Server, software management system including the server, software management method, and computer program

By coordinating software transmission between servers based on activation completion and charging status, the method ensures smooth and error-free software updates in vehicle ECUs, addressing issues of simultaneous transmission in multi-server systems.

JP7794105B2Active Publication Date: 2026-01-06TOYOTA JIDOSHA KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022177455
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-04
Publication Date
2026-01-06
Estimated Expiration
2042-11-04

AI Technical Summary

Technical Problem

In vehicle systems with multiple servers managing software transmission, simultaneous transmission of update software and flag data can lead to errors in electronic control units (ECUs) due to overlapping processes, necessitating additional retransmissions and hindering smooth software updates.

Method used

A server manages software transmission by determining the completion of activation processing for second software before transmitting first software, and adjusts based on charging status to ensure coordinated and error-free updates.

Benefits of technology

This approach enables smooth and efficient software updates in vehicle ECUs by preventing simultaneous execution of update and flag data processes, thereby reducing errors and additional processing needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007794105000001
    Figure 0007794105000001
  • Figure 0007794105000002
    Figure 0007794105000002
  • Figure 0007794105000003
    Figure 0007794105000003
Patent Text Reader

Abstract

To smoothly update software of an electronic apparatus installed on a vehicle.SOLUTION: A flag distribution server 1 manages software of an ECU installed on a vehicle 8. The flag distribution server 1 includes a storage 113 in which flag data 53 is stored, and a processor 111 which transmits the flag data 53 to the vehicle 8 via a wireless communication device. The processor 111 determines whether an activation process of update software transmitted from an OTA server 2 to the vehicle 8 has been completed in the ECU. When the activation process of the update software has not been completed, the processor transmits the flag data 53 to the vehicle 8 after the activation process of the update software is completed.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a server, a software management system including the server, a software management method, and a computer program. [Background technology]

[0002] Research and development is underway on OTA (Over The Air) technology, which wirelessly updates software (vehicle control programs) stored in a vehicle's control device (ECU: Electronic Control Unit). For example, Japanese Patent Application Laid-Open Publication No. 2017-149323 (Patent Document 1) discloses a vehicle control system that can safely update software without compromising user convenience. When a portable device determines that the vehicle's electronic key is located inside the vehicle, it transmits a signal to a server requesting the download of update software. The ECU updates the software by downloading the update software transmitted from the server via the portable device. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-149323 Summary of the Invention [Problem to be solved by the invention]

[0004] A system configuration in which the software of electronic devices installed in a vehicle is managed by multiple servers is conceivable. For example, a server (OTA server) that transmits ECU update software and a server (flag distribution server) that transmits software (so-called flag data) for switching between enabling and disabling specific functions executable by the ECU software can be separately provided.

[0005] In such a system configuration, the software transmission schedules may not be sufficiently coordinated between the two servers. If the transmission of update software and flag data is performed simultaneously, an error may occur in the ECU that receives the two pieces of software. For example, in an ECU in which part of the sequence of processes executed in the order of download-check-switch is shared between the update software reception process and the flag data reception process, an error may occur if the flag data reception process (e.g., downloading flag data) interrupts the execution of the update software reception process (e.g., checking the downloaded software). As a result, the two servers may need to perform additional processes, such as retransmitting the software, which may hinder smooth software updates.

[0006] The present disclosure has been made to solve the above-mentioned problems, and one of the objects of the present disclosure is to smoothly update software of electronic devices installed in a vehicle. [Means for solving the problem]

[0007] (1) A server according to one embodiment of the present disclosure manages software for an electronic device installed in a vehicle. The server includes a storage device storing first software and a processor that transmits the first software to the vehicle via a wireless communication device. The processor determines whether activation processing for second software transmitted to the vehicle from an external server (another server) has been completed in the electronic device, and if the activation processing for the second software has not been completed, transmits the first software to the vehicle after the activation processing for the second software has been completed.

[0008] (2) The first software is flag data for switching between enabling and disabling a specific function of the software, and the second software is update software for updating the software.

[0009] (3) The processor switches between enabling and disabling specific functions depending on the charging status of the vehicle user.

[0010] (4) The first software is update software for updating software. If the update software has a function difference due to a charge, the processor transmits the update software after the activation process of the second software is completed, but if the update software does not have a function difference, the processor transmits the update software without waiting for the activation process of the second software to be completed.

[0011] (5) When the processor receives a notification from the external server indicating that the activation process of the second software has been completed, the processor determines that the activation process of the second software has been completed.

[0012] (6) The processor determines that the activation process of the second software is complete when it receives a notification from the vehicle indicating that the activation process of the second software is complete.

[0013] (7) The external server or the vehicle sends a notification to the processor indicating that the electronic device is processing the second software, and the processor determines that the activation process of the second software has been completed if the notification is not received.

[0014] (8) A software management system according to another aspect of the present disclosure includes the server and an external server.

[0015] (9) According to yet another aspect of the present disclosure, a software management method manages software in an electronic device installed in a vehicle. The software management method includes the steps of wirelessly transmitting first software from a computer to the vehicle and determining whether activation processing of second software wirelessly transmitted to the vehicle from another computer has been completed in the electronic device. The step of wirelessly transmitting the first software includes, if the activation processing of the second software has not been completed, wirelessly transmitting the first software to the vehicle after the activation processing of the second software has been completed.

[0016] (10) A computer program according to yet another aspect of the present disclosure causes a computer to execute the above software management method. [Effects of the Invention]

[0017] According to the present disclosure, software of electronic devices installed in a vehicle can be smoothly updated. [Brief explanation of the drawings]

[0018] [Figure 1] 1 is a diagram illustrating a schematic configuration of an information processing system according to a first embodiment of the present disclosure. [Figure 2] FIG. 1 is a block diagram showing a typical configuration example of a flag distribution server. [Figure 3] FIG. 1 is a block diagram showing a typical configuration example of an OTA server. [Figure 4] FIG. 10 is a diagram for explaining an overview of a software update process. [Figure 5] 10 is a flowchart showing a processing procedure for enabling / disabling a specific function of software. [Figure 6] FIG. 10 is a sequence diagram illustrating an example of a process executed when there is no functional difference due to charges for a specific function. [Figure 7] FIG. 10 is a sequence diagram illustrating an example of a process executed when a specific function has a difference in function due to charges. [Figure 8]FIG. 10 is a sequence diagram showing an example of processing in Modification 1 of Embodiment 1. [Figure 9] FIG. 10 is a sequence diagram showing an example of processing in Modification 2 of Embodiment 1. [Figure 10] FIG. 10 is a sequence diagram showing an example of processing in the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0019] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and description thereof will not be repeated.

[0020] [Embodiment 1] <System configuration> FIG. 1 is a diagram illustrating a schematic configuration of an information processing system ("software management system" according to the present disclosure) according to a first embodiment of the present disclosure. The information processing system 100 includes a flag distribution server 1 and an OTA (Over The Air) server 2. The flag distribution server 1 and the OTA server 2 are connected to each other via a network NW so as to be able to communicate bidirectionally. The flag distribution server 1 and the OTA server 2 are also connected to a plurality of vehicles 8 and a plurality of user equipments (UE) 4 so as to be able to communicate via the network NW. At least a part of the network NW connecting the flag distribution server 1 or the OTA server 2 to the vehicles 8 is a wireless communication network.

[0021] The flag distribution server 1 is a server that provides flag data to each of multiple ECUs (Electronic Control Units) installed in a vehicle. The flag data is software for enabling / disabling a specific function (hereinafter referred to as a "specific function") possessed by software stored in a corresponding ECU among the multiple ECUs. The specific function is typically a vehicle control function, such as a driving assistance function (such as an autonomous driving function). However, the type of the specific function is not particularly limited, and the specific function may be a function unrelated to vehicle control, such as multimedia. The flag distribution server 1 is managed, for example, by a company that develops the specific function. The flag distribution server 1 may also be managed by a company that provides products or services related to the specific function. The configuration of the flag distribution server 1 is described with reference to FIG. 2.

[0022] The OTA server 2 is a server that provides software for updating the software of each of a plurality of ECUs (hereinafter referred to as "update software"). The OTA server 2 is managed, for example, by a vehicle manufacturer that manufactures the vehicle itself (VP: Vehicle Platform). The configuration of the OTA server 2 will be described with reference to FIG. 2.

[0023] The vehicle 8 is managed by a user. The user is typically an individual, but may also be, for example, a corporation (such as a transportation business operator) that conducts business using the vehicle 8. The vehicle 8 may also be an autonomous vehicle. In this case, the OTA server 2 may be managed by the manufacturer of the autonomous driving system (ADS) installed in the VP, instead of or in addition to the vehicle manufacturer. However, the vehicle 8 may also be a vehicle that is not capable of autonomous driving and can only be manually driven.

[0024] The user device 9 is a device operated by a user of the vehicle 8. The user device 9 may be a mobile terminal or a fixed terminal. Mobile terminals include, for example, smartphones, tablets, notebook PCs (Personal Computers), and wearable devices (such as smart watches). Fixed terminals include, for example, desktop PCs.

[0025] 1 shows only one vehicle 8 due to space limitations, but the number of vehicles 8 is arbitrary. Typically, the information processing system 100 includes a large number of vehicles 8. The same applies to the user devices 9.

[0026] <Server configuration> 2 is a block diagram showing a typical configuration example of the flag distribution server 1. The flag distribution server 1 includes a server 11, an input device 12, an output device 13, and a communication device 14. The server 11 includes a processor 111, a memory 112, a storage 113, and a network interface 114. The components of the flag distribution server 1 are connected to each other via a communication bus.

[0027] The processor 111 is, for example, a central processing unit (CPU) or a microprocessing unit (MPU). The memory 112 is a volatile memory such as a random access memory (RAM). The storage 113 is a rewritable nonvolatile memory such as a hard disk drive (HDD), a solid state drive (SSD), or a flash memory. The storage 113 stores a system program 51 including an operating system (OS), a control program 52 including computer-readable code necessary for control calculations, flag data 53, and a billing database 54 for managing billing information (described later) for the flag data 53. The processor 111 performs various processes by reading the system program 51 and the control program 52, expanding them into the memory 112, and executing them. The network interface 114 controls data communication between the server 11 and other devices (such as the vehicle 8 and the user device 9) via the communication device 14.

[0028] The input device 12 is a keyboard, a mouse, etc., and receives input from the operator of the server 11. The output device 13 is, for example, a display, and displays various information to the operator of the server 11.

[0029] 2 shows an example in which the server 11 includes one processor 111, the server 11 may include multiple processors. That is, the server 11 includes one or more processors. The same applies to the memory 112 and the storage 113. In this specification, the term "processor" is not limited to a processor in the narrow sense that executes processing using a stored program, but may also include hardwired circuits such as an ASIC (Application Specific Integrated Circuit) and an FPGA (Field-Programmable Gate Array). Therefore, the term "processor" can also be interpreted as a processing circuitry in which processing is defined in advance by computer-readable code and / or hardwired circuitry.

[0030] 3 is a block diagram showing a typical configuration example of the OTA server 2. The OTA server 2 differs from the flag distribution server 1 in that the OTA server 2 includes update software 63 for updating the software (control program) of the vehicle 8 in place of the flag data 53 and the billing database 54 in the storage 213. Other configurations of the OTA server 2 are similar to the corresponding configurations of the flag distribution server 1, and therefore detailed description thereof will not be repeated.

[0031] In the first embodiment, the flag distribution server 1 corresponds to the "server" or "computer" according to the present disclosure, and the OTA server 2 corresponds to the "external server" or "external computer" according to the present disclosure. The flag data 53 corresponds to the "first software" according to the present disclosure. The update software 63 corresponds to the "second software" according to the present disclosure. The ECU corresponds to the "electronic device" according to the present disclosure.

[0032] <Software Update> 4 is a diagram for explaining an overview of the software update process. In the following, an example will be described in which information exchange between the OTA server 2 and the user (notification from the OTA server 2, input operations by the user, etc.) is performed via the vehicle 8, but some or all of this may be performed via the user device 9. Of the multiple ECUs included in the vehicle 8, the ECU whose software is to be updated will be referred to as the "target ECU," and the ECU that manages the software update will be referred to as the "central ECU."

[0033] The process of updating software using OTA typically involves a series of sequential processes in the following order: configuration synchronization, campaign notification, software download, software installation, software activation, and software update completion notification. Each process in this sequential process will be described in more detail below.

[0034] <Configuration synchronization> A vehicle 8 with its ignition (IG) turned on repeatedly performs configuration synchronization every time a preset time has elapsed. The vehicle 8 also performs configuration synchronization when it receives a configuration synchronization request from the OTA server 2. The configuration synchronization process by the vehicle 8 includes a process of transmitting vehicle configuration information to the OTA server 2. The vehicle configuration information includes, for example, hardware information (information indicating the hardware model number, ECU identifier, etc.) and software information (information indicating the software model number, etc.) for each ECU included in the vehicle 8.

[0035] <Campaign Notification> When the OTA server 2 receives vehicle configuration information from the vehicle 8, it checks for campaigns (updatable software) currently running. If a campaign applicable to the vehicle 8 exists, the OTA server 2 transmits a campaign notification to the vehicle 8. The campaign notification is a signal requesting the user of the vehicle 8 to consent to updating the target software to a new version. The campaign notification may include, for example, a list of target vehicles, a list of target ECUs, information indicating the purpose of the software update, and information indicating functions that may be affected by the update. When the vehicle 8 receives the campaign notification, it prompts the user to perform an input operation indicating whether or not to accept the application of the campaign. For example, the vehicle 8 may display a message such as "New software has been found. Do you want to update?" on an HMI (Human Machine Interface) (not shown) and request the user to perform an input operation indicating either acceptance or rejection.

[0036] <Download> When the user performs an input operation indicating consent, the central ECU executes processing related to the software download. More specifically, the central ECU requests the OTA server 2 for new software (a distribution package including the software). The central ECU then receives the software from the OTA server 2 and stores it in non-volatile memory (not shown). After the software has been stored, the central ECU verifies the authenticity of the stored software. If the verification result is "normal," the central ECU notifies the OTA server 2 that the download has been completed. This notification means that the download was successful.

[0037] <Installation> If the download is successful, the central ECU installs the software. More specifically, the central ECU requests the target ECUs to output their status and diagnostic trouble codes (DTCs). The central ECU determines whether installation can be performed for each target ECU based on the target ECU's status and trouble codes. The central ECU then transfers the new software (update data) to target ECUs that can be installed. Upon receiving the update data, the target ECUs write the update data to their non-volatile memory.

[0038] When the transfer of update data from the central ECU to the target ECU is complete, the target ECU sends a transfer completion notification to the central ECU. Upon receiving the transfer completion notification, the central ECU requests integrity verification from the target ECU. In response to the request from the central ECU, the target ECU performs verification using the integrity verification data and sends the verification result (installation completed / failed / cancelled) to the central ECU. If the verification results for all target ECUs are "normal," the central ECU notifies the OTA server 2 that the installation is complete. This notification means that the installation was successful.

[0039] ≪Activate≫ If the download and subsequent installation are successful, the central ECU enters a state of waiting for activation. After that, for example, when the power switch (not shown) of the vehicle 8 is turned off, the central ECU displays a predetermined message on the HMI and requests the user to input either consent or denial. If the user inputs consent, the central ECU activates the software.

[0040] If the central ECU fails to activate, the central ECU requests the OTA server 2 to roll back the software. When the OTA server 2 receives the rollback request from the vehicle 8, it distributes rollback software to the vehicle 8. This allows the central ECU to use the rollback software to return the software that failed to be activated to its original version. If the user performs an input operation indicating denial, the central ECU stops the process related to the software update without performing activation.

[0041] <Software update completion notification> If activation is successful, the central ECU displays the results of the software update on the HMI. The central ECU then notifies the OTA server 2 that the software update is complete. This notification means that the OTA software update is successful. After the software update completion notification is sent, the control system of the vehicle 8 is shut down and the IG is turned off. Then, when the power switch of the vehicle 8 is turned on, the control system of the vehicle 8 is started up and the IG is turned on. This starts the update software in the target ECU.

[0042] <Functional differences due to charges> In this embodiment, the software updated via OTA is configured so that a specific function can be switched between enabled and disabled. In this example, the specific function is enabled when the user pays for the specific function of the software.

[0043] 5 is a flowchart showing the processing procedure for enabling / disabling a specific software function. This flowchart is executed, for example, when a predetermined condition is met. Each step is realized by software processing by the flag distribution server 1 (server 11), but may also be realized by hardware (electrical circuitry) located within the flag distribution server 1. Hereinafter, step is abbreviated as S.

[0044] In S901, the flag distribution server 1 determines whether there is a functional difference due to a charge for a specific function of the software. Whether there is a functional difference due to a charge is registered in advance. In addition, whether the user has paid for a specific function (which function the user has paid for) is linked to the user ID and stored in the billing database 54 (see FIG. 2). If there is a functional difference due to a charge (YES in S901), the flag distribution server 1 refers to the billing database 54 and determines whether the user has paid for the specific function (S903).

[0045] If the user has paid for the specific function (YES in S903), the flag distribution server 1 generates a flag to enable the specific function (S904). On the other hand, if the user has not paid for the specific function (NO in S903), the flag distribution server 1 generates a flag to disable the specific function (S905). Note that if there is no difference in function due to the charge in S901 (NO in S901), the flag distribution server 1 ends the process without generating a flag to enable / disable the specific function.

[0046] <Processing flow> In this embodiment, the software update process is used differently depending on whether or not there is a functional difference due to charges for the specific function.

[0047] <<No difference in functionality>> 6 is a sequence diagram showing an example of processing executed when there is no functional difference due to charges for a specific function. In the figure, from left to right, processing executed by the flag distribution server 1, the OTA server 2, and the vehicle 8 (central ECU) is shown. The same applies to Figures 7 to 9 described later.

[0048] 6, the OTA server 2 transmits the update software 63 to the vehicle 8 (S101). The vehicle 8 downloads, installs, and activates the update software 63 (S102 to S104). This sequence processing has been described in detail with reference to FIG. 4, and therefore description thereof will not be repeated.

[0049] In this example, during the sequence processing (download-install-activate) for update software 63, flag distribution server 1 transmits flag data 53 to vehicle 8 (S105). Then, vehicle 8 executes the sequence processing for flag data 53. That is, vehicle 8 downloads, installs, and activates flag data 53 (S107 to S109).

[0050] When the sequence processing for the update software 63 is completed, the vehicle 8 transmits an update completion notification indicating that the software update is complete to the OTA server 2 (S106). Furthermore, when the sequence processing for the flag data is completed, the vehicle 8 transmits a switching completion notification indicating that the flag switching is complete to the OTA server 2 (S110).

[0051] 6, even if flag data is received while the vehicle 8 is executing the process of receiving the update software, the two sequence processes are completed successfully. However, for example, in an ECU in which some processes are shared between the sequence process for the update software 63 and the sequence process for the flag data 53, there is a possibility that an error may occur if the sequence process for the flag data 53 interrupts the execution of the sequence process for the update software 63. As a result, the flag distribution server 1 and / or the OTA server 2 may need to perform additional processes, such as resending the software for rollback, which may prevent the software from being updated smoothly.

[0052] <Functional differences exist> 7 is a sequence diagram showing an example of processing executed when a specific function has a functional difference due to a charge. The OTA server 2 transmits the update software 63 to the vehicle 8 (S201). The vehicle 8 downloads, installs, and activates the update software 63 (S202 to S204).

[0053] Prior to transmitting the flag data 53, the flag distribution server 1 inquires of the OTA server 2 whether or not update software has been transmitted to the vehicle 8 within the most recent predetermined period (S205). The flag distribution server 1 waits (suspends) transmission of the flag data until it receives a response from the OTA server 2 (S206).

[0054] When the sequence processing for the update software 63 is completed, the vehicle 8 transmits an update completion notification to the OTA server 2 (S207). When the OTA server 2 receives the update completion notification from the vehicle 8, it transmits the update completion notification to the flag distribution server 1 (S208). This notification corresponds to a response to the inquiry from the flag distribution server 1.

[0055] When the flag distribution server 1 receives the response from the OTA server 2, it transmits the flag data 53 to the vehicle 8 (S209). The vehicle 8 downloads, installs, and activates the flag data 53 (S210 to S212). When the sequence processing for the flag data 53 is completed, the vehicle 8 transmits a switching completion notification to the flag distribution server 1 (S213).

[0056] As described above, in the first embodiment, the flag distribution server 1 suspends transmission of the flag data 53 until it receives an update completion notification from the OTA server 2, and transmits the flag data 53 to the vehicle 8 after receiving the update completion notification. When the vehicle 8 completes the sequence processing for the update software 63, it transmits the update completion notification. This means that the vehicle 8 may be currently executing the sequence processing (download, install, or activate) for the update software 63 before receiving the update completion notification. When the update completion notification is received, it can be determined that the sequence processing (activate) for the update software 63 has been completed, and the flag distribution server 1 therefore transmits the flag data 53 to the vehicle 8. This prevents the sequence processing for two pieces of software (the update software 63 and the flag data 53) from being executed simultaneously, thereby preventing the occurrence of an error that would require additional processing. Therefore, the two pieces of software can be updated smoothly.

[0057] If an error occurs when there is a difference in functionality due to a charge for a specific function, a situation may occur in which "a necessary function was not enabled despite payment being made." Therefore, as described in Fig. 7, particularly when there is a difference in functionality due to a charge for a specific function, it is desirable to suspend transmission of flag data 53 until an update completion notification is received from OTA server 2, thereby ensuring that sequence processing for flag data 53 is executed. This makes it possible to reliably avoid the above-mentioned situation.

[0058] 6, it has been explained that if there is no functional difference in the specific function due to a charge, the flag distribution server 1 transmits the flag data 53 to the vehicle 8 without waiting until it receives the update completion notification. However, even if there is no functional difference in the specific function due to a charge, the flag distribution server 1 may suspend transmission of the flag data 53 until it receives the update completion notification. In this way, it is not essential to switch the transmission method of the flag data 53 depending on whether or not there is a charge.

[0059] In this embodiment, an example in which two pieces of software (update software 63 and flag data 53) are targeted has been described, but a person skilled in the art would easily understand that it is also possible to target three or more pieces of software.

[0060] [First Modification of First Embodiment] In the first embodiment, it has been described that whether the sequence processing (activation) for the software update 63 in the vehicle 8 has been completed is determined based on the update completion notification (S208) from the OTA server 2. However, the method for determining whether activation of the software update 63 has been completed is not limited to this. Two other methods will be described below with reference to Modifications 1 and 2. For simplicity, functional differences due to charges for specific functions will not be taken into consideration here.

[0061] 8 is a sequence diagram showing an example of processing in Modification 1 of Embodiment 1. The OTA server 2 transmits update software 63 to the vehicle 8 (S301). The vehicle 8 downloads, installs, and activates the update software 63 (S302 to S304).

[0062] In the first modification, the flag distribution server 1 inquires of the vehicle 8 whether or not it has received the update software 63 within the most recent predetermined period before transmitting the flag data 53 (S305). The flag distribution server 1 waits (suspends) the transmission of the flag data 53 until it receives a response from the vehicle 8 (S306).

[0063] When the sequence processing for the update software 63 is completed, the vehicle 8 transmits an update completion notification to the OTA server 2 (S307). In addition, the vehicle 8 also transmits an update completion notification to the flag distribution server 1 (S308). This notification corresponds to a response to an inquiry from the flag distribution server 1.

[0064] When the flag distribution server 1 receives the response from the vehicle 8, it transmits the flag data 53 to the vehicle 8 (S309). The vehicle 8 downloads, installs, and activates the flag data 53 (S310 to S312). Then, when the sequence processing for the flag data 53 is completed, the vehicle 8 transmits a switching completion notification to the flag distribution server 1 (S313).

[0065] [Modification 2 of Embodiment 1] 9 is a sequence diagram showing an example of processing in Modification 2 of Embodiment 1. The OTA server 2 transmits update software 63 to the vehicle 8 (S401). The vehicle 8 downloads, installs, and activates the update software 63 (S402 to S404).

[0066] Prior to transmitting the flag data, the flag distribution server 1 inquires of the OTA server 2 whether the update software 63 has been transmitted within the most recent predetermined period (S405). Then, the flag distribution server 1 waits (suspends) the transmission of the flag data 53 (S406).

[0067] In the second modification, when the OTA server 2 receives an inquiry from the flag distribution server 1, it transmits, for example, periodically or intermittently, to the flag distribution server 1, a notification indicating that sequence processing for the update software 63 is being executed (an in-process notification). In the example shown in FIG. 9, four in-process notifications are transmitted (S407 to S410). When the sequence processing for the update software 63 is completed, the vehicle 8 transmits an update completion notification to the OTA server 2 (S411). Then, the OTA server 2 stops transmitting the in-process notification.

[0068] If the in-process notification is not received for a certain period of time, the flag distribution server 1 determines that the sequence processing (activation) for the update software 63 is complete. This period without notification corresponds to the OTA server 2's response to an inquiry from the flag distribution server 1. When the flag distribution server 1 determines that the activation of the update software 63 is complete, it transmits the flag data 53 to the vehicle 8 (S412). The vehicle 8 downloads, installs, and activates the flag data 53 (S413 to S415). Then, when the sequence processing for the flag data 53 is complete, the vehicle 8 transmits a switching completion notification to the flag distribution server 1 (S416).

[0069] 9, it has been explained that the OTA server 2 transmits the in-process notification to the flag distribution server 1 as a response to the inquiry (S405) from the flag distribution server 1. However, the OTA server 2 may transmit the in-process notification to the flag distribution server 1 voluntarily (i.e., even if there is no inquiry from the flag distribution server 1).

[0070] Also, here, an example has been described in which the in-process notification is transmitted from the OTA server 2 to the flag distribution server 1. However, the in-process notification may be transmitted from the vehicle 8 to the flag distribution server 1.

[0071] [Embodiment 2] In the second embodiment, an example will be described in which flag data 53 is transmitted to vehicle 8 before update software 63. Note that the configuration of the information processing system according to the second embodiment is similar to the configuration described with reference to Figures 1 to 3, and therefore description thereof will not be repeated.

[0072] 10 is a sequence diagram showing an example of processing in the second embodiment. In the diagram, from left to right, processing executed by the OTA server 2, the flag distribution server 1, and the vehicle 8 (central ECU) is shown.

[0073] The flag distribution server 1 transmits the flag data 53 to the vehicle 8 (S501). The vehicle 8 downloads, installs, and activates the flag data 53 (S502 to S504).

[0074] Prior to transmitting the update software 63, the OTA server 2 inquires of the flag distribution server 1 whether or not the flag data 53 has been transmitted to the vehicle 8 within the most recent predetermined period (S505). The OTA server 2 waits (suspends) the transmission of the update software 63 until it receives a response from the flag distribution server 1 (S506).

[0075] When the sequence processing for the update software 63 is completed, the vehicle 8 transmits a switching completion notification to the flag distribution server 1 (S507). When the flag distribution server 1 receives the switching completion notification, it transmits a switching completion notification (a response to the inquiry) to the OTA server 2 (S508).

[0076] When the OTA server 2 receives the switching completion notification from the flag distribution server 1, it transmits the update software 63 to the vehicle 8 (S509). The vehicle 8 downloads, installs, and activates the update software 63 (S510 to S512). Then, when the sequence processing for the update software 63 is completed, the vehicle 8 transmits an update completion notification to the OTA server 2 (S513).

[0077] As described above, in the second embodiment, the OTA server 2 suspends transmission of the update software 63 until it receives a switching completion notification from the flag distribution server 1, and transmits the update software 63 to the vehicle 8 after receiving the switching completion notification. By imposing such a condition, it is possible to confirm that the sequence processing (flag switching) for the flag data 53 is completed at the time the update software 63 is transmitted. This prevents the sequence processing for two pieces of software from being executed simultaneously, and therefore prevents the occurrence of an error that would require additional processing. Therefore, the two pieces of software can be updated smoothly.

[0078] In the second embodiment, the OTA server 2 corresponds to the "server" or "computer" according to the present disclosure, and the flag distribution server 1 corresponds to the "external server" or "external computer" according to the present disclosure. The update software 63 corresponds to the "first software" according to the present disclosure. The flag data 53 corresponds to the "second software" according to the present disclosure.

[0079] Although not shown, in the second embodiment, similarly to the first and second modifications of the first embodiment, whether activation (switching of the flag) for the flag data 53 is complete may be determined by other methods. That is, the OTA server 2 may suspend transmission of the update software 63 until it receives a switching completion notification from the vehicle 8 (modification 1). Alternatively, the OTA server 2 may suspend transmission of the update software 63 while it periodically or intermittently receives a processing in progress notification from the flag distribution server 1 (modification 2). Those skilled in the art will easily understand that such modifications are possible.

[0080] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]

[0081] 100 Information processing system, 1 Flag distribution server, 11 Server, 111 Processor, 112 Memory, 113 Storage, 114 Network interface, 12 Input device, 13 Output device, 14 Communication device, 2 OTA server, 21 Server, 211 Processor, 212 Memory, 213 Storage, 214 Network interface, 22 Input device, 23 Output device, 24 Communication device, 51 System program, 52 Control program, 53 Flag data, 54 Billing database, 61 System program, 62 Control program, 63 Update software, 8 Vehicle, 9 User equipment, NW network.

Claims

1. A server that manages software for electronic devices installed in a vehicle, a storage device in which the first software is stored; a processor that transmits the first software to the vehicle via a wireless communication device; The processor: determining whether activation processing of second software transmitted from an external server to the vehicle has been completed in the electronic device; If the activation process of the second software has not been completed, the server transmits the first software to the vehicle after the activation process of the second software has been completed.

2. the first software is flag data for switching between enabling and disabling a specific function of the software, The server according to claim 1 , wherein the second software is update software for updating the software.

3. The server according to claim 2 , wherein the processor switches between enabling and disabling the specific function depending on a charging status by the user of the vehicle.

4. the first software is update software for updating the software, The processor: If the updated software has a function difference due to a charge, the updated software is sent after the activation process of the second software is completed, while The server according to claim 1 , wherein if the update software does not have the functional difference, the server transmits the update software without waiting for the activation process of the second software to be completed.

5. A server according to any one of claims 1 to 4, wherein the processor determines that the activation process of the second software has been completed when it receives a notification from the external server indicating that the activation process of the second software has been completed.

6. The server according to any one of claims 1 to 4, wherein the processor determines that the activation process of the second software has been completed when it receives a notification from the vehicle indicating that the activation process of the second software has been completed.

7. the external server or the vehicle sends a notification to the processor indicating that the electronic device is processing the second software; 5. The server according to claim 1, wherein the processor determines that the activation process of the second software is completed when the notification is not received.

8. A server according to claim 1; and the external server.

9. A software management method for managing software of an electronic device mounted on a vehicle, comprising: wirelessly transmitting first software from a computer to the vehicle; and determining whether activation processing of second software wirelessly transmitted from another computer to the vehicle has been completed in the electronic device; A software management method, wherein the step of wirelessly transmitting the first software includes a step of wirelessly transmitting the first software to the vehicle after the activation process of the second software has been completed if the activation process of the second software has not been completed.

10. A computer program causing a computer to execute the software management method according to claim 9.

Citation Information

Patent Citations

  • Method and system for activating at least one function of a vehicle

    EP3363706A1

  • Distribution system and distribution method

    JP2015079372A

  • Vehicle control system

    JP2017149323A

  • Server, update management method, update management program, software update device, and system comprising server and software update device

    JP2022020439A

  • Vehicle program update device, vehicle, vehicle information management server, and program update method

    JP2022153935A