0006] The present invention has been made in consideration of the above circumstances, and its purpose is to provide an in-vehicle device, a computer program, and a program update method that can prevent communication between buses connected by a relay device from becoming impossible after a program update process. [Means for solving the problem]
[0007] An in-vehicle device according to an embodiment of the present disclosure is connected to a first bus that is connected to a relay device that relays bus-to-bus communication, acquires an update program from outside the vehicle, and updates the programs of the relay device and the in-vehicle ECU, and is equipped with a control unit that prioritizes updating the relay device when the update target includes the relay device and an in-vehicle ECU of a second bus connected to the relay device.
[0008] A computer program according to an embodiment of the present disclosure is connected to a first bus that is connected to a relay device that relays bus-to-bus communication, acquires an update program from outside the vehicle, and causes a computer in an in-vehicle device that updates the programs of the relay device and the in-vehicle ECU to execute processing that prioritizes updating the relay device when the update target includes the relay device and an in-vehicle ECU of a second bus connected to the relay device.
[0009] A program update method according to an embodiment of the present disclosure has an on-board device that is connected to a first bus that is connected to a relay device that relays bus-to-bus communication, acquires an update program from outside the vehicle, and updates the programs of the relay device and on-board ECUs. When the update target includes the relay device and on-board ECUs of a second bus connected to the relay device, the on-board device executes a process that prioritizes updating the relay device. [Effects of the Invention]
[0010] According to the present disclosure, it is possible to prevent a situation in which communication between buses connected by a relay device becomes impossible after a program update process. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a schematic diagram showing the configuration of an in-vehicle update system according to a first embodiment. [Figure 2] FIG. 2 is a block diagram showing the configuration of an in-vehicle device. [Figure 3] 1 is an explanatory diagram illustrating an example of a processing flow (sequence) by an in-vehicle device, devices to be updated (a first GW and an in-vehicle ECU), etc. FIG. [Figure 4] 10 is an explanatory diagram illustrating state transitions of an in-vehicle device, a first GW, and an in-vehicle ECU to be updated during program update processing. FIG. [Figure 5] FIG. 10 is an explanatory diagram illustrating state transitions of an in-vehicle device, a first GW, and an in-vehicle ECU to be updated during rollback processing. [Figure 6] 4 is a flowchart illustrating an example of processing by a control unit of an in-vehicle device. [Figure 7] FIG. 10 is an explanatory diagram illustrating another example of the processing flow (sequence) by the in-vehicle device, the device to be updated (the first GW and the in-vehicle ECU), etc. [Figure 8] 10 is an explanatory diagram illustrating state transitions of an in-vehicle device, a first GW, and an in-vehicle ECU to be updated during program update processing. FIG. [Figure 9] FIG. 10 is an explanatory diagram illustrating state transitions of an in-vehicle device, a first GW, and an in-vehicle ECU to be updated during rollback processing. [Figure 10] 10 is a flowchart illustrating another example of processing by a control unit of an in-vehicle device. [Figure 11] FIG. 10 is an explanatory diagram illustrating an example of state transitions of each device during program update processing in Modification 1. [Figure 12] FIG. 10 is an explanatory diagram illustrating an example of state transitions of each device in rollback processing in Modification 1. [Figure 13] FIG. 10 is an illustrative diagram illustrating a configuration in which an in-vehicle update system according to Modification 2 includes a virtual network. DETAILED DESCRIPTION OF THE INVENTION
[0012] [Description of the embodiment of the present invention] First, embodiments of the present disclosure will be listed and described. At least some of the embodiments described below may be combined in any desired manner.
[0013] (1) An in-vehicle device according to an embodiment of the present disclosure is connected to a first bus that is connected to a relay device that relays bus-to-bus communication, acquires an update program from outside the vehicle, and updates the programs of the relay device and the in-vehicle ECU. When the update target includes the relay device and an in-vehicle ECU of a second bus connected to the relay device, the in-vehicle device is provided with a control unit that prioritizes updating the relay device.
[0014] In this embodiment, when the update targets include the relay device and the in-vehicle ECU of the second bus, the control unit prioritizes updating the relay device and continues the update process while ensuring the normal operation of the relay device, thereby enabling accurate program updates for the in-vehicle ECU of the second bus.
[0015] (2) In an in-vehicle device according to an embodiment of the present disclosure, when the update targets include the in-vehicle ECUs of the relay device and the second bus, and the in-vehicle ECU of the first bus, the control unit prioritizes updating the in-vehicle ECUs of the relay device and the first bus.
[0016] In this embodiment, when the update targets include the on-board ECUs of the first bus in addition to the on-board ECUs of the relay device and the second bus, the control unit prioritizes updating the on-board ECUs of the relay device and the first bus, and continues the update process while ensuring the normal operation of the relay device. Therefore, the program update for the on-board ECUs of the second bus can be performed accurately.
[0017] (3) The in-vehicle device according to the embodiment of the present disclosure includes an abnormality detection unit that detects an abnormality in the relay device after the relay device executes an activation process to apply the update program.
[0018] In this embodiment, after the relay device executes the activation process, the abnormality detection unit detects an abnormality in the relay device and confirms that the relay device is normal. In this way, the normal state of the relay device is ensured and processing continues, so that the program update for the in-vehicle ECU of the second bus can be executed accurately.
[0019] (4) In the in-vehicle device according to the embodiment of the present disclosure, when no abnormality is detected, the control unit updates the in-vehicle ECU of the second bus.
[0020] In this embodiment, after the activation process is executed in the relay device, the abnormality detection unit detects an abnormality in the relay device, and after confirming that no abnormality is detected, continues updating the in-vehicle ECU of the second bus. In this way, since the update is executed while ensuring the normal state of the relay device, it is possible to accurately update the program in the in-vehicle ECU of the second bus.
[0021] (5) In an in-vehicle device according to an embodiment of the present disclosure, when the update targets further include another relay device connected to the second bus and an in-vehicle ECU of a third bus connected to the other relay device, the control unit updates both the in-vehicle ECU of the second bus and the other relay device, and after updating the other relay device, performs the update process for the in-vehicle ECU of the third bus.
[0022] In this embodiment, when the update targets include the relay device, the in-vehicle ECU of the first bus, the in-vehicle ECU of the second bus, the other relay device, and the in-vehicle ECU of the third bus, the control unit updates both the in-vehicle ECU of the second bus and the other relay device, ensuring the normal state of the other relay device, and then continues the update process for the in-vehicle ECU of the third bus. Therefore, the program update for the in-vehicle ECU of the third bus can be accurately executed.
[0023] (6) In the in-vehicle device according to an embodiment of the present disclosure, when an abnormality is detected, the control unit performs a rollback process to restore the updated program to the program before the update, with priority given to the relay device and the in-vehicle ECU of the first bus.
[0024] In this embodiment, if an abnormality is detected after the update, the control unit causes the relay device and the in-vehicle ECUs on the first bus to execute the rollback process preferentially. As a result, the rollback process continues after the normal state of the relay device in the execution environment of the original program is ensured. In this way, the rollback process is executed after the normal state of the relay device is ensured, so that the rollback process can be executed accurately for the in-vehicle ECUs on the second bus.
[0025] (7) In the in-vehicle device according to the embodiment of the present disclosure, the control unit performs the rollback process on the in-vehicle ECU of the second bus after performing the rollback process on the relay device.
[0026] In this embodiment, the control unit causes the relay device to execute a rollback process, and after the relay device is in a normal state in the execution environment of the original program, the control unit causes the in-vehicle ECU of the second bus to execute the rollback process. In this way, the rollback process is executed after ensuring the normal state of the relay device, so that the rollback process can be accurately executed on the in-vehicle ECU of the second bus.
[0027] (8) In an in-vehicle device according to an embodiment of the present disclosure, when further updates are performed on another relay device connected to the second bus and an in-vehicle ECU on a third bus connected to the other relay device, the control unit performs rollback processing on both the in-vehicle ECU on the second bus and the other relay device, and after the rollback processing on the other relay device, performs rollback processing on the in-vehicle ECU on the third bus.
[0028] In this embodiment, when the other relay device and the on-board ECU of the third bus are updated in addition to the relay device, the on-board ECU of the first bus, and the on-board ECU of the second bus, the control unit performs rollback processing for both the on-board ECU of the second bus and the other relay device to ensure the normal state of the other relay device, and then continues the rollback processing for the on-board ECU of the third bus. Therefore, the rollback processing for the on-board ECU of the third bus can be accurately executed.
[0029] (9) A computer program according to an embodiment of the present disclosure is connected to a first bus that is connected to a relay device that relays bus-to-bus communication, acquires an update program from outside the vehicle, and causes a computer of an in-vehicle device that updates the programs of the relay device and the in-vehicle ECU to execute processing that prioritizes updating the relay device when the update target includes the relay device and an in-vehicle ECU of a second bus connected to the relay device.
[0030] In this embodiment, when the update targets include the relay device and the in-vehicle ECU of the second bus, the computer of the in-vehicle device prioritizes updating the relay device and continues the update process while ensuring the normal operation of the relay device, thereby enabling accurate program updates for the in-vehicle ECU of the second bus.
[0031] (10) A program update method according to an embodiment of the present disclosure includes an on-board device that is connected to a first bus that is connected to a relay device that relays bus-to-bus communication, acquires an update program from outside the vehicle, and updates the programs of the relay device and the on-board ECU. When the update target includes the relay device and an on-board ECU of a second bus connected to the relay device, the on-board device executes a process that prioritizes updating the relay device.
[0032] In this embodiment, when the update targets include the relay device and the in-vehicle ECU of the second bus, the in-vehicle device prioritizes updating the relay device and continues the update process while ensuring the normal operation of the relay device, thereby enabling accurate program updates for the in-vehicle ECU of the second bus.
[0033] [Details of the embodiment of the present invention] An in-vehicle device, a computer program, and a program update method according to embodiments of the present disclosure will be described below with reference to the drawings. Note that the present invention is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope of the claims.
[0034] Hereinafter, embodiments will be described with reference to the drawings. Fig. 1 is a schematic diagram showing the configuration of an in-vehicle update system S according to embodiment 1. The in-vehicle update system S includes an exterior communication device 1 and an in-vehicle device 2 mounted on a vehicle C, and transmits an update program acquired from an external server S1 (OTA server) connected via an exterior network N to an in-vehicle ECU 3 (Electronic Control Unit) mounted on the vehicle C.
[0035] The external server S1 is a computer such as a server connected to an external network N, such as the Internet or a public line network, and includes a storage unit S11 such as a RAM (Random Access Memory), a ROM (Read Only Memory), or a hard disk. The storage unit S11 of the external server S1 stores programs or data for controlling the in-vehicle ECU 3, which have been created by the manufacturer of the in-vehicle ECU 3, for example. The programs or data are transmitted to the vehicle C as update programs, as will be described later, and are used to update the programs or data of the in-vehicle ECU 3 installed in the vehicle C. The external server S1 configured in this manner is also referred to as an OTA (Over The Air) server.
[0036] The in-vehicle device 2 functions as a so-called OTA master that transmits the update program acquired from the external server S1 via the extra-vehicle communication device 1 to the in-vehicle ECU 3 to be updated, and also transmits an activation instruction to apply the transmitted update program to the in-vehicle ECU 3.
[0037] The in-vehicle ECU 3 installed in the vehicle C acquires the update program transmitted by wireless communication from the external server S1 via the in-vehicle device 2, and updates (reprograms) the program executed by its own ECU by applying (activating) the update program in response to an activation instruction from the in-vehicle device 2.
[0038] For example, the program includes program code including a control syntax for the in-vehicle ECU 3 to perform processing, and an external file describing data referenced when the program code is executed. When transmitting the update program, the external file describing the program code and data is transmitted from the external server S1 as, for example, an encrypted archive file. When transmitting the update program, the external server S1 generates a package including the update program and transmits the generated package to the vehicle C. The package includes, for example, package information (campaign information) that is information related to the program update, information indicating the update target (target information), and the update program to be applied to the update target.
[0039] The vehicle C includes an exterior communication device 1, an on-board device 2, and a first GW (gateway) 8. A plurality of buses 4 are connected to the first GW 8, and a plurality of on-board ECUs 3 for controlling various on-board devices are connected to each bus 4. The vehicle C also includes a display device 5 (see FIG. 2) and an IG switch 6 (see FIG. 2). In the following, an example will be described in which two buses 4A and 4B are connected to the first GW 8, with in-vehicle ECUs 3Aa and 3Ab connected to the bus 4A and in-vehicle ECUs 3Ba, 3Bb, and 3Bc connected to the bus 4B. However, the present invention is not limited to this, and there may be three or more buses 4, and four or more in-vehicle ECUs 3 may be connected to each bus 4.
[0040] The extra-vehicle communication device 1 and the in-vehicle device 2 are communicatively connected by a harness such as a serial cable. The first gateway 8 selectively relays communication data between the bus 4A and the bus 4B and can convert the communication protocol between the bus 4A and the bus 4B during relaying. The first gateway 8, the in-vehicle device 2, and the in-vehicle ECU 3 are communicatively connected by a bus 4 that supports a communication protocol such as CAN (Control Area Network), CAN-FD (CAN with Flexible Data Rate), or Ethernet (registered trademark).
[0041] The exterior-vehicle communication device 1 has an exterior-vehicle communication unit (not shown) and an input / output I / F (interface) (not shown) for communicating with the in-vehicle device 2. The exterior-vehicle communication unit is a communication device for wireless communication using a mobile communication protocol such as LTE (registered trademark), 4G, 5G, or WiFi (registered trademark), and transmits and receives data to and from an external server S1 via an antenna connected to the exterior-vehicle communication unit. Communication between the exterior-vehicle communication device 1 and the external server S1 is performed via an external network N, such as a public line network or the Internet.
[0042] The input / output I / F of the extra-vehicle communication device 1 is a communication interface for, for example, serial communication with the in-vehicle device 2. The extra-vehicle communication device 1 and the in-vehicle device 2 communicate with each other via a harness such as a serial cable. In this embodiment, the extra-vehicle communication device 1 is a device separate from the in-vehicle device 2, and these devices are communicatively connected by an input / output I / F or the like, but this is not limiting. The extra-vehicle communication device 1 may be built into the in-vehicle device 2 as one component of the in-vehicle device 2. Alternatively, the extra-vehicle communication device 1 and the in-vehicle device 2 may be connected by a bus such as a CAN.
[0043] The first GW8 is an in-vehicle relay device that manages multiple buses 4 (segments) such as an in-vehicle ECU 3 for a control system, an in-vehicle ECU 3 for a safety system, and an in-vehicle ECU 3 for a body system, and relays communications between the in-vehicle ECUs 3 between these buses (segments). The first GW8 functions as a CAN gateway when relaying the CAN protocol, and as a layer 2 switch or layer 3 switch when relaying the TCP / IP protocol. The first GW8 may be a PLB (Power LAN Box) that, in addition to relaying communications, also functions as a power distribution device that distributes and relays power output from a power supply device such as a secondary battery and supplies power to in-vehicle devices such as actuators connected to the first GW8.
[0044] The first GW8 has a storage unit 81. The storage unit 81 stores information about each version of two programs, a current version and an old version, and information about the area (operating surface) in which the currently executed (applied) program is stored. That is, when a program (control program) stored in the first area is currently being executed, the operating surface is stored as the first area. In this case, the non-operating surface is stored as the second area. The current version of the control program is stored in the first area, which is the operating surface. The old version of the control program is stored in the second area, which is the non-operating surface. Alternatively, the second area, which is the non-operating surface, may be a storage area that does not store the old version of the control program or the like and is free space. In this way, by having the non-operating surface be a storage area with free space or a storage area in which the old version of the control program or the like is stored, it is possible to ensure that the old version can be restored by writing the new version of the control program to the non-operating surface during an update.
[0045] FIG. 2 is a block diagram showing the configuration of the in-vehicle device 2. As shown in FIG. The in-vehicle device 2 has a control unit 20, a storage unit 23, an input / output I / F 21, and an in-vehicle communication unit 22. The in-vehicle device 2 is configured to acquire, from the exterior-vehicle communication device 1, an update program (package) that the exterior-vehicle communication device 1 has received from the external server S1 via wireless communication, and transmit the update program (package) to the device to be updated via the bus 4. In other words, the in-vehicle device 2 functions as an OTA master (update control device) that controls program updates in the device to be updated.
[0046] The in-vehicle device 2 may also be configured as one functional part of a body ECU that controls the entire vehicle C. Alternatively, the in-vehicle device 2 may be configured as an integrated ECU that is configured with a central control device such as a vehicle computer and performs overall control of the vehicle C.
[0047] The control unit 20 is composed of a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), and performs various control processes and calculation processes by reading and executing a control program P and data pre-stored in the memory unit 23.
[0048] The storage unit 23 is configured with two storage areas, a first storage unit 231 and a second storage unit 232. Each of the first storage unit 231 and the second storage unit 232 is configured with a volatile memory element such as a random access memory (RAM) or a non-volatile memory element such as a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The first storage unit 231 and the second storage unit 232 pre-store a control program P and data to be referenced during processing. The control program P stored in the storage unit 23 (the first storage unit 231 and the second storage unit 232) may be a control program P read from a recording medium 24 readable by the in-vehicle device 2. Alternatively, the control program P may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 23.
[0049] The input / output I / F 21 is a communication interface for, for example, serial communication, similar to the input / output I / F of the exterior communication device 1. The in-vehicle device 2 is communicably connected to the exterior communication device 1, the display device 5, and the IG switch 6 via the input / output I / F 21. The IG signal may also be acquired via an in-vehicle LAN.
[0050] The in-vehicle communication unit 22 is an input / output interface that uses a communication protocol such as CAN or Ethernet (registered trademark), and the control unit 20 communicates with in-vehicle devices such as the in-vehicle ECU 3 of the bus 4A or the first GW 8 via the in-vehicle communication unit 22, and also communicates with the in-vehicle ECU 3 of the bus 4B via the first GW 8. A plurality of in-vehicle communication units 22 (two in this embodiment) are provided.
[0051] The in-vehicle device 2 executes processing related to application of the update program to the in-vehicle ECU 3 and the first GW 8. As will be described in detail later, the in-vehicle device 2 transmits the update program to the in-vehicle ECU 3 and the first GW 8, issues an activation instruction, checks for abnormalities after the activation process, and issues a rollback instruction when an abnormality is detected.
[0052] The in-vehicle device 2 generates and stores update information used for checking for abnormalities after activation based on the update program from the external server S1. The update information stores at least the ID of each in-vehicle ECU 3, the current program version, and the update program version in association with each other.
[0053] Specifically, the in-vehicle device 2 periodically, cyclically, or steadily communicates with all in-vehicle ECUs 3 and first GWs 8 mounted on the vehicle C (host vehicle) to acquire program version information related to all in-vehicle ECUs 3 and first GWs 8. The in-vehicle device 2 stores the transmitted program version information in association with each device. Alternatively, the in-vehicle device 2 may be configured such that each in-vehicle ECU 3 and first GW 8 periodically or cyclically transmits the current program version to the in-vehicle device 2 without requesting the in-vehicle ECUs 3 and first GWs 8 to transmit the current program version.
[0054] Furthermore, when the in-vehicle device 2 acquires the package from the external server S1, it acquires the version of the update program for each device to be updated based on the campaign information, the target information, and the update program. Alternatively, the device to be updated may be configured to transmit the version of the update program applied to the in-vehicle device 2 each time activation of the update program is completed.
[0055] The in-vehicle device 2 generates the update information by aggregating the versions of the current program and the update program acquired from each in-vehicle ECU 3 and the first GW 8, and stores the update information in the storage unit 23. The update information may be stored in the first storage unit 231 or the second storage unit 232, or may be stored in both the first storage unit 231 and the second storage unit 232 in a redundant manner.
[0056] The in-vehicle ECU 3 includes a control unit, a storage unit, and an in-vehicle communication unit (not shown), similar to the in-vehicle device 2. The storage unit is configured with a volatile memory element such as a random access memory (RAM) or a non-volatile memory element such as a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory, and stores programs or data for the in-vehicle ECU 3. This program or data is to be updated by an update program transmitted from the external server S1 and relayed by the in-vehicle device 2 (first GW 8). The in-vehicle communication unit of the in-vehicle ECU 3, similar to the in-vehicle device 2, is configured with, for example, a CAN transceiver or an Ethernet PHY unit, and communicates with the in-vehicle device 2.
[0057] The storage unit of each on-board ECU 3 is provided with a first area and a second area, similar to the storage unit 81 of the first GW 8. When a program (control program) stored in the first area is currently being executed, the operating area is stored as the first area, and the non-operating area is stored as the second area. The first area, which is the operating area, stores the current version of the control program. The second area, which is the non-operating area, stores an older version of the control program. Alternatively, the second area, which is the non-operating area, may be a storage area that does not store an older version of the control program or the like and is free space.
[0058] 3 is an explanatory diagram illustrating an example of a processing flow (sequence) by the in-vehicle device 2, the device to be updated (the first GW 8 and the in-vehicle ECU 3), etc. That is, FIG. 3 shows the processing sequences of the external server S1, the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated when processing related to program update in the in-vehicle device 2 and the device to be updated (the first GW 8 and the in-vehicle ECU 3). For convenience, the following description will be given taking as an example a case where the in-vehicle ECU 3Aa of the bus 4A, the first GW 8, and the in-vehicle ECUs 3Ba and 3Bb of the bus 4B are to be updated.
[0059] 4 is an explanatory diagram illustrating state transitions of the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated during program update processing, and FIG. 5 is an explanatory diagram illustrating state transitions of the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated during rollback processing. In FIGS. 4 and 5, the states of the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated before and after the update program is applied are shown in inverted display form. In FIG. 4, the update target is indicated by a black circle.
[0060] The in-vehicle device 2 acquires an update program from an external server S1 (S01). The in-vehicle device 2 accesses the external server S1 using, for example, the identification number (VIN: Vehicle Identification Number) of the vehicle C (host vehicle) in which the in-vehicle device 2 is installed, and acquires a package including an update program to be applied to the host vehicle from the external server S1. The package includes, for example, package information (campaign information) that is information related to the program update, information related to the first GW 8 and the in-vehicle ECU 3 to be updated (target information), and the update program to be applied to the first GW 8 and the in-vehicle ECU 3 to be updated.
[0061] The in-vehicle device 2 stores the update program included in the acquired package in the storage unit 23 (S02). The acquired update program is stored in the first storage unit 231 or the second storage unit 232. The in-vehicle device 2 also updates the update information based on the acquired package.
[0062] First, the in-vehicle device 2 outputs (transmits) an update program for the first GW 8 and the in-vehicle ECU 3Aa to the first GW 8 and the in-vehicle ECU 3Aa (see FIG. 4A) that are connected to the bus 4A to which the in-vehicle device 2 is connected (hereinafter referred to as the local bus 4A) among the update targets (S03). The in-vehicle device 2 determines that the first GW 8 is included in the update targets based on the target information acquired from the external server S1, and transmits the update program to the first GW 8 and the in-vehicle ECU 3Aa of the local bus 4A.
[0063] The first GW 8 stores the update program acquired (received) from the in-vehicle device 2 in the storage unit 81, and the in-vehicle ECU 3Aa installs the update program acquired from the in-vehicle device 2 in the storage unit (S04).
[0064] For example, if the currently running program is stored in a first area of the storage unit 81, the first area corresponds to the operating surface. In this case, a program of an earlier version (old version) than the currently running program is stored as a backup in a second area of the storage unit 81, which is the non-operating surface. The first gateway 8 stores the acquired update program for its own device in the second area, which is the non-operating surface. This prevents the currently running program from being overwritten, allowing the current operating state to be stably maintained.
[0065] As with the first GW 8, the in-vehicle ECU 3Aa stores the acquired update program in a non-operational side, thereby preventing the currently executed program (stored in the operational side) from being overwritten.
[0066] The in-vehicle device 2 outputs (transmits) an activation instruction to the first GW 8 and the in-vehicle ECU 3Aa of its own bus 4A (S05). The first GW 8 and the in-vehicle ECU 3Aa perform an activation process in accordance with the activation instruction output from the in-vehicle device 2 (S06). The first GW 8 and the in-vehicle ECU 3Aa that have acquired (received) the activation instruction from the in-vehicle device 2 perform an activation process to apply the update program by restarting the storage area (non-operational surface) in which the update program is stored as the operational surface.
[0067] Through the above process, the activation process of the update program is completed only in the first GW 8 and the in-vehicle ECU 3Aa among the update targets (see FIG. 4B).
[0068] The in-vehicle device 2 performs an operation check (abnormality detection) process on the first GW 8 and the in-vehicle ECU 3Aa for which the activation process has been completed (S07). For example, the in-vehicle device 2 requests the transmission of version information indicating the version of the updated program, and compares the version information sent from the first GW 8 and the in-vehicle ECU 3Aa in response to the request from the in-vehicle device 2 with the update information. If they match, it is determined to be normal, and if they do not match, it is determined to be abnormal. In addition, the in-vehicle device 2 may, for example, monitor whether or not a periodic spontaneous transmission frame is transmitted from the first GW8 and the in-vehicle ECU 3Aa after the activation process, and perform abnormality detection processing depending on whether or not the spontaneous transmission frame is received.
[0069] In response to the result of the abnormality detection, the in-vehicle device 2 outputs (transmits) an update program for the in-vehicle ECU 3 to be updated (in-vehicle ECUs 3Ba, 3Bb) connected to another bus 4B (hereinafter referred to as another bus 4B) to which the in-vehicle device 2 is not connected (S08). The in-vehicle device 2 identifies the in-vehicle ECU 3 to be updated on the other bus 4B based on the target information acquired from the external server S1, and transmits the update program to the in-vehicle ECUs 3Ba, 3Bb of the bus 4B via the first GW 8 for the identified in-vehicle ECU 3.
[0070] The in-vehicle ECU 3 (in-vehicle ECU 3Ba, 3Bb) to be updated installs the update program acquired (received) from the in-vehicle device 2 via the first GW 8 (S09). Similar to the first GW 8, the in-vehicle ECU 3Ba, 3Bb to be updated stores the acquired update program in a non-operational side, thereby preventing the program currently being executed in the operational side from being overwritten.
[0071] The in-vehicle device 2 outputs (transmits) an activation instruction to the in-vehicle ECUs 3 (in-vehicle ECUs 3Ba and 3Bb) to be updated on the other bus 4B via the first GW 8 (S10). The in-vehicle device 2 outputs the activation instruction to each of the in-vehicle ECUs 3Ba and 3Bb, causing the in-vehicle ECUs 3Ba and 3Bb to execute activation processing.
[0072] The in-vehicle ECUs 3Ba and 3Bb of the other bus 4B perform activation processing in response to the activation instruction output from the in-vehicle device 2 (S11). Upon acquiring (receiving) the activation instruction from the in-vehicle device 2, the in-vehicle ECUs 3Ba and 3Bb perform activation processing to apply the update program by restarting the storage area (non-operational surface) in which the update program is stored as the operational surface.
[0073] Through the above processing, the activation processing of the update programs is completed in all of the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb that are the update targets (see FIGS. 4C and 5A).
[0074] The in-vehicle device 2 performs an operation check (abnormality detection) process on the in-vehicle ECUs 3Ba, 3Bb for which the activation process has been completed (S12). For example, the in-vehicle device 2 requests the in-vehicle ECUs 3Ba, 3Bb to transmit version information indicating the version of the updated program, and compares the version information transmitted from the in-vehicle ECUs 3Ba, 3Bb via the first GW 8 in response to the request from the in-vehicle device 2 with the update information. If the information matches, the in-vehicle device 2 determines that the in-vehicle ECUs are normal, and if the information does not match, the in-vehicle device 2 determines that the in-vehicle ECUs are abnormal. In addition, the in-vehicle device 2 may, for example, monitor whether or not a periodic spontaneous transmission frame is transmitted from the in-vehicle ECUs 3Ba and 3Bb after the activation process, and perform abnormality detection processing depending on whether or not the spontaneous transmission frame is received.
[0075] If the result of the abnormality detection is normal, the in-vehicle device 2 outputs (transmits) to the external server S1 a message indicating that the update process has been completed normally, and ends the update process (see S16). On the other hand, if it is determined that there is an abnormality, the in-vehicle device 2 simultaneously outputs (transmits) a rollback instruction to the first GW 8 and the in-vehicle ECU 3Aa connected to its own bus 4A, and the in-vehicle ECUs 3Ba and 3Bb connected to the other bus 4B (S13). That is, if the program update in the in-vehicle ECUs 3Ba and 3Bb has not been completed normally for some reason, the in-vehicle device 2 outputs (transmits) a rollback instruction to the first GW 8 and the in-vehicle ECU 3Aa of its own bus 4A, and the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B.
[0076] The first GW 8 and the in-vehicle ECU 3Aa of the local bus 4A perform rollback processing in response to the rollback instruction output from the in-vehicle device 2 (S14). The in-vehicle ECUs 3Ba and 3Bb of the other bus 4B perform rollback processing based on the rollback instruction output from the in-vehicle device 2 (S15).
[0077] Specifically, upon receiving the rollback instruction output from the in-vehicle device 2, the first GW 8, the in-vehicle ECU 3Aa, and the in-vehicle ECUs 3Ba and 3Bb perform the rollback process by restarting to execute the program (original program) that was running before the update program was applied (activated). The original program is stored (saved) as a backup in a storage area (non-operational surface) different from the storage area (operational surface) in which the update program is stored. The first GW 8, the in-vehicle ECU 3Aa, and the in-vehicle ECUs 3Ba and 3Bb perform the rollback process by restarting with the storage area (non-operational surface) in which the original program is stored as the operation surface and the storage area in which the update program is stored as the non-operational surface.
[0078] Through the above process, rollback processing is performed in all of the first gateway 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb that are the update targets, and the execution environment of the original program is restored (see FIG. 5B).
[0079] The in-vehicle device 2 outputs (transmits) the processing result related to the update program to the external server S1 (S16). As a result of the processing related to the update program, the in-vehicle device 2 outputs (transmits) to the external server S1 an update success notice indicating that the application of the update program to the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb, which are the update targets, was successful, or an update failure notice indicating that the application of the update program failed and a rollback process was performed. The in-vehicle device 2 may output the processing result related to the update program to the display device 5 and cause the display device 5 to display the processing result. The in-vehicle device 2 may modify the update information related to the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb, which are the update targets, based on the processing result of the update program.
[0080] The above-described series of processes (S01 to S16) related to program update are performed during a period when the vehicle C is prohibited from being started, such as a period when engine start or traction motor drive is prohibited. By performing the processes during this prohibited period, it is possible to prevent the engine from being started in a state where a temporary inconsistency (version difference) occurs between the applied programs. When performing the series of processes related to program update during a period when the vehicle C is prohibited from being started, the in-vehicle device 2 may temporarily disable the ON signal output from the IG switch 6 via the input / output I / F 21 or the like by, for example, performing masking processing.
[0081] 6 is a flowchart illustrating an example of processing by the control unit 20 of the in-vehicle device 2. The control unit 20 of the in-vehicle device 2 steadily performs the following processing, for example, when the vehicle C is stopped. The following describes an example in which the in-vehicle ECU 3Aa of the bus 4A, the first GW 8, and the in-vehicle ECUs 3Ba and 3Bb of the bus 4B are to be updated, as shown in FIGS.
[0082] The control unit 20 acquires an update program (package) from the external server S1 via the exterior-vehicle communication device 1 (S101). The control unit 20 stores the update program included in the acquired package in the storage unit 23 (S102). The control unit 20 also updates the update information based on the acquired package.
[0083] First, the control unit 20 outputs (transmits) an update program to the first GW 8 and the in-vehicle ECU 3 of its own bus 4A that are to be updated (S103). The control unit 20 identifies the first GW 8 and the in-vehicle ECU 3 (in-vehicle ECU 3Aa) that are to be updated based on the target information included in the package acquired from the external server S1, and transmits the update program to the identified first GW 8 and in-vehicle ECU 3Aa.
[0084] At this time, the first GW 8 stores the update program transmitted by the control unit 20 in the storage unit 81, and the in-vehicle ECU 3Aa installs the update program transmitted by the control unit 20 in the storage unit. The installation process for such an update program has already been described, and a detailed description thereof will be omitted.
[0085] Next, the control unit 20 outputs (transmits) an activation instruction to the first GW 8 and the in-vehicle ECU 3Aa of the local bus 4A that are to be updated (S104). The control unit 20 outputs the activation instruction to each of the first GW 8 and the in-vehicle ECU 3Aa, and causes the first GW 8 and the in-vehicle ECU 3Aa to execute the activation process.
[0086] At this time, the first GW 8 and the in-vehicle ECU 3Aa perform activation processing in response to the activation instruction output from the in-vehicle device 2. Such activation processing has already been described, and detailed description thereof will be omitted.
[0087] The control unit 20 performs an abnormality detection process (operation check) on the first GW 8 and the in-vehicle ECU 3Aa for which the activation process has been completed, and determines whether an abnormality has been detected (S105). For example, the control unit 20 requests the transmission of version information indicating the version of the updated program, and compares the version information sent from the first GW 8 and the in-vehicle ECU 3Aa in response to the request from the control unit 20 with the update information stored in the storage unit 23. If they match, the control unit 20 determines that the program is normal (no abnormality), and if they do not match, the control unit 20 determines that the program is abnormal.
[0088] If an abnormality is detected, i.e., if it is determined that there is an abnormality (S105: YES), the control unit 20 outputs (transmits) a rollback instruction to the first GW8 and the in-vehicle ECU 3Aa of the own bus 4A on which the update program has been installed (S110).
[0089] In response to the rollback instruction output from the in-vehicle device 2, the first GW 8 and the in-vehicle ECU 3Aa perform rollback processing. The first GW 8 and the in-vehicle ECU 3Aa perform the rollback processing by restarting to execute the program (original program) that was being executed before the update program was applied (activation processing). The rollback processing has already been described, and a detailed description thereof will be omitted. The process then proceeds to S109.
[0090] If no abnormality is detected, i.e., if it is determined to be normal (S105: NO), the control unit 20 outputs (transmits) the update program to the remaining in-vehicle ECUs 3 of the other bus 4B that are to be updated (S106). The control unit 20 identifies the in-vehicle ECUs 3 (in-vehicle ECUs 3Ba, 3Bb) of the other bus 4B that are to be updated based on the target information included in the package acquired from the external server S1, and transmits the update program to the identified in-vehicle ECUs 3Ba, 3Bb via the first GW 8.
[0091] At this time, the in-vehicle ECUs 3Ba, 3Bb install in the storage unit the update program transmitted by the control unit 20. The installation process for such an update program has already been described, and a detailed description thereof will be omitted.
[0092] Next, the control unit 20 outputs (transmits) an activation instruction to the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B that are to be updated (S107). The control unit 20 outputs the activation instruction to each of the in-vehicle ECUs 3Ba and 3Bb via the first GW 8, and causes the in-vehicle ECUs 3Ba and 3Bb to execute the activation process.
[0093] At this time, the in-vehicle ECUs 3Ba and 3Bb perform activation processing in response to the activation instruction output from the in-vehicle device 2. Such activation processing has already been described, and detailed description thereof will be omitted.
[0094] The control unit 20 performs an abnormality detection process (operation check) on the in-vehicle ECUs 3Ba, 3Bb for which activation process has been completed, and determines whether an abnormality has been detected (S108). For example, the control unit 20 requests the in-vehicle ECUs 3Ba, 3Bb to transmit version information indicating the version of the updated program, and compares the version information transmitted from the in-vehicle ECUs 3Ba, 3Bb in response to the request from the control unit 20 with the update information stored in the storage unit 23. If they match, the control unit 20 determines that the ECUs are normal (no abnormality), and if they do not match, the control unit 20 determines that an abnormality has occurred.
[0095] If an abnormality is detected, i.e., if it is determined that there is an abnormality (S108: YES), the control unit 20 outputs (transmits) a rollback instruction to the first GW 8, the in-vehicle ECU 3Aa of the local bus 4A, and the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B, on which the installation of the update program has been completed (S111). Since it was confirmed in step S105 that the first GW 8 is normal, it is possible to simultaneously issue a rollback instruction to the first GW 8, the in-vehicle ECU 3Aa of the local bus 4A, and the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B.
[0096] The first gateway 8, the in-vehicle ECU 3Aa, and the in-vehicle ECUs 3Ba and 3Bb perform rollback processing in response to the rollback instruction output from the in-vehicle device 2. The rollback processing has already been described, and a detailed description thereof will be omitted.
[0097] The above process performs rollback processing in all of the update targets, the first gateway 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb, and returns the execution environment to the original program. This prevents inconsistencies due to differences in program versions between the in-vehicle ECUs 3Ba and 3Bb and the first gateway 8 and the in-vehicle ECU 3Aa.
[0098] On the other hand, if no abnormality is detected, that is, if it is determined to be normal (S108: NO), the control unit 20 outputs (transmits) the processing result related to the update program to the external server S1 (S109). The control unit 20 outputs (transmits) to the external server S1 via the exterior communication device 1, as the processing result related to the update program, an update success notice indicating that the update program has been successfully applied to the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb that are the update targets, or an update failure notice indicating that the application of the update program has failed and a rollback process has been performed, as the processing result related to the update program.
[0099] In the in-vehicle device 2 of this embodiment, when a program is updated and the first GW 8 is included in the update targets, the update of the first GW 8 is prioritized. That is, as described above, when the update targets include the first GW 8, the in-vehicle ECU 3 of the local bus 4, and the in-vehicle ECU 3 of the other bus 4B, the in-vehicle device 2 first completes activation processing for the first GW 8 and the in-vehicle ECU 3 of the local bus 4A, confirms that the first GW 8 is normal, and then continues processing for the in-vehicle ECU 3 of the other bus 4B. In this way, because the program is updated while ensuring the normal state of the first GW 8, the program update for the in-vehicle ECU 3 of the other bus 4B can be accurately executed. This prevents communication between the local bus 4A and the other bus 4B from being lost after the program update processing.
[0100] In addition, in the in-vehicle device 2 of this embodiment, if the update targets include the first GW8 and the in-vehicle ECU 3 of the other bus 4B, i.e., if the in-vehicle ECU 3 of the own bus 4A is not included, the in-vehicle device 2 first completes the activation process for the first GW8, then confirms that the first GW8 is normal, and then continues processing for the in-vehicle ECU 3 of the other bus 4B.
[0101] FIG. 7 is an explanatory diagram illustrating another example of the processing flow (sequence) by the in-vehicle device 2, the device to be updated (the first GW 8 and the in-vehicle ECU 3), and the like. For convenience, the following description will be given taking as an example a case where the in-vehicle ECU 3Aa of the bus 4A, the first GW 8, and the in-vehicle ECUs 3Ba and 3Bb of the bus 4B are to be updated.
[0102] 8 is an explanatory diagram illustrating state transitions of the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated during program update processing, and FIG. 9 is an explanatory diagram illustrating state transitions of the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated during rollback processing. In FIGS. 8 and 9, the states of the in-vehicle device 2, the first GW 8, and the in-vehicle ECU 3 to be updated before and after the update program is applied are shown in inverted display form. In FIG. 8, the update target is indicated by a black circle.
[0103] The in-vehicle device 2 acquires an update program from the external server S1 (S21). The in-vehicle device 2 accesses the external server S1 using, for example, the identification number (VIN) of the vehicle C (host vehicle) in which the in-vehicle device 2 is installed, and acquires a package including an update program to be applied to the host vehicle from the external server S1. The package includes, for example, package information (campaign information) that is information related to the program update, information (target information) related to the first GW 8 and the in-vehicle ECU 3 to be updated, and the update program to be applied to the first GW 8 and the in-vehicle ECU 3 to be updated.
[0104] The in-vehicle device 2 stores the update program included in the acquired package in the storage unit 23 (S22). The acquired update program is stored in the first storage unit 231 or the second storage unit 232. The in-vehicle device 2 also updates the update information based on the acquired package.
[0105] Based on the target information acquired from the external server S1, the in-vehicle device 2 outputs (transmits) update programs for the first GW8 and each in-vehicle ECU to the first GW8 and in-vehicle ECU 3Aa connected to its own bus 4A, which are the update targets, and to the in-vehicle ECUs 3Ba and 3Bb connected to the other bus 4B (see Figure 8A) (S23).
[0106] The first GW 8 stores the update program acquired (received) from the in-vehicle device 2 in the storage unit 81, and the in-vehicle ECU 3Aa installs the update program acquired from the in-vehicle device 2 in the storage unit (S24).
[0107] For example, if the currently running program is stored in a first area of the storage unit 81, the first area corresponds to the operating surface. In this case, a program of an earlier version (old version) than the currently running program is stored as a backup in a second area of the storage unit 81, which is the non-operating surface. The first gateway 8 stores the acquired update program for its own device in the second area, which is the non-operating surface. This prevents the currently running program from being overwritten, allowing the current operating state to be stably maintained.
[0108] As with the first GW 8, the in-vehicle ECU 3Aa stores the acquired update program in a non-operational side, thereby preventing the currently executed program (stored in the operational side) from being overwritten.
[0109] At this time, the in-vehicle ECUs 3Ba, 3Bb to be updated also install the update program acquired (received) from the in-vehicle device 2 via the first GW 8 (S25). As with the first GW 8, the in-vehicle ECUs 3Ba, 3Bb store the acquired update program in a non-operational side, thereby preventing the program currently being executed in the operational side from being overwritten.
[0110] The in-vehicle device 2 outputs (transmits) an activation instruction to the first GW 8 and the in-vehicle ECU 3Aa of its own bus 4A and the in-vehicle ECUs 3Ba, 3Bb of the other bus 4B (S26), causing the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb to execute activation processing.
[0111] The first GW 8 and the in-vehicle ECU 3Aa of the local bus 4 perform activation processing in response to the activation instruction output from the in-vehicle device 2 (S27). The first GW 8 and the in-vehicle ECU 3Aa that have acquired (received) the activation instruction from the in-vehicle device 2 perform activation processing to apply the update program by restarting the storage area (non-operational surface) in which the update program is stored as the operational surface.
[0112] At this time, the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B also perform activation processing in response to the activation instruction output from the in-vehicle device 2 (S28). The in-vehicle ECUs 3Ba and 3Bb that have acquired (received) the activation instruction from the in-vehicle device 2 perform activation processing to apply the update program by restarting the storage area (non-operational surface) in which the update program is stored as the operational surface.
[0113] Through the above processing, the activation processing of the update programs is completed in all of the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb that are the update targets (see FIGS. 8B and 9A).
[0114] The in-vehicle device 2 performs an operation check (abnormality detection) process on the first GW 8 and the in-vehicle ECU 3Aa of the local bus 4A, and the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B, for which the activation process has been completed (S29). The method for such abnormality detection has already been described, so a detailed description will be omitted.
[0115] If the result of the abnormality detection is normal, the in-vehicle device 2 outputs (transmits) to the external server S1 a message indicating that the update process has been completed normally, and ends the update process (see S35). On the other hand, if it is determined that there is an abnormality, the in-vehicle device 2 first outputs (transmits) a rollback instruction to the first GW 8 and the in-vehicle ECU 3Aa connected to its own bus 4A (S30). That is, if the program update in the in-vehicle ECUs 3Ba and 3Bb is not completed normally for some reason, or if an abnormality occurs in the first GW 8, the in-vehicle device 2 first outputs (transmits) a rollback instruction to the first GW 8 of its own bus 4A and the in-vehicle ECU 3Aa.
[0116] The first GW8 and the in-vehicle ECU 3Aa of the local bus 4A perform rollback processing in response to the rollback instruction output from the in-vehicle device 2 (S31). The first GW8 and the in-vehicle ECU 3Aa, which have received the rollback instruction output from the in-vehicle device 2, perform rollback processing by restarting to execute the program (original program) that was running before the update program was applied (activated). The original program is stored (saved) as a backup in a storage area (non-operational surface) different from the storage area (operational surface) in which the update program is stored. The first GW8 and the in-vehicle ECU 3Aa perform rollback processing by restarting with the storage area (non-operational surface) in which the original program is stored as the operation surface and the storage area in which the update program is stored as the non-operational surface.
[0117] By the above process, the rollback process is performed only in the first GW 8 and the in-vehicle ECU 3Aa, and the execution environment of the original program is restored (see FIG. 9B). At this time, the in-vehicle device 2 updates the update information to the information of the original program.
[0118] Next, the in-vehicle device 2 checks whether the program version of the first GW 8 after the rollback process is the same as the original program version (S32). For example, the in-vehicle device 2 requests transmission of version information indicating the program version after the rollback process, and compares the version information sent from the first GW 8 in response to the request from the in-vehicle device 2 with the update information.
[0119] If the program version of the first GW 8 is the version of the original program, the in-vehicle device 2 outputs (transmits) a rollback instruction to the in-vehicle ECUs 3Ba and 3Bb connected to the other bus 4B (S33). That is, when the rollback process is performed on the first GW 8 and the in-vehicle ECU 3Aa among the devices to be updated, the in-vehicle device 2 also outputs a rollback instruction to the in-vehicle ECUs 3Ba and 3Bb, thereby preventing inconsistencies due to differences in the program versions between the in-vehicle ECUs 3Ba and 3Bb and the first GW 8 and the in-vehicle ECU 3Aa.
[0120] The in-vehicle ECUs 3Ba and 3Bb of the other bus 4B perform rollback processing based on the rollback instruction output from the in-vehicle device 2 (S34). The in-vehicle ECUs 3Ba and 3Bb that have received the rollback instruction output from the in-vehicle device 2 perform rollback processing by restarting to execute the original program. The original program is stored (saved) as a backup on an inactive surface. The in-vehicle ECUs 3Ba and 3Bb perform rollback processing by setting the inactive surface in which the original program is stored as the active surface, switching the storage area in which the update program is stored to the inactive surface, and restarting the inactive surface.
[0121] Through the above process, rollback processing is performed in all of the first gateway 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb that are the update targets, and the execution environment of the original program is restored (see FIG. 10C).
[0122] The in-vehicle device 2 outputs (transmits) the processing result related to the update program to the external server S1 (S35). As a result of the processing related to the update program, the in-vehicle device 2 outputs (transmits) to the external server S1 an update success notification indicating that the update program has been successfully applied to the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb that are the update targets, or an update failure notification indicating that the application of the update program has failed and a rollback process has been performed.
[0123] The above-described series of processes (S21 to S35) related to program update are performed during a period when the vehicle C is prohibited from being started, such as a period when engine start or traction motor drive is prohibited. By performing the processes during this prohibited period, it is possible to prevent the engine from being started or the like from being performed when a temporary inconsistency (version difference) has occurred between the applied programs.
[0124] 10 is a flowchart illustrating another example of the processing of the control unit 20 of the in-vehicle device 2. The control unit 20 of the in-vehicle device 2 steadily performs the following processing, for example, when the vehicle C is stopped. The following describes an example in which the in-vehicle ECU 3Aa of the bus 4A, the first GW 8, and the in-vehicle ECUs 3Ba and 3Bb of the bus 4B are to be updated, as shown in FIGS.
[0125] The control unit 20 acquires an update program (package) from the external server S1 via the exterior-vehicle communication device 1 (S201). The control unit 20 stores the update program included in the acquired package in the storage unit 23 (S202). The control unit 20 also updates the update information based on the acquired package.
[0126] Next, the control unit 20 outputs (transmits) the update program to the first GW 8, the in-vehicle ECU 3Aa of the local bus 4A, and the in-vehicle ECUs 3Ba, 3Bb of the other bus 4B, which are the update targets (S203). The control unit 20 identifies the first GW 8 and the in-vehicle ECUs 3 (in-vehicle ECUs 3Aa, 3Ba, 3Bb) to be updated based on the target information included in the package acquired from the external server S1, and transmits the update program to the identified first GW 8 and in-vehicle ECUs 3Aa, 3Ba, 3Bb.
[0127] At this time, the first GW 8 stores the update program transmitted by the control unit 20 in the storage unit 81, and the in-vehicle ECUs 3Aa, 3Ba, 3Bb install the update program transmitted by the control unit 20 in the storage unit. The installation process for such an update program has already been described, and a detailed description thereof will be omitted.
[0128] Next, the control unit 20 outputs (transmits) an activation instruction to the first GW 8, the in-vehicle ECU 3Aa of the local bus 4A, and the in-vehicle ECUs 3Ba, 3Bb of the other bus 4B, which are the update targets (S204). The control unit 20 outputs the activation instruction to each of the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb, and causes the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb to execute the activation process.
[0129] At this time, the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb perform activation processing in response to the activation instruction output from the in-vehicle device 2. Such activation processing has already been described, and detailed description thereof will be omitted.
[0130] The control unit 20 performs an abnormality detection process (operation check) on the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb for which activation process has been completed, and determines whether an abnormality has been detected (S205). For example, the control unit 20 requests the transmission of version information indicating the version of the updated program, and compares the version information sent from the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb in response to the request from the control unit 20 with the update information stored in the storage unit 23. If they match, the control unit 20 determines that the program is normal (no abnormality), and if they do not match, the control unit 20 determines that the program is abnormal.
[0131] If an abnormality is detected, that is, if it is determined that the first GW 8 or any of the in-vehicle ECUs Aa, 3Ba, and 3Bb is abnormal (S205: YES), the control unit 20 first outputs (transmits) a rollback instruction to the first GW 8 and the in-vehicle ECU 3Aa of its own bus 4A (S207). At this time, the control unit 20 updates the update information related to the first GW 8 and the in-vehicle ECU 3Aa of its own bus 4A to the information of the original program.
[0132] In response to the rollback instruction output from the in-vehicle device 2, the first GW 8 and the in-vehicle ECU 3Aa perform rollback processing. The first GW 8 and the in-vehicle ECU 3Aa perform the rollback processing by restarting to execute the program (original program) that was being executed before the update program was applied (activation processing). The rollback processing has already been described, and a detailed description thereof will be omitted.
[0133] Next, the control unit 20 determines whether the version of the program in the first GW 8 after the rollback process is the same as the version of the original program before the update (S208). For example, the control unit 20 requests the transmission of version information indicating the version of the program after the rollback process, and compares the version information sent from the first GW 8 in response to the request from the control unit 20 with the update information.
[0134] If the control unit 20 determines that the version of the program of the first GW 8 after the rollback process is not the version of the original program before the update (S208: NO), the control unit 20 repeats this determination. If this determination is repeated a predetermined number of times or more, the process may be configured to return to S207.
[0135] If the control unit 20 determines that the program version of the first GW 8 after the rollback process is the same as the version of the original program before the update (S208: YES), it confirms that the first GW 8 is normal, and outputs (transmits) a rollback instruction to the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B (S209). At this time, the control unit 20 updates the update information related to the in-vehicle ECUs 3Ba and 3Bb of the other bus 4B to the information of the original program.
[0136] The in-vehicle ECUs 3Ba and 3Bb perform rollback processing in response to the rollback instruction output from the in-vehicle device 2. The rollback processing has already been described, and a detailed description thereof will be omitted.
[0137] By the above processing, the rollback processing is performed in all of the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb that are the update targets, and the execution environment of the original program is restored.
[0138] On the other hand, if no abnormality is detected in S205, that is, if it is determined to be normal (S205: NO), the control unit 20 outputs (transmits) the processing result related to the update program to the external server S1 (S206). The control unit 20 outputs (transmits) to the external server S1 via the exterior-vehicle communication device 1, as the processing result related to the update program, an update success notice indicating that the update program has been successfully applied to the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, 3Bb that are the update targets, or an update failure notice indicating that the application of the update program has failed and a rollback process has been performed, as the processing result related to the update program.
[0139] As described above, in the in-vehicle device 2 of this embodiment, if an abnormality occurs in the in-vehicle ECU 3 of the other bus 4B or the first GW 8 after a program update, the rollback process of the first GW 8 is performed first. That is, if an abnormality occurs in the in-vehicle ECU 3 of the other bus 4B or the first GW 8 after the activation process for all devices to be updated (the first GW 8 and the in-vehicle ECUs 3Aa, 3Ba, and 3Bb) is completed, the in-vehicle device 2 first executes the rollback process on the first GW 8 and the in-vehicle ECU 3 of its own bus 4A. As a result, after ensuring the normal state of the first GW 8 in the execution environment of the original program, the in-vehicle device 2 executes the rollback process on the in-vehicle ECU 3 of the other bus 4B. In this way, the rollback process is executed after ensuring the normal state of the first GW 8, so that the rollback process on the in-vehicle ECU 3 of the other bus 4B can be executed accurately. Therefore, it is possible to prevent communication between the local bus 4A and the other bus 4B from becoming impossible due to an abnormality occurring after the program update process.
[0140] (Variation 1) Although the above description has been given taking as an example a case where only the in-vehicle ECU 3 is connected to the other bus 4B, the present invention is not limited to this. Fig. 11 is an explanatory diagram illustrating an example of state transitions of each device in a program update process in Modification 1, and Fig. 12 is an explanatory diagram illustrating an example of state transitions of each device in a rollback process in Modification 1. In Figs. 11 and 12, the first GW 8 and the in-vehicle ECU 3, which are devices to be updated, are shown in inverted display form before and after the update program is applied. Note that in Fig. 11, the update targets are indicated by black circles.
[0141] In this modified example, a local bus 4A and another bus 4B are connected to a first GW 8, a second GW 9 is further connected to the other end of the other bus 4B, and a bus 4C is connected to the second GW 9. An in-vehicle device 2 and in-vehicle ECUs 3Aa and 3Ab are connected to the local bus 4A, in-vehicle ECUs 3Ba, 3Bb, and 3Bc are connected to the other bus 4B, and in-vehicle ECUs 3Ca and 3Cb are connected to the bus 4C.
[0142] In the in-vehicle device 2 of this modified example, when the update targets include the first GW 8 and other devices during a program update, the update of the first GW 8 is given priority. For convenience, the following description will be given taking as an example a case where the update targets are the in-vehicle ECU 3Aa of the local bus 4A, the first GW 8, the in-vehicle ECUs 3Ba and 3Bb of the bus 4B, the second GW 9, and the in-vehicle ECU 3Ca (see FIG. 11A).
[0143] First, the in-vehicle device 2 performs activation processing on the first GW8 and the in-vehicle ECU 3 (in-vehicle ECU 3Aa) of its own bus 4A (see FIG. 11B). After the activation processing on the first GW8 and the in-vehicle ECU 3Aa is completed, the in-vehicle device 2 checks whether the first GW8 is operating normally (detects abnormality). If the first GW8 is operating normally, the in-vehicle device 2 performs activation processing on the in-vehicle ECUs 3 (in-vehicle ECUs 3Ba and 3Bb) of the other bus 4B and the second GW9 via the first GW8 (see FIG. 11C). After the activation processing on the second GW9 and the in-vehicle ECUs 3Ba and 3Bb is completed, the in-vehicle device 2 checks whether the second GW9 is operating normally (detects abnormality). When the second GW 9 is operating normally, the in-vehicle device 2 continues the activation process for the in-vehicle ECU 3 (in-vehicle ECU 3Ca) on the bus 4C via the first GW 8 and the second GW 9 (see FIG. 11D).
[0144] In this way, when the first GW 8 and the second GW 9 are included in the update targets, the in-vehicle device 2 updates the first GW 8, which has a smaller number of hops, first, and then updates the second GW 9, thereby ensuring the normal status of the first GW 8 and the second GW 9 and executing the program update. Therefore, the program update for the in-vehicle ECU 3 of the other bus 4B and the in-vehicle ECU 3 of the bus 4C can be executed accurately.
[0145] Furthermore, in the in-vehicle device 2 of this modified example, if an abnormality occurs in the first GW8, the in-vehicle ECU 3 of another bus 4, the second GW9, or the in-vehicle ECU 3 of bus 4C after a program update, the rollback processing of the first GW8 is performed with priority.
[0146] It is conceivable that after the activation process for all devices to be updated (1st GW8, 2nd GW9 and in-vehicle ECUs 3Aa, 3Ba, 3Bb, 3Ca) has been completed (see Figure 12A), an abnormality may occur in any of the 1st GW8, 2nd GW9 and in-vehicle ECUs 3Aa, 3Ba, 3Bb, 3Ca.
[0147] In this case, the in-vehicle device 2 first causes the first GW 8 and the in-vehicle ECU 3 of its own bus 4A (in-vehicle ECU 3Aa) to execute rollback processing (see FIG. 12B). This ensures that the first GW 8 is in a normal state in the execution environment of the original program. Thereafter, the in-vehicle device 2 causes the in-vehicle ECUs 3 of the other bus 4B (in-vehicle ECUs 3Ba and 3Bb) and the second GW 9 to execute rollback processing via the first GW 8 (see FIG. 12C). This ensures that the second GW 9 is in a normal state in the execution environment of the original program. Thereafter, the in-vehicle device 2 causes the in-vehicle ECU 3 of the bus 4C (in-vehicle ECU 3Ca) to execute rollback processing via the first GW 8 and the second GW 9 (see FIG. 12D).
[0148] In this way, when the first GW 8 and the second GW 9 are included in the targets of the rollback process, the in-vehicle device 2 performs the rollback process of the first GW 8, which has a smaller number of hops, first, and then performs the rollback process of the second GW 9, thereby ensuring the normal status of the first GW 8 and the second GW 9 and executing the rollback process accordingly. This allows the rollback process to be executed accurately for the in-vehicle ECU 3 of the other bus 4B and the in-vehicle ECU 3 of the bus 4C.
[0149] (Variation 2) The present invention is also applicable to cases where the in-vehicle update system S includes a virtual network. For example, a virtualized operating system such as Hypervisor, VMware, or Xen is stored in a storage unit (not shown) of a vehicle C (see FIG. 1). A control unit (not shown) of the vehicle C can be started using the virtualized operating system to create multiple virtual devices on the virtualized operating system. A specific program is executed on each virtual device, generating one or more tasks according to the processing content of the program.
[0150] In this embodiment, an example will be described in which the virtualization method is a hypervisor method in which a virtualized operating system directly accesses hardware resources such as the control unit, but the virtualization method is not limited to the hypervisor method. For example, the virtualization method may be a host OS method in which an operating system such as Linux (registered trademark) is interposed between the virtualized operating system and the hardware resources. Furthermore, the virtualization method may be one that uses a container-based virtualized operating system.
[0151] FIG. 13 is an exemplary diagram illustrating a configuration in which an in-vehicle update system S according to the second modification includes a virtual network. The vehicle C, which is started up using the virtualized operating system, can construct a virtual in-vehicle device 200, a virtual GW 800, a virtual in-vehicle ECU 30Ba, a virtual in-vehicle ECU 30Bb, a virtual bus I40A, and a virtual bus II40B by using the functions of the virtualized operating system. The virtual in-vehicle device 200 and the virtual GW 800 are logically connected to the virtual bus I40A, and the virtual GW 800, the virtual in-vehicle ECU 30Ba, and the virtual in-vehicle ECU 30Bb are logically connected to the virtual bus II40B. The virtual bus I40A is connected to the out-of-vehicle communication device 1 via a first communication unit 50, and the virtual GW 800 is connected to a bus 4D via a second communication unit 60. The in-vehicle ECUs 3Da, 3Db, and 3Dc are connected to the bus 4D.
[0152] For example, the virtual in-vehicle device 200, the virtual GW 800, and the virtual in-vehicle ECUs 30Ba and 30Bb are allocated hardware resources of the control unit of the vehicle C, and the virtual bus I 40A and the virtual bus II 40B are allocated hardware resources of the storage unit of the vehicle C.
[0153] In the in-vehicle update system S according to the second modification, when a program is updated and the virtual GW 800 is included in the update targets, the update of the virtual GW 800 is given priority. For convenience, the following description will be given taking as an example a case where the virtual in-vehicle ECU 30Ba of the virtual bus II 40B, the virtual GW 800, and the in-vehicle ECUs 3Da and 3Db of the bus 4D are to be updated (see FIG. 13A).
[0154] First, the virtual in-vehicle device 200 performs activation processing on the virtual GW 800 (see FIG. 13B). After the activation processing on the virtual GW 800 is completed, the virtual in-vehicle device 200 checks whether the virtual GW 800 is operating normally (detects an abnormality). If the virtual GW 800 is operating normally, the virtual in-vehicle device 200 performs activation processing on the virtual in-vehicle ECU 30Ba of the virtual bus II 40B via the virtual GW 800, and also performs activation processing on the in-vehicle ECUs 3Da and 3Db of the bus 4D via the second communication unit 60 (see FIG. 13C).
[0155] Furthermore, in the in-vehicle update system S according to the second modification, if an abnormality occurs in the virtual gateway 800, the virtual in-vehicle ECU 30Ba, or the in-vehicle ECUs 3Da and 3Db after a program update, the rollback process of the virtual gateway 800 is performed first. That is, the rollback process is performed on the virtual gateway 800 first, and then the rollback process is performed on the virtual in-vehicle ECU 30Ba or the in-vehicle ECUs 3Da and 3Db. The rollback process has already been described, and a detailed description thereof will be omitted.
[0156] The embodiments disclosed herein are to be considered in all respects as illustrative and not restrictive. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0157] 1. External communication device 2 Onboard equipment 3,3Aa,3Ab,3Ba,3Bb,3Bc,3Ca,3Cb,3Da,3Db,3Dc Automotive ECU 4, 4A, 4B, 4C, 4D buses 5 Display device 6 IG Switch 8 1st GW 9 2nd GW 20 Control Unit 21 Input / Output Interface 22 In-vehicle communication unit 23 Memory section 24 Recording media 30Ba, 30Bb Virtual in-vehicle ECU 40A Virtual Bus I 40B Virtual Bus II 50 First Communications Department 60 Second Communications Department 81 Storage section 200 Virtual vehicle-mounted device 800 virtual gateways 231 1st memory section 232 2nd memory section C vehicle N External network P control program S In-vehicle update system S1 External Server S11 storage section
Claims
1. An in-vehicle device connected to a first bus connected to a relay device that relays bus-to-bus communication, acquiring an update program from outside the vehicle, and updating programs of the relay device and an in-vehicle ECU, and a control unit that, when an update target includes the relay device and a plurality of vehicle-mounted ECUs on a second bus connected to the relay device, prioritizes updating the relay device over any of the vehicle-mounted ECUs. In-vehicle device.
2. When the update targets include the on-board ECUs of the relay device and the second bus, and the on-board ECU of the first bus, the control unit prioritizes updating the on-board ECUs of the relay device and the first bus. The in-vehicle device according to claim 1 .
3. an abnormality detection unit that detects an abnormality in the relay device after an activation process for applying the update program is executed in the relay device; The in-vehicle device according to claim 2 .
4. If no abnormality is detected, the control unit updates the vehicle ECU of the second bus. The in-vehicle device according to claim 3 .
5. When another relay device connected to the second bus and an in-vehicle ECU of a third bus connected to the other relay device are further included in the update target, The control unit updating both the in-vehicle ECU of the second bus and the other relay device; After updating the other relay device, an update process is performed on the vehicle-mounted ECU of the third bus. The in-vehicle device according to any one of claims 2 to 4.
6. When an abnormality is detected, the control unit performs a rollback process for returning the updated program to the program before the update, with priority given to the relay device and the vehicle-mounted ECU of the first bus. The in-vehicle device according to claim 3 .
7. The control unit After the rollback process is performed on the relay device, the rollback process is performed on the vehicle-mounted ECU of the second bus. The in-vehicle device according to claim 6.
8. When further updates are performed in another relay device connected to the second bus and an in-vehicle ECU of a third bus connected to the other relay device, The control unit performing rollback processing for both the in-vehicle ECU of the second bus and the other relay device; After the rollback process of the other relay device, the rollback process of the vehicle-mounted ECU of the third bus is performed. The in-vehicle device according to claim 7.
9. a computer of an in-vehicle device that is connected to a first bus that is connected to a relay device that relays bus-to-bus communications, acquires an update program from outside the vehicle, and updates the programs of the relay device and the in-vehicle ECU; When the update target includes the relay device and a plurality of vehicle-mounted ECUs on a second bus connected to the relay device, the update of the relay device is prioritized over any of the vehicle-mounted ECUs. A computer program that executes a process.
10. an in-vehicle device connected to a first bus connected to a relay device that relays bus-to-bus communications, acquiring an update program from outside the vehicle, and updating the programs of the relay device and the in-vehicle ECU; When the update target includes the relay device and a plurality of vehicle-mounted ECUs on a second bus connected to the relay device, the update of the relay device is prioritized over any of the vehicle-mounted ECUs. A program update method for executing a process.
Citation Information
Patent Citations
Method for updating program
JP1995295943A
Down loading method
JP2000090023A
In-vehicle system
JP2014113952A
On-vehicle network system
JP2016112909A
Relaying apparatus and method and program for relaying
JP2017097851A