Mobile device control device, mobile device control method, and program

The dual-bank ROM and non-volatile memory system in mobile devices ensures minimal downtime and maintains function states during software updates, addressing issues of deactivated functions and downtime in mobile devices.

JP7841014B2Active Publication Date: 2026-04-06HONDA MOTOR CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-27
Publication Date
2026-04-06

AI Technical Summary

Technical Problem

Software updates on mobile devices, such as vehicles, can unintentionally deactivate essential functions like vehicle security or result in prolonged downtime due to resetting functions to initial values.

Method used

A mobile device control system utilizing a dual-bank ROM and non-volatile memory to store functional status information before updating software, ensuring minimal downtime and maintaining function states during ignition off periods.

Benefits of technology

Minimizes downtime and suppresses malfunctions and state changes during software updates, enhancing traffic safety and sustainable transportation systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007841014000001
    Figure 0007841014000001
  • Figure 0007841014000002
    Figure 0007841014000002
  • Figure 0007841014000003
    Figure 0007841014000003
Patent Text Reader

Abstract

To reduce an inoperable time of a movable body as much as possible, and prevent a malfunction and a change of a state after software update.SOLUTION: A movable body controller 1 has software update units 10, 20 that execute software update processing. When executing the software update processing, the software update units 10, 20 write new version software in memories 12, 22, and subsequently write function state information DK indicating the current state of the function of a movable body 100 in a predetermined storage area 40, before completing processing of activating the new version software.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] ,

[0001] The present invention relates to a movement control device, a movement control method, and a program.

Background Art

[0002] Conventionally, in a control device mounted on a moving body such as a vehicle, a technique for supporting software update has been proposed. For example, Patent Document 1 discloses a configuration in which a storage unit that stores a program executed by an ECU (Electronic Control Unit) mounted on a vehicle sets an area for storing a program being executed and an area for storing an update program. According to this configuration, it is possible to store an update program in the storage unit even while the program is being executed, and it is said that the constraints on the timing of updating the program can be reduced.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, when software is updated, if the functions and states of the moving body are reset to initial values, there is a risk that functions that were operating during parking will not operate during parking, or that the setting state of the moving body will change before and after the software update. For example, vehicle security is a function that prevents vehicle theft and operates when the power is off, the vehicle is parked, and the vehicle is locked. The security is set when the user locks the vehicle, and if a software update is performed while the security is set, there is a risk that the security will be unintentionally deactivated after the software update. Alternatively, there is a method to retain the state before the software update and carry over that state after the update, but this may result in a long downtime during which the security will not function temporarily until the software starts up and the transfer process is completed. This invention aims to solve the above-mentioned problems by minimizing the downtime of mobile devices and suppressing malfunctions and state changes after software updates. Ultimately, this will contribute to further improving traffic safety and developing sustainable transportation systems. [Means for solving the problem]

[0005] One aspect of the present disclosure is a mobile device control device comprising a processor and a rewritable dual-bank ROM in which software used by the processor is stored, wherein the device has a software update unit that performs software update processing, the software used by the processor is stored in one bank of the dual-bank ROM, and when the software update unit performs software update processing, When the ignition is on, After writing the new version of the software to the other bank of the dual-bank ROM, When the mobile unit is in a waiting state for ignition off, and the operation to turn off the ignition of the mobile unit is recognized, the activation process of the new version of the software is started, and the mobile unit is turned off, and during the ignition off period, The mobile device control device writes functional status information indicating the current state of a predetermined function of the mobile body controlled by the mobile device control device to a non-volatile memory different from the dual-bank ROM before completing the activation process of the new version of the software, and after restarting with the new version of the software, the processor sets the state of the predetermined function based on the functional status information written to the non-volatile memory.

[0006] Another aspect of the present disclosure relates to a mobile body control method performed by a mobile body control device comprising a processor and a rewritable dual-bank ROM in which software used by the processor is stored, wherein in one bank of the dual-bank ROM, the software used by the processor is stored and an update process for the software is performed, When the ignition is on, After writing the new version of the software to the other bank of the dual-bank ROM, When the mobile unit is in a waiting state for ignition off, and the operation to turn off the ignition of the mobile unit is recognized, the activation process of the new version of the software is started, and the mobile unit is turned off, and during the ignition off period, This mobile body control method involves writing functional status information, which indicates the current state of a predetermined function of the mobile body controlled by the mobile body control device, to a non-volatile memory different from the dual-bank ROM before completing the activation process of the new version of the software, and then having the processor set the state of the predetermined function based on the functional status information written to the non-volatile memory after restarting with the new version of the software.

[0007] Another aspect of the present disclosure is a program that causes at least a portion of a mobile device control system, comprising a processor and a rewritable dual-bank ROM in which software used by the processor is stored, to function as a software update unit that performs software update processing, wherein the software used by the processor is stored in one bank of the dual-bank ROM, and when the software update unit performs software update processing, When the ignition is on, After writing the new version of the software to the other bank of the dual-bank ROM, When the mobile unit is in a waiting state for ignition off, and the operation to turn off the ignition of the mobile unit is recognized, the activation process of the new version of the software is started, and the mobile unit is turned off, and during the ignition off period, The program writes functional status information indicating the current state of a predetermined function of the mobile body controlled by the mobile body control device to a non-volatile memory different from the dual-bank ROM before completing the activation process of the new version of the software, and after restarting with the new version of the software, causes the processor to set the state of the predetermined function based on the functional status information written to the non-volatile memory. [Effects of the Invention]

[0008] According to one aspect of the present invention, the downtime of the mobile body can be minimized, and malfunctions and state changes after software updates can be suppressed. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 is a diagram showing the configuration of a mobile control device. [Figure 2] Figure 2 is a timing chart of the software update process in a mobile device control system. [Figure 3] Figure 3 shows an example of a mobile body in a state of a predetermined function. [Figure 4] Figure 4 illustrates the operation of the second microcontroller when the central ECU requests a reset. [Modes for carrying out the invention]

[0010] [1. Configuration of the mobile control device] Referring to Figure 1, the configuration of the mobile control device 1 of this embodiment will be described. The mobile control device 1 includes a central ECU 2 that performs overall control and information processing of the mobile body 100. In this embodiment, the mobile body 100 is exemplified as a vehicle, but it is not limited to a vehicle and may be an aircraft, ship, etc. The central ECU2 is connected to a communication line including communication lines L1 to L3. The central ECU2 is connected to multiple ECUs via the communication line to control the operation of the mobile unit 100 and functions as a gateway to manage the exchange of communication data. Figure 1 shows an area ECU, among the multiple ECUs, that controls the operation of functions that can be operated while the mobile unit 100 is stationary (door lock and security), along with its surrounding configuration. The area ECU includes a first microcontroller 10 and a second microcontroller 20.

[0011] The communication line is a bus that performs communication compliant with standards such as CAN (Controller Area Network, registered trademark), CAN FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), Ethernet (registered trademark), and FlexRay (registered trademark). Alternatively, communication lines L1 to L3 may be those that perform communication compliant with a different standard.

[0012] The central ECU2 performs software (program) writing to multiple ECUs connected via communication lines, and to other ECUs connected through these ECUs. Software writing includes updating software already written to an ECU and writing new software to an ECU. In other words, the central ECU2 also functions as an OTA (Over The Air) manager that performs OTA management. OTA management includes, for example, the process of downloading updated software for each ECU on the mobile unit 100 from an external server, and control over the software update process.

[0013] The mobile unit 100 includes a communication unit 5 that performs wireless communication with a mobile unit management server 310, etc., via a communication network 300, and a display 6 that functions as a notification unit that notifies the user (occupant) of the mobile unit 100 of various information. The communication unit 5 and the display 6 are connected to the mobile unit control device 1, but the mobile unit control device 1 may also provide them.

[0014] Further, an in-vehicle device 200 mounted on the moving body 100 is connected to the movement control device 1 by a communication line L3. The in-vehicle device 200 includes a configuration related to functions that operate while the moving body 100 is stopped. In this embodiment, the in-vehicle device 200 includes a door lock module 201 and a security module 202. These door lock module 201 and security module 202 are connected to at least one of the first microcomputer 10 and the second microcomputer 20 via the communication line L3.

[0015] The first microcomputer 10 and the second microcomputer 20 execute control and processing assigned to the area ECU. The first microcomputer 10 includes a first processor 11, a first memory 12, a first communication circuit 13, etc. By the first processor 11 executing the first software stored in the first memory 12, the door lock module 201 is locked / unlocked, and the headlights / wipers of the moving body 100 are operated / stopped, etc.

[0016] The second microcomputer 20 includes a second processor 21, a second memory 22, a second communication circuit 23, etc. By the second processor 21 executing the second software stored in the second memory 22, power control of the in-vehicle device 200 and setting of the security module 202 are performed. Note that the control and processing assigned to each of the microcomputers 10 and 20 may be changed as appropriate. Also, the area ECU is not limited to a configuration having two microcomputers 10 and 20, and may be configured to have one or three or more microcomputers.

[0017] The moving body 100 includes an SS (start / stop) switch 7 that can instruct switching between IG (IGNITION) on (power-on state) and IG off (power-off state) of the moving body 100. As shown in FIG. 1, the operation signal of the SS switch 7 (ON / OFF state of the SS switch 7) is input to the second microcomputer 20 via the input circuit 30. Also, an IG relay 8 is connected to the first microcomputer 10 via the input circuit 31, and the ON and OFF of the IG relay 8 are controlled by the control signal output from the second microcomputer 20 via the output circuit 35, so that the IG ON and IG OFF of the moving body 100 are switched. The detection signal of the ON / OFF of the IG relay 8 (ON / OFF state of the IG relay 8) is input to the first microcomputer 10 via the input circuit 31 and is also input to the second microcomputer 20 via the input circuit 32.

[0018] The movement control device 1 updates the first software and the second software by OTA management by performing wireless communication with the mobile body management server 310 via the communication network 300 by the communication unit 5. That is, when the central ECU 2 downloads the new version of the first software 122 from the mobile body management server 310, the first microcomputer 10 updates the first software. Also, when the central ECU 2 downloads the new version of the second software 222 from the mobile body management server 310, the second microcomputer 20 updates the second software.

[0019] The update process of the first software and the update process of the second software correspond to an example of the "update process of software that controls the operation of the functions held by the mobile body 100" of the present disclosure.

[0020] A rewritable dual-bank ROM (two-sided ROM) is applied to the first memory 12 and the second memory 22 in each of the microcomputers 10 and 20. When the old version of the first software 121 used by the first processor 11 is stored in one bank 12a of the first memory 12, the downloaded new version of the first software 122 is written by the first processor 11 to the other bank 12b which is the empty bank of the first memory 12.

[0021] Furthermore, if an older version of the second software 221 used by the second processor 21 is stored in one bank 22a of the second memory 22, the downloaded new version of the second software 222 is written by the second processor 21 to the other bank 22b, which is an empty bank of the second memory 22.

[0022] The first software 121 and 122 are software usable by the first processor 11 and include a control program for the mobile unit 100 and a dataset used for controlling the mobile unit 100. The area 12c of the first memory 12 stores the boot (bootstrap) process program for the first microcontroller 10.

[0023] The second software 221 and 222 are software usable by the second processor 21 and include a control program for the mobile unit 100, a dataset used for controlling the mobile unit 100, and so on. The area 22c of the second memory 22 stores the boot (bootstrap) process program for the second microcontroller 20.

[0024] [2. Software update timing] Referring to Figure 2, the update timing of the first and second software will be explained. Since the updates of the first and second software are performed at the same time and by similar processes, here we will refer to the first and second software collectively as "software," the first microcontroller 10 and the second microcontroller 20 collectively as "microcontrollers," and the first memory 12 and the second memory 22 collectively as "memory." The first software update is performed by the first processor 11 executing the boot process program stored in area 12c of the first memory 12. The second software update is performed by the second processor 21 executing the boot process program stored in area 22c of the second memory 22. Each microcontroller 10 and 20 functions as a "software update unit" in this disclosure by executing the programs for each boot process using the first processor 11 and the second processor 21.

[0025] [3. Operation of the mobile control device during software updates]

[0026] Figure 2 shows the sequence of the software update process in chronological order along the time axis t. When the mobile device control unit 1 recognizes the IG ON operation of the SS switch 7 at time t1, it starts the OTA sequence and performs configuration synchronization → download of reproduction data (data for the new version of the software) from the mobile device management server 310 → software erasure → installation (installation on the 2-sided ROM microcontroller).

[0027] In Figure 2, an example is shown where the mobile device control unit 1 performs an OTA software update when it recognizes the IG ON operation of the SS switch 7. However, the software update may be performed at other times. For example, when the mobile device control unit 1 receives a software update instruction signal transmitted from another ECU via the communication line 41, it may perform the OTA software update process, i.e., configuration synchronization → download of reproduction data (data for the new version of the software) from the mobile device management server 310 → software erasure → installation (installation on the 2-sided ROM microcontroller).

[0028] As indicated by symbols C1 to C5 in Figure 2, the memory area where the old version of the software is stored before the update is designated as side A, and the memory area where the new version of the software is stored after the update is designated as side B. Symbol C1 indicates the situation where side B, where the new version of the software is stored, is being erased, and the erased areas become free areas in sequence. Side A stores the old version of the software that is active (running).

[0029] Next, the microcontroller begins writing the new version of the software to side B, and after writing is complete, it waits for the ignition to be turned off. Code C2 indicates that the new version of the software has been written to side B. At time t2, the microcontroller recognizes the ignition being turned off by the SS switch 7 and begins the activation process. The activation process includes confirming the user's permission to activate, turning off the ignition, activating the software, and resetting the microcontroller.

[0030] The microcontroller verifies the activation permission (including confirmation of updating to a new version of the software). Once permission is confirmed, it turns off the ignition (including a setting that prevents power-on), activates the new version of the software, and resets itself. Code C3 indicates that the writing of the new version of the software to side B is complete and the activation process is finished. The new version of the software will become effective when the microcontroller restarts (equivalent to a processor restart).

[0031] At time t3, when the microcontroller recognizes the IG ON operation of SS switch 7, it confirms that the software update from the old version to the new version is complete and switches the software to be launched from the old version to the new version. Code C5 indicates that when the IG is ON, the software launched by the microcontroller has switched from the old version stored on side A to the new version stored on side B.

[0032] If the software is updated and the functions and status of the mobile unit 100 are reset to their initial values, there is a risk that functions that were operating while the unit was stationary may cease to operate while stationary, or that the settings of the mobile unit may change before and after the software update. Therefore, in this embodiment, as shown in Figure 2, after the microcontroller writes the new version of the software to memory, and before completing the activation process for the new version of the software, it writes the function state information DK, which indicates the current state of a predetermined function of the mobile unit 100, to the non-volatile memory 40, which functions as a predetermined storage area.

[0033] More specifically, when updating the first software, the first microcontroller 10 writes function status information DK, which indicates the status of the function (door lock) controlled by the first software, to a non-volatile memory 40 accessible by the first microcontroller 10. On the other hand, when updating the second software, the second microcontroller 20 writes function status information DK, which indicates the status of the functions (security) controlled by the second software, to a non-volatile memory 40 accessible by the second microcontroller 20. The non-volatile memory 40 can be broadly replaced with any writable non-volatile memory other than the first memory 12 and the second memory 22.

[0034] Figure 3 shows an example of the state of a predetermined function of the mobile body 100. Door locks and security are functions that may operate while the vehicle is stationary and are examples of the “prescribed functions” in this disclosure. As shown in Figure 3, there are four types of door locks, such as door lock operation, super lock control, keyless door lock, and trunk (T) and glove box (G) unlock control. Each function has states such as locked, unlocked, and not in use.

[0035] The door lock function locks or unlocks the door of the mobile unit 100, improving safety and security by locking the door. Super Lock Control is an enhanced version of the general door lock function, providing greater security than when the door lock is normally engaged. Keyless door locking is a function that allows you to lock and unlock the doors remotely or using a keyless entry system, while trunk (T) and glove box (G) unlock control is a function that prevents the unlocking of the trunk and glove box, respectively.

[0036] As shown in Figure 3, there are three types of security features, such as bullet mode control, security specifications, and ultrasonic security, and each function has a state such as enabled / disabled. Bullet mode control is a type of security system for the mobile vehicle 100. For example, when bullet mode control is enabled, only authenticated users are allowed to use the vehicle's functions. Security specifications refer to the specifications and standards related to the security functions of the mobile vehicle 100, such as an immobilizer and an anti-theft alarm system. Ultrasonic security is a security system that utilizes ultrasound.

[0037] Door locks and security are set to lock, unlock, not used, enabled, or disabled according to pre-configured specifications or user selection. In this embodiment, information indicating the latest functional state at the time of writing to the non-volatile memory 40 is written to the non-volatile memory 40 as functional state information DK. In other words, after writing the new version of the software to the memory, the functional state information DK at the time before the activation process of the new version of the software is completed is written to the non-volatile memory 40. This records the functional state information DK immediately before the software update.

[0038] Referring to Figure 4, the operation of the microcontroller when the central ECU2 requests a reset from the microcontroller will be explained. The microcontroller receives a reset request from the central ECU2 and, upon responding to the request, writes the functional status information DK to the non-volatile memory 40 (step Sa). Next, the microcontroller performs a reset synchronization process between the first microcontroller 10 and the second microcontroller 20 using the first communication circuit 13 and the second communication circuit 23, etc. (step Sb), and then restarts the microcontroller (step Sc). The restart enables the new version of the software.

[0039] As shown in Figure 2, when the microcontroller is restarted with the new software version, it sets the state of the functions that operate while the vehicle is stopped in the software, etc., based on the function state information DK written to the non-volatile memory 40. This ensures that the state of the functions that operate while the mobile body 100 is stopped does not change. Here, as shown in Figure 4, the period between steps Sa to Sc is a non-operational period (a period during which the user cannot operate the device). In this embodiment, software updates can be performed immediately regardless of the current functional state of the mobile device 100, and when the software is updated, the functional state of the mobile device 100 is immediately set based on the functional state information DK, making it possible to minimize the non-operational period.

[0040] As described above, when the mobile device control device 1 of this embodiment performs a software update process, the microcontroller writes the new version of the software to the memory, and then, before completing the activation process for the new version of the software, writes the function status information DK, which indicates the current state of predetermined functions (door lock and security) of the mobile device 100, to the non-volatile memory 40, which is a predetermined storage area. This allows the mobile unit 100 to set the state of a predetermined function based on the function status information DK when the software is updated. Furthermore, it enables immediate software updates regardless of the current function state of the mobile unit 100. These features minimize downtime for the mobile unit 100 and reduce malfunctions and state changes after the software update. Ultimately, this contributes to further improving traffic safety and the development of a sustainable transportation system.

[0041] Furthermore, the mobile device control unit 1 has multiple ECUs (which can also be called processors), including ECUs with microcontrollers 10 and 20. After the activation process is started by the microcontrollers 10 and 20, and before the target ECU (processor) restarts, the functional status information DK is written to the non-volatile memory 40. This helps to suppress malfunctions and status changes after software updates.

[0042] Furthermore, since the non-volatile memory 40 is a separate memory recording area from the memory where the software is stored, the software can be rewritten smoothly. Furthermore, after restarting with the new software version, the microcontroller sets the state of a predetermined function based on the function status information DK, thus suppressing malfunctions and state changes after software updates.

[0043] Furthermore, when the mobile device control unit 1 performs a software update process that controls the operation of the mobile device 100, including functions that the mobile device 100 maintains while stationary (for example, door locks and security), it writes the function status information DK to the non-volatile memory 40. This ensures that the state of the mobile device 100 does not change even if the software is updated while stationary. Furthermore, the present invention is not limited to software update processing that controls the operation of a mobile body 100, including a function that the mobile body 100 holds while stationary. In other words, when the present invention performs software update processing that controls the operation of a function held by the mobile body 100, the function state information DK may be written to the non-volatile memory 40. This makes it possible to ensure that the state of the mobile body 100 does not change even when the software is updated.

[0044] In this case, when a reset request is received as shown in Figure 4, if the microcontroller detects user operation on the mobile unit 100, it is preferable to postpone (cancel) the software update process. This avoids a situation where the software update process is performed while the user is in the process of changing the state of a predetermined function, and ensures that the state of the predetermined function does not change even after the software is updated.

[0045] [4. Other Embodiments] The above embodiments are merely one way of implementing the present invention, and can be modified and applied at will without departing from the spirit of the invention.

[0046] The configuration of the mobile device control device 1 shown in Figure 1 is an example, and the configuration may be changed as appropriate. Furthermore, Figure 1 is a schematic diagram showing the configuration of the mobile device control device 1 divided according to its main processing content, in order to facilitate understanding of the present invention, and the mobile device control device 1 may be configured by other divisions. Also, the processing of each component may be performed by one hardware unit or by multiple hardware units. Furthermore, the processing of each component may be performed by one program or by multiple programs.

[0047] [5. Configurations supported by the above embodiment] The above embodiment is a specific example of the following configuration.

[0048] (Configuration 1) A mobile device control device comprising a processor and a memory in which software used by the processor is stored, wherein the mobile device control device has a software update unit that performs software update processing, and when the software update unit performs software update processing, after writing the new version of the software to the memory, and before completing the activation processing of the new version of the software, writes functional status information indicating the current state of a predetermined function of the mobile device to a predetermined storage area. According to the mobile device control device of Configuration 1, when the software is updated, the state of a predetermined function of the mobile device can be set based on the function state information. Furthermore, the software update can be performed immediately regardless of the current function state of the mobile device. As a result, the downtime of the mobile device can be minimized, and malfunctions or state changes after the software update can be suppressed.

[0049] (Configuration 2) A mobile device control device according to Configuration 1, having a plurality of processors including the aforementioned processor, wherein the software update unit writes the functional status information to the storage area after the activation process has started but before the processor restarts. The mobile control device of configuration 2 can suppress malfunctions and state changes after software updates.

[0050] (Configuration 3) The mobile device control device according to Configuration 1 or 2, wherein the storage area is a recording area of ​​a memory separate from the memory. The mobile control device of configuration 3 allows for smooth software rewriting.

[0051] (Configuration 4) A mobile device control device according to any one of Configurations 1 to 3, wherein the processor, after being restarted with the new version of the software, sets the state of the predetermined function based on the function state information. The mobile control device of configuration 4 can suppress malfunctions and state changes after software updates.

[0052] (Configuration 5) The mobile body control device according to any one of Configurations 1 to 4, wherein the software update unit writes the function state information to the storage area when it performs an update process for software that controls the operation of the functions held by the mobile body. According to the mobile device control device of configuration 5, the state of the mobile device can be kept unchanged even when the software is updated.

[0053] (Configuration 6) A mobile device control device according to any one of Configurations 1 to 5, wherein the software update unit delays the software update process if it detects a user operation on the mobile device when a reset request is made in connection with the software update process. The mobile control device of configuration 6 can avoid situations where a user performs a software update process while changing the state of a predetermined function, and it can ensure that the state of the predetermined function does not change even after the software is updated.

[0054] (Configuration 7) A mobile body control method performed by a mobile body control device comprising a processor and a memory in which software used by the processor is stored, wherein when performing a software update process, after writing a new version of the software to the memory, and before completing the activation process of the new version of the software, functional state information indicating the current state of a predetermined function of the mobile body is written to a predetermined storage area. By executing the mobile body control method of configuration 7 using a mobile body control device, the same effects and advantages as the mobile body control device of configuration 1 can be obtained.

[0055] (Configuration 8) A program that causes at least a part of a mobile device control device, which comprises a processor and a memory in which software used by the processor is stored, to function as a software update unit that performs software update processing, wherein when the software update unit performs software update processing, after writing a new version of the software to the memory, and before completing the activation processing of the new version of the software, the program writes functional status information indicating the current state of a predetermined function of the mobile device to a predetermined storage area. By executing the program of configuration 8 using the mobile control device, the same effects and advantages as those of the mobile control device of configuration 1 can be obtained. [Explanation of Symbols]

[0056] 1...Mobile device control unit, 2...Central ECU, 5...Communication unit, 6...Display, 7...SS switch, 8...IG relay, 10...First microcontroller, 11...First processor, 12...First memory, 13...First communication circuit, 20...Second microcontroller, 21...Second processor, 22...Second memory, 23...Second communication circuit, 30, 32, 33...Input circuits, 35...Output circuits, 40...Non-volatile memory (predetermined storage area), 100...Mobile device, 121...Old version of first software, 122...New version of first software, 200...In-vehicle device, 201...Door lock module, 202...Security module, 221...Old version of second software, 222...New version of second software, 300...Communication network, 310...Mobile device management server.

Claims

1. A mobile control device comprising a processor and a rewritable dual-bank ROM in which software used by the processor is stored, It has a software update unit that performs the aforementioned software update process, The software used by the processor is stored in one of the banks of the dual-bank ROM. When the software update unit performs the software update process, if the mobile body is ignition-on, it writes the new version of the software to the other bank of the dual-bank ROM, then waits for the mobile body to be ignition-off, and when it recognizes the operation to turn off the mobile body's ignition, it starts the activation process for the new version of the software, turns off the mobile body's ignition, and during the ignition-off period, before completing the activation process for the new version of the software, it writes functional status information indicating the current state of a predetermined function of the mobile body controlled by the mobile body control device to a non-volatile memory different from the dual-bank ROM. After restarting with the new version of the software, the processor sets the state of the predetermined function based on the function state information written to the non-volatile memory. Mobile device control system.

2. Having multiple processors including the aforementioned processor, The software update unit writes the functional status information to the non-volatile memory after starting the activation process and before the processor restarts. The mobile device control device according to claim 1.

3. The non-volatile memory is a memory that can be accessed by multiple processors. The mobile device control device according to claim 2.

4. When the software update unit performs an update process for the software that controls the operation of the functions held by the mobile body, it writes the function status information to the non-volatile memory. The mobile device control device according to claim 1.

5. The software update unit, upon receiving a reset request related to the software update process, will postpone the software update process if it detects a user operation on the mobile device. The mobile device control device according to claim 1.

6. A mobile body control method performed by a mobile body control device comprising a processor and a rewritable dual-bank ROM in which software used by the processor is stored, The software used by the processor is stored in one of the banks of the dual-bank ROM. When performing the software update process, if the mobile device is ignited on, the new version of the software is written to the other bank of the dual-bank ROM, and then the system waits for the mobile device to be ignited off. When the system recognizes the operation to turn off the mobile device's ignition, it starts the activation process for the new version of the software and turns off the mobile device's ignition. During the ignition off period, before completing the activation process for the new version of the software, the system writes functional status information indicating the current state of a predetermined function of the mobile device controlled by the mobile device control unit to a non-volatile memory different from the dual-bank ROM. The aforementioned processor, after restarting with the new version of the software, causes the state of the predetermined function to be set based on the function state information written to the non-volatile memory. A method for controlling a mobile object.

7. A program that causes at least a part of a mobile device control system, which includes a processor and a rewritable dual-bank ROM in which software used by the processor is stored, to function as a software update unit that performs software update processing, The software used by the processor is stored in one of the banks of the dual-bank ROM. When the software update unit performs the software update process, if the mobile body is ignition-on, it writes the new version of the software to the other bank of the dual-bank ROM, then waits for the mobile body to be ignition-off, and when it recognizes the operation to turn off the mobile body's ignition, it starts the activation process for the new version of the software, turns off the mobile body's ignition, and during the ignition-off period, before completing the activation process for the new version of the software, it writes functional status information indicating the current state of a predetermined function of the mobile body controlled by the mobile body control device to a non-volatile memory different from the dual-bank ROM. The aforementioned processor, after restarting with the new version of the software, causes the state of the predetermined function to be set based on the function state information written to the non-volatile memory. program.

Citation Information

Patent Citations

  • Information processing device, restarting method and restarting program

    JP2003131896A

  • Information processing apparatus, information processing method, and program

    JP2011086247A

  • Platform for integrated system, application, control program with platform and application, electronic apparatus, and update method of application

    JP2012155682A

  • Information process device, information process method and program

    JP2014179039A

  • Vehicle electronic control unit, program update method and program

    JP2019144669A