control system
The control system addresses the time inefficiency in software updates by dividing and encrypting update software for parallel decryption across multiple execution devices, enhancing the speed and efficiency of the update process.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- ADVICS CO LTD
- Filing Date
- 2022-09-27
- Publication Date
- 2026-05-11
AI Technical Summary
Existing software update systems for electronic control units in vehicles require significant time due to the need for an information processing device to wait for the decryption of divided update software parts, leading to prolonged standby states.
A control system that divides update software into multiple parts and transmits them encrypted over a global network, where each part is decrypted by different execution devices within the vehicle, allowing simultaneous decoding and writing to storage devices, reducing the time required for software updates.
The system significantly reduces the time needed for software updates by enabling parallel decryption and writing processes across multiple execution devices, thereby minimizing the standby time of the information processing device.
Smart Images

Figure 0007855982000001 
Figure 0007855982000002 
Figure 0007855982000003
Abstract
Description
Technical Field
[0001] The present invention relates to a control system provided in a vehicle.
Background Art
[0002] Patent Document 1 discloses a system having a function of updating software of a storage device included in an in-vehicle electronic control unit. In this system, when updating software, a Tester is connected to an in-vehicle network to which a plurality of electronic control units are connected. The Tester stores in advance update software for the electronic control unit to be updated. Therefore, when the Tester is connected to the in-vehicle network, the Tester transmits the update software to the electronic control unit to be updated via the in-vehicle network. As a result, in the electronic control unit, the software of the storage device is rewritten with the update software.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In recent years, systems have been developed to update the software in the storage device of an electronic control unit with update software transmitted to the vehicle via wireless communication from an external data center. This system includes an information processing device that acquires the update software transmitted from the data center to the vehicle. When updating the software, the information processing device transmits the update software to the electronic control unit to be updated via the in-vehicle network. At this time, in order to enhance the confidentiality of the information, the information processing device transmits encrypted update software to the electronic control unit. Therefore, the execution device of the electronic control unit decrypts the received update software and writes the decrypted update software to the storage device. The object of the present invention is to suppress the time required for software updates when updating the software of the storage device of an electronic control unit by transmitting encrypted update software to the electronic control unit via the in-vehicle network. [Means for solving the problem]
[0005] A control system for solving the above problems comprises an information processing device that acquires update software transmitted to the vehicle via wireless communication from outside the vehicle, and a global network that connects a plurality of electronic control devices and the information processing device in a communicative manner, and is configured to allow updating of the software in the storage device of the first electronic control device among the plurality of electronic control devices. The control system comprises a first execution device and a second execution device. When updating the software in the storage device of the first electronic control device with update software for the first electronic control device acquired by the information processing device, the information processing device divides the update software into multiple parts and transmits the divided update software to the global network in an encrypted state. The first execution device decrypts the first divided update software, which is one of the update software parts divided and transmitted to the global network by the information processing device. The second execution device decrypts the second divided update software, which is one of the update software parts divided and transmitted to the global network by the information processing device. The first execution device decodes the first update partition software, and the second execution device decodes the second update partition software, and these are written to the storage device of the first electronic control unit.
[0006] Consider a scenario where an information processing device acquires update software, divides it into multiple parts, and transmits these divided update software parts to the first electronic control unit via a global network. In this case, when the first electronic control unit receives the first update software part, its execution unit decodes it. The execution unit then writes the decoded first update software part to its storage device. During this time, the execution unit of the first electronic control unit cannot decode the second update software part, even if it is transmitted. Therefore, the information processing device cannot transmit the second update software part. In other words, the information processing device enters a standby state. The longer the information processing device remains in this standby state, the longer the time required to update the software in the storage device of the first electronic control unit.
[0007] In the control system described above, when the information processing unit transmits the first update partitioned software to the global network, the first execution unit decodes the first update partitioned software. While the first execution unit is decoded the first update partitioned software, the second execution unit waits for the second update partitioned software from the information processing unit. Therefore, while the first execution unit is decoded the first update partitioned software, the second execution unit can decode the second update partitioned software transmitted from the information processing unit. As a result, the time during which the information processing unit is in the aforementioned waiting state can be shortened.
[0008] Therefore, the above control system can suppress the time required for software updates when updating the software of the storage device of the first electronic control unit. [Brief explanation of the drawing]
[0009] [Figure 1] Figure 1 is a schematic diagram showing a vehicle equipped with the control system of the first embodiment and a data center located outside the vehicle. [Figure 2]In Figure 2, (A) is a diagram showing the first half of the processing flow executed by the information processing device of the control system of the first embodiment, (B) is a diagram showing the first half of the processing flow executed by the first electronic control device of the control system, and (C) is a diagram showing the first half of the processing flow executed by the second electronic control device of the control system. [Figure 3] In Figure 3, (A) is a diagram showing the latter half of the processing flow executed by the information processing device, (B) is a diagram showing the latter half of the processing flow executed by the first electronic control device, and (C) is a diagram showing the latter half of the processing flow executed by the second electronic control device. [Figure 4] In Figure 4, (A) to (D) are timing charts showing the process of updating the software of the memory device provided by the first braking ECU, which corresponds to the first electronic control unit. [Figure 5] In Figure 5, (A) is a diagram showing a part of the processing flow performed by the information processing device of the control system of the second embodiment, (B) is a diagram showing a part of the processing flow performed by the first electronic control device of the control system, and (C) is a diagram showing a part of the processing flow performed by the second electronic control device of the control system. [Figure 6] Figure 6 is a schematic diagram showing the control system of the third embodiment. [Figure 7] In Figure 7, (A) is a diagram showing the processing flow executed by the information processing device of the control system of the third embodiment, (B) is a diagram showing the processing flow executed by the first execution device of the first electronic control device of the control system, and (C) is a diagram showing the processing flow executed by the second execution device of the first electronic control device. [Figure 8] Figure 8 is a schematic diagram showing the control system of the fourth embodiment. [Figure 9] In Figure 9, (A) is a diagram showing a part of the processing flow performed by the information processing device of the control system of the fourth embodiment, (B) is a diagram showing a part of the processing flow performed by the first electronic control device of the control system, and (C) is a diagram showing a part of the processing flow performed by the second electronic control device of the control system. [Modes for carrying out the invention]
[0010] (First Embodiment) The first embodiment of the control system will be described below with reference to Figures 1 to 4. In this specification, the electronic control unit will be referred to as "ECU". "ECU" is an abbreviation for "Electronic Control Unit".
[0011] Figure 1 illustrates a vehicle 10 and a data center 100 located outside the vehicle 10. <Data Center> The data center 100 is configured to send and receive various types of information with the vehicle 10 via the external network 200. In other words, the data center 100 sends and receives various types of information with the vehicle 10 via wireless communication.
[0012] As will be explained in more detail later, vehicle 10 is equipped with multiple ECUs. When update software is available to update the storage software of any of the multiple ECUs, data center 100 transmits the update software to vehicle 10 via the external network 200. Among the multiple ECUs installed in vehicle 10, the ECU whose software is to be updated is referred to as the "ECU to be updated".
[0013] <Vehicle> Vehicle 10 is equipped with a control system 15 and actuators. Vehicle 10 is equipped with a first actuator 11 and a second actuator 12 as actuators. The first actuator 11 and the second actuator 12 operate to adjust the braking force generated in vehicle 10.
[0014] <Control System> The control system 15 includes a communication device 20 and an information processing device 30. The communication device 20 is the vehicle-side interface for sending and receiving information with the data center 100.
[0015] The information processing device 30 is configured to communicate with the communication device 20 via the local network 41. The local network 41 is a network for transmitting and receiving information only between the information processing device 30 and the communication device 20.
[0016] The information processing device 30 acquires the update software transmitted to the vehicle 10 from the data center 100 by wireless communication. Specifically, the information processing device 30 includes an execution device 31, a storage device 32, and a storage device 33. For example, the execution device 31 is a CPU, the storage device 32 is a non-volatile memory, and the storage device 33 is a volatile memory. The storage device 32 stores the software executed by the execution device 31. The storage device 33 temporarily stores the information transmitted from the communication device 20 via the local network 41. That is, when the data center 100 transmits the information for specifying the update target ECU and the update software to the vehicle 10, the communication device 20 receives the information transmitted by the data center 100. Then, the communication device 20 transmits the received information to the information processing device 30 via the local network 41. Then, the execution device 31 of the information processing device 30 stores the information received via the local network 41, that is, the information for specifying the update target ECU and the update software, in the storage device 33.
[0017] The control system 15 includes a global network 42 and a plurality of ECUs. The global network 42 is an in-vehicle network that communicably connects the information processing device 30 and the plurality of ECUs. For example, the global network 42 is a CAN bus. CAN is an abbreviation of "Controller Area Network".
[0018] The plurality of ECUs includes a first braking ECU 60 and a second braking ECU 70. The first braking ECU 60 and the second braking ECU 70 are ECUs that adjust the braking force generated in the vehicle 10. The first braking ECU 60 operates the first actuator 11. The second braking ECU 70 operates the second actuator 12. Note that the plurality of ECUs also includes another ECU 50 other than the braking ECU 60.
[0019] The control system 15 includes a local network 43 for transmitting and receiving information only between the first braking ECU 60 and the second braking ECU 70. The local network 43 is configured such that its communication speed is higher than the communication speed of the global network 42. Therefore, in the control system 15, when transmitting and receiving information between the first braking ECU 60 and the second braking ECU 70, either the global network 42 or the local network 43 can be used.
[0020] <ecu> Each ECU (Electronic Control Unit) is equipped with an execution unit, a memory device, and a storage device. For example, the execution unit is the CPU, the memory device is non-volatile memory, and the storage device is volatile memory. The memory device stores the software executed by the execution unit. The storage device temporarily stores the calculation results of the execution unit.
[0021] More specifically, the execution device 61 of the first braking ECU 60 controls the first actuator 11 by executing the software in the storage device 62. The execution device 61 temporarily stores the results of the calculations performed to control the first actuator 11 in the storage device 63.
[0022] The execution device 71 of the second braking ECU 70 controls the second actuator 12 by executing the software in the storage device 72. The execution device 71 temporarily stores the results of the calculations performed to control the second actuator 12 in the storage device 73.
[0023] <Software update process> This embodiment describes a method for updating the software of the storage device provided in the braking ECU. When the ECU to be updated is the first braking ECU 60, the first braking ECU 60 corresponds to the "first electronic control unit," and the second braking ECU 70 corresponds to the "second electronic control unit." In addition, the execution device 61 of the first braking ECU 60 corresponds to the "first execution device," and the execution device 71 of the second braking ECU 70 corresponds to the "second execution device."
[0024] Referring to Figures 2 and 3, the sequence of processes for updating the software of the storage device 62 of the first braking ECU 60 will be explained. Figures 2(A) and 3(A) show the processing routines executed by the execution device 31 of the information processing device 30. Figures 2(B) and 3(B) show the processing routines executed by the execution device 61 of the first braking ECU 60. Figures 2(C) and 3(C) show the processing routines executed by the execution device 71 of the second braking ECU 70. In other words, the processing routines shown in Figures 2(B) and 3(B) are the processing routines executed by the first electronic control unit, and the processing routines shown in Figures 2(C) and 3(C) are the processing routines executed by the second electronic control unit.
[0025] When the execution device 31 of the information processing device 30 obtains the update software for the first braking ECU 60, it starts executing the processing routine shown in Figures 2(A) and 3(A). In step S11, the execution device 31 requests both the first braking ECU 60 and the second braking ECU 70 to change the control mode of the execution device from normal mode to update mode. Normal mode is the control mode used when controlling the actuator. Update mode is the control mode used when updating the software of the storage device.
[0026] In the next step S13, the execution device 31 of the information processing device 30 determines whether it has received notification from both the first braking ECU 60 and the second braking ECU 70 that the mode change has been completed. If the execution device 31 has received the notification from both the first braking ECU 60 and the second braking ECU 70 (S13: YES), it proceeds to step S15. On the other hand, if the execution device 31 has not received the notification from at least one of the first braking ECU 60 and the second braking ECU 70 (S13: NO), it returns to step S11. In other words, the execution device 31 continues to request a mode change from the first braking ECU 60 and the second braking ECU 70 until it receives the notification from both of them.
[0027] As shown in Figures 2(B) and 3(B), in step S101, the execution device 61 of the first braking ECU 60 determines whether or not it has received a request for a mode change from the information processing device 30. If the execution device 61 has received a request for a mode change (S101: YES), it proceeds to step S103. On the other hand, if the execution device 61 has not received a request for a mode change (S101: NO), it repeatedly performs the determination in step S101 until it receives a request. In step S103, the execution device 61 resets itself, changes the control mode to update mode, and restarts. Subsequently, in step S105, the execution device 61 sends a notification to the information processing device 30 indicating that the change from normal mode to update mode is complete. Specifically, the execution device 61 sends this notification to the information processing device 30 via the global network 42. In the next step S107, the execution device 61 starts erasing the pre-update software from the storage device 62. Subsequently, the execution device 61 proceeds to step S109.
[0028] As shown in Figures 2(C) and 3(C), in step S201, the execution device 71 of the second braking ECU 70 determines whether or not it has received a request for a mode change from the information processing device 30. If the execution device 71 has received a request for a mode change (S201: YES), it proceeds to step S203. On the other hand, if the execution device 71 has not received a request for a mode change (S201: NO), it repeatedly performs the determination in step S201 until it receives a request. In step S203, the execution device 71 resets itself, changes the control mode to update mode, and restarts. Subsequently, in step S205, the execution device 71 sends a notification to the information processing device 30 indicating that the change from normal mode to update mode is complete. Specifically, the execution device 71 sends this notification to the information processing device 30 via the global network 42. Then, the execution device 71 proceeds to step S207.
[0029] As shown in Figures 2(A) and 3(A), in step S15, the execution device 31 of the information processing device 30 sets the count M to 1. Then, the execution device 31 divides the update software for the first braking ECU 60 into N parts. "N" is an integer of 3 or more. Then, in step S17, the execution device 31 transmits the Mth update division software, which is one of the N divisions of the update software, to the first braking ECU 60 via the global network 42. At this time, the execution device 31 transmits the encrypted Mth update division software to the first braking ECU 60 via the global network 42. Note that if the count M is 1, the execution device 31 transmits the encrypted first update division software to the first braking ECU 60.
[0030] In step S19, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S21, the execution device 31 transmits the Mth update split software, which is one of the N split update software pieces, to the second braking ECU 70 via the global network 42. At this time, the execution device 31 transmits the encrypted Mth update split software to the second braking ECU 70 via the global network 42. The update split software transmitted to the second braking ECU 70 here is different from the update split software transmitted to the first braking ECU 60 in step S17. If the count M is 2, the execution device 31 transmits the encrypted second update split software to the second braking ECU 70.
[0031] In step S23, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S25, the execution device 31 determines whether the transmission of the update split software has been completed. In this embodiment, if the count M is greater than the number of splits N, the execution device 31 determines that the transmission of N update split software has been completed. On the other hand, if the count M is less than or equal to the number of splits N, the execution device 31 determines that the transmission of the update split software has not been completed because there is still update split software among the N update split software that has not been transmitted. If the transmission of the update split software is completed (S25: YES), the execution device 31 proceeds to step S27. On the other hand, if the transmission of the update split software is not completed (S25: NO), the execution device 31 returns to step S17. That is, the execution device 31 continues to transmit the update split software.
[0032] As shown in Figures 2(B) and 3(B), in step S109, the execution device 61 of the first braking ECU 60 determines whether or not it has received the Mth update split software from the global network 42. If the count M is 1, the execution device 61 determines whether or not it has received the first update split software. If the execution device 61 has received the Mth update split software (S109: YES), it proceeds to step S111. On the other hand, if the execution device 61 has not received the Mth update split software (S109: NO), it repeatedly performs the determination in step S109 until it receives the Mth update split software.
[0033] In step S111, the execution device 61 of the first braking ECU 60 decodes the Mth update segment software received from the information processing device 30. Then, in step S113, the execution device 61 writes the Mth update segment software that it has decoded to the storage device 62. For example, if the count M is 1, the execution device 61 decodes the first update segment software and writes the decoded first update segment software to the storage device 62. After that, the execution device 61 proceeds to step S115.
[0034] As shown in Figures 2(C) and 3(C), in step S207, the execution device 71 of the second braking ECU 70 determines whether or not it has received the Mth update split software from the global network 42. If the count M is 2, the execution device 71 determines whether or not it has received the second update split software. If the execution device 71 has received the Mth update split software (S207: YES), it proceeds to step S209. On the other hand, if the execution device 71 has not received the Mth update split software (S207: NO), it repeatedly performs the determination in step S207 until it receives the Mth update split software.
[0035] In step S209, the execution device 71 of the second braking ECU 70 decodes the Mth update segment software received from the information processing device 30. Then, in step S211, the execution device 71 transmits the decoded Mth update segment software to the first braking ECU 60 via the local network 43. For example, if the count M is 2, the execution device 71 decodes the second update segment software and transmits the decoded second update segment software to the first braking ECU 60 via the local network 43. After that, the execution device 71 proceeds to step S213.
[0036] In step S213, the execution device 71 of the second braking ECU 70 determines whether the software update of the storage device 62 of the first braking ECU 60 is complete. If the update is complete (S213: YES), the execution device 71 proceeds to step S215. On the other hand, if the update is not complete (S213: NO), the execution device 71 returns to step S207. In other words, the execution device 71 repeatedly executes the processes from step S207 to step S211 until the software update of the storage device 62 is complete.
[0037] As shown in Figures 2(B) and 3(B), in step S115, the execution device 61 of the first braking ECU 60 determines whether or not it has received the decoded Mth update split software from the second braking ECU 70 via the local network 43. If the execution device 61 has received the Mth update split software from the second braking ECU 70 (S115: YES), it proceeds to step S117. On the other hand, if the execution device 61 has not received the Mth update split software from the second braking ECU 70 (S115: NO), it repeatedly performs the determination in step S115 until it receives the Mth update split software from the second braking ECU 70. In step S117, the execution device 61 writes the decoded Mth update split software received from the second braking ECU 70 to the storage device 62. For example, if the count M is 2, the execution device 61 receives the decoded second update split software from the second braking ECU 70 via the local network 43 and writes the second update split software to the storage device 62. After that, the execution device 61 proceeds to step S119.
[0038] In step S119, the execution device 61 of the first braking ECU 60 determines whether the software update of the storage device 62 is complete. If the update is complete (S119: YES), the execution device 61 proceeds to step S121. On the other hand, if the update is not complete (S119: NO), the execution device 61 returns to step S109. In other words, the execution device 61 repeatedly executes the processes from step S109 to step S117 until the software update of the storage device 62 is complete.
[0039] As shown in Figures 2(A) and 3(A), in step S27, the execution device 31 of the information processing device 30 requests both the first braking ECU 60 and the second braking ECU 70 to change the control mode of the execution device from update mode to normal mode. In step S29, the execution device 31 determines whether it has received notification from either the first braking ECU 60 or the second braking ECU 70 that the mode change has been completed. If the execution device 31 has received the notification from either the first braking ECU 60 or the second braking ECU 70 (S29: YES), it terminates the processing routine shown in Figures 2(A) and 3(A). On the other hand, if the execution device 31 has not received the notification from at least one of the first braking ECU 60 or the second braking ECU 70 (S29: NO), it returns to step S27. In other words, the execution device 31 continues to request a mode change from the first braking ECU 60 and the second braking ECU 70 until it receives the above notification from either the first braking ECU 60 or the second braking ECU 70.
[0040] As shown in Figures 2(B) and 3(B), in step S121, the execution device 61 of the first braking ECU 60 determines whether or not it has received a mode change request from the information processing device 30. If the execution device 61 has received a mode change request (S121: YES), it proceeds to step S123. On the other hand, if the execution device 61 has not received a mode change request (S121: NO), it repeatedly performs the determination in step S121 until it receives a request. In step S123, the execution device 61 resets itself, changes the control mode from update mode to normal mode, and restarts. Subsequently, in step S125, the execution device 61 sends a notification to the information processing device 30 indicating that the change from update mode to normal mode is complete. After that, the execution device 61 terminates the processing routine shown in Figures 2(B) and 3(B).
[0041] As shown in Figures 2(C) and 3(C), in step S215, the execution device 71 of the second braking ECU 70 determines whether or not it has received a mode change request from the information processing device 30. If the execution device 71 has received a mode change request (S215: YES), it proceeds to step S217. On the other hand, if the execution device 71 has not received a mode change request (S215: NO), it repeatedly performs the determination in step S215 until it receives a request. In step S217, the execution device 71 resets itself, changes the control mode from update mode to normal mode, and restarts. Subsequently, in step S219, the execution device 71 sends a notification to the information processing device 30 indicating that the change from update mode to normal mode is complete. After that, the execution device 71 terminates the processing routine shown in Figures 2(C) and 3(C).
[0042] Furthermore, the control system 15 may update the software of the storage device 72 of the second braking ECU 70. In this case, the second braking ECU 70 becomes the ECU to be updated, so the second braking ECU 70 corresponds to the "first electronic control unit" and the first braking ECU 60 corresponds to the "second electronic control unit". Also, the execution device 71 of the second braking ECU 70 corresponds to the "first execution device" and the execution device 61 of the first braking ECU 60 corresponds to the "second execution device". Therefore, the execution device 71 of the second braking ECU 70 executes the processing routines shown in Figures 2(B) and 3(B), and the execution device 61 of the first braking ECU 60 executes the processing routines shown in Figures 2(C) and 3(C).
[0043] <Operation and Effects of This Embodiment> Referring to Figure 4, the process of updating the software of the storage device 62 of the first braking ECU 60 will be explained. For the sake of ease of explanation, it will be assumed that the number of divisions N of the update software is 6.
[0044] When updating the software of the storage device 62, as shown in Figure 4(C), the first braking ECU 60 begins erasing the pre-update software from the storage device 62 at timing t11. Then, the information processing device 30 divides the update software into six parts. That is, six update split software A1 to A6 are generated. Then, as shown in Figures 4(A) and (B), at timing t12, the encrypted first update split software A1 is sent to the first braking ECU 60 via the global network 42. Subsequently, as shown in Figures 4(A) and (D), at timing t13, the information processing device 30 sends the encrypted second update split software A2 to the second braking ECU 70 via the global network 42.
[0045] In the first braking ECU 60, upon receiving the first update split software A1, the first update split software A1 is decoded. In the example shown in Figure 4, the process of erasing the update split software is executed until timing t15. Therefore, from timing t15, writing of the decoded first update split software A1 to the storage device 62 begins.
[0046] Meanwhile, in the second braking ECU 70, upon receiving the second update split software A2 via the global network 42, the second update split software A2 is decoded. That is, even while the first braking ECU 60 is decoded the first update split software A1, the second braking ECU 70 can decode the second update split software A2. In the second braking ECU 70, once the second update split software A2 is decoded, as shown in Figures 4(B) and (D), the decoded second update split software A2 is transmitted to the first braking ECU 60 via the local network 43 from timing t14. As shown in Figure 4(C), in the first braking ECU 60, after the first update split software A1 has been written to the storage device 62, the writing of the second update split software A2 to the storage device 62 begins.
[0047] Once the first braking ECU 60 has finished writing the second update split software A2 to the storage device 62, the information processing device 30 sends the encrypted third update split software A3 to the first braking ECU 60. In this case as well, the third update split software A3 is sent to the first braking ECU 60 via the global network 42. Subsequently, the information processing device 30 sends the encrypted fourth update split software A4 to the second braking ECU 70. In this case as well, the fourth update split software A4 is sent to the second braking ECU 70 via the global network 42.
[0048] When the first braking ECU 60 receives the third update split software A3, it decodes the third update split software A3. Then, the decoded third update split software A3 is written to the storage device 62.
[0049] In the second braking ECU 70, upon receiving the fourth update split software A4, the fourth update split software A4 is decoded. That is, even while the third update split software A3 is being decoded in the first braking ECU 60, the second braking ECU 70 can decode the fourth update split software A4. Once the fourth update split software A4 is decoded, the decoded fourth update split software A4 is transmitted to the first braking ECU 60 via the local network 43. In the first braking ECU 60, the fourth update split software A4 is written to the storage device 62 after the third update split software A3 has been written to the storage device 62.
[0050] Once the first braking ECU 60 has finished writing the fourth update split software A4 to the storage device 62, the information processing device 30 transmits the encrypted fifth update split software A5 to the first braking ECU 60. In this case as well, the fifth update split software A5 is transmitted to the first braking ECU 60 via the global network 42. After the fifth update split software A5 is transmitted, the information processing device 30 transmits the encrypted sixth update split software A6 to the second braking ECU 70. In this case as well, the sixth update split software A6 is transmitted to the second braking ECU 70 via the global network 42.
[0051] When the first braking ECU 60 receives the fifth update split software A5, it decodes the fifth update split software A5. Then, the decoded fifth update split software A5 is written to the storage device 62.
[0052] In the second braking ECU 70, upon receiving the sixth update split software A6, the sixth update split software A6 is decoded. That is, even while the fifth update split software A5 is being decoded in the first braking ECU 60, the second braking ECU 70 can decode the sixth update split software A6. Once the sixth update split software A6 is decoded, the decoded sixth update split software A6 is transmitted to the first braking ECU 60 via the local network 43. In the first braking ECU 60, the sixth update split software A6 is written to the storage device 62 after the fifth update split software A5 has been written to the storage device 62. This completes the software update of the storage device 62.
[0053] In this embodiment, the following effects can be obtained. (1-1) When the information processing device 30 transmits the first update split software A1 to the first braking ECU 60, it transmits the next update split software (in this case, the second update split software A2) to the second braking ECU 70. While the execution device 61 of the first braking ECU 60 decodes the first update split software A1, the execution device 71 of the second braking ECU 70 can decode the second update split software A2. In other words, the information processing device 30 does not have to wait for the transmission of the second update split software A2 until the decoding of the first update split software A1 is complete. This means that the time during which the information processing device 30 is in a state of waiting for the transmission of update split software can be shortened. Therefore, when the control system 15 updates the software in the storage device 62 of the first braking ECU 60, it is possible to suppress the time required for software updates from becoming longer.
[0054] (1-2) In the control system 15, multiple execution devices 61 and 71 share the task of decoding the update-ready divided software. Therefore, compared to the case where only one execution device decodes N update-ready divided software files, the burden on the execution device during software updates can be reduced.
[0055] (1-3) The second braking ECU 70 transmits the decoded update split software to the first braking ECU 60 via the local network 43. Therefore, the transmission time can be shortened compared to when the update split software is transmitted between the second braking ECU 70 and the first braking ECU 60 via the global network 42. This contributes to shortening the time required for software updates.
[0056] (Second Embodiment) A second embodiment of the control system will be described with reference to Figure 5. Note that the second embodiment differs from the first embodiment in that the update split software is not directly transmitted from the information processing device to the second electronic control device. In the following description, the differences from the first embodiment will be primarily explained, and the same reference numerals will be used for components identical to those in the first embodiment to avoid redundant explanations.
[0057] Referring to Figure 5, the sequence of processes for updating the software of the storage device 62 of the first braking ECU 60 will be explained. Figure 5(A) shows a part of the processing routine executed by the execution device 31 of the information processing device 30. Figure 5(B) shows a part of the processing routine executed by the execution device 61 of the first braking ECU 60. Figure 5(C) shows a part of the processing routine executed by the execution device 71 of the second braking ECU 70. In other words, the processing routine shown in Figure 5(B) is a part of the processing routine executed by the first electronic control unit, and the processing routine shown in Figure 5(C) is a part of the processing routine executed by the second electronic control unit.
[0058] When the execution device 31 of the information processing device 30 obtains the update software for the first braking ECU 60, it sequentially executes the processes of steps S11 and S13 shown in Figures 2(A) and 3(A). Subsequently, as shown in Figure 5(A), in step S15A, the execution device 31 of the information processing device 30 sets the count M to 1. Then, the execution device 31 divides the update software for the first braking ECU 60 into N parts. "N" is an integer of 3 or more. Then, in step S17A, the execution device 31 transmits the Mth update division software, which is one of the N divisions of the update software, to the first braking ECU 60 via the global network 42. At this time, the execution device 31 transmits the encrypted Mth update division software to the first braking ECU 60 via the global network 42. Note that if the count M is 1, the execution device 31 transmits the encrypted first update division software to the first braking ECU 60.
[0059] In step S19A, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S21A, the execution device 31 transmits the Mth update split software, which is one of the split update software, to the first braking ECU 60 via the global network 42. At this time, the execution device 31 transmits the encrypted Mth update split software to the first braking ECU 60 via the global network 42. The update split software transmitted to the first braking ECU 60 here is different from the update split software transmitted to the first braking ECU 60 in step S17A. If the count M is 2, the execution device 31 transmits the encrypted second update split software to the second braking ECU 70.
[0060] In step S23A, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S25A, the execution device 31 determines whether the transmission of N update split software has been completed, similar to step S25 shown in Figures 2(A) and 3(A). If there is still update split software among the N update split software that has not yet been transmitted (S25A: NO), the execution device 31 returns to step S17A. That is, the execution device 31 continues to transmit the update split software. On the other hand, if the transmission of N update split software has been completed (S25A: YES), the execution device 31 proceeds to step S27 shown in Figures 2(A) and 3(A). The flow of processing from step S27 onward is the same as in the first embodiment.
[0061] The execution device 61 of the first braking ECU 60 sequentially executes the processes from step S101 to step S107 shown in Figures 2(B) and 3(B). Then, as shown in Figure 5(B), in step S131, the execution device 61 determines whether or not it has received the Mth update division software transmitted by the information processing device 30 in step S17A from the global network 42. If the count M is 1, the execution device 61 determines whether or not it has received the first update division software A1. If the execution device 61 has received the Mth update division software (S131: YES), it proceeds to step S133. On the other hand, if the execution device 61 has not received the Mth update division software (S131: NO), it repeatedly performs the determination in step S131 until it receives the Mth update division software.
[0062] In step S133, the execution device 61 of the first braking ECU 60 determines whether it has received the Mth update split software transmitted by the information processing device 30 in step S21A from the global network 42. If the count M is 2, the execution device 61 determines whether it has received the second update split software A2. If the execution device 61 has received the Mth update split software (S133: YES), it proceeds to step S135. On the other hand, if the execution device 61 has not received the Mth update split software (S133: NO), it repeatedly performs the determination in step S133 until it receives the Mth update split software.
[0063] In step S135, the execution device 61 of the first braking ECU 60 transmits the Mth update split software received in step S133 to the second braking ECU 70 via the local network 43. For example, if the first braking ECU 60 receives the first update split software A1 and the second update split software A2, the execution device 61 transmits only the second update split software A2 of the two update split software A1 and A2 to the second braking ECU 70 via the local network 43.
[0064] In step S137, the execution device 61 of the first braking ECU 60 decodes the Mth update split software received in step S131. That is, the execution device 61 decodes the update split software that was not sent to the second braking ECU 70 from the two update split software files received from the information processing device 30. In the next step S139, the execution device 61 writes the Mth update split software that it decoded into the storage device 62. Then, the execution device 61 moves the process to step S141.
[0065] The execution device 71 of the second braking ECU 70 sequentially executes the processes from steps S201 to S205 shown in Figures 2(C) and 3(C). Then, as shown in Figure 5(C), in step S231, the execution device 71 determines whether or not it has received the Mth update split software via the local network 43. If the count M is 2, the execution device 71 determines whether or not it has received the second update split software A2. The update split software received here is the update split software transmitted by the information processing device 30 in step S21A. If the execution device 71 has received the Mth update split software (S231: YES), it proceeds to step S233. On the other hand, if the execution device 71 has not received the Mth update split software (S231: NO), it repeatedly performs the determination in step S231 until it receives the Mth update split software.
[0066] In step S233, the execution device 71 of the second braking ECU 70 decodes the received Mth update segment software. Then, in step S235, the execution device 71 transmits the decoded Mth update segment software to the first braking ECU 60 via the local network 43. For example, if the count M is 2, the execution device 71 decodes the second update segment software A2 and transmits the decoded second update segment software A2 to the first braking ECU 60 via the local network 43. After that, the execution device 71 proceeds to step S237.
[0067] In step S237, the execution device 71 of the second braking ECU 70 determines whether the software update of the storage device 62 of the first braking ECU 60 has been completed. If the update is not completed (S237: NO), the execution device 71 returns to step S231. That is, the execution device 71 repeatedly executes the processes from step S231 to step S235 until the software update of the storage device 62 is completed. On the other hand, if the update is completed (S237: YES), the execution device 71 proceeds to step S215 shown in Figures 2(C) and 3(C). The flow of processing from step S215 onward is the same as in the first embodiment.
[0068] As shown in Figure 5(B), in step S141, the execution device 61 of the first braking ECU 60 determines whether or not it has received the Mth update split software from the second braking ECU 70 via the local network 43. If the execution device 61 has received the Mth update split software (S141: YES), it proceeds to step S143. On the other hand, if the execution device 61 has not received the Mth update split software (S141: NO), it repeatedly performs the determination in step S141 until it receives the Mth update split software.
[0069] In step S143, the execution device 61 of the first braking ECU 60 writes the Mth update split software received in step S141 to the storage device 62. That is, the execution device 61 writes the decoded Mth update split software transmitted from the second braking ECU 70 to the storage device 62. Then, in step S145, the execution device 61 determines whether the software update of the storage device 62 is complete. If the update is not complete (S145: NO), the execution device 61 returns to step S131. That is, the execution device 61 repeatedly executes the processes from step S131 to step S143 until the software update of the storage device 62 is complete. On the other hand, if the update is complete (S145: YES), the execution device 61 proceeds to step S121 shown in Figures 2(B) and 3(B). The flow of processing from step S121 onwards is the same as in the first embodiment.
[0070] <Operation and Effects of This Embodiment> This section will explain the operation and effects of this embodiment, focusing on the differences from those of the first embodiment. When updating the software of the storage device 62 of the first braking ECU 60, the information processing device 30 divides the update software into N parts. The information processing device 30 sends the N parts of the update software to the first braking ECU 60, which is the ECU to be updated, via the global network 42. In this embodiment, two parts of the update software are sent to the first braking ECU 60 via the global network 42.
[0071] In the first braking ECU 60, one of the two received update split software files is transmitted to the second braking ECU 70 via the local network 43. The first braking ECU 60 also decodes the update split software file that was not transmitted to the second braking ECU 70. The decoded update split software file by the execution device 61 is then written to the storage device 62.
[0072] Meanwhile, in the second braking ECU 70, the update split software received via the local network 43 is decoded. The decoded update split software is then transmitted to the first braking ECU 60 via the local network 43. In the first braking ECU 60, the decoded update split software received via the local network 43 is written to the storage device 62.
[0073] By repeating this series of processes, the software in the storage device 62 of the first braking ECU 60 is updated. In this embodiment, while the first update split software A1 is being decoded in the first braking ECU 60, the second update split software A2 can also be decoded in the second braking ECU 70. That is, the information processing device 30 does not have to wait for the transmission of the second update split software A2 until the decoding of the first update split software A1 is complete. In other words, the time that the information processing device 30 spends waiting for the transmission of the update split software can be shortened. Therefore, when the control system 15 updates the software in the storage device 62 of the first braking ECU 60, it is possible to suppress the time required for software updates from becoming longer.
[0074] Furthermore, in this embodiment, the information processing device 30 does not need to directly transmit a portion of the N update partitioned software to the second braking ECU 70, which is not the ECU to be updated. Furthermore, in this embodiment, effects equivalent to those of the first embodiment (1-2) and (1-3) can be obtained.
[0075] (Third embodiment) A third embodiment of the control system will be described with reference to Figures 6 and 7. Note that the third embodiment differs from the first embodiment in that the ECU to be updated is a multi-core processor equipped with multiple execution devices. In the following description, the differences from the above embodiments will be primarily explained, and the same reference numerals will be used for components identical to those in the above embodiments to avoid redundant explanations.
[0076] <Control System> The control system 15B of this embodiment will be described with reference to Figure 6. The control system 15B comprises a communication device 20, an information processing device 30, and a plurality of ECUs. The plurality of ECUs are configured to communicate with the information processing device 30 via a global network 42. The plurality of ECUs include ECU 80 and ECU 50. For example, ECU 80 is a braking ECU that controls actuators to adjust the braking force generated in the vehicle 10.
[0077] The ECU80 is a multicore processor. The ECU80 comprises a first execution unit 81A, a second execution unit 81B, a storage device 82, and a storage device 83. For example, the first execution unit 81A and the second execution unit 81B are CPUs, the storage device 82 is non-volatile memory, and the storage device 83 is volatile memory. The storage device 82 stores the software executed by the first execution unit 81A and the second execution unit 81B.
[0078] <Software update process> Referring to Figure 7, the following describes the sequence of processes for updating the software of the storage device 82 in the ECU 80. Figure 7(A) shows the processing routine executed by the execution device 31 of the information processing device 30. Figure 7(B) shows the processing routine executed by the first execution device 81A of the ECU 80. Figure 7(C) shows the processing routine executed by the second execution device 81B of the ECU 80.
[0079] When the execution device 31 of the information processing device 30 obtains update software for the ECU 80, it starts executing the processing routine shown in Figure 7(A). In step S41, the execution device 31 requests the ECU 80 to change the control mode of the execution device from normal mode to update mode. In the next step S43, the execution device 31 determines whether it has received either a first notification indicating that the control mode of the first execution device 81A has been changed to update mode, or a second notification indicating that the control mode of the second execution device 81B has been changed to update mode. If the execution device 31 has received both the first and second notifications (S43: YES), it proceeds to step S45. On the other hand, if the execution device 31 has not received at least one of the first and second notifications (S43: NO), it returns to step S41. In other words, the execution device 31 continues to request the mode change from the ECU 80 until it receives either the first or second notification.
[0080] As shown in Figure 7(B), in step S151A, the first execution device 81A of the ECU 80 determines whether the ECU 80 has received a mode change request from the information processing device 30. If the ECU 80 has received a mode change request (S151A: YES), the first execution device 81A proceeds to step S153A. On the other hand, if the ECU 80 has not received a mode change request (S151A: NO), the first execution device 81A repeatedly performs the determination in step S151A until the ECU 80 receives the request. In step S153A, the first execution device 81A resets itself, changes the control mode to update mode, and restarts. Subsequently, in step S155A, the first execution device 81A sends a first notification to the information processing device 30 indicating that the change from normal mode to update mode is complete. In the next step S157A, the first execution device 81A starts erasing the pre-update software from the storage device 82. Subsequently, the first execution device 81A proceeds to step S159A.
[0081] As shown in Figure 7(C), in step S151B, the second execution device 81B of the ECU 80 determines whether the ECU 80 has received a mode change request from the information processing device 30. If the ECU 80 has received a mode change request (S151B: YES), the second execution device 81B proceeds to step S153B. On the other hand, if the ECU 80 has not received a mode change request (S151B: NO), the second execution device 81B repeatedly performs the determination in step S151B until the ECU 80 receives the request. In step S153B, the second execution device 81B resets itself, changes the control mode to update mode, and restarts. Subsequently, in step S155B, the second execution device 81B sends a second notification to the information processing device 30 indicating that the change from normal mode to update mode is complete. Then, the second execution device 81B proceeds to step S159B.
[0082] As shown in Figure 7(A), in step S45, the execution device 31 of the information processing device 30 sets the count M to 1. Then, the execution device 31 divides the update software for the ECU 80 into N parts, where "N" is an integer of 3 or more. Then, in step S47, the execution device 31 sends one of the divided update software parts, the Mth update software part, to the ECU 80 via the global network 42. At this time, the execution device 31 sends the encrypted Mth update software part to the ECU 80 via the global network 42. If the count M is 1, the execution device 31 sends the encrypted first update software part A1 to the ECU 80.
[0083] In step S49, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S51, the execution device 31 transmits the Mth update split software, which is one of the split update software, to the ECU 80 via the global network 42. At this time, the execution device 31 transmits the encrypted Mth update split software to the ECU 80 via the global network 42. The update split software transmitted to the ECU 80 here is different from the update split software transmitted to the ECU 80 in step S47. If the count M is 2, the execution device 31 transmits the encrypted second update split software A2 to the ECU 80.
[0084] In step S53, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S55, the execution device 31 determines whether the transmission of the update split software has been completed, similar to step S25 shown in Figures 2(A) and 3(A). If the transmission of the update split software has been completed (S55: YES), the execution device 31 proceeds to step S57. On the other hand, if the transmission of the update split software has not been completed (S55: NO), the execution device 31 returns to step S47. That is, the execution device 31 continues to transmit the update split software to the ECU 80.
[0085] As shown in Figure 7(B), in step S159A, the first execution device 81A of the ECU 80 determines whether or not the ECU 80 has received the Mth update split software. The update split software received here is the Mth update split software transmitted by the information processing device 30 in step S47. If the count M is 1, the first execution device 81A determines whether or not it has received the first update split software. If the ECU 80 has received the Mth update split software (S159A: YES), the first execution device 81A proceeds to step S161A. On the other hand, if the ECU 80 has not received the Mth update split software (S159A: NO), the first execution device 81A repeatedly performs the determination in step S159A until it receives the Mth update split software.
[0086] In step S161A, the first execution device 81A of the ECU 80 decodes the Mth update segment software received by the ECU 80 in step S159A. Then, in step S163A, the first execution device 81A writes the Mth update segment software that it has decoded to the storage device 82. For example, if the count M is 1, the first execution device 81A decodes the first update segment software A1 and writes the decoded first update segment software A1 to the storage device 82.
[0087] In step S165A, the first execution unit 81A of the ECU 80 determines whether the software update of the storage device 82 is complete. If the update is complete (S165A: YES), the first execution unit 81A proceeds to step S167A. On the other hand, if the update is not complete (S165A: NO), the first execution unit 81A returns to step S159A. In other words, the first execution unit 81A repeatedly executes the processes from step S159A to step S163A until the software update of the storage device 82 is complete.
[0088] As shown in Figure 7(C), in step S159B, the second execution device 81B of the ECU 80 determines whether or not the ECU 80 has received the Mth update split software. The update split software received here is the Mth update split software transmitted by the information processing device 30 in step S51. If the count M is 2, the second execution device 81B determines whether or not the ECU 80 has received the second update split software. If the ECU 80 has received the Mth update split software (S159B: YES), the second execution device 81B proceeds to step S161B. On the other hand, if the ECU 80 has not received the Mth update split software (S159B: NO), the second execution device 81B repeatedly performs the determination in step S159B until the ECU 80 receives the Mth update split software.
[0089] In step S161B, the second execution device 81B of the ECU 80 decodes the Mth update segment software received in step S159B. Then, in step S161B, the second execution device 81B writes the Mth update segment software that it has decoded to the storage device 62. For example, if the count M is 2, the second execution device 81B decodes the second update segment software A2 and writes the decoded second update segment software A2 to the storage device 62.
[0090] In step S165B, the second execution unit 81B of the ECU 80 determines whether the software update of the storage device 82 is complete. If the update is complete (S165B: YES), the second execution unit 81B proceeds to step S167B. On the other hand, if the update is not complete (S165B: NO), the second execution unit 81B returns to step S159B. In other words, the second execution unit 81B repeatedly executes the processes from step S159B to step S163B until the software update of the storage device 82 is complete.
[0091] As shown in Figure 7(A), in step S57, the execution device 31 of the information processing device 30 requests the ECU 80 to change the control mode of the execution device from update mode to normal mode. In step S59, the execution device 31 determines whether it has received either the third notification that the control mode of the first execution device 81A has been changed to normal mode, or the fourth notification that the control mode of the second execution device 81B has been changed to normal mode. If the execution device 31 has received either the third notification or the fourth notification from the ECU 80 (S59: YES), it terminates the processing routine shown in Figure 7(A). On the other hand, if the execution device 31 has not received at least one of the third notification or the fourth notification (S59: NO), it returns to step S57. That is, the execution device 31 continues to request the mode change from the ECU 80 until it receives either the third notification or the fourth notification.
[0092] As shown in Figure 7(B), when the ECU 80 receives a request for a mode change, the first execution unit 81A of the ECU 80 proceeds to step S167A. In step S167A, the first execution unit 81A resets itself, changes the control mode from update mode to normal mode, and restarts. Subsequently, in step S169A, the first execution unit 81A sends a third notification to the information processing device 30 indicating that the change from update mode to normal mode is complete. After that, the first execution unit 81A terminates the processing routine shown in Figure 7(B).
[0093] As shown in Figure 7(C), when the ECU 80 receives a request for a mode change, the second execution unit 81B of the ECU 80 proceeds to step S167B. In step S167B, the second execution unit 81B resets itself, changes the control mode from update mode to normal mode, and restarts. Subsequently, in step S169B, the second execution unit 81B sends a fourth notification to the information processing device 30 indicating that the change from update mode to normal mode is complete. After that, the second execution unit 81B terminates the processing routine shown in Figure 7(C).
[0094] <Operation and Effects of This Embodiment> This section will explain the operation and effects of this embodiment, focusing on the differences from those of the first embodiment. When updating the software of the storage device 82 of the ECU 80, the information processing device 30 divides the update software into N parts. The information processing device 30 sends the N parts of the update software to the ECU 80 via the global network 42. In this embodiment, the update software is sent to the ECU 80 in pairs via the global network 42.
[0095] In the ECU 80, one of the two received update split software files is processed by the first execution device 81A, while the other is processed by the second execution device 81B. Specifically, the first execution device 81A decodes one of the two update split software files and writes the decoded update split software file to the storage device 82. The second execution device 81B decodes the other of the two update split software files and writes the decoded update split software file to the storage device 82. By repeating this series of processes, the software in the storage device 82 of the ECU 80 is updated.
[0096] In this embodiment, the ECU 80, which is the ECU to be updated, is a multi-core processor. Therefore, for example, while the first execution device 81A is decoding the first update split software A1, the second execution device 81B can update the second update split software A2. As a result, the information processing device 30 does not have to wait for the transmission of the second update split software A2 until the decoding of the first update split software A1 is complete. In other words, the time that the information processing device 30 spends waiting for the transmission of the update split software can be shortened. Consequently, when the control system 15B updates the software in the storage device 82 of the ECU 80, it is possible to suppress the time required for software updates from becoming long.
[0097] Furthermore, in this embodiment, it is not necessary to use multiple ECUs to decode N update-ready software segments. Therefore, it is not necessary to perform communication using a local network between the ECU to be updated and the ECU that assists in updating the software.
[0098] (Fourth Embodiment) A fourth embodiment of the control system will be described with reference to Figures 8 and 9. In the following description, the differences from the above-described embodiments will be mainly explained, and the same reference numerals will be used for components identical to those in the above-described embodiments to avoid redundant explanations.
[0099] <Control System> The control system 15C of this embodiment will be described with reference to Figure 8. The control system 15C comprises a communication device 20, an information processing device 30, and a plurality of ECUs. The plurality of ECUs are configured to communicate with the information processing device 30 via a global network 42. The plurality of ECUs include a first braking ECU 60 and a second braking ECU 90. The first braking ECU 60 acts on the first actuator 11. The second braking ECU 90 acts on the second actuator 12. The plurality of ECUs may include other ECUs besides the first braking ECU 60 and the second braking ECU 90.
[0100] The first braking ECU 60 and the second braking ECU 90 can send and receive various types of information via the local network 43C. The communication speed of the local network 43C is higher than that of the global network 42.
[0101] The first braking ECU 60 comprises an execution device 61, a storage device 62, and a storage device 63. The second braking ECU 90 comprises an execution device 91, a storage device 92, and a storage device 93. For example, the execution device 91 is a CPU, the storage device 92 is non-volatile memory, and the storage device 93 is volatile memory. The storage device 92 is divided into a first storage unit 921 and a second storage unit 922. The first storage unit 921 stores the software to be executed by the execution device 91. The second storage unit 922 does not store the software to be executed by the execution device 91.
[0102] <Software update process> This embodiment describes a method for updating the software of the storage device provided in the braking ECU. When the ECU to be updated is the first braking ECU 60, the first braking ECU 60 corresponds to the "first electronic control unit," and the second braking ECU 90 corresponds to the "second electronic control unit." In addition, the execution device 61 of the first braking ECU 60 corresponds to the "first execution device," and the execution device 91 of the second braking ECU 90 corresponds to the "second execution device."
[0103] Referring to Figure 9, the sequence of processes for updating the software of the storage device 62 of the first braking ECU 60 will be explained. Figure 9(A) shows a part of the processing routine executed by the execution device 31 of the information processing device 30. Figure 9(B) shows a part of the processing routine executed by the execution device 61 of the first braking ECU 60. Figure 9(C) shows a part of the processing routine executed by the execution device 91 of the second braking ECU 90. In other words, the processing routine shown in Figure 9(B) is a part of the processing routine executed by the first electronic control unit, and the processing routine shown in Figure 9(C) is a part of the processing routine executed by the second electronic control unit.
[0104] When the execution device 31 of the information processing device 30 obtains the update software for the first braking ECU 60, it starts executing the processing routine shown in Figure 9(A). In step S81, the execution device 31 requests both the first braking ECU 60 and the second braking ECU 90 to change the control mode of the execution device from normal mode to update mode.
[0105] In the next step S83, the execution device 31 of the information processing device 30 determines whether it has received notification from either the first braking ECU 60 or the second braking ECU 90 that the mode change has been completed. If the execution device 31 has received the notification from either the first braking ECU 60 or the second braking ECU 90 (S83: YES), it proceeds to step S85. On the other hand, if the execution device 31 has not received the notification from at least one of the first braking ECU 60 or the second braking ECU 90 (S83: NO), it returns to step S81. In other words, the execution device 31 continues to request a mode change from the first braking ECU 60 and the second braking ECU 90 until it receives the notification from either of the first braking ECU 60 or the second braking ECU 90.
[0106] As shown in Figure 9(B), in step S181, the execution device 61 of the first braking ECU 60 determines whether or not it has received a request for a mode change from the information processing device 30. If the execution device 61 has received a request for a mode change (S181: YES), it proceeds to step S183. On the other hand, if the execution device 61 has not received a request for a mode change (S181: NO), it repeatedly performs the determination in step S181 until it receives a request. In step S183, the execution device 61 resets itself, changes the control mode to update mode, and restarts. Subsequently, in step S185, the execution device 61 sends a notification to the information processing device 30 indicating that the change from normal mode to update mode is complete. In the next step S187, the execution device 61 starts erasing the pre-update software from the storage device 62. After that, the execution device 61 proceeds to step S189.
[0107] As shown in Figure 9(C), in step S281, the execution device 91 of the second braking ECU 90 determines whether or not it has received a request for a mode change from the information processing device 30. If the execution device 91 has received a request for a mode change (S281: YES), it proceeds to step S283. On the other hand, if the execution device 91 has not received a request for a mode change (S281: NO), it repeatedly performs the determination in step S281 until it receives a request. In step S283, the execution device 91 resets itself, changes the control mode to update mode, and restarts. Subsequently, in step S285, the execution device 91 sends a notification to the information processing device 30 indicating that the change from normal mode to update mode is complete. Then, the execution device 91 proceeds to step S287.
[0108] As shown in Figure 9(A), in step S85, the execution device 31 of the information processing device 30 sets the count M to 1. Then, the execution device 31 divides the update software for the first braking ECU 60 into N parts. "N" is an integer of 3 or more. Then, in step S87, the execution device 31 transmits the Mth update division software, which is one of the N parts of the update software, to the second braking ECU 90 via the global network 42. At this time, the execution device 31 transmits the encrypted Mth update division software to the second braking ECU 90 via the global network 42.
[0109] In step S89, the execution device 31 of the information processing device 30 increments the count M by 1. In the next step S91, the execution device 31 determines whether the transmission of the update split software has been completed, similar to step S25 shown in Figures 2(A) and 3(A). If the transmission of the update split software has been completed (S91: YES), the execution device 31 proceeds to step S27 shown in Figures 2(A) and 3(A). The processing flow from step S27 onward is the same as in the first embodiment. On the other hand, if the transmission of the update split software has not been completed (S91: NO), the execution device 31 returns to step S87. That is, the execution device 31 continues to transmit the update split software to the second braking ECU 90.
[0110] As shown in Figure 9(C), in step S287, the execution device 91 of the second braking ECU 90 determines whether or not it has received the M update split software from the global network 42. If the execution device 91 has received the M update split software (S287: YES), it writes the M update split software to the second storage unit 922 and proceeds to step S289. On the other hand, if the execution device 91 has not received the M update split software (S287: NO), it repeatedly performs the determination in step S287 until it receives the M update split software.
[0111] In step S289, the execution device 91 of the second braking ECU 90 decodes the Mth update partition software stored in the second storage unit 922. Then, in step S291, the execution device 91 transmits the decoded Mth update partition software to the first braking ECU 60 via the local network 43. The execution device 91 then proceeds to step S293.
[0112] In step S293, the execution device 91 of the second braking ECU 90 determines whether the software update of the storage device 62 of the first braking ECU 60 has been completed. If the update is not completed (S293: NO), the execution device 91 returns to step S287. That is, the execution device 91 repeatedly executes the processes from step S287 to step S291 until the software update of the storage device 62 is completed. On the other hand, if the update is completed (S293: YES), the execution device 91 proceeds to step S215 shown in Figures 2(C) and 3(C). The flow of processing from step S215 onward is the same as in the first embodiment.
[0113] As shown in Figure 9(B), in step S189, the execution device 61 of the first braking ECU 60 determines whether or not it has received the decoded Mth update split software from the second braking ECU 90 via the local network 43. If the execution device 61 has received the Mth update split software from the second braking ECU 90 (S189: YES), it proceeds to step S191. On the other hand, if the execution device 61 has not received the Mth update split software from the second braking ECU 90 (S189: NO), it repeatedly performs the determination in step S189 until it receives the Mth update split software from the second braking ECU 90. In step S191, the execution device 61 writes the decoded Mth update split software received from the second braking ECU 90 to the storage device 62. Then, the execution device 61 proceeds to step S193.
[0114] In step S193, the execution device 61 of the first braking ECU 60 determines whether the software update of the storage device 62 is complete. If the update is not complete (S193: NO), the execution device 61 returns to step S189. That is, the execution device 61 repeatedly executes steps S189 and S191 until the software update of the storage device 62 is complete. On the other hand, if the update is complete (S193: YES), the execution device 61 proceeds to step S121 shown in Figures 2(B) and 3(B). The flow of processing from step S121 onward is the same as in the first embodiment.
[0115] <Operation and Effects of This Embodiment> The second braking ECU 90, which corresponds to the second electronic control unit, is equipped not only with a first storage unit 921 but also with a second storage unit 922 as its storage unit. Therefore, the information processing device 30 transmits encrypted update software to the second braking ECU 90 via the global network 42. In the second braking ECU 90, the received update software is stored in the second storage unit 922. When updating the software in the storage device 62 of the first braking ECU 60, the execution device 91 of the second braking ECU 90 decrypts the update software stored in the second storage unit 922 and transmits the decrypted update software to the first braking ECU 60 via the local network 43C. In the first braking ECU 60, the decrypted update software received via the local network 43C is written to the storage device 62.
[0116] Here, the communication speed of the local network 43C is higher than the communication speed of the global network 42. Therefore, by transmitting the update software to the first braking ECU 60 via the local network 43, the time required to update the software in the storage device 62 of the first braking ECU 60 can be shortened.
[0117] <Example of changes> The above-described embodiments can be implemented with the following modifications. The above-described embodiments and the following modifications can be combined with each other to the extent that they do not contradict each other technically.
[0118] In the fourth embodiment, if the storage capacity of the second storage unit 922 of the second braking ECU 90 is large, the information processing device 30 may transmit the update software to the second braking ECU 90 without dividing it.
[0119] In the above-described embodiments, the number of divisions N, which is the number of divisions that the information processing device 30 divides the update software into, may be an even number greater than or equal to 2, and may be other than 2. In the above-described embodiments, the number of divisions N, which is the number of divisions the information processing device 30 uses to divide the update software, may be an odd number as long as it is 2 or greater. For example, in the first embodiment, while the execution device 71 of the second braking ECU 70 is repeating the determination in step S207, the information processing device 30 may complete sending N update software divisions. In such a case, the execution device 71 of the second braking ECU 70 may proceed to step S215 when the information processing device 30 requests that it return the control mode to normal mode.
[0120] In the third embodiment, the number of execution devices provided by the ECU 80 may be three or more. For example, if the ECU 80 also includes a third execution device, while the first execution device 81A is decoding the first update split software A1 and the second execution device 81B is decoding the second update split software A2, the third execution device can also decode the third update split software A3.
[0121] In the second embodiment described above, only one ECU can communicate with the ECU to be updated (first ECU) via the local network. However, the number of ECUs that can communicate with the first ECU via the local network may be two or more. Let us explain using the example where a second ECU and a third ECU are provided as ECUs that can communicate with the first ECU via the local network. In this case, the information processing device 30 can also send three update split software files to the ECU to be updated. The ECU to be updated then sends the second update split software A2 to the second ECU via the local network, and the third update split software A3 to the third ECU via the local network. The second and third ECUs decode the update split software files received via the local network, and the decoded update split software files are sent to the first ECU via the local network. The first ECU decodes the first update split software A1 of the three update split software files, and writes the first update split software A1 to its storage device. In addition, the first ECU also writes the decrypted update split software received via the local network to its own storage device.
[0122] In the first embodiment described above, only one ECU can communicate with the ECU to be updated (first ECU) via the local network. However, the number of ECUs that can communicate with the first ECU via the local network may be two or more. An example will be given in which a second ECU and a third ECU are provided as ECUs that can communicate with the first ECU via the local network. In this case, the information processing device 30 transmits the first update split software A1 to the first ECU, the second update split software A2 to the second ECU, and the third update split software A3 to the third ECU. In the first ECU, the first update split software A1 is decoded and written to its own storage device. In the second and third ECUs, the update split software received via the global network 42 is decoded, and the decoded update split software is transmitted to the first ECU via the local network. Then, in the first ECU, the decoded update split software received via the local network is also written to its own storage device.
[0123] • In the above embodiments, the case in which the ECU to be updated is a braking ECU that adjusts the braking force generated in the vehicle 10 has been described, but it is not limited to this. Any ECU other than a braking ECU may be selected as the ECU to be updated, as long as it can communicate with the information processing device 30 via the global network 42. For example, a drive ECU that controls the power source of the vehicle 10, such as the engine or the drive motor, may be selected as the ECU to be updated, or an ECU that controls the actuator that adjusts the steering angle of the wheels may be selected as the ECU to be updated. In addition, an ADASECU may be selected as the ECU to be updated. "ADAS" stands for "Advanced Driver Assistance System".
[0124] The information processing device 30 and ECU that constitute the control system are not limited to those equipped with a CPU and ROM that execute software processing. In other words, the information processing device 30 and ECU may have any of the following configurations (a) to (c).
[0125] (a) Having one or more processors that perform various processes according to computer programs. A processor includes a CPU and memory such as RAM and ROM. Memory stores program code or instructions configured to cause the CPU to perform processes. Memory, i.e., computer-readable media, includes any available media that can be accessed by a general-purpose or dedicated computer.
[0126] (b) It has one or more dedicated hardware circuits that perform various processes. Examples of dedicated hardware circuits include application-specific integrated circuits, i.e., ASICs or FPGAs. ASIC is an abbreviation for "Application Specific Integrated Circuit," and FPGA is an abbreviation for "Field Programmable Gate Array."
[0127] (c) The system includes a processor that performs some of the various processes according to a computer program, and dedicated hardware circuits that perform the remaining processes. In this specification, the expression "at least one" means "one or more" of the desired options. For example, if there are two options, the expression "at least one" means "only one option" or "both of the two options." As another example, if there are three or more options, the expression "at least one" means "only one option" or "a combination of two or more arbitrary options."
[0128] <Other technological ideas> The technical concepts that can be understood from the above-mentioned multiple embodiments and modifications are described in the appendix. (Note 1) An information processing device that acquires update software transmitted to the vehicle via wireless communication from outside the vehicle, Multiple electronic control devices, A global network that connects the aforementioned plurality of electronic control devices and the information processing device in a manner that enables communication, The system includes a local network for transmitting and receiving information only between the first electronic control unit and the second electronic control unit among the plurality of electronic control units, The communication speed of the local network is faster than the communication speed of the global network. The first electronic control unit comprises a first execution device and a storage device on which software executed by the first execution device is written. The second electronic control unit comprises a second execution unit, a first storage unit on which software to be executed by the second execution unit is written, and a second storage unit on which software to be executed by the second execution unit is not written. When updating the software of the storage device of the first electronic control unit with update software for the first electronic control unit acquired by the information processing device, The information processing device transmits the update software to the second electronic control unit via the global network. The second execution device writes the update software received via the global network to the second storage unit, decrypts the update software written to the second storage unit, and transmits the decrypted update software to the first electronic control unit via the local network. The first execution device is a control system that writes update software received via the local network to the storage device.
[0129] The second electronic control unit has not only a first storage unit but also a second storage unit as its memory unit. Therefore, the information processing unit transmits encrypted update software to the second electronic control unit via the global network. The second electronic control unit stores the received update software in its second storage unit. When updating the software of the first electronic control unit's storage device, the execution unit of the second electronic control unit decrypts the update software stored in the second storage unit and transmits the decrypted update software to the first electronic control unit via the local network. The communication speed of the local network is higher than that of the global network. Therefore, by transmitting the update software to the first electronic control unit via the local network, the time required to update the software of the first electronic control unit's storage device can be shortened. [Explanation of Symbols]
[0130] 10... Vehicles 15, 15B, 15C… Control Systems 30…Information Processing Equipment 42…Global Network 43,43C…Local Network 50, 60, 70, 80, 90... ECU (Electronic Control Unit) 61, 71, 81A, 81B, 91… Execution devices 62,72,82,92…Storage device 921…1st storage unit 922…Second storage unit 100...Data center 200...External network< / ecu>
Claims
1. The system comprises an information processing device that acquires update software transmitted to the vehicle via wireless communication from outside the vehicle, and a global network that enables communication between a plurality of electronic control devices and the information processing device. A control system configured to allow updating of the software of a storage device provided in the first of the plurality of electronic control devices, It comprises a first execution device and a second execution device, When updating the software of the storage device of the first electronic control unit with update software for the first electronic control unit acquired by the information processing device, The information processing device divides the update software into multiple parts, and transmits the divided update software to the global network in an encrypted state. The first execution device decodes the first update split software, which is one of the update software that the information processing device has split and transmitted to the global network. The second execution device decodes the second update split software, which is one of the update software that the information processing device has split and transmitted to the global network. The first update split software decoded by the first execution device and the second update split software decoded by the second execution device are each written to the storage device of the first electronic control unit. Control system.
2. The first execution device is the execution device of the first electronic control unit, The second execution device is an execution device of the second electronic control unit among the plurality of electronic control units, The control system further comprises a local network for transmitting and receiving information only between the first electronic control unit and the second electronic control unit. The second execution device decodes the second update segment software received by the second electronic control unit, and transmits the decoded second update segment software to the first electronic control unit via the local network. The first execution device performs the following actions: decryption of the first update split software received by the first electronic control unit, writing the decrypted first update split software to the storage device, and writing the second update split software received via the local network to the storage device. The control system according to claim 1.
3. The information processing device performs the following actions: transmit the first update partition software via the global network to the first electronic control unit, and transmit the second update partition software via the global network to the second electronic control unit. The first execution device writes the first update split software, which it has decoded, to the storage device, and then writes the second update split software, which the second electronic control unit has transmitted to the first electronic control unit via the local network, to the storage device. The control system according to claim 2.
4. After the information processing device has finished writing the second update split software to the storage device, it transmits the third update split software, which is one of the split update software programs, to the first electronic control device via the global network. The first execution device decodes the third update split software after it has finished writing the second update split software to the storage device, and writes the third update split software to the storage device. The control system according to claim 3.
5. The information processing device transmits either the first update split software or the second update split software to the first electronic control unit via the global network. The first execution device is The first update split software received via the global network is decoded, and the first update split software is written to the storage device. The second update partition software received via the global network is transmitted to the second electronic control unit via the local network. The second update partition software received from the second electronic control unit via the local network is written to the storage device. The second execution device decodes the second update split software received from the first electronic control unit via the local network, and transmits the decoded second update split software to the first electronic control unit via the local network. The control system according to claim 2.
6. The first electronic control unit comprises the first execution device and the second execution device, The first execution device decodes the first update split software and writes the first update split software to the storage device. The second execution device decodes the second update split software and writes the second update split software to the storage device. The control system according to claim 1.