Master device, relay device, external device, data communication system, data processing method, and data processing program

JPWO2025204531A1Pending Publication Date: 2025-10-02
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-03-03
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing diagnostic services for electronic control units (ECUs) in vehicles face constraints due to CAN ID collisions, leading to increased installation time and limited ECU compatibility, affecting services like software updates and remote diagnostics.

Method used

Implementing a diagnostic client in a relay device connected to a master device, allowing data communication and enabling the relay device to perform diagnostic services on service target devices, with the master device distributing location and service information to facilitate parallel installation and execution.

Benefits of technology

This approach reduces installation restrictions, shortens service time, and enables efficient diagnostic services by allowing diagnostic clients to be placed strategically across multiple ECUs, optimizing software updates and remote diagnostics.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

A master device (14) that performs a diagnostic service locates, in a relay device, a diagnostic client necessary for the relay device to perform a diagnostic service on the device to be serviced, with the relay device connected so as to be capable of data communication with the master device. The relay devices (6-8) perform a diagnosis service when a diagnostic client for performing the diagnostic service is located from the master device, authority transfer to the diagnostic client is performed, and execution of the diagnostic service is instructed.
Need to check novelty before this filing date? Find Prior Art

Description

Master device, relay device, external device, data communication system, data processing method, and data processing program CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Japanese Application No. 2024-53765, filed on March 28, 2024, the contents of which are incorporated herein by reference.

[0002] The present disclosure relates to a master device, a relay device, an external device, a data communication system, a data processing method, and a data processing program.

[0003] A vehicle is equipped with a large number of electronic control units (hereinafter referred to as ECUs (Electronic Control Units)). Over-the-air (OTA) repro technology is available as a diagnostic service for the ECUs, which wirelessly updates the software installed in the ECUs. A configuration has been disclosed in which, when there are multiple target ECUs, which are devices subject to software updates, software is installed in parallel from an OTA master to the multiple target ECUs (see, for example, Patent Document 1).

[0004] Japanese Patent Application Laid-Open No. 2018-92577

[0005] When installing software from an OTA master to multiple target ECUs in parallel, data communication using the standard 11-bit CAN ID prevents data communication if identical CAN IDs collide. Therefore, to prevent CAN ID collisions, only one installer serving as a diagnostic client must be installed per vehicle. This requires mediation to stop transmissions in the installer, which increases the time required for software installation. Furthermore, because one installer is installed on a specific ECU, the ECUs to which the installer is installed are limited to ECUs that can communicate with all ECUs in the vehicle or ECUs with high-performance specifications. The above-mentioned issues are common to all diagnostic services that use diagnostic communication and can arise not only when installing software in parallel, but also when performing remote diagnostics, vehicle information collection, and other similar tasks in parallel.

[0006] The first objective of the present disclosure is to appropriately reduce the constraints on the placement of diagnostic clients, appropriately shorten the time required for diagnostic services, and appropriately perform diagnostic services, and the second objective is to have the master device and relay device appropriately perform diagnostic services.

[0007] According to one aspect of the present disclosure, a master device performs a diagnostic service, and a relay device connected to the master device so as to be able to perform data communication therewith has a diagnostic client arranged in the relay device for performing the diagnostic service on a service target device.

[0008] A relay device according to an embodiment of the present disclosure is capable of data communication with a master device that performs a diagnostic service. A diagnostic client for performing the diagnostic service is located from the master device, and when authority is transferred to the diagnostic client and an instruction to perform the diagnostic service is issued, the relay device performs the diagnostic service on a service target device.

[0009] An external device according to an aspect of the present disclosure is capable of data communication with a master device that performs a diagnostic service, and distributes to the master device location information for the master device to identify a location for a diagnostic client corresponding to the diagnostic service and diagnostic service information for the master device to perform the diagnostic service on a service target device.

[0010] A data communication system according to one aspect of the present disclosure includes a master device that performs a diagnostic service and an external device capable of data communication with the master device. The external device distributes to the master device location information for the master device to identify a location for a diagnostic client corresponding to the diagnostic service and diagnostic service information for the master device to perform the diagnostic service for a service target device. The master device distributes the diagnostic client to the relay device based on the location information received from the external device, and performs the diagnostic service for the service target device based on the diagnostic service information received from the external device.

[0011] A data processing method of one aspect of the present disclosure includes a master device that performs diagnostic services, and a relay device that is connected to the master device so as to be able to communicate data with the master device performs a diagnostic client placement procedure in which the relay device places a diagnostic client in the relay device to perform diagnostic services on a service target device.

[0012] A data processing program of one embodiment of the present disclosure causes a master device that performs diagnostic services to execute a diagnostic client placement procedure in which a relay device that is connected to the master device so as to be able to communicate data with the master device places a diagnostic client in the relay device to perform diagnostic services on a service target device.

[0013] A data processing method of one embodiment of the present disclosure includes a relay device capable of data communication with a master device that performs a diagnostic service, in which a diagnostic client for performing the diagnostic service is placed from the master device, and when authority is transferred to the diagnostic client and an instruction is given to execute the diagnostic service, a diagnostic service execution procedure is performed to perform the diagnostic service on the service target device.

[0014] A data processing program of one embodiment of the present disclosure places a diagnostic client for performing the diagnostic service from a master device that performs the diagnostic service on a relay device that is capable of data communication with the master device, and when authority is transferred to the diagnostic client and an instruction is given to execute the diagnostic service, executes a diagnostic service execution procedure to perform the diagnostic service on the service target device.

[0015] A data processing method of one embodiment of the present disclosure performs a distribution procedure in an external device capable of data communication with a master device that performs a diagnostic service, in which the master device distributes to the master device location information for the master device to identify the location of a diagnostic client corresponding to the diagnostic service, and diagnostic service information for the master device to perform the diagnostic service on a service target device.

[0016] A data processing program of one embodiment of the present disclosure causes an external device capable of data communication with a master device that performs a diagnostic service to execute a distribution procedure that distributes to the master device location information that enables the master device to identify the location of a diagnostic client corresponding to the diagnostic service, and diagnostic service information that enables the master device to perform the diagnostic service on a service target device.

[0017] According to one aspect of the present disclosure, a relay device that is connected to a master device that performs diagnostic services and is capable of data communication has a diagnostic client that is installed in the relay device to perform diagnostic services on service target devices. This appropriately reduces restrictions on where the diagnostic client can be installed, appropriately shortens the time required for diagnostic services, and enables appropriate diagnostic services to be performed.

[0018] According to one aspect of the present disclosure, a diagnostic client for performing diagnostic services is placed from a master device, and when authority is transferred to the diagnostic client and an instruction to perform the diagnostic service is given, the diagnostic service is performed. This appropriately reduces restrictions on the placement location of the diagnostic client, appropriately shortens the time required for the diagnostic service, and enables the diagnostic service to be performed appropriately.

[0019] According to one aspect of the present disclosure, the master device is configured to distribute to the relay device location information for the master device to identify the location of the diagnostic client for providing the diagnostic service and diagnostic service information for providing the diagnostic service to the service target device, thereby allowing the master device and the relay device to appropriately provide the diagnostic service.

[0020] According to one aspect of the present disclosure, an external device distributes to the master device location information for the master device to identify a location for a diagnostic client corresponding to a diagnostic service and diagnostic service information for providing the diagnostic service to the service target device. The master device distributes the diagnostic client to the relay device based on the location information received from the external device, and provides the diagnostic service to the service target device based on the diagnostic service information received from the external device. The external device can cause the master device and the relay device to appropriately provide the diagnostic service. The master device and the relay device appropriately reduce restrictions on the location of the diagnostic client, appropriately shorten the time required for the diagnostic service, and appropriately provide the diagnostic service.

[0021] The above and other objects, features, and advantages of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which Fig. 1 is a diagram showing the overall configuration of one embodiment, Fig. 2 is a functional block diagram of the ReproMaster, Fig. 3 is a diagram showing the distribution of specification data and an installer, Fig. 4 is a diagram showing a series of processing phases, Fig. 5 is a diagram explaining the transfer of authority to the installer, Fig. 6 is a diagram showing specification data, Fig. 7 is a diagram showing specification data, Fig. 8 is a flowchart, Fig. 9 is a flowchart, Fig. 10 is a flowchart, Fig. 11 is a flowchart, and Fig. 12 is a flowchart.

[0022] An embodiment will be described below with reference to the drawings. In this embodiment, a diagnostic service includes all services that utilize diagnostic communication, such as software updates, remote diagnostics, and vehicle information collection. A diagnostic client corresponds to an installer, which is a write control function unit for performing installation in the software update installation phase, a control function unit for performing remote diagnostics, a control function unit for performing vehicle information collection, and the like.

[0023] As shown in Fig. 1, a data communication system 1 (corresponding to a data communication system) is configured to enable data communication between an over-the-air (OTA) center 2 (corresponding to an external device) and a vehicle-side system 3 installed in a vehicle. An unspecified number of vehicle-side systems 3 can communicate data with the OTA center 2. The vehicle is, for example, an electric vehicle such as a BEV powered by electricity from an on-board battery. Unlike non-electric vehicles such as gasoline-powered vehicles, electric vehicles can freely control the power supply to all ECUs installed in the vehicle using software.

[0024] The vehicle-side system 3 includes an in-vehicle communication device (hereinafter referred to as DCM (Data Communication Module)) 4 (corresponding to the controlled device), a central gateway (hereinafter referred to as CGW (Central Gateway)) 5, a first repeater 6 (corresponding to the repeater), a second repeater 7 (corresponding to the repeater), and a third repeater 8 (corresponding to the repeater). The CGW 5, the first repeater 6, the second repeater 7, and the third repeater 8 are referred to as a domain controller. The first repeater 6, the second repeater 7, and the third repeater 8 are connected to the CGW 5, for example, via Ethernet (registered trademark).

[0025] The OTA center 2 generates and stores an update package including software and specification data to be updated. The OTA center 2 also stores update packages acquired from external sources, such as an OEM (Original Equipment Manufacturer). The OTA center 2 includes a configuration management function unit that manages the vehicle hardware and software configurations that may be targets for the update package distribution, and a distribution management function unit that manages the distribution of the update package to the vehicle. The software includes programs, data, libraries, etc. for operating the ECU.

[0026] The specification data includes information capable of identifying an ECU compatible with OTA, information capable of identifying a target ECU that is the target of the software update, information capable of identifying an installation target in the installation phase described below, information capable of identifying the order of installation, information capable of identifying an activation target in the activation phase described below, information capable of identifying the order of activation, etc. An ECU compatible with OTA is an ECU that can implement OTA. Note that the OTA center 2 may include the specification data in an update package and distribute it to the vehicle, or may not include the specification data in the update package and distribute the specification data to the vehicle separately from the update package.

[0027] The DCM 4 performs data communication with the OTA center 2 via a communication network. The communication network may include, for example, a mobile communication network using a 4G line or a 5G line, the Internet, Wi-Fi (Wireless Fidelity) (registered trademark), etc. The DCM 4 and the CGW 5 may be integrated, and the functions of the DCM 4 may be incorporated into the CGW 5. Alternatively, the functions of the DCM 4 and the CGW 5 may be incorporated into a display device or the like. When the DCM 4 receives an update package distributed from the OTA center 2, the DCM 4 forwards the received update package to the CGW 5. Software distributed from the OTA center 2 to the DCM 4 is, for example, OTA repro software. Inter-center communication, which is data communication between the OTA center 2 and the DCM 4, uses, for example, an SOVD format conforming to the SOVD communication specifications or a Rest (REpresentational State Transfer) API format conforming to the Rest API communication specifications. A software update using an update package distributed from the OTA center 2 is called wireless repro. On the other hand, a software update using an update package distributed from an external tool (described later) is called wired repro.

[0028] The CGW 5 includes a ReproMaster 9, an in-vehicle HMI (Human Machine Interface) 10, a remote diagnostics 11, and an onboard client (hereinafter referred to as OBC) 12. As shown in Fig. 2, the ReproMaster 9 includes a downloader 13 and an OTA master 14 (corresponding to a master device).

[0029] When a download execution request is input from the OTA master 14, the downloader 13 instructs the DCM 4 to execute the download process. The update package distributed from the OTA center 2 is received by the DCM 4, and the received update package is transferred from the DCM 4, whereby the downloader 13 downloads the update package from the OTA center 2 via the DCM 4. The downloaded update package is temporarily stored in the ReproMaster 9 or an external memory, which will be described later.

[0030] The OTA master 14 includes an update control function unit 15, a state management function unit 16, a display control function unit 17, a write control function unit (Flashing Adapter) 18, a power control function unit 19, an OTA-compatible ECU list storage unit 20, and a campaign target ECU list storage unit 21. These functions are realized by software processing in which a microcomputer executes a computer program stored in a non-transient physical storage medium using a CPU, or by hardware processing using a dedicated electronic circuit.

[0031] The update control function unit 15 has a function of controlling software updates. The status management function unit 16 has a function of managing the status of the software to be updated as the software is updated. The display control function unit 17 has a function of controlling the display on the in-vehicle HMI 10 as the software is updated. The write control function unit 18 has a function of controlling the installation of software into the software to be updated. Hereinafter, the write control function unit 18 may be referred to as an installer 18 (equivalent to a diagnostic client).

[0032] The OTA-compatible ECU list storage unit 20 stores information included in the specification data that can identify ECUs that are compatible with OTA as an OTA-compatible ECU list. The campaign target ECU list storage unit 21 stores information included in the specification data that can identify target ECUs as a campaign target ECU list. Among the ECUs that are compatible with OTA, an ECU that is recorded in the campaign target ECU list is the target ECU, and among the ECUs that are compatible with OTA, an ECU that is not recorded in the campaign target ECU list is an ECU that is not eligible for the campaign.

[0033] The power supply control function unit 19 refers to the OTA-compatible ECU list and identifies an ECU that supports OTA. The power supply control function unit 19 refers to the campaign target ECU list and identifies a target ECU. The power supply control function unit 19 cooperates with the power supply control app 22 located in the second relay 7 to control the power supply to the ECU as the software update progresses. Note that, although the present embodiment illustrates a case in which the power supply control function unit 19 cooperates with the power supply control app 22 to control the power supply to the ECU, a configuration in which a power control ECU that controls the power supply to the ECU is located may also be used. Targets for which the power supply control function unit 19 controls power supply include the DCM 4, the in-vehicle HMI 10, the first relay 6, the second relay 7, the third relay 8, etc.

[0034] The OBC 12 includes an arbitration function unit 23 and a diagnostic communication function unit 24. The arbitration function unit 23 is responsible for diagnostic communication between the ReproMaster 9 and the repeater or ECU, and arbitrates which diagnostic communication should be prioritized. The diagnostic communication function unit 24 performs diagnostic communication between the ReproMaster 9 and the repeater or ECU according to the arbitration result of the arbitration function unit 23.

[0035] The OBC 12 is connected to a plurality of ECUs 25, 26 (corresponding to service target devices, software update target devices) via a first repeater 6. The plurality of ECUs 25, 26 are connected to the first repeater 6 via, for example, a CAN bus. CAN communication between the first repeater 6 and the plurality of ECUs 25, 26 is data communication using a 29-bit CAN ID. Of the plurality of ECUs 25, 26 connected to the first repeater 6, an ECU whose software is to be updated can be the target ECU. Although the example shows a case where two ECUs are connected to the first repeater 6, the number of ECUs connected to the first repeater 6 is not limited to two.

[0036] Similarly, the OBC 12 is connected to a plurality of ECUs 27, 28 (corresponding to service target devices, software update target devices) via a second relay 7. The plurality of ECUs 27, 28 are connected to the second relay 7 via, for example, a CAN bus. CAN communication between the second relay 7 and the plurality of ECUs 27, 28 is data communication using a 29-bit CAN ID. Of the plurality of ECUs 27, 28 connected to the second relay 7, an ECU whose software is to be updated can be the target ECU. Although the example shows a case where two ECUs are connected to the second relay 7, the number of ECUs connected to the second relay 7 is not limited to two.

[0037] Similarly, the OBC 12 is connected to a plurality of ECUs 29, 30 (corresponding to service target devices, software update target devices) via a third relay 8. The plurality of ECUs 29, 30 are connected to the third relay 8 via, for example, a CAN bus. CAN communication between the third relay 8 and the plurality of ECUs 29, 30 is data communication using a 29-bit CAN ID. An ECU that is the target of a software update among the plurality of ECUs 29, 30 connected to the third relay 8 can be the target ECU. Although the example shows a case where two ECUs are connected to the third relay 8, the number of ECUs connected to the third relay 8 is not limited to two.

[0038] Furthermore, the OBC 12 is connected to the ECU 31 without a relay. An ECU that is the target of software update among multiple ECUs connected to the OBC 12 can be the target ECU. Although the example shows a case where one ECU is connected to the OBC 12 without a relay, the number of ECUs that can be connected to the OBC 12 without a relay is not limited to one.

[0039] The power control application 22 arranged in the second repeater 7 cooperates with the power control function unit 19 of the OTA master 14 as described above, and controls the power supply to the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 as the software update progresses. That is, the OTA master 14 cooperates the power control function unit 19 with the power control application 22, and controls the power supply to the repeaters 6 to 8 and the ECUs 25 to 31 that are capable of diagnostic communication via the diagnostic communication function unit 24.

[0040] When a start request is input from the OTA master 14 while the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 are in a stopped state, the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 transition to a started state, and the supply of power from the in-vehicle battery is stopped. When a stop request is input from the OTA master 14 while the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 are in a started state, the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 transition to a stopped state, and the supply of power from the in-vehicle battery is stopped.

[0041] The external tool 32, while attached to a connector arranged in the vehicle, delivers the update package to the OTA master 14. The external memory 33 functions as external storage for the OTA master 14, and as a temporary storage destination for the update package downloaded from the OTA center 2 as described above, and also as a temporary save destination for pre-update software when updating the software of the repeaters 6 to 8 and the ECUs 25 to 31.

[0042] A series of processing phases related to a software update includes a configuration synchronization phase, a download phase, an installation phase, an activation phase, and an update completion notification phase. The configuration synchronization phase is a phase in which the OTA center 2 synchronizes configuration information of the software and hardware of the ECU installed in the target vehicle with configuration information of the software and hardware of the ECU.

[0043] The download phase is a phase in which the OTA master 14 downloads an update package from the OTA center 2. Before performing the download phase, the OTA master 14 determines, for example, whether the software to be downloaded is legitimate, and whether the download can be completed by checking the data volume of the software to be downloaded against the remaining charge of the vehicle battery. If the OTA master 14 determines, for example, that the software to be downloaded is legitimate and that the remaining charge of the vehicle battery is sufficient for the data volume of the software to be downloaded, the OTA master 14 performs the download phase.

[0044] The installation phase is a phase in which the OTA master 14 installs software extracted from the update package into the target ECU. Installation means writing the software to a storage area of ​​the target ECU. Before performing the installation phase, the OTA master 14 determines, for example, whether the software to be installed is authentic, and whether the installation can be completed by comparing the data volume of the software to be installed with the remaining charge of the vehicle battery. If the OTA master 14 determines, for example, that the software to be installed is authentic and that the remaining charge of the vehicle battery is sufficient for the data volume of the software to be installed, the OTA master 14 performs the installation phase.

[0045] The activation phase is a phase in which the installed software is activated in the target ECU. Before performing the activation phase, the OTA master 14 determines, for example, whether the software to be activated is authentic, and whether the activation can be completed by comparing the data volume of the software to be activated with the remaining charge of the vehicle battery. If the OTA master 14 determines, for example, that the software to be activated is authentic and that the remaining charge of the vehicle battery is sufficient for the data volume of the software to be activated, the OTA master 14 performs the activation phase.

[0046] The update completion notification phase is a phase in which the OTA master 14 transmits an update completion notification to the OTA center 2 when the OTA master 14 receives an update completion notification from the target ECU upon completion of activation.

[0047] As shown in Fig. 3, the OTA center 2 distributes specification data including location information, diagnostic service information, authority transfer information, and parallel execution information, as well as an installer, to the vehicle (corresponding to a distribution procedure). The OTA center 2 performs the distribution procedure using a data processing method and causes the distribution procedure to be executed using a data processing program. The location information is information that allows the OTA master 14 to identify the location of the installer. Based on the location information, the OTA master 14 identifies the first relay 6, the second relay 7, and the third relay 8 as the location of the installer, and distributes the installer to the first relay 6, the second relay 7, and the third relay 8, as described below.

[0048] The diagnostic service information is information used by the OTA master 14 to install software into target ECUs. The OTA master 14 identifies target ECUs based on the diagnostic service information, and determines the order in which software should be installed into the identified target ECUs, whether the software will be installed into the identified target ECUs using, for example, a storage method or a streaming method. As described below, when authority is transferred from the OTA master 14 to an installer, the installer to which authority is transferred from the OTA master 14 identifies target ECUs based on the diagnostic service information, and determines the order in which software should be installed into the identified target ECUs, whether the software will be installed into the identified target ECUs using, for example, a storage method or a streaming method, and installs the software into the target ECUs.

[0049] The OTA master 14 determines the destination of authority transfer to the installer, the order of authority transfer, etc., based on the authority transfer information. When software is installed serially into the target ECUs 25 to 28, for example, when software is installed first into the target ECUs 25 and 26 connected to the first repeater 6 and then into the target ECUs 27 and 28 connected to the second repeater 7, the OTA master 14 transfers authority to the installer arranged in the first repeater 6 first and then into the installer arranged in the second repeater 7. When software is installed in parallel into the target ECUs 25 to 28 according to parallel execution information described later, for example, the OTA master 14 transfers authority to the installer arranged in the first repeater 6 and the installer arranged in the second repeater 7 simultaneously.

[0050] The parallel execution information is information for the installers to install software in the target ECUs in parallel, i.e., the information for the installer located in the first relay device 6 to install software in the target ECUs 25 and 26, the installer located in the second relay device 7 to install software in the target ECUs 27 and 28, and the installer located in the third relay device 8 to install software in the target ECUs 29 and 30 in parallel.

[0051] The parallel execution information includes information that can identify whether multiple installers should install software in the target ECU in parallel, in other words, simultaneously. The OTA master 14 instructs the installer to which authority has been delegated to perform installation based on the parallel execution information. When the OTA master 14 causes multiple installers to install software in the target ECU in parallel, the OTA master 14 causes the multiple installers to install the software in the target ECU simultaneously. To achieve this, the OTA master 14 instructs the multiple installers to install the software in parallel, for example, or simultaneously.

[0052] The parallel execution information may include information that can identify whether multiple installers should install software on the target ECU serially, in other words, sequentially, and information that can identify the order in which the software should be installed sequentially. When the OTA master 14 causes multiple installers to install software on the target ECU serially, the OTA master 14 causes the multiple installers to install the software on the target ECU sequentially. To achieve this, the OTA master 14, for example, instructs one installer to install the software, waits for a notification of installation completion from that installer, and, after receiving the notification of installation completion, instructs the next installer in the order to install the software. Note that waiting for such a notification of installation completion is not necessary when instructing multiple installers to install the software in parallel.

[0053] The parallel execution information may include information for each of the authorized installers to install software in multiple target ECUs in parallel. The authorized installer installs software in multiple target ECUs in parallel or serially based on the parallel execution information. When installing software in multiple target ECUs in parallel, the installer installs software in multiple ECUs simultaneously in parallel. When installing software in multiple target ECUs in serial, the installer installs software in one target ECU, and after completing the installation of the software in the one target ECU, installs the software in the next ECU.

[0054] The OTA master 14 places the installer in the relay devices 6 to 8 based on the placement destination information received from the OTA center 2 (corresponding to the diagnostic client placement procedure). The OTA master 14 performs the diagnostic client placement procedure using a data processing method, and causes the diagnostic client placement procedure to be executed using a data processing program.

[0055] An example of a method by which the OTA master 14 places an installer in a destination is a method in which the OTA master 14 installs the installer as an application by additionally placing an executable file of the installer received from the OTA center 2 in a file system of the destination. The OTA master 14 can delete the placed installer from the destination where the installer was placed. An example of a method by which the OTA master 14 deletes an installer is a method in which the OTA master 14 uninstalls the installer as an application by deleting an executable file of the installer that was additionally placed in the file system of the destination. Another method by which the OTA master 14 places or deletes an installer is a method in which the OTA master 14 installs or uninstalls the installer by writing or deleting binary data including the installer to or from an address area of ​​non-volatile memory in the destination.

[0056] The OTA master 14 transfers authority to the installers arranged in the relay devices 6 to 8 based on the authority transfer information received from the OTA center 2, and instructs the installers to install the software into the target ECUs. The OTA master 14 installs the software into the target ECUs in parallel according to the parallel execution information received from the OTA center 2.

[0057] As shown in Fig. 4, the OTA master 14 performs a series of processing phases related to a software update, including a configuration synchronization phase (S1), a download phase (S2), an installation phase (S3), an activation phase (S4), and an update completion notification phase (S5). As shown in Fig. 5, in the installation phase, the OTA master 14 places the installer 18, the OBC 12, and the specification data in the relays 6 to 8, transfers authority to the placed installer 18, and instructs the installer 18 to install the software in the target ECU.

[0058] That is, when the installer 18 is placed by the OTA master 14, authority is transferred to the installer 18, and an instruction to execute installation is given, the first repeater 6 installs software into the target ECUs 25, 26 (corresponding to a diagnostic service execution procedure). The first repeater 6 executes the diagnostic service execution procedure using a data processing method, and causes the diagnostic service execution procedure to be executed using a data processing program.

[0059] Similarly, when the OTA master 14 places the installer 18, transfers authority to the installer 18, and instructs the second relay 7 to install software into the target ECUs 27 and 28, the second relay 7 installs software into the target ECUs 27 and 28. When the OTA master 14 places the installer 18, transfers authority to the installer 18, and instructs the third relay 8 to install software into the target ECUs 29 and 30, the third relay 8 installs software into the target ECUs 29 and 30.

[0060] The specification data will now be described. When the OTA master 14 places specification data in the repeaters 6-8, it may place specification data common to the OTA master 14 and the repeaters 6-8, or it may place specification data specific to each repeater 6-8. When placing specification data common to the OTA master 14 and the repeaters 6-8, it places specification data that records information about each target ECU of the OTA master 14 and the repeaters 6-8, as shown in FIG. 6. The data referenced by the repeaters 6-8 is included in "Sync Group Info A." The repeaters 6-8 each refer to the data defined as their own reference target and install software into the target ECUs 25-30.

[0061] When specific data specific to the OTA master 14 and the repeaters 6 to 8 is allocated, specific data recording information on each target ECU for each repeater 6 to 8 is allocated, as shown in Figure 7. The data referenced by the first repeater 6 is included in "Sync Group Info B," the data referenced by the second repeater 7 is included in "Sync Group Info C," and the data referenced by the third repeater 8 is included in "Sync Group Info D." The repeaters 6 to 8 each refer to the data defined as their own reference target and install software into the target ECUs 25 to 30.

[0062] Next, the operation of the above-described configuration will be described with reference to Figures 8 to 12. An installer placement process in which the OTA master 14 places the installer 18, the OBC 12, and the specification data in the repeaters 6 to 8, and an authority transfer determination process in which the repeaters 6 to 8 determine whether authority has been transferred from the OTA master 14 to the installer 18 will be described. Note that, while a case in which the OTA master 14 places the installer 18, the OBC 12, and the specification data in the first repeater 6 will be described here, the same applies to the second repeater 7 and the third repeater 8.

[0063] (1) Installer Placement Process (See FIG. 8) When the OTA master 14 completes the download phase and starts the installation phase, it starts the installer placement process, transmits the installer 18, the OBC 12, and the specification data to the first repeater 6, and places the installer 18, the OBC 12, and the specification data in the first repeater 6 (A1). The OTA master 14 determines whether authority can be transferred to the installer 18 placed in the first repeater 6 (A2).

[0064] When the OTA master 14 determines that software installation into the target ECUs 25, 26 is not possible because, for example, the processing load of the first relay device 6 is equal to or greater than a threshold, and that authority cannot be transferred to the installer 18 located in the first relay device 6 (A2: NO), the OTA master 14 terminates the installer placement process. Note that, when the OTA master 14 determines that authority transfer to the installer 18 is not possible, it may wait until it determines that authority transfer to the installer 18 is possible.

[0065] When the OTA master 14 determines that software installation into the target ECUs 25, 26 is possible because, for example, the processing load of the first relay 6 is below a threshold, and that authority can be transferred to the installer 18 located in the first relay 6 (A2: YES), the OTA master 14 transfers authority to the installer 18 located in the first relay 6 (A3). The OTA master 14 instructs the installer 18 to perform installation (A4) and waits for reception of an installation completion notification from the first relay 6 (A5). When the OTA master 14 determines that the installation completion notification has been received from the first relay 6 (A5: YES), the OTA master 14 transmits a deletion instruction notification to the first relay 6 to delete the installer 18, the OBC 12, and the specification data, and instructs the first relay 6 to delete the installer 18, the OBC 12, and the specification data (A6), thereby completing the installer deployment process.

[0066] In addition, the OTA master 14 may perform the installer placement process of placing the installer 18 in the first repeater 6, the installer placement process of placing the installer 18 in the second repeater 7, and the installer placement process of placing the installer 18 in the third repeater 8 in series or in parallel.

[0067] (2) Authority Transfer Determination Process (See FIG. 9 ) When the installer 18, OBC 12, and specification data are transferred from the OTA master 4, the first repeater 6 starts the authority transfer determination process and waits for authority transfer from the OTA master 14 to the installer 18 ( B1 ). For example, if the first repeater 6 determines that authority transfer from the OTA master 14 to the installer 18 has not occurred within a predetermined time after the installer 18, OBC 12, and specification data are transferred ( B1 : NO), the first repeater 6 deletes the installer 18, OBC 12, and specification data ( B8 ), transmits a status notification to the OTA master 4 indicating that the deletion of the installer 18, OBC 12, and specification data has been completed ( B9 ), and terminates the authority transfer determination process. By deleting the installer 18, OBC 12, and specification data, the first repeater 6 avoids unnecessary memory usage and prevents unauthorized installation by an installer 18 that is unnecessarily remaining.

[0068] For example, when the first repeater 6 determines that authority has been transferred from the OTA master 14 to the installer 18 within a predetermined time after the installer 18, OBC 12, and specification data have been placed (B1: YES), it waits for an instruction to execute installation to the installer 18 for which authority has been transferred (B2).

[0069] For example, if the first repeater 6 determines that the installer 18 has not been instructed to perform installation within a predetermined time after the transfer of authority to the installer 18 (B2: NO), it performs the above-mentioned steps S8 and S9 and terminates the authority transfer determination process.

[0070] For example, if the first relay device 6 determines that an installation instruction has been issued to the installer 18 within a predetermined time after the transfer of authority to the installer 18 (B2: YES), the first relay device 6 identifies a target ECU based on the specification data (B3). The first relay device 6 installs the software in the identified target ECU (B4) and waits for the installation of the software in the target ECU to be completed (B5). That is, the first relay device 6 installs the software in the target ECUs 25 and 26 and waits for the installation of the software in the target ECUs 25 and 26 to be completed. In this case, the first relay device 6 may install the software in the target ECU 25 and the software in the target ECU 26 in series or in parallel.

[0071] When the first repeater 6 determines that the installation of the software into the target ECUs 25, 26 is completed (B5: YES), it transmits an installation completion notification to the OTA master 14 (B6) and waits for a deletion instruction notification of the installer 18, the OBC 12, and the specification data from the OTA master 4 (B7).When the first repeater 6 determines that the deletion instruction notification of the installer 18, the OBC 12, and the specification data has been received from the OTA master 4 (B7: YES), it performs the above-mentioned steps S8 and S9 and ends the authority transfer determination process.

[0072] Furthermore, when authority is transferred to the installer 18 located in the relays 6 to 8, the installation of software from the first relay 6 to the target ECUs 25 and 26, the installation of software from the second relay 7 to the target ECUs 27 and 28, and the installation of software from the third relay 8 to the target ECUs 29 and 30 may be performed in series or in parallel.

[0073] The above is an example of a case where the installer 18, OBC 12, and specification data placed on the relay devices 6 to 8 are deleted on the condition that the software installation is completed, but the installer 18, OBC 12, and specification data placed on the relay devices 6 to 8 may also be deleted on the condition that the software activation is completed.

[0074] 10, the OTA master 14 instructs the installer 18 to perform installation (A4), and upon determining that the installation has been completed, instructs the installer 18 to perform activation (A11), and waits for reception of an activation completion notification from the first repeater 6 (A12). When the OTA master 14 determines that an activation completion notification has been received from the first repeater 6 (A12: YES), the OTA master 14 transmits a deletion instruction notification to the first repeater 6 to delete the installer 18, the OBC 12, and the specification data, and instructs the first repeater 6 to delete the installer 18, the OBC 12, and the specification data (A6), thereby completing the installer deployment process.

[0075] 11 and 12, the first repeater 6 waits for the completion of the software installation in the target ECU (B5). When the first repeater 6 determines that the software installation is complete (B5: YES), it waits for the completion of the software activation (B11). When the first repeater 6 determines that the software activation is complete (B11: YES), it transmits an activation execution completion notification to the OTA master 14 (B12) and waits for the receipt of a deletion instruction notification for the installer 18, the OBC 12, and the specification data from the OTA master 4 (B7). When the first repeater 6 determines that the deletion instruction notification for the installer 18, the OBC 12, and the specification data has been received from the OTA master 4 (B7: YES), it performs steps S8 and S9 described above and ends the authority transfer determination process.

[0076] The above describes an example of a configuration in which the OTA master 14 places installers in the relays 6 to 8 connected to itself and transfers authority to the installers placed in the relays 6 to 8, but installers may be placed in multiple tiers and authority may be transferred to the installers in multiple tiers. For example, in a configuration in which ECUs are connected in a hierarchical structure, the OTA master 14 may place an installer in an ECU at a higher tier and transfer authority to the installer placed in the ECU at the higher tier, and an installer from the ECU at the higher tier may be placed in an ECU at a lower tier and transfer authority to the installer placed in the ECU at the lower tier.

[0077] As described above, the embodiment provides the following advantageous effects. In the OTA master 14, an installer for installing software into a target ECU is arranged in the relays 6 to 8. In the relays 6 to 8, an installer is arranged from the OTA master 14, and when authority is transferred to the arranged installer and an instruction to install software is given, the software is installed into the target ECU. This appropriately reduces restrictions on where the installer can be arranged, appropriately shortens the time required to install software into the target ECU, and allows the software to be appropriately installed into the target ECU.

[0078] The OTA center 2 distributes to the OTA master 14 location information for the OTA master 14 to place the installer in the relay devices 6 to 8, and diagnostic service information for installing the software in the target ECU. The OTA master 14 and the relay devices 6 to 8 can be made to appropriately install the software in the target ECU.

[0079] The present disclosure includes the following disclosures in addition to the claims: [1] A master device (14) that performs a diagnostic service, wherein a relay device connected to the master device so as to be able to perform data communication therewith arranges a diagnostic client in the relay device for performing the diagnostic service on a service target device.

[0080] [2] The master device according to [1], which transfers authority to the diagnostic client located in the relay device and instructs the diagnostic client to which authority has been transferred to execute the diagnostic service.

[0081] [3] The master device according to [2], which waits for a notification of completion of execution of the diagnostic service from a relay device in which the diagnostic client to which the authority is to be transferred is located.

[0082] [4] The master device according to [3], which instructs the relay device to delete the diagnostic client when a notification of completion of execution of the diagnostic service is received from the relay device.

[0083] [5] A master device described in any one of [1] to [4], which places the diagnostic client on multiple relay devices, transfers authority to multiple diagnostic clients placed on the multiple relay devices, and instructs the execution of the diagnostic service in parallel to the multiple diagnostic clients to which authority has been transferred.

[0084] [6] A master device according to any one of [1] to [5], in which an installer for installing software into a software update target device is placed on the relay device as the diagnostic client, and the master device installs software into the update target device as the diagnostic service.

[0085] [7] A relay device (6-8) capable of data communication with a master device (14) that performs a diagnostic service, wherein a diagnostic client for performing the diagnostic service is placed from the master device, authority is transferred to the diagnostic client, and when execution of the diagnostic service is instructed, the relay device performs the diagnostic service to a service target device.

[0086] [8] The relay device according to [7], wherein when the diagnostic service is completed, a notification of completion of execution of the diagnostic service for the service target device is transmitted to the master device.

[0087] [9] The relay device according to [7] or [8], which deletes the diagnostic client when instructed by the master device to delete the diagnostic client.

[0088]

[10] The relay device according to [9], wherein when the deletion of the diagnostic client is completed, the relay device transmits a deletion completion notice of the diagnostic client to the master device.

[0089]

[11] An external device (2) capable of data communication with a master device (14) that performs a diagnostic service, the external device distributing to the master device location information for the master device to identify the location of a diagnostic client corresponding to the diagnostic service, and diagnostic service information for the master device to perform the diagnostic service on a service target device.

[0090]

[12] The external device according to

[11] , which distributes authority transfer information to the master device for the master device to specify a destination to which authority of the diagnostic client is to be transferred.

[0091]

[13] The external device according to

[11] or

[12] , which distributes parallel execution information to the master device so that a plurality of diagnostic clients located at different locations can perform the diagnostic service in parallel.

[0092]

[14] The external device according to any one of

[11] to

[13] , which distributes the diagnostic client to the master device.

[0093]

[15] The external device according to any one of

[11] to

[14] , which distributes specification data relating to a software update of a software update target device to the master device as the diagnostic service.

[0094]

[16] A data communication system (1) comprising a master device (14) that performs a diagnostic service and an external device (2) capable of data communication with the master device, wherein the external device distributes to the master device location information for the master device to identify a location for a diagnostic client corresponding to the diagnostic service and diagnostic service information for the master device to perform the diagnostic service to a service target device, and the master device places the diagnostic client on the relay device based on the location information received from the external device, and performs the diagnostic service to the service target device based on the diagnostic service information received from the external device.

[0095]

[17] The data communication system described in

[16] , wherein the external device distributes authority transfer information to the master device to enable the master device to identify the destination of authority transfer to the diagnostic client, and the master device transfers authority to the diagnostic client based on the authority transfer information received from the external device, and instructs the diagnostic client to which authority has been transferred to execute the diagnostic service.

[0096]

[18] A data communication system as described in

[17] , in which the external device distributes parallel execution information to the master device so that multiple diagnostic clients located at different locations can perform the diagnostic service in parallel, and the master device instructs the multiple diagnostic clients to which authority has been transferred to execute the diagnostic service in parallel based on the parallel execution information received from the external device.

[0097]

[19] A data communication system according to any one of

[16] to

[18] , wherein the external device distributes the diagnostic client to the master device, and the master device places the diagnostic client received from the external device in the relay device specified by the placement destination information.

[0098]

[20] A data communication system according to any one of

[16] to

[19] , wherein the master device, as the diagnostic client, places an installer for updating software of the software update target device on the relay device, and installs software on the update target device as the diagnostic service.

[0099] Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and modifications within the scope of equivalents. In addition, various combinations and forms, as well as other combinations and forms including only one element, more than one element, or less than one element, are also within the scope and spirit of the present disclosure.

[0100] Although the OTA center 2 is used as an example of an external device and wireless reprogramming is described, the present invention can also be applied to wired reprogramming using an external tool 32 that is wired connected to the CGW 5. Furthermore, the external device is not limited to the OTA center 2 or the external tool 32, and may be, for example, a mobile information terminal such as a smartphone or a tablet terminal.

[0101] In the example shown, the repeaters 6 to 8 delete the installer 18, OBC 12, and specification data on the condition that a deletion instruction notification for the installer 18, OBC 12, and specification data is received from the OTA master 4 after the installation of the software in the target ECU is completed. However, the configuration may also be such that the installer 18, OBC 12, and specification data are deleted on the condition that the installation of the software in the target ECU is completed, rather than on the condition that a deletion instruction notification is received.

[0102] Although the target ECUs 25 to 30 are exemplified as devices for which software is to be updated, the relays 6 to 8 may also be included as devices for which software is to be updated.

[0103] The control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit and the method described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to perform one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible storage medium.

Claims

1. A master device (14) that performs diagnostic services, in which a relay device connected to the master device so as to be able to communicate data places a diagnostic client in the relay device for performing diagnostic services on a service target device.

2. The master device according to claim 1, which transfers authority to the diagnostic client located in the relay device and instructs the diagnostic client to which authority has been transferred to execute the diagnostic service.

3. The master device according to claim 2, which waits for a notification of completion of execution of the diagnostic service from a relay device in which the diagnostic client to which the authority is to be transferred is located.

4. The master device according to claim 3, which instructs the relay device to delete the diagnostic client when a notification of completion of execution of the diagnostic service is received from the relay device.

5. A master device as described in claim 1, which places the diagnostic client on multiple relay devices, transfers authority to multiple diagnostic clients placed on the multiple relay devices, and instructs the execution of the diagnostic service in parallel to the multiple diagnostic clients to which authority has been transferred.

6. The master device according to claim 1, wherein an installer for installing software into a software update target device as the diagnostic client is arranged in the relay device, and the software is installed into the update target device as the diagnostic service.

7. A relay device (6-8) capable of data communication with a master device (14) that performs diagnostic services, wherein a diagnostic client for performing the diagnostic services is placed from the master device, authority is transferred to the diagnostic client, and when execution of the diagnostic services is instructed, the relay device performs the diagnostic services on the service target device.

8. The relay device according to claim 7, wherein when the diagnostic service is completed, a notification of completion of execution of the diagnostic service is transmitted to the master device.

9. The relay device according to claim 7, wherein the relay device deletes the diagnostic client when the master device instructs the deletion of the diagnostic client.

10. The relay device according to claim 9, wherein when the deletion of the diagnostic client is completed, a notification of the completion of deletion of the diagnostic client is transmitted to the master device.

11. An external device (2) capable of data communication with a master device (14) that performs a diagnostic service, which distributes to the master device location information for the master device to identify the location of a diagnostic client corresponding to the diagnostic service, and diagnostic service information for the master device to perform the diagnostic service on a service target device.

12. The external device according to claim 11, which distributes to the master device authority transfer information for the master device to specify a destination to which authority of the diagnostic client is to be transferred.

13. The external device according to claim 11, wherein parallel execution information for allowing a plurality of diagnostic clients located at different locations to perform the diagnostic service in parallel is distributed to the master device.

14. The external device according to claim 11, which distributes the diagnostic client to the master device.

15. The external device according to claim 11, wherein the diagnostic service distributes specification data relating to software updates of target devices to the master device.

16. A data communication system (1) comprising a master device (14) that performs diagnostic services and an external device (2) capable of data communication with the master device, wherein the external device distributes to the master device location information for the master device to identify the location of a diagnostic client corresponding to the diagnostic service and diagnostic service information for the master device to perform the diagnostic service to a service target device, and the master device places the diagnostic client on the relay device based on the location information received from the external device, and performs the diagnostic service to the service target device based on the diagnostic service information received from the external device.

17. A data communication system as described in claim 16, wherein the external device distributes authority transfer information to the master device to enable the master device to identify the destination of authority transfer to the diagnostic client, and the master device transfers authority to the diagnostic client based on the authority transfer information received from the external device, and instructs the diagnostic client to which authority has been transferred to execute the diagnostic service.

18. A data communication system as described in claim 17, wherein the external device distributes parallel execution information to the master device so that multiple diagnostic clients located at different locations can perform the diagnostic service in parallel, and the master device instructs the multiple diagnostic clients to which authority has been transferred to execute the diagnostic service in parallel based on the parallel execution information received from the external device.

19. A data communication system as described in claim 16, wherein the external device distributes the diagnostic client to the master device, and the master device places the diagnostic client received from the external device in the relay device specified by the placement destination information.

20. A data communication system as described in claim 16, wherein the master device places an installer for updating software of the device to be updated on the relay device as the diagnostic client, and installs software on the device to be updated as the diagnostic service.

21. A data processing method in which, in a master device (14) that provides diagnostic services, a relay device connected to the master device so as to be able to communicate data performs a diagnostic client placement procedure in which the relay device places a diagnostic client in the relay device to provide diagnostic services to a service target device.

22. A data processing program that causes a master device (14) that performs diagnostic services to execute a diagnostic client placement procedure in which a relay device connected to the master device so as to be able to communicate data with the master device places a diagnostic client in the relay device to perform diagnostic services on a service target device.

23. A data processing method in which, in a master device (14) that performs a diagnostic service and a relay device (6-8) capable of data communication, a diagnostic client for performing the diagnostic service is placed from the master device, authority is transferred to the diagnostic client, and when execution of the diagnostic service is instructed, a diagnostic service execution procedure is performed to perform the diagnostic service on a service target device.

24. A data processing program that causes a master device (14) that performs a diagnostic service and a relay device (6-8) capable of data communication to execute a diagnostic service execution procedure for performing the diagnostic service on a service target device when a diagnostic client for performing the diagnostic service is placed from the master device, authority is transferred to the diagnostic client, and execution of the diagnostic service is instructed.

25. A data processing method in which an external device (2) capable of data communication with a master device (14) that performs a diagnostic service performs a distribution procedure to distribute to the master device location information for the master device to identify the location of a diagnostic client corresponding to the diagnostic service, and diagnostic service information for the master device to perform the diagnostic service on a service target device.

26. A data processing program that causes a master device (14) that performs a diagnostic service and an external device (2) capable of data communication to execute a distribution procedure for distributing to the master device location information for the master device to identify the location of a diagnostic client corresponding to the diagnostic service and diagnostic service information for the master device to perform the diagnostic service on a service target device.