Update management device, in-vehicle system, control method, and computer program
The update management device optimizes software updates for in-vehicle ECUs by transmitting data based on their power states, addressing the inefficiencies and power consumption issues of existing methods, ensuring timely and efficient vehicle readiness.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- AUTONETWORKS TECH LTD
- Filing Date
- 2022-10-28
- Publication Date
- 2026-05-15
AI Technical Summary
Existing software update methods for in-vehicle ECUs prolong the time it takes for a vehicle to become drivable due to the need for all ECUs to be powered on, leading to potential communication discrepancies and increased power consumption, especially when not all ECUs require updates.
An update management device that determines the power state of the vehicle and transmits update data to ECUs only when they are in a suitable power state, allowing updates to be performed sequentially based on their operational state, thereby reducing the time to become drivable.
This approach ensures that software updates are performed efficiently, minimizing power consumption and reducing the risk of communication discrepancies among ECUs, thus shortening the time required for the vehicle to become operational.
Smart Images

Figure 0007859280000001 
Figure 0007859280000002 
Figure 0007859280000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to an update management device, an in-vehicle system, a control method, and a computer program.
Background Art
[0002] There is known an in-vehicle device mounted on a vehicle and connected to a plurality of ECUs (Electronic Control Units). In recent years, the power supply of vehicles has become more complex and its power supply state has become diversified. Also, with the diversification of vehicle control such as a parking support system, the opportunity to update the software installed in the ECU has increased.
[0003] Patent Document 1 discloses a CGW (Central Gate Way) to which a plurality of ECUs are connected. The CGW of Patent Document 1 monitors the power supply state and maintains the power supply state with a power management ECU that manages the power supply during the update and activation of the ECU software.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] In order to update and activate the software of the ECU, the power supply state of the vehicle needs to be the power supply state in which the target ECU operates. For this reason, after the power supply state required by the ECU is achieved, the update and activation of the ECU are started. In particular, when the ECU to be updated becomes operable after the key switch for making the vehicle drivable is set to the drivable position, there is a risk that the time for the vehicle to become drivable will be prolonged.
[0006] In light of these challenges, this disclosure aims to provide an update management device that reduces waiting times for software updates and activations. [Means for solving the problem]
[0007] The update management device of the present disclosure is an update management device for managing software updates of in-vehicle devices in a vehicle having multiple power states, and comprises: a receiving unit that receives from an external device of the vehicle first update data for updating the software of a first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; and a transmitting unit that transmits the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state, and transmits the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state.
[0008] The control method of the present disclosure is a control method for an update management device that manages software updates for in-vehicle devices in a vehicle having multiple power states, and comprises: a receiving step of receiving first update data for updating the software of a first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state, from an external device of the vehicle; a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first transmission step of transmitting the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state; and a second transmission step of transmitting the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state.
[0009] The computer program of this disclosure is a computer program for controlling an update management device that manages software updates for in-vehicle devices in a vehicle having multiple power states, and comprises: a receiving step of receiving first update data for updating the software of a first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state, from an external device of the vehicle; a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first transmission step of transmitting the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state; and a second transmission step of transmitting the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state. [Brief explanation of the drawing]
[0010] [Figure 1] This is a block diagram showing an example of an in-vehicle system according to Embodiment 1. [Figure 2] This is a block diagram showing an example of the internal configuration of the update management ECU according to Embodiment 1. [Figure 3] This is a block diagram showing an example of the internal configuration of an ECU according to Embodiment 1. [Figure 4] This is a functional block diagram of the update management ECU according to Embodiment 1. [Figure 5] This table shows an example of an ECU table listing ECUs. [Figure 6] This table shows an example of an ECU table listing ECUs. [Figure 7] This flowchart shows the control method according to Embodiment 1. [Figure 8] This is a sequence diagram of the in-vehicle system according to Embodiment 1. [Figure 9]This is a sequence diagram of the in-vehicle system according to Embodiment 1. [Figure 10] This flowchart shows the control method according to Embodiment 2 when an aftermarket ECU is detected. [Modes for carrying out the invention]
[0011] [Description of Embodiments in this Disclosure] The embodiments of this disclosure include, in essence, the following configurations.
[0012] (1) The update management device of the present disclosure is an update management device for managing software updates of in-vehicle devices in a vehicle having multiple power states, and comprises: a receiving unit that receives from an external device of the vehicle first update data for updating the software of a first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state; a determination unit that determines whether the power state of the vehicle is the first power state or the second power state; and a transmitting unit that transmits the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state, and transmits the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state.
[0013] Depending on the vehicle's power status, the update management device sends update data to in-vehicle devices whose software can be updated under that power status. This ensures that the software of the in-vehicle devices is updated sequentially at the appropriate time according to the power status, shortening the time it takes for the vehicle to become drivable.
[0014] (2) The receiving unit may receive the first update data and the second update data from the external device while the power supply state is the first power supply state.
[0015] By configuring it in this way, the update management device can receive update data from an external device in advance. As a result, the update data is downloaded earlier, and the time it takes for the vehicle to become drivable is shortened.
[0016] (3) When the determination unit determines that the power state is the first state, the update management device may further activate the software updated by the first update data in the first in-vehicle device that executes a predetermined first function without the second in-vehicle device, and when the determination unit determines that the power state is the second state, the update management device may further activate the software updated by the first update data and the second update data in the first in-vehicle device and the second in-vehicle device that execute a predetermined second function by the first in-vehicle device and the second in-vehicle device. The update management device may include an activation unit.
[0017] In the power state in which a group of in-vehicle devices that execute a predetermined function operate, the update management device activates software in the group of in-vehicle devices. A group of in-vehicle devices including in-vehicle devices that operate in different power states can execute a predetermined function without conflict.
[0018] (4) When a new third in-vehicle device is connected to the update management device to which the first in-vehicle device and the second in-vehicle device are connected, the receiving unit receives third update data for updating the software of the third in-vehicle device from an external device of the vehicle. When the determination unit determines that the power state of the vehicle is the first power state when the third in-vehicle device operates in the first power state and the second power state, the transmitting unit transmits the third update data to the third in-vehicle device. When the third in-vehicle device does not operate in the first power state and operates in the second power state, and when the determination unit determines that the power state of the vehicle is the second power state, the transmitting unit may transmit the third update data to the third in-vehicle device.
[0019] When a new third in-vehicle device is connected to the update management device, the third update data is transmitted to the third in-vehicle device while it is in a powered state capable of operation. This allows the newly added third in-vehicle device to be updated at the appropriate time.
[0020] (5) The receiving unit may receive the first update data, the second update data, and the third update data from an external device while the power supply state is the first power supply state.
[0021] With this configuration, the third update data is downloaded to the update management device in the first power state. For example, if the third in-vehicle device does not operate in the first power state but operates in the second power state, there is no need to switch to the second power state and download the third update data, allowing for efficient updating of the third in-vehicle device.
[0022] (6) When the third in-vehicle device operates in the first power state and the second power state, and the determination unit determines that the power state is the first state, the activation unit may cause the third in-vehicle device to perform a predetermined third function with the first in-vehicle device without the second in-vehicle device, to activate the software updated by the third update data, and cause the first in-vehicle device to perform the third function, to activate the software updated by the first update data. When the third in-vehicle device does not operate in the first power state but operates in the second power state, and the determination unit determines that the power state is the second state, the activation unit may cause the third in-vehicle device to perform a predetermined fourth function with the second in-vehicle device, to activate the software updated by the third update data, and cause the second in-vehicle device to perform the fourth function, to activate the software updated by the second update data.
[0023] With this configuration, even when a new in-vehicle device is connected, the update management device activates the group of in-vehicle devices that perform the predetermined functions while they are under a power supply condition in which they are operating. As a result, even when a new in-vehicle device is connected, the group of in-vehicle devices, including those operating under different power supply conditions, can perform their predetermined functions without any discrepancies.
[0024] (7) The first power state is the power state when the vehicle is unable to run, and the second power state may be the power state when the vehicle is able to run.
[0025] With this configuration, for in-vehicle devices that can be updated while the vehicle is in a state where it cannot run, the update management device will cause the in-vehicle device to perform the update. On the other hand, for in-vehicle devices that cannot be updated unless the vehicle is in a state where it can run, the update management device will cause the in-vehicle device to perform the update when the vehicle becomes drivable. This shortens the time it takes for the vehicle to become drivable. In addition, a group of in-vehicle devices that perform predetermined functions can perform those functions without any discrepancies.
[0026] (8) The in-vehicle system of the present disclosure is an in-vehicle system comprising any update management device described in (1) to (7) above, and the first in-vehicle device, the second in-vehicle device, or the third in-vehicle device connected to the update management device.
[0027] (9) The control method of the present disclosure is a control method for an update management device that manages software updates for an in-vehicle device in a vehicle having a plurality of power states, comprising: a receiving step of receiving from an external device of the vehicle first update data for updating the software of a first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state; a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first transmission step of transmitting the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state; and a second transmission step of transmitting the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state.
[0028] Depending on the vehicle's power status, the update management device sends update data to in-vehicle devices whose software can be updated under that power status. This ensures that the software of the in-vehicle devices is updated sequentially at the appropriate time according to the power status, shortening the time it takes for the vehicle to become drivable.
[0029] (10) The computer program of the present disclosure is a computer program for controlling an update management device that manages software updates for in-vehicle devices in a vehicle having multiple power states, and comprises: a receiving step of receiving first update data for updating the software of a first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state, from an external device of the vehicle; a determination step of determining whether the power state of the vehicle is the first power state or the second power state; a first transmission step of transmitting the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state; and a second transmission step of transmitting the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state.
[0030] Depending on the vehicle's power status, the update management device sends update data to in-vehicle devices whose software can be updated under that power status. This ensures that the software of the in-vehicle devices is updated sequentially at the appropriate time according to the power status, shortening the time it takes for the vehicle to become drivable.
[0031] <Embodiment 1> [1. Details of Embodiment 1 of this Disclosure] The details of Embodiment 1 of this disclosure will be described below with reference to the drawings.
[0032] [1.1 In-vehicle system configuration] Figure 1 is a diagram showing an example of the configuration of the in-vehicle system 1 according to Embodiment 1. The in-vehicle system 1 is a system installed in a vehicle such as an automobile. The in-vehicle system 1 comprises an update management ECU 11, a first ECU 12, a second ECU 13, a third ECU 14, communication buses 16a and 16b, and a communication device 15.
[0033] The update management ECU11 (ECU: Electronic Control Unit) is an update management device that manages software updates for in-vehicle devices in vehicles having multiple power states. The multiple power states consist of at least a first power state and a second power state. The first power state is, for example, the power state when the vehicle is unable to run, and the second power state is the power state when the vehicle is able to run. The first power state is, for example, the power state when the key switch is in the OFF position, which is used to start the engine by inserting the key. Specifically, in the first power state, power is not supplied from the vehicle's battery to most of the electrical equipment in the vehicle, but power is directly supplied only to the minimum necessary onboard equipment. Examples of such a small number of electrical devices include security systems and clocks. Hereafter, the first power state may be referred to as the +B state. The second power state is, for example, the power state when the key switch used to start the engine is in the ignition position. Specifically, in the second power state, power is supplied to all electrical equipment, and the vehicle will start moving when the accelerator is pressed. Hereafter, the second power state may be referred to as the IG state. The vehicle's power state will be explained using two types: the first power state and the second power state, but this is not limited to these two types, and further subdivisions are possible. Also, the on-board device may be referred to as the ECU.
[0034] The update management ECU 11 manages software updates for in-vehicle devices in vehicles with multiple power states. Therefore, the update management ECU 11 is configured to operate in the power state where software updates are performed. For example, the update management ECU 11 can operate in both the +B and IG states.
[0035] The update management ECU 11 functions as an integrated ECU that manages, for example, the first ECU 12, the second ECU 13, and the third ECU 14. The update management ECU 11 may also transmit update data downloaded from, for example, a server 2, which is an external device outside the vehicle connected via network 3, to the first ECU 12, the second ECU 13, and the third ECU 14.
[0036] The update management ECU 11 may also function as a GW-ECU (Gateway-ECU) that relays data transmitted and received between the first ECU 12, second ECU 13, third ECU 14, and the communication device 15. The internal configuration of the update management ECU 11 will be described later.
[0037] The communication device 15 is, for example, a communication interface for wireless communication. The communication device 15 communicates with the server 2 via a network 3, such as the Internet. Specifically, the communication device 15 is a TCU (Telematics Communication Unit). Via the network 3, the communication device 15 transmits data output from the update management ECU 11 to the server 2. The communication device 15 also receives data (such as update data) transmitted from the server 2 via the network 3. Via the communication bus 16b, the communication device 15 transmits this data to the update management ECU 11.
[0038] Server 2 is a device installed outside the vehicle. Server 2 is a server comprising, for example, a control unit, a storage unit, and a communication unit (not shown). The storage unit of Server 2 stores, for example, programs or data for controlling each part of the in-vehicle system 1 (for example, the update management ECU 11, the first ECU 12, the second ECU 13, and the third ECU 14). For example, the manufacturers of the first ECU 12, the second ECU 13, and the third ECU 14 update the programs or data as needed and store the updated programs or data in the storage unit of Server 2 as they occur. The control unit of Server 2 uses the communication unit to transmit the updated programs or data to the update management ECU 11 as update data.
[0039] Communication buses 16a and 16b are in-vehicle communication networks connected to the update management ECU 11. Various devices (first ECU 12, second ECU 13, third ECU 14, and communication device 15, etc.) are connected to communication buses 16a and 16b extending from the update management ECU 11. In the example in Figure 1, two communication buses 16a and 16b extend from the update management ECU 11, but the number of communication buses is not particularly limited. Communication buses 16a and 16b comply with communication protocols such as CAN (Controller Area Network), Ethernet (registered trademark), or FlexRay (registered trademark), but are not limited to these.
[0040] The update management ECU 11 is connected to the first ECU 12, second ECU 13, and third ECU 14 via the communication bus 16a. In the example in Figure 1, the update management ECU 11 is connected to the first ECU 12, second ECU 13, and third ECU 14 via the communication bus 16a.
[0041] The number of ECUs included in the in-vehicle system 1 is not particularly limited, as long as there are two or more. An ECU is a device that controls various parts of the vehicle (e.g., braking system, doors, battery, air conditioner, etc.) (operation system ECU). The function of the ECU is not particularly limited, and an ECU may be a device that communicates with sensors to monitor the status of various parts of the vehicle (cognition system ECU). Multiple ECUs may each have different functions, or they may each have the same function.
[0042] The first ECU12 is an ECU that operates in both the +B state and the IG state. The internal configuration of the first ECU12 will be described later. Note that an ECU that operates in both the +B state and the IG state is sometimes referred to as a +B drive ECU.
[0043] The second ECU13 is an ECU that does not operate in the +B state but operates in the IG state. The internal configuration of the second ECU13 will be described later. Note that an ECU that does not operate in the +B state but operates in the IG state is sometimes called an IG-driven ECU.
[0044] The third ECU14 was not initially connected, but has now been connected to the update management ECU11. The internal configuration of the third ECU14 will be described later.
[0045] [1.2 Internal configuration of the update management ECU11] Figure 2 shows an example of the internal configuration of the update management ECU11. The update management ECU 11 includes an information processing unit 21, which includes a control unit 22 and a storage unit 23, and a plurality of transceivers 25a, 25b. These units are electrically connected by an internal bus 24.
[0046] The control unit 22 includes, for example, one or more CPUs (Central Processing Units). In the case of a CPU, the control unit 22 reads the computer program stored in the memory unit 23 and performs various calculations and controls.
[0047] The storage unit 23 has volatile memory and non-volatile memory, and stores various types of data. The volatile memory includes, for example, RAM (Random Access Memory). The non-volatile memory includes, for example, flash memory, HDD (Hard Disk Drive), SSD (Solid State Drive), or ROM (Read Only Memory). A portion of the non-volatile memory may be located outside the update management ECU 11.
[0048] The storage unit 23 stores computer programs, various parameters, and tables in non-volatile memory, for example. The storage unit 23 also stores computer programs, various parameters, and tables downloaded from server 2 via network 3 and communication device 15.
[0049] Multiple transceivers 25a and 25b transmit and receive signals flowing through communication buses 16a and 16b via their respective ports (not shown). Transceivers 25a and 25b send information contained in the received signals to the control unit 22 via the internal bus 24. Transceivers 25a and 25b receive the information sent by the control unit 22 via the internal bus 24 and transmit it to communication buses 16a and 16b. Transceiver 25a is connected to communication bus 16b, and transceiver 25b is connected to communication bus 16b.
[0050] In the above explanation, the control unit 22 of the information processing unit 21 was described as including a CPU, but this is not the only example. For example, the information processing unit 21 may be an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), etc. In the case of an FPGA, the information processing unit 21 performs various calculations and controls according to a pre-programmed configuration. In the case of an ASIC, the information processing unit 21 performs various calculations and controls according to a configuration built in during manufacturing.
[0051] [1.3 Internal Configuration of the ECU] Figure 3 shows an example of the internal configuration of the first ECU12. The internal configurations of the second ECU13 and third ECU14 are the same as those of the first ECU12, so their explanation is omitted.
[0052] The first ECU 12 includes an information processing unit 31, which includes a control unit 32 and a storage unit 33, a transceiver 37, an input unit 35, and an output unit 36. The transceiver 37 is electrically connected to the information processing unit 31 via an internal bus 34.
[0053] The control unit 32, for example, reads a computer program stored in the memory unit 33 and performs various calculations and controls.
[0054] Like the storage unit 23, the storage unit 33 has both volatile memory and non-volatile memory, and stores various types of data. For example, the storage unit 33 stores computer programs, various parameters, and tables in its non-volatile memory.
[0055] The transceiver 37 is composed of, for example, an integrated circuit (IC), and is a CAN transceiver. The transceiver 37 is connected to the communication bus 16a and receives various control messages from the communication bus 16a.
[0056] The transceiver 37 includes a transmitting circuit and a receiving circuit (not shown). The transmitting circuit and the receiving circuit communicate in accordance with the communication protocol of the communication bus 16a. The transmitting circuit converts the digital signal data output by the information processing unit 31 into a predetermined analog signal and sends it to the communication bus 16a. The receiving circuit converts the analog signal input from the communication bus 16a into a digital signal that can be read by the information processing unit 31 and outputs the digital signal to the information processing unit 31.
[0057] The input unit 35 is connected to, for example, sensors and input devices. The input unit 35 receives signals corresponding to the vehicle's status and signals corresponding to instructions from the driver, etc. Sensors include, for example, a temperature sensor that detects the temperature inside the vehicle and a door switch that detects whether a door is closed. Input devices include, for example, a switch for operating the air conditioner.
[0058] The output unit 36 is connected to, for example, a motor, a solenoid, etc. Based on the information sent by the information processing unit 31, the output unit 36 drives the connected motor, solenoid, etc. This information is, for example, information indicating the movement of the connected motor, etc. The motor is, for example, a motor that raises and lowers a door window. The solenoid is, for example, a solenoid that locks a door.
[0059] [1.4 Problems that this embodiment aims to solve] If ECUs that had received software updates and those that had not were mixed, there was a risk of communication discrepancies between the ECUs. For this reason, software updates were performed when all ECUs were powered on, for example, when the ignition was engaged. In such cases, the software update would begin from the moment the driver turned the key switch to the ignition position, potentially increasing the time it took for the vehicle to become drivable. Furthermore, because the update was performed when all ECUs were powered on, regardless of whether an update was necessary or not, power was supplied to ECUs that did not require an update, potentially increasing power consumption.
[0060] Furthermore, if, for example, the software of each ECU is updated while the vehicle is in the ignition state, the timing of the completion of the software update for each ECU may differ from one ECU to another. If the ECUs are activated immediately after the software update, there is a risk that functions that require multiple ECUs to work together may not be executed. For example, if an activated ECU sends a command to an ECU that has not yet been activated, the ECU that has not yet been activated may not understand the command, and therefore the function may not be executed.
[0061] For example, in the case of the power window control function for rainy weather, the door ECU that controls the power window, the rain sensor ECU that detects raindrops, and the BCM (Body Control Module) that acquires information from the rain sensor ECU and sends a command to the door ECU to close the window work together to execute the power window control function for rainy weather. For example, if the rain sensor's rainfall sensitivity is improved compared to before, and the reference rainfall amount for closing the power window is changed and the program is updated, it is foreseeable that the software for the rain sensor ECU will be updated, but the software for the BCM will not. In such a situation, there is a risk of discrepancies occurring, such as the door window remaining open even though it is raining.
[0062] The specific control details of the in-vehicle system 1 will be explained below, with reference to Figures 1 to 6 as appropriate.
[0063] • 5. Functions of the Update Management Device Figure 4 is a functional block diagram showing the functions included in the update management ECU 11. Figures 5 and 6 are tables showing an example of an ECU table listing the ECUs. The update management ECU 11 includes four functional blocks: a receiving unit 41, a determination unit 42, a transmitting unit 43, and an activation unit 44.
[0064] [1.5.1 Receiving Unit] The receiving unit 41 receives from an external device of the vehicle first update data for updating the software of the first in-vehicle device which operates in a first power state and a second power state different from the first power state, and second update data for updating the software of the second in-vehicle device which does not operate in the first power state but operates in the second power state.
[0065] Specifically, the receiving unit 41 has the function of downloading first update data and second data from the server 2. The server 2 is located, for example, in the vehicle manufacturer's data center. The server 2 stores, for example, update data for each ECU. The first update data is update data for updating the software of the first ECU 12, which is a +B drive ECU. The second update data is update data for updating the software of the second ECU 13, which is an IG drive ECU.
[0066] The receiving unit 41 operates the control unit 22 to access the server 2 via the internal bus 24, transceiver 25a, communication device 15, and network 3, and downloads the update data stored in the server 2. The trigger for starting the download is, for example, when new update data is recorded in the server 2. In this case, the server transmits information indicating that new update data has been recorded to each in-vehicle system 1. The information indicating that new update data has been recorded may include information indicating the version of the newly recorded update data. Hereafter, the information indicating that new update data has been recorded will be referred to as update software information. For example, an example of new update data being recorded in the server 2 is a version upgrade of the program to improve the rainfall sensitivity compared to the previous rain sensor and change the reference rainfall amount for closing the power windows.
[0067] Each in-vehicle system 1's update management ECU 11 stores an ECU table in the storage unit 23, for example, as shown in Figure 5. For example, the ECU table includes information indicating a predetermined function, the ECU that performs the predetermined function, the power supply state in which the ECU operates, and the software version of the ECU, and is recorded in the storage unit 23 in a tabular format for each predetermined function. An example of a predetermined function is a power window control function in rainy weather. An example of an ECU that performs this function is a door ECU that controls the power window, a rain sensor ECU that detects raindrops, and a BCM that acquires information from the rain sensor ECU and transmits a control to the door ECU to close the window. The power supply state in which the ECU operates is, for example, the +B state for the door ECU and BCM, but the IG state for the rain sensor ECU. An example of an ECU software version is 1.02. In this example, since a +B drive ECU and an IG drive ECU are included, the system as a whole does not operate in the +B state but in the IG state. The explanation uses the example where the ECU table is stored in the memory unit 23 of the update management ECU 11, but it is not limited to this; for example, it may be stored in the memory unit of server 2.
[0068] Figure 6 shows an ECU table for another example. In this example, the predetermined function is, for example, an anti-theft function. The ECUs that perform the predetermined function are, for example, a door detection ECU that detects whether the door is closed and locked, and a notification ECU that alerts the driver. The power state in which the ECUs operate is, for example, the +B state for both the door detection ECU and the notification ECU. The software version of the ECUs is, for example, 1.01. In this example, since all ECUs are +B driven ECUs, the system as a whole operates in the +B state and the IG state.
[0069] The receiving unit 41, for example, compares the version information contained in the update software information sent from the server with the version information recorded in the ECU table to determine whether the software has been updated. If it determines that the software has been updated, the receiving unit 41 requests the update data from the server 2 and downloads it. The receiving unit 41 temporarily records the downloaded update data in the storage unit 23.
[0070] [1.5.2 Judgment part] The determination unit 42 has a function to determine whether the power state of the vehicle is the first power state or the second power state.
[0071] Specifically, the determination unit 42 detects, for example, the power state of the vehicle and determines whether the detected power state is in the +B state or the IG state. The detection of the vehicle's power state may be performed by the update management ECU 11 or by the power monitoring ECU that monitors the vehicle's power state. In the case of the +B state, for example, the voltage of the power bus connected to an electrical device that is directly powered from the vehicle's battery, such as the notification ECU, is detected, and if the voltage is above a predetermined level, it is determined to be in the +B state. In the case of the IG state, for example, the voltage of the power bus that supplies power to an ECU that operates when the accelerator is pressed and the vehicle starts moving, such as the engine control ECU, is detected, and if the voltage is above a predetermined level, it is determined to be in the IG state. If the state is both +B and IG, it is determined to be in the IG state.
[0072] [1.5.3 Transmitter Section] The transmitting unit 43 has the function of transmitting the first update data to the first in-vehicle device when the determination unit determines that the power state of the vehicle is the first power state, and transmitting the second update data to the second in-vehicle device when the determination unit determines that the power state of the vehicle is the second power state.
[0073] Specifically, when the determination unit 42 determines that the vehicle's power state is in the +B state, the transmission unit 43 transmits first update data to the first ECU 12, which is a +B drive ECU, for example, the door ECU and BCM. On the other hand, when the determination unit 42 determines that the vehicle's power state is in the IG state, the transmission unit 43 transmits second update data to the second ECU 13, which is an IG drive ECU, for example, the rain sensor ECU.
[0074] When update data is received, the first ECU 12 and the second ECU 13 temporarily store the received update data in the storage unit 33, for example. After the reception of the received update data is complete, the control unit 32 of the ECU 12 may be configured to update the software based on the update data temporarily stored in the storage unit 33.
[0075] [1.5.4 Activation Section] The Activate Unit 44 has the function of causing the First In-Vehicle Device, which performs a predetermined First Function without the Second In-Vehicle Device, to activate the software updated by the First Update Data when the Determination Unit determines that the power state is the First State, and when the Determination Unit determines that the power state is the Second State, to cause the First In-Vehicle Device and the Second In-Vehicle Device, which perform a predetermined Second Function by performing a predetermined Second Function together, to activate the software updated by the First Update Data and the Second Update Data.
[0076] Specifically, in the example shown in Figure 6, which is a security function that operates in a +B state overall, when the determination unit 42 determines that the power state is in a +B state, the activation unit 44 causes the door detection ECU and the notification ECU, which operate in a +B state, to activate the software updated with the first update data. More specifically, the activation unit 44 refers to the ECU table stored in the storage unit 23, for example, the contents shown in Figure 6. From the referenced ECU table, the activation unit 44 obtains information indicating which power state the function operates in. In the example in Figure 6, the security function operates in both a +B state and an IG state, so for example, when the power state is in a +B state, the activation unit 44 simultaneously sends commands to the door detection ECU and the notification ECU to activate.
[0077] On the other hand, when the determination unit 42 determines that the power supply state is in the IG state, the activation unit 44 activates the ECUs that perform functions that operate in the IG state as a whole. For example, in the case of the power window control function in rainy weather, the activation unit 44 simultaneously activates the updated software in the door ECU, BCM, and rain sensor ECU. More specifically, the activation unit 44 refers to the ECU table (Figure 5) and obtains information indicating that the power window control function in rainy weather operates in the IG state as a whole. When the determination unit 42 determines that the power supply state is in the IG state, based on the acquired information, the activation unit 44 simultaneously sends commands to the door ECU, BCM, and rain sensor ECU to instruct them to activate.
[0078] [1.6 Control Method] Figure 7 is a flowchart showing an example of a control method performed by the update management ECU 11. The order of each step shown in Figure 7 may be changed as appropriate. The series of control methods will be explained using Figure 7.
[0079] The control performed by the update management ECU 11 is carried out by the information processing unit 21. When the information processing unit 21 performs control, the control unit 22 reads a computer program from the storage unit 23 and performs various calculations and processes. Furthermore, the control performed by the first ECU 12 is carried out by the information processing unit 31. When the information processing unit 31 performs control, the control unit 32 reads a computer program from the storage unit 33 and performs various calculations and processes.
[0080] First, the receiving unit 41 of the update management ECU 11 downloads update data from the server 2 (steps S10 and S101). Specifically, the update management ECU 11 receives from the vehicle's external device first update data for updating the software of the first in-vehicle device that operates in a first power state and a second power state different from the first power state, and second update data for updating the software of the second in-vehicle device that does not operate in the first power state but operates in the second power state. After the reception is complete, the process proceeds to step S102.
[0081] More specifically, the receiving unit 41 of the update management ECU 11 downloads the first update data and the second data from the server 2. The server 2 stores the update data for each ECU. The first update data is an update data for updating the software of the first ECU 12, which is a +B drive ECU. Ta Yes. The second update data is update data for updating the software of the second ECU 13, which is the IG drive ECU. The update management ECU 11 accesses server 2 via communication bus 16b, transceiver 25a, communication device 15, and network 3, and downloads the update data stored in server 2.
[0082] For example, when update data is newly recorded on server 2, server 2 transmits update software information to each in-vehicle system 1. The update software information may include information indicating the version of the newly recorded update data.
[0083] Each in-vehicle system 1's update management ECU 11 stores, for example, an ECU table in its storage unit 23, as shown in Figure 5. The ECU table records, in tabular format for each predetermined function, information indicating a predetermined function, the ECU that performs the predetermined function, the power supply state in which the ECU operates, and the software version of the ECU.
[0084] The receiving unit 41 of the update management ECU 11 compares, for example, the update software information (including version information) sent from the server with the ECU table recorded in the storage unit 23 to determine whether the software has been updated. For example, it compares the software versions to determine whether it has been updated. If it determines that it has been updated, the receiving unit 41 requests the update data from the server 2 and downloads it. The receiving unit 41 temporarily records the downloaded update data in the storage unit 23. After the download is complete, the process proceeds to step S102.
[0085] Next, the determination unit 42 of the update management ECU 11 determines whether the power state of the vehicle is the first power state or the second power state (step S102).
[0086] Specifically, the determination unit 42 of the update management ECU 11 detects, for example, the power supply state of the vehicle and determines whether the detected power supply state is in the +B state or not. If the determination unit 42 of the update management ECU 11 determines that it is in the +B state (YES in step S102), the process proceeds to step S103. If it determines that it is not in the +B state, i.e., in the IG state (NO in step S102), the process proceeds to step S104.
[0087] Next, when the transmission unit 43 of the update management ECU 11 determines that the vehicle's power state is the first power state (YES in step S102), it transmits the first update data to the first in-vehicle device (step S103). After transmission is complete, the process proceeds to step S105. Specifically, for example, when the determination unit 42 determines that the vehicle's power state is the +B state, the transmission unit 43 of the update management ECU 11 transmits the first update data to the first ECU 12, which is a +B drive ECU that has not been updated. Whether or not the ECU software has been updated is determined, for example, by recording whether or not it has been updated in the ECU table. Based on the ECU table stored in the storage unit 23, the transmission unit 43 of the update management ECU 11 may transmit the update data to the +B drive ECUs stored in the ECU table. In the example in Figure 5, the update data is transmitted to the door ECU and the BCM.
[0088] On the other hand, when the determination unit determines that the vehicle's power state is the second power state (NO in step S102), the second update data is transmitted to the second in-vehicle device (step S104). After transmission is complete, the process proceeds to step S105. Specifically, for example, when the determination unit 42 determines that the vehicle's power state is the IG state, the transmission unit 43 of the update management ECU 11 transmits the second update data to the second ECU 13, which is an IG drive ECU that has not been updated. Based on the ECU table stored in the storage unit 23, the transmission unit 43 of the update management ECU 11 may also transmit update data to the IG drive ECUs stored in the ECU table. In the example in Figure 5, update data is transmitted to the rain sensor ECU.
[0089] Even if the determination unit 42 determines that the state is IG, if there are still +B drive ECUs that have not been updated, the transmission unit 43 may send the first update data to those ECUs. This is because the power state may change from +B state to IG state while the first update data is being sent to an unupdated +B drive ECU, but the +B drive ECU will still operate even if the power state is IG. Therefore, in step S104, regardless of whether it is a +B drive ECU or an IG drive ECU, the transmission unit 43 will send the update data to the unupdated ECU.
[0090] The first ECU 12 (door ECU, BCM) and the second ECU 13 (rain sensor ECU) temporarily store the received update data in the storage unit 33, for example, when update data is sent. After the reception of the received update data is complete, the control unit 32 may update the software based on the update data temporarily stored in the storage unit 33.
[0091] Next, the transmission unit 43 of the update management ECU 11 determines whether or not update data has been sent to all of the multiple ECUs that perform a predetermined function (step S105). Specifically, for example, the transmission unit 43 of the update management ECU 11 refers to the ECU table stored in the storage unit 23 and determines whether or not update data has been sent to all of the ECUs stored in the ECU table. If the transmission unit 43 determines that update data has been sent to all ECUs, it proceeds to step S106, and if it determines that update data has not been sent to all ECUs, it returns to step S102. Therefore, steps S102 to S104 are repeated until the transmission unit 43 has sent update data to all ECUs. In the example shown in Figure 5, the power window control function in rainy weather is performed by the door ECU, rain sensor ECU, and BCM, so it is determined whether or not update data has been sent to all three ECUs: the door ECU, rain sensor ECU, and BCM.
[0092] Next, activate the update management ECU11. Department 44 is the power state of the vehicle when the power state is such that a predetermined function is in operation. In a manner The system determines whether or not the power supply is present (step S106). If the activation unit 44 of the update management ECU 11 determines that the power supply state is such that an ECU that performs a predetermined function can operate, it proceeds to step S107. If it determines that the power supply state is not such that an ECU that performs a predetermined function can operate, it returns to step S106. Therefore, the activation unit 44 of the update management ECU 11 waits until the vehicle's power supply state becomes such that a predetermined function can operate.
[0093] For example, the aforementioned anti-theft function is performed by a door detection ECU that detects whether the door is closed and locked, and a notification ECU that alerts the driver. Since both the door detection ECU and the notification ECU are +B drive ECUs, the anti-theft function as a whole operates in both the +B state and the IG state. In this example, after the update management ECU 11 sends update data to the ECU, it proceeds to step S107 when it determines that the power state is in the +B state.
[0094] On the other hand, the aforementioned power window control function during rainy weather is performed by the door ECU, rain sensor ECU, and BCM. The door ECU and BCM are +B drive ECUs, but the rain sensor ECU is an IG drive ECU, so the power window control function as a whole operates in the IG state. For this reason, in this example, the activation unit 44 of the update management ECU 11 proceeds to step S107 when it determines that the power state is in the IG state after sending the update data to the ECU.
[0095] Next, the activation unit 44 of the update management ECU 11 activates a group of ECUs that perform a predetermined function (step S107). Specifically, for example, the activation unit 44 of the update management ECU 11 transmits an activation command to the first ECU 12 or the second ECU via the internal bus 24 transceiver 25b and the communication bus 16a, using the control unit 22. The ECU that receives the activation command activates the software updated with the update data. For example, in the case of the anti-theft function described above, it transmits an activation command to the door detection ECU and the notification ECU. In the case of the power window control function during rainy weather described above, it transmits an activation command to the door ECU, the rain sensor ECU, and the BCM. Then, after sending a command to activate, the series of controls ends.
[0096] [1.7 Control Sequence] Next, the control sequence of the in-vehicle system 1 will be described. Figure 8 is a sequence diagram when a predetermined function is performed by the +B drive ECU. Figure 9 is a sequence diagram when a predetermined function is performed by both the +B drive ECU and the IG drive ECU.
[0097] [1.7.1 When executed by the +B drive ECU] One example of a function performed by the +B drive ECU is the anti-theft function mentioned above. First, the receiving unit 41 of the update management ECU 11 downloads update data from the server 2 (step S201). Since it only downloads update data, it is sufficient for the update management ECU 11 to be operational. The update management ECU 11 can operate in both the +B and IG states, so step S201 is executed as long as the power supply state is at least +B.
[0098] Next, the transmission unit 43 of the update management ECU 11 transmits update data from the update management ECU 11 to the first ECU 12 (step S202). In the example of the security function described above, the transmission unit 43 transmits update data to the door detection ECU and the notification ECU.
[0099] Next, the first ECU 12 updates its software based on the update data (step S203). The first ECU 12 is configured to update its software based on the update data after, for example, the completion of receiving the update data.
[0100] Next, the activate unit 44 of the update management ECU 11 sends a command to the first ECU instructing it to activate (step S204).
[0101] Next, the group of first ECUs 12 that perform predetermined functions and have received an activation command activate the updated software (step S205). After the activation is complete, the series of controls is terminated.
[0102] [1.7.2 When executed by the +B drive ECU and IG drive ECU] One example of a function performed by the +B drive ECU and IG drive ECU is the power window control function mentioned above. First, the receiving unit 41 of the update management ECU 11 downloads update data from the server 2 (steps S30 and S301).
[0103] Next, the transmission unit 43 of the update management ECU 11 transmits update data to the first ECU 12 (step S302). In the example of the power window control function described above, the door ECU and BCM are +B drive ECUs, but the rain sensor ECU is an IG drive ECU, so in this step, update data is transmitted to the door ECU and BCM.
[0104] Next, the first ECU 12 updates its software based on the update data (step S303).
[0105] Next, when the power state changes from the +B state to the IG state, that is, when the determination unit 42 of the update management ECU 11 determines that the power state is the IG state, the transmission unit 43 of the update management ECU 11 transmits update data to the update management ECU 11. In the case of the power window control function described above, the transmission unit 43 transmits the update data to the rain sensor ECU, which is the IG drive ECU (step S304).
[0106] Next, the second ECU 13 updates the software of the ECU based on the update data (step S305). The second ECU 13 is configured to update the software based on the update data after, for example, the completion of receiving the update data.
[0107] Next, the activation unit 44 of the update management ECU 11 sends commands to the first ECU 12 and the second ECU 13 instructing them to activate (step S306).
[0108] Next, the group of first ECUs 12 and second ECUs 13 that perform predetermined functions activate the updated software (steps S307 and S308). After activation is complete, the series of controls is terminated.
[0109] [1.8 Summary] If ECUs that had received software updates and those that had not were mixed, there was a risk of communication discrepancies between the ECUs. For this reason, software updates were performed when all ECUs were powered on, for example, when the ignition was engaged. In such cases, the software update would begin from the moment the driver turned the key switch to the ignition position, potentially increasing the time it took for the vehicle to become drivable. Furthermore, because the update was performed when all ECUs were powered on, regardless of whether an update was necessary or not, power was supplied to ECUs that did not require an update, potentially increasing power consumption.
[0110] According to this embodiment, the update management ECU 11 sends update data to ECUs whose software can be updated, depending on the vehicle's power state, and causes those ECUs to update their software. In the example described above, the update management ECU 11 sends update data to the +B drive ECUs, namely the door ECU, BCM, door detection ECU, and notification ECU, while the power state is +B, without waiting for the power state to become IG. In the +B state, each +B drive ECU can update its software based on the update data. Therefore, when the vehicle driver turns the key switch to the ignition position to start the engine, that is, when the power state changes from +B to IG, the software update of the ECU is completed. Consequently, the vehicle can be driven only by waiting for the software update of the IG drive ECU, which only operates in the IG state, thus shortening the time it takes for the vehicle to become drivable. In addition, since the software update of the +B drive ECU is performed during a period when the IG drive ECU is not operating, power consumption can be reduced.
[0111] Furthermore, when software updates are performed on each ECU, the timing of the completion of the software update for each ECU may differ. If each ECU is activated immediately after its software update, there is a risk that functions that require multiple ECUs to work together may not be executed. For example, if an activated ECU sends a command to an ECU that has not yet been activated, the unactivated ECU may not understand the command, and therefore the function may not be executed.
[0112] According to this embodiment, the update management ECU 11 activates the updated software simultaneously for a group of in-vehicle devices that perform a predetermined function, while the power supply state is in which the function is operating. For example, the aforementioned power window control function during rainy weather is performed by the door ECU, rain sensor ECU, and BCM. Since the door ECU and BCM are +B drive ECUs, and the rain sensor ECU is an IG drive ECU, the function as a whole operates in the IG state. Therefore, when the power supply state is in the IG state, the update management ECU 11 simultaneously activates these ECUs. Consequently, each ECU communicates without discrepancies, the door windows are closed when there is an appropriate amount of rain, and the risk of discrepancies such as the door windows remaining open even when it is raining is eliminated.
[0113] <Embodiment 2> [2. Details of Embodiment 2 of this Disclosure] The details of Embodiment 2 of this disclosure will be described below with reference to the drawings. The difference between Embodiment 1 and Embodiment 2 is that Embodiment 2 is an update management device that also updates software for ECUs added at a later date, but otherwise they are the same. The same reference numerals are used for components identical to those in Embodiment 1, and descriptions of identical components, functions, and operations are omitted. An example of adding a new ECU at a later date is when a seat heater is added to a completed vehicle that does not have one, and a seat ECU to control the seat heater is added at a later date.
[0114] [2.1 Problems to be solved by this embodiment] Previously, when a new system involving the addition of an ECU was installed in a new vehicle, there was no function to update the software of the aftermarket ECU. As a result, the software of the aftermarket ECU would not be updated, potentially leading to malfunctions such as the inability to perform certain functions, or, for example, the seat heater not heating up.
[0115] [2.2 Means for solving the problems of this embodiment] Therefore, in this embodiment, when a third in-vehicle device is newly connected to the update management device to which the first in-vehicle device and the second in-vehicle device are connected, the receiving unit receives third update data for updating the software of the third in-vehicle device from an external device of the vehicle. When the third in-vehicle device operates in the first power state and the second power state, and the determination unit determines that the power state of the vehicle is the first power state, the transmitting unit transmits the third update data to the third in-vehicle device. When the third in-vehicle device does not operate in the first power state but operates in the second power state, and the determination unit determines that the power state of the vehicle is the second power state, the transmitting unit transmits the third update data to the third in-vehicle device.
[0116] In particular, in this embodiment, the operation of the update management device when a third in-vehicle device is newly connected to the update management device to which the first and second in-vehicle devices are connected differs from that of Embodiment 1. The control method for this difference will be described below.
[0117] [2.3 Control Method] Figure 10 shows the operation flowchart of the update management ECU 11 when a new ECU is added, specifically the portion added to the flowchart in Figure 7. The newly connected third in-vehicle device is the third ECU 14 in Figure 1.
[0118] First, the update management ECU 11 detects the retrofitted ECU (step S401) and proceeds to step S402. One way to detect the retrofitted ECU is, for example, by checking whether communication has been established between the update management ECU 11 and the newly connected third ECU 14. Alternatively, the update management ECU 11 periodically broadcasts a command to the communication bus 16a requesting a response from all ECUs connected to the communication bus 16a. The update management ECU 11 may then compare the responding ECUs with the ECU table stored in the storage unit 23, which lists already connected ECUs, and determine that a retrofitted ECU has been detected if a response is received from an ECU not listed in the ECU table.
[0119] Next, the update management ECU 11 obtains the vehicle's power status (step S402) and proceeds to step S403.
[0120] Next, the update management ECU 11 determines whether the power supply state is +B state or not (step S403). If it determines that the power supply state is +B state, it proceeds to step S404. On the other hand, if it determines that the power supply state is not +B state, that is, if it determines that the power supply state is IG state, it proceeds to step S405. Since the +B drive ECU responds when the power supply state is +B state and the IG drive ECU responds when the power supply state is IG state, by knowing the power supply state, the update management ECU 11 can determine whether the ECU that newly responded in step S401 is a +B drive ECU or an IG drive ECU.
[0121] Next, if the update management ECU 11 determines that the power state is +B, the update management ECU 11 adds the ECU that detected step S401 to the ECU table, which lists the ECUs that perform a predetermined function when the function as a whole operates in the +B state (step S404). On the other hand, if the update management ECU 11 determines that the power supply state is not +B state (i.e., it is IG state), then, for example, if a predetermined function operates as a whole in the IG state, the ECU that detected step S401 will be added to the ECU table that lists the ECUs that execute the function (step S405). After the above series of processes are completed, the update management ECU 11 proceeds to step S101 shown in Figure 7 and continues processing.
[0122] [2.4 Summary] Previously, when a new system involving the addition of an ECU was installed in a new vehicle, there was no function to update the software of the retrofitted ECU. As a result, the software of the retrofitted ECU would not be updated, potentially leading to discrepancies where the intended functions could not be performed.
[0123] According to this disclosure, when a new third in-vehicle device is connected to the update management device, the third update data is transmitted to the third in-vehicle device while the third in-vehicle device is in an operational power state. This allows the newly added third in-vehicle device to be updated at the appropriate time.
[0124] [3. Supplementary Notes] Furthermore, at least some of the embodiments and variations described above may be combined in any way. Also, the embodiments and variations disclosed herein should be considered in all respects as illustrative and not restrictive. The scope of this disclosure is defined by the claims, and all modifications within the meaning and scope of equivalence to the claims are intended. [Explanation of Symbols]
[0125] 1. In-vehicle systems 2 servers 3 Network 11 Update management ECU 12 1st ECU 13 2nd ECU 14 3rd ECU 15. Communication equipment 16a Communications bus 16b Communications Bus 21 Information Processing Department 22 Control Unit 23 Memory section 24 Internal bus 25a Transceiver 25b Transceiver 31 Information Processing Department 32 Control Unit 33 Storage section 34 Internal bus 35 Input section 36 Output section 37 Transceivers 41 Receiving unit 42 Judgment section 43 Transmitter 44 Activation Department
Claims
1. A software update management device for managing software updates for in-vehicle devices in a vehicle having multiple power states, The plurality of power states include a first power state and a second power state different from the first power state, and the receiving unit receives from an external device of the vehicle first update data for updating the software of a first in-vehicle device that operates in the first power state and the second power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state, A determination unit that determines whether the power state of the vehicle is the first power state or the second power state, When the determination unit determines that the power state of the vehicle is the first power state, the first update data is transmitted to the first in-vehicle device. When the determination unit determines that the power state of the vehicle is the second power state, the transmission unit transmits the second update data to the second in-vehicle device, When the determination unit determines that the power state is the first power state, the first in-vehicle device, which performs a predetermined first function without the second in-vehicle device, is instructed to activate the software updated by the first update data. When the determination unit determines that the power state is the second power state, the activation unit causes the first and second in-vehicle devices, which execute a predetermined second function, to activate the software updated by the first update data and the second update data. Equipped with, Update management device.
2. The receiving unit receives the first update data and the second update data from the external device while the power state is the first power state. The update management device according to claim 1.
3. The update management device is, When a third in-vehicle device is newly connected to the update management device to which the first and second in-vehicle devices are connected, the receiving unit receives third update data for updating the software of the third in-vehicle device from an external device of the vehicle. When the third in-vehicle device operates in the first power state and the second power state, and the determination unit determines that the vehicle's power state is the first power state, the transmission unit transmits the third update data to the third in-vehicle device. When the third in-vehicle device does not operate in the first power state but operates in the second power state, and the determination unit determines that the vehicle's power state is the second power state, the transmission unit transmits the third update data to the third in-vehicle device. The update management device according to claim 1.
4. The receiving unit receives the first update data, the second update data, and the third update data from an external device while the power state is the first power state. The update management device according to claim 3.
5. The activation unit is, When the third in-vehicle device operates in the first power state and the second power state, and the determination unit determines that the power state is the first power state, the determination unit causes the third in-vehicle device to activate the software updated by the third update data in the third in-vehicle device which performs a predetermined third function with the first in-vehicle device without the second in-vehicle device, and causes the first in-vehicle device which performs the third function to activate the software updated by the first update data. When the third in-vehicle device does not operate in the first power state but operates in the second power state, and the determination unit determines that the power state is the second power state, the third in-vehicle device, which performs a predetermined fourth function with the second in-vehicle device, is instructed to activate the software updated by the third update data, and the second in-vehicle device, which performs the fourth function, is instructed to activate the software updated by the second update data. The update management device according to claim 3.
6. The update management device according to claim 1, wherein the first power state is the power state when the vehicle is in a state where it cannot run, and the second power state is the power state when the vehicle is in a state where it can run.
7. The update management device according to any one of claims 1, 2, or 6, An in-vehicle system comprising the first in-vehicle device and the second in-vehicle device connected to the update management device.
8. The update management device according to any one of claims 3 to 5, An in-vehicle system comprising the first in-vehicle device, the second in-vehicle device, or the third in-vehicle device connected to the update management device.
9. A control method for an update management device that manages software updates for in-vehicle devices in a vehicle having multiple power states, The plurality of power states include a first power state and a second power state different from the first power state, and the receiving step includes receiving first update data for updating the software of a first in-vehicle device that operates in the first power state and the second power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state, from an external device of the vehicle. A determination step of determining whether the power state of the vehicle is the first power state or the second power state, If the determination step determines that the power state of the vehicle is the first power state, a first transmission step is performed to transmit the first update data to the first in-vehicle device, If the determination step determines that the power state of the vehicle is the second power state, a second transmission step is performed to transmit the second update data to the second in-vehicle device, When it is determined that the power state is the first power state, the first in-vehicle device, which performs a predetermined first function without the second in-vehicle device, activates the software updated by the first update data; When it is determined that the power state is the second power state, the first and second in-vehicle devices perform a predetermined second function, and the first and second in-vehicle devices activate the software updated by the first update data and the second update data. Equipped with, A control method for an update management device.
10. A computer program for controlling an update management device that manages software updates for in-vehicle devices in a vehicle having multiple power states, The plurality of power states include a first power state and a second power state different from the first power state, and the receiving step includes receiving first update data for updating the software of a first in-vehicle device that operates in the first power state and the second power state, and second update data for updating the software of a second in-vehicle device that does not operate in the first power state but operates in the second power state, from an external device of the vehicle. A determination step of determining whether the power state of the vehicle is the first power state or the second power state, If the determination step determines that the power state of the vehicle is the first power state, a first transmission step is performed to transmit the first update data to the first in-vehicle device, If the determination step determines that the power state of the vehicle is the second power state, a second transmission step is performed to transmit the second update data to the second in-vehicle device, When it is determined that the power state is the first power state, the first in-vehicle device, which performs a predetermined first function without the second in-vehicle device, activates the software updated by the first update data; When it is determined that the power state is the second power state, the first and second in-vehicle devices perform a predetermined second function, and the first and second in-vehicle devices activate the software updated by the first update data and the second update data. Equipped with, A computer program for controlling an update management device.