In-vehicle network management system and in-vehicle network management method
The in-vehicle network management system addresses the challenge of configuring message relay processing by using an integrated update, configuration, and relay management unit to ensure relay processing aligns with the latest hardware and software configurations.
Patent Information
- Application Number
- PCT/JP2024/039417
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-13
- Filing Date
- 2024-11-06
- Publication Date
- 2025-05-22
AI Technical Summary
Existing in-vehicle network management systems struggle to appropriately configure message relay processing, especially when hardware configurations change or software updates occur.
The system includes an update management unit, a configuration management unit, and a relay management unit that work together to update target software, monitor hardware configurations, and set up message relay processing. When hardware configurations change, the units exchange relevant configuration information to ensure relay processing is updated accordingly.
This configuration allows for appropriate setting of message relay processing in in-vehicle networks, ensuring that relay processing is based on the latest hardware and software configurations, even during changes or updates.
Smart Images

Figure JP2024039417_22052025_PF_FP_ABST
Abstract
Description
In-vehicle network management system and in-vehicle network management method
[0001] This application claims priority from Japanese Patent Application No. 2023-192674, filed November 13, 2023, the disclosure of which is incorporated herein by reference in its entirety.
[0002] Patent Literature 1 (WO 2020 / 179123) discloses the following management device: That is, the management device includes a detection unit that detects the addition of a functional unit to a network that includes one or more in-vehicle functional units, an acquisition unit that acquires functional unit information including information on the new functional unit that is the functional unit whose addition is detected by the detection unit and on the network configuration of the in-vehicle functional unit at a layer lower than the application layer, and a generation unit that generates configuration information of the new network that is the network that further includes the new functional unit, based on the functional unit information acquired by the acquisition unit.
[0003] International Publication No. 2020 / 179123
[0004] "ST-OTA-4 OTA Software Update Vehicle System Requirements Specification Document Ver. 1.2," JasPar OTA Technology Working Group, January 13, 2023
[0005] The in-vehicle network management system of the present disclosure includes an update management unit that updates target software, which is software that is the target of update processing in an in-vehicle network, a configuration management unit that monitors the hardware configuration in the in-vehicle network, and a relay management unit that sets up message relay processing in the in-vehicle network, and when the hardware configuration changes, the configuration management unit transmits connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit, and when the hardware configuration changes, the update management unit transmits to the relay management unit vehicle configuration information in the in-vehicle network after the change in hardware configuration, which indicates the correspondence between the target software, the in-vehicle device on which the target software is installed, and the version of the target software, and when the target software is updated, the update management unit transmits to the relay management unit the vehicle configuration information in the in-vehicle network including the updated target software.
[0006] One aspect of the present disclosure may be realized not only as an in-vehicle network management system including such a characteristic processing unit, but also as a program for causing a computer to execute the steps of such characteristic processing, or as a semiconductor integrated circuit that realizes part or all of the in-vehicle network management system.
[0007] FIG. 1 is a diagram illustrating an example of the configuration of an in-vehicle network management system according to an embodiment of the present disclosure. FIG. 2 is a diagram illustrating a configuration of a relay device according to an embodiment of the present disclosure. FIG. 3 is a diagram illustrating an example of an update list stored in a storage unit of the relay device according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating an example of an inhibition list stored in a storage unit of the relay device according to an embodiment of the present disclosure. FIG. 5 is a diagram illustrating an example of a topology correspondence table created by a configuration management unit of the relay device according to an embodiment of the present disclosure. FIG. 6 is a diagram illustrating an example of a vehicle configuration table created by an update management unit of the relay device according to an embodiment of the present disclosure. FIG. 7 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. FIG. 8 is a diagram illustrating an example of a topology correspondence table after an update by a configuration management unit of the relay device according to an embodiment of the present disclosure. FIG. 9 is a diagram illustrating an example of a vehicle configuration table created by an update management unit of the relay device according to an embodiment of the present disclosure. FIG. 10 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. FIG. 11 is a diagram illustrating an example of an update list after an update by an update management unit of the relay device according to an embodiment of the present disclosure. FIG. 12 is a diagram illustrating an example of an inhibition list after updating by an update management unit in a relay device according to an embodiment of the present disclosure. FIG. 13 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. FIG. 14 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. FIG. 15 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. FIG. 16 is a diagram illustrating an example of a topology correspondence table after updating by a configuration management unit in a relay device according to an embodiment of the present disclosure. FIG. 17 is a diagram illustrating an example of an inhibition list after updating by an update management unit in a relay device according to an embodiment of the present disclosure. FIG. 18 is a diagram illustrating an example of a sequence for changing the settings of relay processing in an in-vehicle network management system according to an embodiment of the present disclosure. FIG. 19 is a diagram illustrating an example of a sequence for changing the settings of relay processing in an in-vehicle network management system according to an embodiment of the present disclosure.
[0008] In recent years, with the spread of car sharing and the demand for improved processing power of in-vehicle devices, there is a demand for customizing in-vehicle networks by adding applications to the in-vehicle network. Thus, there is a demand for technology that enables various applications to be added or removed from the in-vehicle network according to user needs.
[0009] [Problem to be Solved by the Present Disclosure] There is a need for a technology that goes beyond the technology described in Patent Document 1 and Non-Patent Document 1 and that is capable of appropriately setting the relay processing of messages in an in-vehicle network.
[0010] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide an in-vehicle network management system and an in-vehicle network management method that are capable of appropriately configuring message relay processing in an in-vehicle network.
[0011] Effect of the Present Disclosure According to the present disclosure, it is possible to appropriately set the relay process of messages in an in-vehicle network.
[0012] [Description of Embodiments of the Present Disclosure] First, the contents of the embodiments of the present disclosure will be listed and described.
[0013] (1) An in-vehicle network management system according to an embodiment of the present disclosure includes an update management unit that updates target software, which is software that is subject to update processing in an in-vehicle network; a configuration management unit that monitors the hardware configuration in the in-vehicle network; and a relay management unit that sets message relay processing in the in-vehicle network. When the hardware configuration changes, the configuration management unit transmits connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit. When the hardware configuration changes, the update management unit transmits vehicle configuration information in the in-vehicle network after the change in hardware configuration, which indicates a correspondence between the target software, the in-vehicle device on which the target software is installed, and the version of the target software to the relay management unit. When the target software is updated, the update management unit transmits the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit.
[0014] With this configuration, in an in-vehicle network where the hardware configuration changes or the software is updated, connection configuration information for the in-vehicle network after the hardware configuration change and vehicle configuration information for the in-vehicle network including the updated software can be provided to the relay management unit, so that message relay processing in the in-vehicle network can be set based on the latest hardware configuration and the latest software configuration. Therefore, message relay processing in the in-vehicle network can be set appropriately.
[0015] (2) In (1) above, the update management unit may create the vehicle configuration information based on an update list indicating the on-board device on which the target software is installed, and the update management unit may update the update list when the on-board device on which the target software is installed is added to the on-board network.
[0016] With this configuration, for example, when target software is installed in an on-board device added to an on-board network, message relay processing in the on-board network to which the on-board device has been added can be configured based on the latest software configuration including the software.
[0017] (3) In the above (2), the update management unit may obtain app information indicating the version of the target software installed in the in-vehicle device from the in-vehicle device indicated by the update list, and create the vehicle configuration information based on the obtained app information.
[0018] With this configuration, application information can be obtained from the in-vehicle device through communication with the in-vehicle device, and the latest vehicle configuration information can be created in the in-vehicle network. Therefore, compared to a configuration in which application information is received from a user, for example, vehicle configuration information can be created automatically and easily.
[0019] (4) In any of (1) to (3) above, the update management unit may perform a process to prevent shutdown of the on-board device on which the target software to be updated in the update process is installed, based on an inhibition list indicating the on-board devices that need to operate in the update process of the target software, and the update management unit may update the inhibition list when the on-board device on which the target software is installed is added to the on-board network.
[0020] With this configuration, for example, when the target software is installed in an in-vehicle device added to an in-vehicle network, the operating state of the in-vehicle device can be maintained during the software update process, so that the software update process can be performed while the vehicle power is off.
[0021] (5) In the above (4), the update management unit may further perform processing to inhibit shutdown of a relay device that needs to relay a message related to the update processing, based on the inhibition list.
[0022] With this configuration, for example, when the target software is installed in an in-vehicle device that sends and receives messages regarding update processing with the update management unit via a relay device, the relay device can be maintained in an operating state during the software update processing, and the software update processing can be performed during the period when the vehicle's power is turned off.
[0023] (6) An in-vehicle network management method according to an embodiment of the present disclosure is an in-vehicle network management method in an in-vehicle network management system including an update management unit that updates target software, which is software that is subject to update processing in an in-vehicle network, a configuration management unit that monitors the hardware configuration in the in-vehicle network, and a relay management unit that sets message relay processing in the in-vehicle network, and includes a step in which, when the hardware configuration has changed, the configuration management unit sends connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit; when the hardware configuration has changed, the update management unit sends vehicle configuration information in the in-vehicle network after the change in hardware configuration to the relay management unit, the vehicle configuration information indicating a correspondence between the target software, the in-vehicle device on which the target software is installed, and the version of the target software; and when the update management unit updates the target software, the update management unit sends the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit.
[0024] With this method, in an in-vehicle network where the hardware configuration changes or the software is updated, connection configuration information in the in-vehicle network after the hardware configuration change and vehicle configuration information in the in-vehicle network including the updated software can be provided to the relay management unit, so that message relay processing in the in-vehicle network can be set based on the latest hardware configuration and the latest software configuration, thereby allowing appropriate setting of message relay processing in the in-vehicle network.
[0025] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, identical or corresponding parts are designated by the same reference numerals, and their description will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any manner.
[0026] [Configuration and Basic Operation] Fig. 1 is a diagram illustrating an example of the configuration of an in-vehicle network management system according to an embodiment of the present disclosure. Referring to Fig. 1, an in-vehicle network management system 301 includes a relay device 101, in-vehicle ECUs (Electronic Control Units) 111 (ECUs 111A, 111B, and 111C), and an external communication device 151. The in-vehicle network management system 301 is mounted on a vehicle 1. The in-vehicle ECU 111 is an example of an in-vehicle device. The relay device 101, the in-vehicle ECUs 111A, 111B, and 111C, and the external communication device 151 configure an in-vehicle network 31A.
[0027] The relay device 101 includes communication ports PA1, PA2, PA3, and PA4, which are communication ports PA, and a communication port PB. The communication ports PA and PB are terminals to which an Ethernet (registered trademark) cable 32 can be connected.
[0028] The in-vehicle ECU 111 and the external communication device 151 are connected to the relay device 101 via an Ethernet cable 32. More specifically, the in-vehicle ECUs 111A, 111B, and 111C are connected to communication ports PA1, PA2, and PA3 in the relay device 101, respectively, via the Ethernet cable 32. The external communication device 151 is connected to a communication port PB in the relay device 101 via the Ethernet cable 32.
[0029] The external communication device 151 is, for example, a TCU (Telematics Communication Unit). The external communication device 151 is capable of wireless communication with an OTA (Over The Air) server (not shown) outside the vehicle 1.
[0030] The in-vehicle ECU 111 is, for example, an automatic driving ECU, an engine ECU, a sensor, a navigation device, a human-machine interface, a camera, and the like.
[0031] The in-vehicle ECUs 111A, 111B, and 111C are respectively equipped with applications 112A, 112B, and 112C, which are the application 112. The application 112 is an example of target software. The application 112 is software that is subject to update processing in the in-vehicle network 31, and is updated periodically or irregularly using OTA technology.
[0032] The application 112 generates messages including various data by performing processing on the application layer. For example, the application 112 in the in-vehicle ECU 111, which is a temperature sensor, generates messages including temperature data indicating the outside air temperature of the vehicle 1 at a predetermined interval.
[0033] The relay device 101 is, for example, a gateway device, and is capable of relaying messages transmitted and received in the in-vehicle network 31. The relay device 101 performs relay processing of messages exchanged between the in-vehicle ECUs 111 and messages exchanged between the in-vehicle ECUs 111 and the external communication device 151 in accordance with the Ethernet communication standard.
[0034] The relay device 101 updates the application 112 in the in-vehicle network 31, monitors the hardware configuration in the in-vehicle network 31, and sets the relay process. More specifically, the relay device 101 receives update data for the application 112 from an OTA server outside the vehicle 1 via the external communication device 151, and updates the application 112 using the received update data. Furthermore, when the hardware configuration in the in-vehicle network 31 changes or when the application 112 is updated, the relay device 101 changes the settings for the relay process.
[0035] Note that the in-vehicle network 31 is not limited to a configuration in which messages are relayed in accordance with the Ethernet communication standard, and may be a configuration in which messages are relayed in accordance with a communication standard such as CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), and LIN (Local Interconnect Network).
[0036] Furthermore, the in-vehicle network management system 301 is not limited to a configuration including three in-vehicle ECUs 111, but may be a configuration including one, two, or four or more in-vehicle ECUs 111. Furthermore, the in-vehicle network management system 301 is not limited to a configuration including one application 112 mounted on one in-vehicle ECU 111, but may be a configuration including two or more applications 112 mounted on one in-vehicle ECU 111. Furthermore, the in-vehicle network management system 301 is not limited to a configuration including one relay device 101, but may be a configuration including multiple relay devices 101.
[0037] [Problem] In a conventional in-vehicle communication system, for example, when an in-vehicle ECU 111 equipped with an application 112 is retrofitted to an in-vehicle network 31, it may not be possible to properly update the application 112. Furthermore, in a conventional in-vehicle communication system, when the application 112 is updated, it may not be possible to properly set a relay process according to the latest update status of the application 112.
[0038] Therefore, the in-vehicle network management system 301 according to the embodiment of the present disclosure solves the above problem by using the following configuration.
[0039] (Relay Device) FIG. 2 is a diagram illustrating the configuration of a relay device according to an embodiment of the present disclosure. Referring to FIG. 2, relay device 101 includes relay unit 11, update management unit 12, configuration management unit 13, relay management unit 14, and storage unit 15. Update management unit 12 includes update unit 12A, creation unit 12B, and transmission unit 12C. Update management unit 12 is an example of an update management device. Some or all of relay unit 11, update management unit 12, configuration management unit 13, and relay management unit 14 are realized, for example, by a processing circuit (circuitry) including one or more processors. Storage unit 15 is, for example, a non-volatile memory included in the processing circuit.
[0040] The relay unit 11 relays messages in the in-vehicle network 31. More specifically, the relay unit 11 receives a message from the in-vehicle ECU 111 via a corresponding communication port PA, and transmits the received message to the destination in-vehicle ECU 111 via the corresponding communication port PA.
[0041] The update management unit 12 updates the application 112. More specifically, the update unit 12A in the update management unit 12 receives update data from the OTA server via the external communication device 151 and the relay unit 11, and performs update processing to update the application 112 using the received update data.
[0042] The configuration management unit 13 monitors the hardware configuration of the in-vehicle network 31. For example, the configuration management unit 13 detects a change in the in-vehicle network 31 due to the addition or removal of an in-vehicle device.
[0043] 3 is a diagram illustrating an example of an update list stored in a storage unit in the relay device according to the embodiment of the present disclosure. Referring to FIG. 3, the storage unit 15 stores an update list L1 indicating ECU IDs, which are IDs of the in-vehicle ECUs 111 on which the application 112 is installed. The ECU IDs of the in-vehicle ECUs 111A, 111B, and 111C are assumed to be "ecu001," "ecu002," and "ecu003," respectively.
[0044] 4 is a diagram illustrating an example of an inhibition list stored in a storage unit in the relay device according to the embodiment of the present disclosure. Referring to FIG. 4, the storage unit 15 stores an inhibition list L2 indicating a correspondence relationship between an application ID, which is the ID of an application 112, and a device ID, which is the ID of an in-vehicle device that needs to operate in the update process of the application 112.
[0045] For example, the update list L1 and the inhibition list L2 are created by the update management unit 12 and stored in the storage unit 15. The update management unit 12 acquires the ECU ID of the in-vehicle ECU 111 on which the application 112 is installed by communicating with each in-vehicle ECU 111 via the relay unit 11, and creates the update list L1 and the inhibition list L2 including the acquired ECU ID. The update management unit 12 stores the created update list L1 and the inhibition list L2 in the storage unit 15.
[0046] 5 is a diagram illustrating an example of a topology correspondence table created by a configuration management unit in a relay device according to an embodiment of the present disclosure. Referring to FIG. 5, the configuration management unit 13 creates a topology correspondence table T1 indicating a correspondence relationship between a relay device ID, which is an ID of a relay device in the in-vehicle network 31, a port ID, which is an ID of a communication port PA, and a connection node ID, which is an ID of a device connected to the communication port PA. The topology correspondence table T1 is an example of connection configuration information indicating a hardware configuration in the in-vehicle network 31. The relay device ID of the relay device 101 is assumed to be "esw001." Furthermore, the port IDs of the communication ports PA1, PA2, PA3, and PA4 are assumed to be "A1," "A2," "A3," and "A4," respectively.
[0047] For example, the configuration management unit 13 acquires the ECU ID of each on-board ECU 111 by communicating with each on-board ECU 111 via the relay unit 11, and creates a topology correspondence table T1 based on the acquired ECU ID. The configuration management unit 13 outputs the created topology correspondence table T1 to the update management unit 12 and the relay management unit 14. The configuration management unit 13 also stores the created topology correspondence table T1 in the storage unit 15.
[0048] 6 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. Referring to FIG. 6, creation unit 12B in update management unit 12 creates vehicle configuration table T2 indicating the correspondence between the app ID of application 112, the ECU ID of in-vehicle ECU 111 on which application 112 is installed, and the version of application 112. Vehicle configuration table T2 is an example of vehicle configuration information. It is assumed that the app IDs of applications 112A, 112B, and 112C are "app001," "app002," and "app003," respectively.
[0049] For example, the creation unit 12B communicates with the in-vehicle ECU 111 indicated in the update list L1 via the relay unit 11 to acquire app information indicating the app ID and version of the application 112 from the in-vehicle ECU 111, and creates the vehicle configuration table T2 based on the acquired app information. The transmission unit 12C in the update management unit 12 outputs the vehicle configuration table T2 created by the creation unit 12B to the relay management unit 14.
[0050] The relay management unit 14 sets the relay processing of messages in the in-vehicle network 31. For example, the relay management unit 14 selects the settings for the relay processing in the relay unit 11 based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12. For example, the relay management unit 14 selects the correspondence relationship between the type of message, the receiving port ID, and the transmitting port ID as the selection of the relay processing setting.
[0051] More specifically, the storage unit 15 stores a setting table T3 that indicates the correspondence between message types, receiving port IDs, and transmitting port IDs. For example, the storage unit 15 stores multiple setting tables T3, each with different settings for relay processing.
[0052] Based on the topology correspondence table T1 and the vehicle configuration table T2, the relay management unit 14 selects, from the multiple setting tables T3 in the storage unit 15, a setting table T3 that indicates setting contents to be used for relay processing by the relay unit 11 in the in-vehicle network 31. The relay management unit 14 outputs the selected setting table T3 to the relay unit 11.
[0053] The relay unit 11 receives the setting table T3 from the relay management unit 14 and performs relay processing in accordance with the received setting table T3.
[0054] When the hardware configuration of the in-vehicle network 31 is changed or when the application 112 is updated, the relay management unit 14 changes the settings of the relay processing of the relay unit 11. A specific example of changing the settings of the relay processing of the relay unit 11 will be described below.
[0055] (Example 1 of Relay Processing Setting Change) (1) Setting Change According to Change in Hardware Configuration Fig. 7 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Compared to the in-vehicle network 31A illustrated in Fig. 1 , Fig. 7 illustrates an in-vehicle network 31B in which an in-vehicle ECU 111D is connected to a communication port PA4 in the relay device 101 via an Ethernet cable 32. Referring to Fig. 7 , when the in-vehicle ECU 111D is connected to the relay device 101, the hardware configuration of the in-vehicle network 31 changes, and the in-vehicle network 31A illustrated in Fig. 1 changes to the in-vehicle network 31B, which is the in-vehicle network 31.
[0056] Compared to the in-vehicle ECUs 111A, 111B, and 111C, the in-vehicle ECU 111D is equipped with a PnP (Plug and Play) terminal unit 113 instead of the application 112. When the in-vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information including the ECU ID of the in-vehicle ECU 111D and information indicating that the in-vehicle ECU 111D does not have the application 112 to the relay device 101. The ECU ID of the in-vehicle ECU 111D is assumed to be "ecu004."
[0057] 2 again, relay unit 11 receives connection information from PnP terminal unit 113 via communication port PA4, and outputs the received connection information to configuration management unit 13. In addition, relay unit 11 outputs port information indicating the port ID of communication port PA4 through which the connection information has passed to configuration management unit 13.
[0058] When the hardware configuration in the in-vehicle network 31 changes, the configuration management unit 13 outputs a topology correspondence table T1 indicating the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information and port information from the relay unit 11, and updates the topology correspondence table T1 in the storage unit 15 based on the received connection information and port information.
[0059] 8 is a diagram illustrating an example of a topology correspondence table after being updated by the configuration management unit in the relay device according to the embodiment of the present disclosure. Referring to FIG. 8, the configuration management unit 13 updates the topology correspondence table T1 shown in FIG. 5 in the storage unit 15 to a topology correspondence table T1 to which a correspondence indicating a connection relationship of the in-vehicle ECU 111D has been added.
[0060] The configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12. The configuration management unit 13 also outputs the updated topology correspondence table T1 to the relay management unit .
[0061] 2 , the update management unit 12 receives the connection information and the topology correspondence table T1 from the configuration management unit 13 and recognizes, based on the received connection information and the topology correspondence table T1, that the application 112 is not installed in the in-vehicle ECU 111D that has been added to the in-vehicle network 31. In this case, the update management unit 12 does not update the update list L1 and the inhibition list L2 in the storage unit 15.
[0062] When the hardware configuration of the in-vehicle network 31 is changed, the update management unit 12 outputs the vehicle configuration table T2 in the in-vehicle network 31B after the hardware configuration change to the relay management unit 14.
[0063] For example, the update management unit 12 executes the OTA master process described on page 58 of Non-Patent Document 1 and creates a vehicle configuration table T2 in the in-vehicle network 31B based on the update list L1. More specifically, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated in the update list L1 in the storage unit 15, and creates a vehicle configuration table T2 in the in-vehicle network 31B based on the acquired application information. Note that, because the in-vehicle ECU 111D is not equipped with an application 112, the vehicle configuration table T2 in the in-vehicle network 31B is the same as the vehicle configuration table T2 in the in-vehicle network 31A before the in-vehicle ECU 111D was connected to the relay device 101. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0064] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31B.
[0065] For example, the relay management unit 14 selects a setting table T3 that includes records of the receiving port IDs and transmitting port IDs of messages sent from the in-vehicle ECU 111D and records of the receiving port IDs and transmitting port IDs of messages addressed to the in-vehicle ECU 111D, as the setting table T3 that indicates the settings of the relay processing of the relay unit 11 in the in-vehicle network 31B. The relay management unit 14 outputs a setting change request that includes the selected setting table T3 to the relay unit 11.
[0066] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0067] (2) Changing Settings in Accordance with Application Updates After that, the update management unit 12 receives update data for updating, for example, the version of the application 112A from “1.0” to “2.0” from the OTA server via the external communication device 151 and the relay unit 11. The update management unit 12 uses the received update data to perform an update process for updating the application 112A.
[0068] For example, as an update process, the update management unit 12 executes an installation process, which is an OTA master process described on pages 61 and 62 of Non-Patent Document 1, and an activation process, which is an OTA master process described on page 63 of Non-Patent Document 1.
[0069] As an installation process, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECU 111A via the relay unit 11.
[0070] The in-vehicle ECU 111A receives the installation request from the relay device 101 and installs the update program based on the update data included in the received installation request. When the in-vehicle ECU 111A completes the installation of the update program, it transmits an installation completion notice to the relay device 101.
[0071] The update management unit 12 in the relay device 101 performs processing to inhibit shutdown of the in-vehicle ECU 111A on which the application 112A is installed, based on the inhibition list L2. More specifically, the update management unit 12 receives an installation completion notification from the in-vehicle ECU 111A via the relay unit 11, and refers to the inhibition list L2 in the storage unit 15 to obtain a device ID corresponding to the application 112A. The update management unit 12 transmits a shutdown inhibition request via the relay unit 11 to the in-vehicle ECU 111A identified by the obtained device ID.
[0072] The on-board ECU 111A receives the shutdown prevention request from the relay device 101 and transmits a shutdown prevention response to the relay device 101 in response to the received shutdown prevention request. In accordance with the shutdown prevention request, the on-board ECU 111A continues to operate even after the ignition power of the vehicle 1 is turned off. On the other hand, the on-board ECUs 111B, 111C, and 111D stop operating when the ignition power of the vehicle 1 is turned off.
[0073] The update management unit 12 receives the shutdown prevention response from the in-vehicle ECU 111A via the relay unit 11 and waits for the ignition power of the vehicle 1 to be turned off. Then, when the ignition power of the vehicle 1 is turned off, the update management unit 12 executes the activation process. More specifically, as the activation process, the update management unit 12 transmits an activation request to the in-vehicle ECU 111A via the relay unit 11. The activation request is an example of a message related to the update process.
[0074] The in-vehicle ECU 111A receives the activation request from the relay device 101 and updates the application 112A by activating the installed update program in accordance with the received activation request. When the in-vehicle ECU 111A completes the activation of the update program, it transmits an activation completion notification to the relay device 101. The activation completion notification is an example of a message related to the update process.
[0075] When the application 112A is updated, the update management unit 12 in the relay device 101 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31B including the updated application 112A.
[0076] 9 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. Referring to FIG. 9 , when update management unit 12 receives an activation completion notification from on-board ECU 111A via relay unit 11, update management unit 12 acquires application information from on-board ECU 111 indicated in update list L1 in storage unit 15, and creates a vehicle configuration table T2 indicating that application 112A has been updated to version 2.0 based on the acquired application information. Update management unit 12 outputs the created vehicle configuration table T2 to relay management unit 14.
[0077] 2 again, the relay management unit 14 selects, from among the multiple setting tables T3 in the storage unit 15, a setting table T3 that indicates setting contents to be used for relay processing by the relay unit 11 in the in-vehicle network 31B, based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0078] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0079] When the relay management unit 14 completes the change of the settings of the relay process in the relay unit 11 , it outputs a change completion notice to the update management unit 12 .
[0080] The update management unit 12 performs a process of stopping the in-vehicle ECU 111A upon receiving the change completion notification from the relay management unit 14. The update management unit 12 also performs a process of notifying the user that the update of the application 112A has been completed.
[0081] Thereafter, when the ignition power of the vehicle 1 is turned on, the updated application 112A in the in-vehicle ECU 111A starts to operate.
[0082] (Example 2 of Relay Processing Setting Change) (1) Setting Change According to Change in Hardware Configuration Fig. 10 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Fig. 10 illustrates an in-vehicle network 31C in which, compared to the in-vehicle network 31B illustrated in Fig. 7, an application 112D, which is the application 112, is further installed in the in-vehicle ECU 111D. Referring to Fig. 10, when the in-vehicle ECU 111D is connected to the relay device 101, the hardware configuration of the in-vehicle network 31 changes, and the in-vehicle network 31A illustrated in Fig. 1 changes to the in-vehicle network 31C.
[0083] When the in-vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information to the relay device 101, the connection information including the ECU ID of the in-vehicle ECU 111D and the app ID of the application 112D installed in the in-vehicle ECU 111D.
[0084] 2 again, relay unit 11 receives connection information from PnP terminal unit 113 via communication port PA4, and outputs the received connection information to configuration management unit 13. In addition, relay unit 11 outputs port information indicating the port ID of communication port PA4 through which the connection information has passed to configuration management unit 13.
[0085] When the hardware configuration of the in-vehicle network 31 changes, the configuration management unit 13 outputs a topology correspondence table T1 indicating the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information and port information from the relay unit 11, and updates the topology correspondence table T1 shown in FIG. 5 in the storage unit 15 to the topology correspondence table T1 shown in FIG. 8 based on the received connection information and port information. The configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12. The configuration management unit 13 also outputs the updated topology correspondence table T1 to the relay management unit 14.
[0086] When an in-vehicle ECU 111 equipped with an application 112 is added to the in-vehicle network 31, the update management unit 12 updates the update list L1 and the inhibition list L2 in the storage unit 15. More specifically, the update management unit 12 receives connection information and the topology correspondence table T1 from the configuration management unit 13, and recognizes, based on the received connection information and topology correspondence table T1, that an application 112D is installed in the in-vehicle ECU 111D that has been added to the in-vehicle network 31. In this case, the update management unit 12 updates the update list L1 and the inhibition list L2 in the storage unit 15.
[0087] 11 is a diagram illustrating an example of an update list after an update by the update management unit 12 in the relay device according to the embodiment of the present disclosure. Referring to FIG. 11, the update management unit 12 adds the ECU ID of the in-vehicle ECU 111E to the update list L1 in the storage unit 15.
[0088] 12 is a diagram illustrating an example of the suppression list after being updated by the update management unit 12 in the relay device according to the embodiment of the present disclosure. Referring to FIG. 12, the update management unit 12 adds, to the suppression list L2 in the storage unit 15, a correspondence relationship between the application ID “app004” of the application 112D and the ECU ID of the in-vehicle ECU 111E.
[0089] When the hardware configuration of the in-vehicle network 31 changes, the update management unit 12 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31C after the hardware configuration change.
[0090] For example, the update management unit 12 executes the OTA master process described on page 58 of Non-Patent Document 1, and creates a vehicle configuration table T2 in the in-vehicle network 31C based on the update list L1.
[0091] 13 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. Referring to FIG. 13 , update management unit 12 acquires application information from on-board ECU 111 indicated in update list L1 in storage unit 15, and creates vehicle configuration table T2 based on the acquired application information, including a correspondence relationship between the application ID of application 112D, the ECU ID of on-board ECU 111D, and the version of application 112D. Update management unit 12 outputs the created vehicle configuration table T2 to relay management unit 14.
[0092] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31C.
[0093] For example, the relay management unit 14 selects a setting table T3 that includes records of the receiving port IDs and transmitting port IDs of messages sent from the in-vehicle ECU 111D and records of the receiving port IDs and transmitting port IDs of messages addressed to the in-vehicle ECU 111D, as the setting table T3 that indicates the settings of the relay processing of the relay unit 11 in the in-vehicle network 31C. The relay management unit 14 outputs a setting change request that includes the selected setting table T3 to the relay unit 11.
[0094] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0095] 2 , thereafter, update management unit 12 receives update data for updating, for example, the versions of applications 112A and 112D from “1.0” to “2.0” from the OTA server via external communication device 151 and relay unit 11. Update management unit 12 performs an update process for updating applications 112A and 112D using the received update data.
[0096] As an installation process, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECUs 111A and 111D via the relay unit 11.
[0097] The in-vehicle ECUs 111A and 111D receive the installation request from the relay device 101 and install the update program based on the update data included in the received installation request. When the in-vehicle ECUs 111A and 111D complete the installation of the update program, they transmit an installation completion notice to the relay device 101.
[0098] The update management unit 12 in the relay device 101 performs processing to inhibit shutdown of the in-vehicle ECUs 111A and 111D on which the applications 112A and 112D are installed, based on the inhibition list L2. More specifically, the update management unit 12 receives an installation completion notification from the in-vehicle ECUs 111A and 111D via the relay unit 11, and refers to the inhibition list L2 in the storage unit 15 to obtain the device ID corresponding to the application 112A and the device ID corresponding to the application 112D. The update management unit 12 transmits a shutdown inhibition request via the relay unit 11 to the in-vehicle ECUs 111A and 111D indicated by the obtained device IDs.
[0099] The on-board ECUs 111A and 111D receive a shutdown prevention request from the relay device 101 and transmit a shutdown prevention response to the relay device 101 in response to the received shutdown prevention request. In accordance with the shutdown prevention request, the on-board ECUs 111A and 111D continue to operate even after the ignition power of the vehicle 1 is turned off. On the other hand, the on-board ECUs 111B and 111C stop operating when the ignition power of the vehicle 1 is turned off.
[0100] The update management unit 12 receives the shutdown prevention response from the on-board ECUs 111A and 111D via the relay unit 11 and waits for the ignition power of the vehicle 1 to be turned off. Then, the update management unit 12 executes an activation process when the ignition power of the vehicle 1 is turned off. More specifically, as the activation process, the update management unit 12 transmits an activation request to the on-board ECUs 111A and 111D via the relay unit 11.
[0101] The in-vehicle ECUs 111A and 111D each receive an activation request from the relay device 101 and update the installed update program in accordance with the received activation request, thereby updating the application 112A or 112D. When the in-vehicle ECUs 111A and 111D each complete the activation of the update program, they each transmit an activation completion notification to the relay device 101.
[0102] When the applications 112A and 112D are updated, the update management unit 12 in the relay device 101 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31C including the updated application 112A.
[0103] 14 is a diagram illustrating an example of a vehicle configuration table created by an update management unit in a relay device according to an embodiment of the present disclosure. Referring to FIG. 14 , when update management unit 12 receives an activation completion notification from on-board ECU 111A, 111D via relay unit 11, update management unit 12 acquires application information from on-board ECU 111 indicated in update list L1 in storage unit 15. Based on the acquired application information, update management unit 12 creates a vehicle configuration table T2 indicating that the versions of applications 112A, 112D have been updated to 2.0. Update management unit 12 outputs the created vehicle configuration table T2 to relay management unit 14.
[0104] 2 again, the relay management unit 14 selects, from among the multiple setting tables T3 in the storage unit 15, a setting table T3 that indicates setting contents to be used for relay processing by the relay unit 11 in the in-vehicle network 31C, based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0105] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0106] When the relay management unit 14 completes the change of the settings of the relay process in the relay unit 11 , it outputs a change completion notice to the update management unit 12 .
[0107] The update management unit 12 performs a process of stopping the in-vehicle ECUs 111A and 111D upon receiving the change completion notification from the relay management unit 14. The update management unit 12 also performs a process of notifying the user that the updates of the applications 112A and 112D have been completed.
[0108] Thereafter, when the ignition power of the vehicle 1 is turned on, the updated applications 112A and 112D in the in-vehicle ECUs 111A and 111D start operating.
[0109] (Example 3 of changing settings of relay processing) (1) Changing settings in response to changes in hardware configuration Fig. 15 is a diagram illustrating an example of an in-vehicle network according to an embodiment of the present disclosure. Compared to the in-vehicle network 31C illustrated in Fig. 10, Fig. 15 illustrates an in-vehicle network 31D in which a relay device 102 is connected to a relay device 101 and an in-vehicle ECU 111D is connected to the relay device 102. Like the relay device 101, the relay device 102 can relay messages transmitted and received in the in-vehicle network 31.
[0110] 10 , the relay device 102 includes a PnP terminal unit 114 and communication ports PC1 and PC2, which are communication ports PC. A communication port PA4 in the relay device 101 is connected to the communication port PC1 in the relay device 102 via an Ethernet cable 32. An in-vehicle ECU 111D is connected to the communication port PC2 in the relay device 102 via the Ethernet cable 32. When the relay device 102 to which the in-vehicle ECU 111D is connected is connected to the relay device 101, the hardware configuration of the in-vehicle network 31 changes, and the in-vehicle network 31A shown in FIG. 1 changes to an in-vehicle network 31D.
[0111] When the relay device 102 is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information including the ECU ID of the in-vehicle ECU 111D and the app ID of the application 112D installed in the in-vehicle ECU 111D to the relay device 101 via the relay device 102.
[0112] When the relay device 102 is connected to the relay device 101 via the Ethernet cable 32 , the PnP terminal unit 114 in the relay device 102 transmits relay connection information including the relay device ID of the relay device 102 to the relay device 101 .
[0113] 2 again, relay unit 11 receives connection information and relay connection information from PnP terminal units 113 and 114 via communication port PA4, and outputs the received connection information and relay connection information to configuration management unit 13. Furthermore, relay unit 11 outputs port information indicating the port ID of communication port PA4 through which the connection information and the relay connection information have passed to configuration management unit 13.
[0114] When the hardware configuration in the in-vehicle network 31 changes, the configuration management unit 13 outputs a topology correspondence table T1 indicating the changed hardware configuration to the update management unit 12 and the relay management unit 14. More specifically, the configuration management unit 13 receives connection information, relay connection information, and port information from the relay unit 11, and updates the topology correspondence table T1 in the storage unit 15 based on the received connection information, relay connection information, and port information.
[0115] 16 is a diagram illustrating an example of a topology correspondence table after being updated by the configuration management unit in the relay device according to the embodiment of the present disclosure. The relay device ID of the relay device 102 is assumed to be "esw002." The port IDs of the communication ports PC1 and PC2 are assumed to be "C1" and "C2," respectively.
[0116] 16, the configuration management unit 13 updates the topology correspondence table T1 shown in FIG. 5 in the storage unit 15 to a topology correspondence table T1 to which a correspondence indicating the connection relationship between the relay device 102 and the in-vehicle ECU 111D has been added.
[0117] The configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12. The configuration management unit 13 also outputs the updated topology correspondence table T1 to the relay management unit .
[0118] The update management unit 12 receives the connection information and the topology correspondence table T1 from the configuration management unit 13 and recognizes, based on the received connection information and the topology correspondence table T1, that the application 112D is installed in the in-vehicle ECU 111D that has been added to the in-vehicle network 31. In this case, the update management unit 12 updates the update list L1 and the inhibition list L2 in the storage unit 15.
[0119] More specifically, the update management unit 12 adds the ECU ID of the in-vehicle ECU 111E to the update list L1 in the storage unit 15, as shown in FIG.
[0120] 17 is a diagram illustrating an example of the inhibit list after being updated by the update management unit in the relay device according to the embodiment of the present disclosure. Referring to FIG. 17 , the update management unit 12 adds, to the inhibit list L2 in the storage unit 15, a correspondence relationship between the application ID “app004” of the application 112D, the relay device ID of the relay device 102, and the ECU ID of the in-vehicle ECU 111E.
[0121] Referring back to FIG. 2, when the hardware configuration of the in-vehicle network 31 is changed, the update management unit 12 outputs to the relay management unit 14 a vehicle configuration table T2 in the in-vehicle network 31D after the hardware configuration change.
[0122] For example, the update management unit 12 executes the OTA master process described on page 58 of Non-Patent Document 1 and creates a vehicle configuration table T2 in the in-vehicle network 31D based on the update list L1. More specifically, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated in the update list L1 in the storage unit 15, and creates the vehicle configuration table T2 shown in FIG. 13 based on the acquired application information. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0123] Based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31D.
[0124] For example, the relay management unit 14 selects a setting table T3 that includes records of the receiving port IDs and transmitting port IDs of messages sent from the in-vehicle ECU 111D and records of the receiving port IDs and transmitting port IDs of messages addressed to the in-vehicle ECU 111D, as the setting table T3 that indicates the settings of the relay processing of the relay unit 11 in the in-vehicle network 31C. The relay management unit 14 outputs a setting change request that includes the selected setting table T3 to the relay unit 11.
[0125] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0126] (2) Changing Settings in Accordance with Application Updates After that, the update management unit 12 receives update data for updating, for example, the versions of the applications 112A and 112D from “1.0” to “2.0” from the OTA server via the external communication device 151 and the relay unit 11. The update management unit 12 uses the received update data to perform update processing to update the applications 112A and 112D.
[0127] As part of the installation process, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECU 111A via the relay unit 11, and transmits the request to the in-vehicle ECU 111D via the relay unit 11 and the relay device 102.
[0128] The in-vehicle ECUs 111A and 111D receive the installation request from the relay device 101 and install the update program based on the update data included in the received installation request. When the in-vehicle ECUs 111A and 111D complete the installation of the update program, they transmit an installation completion notice to the relay device 101.
[0129] Based on the inhibition list L2, the update management unit 12 in the relay device 101 performs processing to inhibit shutdown of the in-vehicle ECUs 111A and 111D on which the applications 112A and 112D are installed, and the relay device 102 that needs to relay a message related to the update process of the application 112D. More specifically, the update management unit 12 receives an installation completion notification from the in-vehicle ECUs 111A and 111D via the relay unit 11, and refers to the inhibition list L2 in the storage unit 15 to obtain the device ID corresponding to the application 112A and the device ID corresponding to the application 112D. The update management unit 12 transmits a shutdown inhibition request via the relay unit 11 to the relay device 102 and the in-vehicle ECUs 111A and 111D indicated by the obtained device IDs.
[0130] The relay device 102 and the on-board ECUs 111A and 111D receive the shutdown prevention request from the relay device 101 and transmit a shutdown prevention response to the relay device 101 in response to the received shutdown prevention request. In accordance with the shutdown prevention request, the relay device 102 and the on-board ECUs 111A and 111D continue to operate even after the ignition power of the vehicle 1 is turned off. On the other hand, the on-board ECUs 111B and 111C stop operating when the ignition power of the vehicle 1 is turned off.
[0131] The update management unit 12 receives a shutdown prevention response from the relay device 102 and the in-vehicle ECUs 111A and 111D via the relay unit 11, and waits for the ignition power of the vehicle 1 to be turned off. Then, the update management unit 12 executes an activation process when the ignition power of the vehicle 1 is turned off. More specifically, as the activation process, the update management unit 12 transmits an activation request to the in-vehicle ECU 111A via the relay unit 11, and transmits an activation request to the in-vehicle ECU 111D via the relay unit 11 and the relay device 102.
[0132] The in-vehicle ECUs 111A and 111D each receive an activation request from the relay device 101 and update the installed update programs by activating the applications 112A and 112D. When the in-vehicle ECUs 111A and 111D each complete the activation of the update programs, they each transmit an activation completion notification to the relay device 101.
[0133] When the update management unit 12 in the relay device 101 updates the applications 112A and 112D, it outputs a vehicle configuration table T2 in the in-vehicle network 31C including the updated application 112D to the relay management unit 14. More specifically, when the update management unit 12 receives an activation completion notification from the in-vehicle ECUs 111A and 111D via the relay unit 11, it acquires app information from the in-vehicle ECU 111 indicated in the update list L1 in the storage unit 15. The update management unit 12 creates the vehicle configuration table T2 shown in FIG. 14 based on the acquired app information. The update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14.
[0134] The relay management unit 14 selects a setting table T3 indicating the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31C from among the multiple setting tables T3 in the storage unit 15, based on the topology correspondence table T1 and the vehicle configuration table T2 received from the update management unit 12. The relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11.
[0135] The relay unit 11 receives a setting change request from the relay management unit 14 and changes the settings of the relay process in accordance with the setting table T3 included in the received setting change request.
[0136] When the relay management unit 14 completes the change of the settings of the relay process in the relay unit 11 , it outputs a change completion notice to the update management unit 12 .
[0137] The update management unit 12 receives the change completion notification from the relay management unit 14 and performs a process of stopping the relay device 102 and the in-vehicle ECUs 111A and 111D. The update management unit 12 also performs a process of notifying the user that the updates of the applications 112A and 112D have been completed.
[0138] Thereafter, when the ignition power of the vehicle 1 is turned on, the updated applications 112A and 112D in the in-vehicle ECUs 111A and 111D start operating.
[0139] [Operation Flow] Fig. 18 is a diagram showing an example of a sequence for changing the settings of the relay process in the in-vehicle network management system according to the embodiment of the present disclosure. Fig. 18 shows the sequence for "changing the settings in response to a change in the hardware configuration" described above.
[0140] 18, first, when the in-vehicle ECU 111D is connected to the relay device 101 via the Ethernet cable 32, the PnP terminal unit 113 in the in-vehicle ECU 111D transmits connection information to the relay device 101 (step S11).
[0141] Next, the relay unit 11 in the relay device 101 outputs the connection information and port information received from the PnP terminal unit 113 to the configuration management unit 13 (step S12).
[0142] Next, the configuration management unit 13 updates the topology correspondence table T1 based on the connection information and port information received from the relay unit 11 (step S13).
[0143] Next, the configuration management unit 13 outputs the updated topology correspondence table T1 and the connection information to the update management unit 12 (step S14).
[0144] Furthermore, the configuration management unit 13 outputs the updated topology correspondence table T1 to the relay management unit 14 (step S15).
[0145] Next, based on the connection information and topology correspondence table T1 received from the configuration management unit 13, the update management unit 12 recognizes that application 112D is installed in, for example, the in-vehicle ECU 111D added to the in-vehicle network 31, and updates the update list L1 and the inhibition list L2 (step S16).
[0146] Next, the update management unit 12 acquires application information from the in-vehicle ECU 111 indicated by the update list L1, and creates a vehicle configuration table T2 based on the acquired application information (step S17).
[0147] Next, the update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14 (step S18).
[0148] Next, based on the topology correspondence table T1 received from the configuration management unit 13 and the vehicle configuration table T2 received from the update management unit 12, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31 (step S19).
[0149] Next, the relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11 (step S20).
[0150] Next, the relay unit 11 changes the settings of the relay process in accordance with the setting table T3 included in the setting change request received from the relay management unit 14 (step S21).
[0151] 19 is a diagram illustrating an example of a sequence for changing settings of a relay process in an in-vehicle network management system according to an embodiment of the present disclosure. FIG. 19 illustrates the sequence for the above-described "settings change in response to an application update."
[0152] Referring to FIG. 19, first, update management unit 12 receives update data for application 112 from the OTA server via external communication device 151 and relay unit 11 (step S31).
[0153] Next, the update management unit 12 transmits an installation request including the update data to the in-vehicle ECU 111 via (step S32).
[0154] Next, the in-vehicle ECU 111 installs the update program based on the update data included in the received installation request (step S33).
[0155] Next, the in-vehicle ECU 111 transmits an installation completion notification to the relay device 101 (step S34).
[0156] Next, the update management unit 12 in the relay device 101 transmits a shutdown prevention request to the in-vehicle ECU 111 (step S35).
[0157] Next, the in-vehicle ECU 111 transmits a shutdown prevention response to the relay device 101 in response to the received shutdown prevention request (step S36).
[0158] Next, the update management unit 12 waits for the ignition power of the vehicle 1 to be turned off, and when the ignition power of the vehicle 1 is turned off, transmits an activation request to the in-vehicle ECU 111 (step S37).
[0159] Next, in accordance with the received activation request, the in-vehicle ECU 111 activates the installed update program to update the application 112 (step S38).
[0160] Next, the in-vehicle ECU 111 transmits an activation completion notification to the relay device 101 (step S39).
[0161] Next, the update management unit 12 in the relay device 101 acquires application information from the in-vehicle ECU 111 indicated by the update list L1, and creates a vehicle configuration table T2 based on the acquired application information (step S40).
[0162] Next, the update management unit 12 outputs the created vehicle configuration table T2 to the relay management unit 14 (step S41).
[0163] Next, based on the topology correspondence table T1 and the vehicle configuration table T2, the relay management unit 14 selects a setting table T3 from the multiple setting tables T3 in the memory unit 15 that indicates the setting contents to be used for the relay processing of the relay unit 11 in the in-vehicle network 31C (step S42).
[0164] Next, the relay management unit 14 outputs a setting change request including the selected setting table T3 to the relay unit 11 (step S43).
[0165] Next, the relay unit 11 changes the settings of the relay process in accordance with the setting table T3 included in the setting change request received from the relay management unit 14 (step S44).
[0166] Next, the relay management unit 14 outputs a change completion notification to the update management unit 12 (step S45).
[0167] Next, the update management unit 12 performs a process of stopping the in-vehicle ECU 111 (step S46).
[0168] Next, when the ignition power of the vehicle 1 is turned on, the updated application 112 in the in-vehicle ECU 111 starts operating (step S47).
[0169] In the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12, the configuration management unit 13, and the relay management unit 14 are configured to be provided in the relay device 101, but this is not limiting. At least one of the update management unit 12, the configuration management unit 13, and the relay management unit 14 may be provided in a device other than the relay device 101. For example, in the in-vehicle network 31D shown in FIG. 15 , when the update management unit 12 is provided in a device other than the relay device 101, the update management unit 12 further performs processing to inhibit shutdown of the relay device 101 based on the inhibition list L2.
[0170] Furthermore, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to update the update list L1 and the inhibition list L2 when the in-vehicle ECU 111 on which the application 112 is installed is added to the in-vehicle network 31. However, this is not limited to this. The update management unit 12 may be configured not to update the update list L1 and the inhibition list L2 even when the in-vehicle ECU 111 on which the application 112 is installed is added to the in-vehicle network 31. In this case, the update management unit 12 updates the application 112 installed in the in-vehicle ECU 111 in the initial in-vehicle network 31, but does not update the application 112 installed in the in-vehicle ECU 111 added to the in-vehicle network 31. The update of the application 112 installed in the in-vehicle ECU 111 added to the in-vehicle network 31 may be performed by a unit other than the update management unit 12 in the in-vehicle network management system 301, or by a user of the vehicle 1 or a maintenance company for the vehicle 1.
[0171] Furthermore, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to acquire application information from the in-vehicle ECU 111 indicated by the update list L1 and create the vehicle configuration table T2 based on the acquired application information, but this is not limited to this. The update management unit 12 may also be configured to accept application information from a user of the in-vehicle network management system 301 and create the vehicle configuration table T2 based on the accepted application information.
[0172] Furthermore, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to perform a process of suppressing shutdown of the relay device 102 with which communication is required for updating the application 112. However, this is not limited to this. The update management unit 12 may be configured not to perform a process of suppressing shutdown of the relay device 102. More specifically, the update management unit 12 updates the application 112 installed in the in-vehicle ECU 111 connected to the relay device 101, but does not update the application 112 installed in the in-vehicle ECU 111 connected to the relay device 101 via the relay device 102. The update of the application 112 installed in the in-vehicle ECU 111 connected to the relay device 101 via the relay device 102 may be performed by a unit other than the update management unit 12 in the in-vehicle network management system 301, or by a user of the vehicle 1 or a maintenance company for the vehicle 1. In this case, the update management unit 12 does not perform a process of suppressing shutdown of the relay device 102.
[0173] In addition, in the in-vehicle network management system 301 according to the embodiment of the present disclosure, the update management unit 12 is configured to receive update data from the OTA server via the external communication device 151 and the relay unit 11, but this is not limiting. The update management unit 12 may also be configured to receive update data from the OTA server via wired communication.
[0174] The above-described embodiments should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims.
[0175] Each process (each function) in the above-described embodiments is realized by a processing circuit (circuitry) including one or more processors. The processing circuit may be configured as an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the processes. The one or more processors may execute each of the processes according to the program read from the one or more memories, or may execute each of the processes according to a logic circuit designed in advance to execute each of the processes. The processor may be any of various processors suitable for computer control, such as a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and an ASIC (Application Specific Integrated Circuit). Note that the physically separated processors may cooperate with each other to execute the processes. For example, the processors installed in the physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the processes. The program may be installed into the memory from an external server device or the like via the network, or may be distributed in a state stored on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disc Read Only Memory), or a semiconductor memory, and then installed into the memory from the recording medium.
[0176] The above description includes the following additional features: [Supplementary Note 1] An update management device comprising: an update unit that updates target software that is software that is the target of an update process in an in-vehicle network; a creation unit that creates vehicle configuration information indicating a correspondence between the target software, an in-vehicle device on which the target software is installed, and a version of the target software when the update unit updates the target software or when a hardware configuration in the in-vehicle network changes; and a transmission unit that transmits the vehicle configuration information created by the creation unit to a relay management unit that sets up message relay processing in the in-vehicle network.
[0177] [Supplementary Note 2] An update management device comprising a processing circuit, wherein when target software that is the software that is the subject of update processing in an in-vehicle network is updated or when the hardware configuration in the in-vehicle network changes, the processing circuit creates vehicle configuration information indicating the correspondence between the target software, the in-vehicle device in which the target software is installed, and the version of the target software, and transmits the created vehicle configuration information to a relay management unit that sets up message relay processing in the in-vehicle network.
[0178] REFERENCE SIGNS LIST 1 Vehicle 11 Relay unit 12 Update management unit 12A Update unit 12B Creation unit 12C Transmission unit 13 Configuration management unit 14 Relay management unit 15 Storage unit 31, 31A, 31B, 31C, 31D In-vehicle network 32 Ethernet cable 101, 102 Relay device 111, 111A, 111B, 111C, 111D In-vehicle ECU 112, 112A, 112B, 112C, 112D Application 113, 114 PnP terminal unit 151 External communication device 301 In-vehicle network management system PA, PA1, PA2, PA3, PA4, PB Communication port L1 Update list L2 Inhibition list T1 Topology correspondence table T2 Vehicle configuration table
Claims
1. An in-vehicle network management system comprising: an update management unit that updates target software, which is software that is the target of update processing in an in-vehicle network; a configuration management unit that monitors the hardware configuration in the in-vehicle network; and a relay management unit that sets up message relay processing in the in-vehicle network, wherein when the hardware configuration changes, the configuration management unit transmits connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit, when the hardware configuration changes, the update management unit transmits to the relay management unit the vehicle configuration information in the in-vehicle network after the change in hardware configuration, which indicates the correspondence between the target software, the in-vehicle device in which the target software is installed, and the version of the target software, and when the target software is updated, the update management unit transmits to the relay management unit the vehicle configuration information in the in-vehicle network including the updated target software.
2. The in-vehicle network management system of claim 1, wherein the update management unit creates the vehicle configuration information based on an update list indicating the in-vehicle devices on which the target software is installed, and the update management unit updates the update list when the in-vehicle device on which the target software is installed is added to the in-vehicle network.
3. The in-vehicle network management system of claim 2, wherein the update management unit obtains application information indicating the version of the target software installed in the in-vehicle device from the in-vehicle device indicated in the update list, and creates the vehicle configuration information based on the obtained application information.
4. An in-vehicle network management system as described in any one of claims 1 to 3, wherein the update management unit performs a process to suppress shutdown of the in-vehicle device on which the target software to be updated in the update process is installed based on an inhibition list indicating the in-vehicle devices that need to operate in the update process of the target software, and the update management unit updates the inhibition list when the in-vehicle device on which the target software is installed is added to the in-vehicle network.
5. The in-vehicle network management system according to claim 4, wherein the update management unit further performs processing for suppressing shutdown of a relay device that needs to relay a message related to the update processing, based on the suppression list.
6. An in-vehicle network management method in an in-vehicle network management system including an update management unit that updates target software, which is software that is subject to update processing in an in-vehicle network, a configuration management unit that monitors the hardware configuration in the in-vehicle network, and a relay management unit that sets relay processing of messages in the in-vehicle network, the in-vehicle network management method including the steps of: when the hardware configuration has changed, the configuration management unit transmitting connection configuration information indicating the changed hardware configuration to the update management unit and the relay management unit; when the hardware configuration has changed, the update management unit transmitting vehicle configuration information in the in-vehicle network after the change in hardware configuration, the vehicle configuration information indicating the correspondence between the target software, an in-vehicle device in which the target software is installed, and a version of the target software to the relay management unit; and when the update management unit updates the target software, transmitting the vehicle configuration information in the in-vehicle network including the updated target software to the relay management unit.
Citation Information
Patent Citations
In-vehicle relay device, information processing method, and program
JP2021157466A
Software update device, software update system, and software update method
JP2022144814A
Vehicle information communication system and vehicle information communication method
JP2023126403A