warm water machine

The hot water heating device monitors microcomputer operation during firmware updates through a dual-control unit system, ensuring normal operation and stability during software updates.

JP7869437B2Active Publication Date: 2026-06-03NORITZ CORP

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
NORITZ CORP
Filing Date
2022-02-17
Publication Date
2026-06-03

AI Technical Summary

Technical Problem

Existing hot water equipment cannot monitor whether the control unit (microcomputer) is operating normally during software update processing such as firmware updates.

Method used

A hot water heating device with a first microcomputer and an abnormality monitor that includes a second control unit for monitoring abnormalities during software updates, and a third control unit for controlling software update processing, allowing parallel operation of abnormality detection and firmware updates.

Benefits of technology

Enables continuous monitoring of the microcomputer's normal operation during software updates, ensuring the system's stability and functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007869437000001
    Figure 0007869437000001
  • Figure 0007869437000002
    Figure 0007869437000002
  • Figure 0007869437000003
    Figure 0007869437000003
Patent Text Reader

Abstract

To provide a water heater capable of appropriately monitoring whether a microcomputer is operating normally even during software update processing.SOLUTION: Each of a monitoring IC 220A and a sub-microcomputer 220B communicates with a microcomputer 210 to detect an abnormality in the microcomputer 210. During software update processing of the microcomputer 210, an update control unit 230 on the one hand sets, as an update processing target, software related to an apparatus control unit 234 and an abnormality determination unit 232b, and on the other hand excludes software related to an abnormality determination unit 232a from the update processing target. The abnormality determination unit 232a performs periodic communication for abnormality monitoring with the monitoring IC 220A or the sub-microcomputer 220B during software update processing in the apparatus control unit 234.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to hot water equipment.

Background Art

[0002] Japanese Patent Application Laid-Open No. 2020-133958 (Patent Document 1) describes a hot water supply device having an abnormality determination function by performing communication between a plurality of control units. Specifically, an abnormality determination function is realized by an abnormality determination unit that performs predetermined communication from one control unit to another control unit and determines the abnormality of the other control unit based on the presence or absence of a response to the predetermined communication. Further, Patent Document 1 describes that the abnormality determination unit is invalidated during a period when the other control unit is updating firmware, so as to appropriately execute the abnormality determination.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the hot water equipment of Patent Document 1, there is a problem that it becomes impossible to monitor whether the control unit (microcomputer) is operating normally during software update processing such as firmware.

[0005] The present invention has been made to solve such problems, and an object of the present invention is to provide a hot water equipment capable of appropriately monitoring whether a microcomputer is operating normally even during software update processing.

Means for Solving the Problems

[0006] According to one embodiment of the present disclosure, a hot water heating device is provided. The hot water heating device comprises a first microcomputer and an abnormality monitor for detecting abnormalities in the first microcomputer with communication between the first microcomputer and the first microcomputer. The first microcomputer has a first control unit for controlling the operation of mounted equipment of the hot water heating device, a second control unit for performing communication with the abnormality monitor for monitoring abnormalities of the first microcomputer, and a third control unit for controlling software update processing in the first microcomputer. The second control unit has a first abnormality monitoring unit that performs communication with the abnormality monitor for monitoring abnormalities during software update processing of the first control unit, and a second abnormality monitoring unit that performs communication with the abnormality monitor for monitoring abnormalities when the first control unit is operating. [Effects of the Invention]

[0007] According to the present invention, it is possible to appropriately monitor whether the microcomputer is operating normally during the software update process of the microcomputer of a hot water equipment. [Brief explanation of the drawing]

[0008] [Figure 1] This is a schematic diagram showing an example of the configuration of a communication system for a hot water heater according to this embodiment. [Figure 2] This is a block diagram illustrating the anomaly monitoring configuration for a microcontroller. [Figure 3] This is a block diagram illustrating an example of a microcontroller configuration. [Figure 4] This block diagram illustrates a comparative example of microcontroller operation and anomaly monitoring during firmware updates. [Figure 5] This is a block diagram illustrating the operation of the microcontroller and abnormality monitoring during firmware updates in the hot water equipment according to this embodiment. [Figure 6] This is a conceptual diagram illustrating an example of the timing of anomaly monitoring during firmware update processing. [Figure 7]This is a flowchart illustrating the control process performed by the firmware update control unit. [Modes for carrying out the invention]

[0009] Embodiments of the present invention will be described in detail below with reference to the drawings. In the following description, the same or corresponding parts in the drawings will be denoted by the same reference numerals, and their descriptions will not be repeated in principle.

[0010] Figure 1 is a schematic diagram showing an example of the configuration of a communication system for a hot water equipment according to this embodiment.

[0011] Referring to Figure 1, the communication system 5 for the hot water equipment according to this embodiment comprises a hot water equipment 100, an interface device 20, an external communication network 40, and a server 50. The communication system 5 establishes a communication connection between the hot water equipment 100 and the server 50 for remote management and remote operation of the hot water equipment 100 via the server 50.

[0012] The hot water equipment 100 is, for example, a hot water supply system and includes a water heater 110, remote controllers (hereinafter also simply referred to as "remote controls") 120, 130, and a communication adapter 150.

[0013] For example, remote control 120 can be installed in the bathroom. Also, remote control 130 can be installed in the kitchen. In this way, using remote controls 120 and 130, the user can make various settings for each function of the water heater 110.

[0014] The communication adapter 150 has a wireless communication function for communicating with the interface device 20 using a predetermined communication protocol (e.g., IEEE802.11n). In the example shown in Figure 1, the communication adapter 150 is built into the remote control 130, but it may also be located outside the remote controls 120 and 130.

[0015] The hot water from the water heater 110 is sent to the hot water supply destination via the pipes connected to the plurality of hot water outlets 111. For example, the hot water supply destination includes a faucet and a bathtub not shown in the figure. Alternatively, by including a heater (not shown) that uses high-temperature water as a heat source in the hot water supply destination, the hot water equipment 100 can have a heating function.

[0016] Inside the water heater 110, a circuit board 200 is mounted. On the circuit board 200, a microcomputer (hereinafter referred to as "microcontroller") 210 for driving and controlling the water heater 110 is mounted. By the microcontroller 210, a solenoid valve (not shown) for controlling the supply of fuel gas to a burner not shown in the figure, an air supply fan (not shown) for supplying air mixed with the fuel gas, etc. are controlled.

[0017] The water heater 110 and the remote controllers 120, 130 are connected by a communication line (for example, a two-core communication line) 101. The remote controllers 120, 130 have display units 121, 131 and input units 122, 132. The user can set hot water filling, hot water supply set temperature, etc. by operating the input units 122, 132 according to the display screens on the display units 121, 131.

[0018] The interface device 20 has a function of communicatively connecting devices existing within a certain range including the remote controllers 120, 130 to the server 50 via the external communication network 40. For example, the interface device 20 can be constituted by a so-called wireless LAN (Local Area Network) router. Also, the external communication network 40 is typically the Internet. Hereinafter, the external communication network 40 will also be simply referred to as the Internet 40.

[0019] Incidentally, as the interface device 20, it is also possible to use a wired LAN router instead of a wireless LAN router. In this case, the communication adapter 150 can be configured to communicate with the wired LAN router using a predetermined communication protocol (for example, IEEE802.3 of the Ethernet standard, etc.).

[0020] Server 50 is connected to the Internet 40 and has a function for managing remote control (remote operation and remote monitoring) of the hot water equipment 100. The communication adapter 150 can communicate with the server 50 via the Internet 40 by being communicatively connected to the interface device 20 through wireless communication. Thereby, the hot water equipment 100 is communicatively connected to the server 50 with the communication adapter 150 as a relay device.

[0021] It is also possible to communicatively connect to the server 50 from a portable terminal device 30 such as a smartphone or a tablet terminal. When the portable terminal device 30 exists within a range where it can be connected to the interface device 20, the portable terminal device 30 can communicate with the server 50 by being connected to the interface device 20 through wireless communication. Also, when the portable terminal device 30 is outside the house or the like, the portable terminal device 30 can communicate with the server 50 by connecting to the Internet 40 via the router 60 or the base station 70.

[0022] In this way, in addition to operating the remote controls 120 and 130, the user can also perform remote control (remote operation and remote monitoring) of the hot water equipment 100 by accessing the server 50 both inside and outside the range where the portable terminal device 30 can be connected to the interface device 20.

[0023] An application program for the hot water equipment 100 can be installed in the portable terminal device 30. For example, the application program is installed after being downloaded from the server 50.

[0024] In addition, the water heater 110 (microcomputer 210) and the remote controls 120 and 130 each store software (hereinafter also referred to as "firmware (F / W)") for controlling the operation of the water heater 110. The firmware is written to the system at the time of factory shipment with the current version, and in this embodiment, it can be rewritten with a different version of the firmware through distribution from the server 50.

[0025] Next, the configuration for monitoring abnormalities in the microcontroller 210 of the water heater 110 will be explained using Figure 2.

[0026] As shown in Figure 2(a), in addition to the microcontroller 210, a monitoring IC 220A, such as a watchdog IC (Integrated Circuit), can be mounted on the circuit board 200 to perform abnormal monitoring of the microcontroller 210.

[0027] In this case, the microcontroller 210 is programmed to output a pulse PLS periodically, for example, at regular intervals or after a certain unit of program processing is completed. The monitoring IC 220A receives the pulse PLS periodically output from the microcontroller 210, and if it does not receive the next pulse after a predetermined time has elapsed since the previous pulse was received, it determines that the pulse PLS has been interrupted and detects an abnormality in the microcontroller 210.

[0028] When the monitoring IC 220A detects an abnormality in the microcontroller 210, it outputs a reset signal to initialize the microcontroller 210. When the microcontroller 210 receives the reset signal from the monitoring IC 220A, it executes a reset process (initialization process). This prevents the control of the water heater 110 from continuing while the microcontroller 210 remains in an abnormal state.

[0029] Referring to Figure 2(b), if multiple microcontrollers are mounted on the circuit board 200, it is possible to monitor each other for abnormalities through communication between the microcontrollers. For example, in addition to the microcontroller 210, a sub-microcontroller 220B is further mounted on the circuit board 200.

[0030] In this case, the sub-microcontroller 220B is configured to have different control functions than the microcontroller 210, such as a function to control the lighting of a display LED (Light Emitting Diode). Periodic bidirectional communication takes place between the microcontroller 210 and the sub-microcontroller 220B, in which the microcontroller 210 outputs transmission data DT1 to the sub-microcontroller 220B, and the sub-microcontroller 220B outputs transmission data DT2 to the microcontroller 210. For example, transmission data DT1 includes a command for display control using the LED, and transmission data DT2 includes information indicating the current display state of the LED.

[0031] When this periodic communication is interrupted, the sub-microcontroller 220B can detect an abnormality in the microcontroller 210. For example, if the sub-microcontroller 220B does not receive the next transmission data DT1 after a predetermined time has elapsed since it last received the transmission data DT1 from the microcontroller 210, it determines that the transmission data DT1 has been interrupted and detects an abnormality in the microcontroller 210.

[0032] Figure 3 shows a block diagram illustrating an example configuration of the microcontroller 210.

[0033] Referring to Figure 3, the microcontroller 210 includes a CPU (Central Processing Unit) 211, memory 212, interface (I / F) 213, bus 214, and communication circuits 215 and 216. The CPU 211, memory 212, interface (I / F) 213, and communication circuits 215 and 216 are configured to exchange data with each other via the bus 214.

[0034] Memory 212 includes RAM (Random Access Memory) and ROM (Read Only Memory), which are not shown in the diagram. The ROM is typically composed of EEPROM (Electrically Erasable Programmable Read-Only Memory) and stores the firmware of the communication adapter 150 and data used for control. During the startup process, the CPU 211 reads the firmware stored in ROM and loads it into RAM, thereby sequentially executing the various processes programmed in the firmware.

[0035] Interface (I / F) 213 has the function of receiving an analog voltage, which is a detection value from a sensor (not shown) located on the water heater 110, and converting it into digital data used for the program processing described above. Furthermore, interface 213 has the function of converting a digital signal indicating a control command to each component (not shown) of the water heater 110, generated by the program processing, into an analog voltage signal to be output to said component.

[0036] The communication circuit 215 is configured to communicate data bidirectionally with the microcomputers (not shown) of the remote controls 120 and 130, enabling mutual exchange of information. Similarly, the communication circuit 216 is configured to communicate with the monitoring IC 220A or sub-microcontroller 220B shown in Figure 2.

[0037] Next, we will explain a comparative example of the operation of the microcontroller 210 and abnormality monitoring during firmware updates using Figure 4.

[0038] Figures 4(a) and 4(b) show comparative examples of the operation of the microcontroller 210 and abnormality monitoring during firmware updates in the abnormality monitoring configurations shown in Figures 2(a) and 2(b), respectively. In these comparative examples, the technology described in Patent Document 1 is applied.

[0039] Referring to Figure 4(a), the microcontroller 210 includes a firmware update control unit 230, an abnormality detection unit 232, and an equipment control unit 234. In Figure 3, the firmware update control unit 230, the abnormality detection unit 232, and the equipment control unit 234 are shown as functional blocks that perform the respective functions of the microcontroller 210, which are realized by the CPU 211 executing different programs. The abnormality detection unit 232 has the function of periodically outputting a pulse PLS, as described in Figure 2(a).

[0040] In the communication system 5 shown in Figure 1, the server 50, which is connected to the water heater 110 via a communication adapter 150, manages the firmware version information of the water heater 110 and sends a firmware update instruction to the water heater 110 in response to firmware version upgrades, etc. The update instruction includes the URL (Uniform Resource Locator) for downloading the new program after the update (hereinafter also referred to as the "update program") and the program for rewriting with the update program (hereinafter also referred to as the "rewrite program"), as well as information indicating the date and time the firmware update will start.

[0041] When the firmware update control unit 230 receives a firmware update instruction from the server 50, it can download the update program and rewrite program from the server 50 by accessing the URL at an appropriate time after the update start date and time.

[0042] Furthermore, the firmware update control unit 230 executes the firmware update process to the above-mentioned update program, targeting both the abnormality detection unit 232 and the device control unit 234. Therefore, during firmware updates, the functions of the abnormality detection unit 232 and the device control unit 234 become unavailable. Consequently, the abnormality detection unit 232 cannot perform periodic pulse output during firmware updates, and as a result, if the monitoring IC 220A outputs a reset signal to the microcontroller 210, the firmware update process cannot be executed.

[0043] Therefore, in the comparative example shown in Figure 4(a), where Patent Document 1 is applied to the configuration in Figure 2(a), during the firmware update process, the firmware update control unit 230 outputs an instruction signal to the monitoring IC 220A to disable abnormality monitoring. While this enables the firmware update, it makes it impossible to monitor whether the microcontroller 210 is operating normally during the update process.

[0044] In Figure 4(b), the configuration of the microcontroller 210 and its operation during firmware updates are the same as in Figure 4(a). In Figure 4(b), the abnormality detection unit 232 cannot periodically output the transmission data DT1 to the sub-microcontroller 220B during firmware updates. If the sub-microcontroller 220B outputs a reset signal to the microcontroller 210 in response, the firmware update process cannot be executed.

[0045] Therefore, in the comparative example shown in Figure 4(b), where Patent Document 1 is applied to the configuration in Figure 2(b), during the firmware update process, the firmware update control unit 230 outputs an instruction signal to the sub-microcontroller 220B to disable abnormality monitoring. While this enables the firmware update, it makes it impossible to monitor whether the microcontroller 210 is operating normally during the update process.

[0046] Figure 5 shows a block diagram illustrating the operation of the microcontroller and abnormality monitoring during firmware updates in the hot water equipment according to this embodiment.

[0047] Figure 5(a) shows an example of applying this embodiment to the configuration in Figure 2(a). As shown in Figure 5(a), in this embodiment, the abnormality detection unit 232 in Figures 2(a) and 4(a) is divided into an abnormality detection unit 232a for operation during firmware updates and an abnormality detection unit 232b for operation during normal times (for example, when the device control unit 234 is operating).

[0048] When the firmware update control unit 230 performs a firmware update process to rewrite the program related to the device control unit 234 into an update program, it includes the abnormality determination unit 232b in the firmware update process, while excluding the abnormality determination unit 232a from the firmware update process by not updating the related program.

[0049] This allows the abnormality detection unit 232a to periodically output pulses to the monitoring IC 220A for abnormality monitoring, in parallel with the firmware update related to the equipment control unit 234.

[0050] When the firmware is not being updated and the device control unit 234 is operating under normal conditions, the firmware update control unit 230 is disabled. Under normal conditions, in parallel with the operation of the device control unit 234, the abnormality detection unit 232b periodically transmits pulse PLS to the monitoring IC 220A, as shown in Figure 2(a). As a result, the monitoring IC 220A performs the abnormality monitoring described in Figure 2(a).

[0051] Similarly, Figure 5(b) shows an example of applying this embodiment to the configuration in Figure 2(b). In Figure 5(b) as well, the abnormality determination unit 232 in Figures 2(b) and 4(b) is divided into an abnormality determination unit 232a and an abnormality determination unit 232b, similar to Figure 5(a).

[0052] In Figure 5(b), the firmware update control unit 230 also includes the abnormality determination unit 232b as a target for firmware update processing when performing firmware update processing related to the device control unit 234, while excluding the abnormality determination unit 232a from the firmware update processing.

[0053] As a result, the abnormality detection unit 232a can periodically output transmission data DT1* for abnormality monitoring to the sub-microcontroller 220B in parallel with firmware updates related to the equipment control unit 234, and periodically receive transmission data DT2* from the sub-microcontroller 220B.

[0054] Under normal circumstances, the firmware update control unit 230 is disabled, and the abnormality detection unit 232b periodically outputs transmission data DT1 to the sub-microcontroller 220B in parallel with the operation of the device control unit 234, as shown in Figure 2(b). As a result, the sub-microcontroller 220B performs the abnormality monitoring described in Figure 2(b).

[0055] Furthermore, in Figure 5(b), during the firmware update process, it is preferable that the abnormality detection unit 232a operates in such a way that the data DT1* transmitted from the microcontroller 210 to the sub-microcontroller 220B consists of a smaller amount of data compared to the normal data DT1 transmitted by the abnormality detection unit 232b (Figure 2(b)).

[0056] For example, while the normal transmission data DT1 (anomaly detection unit 232b) includes command data for the sub-microcontroller 220B, during firmware updates, the transmission data DT1* (anomaly detection unit 232a) can be configured with simplified content containing only the information necessary for mutual communication.

[0057] Similarly, regarding the data transmitted from the sub-microcontroller 220B to the microcontroller 210, it is preferable that the transmitted data DT2* during firmware updates consists of a smaller amount of data than the transmitted data DT2 under normal circumstances (Figure 2(b)).

[0058] Thus, in the hot water equipment according to this embodiment, when updating the firmware of the equipment control unit 234, which is the main function of the microcomputer 210, a part of the abnormality determination unit 232 (abnormality determination unit 232a) is excluded from the target of the firmware update and operated in parallel with the firmware update.

[0059] Alternatively, the timing of the operation of the abnormality detection unit 232a during firmware updates can be set periodically in conjunction with the progress of the update program writing process. For example, abnormality monitoring by the abnormality detection unit 232a during firmware updates may be performed in parallel with the entire software update process by executing each step of the firmware update process after it is completed.

[0060] Figure 6 shows a conceptual diagram illustrating an example of the timing of anomaly monitoring during firmware update processing.

[0061] Referring to Figure 6, the firmware update control unit 230 divides the update program into N blocks BLK1 to BLKN (N: an integer of 2 or more) and executes the update process to write them to the memory 212 of the microcontroller 210.

[0062] For example, when the firmware update process starts at time ts, at time t1, when the writing of block BLK1 of the update firmware to memory 212 is completed, the abnormality detection unit 232a is instructed to send a pulse PLS (Figure 5(a)) or data DT1*. Then, when the transmission process by the abnormality detection unit 232a is completed, the writing of block BLK2 of the update firmware to memory 212 begins.

[0063] As a result, it is possible to set the operation timing of the abnormality detection unit 232a at each of the times t1 to tN-1 when the writing of blocks BLK1 to BLKN-1 is completed, until the writing of the last block BLKN is completed at time te.

[0064] Figure 7 shows a flowchart illustrating the control process by the firmware update control unit. Once the firmware update control unit 230 has finished downloading the update program and rewrite program from the server 50 as described above, it executes the firmware update process according to the control process shown in Figure 7.

[0065] In step 110 (hereinafter simply referred to as "S"), the firmware update control unit 230 initializes the block counter i (i: a natural number) to 1, and then in step S120, executes a write operation for the i-th block BLKi of the update program to memory 212. Furthermore, once the write operation for block BLKi is completed, in step S130, a write verification operation for the block BLKi is executed. If the write verification result is abnormal, the write operation for block BLKi in step S120 may be re-executed.

[0066] When the writing process for block BLKi is successfully completed, the firmware update control unit 230 sets an operating timing for the abnormality determination unit 232a in S140, and in S150 increments the block counter i. Furthermore, in S160, it is determined whether the incremented block counter i is greater than or equal to (N+1) relative to the number of block divisions N. While i < (N+1) (when S160 determines NO), the processes from S120 to S160 are repeatedly executed. As a result, as shown in Figure 6, an operating timing for the abnormality determination unit 232a is set at each of the times t1 to tN-1. Then, when the writing process for block BLKN is completed, the block counter i is set to = (N+1).

[0067] When i ≥ (N+1) (when S160 is determined to be YES), the firmware update control unit 230 performs a final write verification in S170. If the verification result is normal (when S180 is determined to be YES), the microcontroller 210 is restarted in S190. This allows the water heater 110 to be in a state where the updated firmware is applied.

[0068] On the other hand, if the verification result is not normal (when S180 determines NO), an error message is output by S195. Furthermore, in the firmware update process, by preparing multiple program storage areas in memory 212 in advance, if the pre-update program is still available during the firmware update process, S195 can execute a process to revert to the pre-update firmware.

[0069] In this way, the periodic communication timing for abnormality monitoring by the abnormality detection unit 232a during the firmware update process of the device control unit 234 can be arbitrarily set at regular intervals or after a certain unit of processing is completed.

[0070] As described above, with the hot water equipment according to this embodiment, even during software modification processes of the microcontroller 210, such as firmware update processing, it is possible to appropriately monitor whether the microcontroller 210 is operating normally by operating the abnormality determination unit 232a.

[0071] In Figures 5(a) and 5(b), the microcontroller 210 corresponds to one embodiment of the "first microcontroller," and the monitoring IC 220A corresponds to one embodiment of the "anomaly monitor" and "monitoring integrated circuit." Furthermore, the sub-microcontroller 220B corresponds to one embodiment of the "anomaly monitor" and "second microcontroller." In addition, the device control unit 234 corresponds to one embodiment of the "first control unit," the anomaly determination unit 232 corresponds to one embodiment of the "second control unit," and the firmware update control unit 230 corresponds to one embodiment of the "third control unit." Moreover, the anomaly determination unit 232a as the first anomaly monitoring unit and the anomaly determination unit 232b as the second anomaly monitoring unit together correspond to one embodiment of the second control unit.

[0072] The above example illustrates a configuration in which multiple anomaly monitoring functions (anomaly detection units) are included in a single control unit (e.g., a microcontroller 210). In other situations, a configuration in which each control unit has its own anomaly monitoring unit can also be adopted. For example, the first control unit (e.g., an equipment control unit 234) may be configured to include an anomaly detection unit 232b as a second anomaly monitoring unit, and the third control unit (e.g., a firmware update control unit 230) may be configured to include an anomaly detection unit 232a as a first anomaly monitoring unit.

[0073] Furthermore, while Figure 1 illustrates a hot water supply system including a water heater 110 as the hot water equipment 100, the hot water equipment 100 is not limited to such examples in the application of this embodiment. For example, even if the hot water equipment 100 is a bath water filtration system, a bath water supply system, a hot water supply system equipped with a fuel cell waste heat recovery function, or a heat pump type hot water supply system, this embodiment can be applied to monitoring for microcontroller abnormalities during software updates of the microcontroller of the hot water equipment.

[0074] Furthermore, this embodiment can also be applied to updates of any software other than firmware. In addition, although this embodiment describes an example where software updates are automatically performed by downloading from the server 50, this embodiment can also be applied when the software of the microcontroller 210 is updated by other means, such as when a service technician connects a dedicated device to the microcontroller 210.

[0075] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than by the foregoing description, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]

[0076] 5 Communication system, 20 Interface equipment, 30 Mobile terminal equipment, 40 External communication network (Internet), 50 Server, 60 Router, 70 Base station, 100 Hot water equipment, 110 Water heater, 111 Hot water outlet, 120,130 Remote control, 121,131 Display unit, 122,132 Input unit, 150 Communication adapter, 200 Circuit board, 210 Microcontroller, 212 Memory, 213 Interface, 214 Bus, 215,216 Communication circuit, 220A Monitoring IC, 220B Sub-microcontroller, 230 Firmware update control unit, 232,232a,232b Anomaly detection unit, 234 Equipment control unit, BLK1~BLKN Block (update program), DT1,DT2 Transmit data, DT1*,DT2* Transmit data (during software update processing), PLS Pulse.

Claims

1. It is a hot water appliance, The first microcomputer and The system includes an abnormality monitor for detecting abnormalities in the first microcomputer, which communicates with the first microcomputer, The first microcomputer is, A first control unit for controlling the operation of the equipment mounted on the hot water equipment, The abnormality monitor has a second control unit for performing communication for abnormality monitoring of the first microcomputer, It comprises a third control unit that controls the software update process in the first microcomputer, The second control unit is, During the software update process of the first control unit, a first abnormality monitoring unit executes the communication for abnormality monitoring to the abnormality monitor, The system includes a second abnormality monitoring unit which, when the first control unit is in operation, communicates with the abnormality monitor for the purpose of abnormality monitoring, The anomaly monitor is a second microcomputer that periodically communicates with the first microcomputer, Each of the first anomaly monitoring unit and the second anomaly monitoring unit performs the anomaly monitoring communication such as periodically transmitting a first data signal to the second microcomputer and receiving second data from the second microcomputer. The second microcomputer is configured to initialize the first microcomputer when the transmission of the first data signal from the first microcomputer is interrupted. A water heater wherein the amount of data in the first data signal transmitted by the first abnormality monitoring unit to the second microcomputer is set to be less than the amount of data in the first data signal transmitted by the second abnormality monitoring unit to the second microcomputer during the operation of the first control unit.

2. The hot water equipment according to claim 1, wherein, during the software update process of the first control unit, the timing of the communication for abnormality monitoring by the first abnormality monitoring unit is set in conjunction with the progress of the software update process.