Signal processing device, vehicle control device having same, and operation method thereof

The signal processing device addresses the inconvenience and safety concerns of vehicle software updates by using the OTA method and determining safe update times, ensuring efficient and safe software updates for vehicles.

WO2025127438A1PCT designated stage expired Publication Date: 2025-06-19LG ELECTRONICS INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/017885
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-14
Filing Date
2024-11-12
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing methods for updating vehicle software are inconvenient, particularly when they require moving the vehicle to a location with update equipment and can pose safety risks if performed while the vehicle is in operation or occupied.

Method used

A signal processing device that uses the Over The Air (OTA) method to download and update vehicle software, with a processor that determines whether the update can be safely performed while the vehicle is in operation or requires termination of vehicle operation to ensure safety conditions.

Benefits of technology

Enables software updates to be performed safely and efficiently, minimizing disruptions to vehicle operation and reducing the amount of data needed for updates, while ensuring that updates are only performed when it is safe to do so.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024017885_19062025_PF_FP_ABST
    Figure KR2024017885_19062025_PF_FP_ABST
Patent Text Reader

Abstract

A signal processing device according to one embodiment of the present disclosure includes a processor for processing data received from a server through an over-the-air (OTA) method, wherein the processor may: determine whether software to be updated on the basis of the data received from the server is predetermined software preconfigured to be updateable during driving of a vehicle; if the software to be updated is the predetermined software, update the software to be updated on the basis of the data received from the server; and determine whether a predetermined condition related to safety is satisfied when the driving of the vehicle is terminated if the software to be updated is not the predetermined software, and update the software to be updated in response to the predetermined condition being satisfied.
Need to check novelty before this filing date? Find Prior Art

Description

Signal processing device, vehicle control device having the same, and operating method thereof

[0001] The present disclosure relates to a signal processing device, a vehicle control device having the same, and an operating method thereof, and more specifically, to a signal processing device that acquires data and updates software using an OTA (Over The Air) method, a vehicle control device having the same, and an operating method thereof.

[0002] A vehicle is a device that moves its user in the desired direction. A typical example is an automobile. For the convenience of vehicle users, a vehicle signal processing unit is installed inside the vehicle. This vehicle signal processing unit can perform various services based on various sensor data from sensor devices or camera data from cameras.

[0003] Meanwhile, vehicles are equipped with various electronic devices, and software for their use is installed in the vehicle. This software may require updates, upgrades, reprogramming, or replacement to correct existing errors or upgrade to newer versions.

[0004] Previously, updating a vehicle's software required the vehicle to be transported to a location equipped with software update equipment, which was inconvenient. Furthermore, when users updated their vehicle's software themselves, they had to store the update data on an external device, connect the external device to the vehicle, and then run a program to update the vehicle's software.

[0005] Recently, various studies have been conducted on wirelessly updating vehicle software using the Over-The-Air (OTA) method to alleviate the inconvenience associated with software updates. Using OTA, the vehicle wirelessly downloads software update data from a server and uses the downloaded data to perform the software update.

[0006] When software updates are performed while a vehicle is in motion, safety issues arise due to software updates related to driving. Furthermore, even if software updates are performed while the vehicle is not in motion, if the user starts the vehicle and drives it during the update, follow-up processes for incomplete updates and downloaded data processing are required. Furthermore, if a software update is performed while occupants are present, vehicle functionality may be limited, preventing occupants from exiting the vehicle. Furthermore, there is a growing demand for ways to optimize the software update process, such as reducing the size of downloaded data using OTA methods or preventing repeated software updates.

[0007] The present disclosure aims to solve the above-mentioned and other problems.

[0008] Another purpose may be to provide a signal processing device capable of performing software updates while taking into account safety conditions during vehicle operation, a vehicle control device having the same, and an operating method thereof.

[0009] Another object may be to provide a signal processing device capable of performing an update to software by considering whether the operation of the vehicle is completely terminated, a vehicle control device having the same, and an operating method thereof.

[0010] Another purpose may be to provide a signal processing device capable of minimizing the amount of data downloaded wirelessly for software updates, a vehicle control device having the same, and an operating method thereof.

[0011] Another purpose may be to provide a signal processing device capable of updating software according to an optimized process, taking into account the condition of the vehicle, a vehicle control device having the same, and an operating method thereof.

[0012] A signal processing device according to one embodiment of the present disclosure includes a processor that processes data received from a server via an OTA (Over The Air) method, and the processor determines whether software that is a target of an update based on the data received from the server is predetermined software that is preset to be updated while a vehicle is in operation, and if the software that is a target of the update is the predetermined software, performs an update on the software that is a target of the update based on the data received from the server, and if the software that is a target of the update is not the predetermined software, determines whether a predetermined condition regarding safety is satisfied when the vehicle is terminated from operation, and performs an update on the software that is a target of the update in response to the satisfaction of the predetermined condition.

[0013] An operating method of a signal processing device according to one embodiment of the present disclosure may include an operation of determining whether software to be updated based on data received from a server via an OTA (Over The Air) method is predetermined software that is preset to be updated while a vehicle is in operation; an operation of performing an update on the software to be updated based on data received from the server when the software to be updated is the predetermined software; an operation of determining whether a predetermined condition regarding safety is satisfied when the vehicle is terminated when the software to be updated is not the predetermined software; and an operation of performing an update on the software to be updated in response to the satisfaction of the predetermined condition.

[0014] A vehicle control device according to one embodiment of the present disclosure includes a signal processing device having a communication unit that communicates with a server via an OTA (Over The Air) method, a memory that stores data received from the server, and a processor that processes the data received from the server, wherein the signal processing device determines whether software that is a target of an update based on the data received from the server is predetermined software that is set to be updateable while the vehicle is in operation, and if the software that is a target of the update is the predetermined software, performs an update on the software that is a target of the update based on the data received from the server, and if the software that is a target of the update is not the predetermined software, determines whether a predetermined condition regarding safety is satisfied when the vehicle is terminated, and performs an update on the software that is a target of the update in response to the satisfaction of the predetermined condition.

[0015] The effects of the signal processing device according to the present disclosure, the vehicle control device including the same, and the operating method thereof are described as follows.

[0016] According to at least one embodiment of the present disclosure, an update to software can be performed taking into account safety conditions during operation of a vehicle, thereby minimizing the impact on the operation of the vehicle.

[0017] According to at least one embodiment of the present disclosure, software updates can be performed while the vehicle is completely shut down, thereby enabling software updates to be performed more safely.

[0018] According to at least one embodiment of the present disclosure, the amount of data downloaded wirelessly for updates to software can be minimized.

[0019] According to at least one embodiment of the present disclosure, software can be updated according to an optimized process, taking into account the condition of the vehicle.

[0020] Figure 1 is a drawing showing an example of the exterior and interior of a vehicle.

[0021] FIGS. 2A to 2C are diagrams illustrating various architectures of a vehicle communication gateway according to an embodiment of the present disclosure.

[0022] Fig. 3 is an example of an internal block diagram of the signal processing device of Fig. 2a.

[0023] FIG. 4A is a drawing illustrating an example of the arrangement of a vehicle control device inside a vehicle according to an embodiment of the present disclosure.

[0024] FIG. 4b is a drawing illustrating another example of the arrangement of a vehicle control device inside a vehicle according to an embodiment of the present disclosure.

[0025] Fig. 5 is an example of an internal block diagram of the vehicle control device of Fig. 4b.

[0026] Figure 6 is an example of an internal block diagram of a vehicle communication device.

[0027] Fig. 7 is another example of an internal block diagram of a vehicle communication device.

[0028] Figures 8a to 8d are drawings showing various examples of vehicle communication devices.

[0029] FIG. 9A is a diagram illustrating an example of a vehicle communication device according to an embodiment of the present disclosure.

[0030] FIG. 9b is a diagram illustrating another example of a vehicle communication device according to an embodiment of the present disclosure.

[0031] FIGS. 10 to 12 are flowcharts showing the operation method of a signal processing device according to various embodiments of the present disclosure.

[0032] FIG. 13 is a diagram illustrating an example of a system according to an embodiment of the present disclosure.

[0033] FIG. 14a and FIG. 14b are flowcharts showing an operation method of a signal processing device according to one embodiment of the present disclosure.

[0034] Hereinafter, the present disclosure will be described in detail with reference to the drawings. In the drawings, portions irrelevant to the description are omitted to clearly and concisely describe the present disclosure, and the same reference numerals are used for identical or extremely similar portions throughout the specification.

[0035] The suffixes "module" and "part" used in the following description are given solely for the convenience of writing this specification and do not impart any particularly significant meaning or role to the components themselves. Therefore, the terms "module" and "part" may be used interchangeably.

[0036] In this application, it should be understood that terms such as “include” or “have” are intended to specify the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but do not preclude the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0037] Additionally, while terms such as "first" and "second" may be used in this specification to describe various elements, these elements are not limited by these terms. These terms are used only to distinguish one element from another.

[0038] Figure 1 is a drawing showing an example of the exterior and interior of a vehicle.

[0039] Referring to the drawing, the vehicle (200) is operated by a plurality of wheels (103FR, 103FL, 103RL, etc.) that rotate by a power source and a steering wheel (150) for controlling the direction of travel of the vehicle (200).

[0040] Meanwhile, the vehicle (200) may further be equipped with a camera (195) for capturing images of the front of the vehicle.

[0041] Meanwhile, the vehicle (200) may be equipped with multiple displays (180a, 180b) for displaying images, information, etc. inside.

[0042] In Fig. 1, a cluster display (180a) and an AVN (Audio Video Navigation) display (180b) are exemplified as multiple displays (180a, 180b). In addition, a HUD (Head Up Display) is also possible.

[0043] Meanwhile, the AVN (Audio Video Navigation) display (180b) may also be named a center information display.

[0044] Meanwhile, the vehicle (200) described in this specification may be a concept that includes all of a vehicle equipped with an engine as a power source, a hybrid vehicle equipped with an engine and an electric motor as a power source, and an electric vehicle equipped with an electric motor as a power source.

[0045] FIGS. 2A to 2C are diagrams illustrating various architectures of a vehicle communication gateway according to an embodiment of the present disclosure.

[0046] First, FIG. 2a is a diagram illustrating a first architecture of a vehicle communication gateway according to an embodiment of the present disclosure.

[0047] Referring to the drawing, the first architecture (300a) can correspond to a zone-based architecture.

[0048] Accordingly, sensor devices and processors inside the vehicle may be placed in each of the plurality of zones (Z1 to Z4), and a signal processing device (170a) including a vehicle communication gateway (GWDa) may be placed in the central area of ​​the plurality of zones (Z1 to Z4).

[0049] Meanwhile, the signal processing device (170a) may further include, in addition to the vehicle communication gateway (GWDa), an autonomous driving control module (ACC), a cockpit control module (CPG), etc.

[0050] The vehicle communication gateway (GWDa) within the signal processing device (170a) may be an HPC (High Performance Computing) gateway.

[0051] That is, the signal processing device (170a) of FIG. 2a is an integrated HPC and can exchange data with an external communication module (not shown) or a processor (not shown) within multiple zones (Z1 to Z4).

[0052] FIG. 2b is a diagram illustrating a second architecture of a vehicle communication gateway according to an embodiment of the present disclosure.

[0053] Referring to the drawing, the second architecture (300b) can correspond to a domain-integrated architecture.

[0054] Accordingly, a body chassis control module (BSG), a power control module (PTG), an ADAS control module (ADG), and a cockpit control module (CPG) are connected in parallel to the gateway (GWDb), and multiple processors (ECUs) can be electrically connected to each module (BSG, PTG, ADG, CPG).

[0055] Meanwhile, each processor (ECU) can be integrated and connected to a gateway (GWDb).

[0056] Meanwhile, the signal processing device (170) including the gateway (GWDb) of FIG. 2b operates as a domain-integrated signal processing device.

[0057] FIG. 2c is a diagram illustrating a third architecture of a vehicle communication gateway according to an embodiment of the present disclosure.

[0058] Referring to the drawing, the third architecture (300c) can correspond to a distributed architecture.

[0059] Accordingly, a body chassis control module (BSG), a power control module (PTG), an ADAS control module (ADG), and a cockpit control module (CPG) are connected in parallel to the gateway (GWDc), and in particular, multiple processors (ECUs) within each control module can be connected in parallel to the gateway (GWDb).

[0060] Compared to Fig. 2b, the third architecture differs in that each processor (ECU) is directly connected to the gateway (GWDb) without being connected to other modules.

[0061] Meanwhile, the signal processing device (170) including the gateway (GWDc) of FIG. 2c operates as a distributed signal processing device.

[0062] Fig. 3 is an example of an internal block diagram of the signal processing device of Fig. 2a.

[0063] Referring to the drawings, a signal processing device (170) according to an embodiment of the present disclosure includes a first processor (732a) that receives a first message including a sensor signal within a vehicle based on a first communication method and performs signal processing, and a second processor (732b) that receives a second message including a communication message received from the outside based on a second communication method and performs signal processing of the received second message.

[0064] At this time, the second communication method may have a faster communication speed or a larger bandwidth than the first communication method.

[0065] For example, the second communication method may be an Ethernet communication method, and the first communication method may be a CAN communication method. Accordingly, the first message may be a CAN message, and the second message may be an Ethernet message.

[0066] Meanwhile, the signal processing device (170) according to the embodiment of the present disclosure further includes a first memory (320) having an IPC channel and a second memory (330) storing sensor data including vehicle speed data.

[0067] For example, the first memory (320) may be SRAM (Static RAM), and the second memory (330) may be DDR memory. In particular, the second memory (330) may be DDR SDRAM (Double data rate synchronous dynamic random access memory).

[0068] Meanwhile, the signal processing device (170) according to the embodiment of the present disclosure includes a shared memory (508) that operates to transmit a first message or a second message between a first processor (732a) and a second processor (732b).

[0069] In this way, by performing inter-processor communication using shared memory (508) during communication between the first processor (732a) and the second processor (732b), it is possible to reduce delay time and perform high-speed data transmission during inter-processor communication. Data transmission can be performed.

[0070] Meanwhile, it is preferable that the shared memory (508) be provided within the first memory (320). Accordingly, it is possible to reduce delay time and perform high-speed data transmission during inter-processor communication.

[0071] Meanwhile, the first processor (732a) may have multiple processor cores (317o, 317a, 317b) inside.

[0072] Meanwhile, the first processor (732a) may further include an interface (319) for receiving CAN messages from external vehicle sensors.

[0073] For example, a first processor core (317o) within a first processor (732a) may execute multiple applications or execute a first AUTomotive Open System Architecture (AUTOSAR) (312).

[0074] In particular, the first processor core (317o) can execute the second auto-synchronization (312) to execute the interprocessor communication handler (IPC Handler) (314).

[0075] Meanwhile, the IPC Handler (314) can exchange data with the first memory (320) or exchange IPC data with an application running on the first processor core (317o).

[0076] Meanwhile, the IPC Handler (314) can exchange interrupts with the IPC driver (348) within the second processor (732b).

[0077] Meanwhile, the second processor core (317a) within the first processor (732a) can execute IDS and receive CAN data from the second memory (330).

[0078] Meanwhile, the third processor core (317b) within the first processor (732a) can execute logging and store CAN data received through the interface (319) in the second memory (330).

[0079] Meanwhile, the third processor core (317b) within the first processor (732a) can execute an interprocessor communication (IPC) module (318) to exchange IPC data with the first memory (320).

[0080] Meanwhile, the third processor core (317b) within the first processor (732a) can transmit an interrupt to the IPC driver (348) within the second processor (732b).

[0081] The first memory (320) can exchange IPC data with the IPC Handler (314) or the IPC module (318).

[0082] Meanwhile, the second processor (732b) can execute an application (343), an IPC handler (345), an IPC daemon (346), an IPC driver (348), etc.

[0083] Meanwhile, the second processor (732b) can further execute a service-oriented architecture (SOA) adapter (341), a diagnostic server (342), and a second auto-stor (347).

[0084] The second AUTOSAR (347) may be an adaptive AUTOSAR, and the first AUTOSAR (312) may be a classic AUTOSAR.

[0085] The IPC daemon (346) can exchange interrupt signals with the SOA adapter (341), diagnostic server (342), IPC handler (345), IPC driver (348), etc.

[0086] Meanwhile, the first memory (320) can exchange IPC data with a SOA adapter (341), a diagnostic server (342), an IPC handler (345), etc.

[0087] Meanwhile, the IPC data described in the description of FIG. 3 may be a CAN message or an Ethernet message.

[0088] Meanwhile, the IPC Handler (345) can operate as a Service Provider that provides data such as diagnosis, firmware upgrade, and system information based on the second auto-stor (347).

[0089] Meanwhile, although not shown in FIG. 3, the first processor (732a) can control a message router (not shown) to execute, and the message router can convert the frame of a first message, such as a CAN message, into a frame format of a second message, such as an Ethernet message, and transmit it to the second processor (732b).

[0090] Meanwhile, although not shown in FIG. 3, the first processor (732a) can further execute a CAN driver (not shown) and a CAN interface (not shown).

[0091] For example, the CAN interface (not shown) can be executed with 8 channels each in the 4th processor core (not shown) and the 5th processor core (not shown) within the 1st processor (732a), for a total of 16 channels.

[0092] At this time, the first CAN interface (not shown) running on the fourth processor core (not shown) corresponds to the first queue (PTb) (queue) during inter-processor communication, and the second CAN interface (not shown) running on the fifth processor core (not shown) corresponds to the second queue (PTa) having a higher priority than the first queue (PTb) during inter-processor communication.

[0093] FIG. 4A is a drawing illustrating an example of the arrangement of a vehicle control device inside a vehicle according to an embodiment of the present disclosure.

[0094] Referring to the drawing, the interior of the vehicle may be equipped with a cluster display (180a), an AVN (Audio Video Navigation) display (180b), a rear seat entertainment display (180c, 180d), a room mirror display (not shown), etc.

[0095] FIG. 4b is a drawing illustrating another example of the arrangement of a vehicle control device inside a vehicle according to an embodiment of the present disclosure.

[0096] A vehicle control device (100) according to an embodiment of the present disclosure may be equipped with a plurality of displays (180a to 180b) and a signal processing device (170) that performs signal processing for displaying images, information, etc. on the plurality of displays (180a to 180b).

[0097] Among the plurality of displays (180a to 180b), the first display (180a) may be a cluster display (180a) for displaying driving status, operation information, etc., and the second display (180b) may be an AVN (Audio Video Navigation) display (180b) for displaying vehicle driving information, a navigation map, various entertainment information, or images.

[0098] The signal processing device (170) has a processor (175) inside and can execute a first virtual machine to a third virtual machine (not shown) on a hypervisor (not shown) within the processor (175).

[0099] A second virtual machine (not shown) can operate for the first display (180a), and a third virtual machine (not shown) can operate for the second display (180b).

[0100] Meanwhile, the first virtual machine (not shown) within the processor (175) can control the shared memory (508) based on the hypervisor (505) to be set for the same data transmission to the second virtual machine (not shown) and the third virtual machine (not shown). Accordingly, the same information or the same image can be displayed in synchronization on the first display (180a) and the second display (180b) within the vehicle.

[0101] Meanwhile, the first virtual machine (not shown) within the processor (175) shares at least a portion of data with the second virtual machine (not shown) and the third virtual machine (not shown) for data sharing processing. Accordingly, data can be shared and processed among multiple virtual machines for multiple displays within the vehicle.

[0102] Meanwhile, a first virtual machine (not shown) within a processor (175) may receive and process vehicle wheel speed sensor data, and transmit the processed wheel speed sensor data to at least one of a second virtual machine (not shown) or a third virtual machine (not shown). Accordingly, the vehicle wheel speed sensor data may be shared with at least one virtual machine.

[0103] Meanwhile, the vehicle control device (100) according to the embodiment of the present disclosure may further include a rear seat entertainment display (180c) for displaying driving status information, simple navigation information, various entertainment information, or images.

[0104] The signal processing device (170) can control the RSE display (180c) by executing a fourth virtual machine (not shown) in addition to the first virtual machine to the third virtual machine (not shown) on a hypervisor (not shown) within the processor (175).

[0105] Accordingly, it is possible to control various displays (180a to 180c) using one signal processing device (170).

[0106] Meanwhile, some of the multiple displays (180a~180c) may operate under Linux OS, while others may operate under Web OS.

[0107] The signal processing device (170) according to the embodiment of the present disclosure can control the display (180a to 180c) operating under various operating systems (OS) to display the same information or the same image in synchronization.

[0108] Meanwhile, in FIG. 4b, a vehicle speed indicator (212a) and a vehicle interior temperature indicator (213a) are displayed on a first display (180a), a home screen (222) including a plurality of applications and a vehicle speed indicator (212b) and a vehicle interior temperature indicator (213b) are displayed on a second display (180b), and a second home screen (222b) including a plurality of applications and a vehicle interior temperature indicator (213c) are displayed on a third display (180c).

[0109] Fig. 5 is an example of an internal block diagram of the vehicle control device of Fig. 4b.

[0110] Referring to the drawings, a vehicle control device (100) according to an embodiment of the present disclosure may include an input unit (110), a communication unit (120) for communication with an external device, a plurality of communication modules (EMa to EMd) for internal communication, a memory (140), a signal processing unit (170), a plurality of displays (180a to 180c), an audio output unit (185), and a power supply unit (190).

[0111] A plurality of communication modules (EMa to EMd) can be arranged, for example, in a plurality of zones (Z1 to Z4) of FIG. 2a, respectively.

[0112] Meanwhile, the signal processing device (170) may be equipped with an Ethernet switch (736b) for data communication with each communication module (EM1 to EM4) inside.

[0113] Each communication module (EM1 to EM4) can perform data communication with multiple sensor devices (SN) or ECUs (770).

[0114] Meanwhile, the plurality of sensor devices (SN) may include a camera (195), a lidar (196), a radar (197), or a position sensor (198).

[0115] The input unit (110) may be equipped with physical buttons, pads, etc. for button input, touch input, etc.

[0116] Meanwhile, the input unit (110) may be equipped with a microphone (not shown) for user voice input.

[0117] The communication unit (120) can exchange data wirelessly with a mobile terminal (500) or server (400).

[0118] In particular, the communication unit (120) can wirelessly exchange data with the vehicle driver's mobile terminal. Various data communication methods are possible, such as Bluetooth, WiFi, WiFi Direct, and APiX.

[0119] The communication unit (120) can receive weather information, road traffic information, for example, TPEG (Transport Protocol Expert Group) information, from a mobile terminal (500) or a server (400). To this end, the communication unit (120) may be equipped with a mobile communication module (not shown).

[0120] A plurality of communication modules (EM1 to EM4) can receive sensor data, etc. from an ECU (770) or a sensor device (SN) and transmit the received sensor data to a signal processing device (170).

[0121] Here, the sensor data may include at least one of vehicle direction data, vehicle location data (GPS data), vehicle angle data, vehicle speed data, vehicle acceleration data, vehicle inclination data, vehicle forward / backward data, battery data, fuel data, tire data, vehicle lamp data, vehicle interior temperature data, and vehicle interior humidity data.

[0122] Such sensor data can be obtained from a heading sensor, a yaw sensor, a gyro sensor, a position module, a vehicle forward / backward sensor, a wheel sensor, a vehicle speed sensor, a body tilt detection sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor by steering wheel rotation, a vehicle interior temperature sensor, a vehicle interior humidity sensor, etc.

[0123] Meanwhile, the position module may include a GPS module or a position sensor (198) for receiving GPS information.

[0124] Meanwhile, at least one of the plurality of communication modules (EM1 to EM4) can transmit location information data sensed by a GPS module or location sensor (198) to a signal processing device (170).

[0125] Meanwhile, at least one of the plurality of communication modules (EM1 to EM4) can receive vehicle front image data, vehicle side image data, vehicle rear image data, vehicle surrounding obstacle distance information, etc. from a camera (195), lidar (196), radar (197), etc., and transmit the received information to a signal processing device (170).

[0126] The memory (140) can store various data for the overall operation of the vehicle control device (100), such as a program for processing or controlling the signal processing device (170).

[0127] For example, the memory (140) may store data regarding a hypervisor, a first virtual machine, a third virtual machine, or the like, for execution within the processor (175).

[0128] The audio output unit (185) converts an electric signal from the signal processing device (170) into an audio signal and outputs it. For this purpose, a speaker or the like may be provided.

[0129] The power supply unit (190) can supply power required for the operation of each component under the control of the signal processing unit (170). In particular, the power supply unit (190) can receive power from a battery inside the vehicle, etc.

[0130] The signal processing device (170) controls the overall operation of each unit in the vehicle control device (100).

[0131] For example, the signal processing device (170) may include a processor (175) that performs signal processing for a vehicle display (180a, 180b).

[0132] The processor (175) can execute a first virtual machine to a third virtual machine (not shown) on a hypervisor (not shown) within the processor (175).

[0133] Among the first virtual machine to the third virtual machine (not shown), the first virtual machine (not shown) may be named a server virtual machine (Server Virtual Maschine), and the second virtual machine to the third virtual machine (not shown) may be named a guest virtual machine (Guest Virtual Maschine).

[0134] For example, a first virtual machine (not shown) within a processor (175) may receive, process, or output sensor data from a plurality of sensor devices, such as vehicle sensor data, location information data, camera image data, audio data, or touch input data.

[0135] In this way, by performing most of the data processing in the first virtual machine (not shown), data sharing in a 1:N manner becomes possible.

[0136] As another example, a first virtual machine (not shown) can directly receive and process CAN data, Ethernet data, audio data, radio data, USB data, and wireless communication data for a second virtual machine or a third virtual machine (not shown).

[0137] And, the first virtual machine (not shown) can transmit processed data to the second virtual machine or the third virtual machine (not shown).

[0138] Accordingly, among the first virtual machine to the third virtual machine (not shown), only the first virtual machine (not shown) receives sensor data, communication data, or external input data from multiple sensor devices and performs signal processing, thereby reducing the signal processing burden on other virtual machines, enabling 1:N data communication, and enabling synchronization when sharing data.

[0139] Meanwhile, the first virtual machine (not shown) can control the second virtual machine (not shown) and the third virtual machine (not shown) to share the same data by writing data to the shared memory (508).

[0140] For example, a first virtual machine (not shown) can record vehicle sensor data, the location information data, the camera image data, or the touch input data in shared memory (508) and control the same data to be shared with a second virtual machine (not shown) and a third virtual machine (not shown). Accordingly, data sharing in a 1:N manner becomes possible.

[0141] Ultimately, by performing most of the data processing on the first virtual machine (not shown), data sharing in a 1:N manner becomes possible.

[0142] Meanwhile, the first virtual machine (not shown) within the processor (175) can control the shared memory (508) based on the hypervisor (505) to be set for the same data transmission to the second virtual machine (not shown) and the third virtual machine (not shown).

[0143] Meanwhile, the signal processing device (170) can process various signals such as audio signals, video signals, and data signals. To this end, the signal processing device (170) can be implemented in the form of a system on chip (SOC).

[0144] Meanwhile, the signal processing device (170) in the display device (100) of FIG. 5 may be the same as the signal processing device (170) of the vehicle communication device (700) of FIG. 7, etc.

[0145] Figure 6 is an example of an internal block diagram of a vehicle communication device.

[0146] Referring to the drawing, a vehicle communication device (600x) related to the present disclosure includes a first communication gateway (630a) and a second communication gateway (630b).

[0147] The first communication gateway (630a) may include a CAN transceiver (636a) for exchanging CAN signals through CAN communication with a body module (610), a chassis module (614), a CAN communication diagnostic device (616), at least one CAN communication ECU (618), etc., and a first processor (632a) for signal processing a CAN signal received from the CAN transceiver (636a).

[0148] Meanwhile, the first processor (632a) may be equipped with an IPC manager (634a) for performing inter-processor communication with the second processor (632b) within the second communication gateway (630b).

[0149] The second communication gateway (630b) may include an Ethernet switch (636b) for exchanging Ethernet messages through Ethernet communication with a telematics control module (620), a head module (622), an Ethernet communication diagnostic device (624), at least one Ethernet communication ECU (626), and a second processor (632b) for signal processing an Ethernet message received from the Ethernet switch (636b).

[0150] Meanwhile, the second processor (632b) may be equipped with an IPC manager (634b) for performing inter-processor communication with the first processor (632a) within the first communication gateway (630a).

[0151] Meanwhile, the IPC manager (634a) within the first processor (632a) and the IPC manager (634b) within the second processor (632b) can perform inter-processor communication based on Ethernet communication.

[0152] According to this method, interprocessor communication is advantageous for high-speed transmission of large amounts of data using Ethernet-based high bandwidth, but has the disadvantage of causing latency in communication between protocol stacks and physical layers (PHY).

[0153] Accordingly, this disclosure proposes a method for reducing latency and achieving high-speed data transmission during inter-processor communication. This is described with reference to FIG. 7 and below.

[0154] Fig. 7 is another example of an internal block diagram of a vehicle communication device.

[0155] Referring to the drawings, a vehicle communication device (700) according to an embodiment of the present disclosure includes a first communication gateway (730a), a second communication gateway (730b), a first processor (732a) that receives a first message including a sensor signal within a vehicle based on a first communication method and performs signal processing, a second processor (732b) that receives a second message including a communication message received from the outside based on a second communication method and performs signal processing of the received second message, and a shared memory (508) that operates to transmit the first message or the second message between the first processor (732a) and the second processor (732b).

[0156] Compared to the communication device (600x) of FIG. 6, by using shared memory (508) for inter-processor communication (IPC) between the first processor (732a) and the second processor (732b), the latency during inter-processor communication is reduced, and high-speed data transmission can be performed.

[0157] In addition, compared to the communication device (600x) of FIG. 6, by implementing the first processor (732a), the second processor (732b), and the shared memory (508) as one signal processing device (170) as one chip, the latency during inter-processor communication is reduced, and high-speed data transmission can be performed.

[0158] Meanwhile, it is desirable that the second communication method have a larger bandwidth and a faster transmission speed than the first communication method.

[0159] For example, the second communication method may be an Ethernet communication method, and the first communication method may be a CAN communication method. Accordingly, the first message may be a CAN message or a CAN signal, and the second message may be an Ethernet message.

[0160] Meanwhile, a signal processing device (170) and a vehicle communication device (700) including the same according to one embodiment of the present disclosure may further include a transceiver (736a) that receives a first message including a sensor signal within the vehicle based on a first communication method and transmits the first message to a first processor (732a), and a switch (736b) that receives a second message including a communication message received from the outside based on a second communication method and transmits the second message to a second processor (732b). Accordingly, the first message and the second message can be stably transmitted to the first processor (732a) and the second processor (732b), respectively.

[0161] The first processor (732a) or transceiver (736a) can exchange CAN signals through CAN communication with a body module (610), a chassis module (614), a CAN communication diagnostic device (616), at least one CAN communication ECU (618), etc.

[0162] Meanwhile, the first processor (732a) may be equipped with a first manager (734a) for inter-processor communication (IPC) with the second processor (732b). The first manager (734a) may also be referred to as an IPC manager.

[0163] Meanwhile, the first manager (734a) may include a first cache (735a).

[0164] Meanwhile, the second processor (732b) or switch (736b) can exchange Ethernet messages through Ethernet communication with a telematics control module (620), a head module (622), an Ethernet communication diagnostic device (624), at least one Ethernet communication ECU (626), etc. The switch (736b) may also be referred to as an Ethernet switch.

[0165] Meanwhile, the second processor (732b) may be equipped with a second manager (734b) for inter-processor communication (IPC) with the first processor (732a). The second manager (734b) may also be referred to as an IPC manager.

[0166] Meanwhile, the second manager (734b) may include a second cache (735b) and a timer (737).

[0167] Meanwhile, the second processor (732b) can receive a periodic subscription request for the first message from the Ethernet processor or Ethernet communication ECU (626).

[0168] Accordingly, the second processor (732b) can transmit a periodic subscription request for the first message to the first processor (732a).

[0169] In particular, the second processor (732b) can transmit a subscription request via interprocessor communication (IPC). Accordingly, interprocessor communication can be performed.

[0170] Meanwhile, the first processor (732a) periodically receives CAN communication data from at least one CAN communication ECU (618).

[0171] For example, the first processor (732a) periodically receives a first message predefined in a CAN database (DB) from at least one CAN communication ECU (618).

[0172] For example, the periodic first message may include sensor data such as vehicle speed information or location information.

[0173] As another example, the periodic first message may include at least one of vehicle direction information, vehicle location information (GPS information), vehicle angle information, vehicle acceleration information, vehicle tilt information, vehicle forward / backward information, battery information, fuel information, tire information, vehicle lamp information, vehicle interior temperature information, and vehicle interior humidity information.

[0174] Meanwhile, the first processor (732a) can select a first message for which a subscription request has been received from among the CAN communication data or first messages that are periodically received, and transmit the first message for which a subscription request has been received to the second processor (732b) through inter-processor communication.

[0175] Meanwhile, the first processor (732a) separately processes the first message that has not received a subscription request among the periodically received CAN communication data or first messages according to its internal operation and does not transmit it to the second processor (732b).

[0176] Specifically, the first processor (732a) stores or manages a first message for which a subscription request has been received in the first cache (735a), and when the first message is received, compares the value stored in the first cache (735a), and if the difference is greater than a predetermined value, transmits the first message to the second processor (732b) through inter-processor communication.

[0177] Meanwhile, the first processor (732a) stores or manages the first message for which a subscription request has been received in the first cache (735a), and when the first message is received, compares it with the value stored in the first cache (735a), and if the difference is greater than a predetermined value, transmits the first message to the second processor (732b) through inter-processor communication using the shared memory (508).

[0178] For example, when receiving a first message, the first processor (732a) can compare the value stored in the first cache (735a) and, if they are not the same, transmit the first message to the second processor (732b) through inter-processor communication using the shared memory (508).

[0179] As another example, when receiving a first message, the first processor (732a) may compare the values ​​stored in the first cache (735a) and, if they are the same, may not transmit the first message to the second processor (732b).

[0180] Accordingly, by minimizing cache or buffer occupancy of identical data, delays during interprocessor communication can be reduced and high-speed data transfers can be achieved. Accordingly, by minimizing cache or buffer occupancy of identical data, delays during interprocessor communication can be reduced and high-speed data transfers can be achieved.

[0181] Meanwhile, the second processor (732b) can store the first message in the second cache (735b) upon first reception of the first message, and update the second cache (735b) upon subsequent reception of the first message. Accordingly, delay time can be reduced and high-speed data transmission can be achieved during inter-processor communication.

[0182] Meanwhile, the second processor (732b) can create a thread of the timer (737) upon receipt of the first message, and transfer the value of the second cache (735b) to the Ethernet processor or Ethernet communication ECU (626) upon expiration of the thread. Accordingly, it is possible to reduce delay time and perform high-speed data transmission during inter-processor communication.

[0183] Meanwhile, the second processor (732b) can transfer the value of the second cache (735b) to the Ethernet processor or Ethernet communication ECU (626) during a period in which inter-processor communication is not performed and the first message is not received.

[0184] That is, if the value of the subscribed first message does not change within the cycle, the cache value stored in the second processor (732b) can be transferred to the Ethernet processor (626) without inter-processor communication.

[0185] Accordingly, the use of the IPC buffer within the shared memory (508) operated as a FIFO can be minimized. In addition, by keeping the use of the IPC buffer to a minimum, data such as the first message or the second message can be quickly transmitted through interprocessor communication.

[0186] Meanwhile, the second processor (732b) can transmit the updated value in the second cache (735b) to the Ethernet processor or Ethernet communication ECU (626) during the period in which inter-processor communication is performed and the first message is received. Accordingly, it is possible to reduce delay time and perform high-speed data transmission during inter-processor communication.

[0187] Meanwhile, the shared memory (508) can transmit data between the first processor (732a) and the second processor (732b) through the first queue (PTb) and the second queue (PTa) having a higher priority than the first queue (PTb) during inter-processor communication.

[0188] In particular, the shared memory (508) can ensure that only data corresponding to events allocated for the second queue (PTa) are transmitted through the second queue (PTa), even if the number of events for inter-processor communication increases. Accordingly, real-time transmission of high-priority events in inter-processor communication can be guaranteed.

[0189] For example, the first queue (PTb) may be a normal priority queue, and the second queue (PTa) may be a high priority queue.

[0190] Specifically, the shared memory (508) can transmit most of the data through the first queue (PTb) during inter-processor communication.

[0191] However, the shared memory (508) can transmit only time-sensitive and important data without delay through the second queue (PTa) with a higher priority than the first queue (PTb).

[0192] For example, time sensitive-critical data may be speed data or location information data.

[0193] That is, the shared memory (508) can transmit speed data or position information data between the first processor (732a) and the second processor (732b) via the second queue (PTa). Accordingly, real-time transmission of high-priority speed data or position information data can be guaranteed in inter-processor communication.

[0194] Meanwhile, the first processor (732a) or the second processor (732b) can manage a list including applications that can use the second queue (PTa).

[0195] For example, the second processor (732b) can manage an application for displaying speed information by including it in the second list (738b) as an application that can utilize the second queue (PTa).

[0196] Meanwhile, for real-time data transmission using the second queue (PTa), it is desirable to control the scenarios or applications to operate to a minimum so as not to overlap.

[0197] In this way, by performing real-time data transmission using the second queue (PTa) for time-sensitive and important data, real-time transmission of high-priority events in inter-processor communication can be guaranteed.

[0198] Meanwhile, shared memory (508) can reduce delay time in inter-processor communication and perform high-speed data transmission by allocating at least two queues.

[0199] The drawing illustrates that a first manager (734a) within a first processor (732a) manages a first list (738a), which is a white list, and a second manager (734b) within a second processor (732b) manages a second list (738b), which is a white list. Accordingly, real-time transmission of high-priority events can be guaranteed in inter-processor communication.

[0200] Figures 8a to 8d are drawings showing various examples of vehicle communication devices.

[0201] FIG. 8A illustrates an example of a vehicle communication device according to an embodiment of the present disclosure.

[0202] Referring to the drawing, a vehicle communication device (800a) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0203] Meanwhile, in the drawing, two signal processing devices (170a1, 170a2) are exemplified, but this is for backup purposes, etc., and one is also possible.

[0204] Meanwhile, the signal processing device (170a1, 170a2) may also be named an HPC (High Performance Computing) signal processing device.

[0205] Multiple area signal processing devices (170Z1 to 170Z4) are arranged in each area (Z1 to Z4) and can transmit sensor data to signal processing devices (170a1, 170a2).

[0206] The signal processing device (170a1, 170a2) receives data via wire from multiple area signal processing devices (170Z1 to 170Z4) or a communication device (120).

[0207] In the drawing, data is exchanged based on wired communication between a signal processing device (170a1, 170a2) and multiple area signal processing devices (170Z1 to 170Z4), and the signal processing device (170a1, 170a2) and the server (400) exchange data based on wireless communication. However, data may be exchanged based on wireless communication between a communication device (120) and a server (400), and the signal processing device (170a1, 170a2) and the communication device (120) may exchange data based on wired communication.

[0208] Meanwhile, data received by the signal processing device (170a1, 170a2) may include camera data or sensor data.

[0209] For example, sensor data within a vehicle may include at least one of vehicle wheel speed data, vehicle direction data, vehicle location data (GPS data), vehicle angle data, vehicle speed data, vehicle acceleration data, vehicle inclination data, vehicle forward / backward data, battery data, fuel data, tire data, vehicle lamp data, vehicle interior temperature data, vehicle interior humidity data, vehicle exterior radar data, and vehicle exterior lidar data.

[0210] Meanwhile, camera data may include vehicle exterior camera data and vehicle interior camera data.

[0211] Meanwhile, the signal processing device (170a1, 170a2) can execute multiple virtual machines (820, 830, 840) based on safety standards.

[0212] In the drawing, it is illustrated that a processor (175) in a signal processing device (170a) executes a hypervisor (505) and, on the hypervisor (505), executes first to third virtual machines (820 to 840) according to the automotive safety integrity level (Automotive SIL; ASIL).

[0213] The first virtual machine (820) may be a virtual machine corresponding to Quality Management (QM), which is the lowest safety level in the Automotive Safety Integrity Level (ASIL) and is a non-enforceable level.

[0214] The first virtual machine (820) can execute an operating system (822), a container runtime (824) on the operating system (822), and containers (827, 829) on the container runtime (824).

[0215] The second virtual machine (830) may be a virtual machine corresponding to ASIL A or ASIL B, in which the sum of severity, exposure, and controllability is 7 or 8 in the automotive safety integrity level (ASIL).

[0216] The second virtual machine (830) can execute an operating system (832), a container runtime (834) on the operating system (832), and containers (837, 839) on the container runtime (834).

[0217] The third virtual machine (840) may be a virtual machine corresponding to ASIL C or ASIL D, in which the sum of severity, exposure, and controllability is 9 or 10 in the automotive safety integrity level (ASIL).

[0218] Meanwhile, ASIL D can correspond to the grade that requires the highest safety level.

[0219] The third virtual machine (840) can run a safety operating system (842) and an application (845) on the operating system (842).

[0220] Meanwhile, the third virtual machine (840) may also execute a safety operating system (842), a container runtime (844) on the safety operating system (842), and a container (847) on the container runtime (844).

[0221] Meanwhile, unlike the drawing, the third virtual machine (840) can also be executed through a separate core rather than the processor (175). This will be described later with reference to FIG. 8b.

[0222] Meanwhile, the processor (175) executing the first to third virtual machines (820 to 840) may correspond to the second processor (732b) of FIG. 7.

[0223] FIG. 8b illustrates another example of a vehicle communication device according to an embodiment of the present disclosure.

[0224] Referring to the drawing, a vehicle communication device (800b) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0225] The vehicle communication device (800b) of FIG. 8b is similar to the vehicle communication device (800a) of FIG. 8a, but the signal processing device (170a1) has some differences from the signal processing device (170a1) of FIG. 8a.

[0226] To describe the difference, the signal processing device (170a1) may include a processor (175) and a second processor (177).

[0227] The processor (175) within the signal processing device (170a1) executes a hypervisor (505), and executes first and second virtual machines (820 to 830) on the hypervisor (505) according to the automotive safety integrity level (Automotive SIL; ASIL).

[0228] The first virtual machine (820) can execute an operating system (822), a container runtime (824) on the operating system (822), and containers (827, 829) on the container runtime (824).

[0229] The second virtual machine (830) can execute an operating system (832), a container runtime (834) on the operating system (832), and containers (837, 839) on the container runtime (834).

[0230] Meanwhile, the second processor (177) in the signal processing device (170a1) can execute the third virtual machine (840).

[0231] The third virtual machine (840) can execute a safety operating system (842), an auto-execution (845) on the operating system (842), and an application (845) on the auto-execution (845). That is, unlike FIG. 8A, an auto-execution (846) on the operating system (842) can be executed.

[0232] Meanwhile, the third virtual machine (840) may, similarly to FIG. 8a, execute a safety operating system (842), a container runtime (844) on the safety operating system (842), and a container (847) on the container runtime (844).

[0233] Meanwhile, the third virtual machine (840) requiring a high level of security is preferably executed on a second processor (177), which is a different core or different processor, unlike the first and second virtual machines (820 to 830).

[0234] Meanwhile, the processor (175) executing the first and second virtual machines (820 to 830) may correspond to the second processor (732b) of FIG. 7, and the second processor (177) executing the third virtual machine (840) may correspond to the first processor (732a) of FIG. 7.

[0235] Meanwhile, in the signal processing devices (170a1, 170a2) of FIGS. 8a and 8b, when the first signal processing device (170a) malfunctions, the second signal processing device (170a2), which is a backup device, can operate.

[0236] Alternatively, it is also possible for the signal processing devices (170a1, 170a2) to operate simultaneously, with the first signal processing device (170a) operating as the main device and the second signal processing device (170a2) operating as the sub device. This will be described with reference to FIGS. 8c and 8d.

[0237] FIG. 8c illustrates another example of a vehicle communication device according to an embodiment of the present disclosure.

[0238] Referring to the drawing, a vehicle communication device (800c) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0239] Meanwhile, in the drawing, two signal processing devices (170a1, 170a2) are exemplified, but this is for backup purposes, etc., and one is also possible.

[0240] Meanwhile, the signal processing device (170a1, 170a2) may also be named an HPC (High Performance Computing) signal processing device.

[0241] Multiple area signal processing devices (170Z1 to 170Z4) are arranged in each area (Z1 to Z4) and can transmit sensor data to signal processing devices (170a1, 170a2).

[0242] The signal processing device (170a1, 170a2) receives data via wire from multiple area signal processing devices (170Z1 to 170Z4) or a communication device (120).

[0243] In the drawing, data is exchanged based on wired communication between a signal processing device (170a1, 170a2) and multiple area signal processing devices (170Z1 to 170Z4), and the signal processing device (170a1, 170a2) and the server (400) exchange data based on wireless communication. However, data may be exchanged based on wireless communication between a communication device (120) and a server (400), and the signal processing device (170a1, 170a2) and the communication device (120) may exchange data based on wired communication.

[0244] Meanwhile, data received by the signal processing device (170a1, 170a2) may include camera data or sensor data.

[0245] Meanwhile, among the signal processing devices (170a1, 170a2), the processor (175) in the first signal processing device (170a1) executes a hypervisor (505) and can execute a safety virtualization machine (860) and a non-safety virtualization machine (870) on the hypervisor (505).

[0246] Meanwhile, among the signal processing devices (170a1, 170a2), the processor (17b5) in the second signal processing device (170a2) executes the hypervisor (505b) and can execute only the safety virtualization machine (880) on the hypervisor (505).

[0247] In this way, since the processing for safety is separated between the first signal processing device (170a1) and the second signal processing device (170a2), it is possible to improve stability and processing speed.

[0248] Meanwhile, high-speed network communication can be performed between the first signal processing device (170a1) and the second signal processing device (170a2).

[0249] FIG. 8d illustrates another example of a vehicle communication device according to an embodiment of the present disclosure.

[0250] Referring to the drawing, a vehicle communication device (800d) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0251] The vehicle communication device (800d) of FIG. 8d is similar to the vehicle communication device (800c) of FIG. 8c, but the second signal processing device (170a2) has some differences from the second signal processing device (170a2) of FIG. 8c.

[0252] The processor (17b5) in the second signal processing device (170a2) of FIG. 8d executes a hypervisor (505b) and can execute a safety virtualization machine (880) and a non-safety virtualization machine (890) on the hypervisor (505).

[0253] That is, unlike FIG. 8c, the difference is that the processor (17b5) within the second signal processing device (170a2) further executes a non-safety virtual machine (890).

[0254] In this way, since the processing for safety and non-safety is separated between the first signal processing device (170a1) and the second signal processing device (170a2), it is possible to improve stability and processing speed.

[0255] FIG. 9A is a diagram illustrating an example of a vehicle communication device according to an embodiment of the present disclosure.

[0256] Referring to the drawing, a vehicle communication device (900) according to an embodiment of the present disclosure includes a plurality of area signal processing devices (170Z1 to 170Z4) and a signal processing device (170).

[0257] The signal processing device (170) at this time may be called an HPC (High Performance Computing) signal processing device or a central signal processing device.

[0258] The multiple area signal processing devices (170Z1 to 170Z4) and the signal processing device (170) are connected by wired cables (CB1 to CB4).

[0259] Meanwhile, multiple area signal processing devices (170Z1 to 170Z4) are connected to each other by wired cables (CBa to CBd).

[0260] Meanwhile, a storage device (925 in FIG. 9b) is provided in the signal processing device (170) according to the embodiment of the present disclosure.

[0261] Meanwhile, when sensor data is transmitted from at least one of the multiple area signal processing devices (170Z1 to 170Z4) to the signal processing device (170), it is preferable that multi-path routing be performed to prevent a network bottleneck from occurring.

[0262] Specifically, since the data read or write speed to the storage device (925 in FIG. 9b) is faster than the network speed when sensor data is transmitted from at least one of the plurality of area signal processing devices (170Z1 to 170Z4) to the signal processing device (170), it is preferable that multi-path routing be performed so that a network bottleneck does not occur.

[0263] To this end, the signal processing device (170) according to the embodiment of the present disclosure performs multi-path routing based on a Software Defined Network (SDN). Accordingly, a stable network environment can be secured when reading or writing data from a storage device (925).

[0264] FIG. 9b is a diagram illustrating another example of a vehicle communication device according to an embodiment of the present disclosure.

[0265] Referring to the drawing, a vehicle communication device (900b) according to an embodiment of the present disclosure includes a plurality of area signal processing devices (170Z1 to 170Z4) and a signal processing device (170).

[0266] The multiple area signal processing devices (170Z1 to 170Z4) and the signal processing device (170) are connected by wired cables (CB1 to CB4).

[0267] Meanwhile, multiple area signal processing devices (170Z1 to 170Z4) can be connected to each other with wired cables (CBa to CBd).

[0268] Meanwhile, a signal processing device (170) according to one embodiment of the present disclosure includes a network controller (915) that controls multi-path routing for at least one of a plurality of area signal processing devices (170Z1 to 170Z4), and a storage device (925) that stores data received through multi-path routing.

[0269] A signal processing device (170) according to one embodiment of the present disclosure may further include a storage device controller (920) that controls a storage device (925).

[0270] Since the data read speed or write speed to the storage device (925) is faster than the network speed when sensor data is transmitted from at least one of the plurality of area signal processing devices (170Z1 to 170Z4) to the signal processing device (170), it is preferable that multi-path routing be performed so that a network bottleneck does not occur.

[0271] Meanwhile, the network controller (915) receives a part of the sensor data from the first area signal processing device (170Z1) among the plurality of area signal processing devices (170Z1 to 170Z4) from the first area signal processing device (170Z1), and controls another part of the sensor data to be received through or directly from at least one area signal processing device (170Z1 to 170Z4) other than the first area signal processing device (170Z1).

[0272] Accordingly, a stable network environment can be secured when reading or writing data from the storage device (925). Furthermore, data can be transmitted to the storage device (925) using multiple paths. Meanwhile, data can be transmitted by dynamically changing the network configuration.

[0273] The sensor data at this time may include at least one of camera data, lidar data, radar data, vehicle direction data, vehicle location data (GPS data), vehicle angle data, vehicle speed data, vehicle acceleration data, vehicle inclination data, vehicle forward / backward data, battery data, fuel data, tire data, vehicle lamp data, vehicle interior temperature data, and vehicle interior humidity data.

[0274] In the drawing, it is exemplified that camera data from a camera (195a) and lidar data from a lidar sensor (196) are input to a first area signal processing device (170Z1), and that the camera data and lidar data are transmitted to a signal processing device (170) via a second area signal processing device (170Z2), a third area signal processing device (170Z3), etc.

[0275] Meanwhile, the network controller (915) can control data that is not time-critical among the sensor data from the first area signal processing device (170Z1) to be received directly from the first area signal processing device (170Z1).

[0276] In the drawing, it is exemplified that non-time critical data, which is not time critical data among the sensor data from the first area signal processing device (170Z1), is directly received from the first area signal processing device (170Z1) to the signal processing device (170).

[0277] Meanwhile, the network controller (915) can control time-critical data among sensor data from the first area signal processing device (170Z1) to be received through or directly by at least one area signal processing device (170Z1 to 170Z4) other than the first area signal processing device (170Z1).

[0278] In the drawing, it is exemplified that some of the time-critical data among the sensor data from the first area signal processing device (170Z1) is transmitted to the signal processing device (170) via the second signal processing device (170Z2), other of the time-critical data among the sensor data from the first area signal processing device (170Z1) is transmitted to the signal processing device (170) via the third signal processing device (170Z3), and still other of the time-critical data is directly received by the signal processing device (170).

[0279] At this time, the network controller (915) can set the network speed or bandwidth of the path passing through at least one area signal processing device (170Z1 to 170Z4) other than the first area signal processing device (170Z1) to be greater than the network speed or bandwidth of the path directly transmitted to the signal processing device (170).

[0280] Accordingly, a stable network environment can be secured when reading or writing data from the storage device (925). Furthermore, data can be transmitted to the storage device (925) using multiple paths.

[0281] Meanwhile, the storage device controller (920) can control both time critical data and non-time critical data received through the network controller (915) to be stored in the storage device (925).

[0282] Meanwhile, the network controller (915) can monitor the network topology with multiple area signal processing devices (170Z1 to 170Z4) and, based on the monitoring, perform bandwidth distribution and path setting for multi-path routing.

[0283] Meanwhile, the network controller (915) can set the bandwidth based on the path capacity when setting the path for multi-path routing.

[0284] Meanwhile, the network controller (915) can perform multi-path routing based on a software defined network (SDN).

[0285] Meanwhile, the network controller (915) does not perform path re-search during multi-path routing. Accordingly, a stable network environment can be secured when reading or writing data from the storage device (925).

[0286] Meanwhile, various services executed within the vehicle's multiple area signal processing devices (170Z1 to 170Z4) or signal processing device (170) may be forged or altered due to external attacks, etc.

[0287] FIGS. 10 to 12 are flowcharts illustrating an operating method of a signal processing device according to various embodiments of the present disclosure. Detailed descriptions of overlapping content with respect to FIGS. 10 to 12 will be omitted. Hereinafter, software may be interpreted as including a system, configuration, firmware, etc. of a vehicle (200). Meanwhile, in the present disclosure, the signal processing device (170) and the server (400) will be described based on wireless communication using the OTA (Over The Air) method. The signal processing device (170) may also include an OTA update manager that controls operations using the OTA method.

[0288] Referring to FIG. 10, the signal processing device (170) can, in operation S1001, check whether an update to the system of the vehicle (200) is incomplete. For example, the signal processing device (170) can check whether an update to the flash bootloader (FBL) of the ECU is incomplete.

[0289] According to one embodiment, the signal processing device (170) can set the status of an update for the system of the vehicle (200). For example, the signal processing device (170) can compare information about the version of the system of the vehicle (200) received from the server (400) with the current version of the system of the vehicle (200) to determine whether an update for the system of the vehicle (200) is required. At this time, if an update for the system of the vehicle (200) is required, the signal processing device (170) can set the status of the update for the system of the vehicle (200) to an incomplete state.

[0290] The signal processing device (170) can check the version and status of the system of the vehicle (200) in operation S1002. For example, the signal processing device (170) can perform a diagnosis on whether the system of the vehicle (200) is operating normally according to a predetermined diagnostic protocol (e.g., an OBD (On-board Diagnostics) protocol). At this time, the signal processing device (170) can determine the status of the system of the vehicle (200) based on a signal received from the ECU.

[0291] The signal processing device (170) can determine, in operation S1003, whether or not the system of the vehicle (200) requires recovery. For example, the signal processing device (170) can determine that the system of the vehicle (200) requires recovery based on the reception of a signal indicating an error in the system from the ECU. In this case, if an update to the system is performed while an error has occurred in the system, the update may not be completed normally. Therefore, the signal processing device (170) can preferentially perform recovery of the system of the vehicle (200) when an error has occurred in the system of the vehicle (200).

[0292] The signal processing device (170), in operation S1004, may transmit first system information to the server (400) when recovery of the system of the vehicle (200) is required. Here, the first system information may refer to information corresponding to recovery of the system of the vehicle (200). For example, the first system information may include the manufacturer of the hardware used by the system, the current version of the system of the vehicle (200), data indicating recovery of the system, whether backup data used for recovery of the system is stored, etc.

[0293] The signal processing device (170), in operation S1005, may transmit second system information to the server (400) if recovery of the vehicle's (200) system is unnecessary. Here, the second system information may refer to information corresponding to an update of the vehicle's (200) system. For example, the second system information may include the manufacturer of the hardware used by the system, the current version of the vehicle's (200) system, etc.

[0294] The signal processing device (170), in operation S1006, can receive package data (hereinafter, system package) containing data regarding the system of the vehicle (200) from the server (400). Here, the package data may mean data in which a program is encoded, compressed, and / or packaged in a format that the signal processing device (170) can process.

[0295] The signal processing device (170) can determine, in operation S1007, whether the system package is a package related to recovery of the system of the vehicle (200). For example, if the system package includes dummy data, the signal processing device (170) can determine that the system package is a recovery-related package. For example, if the system package includes data used for recovery of the current version of the system of the vehicle (200), the signal processing device (170) can determine that the system package is a recovery-related package. For example, if the system package includes data used for updating the system of the vehicle (200) to the latest version, the signal processing device (170) can determine that the system package is an update-related package.

[0296] The signal processing device (170), in operation S1008, may determine to perform recovery of the system of the vehicle (200) if the system package is a package related to recovery of the system of the vehicle (200).

[0297] The signal processing device (170), in operation S1009, may determine to perform an update on the system of the vehicle (200) if the system package is a package regarding an update of the system of the vehicle (200).

[0298] The signal processing device (170) can determine whether the operation of the vehicle (200) is completely terminated in operation S1010. For example, the signal processing device (170) can determine whether the operation of the vehicle (200) is completely terminated based on whether the engine of the vehicle (200) is turned off and the operation of the engine is terminated.

[0299] According to one embodiment, when the engine of the vehicle (200) is turned off, the signal processing device (170) can determine whether the operation of the vehicle (200) is completely ended by checking whether a predetermined condition regarding safety is satisfied when the operation of the vehicle (200) is ended. In this case, the signal processing device (170) can determine that the operation of the vehicle (200) is completely ended when all of a plurality of conditions regarding safety are satisfied when the operation of the vehicle (200) is ended.

[0300] For example, the signal processing device (170) can determine that the operation of the vehicle (200) is completely terminated when the transmission of the vehicle (200) is in the parked state and the parking brake is in use, and the vehicle (200) is set to the locked state (arm).

[0301] For example, the signal processing device (170) can determine that the operation of the vehicle (200) is completely terminated when the vehicle (200) is set to a locked state (arm) while both the door and window of the vehicle (200) are closed.

[0302] For example, the signal processing device (170) can determine that the operation of the vehicle (200) is completely terminated when the vehicle (200) is set to a locked state (arm) when it is determined that there are no passengers inside the vehicle (200) using an internal camera, sensor, etc.

[0303] According to one embodiment, the signal processing device (170) may output a notification that induces the complete termination of operation of the vehicle (200). For example, the signal processing device (170) may output a notification that induces the passenger to disembark and set the arm to a locked state through the display (180a, 180b).

[0304] According to one embodiment, the signal processing device (170) may output a notification regarding the performance of an update to the system when the vehicle (200) is turned off. At this time, the signal processing device (170) may determine whether to perform an update to the system based on a user input received through the input unit (110). Meanwhile, if the update to the system is an essential update for the operation of the vehicle (200), the signal processing device (170) may perform the update to the system regardless of the user input.

[0305] The signal processing device (170) can determine whether the battery of the vehicle (200) is low in operation S1011. For example, the signal processing device (170) can monitor whether the level of the battery of the vehicle (200) is below a reference value corresponding to low battery level.

[0306] The signal processing device (170), in operation S1012, can perform recovery or update on the system of the vehicle (200) if the battery of the vehicle (200) is sufficient. For example, the signal processing device (170) can perform recovery on the system using backup data used for recovery of the system stored in the memory of the vehicle (200). For example, the signal processing device (170) can perform recovery or update on the system based on data included in a system package received from the server (400).

[0307] The signal processing device (170) can, in operation S1013, check whether the recovery or update of the system of the vehicle (200) is completed. The signal processing device (170) can monitor whether the battery of the vehicle (200) is insufficient until the recovery or update of the system of the vehicle (200) is completed.

[0308] When the system of the vehicle (200) is restored or updated, the signal processing device (170) may output a notification regarding the completion of the system of the vehicle (200). For example, the signal processing device (170) may transmit a notification regarding the completion of the system of the vehicle (200) to the mobile terminal (500). For example, when the engine of the vehicle (200) is turned on, the signal processing device (170) may output a notification regarding the completion of the system of the vehicle (200) through the display (180a, 180b).

[0309] The signal processing device (170) can change the status of the update for the system of the vehicle (200) to a completed status when the recovery or update for the system of the vehicle (200) is completed.

[0310] Meanwhile, the signal processing device (170) may perform a rollback for the system in the case where the battery of the vehicle (200) is insufficient in operation S1014. At this time, the signal processing device (170) may maintain the status of the update for the system of the vehicle (200) as incomplete. Through this, the signal processing device (170) may, when the ignition of the vehicle (200) is turned on, re-perform an operation for recovery or update for the system based on the status of the update for the system of the vehicle (200) being incomplete.

[0311] The signal processing device (170) may store data used for system recovery or update in the memory of the vehicle (200) when performing a rollback on the system. For example, the signal processing device (170) may store data included in a system package received from the server (400) in the memory of the vehicle (200). Through this, the signal processing device (170) may perform system recovery or update based on the data stored in the memory of the vehicle (200) even without receiving data from the server (400) again.

[0312] Referring to FIG. 11, the signal processing device (170) can check whether there are new settings for the vehicle (200) in operation S1101. Here, the settings may be related to the system, service, function, application, etc. of the vehicle (200). For example, the signal processing device (170) can determine whether there are updates for new settings for the vehicle (200) based on a signal received from the server (400). For example, the signal processing device (170) can determine whether there are updates for new settings for the vehicle (200) based on a signal received from the mobile terminal (500).

[0313] Meanwhile, the signal processing device (170) can check whether there is a new setting for the vehicle (200) each time the vehicle (200) is turned on.

[0314] According to one embodiment, the signal processing device (170) may perform user authentication in relation to settings for the vehicle (200). Here, user authentication may refer to authentication of whether the user is registered in a service for using settings for the vehicle (200). In this case, the signal processing device (170) may perform an operation of updating the settings of the vehicle (200) when user authentication is completed.

[0315] For example, the signal processing device (170) can transmit data used for user authentication to the server (400) through the communication unit (120). For example, the signal processing device (170) can transmit a signal requesting user authentication to the mobile terminal (500) through the communication unit (120).

[0316] In operation S1102, if it is determined that new settings exist for the vehicle (200), the signal processing device (170) can determine whether an update of the settings for the vehicle (200) is required. For example, the signal processing device (170) can determine whether an update of the settings for the vehicle (200) is required by comparing the version of the new settings to be updated with the current version of the settings for the vehicle (200).

[0317] In operation S1103, if an update of settings for the vehicle (200) is required, the signal processing device (170) may determine whether data download via the OTA method is required. For example, if the update of settings for the vehicle (200) is an update that activates or deactivates the use of a certain function, the signal processing device (170) may determine that data download via the OTA method is unnecessary. For example, if the data to be downloaded is already stored in the memory of the vehicle (200), the signal processing device (170) may determine that data download via the OTA method is unnecessary. For example, if the data to be downloaded can be transmitted from the mobile terminal (500), the signal processing device (170) may determine that data download via the OTA method is unnecessary.

[0318] In operation S1104, if data download via OTA is required, the signal processing device (170) can download data used for updating settings for the vehicle (200) from the server (400). The signal processing device (170) can store the data downloaded from the server (400) in the memory of the vehicle (200).

[0319] The signal processing device (170) can determine, in operation S1105, whether the vehicle (200) is turned off and the engine operation is terminated.

[0320] The signal processing device (170) may output a notification regarding a setting update when the vehicle (200) is turned off and engine operation is terminated in operation S1106. For example, the signal processing device (170) may output a notification asking whether to update the vehicle (200) settings through the display (180a, 180b).

[0321] The signal processing device (170) may determine, in operation S1107, whether to perform an update on the settings of the vehicle (200). For example, the signal processing device (170) may determine to perform an update on the settings of the vehicle (200) based on receiving a user input approving the performance of an update on the settings of the vehicle (200) through the input unit (110).

[0322] The signal processing device (170) can determine, in operation S1108, whether the operation of the vehicle (200) has been completely terminated.

[0323] The signal processing device (170) can perform an update on the settings of the vehicle (200) when the operation of the vehicle (200) is completely terminated in operation S1109.

[0324] The signal processing device (170) can output the result of updating the settings of the vehicle (200) when the vehicle (200) is turned on in operation S1110.

[0325] Meanwhile, the signal processing device (170) may delete the downloaded data from the memory of the vehicle (200) if, in operation S1111, an update of the settings of the vehicle (200) is not performed. For example, the signal processing device (170) may determine not to perform an update of the settings of the vehicle (200) based on receiving a user input that does not permit an update of the settings of the vehicle (200) through the input unit (110).

[0326] Referring to FIG. 12, in operation S1201, the signal processing device (170) can log in to the server (400) using an account corresponding to the vehicle (200) when the vehicle (200) is turned on. The signal processing device (170) can perform a logout every time the vehicle (200) is turned off, and can perform a log-in every time the vehicle (200) is turned on.

[0327] The signal processing device (170) can transmit a hash of data used in the software to the server (400) in operation S1202. In the present disclosure, the data for the navigation map is described, but is not limited thereto.

[0328] A hash corresponding to data for a navigation map may be stored in the memory of the vehicle (200). For example, the signal processing device (170) may generate a hash corresponding to data for a navigation map using a predetermined hash function.

[0329] The server (400) may store a hash corresponding to data for the latest version of the navigation map. At this time, when a hash corresponding to data for the navigation map is received from the signal processing device (170), the server (400) may compare the hash of the latest version with the hash received from the signal processing device (170) to determine which data among the data for the latest version of the navigation map will be used for updating the navigation map of the signal processing device (170).

[0330] The signal processing device (170) can determine, in operation S1203, whether an update is required for the data. For example, if there is a difference between the latest version of the hash and the hash received from the signal processing device (170), the server (400) can transmit a signal indicating an update to the navigation map to the signal processing device (170). At this time, the signal processing device (170) can determine that an update is required for the data if a signal indicating an update to the navigation map is received from the server (400).

[0331] In one embodiment, the server (400) may, in response to a login using an account corresponding to the vehicle (200), determine whether there is a difference between a predetermined version of the hash compared to the last hash received from the signal processing device (170) and the latest version of the hash. In this case, if there is a difference between the predetermined version of the hash and the latest version of the hash, the server (400) may transmit a signal indicating an update to the navigation map to the signal processing device (170). This may eliminate the need for repeated transmission of hashes for data from the signal processing device (170).

[0332] The signal processing device (170) may, in operation S1204, output a notification regarding data when an update is required. For example, the signal processing device (170) may output a notification through the display (180a, 180b) asking whether to update the navigation map.

[0333] The signal processing device (170) may determine, in operation S1205, whether to perform an update on the data. For example, the signal processing device (170) may determine to perform an update on the data related to the navigation map based on receiving a user input approving the performance of an update on the navigation map through the input unit (110).

[0334] The signal processing device (170), when it is determined to perform an update on data in operation S1206, can download the data used for the update from the server (400) via the OTA method.

[0335] The signal processing device (170) can perform an update on data in operation S1207. For example, the signal processing device (170) can perform an update on a navigation map while the vehicle (200) is driving.

[0336] The signal processing device (170) may, in operation S1208, output the result of performing the update on the data in response to the completion of the update on the data. For example, the signal processing device (170) may display an updated navigation map through the display (180a, 180b).

[0337] FIG. 13 is a diagram illustrating an example of a system according to an embodiment of the present disclosure.

[0338] Referring to FIG. 13, the server (400) may include a first server (410) that communicates with a vehicle (200), a second server (420) that generates data used for updating the system, a third server (430) that generates data used for updating vehicle data, etc. The first server (410), the second server (420), and / or the third server (430) may be configured as a single server or may be configured as separate servers that are distinct from each other.

[0339] The second server (420) can extract data (423) corresponding to the difference between data (421) regarding the version of the system received from the vehicle (200) and data (422) regarding the latest version of the system. For example, the second server (420) can extract data (423) using an incremental update method.

[0340] The third server (430) can extract data (433) to be used for updating the navigation map based on the difference between the hash (431) received from the vehicle (200) and the hash (432) corresponding to data for the latest version of the navigation map.

[0341] When using a hash for software updates, the size of the hash data is smaller than the data used for the update, so the size of the data transmitted between the vehicle (200) and the server (400) can be reduced. In addition, when the vehicle (200) transmits a hash corresponding to actual data, the server (400) can accurately confirm the data currently being used in the vehicle (200), compared to when simply transmitting information about the software version, thereby optimizing the extraction of data required for software updates.

[0342] The first server (410) can transmit data (423, 433) used for software updates to the vehicle (200) via a network (10) using the OTA method. The vehicle (200) can perform a software update using the data (423, 433) received from the server (400).

[0343] The server (400) can store data regarding the vehicle (200). For example, the server (400) can store a list including the vehicle information number (VIN) of the vehicle (200) that has requested a software update. For example, the server (400) can store a list including the vehicle identification number (VIN) of the vehicle (200) that has requested a software repair. Through this, the server (400) can manage a history regarding software updates and / or repairs.

[0344] The server (400) may provide software updates based on data about the vehicles (200). For example, the server (400) may provide data for software updates and / or repairs for a predetermined number of vehicles (200). In this case, if the software updates and / or repairs are completed normally for the predetermined number of vehicles (200), data for software updates and / or repairs may be provided for subsequent vehicles (200). Meanwhile, if the software updates and / or repairs are not completed normally for the predetermined number of vehicles (200), the software updates and / or repairs may be stopped.

[0345] FIGS. 14A and 14B are flowcharts illustrating the operating method of a signal processing device according to one embodiment of the present disclosure. Any details that overlap with those described in FIGS. 10 to 12 will be omitted for brevity. At least some of the operations of FIGS. 14A and 14 may be applied to at least one of FIGS. 10 to 12.

[0346] Referring to FIG. 14a, the signal processing device (170) can determine, in operation S1401, whether data used for updating software is already stored in the memory of the vehicle (200).

[0347] In operation S1402, if data used for software update is not stored in the memory of the vehicle (200), the signal processing device (170) can download data used for software update from the server (400) via the OTA method.

[0348] The signal processing device (170) can determine, in operation S1403, whether the software to be updated is software that is preset to be able to be updated while the vehicle (200) is in operation. If the predetermined software to be updated is software related to the driving of the vehicle (200), the predetermined software can be preset to not be updated while the vehicle (200) is in operation.

[0349] According to one embodiment, the signal processing device (170) can determine whether the software to be updated is software that is preset to be updated while the vehicle (200) is in operation, based on predetermined criteria related to the safety of the vehicle (200). For example, the predetermined criteria related to the safety of the vehicle (200) may be ASIL (Automotive Safety Integrity Level).

[0350] In operation S1404, the signal processing device (170) can output a notification regarding the performance of a software update if the software to be updated is software that can be updated while the vehicle (200) is in operation.

[0351] The signal processing device (170) may determine, in operation S1405, whether user approval for a software update has been obtained. For example, the signal processing device (170) may determine that user approval for a software update has been obtained based on receiving a user input approving the execution of a software update through the input unit (110).

[0352] The signal processing device (170) can perform an update to the software if, in operation S1406, the user's approval for the update of the software is obtained.

[0353] The signal processing device (170) can check, in operation S1407, whether the update to the software is completed.

[0354] In operation S1408, when the software update is completed, the signal processing device (170) can check whether the updated software is operating normally. For example, the signal processing device (170) can use a predetermined diagnostic protocol to check whether the updated software is operating normally.

[0355] The signal processing device (170) can set the use of the updated software if the updated software operates normally in operation S1409.

[0356] The signal processing device (170) may output a notification regarding the completion of a software update in operation S1410. For example, the signal processing device (170) may transmit a notification regarding the completion of a software update to the mobile terminal (500). For example, when the vehicle (200) is turned on, the signal processing device (170) may output a notification regarding the completion of a software update through the display (180a, 180b).

[0357] The signal processing device (170) can perform a rollback on the software if the updated software does not operate normally in operation S1411.

[0358] The signal processing device (170) can store data used for software update in the memory of the vehicle (200) in operation S1412. Through this, the signal processing device (170) can perform a software update again based on the data stored in the memory of the vehicle (200) even without receiving data from the server (400) again.

[0359] Meanwhile, referring to FIG. 14b, in operation S1421, the signal processing device (170) can determine whether the engine operation is terminated by turning off the vehicle (200) if the software to be updated is software that cannot be updated while the vehicle (200) is in operation.

[0360] The signal processing device (170) can output a notification regarding the execution of a software update when the vehicle (200) is turned off and the engine operation is terminated in operation S1422.

[0361] The signal processing device (170) can determine, in operation S1423, whether or not to obtain the user's approval for software update.

[0362] The signal processing device (170) can determine whether the operation of the vehicle (200) is completely terminated when the user's approval for the software update is obtained in operation S1424.

[0363] The signal processing device (170) can perform an update to the software when the operation of the vehicle (200) is completely terminated in operation S1425.

[0364] The signal processing device (170) can determine, in operation S1426, whether the update to the software is completed.

[0365] The signal processing device (170), in operation S1427, can check whether the updated software is operating normally when the update to the software is completed.

[0366] The signal processing device (170) can set the use of the updated software if the updated software operates normally in operation S1428.

[0367] The signal processing device (170) can output a notification regarding the completion of software update in operation S1429.

[0368] Meanwhile, the signal processing device (170) can check whether the vehicle (200) is turned on if the update to the software is not completed in operation S1430.

[0369] The signal processing device (170) may perform a rollback on the software in operation S1431 if the updated software does not operate normally or if the vehicle is turned on before the update to the software is completed.

[0370] The signal processing device (170) can store data used for software update in the memory of the vehicle (200) in operation S1432.

[0371] As described above, according to at least one embodiment of the present disclosure, it is possible to perform an update on software while taking into account safety conditions during operation of the vehicle (200), thereby minimizing the impact on the operation of the vehicle (200).

[0372] Additionally, according to at least one embodiment of the present disclosure, software updates can be performed while the vehicle is completely shut down, thereby enabling software updates to be performed more safely.

[0373] Additionally, according to at least one embodiment of the present disclosure, the amount of data downloaded wirelessly for updates to software can be minimized.

[0374] Additionally, according to at least one embodiment of the present disclosure, software can be updated according to an optimized process, taking into account the state of the vehicle (200).

[0375] Referring to FIGS. 1 to 14b, a signal processing device according to an embodiment of the present disclosure includes a processor that processes data received from a server via an OTA (Over The Air) method, and the processor determines whether software that is a target of an update based on the data received from the server is predetermined software that is preset to be updateable while the vehicle is in operation, and if the software that is a target of the update is the predetermined software, performs an update on the software that is a target of the update based on the data received from the server, and if the software that is a target of the update is not the predetermined software, determines whether a predetermined condition regarding safety is satisfied when the vehicle is terminated from operation, and performs an update on the software that is a target of the update in response to the satisfaction of the predetermined condition.

[0376] Additionally, according to one aspect of the present disclosure, the processor can determine whether the software that is the target of the update is the predetermined software based on ASIL (Automotive Safety Integrity Level).

[0377] In addition, according to one aspect of the present disclosure, the processor may output a notification notifying the performance of an update for the software that is the target of the update based on the vehicle's ignition being turned off if the software that is the target of the update is not the predetermined software, and may determine whether the predetermined condition is satisfied in response to receiving a user input approving the update for the software that is the target of the update.

[0378] Additionally, according to one aspect of the present disclosure, the processor may determine that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) while the transmission and parking brake of the vehicle satisfy the first condition regarding safety corresponding to parking of the vehicle after the vehicle is turned off.

[0379] Additionally, according to one aspect of the present disclosure, the processor may determine that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) while both the doors and windows of the vehicle are closed and the second safety condition is satisfied.

[0380] Additionally, according to one aspect of the present disclosure, the processor may determine that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) while the third safety condition of no passenger being present inside the vehicle is satisfied based on data from at least one of an internal camera and sensor of the vehicle.

[0381] Additionally, according to one aspect of the present disclosure, the processor may output a notification to induce the passenger to disembark if the third condition is not met.

[0382] Additionally, according to one aspect of the present disclosure, when the vehicle is turned on while performing an update on the software that is the target of the update in response to satisfaction of the predetermined condition, the processor can perform a rollback on the software that is the target of the update.

[0383] In addition, according to one aspect of the present disclosure, the processor may output a result of performing an update on the software that is the target of the update based on the vehicle being turned on after performing an update on the software that is the target of the update in response to the satisfaction of the predetermined condition.

[0384] In addition, according to one aspect of the present disclosure, the processor can transmit information corresponding to recovery of the software to the server based on the occurrence of an error in the software that is the target of the update, and perform recovery of the software that is the target of the update based on receiving package data regarding recovery of the software that is the target of the update from the server.

[0385] Additionally, according to one aspect of the present disclosure, the processor may transmit a hash of data used in the first software to the server based on the vehicle's ignition being turned on, and determine whether an update to the first software is required based on a response to the transmission of the hash received from the server.

[0386] An operating method of a signal processing device according to one embodiment of the present disclosure may include an operation of determining whether software to be updated based on data received from a server via an OTA (Over The Air) method is predetermined software that is preset to be updated while a vehicle is in operation; an operation of performing an update on the software to be updated based on data received from the server when the software to be updated is the predetermined software; an operation of determining whether a predetermined condition regarding safety is satisfied when the vehicle is terminated when the software to be updated is not the predetermined software; and an operation of performing an update on the software to be updated in response to the satisfaction of the predetermined condition.

[0387] In addition, according to one aspect of the present disclosure, the operation of determining whether the software that is the target of the update is the predetermined software may include an operation of determining whether the software that is the target of the update is the predetermined software based on ASIL (Automotive Safety Integrity Level).

[0388] In addition, according to one aspect of the present disclosure, the operation of determining whether the predetermined condition is satisfied may include an operation of outputting a notification notifying that an update for the software that is the target of the update is to be performed based on the vehicle's ignition being turned off if the software that is the target of the update is not the predetermined software; and an operation of determining whether the predetermined condition is satisfied in response to receiving a user input approving an update for the software that is the target of the update.

[0389] In addition, according to one aspect of the present disclosure, the operation of determining whether the predetermined condition is satisfied may include an operation of determining that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) in a state where at least one of the first safety condition in which the transmission and parking brake of the vehicle correspond to parking of the vehicle after the engine of the vehicle is turned off, the second safety condition in which all doors and windows of the vehicle are closed, and the third safety condition in which no passenger is present inside the vehicle based on data from at least one of an internal camera and sensor of the vehicle is satisfied.

[0390] In addition, according to one aspect of the present disclosure, when the vehicle is turned on while performing an update on the software that is the target of the update in response to satisfaction of the predetermined condition, an operation of performing a rollback on the software that is the target of the update may be further included.

[0391] In addition, according to one aspect of the present disclosure, an operation of outputting a result of performing an update on the software that is the target of the update based on the vehicle being turned on after performing an update on the software that is the target of the update in response to satisfaction of the predetermined condition may be further included.

[0392] In addition, according to one aspect of the present disclosure, the method may further include an operation of transmitting information corresponding to recovery of the software to the server based on the occurrence of an error in the software that is the target of the update; and an operation of performing recovery of the software that is the target of the update based on receiving package data regarding recovery of the software that is the target of the update from the server.

[0393] In addition, according to one aspect of the present disclosure, the method may further include: transmitting a hash of data used in the first software to the server based on the vehicle's engine being turned on; and determining whether an update to the first software is required based on a response to the transmission of the hash received from the server.

[0394] A vehicle control device according to one embodiment of the present disclosure includes a signal processing device having a communication unit that communicates with a server via an OTA (Over The Air) method, a memory that stores data received from the server, and a processor that processes the data received from the server, wherein the signal processing device determines whether software that is a target of an update based on the data received from the server is predetermined software that is set to be updateable while the vehicle is in operation, and if the software that is a target of the update is the predetermined software, performs an update on the software that is a target of the update based on the data received from the server, and if the software that is a target of the update is not the predetermined software, determines whether a predetermined condition regarding safety is satisfied when the vehicle is terminated, and performs an update on the software that is a target of the update in response to the satisfaction of the predetermined condition.

[0395] The attached drawings are only intended to facilitate understanding of the embodiments disclosed in this specification, and the technical ideas disclosed in this specification are not limited by the attached drawings, and should be understood to include all modifications, equivalents, or substitutes included in the spirit and technical scope of the present disclosure.

[0396] Meanwhile, the operating method of the present disclosure can be implemented as processor-readable code on a processor-readable recording medium. A processor-readable recording medium includes all types of recording devices that store data that can be read by a processor. Examples of processor-readable recording media include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage devices, etc., and also include those implemented in the form of a carrier wave, such as transmission via the Internet. Furthermore, the processor-readable recording medium can be distributed across network-connected computer systems, so that the processor-readable code can be stored and executed in a distributed manner.

[0397] In addition, although the preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above, and various modifications may be made by a person having ordinary skill in the art to which the present invention pertains without departing from the gist of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical idea or prospect of the present disclosure.

Claims

1. Includes a processor that processes data received from a server via OTA (Over The Air) method, The above processor, Determine whether the software that is the target of the update based on the data received from the above server is a predetermined software that is set to be updated while the vehicle is in operation, If the software that is the target of the above update is the above specified software, an update is performed on the software that is the target of the update based on the data received from the server, If the software that is the target of the above update is not the above specified software, determine whether the specified safety conditions are met when the vehicle is terminated, A signal processing device characterized in that it performs an update on software that is the target of the update in response to satisfaction of the above-mentioned predetermined condition.

2. In paragraph 1, The above processor, A signal processing device characterized in that it determines whether the software that is the target of the update is the specified software based on ASIL (Automotive Safety Integrity Level).

3. In paragraph 1, The above processor, If the software that is the target of the above update is not the specified software, a notification is output to notify that an update is to be performed for the software that is the target of the update based on the vehicle's ignition being turned off. A signal processing device characterized in that, in response to receiving a user input approving an update to software that is the target of the update, it determines whether the predetermined condition is satisfied.

4. In paragraph 1, The above processor, A signal processing device characterized in that it is determined that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) while the transmission and parking brake of the vehicle satisfy the first safety condition corresponding to parking of the vehicle after the ignition of the vehicle is turned off.

5. In paragraph 1, The above processor, A signal processing device characterized in that it is determined that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) while satisfying the second safety condition in which all doors and windows of the vehicle are closed.

6. In paragraph 1, The above processor, A signal processing device characterized in that it is determined that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) based on data from at least one of an internal camera and sensor of the vehicle and the third safety condition of no occupants being present inside the vehicle is satisfied.

7. In paragraph 6, The above processor, A signal processing device characterized in that it outputs a notification to induce the passenger to disembark if the third condition is not met.

8. In paragraph 1, The above processor, A signal processing device characterized in that, when the vehicle is turned on while performing an update on the software that is the target of the update in response to the satisfaction of the above-mentioned predetermined condition, a rollback on the software that is the target of the update is performed.

9. In paragraph 1, The above processor, A signal processing device characterized in that it outputs the result of performing an update on the software that is the target of the update based on the vehicle being turned on after performing an update on the software that is the target of the update in response to the satisfaction of the above-mentioned predetermined condition.

10. In paragraph 1, The above processor, Based on the occurrence of an error in the software that is the target of the above update, information corresponding to the recovery of the software is transmitted to the server, A signal processing device characterized in that recovery of software that is the target of the update is performed based on receiving package data regarding recovery of software that is the target of the update from the server.

11. In paragraph 1, The above processor, Based on the vehicle's engine being turned on, a hash of the data used in the first software is transmitted to the server, A signal processing device characterized in that it determines whether an update is required for the first software based on a response to the transmission of the hash received from the server.

12. In the operating method of the signal processing device, An action to determine whether the software that is the target of an update based on data received from a server via the OTA (Over The Air) method is a predetermined software that is set to be updated while the vehicle is in operation; An operation of performing an update on the software that is the target of the update based on data received from the server, when the software that is the target of the update is the predetermined software; If the software that is the target of the above update is not the above specified software, an operation for determining whether the specified conditions regarding safety are met when the operation of the vehicle is terminated; and An operating method of a signal processing device including an operation of performing an update on software that is a target of the update in response to satisfaction of the above-mentioned predetermined condition.

13. In paragraph 12, The action of determining whether the software that is the target of the above update is the above specified software is as follows: An operating method of a signal processing device, characterized in that it includes an operation for determining whether the software that is the target of the update is the specified software based on ASIL (Automotive Safety Integrity Level).

14. In paragraph 12, The action of determining whether the above conditions are met is: If the software that is the target of the update is not the specified software, an operation of outputting a notification that an update is to be performed for the software that is the target of the update based on the vehicle's ignition being turned off; and An operating method of a signal processing device, characterized in that it includes an operation for determining whether the predetermined condition is satisfied in response to receiving a user input approving an update to the software that is the target of the update.

15. In paragraph 12, The action of determining whether the above conditions are met is: An operating method of a signal processing device, characterized in that it includes an operation of determining that the predetermined condition is satisfied when the vehicle is set to a locked state (arm) in a state where at least one of the first safety condition corresponding to parking of the vehicle, the second safety condition that all doors and windows of the vehicle are closed, and the third safety condition that no occupants are present inside the vehicle is satisfied based on data from at least one of an internal camera and sensor of the vehicle after the ignition of the vehicle is turned off, the transmission and parking brake of the vehicle are engaged.

16. In paragraph 12, An operating method of a signal processing device, characterized in that it further includes an operation of performing a rollback on the software that is the target of the update when the vehicle is turned on while performing an update on the software that is the target of the update in response to satisfaction of the above-mentioned predetermined condition.

17. In paragraph 12, An operating method of a signal processing device, characterized in that it further includes an operation of outputting a result of performing an update on the software that is the target of the update based on the vehicle being turned on after performing an update on the software that is the target of the update in response to the satisfaction of the above-mentioned predetermined condition.

18. In paragraph 12, An operation of transmitting information corresponding to the recovery of the software to the server based on the occurrence of an error in the software that is the target of the update; and An operating method of a signal processing device, characterized in that it further includes an operation of performing recovery for software that is the target of the update based on receiving package data regarding recovery of software that is the target of the update from the server.

19. In paragraph 12, An operation of transmitting a hash of data used in the first software to the server based on the vehicle's engine being turned on; and An operating method of a signal processing device, characterized in that it further includes an operation of determining whether an update is required for the first software based on a response to the transmission of the hash received from the server.

20. A vehicle control device including a signal processing device according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Update management system

    JP2018136727A

  • Mobility control system, method, and program

    JP2023115229A

  • Apparatus and method for updating software of vehicle

    KR1020160045191A

  • Vehicle, vehicle software update system and vehicle software update method

    KR1020170130037A

  • Electro static charge removal apparatus in semiconductor processing system

    KR102358908B1