Control device, vehicle, control method, and program
The control device and method address functional restrictions in vehicle software updates by displaying tailored confirmation screens based on different update procedures, enhancing user convenience and clarity regarding activation process timings and restrictions.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2026-04-14
AI Technical Summary
Existing software update processes in vehicles can restrict vehicle functions during the activation phase, and the timing of these restrictions varies depending on the update procedure, necessitating appropriate confirmation screens based on the timing of the activation process.
A control device and method that display different confirmation images on a display unit before the activation process, depending on whether the update is performed in a first or second update procedure, where the activation process occurs in response to different power mode switches, ensuring users are informed of the specific functional restrictions and timing.
The solution allows for displaying appropriate confirmation screens based on the activation process timing, improving user convenience by enabling informed decisions and accurate notification of functional restrictions and completion times.
Smart Images

Figure 0007845341000001 
Figure 0007845341000002 
Figure 0007845341000003
Abstract
Description
Technical Field
[0001] The present invention relates to a control device, a vehicle, a control method, and a program for performing display control of information related to software update of in-vehicle devices.
Background Art
[0002] Vehicles are equipped with various in-vehicle devices that operate by executing software. There is known an OTA (Over The Air) technology for updating the software of in-vehicle devices with software downloaded from outside the vehicle via wireless communication. As described in Patent Document 1, software update is performed through an installation process of writing the downloaded updated software into the storage module of the in-vehicle device and an activation process of activating the installed updated software.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When the activation process is carried out, some functions of the vehicle may be restricted. Therefore, it is desirable to confirm with the user before starting the activation process. On the other hand, it is conceivable to carry out the activation process at different timings depending on the type of in-vehicle device and the type of software. In such a case, depending on the timing of carrying out the activation process, the timing at which vehicle function restriction occurs changes. Therefore, it is desired that an appropriate confirmation screen be displayed according to the timing of carrying out the activation process.
Means for Solving the Problems
[0005] A control device that solves the above problems is a control device that controls a display unit that displays information regarding software updates for in-vehicle equipment installed in a vehicle having multiple switchable power modes, and when the software update is performed in a first update procedure in which an activation process to activate update software installed in the in-vehicle equipment is performed in accordance with the switching of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activation process, and when the software update is performed in a second update procedure in which the activation process is performed in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activation process.
[0006] A vehicle that solves the above problems is equipped with the above-mentioned control device. A control method for solving the above problems is a control method for a display unit that displays information regarding software updates of in-vehicle equipment mounted in a vehicle, wherein when the software update is performed in a first update procedure in which an activation process to activate update software installed in the in-vehicle equipment is performed in accordance with the switching of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activation process, and when the software update is performed in a second update procedure in which the activation process is started in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activation process.
[0007] A program to solve the above problem is a program executed by a control device that controls a display unit that displays information regarding software updates for in-vehicle equipment installed in a vehicle, and causes the control device to execute the following: when the software update is performed in a first update procedure in which an activation process to enable update software installed in the in-vehicle equipment is performed in accordance with the switching of the power mode in a first switching pattern, the program causes the control device to execute the following: when the software update is performed in a second update procedure in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, the program causes the program [Effects of the Invention]
[0008] The above-described control device, vehicle, control method, and program have the effect of displaying an appropriate confirmation screen according to the timing of the activation process. [Brief explanation of the drawing]
[0009] [Figure 1] This diagram schematically shows the configuration of the control device and vehicle according to the first embodiment. [Figure 2] This diagram schematically shows the configuration of an in-vehicle device equipped with a single-bank memory module. [Figure 3] This diagram schematically illustrates the configuration of an in-vehicle device equipped with a dual-bank memory module. [Figure 4] This is a sequence diagram showing the processing flow of the activation phase when a software update is performed in the first update procedure in the first embodiment. [Figure 5] This is a diagram showing an example of the display of the first pre-check image. [Figure 6] This figure shows an example of the display of the first final confirmation image. [Figure 7] This is a diagram showing an example of the display of the first guidance image. [Figure 8]This figure shows an example of how the first completion notification image is displayed. [Figure 9] This is a sequence diagram showing the processing flow of the activation phase when a software update is performed in the second update procedure in the first embodiment. [Figure 10] This figure shows an example of the display of the second pre-confirmation image. [Figure 11] This figure shows an example of the display of the second final confirmation image. [Figure 12] This figure shows an example of how the second guidance image is displayed. [Figure 13] This figure shows an example of how the second completion notification image is displayed. [Figure 14] This is a sequence diagram showing the processing flow of the activation phase when a software update is performed in the first update procedure in the second embodiment. [Figure 15] This is a sequence diagram showing the processing flow of the activation phase when a software update is performed in the second update procedure in the second embodiment. [Modes for carrying out the invention]
[0010] (First Embodiment) The first embodiment of the control device, vehicle, control method, and program will be described in detail below with reference to Figures 1 to 13.
[0011] <Control device and vehicle configuration> First, referring to FIG. 1, the configuration of the control device and the vehicle according to the present embodiment will be described. As shown in FIG. 1, the vehicle 10 is equipped with in-vehicle devices such as an OTA master 11, a DCM 12, an ADAS 13, a PCU 14, an engine ECU 15, a transmission ECU 16, a brake ECU 17, and an HMI 18. These in-vehicle devices are communicably connected to each other via an in-vehicle network 19. The OTA master 11 is in charge of managing software updates for the in-vehicle devices including itself. The DCM 12 is a Data Communication Module that provides a wireless communication function with the outside of the vehicle via a mobile communication network 20. In the case of the present embodiment, the DCM 12 has a function of recording the results of self-diagnostics performed by each in-vehicle device of the vehicle 10 and transmitting them to an external data center or the like. The ADAS 13 is an Advanced Driving Assistant System that provides advanced driving assistance functions such as an automatic braking device and a sudden acceleration prevention device. The PCU 14 is a Power Control Unit that performs power control inside the vehicle. The engine ECU 15 is an Electronic Control Unit for engine control. The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a Human Machine Interface. The HMI 18 includes an input device that receives operations from passengers and a display device that displays information to passengers by images and sounds. The HMI 18 may be configured to include a navigation function for guiding a driving route and an entertainment function for playing music and videos. Each of these in-vehicle devices has a storage module 21 in which software is stored and a processor 22 that executes the software. The OTA master 11 further has a data storage 23 that stores updated software acquired from the outside of the vehicle.
[0012] Vehicle 10 has multiple power modes. The multiple power modes include a power mode for driving and a power mode for parking. For each power mode, it is determined which in-vehicle devices are to be powered on. When the power mode for driving is set, the power of the in-vehicle devices necessary for the driving of vehicle 10 and the provision of services during driving is turned on. In the case of this embodiment, when the power mode for driving is set, the power of all the in-vehicle devices shown in FIG. 1 is turned on. When the power mode for parking is set, only the in-vehicle devices that need to operate even when vehicle 10 is parked are powered on. The in-vehicle devices that are powered on in each power mode can be changed according to the environment and user settings.
[0013] Vehicle 10 is provided with a power switch 24 for switching between the power mode for driving and the power mode for parking. The switching from the power mode for driving to the power mode for parking is performed in response to the switching of the power switch 24 from on to off. The switching from the power mode for parking to the power mode for driving is performed in response to the switching of the power switch 24 from off to on. The power switch 24 may be called an ignition switch in a conventional vehicle that uses only an engine as a drive source. Also, in a vehicle capable of electric driving such as a BEV or PHEV, the power switch 24 may be called a Ready switch.
[0014] Vehicle 10 is connected to an OTA server 30 via a mobile communication network 20. The OTA server 30 is a server device that distributes updated software for in-vehicle devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing updated software, and a processor 32 that executes the program for distribution.
[0015] The OTA server 30 can communicate with the user's information terminal 40 in the vehicle 10 via the mobile communication network 20. An example of the information terminal 40 is a smartphone. The information terminal 40 may also be a tablet or a PC. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes the software stored in the storage device 41. The HMI 43 includes an input device that accepts user input and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as checking information about the vehicle 10 owned by the user and remote operation.
[0016] <Overview of Software Updates> Next, an overview of the software update for the in-vehicle equipment in vehicle 10 will be described. The in-vehicle equipment subject to the software update includes the OTA master 11, DCM 12, ADAS 13, PCU 14, engine ECU 15, transmission ECU 16, brake ECU 17, and HMI 18. The software update is performed through a download phase, an installation phase, and an activation phase.
[0017] In the download phase, the OTA server 30 transmits the update software to the vehicle 10. The OTA master 11 stores the update software received from the OTA server 30 in the data storage 23. The download phase includes a series of processes related to the download, such as determining whether to proceed with the download and verifying the update data. The transmission of the update software from the OTA server 30 to the OTA master 11 may be performed by transmitting compressed data containing the update software, or by transmitting segmented data containing the update software or compressed data. Alternatively, update software for multiple in-vehicle devices may be transmitted together.
[0018] During the installation phase, the update software is installed on the in-vehicle device to be updated. In the installation phase, the OTA master 11 installs the update software on the storage module 21 of the in-vehicle device to be updated, based on the update data downloaded to the data storage 23. The installation phase includes a series of processes related to installation, such as determining whether installation is possible, transferring the update data, and verifying the update software. If the update data includes the update software itself, the OTA master 11 transfers the update data to the in-vehicle device to be updated during the installation phase. If the update data includes compressed data, differential data, or segmented data of the update software, a process of generating the update software from the update data is performed. This generation process may be performed by the OTA master 11 or by the in-vehicle device to be updated. The generation of the update software can be done by decompressing the compressed data or assembling the differential data or segmented data. Note that the update software is deactivated upon completion of the installation phase.
[0019] During the activation phase, the update software is activated, or enabled, on the in-vehicle equipment being updated. The activation phase includes a series of activation-related processes, such as determining whether or not to perform the activation, checking the compatibility of the update software, and verifying the results of the activation.
[0020] <Two methods for updating the software> There are two procedures for updating the software of in-vehicle equipment: the first update procedure and the second update procedure. In both the first and second update procedures, the software update is performed using the same procedure until the completion of the installation phase. The first and second update procedures differ in the timing at which the activation process begins in the activation phase. The activation process is the process of enabling the update software installed in the memory module 21 of the in-vehicle equipment to be updated.
[0021] In the first update procedure, the activation process is performed in response to the switching of the power switch 24 from on to off. In other words, in the first update procedure, the activation process is performed in response to the switching from the driving power mode to the parking power mode. When a software update is performed in the first update procedure, the power switch 24 is prohibited from being switched back to on during the period from the start to the completion of the activation process. To put it another way, when a software update is performed in the first update procedure, the switching to the driving power mode is prohibited during the period from the start to the completion of the activation process.
[0022] In contrast, in the second update procedure, the activation process is performed in response to the switching of the power switch 24 from off to on. That is, in the second update procedure, the activation process is performed in response to the switching from the parking power mode to the driving power mode. More specifically, in the second update procedure, the activation process starts in response to the switching of the power switch 24 from off to on. Then, after waiting for the activation process to complete, the power mode is switched from the parking power mode to the driving power mode.
[0023] The choice between the first and second update procedures for performing a software update is determined, for example, by the type of in-vehicle equipment, hardware configuration, and software type. The decision of which procedure to use may also be based on environmental conditions, user settings, and combinations of other in-vehicle equipment undergoing activation simultaneously.
[0024] When performing a software update using the first update procedure, power must be supplied to the in-vehicle equipment during the activation process, even while the vehicle 10 is parked. Therefore, the in-vehicle equipment undergoing a software update using the first update procedure must be connected to a dedicated power line to ensure power is supplied even while parked. Consequently, it is generally preferable to perform software updates for in-vehicle equipment using the second update procedure, which does not require a dedicated power line.
[0025] However, for some in-vehicle devices, it is preferable to perform the software update using the first update procedure rather than the second update procedure. In the first update procedure, the activation process is already completed when the power switch 24 is switched from on to off and then back to on. Therefore, in this case, the in-vehicle device to be updated can start operating immediately after the power switch 24 is switched from off to on. In contrast, in the second update procedure, the activation process starts after the power switch 24 is switched from off to on. Therefore, even if the user switches the power switch 24 from off to on to start driving the vehicle 10, the in-vehicle device to be updated cannot start operating until the activation process is completed. Consequently, for in-vehicle devices that are required to start operating immediately after the power switch 24 of the vehicle 10 is switched from off to on, it is preferable to perform the software update using the first update procedure.
[0026] In this embodiment, the DCM12, ADAS13, and PCU14 are classified as in-vehicle devices whose software is updated in the first update procedure. The communication function provided by the DCM12 is used to notify the outside of any abnormalities that occur in the vehicle 10. Furthermore, in this embodiment, the DCM12 is responsible for recording the results of the self-diagnosis of each in-vehicle device. It is desirable that the functions of the DCM12, such as reporting abnormalities and recording self-diagnosis results, be available immediately after the power switch 24 is switched from off to on. In addition, the ADAS13 needs to provide driving assistance from the moment the vehicle 10 starts moving. Furthermore, while the PCU14 is stopped, power cannot be supplied to the drive system, making it impossible to start driving the vehicle 10. Thus, the DCM12, ADAS13, and PCU14 are in-vehicle devices that are required to start operating immediately after the power switch 24 is switched from off to on.
[0027] Furthermore, depending on the hardware configuration of the memory module 21 installed in the in-vehicle equipment, a software update in the first update procedure may also be required. In this embodiment, among the in-vehicle equipment other than the DCM12, ADAS13, and PCU14 mentioned above, in-vehicle equipment equipped with a single-bank memory module 21 is classified as in-vehicle equipment that undergoes a software update in the first update procedure. Among the in-vehicle equipment other than the DCM12, ADAS13, and PCU14, in-vehicle equipment equipped with a dual-bank memory module 21 is classified as in-vehicle equipment that undergoes a software update in the second update procedure.
[0028] Figure 2 shows the configuration of an in-vehicle device D1 equipped with a single-bank memory module 21A. The memory module 21A of this in-vehicle device D1 has only one memory area B that stores the software executed by the processor 32. In the case of such an in-vehicle device D1, the updated software is installed in the same memory area B that stored the software before the update. Therefore, it is necessary to stop the operation of the in-vehicle device D1 even while the installation is being performed. Furthermore, in order to recover if activation fails, it is necessary to reinstall the software before the update into memory area B. Such reinstallation for recovery takes a long time. Moreover, if the software before the update is not backed up, it is necessary to redownload the software before the update. Thus, in the case of an in-vehicle device D1 equipped with a single-bank memory module 21A, considering the recovery in the event of failure, it may take a very long time from the start of activation until it can start operating. For this reason, in this embodiment, the software update of the in-vehicle device D1 equipped with a single-bank memory module 21A is performed in the first update procedure. Furthermore, in this embodiment, the in-vehicle equipment that performs the software update in the first update procedure has its power switched on and off in conjunction with the on / off state of the power switch 24 of the vehicle 10.
[0029] Figure 3 shows the configuration of an in-vehicle device D2 equipped with a dual-bank memory module 21B. The dual-bank memory module 21B has two memory areas B1 and B2. One of the two memory areas B1 and B2 is disabled, and the other is enabled. The processor 22 reads and executes the software from the enabled memory area. In the case of such an in-vehicle device D2, the updated software is installed in the disabled memory area, that is, in a memory area different from the memory area that stored the software before the update. After installation, activation is performed by switching the memory area to be enabled. If activation fails, the system can be restored to its pre-update state in a short time by switching the memory area to be enabled again. Therefore, in the case of an in-vehicle device D2 equipped with a dual-bank memory module 21B, even considering recovery in the event of failure, it does not take very long from the start of activation until the system can start operating. Accordingly, in this embodiment, the software update using the second update procedure is limited to in-vehicle device D2 equipped with a dual-bank memory module 21B.
[0030] Furthermore, many in-vehicle devices may have multiple software programs installed that provide different functions. Among these programs, some may need to be executed immediately after the power switch 24 is switched from off to on, while others do not need to be executed immediately. If the software needs to be executed immediately after the power switch 24 is switched from off to on, the update may not be completed in time if the update is performed using the second update procedure. Therefore, even for the same in-vehicle device, it may be advisable to differentiate between updating using the first update procedure or the second update procedure depending on the type of software to be updated.
[0031] The OTA master 11 determines, at least by the start of the activation phase, whether the software update will be performed using the first update procedure or the second update procedure. For example, the OTA master 11 makes the above determination based on campaign information. In this case, the campaign information includes information indicating whether the software update procedure is the first update procedure or the second update procedure. Alternatively, the above determination may be made in the following manner. First, the classification information of the types of in-vehicle devices and software to be updated using the first update procedure, and the types of in-vehicle devices and software to be updated using the second update procedure, is stored in advance in the storage module 21 of the OTA master 11. When updating the software, the OTA master 11 obtains the types of in-vehicle devices and software to be updated from the campaign information or the in-vehicle devices to be updated. Then, the OTA master 11 refers to the classification information stored in the storage module 21 and determines which update procedure the obtained types are classified under.
[0032] <Activation process in the first update procedure> Next, with reference to Figures 4 to 8, the details of the activation process in the first update procedure will be explained. The storage module 21 of the OTA master 11 stores a program for managing software updates and a program for controlling the display of information related to software updates. The processing of the OTA master 11 shown in Figure 4 and Figure 9 described later is performed by the processor 22 of the OTA master 11 reading and executing these programs.
[0033] Figure 4 shows the processing flow of the activation phase when a software update is performed in the first update procedure. Once the installation phase is complete, the OTA master 11 instructs the HMI 18 to display a first pre-confirmation image to confirm with the user that the activation process will be executed (S10). In response to the instruction, the HMI 18 displays a first pre-confirmation image as exemplified in Figure 5 (S11).
[0034] Figure 5 shows an example of the display of the first pre-confirmation image. The first pre-confirmation image includes a display prompting the user to select whether or not to allow the activation process to be performed. Specifically, the first pre-confirmation image displays a button to select whether to allow the activation process to be performed and a button to select whether to postpone the activation process to be performed. Note that these buttons are disabled while the vehicle 10 is in motion and are only enabled when the vehicle is parked.
[0035] Furthermore, the first pre-check image displays information about the functional limitations of the vehicle 10 that occur during the activation process. Specifically, the information displays that the power switch 24 cannot be switched back to the ON position during the activation process. This functional limitation indicates that it is not possible to switch to the driving power mode. In addition, the first pre-check image displays information about the estimated time for the activation process. The estimated time for the activation process here is the estimated time required from when the power switch 24 is switched from ON to ON until the activation process is completed and the power switch 24 can be switched back to the ON position. The OTA master 11 obtains the estimated time from, for example, campaign information. The OTA master 11 may also calculate the estimated time based on the data size of the update software and the type of in-vehicle equipment to be updated.
[0036] The first pre-check image also displays information such as warnings to the user regarding the activation process. Examples of this warning information include that the power switch 24 must be turned off to update the software, that activation should be performed in a safe location, and that some functions of the vehicle 10 will be disabled the next time the power switch 24 is turned on.
[0037] When the user selects permission to execute the activation process on the HMI18 displaying the first pre-confirmation image (S12), the HMI18 notifies the OTA master 11 that permission to execute the activation process has been granted (S13). After the OTA master 11 confirms permission to execute the activation process, it instructs the HMI18 to display the first final confirmation image when it becomes possible to switch the power switch 24 from on to off (S14). In response to the instruction, the HMI18 displays the first final confirmation image as illustrated in Figure 6 (S15). The OTA master 11 determines that the power switch 24 is in a state where it can be switched from on to off, based on conditions such as the vehicle 10 being stopped, the parking shift operation being performed, and the parking brake being engaged.
[0038] Figure 6 shows an example of the display of the first final confirmation image. Similar to the first pre-confirmation image, the first final confirmation image displays information about the functional limitations of the vehicle 10 due to the activation process. Specifically, the first final confirmation image displays information indicating that if the power switch 24 is turned off, it will not be possible to turn the power switch 24 back on and drive the vehicle 10 until the activation process is complete. The first final confirmation image also displays information about the estimated time for the activation process. The first final confirmation image also displays information indicating that it is possible to turn off the power switch 24 after confirming that the vehicle is in a safe location, and to resume driving, in which case the software update will resume with the display of the first final confirmation image at the next stop. Furthermore, the first final confirmation image also displays an indication that the software update can be temporarily paused. The activation phase process continues if the user does not select to pause the software update in the first final confirmation image. On the other hand, if the user selects to pause the software update in the first final confirmation image, the activation phase process is temporarily stopped. The activation phase process then resumes when the vehicle 10 becomes available to be switched off.
[0039] If the activation phase processing continues, and the user then switches the power switch 24 from on to off (S16), the OTA master 11 starts the activation process (S17). At the same time, the OTA master 11 instructs the HMI 18 to display the first guide image as illustrated in Figure 7 (S18). The HMI 18 displays the first guide image in response to the instruction (S19).
[0040] As shown in Figure 7, the first guidance image displays information indicating that the power switch 24 cannot be switched on, and information indicating the estimated time until the power switch 24 can be switched on. The OTA master 11 calculates the estimated time for displaying the information in the first guidance image by subtracting the time elapsed from the start of the activation process to the present from the estimated time required from the start to the completion of the activation process. The HMI 18 temporarily dims the screen in response to the locking of the vehicle 10 or the passage of a certain amount of time, but displays the first guidance image again in response to the unlocking of the vehicle 10 or operation of the HMI 18.
[0041] When the activation process is complete, the OTA master 11 instructs the HMI 18 to display a first completion notification image as illustrated in Figure 8 (S20). The HMI 18 displays the first completion notification image in response to the instruction (S21). As shown in Figure 8, the first completion notification image displays information indicating that the software update is complete and information indicating that the power switch 24 can now be switched on.
[0042] <Activation process in the second update procedure> Next, we will explain the details of the activation process in the second update procedure with reference to Figures 9 to 11. Figure 9 shows the flow of the activation phase when a software update is performed in the second update procedure.
[0043] In this case, once the installation phase is complete, the OTA master 11 instructs the HMI 18 to display a second pre-confirmation image to confirm with the user that the activation process has been executed (S30). The HMI 18 responds to the instruction and displays a second pre-confirmation image as illustrated in Figure 10 (S31).
[0044] Figure 10 shows an example of the display of the second pre-confirmation image. Similar to the first pre-confirmation image, the second pre-confirmation image includes a display indicating whether or not to accept the selection operation to perform the activation process. The second pre-confirmation image also indicates that the activation process will be performed when the power switch 24 is next switched to the ON position. Furthermore, the second pre-confirmation image displays information on the estimated time from when the power switch 24 is switched from OFF to ON until the activation process is completed.
[0045] When the user selects permission to execute the activation process on the HMI18 displaying the second pre-confirmation image (S32), the HMI18 notifies the OTA master 11 that permission to execute the activation process has been granted (S33). After the OTA master 11 confirms permission to execute the activation process, it instructs the HMI18 to display the second final confirmation image when the vehicle 10 is in a state where it can be switched from power on to power off (S34). In response to the instruction, the HMI18 displays the second final confirmation image as illustrated in Figure 11 (S35).
[0046] Figure 11 shows an example of the display of the second final confirmation image. The second final confirmation image displays information indicating that the activation process is ready, and information indicating that the software update will resume when the power switch 24 is switched from off to on.
[0047] Subsequently, when the power switch 24 switches from on to off and then back to on, the OTA master 11 starts the activation process (S36). In addition, the OTA master 11 instructs the HMI 18 to display a second guidance image as illustrated in Figure 12 (S37). The HMI 18 displays the second guidance image in response to the instruction (S38).
[0048] As shown in Figure 12, the second guidance image displays information indicating that a software update is in progress, as well as information indicating the estimated time until the update is completed. The OTA master 11 calculates the estimated time for displaying the information in the second guidance image by subtracting the time elapsed from the start of the activation process to the present from the estimated time required from the start to the completion of the activation process.
[0049] Once the activation process is complete, the OTA master 11 instructs the HMI 18 to display a second completion notification image, as illustrated in Figure 13 (S39). The HMI 18 displays the second completion notification image in response to the instruction (S40). As shown in Figure 13, the second completion notification image displays information indicating that the software update is complete. The second completion notification image also displays information indicating that the functional restrictions associated with the activation process have been lifted. For example, if the vehicle 10 was prohibited from driving during the activation process, information indicating that the vehicle 10 is now able to drive will be displayed in the second completion notification image.
[0050] <Effects and Effects of the Embodiment> The OTA master 11 controls the display of the HMI 18, which displays information regarding software updates for in-vehicle equipment installed in the vehicle 10. Software updates for in-vehicle equipment are performed using either a first update procedure or a second update procedure. In the first update procedure, an activation process to enable the update software installed on the in-vehicle equipment is performed in accordance with the switch from the driving power mode to the parking power mode. In the second update procedure, the activation process is performed in accordance with the switch from the parking power mode to the driving power mode. When a software update is performed using the first update procedure, the OTA master 11 displays a first pre-confirmation image and a first final confirmation image on the HMI 18 before the activation process begins. Conversely, when a software update is performed using the second update procedure, the OTA master 11 displays a second pre-confirmation image and a second final confirmation image, which are different from the first pre-confirmation image and the first final confirmation image, on the HMI 18 before the activation process begins.
[0051] The timing and nature of the restrictions on the vehicle 10's functions during the activation process differ depending on whether the software update is performed using the first or second update procedure. Therefore, simply notifying the user that the activation process will be performed may cause unexpected function restrictions, potentially confusing the user. In this embodiment, the user can confirm whether the software update will be performed using the first or second update procedure by observing the difference in the confirmation image displayed on the HMI 18 before the activation process begins.
[0052] The control device, vehicle, control method, and program of this embodiment described above can achieve the following effects. (1) The confirmation image displayed on the HMI18 before the activation process begins differs depending on whether the software update is performed using the first update procedure or the second update procedure. Therefore, this embodiment has the effect of being able to display an appropriate confirmation screen according to the timing of the activation process.
[0053] (2) Users can decide whether or not to perform the activation process after confirming the timing of the process. This improves user convenience. (3) Different timings for the activation process result in different timings and content of the functional restrictions on the vehicle 10. In response to this, the OTA master 11 displays information about the functional restrictions on the vehicle 10 resulting from the activation process within the first pre- / final confirmation image. Furthermore, the OTA master 11 displays information different from that displayed within the first pre- / final confirmation image as functional restriction information within the second pre- / final confirmation image. Therefore, the functional restrictions on the vehicle 10 resulting from the activation process can be accurately notified to the user.
[0054] (4) The OTA master 11 displays information in the first pre- and final confirmation images regarding the period during which the functions of the vehicle 10 will be restricted due to the activation process. In addition, the OTA master 11 displays information in the second pre- and final confirmation images regarding a period different from the period during which the functions of the vehicle 10 will be restricted. Therefore, the user can be accurately notified of the period during which the functions of the vehicle 10 will be restricted due to the activation process.
[0055] (5) The OTA master 11 displays information in the first pre- / final confirmation image regarding the estimated time from when the power switch 24 is switched from on to off until it can be switched back to on. Therefore, the user can check the period during which the power switch 24 cannot be turned on due to the activation process and decide whether or not to perform the activation process.
[0056] (6) The OTA master 11 displays information in the second pre-confirmation image regarding the estimated time from when the power switch 24 is switched from off to on until the activation process is completed. Therefore, when the user drives the vehicle 10 next, they can check the period during which the activation process will result in functional limitations and decide whether or not to perform the activation process.
[0057] (7) The first pre- / final confirmation image and the second pre-confirmation image include a prompt to accept the user's choice of whether or not to allow the activation process to begin. Therefore, the user can decide whether or not to proceed with the activation process while checking the timing of the activation process and the content and timing of any functional restrictions that may arise from its implementation.
[0058] (8) The functional limitations of the vehicle 10 caused by the activation process differ between the first update procedure and the second update procedure. Therefore, users may not be able to understand the situation simply by knowing that the activation process is in progress. To address this, the OTA master 11 displays a first guidance image on the HMI 18 during the activation process when a software update is performed in the first update procedure. Also, the OTA master 11 displays a second guidance image, different from the first guidance image, on the HMI 18 during the activation process when a software update is performed in the second update procedure. Therefore, it is easier for users to understand the effects of the activation process.
[0059] (9) The OTA master 11 displays information in the first guidance image indicating that the power switch 24 cannot be switched on, that is, that it cannot be switched to the power mode for driving. Furthermore, the OTA master 11 displays information in the first guidance image indicating the estimated time until the power switch 24 can be switched on. This makes it easier for the user to understand the situation.
[0060] (10) The OTA master 11 displays information about the estimated time until the activation process is completed within the second guidance image. This allows the user to know when the updated software's functions will become available.
[0061] (11) Depending on whether the software update is performed using the first update procedure or the second update procedure, the functions of the vehicle 10 whose restrictions are lifted upon completion of the activation process will differ. In response to this, when the software update is performed using the first update procedure, the OTA master 11 displays a first completion notification image on the HMI 18 after the activation process is completed. When the software update is performed using the second update procedure, the OTA master 11 displays a second completion notification image on the HMI 18 that is different from the first completion notification image after the activation process is completed. Specifically, the OTA master 11 displays in the first completion notification image that the power switch 24 can now be switched on, while displaying in the second completion notification image that the functions of the in-vehicle equipment that were restricted due to the activation process have become available. As a result, the user can easily understand which functions of the vehicle 10 whose restrictions are lifted upon completion of the activation process.
[0062] (12) The DCM12, ADAS13, and PCU14 are required to start operating immediately after the power switch 24 is switched from off to on. In this embodiment, the software update of the DCM12, ADAS13, and PCU14 is performed in a first update procedure in which the activation process is performed while the power switch 24 is off. Therefore, the time from when the power switch 24 is switched from off to on until the DCM12, ADAS13, and PCU14 start operating is not prolonged by the activation process. Thus, in this embodiment, the in-vehicle equipment whose software is updated in the first update procedure and the in-vehicle equipment whose software is updated in the second update procedure are classified according to the function of the in-vehicle equipment.
[0063] (13) In-vehicle device D1 equipped with a single-bank memory module 21A requires a longer activation process than in-vehicle device D2 equipped with a dual-bank memory module 21B. Therefore, if the activation process is started after the power switch 24 is switched from off to on, the functions of in-vehicle device D1 may be unavailable for a long time until the process is completed. In contrast to this, in this embodiment, among the in-vehicle devices other than DCM12, ADAS13, and PCU14, in-vehicle device D1 equipped with a single-bank memory module 21A undergoes a software update in the first update procedure. In contrast to the other in-vehicle devices, in-vehicle device D2 equipped with a dual-bank memory module 21B undergoes a software update in the second update procedure. Therefore, by performing the activation process, it is possible to avoid a long period of functional limitation of the in-vehicle device after the power switch 24 is switched from off to on.
[0064] (14) When a software update is performed in the first update procedure, the OTA master 11 starts the activation process of the in-vehicle equipment in response to the power switch 24 switching from on to off. Also, when a software update is performed in the second update procedure, the OTA master 11 starts the activation process of the in-vehicle equipment in response to the power switch 24 switching from off to on. Thus, in this embodiment, the OTA master 11 that manages the software update controls the display of information. Therefore, it is possible to accurately display information according to the progress of the software update.
[0065] (15) The OTA master 11 displays a first pre- and second confirmation image on the HMI 18 when the installation phase is complete. Furthermore, the OTA master 11 displays a first and second final confirmation image on the HMI 18 when the vehicle 10 is in a state where the power switch 24 can be switched from on to off. This makes it easy for the user to confirm that the activation process will be performed afterward.
[0066] <Correspondence> In this embodiment, the first pre-confirmation image and the first final confirmation image correspond to the first confirmation image, and the second pre-confirmation image and the second final confirmation image correspond to the second confirmation image. In this embodiment, the HMI 18 installed in the vehicle 10 corresponds to the display unit, and the OTA master 11 mounted on the vehicle 10 corresponds to the control unit.
[0067] In this embodiment, the driving power mode corresponds to the first power mode and the power mode in which the vehicle 10 is capable of driving. The parking power mode corresponds to the second power mode and the power mode in which the vehicle 10 is not capable of driving. Switching from the driving power mode to the parking power mode corresponds to the power mode switching in the first switching pattern, and switching from the parking power mode to the driving power mode corresponds to the power mode switching in the second switching pattern. Furthermore, in Figure 4, processes S10 and S14 correspond to the first display process, process S18 corresponds to the third display process, and process S20 corresponds to the fifth display process. Also, in Figure 9, processes S30 and S34 correspond to the second display process, process S37 corresponds to the fourth display process, and process S39 corresponds to the sixth display process.
[0068] (Second Embodiment) Next, a second embodiment of the control device, control method, and program will be described in detail with reference to Figures 14 and 15. In this embodiment, components common to the above embodiment are denoted by the same reference numerals, and their detailed descriptions are omitted.
[0069] In the first embodiment, the display control of information regarding software updates on the HMI 18 installed in the vehicle 10 was performed by an OTA master 11 also installed in the same vehicle 10. In this embodiment, information regarding software updates is displayed on the HMI 43 of the user-owned information terminal 40 in the vehicle 10. The display control is performed by an OTA server 30 in the data center.
[0070] <Activation process in the first update procedure> Figure 14 shows the processing flow of the activation phase when a software update is performed in the first update procedure in this embodiment. As shown in Figure 14, when the installation phase is completed, the OTA master 11 notifies the OTA server 30 (S50). When the OTA server 30 confirms the completion of the installation phase, it instructs the information terminal 40 to display the first pre-confirmation image (S51). The information terminal 40 displays the first pre-confirmation image on its HMI 43 in response to the instruction (S52). The first pre-confirmation image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 5.
[0071] When the user selects permission to perform the activation process on the information terminal 40 (S53), the information terminal 40 notifies the OTA server 30 that permission to perform the activation process has been granted (S54). Furthermore, the OTA server 30 notifies the vehicle 10's OTA master 11 that permission to perform the activation process has been granted (S55).
[0072] When the OTA master 11 becomes capable of switching the power switch 24 from on to off, it notifies the OTA server 30 of this state (S56). In response to this notification, the OTA server 30 instructs the information terminal 40 to display the first final confirmation image (S57). The information terminal 40 displays the first final confirmation image on its HMI 43 in response to the instruction (S58). The first final confirmation image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 6.
[0073] Subsequently, when the power switch 24 is switched from on to off, the OTA master 11 starts the activation process (S59). The OTA master 11 also notifies the OTA server 30 that the activation process has started (S60). Once the OTA server 30 confirms that the activation process has started, it instructs the information terminal 40 to display the first guidance image (S61). In response to the instruction, the information terminal 40 displays the first guidance image on its HMI 43 (S62). The first guidance image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 7.
[0074] When the OTA master 11 completes the activation process, it notifies the OTA server 30 (S63). Upon confirming the completion of the activation process, the OTA server 30 instructs the information terminal 40 to display the first completion notification image (S64). The information terminal 40 displays the first completion notification image on its HMI 43 in response to the instruction (S65). The first completion notification image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 8.
[0075] <Activation process in the second update procedure> Figure 15 shows the processing flow of the activation phase when a software update is performed in the second update procedure in this embodiment. As shown in Figure 15, when the installation phase is completed, the OTA master 11 notifies the OTA server 30 (S70). When the OTA server 30 confirms the completion of the installation phase, it instructs the information terminal 40 to display the second pre-confirmation image (S71). The information terminal 40 displays the first pre-confirmation image on its HMI 43 in response to the instruction (S72). The first pre-confirmation image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 10.
[0076] When the user selects permission to perform the activation process on the information terminal 40 (S73), the information terminal 40 notifies the OTA server 30 that permission to perform the activation process has been granted (S74). The OTA server 30 then notifies the vehicle 10's OTA master 11 that permission to perform the activation process has been granted (S75).
[0077] When the OTA master 11 becomes ready to switch the power switch 24 from on to off, it notifies the OTA server 30 of this (S76). In response to the notification, the OTA server 30 instructs the information terminal 40 to display the second final confirmation image (S77). In response to the instruction, the information terminal 40 displays the second final confirmation image on its HMI 43 (S78). The second final confirmation image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 11.
[0078] Subsequently, when the power switch 24 switches from on to off and then back to on, the OTA master 11 starts the activation process (S79). The OTA master 11 also notifies the OTA server 30 that the activation process has started (S80). Once the OTA server 30 confirms that the activation process has started, it instructs the information terminal 40 to display the second guidance image (S81). In response to the instruction, the information terminal 40 displays the second guidance image on its HMI 43 (S82). The second guidance image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 12.
[0079] When the OTA master 11 completes the activation process, it notifies the OTA master 11 of its completion (S83). When the OTA server 30 confirms the completion of the activation process, it instructs the information terminal 40 to display the second completion notification image (S84). The information terminal 40 displays the second completion notification image on its HMI 43 in response to the instruction (S85). The first completion notification image displayed on the HMI 43 of the information terminal 40 is as shown in Figure 13.
[0080] In this embodiment, the HMI 43 of the information terminal 40 corresponds to the display unit, and the OTA server 30 corresponds to the control unit. This embodiment provides the same or similar functions and effects as the first embodiment.
[0081] (Other embodiments) The above embodiment can be implemented with the following modifications. The above embodiment and the following modifications can be combined with each other to the extent that they do not contradict each other technically.
[0082] In addition to the display control of the vehicle 10's HMI 18 by the OTA master 11 in the first embodiment, the display control of the information terminal 40 by the OTA server 30 in the second embodiment may also be performed. In this case, both the OTA master 11 and the OTA server 30 correspond to control devices.
[0083] In the first embodiment, the display control of the HMI 18 of the vehicle 10 may be performed by the OTA server 30. • In the second embodiment, the display control of the information terminal 40 may be performed by the OTA master 11.
[0084] • In-vehicle devices that are subject to software updates may be configured to control the display of information related to the software update. The display examples shown in Figures 5-8 and 10-13 were configured to display information within the images using text. However, information may also be displayed within these images using non-textual methods such as still images or videos.
[0085] The configuration of the first completion notification image (Figure 8) and the second completion notification image (Figure 13) can be changed as appropriate. In the above embodiment, information indicating that the power switch 24 can be switched on was displayed in the first completion notification image, but this information may be omitted. Also, in the above embodiment, information indicating that the functions of the in-vehicle equipment that were restricted due to the activation process have become available, specifically information indicating that the vehicle 10 is now drivable, was displayed in the second completion notification image, but this display may be omitted. It is assumed that the user is aware of the content of the function restrictions during the activation process in both cases, whether the software update was performed using the first update procedure or the second update procedure. In this case, if the user knows whether the software update was performed using the first update procedure or the second update procedure, they can know which functions of the vehicle 10 will be unlocked and available upon completion of the activation process. Therefore, it is preferable that the first completion notification image and the second completion notification image be configured so that the user can understand that they are notifying the user of the completion of the activation process and can distinguish between the two images. If the first and second completion notification images are configured in this way, it becomes less likely that unexpected functional limitations will occur during the activation process, causing confusion for the user.
[0086] • Regardless of whether the software update is performed using the first or second update procedure, a common completion image may be displayed after the activation process is complete. • You may choose not to display the completion image after the activation process is finished.
[0087] The configuration of the first guidance image (Figure 7) and the second guidance image (Figure 12) can be changed as appropriate. For example, the display of information indicating the estimated time until the activation process is completed in the first / second guidance image may be omitted, or the display of information indicating that the power switch 24 cannot be switched on may be omitted in the first guidance image. The first and second guidance images should be configured so that the user can understand that the activation process is in progress and so that the user can distinguish between the two images.
[0088] • Regardless of whether the software update is performed using the first or second update procedure, a common guidance image may be displayed during the activation process. • You may choose not to display guidance images while the activation process is running.
[0089] The configurations of the first pre-confirmation image (Figure 5) and the second pre-confirmation image (Figure 10) can be changed as appropriate. For example, the display of information regarding the estimated time of the activation process in the first / second pre-confirmation image may be omitted. Also, information different from the examples shown may be displayed as information regarding the functional limitations associated with the activation process, or the display of functional limitation information may be omitted. Furthermore, in cases where the activation process is automatically executed without user permission, or where user permission has been obtained before the completion of the installation phase, the display of the option to allow or deny the start of the activation process may be omitted. In any case, it is sufficient that the user can recognize that the activation process is being notified in advance, and that the first pre-confirmation image and the second pre-confirmation image are configured as different images so that the user can distinguish between them. The same applies to the first final confirmation image (Figure 6) and the second final confirmation image (Figure 11).
[0090] In the above embodiment, the first / second pre-confirmation images were displayed when the installation phase was completed, and the first / second final confirmation images were displayed when the power switch 24 could be switched from on to off. It is also possible to display only one of the first / second pre-confirmation images and the first / second final confirmation images.
[0091] • The OTA master 11, which manages software updates, controlled the display of information related to software updates. Alternatively, software update management and the display control of information related to software updates could be handled by a separate in-vehicle device.
[0092] In the above embodiment, the activation process was performed either when switching from the driving power mode to the parking power mode, or when switching from the parking power mode to the driving power mode. If the vehicle 10's power modes include power modes other than the two above, the activation process may be performed in accordance with the power mode switching in a switching pattern other than those described above. If the power mode switching pattern for which the activation process is performed is different, the timing of the activation process will be different, resulting in differences in the tolerance and content of the functional limitations of the vehicle 10 that accompany its implementation. Therefore, it is desirable to display a different confirmation image for each power mode switching pattern for which the activation process is performed. Examples of power modes other than driving and parking include power modes that provide functions that cannot be provided in the normal parking power mode, such as entertainment functions and external power supply functions, while the vehicle is parked. In addition, multiple power modes may be included, each corresponding to the following IG (ignition) on state, ACC (accessory power) on state, and vehicle power off state. The IG on state is a state in which the vehicle's engine is running and the power to multiple ECUs is turned on. The ACC ON state is a state where only some ECUs are powered on, compared to the IG ON state. The vehicle power OFF state is a state where almost all ECUs are powered off.
[0093] The control device may be configured as a circuit including one or more processors that operate according to a computer program, one or more dedicated hardware circuits that perform at least some of the various processes, or a combination thereof. Examples of dedicated hardware include application-specific integrated circuits (ASICs). The processor includes a CPU and memory such as RAM and ROM, where memory stores program code or instructions configured to cause the CPU to perform processes. Memory, or storage medium, includes any available medium that can be accessed by a general-purpose or dedicated computer.
[0094] <Additional Notes> [Note 1] A control device for controlling a display unit that displays information regarding software updates for in-vehicle equipment installed in a vehicle having multiple switchable power modes, wherein when the software update is performed in a first update procedure in which an activation process to activate update software installed in the in-vehicle equipment is performed in accordance with the switching of the power mode in a first switching pattern, the control device displays a first confirmation image on the display unit before the start of the activation process, and when the software update is performed in a second update procedure in which the activation process is performed in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, the control device displays a second confirmation image different from the first confirmation image on the display unit before the start of the activation process.
[0095] [Note 2] The control device according to Note 1, wherein information regarding the functional limitations of the vehicle resulting from the activation process is displayed in the first confirmation image, and information different from the information displayed in the first confirmation image is displayed in the second confirmation image as information regarding the functional limitations.
[0096] [Note 3] The control device according to Note 1 or Note 2, wherein information regarding the period during which the functions of the vehicle are restricted due to the execution of the activation process is displayed in the first confirmation image, and information regarding a period different from the period for which information is displayed in the first confirmation image is displayed in the second confirmation image as information regarding the period during which the functions of the vehicle are restricted.
[0097] [Note 4] The control device according to any one of Notes 1 to 3, wherein the first confirmation image and the second confirmation image include a display indicating acceptance of a selection operation to allow or deny the commencement of the activation process.
[0098] [Note 5] A control device according to any one of Notes 1 to 4 that determines whether the software update is performed using the first update procedure or the second update procedure, based on the type of in-vehicle equipment to which the software update is to be performed.
[0099] [Appendix 6] A control device according to any one of Appendix 1 to 5 that determines whether the software update is performed in the first update procedure or the second update procedure, based on the type of software to be updated.
[0100] [Note 7] The in-vehicle equipment on which the software update is performed in the first update procedure and the in-vehicle equipment on which the software update is performed in the second update procedure are control devices as described in any of Notes 1 to 6, classified according to the function of the in-vehicle equipment.
[0101] [Note 8] A control device according to any one of Notes 1 to 7, wherein, when the software update is performed in the first update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the first switching pattern, and when the software update is performed in the second update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the second switching pattern.
[0102] [Note 9] The control device according to any one of Notes 1 to 8, wherein the switching of the power supply mode in the first switching pattern is a switch from a first power supply mode in which the vehicle is able to run to a second power supply mode in which the vehicle is not able to run, and the switching of the power supply mode in the second switching pattern is a switch from the second power supply mode to the first power supply mode.
[0103] [Note 10] The control device according to Note 9, wherein the switching of the power mode in the first switching pattern is performed in accordance with the switching of the vehicle's power switch from on to off, and the switching of the power mode in the second switching pattern is performed in accordance with the switching of the power switch from off to on.
[0104] [Note 11] The control device according to Note 9 or Note 10, which displays information in the first confirmation image about the estimated time from when the power mode is switched to the second power mode until the power mode can be switched back to the first power mode.
[0105] [Note 12] A control device according to any one of Notes 9 to 11, which displays information in the second confirmation image about the estimated time from when the power mode is switched from the second power mode to the first power mode until the activation process is completed.
[0106] [Note 13] A control device according to any one of Notes 9 to 12, wherein, when the software update is performed in the first update procedure, a first guidance image is displayed on the display unit during the activation process, and when the software update is performed in the second update procedure, a second guidance image different from the first guidance image is displayed on the display unit during the activation process.
[0107] [Note 14] The control device according to Note 13, which displays information in the first guide image indicating that the power mode cannot be switched to the first power mode. [Note 15] The control device according to Note 13 or Note 14, which displays information about the estimated time until the power mode can be switched to the first power mode in the first guide image.
[0108] [Note 16] A control device according to any one of Notes 13 to 15, which displays information on the estimated time until the activation process is completed within the second guidance image. [Note 17] A control device according to any one of Notes 9 to 16, wherein, when the software update is performed in the first update procedure, a first completion notification image is displayed on the display unit after the activation process is completed, and when the software update is performed in the second update procedure, a second completion notification image different from the first completion notification image is displayed on the display unit after the activation process is completed.
[0109] [Note 18] The control device according to Note 17, which displays information in the first completion notification image indicating that the power mode can be switched to the first power mode. [Note 19] The control device according to Note 17 or Note 18, which displays information in the second completion notification image indicating that the functions of the in-vehicle equipment that were restricted as a result of the activation process have become available.
[0110] [Note 20] The control device according to any one of Notes 9 to 19, wherein the in-vehicle device on which the software update is performed in the first update procedure is equipped with a single-bank storage module in which the updated software is installed in a storage area that stores the software before the update, and the in-vehicle device on which the software update is performed in the second update procedure is equipped with a dual-bank storage module in which the updated software is installed in a storage area separate from the storage area that stores the software before the update.
[0111] [Note 21] The data communication module for external vehicle communication is the control device described in any of Notes 9 to 20, which is the in-vehicle device on which the software update is performed in the second update procedure. [Note 22] The advanced driver assistance system is the control device described in any of Notes 9 to 21, which is the in-vehicle device on which the software update is performed in the second update procedure.
[0112] [Note 23] The power control unit of the vehicle is the control device described in any of Notes 9 to 22, which is the in-vehicle device on which the software update is performed in the second update procedure. [Note 24] The display unit is a control device described in any of Notes 1 to 23, which is installed in the vehicle.
[0113] [Note 25] The display unit is a control device according to any one of Notes 1 to 23, provided on an information terminal independent of the vehicle. [Note 26] The control device is a server device independent of the vehicle, as described in any of Notes 1 to 25.
[0114] [Note 27] A vehicle equipped with a control device as described in any one of the items in Notes 1 to 25. [Note 28] A control method for a display unit that displays progress information of software updates for in-vehicle equipment installed in a vehicle having multiple switchable power modes, wherein when the software update is performed in a first update procedure in which an activation process to activate update software installed in the in-vehicle equipment is performed in accordance with the switching of the power mode in a first switching pattern, a first confirmation image is displayed on the display unit before the start of the activation process, and when the software update is performed in a second update procedure in which the activation process is performed in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activation process.
[0115] [Note 29] The control method according to Note 28, wherein information regarding the functional limitations of the vehicle resulting from the activation process is displayed in the first confirmation image, and information different from the information displayed in the first confirmation image is displayed in the second confirmation image as information regarding the functional limitations.
[0116] [Note 30] The control method according to Note 28 or Note 29, wherein information regarding the period during which the functions of the vehicle are restricted due to the execution of the activation process is displayed in the first confirmation image, and information regarding a period different from the period for which information is displayed in the first confirmation image is displayed in the second confirmation image as information regarding the period during which the functions of the vehicle are restricted.
[0117] [Note 31] The control method according to any one of Notes 28 to 30, wherein the first confirmation image and the second confirmation image include a display indicating whether or not to allow the start of the activation process.
[0118] [Note 32] A control method according to any one of Notes 28 to 31, which determines whether the software update is performed using the first update procedure or the second update procedure, based on the type of in-vehicle equipment to which the software update is to be performed.
[0119] [Note 33] A control method according to any one of Notes 28 to 32 that determines whether the software update is performed in the first update procedure or the second update procedure, based on the type of software to be updated.
[0120] [Note 34] The in-vehicle device on which the software update is performed in the first update procedure and the in-vehicle device on which the software update is performed in the second update procedure are the control methods described in any of Notes 28 to 33, which are classified according to the function of the in-vehicle device.
[0121] [Note 35] The control method according to any one of Notes 28 to 34, wherein, when the software update is performed in the first update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the first switching pattern, and when the software update is performed in the second update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the second switching pattern.
[0122] [Note 36] The control method according to any one of Notes 28 to 35, wherein the switching of the power supply mode in the first switching pattern is a switch from a first power supply mode in which the vehicle is in a state where it can run to a second power supply mode in which the vehicle is in a state where it cannot run, and the switching of the power supply mode in the second switching pattern is a switch from the second power supply mode to the first power supply mode.
[0123] [Note 37] The control method according to Note 36, wherein the switching of the power mode in the first switching pattern is performed in accordance with the switching of the vehicle's power switch from on to off, and the switching of the power mode in the second switching pattern is performed in accordance with the switching of the power switch from off to on.
[0124] [Note 38] The control method according to Note 36 or Note 37, wherein information on the estimated time from when the power mode is switched to the second power mode until the power mode can be switched back to the first power mode is displayed in the first confirmation image.
[0125] [Note 39] The control method according to any one of Notes 36 to 38, wherein information on the estimated time from when the switching of the power mode from the second power mode to the first power mode is instructed until the activation process is completed is displayed in the second confirmation image.
[0126] [Note 40] The control method according to any one of Notes 36 to 39, wherein when the software update is performed in the first update procedure, the first guidance image is displayed on the display unit during the activation process, and when the software update is performed in the second update procedure, a second guidance image different from the first guidance image is displayed on the display unit during the activation process.
[0127] [Note 41] The control method according to Note 40, wherein information indicating that the power mode cannot be switched to the first power mode is displayed in the first guide image. [Note 42] The control method according to Note 40 or Note 41, wherein information on the estimated time until the power supply mode can be switched to the first power supply mode is displayed in the first guide image.
[0128] [Note 43] The control method according to any one of Notes 40 to 42, wherein information on the estimated time until the activation process is completed is displayed in the second guidance image. [Note 44] The control method according to any one of Notes 36 to 43, wherein, when the software update is performed in the first update procedure, a first completion notification image is displayed on the display unit after the activation process is completed, and when the software update is performed in the second update procedure, a second completion notification image different from the first completion notification image is displayed on the display unit after the activation process is completed.
[0129] [Note 45] The control method according to Note 44, wherein information indicating that the power mode can be switched to the first power mode is displayed in the first completion notification image. [Note 46] The control method according to Note 44 or Note 45, wherein information indicating that the functions of the in-vehicle equipment that were restricted as a result of the activation process have become available is displayed in the second completion notification image.
[0130] [Note 47] The control method according to any one of Notes 36 to 46, wherein the in-vehicle device on which the software update is performed in the first update procedure is equipped with a single-bank storage module in which the updated software is installed in a storage area that stores the software before the update, and the in-vehicle device on which the software update is performed in the second update procedure is equipped with a dual-bank storage module in which the updated software is installed in a storage area separate from the storage area that stores the software before the update.
[0131] [Note 48] The control method described in any of Notes 36 to 47, wherein the data communication module for external vehicle communication is the in-vehicle device on which the software update is performed in the second update procedure.
[0132] [Note 49] The advanced driver assistance system is the in-vehicle device on which the software update is performed in the second update procedure, as described in any of Notes 36 to 48. [Note 50] The power control unit of the vehicle is the in-vehicle device on which the software update is performed in the second update procedure, as described in any of Notes 36 to 49.
[0133] [Note 51] The display unit is the control method described in any of Notes 28 to 50 installed in the vehicle. [Note 52] The control method described in any of Notes 28 to 51, wherein the display unit is provided on an information terminal independent of the vehicle.
[0134] [Note 53] A program executed by a control device that controls a display unit that displays progress information of software updates for in-vehicle equipment installed in a vehicle having multiple switchable power modes, wherein when the software update is performed in a first update procedure in which an activation process to activate update software installed in the in-vehicle equipment is performed in accordance with the switching of the power mode in a first switching pattern, the program causes the control device to execute a first display process that displays a first confirmation image on the display unit before the start of the activation process, and when the software update is performed in a second update procedure in which the activation process is performed in accordance with the switching of the power mode in a second switching pattern different from the first switching pattern, the program causes the control device to execute a second display process that displays a second confirmation image different from the first confirmation image on the display unit before the start of the activation process.
[0135] [Note 54] The program as described in Note 53, wherein the first display process is a process of displaying information about the functional limitations of the vehicle in the first confirmation image, and the second display process is a process of displaying information different from the information displayed in the first confirmation image as information about the functional limitations in the second confirmation image.
[0136] [Note 55] The program as described in Note 53 or Note 54, wherein the first display process is a process of displaying information in the first confirmation image for a period during which the functions of the vehicle are restricted due to the execution of the activation process, and the second display process is a process of displaying information in the second confirmation image as information for a period different from the period during which the functions of the vehicle are restricted.
[0137] [Note 56] The program described in any of Notes 53 to 55, wherein the first display process is a process of displaying an acceptance display for a selection operation of whether or not to allow the start of the activation process within the first confirmation image, and the second display process is a process of displaying the acceptance display within the second confirmation image.
[0138] [Note 57] A program according to any one of Notes 53 to 56 that causes the control device to execute a process to determine whether the software update is performed using the first update procedure or the second update procedure, based on the type of in-vehicle device to which the software update is to be performed.
[0139] [Appendix 58] A program according to any one of Appendix 53 to 57 that causes the control device to execute a process to determine whether the software update is performed in the first update procedure or the second update procedure, based on the type of software to be updated.
[0140] [Note 59] If the software update is performed in the first update procedure, a process to start the activation process of the in-vehicle device in response to the switching of the power mode in the first switching pattern; if the software update is performed in the second update procedure, a process to start the activation process of the in-vehicle device in response to the switching of the power mode in the second switching pattern; and a program described in any of Notes 53 to 58 to be executed by the control device.
[0141] [Note 60] The program described in any of Notes 53 to 59, wherein the switching of the power supply mode in the first switching pattern is a switch from a first power supply mode in which the vehicle is able to run to a second power supply mode in which the vehicle is not able to run, and the switching of the power supply mode in the second switching pattern is a switch from the second power supply mode to the first power supply mode.
[0142] [Note 61] The program described in Note 60, wherein the switching of the power mode in the first switching pattern is performed in accordance with the switching of the vehicle's power switch from on to off, and the switching of the power mode in the second switching pattern is performed in accordance with the switching of the power switch from off to on.
[0143] [Note 62] The program described in Note 60 or Note 61, wherein the first display process is a process that displays information in the first confirmation image about the estimated time from when the power mode is switched to the second power mode until the power mode can be switched back to the first power mode.
[0144] [Note 62] The second display process is a program described in any of Notes 60 to 62, which displays information in the second confirmation image about the estimated time from when the power mode is switched from the second power mode to the first power mode until the activation process is completed.
[0145] [Note 63] A program according to any one of Notes 53 to 62 that causes the control device to perform a third display process, which displays a first guidance image on the display unit during the activation process, when the software update is performed in the first update procedure, and a fourth display process, which displays a second guidance image different from the first guidance image on the display unit during the activation process, when the software update is performed in the second update procedure.
[0146] [Note 64] The third display process is the program described in Note 63, which displays information in the first guide image indicating that the power mode cannot be switched to the first power mode.
[0147] [Note 65] The third display process is the program described in Note 63 or Note 64, which displays information about the estimated time until the power mode can be switched to the first power mode within the first guide image.
[0148] [Note 66] The fourth display process is a program described in any of Notes 63 to 65, which displays information about the estimated time until the activation process is completed within the second guidance image.
[0149] [Note 67] A program according to any one of Notes 53 to 66 that causes the control device to perform a fifth display process to display a first completion notification image on the display unit after the activation process is completed, when the software update is performed in the first update procedure, and a sixth display process to display a second completion notification image different from the first completion notification image on the display unit after the activation process is completed, when the software update is performed in the second update procedure.
[0150] [Note 68] The fifth display process is the program described in Note 67, which displays information in the first completion notification image indicating that the power mode can be switched to the first power mode.
[0151] [Note 69] The sixth display process is the program described in Note 67 or Note 68, which displays information in the second completion notification image indicating that the functions of the in-vehicle equipment that were restricted as a result of the activation process have become available.
[0152] [Note 70] A storage medium containing the program described in any of Notes 53 to 69. [Explanation of Symbols]
[0153] 10 vehicles 11. OTA Master (Control device, in-vehicle equipment) 12 DCM (In-vehicle equipment) 13 ADAS (vehicle equipment) 14 PCU (vehicle equipment) 15. Engine ECU (Onboard Equipment) 16. Transmission ECU (On-board equipment) 17. Brake ECU (On-board equipment) 18 HMI (vehicle equipment) 19 In-vehicle network 20 Mobile communications network 21 Memory Modules 22 processors 23 Data Storage 24 Power switch 30 OTA servers 31 Storage device 32 processors 40 Information terminals 41 Storage device 42 processors 43 HMI B,B1,B2 storage area
Claims
1. A control device that controls a display unit that displays information regarding software updates for in-vehicle equipment installed in a vehicle having multiple switchable power modes, When the software update is performed in a first update procedure in which an activation process to enable the update software installed on the in-vehicle device is performed in accordance with the switching of the power mode in the first switching pattern, a first confirmation image is displayed on the display unit before the start of the activation process. When the software update is performed in a second update procedure that performs the activation process in response to the switching of the power mode in a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the start of the activation process. A control device that performs this function.
2. The first confirmation image displays information regarding the functional limitations of the vehicle resulting from the activation process, and the second confirmation image displays information different from the information displayed in the first confirmation image as information regarding the functional limitations. The control device according to claim 1.
3. The control device according to claim 1, wherein information regarding the period during which the functions of the vehicle are restricted due to the execution of the activation process is displayed in the first confirmation image, and information regarding a period different from the period for which information is displayed in the first confirmation image is displayed in the second confirmation image as information regarding the period during which the functions of the vehicle are restricted.
4. The control device according to claim 1, wherein the first confirmation image and the second confirmation image include a display indicating acceptance of a selection operation to permit or deny the commencement of the activation process.
5. The control device according to claim 1, which determines whether the software update is performed using the first update procedure or the second update procedure, based on the type of in-vehicle device to which the software update is to be performed.
6. The control device according to claim 1, which determines whether the software update is performed using the first update procedure or the second update procedure, based on the type of software to be updated.
7. The control device according to claim 1, wherein the in-vehicle equipment on which the software update is performed in the first update procedure and the in-vehicle equipment on which the software update is performed in the second update procedure are classified according to the function of the in-vehicle equipment.
8. When the software update is performed in the first update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the first switching pattern. When the software update is performed in the second update procedure, the activation process of the in-vehicle device is started in response to the switching of the power mode in the second switching pattern. The control device according to claim 1, which performs the following:
9. The switching of the power mode in the first switching pattern is a switch from a first power mode in which the vehicle is in a state where it can run to a second power mode in which the vehicle is in a state where it cannot run. The power mode switching in the second switching pattern is a switch from the second power mode to the first power mode. The control device according to claim 1.
10. The switching of the power mode in the first switching pattern is performed in accordance with the switching of the vehicle's power switch from on to off. The power mode switching in the second switching pattern is performed in response to the switching of the power switch from off to on. The control device according to claim 9.
11. The control device according to claim 9, wherein information regarding the estimated time from when the power mode is switched to the second power mode until the power mode can be switched back to the first power mode is displayed in the first confirmation image.
12. The control device according to claim 9, wherein information regarding the estimated time from when a switch in the power mode from the second power mode to the first power mode is instructed until the activation process is completed is displayed in the second confirmation image.
13. When the software update is performed in the first update procedure, the first guidance image is displayed on the display unit during the activation process. When the software update is performed in the second update procedure, a second guide image different from the first guide image is displayed on the display unit during the activation process. The control device according to claim 9, which performs the following:
14. The control device according to claim 13, wherein information indicating that the power mode cannot be switched to the first power mode is displayed in the first guide image.
15. The control device according to claim 13, wherein information regarding the estimated time until the power mode can be switched to the first power mode is displayed in the first guide image.
16. The control device according to claim 13, wherein information regarding the estimated time until the completion of the activation process is displayed in the second guidance image.
17. When the software update is performed in the first update procedure, the first completion notification image is displayed on the display unit after the activation process is completed. When the software update is performed in the second update procedure, a second completion notification image different from the first completion notification image is displayed on the display unit after the activation process is completed. The control device according to claim 9, which performs the following:
18. The control device according to claim 17, wherein information indicating that the power mode can be switched to the first power mode is displayed in the first completion notification image.
19. The control device according to claim 17, wherein information indicating that the functions of the in-vehicle device that were restricted upon the execution of the activation process have become available is displayed in the second completion notification image.
20. The in-vehicle device on which the software update is performed in the first update procedure includes a single-bank storage module in which the updated software is installed in a storage area that stores the software before the update. The in-vehicle device on which the software update is performed in the second update procedure is equipped with a dual-bank storage module in which the updated software is installed in a storage area separate from the storage area that stores the software before the update. The control device according to claim 9 or 10.
21. The control device according to claim 9, wherein the data communication module for external vehicle communication is the in-vehicle device on which the software update is performed in the second update procedure.
22. The control device according to claim 9, wherein the advanced driver assistance system is the in-vehicle device on which the software update is performed in the second update procedure.
23. The control device according to claim 9, wherein the power control unit of the vehicle is the in-vehicle device on which the software update is performed in the second update procedure.
24. The control device according to claim 1, wherein the display unit is installed in the vehicle.
25. The control device according to claim 1, wherein the display unit is provided on an information terminal independent of the vehicle.
26. The control device according to claim 1, wherein the control device is a server device independent of the vehicle.
27. A vehicle equipped with the control device described in claim 1.
28. A control method for a display unit that displays progress information of software updates for in-vehicle equipment installed in a vehicle having multiple switchable power modes, When the software update is performed in a first update procedure in which the activation process for enabling the update software installed on the in-vehicle device is performed in accordance with the switching of the power mode in the first switching pattern, a first confirmation image is displayed on the display unit before the start of the activation process. When the software update is performed in a second update procedure that performs the activation process in response to a switch in the power mode using a second switching pattern different from the first switching pattern, a second confirmation image different from the first confirmation image is displayed on the display unit before the activation process begins. Control method.
29. A program executed by a control device that controls a display unit that displays progress information for software updates of in-vehicle equipment installed in a vehicle having multiple switchable power modes, When the software update is performed in a first update procedure in which an activation process to enable the update software installed on the in-vehicle device is performed in accordance with the switching of the power mode in a first switching pattern, a first display process is performed to display a first confirmation image on the display unit before the start of the activation process, When the software update is performed in a second update procedure that performs the activation process in response to the switching of the power mode in a second switching pattern different from the first switching pattern, a second display process is performed to display a second confirmation image different from the first confirmation image on the display unit before the start of the activation process. A program that causes the control device to execute the following.
Citation Information
Patent Citations
Electronic control device, electronic control system for vehicle, method for controlling execution of activation, and program for controlling execution of activation
JP2020027632A
Electronic control device, method for controlling execution of rewriting, and program for controlling execution of rewriting
JP2020027640A
Electronic control system for vehicle, and method and program for controlling execution of self holding of power source
JP2020027643A
OTA master, update control method, update control program, and OTA center
JP2022163396A
System for prior setting the function of car facilities by the prospect of driver's riding pattern and method therefor
KR1020190080253A