Vehicle, software update methods, and programs

JP7920869B2Active Publication Date: 2026-09-15TOYOTA JIDOSHA KK
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022189045
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2026-09-15
Estimated Expiration
2042-11-28

Smart Images

  • Figure 0007920869000001
    Figure 0007920869000001
  • Figure 0007920869000002
    Figure 0007920869000002
  • Figure 0007920869000003
    Figure 0007920869000003
Patent Text Reader

Abstract

To appropriately and quickly enable update of software, even when a single bank type computer and a dual bank type computer are mixed, as an on-vehicle ECU.SOLUTION: An update master, in a single bank type target ECU, after downloading software distributed from an OTA center 500, since an activation switch is operated to turn off, installs software to the target ECU to execute activation. In a dual bank type target ECU, after the software is installed, since the activation switch is operated to turn off, the activation is executed.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a vehicle, a software update method, and a program. Background Art

[0002] Japanese Unexamined Patent Application Publication No. 2017-149323 (Patent Document 1) discloses a technique for updating software of an ECU (Electronic Control Unit) mounted on a vehicle via OTA (Over The Air). Prior Art Literature Patent Documents

[0003] Patent Document 1 Japanese Unexamined Patent Application Publication No. 2017-149323 Summary of the Invention Problems to be Solved by the Invention

[0004] A vehicle can download new software for an on-board ECU from an OTA center by performing wireless communication with the OTA center. Then, in the vehicle, the software can be updated when a target ECU (the ECU targeted for software update) sequentially executes installation and activation.

[0005] A typical on-board ECU includes one or more computers (microcomputers). Typical computers in on-board ECUs are broadly classified into dual-bank type and single-bank type.

[0006] In the dual-bank type, two banks are formed by two memory areas. The dual-bank type has an area for storing currently executed software (program) and an area for storing update (new) software, and allows installation of the update software while the current software is being executed.

[0007] In a single-bank configuration, one bank is formed by a single memory region. Furthermore, in a single-bank configuration, the area storing the current software and the area storing the update software are the same, making it difficult to install update software while the current software is running.

[0008] In a vehicle where single-bank and dual-bank ECUs coexist, it is conceivable to initiate the installation of the vehicle ECU (target ECU) when the single-bank ECU has stopped executing its software (program), for example, when the vehicle system is shut down. However, in this case, there are concerns that the timing of software updates may be limited or postponed.

[0009] The purpose of this disclosure is to enable appropriate and prompt software updates even when single-bank and dual-bank type computers are mixed in the in-vehicle ECU. [Means for solving the problem]

[0010] The vehicle described herein is equipped with an ECU that allows for software updates. The vehicle includes a start switch that activates the vehicle's control system when turned on, and a control device that controls the software update process delivered from a server. The control device is configured to request consent to perform activation after the start switch is turned off. The control device is configured such that, if the ECU is a single-bank type computer, it downloads the software delivered from the server, and after the user consents to perform activation, it installs the downloaded software into the ECU and performs activation. If the ECU is a dual-bank type computer, it downloads the software delivered from the server and installs it into the ECU, and after the user consents to perform activation, it performs activation of the installed software.

[0011] In this configuration, when the ECU consists of a mix of single-bank and dual-bank computers, the control unit downloads the software from the server to the ECU, and then, after obtaining user consent to perform activation, installs the downloaded software into the ECU and performs activation. Similarly, in the case of ECUs consisting of dual-bank computers, the control unit downloads the software from the server and installs it into the ECU, and then, after obtaining user consent to perform activation, performs activation of the installed software.

[0012] When the power switch is turned off, the vehicle's control system can be shut down, allowing software installation to be performed on a single-bank type computer. Therefore, in an ECU composed of a single-bank type computer, after the power switch is turned off and permission to activate is granted, the installation and activation will be performed. In an ECU composed of a dual-bank type computer, the software installation is performed before the power switch is turned off, and activation is performed after the power switch is turned off and permission to activate is granted. This allows for appropriate and timely software updates for each ECU.

[0013] When updating the ECU software, it is desirable to obtain consent from the vehicle user. In this case, if the ECU consists of both single-bank and dual-bank type computers, requesting consent for "installation and activation" for the single-bank type ECU and then requesting consent for "activation" for the dual-bank type ECU after the power switch has been turned off would require the user to give two different consents, which would be cumbersome.

[0014] In this configuration, when the power switch is turned off, the control unit requests consent to perform activation. When the user consents to perform activation, if the ECU is a single-bank type computer, it performs software installation and activation; if the ECU is a dual-bank type computer, it performs activation of the installed software. Therefore, since installation and activation are performed by consent to "activate" in the case of a single-bank type ECU, the number of consents after the power switch is turned off can be reduced to one, thus mitigating complexity.

[0015] Preferably, the ECU is an ECU that controls the vehicle's driving, and when the start switch is turned off, it is possible to stop the execution of the software (program) by the ECU and put the vehicle's control system into a stopped state.

[0016] The software update method described herein is a software update method for updating the software of an in-vehicle ECU using software distributed from a server. The software update method includes: requesting consent to perform activation when the activation switch, which activates the vehicle's control system when turned ON, is turned OFF; if the in-vehicle ECU is a single-bank type computer, downloading the software distributed from the server, obtaining consent from the user to perform activation, installing the downloaded software on the in-vehicle ECU and performing activation; and if the in-vehicle ECU is a dual-bank type computer, downloading the software distributed from the server and installing it on the in-vehicle ECU, obtaining consent from the user to perform activation, and then performing activation of the installed software.

[0017] According to this method, in ECUs consisting of a single-bank computer, the installation and activation are performed when the power switch is turned off and consent to perform activation is given. In ECUs consisting of a dual-bank computer, the software installation is performed before the power switch is turned off, and the activation is performed when the power switch is turned off and consent to perform activation is given. This makes it possible to perform appropriate and timely software updates for each ECU.

[0018] According to this method, when the start switch is turned off, consent to perform activation is requested, and upon the user giving consent, installation and activation are executed in a single-bank type ECU. Therefore, only one type of consent is required after the start switch is turned off, and complexity can be reduced.

[0019] Further, there is provided a program that causes a control device to execute the software update method described above.

Effects of the Invention

[0020] According to the present disclosure, even when a single-bank type computer and a dual-bank type computer coexist as in-vehicle ECUs, appropriate and prompt software update can be achieved.

Brief Description of Drawings

[0021] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of a software update system including a vehicle according to the present embodiment. [Figure 2] FIG. 2 is a diagram for explaining an outline of a software update method using OTA. [Figure 3] FIG. 3 is a diagram schematically showing a part of a sequence executed in the software update system of the present embodiment. [Figure 4] FIG. 4 is a diagram showing an example of a display screen displayed on a touch panel display of an HMI. [Figure 5] FIG. 5 is a diagram showing an example of a display screen displayed on a touch panel display of an HMI. [Figure 6] FIG. 6 is a diagram showing an example of a display screen displayed on a touch panel display of an HMI.

Mode for Carrying Out the Invention

[0022] Embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding portions are denoted by the same reference numerals, and description thereof will not be repeated.

[0023] Figure 1 shows a schematic configuration of a software update system including a vehicle according to this embodiment. This software update system includes vehicle 100, vehicle 200, user terminals 300 and 400, and OTA center 500. "OTA" is an abbreviation for "Over The Air".

[0024] Vehicles 100 and 200 are, for example, electric vehicles (BEVs: Battery Electric Vehicles) without internal combustion engines. Vehicle 100 has an OTA access function (a function to communicate wirelessly directly with the OTA center 500), but vehicle 200 does not have an OTA access function. Vehicle 100 can communicate wirelessly directly with the OTA center 500, but vehicle 200 cannot communicate with the OTA center 500 without going through another communication device (i.e., a communication device that is not a communication device built into vehicle 200 itself). Vehicle 200 communicates wirelessly with the OTA center 500 via the user terminal 300.

[0025] The user terminal 300 is configured to be portable by the user. The user terminal 300 is a mobile terminal carried and operated by the user (vehicle manager) of the vehicle 200. In this embodiment, a smartphone equipped with a touch panel display (display unit) is used as the user terminal 300. The smartphone has a built-in computer and a speaker function. However, it is not limited to this, and any terminal that can be carried by the user of the vehicle 200 can be used as the user terminal 300. For example, laptops, tablet terminals, portable game consoles, and wearable devices (smartwatches, smart glasses, smart gloves, etc.) can also be used as the user terminal 300.

[0026] The user terminal 300 comprises a processor 310, memory 320, and a communication module 330. The processor 310 includes, for example, a CPU (Central Processing Unit). The memory 320 includes, for example, non-volatile memory such as flash memory. The communication module 330 includes a communication interface (I / F) for direct wireless communication with the OTA center 500. The communication module 330 also includes a communication interface for direct wireless communication with the vehicle 200. This enables the vehicle 200 and the OTA center 500 to exchange data via the user terminal 300. For example, when the user terminal 300 requests the vehicle 200, it can access the communication network NW by specifying the address of the OTA center 500, thereby enabling data exchange (communication) between the vehicle 200 (ECU 210) and the OTA center 500 via the user terminal 300.

[0027] The user terminal 300 has application software (hereinafter referred to as the "mobile app") installed for using the services provided by the OTA center 500. The mobile app links the user terminal 300's identification information (terminal ID) with the vehicle 200's identification information (vehicle ID) and registers it with the OTA center 500. The user terminal 300 can also exchange information with the OTA center 500 through the mobile app. Furthermore, the user terminal 300 functions as both an input device and a display device.

[0028] The OTA Center 500 is a server that provides vehicle software update services using OTA technology. The OTA Center 500 is configured to perform remote in-vehicle ECU software updates via a communication channel from the center. The OTA Center 500 distributes the software for the in-vehicle ECU. "ECU" stands for Electronic Control Unit.

[0029] The OTA center 500 comprises a processor 510, memory 520, and a communication module 530. The processor 510 includes, for example, a CPU. The memory 520 includes, for example, non-volatile memory such as flash memory. The communication module 530 is connected to a communication network NW by a wire and communicates with each of the multiple vehicles (including vehicle 100) and multiple mobile terminals (including user terminal 300) via the communication network NW. The communication network NW is a wide-area network constructed by, for example, the internet and wireless base stations. The communication network NW may also include a mobile phone network.

[0030] Vehicle 100 includes an OTA master 110 and a plurality of ECUs (including ECUs 121 and 122). Vehicle 200 includes a plurality of ECUs (including ECUs 210, 221, and 222). The OTA master 110 has a built-in computer and functions as an in-vehicle diagnostic device. The number of ECUs in each vehicle is arbitrary. Each in-vehicle ECU has a built-in computer that includes at least one processor and at least one memory. Each in-vehicle ECU may have multiple microcontrollers (microcomputers) in the form of a main microcontroller and sub-microcontrollers.

[0031] In vehicle 100, the OTA master 110 and each ECU are connected via a communication bus and are configured to communicate with each other via wired connections. In vehicle 200, the ECUs are connected to each other via a communication bus and are configured to communicate with each other via wired connections. The communication method between control devices in each vehicle is not particularly limited, but may be, for example, CAN (Controller Area Network) or Ethernet (registered trademark).

[0032] The OTA master 110 comprises a processor 111, memory 112, and a communication module 113. The processor 111 includes, for example, a CPU. The memory 112 includes, for example, non-volatile memory such as flash memory. The communication module 113 includes a communication interface (I / F) for directly communicating wirelessly with the OTA center 500. For example, wireless communication between the vehicle 100 (communication module 113) and the OTA center 500 is established by the communication module 113 accessing the communication network NW by specifying the address of the OTA center 500. The communication module 113 may also include a Telematics Control Unit (TCU) and / or Data Communication Module (DCM) for wireless communication.

[0033] In vehicle 200, the ECU 210 includes a processor 211 and memory 212. The processor 211 includes, for example, a CPU. The memory 212 includes, for example, non-volatile memory such as flash memory. Vehicle 200 further includes a communication device 290. The ECU 210 communicates with devices outside the vehicle through the communication device 290. The communication device 290 includes a communication interface for direct wireless communication with a user terminal 300. The communication device 290 and the user terminal 300 may communicate using short-range communication such as wireless LAN (Local Area Network), NFC (Near Field Communication), or Bluetooth®. The communication device 290 may communicate directly with a user terminal 300 located inside or within range of the vehicle. While vehicle 200 is stopped, the user terminal 300 inside or outside the vehicle and the ECU 210 may exchange information with each other via the communication device 290. Furthermore, while the vehicle 200 is in motion, the user terminal 300 and the ECU 210 may exchange information with each other via the communication device 290. As described above, the ECU 210 can communicate with the OTA center 500 via the user terminal 300 by requesting the user terminal 300 to communicate with the OTA center 500.

[0034] In vehicle 100, the OTA master 110 is capable of communicating with the user terminal 400 via a communication module 113. The communication module 113 includes a communication interface for direct wireless communication with the user terminal 400. The communication module 113 and the user terminal 400 may communicate using short-range communication such as Wi-Fi, NFC, or Bluetooth®. The user terminal 400 may be a smartphone equipped with a touch panel display (display unit) and also functions as an input device and display device.

[0035] As described above, the OTA master 110 of vehicle 100 and the ECU 210 of vehicle 200 are each configured to communicate wirelessly with the OTA center 500. Both vehicles 100 and 200 can communicate with the OTA center 500 whether they are stationary or in motion. The OTA master 110 and the ECU 210 each manage in-vehicle information, receive campaigns, and manage the software update sequence. Hereafter, unless distinguished, the OTA master 110 and the ECU 210 will be referred to as the "update master". The OTA master 110 corresponds to the update master of vehicle 100, and the ECU 210 corresponds to the update master of vehicle 200.

[0036] Each of vehicles 100 and 200 is an autonomous vehicle configured to be capable of autonomous driving. Each of vehicles 100 and 200 is configured to be capable of both manned and unmanned driving. Although each of vehicles 100 and 200 is configured to be capable of autonomous driving without a driver, it can also be driven manually by a user (manned driving). In addition, each of vehicles 100 and 200 can perform autonomous driving (e.g., automatic cruise control) while being driven by a driver. The level of autonomous driving may be fully autonomous driving (level 5) or conditional autonomous driving (e.g., level 4).

[0037] Vehicles 100 and 200 are equipped with driving devices 130 and 230, and ADS (Autonomous Driving System) 140 and 240, respectively. In vehicle 100, the ECU 121 is configured to control the driving device 130. In vehicle 200, the ECU 221 is configured to control the driving device 230.

[0038] Each of the driving devices 130 and 230 includes an accelerator device, a brake device, and a steering device. The accelerator device includes, for example, a motor generator (hereinafter referred to as "MG") that rotates the drive wheels of the vehicle, a PCU (Power Control Unit) that drives the MG, and a battery that supplies power to the PCU to drive the MG.

[0039] Each of the ADS140 and 240 includes a recognition sensor (for example, at least one of a camera, millimeter-wave radar, or lidar) that recognizes the external environment of the vehicle, and performs processing related to autonomous driving based on information sequentially acquired by the recognition sensor. The ADS140 and 240 work in cooperation with the ECU121 and 221 respectively to generate a driving plan (information indicating the future behavior of the vehicle) according to the external environment of the vehicle. Then, the ADS140 and 240 request the ECU121 and 221 to control the various actuators included in the driving devices 130 and 230 so that the vehicles 100 and 200 are driven according to the driving plan.

[0040] Vehicles 100 and 200 are equipped with start switches 150 and 250, and HMI (Human Machine Interface) devices 170 and 270, respectively.

[0041] The start switches 150 and 250, respectively, are switches used by the user to activate the vehicle system (the control system of vehicle 100, 200), and are installed, for example, inside the passenger compartment. Generally, start switches are referred to as "power switches" or "ignition switches." By operating the start switches 150 and 250, the user switches the vehicle system (including each ECU installed in the vehicle) on (operating) / off (stopped). When the start switches 150 and 250 are turned on, the vehicle system, which was in a stopped state, is activated, and the vehicle system becomes operational (hereinafter also referred to as "IG on"). Also, when the vehicle system is operational, if the start switches 150 and 250 are turned off, the vehicle system becomes stopped (hereinafter also referred to as "IG off").

[0042] Turning on the start switches 150 and 250 switches the vehicle's state from ignition off to ignition on. When the user turns on the start switches 150 and 250, a start request is input to each onboard ECU. In other words, each onboard ECU accepts the start request from the user. On the other hand, turning off the start switches 150 and 250 switches the vehicle's state from ignition on to ignition off. When the user turns off the start switches 150 and 250, a shutdown request is input to each onboard ECU. In other words, each onboard ECU accepts the shutdown request from the user. However, turning off the start switches 150 and 250 is prohibited in a moving vehicle.

[0043] Each of the HMI devices 170 and 270 includes an input device and a display device. Each of the HMI devices 170 and 270 may also include a touch panel display that functions as an input device and a display device. Each of the HMI devices 170 and 270 may also include an input device and a display device for a car navigation system.

[0044] Figure 2 is a diagram illustrating the overview of the software update method using OTA. Referring to Figure 2 in conjunction with Figure 1, the software update process is carried out in steps such as configuration synchronization, campaign notification and acceptance, download, installation, activation, and software update completion notification. The processes described below are performed by OTA Center 500 and each vehicle (including vehicles 100 and 200) that receives software distribution from OTA Center 500. The number of vehicles receiving distribution from OTA Center 500 may be around 50, or between 100 and 1000, or more than 1000. Note that the following explanation is for the case where the ECU to be updated (hereinafter also referred to as the "Target ECU") is composed of a dual-bank type computer.

[0045] Vehicles with the ignition on repeatedly perform configuration synchronization at predetermined intervals. Vehicles with the ignition on also perform configuration synchronization when they receive a request for it from the OTA center 500. The vehicle's configuration synchronization process includes transmitting vehicle configuration information to the OTA center 500. Vehicle configuration information includes, for example, hardware information (information indicating hardware part numbers, ECU identifiers, etc.) and software information (information indicating software part numbers, etc.) for each ECU included in the vehicle.

[0046] When the OTA Center 500 receives the above vehicle configuration information from the vehicle, it checks for any currently active campaigns (software updates). If there is a campaign applicable to the vehicle, the OTA Center 500 sends a consent request signal to the vehicle user requesting their consent to download the new software (software update) related to that campaign. The consent request signal includes information about the campaign (campaign information). The campaign information may include, for example, campaign attribute information (information indicating the purpose of the software update and vehicle functions that may be affected by the update), a list of campaign-eligible vehicles, information about campaign-eligible ECUs (for example, software information before and after the update), and information about notifications to the user before and after the update. The campaign that is notified may be a newly occurring campaign or a campaign that was not previously applied. Hereafter, the transmission of the above consent request signal will also be referred to as a "campaign notification."

[0047] When the vehicle receives a campaign notification (acceptance request signal), it prompts the user to input whether or not they accept the application of that campaign. For example, the vehicle displays a message such as "New software has been found. Do you want to apply it to this vehicle?" on the HMI (HMI device 170, 270 or user terminal 300, 400) and requests the user to input either "accept" or "reject". If the user inputs "accept", the vehicle executes the download process described below. On the other hand, if the user inputs "reject", the vehicle does not execute the download process. In this case, the OTA center 500 terminates the software update process without proceeding to the download phase.

[0048] In this embodiment, the OTA center 500 and the vehicle update master (for example, the OTA master 110 or ECU 210) perform the download process according to the procedure described below.

[0049] The vehicle update master requests a distribution package containing the new software from the OTA center 500. The update master then downloads (receives and saves) the distribution package from the OTA center 500. In addition to the new software (for example, a set of update data for each ECU targeted by the campaign), the distribution package may also include package attribute information (information indicating the update category, the number of update data in the distribution package, the installation order for each ECU, etc.) and update data attribute information (identifier of the target ECU, verification data to verify the legitimacy of the update data, etc.). There may be multiple target ECUs in vehicles 100,200.

[0050] The download process described above saves the distribution package to the storage device (for example, memory 112 or 212) of the update master. After the download is complete, the update master verifies the authenticity of the downloaded distribution package. If the verification is successful, the update master notifies the OTA center 500 of the software update status (download complete). This notification indicates that the download was successful.

[0051] If the download is successful, the vehicle will perform the installation. The update master requests the status and DTC (Diagnostic Trouble Code) output of at least one target ECU (for example, ECU121 or 221) from that target ECU. Based on the status and DTC of the target ECU, the update master determines whether installation can be performed for each target ECU. The update master then displays a predetermined message on the HMI and requests the user to input either "Accept" or "Reject". If the user inputs "Accept", the update master transfers the new software (update data) to the target ECU that can perform the installation. The target ECU that receives the update data performs the installation of the update data (writing to non-volatile memory).

[0052] Once the transfer of the update data from the update master to the target ECU is complete, the target ECU sends a transfer completion notification to the update master. Upon receiving the transfer completion notification, the update master requests integrity verification from the target ECU. The target ECU, upon receiving this request, performs verification using integrity verification data (verification data) and sends the verification results to the update master. The update master saves the verification results (installation complete / failed / cancelled) for each target ECU. Once integrity verification is complete for all target ECUs and all verification results are "normal", the update master notifies the OTA center 500 of the software update status (installation complete). This notification indicates that the installation was successful.

[0053] If the download and installation are successful, the vehicle enters an activation waiting state. Subsequently, if the vehicle's power switch (for example, power switch 150 or 250) is turned off, the update master displays a predetermined message on the HMI and requests the user to input either "Accept" or "Reject". If the user inputs "Accept", the update master performs activation (activating the installed software). If the update master fails to activate, the update master requests a software rollback from the OTA center 500. Upon receiving a rollback request from the vehicle, the OTA center 500 distributes rollback software to that vehicle. This allows the update master to use the rollback software to revert the software that failed to activate back to its original version (rollback). If the user inputs "Reject", the update master stops the software update process without performing activation, and the vehicle system shuts down.

[0054] Once the update master is successfully activated, it displays the software update results on the HMI. The update master then notifies the OTA center 500 of the software update status (software update complete). This notification indicates that the OTA software update was successful. Upon receiving this notification, the vehicle's control system shuts down and the ignition is turned off. Subsequently, when the vehicle's start switch is turned on, the vehicle system's ignition is turned on. This starts the update program (new version of software) on the target ECU. Note that the software to be updated is not limited to driver assistance control programs such as the aforementioned autonomous driving control program; it can be any software.

[0055] Thus, when a distribution package (software) is downloaded and the software of the target ECU is updated, if the target ECU is composed of a single-bank type computer, the area for storing the current software and the area for storing the update software are the same, making it difficult to install the update data (update software) while the current software is running. For this reason, in this embodiment, when the target ECU contains a mix of single-bank and dual-bank type computers, the processing before and after the off operation of the start switches 150 and 250 is made different for the single-bank and dual-bank types to enable appropriate and prompt software updates.

[0056] Figure 3 is a schematic diagram showing a part of the sequence executed in the software update system of this embodiment. This sequence is processed at the OTA center 500, the update master (OTA master 110, ECU 210), and user terminals 300 and 400. This processing is achieved by one or more processors in each device reading and executing a program stored in one or more memories.

[0057] Referring to Figure 3, once the configuration synchronization process is complete, the OTA center 500 determines in step 10 (hereinafter, steps are abbreviated as "S") whether or not an applicable campaign exists. If an applicable campaign exists, in S11, the OTA center 500 sends campaign information (acceptance request signal) to the update master (OTA master 110, ECU 210). Upon receiving the campaign information, the update master sends an acceptance display request to the HMI (HMI devices 170, 270 or user terminals 300, 400) (S20). This acceptance display request displays an indication on the HMI whether or not the user accepts the download of the distribution package (whether or not the user accepts the application of the campaign), and prompts the user to input whether or not they accept the software update process. The update master (OTA master 110, ECU 210) corresponds to an example of the "control device" in this disclosure.

[0058] When the HMI (HMI device 170, 270 or user terminal 300, 400) receives a request for acceptance, it displays an operation section (operation button) on the touch panel display for accepting the software update (download of distribution package) (S30).

[0059] Figure 4 shows an example of a display screen shown on the HMI's touch panel display D. As shown in Figure 4, the touch panel display D displays a message regarding the vehicle software update process, along with an operation section for accepting the software download. In Figure 4, the "Yes" button 341 is the operation section (operation button) for accepting the download. When the "Yes" button 341 is pressed by the user, the software (distribution package) download (software update process) is executed. When the "No" button 342 displayed on the touch panel display D is pressed by the user, the software download (software update process) is not executed, and this sequence ends.

[0060] Referring again to Figure 3, when the user operates the "Yes" button 341 on the touch panel display D and accepts the download (software update process), the HMI sends acceptance information to the update master (S31). Upon receiving the acceptance information, the update master sends a distribution package transmission request to the OTA center 500 (S21). Upon receiving the distribution package transmission request, the OTA center 500 sends the distribution package (software) to the update master (S12).

[0061] Next, the update master stores the distribution package sent (distributed) from the OTA center 500 in memory 112 or memory 211 and downloads it (S22). Once the download of the distribution package is complete, the update master verifies the authenticity of the distribution package and then determines whether or not the ECU (target ECU) to be updated with software includes a dual-bank type computer (S23). If the target ECU includes a dual-bank type computer, S23 determines this to be true, and in S24, it sends an acceptance request to the HMI. This acceptance request displays an indication on the HMI asking the user whether or not they accept the installation of the distribution package (software), and requests their acceptance of the installation.

[0062] When the HMI receives a request for acceptance, it displays an operation section (operation button) on the touch panel display for accepting the software installation (S32).

[0063] Figure 5 shows an example of a display screen shown on the HMI's touch panel display D. As shown in Figure 5, the touch panel display D displays a message regarding the vehicle software update process, along with an operation section for accepting the software installation. In Figure 5, the "Yes" button 351 is the operation section (operation button) for accepting the installation. When the "Yes" button 351 is pressed by the user, the installation is executed. When the "No" button 352 displayed on the touch panel display D is pressed by the user, the software update process is interrupted, and this sequence ends.

[0064] Referring again to Figure 3, when the user operates the "Yes" button 351 on the touch panel display D and accepts the installation, the HMI sends acceptance information to the update master (S33). Upon receiving the acceptance information (S33), the update master sends the distribution package (update software (update data)) to the dual-bank type target ECU and instructs it to execute the installation of the update data (S25). The target ECU (dual-bank type) that receives the update data executes the installation of the update software (writing to non-volatile memory) (S40). Once the installation of the update software is complete, the dual-bank type target ECU sends a completion notification to the update master (S41). Upon receiving the completion notification from the target ECU, the update master waits for the start switches 150 and 250 to be turned off.

[0065] If the target ECU does not include a dual-bank type computer, S23 will determine that it is not a valid option, and the update master will wait for the activation switches 150 and 250 to be turned off without sending the distribution package or performing any other actions.

[0066] While the system is waiting for the activation switches 150 and 250 to be turned off, if the user turns off the activation switches 150 and 250, the update master sends an acceptance request to the HMI (S26). This acceptance request displays an indication on the HMI asking whether the user agrees to activate the software installed on the target ECU (whether or not they agree to the application of the campaign), and seeks the user's consent.

[0067] When the HMI receives a consent request, it displays an operation section on the touch panel display for consenting to the software activation (S3 4 ).

[0068] Figure 6 shows an example of a display screen shown on the HMI's touch panel display D. As shown in Figure 6, the touch panel display D displays a message regarding the vehicle software update process, along with an operation section for accepting the software activation. In Figure 6, the "Yes" button 361 is the operation section (operation button) for accepting the activation. When the "Yes" button 361 is pressed by the user, the software activation (software activation process) is accepted by the user and the activation is performed. When the "No" button 362 displayed on the touch panel display D is pressed by the user, the software update process is interrupted and this sequence ends.

[0069] Referring again to Figure 3, when the user operates the "Yes" button 361 on the touch panel display D and accepts the download (software update process), the HMI sends acceptance information to the update master (S35). Upon receiving the acceptance information, the update master determines in S27 whether the target ECU contains a single-bank type computer. If the target ECU contains a single-bank type computer, it is determined to be positive in S24, and in S28, it sends a distribution package to the single-bank type target ECU and instructs it to execute the installation of the update data. The target ECU (single-bank type) that receives the update data executes the installation of the update software (writing to non-volatile memory) (S42). Once the installation of the update software is complete, the single-bank type target ECU sends a completion notification to the update master (S43).

[0070] If the target ECU does not contain a single-bank type computer and this is determined to be invalid in S27, or if the update master receives a notification of completion of the update software installation from a single-bank type target ECU (S43), the update master sends an activation command to the target ECU (S29). Upon receiving the activation command from the update master, the target ECU activates the installed update software (S44). If the activation is successful, the target ECU sends an update completion notification to the update master (S45).

[0071] According to this embodiment, vehicles 100 and 200 equipped with target ECUs (ECUs 121, 122, 221, 222) include start switches 150 and 250 that activate the control system of vehicles 100 and 200 when turned on, and update masters (OTA masters 110 and 210) that control the software update process distributed from the OTA center 500. When single-bank type computers and dual-bank type computers are mixed as target ECUs, the update master, in the case of target ECUs composed of single-bank type computers, downloads the software distributed from the OTA center 500 (S22), then, after the start switches 150 and 250 are turned off, installs the downloaded software into the target ECU (S42) and activates it (S44). Furthermore, in the case of a target ECU consisting of a dual-bank type computer, the update master downloads the software distributed from the OTA center 500 (S22), installs it on the target ECU (S40), and then activates the installed software (S44) after the power switches 150 and 250 are turned off.

[0072] When the activation switches 150 and 250 are turned off, the control systems of vehicles 100 and 200 can be shut down. This allows software installation to be performed on single-bank type computers. Therefore, for target ECUs consisting of single-bank type computers, installation and activation are performed after the activation switches 150 and 250 are turned off. For target ECUs consisting of dual-bank type computers, software installation is performed before the activation switches 150 and 250 are turned off, and activation is performed after the activation switches 150 and 250 are turned off. This allows for appropriate and prompt software updates according to the type of each target ECU.

[0073] According to this embodiment, when the start switches 150 and 250 are turned off, the update master requests consent to perform activation (S26). When the user consents to activation, if the target ECU is a single-bank type computer, the software installation ( S 42) and activate (S44), and if the target ECU is a dual-bank type computer, activate (S44) the installed software. Therefore, in the case of a single-bank type ECU, installation and activation are performed when the activation is accepted (S33), so even if the target ECU has a mix of single-bank and dual-bank type computers, the acceptance request displayed on the HMI after the power switch is turned off can be made into one.

[0074] The vehicle may be an xEV (electric vehicle) other than a BEV. The vehicle may be a PHEV (plug-in hybrid vehicle) or HEV (hybrid vehicle) equipped with an internal combustion engine (e.g., a gasoline engine, biofuel engine, or hydrogen engine). The vehicle is not limited to a four-wheeled passenger car, but may be a bus or truck, or a three-wheeled xEV. The vehicle may have flight capabilities. The vehicle may be a vehicle used in MaaS (Mobility as a Service). The vehicle may be a multi-purpose vehicle customized according to the user's purpose of use. The vehicle may be a mobile store vehicle, a robotaxi, an automated guided vehicle (AGV), or agricultural machinery. The vehicle may be an unmanned or single-seater small BEV (e.g., a last-mile BEV, an electric wheelchair, or an electric scooter).

[0075] Furthermore, in the above embodiment, when the target ECU is of the dual-bank type, a request for consent to install was displayed (S24, S32). However, if the operation of the target ECU is not restricted as a result of the installation, this consent request may be omitted.

[0076] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of symbols]

[0077] 100,200 vehicles, 110 OTA masters, 121,122,210,221,222 ECUs, 111,211,310,510 processors, 112,212,320,520 memory, 113,330,530 communication modules, 130,230 driving devices, 140,240 ADS, 150,250 start switches, 170,270 HMI devices, 290 communication devices, 300,400 user terminals, 500 OTA centers, D touch panel displays.

Claims

1. A vehicle equipped with an ECU that allows for software updates, A start switch that activates the vehicle's control system when turned on, The system includes a control device that controls the software update process delivered from the server, The control device is After the aforementioned activation switch is turned off, consent is requested to perform the activation. If the ECU is a single-bank type computer, after downloading the software distributed from the server, and after the user consents to perform activation, the downloaded software is installed on the ECU and activation is performed. If the ECU is a dual-bank type computer, it is configured to download the software distributed from the server, then request consent to install the downloaded software, and once the user consents to install the software, install the software on the ECU, and then, once the user consents to activate the software, activate the installed software. Furthermore, equipped with a display device, A vehicle in which, when the control device requests consent to perform the activation, the display device shows the processing time and that the vehicle cannot be started during processing, and when the ECU is a dual-bank type computer, the display device does not show the processing time and does not show that the vehicle cannot be started during processing.

2. The vehicle according to claim 1, wherein the ECU is an ECU that controls the driving of the vehicle.

3. A software update method for updating the software of an in-vehicle ECU using software distributed from a server, When the activation switch, which activates the vehicle's control system when turned ON, is turned OFF, the system will ask for consent to perform the activation, If the in-vehicle ECU is a single-bank type computer, after downloading the software distributed from the server, the user consents to perform activation, and then the downloaded software is installed on the in-vehicle ECU and activation is performed. If the in-vehicle ECU is a dual-bank type computer, after downloading the software distributed from the server, consent will be requested to install the downloaded software. If the in-vehicle ECU is a dual-bank type computer, when the user consents to perform the installation, the software is installed on the in-vehicle ECU, and then, after the user consents to perform the activation, the installed software is activated. When requesting consent to perform the aforementioned activation, the display device shall show the processing time and that the vehicle cannot be started during processing, A software update method that, when requesting consent to perform the installation when the in-vehicle ECU is a dual-bank type computer, includes not displaying the processing time on the display device and not displaying a message that the vehicle cannot be started during processing.

4. A program that causes a control device to execute the software update method described in claim 3.

Citation Information

Patent Citations

  • Vehicle control system

    JP2017149323A

  • Vehicle, software update system and software update method

    JP2021105923A

  • Server for update data distribution, software update system, update data distribution method and distribution program

    JP2022061381A

  • Vehicle master device, rollback execution control method, and rollback execution control program

    JP2022120055A

  • Program update control device, program update control method, and program

    JP2022144936A