In-vehicle system, update control device, and program update control method

The in-vehicle system distributes update data across multiple devices to address storage constraints, enabling program updates without additional storage on the update control device by combining partial data from external and internal sources.

JP7859152B2Active Publication Date: 2026-05-15AUTONETWORKS TECH LTD +2
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
AUTONETWORKS TECH LTD
Filing Date
2022-04-04
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing in-vehicle update systems face challenges in securing storage space for update programs, especially when backup data is essential for device operation.

Method used

An in-vehicle system and method that distributes update data across multiple in-vehicle devices, utilizing partial data received from an external source and combining it with partial data stored in non-target devices to generate update data, allowing for efficient use of storage capacity without requiring additional storage space on the update control device.

Benefits of technology

Enables the download and update of programs even when the update control device's storage capacity is insufficient, by leveraging other in-vehicle devices to store and combine partial data, thus overcoming storage limitations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007859152000001
    Figure 0007859152000001
  • Figure 0007859152000002
    Figure 0007859152000002
  • Figure 0007859152000003
    Figure 0007859152000003
Patent Text Reader

Abstract

To download update data even if free space in a storage unit of an update control device is insufficient.SOLUTION: An update control device comprises: a reception unit that receives, from an external device placed outside a vehicle, first partial data that is partial data of update data to be used for updating a program; a storage unit that stores the first partial data received by the reception unit; and a transmission unit that transmits the first partial data stored in the storage unit to a target in-vehicle device such that the target in-vehicle device generates the update data by combining the first partial data with second partial data which is different from the first partial data, the second partial data being transmitted from a selected in-vehicle device and being partial data of the update data. The selected in-vehicle device is an in-vehicle device that stores the second partial data transmitted from the external device, and is selected from among a plurality of non-target in-vehicle devices on the basis of a selection condition relating to each of the plurality of in-vehicle devices.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an in-vehicle system, an update control device, and a program update control method.

Background Art

[0002] Vehicles are equipped with in-vehicle ECUs (Electronic Control Units) for controlling in-vehicle devices such as power train systems for engine control and body systems for air conditioner control. In Patent Document 1, there is disclosed an in-vehicle update device that, when updating the program of an in-vehicle ECU, temporarily stores (caches) an update program downloaded from an external server in a storage unit and transmits the update program to the in-vehicle ECU to be updated. The in-vehicle update device disclosed in Patent Document 1 transmits backup data stored in the storage unit to an external server or an in-vehicle ECU that is not the update target before downloading the update program from the external server to secure a storage area for the update program.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, it may be difficult to secure a storage area for the update program by transmitting the backup data, as in the case where the backup data is essential for the operation of the in-vehicle update device.

Means for Solving the Problems

[0005] An in-vehicle system according to one aspect of the present disclosure comprises: a target in-vehicle device which is an in-vehicle device to be updated with a program; a plurality of non-target in-vehicle devices which are in-vehicle devices that are not to be updated with a program; and an update control device which controls the program update in the target in-vehicle device, wherein the update control device includes: a first receiving unit which receives first partial data which is partial data of update data used for updating the program from an external device located outside the vehicle; a first storage unit which stores the first partial data received by the first receiving unit; and a first transmitting unit which transmits the first partial data stored in the first storage unit to the target in-vehicle device, wherein the selected in-vehicle device selected from the plurality of non-target in-vehicle devices is a partial data of the update data which is different from the first partial data The system includes a second receiving unit that receives partial data from the external device, a second storage unit that stores the partial data received by the second receiving unit, and a second transmitting unit that transmits the partial data stored in the second storage unit to the target in-vehicle device. The target in-vehicle device includes a third receiving unit that receives the partial data from the update control device and the partial data from the selected in-vehicle device, a generation unit that combines the partial data and partial data received by the third receiving unit to generate update data, and an update unit that updates the program using the update data generated by the generation unit. The selected in-vehicle device is selected from a plurality of non-target in-vehicle devices based on selection criteria for each of the plurality of in-vehicle devices.

[0006] An update control device according to one aspect of the present disclosure is an update control device that controls the update of a program in an in-vehicle device which is an in-vehicle device that is the target of a program update, comprising: a receiving unit that receives first partial data, which is partial data of update data used for updating the program, from an external device located outside the vehicle; a storage unit that stores the first partial data received by the receiving unit; and a transmitting unit that transmits the first partial data stored in the storage unit to the target in-vehicle device in order for the target in-vehicle device to combine the first partial data with a second partial data, which is partial data of the update data transmitted from a selected in-vehicle device and is different from the first partial data, to generate the update data, wherein the selected in-vehicle device is an in-vehicle device that stores the second partial data transmitted from the external device, and is selected from a plurality of non-target in-vehicle devices based on selection conditions for each of the plurality of in-vehicle devices.

[0007] A program update control method according to one aspect of the present disclosure is a program update control method by an update control device that controls the update of a program in a target in-vehicle device which is an in-vehicle device that is the target of a program update, comprising the steps of: the update control device receiving first partial data, which is partial data of update data used for updating the program, from an external device located outside the vehicle; the update control device storing the received first partial data; and the update control device transmitting the stored first partial data to the target in-vehicle device in order for the target in-vehicle device to combine the first partial data with second partial data, which is partial data of the update data transmitted from a selected in-vehicle device and is different from the first partial data, to generate the update data, wherein the selected in-vehicle device is an in-vehicle device that stores the second partial data transmitted from the external device, and is selected from a plurality of non-target in-vehicle devices based on selection conditions for each of the plurality of in-vehicle devices.

[0008] This disclosure can be implemented not only as an update control device having the characteristic configuration described above, and an in-vehicle system including the update control device, but also as a program update control method in which the characteristic processing in the update control device is performed in steps, as a program for causing the update control device to perform the characteristic processing described above, or as part or all of the update control device being implemented as a semiconductor integrated circuit. [Effects of the Invention]

[0009] According to this disclosure, even if the storage capacity of the update control device is insufficient, update data can be downloaded without backing up the data in the storage unit of the update control device. [Brief explanation of the drawing]

[0010] [Figure 1] This is a schematic diagram illustrating an example of a program update system according to an embodiment. [Figure 2] This is a block diagram showing an example of the configuration of an in-vehicle system according to the embodiment. [Figure 3] This block diagram shows an example of the configuration of an OTA master according to the embodiment. [Figure 4] This block diagram shows an example of the configuration of an ECU according to the embodiment. [Figure 5] This is a functional block diagram showing an example of the functions of the in-vehicle system according to the embodiment. [Figure 6] This diagram illustrates an example of the weights and scores for each item in the selection criteria according to the embodiment. [Figure 7] This is a diagram illustrating an example of the structure of update data. [Figure 8] This diagram illustrates an example of data splitting for updates. [Figure 9A] This figure shows an example of the structure of the first update data. [Figure 9B] This figure shows an example of the structure of the second update data. [Figure 10]This is a sequence diagram for explaining an example of memory free space confirmation processing. [Figure 11] This is a sequence diagram for explaining an example of split download processing. [Figure 12] This is a flowchart showing an example of selection processing. [Figure 13] This is a sequence diagram for explaining an example of program update processing. [Figure 14A] This is a flowchart showing a part of an example of selection processing according to a modification example. [Figure 14B] This is a flowchart showing another part of an example of selection processing according to a modification example.

Mode for Carrying Out the Invention

[0011] <Summary of Embodiments of the Present Disclosure> Hereinafter, the summary of the embodiments of the present disclosure will be listed and explained.

[0012] (1) The in-vehicle system according to this embodiment comprises: a target in-vehicle device which is an in-vehicle device to be updated with a program; a plurality of non-target in-vehicle devices which are in-vehicle devices that are not to be updated with a program; and an update control device which controls the program update in the target in-vehicle device. The update control device includes: a first receiving unit which receives first partial data which is partial data of update data used for updating the program from an external device located outside the vehicle; a first storage unit which stores the first partial data received by the first receiving unit; and a first transmitting unit which transmits the first partial data stored in the first storage unit to the target in-vehicle device. The selected in-vehicle device selected from the plurality of non-target in-vehicle devices is the target in-vehicle device which is the target in-vehicle device. The system includes a second receiving unit that receives a second partial data, which is a partial data and different from the first partial data, from an external device; a second storage unit that stores the second partial data received by the second receiving unit; and a second transmitting unit that transmits the second partial data stored in the second storage unit to the target in-vehicle device. The target in-vehicle device includes a third receiving unit that receives the first partial data from the update control device and the second partial data from the selected in-vehicle device; a generation unit that combines the first partial data and the second partial data received by the third receiving unit to generate the update data; and an update unit that updates the program using the update data generated by the generation unit. As a result, the update control device stores a portion of the update data, and the selected in-vehicle device stores the other portion of the update data. Therefore, even if the storage capacity of the update control device is insufficient, the update data can be downloaded without backing up the data in the storage unit of the update control device.

[0013] (2) In (1) above, the selected in-vehicle device may be selected from the plurality of non-target in-vehicle devices based on the selection criteria for each of the plurality of in-vehicle devices. This makes it possible to select the selected in-vehicle device from the plurality of non-target in-vehicle devices in accordance with the selection criteria.

[0014] (3) In the above (2), the selection conditions may be conditions related to at least one of the processing load of the in-vehicle device when the vehicle is in an operating state, the processing load of the in-vehicle device when a passenger is on board the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the free capacity of the storage unit provided in the in-vehicle device, the writing and reading speeds of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device. Thereby, an appropriate selected in-vehicle device can be selected according to the above conditions.

[0015] (4) In the above (3), the in-vehicle system includes an external communication device capable of communicating with the external device, and the security strength of the in-vehicle device connected to the same bus as the external communication device may be lower than the security strength of the in-vehicle device connected to a bus different from the external communication device. Thereby, an appropriate selected in-vehicle device can be selected according to the bus to which the in-vehicle device is connected in the in-vehicle system.

[0016] (5) In the above (3) or (4), the communication accessibility of the in-vehicle device connected to the same bus as the target in-vehicle device may be higher than the communication accessibility of the in-vehicle device connected to a bus different from the target in-vehicle device. Thereby, an appropriate selected in-vehicle device can be selected according to the bus to which the in-vehicle device is connected in the in-vehicle system.

[0017] (6) In any one of the above (3) to (5), the number of logical constituent units in the storage unit of the in-vehicle device may include the case where the non-volatile memory of the in-vehicle device is a single bank and the case where it is a double bank. Thereby, an appropriate selected in-vehicle device can be selected according to whether the storage unit of the in-vehicle device is a single bank memory or a double bank memory.

[0018] (7) In any one of (3) to (6) above, the update control device may include a selection unit that selects a selected in-vehicle device from the plurality of non-target in-vehicle devices based on the selection conditions, and a notification unit that notifies the external device of the selected in-vehicle device selected by the selection unit. This allows the update control device mounted on the vehicle to select a selected in-vehicle device.

[0019] (8) In (7) above, the selection unit may assign points to each of the multiple non-target in-vehicle devices for at least one of the following items: the processing load of the in-vehicle device when the vehicle is in operation, the processing load of the in-vehicle device when there are occupants in the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the available capacity of the storage unit provided in the in-vehicle device, the write and read speed of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device, and select the selected in-vehicle device from the multiple non-target in-vehicle devices based on the points. This allows for a quantitative evaluation of the non-target in-vehicle devices for the above items and enables the selection of a suitable in-vehicle device according to the evaluation results.

[0020] (9) In (8) above, the selection unit may set weights for each of several items, such as the processing load of the in-vehicle device when the vehicle is in operation, the processing load of the in-vehicle device when there are occupants in the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the available capacity of the storage unit provided in the in-vehicle device, the write and read speed of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device, and select the selected in-vehicle device from the plurality of non-target in-vehicle devices based on the result of multiplying the score by the weight. This makes it possible to quantitatively evaluate the non-target in-vehicle devices according to the importance of the above items and to appropriately select the selected in-vehicle device according to the evaluation result.

[0021] (10) In (7) above, the selection conditions include a plurality of conditions relating to a plurality of items selected from a plurality of items such as the processing load of the in-vehicle device when the vehicle is in operation, the processing load of the in-vehicle device when there are occupants in the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the available capacity of the storage unit provided in the in-vehicle device, the write and read speed of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device, and the selection unit may select the selected in-vehicle device by sequentially determining an in-vehicle device that meets the conditions from a plurality of non-target in-vehicle devices for the plurality of conditions. In this way, by sequentially determining an in-vehicle device that meets the plurality of conditions, the number of in-vehicle devices that can be candidates for the selected in-vehicle device can be narrowed down.

[0022] (11) In any one of (1) to (10) above, the first receiving unit receives first update data from the external device, which includes the first partial data and first verification data for verifying the first partial data; the update control device includes a first verification unit that verifies the first partial data included in the first update data using the first verification data included in the first update data; the first transmitting unit transmits the first partial data to the target in-vehicle device if the verification of the first partial data by the first verification unit is successful; the second receiving unit receives second update data from the external device, which includes the second partial data and second verification data for verifying the second partial data; the selected in-vehicle device includes a second verification unit that verifies the second partial data included in the second update data using the second verification data included in the second update data; and the second transmitting unit transmits the second partial data to the target in-vehicle device if the verification of the second partial data by the second verification unit is successful. This allows the first partial data and the second partial data to be verified individually.

[0023] (12) In any one of (1) to (11) above, the update data includes an update program which is the updated program and program verification data used to verify the update program, and the program verification data may be included in either the first partial data or the second partial data. This makes it possible to verify the update program included in the update data which is a combination of the first partial data and the second partial data.

[0024] (13) The update control device according to this embodiment is an update control device that controls the update of a program in a target in-vehicle device which is an in-vehicle device that is the target of the program update, and comprises: a receiving unit that receives first partial data, which is partial data of the update data used for updating the program, from an external device located outside the vehicle; a storage unit that stores the first partial data received by the receiving unit; and a transmitting unit that transmits the first partial data stored in the storage unit to the target in-vehicle device in order for the target in-vehicle device to combine the first partial data with a second partial data, which is partial data of the update data transmitted from a selected in-vehicle device and is different from the first partial data, to generate the update data, wherein the selected in-vehicle device is an in-vehicle device that stores the second partial data transmitted from the external device. As a result, the update control device stores a part of the update data and the selected in-vehicle device stores the other part of the update data, so that even if the storage unit of the update control device is full, the update data can be downloaded without saving the data in the storage unit of the update control device.

[0025] (14) The program update control method according to this embodiment is a program update control method by an update control device that controls the update of a program in a target in-vehicle device which is an in-vehicle device that is the target of the program update, and includes the steps of: the update control device receiving first partial data, which is partial data of update data used for updating the program, from an external device located outside the vehicle; the update control device storing the received first partial data; and the update control device transmitting the stored first partial data to the target in-vehicle device in order for the target in-vehicle device to combine the first partial data with second partial data, which is partial data of the update data transmitted from a selected in-vehicle device and is different from the first partial data, in order to generate the update data, wherein the selected in-vehicle device is an in-vehicle device that stores the second partial data transmitted from the external device. As a result, the update control device stores a part of the update data and the selected in-vehicle device stores the other part of the update data, so that even if the storage capacity of the update control device is insufficient, the update data can be downloaded without saving the data in the storage unit of the update control device.

[0026] <Details of the embodiments of this disclosure> The embodiments of the present invention will be described in detail below with reference to the drawings. At least some of the embodiments described below may be combined in any way.

[0027] [1. Program Update System] Figure 1 is a schematic diagram illustrating an example of a program update system according to this embodiment.

[0028] The program update system is a system for updating the control programs of the in-vehicle devices installed in the vehicle 10. The program update system includes the vehicle 10 and the OTA (Over The Air) server 50. The vehicle 10 is equipped with the in-vehicle systems described later.

[0029] Vehicle 10 is capable of communicating with external devices via wireless communication. Vehicle 10 is equipped with a wireless communication terminal compliant with, for example, a fifth-generation mobile communication system (5G) or a fourth-generation mobile communication system (4G), and can communicate wirelessly with base station 20. Base station 20 is connected to the internet 30. OTA server 50 is also connected to the internet 30. With this configuration, vehicle 10 and OTA server 50 can communicate with each other.

[0030] The OTA server 50 can provide the vehicle 10 with data for program updates. The OTA server 50 is an example of an "external device".

[0031] [2. In-vehicle systems] Figure 2 is a block diagram showing an example of the configuration of an in-vehicle system according to this embodiment.

[0032] This implementation form The in-vehicle system 100 includes an integrated ECU (Electronic Control Unit) 200 and individual ECUs 300A, 300B, 300C, 300D, and 300E. U3 It consists of 00A, 300B, 300C, 300D, 300E, and the communication cables (communication buses) connecting them.

[0033] The integrated ECU 200 is a gateway that relays communication between multiple individual ECUs. The integrated ECU 200 is an OTA master that controls the updates of the control programs of individual ECUs 300A, 300B, 300C, 300D, and 300E. The integrated ECU 200 is an example of an "update control device". Hereinafter, the integrated ECU 200 will also be referred to as the "OTA master 200".

[0034] Multiple individual ECUs 300A, 300B, 300C, 300D, and 300E are located in various parts of the vehicle 10. These individual ECUs 300A, 300B, 300C, 300D, and 300E individually control the hardware of each part of the vehicle 10 or monitor the status of the hardware of each part of the vehicle 10. For example, individual ECUs 300A, 300B, 300C, 300D, and 300E are ECUs for the powertrain system, body system, and information and entertainment system. Individual ECUs 300A, 300B, 300C, 300D, and 300E are examples of "in-vehicle devices." In the following explanation, individual ECUs will also be referred to as "ECUs," and individual ECUs 300A, 300B, 300C, and 300E will be referred to as "ECUs." ,300E These are collectively referred to as "ECU300".

[0035] The OTA Master 200 is connected to each of the ECUs 300A, 300B, 300C, 300D, and 300E via in-vehicle buses 400A, 400B, and 400C, which are similar to a CAN (Controller Area Network) bus. Specifically, bus 400A is connected to ECUs 300A and 300B. Bus 400B is connected to ECUs 300C and 300D. Bus 400C is connected to ECU 300E. The OTA Master 200 can communicate with each of the ECUs 300A, 300B, 300C, 300D, and 300E.

[0036] The OTA master 200 is connected to the external communication device 500 via bus 400C. The external communication device 500 is, for example, a wireless communication terminal compliant with 5G or 4G, such as a TSU (Telematics Control Unit). The external communication device 500 can communicate with the OTA server 50. The external communication device 500 relays communication between the OTA master 200 and the OTA server 50.

[0037] Bus 400C, connected to the external communication device 500, is an external communication bus used not only for communication within the vehicle but also for communication with devices outside the vehicle. Buses 400A and 400B are internal communication buses used only for communication within the vehicle.

[0038] [3. Configuration of the OTA Master] Figure 3 is a block diagram showing an example of the configuration of an OTA master according to this embodiment. The OTA master 200 includes a processor 201, a non-volatile memory 202, a volatile memory 203, and a communication interface (I / F) 204.

[0039] The volatile memory 203 is a semiconductor memory such as SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory). The non-volatile memory 202 is a flash memory, hard disk, etc. The non-volatile memory 202 is readable and writable. The non-volatile memory 202 stores an update control program 205, which is a computer program, and data used to execute the update control program 205. The OTA master 200 can store the first update data downloaded from the OTA server 50 in the non-volatile memory 202. The OTA master 200 is configured with a computer, and each function of the OTA master 200 is performed by executing the update control program 205, which is a computer program stored in the storage device of the computer.

[0040] The update control program 205 is a program for controlling the update of the control program of the ECU 300. More specifically, the update control program 205 is a program for selecting a storage location for a portion of the control program update data (second portion data) from among ECUs 300A, 300B, 300C, 300D, and 300E, and for notifying the OTA server 50 of the selected ECU. The update control program 205 is a program for downloading the first update data, which includes the first portion data of the update data, from the OTA server 50, storing the first portion data included in the downloaded first update data in the non-volatile memory 202, and sending the first portion data to the target ECU, which is the ECU to be updated.

[0041] The non-volatile memory 202 stores key data 206. Key data 206 is used to verify the update data (first update data) downloaded from the OTA server 50.

[0042] Processor 201 is, for example, a CPU (Central Processing Unit). However, processor 201 is not limited to a CPU. Processor 201 may also be a GPU (Graphics Processing Unit). Processor 201 is configured to execute computer programs. However, processor 201 may include, for example, an ASIC (Application Specific Integrated Circuit) or a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0043] Communication I / F204 is a communication interface compliant with CAN (Controller Area Network), a communication protocol for in-vehicle networks, for example. Communication I / F204 may also be a communication interface compliant with protocols such as CAN FD (CAN with Flexible Data rate), Ethernet (Ethernet is a registered trademark), or LIN (Local Interconnect Network). Communication I / F204 includes multiple communication ports and is connected to buses 400A, 400B, and 400C, respectively. Communication I / F204 is connected to ECUs 300A, 300B, 300C, 300D, and 300E, respectively, via buses 400A, 400B, and 400C. The OTA master 200 can communicate with ECUs 300A, 300B, 300C, 300D, and 300E via communication I / F204. Furthermore, the OTA master 200 can communicate with the OTA server 50 via the external communication device 500 using the communication I / F 204.

[0044] [4. OTA Server] The OTA server 50 consists of a processor, storage devices (non-volatile memory and volatile memory), a communication interface, etc. The OTA server 50 provides the updated program (hereinafter referred to as the "update program") to the ECU 300.

[0045] The OTA server 50 can download update data, which is a package containing the update program and verification data used to verify the update program (hereinafter also referred to as "PG verification data"), to the OTA master 200. When the OTA server 50 receives a request from the OTA master 200 to split the update data, it can split the update data to generate a first partial data and a second partial data, and download the first update data containing the first partial data and the second update data containing the second partial data separately.

[0046] [5. ECU Configuration] Figure 4 is a block diagram showing an example of the configuration of an ECU according to this embodiment. The ECU 300 includes a processor 301, a non-volatile memory 302, a volatile memory 303, a communication I / F 304, and an input / output I / F (I / O) 305.

[0047] The volatile memory 303 is a semiconductor memory such as SRAM or DRAM. The non-volatile memory 302 is a flash memory, hard disk, ROM, etc. The non-volatile memory 302 is managed by a memory controller in units of banks, which are composed of one or more flash memory chips. That is, a bank is a logical constituent unit of the non-volatile memory 302. A bank is defined for each side of the memory module that constitutes the non-volatile memory 302. A non-volatile memory 302 in which flash memory chips are mounted on only one side of the memory module is a single-bank memory, and a non-volatile memory 302 in which flash memory chips are mounted on both sides of the memory module is a double-bank memory. The non-volatile memory 302 stores a control program 306, which is a computer program, and data used to execute the control program 306. The individual ECU 300 is configured with a computer, and each function of the individual ECU 300 is performed by executing the control program 306, which is a computer program stored in the storage device of the computer. The control program 306 is, for example, a program for controlling some of the hardware of the vehicle 10.

[0048] The non-volatile memory 302 stores the update program 308 and the data used to execute the update program 308. The update program 308 is a program that receives update data from the OTA master 200 and updates the control program 306 using the received update data. The non-volatile memory 302 also stores key data 307. The key data 307 is used for updates. data It is used to decode the PG verification data contained within.

[0049] The non-volatile memory 302 also stores the update assistance program 309 and the data used to execute the update assistance program 309. The update assistance program 309 is a program that receives the second update data transmitted from the OTA server 50 via the OTA master 200, stores the second partial data contained in the received second update data in the non-volatile memory 302, and transmits the second partial data to the target ECU.

[0050] The processor 301 is, for example, a CPU. However, the processor 301 is not limited to a CPU. The processor 301 may be a GPU. The processor 301 may include, for example, an ASIC as part, or a programmable logic device such as an FPGA as part.

[0051] The communication interface 304 is, for example, a CAN-compliant communication interface. The communication interface 304 may also be a communication interface compliant with protocols such as CAN FD, Ethernet, or LIN. The communication interface 304 includes at least one communication port and is connected to one of the buses 400A, 400B, or 400C. The communication interface 304 is connected to the OTA master 200 via one of the buses 400A, 400B, or 400C. The ECU 300 can communicate with the OTA master 200 via the communication interface 304.

[0052] I / O305 is connected to, for example, a sensor or actuator (not shown). I / O305 can receive sensor data output from the sensor and output control signals to the actuator.

[0053] [5. Functions of the in-vehicle system] Figure 5 is a functional block diagram showing an example of the functions of the in-vehicle system according to this embodiment. In the following description, we will explain an example in which the control program 306 of ECU300A is updated, that is, ECU300A is the target ECU, and ECU300B is selected as the storage location for a portion of the update data, that is, ECU300B is the selected ECU. The target ECU is an example of a "target in-vehicle device", and the selected ECU is an example of a "selected in-vehicle device".

[0054] The processor 201 of the OTA master 200 executes the update control program 205, thereby realizing the functions of the selection unit 211, the notification unit 212, the first receiving unit 213, the first storage unit 214, the first verification unit 215, and the first transmitting unit 216. The processor 301 of the selected ECU 310 (ECU 300B in this example) among ECUs 300A, 300B, 300C, 300D, and 300E executes the update assistance program 309, thereby realizing the functions of the second receiving unit 311, the second storage unit 312, the second verification unit 313, and the second transmitting unit 314. Furthermore, when the processor 301 of the target ECU 320 (ECU 300A in this example) among ECUs 300A, 300B, 300C, 300D, and 300E executes the update program 308, the functions of the third receiving unit 321, the third storage unit 322, the generation unit 323, the third verification unit 324, and the update unit 325 are realized.

[0055] The selection unit 211 selects the target ECU 310 from among the ECUs 300B, 300C, 300D, and 300E (non-target in-vehicle devices), excluding the target ECU 320, ECU 300A, based on the selection criteria. The selection criteria are conditions for each of the multiple ECUs 300B, 300C, 300D, and 300E. In a specific example, the selection criteria are conditions for at least one of the following: the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the available capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300.

[0056] For example, the security strength of ECU300 is determined by buses 400A, 400B, and 400C connected to ECU300. Specifically, the security strength of ECU300E connected to external communication bus 400C is lower than that of ECU300A, 300B, 300C, and 300D connected to internal communication buses 400A and 400B.

[0057] For example, the communication accessibility of ECU300 is determined by the buses 400A, 400B, and 400C to which ECU300 is connected. Specifically, the communication accessibility of ECU300B connected to the same bus 400A as the target ECU320 is higher than that of ECU300C, 300D, and 300E connected to different buses 400B and 400C than the target ECU320.

[0058] For example, depending on the number of logical configuration units in the non-volatile memory 302 of the ECU 300, the ECU can be divided into one having a single-bank memory unit and one having a double-bank memory unit.

[0059] For example, the selection unit 211 assigns points to each of the ECUs 300B, 300C, 300D, and 300E for at least one of the following items: the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300. Based on these points, the selection unit 211 selects the ECU 310 from among the ECUs 300B, 300C, 300D, and 300E. In a more specific example, the selection unit 211 sets weights for multiple items among those listed below, such as the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300, and selects the ECU 310 from ECU 300B, 300C, 300D, and 300E based on the result of multiplying the score by the weight.

[0060] Figure 6 is a diagram illustrating an example of the weights and scores of each item in the selection criteria according to this embodiment. In the example in Figure 6, the weight of x1 for the processing load of the ECU 300 (item "driving state" in Figure 6) when the vehicle 10 is in operation is 15%. The score (value) for item x1 of an ECU 300 with a high processing load when the vehicle 10 is in operation (hereinafter referred to as "driving state") is 0, and the score for item x1 of an ECU 300 with a low processing load when the vehicle is in operation is 1. That is, since ECU 300B and 300C have a high processing load when the vehicle is in operation, the score for item x1 of ECU 300B and 300C is 0. Since ECU 300D and 300E have a low processing load when the vehicle is in operation, the score for item x1 of ECU 300D and 300E is 1.

[0061] The weight for the processing load of the ECU300 (item "occupied state" in Figure 6) x2 when there are occupants in the vehicle 10 is 15%. When there are occupants in the vehicle 10 (hereinafter referred to as "occupied state"), the score for item x2 of the ECU300 with a high processing load is 0, and the score for item x2 of the ECU300 with a low processing load in the occupied state is 1. In other words, ECU300C and 300E have a high processing load in the occupied state, so the score for item x2 of ECU300C and 300E is 0. ECU300B and 300D have a low processing load in the occupied state, so the score for item x2 of ECU300B and 300D is 1.

[0062] The weight for the security strength x3 of ECU300 is 20%. The score for item x3 of ECU300 with low security strength, i.e., ECU300E connected to the external communication bus 400C, is 0, and the score for item x3 of ECU300 with high security strength, i.e., ECU300B, 300C, and 300D connected to the internal communication buses 400A and 400B, is 1.

[0063] The weight for communication accessibility x4 of ECU300 is 10%. ECU300s with low communication accessibility, i.e., ECU300C, 300D, and 300E connected to buses 400B and 400C different from the target ECU320, have a score of 0 for item x4, while ECU300B with high communication accessibility, i.e., ECU300B connected to the same bus 400A as the target ECU320, has a score of 1 for item x4.

[0064] The weight for the free capacity of the non-volatile memory 302 in the ECU300 (item "Free Memory Capacity" in Figure 6) x 5 is 10%. The score for item x 5 is given as a real value corresponding to the free capacity of the non-volatile memory 302. For example, the score is calculated as Free capacity of non-volatile memory 302 (MB) × 0.01. However, if the result of the calculation using the above formula is 1 or greater, the score is set to 1. In the example in Figure 6, the free memory capacity of ECU300B is 10MB, so the score for item x 5 of ECU300B is 0.1. The free memory capacity of ECU300C is 2MB, so the score for item x 5 of ECU300C is 0.02. The free memory capacity of ECU300D is 50MB, so the score for item x 5 of ECU300D is 0.5. The free memory capacity of ECU300E is 150MB, so ECU300 E The score for item x5 is 1.

[0065] The weight for the write and read speeds of the non-volatile memory 302 provided in the ECU300 (item "Memory Write / Read Speed" in Figure 6) x6 is 10%. The score for item x6 is given as a real value corresponding to the write and read speeds of the non-volatile memory 302. For example, the score is calculated as write speed (kbps) × 0.001 + read speed (kbps) × 0.001. However, if the result of the calculation using the above formula is 1 or greater, the score is set to 1. In the example in Figure 6, the memory write speed of ECU300B is 500kbps and the read speed is 500kbps, so the score for item x6 of ECU300B is 1. The memory write speed of ECU300C is 100kbps and the read speed is 200kbps, so the score for item x6 of ECU300C is 0.3. The memory write speed of ECU300D is 200kbps and the read speed is 500kbps, so the score for item x6 for ECU300D is 0.7. The memory write speed of ECU300E is 1Mbps and the read speed is 1Mbps, so the score for item x6 for ECU300E is 1.

[0066] The weight for the number of logical constituent units (banks) in the non-volatile memory 302 of ECU300 (item "Memory Bank" in Figure 6) x 7 is 20%. The score for item x 7 for ECU300B and 300E, which have double-bank non-volatile memory 302, is 1. The score for item x 7 for ECU300C and 300D, which have single-bank non-volatile memory 302, is 0.

[0067] Returning to Figure 5, the selection unit 211 calculates the evaluation value E for each ECU 300 using the formula E = 15x1 + 15x2 + 20x3 + 10x4 + 10x5 + 10x6 + 20x7. This formula for calculating the evaluation value E represents the selection criteria. The selection unit 211 selects the ECU 300 with the highest evaluation value E among the candidate ECU 300s for storage of part of the update data (the target ECU 320 is excluded from the candidates) as the storage location for part of the update data (selected ECU 310). In this example, the selection criteria were set for the following items: the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300, but the criteria are not limited to these. The criteria may also be set for one or more items selected from the following: the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300.

[0068] The notification unit 212 notifies the OTA server 50 of the selected ECU 310 selected by the selection unit 211. For example, the notification unit 212 can notify the OTA server 50 of the identification information of the selected ECU 310.

[0069] The OTA server 50 divides the update data into a first part and a second part. The OTA server 50 sends the first update data containing the first part, and then sends the second update data containing the second part.

[0070] Figure 7 is a diagram illustrating an example of the structure of update data. The update data 610 is data used to update the control program 306 by the target ECU 320. The update data 610 includes the update program 601 (binary data of the update program in executable format) and program verification data (hereinafter referred to as "PG verification data") 602. The PG verification data 602 is data used to verify the update program 601 by the target ECU 320. The OTA server 50 encrypts the hash value of the update program 601 with key data and generates the PG verification data 602. The OTA server 50 combines the update program 601 and the PG verification data 602 and generates the update data 610.

[0071] The update package 600 shown in Figure 7 includes update data 610 and OTA master verification data 603. The OTA master verification data 603 is data used by the OTA master 200 to verify the update data 610. The OTA server 50 encrypts the hash value of the update data 610 with key data to generate the OTA master verification data 603. The OTA server 50 combines the update data 610 and the OTA master verification data 603 to generate the update package 600.

[0072] If there is free space in the non-volatile memory 202 of the OTA master 200 that is large enough to store the update package 600, the OTA server 50 downloads the update package 600 to the OTA master 200. The OTA master 200 stores the downloaded update package 600 in the non-volatile memory 202. The OTA master 200 decrypts the OTA master verification data 603 contained in the update package 600 using the key data 206 stored in the non-volatile memory 202. The OTA master 200 calculates the hash value of the update data 610 contained in the update package 600 and uses the calculated hash value to decrypt the OTA master verification data 603. decrypt The updated data 610 is verified by comparing it with the hash value obtained by doing so.

[0073] If the two hash values ​​match, the OTA master 200 sends the update data 610 to the target ECU 320. The target ECU 320 stores the received update data 610 in the non-volatile memory 302. The target ECU 320 decrypts the PG verification data 602 contained in the update data 610 using the key data 307 stored in the non-volatile memory 302. The target ECU 320 calculates the hash value of the update program 601 contained in the update data 610 and verifies the update program 601 by comparing the calculated hash value with the hash value obtained by decrypting the PG verification data 602. If the verification of the update program 601 is successful, that is, if the two hash values ​​match, the target ECU 320 installs the update program 601 and updates the control program 306.

[0074] If there is no free space in the non-volatile memory 202 of the OTA master 200 that is large enough to store the update package 600, the selection unit 211 selects a selection ECU 310. The OTA master 200 requests the OTA server 50 to split the update data 610. This request includes information about the selection ECU 310. In other words, the OTA master 200 notifies the OTA server 50 of the selection ECU 310 by requesting the OTA server 50 to split the update data 610.

[0075] When the OTA server 50 receives a request to split the update data 610, it splits the update data 610. Figure 8 is a diagram illustrating an example of splitting the update data 610. In this embodiment, the OTA server 50 splits the update data 610 into two parts: a first partial data 611 and a second partial data 612. However, the update data 610 may be split into three or more partial data.

[0076] The update data 610 consists of the update program 601 and the PG verification data 602. The PG verification data 602 is contained in either the first partial data 611 or the second partial data 612. However, a portion of the PG verification data 602 may be contained in the first partial data 611, and the remaining portion of the PG verification data 602 may be contained in the second partial data 612.

[0077] Figure 9A shows an example of the structure of the first update data. The first update data 620 shown in Figure 9A includes the first partial data 611 and the OTA master verification data 621. The OTA master verification data 621 is data used for verification of the first partial data 611 by the OTA master 200, and is an example of "first verification data". The OTA server 50 encrypts the hash value of the first partial data 611 with key data and generates the OTA master verification data 621. The OTA server 50 combines the first partial data 611 and the OTA master verification data 621 to generate the first update data 620.

[0078] Figure 9B shows an example of the structure of the second update data. The second update data 630 shown in Figure 9B includes second partial data 612 and ECU verification data 631. The ECU verification data 631 is data used to verify the second partial data 612 by the selected ECU 310, and is an example of "second verification data". The OTA server 50 encrypts the hash value of the second partial data 612 with key data and generates the ECU verification data 631. The OTA server 50 combines the second partial data 612 and the ECU verification data 631 to generate the second update data 630.

[0079] Returning to Figure 5, the OTA server 50 sends the first update data 620 to the OTA master 200. The first receiving unit 213 of the OTA master 200 receives the first update data 620 sent from the OTA server 50. The first storage unit 214 stores the first update data 620 received by the first receiving unit 213.

[0080] The first verification unit 215 decrypts the OTA master verification data 621 contained in the first update data 620 using the key data 206 stored in the non-volatile memory 202. The first verification unit 215 calculates the hash value of the first partial data 611 contained in the first update data 620 and verifies the first partial data 611 by comparing the calculated hash value with the hash value obtained by decrypting the OTA master verification data 621.

[0081] If the verification of the first partial data 611 is successful, that is, if the two hash values ​​match, the first transmission unit 216 transmits the first partial data 611 to the target ECU 320.

[0082] The OTA server 50 sends the second update data 630 to the OTA master 200. The OTA master 200 sends the received second update data 630 to the selected ECU 310. The second receiving unit 311 of the selected ECU 310 receives the second update data 630 sent from the OTA server 50. The second storage unit 312 stores the second update data 630 received by the second receiving unit 311.

[0083] The second verification unit 313 decrypts the ECU verification data 631 contained in the second update data 630 using the key data 307 stored in the non-volatile memory 302. The second verification unit 313 calculates the hash value of the second partial data 612 contained in the second update data 630 and verifies the second partial data 612 by comparing the calculated hash value with the hash value obtained by decrypting the ECU verification data 631.

[0084] If the verification of the second partial data 612 is successful, that is, if the two hash values ​​match, the second transmission unit 314 transmits the second partial data 612 to the target ECU 320.

[0085] The third receiver 321 of the target ECU 320 receives the first partial data 611 transmitted from the OTA master 200. The third storage unit 322 stores the received first partial data 611. The third receiver 321 receives the second partial data 612 transmitted from the selected ECU 310. The third storage unit 322 stores the received second partial data 612.

[0086] The generating unit 323 is the third receiving unit 321 The first partial data 611 and the second partial data 612 received by are combined to generate (restore) the updated data 610.

[0087] The third verification unit 324 decrypts the PG verification data 602 contained in the update data 610 using the key data 307 stored in the non-volatile memory 302. The third verification unit 324 calculates the hash value of the update program 601 contained in the update data 610 and verifies the update program 601 by comparing the calculated hash value with the hash value obtained by decrypting the PG verification data 602.

[0088] If the verification of update program 601 is successful, that is, if the two hash values ​​match, the update unit 325 installs update program 601 and updates the control program 306.

[0089] [6. Operation of the Program Update System] The operation of the program update system according to this embodiment will be described below.

[0090] [6-1. Checking available memory space] The OTA master 200 performs a memory availability check process to confirm the available capacity of the non-volatile memory 302 of ECUs 300A, 300B, 300C, 300D, and 300E in order to collect information used to select the storage location for some of the update data. Figure 10 is a sequence diagram illustrating an example of the memory availability check process.

[0091] The OTA master 200 sends a request to ECUs 300A, 300B, 300C, 300D, and 300E to check the available space in the non-volatile memory 302 (steps S11-S13). Upon receiving the request, each of the ECUs 300A, 300B, 300C, 300D, and 300E obtains information indicating the available space in the non-volatile memory 302 and transmits this information to the OTA master 200. 302 The free capacity is notified (steps S21-S23). The OTA master 200 receives information transmitted from each of the ECUs 300A, 300B, 300C, 300D, and 300E and obtains the free capacity of the non-volatile memory 302 of each of the ECUs 300A, 300B, 300C, 300D, and 300E.

[0092] The OTA master 200 sends a request to check the free capacity of the non-volatile memory 302, as described above, for example, at regular intervals. This periodically updates the free capacity of the non-volatile memory 302 of each of the ECUs 300A, 300B, 300C, 300D, and 300E, allowing the OTA master 200 to select a storage location for some of the updated data.

[0093] [6-2. Split Download Process] As described above, if there is no free space in the non-volatile memory 202 of the OTA master 200 large enough to store the update package 600, the program update system performs a segmented download process to download the update data in segments. Figure 11 is a sequence diagram illustrating an example of the segmented download process.

[0094] When a new version of the control program 306 is released for a particular ECU 300, the OTA server 50 stores update data 610, which includes the update program 601 for that version. In this case, the OTA server 50 sends an update request for the control program 306 to the OTA master 200. Upon receiving the update request for the control program 306, the OTA master 200 sends a response to the OTA server 50 (step S31).

[0095] Next, the OTA master 200 sends authentication data to the OTA server 50 to authenticate that the OTA master 200 is genuine, and the OTA server 50 performs the authentication. If the authentication is successful, the OTA server 50 notifies the OTA master 200 of the authentication success (step S32).

[0096] The OTA master 200 sends a request to the OTA server 50 to check the size of the update package 600 (step S33). When the OTA server 50 receives the request to check the size of the update package 600, it notifies the OTA master 200 of the size of the update package 600 (step S34).

[0097] The OTA master 200 compares the available space in the non-volatile memory 202 with the size of the update package 600 to determine whether the update package 600 can be stored in the non-volatile memory 202, that is, whether the update package 600 can be downloaded (step S35). If the update package 600 can be downloaded, it is downloaded from the OTA server 50 as described above. Note that in Figure 11, the processing when the update package 600 can be downloaded is omitted, and only the processing when the update package 600 cannot be downloaded is shown.

[0098] If the OTA master 200 determines that it is not possible to download the update package 600, it executes a selection process to select a storage location for a portion of the update data (step S36).

[0099] Figure 12 is a flowchart illustrating an example of the selection process. The processor 201 of the OTA master 200 checks the power status of the vehicle 10 and identifies the ECUs 300 that are operational (receiving power). If the vehicle 10 is in the ignition (IG) ON state, power is supplied to all ECUs 300 and all ECUs 300 are operational. If the vehicle 10 is in the IG OFF state, power is supplied only to the ECUs 300 driven by the battery power supply and these ECUs 300 are operational. The processor 201 determines the operational ECUs 300, excluding the target ECU 320, as candidates for storage locations for some of the update data (step S101).

[0100] Next, the processor 201 calculates the evaluation value E for all candidates using the formula for evaluation value E described above (step S102). The processor 201 selects the candidate with the highest evaluation value E as the storage location (selected ECU 310) for a portion of the update data (step S103). This completes the selection process.

[0101] Returning to Figure 11, the OTA master 200 sends a request to the OTA server 50 to split the update data (step S37). The splitting request includes the identification information of the selected ECU 310. Alternatively, instead of the identification information of the selected ECU 310, the OTA master 200 may notify the OTA server 50 of the free capacity of the non-volatile memory 302 of the selected ECU 310.

[0102] When the OTA server 50 receives a request, it divides the update data 610 into sizes corresponding to the OTA master 200 and the selected ECU 310 (step S38). The OTA server 50 generates OTA master verification data 621 and combines the first partial data 611 and the OTA master verification data 621 to create the first update data 620. The OTA server 50 generates ECU verification data 631 and combines the second partial data 612 and the ECU verification data 631 to create the second update data 630 (step S39).

[0103] The OTA server 50 sends the first update data 620 to the OTA master 200 (step S40). Upon receiving the first update data 620, the OTA master 200 stores the first update data 620 in the non-volatile memory 202 (step S41). The OTA master 200 verifies the first partial data 611 contained in the first update data 620 using the OTA master verification data 621 (step S42).

[0104] The OTA server 50 sends the second update data 630 to the OTA master 200 (step S43). Upon receiving the second update data 630, the OTA master 200 forwards the received second update data 630 to the selected ECU 310 (step S44). Upon receiving the second update data 630, the selected ECU 310 stores the second update data 630 in the non-volatile memory 302 (step S45). The selected ECU 310 verifies the second partial data 612 contained in the second update data 630 using the ECU verification data 631 (step S46). This completes the segmented download process.

[0105] [6-3. Program Update Process] The program update system performs a program update process to update the control program of the target ECU320 after the segmented download process. Figure 13 is a sequence diagram illustrating an example of the program update process.

[0106] If the OTA master 200 successfully verifies the first partial data 611, it transmits the first partial data 611 to the target ECU 320 (step S51). When the target ECU 320 receives the first partial data 611, it stores the received first partial data 611 in the non-volatile memory 302 (step S52).

[0107] The OTA master 200 sends a transmission instruction for the second part data 612 to the selected ECU 310 (step S53). Upon receiving the transmission instruction for the second part data 612, the selected ECU 310, having successfully verified the second part data 612, transmits the second part data 612 to the target ECU 320 (step S54). Upon receiving the second part data 612, the target ECU 320 stores the received second part data 612 in the non-volatile memory 302 (step S55).

[0108] The target ECU 320 combines the received first partial data 611 and the received second partial data 612 to restore the update data 610 (step S56). The target ECU 320 verifies the update program 601 included in the update data 610 using the PG verification data 602 (step S57). If the verification is successful, the target ECU 320 installs the update program 601 into the non-volatile memory 302 and updates the control program 306 (step S58). This completes the program update process.

[0109] [7. Variation Examples] The selection unit 211 may also select the selected ECU 310 by sequentially determining the ECU 300 that meets the conditions from among ECU 300B, 300C, 300D, and 300E for each of the multiple conditions included in the selection criteria.

[0110] Figures 14A and 14B are flowcharts illustrating an example of the selection process in this modified example. In this modified example, the processor 201 of the OTA master 200 performs the following selection process (step S36).

[0111] The processor 201 determines whether the vehicle 10 is in the ignition on state (step S201). If the vehicle 10 is in the ignition on state (YES in step S201), the processor 201 determines all ECUs 300 except the target ECU 320 as candidates for storage locations for part of the update data 610 (step S202). If the vehicle 10 is in the ignition off state (NO in step S201), the processor 201 determines all ECUs 300 other than those powered by the ignition power supply (i.e., ECUs 300 powered by the battery power supply) as candidates for storage locations for part of the update data 610 (step S203). After step S202 or S203, the processor 201 moves to step S204.

[0112] The processor 201 determines whether or not there are occupants in the vehicle 10 (step S204). If there are occupants in the vehicle 10 (YES in step S204), the processor 201 removes the ECU 300, which has a high processing load when an occupant is present, from the candidates (step S205). After step S205, the processor 201 moves to step S206. If there are no occupants in the vehicle 10 (NO in step S204), the processor 201 also moves to step S206.

[0113] The processor 201 determines whether the vehicle 10 is in operation (driving) (step S206). If the vehicle 10 is in operation (YES in step S206), the processor 201 removes the ECU 300 that has a high processing load in the driving state from the candidates (step S207). After step S207, the processor 201 moves to step S208. If the vehicle 10 is not in operation, i.e., stopped (NO in step S206), the processor 201 also moves to step S208.

[0114] The processor 201 determines whether the security strength of the target ECU 320 is high or low (step S208). If the target ECU 320 is connected to the in-vehicle communication bus 400A or 400B, the processor 201 determines that the security strength of the target ECU 320 is high (step S208 (YES in this case). In this case, processor 201 removes ECU 300 on the in-vehicle communication bus 400A, 400B from the candidates (step S209). After step S209, processor 201 moves to step S212.

[0115] If the target ECU320 is connected to the external communication bus 400C, the processor 201 determines that the security strength of the target ECU320 is low (step S 208 (NO in step S210). In this case, the processor 201 determines whether or not ECU300 connected to the same bus as the target ECU320 is included as a candidate (step S210). If ECU300 connected to the same bus as the target ECU320 is included as a candidate (YES in step S210), the processor 201 removes ECU300 connected to a different bus from the target ECU320 from the candidates (step S211). After step S211, the processor 201 moves to step S212. If ECU300 connected to the same bus as the target ECU320 is not included as a candidate (NO in step S210), the processor 201 also moves to step S212.

[0116] The processor 201 selects the ECU 300 with the largest available non-volatile memory 302 from among the candidates as the storage location for a portion of the update data 610 (step S212). This completes the selection process.

[0117] [8. Other variations] In the embodiment described above, the integrated ECU 200 was used as the OTA master, but the invention is not limited to this. An individual ECU 300 may also be used as the OTA master.

[0118] In the embodiment described above, the OTA master 200 selected the storage location for a portion of the update data 610, but this is not limited to this. For example, the OTA server 50 may select the storage location for a portion of the update data 610. In this case, the OTA master 200 may notify the OTA server 50 of the available capacity of the non-volatile memory 302 of each ECU 300A, 300B, 300C, 300D, 300E.

[0119] [9. Effects of the Embodiment] The in-vehicle system 100 includes a target ECU 320 (target in-vehicle device) which is an ECU 300 that is subject to the update of the control program 306, a plurality of ECUs 300B, 300C, 300D, 300E (non-target in-vehicle devices) which are ECUs 300 that are not subject to the update of the control program 306, and an OTA master 200 (update control device) which controls the update of the control program 306 in the target ECU 320. The OTA master 200 includes a first receiving unit 213, a first storage unit 214, and a first transmitting unit 216. The first receiving unit 213 receives first partial data 611 from an OTA server 50 (external device) located outside the vehicle 10. The first partial data 611 is partial data of update data 610 used to update the control program 306. The first storage unit 214 stores the first partial data 611 received by the first receiving unit 213. The first transmitting unit 216 transmits the first partial data 611 stored in the first storage unit 214 to the target ECU 320. The selected ECU 310 (selected in-vehicle device), selected from a plurality of ECUs 300B, 300C, 300D, and 300E, includes a second receiving unit 311, a second storage unit 312, and a second transmitting unit 314. The second receiving unit 311 receives the second partial data 612 from the OTA server 50. The second partial data 612 is partial data of the update data 610 and is different from the first partial data 611. The second storage unit 312 stores the second partial data 612 received by the second receiving unit 311. The second transmitting unit 314 transmits the second partial data 612 stored in the second storage unit 312 to the target ECU 320. The target ECU 320 includes a third receiving unit 321, a generation unit 323, and an update unit 325. The third receiving unit 321 receives first partial data 611 from the OTA master 200 and second partial data 612 from the selected ECU 310. The generation unit 323 combines the first partial data 611 and the second partial data 612 received by the third receiving unit 321 to generate update data 610. The update unit 325 updates the control program 306 using the update data 610 generated by the generation unit 323.As a result, the OTA master 200 stores a portion of the update data 610, and the selected ECU 310 stores the other portion of the update data 610. Therefore, even if the non-volatile memory 202 of the OTA master 200 is full, the update data 610 can be downloaded without backing up the data in the non-volatile memory 202 of the OTA master 200.

[0120] The selected ECU310 may be chosen from ECU300B, 300B, 300C, 300D, and 300E based on selection criteria for each of the multiple ECU300A, 300B, 300C, 300D, and 300E. This allows for the selection of ECU310 from ECU300B, 300C, 300D, and 300E according to the selection criteria.

[0121] The selection criteria may also relate to at least one of the following: the processing load of the ECU 300 when the vehicle 10 is in operation; the processing load of the ECU 300 when there are occupants in the vehicle 10; the security strength of the ECU 300; the communication accessibility of the ECU 300; the available capacity of the non-volatile memory 302 provided in the ECU 300; the write and read speeds of the non-volatile memory 302 provided in the ECU 300; and the number of logical constituent units in the non-volatile memory 302 of the ECU 300. This allows for the appropriate selection of the ECU 310 based on the above-mentioned criteria.

[0122] The in-vehicle system 100 may include an external communication device 500 capable of communicating with the OTA server 50. The security strength of an ECU 300 connected to the same bus 400C as the external communication device 500 may be lower than the security strength of an ECU 300 connected to a different bus 400A or 400B than the external communication device 500. This allows the in-vehicle system 100 to appropriately select an ECU 310 depending on the bus to which the ECU 300 is connected.

[0123] The communication accessibility of an ECU300 connected to the same bus 400A as the target ECU320 may be higher than that of an ECU300 connected to different buses 400B and 400C. This allows for the appropriate selection of the ECU310 in the in-vehicle system 100 depending on the bus to which the ECU300 is connected.

[0124] The number of logical configuration units in the non-volatile memory 302 of the ECU 300 may include cases where the non-volatile memory 302 of the ECU 300 is a single bank and cases where it is a double bank. No Depending on whether the volatile memory 302 is a single-bank memory or a double-bank memory, the appropriate ECU 310 can be selected.

[0125] The OTA master 200 may include a selection unit 211 and a notification unit 212. The selection unit 211 selects a selection ECU 310 from a plurality of ECUs 300B, 300C, 300D, and 300E based on selection criteria. The notification unit 212 notifies the OTA server 50 of the selection ECU 310 selected by the selection unit 211. This allows the OTA master 200 installed in the vehicle 10 to select the selection ECU 310.

[0126] The selection unit 211 may assign points to each of the ECUs 300B, 300C, 300D, and 300E for at least one of the following items: the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302 provided in the ECU 300, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300. Based on these points, the selection unit 211 may select the ECU 310 from among the ECUs 300B, 300C, 300D, and 300E. This allows for a quantitative evaluation of the ECUs 300B, 300C, 300D, and 300E for the above items, and enables the selection of the ECU 310 appropriately according to the evaluation results.

[0127] The selection unit 211 may set weights for multiple items, such as the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302 provided in the ECU 300, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300, and select the ECU 310 from ECU 300B, 300C, 300D, and 300E based on the result of multiplying the score by the weight. This allows for a quantitative evaluation of ECU 300B, 300C, 300D, and 300E according to the importance of the above items, and enables the selection of the ECU 310 appropriately according to the evaluation result.

[0128] SelectionThe specified conditions may include multiple conditions related to multiple items selected from among the following: the processing load of the ECU 300 when the vehicle 10 is in operation, the processing load of the ECU 300 when there are occupants in the vehicle 10, the security strength of the ECU 300, the communication accessibility of the ECU 300, the free capacity of the non-volatile memory 302 provided in the ECU 300, the write and read speed of the non-volatile memory 302 provided in the ECU 300, and the number of logical constituent units in the non-volatile memory 302 of the ECU 300. The selection unit 211 may select the selected ECU 310 by sequentially determining the ECU 300 that meets the conditions from among ECU 300B, 300C, 300D, and 300E for each of the multiple conditions. In this way, by sequentially determining the ECU 300 that meets multiple conditions, the number of candidate ECU 300s for the selected ECU 310 can be narrowed down.

[0129] The first receiving unit 213 may receive first update data 620 from the OTA server 50, which includes first partial data 611 and OTA master verification data 621 (first verification data) for verifying the first partial data 611. The OTA master 200 may include a first verification unit 215. The first verification unit 215 verifies the first partial data 611 included in the first update data 620 using the OTA master verification data 621 included in the first update data 620. The first transmitting unit 216 may transmit the first partial data 611 to the target ECU 320 if the verification of the first partial data 611 by the first verification unit 215 is successful. The second receiving unit 311 may receive second update data 630 from the OTA server 50, which includes second partial data 612 and ECU verification data 631 (second verification data) for verifying the second partial data 612. The selected ECU 310 may include a second verification unit 313. The second verification unit 313 verifies the second partial data 612 included in the second update data 630 using the ECU verification data 631 included in the second update data 630. The second transmission unit 314 may transmit the second partial data 612 to the target ECU 320 if the verification of the second partial data 612 by the second verification unit 313 is successful. This allows the first partial data 611 and the second partial data 612 to be verified individually.

[0130] The update data 610 may include the updated program, update program 601, and PG verification data 602 used to verify update program 601. The PG verification data 602 may be included in either the first partial data 611 or the second partial data 612. This allows for the verification of update program 601 included in the update data 610, which is a combination of the first partial data 611 and the second partial data 612.

[0131] [10. Addendum] An update control program used in an update control device that controls the update of a program in a target in-vehicle device, which is an in-vehicle device that is the target of the program update, Computers, A receiving unit receives first partial data, which is partial data of the update data used to update the aforementioned program, from an external device located outside the vehicle. A storage unit that stores the first partial data received by the receiving unit, The target in-vehicle device is a transmission unit that transmits the first partial data stored in the storage unit to the target in-vehicle device in order to combine the first partial data with a second partial data, which is a partial data of the update data transmitted from the selected in-vehicle device and is different from the first partial data, in order to generate the update data. To make it function as, The selected in-vehicle device is an in-vehicle device that stores the second partial data transmitted from the external device. Update control program.

[0132] [11. Supplementary Notes] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is indicated by the claims rather than by the embodiments described above, and includes all modifications within the meaning and scope of the equivalents of the claims. [Explanation of Symbols]

[0133] 10 vehicles 20 base station 30 Internet 50 OTA Servers (External Devices) 100 In-vehicle systems 200 Integrated ECU (OTA Master, Update Control Unit) 201 Processor 202 Non-volatile memory 203 Volatile memory 204 Communication Interface (Communication I / F) 205 Update control program 206 Key Data 211 Selection Department 212 Notification Department 213 First Receiving Unit 214 1st memory section 215 First Verification Department 216 First Transmitter 300,300A,300B,300C,300D,300E Individual ECU (ECU, in-vehicle device) 301 Processor 302 Non-volatile memory 303 Volatile memory 304 Communication Interface (Communication I / F) 305 Input / Output Interface (I / O) 306 Control Program 307 Key Data Update 308 309 Update Support Program 310 Selected ECU (selected in-vehicle device) 311 Second Receiving Unit 312 2nd memory section 313 Second Verification Department 314 Second Transmitter 320 Target ECUs (Target In-Vehicle Devices) 321 Third Receiving Unit 322 Third memory section 323 Generation part 324 Third Verification Department 325 Update Department 400A, 400B In-vehicle communication bus 400C External Communication Bus 500 External communication device 600 update packages Update 601 602 Program Verification Data (PG Verification Data) 603 OTA Master Verification Data 610 Update Data 611 Part 1 Data 612 Second Part Data 620 First Update Data 621 OTA Master Verification Data (First Verification Data) 630 Second Update Data 631 ECU Verification Data (Second Verification Data)

Claims

1. The target vehicle device is the vehicle device that is subject to the program update, Multiple in-vehicle devices that are not subject to program updates, An update control device that controls the updating of the program in the target in-vehicle device, Equipped with, The update control device is A first receiving unit receives first partial data, which is partial data of the update data used to update the aforementioned program, from an external device located outside the vehicle. A first storage unit that stores the first partial data received by the first receiving unit, A first transmission unit transmits the first partial data stored in the first storage unit to the target in-vehicle device, Includes, The selected vehicle-mounted device, chosen from the aforementioned multiple non-target vehicle-mounted devices, is: A second receiving unit receives a second partial data from the external device, which is a partial data of the update data and is different from the first partial data. A second storage unit that stores the second partial data received by the second receiving unit, A second transmission unit transmits the second partial data stored in the second storage unit to the target in-vehicle device, Includes, The aforementioned in-vehicle device is: A third receiving unit that receives the first partial data from the update control device and the second partial data from the selected in-vehicle device, A generation unit that combines the first partial data and the second partial data received by the third receiving unit to generate the updated data, An update unit updates the program using the update data generated by the generation unit, including, In-vehicle systems.

2. The selected in-vehicle device is selected from the plurality of non-target in-vehicle devices based on the selection criteria for each of the plurality of in-vehicle devices. The in-vehicle system according to claim 1.

3. The selection criteria are conditions relating to at least one of the following: the processing load of the in-vehicle device when the vehicle is in operation; the processing load of the in-vehicle device when there are occupants in the vehicle; the security strength of the in-vehicle device; the communication accessibility of the in-vehicle device; the available capacity of the storage unit provided in the in-vehicle device; the write and read speed of the storage unit; and the number of logical constituent units in the storage unit of the in-vehicle device. The in-vehicle system according to claim 2.

4. The in-vehicle system includes an external communication device capable of communicating with the external device, The security strength of an in-vehicle device connected to the same bus as the external communication device is lower than the security strength of an in-vehicle device connected to a different bus than the external communication device. The in-vehicle system according to claim 3.

5. The communication accessibility of an in-vehicle device connected to the same bus as the aforementioned target in-vehicle device is higher than that of an in-vehicle device connected to a different bus. The in-vehicle system according to claim 3.

6. The number of logical constituent units in the storage unit of the in-vehicle device includes cases where the non-volatile memory of the in-vehicle device is a single bank and cases where it is a double bank. The in-vehicle system according to claim 3.

7. The update control device is A selection unit that selects the selected in-vehicle device from the plurality of non-target in-vehicle devices based on the selection criteria, A notification unit that notifies the external device of the selected in-vehicle device selected by the selection unit, including, The in-vehicle system according to any one of claims 3 to 6.

8. The selection unit assigns points to each of the multiple non-targeted in-vehicle devices for at least one of the following items: the processing load of the in-vehicle device when the vehicle is in operation, the processing load of the in-vehicle device when there are occupants in the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the available capacity of the storage unit provided in the in-vehicle device, the write and read speed of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device, and selects the selected in-vehicle device from the multiple non-targeted in-vehicle devices based on the points. The in-vehicle system according to claim 7.

9. The selection unit sets weights for each of several items, including the processing load of the in-vehicle device when the vehicle is in operation, the processing load of the in-vehicle device when there are occupants in the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the available capacity of the storage unit provided in the in-vehicle device, the write and read speed of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device, and selects the selected in-vehicle device from the plurality of non-target in-vehicle devices based on the result of multiplying the score by the weight. The in-vehicle system according to claim 8.

10. The selection criteria include multiple conditions relating to multiple items selected from among the following: the processing load of the in-vehicle device when the vehicle is in operation, the processing load of the in-vehicle device when there are occupants in the vehicle, the security strength of the in-vehicle device, the communication accessibility of the in-vehicle device, the available capacity of the storage unit provided in the in-vehicle device, the write and read speed of the storage unit, and the number of logical constituent units in the storage unit of the in-vehicle device. The selection unit selects the selected in-vehicle device by sequentially determining, from among the multiple non-target in-vehicle devices, an in-vehicle device that meets the conditions for each of the multiple conditions. The in-vehicle system according to claim 7.

11. The first receiving unit receives first update data from the external device, which includes the first partial data and first verification data for verifying the first partial data. The update control device includes a first verification unit that verifies the first partial data included in the first update data using the first verification data included in the first update data. The first transmission unit transmits the first partial data to the target in-vehicle device if the verification of the first partial data by the first verification unit is successful. The second receiving unit receives second update data from the external device, which includes the second partial data and second verification data for verifying the second partial data. The selected in-vehicle device includes a second verification unit that verifies the second partial data included in the second update data using the second verification data included in the second update data. The second transmission unit transmits the second partial data to the target in-vehicle device if the verification of the second partial data by the second verification unit is successful. The in-vehicle system according to claim 1.

12. The update data includes an update program, which is the updated program, and program verification data used to verify the update program. The program verification data is included in either the first partial data or the second partial data. The in-vehicle system according to claim 1.

13. An update control device that controls the update of the program in a target in-vehicle device, which is an in-vehicle device that is the target of the program update, A receiving unit receives first partial data, which is partial data of the update data used to update the aforementioned program, from an external device located outside the vehicle. A storage unit that stores the first partial data received by the receiving unit, A transmission unit that transmits the first partial data stored in the storage unit to the target in-vehicle device, A selection unit selects a selected in-vehicle device from a plurality of non-target in-vehicle devices, which are in-vehicle devices that are not subject to the program update, which receives a second partial data, which is a partial data of the update data and is different from the first partial data, from the external device and transmits the received second partial data to the target in-vehicle device. Equipped with, Update control device.

14. A program update control method by an update control device that controls the update of a program in a target in-vehicle device which is an in-vehicle device that is the target of a program update, The update control device receives first partial data, which is partial data of the update data used to update the program, from an external device located outside the vehicle. The update control device includes the step of storing the received first partial data, The update control device transmits the stored first partial data to the target in-vehicle device, The update control device selects a selected in-vehicle device from a plurality of non-target in-vehicle devices, which are in-vehicle devices that are not subject to the program update, to receive a second partial data from the external device, which is a partial data of the update data and is different from the first partial data, and to transmit the received second partial data to the target in-vehicle device. including, Program update control method.