Control device, vehicle, control method, program, and non-transitory computer-readable storage medium

The control device addresses the variability in function restrictions during in-vehicle software updates by displaying distinct confirmation images based on the update procedure, improving user awareness and convenience.

WO2025115373A1PCT designated stage expired Publication Date: 2025-06-05TOYOTA JIDOSHA KK
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/034545
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-29
Filing Date
2024-09-26
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing software update processes for in-vehicle devices via OTA technology may restrict vehicle functions during the activation phase, necessitating user confirmation before activation. However, the timing of function restrictions varies based on the update procedure, requiring an appropriate confirmation screen to be displayed accordingly.

Method used

A control device with a processing circuit that controls a display unit to show different confirmation images before the activation process, depending on the update procedure. In the first update procedure, a first confirmation image is displayed when switching from driving to parking mode, while in the second procedure, a second confirmation image is displayed when switching from parking to driving mode.

Benefits of technology

Ensures that users are appropriately informed of the function restrictions and activation timing, enhancing user convenience and clarity regarding the software update process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024034545_05062025_PF_FP_ABST
    Figure JP2024034545_05062025_PF_FP_ABST
Patent Text Reader

Abstract

This control device performs control of a display unit for displaying information related to software update of on-vehicle equipment mounted on a vehicle having a plurality of power supply modes. The software update includes an activation process. When the software update is performed in a first update procedure for executing the activation process in accordance with the switching between the plurality of power supply modes in a first switching pattern, the control device causes the display unit to display a first confirmation image before the start of the activation process. When the software update is performed in a second update procedure for executing the activation process in accordance with the switching between the plurality of power supply modes in a second switching pattern, the control device causes the display unit to display a second confirmation image before the start of the activation process.
Need to check novelty before this filing date? Find Prior Art

Description

Control device, vehicle, control method, program, and non-transitory computer-readable storage medium

[0001] The present disclosure relates to a control device that controls the display of information about software updates for in-vehicle devices, and further to a vehicle, a control method, a program, and a non-transitory computer-readable storage medium related to the display control.

[0002] Vehicles are equipped with various in-vehicle devices that operate through the execution of software. Over-the-air (OTA) technology is known, which updates the software of the in-vehicle devices using software downloaded from outside the vehicle via wireless communication. As described in Patent Literature 1, software updates are performed through an installation process in which the downloaded update software is written to a storage module of the in-vehicle device, and an activation process in which the installed update software is enabled.

[0003] Japanese Patent Application Laid-Open No. 2022-163396

[0004] Since some vehicle functions may be restricted when the activation process is performed, it is desirable to confirm with the user before starting the activation process. Meanwhile, it is conceivable that the activation process will be performed at different times depending on the type of in-vehicle device or the type of software. In such cases, the timing at which the vehicle functions are restricted will change depending on the timing at which the activation process is performed. Therefore, it is desirable to display an appropriate confirmation screen according to the timing at which the activation process is performed.

[0005] According to one aspect of the present disclosure, there is provided a control device including a processing circuit configured to control a display unit configured to display information regarding a software update for an on-board device mounted on a vehicle configured to selectively switch between a plurality of power modes, the software update including an activation process for enabling update software installed in the on-board device, the processing circuit configured to cause the display unit to display a first confirmation image before initiation of the activation process if the software update is performed in a first update procedure in which the activation process is performed in response to switching between the plurality of power modes in a first switching pattern, and the processing circuit configured to cause the display unit to display a second confirmation image before initiation of the activation process if the software update is performed in a second update procedure in which the activation process is performed in response to switching between the plurality of power modes in a second switching pattern, the first switching pattern and the second switching pattern being different from each other, and the first confirmation image and the second confirmation image being different from each other.

[0006] According to one aspect of the present disclosure, there is provided a vehicle equipped with the above-described control device. According to another aspect of the present disclosure, there is provided a control method. The control method includes controlling a display unit that displays progress information of a software update of an on-board device mounted on a vehicle configured to selectively switch between multiple power modes, the software update including an activation process that activates update software installed in the on-board device, and displaying a first confirmation image on the display unit before starting the activation process if the software update is performed using a first update procedure in which the activation process is performed in response to switching between the multiple power modes in a first switching pattern, and displaying a second confirmation image on the display unit before starting the activation process if the software update is performed using a second update procedure in which the activation process is performed in response to switching between the multiple power modes in a second switching pattern, wherein the first switching pattern and the second switching pattern are different from each other, and the first confirmation image and the second confirmation image are different from each other.

[0007] According to one aspect of the present disclosure, there is provided a program that, when executed by a control device, causes the control device to execute a control process for controlling a display unit that displays progress information of a software update of an on-board device mounted on a vehicle configured to selectively switch between a plurality of power modes, the software update including an activation process for enabling update software installed in the on-board device, a first display process for displaying a first confirmation image on the display unit before starting the activation process if the software update is performed in a first update procedure in which the activation process is performed in response to switching between the plurality of power modes in a first switching pattern, and a second display process for displaying a second confirmation image on the display unit before starting the activation process if the software update is performed in a second update procedure in which the activation process is performed in response to switching between the plurality of power modes in a second switching pattern, the first switching pattern and the second switching pattern being different from each other, and the first confirmation image and the second confirmation image being different from each other.

[0008] According to one aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing the above program.

[0009] 1 is a diagram schematically showing the configuration of a control device and a vehicle of a first embodiment. FIG. 2 is a diagram schematically showing the configuration of an on-board device equipped with a single-bank storage module. FIG. 3 is a diagram schematically showing the configuration of an on-board device equipped with a dual-bank storage module. FIG. 4 is a sequence diagram showing the processing flow of the activate phase when a software update is performed using the first update procedure in the first embodiment. FIG. 5 is a diagram showing an example of a display of a first pre-confirmation image. FIG. 6 is a diagram showing an example of a display of a first final confirmation image. FIG. 7 is a diagram showing an example of a display of a first guide image. FIG. 8 is a diagram showing an example of a display of a first completion notification image. FIG. 9 is a sequence diagram showing the processing flow of the activate phase when a software update is performed using the second update procedure in the first embodiment. FIG. 10 is a diagram showing an example of a display of a second pre-confirmation image. FIG. 11 is a diagram showing an example of a display of a second final confirmation image. FIG. 12 is a diagram showing an example of a display of a second guide image. FIG. 13 is a diagram showing an example of a display of a second completion notification image. FIG. 14 is a sequence diagram showing the processing flow of the activate phase when a software update is performed using the first update procedure in the second embodiment.

[0010] First Embodiment Hereinafter, a first embodiment of a control device, a vehicle equipped with the control device, a control method, a program (program product), and a non-transitory computer-readable storage medium will be described in detail with reference to FIGS. 1 to 13. Here, the control method is a method executed by the control device. The program causes the control device to execute the control method. The non-transitory computer-readable storage medium stores the program.

[0011] <Configuration of Control Device and Vehicle> First, the configuration of the control device and vehicle of this embodiment will be described with reference to FIG. 1 . As shown in FIG. 1 , a vehicle 10 is equipped with on-board devices such as an OTA (Over-The-Air) master 11, a DCM (Data Communication Module) 12, an ADAS (Advanced Driving Assistant System) 13, a PCU (Power Control Unit) 14, an engine ECU (Electronic Control Unit) 15, a transmission ECU 16, a brake ECU 17, and an HMI (Human Machine Interface) 18. These on-board devices are connected to each other via an on-board network 19 so as to be able to communicate with each other. The OTA master 11 manages software updates for the on-board devices, including the OTA master 11 itself. The DCM 12 is a data communication module that provides wireless communication with the outside of the vehicle via a mobile communication network 20. In this embodiment, the DCM 12 records the results of self-diagnosis performed by each on-board device of the vehicle 10 and transmits the results to an external data center or the like. The ADAS 13 is an Advanced Driving Assistant System that provides advanced driving assistance functions such as an automatic braking system and a sudden acceleration prevention system. The PCU 14 is a power control unit that controls power within the vehicle. The engine ECU 15 is an electronic control unit for engine control. The transmission ECU 16 is an electronic control unit for transmission control. The brake ECU 17 is an electronic control unit for brake control. The HMI 18 is a human-machine interface. The HMI 18 includes an input device that accepts operations by the occupant and a display device that displays information to the occupant using images and audio. The HMI 18 may also include a navigation function that provides route guidance and an entertainment function that plays music and videos. Each of these on-board devices includes a storage module 21 in which software is stored and a processor 22 that executes the software.The OTA master 11 further includes a data storage 23 for storing update software acquired from outside the vehicle.

[0012] The vehicle 10 has multiple power modes. The multiple power modes include a driving power mode and a parking power mode. For each power mode, it is determined which on-board devices are to be powered on. When the driving power mode is set, the on-board devices necessary for driving the vehicle 10 and providing services while driving are powered on. In this embodiment, when the driving power mode is set, all of the on-board devices shown in FIG. 1 are powered on. When the parking power mode is set, only the on-board devices that need to operate while the vehicle 10 is parked are powered on. The on-board devices that are powered on in each power mode can be changed depending on the environment and user settings.

[0013] The vehicle 10 is provided with a power switch 24 for switching between a driving power mode and a parking power mode. Switching from the driving power mode to the parking power mode is performed by switching the power switch 24 from on to off. Switching from the parking power mode to the driving power mode is performed by switching the power switch 24 from off to on. In conventional vehicles that are driven solely by an engine, the power switch 24 is sometimes called an ignition switch. In vehicles capable of electric travel, such as BEVs (Battery Electric Vehicles) and PHEVs (Plug-in Hybrid Electric Vehicles), the power switch 24 is sometimes called a Ready switch.

[0014] The vehicle 10 is connected to an OTA server 30 via a mobile communication network 20. The OTA server 30 is a server device that distributes update software for on-board devices. The OTA server 30 has a storage device 31 that stores programs and data for distributing the update software, and a processor 32 that executes the distribution programs.

[0015] The OTA server 30 can communicate with an information terminal 40 of a user of the vehicle 10 via the mobile communication network 20. An example of the information terminal 40 is a smartphone. The information terminal 40 may be a tablet terminal or a PC terminal. The information terminal 40 includes a storage device 41, a processor 42, and an HMI 43. The processor 42 reads and executes software stored in the storage device 41. The HMI 43 includes an input device that accepts user operations and a display device that displays information to the user. The software stored in the storage device 41 includes software that provides functions such as checking information about the vehicle 10 owned by the user and remote operation.

[0016] <Overview of Software Update> Next, an overview of software update for on-board devices in the vehicle 10 will be described. The on-board devices that are subject to software update include the OTA master 11, DCM 12, ADAS 13, PCU 14, engine ECU 15, transmission ECU 16, brake ECU 17, and HMI 18. The software update is performed through a download phase, an install phase, and an activate phase.

[0017] In the download phase, update software is transmitted from the OTA server 30 to the vehicle 10. The OTA master 11 stores the update software received from the OTA server 30 in the data storage 23. The download phase includes a series of processes related to the download, such as determining whether the download can be performed and verifying the update data. The update software may be transmitted from the OTA server 30 to the OTA master 11 by transmitting compressed data obtained by compressing the update software, or by transmitting divided data obtained by dividing the update software or compressed data. Update software for multiple in-vehicle devices may also be transmitted together.

[0018] In the installation phase, update software is installed in the in-vehicle device to be updated. In the installation phase, the OTA master 11 installs the update software in the storage module 21 of the in-vehicle device to be updated based on the update data downloaded to the data storage 23. The installation phase includes a series of installation-related processes, such as determining whether installation can be performed, transferring the update data, and verifying the update software. If the update data includes the update software itself, the OTA master 11 transfers the update data to the in-vehicle device to be updated in the installation phase. If the update data includes compressed data, difference data, or divided data of the update software, a process of generating update software from the update data is performed. The generation process may be performed by the OTA master 11 or by the in-vehicle device to be updated. The update software can be generated by decompressing the compressed data and assembling the difference data or divided data. Note that the update software is disabled when the installation phase is complete.

[0019] In the activation phase, the update software is activated, i.e., the update software is enabled, in the in-vehicle device to be updated. The activation phase includes a series of processes related to activation, such as determining whether activation can be performed, checking the consistency of the update software, and verifying the results of the activation.

[0020] <Two Software Update Procedures> There are two software update procedures for in-vehicle devices: a first update procedure and a second update procedure. In both the first update procedure and the second update procedure, the software update is performed using the same procedure until the installation phase is completed. The first update procedure and the second update procedure differ in the timing at which the activation process in the activation phase begins. The activation process is a process for validating the update software installed in the storage module 21 of the in-vehicle device to be updated.

[0021] In the first update procedure, the activation process is performed in response to switching the power switch 24 from on to off. That is, in the first update procedure, the activation process is performed in response to switching from a driving power mode to a parking power mode. When a software update is performed in the first update procedure, the power switch 24 is prohibited from being switched on again during the period from the start to the completion of the activation process. In other words, when a software update is performed in the first update procedure, switching to the driving power mode is prohibited during the period from the start to the completion of the activation process.

[0022] In contrast, in the second update procedure, the activation process is performed in response to switching of the power switch 24 from off to on. That is, in the second update procedure, the activation process is performed in response to switching from the parking power mode to the driving power mode. More specifically, in the second update procedure, the activation process is started in response to switching of the power switch 24 from off to on. Then, after the activation process is completed, the power mode is switched from the parking power mode to the driving power mode.

[0023] The method for performing the software update, either the first update method or the second update method, is determined based on, for example, the type of in-vehicle device, the hardware configuration, and the type of software. The method for performing the software update, either the first update method or the second update method, may be determined based on environmental conditions, user settings, a combination of other in-vehicle devices that are simultaneously activated, and the like.

[0024] When software is updated using the first update procedure, power must be supplied to the in-vehicle device undergoing activation processing even while the vehicle 10 is parked. Therefore, a dedicated power line must be connected to the in-vehicle device for which software is updated using the first update procedure to supply power even while the vehicle is parked. In contrast, by updating the software of the in-vehicle device using the second update procedure, the need for a dedicated power line can be eliminated.

[0025] However, for some in-vehicle devices, it may be more desirable to perform a software update using the first update procedure rather than the second update procedure. In the first update procedure, the activation process is already completed when the power switch 24 is switched from on to off and then back on. Therefore, in this case, the in-vehicle device to be updated can start operating immediately after the power switch 24 is switched from off to on. In contrast, in the second update procedure, the activation process starts after the power switch 24 is switched from off to on. Therefore, even if the user switches the power switch 24 from off to on to start driving the vehicle 10, the in-vehicle device to be updated cannot start operating until the activation process is completed. In contrast, by performing a software update of the in-vehicle device using the first update procedure, the in-vehicle device can start operating immediately after the power switch 24 of the vehicle 10 is switched from off to on.

[0026] In this embodiment, the DCM 12, the ADAS 13, and the PCU 14 are classified as in-vehicle devices that undergo software updates using the first update procedure. The communication function provided by the DCM 12 is used to report any abnormalities that occur in the vehicle 10 to the outside. Furthermore, in this embodiment, the DCM 12 is responsible for recording the results of self-diagnosis of each in-vehicle device. It is desirable that the DCM 12's functions, such as reporting abnormalities and recording self-diagnosis results, be available immediately after the power switch 24 is switched from off to on. Furthermore, the ADAS 13 must provide driving assistance from the moment the vehicle 10 starts traveling. Furthermore, while the PCU 14 is stopped, power cannot be supplied to the drive system, preventing the vehicle 10 from starting traveling. Thus, the DCM 12, the ADAS 13, and the PCU 14 are in-vehicle devices that must start operating immediately after the power switch 24 is switched from off to on.

[0027] Furthermore, depending on the hardware configuration of the storage module 21 installed in the in-vehicle device, a software update using the first update procedure may also be required. In this embodiment, among the in-vehicle devices other than the DCM 12, ADAS 13, and PCU 14, in-vehicle devices equipped with a single-bank storage module 21 are classified as in-vehicle devices that undergo software updates using the first update procedure. Furthermore, among the in-vehicle devices other than the DCM 12, ADAS 13, and PCU 14, in-vehicle devices equipped with a dual-bank storage module 21 are classified as in-vehicle devices that undergo software updates using the second update procedure.

[0028] FIG. 2 shows the configuration of an in-vehicle device D1 equipped with a single-bank storage module 21A. The storage module 21A of this in-vehicle device D1 has only one storage area B for storing software executed by the processor 32. In this in-vehicle device D1, the updated software is installed in the same storage area B as the storage area B storing the pre-update software. Therefore, operation of the in-vehicle device D1 must be stopped even during installation. Furthermore, to recover from an activation failure, the pre-update software must be reinstalled in storage area B. This reinstallation for recovery takes a long time. Furthermore, if the pre-update software is not backed up, the pre-update software must be re-downloaded. Thus, for an in-vehicle device D1 equipped with a single-bank storage module 21A, considering recovery in the event of a failure, it may take a very long time from the start of activation until the device is able to start operating. Therefore, in this embodiment, the in-vehicle device D1 equipped with a single-bank storage module 21A performs software updates using the first update procedure. In addition, in this embodiment, the on-board devices that undergo software updates in the first update procedure are powered on and off in conjunction with the on and off of the power switch 24 of the vehicle 10 .

[0029] FIG. 3 shows the configuration of an in-vehicle device D2 equipped with a dual-bank storage module 21B. The dual-bank storage module 21B has two storage areas B1 and B2. One of the two storage areas B1 and B2 is disabled, and the other is enabled. The processor 22 reads and executes software from the enabled storage area. In the case of such an in-vehicle device D2, the updated software is installed in the disabled storage area, i.e., in a storage area different from the storage area storing the pre-update software. After installation, activation is performed by switching the storage area to be enabled. If activation fails, the pre-update state can be restored in a short time by switching the storage area to be enabled again. Therefore, for an in-vehicle device D2 equipped with a dual-bank storage module 21B, even allowing for recovery in the event of a failure, it does not take a long time from the start of activation until the device is able to start operating. Therefore, in this embodiment, software update using the second update procedure is performed only on in-vehicle devices D2 equipped with a dual-bank storage module 21B.

[0030] Many in-vehicle devices may have multiple pieces of software installed that provide different functions. Among these pieces of software, some pieces of software must be executed immediately after the power switch 24 is turned from off to on, while others do not. If the software needs to be executed immediately after the power switch 24 is turned from off to on, updating using the second update procedure may result in the software not being executed in time. Therefore, even for the same in-vehicle device, the first update procedure or the second update procedure may be used depending on the type of software to be updated.

[0031] The OTA master 11 determines whether the software update will be performed using the first update procedure or the second update procedure at least by the start of the activation phase. For example, the OTA master 11 makes this determination based on campaign information. In this case, the campaign information includes information indicating whether the software update procedure is the first update procedure or the second update procedure. Alternatively, the OTA master 11 may make this determination in the following manner. First, classification information for the types of in-vehicle devices and software to be updated using the first update procedure and the types of in-vehicle devices and software to be updated using the second update procedure is stored in advance in the storage module 21 of the OTA master 11. When updating software, the OTA master 11 acquires the types of in-vehicle devices and software to be updated from the campaign information or the in-vehicle devices to be updated. Then, the OTA master 11 references the classification information stored in the storage module 21 to determine which update procedure the acquired type is classified as.

[0032] <Activation Process in First Update Procedure> Next, the activation process in the first update procedure will be described in detail with reference to Figures 4 to 8. A program for managing software updates and a program for controlling the display of information related to software updates are stored in the storage module 21 of the OTA master 11. The processing of the OTA master 11 shown in Figure 4 and Figure 9 (described later) is performed by the processor 22 of the OTA master 11 reading and executing these programs.

[0033] 4 shows the process flow of the activation phase when a software update is performed using the first update procedure. When the installation phase is completed, the OTA master 11 instructs the HMI 18 to display a first preview image to confirm the execution of the activation process (S10). In response to the instruction, the HMI 18 displays the first preview image as shown in FIG. 5 (S11).

[0034] 5 shows an example of the display of the first pre-confirmation image. The first pre-confirmation image includes a display for accepting a selection operation for deciding whether or not to execute the activation process. Specifically, the first pre-confirmation image displays a button for selecting whether to allow the execution of the activation process and a button for selecting whether to postpone the execution of the activation process. Note that the operation of these buttons is disabled while the vehicle 10 is moving and is enabled only while the vehicle is parked.

[0035] The first pre-check image also displays information about functional limitations of the vehicle 10 that accompany the activation process. Specifically, the functional limitation information indicates that the power switch 24 cannot be switched back on during the activation process. This functional limitation information indicates that the vehicle cannot be switched back to a driving power mode. The first pre-check image also displays information about the estimated time required for the activation process. The estimated activation process time here is the estimated time required from when the power switch 24 is switched from on to off until the activation process is completed and the power switch 24 can be switched back on. The OTA master 11 obtains the estimated time from, for example, campaign information. The OTA master 11 may also calculate the estimated time based on the data size of the update software, the type of in-vehicle device to be updated, and the like.

[0036] The first preview image also displays information such as a warning to the user in response to the execution of the activation process, such as a warning that the power switch 24 must be turned off to update the software, that activation should be performed in a safe place, and that some functions of the vehicle 10 will be disabled the next time the power switch 24 is turned on.

[0037] When the user selects permission to execute the activation process on the HMI 18 displaying the first preliminary confirmation image (S12), the HMI 18 notifies the OTA master 11 that execution of the activation process is permitted (S13). After confirming permission to execute the activation process, the OTA master 11 instructs the HMI 18 to display a first final confirmation image when it becomes possible to switch the power switch 24 from on to off (S14). In response to the instruction, the HMI 18 displays the first final confirmation image as shown in FIG. 6 (S15). The OTA master 11 determines that the power switch 24 is in a state where it can be switched from on to off, for example, based on conditions such as the vehicle 10 being stopped, the shift operation into park, and the parking brake being applied.

[0038] FIG. 6 shows an example of the display of the first final confirmation image. Similar to the first preliminary confirmation image, the first final confirmation image displays information about the functional limitations of the vehicle 10 associated with the activation process. Specifically, the first final confirmation image displays information indicating that, once the power switch 24 is turned off, the vehicle 10 cannot be driven by turning the power switch 24 back on until the activation process is complete. The first final confirmation image also displays information indicating the estimated time required for the activation process. The first final confirmation image also displays information indicating that the user can turn off the power switch 24 and resume driving after confirming that they are in a safe location, and that in that case, the software update will resume with the display of the first final confirmation image the next time the vehicle is stopped. The first final confirmation image also displays an indication of whether the software update can be paused. The activation phase continues if the user does not select to pause the software update in the first final confirmation image. On the other hand, if the user selects to pause the software update in the first final confirmation image, the activation phase is temporarily halted. The activation phase process is then resumed the next time the vehicle 10 is ready to be turned off.

[0039] If the activation phase processing continues, and the user subsequently switches the power switch 24 from on to off (S16), the OTA master 11 starts the activation processing (S17). At the same time, the OTA master 11 instructs the HMI 18 to display a first guide image such as the one shown in Fig. 7 (S18). The HMI 18 displays the first guide image in response to the instruction (S19).

[0040] As shown in Figure 7, the first guide image displays information indicating that the power switch 24 cannot be turned on and information about the estimated time until the power switch 24 can be turned on. The OTA master 11 calculates the estimated time for displaying the information in the first guide image by subtracting the time elapsed since the start of the activation process from the estimated time required from start to completion. The HMI 18 temporarily darkens the screen when the vehicle 10 is locked or a certain amount of time has passed, but then displays the first guide image again when the vehicle 10 is unlocked or the HMI 18 is operated.

[0041] When the activation process is completed, the OTA master 11 instructs the HMI 18 to display a first completion notification image as shown in Fig. 8 (S20). The HMI 18 displays the first completion notification image in response to the instruction (S21). As shown in Fig. 8, the first completion notification image displays information indicating that the software update has been completed and information indicating that the power switch 24 can now be turned on.

[0042] <Activation Processing in Second Update Procedure> Next, details of the activation processing in the second update procedure will be described with reference to Figures 9 to 11. Figure 9 shows the processing flow of the activation phase when software is updated in the second update procedure.

[0043] In this case, when the installation phase is completed, the OTA master 11 instructs the HMI 18 to display a second preview image to confirm the execution of the activation process to the user (S30). In response to the instruction, the HMI 18 displays the second preview image as shown in FIG. 10 (S31).

[0044] 10 shows an example of the display of the second preview check image. Like the first preview check image, the second preview check image includes a display for accepting a selection operation for whether or not to execute the activation process. The second preview check image also displays information indicating that the activation process will be performed the next time the power switch 24 is turned on. The second preview check image also displays information regarding the estimated time from when the power switch 24 is turned from off to on until the activation process is completed.

[0045] When the user selects permission to execute the activation process on the HMI 18 displaying the second preliminary confirmation image (S32), the HMI 18 notifies the OTA master 11 that execution of the activation process is permitted (S33). After confirming permission to execute the activation process, the OTA master 11 instructs the HMI 18 to display a second final confirmation image when the vehicle 10 is ready to be powered off (S34). In response to the instruction, the HMI 18 displays the second final confirmation image as shown in FIG. 11 (S35).

[0046] 11 shows an example of the display of the second final confirmation image. The second final confirmation image displays information indicating that the activation process is ready and information indicating that the software update will resume the next time the power switch 24 is switched from off to on.

[0047] Thereafter, when the power switch 24 is switched from on to off and then back on, the OTA master 11 starts the activation process (S36). In addition, the OTA master 11 instructs the HMI 18 to display a second guide image as shown in Fig. 12 (S37). The HMI 18 displays the second guide image in response to the instruction (S38).

[0048] 12, the second guide image displays information indicating that a software update is in progress and information about the estimated time until the update is completed. The OTA master 11 calculates the estimated time for displaying the information in the second guide image by subtracting the time that has elapsed since the start of the activation process from the estimated time required from the start to completion of the activation process.

[0049] When the activation process is complete, the OTA master 11 instructs the HMI 18 to display a second completion notification image, as shown in FIG. 13 (S39). The HMI 18 displays the second completion notification image in response to the instruction (S40). As shown in FIG. 13, the second completion notification image displays information indicating that the software update has been completed. The second completion notification image also displays information indicating that functional restrictions associated with the activation process have been lifted. For example, if the vehicle 10 was prohibited from driving during the activation process, the second completion notification image displays information indicating that the vehicle 10 can now be driven.

[0050] <Operations and Effects of the Embodiment> The OTA master 11 controls the display of the HMI 18, which displays information about software updates for on-board devices installed in the vehicle 10. Software updates for on-board devices are performed using a first update procedure or a second update procedure. In the first update procedure, an activation process for validating the update software installed in the on-board device is performed in response to a switch from the driving power mode to the parking power mode. In the second update procedure, the activation process is performed in response to a switch from the parking power mode to the driving power mode. When a software update is performed using the first update procedure, the OTA master 11 causes the HMI 18 to display a first preliminary confirmation image and a first final confirmation image before the activation process begins. In contrast, when a software update is performed using the second update procedure, the OTA master 11 causes the HMI 18 to display a second preliminary confirmation image and a second final confirmation image, which are different from the first preliminary confirmation image and the first final confirmation image, respectively, before the activation process begins.

[0051] The timing at which the functions of the vehicle 10 are restricted due to the activation process and the content of the restrictions differ between when the software update is performed using the first update procedure and when it is performed using the second update procedure. Therefore, simply notifying the user that the activation process will be performed may result in unexpected functional restrictions, which may confuse the user. In this embodiment, the user can confirm whether the software update will be performed using the first update procedure or the second update procedure based on the difference in the confirmation image displayed on the HMI 18 before the activation process begins.

[0052] The control device, vehicle, control method, program, and non-transitory computer-readable storage medium of the present embodiment described above can achieve the following effects: (1) The confirmation image displayed on the HMI 18 before the start of the activation process differs depending on whether the software update is performed using the first update procedure or the second update procedure. Therefore, this embodiment has the effect of being able to display an appropriate confirmation screen depending on the timing of the activation process.

[0053] (2) The user can check the timing of the activation process before deciding whether to perform the activation process. This improves user convenience. (3) If the timing of the activation process differs, the timing and content of the functional restrictions on the vehicle 10 associated with the activation process will differ. In response to this, the OTA master 11 displays information about the functional restrictions on the vehicle 10 associated with the activation process in the first preliminary / final confirmation image. Furthermore, the OTA master 11 displays information about the functional restrictions in the second preliminary / final confirmation image that is different from the information displayed in the first preliminary / final confirmation image. This allows the user to be accurately notified of the functional restrictions on the vehicle 10 associated with the activation process.

[0054] (4) The OTA master 11 displays, in the first preliminary / final confirmation image, information about the period during which the functions of the vehicle 10 are restricted due to the implementation of the activation process. The OTA master 11 also displays, in the second preliminary confirmation image, information about a period different from the period for which the information is displayed in the first preliminary / final confirmation image as information about the period during which the functions of the vehicle 10 are restricted. This allows the user to be accurately notified of the period during which the functions of the vehicle 10 are restricted due to the implementation of the activation process.

[0055] (5) The OTA master 11 displays, in the first preliminary / final confirmation image, information about the estimated time from when the power switch 24 is switched from on to off until it can be switched on again. This allows the user to confirm the period during which the power switch 24 cannot be turned on due to the activation process, and then decide whether to perform the activation process.

[0056] (6) The OTA master 11 displays, in the second pre-check image, information about the estimated time from when the power switch 24 is switched from off to on until the activation process is completed. Therefore, the next time the user drives the vehicle 10, the user can check the period during which the activation process will cause functional restrictions and then decide whether to perform the activation process.

[0057] (7) The first preliminary / final confirmation image and the second preliminary confirmation image include a display for accepting a selection operation for allowing or disallowing the start of the activation process. Therefore, the user can decide whether to proceed with the activation process while checking the timing of the activation process and the content and timing of the functional restrictions that accompany its implementation.

[0058] (8) The functional limitations of the vehicle 10 that result from the activation process during the first update procedure differ from those during the activation process during the second update procedure. Therefore, the user may not be able to understand the situation simply by knowing that the activation process is in progress. In response to this, when a software update is performed using the first update procedure, the OTA master 11 causes the HMI 18 to display a first guide image during the activation process. Furthermore, when a software update is performed using the second update procedure, the OTA master 11 causes the HMI 18 to display a second guide image, which is different from the first guide image, during the activation process. This makes it easier for the user to understand the impact of the activation process.

[0059] (9) The OTA master 11 displays, within the first guide image, information indicating that the power switch 24 cannot be turned on, i.e., that the power mode cannot be switched to driving power mode. Furthermore, the OTA master 11 displays, within the first guide image, information indicating the estimated time until the power switch 24 can be turned on. This makes it easier for the user to understand the situation.

[0060] (10) The OTA master 11 displays information about the estimated time until the activation process is completed in the second guide image, so that the user can know when the functions of the updated software will become available.

[0061] (11) The functions of the vehicle 10 whose restrictions are lifted upon completion of the activation process differ depending on whether the software update is performed using the first update procedure or the second update procedure. In response to this, when the software update is performed using the first update procedure, the OTA master 11 causes the HMI 18 to display a first completion notification image after the activation process is completed. Furthermore, when the software update is performed using the second update procedure, the OTA master 11 causes the HMI 18 to display a second completion notification image, different from the first completion notification image, after the activation process is completed. Specifically, the OTA master 11 displays the first completion notification image indicating that the power switch 24 can now be turned on, while displaying the second completion notification image indicating that the restricted functions of the in-vehicle device have become available as a result of the activation process being performed. This makes it easy for the user to understand the functions of the vehicle 10 whose restrictions are lifted upon completion of the activation process.

[0062] (12) The DCM 12, ADAS 13, and PCU 14 are required to start operating immediately after the power switch 24 is switched from off to on. In this embodiment, software updates for the DCM 12, ADAS 13, and PCU 14 are performed using a first update procedure in which activation processing is performed while the power switch 24 is off. This prevents the activation processing from lengthening the time from when the power switch 24 is switched from off to on until the DCM 12, ADAS 13, and PCU 14 start operating. In this embodiment, the in-vehicle devices whose software is updated using the first update procedure and the in-vehicle devices whose software is updated using the second update procedure are classified according to the function of the in-vehicle devices.

[0063] (13) The activation process for the in-vehicle device D1 equipped with a single-bank storage module 21A takes longer than the activation process for the in-vehicle device D2 equipped with a dual-bank storage module 21B. Therefore, if the activation process is initiated after the power switch 24 is switched from off to on, the functions of the in-vehicle device D1 may be unavailable for a long time until the activation process is completed. In contrast, in this embodiment, among the in-vehicle devices other than the DCM 12, the ADAS 13, and the PCU 14, the in-vehicle device D1 equipped with a single-bank storage module 21A performs a software update using the first update procedure. In contrast, among the in-vehicle devices other than the above, the in-vehicle device D2 equipped with a dual-bank storage module 21B performs a software update using the second update procedure. Therefore, by performing the activation process, it is possible to prevent the in-vehicle device's functions from being restricted for a long period of time after the power switch 24 is switched from off to on.

[0064] (14) When the software update is performed according to the first update procedure, the OTA master 11 starts the activation process of the in-vehicle device in response to the power switch 24 being switched from on to off. When the software update is performed according to the second update procedure, the OTA master 11 starts the activation process of the in-vehicle device in response to the power switch 24 being switched from off to on. In this manner, in this embodiment, the OTA master 11, which manages the software update, controls the display of information. Therefore, information can be accurately displayed according to the progress of the software update.

[0065] (15) When the installation phase is completed, the OTA master 11 displays the first preliminary and second confirmation images on the HMI 18. Furthermore, when the vehicle 10 is subsequently in a state where the power switch 24 can be switched from on to off, the OTA master 11 displays the first and second final confirmation images on the HMI 18. This allows the user to easily confirm that the activation process will be executed thereafter.

[0066] In this embodiment, the first preliminary confirmation image and the first final confirmation image correspond to the first confirmation image, and the second preliminary confirmation image and the second final confirmation image correspond to the second confirmation image. Also, in this embodiment, the HMI 18 installed in the vehicle 10 corresponds to the display unit, and the OTA master 11 mounted on the vehicle 10 corresponds to the control device.

[0067] In this embodiment, the driving power mode corresponds to the first power mode and the power mode in which the vehicle 10 is capable of driving. The parking power mode corresponds to the second power mode and the power mode in which the vehicle 10 is not capable of driving. Switching from the driving power mode to the parking power mode corresponds to the first switching pattern of power mode switching, and switching from the parking power mode to the driving power mode corresponds to the second switching pattern of power mode switching. Furthermore, the processes of S10 and S14 in FIG. 4 correspond to the first display process of displaying a first confirmation image on the display unit before the activation process begins. The process of S18 corresponds to the third display process of displaying a first guide image on the display unit during the activation process. The process of S20 corresponds to the fifth display process of displaying a first completion notification image on the display unit after the activation process is completed. Furthermore, the processes of S30 and S34 in FIG. 9 correspond to the second display process of displaying a second confirmation image, different from the first confirmation image, on the display unit before the activation process begins. The process of S37 corresponds to a fourth display process in which a second guide image different from the first guide image is displayed on the display unit during the activation process. The process of S39 corresponds to a sixth display process in which a second completion notification image different from the first completion notification image is displayed on the display unit after the activation process is completed.

[0068] Second Embodiment Next, a second embodiment of the control device, the control method, the program (program product), and the non-transitory computer-readable storage medium will be described in detail with reference to Figures 14 and 15. Note that in the second embodiment, components common to the first embodiment are denoted by the same reference numerals, and detailed descriptions thereof will be omitted.

[0069] In the first embodiment, the display control of information related to software updates on the HMI 18 installed in the vehicle 10 was performed by the OTA master 11 mounted on the same vehicle 10. In the second embodiment, information related to software updates is displayed on the HMI 43 of the information terminal 40 owned by the user of the vehicle 10. The display control is performed by the OTA server 30 in the data center.

[0070] <Activation Process in First Update Procedure> Figure 14 shows the flow of the activation phase process when software is updated in the first update procedure in the second embodiment. As shown in Figure 14, when the installation phase is completed, the OTA master 11 notifies the OTA server 30 (S50). When the OTA server 30 confirms the completion of the installation phase, it instructs the information terminal 40 to display a first preview confirmation image (S51). In response to the instruction, the information terminal 40 displays the first preview confirmation image on its own HMI 43 (S52). The first preview confirmation image displayed on the HMI 43 of the information terminal 40 conforms to Figure 5.

[0071] When the user operates the information terminal 40 to select permission to execute the activation process (S53), the information terminal 40 notifies the OTA server 30 that execution of the activation process is permitted (S54). Furthermore, the OTA server 30 notifies the OTA master 11 of the vehicle 10 that execution of the activation process is permitted (S55).

[0072] When the OTA master 11 subsequently becomes capable of switching the power switch 24 from on to off, it notifies the OTA server 30 of this state (S56). In response to this notification, the OTA server 30 instructs the information terminal 40 to display a first final confirmation image (S57). In response to the instruction, the information terminal 40 displays the first final confirmation image on its own HMI 43 (S58). The first final confirmation image displayed on the HMI 43 of the information terminal 40 conforms to that shown in FIG. 6.

[0073] Thereafter, when the power switch 24 is switched from on to off, the OTA master 11 starts the activation process (S59). The OTA master 11 also notifies the OTA server 30 of the start of the activation process (S60). When the OTA server 30 confirms the start of the activation process, it instructs the information terminal 40 to display a first guide image (S61). In response to the instruction, the information terminal 40 displays the first guide image on its own HMI 43 (S62). The first guide image displayed on the HMI 43 of the information terminal 40 conforms to that shown in FIG. 7.

[0074] When the activation process is completed, the OTA master 11 notifies the OTA server 30 of this (S63). When the OTA server 30 confirms the completion of the activation process, it instructs the information terminal 40 to display a first completion notification image (S64). In response to the instruction, the information terminal 40 displays the first completion notification image on its own HMI 43 (S65). The first completion notification image displayed on the HMI 43 of the information terminal 40 conforms to that shown in FIG. 8.

[0075] <Activation Process in Second Update Procedure> Figure 15 shows the flow of the activation phase process when software is updated in the second update procedure in the second embodiment. As shown in Figure 15, when the installation phase is completed, the OTA master 11 notifies the OTA server 30 of this (S70). When the OTA server 30 confirms the completion of the installation phase, it instructs the information terminal 40 to display a second pre-check image (S71). In response to the instruction, the information terminal 40 displays the second pre-check image on its own HMI 43 (S72). The second pre-check image displayed on the HMI 43 of the information terminal 40 conforms to Figure 10.

[0076] When the user operates the information terminal 40 to select permission to execute the activation process (S73), the information terminal 40 notifies the OTA server 30 that execution of the activation process is permitted (S74). The OTA server 30 notifies the OTA master 11 of the vehicle 10 that execution of the activation process is permitted (S75).

[0077] When the power switch 24 is then ready to be switched from on to off, the OTA master 11 notifies the OTA server 30 of this (S76). In response to the notification, the OTA server 30 instructs the information terminal 40 to display a second final confirmation image (S77). In response to the instruction, the information terminal 40 displays the second final confirmation image on its own HMI 43 (S78). The second final confirmation image displayed on the HMI 43 of the information terminal 40 conforms to that shown in FIG. 11.

[0078] Thereafter, when the power switch 24 is switched from on to off and then back on, the OTA master 11 starts the activation process (S79). The OTA master 11 also notifies the OTA server 30 of the start of the activation process (S80). When the OTA server 30 confirms the start of the activation process, it instructs the information terminal 40 to display a second guide image (S81). In response to the instruction, the information terminal 40 displays the second guide image on its own HMI 43 (S82). The second guide image displayed on the HMI 43 of the information terminal 40 is similar to that shown in FIG. 12 .

[0079] When the activation process is completed, the OTA master 11 notifies the OTA master 11 of the completion (S83). When the OTA server 30 confirms the completion of the activation process, it instructs the information terminal 40 to display a second completion notification image (S84). In response to the instruction, the information terminal 40 displays the second completion notification image on its own HMI 43 (S85). The second completion notification image displayed on the HMI 43 of the information terminal 40 conforms to that shown in FIG. 13.

[0080] In the second embodiment, the HMI 43 of the information terminal 40 corresponds to the display unit, and the OTA server 30 corresponds to the control device. The second embodiment provides the same or equivalent functions and effects as the first embodiment.

[0081] (Other Embodiments) The above embodiment can be modified as follows: The above embodiment and the following modifications can be combined with each other within the scope of technical compatibility.

[0082] In addition to the display control of the HMI 18 of the vehicle 10 by the OTA master 11 in the first embodiment, the display control of the information terminal 40 by the OTA server 30 in the second embodiment may be performed. In this case, both the OTA master 11 and the OTA server 30 correspond to the control device.

[0083] The display control of the HMI 18 of the vehicle 10 in the first embodiment may be performed by the OTA server 30. The display control of the information terminal 40 in the second embodiment may be performed by the OTA master 11.

[0084] The in-vehicle device that is the target of the software update may control the display of information about the software update. The display examples of the images shown in Figures 5 to 8 and 10 to 13 are configured to display information within the image using text. Information may also be displayed within these images using methods other than text, such as still images or videos.

[0085] The configuration of the first completion notification image ( FIG. 8 ) and the second completion notification image ( FIG. 13 ) can be changed as appropriate. In the above embodiment, information indicating that the power switch 24 can be turned on was displayed in the first completion notification image. However, this display may be omitted. Furthermore, in the above embodiment, information indicating that the restricted functions of the in-vehicle devices have become available as a result of the activation process, specifically, information indicating that the vehicle 10 can be driven, was displayed in the second completion notification image. However, this display may be omitted. It is assumed that the user is aware of the functional restrictions during the activation process in both cases where the software update was performed using the first update procedure and the second update procedure. In this case, if the user knows whether the software update was performed using the first update procedure or the second update procedure, they can know the functions of the vehicle 10 that will be released and become available upon completion of the activation process. Therefore, it is preferable that the first completion notification image and the second completion notification image be configured so that the user can understand that they are notifying the user of the completion of the activation process and can distinguish between the two images. If the first completion notification image and the second completion notification image are configured in this manner, it is less likely that the user will be confused by unexpected functional restrictions that occur during the activation process.

[0086] The same completion image may be displayed after the activation process is completed, regardless of whether the software update is performed using the first update procedure or the second update procedure. The completion image may not be displayed after the activation process is completed.

[0087] The configuration of the first guide image ( FIG. 7 ) and the second guide image ( FIG. 12 ) may be changed as appropriate. For example, the display of information about the estimated time remaining until the activation process is completed in the first and second guide images may be omitted, or the display of information indicating that the power switch 24 cannot be turned on in the first guide image may be omitted. The first and second guide images may be configured in any way that allows the user to understand that the activation process is in progress and allows the user to distinguish between the two images.

[0088] The same guide image may be displayed during the activation process whether the software update is performed using the first update procedure or the second update procedure. The guide image may not be displayed during the activation process.

[0089] The configuration of the first preview confirmation image ( FIG. 5 ) and the second preview confirmation image ( FIG. 10 ) may be modified as appropriate. For example, the display of information about the estimated activation time may be omitted in the first and second preview confirmation images. Furthermore, information about functional limitations associated with the activation process may be displayed differently from the example shown, or the display of the functional limitations may be omitted altogether. Furthermore, when the activation process is automatically executed without user consent or when user consent is obtained before the installation phase is completed, the display of the selection operation for allowing or disallowing the start of the activation process may be omitted. In any case, it is sufficient that the first preview confirmation image and the second preview confirmation image are configured differently so that the user can recognize that they are notifying the user in advance of the activation process and can distinguish between them. The same applies to the first final confirmation image ( FIG. 6 ) and the second final confirmation image ( FIG. 11 ).

[0090] In the above embodiment, the first / second preliminary confirmation image is displayed when the installation phase is completed, and the first / second final confirmation image is displayed when it becomes possible to switch the power switch 24 from on to off. However, it is also possible to display only either the first / second preliminary confirmation image or the first / second final confirmation image.

[0091] The OTA master 11 that manages the software update controls the display of information related to the software update. However, the management of the software update and the display control of information related to the software update may be performed by different in-vehicle devices.

[0092] In the above embodiment, the activation process is performed either when switching from a driving power mode to a parking power mode or when switching from a parking power mode to a driving power mode. If the vehicle 10 includes power modes other than the above two, the activation process may be performed in response to a power mode switch in a switching pattern other than the above. Different power mode switching patterns for the activation process result in different timing for the activation process, which results in different resistance to and content of the function restrictions on the vehicle 10 associated with the activation process. Therefore, it is desirable to display a different confirmation image for each power mode switching pattern for the activation process. Examples of power modes other than those for driving and parking include power modes that provide functions, such as entertainment functions and external power supply functions, that cannot be provided in the normal parking power mode while the vehicle is parked. Furthermore, the multiple power modes may include power modes corresponding to the ignition (IG) on state, the accessory power (ACC) on state, and the vehicle power off state, as described below. The IG on state is a state in which the vehicle engine is running and multiple ECUs are powered on. The ACC on state is a state in which only some of the ECUs are powered on compared to the IG on state. The vehicle power off state is a state in which almost all ECUs are powered off.

[0093] The control device may be configured as processing circuitry including one or more processors operating according to a computer program, one or more dedicated hardware circuits such as dedicated hardware for performing at least some of the various processes, or a combination thereof. Dedicated hardware may include, for example, an application-specific integrated circuit (ASIC). The processor includes a central processing unit (CPU) and memory such as random-access memory (RAM) and read-only memory (ROM), which stores program code or instructions configured to cause the CPU to perform processes. The memory, i.e., storage medium, includes any available medium accessible by a general-purpose or dedicated computer.

Claims

1. A control device comprising a processing circuit, the processing circuit being configured to control a display unit configured to display information regarding a software update of an on-board device mounted on a vehicle configured to selectively switch to one of a plurality of power modes, the software update including an activation process for enabling update software installed in the on-board device, the processing circuit being configured to cause the display unit to display a first confirmation image before start of the activation process if the software update is performed by a first update procedure in which the activation process is performed in response to switching between the plurality of power modes in a first switching pattern, and the processing circuit being configured to cause the display unit to display a second confirmation image before start of the activation process if the software update is performed by a second update procedure in which the activation process is performed in response to switching between the plurality of power modes in a second switching pattern, the first switching pattern and the second switching pattern being different from each other, and the first confirmation image and the second confirmation image being different from each other.

2. The control device described in claim 1, wherein the processing circuit is configured to display information on functional restrictions of the vehicle associated with the execution of the activation process in the first confirmation image, and to display information different from the information displayed in the first confirmation image as information on the functional restrictions in the second confirmation image.

3. A control device as described in claim 1 or claim 2, wherein the processing circuit is configured to display, in the first confirmation image, information about a period during which the vehicle's functions are restricted as a result of the activation process being carried out, and to display, in the second confirmation image, information about a period different from the period during which information is displayed in the first confirmation image as information about a period during which the vehicle's functions are restricted.

4. A control device as described in any one of claims 1 to 3, wherein the first confirmation image and the second confirmation image include an indication for accepting a selection operation of whether or not to allow the start of the activation process.

5. A control device as described in any one of claims 1 to 4, wherein the processing circuit is configured to determine whether the software update will be performed using the first update procedure or the second update procedure based on the type of the in-vehicle equipment that is the target of the software update.

6. A control device as described in any one of claims 1 to 5, wherein the processing circuit is configured to determine whether the software update will be performed using the first update procedure or the second update procedure based on the type of software that is the target of the software update.

7. A control device as described in any one of claims 1 to 6, wherein the in-vehicle equipment for which the software update is performed in the first update procedure and the in-vehicle equipment for which the software update is performed in the second update procedure are classified according to the function of the in-vehicle equipment.

8. A control device as described in any one of claims 1 to 7, wherein the processing circuit is configured to start the activation process of the in-vehicle equipment in response to switching between the multiple power modes in the first switching pattern when the software update is performed in the first update procedure, and the processing circuit is configured to start the activation process of the in-vehicle equipment in response to switching between the multiple power modes in the second switching pattern when the software update is performed in the second update procedure.

9. A control device as described in any one of claims 1 to 8, wherein the switching between the multiple power supply modes in the first switching pattern is switching from a first power supply mode in which the vehicle is in a state in which it is unable to run to a second power supply mode in which the vehicle is in a state in which it is unable to run, and the switching between the multiple power supply modes in the second switching pattern is switching from the second power supply mode to the first power supply mode.

10. The control device according to claim 9, wherein switching between the multiple power modes in the first switching pattern is performed in response to switching of a power switch of the vehicle from on to off, and switching between the multiple power modes in the second switching pattern is performed in response to switching of the power switch from off to on.

11. The control device according to claim 9 or claim 10, wherein the processing circuit is configured to display, within the first confirmation image, information on an estimated time from when the vehicle is switched to the second power supply mode until when the vehicle can be switched to the first power supply mode.

12. A control device as described in any one of claims 9 to 11, wherein the processing circuit is configured to display information on an estimated time from when an instruction to switch from the second power mode to the first power mode is given until the activation process is completed within the second confirmation image.

13. A control device as described in any one of claims 9 to 12, wherein the processing circuit is configured to cause the display unit to display a first guide image during the activation process when the software update is performed using the first update procedure, and the processing circuit is configured to cause the display unit to display a second guide image, different from the first guide image, during the activation process when the software update is performed using the second update procedure.

14. The control device according to claim 13, wherein the processing circuit is configured to cause information indicating that the vehicle cannot be switched to the first power supply mode to be displayed within the first guidance image.

15. The control device according to claim 13 or 14, wherein the processing circuit is configured to cause information on an expected time until the vehicle can be switched to the first power supply mode to be displayed within the first guidance image.

16. The control device according to any one of claims 13 to 15, wherein the processing circuit is configured to display information on an expected time until completion of the activation process within the second guide image.

17. A control device as described in any one of claims 9 to 16, wherein the processing circuit is configured to cause the display unit to display a first completion notification image after completion of the activation process when the software update is performed by the first update procedure, and the processing circuit is configured to cause the display unit to display a second completion notification image different from the first completion notification image after completion of the activation process when the software update is performed by the second update procedure.

18. The control device according to claim 17, wherein the processing circuit is configured to cause information indicating that the vehicle can be switched to the first power supply mode to be displayed within the first completion notification image.

19. A control device as described in claim 17 or claim 18, wherein the processing circuit is configured to display information within the second completion notification image indicating that a restricted function of the in-vehicle equipment has become available as a result of the activation process being carried out.

20. A control device as described in any one of claims 9 to 19, wherein the in-vehicle device is one of a plurality of in-vehicle devices, one of the plurality of in-vehicle devices for which the software update is performed in the first update procedure is provided with a single-bank storage module in which updated software is installed in a storage area storing the pre-update software, and another of the plurality of in-vehicle devices for which the software update is performed in the second update procedure is provided with a dual-bank storage module in which updated software is installed in a storage area separate from the storage area storing the pre-update software.

21. A control device according to any one of claims 9 to 20, wherein a data communication module for communication outside the vehicle is the in-vehicle device in which the software update is performed in the second update procedure.

22. A control device according to any one of claims 9 to 21, wherein the advanced driver assistance system is the in-vehicle equipment for which the software update is performed in the second update procedure.

23. A control device according to any one of claims 9 to 22, wherein a power supply control unit of the vehicle is the in-vehicle device in which the software update is performed in the second update procedure.

24. A control device according to any one of claims 1 to 23, wherein the display unit is installed in the vehicle.

25. A control device as claimed in any one of claims 1 to 23, wherein the display unit is provided in an information terminal independent of the vehicle.

26. A control device as claimed in any one of claims 1 to 25, wherein the control device is a server device independent of the vehicle.

27. A vehicle equipped with a control device according to any one of claims 1 to 25.

28. A control method comprising: controlling a display unit that displays progress information of a software update of an in-vehicle device mounted on a vehicle configured to selectively switch to one of a plurality of power modes, the software update including an activation process that activates update software installed in the in-vehicle device; and, when the software update is performed by a first update procedure in which the activation process is performed in response to switching between the plurality of power modes in a first switching pattern, displaying a first confirmation image on the display unit before starting the activation process; and, when the software update is performed by a second update procedure in which the activation process is performed in response to switching between the plurality of power modes in a second switching pattern, displaying a second confirmation image on the display unit before starting the activation process, wherein the first switching pattern and the second switching pattern are different from each other, and the first confirmation image and the second confirmation image are different from each other.

29. A program which, when executed by a control device, causes the control device to execute the following: a control process for controlling a display unit that displays progress information of a software update of an in-vehicle device mounted on a vehicle configured to selectively switch to one of a plurality of power modes, the software update including an activation process for enabling update software installed in the in-vehicle device; a first display process for displaying a first confirmation image on the display unit before start of the activation process, if the software update is performed by a first update procedure in which the activation process is performed in response to switching between the plurality of power modes in a first switching pattern; and a second display process for displaying a second confirmation image on the display unit before start of the activation process, if the software update is performed by a second update procedure in which the activation process is performed in response to switching between the plurality of power modes in a second switching pattern; wherein the first switching pattern and the second switching pattern are different from each other, and the first confirmation image and the second confirmation image are different from each other.

Citation Information

Patent Citations

  • OTA master, update control method, update control program, and OTA center

    JP2022163396A

  • Electronic control device, electronic control system for vehicle, method for controlling execution of activation, and program for controlling execution of activation

    JP2020027632A

  • Electronic control device, method for controlling execution of rewriting, and program for controlling execution of rewriting

    JP2020027640A

  • Electronic control system for vehicle, and method and program for controlling execution of self holding of power source

    JP2020027643A

  • High voltage connector assembly and electric compressor include the same

    KR1020210004206A