Software update device, software update program, software update method, and software update system

The software update system addresses the issue of inconvenient updates by predicting blank periods based on user schedules, ensuring updates occur when the user is unlikely to be using the devices, thus minimizing inconvenience.

JP7819660B2Active Publication Date: 2026-02-25TOYOTA JIDOSHA KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023038709
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-03-13
Publication Date
2026-02-25
Estimated Expiration
2043-03-13

AI Technical Summary

Technical Problem

Software updates for devices in a control system often overlap with user-scheduled events, causing inconvenience as the devices become unavailable during the update process.

Method used

A software update system that predicts blank periods based on user schedule information to determine optimal update times, ensuring updates occur when the user is unlikely to have plans.

Benefits of technology

Prevents software updates from happening at inconvenient times by scheduling them during blank periods, minimizing device unavailability and user inconvenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007819660000001
    Figure 0007819660000001
  • Figure 0007819660000002
    Figure 0007819660000002
Patent Text Reader

Abstract

To suppress software updating from being performed at a time that is inconvenient for a user.SOLUTION: A software updating device executes acquiring schedule information including information regarding whether or not there is a scheduled event of a user and regarding a time slot of the scheduled event. The updating device executes predicting a blank period in the future in which the scheduled event will not occur, based on the acquired schedule information. The updating device executes determining a scheduled update date-and-time that is the date and time when an update of software for an information processing device is performed, within the blank period. The updating device executes performing the update of the software at the scheduled update date-and-time.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a software update device, a software update program, a software update method, and a software update system. [Background technology]

[0002] The control system disclosed in Patent Document 1 includes a personal terminal, multiple devices, and a control device. The control device acquires operation patterns of the devices at various times. Here, the operation pattern indicates a combination of the operation statuses of the multiple devices, such as the on / off status of a first device and the on / off status of a second device. The control device then stores the operation patterns acquired at various times. The control device also acquires schedule information of the user from the user's personal terminal. Here, the schedule information includes information on whether or not there are scheduled events for the user and the time periods of the scheduled events. For each scheduled event included in the schedule information, the control device determines an operation pattern for operating the devices during the time period of the scheduled event. The control device then determines the operation pattern for operating the devices during the time period of the scheduled event by having the user select an operation pattern from the operation patterns stored in the control device. The control device then operates the multiple devices according to the determined operation pattern during the time period of the scheduled event. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2011-158186 Summary of the Invention [Problem to be solved by the invention]

[0004] In a control system such as that described in Patent Document 1, for example, there may be cases where software for each device needs to be updated. Generally, some or all of the functions of each device are unavailable during a software update. Therefore, if software updates are performed indiscriminately, there is a risk that the software update timing will overlap with the timing when the user wants to use each device or when each device should be operating. In this case, the user will have to wait until the software update is complete before using each device, which is inconvenient. [Means for solving the problem]

[0005] A software update device for solving the above problem acquires schedule information including information regarding whether or not a user has scheduled events and the time periods of those scheduled events, predicts a blank period in the future when no scheduled events will occur based on the acquired schedule information, determines a scheduled update date and time within the blank period when software for the information processing device will be updated, and performs the software update on the scheduled update date and time.

[0006] A software update program for solving the above problem causes an update device to acquire schedule information including information regarding whether or not a user has scheduled events and the time periods of the scheduled events, predict a blank period in the future when the scheduled events will not occur based on the acquired schedule information, determine a scheduled update date and time within the blank period when the software on the information processing device will be updated, and perform the software update on the scheduled update date and time.

[0007] A software update method for solving the above problem involves an update device acquiring schedule information including information on whether or not a user has scheduled events and the time periods of the scheduled events, predicting a blank period in the future when the scheduled events will not occur based on the acquired schedule information, determining a scheduled update date and time within the blank period when software for the information processing device will be updated, and updating the software on the scheduled update date and time.

[0008] A software update system for solving the above problem comprises a schedule management device that stores schedule information including information regarding whether or not a user has scheduled events and the time periods of the scheduled events, and an update device mounted on a vehicle that can communicate with the schedule management device, wherein the update device acquires the schedule information from the schedule management device, predicts a blank period in the future when no scheduled events will occur based on the acquired schedule information, determines a scheduled update date and time within the blank period, which is a date and time when a software update will be performed for an information processing device mounted on the vehicle, and when the scheduled update date and time is determined, transmits information regarding the scheduled update date and time to the schedule management device and updates the software at the scheduled update date and time, and the schedule management device acquires information regarding the scheduled update date and time from the update device and updates the schedule information in accordance with the information regarding the scheduled update date and time. [Effects of the Invention]

[0009] According to the above configuration, the scheduled update date and time is determined within a blank period when the user is unlikely to have any plans, so that software updates can be prevented from being performed at times that are inconvenient for the user. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a schematic configuration diagram of an update system. [Figure 2]FIG. 4 is a sequence diagram showing first control, second control, and third control. DETAILED DESCRIPTION OF THE INVENTION

[0011] <Outline of update system configuration> An embodiment of the present invention will now be described with reference to Figures 1 and 2. First, the general configuration of the update system US will be described.

[0012] As shown in Fig. 1, the update system US includes a plurality of vehicles 100. The vehicles 100 are, for example, automobiles owned by users. Note that Fig. 1 illustrates only one representative vehicle 100.

[0013] The vehicle 100 includes a central ECU 10, a powertrain ECU 20, a multimedia ECU 30, an advanced driving assistance ECU 40, and a DCM 50. The vehicle 100 also includes a first external bus 61, a second external bus 62, a third external bus 63, and a fourth external bus 64. "ECU" is an abbreviation for Electronic Control Unit. "DCM" is an abbreviation for Data Communication Module.

[0014] The central ECU 10 controls the entire vehicle 100. The central ECU 10 includes a CPU 11, a ROM 12, a RAM 13, a storage 14, and an internal bus 15. The internal bus 15 connects the CPU 11, the ROM 12, the RAM 13, and the storage 14 so that they can communicate with one another. The ROM 12 stores various programs and various data in advance. The ROM 12 also stores an update program 12A, which is executed during a software update, as one of the various programs. The RAM 13 is a volatile memory. The RAM 13 temporarily stores various programs and various data. The CPU 11 uses the RAM 13 as a work area to read out the programs in the ROM 12 and executes various processes. The CPU 11 also reads out the update program 12A and executes various processes in a software update method. In this embodiment, the central ECU 10 is an example of a software update device.

[0015] The storage 14 can store various programs and various data. The storage 14 is an electrically rewritable nonvolatile memory. For example, the storage 14 is a NAND flash memory.

[0016] The DCM 50 is connected to the central ECU 10 via a first external bus 61. The DCM 50 is capable of wireless communication with devices external to the vehicle 100 via a communication network NW. Therefore, the central ECU 10 is capable of wireless communication with devices external to the vehicle 100 via the first external bus 61 and the DCM 50.

[0017] The powertrain ECU 20 can communicate with the central ECU 10 via a second external bus 62. The powertrain ECU 20 executes various processes for controlling an engine, a transmission, and the like (not shown). The powertrain ECU 20 includes a CPU 21, a ROM 22, a RAM 23, a storage 24, and an internal bus 25. The internal bus 25 connects the CPU 21, the ROM 22, the RAM 23, and the storage 24 so that they can communicate with each other. The ROM 22 stores various programs and various data in advance. The ROM 22 also stores a control program 22A as one of the various programs in advance. The ROM 22 is a so-called EPROM (Erasable Programmable Read Only Memory). That is, the control program 22A stored in the ROM 22 is updatable. The RAM 23 is a volatile memory. The RAM 23 temporarily stores various programs and various data. The CPU 21 executes various processes by reading programs from the ROM 22 using the RAM 23 as a working area. Moreover, the CPU 21 reads out the control program 22A to execute various processes for controlling the engine, transmission, etc. In this embodiment, the powertrain ECU 20 is an example of an information processing device in which software is updated.

[0018] The storage 24 can store various programs and various data. The storage 24 is an electrically rewritable nonvolatile memory. For example, the storage 24 is a NOR flash memory.

[0019] The multimedia ECU 30 can communicate with the central ECU 10 via a third external bus 63. The multimedia ECU 30 controls a navigation device, an audio device, and the like (not shown). The internal configuration of the multimedia ECU 30 is similar to that of the powertrain ECU 20. The advanced driving assistance ECU 40 can communicate with the central ECU 10 via a fourth external bus 64. The advanced driving assistance ECU 40 executes various applications to realize various driving assistance functions. The various applications include an application for following a preceding vehicle traveling ahead of the vehicle 100 while maintaining a constant distance from the preceding vehicle, and an application for automatically applying the brakes to mitigate damage to the vehicle 100 in the event of a collision. The internal configuration of the advanced driving assistance ECU 40 is similar to that of the powertrain ECU 20. The vehicle 100 includes various ECUs, such as a steering ECU, a brake ECU, and a body ECU (not shown). These various ECUs can communicate with the central ECU 10 via the buses.

[0020] As shown in Fig. 1, the vehicle 100 includes a device group made up of multiple devices. Examples of these devices are a secondary battery 71 and a display 76. The secondary battery 71 supplies power to the central ECU 10, the powertrain ECU 20, the multimedia ECU 30, the advanced driver assistance ECU 40, the DCM 50, and the like. Note that Fig. 1 representatively illustrates only the power path connecting the secondary battery 71 and the central ECU 10 and the power path connecting the secondary battery 71 and the powertrain ECU 20.

[0021] The display 76 can display various types of information. The display 76 is a so-called touch panel display. Therefore, the user of the vehicle 100 can input various types of information via the display 76. In other words, the display 76 functions as both an output device that outputs information to the user and an input device that receives information from the user.

[0022] The central ECU 10 outputs a control signal to the display 76 to display various information on the display 76. The central ECU 10 also acquires information input by the user of the vehicle 100 from the display 76.

[0023] As shown in FIG. 1, the update system US includes a data center 200. An example of the data center 200 is a so-called server. The data center 200 includes an execution unit 210, a memory unit 220, and a communication unit 230. The communication unit 230 is capable of communicating with devices external to the data center 200 via a communication network NW. The memory unit 220 includes a ROM, a RAM, and storage. The memory unit 220 stores various types of data. The memory unit 220 also stores various programs in advance. The execution unit 210 executes various processes by reading the programs from the memory unit 220. An example of the execution unit 210 is a CPU.

[0024] As shown in FIG. 1, the update system US includes multiple personal terminals 300. An example of the personal terminal 300 is a mobile terminal, a so-called smartphone, owned by the user of the vehicle 100. Note that FIG. 1 illustrates only one representative personal terminal 300. The personal terminal 300 includes an execution unit 310, a memory unit 320, and a communication unit 330. The communication unit 330 is capable of communicating with devices external to the personal terminal 300 via a communication network NW. The memory unit 320 includes a ROM, a RAM, and a storage device. The memory unit 320 stores various data. The memory unit 320 also stores schedule information IS as one of the various data. Here, the schedule information IS includes information regarding whether or not a user has a scheduled event, information regarding the time period of the scheduled event, and information regarding the location of the scheduled event. For example, a scheduled event is specified along with the name and location of the scheduled event, such as from A:00 to B:00 on X:YY date and Z:YY date. Therefore, a time period for which a scheduled event is specified as described above indicates that a scheduled event occurs during that time period. A time period in which no time period for any scheduled event is specified indicates that no scheduled event occurs in that time period. Scheduled events are input by the user through operation of the personal terminal 300 and stored in the storage unit 320 as schedule information IS. Furthermore, the storage unit 320 stores various programs in advance. The execution unit 310 executes various processes by reading the programs from the storage unit 320. An example of the execution unit 310 is a CPU. In this embodiment, the personal terminal 300 is an example of a schedule management device.

[0025] <First control> Next, referring to FIG. 2, a first control executed by the central ECU 10 of the vehicle 100 and the data center 200 will be described. This first control is control related to downloading software to be updated. The first control is executed in parallel between the central ECUs 10 of multiple vehicles 100 and one data center 200. In this embodiment, the data center 200 starts executing the first control every time a software update request occurs. Note that, below, a process for updating the control program 22A will be described as an example of software update.

[0026] 2, when the execution unit 210 of the data center 200 starts the first control, it executes the process of step S11. In step S11, the execution unit 210 of the data center 200 transmits a campaign notification NC indicating that a request for software update has occurred to the central ECU 10. Here, the campaign notification NC includes information indicating the type of software to be updated, information indicating the capacity of the software to be updated, etc. In the example described here, the information indicating the type of software to be updated is information indicating that the software to be updated is the control program 22A of the powertrain ECU 20. When the CPU 11 of the central ECU 10 receives the campaign notification NC, the CPU 11 of the central ECU 10 proceeds to the process of step S12.

[0027] In step S12, the CPU 11 of the central ECU 10 confirms with the user of the vehicle 100 whether or not the user agrees to the download of a new control program 22A to update the control program 22A. Specifically, the CPU 11 of the central ECU 10 outputs a control signal to the display 76 to display on the display 76 an option for agreeing to the download of the control program 22A. If the user of the vehicle 100 does not agree, the CPU 11 of the central ECU 10 periodically displays an option for agreeing to the download of the control program 22A. On the other hand, if the user of the vehicle 100 agrees, the CPU 11 of the central ECU 10 proceeds to step S13.

[0028] In step S13, the CPU 11 of the central ECU 10 transmits a request signal to request transmission of the new control program 22A to the data center 200. When the execution unit 210 of the data center 200 receives the request signal, the execution unit 210 of the data center 200 proceeds to step S14.

[0029] In step S14, the execution unit 210 of the data center 200 transmits the new control program 22A to the central ECU 10. In other words, the CPU 11 of the central ECU 10 downloads the new control program 22A from the data center 200. At this time, the CPU 11 of the central ECU 10 stores the new control program 22A in the storage 14 of the central ECU 10. After step S14, the CPU 11 of the central ECU 10 ends the current first control.

[0030] <Second control> Next, with reference to Fig. 2, a second control executed by the central ECU 10 of the vehicle 100 and the personal terminal 300 will be described. This second control is control related to determining a scheduled update date and time TZ for the software to be updated. The second control is executed between the central ECU 10 of the vehicle 100 and the personal terminal 300 of the user of the vehicle 100. Note that the central ECU 10 of the vehicle 100 and the personal terminal 300 of the user of the vehicle 100 are linked in advance. In this embodiment, the CPU 11 of the central ECU 10 starts executing the second control on the condition that the first control has ended.

[0031] 2, when the CPU 11 of the central ECU 10 starts the second control, it executes the process of step S31. In step S31, the CPU 11 of the central ECU 10 transmits a request signal to the personal terminal 300 to request transmission of schedule information IS. When the execution unit 310 of the personal terminal 300 receives the request signal, the execution unit 310 of the personal terminal 300 advances the process to step S32.

[0032] In step S32, the execution unit 310 of the personal terminal 300 transmits the schedule information IS to the central ECU 10. Then, when the CPU 11 of the central ECU 10 receives the schedule information IS, the CPU 11 of the central ECU 10 stores the schedule information IS in the storage 14 of the central ECU 10. Therefore, the processing of step S32 is processing to acquire the schedule information IS. After step S32, the CPU 11 of the central ECU 10 advances the processing to step S41.

[0033] In step S41, the CPU 11 of the central ECU 10 identifies an unset period TA during which no scheduled events are set, based on the schedule information IS. Specifically, the CPU 11 of the central ECU 10 identifies the unset period TA based on information regarding the time periods of scheduled events included in the schedule information IS. For example, assume that the user's scheduled events included in the schedule information IS include a first scheduled event and a second scheduled event on a certain specific day. The time period for the first scheduled event is from 6:00 to 12:00. The time period for the second scheduled event is from 18:00 to 24:00. In this case, the CPU 11 of the central ECU 10 identifies the time periods of the specific day excluding the time periods for the first scheduled event and the second scheduled event, i.e., the time periods from 12:00 to 6:00 and the time periods from 12:00 to 18:00, as the unset period TA of the specific day. The CPU 11 of the central ECU 10 identifies future time periods after the time point at which step S41 is performed as the unset period TA. In this embodiment, the CPU 11 of the central ECU 10 identifies a plurality of unset periods TA in the above manner. After step S41, the CPU 11 of the central ECU 10 advances the process to step S42.

[0034] In step S42, the CPU 11 of the central ECU 10 predicts a non-use period TB, which is a period during which the user of the vehicle 100 does not use the vehicle 100. The CPU 11 of the central ECU 10 predicts the non-use period TB, for example, as follows. First, the CPU 11 of the central ECU 10 acquires a usage history of the vehicle 100 by the user of the vehicle 100 for a period from the time of processing step S42 to a specified period before. Here, an example of the specified period is seven days. Furthermore, based on the acquired usage history of the vehicle 100, the CPU 11 of the central ECU 10 extracts time periods during which the vehicle 100 was not used on any day for a period from the time of processing step S42 to a specified period before. The CPU 11 of the central ECU 10 then predicts the extracted time periods as the non-use period TB. For example, suppose that the vehicle 100 was used from 6:00 to 12:00 on a certain first specific day. Furthermore, suppose that the vehicle 100 was used from 9:00 to 15:00 on a certain second specific day. Furthermore, suppose that the vehicle 100 is used during a time period from 12:00 to 18:00 on a certain third specific day. In this case, the CPU 11 of the central ECU 10 extracts the time period from midnight to 6:00 and the time period from 18:00 to 24:00 as time periods during which the vehicle 100 is not used on any day. Then, the CPU 11 of the central ECU 10 predicts the time period from midnight to 6:00 and the time period from 18:00 to 24:00 as non-use periods TB. After step S42, the CPU 11 of the central ECU 10 proceeds to step S43.

[0035] In step S43, the CPU 11 of the central ECU 10 predicts a blank period TC in the future where no scheduled events will be included, based on the schedule information IS. Specifically, the CPU 11 of the central ECU 10 predicts a period that is within the non-use period TB and is an unset period TA as the blank period TC. For example, the non-use period TB is assumed to be a time slot from midnight to 6:00 and a time slot from 18:00 to 24:00. The unset period TA is assumed to be a time slot from midnight to 6:00 and a time slot from 12:00 to 18:00. In this case, the blank period TC is a time slot from midnight to 6:00. The CPU 11 of the central ECU 10 predicts a future time slot after the processing time of step S43 as the blank period TC. In this embodiment, the CPU 11 of the central ECU 10 predicts multiple blank periods TC in the above manner. After step S43, the CPU 11 of the central ECU 10 proceeds to step S44.

[0036] In step S44, the CPU 11 of the central ECU 10 determines the scheduled update date and time TZ, which is the date and time when the control program 22A for the powertrain ECU 20 will be updated, within the blank period TC. The CPU 11 of the central ECU 10 determines the scheduled update date and time TZ, for example, as follows: First, the CPU 11 of the central ECU 10 estimates the length of the period required to update the control program 22A based on information indicating the capacity of the software to be updated, which is included in the campaign notification NC. The CPU 11 of the central ECU 10 then extracts, from the multiple blank periods TC, a blank period TC whose length is longer than the period required to update the control program 22A. The CPU 11 of the central ECU 10 then identifies, from the extracted multiple blank periods TC, a blank period TC that is closest to the processing time of step S44. The CPU 11 of the central ECU 10 then determines the scheduled update date and time TZ to be midway within the identified blank period TC. For example, the blank period TC is assumed to be a time period from midnight to 6:00 a.m. Also, assume that the length of the period required to update the control program 22A is two hours. In this case, the CPU 11 of the central ECU 10 sets the time period from 2:00 to 4:00 as the scheduled update date and time TZ. After step S44, the CPU 11 of the central ECU 10 proceeds to step S51. In other words, when the CPU 11 of the central ECU 10 determines the scheduled update date and time TZ, it proceeds to step S51.

[0037] In step S51, the CPU 11 of the central ECU 10 confirms with the user of the vehicle 100 whether or not the user agrees to update the control program 22A at the scheduled update date and time TZ. Specifically, the CPU 11 of the central ECU 10 outputs a control signal to the display 76, causing the display 76 to display options for whether or not the user agrees to update the control program 22A at the scheduled update date and time TZ. If the user of the vehicle 100 does not agree, the CPU 11 of the central ECU 10 periodically displays options for whether or not the user agrees to update the control program 22A at the scheduled update date and time TZ. On the other hand, if the user of the vehicle 100 agrees, the CPU 11 of the central ECU 10 proceeds to step S52. In other words, the CPU 11 of the central ECU 10 proceeds to step S52 on the condition that the user agrees to update the control program 22A at the scheduled update date and time TZ.

[0038] In step S52, the CPU 11 of the central ECU 10 transmits an addition notification NA to the personal terminal 300, requesting the addition of a scheduled event for updating the control program 22A at the scheduled update date and time TZ. The addition notification NA includes information about the scheduled update date and time TZ. The processing of step S52 is a processing in which the central ECU 10 transmits information about the scheduled update date and time TZ to the outside. The processing of step S52 is also a processing in which the personal terminal 300 acquires information about the scheduled update date and time TZ from the central ECU 10. When the execution unit 310 of the personal terminal 300 receives the addition notification NA, the execution unit 310 of the personal terminal 300 proceeds to step S53.

[0039] In step S53, the execution unit 310 of the personal terminal 300 updates the schedule information IS based on the addition notification NA. Specifically, the CPU 11 of the central ECU 10 adds a scheduled event of updating the control program 22A at the scheduled update date and time TZ to the schedule information IS based on the addition notification NA. After step S53, the execution unit 310 of the personal terminal 300 ends this second control.

[0040] <Third Control> Next, with reference to FIG. 2, a third control executed by the central ECU 10 of the vehicle 100 will be described. This third control is control related to the activation of software to be updated. In this embodiment, the CPU 11 of the central ECU 10 starts executing the third control on the condition that the second control has ended and the system of the vehicle 100 is in an off state. The system of the vehicle 100 being in an off state refers to a state in which power is not supplied to each ECU except for the central ECU 10. Therefore, the system of the vehicle 100 is in an on state when the vehicle 100 is running and in an accessory on state in which each device of the vehicle 100 can be used.

[0041] 2, when the CPU 11 of the central ECU 10 starts the third control, it executes the processing of step S71. In step S71, the CPU 11 of the central ECU 10 determines whether the time point of processing step S71 is within the scheduled update date and time TZ. If the CPU 11 of the central ECU 10 determines in step S71 that the time point of processing step S71 is not within the scheduled update date and time TZ, the CPU 11 of the central ECU 10 advances the processing to step S71 again. On the other hand, if the CPU 11 of the central ECU 10 determines in step S71 that the time point of processing step S71 is within the scheduled update date and time TZ, the CPU 11 of the central ECU 10 advances the processing to step S72.

[0042] In step S72, the CPU 11 of the central ECU 10 updates the control program 22A stored in the ROM 22 of the powertrain ECU 20. Specifically, the CPU 11 of the central ECU 10 turns the powertrain ECU 20 on. Furthermore, the CPU 11 of the central ECU 10 installs the new control program 22A stored in the storage 14 into the ROM 22 of the powertrain ECU 20. Then, the CPU 11 of the central ECU 10 activates the installed control program 22A. Thereafter, the CPU 11 of the central ECU 10 turns the powertrain ECU 20 off. After step S72, the CPU 11 of the central ECU 10 ends the current third control.

[0043] <Operation of this embodiment> For example, suppose a request to update the control program 22A stored in the powertrain ECU 20 of the vehicle 100 occurs. In this case, as shown in FIG. 2, the central ECU 10 and the data center 200 of the vehicle 100 execute a first control, i.e., the processing of steps S11 to S14. As a result, the CPU 11 of the central ECU 10 downloads a new control program 22A from the data center 200. After the first control ends, the central ECU 10 and the personal terminal 300 of the vehicle 100 execute a second control, i.e., the processing of steps S31 to S53. Then, in step S32, the CPU 11 of the central ECU 10 acquires schedule information IS from the personal terminal 300. Furthermore, in steps S41 to S43, the CPU 11 of the central ECU 10 predicts a blank period TC in the future in which no scheduled events will be inserted, based on the schedule information IS. Furthermore, in step S44, the CPU 11 of the central ECU 10 determines, within the blank period TC, a scheduled update date and time TZ, which is the date and time when the control program 22A for the powertrain ECU 20 will be updated. After the second control ends, the central ECU 10 of the vehicle 100 executes the third control, i.e., the processing of steps S71 and S72. As a result, when the scheduled update date and time TZ arrives, the CPU 11 of the central ECU 10 updates the control program 22A stored in the ROM 22 of the powertrain ECU 20. Specifically, the CPU 11 of the central ECU 10 installs and activates the new control program 22A at the scheduled update date and time TZ.

[0044] <Effects of this embodiment> (1) According to this embodiment, the scheduled update date and time TZ is determined within a blank period TC during which the user of the vehicle 100 is unlikely to have any plans. This prevents the control program 22A from being updated at a time inconvenient for the user of the vehicle 100.

[0045] (2) In step S52 of the second control, the CPU 11 of the central ECU 10 transmits an additional notification NA including information about the scheduled update date and time TZ to the personal terminal 300. This allows the user of the vehicle 100 to know the scheduled update date and time TZ when the update of the control program 22A will be performed, for example, by checking the information about the scheduled update date and time TZ transmitted to the personal terminal 300.

[0046] (3) In step S52 of the second control, the personal terminal 300 acquires an addition notification NA from the central ECU 10 of the vehicle 100, requesting the addition of a scheduled event for updating the control program 22A at the scheduled update date and time TZ. Then, in step S53, the execution unit 310 of the personal terminal 300 updates the schedule information IS based on the addition notification NA. Specifically, the CPU 11 of the central ECU 10 adds the scheduled event for updating the control program 22A at the scheduled update date and time TZ to the schedule information IS based on the addition notification NA. This allows the user of the vehicle 100 to collectively manage the scheduled event for updating the control program 22A at the scheduled update date and time TZ together with other scheduled events.

[0047] (4) In step S41 of the second control, the CPU 11 of the central ECU 10 identifies an unset period TA during which no scheduled events are set, based on the schedule information IS. In step S42, the CPU 11 of the central ECU 10 predicts a non-use period TB, which is a period during which the user of the vehicle 100 does not use the vehicle 100. In step S43, the CPU 11 of the central ECU 10 predicts the unset period TA within the non-use period TB as a blank period TC during which no scheduled events will be scheduled in the future. In other words, the CPU 11 of the central ECU 10 predicts the blank period TC by taking into account not only the unset period TA during which no scheduled events are set in the schedule information IS, but also the non-use period TB, which is a period during which the user of the vehicle 100 does not use the vehicle 100. By taking the non-use period TB into account in this way, it is possible to prevent the blank period TC from overlapping with a period during which the user of the vehicle 100 intends to use the vehicle 100. As a result, it is possible to prevent the vehicle 100 from becoming unavailable due to an update of the control program 22A.

[0048] (5) In step S51 of the second control, the CPU 11 of the central ECU 10 confirms with the user of the vehicle 100 whether or not the user agrees to update the control program 22A at the scheduled update date and time TZ. Then, on the condition that consent to update the control program 22A at the scheduled update date and time TZ has been obtained, the CPU 11 of the central ECU 10 proceeds with the processing from step S52 onwards. In other words, on the condition that consent to update the control program 22A at the scheduled update date and time TZ has been obtained, the CPU 11 of the central ECU 10 executes the update of the control program 22A at the scheduled update date and time TZ in the third control. This more reliably prevents the update of the control program 22A from being performed at a time inconvenient for the user of the vehicle 100.

[0049] (6) Generally, ROMs can be broadly divided into single-sided ROMs, which have one data storage area, and dual-sided ROMs, which have two data storage areas. When updating software, with a single-sided ROM, the single-sided ROM must be turned off before installing and activating the software. On the other hand, with a dual-sided ROM, even if the dual-sided ROM is on, software can be installed in a storage area separate from the data storage area used when the dual-sided ROM is on. However, even with a dual-sided ROM, the dual-sided ROM must be turned off before software activation can be performed.

[0050] In this regard, in step S72 of the third control, the CPU 11 of the central ECU 10 installs and activates a new control program 22A at the scheduled update date and time TZ. That is, the update of the control program 22A in step S72 includes activation. Therefore, even if the ROM 22 in which the control program 22A is updated is a dual-sided ROM, the ROM 22 becomes unavailable during the period in which the update of the control program 22A is performed in step S72. Therefore, it is particularly effective to perform the update of the control program 22A in step S72 at the scheduled update date and time TZ determined within the blank period TC.

[0051] <Example of change> This embodiment can be modified as follows: This embodiment and the following modifications can be combined and implemented within the scope of technical compatibility.

[0052] In the above embodiment, the first control may be changed. For example, the processing of step S12 may be omitted. As a specific example, when the CPU 11 of the central ECU 10 receives the campaign notification NC in step S11, the CPU 11 of the central ECU 10 may proceed to the processing of step S13. Note that even if the processing of step S12 is omitted, the impact is small as long as the CPU 11 of the central ECU 10 confirms in step S51 whether or not to approve the update of the control program 22A at the scheduled update date and time TZ.

[0053] In the above embodiment, the second control may be changed. For example, the method for predicting the non-use period TB in step S42 may be changed. As a specific example, the CPU 11 of the central ECU 10 may predict, as the non-use period TB, a time period in which the vehicle 100 is not used on any day, with a margin added to the time period in which the vehicle 100 is not used. As an example, for the period from the time of processing step S42 until the specified period before, the time period in which the vehicle 100 is not used on any day is the time period from midnight to 6:00. In this case, the CPU 11 of the central ECU 10 may predict, as the non-use period TB, a time period in which the vehicle 100 is not used on any day, with a margin added to the time period in which the vehicle 100 is not used, for example, the time period from 1:00 to 5:00.

[0054] As a specific example, the CPU 11 of the central ECU 10 may predict the non-use period TB based on information about the time periods of the scheduled events and information about the locations of the scheduled events, which are included in the schedule information IS. For example, assume that the user's scheduled events included in the schedule information IS include a first scheduled event and a second scheduled event on a certain day. The time period for the first scheduled event is from 6:00 to 12:00. The time period for the second scheduled event is from 6:00 to 24:00. The CPU 11 of the central ECU 10 then determines whether the user is likely to use the vehicle 100 during that time period based on the distance from the location of the first scheduled event to the location of the second event and the length of the time period between the first scheduled event and the second event. For example, if the value obtained by dividing the distance from the location of the first scheduled event to the location of the second event by the length of the time period between the first scheduled event and the second event is equal to or less than a predetermined value, the CPU 11 estimates that the user is likely to use the vehicle 100. In other words, when the distance from the location of the first scheduled event to the location of the second event is relatively short compared to the length of the time period between the first scheduled event and the second event, the CPU 11 estimates that there is a high possibility that the user will use the vehicle 100. Then, when the CPU 11 estimates that there is a high possibility that the user will use the vehicle 100 during the time period between the first scheduled event and the second event, it predicts the time period excluding that time period as the non-use period TB. In the above case, the non-use period TB is the time period from midnight to 12:00 and the time period from 18:00 to 24:00.

[0055] For example, the method for predicting the blank period TC in step S43 may be changed. As a specific example, the CPU 11 of the central ECU 10 may predict the unset period TA as the blank period TC. In this case, the processing of step S42 can be omitted. Also, as a specific example, the CPU 11 of the central ECU 10 may predict a time period that takes into account a margin for the unset period TA as the blank period TC. As an example, assume that the unset period TA is a time period from midnight to 6:00. In this case, the CPU 11 of the central ECU 10 may predict a time period that takes into account a margin for the unset period TA, for example, a time period from 1:00 to 5:00, as the blank period TC.

[0056] For example, the method for determining the scheduled update date and time TZ in step S44 may be changed. As a specific example, the CPU 11 of the central ECU 10 may determine the scheduled update date and time TZ to be in the first half of the blank period TC if the scheduled update date and time TZ is within the blank period TC, or may determine the scheduled update date and time TZ to be in the second half of the blank period TC.

[0057] For example, the way of confirming consent in step S51 may be changed. As a specific example, the CPU 11 of the central ECU 10 may output a control signal to the personal terminal 300 to cause the personal terminal 300 to display a choice of whether or not to consent to updating the control program 22A at the scheduled update date and time TZ.

[0058] For example, the process of step S51 may be omitted. Note that even if the process of step S51 is omitted, the CPU 11 of the central ECU 10 determines the scheduled update date and time TZ within the blank period TC, so the effect is small.

[0059] For example, the processing contents of steps S52 and S53 may be changed. As a specific example, in step S52, the CPU 11 of the central ECU 10 may transmit only information related to the scheduled update date and time TZ to the personal terminal 300, instead of the additional notification NA. In this case, in step S53, the execution unit 310 of the personal terminal 300 does not need to update the schedule information IS. Note that it is preferable that the execution unit 310 of the personal terminal 300 notifies the user of the personal terminal 300, on a display or the like of the personal terminal 300, based on the information related to the scheduled update date and time TZ, that the control program 22A will be updated at the scheduled update date and time TZ.

[0060] For example, the processes of steps S52 and S53 may be omitted. Note that even if the processes of steps S52 and S53 are omitted, the CPU 11 of the central ECU 10 determines the scheduled update date and time TZ within the blank period TC, so the effect is small.

[0061] In the above embodiment, the third control may be changed. For example, the processing content of step S72 may be changed. As a specific example, in step S72, the CPU 11 of the central ECU 10 may download, install, and activate the new control program 22A at the scheduled update date and time TZ. In this case, the processing of steps S13 and S14 can be omitted in the first control.

[0062] As a specific example, in step S72, the CPU 11 of the central ECU 10 may execute only the activation of the new control program 22A among the download, installation, and activation of the new control program 22A at the scheduled update date and time TZ. In this case, in step S14, the CPU 11 of the central ECU 10 may execute the download and installation of the new control program 22A.

[0063] In the above embodiment, the configuration of the update system US may be changed. For example, the software update device is not limited to the central ECU 10. As a specific example, instead of the central ECU 10, the CPU of the multimedia ECU 30 may execute the first control, the second control, and the third control by reading out the update program 12A stored in the ROM of the multimedia ECU 30. In other words, the software update device is not limited to the central ECU 10, and other ECUs mounted on the vehicle 100 may be used.

[0064] As a specific example, instead of the central ECU 10, a personal terminal of the user of the vehicle 100, a server external to the vehicle 100, or the like may be employed. In other words, the software update device is not limited to the central ECU 10, and other devices not installed in the vehicle 100 may be employed.

[0065] For example, the schedule management device is not limited to the personal terminal 300. As a specific example, the schedule information IS may be stored in a so-called server or the like instead of the personal terminal 300. In this case, the CPU 11 of the central ECU 10 may acquire the schedule information IS stored in the server or the like.

[0066] <Other technical ideas> The technical ideas that can be understood from the above-described embodiment and modified examples will be described. (Appendix 1) Obtaining schedule information including information regarding whether or not a user has a scheduled event and the time period of the scheduled event; predicting a blank period in the future in which the scheduled event will not occur based on the acquired schedule information; determining a scheduled update date and time, which is a date and time for updating software for the information processing device, within the blank period; updating the software on the scheduled update date and time; Run Software update device.

[0067] (Appendix 2) When the scheduled update date and time is determined, transmitting information regarding the scheduled update date and time to an external party; Run 10. The software update device of claim 1.

[0068] (Appendix 3) When the scheduled update date and time is determined, confirming whether or not to accept updating the software on the scheduled update date and time; updating the software on the scheduled update date and time, on the condition that consent to updating the software on the scheduled update date and time has been obtained; Run 10. The software update device according to claim 1 or 2.

[0069] (Appendix 4) The update includes activating the software. 4. The software update device according to claim 1.

[0070] (Appendix 5) The information processing device is mounted on a vehicle, predicting a non-use period during which the user will not use the vehicle; predicting a period within the non-use period in which the user has no plans as the blank period; Run 5. The software update device according to any one of Supplementary Note 1 to Supplementary Note 4. [Explanation of symbols]

[0071] NW: communication network US…Update System 10...Central ECU 11...CPU 12...ROM 12A…Update Program 13...RAM 14…Storage 20...Powertrain ECU 21...CPU 22...ROM 22A...Control program 23...RAM 24…Storage 30...Multimedia ECU 40...Advanced driver assistance ECU 50…DCM 71…Secondary battery 76...Display 100...Vehicle 200...Data center 300...Personal devices

Claims

1. Obtaining schedule information including information regarding whether or not a user has a scheduled event and the time period of the scheduled event; predicting a blank period in the future in which the scheduled event will not occur based on the acquired schedule information; determining a scheduled update date and time, which is a date and time for updating software for the information processing device, within the blank period; updating the software on the scheduled update date and time; Run Software update device.

2. When the scheduled update date and time is determined, transmitting information regarding the scheduled update date and time to an external party; Run 2. The software update device according to claim 1.

3. When the scheduled update date and time is determined, confirming whether or not to accept updating the software on the scheduled update date and time; updating the software on the scheduled update date and time, on the condition that consent to updating the software on the scheduled update date and time has been obtained; Run 3. The software update device according to claim 1.

4. The update includes activating the software.

3. The software update device according to claim 1.

5. The information processing device is mounted on a vehicle, predicting a non-use period during which the user will not use the vehicle; predicting a period within the non-use period in which the user has no plans as the blank period; Run 3. The software update device according to claim 1.

6. To the update device, Obtaining schedule information including information regarding whether or not a user has a scheduled event and the time period of the scheduled event; predicting a blank period in the future in which the scheduled event will not occur based on the acquired schedule information; determining a scheduled update date and time, which is a date and time for updating software for the information processing device, within the blank period; updating the software on the scheduled update date and time; Run Software updates.

7. The update device is Obtaining schedule information including information regarding whether or not a user has a scheduled event and the time period of the scheduled event; predicting a blank period in the future in which the scheduled event will not occur based on the acquired schedule information; determining a scheduled update date and time, which is a date and time for updating software for the information processing device, within the blank period; updating the software on the scheduled update date and time; Run How to update your software.

8. a schedule management device that stores schedule information including information regarding whether or not a user has a scheduled event and the time period of the scheduled event; an update device mounted on a vehicle capable of communicating with the schedule management device; Equipped with The update device acquiring the schedule information from the schedule management device; predicting a blank period in the future in which the scheduled event will not occur based on the acquired schedule information; determining a scheduled update date and time, which is a date and time for updating software for the information processing device mounted on the vehicle, within the blank period; When the scheduled update date and time is determined, transmitting information about the scheduled update date and time to the schedule management device; updating the software on the scheduled update date and time; Run The schedule management device acquiring information about the scheduled update date and time from the update device; updating the schedule information according to information about the scheduled update date and time; Run Software update system.

Citation Information

Patent Citations

  • Equipment management system, user terminal, and control method of equipment

    JP2011158186A

  • controller

    JP2012014253A

  • Device, method, and system for processing information

    JP2023005815A

  • Software updating device, software updating system, and software updating method

    WO2023007577A1