Management device, management system, management method, and computer program
The management device with multiple communication units and path switching capabilities addresses communication errors in ECU updates, ensuring efficient and timely data delivery to ECUs.
Patent Information
- Application Number
- JP2025043526
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2041-11-09
AI Technical Summary
Communication errors during the update process of ECUs in vehicles lead to prolonged downtime as updates are halted until the error is resolved.
A management device with multiple communication units and a control unit that switches transmission paths to ensure uninterrupted data delivery to ECUs by switching from one communication route to another upon detecting an interruption.
Reduces the time required for ECU updates by allowing continuous data transmission even in the presence of communication abnormalities.
Smart Images

Figure 0007800749000001 
Figure 0007800749000002 
Figure 0007800749000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a management device, a management system, a management method, and a computer program. [Background technology]
[0002] Conventionally, there have been known techniques for updating programs or data in ECUs (Electronic Control Units) mounted on vehicles. For example, Patent Document 1 discloses a technique in which a gateway ECU relays an update program transmitted from an external tool to multiple ECUs.
[0003] Patent Document 2 discloses a technology for selecting a communication path depending on the software to be updated. Patent Document 3 discloses a technology for identifying a retry point for resuming program rewriting in the event that the program rewriting process in an ECU is interrupted. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-112120 [Patent Document 2] Japanese Patent Application Publication No. 2019-20866 [Patent Document 3] Japanese Patent Publication No. 2020-27635 Summary of the Invention [Problem to be solved by the invention]
[0005] If a communication error such as a communication breakdown occurs between the update data provider (e.g., an external tool) and the gateway ECU while update data is being sent from the gateway ECU to another ECU, the update in the other ECU has traditionally been put on hold until the communication error is resolved, which takes time to complete the update.
[0006] The present disclosure has been made in consideration of the above circumstances, and aims to further reduce the time required to update an ECU. [Means for solving the problem]
[0007] The management device disclosed herein is a management device mounted on a vehicle, and includes a first communication unit that communicates with a target ECU that is to be updated among one or more ECUs mounted on the vehicle; a second communication unit that communicates with an on-board extra-vehicle communication device and is capable of receiving update data for the target ECU that is transmitted from a first external device outside the vehicle to the extra-vehicle communication device via a network; a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data; and a control unit that causes the update data received by the second communication unit or the third communication unit to be transmitted from the first communication unit to the target ECU, wherein the control unit switches from a first route, which causes the first communication unit to transmit the update data received by one of the second communication unit and the third communication unit, to a second route, which causes the first communication unit to transmit the update data received by the other of the second communication unit and the third communication unit.
[0008] The management method disclosed herein is a management method in which a management device manages updates to one or more ECUs installed in a vehicle, wherein the management device includes a first communication unit that communicates with a target ECU that is to be updated among the one or more ECUs, a second communication unit that communicates with an extra-vehicle communication device installed in the vehicle and is capable of receiving update data for the target ECU that is transmitted from a first external device outside the vehicle to the extra-vehicle communication device via a network, and a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data, and the management method includes a step of switching a first route, which causes the first communication unit to transmit the update data received by one of the second communication unit and the third communication unit, to a second route, which causes the first communication unit to transmit the update data received by the other of the second communication unit and the third communication unit.
[0009] The computer program disclosed herein is a computer program for a management device to manage updates to one or more ECUs installed in a vehicle, the management device comprising: a first communication unit that communicates with a target ECU that is to be updated among the one or more ECUs; a second communication unit that communicates with an extra-vehicle communication device installed in the vehicle and is capable of receiving update data for the target ECU that is transmitted from a first external device outside the vehicle to the extra-vehicle communication device via a network; and a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data, the computer program causing a computer to execute a step of switching from a first route, which causes the first communication unit to transmit the update data received by one of the second communication unit and the third communication unit, to a second route, which causes the first communication unit to transmit the update data received by the other of the second communication unit and the third communication unit. [Effects of the Invention]
[0010] According to the present disclosure, the time required to update an ECU can be further reduced. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a schematic diagram illustrating a management system according to an embodiment. [Figure 2] FIG. 2 is a block diagram illustrating the functional configuration of the control unit according to the embodiment. [Figure 3] FIG. 3 is a flowchart illustrating a management method according to an embodiment. [Figure 4] FIG. 4 is a sequence diagram illustrating a management method according to the embodiment. [Figure 5] FIG. 5 is a table illustrating a predetermined time according to the embodiment. [Figure 6] FIG. 6 is a sequence diagram illustrating a management method according to the embodiment. [Figure 7] FIG. 7 is a table illustrating an example of priorities according to a modified example. DETAILED DESCRIPTION OF THE INVENTION
[0012] <Summary of Embodiments of the Present Disclosure> The following provides an outline of embodiments of the present disclosure.
[0013] (1) The management device of the present disclosure is a management device mounted on a vehicle, and includes a first communication unit that communicates with a target ECU that is to be updated among one or more ECUs mounted on the vehicle; a second communication unit that communicates with an on-board extra-vehicle communication device and is capable of receiving update data for the target ECU that is transmitted from a first external device outside the vehicle to the extra-vehicle communication device via a network; a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data; and a control unit that causes the update data received by the second communication unit or the third communication unit to be transmitted from the first communication unit to the target ECU, wherein the control unit switches a first route, which causes the first communication unit to transmit the update data received by one of the second communication unit and the third communication unit, to a second route, which causes the first communication unit to transmit the update data received by the other of the second communication unit and the third communication unit.
[0014] By configuring in this way, even if a communication abnormality or the like occurs, the path for transmitting update data to the target ECU can be switched, thereby reducing the time required for the update.
[0015] (2) The control unit may determine that communication has been interrupted if the divided data is not received on the first route for a predetermined time between when the first data of the multiple divided data into which the update data is divided is received on the first route and when the last data of the multiple divided data is received on the first route, and may switch the first route to the second route when communication has been interrupted.
[0016] With this configuration, when a communication interruption is determined, the path for transmitting update data to the target ECU can be switched, thereby reducing the time required for the update.
[0017] (3) The control unit may cause the plurality of divided data to be transmitted sequentially from the first communication unit at a transmission interval set according to the target ECU, and the specified time may be a time that is at least twice the transmission interval.
[0018] The control unit can more accurately determine whether communication has been interrupted by using the predetermined time set according to the target ECU.
[0019] (4) The first communication unit may communicate with a plurality of the target ECUs, and the predetermined time may be set as the same value for the plurality of target ECUs.
[0020] Since the predetermined time is the same value for a plurality of target ECUs, the control load on the control unit 21 can be reduced.
[0021] (5) When the control unit determines that communication has been interrupted, it may obtain a retry point for the update data to resume updating the target ECU from the middle of the update data, and when switching from the first path to the second path, it may cause the first communication unit to transmit the data from the retry point onwards of the divided data to the target ECU.
[0022] By configuring in this way, it is possible to shorten the time required for updating and reduce the amount of communication required for updating, compared to when updating data is sent again from the beginning.
[0023] (6) When the control unit determines that communication has been interrupted, it may determine, depending on the target ECU or the update data, whether to resume updating the target ECU from the middle of the update data or to restart updating the target ECU from the beginning of the update data.
[0024] With this configuration, it is possible to select a mode for resuming the update of the target ECU depending on the target ECU or the update data.
[0025] (7) The control unit may acquire the retry point based on information regarding the order in which the divided data was transmitted from the first communication unit via the first route before the communication disruption was determined.
[0026] (8) The control unit may cause the second communication unit or the third communication unit to transmit a signal requesting data from the divided data after the retry point to the first external device or the second external device, which is the communication destination of the second path.
[0027] (9) The second external device may be a diagnostic device capable of receiving the update data from the first external device via a network.
[0028] (10) The first route may be a route for transmitting the update data received by the second communication unit from the first communication unit, and the second route may be a route for transmitting the update data received by the third communication unit from the first communication unit, and when switching from the first route to the second route, the control unit may request the diagnostic device to obtain update data from the first external device having the same version information as the update data transmitted through the first route.
[0029] With this configuration, the update data of the diagnostic device and the update data of the first external device can be synchronized.
[0030] (11) The device may further include at least one of a fourth communication unit that communicates with the second external device via a communication line that conforms to a communication protocol different from that of the third communication unit, and a fifth communication unit that communicates with an information acquisition device that acquires the update data from the first external device or from a recording medium via a network, and the control unit may switch the first route to the second route, a third route that causes the update data received by the fourth communication unit to be transmitted from the first communication unit, or a fourth route that causes the update data received by the fifth communication unit to be transmitted from the first communication unit.
[0031] By configuring in this way, it is possible to switch from three or more update data paths to multiple paths.
[0032] (12) The first communication unit may communicate with a plurality of the target ECUs, and the control unit may determine a route to switch to depending on the priority of the routes set for each of the plurality of target ECUs.
[0033] By configuring in this way, it is possible to switch to a more suitable path for each of a plurality of target ECUs.
[0034] (13) The management system of the present disclosure is an in-vehicle management system that includes any one of the management devices (1) to (12), the target ECU connected to the first communication unit, and the off-vehicle communication device connected to the second communication unit.
[0035] (14) A management method disclosed herein is a management method in which a management device manages updates to one or more ECUs mounted on a vehicle, the management device comprising: a first communication unit that communicates with a target ECU that is to be updated among the one or more ECUs; a second communication unit that communicates with an on-vehicle extra-vehicle communication device and is capable of receiving update data for the target ECU that is transmitted from a first external device outside the vehicle to the extra-vehicle communication device via a network; and a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data, the management method comprising a step of switching a first route, which causes the first communication unit to transmit the update data received by one of the second communication unit and the third communication unit, to a second route, which causes the first communication unit to transmit the update data received by the other of the second communication unit and the third communication unit.
[0036] By configuring in this way, even if a communication abnormality or the like occurs, the path for transmitting update data to the target ECU can be switched, thereby reducing the time required for the update.
[0037] (15) A computer program disclosed herein is a computer program for a management device to manage updates to one or more ECUs installed in a vehicle, the management device including: a first communication unit that communicates with a target ECU that is to be updated among the one or more ECUs; a second communication unit that communicates with an on-board extra-vehicle communication device and is capable of receiving update data for the target ECU that is transmitted from a first external device outside the vehicle to the extra-vehicle communication device via a network; and a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data, the computer program causing a computer to execute a step of switching from a first route, which causes the first communication unit to transmit the update data received by one of the second communication unit and the third communication unit, to a second route, which causes the first communication unit to transmit the update data received by the other of the second communication unit and the third communication unit.
[0038] By configuring in this way, even if a communication abnormality or the like occurs, the path for transmitting update data to the target ECU can be switched, thereby reducing the time required for the update.
[0039] <Details of the embodiment of the present disclosure> Hereinafter, the details of the embodiments of the present invention will be described with reference to the drawings.
[0040] [1. Management System] FIG. 1 is a schematic diagram illustrating a management system 1 according to the present embodiment.
[0041] The management system 1 is a system mounted on a vehicle V1. The vehicle V1 is, for example, an automobile, but the type of the vehicle V1 is not particularly limited. The management system 1 includes a management device 10, one or more ECUs 30, an external vehicle communication device 41, and an information acquisition device 42.
[0042] The management device 10 is a device that updates (reprograms) the ECU 30 based on update data provided from an external device 61 and an external device such as a diagnostic device 51 (described later). The management device 10 is a device that relays update data input from an external communication device 41, an information acquisition device 42, or the diagnostic device 51 (described later) to the ECU 30, and is, for example, an ECU that functions as a central gateway (CGW). The management device 10 is also called a "repromaster" because it comprehensively manages updates to the ECU 30.
[0043] The network N1 is a network outside the vehicle V1, such as the Internet, etc. The network N1 may be a relatively local network such as a wide area network (WAN) or a local area network (LAN).
[0044] The external device 61 is an example of a "first external device" in the present disclosure. The external device 61 is, for example, a server, and includes a control unit (not shown), a storage unit (not shown), and a communication unit (not shown). The communication unit of the external device 61 communicates with the exterior communication device 41, the information acquisition device 42, and the diagnostic device 51 via the network N1. The storage unit of the external device 61 stores, for example, a program or data for controlling the ECU 30. For example, a manufacturer of the ECU 30 modifies the program or data as needed, and the modified program or data is stored in the storage unit of the external device 61 as needed. The control unit of the external device 61 distributes the modified program or data to the management system 1 as update data, as described below. For this reason, the external device 61 is also referred to as an OTA (Over The Air) server.
[0045] The update data may be a program (application program) for updating the software of the ECU 30, or may be a program (firmware program) for updating the firmware of the ECU 30. The update data may also be data for updating parameter information stored in the ECU 30. The parameter information is data used for software implemented in the ECU 30, and specifically includes map information, control parameters, etc.
[0046] The ECU 30 is, for example, a device (operation system ECU) that controls each part of the vehicle V1 (for example, a braking system, doors, a battery, an air conditioner, etc.). The function of the ECU 30 is not particularly limited, and the ECU 30 may be a device (cognition system ECU) that connects to existing sensors (not shown) and monitors the state of each part of the vehicle V1. The ECU 30 is a collective term for a first ECU 31, a second ECU 32, and a third ECU 33, which will be described later.
[0047] The first ECU 31 is an ECU connected to the management device 10 via a communication line 34. In the following description, the first ECU 31 will also be simply referred to as "ECU 31." Although two first ECUs 31a and 31b are illustrated in FIG. 1, the number of first ECUs 31 is not particularly limited and may be one or more. The communication line 34 is an in-vehicle network that complies with a first communication standard, for example, a network that complies with the CAN communication standard.
[0048] The second ECU 32 is an ECU connected to the management device 10 via a communication line 35. In the following description, the second ECU 32 will also be simply referred to as "ECU 32." While two second ECUs 32a and 32b are illustrated in FIG. 1, the number of second ECUs 32 is not particularly limited and may be one or more. The communication line 35 is an in-vehicle network that complies with a second communication standard different from the first communication standard, such as a network that complies with Ethernet (registered trademark).
[0049] The third ECU 33 is an ECU that is connected to the management device 10 via a communication line 34 and is also connected to the management device 10 via a communication line 35. In the following description, the third ECU 33 will also be simply referred to as "ECU 33." Although one third ECU 33 is illustrated in FIG. 1, the number of third ECUs 33 is not particularly limited, and may be one or more.
[0050] The exterior-vehicle communication device 41 is, for example, a TCU (Telematics Communication Unit) and is also referred to as "TCU 41." The exterior-vehicle communication device 41 is an ECU and may be included in the ECU 30 to be updated. The exterior-vehicle communication device 41 performs wireless communication with the external device 61 via the network N1 in accordance with a communication standard such as 3G (third-generation mobile communication system), 4G / LTE (fourth-generation mobile communication system / Long Term Evolution, LTE is a registered trademark), or 5G (fifth-generation mobile communication system).
[0051] The information acquisition device 42 is a device that can acquire update data from at least one of the recording medium 72, the terminal 73, and the external device 61. The information acquisition device 42 is an ECU, and may be included in the ECU 30 that is to be updated. More specifically, the information acquisition device 42 functions as a navigation device, and guides the driver of the vehicle V1 along a route searched for based on map information, etc.
[0052] The recording medium 72 is, for example, a memory card or a flash memory such as a USB memory. The recording medium 72 is connected to a terminal provided on the information acquisition device 42. The terminal 73 is, for example, a mobile terminal such as a smartphone, a tablet terminal, or a laptop computer. The terminal 73 is connected to the information acquisition device 42 via a communication line 74. The communication line 74 may be, for example, a wired communication line such as a USB cable, or a wireless communication line such as Bluetooth (registered trademark). The information acquisition device 42 has a wireless communication interface 75 connectable to the network N1, and acquires update data from the external device 61 via the network N1 in accordance with a wireless communication standard such as Wi-Fi (registered trademark).
[0053] The diagnostic device 51 is an example of a "second external device" of the present disclosure. The diagnostic device 51 (also referred to as a "diagnostic tool") is a device used by a vehicle maintenance company (e.g., a dealer) that maintains the vehicle V1. The diagnostic device 51 is, for example, a general-purpose information terminal such as a personal computer, tablet terminal, or smartphone on which an application that diagnoses the status of each part (e.g., ECU 30) of the management system 1 is installed. The diagnostic device 51 may also be a dedicated terminal on which the application is installed.
[0054] The diagnostic device 51 has a control unit (not shown), a storage unit (not shown), and a communication unit (not shown). When performing maintenance work on the management system 1 using the diagnostic device 51, the communication unit of the diagnostic device 51 is connected to the management device 10 via communication lines 52 and 53. The communication line 52 is a network that complies with the same first communication standard (e.g., CAN) as the communication line 34. The communication line 53 is a network that complies with the same second communication standard (e.g., Ethernet) as the communication line 35. The communication unit of the diagnostic device 51 communicates with the external device 61 via the network N1 in accordance with a wireless communication standard such as Wi-Fi.
[0055] [2. Management device 10] The management device 10 includes first communication units 11a and 11b, a second communication unit 12, a third communication unit 13, a fourth communication unit 14, a fifth communication unit 15, a control unit 21, a storage unit 22, and a reading unit 23. The units included in the management device 10 are electrically connected to each other via, for example, a bus B1.
[0056] The first communication unit 11a communicates with the ECUs 31 and 33 via a communication line 34. The first communication unit 11b communicates with the ECUs 32 and 33 via a communication line 35. When the first communication units 11a and 11b are not particularly distinguished from each other, they are simply referred to as the "first communication unit 11." The second communication unit 12 communicates with the TCU 41. The communication standard between the second communication unit 12 and the TCU 41 is not particularly limited, but communication is performed according to, for example, CAN or Ethernet.
[0057] The third communication unit 13 communicates with the diagnostic device 51 via a communication line 52. The fourth communication unit 14 communicates with the diagnostic device 51 via a communication line 53. The fifth communication unit 15 communicates with the information acquisition device 42. The communication standard between the fifth communication unit 15 and the information acquisition device 42 is not particularly limited, but communication is performed according to, for example, CAN or Ethernet.
[0058] The control unit 21 is a CPU (Central Processing Unit). The control unit 21 may be an integrated circuit such as an FPGA (Field-Programmable Gate Array). The control unit 21 executes various calculations and processes based on a computer program P1 (described later) stored in the storage unit 22, thereby realizing various functions (described later).
[0059] The storage unit 22 has a volatile memory and a nonvolatile memory, and stores various data. The volatile memory is, for example, a random access memory (RAM). The nonvolatile memory includes, for example, a flash memory, a hard disk drive (HDD), a solid state drive (SSD), or a read only memory (ROM).
[0060] The reading unit 23 reads information from a computer-readable recording medium 71. The recording medium 71 is, for example, an optical disc such as a CD or a DVD, or a USB flash memory. The reading unit 23 is, for example, an optical drive or a USB terminal. A computer program P1 is recorded on the recording medium 71, and by having the reading unit 23 read the recording medium 71, the computer program P1 is stored in the non-volatile memory of the storage unit 22.
[0061] 2 is a block diagram illustrating an example of the functional configuration of the control unit 21. The control unit 21 includes a management unit 24, a communication determination unit 25, a path selection unit 26, a switching unit 27, and an output unit 28. The management unit 24 manages the output status of update data. For example, the management unit 24 stores the numbers of the divided data (described below) distributed from the management device 10 to the ECU 30 in the memory unit 22. The communication determination unit 25 determines whether communication has been interrupted in the second communication unit 12, the third communication unit 13, the fourth communication unit 14, and the fifth communication unit 15.
[0062] When communication is determined to be interrupted in at least one of the second communication unit 12, the third communication unit 13, the fourth communication unit 14, and the fifth communication unit 15, the path selection unit 26 selects a communication path via another communication unit, for example, according to a preset priority. The switching unit 27 switches the communication path by outputting various requests to the connection destination of the communication path selected by the path selection unit 26. The output unit 28 outputs update data to the ECU 30 to be updated, based on the management contents of the management unit 24.
[0063] [3. About the update data path] The management device 10 has multiple routes for transmitting and receiving update data. The route through which update data received by one of the second communication unit 12 and the third communication unit 13 is transmitted from the first communication unit 11 is referred to as the "first route R1." Furthermore, the route through which update data received by the other of the second communication unit 12 and the third communication unit 13 is transmitted from the first communication unit 11 is referred to as the "second route R2." If the first route R1 is the route through which update data received by the second communication unit 12 is transmitted from the first communication unit 11, the second route R2 is the route through which update data received by the third communication unit 13 is transmitted from the first communication unit 11.
[0064] Furthermore, the route through which update data received by the fourth communication unit 14 is transmitted from the first communication unit 11 is referred to as the "third route R3," and the route through which update data received by the fifth communication unit 15 is transmitted from the first communication unit 11 is referred to as the "fourth route R4." The management device 10 shown in FIG. 1 has four routes, from the first route R1 to the fourth route R4, but the number of routes is not particularly limited as long as it is two or more. For example, the management device 10 may have only the first route R1 and the second route R2, or may have routes other than these four routes R1 to R4.
[0065] [4. Management method] Fig. 3 is a flowchart illustrating a management method according to an embodiment. The flowchart in Fig. 3 shows the operation procedure of the control unit 21. The operation procedure is realized by the control unit 21 reading the computer program P1 from the storage unit 22 and executing various calculations and processes. The order of the steps shown in Fig. 3 may be changed as appropriate.
[0066] The management method described below is a method for managing the input and output of update data for updating a target ECU (ECU 31a in the example of FIG. 4) among the ECUs 30 that is to be updated. The management method is executed, for example, for a parked vehicle V1. Note that the management method may also be executed for a running vehicle V1. The management method is executed, for example, at a manufacturing plant for the vehicle V1 before the vehicle V1 is shipped. Note that the management method may be executed at a vehicle maintenance plant for the vehicle V1 during periodic or special inspection of the vehicle V1, or may be executed daily in the parking lot of the user of the vehicle V1.
[0067] [4.1 First control example] FIG. 4 is a sequence diagram illustrating a management method according to the embodiment (first control example). 4, the management device 10 first transmits update data provided from the diagnostic device 51 to the target ECU 31a. If communication between the diagnostic device 51 and the management device 10 is interrupted while update data is being provided to the management device 10 from the diagnostic device 51, the management device 10 records a retry point for the update data. Then, the management device 10 switches the communication path to communicate with the external device 61 via the exterior communication device 41, and requests the external device 61 for update data from the retry point onwards.
[0068] As a result, even if communication is interrupted on one of the communication paths, the delivery of update data to ECU 30 can be continued by switching the communication path, thereby reducing the time required for the update compared to stopping the delivery of update data until communication is restored. Furthermore, after switching the communication path, update data from the retry point onwards is transmitted from external device 61 to management device 10, thereby reducing the time required for the update and the amount of communication required for the update compared to restarting transmission of the update data from the beginning.
[0069] Hereinafter, the management method according to the embodiment will be described in detail with reference to FIGS. 1 to 4 as appropriate. First, tool authentication for security purposes is performed between the diagnostic device 51 and the management device 10. The diagnostic device 51 transmits an authentication signal to the management device 10 (step ST201). If the authentication signal matches a signal that the management device 10 itself can authenticate, the management device 10 transmits a signal to the diagnostic device 51 indicating that security will be released, and establishes communication with the diagnostic device 51 (step ST202).
[0070] Next, the diagnostic device 51 divides the update data for updating the target ECU 31a into a plurality of divided data, and sequentially transmits the plurality of divided data to the management device 10 (steps ST203 and ST204). For example, the diagnostic device 51 transmits the first data of the plurality of divided data to the management device 10 in step ST203, and transmits the second data of the plurality of divided data to the management device 10 in step ST204. The diagnostic device 51 sequentially transmits the plurality of divided data at predetermined transmission intervals tx. In addition to the divided update data, each divided data stores version information of the update data and order information regarding the transmission order of the divided data (for example, a numerical value indicating the transmission order).
[0071] The divided data transmitted from the diagnostic device 51 is received by the third communication unit 13 and then temporarily stored in the storage unit 22. The control unit 21 extracts version information and order information from the divided data and stores them in the storage unit 22. The control unit 21 sequentially transmits the divided data received by the third communication unit 13 from the first communication unit 11a to the target ECU 31a (steps ST206 and ST207). That is, the control unit 21 transmits the update data to the target ECU 31a via the first route R1.
[0072] 3, the control unit 21 first monitors whether update data has been received (step ST101). Specifically, the control unit 21 monitors whether the first data of the plurality of divided data sets (hereinafter referred to as "first data") has been input to at least one of the second communication unit 12, the third communication unit 13, the fourth communication unit 14, and the fifth communication unit 15. In the example of FIG. 4, after the diagnostic device 51 and the management device 10 are authenticated, the first data set is received by the third communication unit 13 in step ST203, and therefore the control unit 21 determines that update data has been received in step ST203 (YES in step ST101).
[0073] Next, the control unit 21 monitors whether or not a communication interruption has occurred between the third communication unit 13, which has received the initial data, and the diagnostic device 51 (step ST102). For example, if no divided data is received by the third communication unit 13 for a predetermined time A1 from when the initial data is received by the third communication unit 13 until the last data of the multiple divided data is received by the third communication unit 13, the control unit 21 determines that a communication interruption has occurred between the third communication unit 13 and the diagnostic device 51 (YES in step ST102).
[0074] 4, after step ST204, a communication error occurs between the diagnostic device 51 and the third communication unit 13, and the third communication unit 13 does not receive the third or subsequent data among the plurality of divided data during the predetermined time A1 since step ST204 (step ST205). Therefore, the control unit 21 determines that communication in the third communication unit 13 has been interrupted (YES in step ST102 and step ST208).
[0075] FIG. 5 is a table illustrating a predetermined time A1 according to the embodiment. FIG. 5 also illustrates a predetermined time A2 as a variation of the predetermined time A1. The control unit 21 calculates the predetermined time A1 based on the transmission interval tx of the divided data. The memory unit 22 stores an individual transmission interval tx for each communication line 34, 35 (or for each ECU 30), for example, in the form of a table. For example, the memory unit 22 stores the transmission interval t1 of the ECU 31, the transmission interval t2 of the ECU 32, and the transmission interval t3 of the ECU 33. The memory unit 22 also stores a coefficient F1 for calculating the predetermined time A1. The coefficient F1 is an integer equal to or greater than 2, for example, 3.
[0076] The control unit 21 calculates the predetermined time A1 by multiplying the coefficient F1 by the transmission interval tx (A1=F1×tx). Therefore, the predetermined time A1 varies depending on the transmission interval tx of the divided data of the target ECU. In the example of FIG. 4, the target ECU is ECU 31a, so the predetermined time A1 is (F1×t1). The control unit 21 can more accurately determine a communication disruption based on the predetermined time A1.
[0077] Note that the control unit 21 may monitor whether or not a communication disruption has occurred based on a predetermined time A2, which is a fixed value, instead of the predetermined time A1. The predetermined time A2 is, for example, a timeout time (Tout), and is stored in the storage unit 22 as the same value for, for example, multiple target ECUs. The timeout time is a value that is sufficiently large with respect to the transmission interval tx, and is, for example, a value that is three or more times the longest transmission interval among the transmission intervals t1 to t3. Because the predetermined time A2 is the same value for multiple target ECUs, it is possible to reduce the capacity used by the storage unit 22 and reduce the processing load on the control unit 21 compared to when the predetermined time A1 is used.
[0078] See Fig. 3. When the control unit 21 determines that communication has been interrupted, it stores, as interruption information, in the storage unit 22 (step ST103), various pieces of information included in the divided data (the second divided data in the example of Fig. 4) received by the third communication unit 13 immediately before the communication interruption occurred. The interruption information includes, for example, version information, order information of the divided data (for example, a number indicating the transmission order of the divided data, "2" in the example of Fig. 4), the type of the target ECU 31a, and the type of update data.
[0079] The control unit 21 acquires a retry point for the update data based on the order information of the divided data. The retry point is a position for resuming reception of the update data from an intermediate point after a communication interruption occurs. In the example of FIG. 4, the third communication unit 13 has received up to the second divided data, and a communication interruption occurs before the third divided data is received. Therefore, when reception of the update data is to be resumed from an intermediate point, reception is resumed from the third divided data. For example, the control unit 21 acquires a value obtained by adding "1" to the transmission order of the divided data indicated in the order information as the retry point.
[0080] Next, the control unit 21 selects, from the plurality of routes, the second route R2, the third route R3, or the fourth route R4 that does not pass through the third communication unit 13 where the communication interruption occurred (step ST104). For example, the storage unit 22 stores a table relating to the priorities of the plurality of routes. In the table, for example, the higher the communication speed of a route, the higher the priority is set.
[0081] In the table, if the first route R1 (third communication unit 13), the second route R2 (second communication unit 12), the third route R3 (fourth communication unit 14), and the fourth route R4 (fifth communication unit 15) are set in order of priority, the control unit 21 selects the second route R2, which has the next highest priority after the first route R1, in step ST104.
[0082] Next, the control unit 21 determines whether the target ECU 31a can be updated from the middle of the update data based on the interruption information (step ST105). For example, the control unit 21 determines whether the target ECU 31a is an ECU that can be updated from the middle of the update data based on the type of the target ECU 31a included in the interruption information.
[0083] For example, if the target ECU 31a is a device related to control of the vehicle V1 (e.g., control of a braking device), the control unit 21 determines that the target ECU 31a cannot be updated from the middle of the update data (NO in step ST105) because more accurate updating is required even if it takes some time to update. On the other hand, if the target ECU 31a is a device related to control other than the vehicle V1's driving (e.g., control of an air conditioner), the control unit 21 determines that the target ECU 31a can be updated from the middle of the update data to prioritize shortening the update time (YES in step ST105).
[0084] The type of the target ECU 31a included in the interruption information may be one of four levels A, B, C, and D included in the Automotive Safety Integrity Level (ASIL) defined by the ISO 26262 standard. In this case, the control unit 21 may determine that the update is possible from the middle of the update data if the type of the target ECU 31a is equal to or lower than a predetermined level (for example, level B) (i.e., level A or B), and may determine that the update is not possible from the middle of the update data if the type of the target ECU 31a is higher than the predetermined level (i.e., level C or D).
[0085] Furthermore, based on the type of update data included in the interruption information, control unit 21 determines whether the update data is a program or data that can be updated midway. The type of update data included in the interruption information may be one of four stages A, B, C, and D included in the ASIL. In this case, control unit 21 may determine that an update can be made midway if the type of update data is equal to or lower than a predetermined stage (for example, stage B) (i.e., stage A or B), and may determine that an update cannot be made midway if the type of update data is higher than the predetermined stage (i.e., stage C or D).
[0086] When the control unit 21 determines that the target ECU 31a can be updated from the middle of the update data, it requests the communication destination of the path selected in step ST104 to transmit the update data from the retry point onwards (step ST106).
[0087] 4. Specifically, the control unit 21 transmits a request signal to the exterior-of-vehicle communication device 41, which is the communication destination of the selected second route R2 (step ST209). The exterior-of-vehicle communication device 41 transfers the request signal to the external device 61 via the network N1 (step ST210).
[0088] The request signal includes, for example, a communication disruption notification that notifies that communication has been disrupted between the diagnostic device 51 and the third communication unit 13, a switching notification that notifies that the route will be switched from the first route R1 to the second route R2, information regarding the retry point (for example, a numerical value indicating the retry point), and version information included in the interruption information.
[0089] In step ST106, the control unit 21 may transmit an interruption signal to the target ECU 31a to inform the target ECU 31a that the update will be temporarily interrupted (step ST211). Upon receiving the interruption signal, the target ECU 31a temporarily interrupts the update and waits for reception of the next divided data (step ST212).
[0090] Upon receiving the request signal, the external device 61 performs server authentication for security purposes in order to establish communication with the management device 10 via the exterior-vehicle communication device 41. The external device 61 transmits an authentication signal to the management device 10 via the exterior-vehicle communication device 41 (steps ST213 and ST214). If the authentication signal matches a signal that the management device 10 itself can authenticate, the management device 10 transmits a signal to the external device 61 via the exterior-vehicle communication device 41 indicating that security will be released, and establishes communication with the external device 61 (steps ST215 and ST216).
[0091] Next, the external device 61 prepares update data for updating the target ECU 31a. First, the external device 61 prepares update data having the same version information as the version information included in the request signal. Next, the external device 61 divides the update data into a plurality of divided data, and based on the information about the retry point included in the request signal, sequentially transmits the plurality of divided data from the retry point onwards to the exterior-vehicle communication device 41 (steps ST217, ST218, ST219). The exterior-vehicle communication device 41 sequentially transfers the plurality of divided data transmitted from the external device 61 to the management device 10 (steps ST220, ST221, ST221).
[0092] For example, the external device 61 transmits the third divided data to the management device 10 in step ST217, and transmits the fourth divided data of the update data to the management device 10 in step ST218. In this way, the external device 61 transmits the third and subsequent divided data in sequence, and transmits the last divided data to the management device 10 in step ST219.
[0093] The divided data transferred from the exterior communication device 41 is received by the second communication unit 12 and then temporarily stored in the storage unit 22. The control unit 21 extracts version information and order information from the divided data and stores them in the storage unit 22. The control unit 21 sequentially distributes the divided data received by the second communication unit 12 from the first communication unit 11a to the target ECU 31a (step ST109). That is, the control unit 21 outputs update data from the retry point onwards to the target ECU 31a via the second route R2 (steps ST223, ST224, ST225).
[0094] When the target ECU 31a receives the third and subsequent divided data from the management device 10 in steps ST223 and ST224, the target ECU 31a sequentially resumes the update. Then, the target ECU 31a completes the update based on the last divided data received in step ST225 (step ST226). When the update is completed, the target ECU 31a transmits a completion notice to the management device 10 notifying that the update has been completed (step ST227).
[0095] When the management device 10 receives the completion notification from the target ECU 31a, it transmits the completion notification to both the input destination of the first route R1 and the input destination of the second route R2 (step ST110). Specifically, the management device 10 transmits the completion notification to the exterior communication device 41, which is the input destination of the second route R2 after switching (step ST228). When the exterior communication device 41 receives the completion notification, it transfers the completion notification to the external device 61 via the network N1 (step ST229).
[0096] After receiving the completion notification from the target ECU 31a, when communication between the diagnostic device 51 and the management device 10 is restored, the management device 10 also transmits a completion notification to the diagnostic device 51, which is the input destination of the first route R1 before switching (step ST230). This allows the diagnostic device 51 to know that the target ECU 31a has completed the update, making it possible to prevent the diagnostic device 51 from transmitting update data to the management device 10 again.
[0097] 4, even if communication between the diagnostic device 51 and the management device 10 is interrupted, the management device 10 can continue to distribute the update data to the target ECU 31a by switching the communication path for the update data to a path that passes through the exterior communication device 41. This reduces the time required to update the target ECU 31a compared to when distribution of the update data is stopped until communication between the diagnostic device 51 and the management device 10 is restored.
[0098] Furthermore, after switching the communication path, the update data from the retry point onwards is transmitted from the external device 61 to the management device 10, and the management device 10 distributes the update data from the retry point onwards to the target ECU 31a. Therefore, compared to the case where the update data is transmitted again from the beginning, the time required for the update can be shortened and the amount of communication required for the update can be reduced.
[0099] [4.2 Second control example] FIG. 6 is a sequence diagram illustrating a management method according to the embodiment (second control example). 6, the management device 10 first outputs update data provided from the external device 61 via the external communication device 41 to the target ECU 31a. If communication between the external device 61 and the management device 10 is interrupted, the management device 10 switches the communication path to communicate with the diagnostic device 51 and requests the diagnostic device 51 for the update data.
[0100] As a result, even if a communication interruption occurs on one of the communication paths, the delivery of update data to ECU 30 can be continued by switching the communication path, thereby reducing the time required for the update compared to stopping the delivery of update data until communication is restored.
[0101] The second control example (FIG. 6) differs from the first control example (FIG. 4) in that the path for communication with the external device 61 via the exterior communication device 41 is switched to the path for communication with the diagnostic device 51. The second control example also differs from the first control example in that, when communication is interrupted, the update data that has been partially updated in the target ECU 31a is erased, and after switching to the path for communication with the diagnostic device 51, the update is performed from the beginning of the update data. That is, the second control example is a control example in which the route of NO is taken in step ST105 of the flowchart in FIG. 3.
[0102] A second control example of the management method according to the embodiment will be described below with appropriate reference to Figures 1 to 3 and 6. In the second control example, descriptions of matters common to the first control example will be omitted as appropriate.
[0103] First, authentication for security purposes is performed between the external device 61 and the management device 10. The external device 61 transmits an authentication signal to the management device 10 via the exterior communication device 41 (steps ST301 and ST302), and if the authentication signal matches a signal that the management device 10 itself can authenticate, the management device 10 transmits a signal to the external device 61 via the exterior communication device 41 indicating that security will be released (steps ST303 and ST304). This establishes communication between the external device 61 and the management device 10.
[0104] Next, the external device 61 divides update data for updating the target ECU 31a into multiple pieces of divided data and sequentially transmits the divided data to the exterior communication device 41 (steps ST305 and ST306). The exterior communication device 41 sequentially transfers the multiple pieces of divided data to the management device 10 (steps ST308 and ST309). The divided data is received by the exterior communication device 41 from the exterior communication device 41 and then temporarily stored in the storage unit 22. The control unit 21 extracts version information and order information from the divided data and stores them in the storage unit 22. The control unit 21 sequentially transmits the divided data received by the second communication unit 12 from the first communication unit 11a to the target ECU 31a (steps ST311 and ST312). That is, the control unit 21 transmits the update data to the target ECU 31a via the first route R1. In the second control example, the first route R1 is a route for transmitting the update data received by the second communication unit 12 from the first communication unit 11a.
[0105] 3, the control unit 21 first monitors whether or not update data has been received (step ST101). In the example of Fig. 6, after authentication between the external device 61 and the management device 10 is completed, the first data of the divided data is input to the second communication unit 12 in step ST308, and therefore the control unit 21 determines that update data has been received in step ST308 (YES in step ST101).
[0106] Next, the control unit 21 monitors whether or not a communication interruption has occurred in the second communication unit 12 that has received the leading data with the external device 61 (step ST102). For example, if no divided data is received by the second communication unit 12 for a predetermined time A1 from when the leading data is received by the second communication unit 12 until the last data of the multiple divided data is received by the second communication unit 12, the control unit 21 determines that a communication interruption has occurred between the second communication unit 12 and the external device 61 (YES in step ST102).
[0107] 6, after steps ST306 and ST309, a communication error occurs between the external device 61 and the second communication unit 12, and the second communication unit 12 does not receive the third or subsequent divided data during the predetermined time A1 since step ST309 (step ST310). Therefore, the control unit 21 determines that communication in the second communication unit 12 has been interrupted (YES in step ST102 and step ST313).
[0108] Here, communication disruption between the second communication unit 12 and the external device 61 includes a case where communication is disrupted between the external device 61 and the vehicle-exterior communication device 41 (when data cannot be transmitted in step ST307), and a case where communication is effective between the external device 61 and the vehicle-exterior communication device 41, but communication is disrupted between the vehicle-exterior communication device 41 and the second communication unit 12 (when data can be transmitted in step ST307, but cannot be transmitted in step ST310).
[0109] When the control unit 21 determines that communication has been interrupted, it stores, as interruption information, various pieces of information included in the divided data (the second divided data in the example of FIG. 6) received by the second communication unit 12 immediately before the communication interruption occurred in the storage unit 22 (step ST103). Next, the control unit 21 selects, from among the multiple routes, a route that does not pass through the second communication unit 12 where communication has been interrupted (for example, the second route R2 that passes through the third communication unit 13) (step ST104).
[0110] Next, the control unit 21 determines whether the target ECU 31a can be updated from the middle of the update data based on the interruption information (step ST105). Since the type of update data in the example of Fig. 6 is data that needs to be updated more accurately, the control unit 21 determines that the target ECU 31a cannot be updated from the middle of the update data (NO in step ST105).
[0111] In this case, the control unit 21 outputs an erase instruction to the target ECU 31a to erase the update data (the first and second divided data) that have already been transmitted (steps ST107 and ST314). Upon receiving the erase instruction, the target ECU 31a erases the divided data received in steps ST311 and ST312, and returns to the state before the update (step ST315).
[0112] If the target ECU 31a is configured to erase the received divided data if the update is not completed within the predetermined time A3, steps ST314 and ST315 may be omitted. The predetermined time A3 is a timeout period from the start of the update to the completion of the update in the target ECU 31a, and is, for example, longer than the predetermined times A1 and A2.
[0113] Next, the control unit 21 requests the communication destination of the path selected in step ST104 to transmit the divided data starting from the first data (step ST108). Specifically, the control unit 21 transmits a request signal to the diagnostic device 51, which is the input destination of the selected second path R2, requesting transmission of the divided data from the first data onwards (step ST316). The request signal includes a signal requesting synchronization of the update data of the diagnostic device 51 with the update data of the external device 61 (input destination of the first path R1). Specifically, the request signal includes a signal requesting the diagnostic device 51 to obtain, from the external device 61, update data having the same version information as the update data output from the first path R1.
[0114] Upon receiving the request signal, the diagnostic device 51 performs tool authentication for security purposes in order to establish communication with the management device 10. The diagnostic device 51 transmits an authentication signal to the management device 10 (step ST317). If the authentication signal matches a signal that the management device 10 itself can authenticate, the management device 10 transmits a signal to the diagnostic device 51 indicating that security will be released, and establishes communication with the diagnostic device 51 (step ST318).
[0115] Next, the diagnostic device 51 prepares update data for updating the target ECU 31a. First, the diagnostic device 51 prepares update data having the same version information as the version information included in the request signal (the version information of the update data output from the first path R1). Specifically, the diagnostic device 51 checks whether or not update data having the version information is stored in its own storage unit.
[0116] If the update data having the version information is not stored in the storage unit of the diagnostic device 51, the diagnostic device 51 transmits a signal to the external device 61 via the network N1 requesting transmission of the update data having the version information (step ST319). Upon receiving the signal, the external device 61 transmits the update data having the version information to the diagnostic device 51 (step ST320). This synchronizes the update data between the diagnostic device 51 and the external device 61.
[0117] If the update data containing the version information is stored in the storage section of the diagnostic device 51, the diagnostic device 51 and the external device 61 are synchronized, so steps ST319 and ST320 may be omitted.
[0118] Next, the diagnostic device 51 divides the update data having the version information into a plurality of divided data, and transmits the divided data to the management device 10 in order, starting from the first divided data (steps ST321, ST322, ST323). For example, the diagnostic device 51 transmits the first divided data to the management device 10 in step ST321, and transmits the second divided data to the management device 10 in step ST322. In this way, the diagnostic device 51 transmits the plurality of divided data in order, and transmits the last divided data of the plurality of divided data to the management device 10 in step ST323.
[0119] The divided data transmitted from the diagnostic device 51 is received by the third communication unit 13 and then temporarily stored in the storage unit 22. The control unit 21 extracts version information and order information from the divided data and stores them in the storage unit 22. The control unit 21 sequentially distributes the divided data received by the third communication unit 13 from the first communication unit 11a to the target ECU 31a (step ST109). That is, the control unit 21 sequentially outputs the plurality of divided data to the target ECU 31a, starting from the first data, via the second route R2 (steps ST324, ST325, ST326).
[0120] When the target ECU 31a receives the first data from the management device 10 in step ST324, it starts the update again from the beginning. Then, the target ECU 31a completes the update based on the last data received in step ST326 (step ST327). When the update is complete, the target ECU 31a transmits a completion notice to the management device 10 notifying that the update has been completed (step ST328).
[0121] When the management device 10 receives the completion notification from the target ECU 31a, the management device 10 transmits the completion notification to both the communication destination of the first route R1 and the communication destination of the second route R2 (step ST110). Specifically, the management device 10 transmits the completion notification to the diagnostic device 51, which is the communication destination of the second route R2 after the switch (step ST329).
[0122] After receiving the completion notification from the target ECU 31a, when communication between the external device 61 and the management device 10 via the extra-vehicle communication device 41 is restored, the management device 10 also transmits a completion notification to the external device 61, which is the communication destination of the first route R1 before switching (steps ST330 and ST331). This allows the external device 61 to know that the target ECU 31a has completed the update, making it possible to prevent the external device 61 from transmitting update data to the management device 10 again.
[0123] 6, even if communication between the external device 61 and the management device 10 is interrupted, the management device 10 can continue to distribute the update data to the target ECU 31a by switching the communication path for the update data to a path that passes through the diagnostic device 51. This reduces the time required to update the target ECU 31a compared to when distribution of the update data is stopped until communication between the external device 61 and the management device 10 is restored.
[0124] [5. Modifications] Modifications of the embodiment will be described below. In the modifications, the same components as those in the embodiment will be denoted by the same reference numerals and the description thereof will be omitted.
[0125] [5.1 Modifications of the target ECU] In the above description, the ECU 31a is the target ECU, but the target ECU may be any ECU among the ECUs 30. There may also be multiple target ECUs. For example, the target ECUs may include ECU 31b (hereinafter also referred to as "first target ECU 31b") and ECU 32b (hereinafter also referred to as "second target ECU 32b").
[0126] In this case, a priority of the path is set for each of the plurality of target ECUs, and the control unit 21 may determine a path to switch to when a communication interruption occurs for each of the plurality of target ECUs according to the priority.
[0127] 7 is a table illustrating priorities according to a modified example. The table is stored in the storage unit 22 and is updated, for example, when an ECU is newly registered or updated. The table lists, for example, the type of ECU, the update content, and priorities 1 to 6. Priority 1 is the highest priority route, and priority 6 is the lowest priority route.
[0128] For example, when the target ECU is the ECU 31 and the update content is an application (program update), the routes with priorities 1 to 6 are shown as follows:
[0129] Priority 1: A path (DoCAN path) through which update data is received from the diagnostic device 51 to the third communication unit 13 via the communication line 52 (DoCAN) Priority 2: A route (DoIP route) through which update data is received from the diagnostic device 51 to the fourth communication unit 14 via the communication line 53 (DoIP) Priority 3: A route in which update data is received by the second communication unit 12 via the external communication device 41 Priority 4: A route in which update data is received from the recording medium 72 to the fifth communication unit 15 via the information acquisition device 42 Priority 5: A route through which update data is received from the terminal 73 to the fifth communication unit 15 via the information acquisition device 42 Priority 6: A route through which update data is received from the external device 61 to the fifth communication unit 15 via the wireless communication interface 75 and the information acquisition device 42
[0130] In the case of ECU 31, using communication line 52, which has the same standard as communication line 34, allows for faster communication than using communication line 53, so priority 1 is given to the DoCAN route. On the other hand, in the case of ECU 32, using communication line 53, which has the same standard as communication line 35, allows for faster communication than using communication line 52, so priority 1 is given to the DoIP route and priority 2 is given to the DoCAN route.
[0131] In the case of ECU 33, since it is connected to both communication lines 34 and 35, communication can be performed faster using communication line 53, which has a faster communication speed, than using communication line 52. Therefore, in the case of ECU 33, priority 1 is the DoIP path and priority 2 is the DoCAN path. In ECUs 32 and 33, priorities 3 to 6 are the same as priorities 3 to 6 of ECU 31.
[0132] Since the information acquisition device 42 is a type of ECU, the information acquisition device 42 may also be the target ECU. When the target ECU is the information acquisition device 42 and the update content is an application (program update), the paths with priorities 1 to 6 are the same as those for the ECU 31, for example.
[0133] Furthermore, when the target ECU is the information acquisition device 42 and the update content is map information (data update), the routes with priorities 1 to 6 are shown, for example, as follows:
[0134] Priority 1: A route through which update data is received from the recording medium 72 to the fifth communication unit 15 via the information acquisition device 42 Priority 2: A route through which update data is received from the terminal 73 to the fifth communication unit 15 via the information acquisition device 42 Priority 3: A path (DoCAN path) through which update data is received from the diagnostic device 51 to the third communication unit 13 via the communication line 52 (DoCAN) Priority 4: A route (DoIP route) through which update data is received from the diagnostic device 51 to the fourth communication unit 14 via the communication line 53 (DoIP) Priority 5: A route in which update data is received by the second communication unit 12 via the external communication device 41 Priority 6: A route through which update data is received from the external device 61 to the fifth communication unit 15 via the wireless communication interface 75 and the information acquisition device 42
[0135] When updating a large amount of data such as map information, it is preferable to input the update data directly from the recording medium 72 to the information acquisition device 42 in order to prevent a strain on communication capacity.
[0136] Consider a case where a table like that shown in Figure 7 is stored in the memory unit 22, and for example, first update data for updating the first target ECU 31b and second update data for updating the second target ECU 32b are received from the external device 61 by the second communication unit 12 via the off-vehicle communication device 41, the first update data is transmitted from the first communication unit 11a to the first target ECU 31b, and the second update data is transmitted from the first communication unit 11b to the second target ECU 32b.
[0137] In this case, if communication between the external device 61 and the management device 10 is interrupted, the control unit 21 switches the route through which the first update data travels to the route with priority 1 in the ECU 31 (DoCAN route) based on the priority in the table stored in the storage unit 22. The control unit 21 also switches the route through which the second update data travels to the route with priority 1 in the ECU 32 (DoIP route).
[0138] This allows the system to switch to a more suitable route depending on the ECU when a communication interruption occurs, thereby further shortening the time required to update the ECU.
[0139] [5.2 Modifications of the control unit] In the embodiment, the control unit 21 switches the path when a communication interruption occurs. However, the control unit 21 may switch the path even when a communication interruption does not occur. For example, in the example of Fig. 4, after steps ST203 and ST204, the transmission of divided data from the diagnostic device 51 to the management device 10 continues, but if the reception speed of the divided data at the management device 10 shown in step ST205 becomes slower than a predetermined speed, the control unit 21 may determine that "a communication abnormality has occurred" and switch the path as in the example of Fig. 4.
[0140] Even in such a case, the time required to update the target ECU can be further reduced compared to when the path is not switched.
[0141] [6. Supplementary Notes] It should be noted that at least some of the above-described embodiments may be combined with each other in any desired manner. Furthermore, the embodiments disclosed herein should be considered to be illustrative and not restrictive in all respects. The scope of the present disclosure is defined by the claims, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of symbols]
[0142] 1 Management System 10 Management device 11 First Communications Department 11a 1st Communication Department 11b 1st Communication Department 12 Second Communications Department 13 Third Communications Department 14 4th Communications Department 15 5th Communications Department 21 Control section 22 Memory section 23 Reading unit 24 Management Department 25 Communication determination section 26 Route selection section 27 Switching section 28 Output section 31 1st ECU 31a First ECU (example of target ECU) 31b First ECU (an example of the first target ECU) 32 2nd ECU 32a 2nd ECU 32b Second ECU (an example of the second target ECU) 33 3rd ECU 34 Communication lines 35 Communication lines 41 External communication device 42 Information acquisition device 51 Diagnostic device (an example of a second external device) 52 Communication lines 53 Communication Line 61 External device (an example of a first external device) 71 Recording Media 72 Recording Media 73 terminals 74 Communication lines 75 Wireless communication interface V1 vehicle N1 Network B1 Bus P1 Computer Program R1 1st pathway R2 Second pathway R3 Third pathway R4 4th pathway A1 Scheduled time A2 Predetermined time A3 Predetermined time t1 transmission interval t2 Transmission interval t3 Transmission interval F1 coefficient
Claims
1. A management device mounted on a vehicle, a first communication unit that communicates with a target ECU that is to be updated among one or more ECUs mounted on the vehicle; a second communication unit that communicates with an on-board external communication device and is capable of receiving update data for the target ECU transmitted from a first external device outside the vehicle to the on-board external communication device via a network; a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data; a control unit that causes the update data received by the second communication unit or the third communication unit to be transmitted from the first communication unit to the target ECU; Equipped with the control unit switches a first path through which the update data received by one of the second communication unit and the third communication unit is transmitted from the first communication unit to a second path through which the update data received by the other of the second communication unit and the third communication unit is transmitted from the first communication unit; When it is determined that communication has been interrupted in the middle of the update data, the control unit determines, based on the type of the target ECU, whether to resume the update of the target ECU from the middle of the update data or to restart the update of the target ECU from the beginning of the update data. Management device.
2. The control unit determining that communication has been interrupted when the divided data is not received on the first path for a predetermined time period from when the first data of the plurality of divided data obtained by dividing the update data is received on the first path until when the last data of the plurality of divided data is received on the first path; When the communication disruption is determined, the first route is switched to the second route. The management device according to claim 1 .
3. the control unit sequentially transmits the plurality of divided data from the first communication unit at transmission intervals set in accordance with the target ECU; The predetermined time is at least twice the transmission interval. The management device according to claim 2 .
4. the first communication unit communicates with a plurality of the target ECUs; The predetermined time is a time set to the same value for the plurality of target ECUs. The management device according to claim 2 .
5. The control unit When it is determined that the communication has been interrupted, a retry point for the update data is acquired for resuming the update of the target ECU from a point midway through the update data; When switching from the first path to the second path, the first communication unit transmits data from the retry point onward of the divided data to the target ECU. The management device according to any one of claims 2 to 4.
6. When the communication disruption is determined, the control unit determines, in accordance with the update data, whether to resume the update of the target ECU from the middle of the update data or to restart the update of the target ECU from the beginning of the update data. The management device according to claim 5 .
7. the control unit acquires the retry point based on information regarding a transmission order of the divided data items transmitted from the first communication unit via the first route before the communication disruption is determined. The management device according to claim 5 or 6.
8. the control unit causes the second communication unit or the third communication unit to transmit a signal requesting data from the retry point onwards among the divided data to the first external device or the second external device that is a communication destination of the second path. The management device according to any one of claims 5 to 7.
9. the second external device is a diagnostic device capable of receiving the update data from the first external device via a network; The management device according to any one of claims 1 to 8.
10. the first path is a path for transmitting the update data received by the second communication unit from the first communication unit, the second path is a path for transmitting the update data received by the third communication unit from the first communication unit, When switching from the first path to the second path, the control unit requests the diagnostic device to acquire, from the first external device, update data having the same version information as the update data transmitted through the first path. The management device according to claim 9 .
11. a fourth communication unit that communicates with the second external device via a communication line that complies with a communication protocol different from that of the third communication unit; and a fifth communication unit that communicates with an information acquisition device that acquires the update data from the first external device or from a recording medium via a network; and the control unit switches the first route to the second route, a third route that causes the update data received by the fourth communication unit to be transmitted from the first communication unit, or a fourth route that causes the update data received by the fifth communication unit to be transmitted from the first communication unit. The management device according to any one of claims 1 to 10.
12. the first communication unit communicates with a plurality of the target ECUs; The control unit determines a route to be switched to in accordance with the priority of the routes set for each of the plurality of target ECUs. The management device according to claim 11.
13. An in-vehicle management system, The management device according to any one of claims 1 to 12; the target ECU connected to the first communication unit; the vehicle exterior communication device connected to the second communication unit; A management system comprising:
14. A management method in which a management device manages updates to one or more ECUs mounted on a vehicle, comprising: The management device a first communication unit that communicates with a target ECU that is an update target among the one or more ECUs; a second communication unit that communicates with an on-board external communication device and is capable of receiving update data for the target ECU transmitted from a first external device outside the vehicle to the on-board external communication device via a network; a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data; Equipped with The management method includes: switching a first path through which the update data received by one of the second communication unit and the third communication unit is transmitted from the first communication unit to a second path through which the update data received by the other of the second communication unit and the third communication unit is transmitted from the first communication unit; a step of determining, when it is determined that communication has been interrupted in the middle of the update data, whether to resume the update of the target ECU from the middle of the update data or to restart the update of the target ECU from the beginning of the update data, based on the type of the target ECU; Equipped with Management method.
15. A computer program for a management device to manage updates to one or more ECUs mounted on a vehicle, The management device a first communication unit that communicates with a target ECU that is an update target among the one or more ECUs; a second communication unit that communicates with an on-board external communication device and is capable of receiving update data for the target ECU transmitted from a first external device outside the vehicle to the on-board external communication device via a network; a third communication unit that communicates with a second external device outside the vehicle and is capable of receiving the update data; Equipped with The computer program includes: switching a first path through which the update data received by one of the second communication unit and the third communication unit is transmitted from the first communication unit to a second path through which the update data received by the other of the second communication unit and the third communication unit is transmitted from the first communication unit; a step of determining, when it is determined that communication has been interrupted in the middle of the update data, whether to resume the update of the target ECU from the middle of the update data or to restart the update of the target ECU from the beginning of the update data, based on the type of the target ECU; Execute Computer program.
Citation Information
Patent Citations
Infrared data communication device, printer, and notification method of communication failure
JP2007201828A
Electronic equipment and firmware update method
JP2012059080A
In-vehicle communication system
JP2013112120A
Information distribution system and in-vehicle device
JP2019020866A
On-vehicle update device, update processing method, and update processing program
JP2019196158A