Master device, connection information holding device, vehicle system, electronic control device, connection information initialization instruction method, and connection information initialization instruction program

The master device ensures software updates are completed with initialized connection information, preventing vehicle malfunctions by addressing unattended connection risks.

WO2025225284A1PCT designated stage Publication Date: 2025-10-30DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/013180
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-26
Filing Date
2025-03-31
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing technologies do not address the risk of vehicles connecting to factory or yard wireless equipment after release, leading to potential malfunctions due to unattended connection information.

Method used

A master device initiates software updates via a wireless link before vehicle release, and upon completion, instructs a connection information holding device to initialize connection information, preventing unattended connection issues.

Benefits of technology

Prevents malfunctions by ensuring connection information is initialized before vehicle release, avoiding inappropriate vehicle behavior near factory or yard wireless equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025013180_30102025_PF_FP_ABST
    Figure JP2025013180_30102025_PF_FP_ABST
Patent Text Reader

Abstract

In the present invention, an Over The Air (OTA) master (14) performs processing related to the updating of software by connecting a wireless line with a wireless facility before a vehicle is brought to market. Once completing the updating of the software before the vehicle is brought to market, the OTA master instructs a connection information holding device, which holds connection information used to connect the wireless line, to initialize the connection information.
Need to check novelty before this filing date? Find Prior Art

Description

Master device, connection information holding device, vehicle system, electronic control device, connection information initialization instruction method, and connection information initialization instruction program CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Japanese Application No. 2024-72797, filed on April 26, 2024, the contents of which are incorporated herein by reference.

[0002] The present invention relates to a master device, a connection information holding device, a vehicle system, an electronic control device, a connection information initialization instruction method, and a connection information initialization instruction program.

[0003] Vehicles are equipped with numerous electronic control units (hereinafter referred to as ECUs (Electronic Control Units)). With the diversification of vehicle control, such as driver assistance functions and autonomous driving functions, OTA (Over The Air) reprogramming technology has been developed to wirelessly update software installed in ECUs. In OTA reprogramming, the OTA master in the vehicle distributes software downloaded from an OTA center to a target ECU, which is a device to be updated, and instructs the target ECU to update the software, causing the target ECU to update the software.

[0004] OTA reprogramming can be performed even before a vehicle is released to the market, for example, immediately before final inspection at a factory or in a yard where the vehicle is waiting for shipment. In such cases, OTA reprogramming may be performed by temporarily connecting wireless equipment in the factory or yard to the vehicle via a wireless line such as Wi-Fi (registered trademark). However, if the vehicle is released to the market while the connection information used to connect to the wireless equipment in the factory or yard is still stored in the vehicle, there is a risk that the vehicle will connect to the wireless equipment in the factory or yard when the vehicle travels near the factory or yard. As a result, there is a risk of malfunctions, such as the vehicle behaving inappropriately due to temporary disruption of the connection status. Meanwhile, for example, Patent Document 1 discloses a technology for initializing connection information stored in the vehicle.

[0005] Japanese Patent Application Laid-Open No. 2023-136202

[0006] However, Patent Document 1 does not take into account OTA repro and does not solve the above-mentioned problems.

[0007] The present disclosure aims to prevent problems from occurring due to connection information used in software updates being left unattended before a vehicle is released to the market.

[0008] A master device according to an aspect of the present disclosure performs a process for updating software between the master device and wireless equipment via a wireless link before a vehicle is released to the market, and when the software update before the vehicle is released to the market is completed, the master device instructs a connection information holding device that holds the connection information to initialize the connection information used to connect the wireless link.

[0009] A connection information holding device according to an embodiment of the present disclosure holds connection information used by a master device that performs software update processing with wireless equipment via a wireless link, and initializes the connection information when instructed to do so by the master device.

[0010] A vehicle system according to one aspect of the present disclosure includes a master device that performs software update processing between the master device and wireless equipment via a wireless link before a vehicle is released to the market, and a connection information holding device that holds connection information used by the master device. When the master device completes the software update before the vehicle is released to the market, the master device instructs the connection information holding device to initialize the connection information used to connect the wireless link. When the master device instructs the connection information holding device to initialize the connection information, the connection information holding device initializes the connection information.

[0011] According to one aspect of the present disclosure, an electronic control device includes a first functional unit that performs processing related to a software update via a wireless link with wireless equipment before a vehicle is released to the market, and a second functional unit that stores connection information used by the first functional unit. Upon completing the software update before the vehicle is released to the market, the first functional unit instructs the second functional unit to initialize the connection information used to connect the wireless link. Upon receiving the instruction to initialize the connection information from the first functional unit, the second functional unit initializes the connection information.

[0012] A method for instructing initialization of connection information according to one embodiment of the present disclosure includes, in a master device that performs processing related to software updates via a wireless line with wireless equipment before a vehicle is released to the market, instructing a connection information holding device that holds the connection information to initialize the connection information used to connect the wireless line when the software update before the vehicle is released to the market is completed.

[0013] A connection information initialization instruction program of one embodiment of the present disclosure causes a master device that performs processing related to software updates via a wireless line with wireless equipment before a vehicle is released to the market to execute an initialization instruction procedure that instructs a connection information holding device that holds the connection information to initialize the connection information used to connect the wireless line once the software update before the vehicle is released to the market is completed.

[0014] According to one aspect of the present disclosure, when a software update before the vehicle is released to the market is completed, a connection information storage device that stores the connection information is instructed to initialize the connection information used to connect the wireless line. By initializing the connection information used in the software update before the vehicle is released to the market, it is possible to prevent problems from occurring due to the connection information being left untouched.

[0015] According to one aspect of the present disclosure, connection information used by a master device that performs software update processing with wireless equipment via a wireless link is stored. When an instruction to initialize the connection information is received from the master device, the connection information is initialized. By initializing the connection information used in the software update before the vehicle is released to the market, it is possible to prevent malfunctions caused by leaving the connection information unattended.

[0016] According to one aspect of the present disclosure, when a software update performed before a vehicle is released to the market is completed, the master device instructs the connection information holding device to initialize the connection information used to connect the wireless line. When the master device instructs the connection information holding device to initialize the connection information, the connection information holding device initializes the connection information. By initializing the connection information used in the software update before the vehicle is released to the market, it is possible to prevent malfunctions caused by leaving the connection information unattended.

[0017] According to one aspect of the present disclosure, when a software update before the vehicle is released to the market is completed, a first functional unit instructs a second functional unit to initialize connection information used to connect a wireless line. When the second functional unit receives an instruction to initialize the connection information from the first functional unit, the second functional unit initializes the connection information. By initializing the connection information used in the software update before the vehicle is released to the market, it is possible to prevent malfunctions caused by leaving the connection information unattended.

[0018] The above and other objects, features, and advantages of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, in which Fig. 1 is a diagram showing the overall configuration of one embodiment, Fig. 2 is a functional block diagram of a ReproMaster, Fig. 3 is a diagram showing a connection information list, Fig. 4 is a flowchart, Fig. 5 is a flowchart, Fig. 6 is a flowchart, Fig. 7 is a diagram showing update type information, and Fig. 8 is a functional block diagram of an electronic control device.

[0019] An embodiment will be described below with reference to the drawings. As shown in Fig. 1, a data communication system 1 is configured to enable data communication between an over-the-air (OTA) center 2 and a vehicle system 3 installed in a vehicle. An unspecified number of vehicle systems 3 can communicate data with the OTA center 2. The vehicle is, for example, an electric vehicle such as a BEV powered by electricity from an on-board battery. Unlike non-electric vehicles such as gasoline-powered vehicles, electric vehicles can freely control the power supply to all ECUs installed in the vehicle using software.

[0020] The vehicle system 3 includes an in-vehicle communication device (hereinafter referred to as DCM (Data Communication Module)) 4 (corresponding to a connection information holding device), a central gateway (hereinafter referred to as CGW (Central Gateway)) 5, a first repeater 6, a second repeater, and a third repeater 8. The CGW 5, the first repeater 6, the second repeater 7, and the third repeater 8 are referred to as domain controllers. The first repeater 6, the second repeater 7, and the third repeater 8 are connected to the CGW 5, for example, via Ethernet (registered trademark).

[0021] The OTA center 2 generates and stores an update package including software and specification data to be updated. The OTA center 2 also stores update packages acquired from external sources, such as an OEM (Original Equipment Manufacturer). The OTA center 2 includes a configuration management function unit that manages the vehicle hardware and software configurations that may be targets for the update package distribution, and a distribution management function unit that manages the distribution of the update package to the vehicle. The software includes programs, data, libraries, etc. for operating the ECU.

[0022] The specification data includes information capable of identifying an ECU compatible with OTA, information capable of identifying a target ECU that is the target of the software update, information capable of identifying an installation target in the installation phase described below, information capable of identifying the order of installation, information capable of identifying an activation target in the activation phase described below, information capable of identifying the order of activation, etc. An ECU compatible with OTA is an ECU that can implement OTA. The OTA center 2 may include the specification data in an update package and distribute it to the vehicle, or may distribute the specification data to the vehicle separately from the update package without including the specification data in the update package.

[0023] The DCM 4 performs data communication with the OTA center 2 via a communication network. The communication network may include, for example, a mobile communication network using a 4G line or a 5G line, the Internet, Wi-Fi, etc. The DCM 4 and the CGW 5 may be integrated, and the functions of the DCM 4 may be incorporated into the CGW 5. Alternatively, the functions of the DCM 4 and the CGW 5 may be incorporated into a display device or the like. When the DCM 4 receives an update package distributed from the OTA center 2, it forwards the received update package to the CGW 5. Software distributed from the OTA center 2 to the DCM 4 is, for example, OTA repro software. For inter-center communication, which is data communication between the OTA center 2 and the DCM 4, for example, an SOVD format conforming to the SOVD communication specifications or a Rest (REpresentational State Transfer) API format conforming to the Rest API communication specifications is applied. A software update using an update package distributed from the OTA center 2 is called wireless repro. On the other hand, a software update using an update package distributed from an external tool (described later) is called wired repro.

[0024] The CGW 5 includes a ReproMaster 9, an in-vehicle HMI (Human Machine Interface) 10, a remote diagnostics 11, and an onboard client (hereinafter referred to as OBC) 12. As shown in Fig. 2, the ReproMaster 9 includes a downloader 13 and an OTA master 14 (corresponding to a master device).

[0025] When a download execution request is input from the OTA master 14, the downloader 13 instructs the DCM 4 to execute the download process. The update package distributed from the OTA center 2 is received by the DCM 4, and the received update package is transferred from the DCM 4, whereby the downloader 13 downloads the update package from the OTA center 2 via the DCM 4. The downloaded update package is temporarily stored in the ReproMaster 9 or an external memory, which will be described later.

[0026] The OTA master 14 includes an update control function unit 15, a state management function unit 16, a display control function unit 17, a write control function unit (Flashing Adapter) 18, a power control function unit 19, an OTA-compatible ECU list storage unit 20, and a campaign target ECU list storage unit 21. These functions are realized by software processing in which a microcomputer executes a computer program stored in a non-transient physical storage medium using a CPU, or by hardware processing using a dedicated electronic circuit.

[0027] The update control function unit 15 has a function of controlling software updates. The state management function unit 16 has a function of managing the state of the software to be updated in accordance with the software update. The display control function unit 17 has a function of controlling the display on the in-vehicle HMI 10 in accordance with the software update. The write control function unit 18 has a function of controlling the installation of software to the software to be updated.

[0028] The OTA-compatible ECU list storage unit 20 stores information included in the specification data that can identify ECUs that are compatible with OTA as an OTA-compatible ECU list. The campaign target ECU list storage unit 21 stores information included in the specification data that can identify target ECUs as a campaign target ECU list. Among the ECUs that are compatible with OTA, an ECU that is recorded in the campaign target ECU list is the target ECU, and among the ECUs that are compatible with OTA, an ECU that is not recorded in the campaign target ECU list is an ECU that is not eligible for the campaign.

[0029] The power supply control function unit 19 refers to the OTA-compatible ECU list and identifies an ECU that supports OTA. The power supply control function unit 19 refers to the campaign target ECU list and identifies a target ECU. The power supply control function unit 19 cooperates with the power supply control app 22 located in the second relay 7 to control the power supply to the ECU as the software update progresses. Note that, although the present embodiment illustrates a case in which the power supply control function unit 19 cooperates with the power supply control app 22 to control the power supply to the ECU, a configuration in which a power control ECU that controls the power supply to the ECU is located may also be used. Targets for which the power supply control function unit 19 controls power supply include the DCM 4, the in-vehicle HMI 10, the first relay 6, the second relay 7, the third relay 8, etc.

[0030] The OBC 12 includes an arbitration function unit 23 and a diagnostic communication function unit 24. The arbitration function unit 23 is responsible for diagnostic communication between the ReproMaster 9 and the repeater or ECU, and arbitrates which diagnostic communication should be prioritized. The diagnostic communication function unit 24 performs diagnostic communication between the ReproMaster 9 and the repeater or ECU according to the arbitration result of the arbitration function unit 23.

[0031] The OBC 12 is connected to a plurality of ECUs 25, 26 via a first repeater 6. The plurality of ECUs 25, 26 are connected to the first repeater 6 via, for example, a CAN bus. CAN communication between the first repeater 6 and the plurality of ECUs 25, 26 is data communication using a 29-bit CAN ID. An ECU that is the target of software update among the plurality of ECUs 25, 26 connected to the first repeater 6 can be the target ECU. Although the example shows a case where two ECUs are connected to the first repeater 6, the number of ECUs connected to the first repeater 6 is not limited to two.

[0032] Similarly, the OBC 12 is connected to a plurality of ECUs 27, 28 via a second relay 7. The plurality of ECUs 27, 28 are connected to the second relay 7 via, for example, a CAN bus. CAN communication between the second relay 7 and the plurality of ECUs 27, 28 is data communication using a 29-bit CAN ID. An ECU that is the target of software update among the plurality of ECUs 27, 28 connected to the second relay 7 can be the target ECU. Although the example shows a case where two ECUs are connected to the second relay 7, the number of ECUs connected to the second relay 7 is not limited to two.

[0033] Similarly, the OBC 12 is connected to a plurality of ECUs 29, 30 via a third relay 8. The plurality of ECUs 29, 30 are connected to the third relay 8 via, for example, a CAN bus. CAN communication between the third relay 8 and the plurality of ECUs 29, 30 is data communication using a 29-bit CAN ID. An ECU that is the subject of software update among the plurality of ECUs 29, 30 connected to the third relay 8 can be the target ECU. Although the example shows a case where two ECUs are connected to the third relay 8, the number of ECUs connected to the third relay 8 is not limited to two.

[0034] Furthermore, the OBC 12 is connected to the ECU 31 without a repeater. An ECU that is the target of software update among the multiple ECUs connected to the OBC 12 can be the target ECU. While the example shows a case where one ECU is connected to the OBC 12 without a repeater, the number of ECUs connected to the OBC 12 without a repeater is not limited to one. CAN communication between the first repeater 6 and the multiple ECUs 25 and 26, CAN communication between the second repeater 7 and the multiple ECUs 27 and 28, and CAN communication between the third repeater 8 and the multiple ECUs 29 and 30 may be data communication using an 11-bit CAN ID.

[0035] The power control application 22 arranged in the second repeater 7 cooperates with the power control function unit 19 of the OTA master 14 as described above, and controls the power supply to the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 as the software update progresses. That is, the OTA master 14 cooperates the power control function unit 19 with the power control application 22, and controls the power supply to the repeaters 6 to 8 and the ECUs 25 to 31 that are capable of diagnostic communication via the diagnostic communication function unit 24.

[0036] When a start request is input from the OTA master 14 while the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 are in a stopped state, the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 transition to a started state, and the supply of power from the in-vehicle battery is stopped. When a stop request is input from the OTA master 14 while the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 are in a started state, the DCM 4, the in-vehicle HMI 10, the repeaters 6 to 8, and the ECUs 25 to 31 transition to a stopped state, and the supply of power from the in-vehicle battery is stopped.

[0037] The external tool 32, while attached to a connector provided in the vehicle, delivers the update package to the OTA master 14. The external memory 33 functions as external storage for the OTA master 14, and as a temporary storage destination for the update package downloaded from the OTA center 2 as described above, and also as a temporary save destination for pre-update software when updating the software of the repeaters 6 to 8 and the ECUs 25 to 31.

[0038] A series of processing phases related to a software update includes a configuration synchronization phase, a download phase, an installation phase, an activation phase, and an update completion notification phase. The configuration synchronization phase is a phase in which the OTA center 2 synchronizes configuration information of the software and hardware of the ECU installed in the target vehicle with configuration information of the software and hardware of the ECU.

[0039] The download phase is a phase in which the OTA master 14 downloads an update package from the OTA center 2. Before performing the download phase, the OTA master 14 determines, for example, whether the software to be downloaded is legitimate, and whether the download can be completed by checking the data volume of the software to be downloaded against the remaining charge of the vehicle battery. If the OTA master 14 determines, for example, that the software to be downloaded is legitimate and that the remaining charge of the vehicle battery is sufficient for the data volume of the software to be downloaded, the OTA master 14 performs the download phase.

[0040] The installation phase is a phase in which the OTA master 14 installs software extracted from the update package into the target ECU. Installation means writing the software to a storage area of ​​the target ECU. Before performing the installation phase, the OTA master 14 determines, for example, whether the software to be installed is authentic, and whether the installation can be completed by comparing the data volume of the software to be installed with the remaining charge of the vehicle battery. If the OTA master 14 determines, for example, that the software to be installed is authentic and that the remaining charge of the vehicle battery is sufficient for the data volume of the software to be installed, the OTA master 14 performs the installation phase.

[0041] The activation phase is a phase in which the installed software is activated in the target ECU. Before performing the activation phase, the OTA master 14 determines, for example, whether the software to be activated is authentic, and whether the activation can be completed by comparing the data volume of the software to be activated with the remaining charge of the vehicle battery. If the OTA master 14 determines, for example, that the software to be activated is authentic and that the remaining charge of the vehicle battery is sufficient for the data volume of the software to be activated, the OTA master 14 performs the activation phase.

[0042] The update completion notification phase is a phase in which the OTA master 14 transmits an update completion notification to the OTA center 2 when the OTA master 14 receives an update completion notification from the target ECU upon completion of activation.

[0043] OTA reprogramming can be performed even before a vehicle is released to the market, for example, immediately before final inspection at a factory, or in a shipping waiting area, for example. In such cases, OTA reprogramming is performed by temporarily connecting wireless equipment in the factory or yard with the OTA master via a wireless line such as Wi-Fi (registered trademark). OTA reprogramming performed at a factory immediately before final inspection is referred to as "immediately before final inspection OTA reprogramming," OTA reprogramming performed at a yard is referred to as "yard OTA reprogramming," and OTA reprogramming performed after a vehicle is released to the market is referred to as "market OTA reprogramming."

[0044] Before the vehicle is released to the market, a connection contract between the vehicle and the OTA center 2 has not been concluded by the vehicle owner in the market. Therefore, the wireless equipment in the factory or yard is connected to the vehicle using an SSID (Service Set Identifier) ​​for OTA repro just before final inspection or an SSID for yard OTA repro, which will be described later, and the above-mentioned update package and specification data distributed from the OTA center 2 are received by the OTA master 14 via the wireless equipment. In this case, the wireless equipment in the factory distributes specification data to the vehicle, in which OTA information just before final inspection, which can identify that the current campaign is OTA repro just before final inspection, is registered as the update type. The wireless equipment in the yard distributes specification data to the vehicle, in which yard OTA information, which can identify that the current campaign is OTA repro just before final inspection, is registered as the update type. After the vehicle is released on the market, if a connection contract has been concluded between the vehicle side and the OTA center 2 by the vehicle owner in the market, the OTA center 2 distributes to the vehicle side specification data in which market OTA information that can identify that this campaign is a market repro is registered as an update type.

[0045] The OTA master 14 can identify whether the current campaign is OTA repro just before final inspection, OTA yard repro, or OTA repro in market by analyzing the update type information registered in the campaign information. Before the vehicle is released to the market, the OTA master 14 identifies the current campaign as OTA repro just before final inspection by identifying the OTA information just before final inspection, and identifies the current campaign as yard OTA repro by identifying the yard OTA information. After the vehicle is released to the market, the OTA master 14 identifies the current campaign as market OTA repro by identifying the market OTA information. Note that if market OTA information is not registered as update type information, the OTA master 14 may identify the current campaign as market OTA repro after the vehicle is released to the market by not identifying either the OTA information just before final inspection or the yard OTA information.

[0046] For example, the DCM 4 holds a connection information list for wireless connections. As shown in FIG. 3 , the connection information list stores multiple pieces of connection information. For example, if the specifications are to temporarily connect in-factory wireless equipment to Wi-Fi to perform OTA reprogramming immediately before final inspection, the connection information list includes an SSID for OTA reprogramming immediately before final inspection for connecting the in-factory wireless equipment to Wi-Fi. For example, if the specifications are to temporarily connect in-yard wireless equipment to Wi-Fi to perform yard OTA reprogramming, the connection information list includes an SSID for yard OTA reprogramming immediately before final inspection for connecting the in-yard wireless equipment to Wi-Fi. FIG. 3 illustrates an example in which there is one SSID for OTA reprogramming immediately before final inspection, but if OTA reprogramming immediately before final inspection is performed at multiple locations, there will be multiple SSIDs for OTA reprogramming immediately before final inspection. Although there is one SSID for yard OTA reprogramming, if yard OTA reprogramming is performed at multiple locations, there will be multiple SSIDs for yard OTA reprogramming. In this embodiment, Wi-Fi is used as an example of the wireless connection method, but methods conforming to other communication standards may also be used. Furthermore, the connection information may include a password in addition to the SSID, and may include a password for OTA repro just before the final inspection and a password for yard OTA repro. In the initialization described below, if the connection information includes both the SSID and password, both the SSID and password may be initialized, or either the SSID or the password may be initialized. In other words, as long as it is possible to avoid problems caused by leaving the SSID or password used for OTA before the vehicle is released to the market, either one may be initialized.

[0047] The OTA master 14 outputs a connection instruction for either a cellular connection or a Wi-Fi connection to the DCM 4, causing the DCM 4 to establish a cellular connection or a Wi-Fi connection. In the factory, the OTA master 14 outputs a connection instruction for a Wi-Fi connection to the DCM 4, and performs OTA reprogramming immediately before completion inspection while the DCM 4 is connected to wireless equipment in the factory via Wi-Fi using the SSID for OTA reprogramming immediately before completion inspection stored in the connection information list. In the yard, the OTA master 14 outputs a connection instruction for a Wi-Fi connection to the DCM 4, and performs yard OTA reprogramming while the DCM 4 is connected to wireless equipment in the yard via Wi-Fi using the SSID for yard OTA reprogramming stored in the connection information list. The connection information list includes, in addition to the SSID for OTA reprogramming immediately before completion inspection and the SSID for yard OTA reprogramming, SSIDs to be used for other purposes, for example, after the vehicle is released to the market. For example, it includes an SSID for connecting to wireless equipment in a maintenance facility that performs statutory inspections after a vehicle is released onto the market.

[0048] The DCM 4 is connected to Wi-Fi when a Wi-Fi connection instruction is input from the OTA master 14. In addition, for example, if the Wi-Fi automatic connection function is enabled, the DCM 4 can also be connected to Wi-Fi by identifying a change from outside the Wi-Fi range to within the Wi-Fi range even if a Wi-Fi connection instruction is not input from the OTA master 14. Therefore, if a vehicle is released to the market while retaining the SSID used for a Wi-Fi connection with wireless equipment in a factory or yard, when the vehicle travels near the factory or yard, the vehicle may connect to Wi-Fi with the wireless equipment in the factory or yard, which could cause problems such as the vehicle behaving inappropriately, for example, by temporarily disrupting the connection status.

[0049] In the present embodiment, the DCM 4 holds the connection information list. However, the connection information list may be held by a device other than the DCM 4. For example, an ECU for an in-vehicle infotainment system (hereinafter referred to as IVI (In-Vehicle Infotainment)) may hold the connection information list. In this case, the OTA master 14 outputs a connection instruction for a Wi-Fi connection to the IVI ECU in the factory, and performs OTA reprogramming immediately before the completion inspection while the IVI ECU is connected to wireless equipment in the factory via Wi-Fi using the SSID for OTA reprogramming immediately before the completion inspection stored in the connection information list. In the yard, the OTA master 14 outputs a connection instruction for a Wi-Fi connection to the IVI ECU, and performs yard OTA reprogramming while the IVI ECU is connected to wireless equipment in the yard via Wi-Fi using the SSID for yard OTA reprogramming stored in the connection information list. In the IVI ECU, for example, if the Wi-Fi automatic connection function is enabled, a Wi-Fi connection can be established by identifying a change from outside the Wi-Fi range to within the Wi-Fi range, even if a Wi-Fi connection instruction is not input from the OTA master 14. Alternatively, the OTA master 14 may hold a connection information list and transfer the held connection information list to the DCM 4 and the IVI ECU.

[0050] Next, the operation of the above-described configuration will be described with reference to Figures 4 to 8. Here, the connection information initialization determination process performed by the OTA master 14 and the initialization instruction notification reception determination process performed by the DCM 4 will be described. Note that SSID initialization includes both deleting the corresponding SSID information from the storage medium and invalidating the corresponding SSID information by, for example, setting an invalidation flag without deleting it from the storage medium. Furthermore, if the IVI-related ECU holds the connection information list, the IVI-related ECU performs the initialization instruction notification reception determination process.

[0051] (1) Connection Information Initialization Determination Process Performed by the OTA Master 14 (See FIGS. 4 and 5) When the OTA master 14 starts the connection information initialization determination process, it synchronizes the configuration information (A1), checks the current campaign information (A2), and determines whether or not there is a software update (A3). If the OTA master 14 determines that there is no software update (A3: NO), it returns to step A1 and repeats step A1 and subsequent steps.

[0052] When the OTA master 14 determines that there is a software update (A3: YES), it checks the update type information (A4) and determines whether the current campaign is either OTA repro just before completion inspection or yard OTA repro (A5). When the OTA master 14 determines that neither OTA information just before completion inspection nor yard OTA information is registered as the update type and that the current campaign is neither OTA repro just before completion inspection nor yard OTA repro (A5: NO), it ends the connection information initialization determination process.

[0053] The OTA master 14 has either immediately before completion inspection OTA information or yard OTA information registered as the update type, and when it determines that the current campaign is either immediately before completion inspection OTA reprocessing or yard OTA reprocessing (A5: YES), it performs either immediately before completion inspection OTA reprocessing or yard OTA reprocessing (A6). That is, when the OTA master 14 determines that the current campaign is immediately before completion inspection OTA reprocessing, it performs immediately before completion inspection OTA reprocessing, and when it determines that the current campaign is yard OTA reprocessing, it performs yard OTA reprocessing.

[0054] When the OTA master 14 completes either the OTA repro just before completion inspection or the yard OTA repro, it synchronizes the configuration information again to notify the OTA center 2 of the updated version information (A7), checks the campaign information again (A8), and determines again whether there is a software update (A9). If the OTA master 14 determines that there is a software update (A9: YES), it checks the update type information again (A10) and determines whether the current campaign is either the OTA repro just before completion inspection or the yard OTA repro (A11). If the OTA master 14 determines that neither the OTA information just before completion inspection nor the yard OTA information is registered as the update type and that the current campaign is neither the OTA repro just before completion inspection nor the yard OTA repro (A11: NO), it ends the connection information initialization determination process.

[0055] The OTA master 14 has registered either OTA information just before completion inspection or yard OTA information as the update type, and if it determines that the current campaign is either OTA repro just before completion inspection or yard OTA repro (A11: YES), it returns to step A6 and repeats steps A6 and onwards.

[0056] When the OTA master 14 determines that there is no software update (A9: NO), it confirms the completion of the OTA before the vehicle is released to the market. When the OTA master 14 confirms the completion of the OTA before the vehicle is released to the market, it sends an initialization instruction notice to the DCM 4 (A12, corresponding to the initialization instruction procedure) and waits to receive an initialization success notice from the DCM 4 (A13). That is, if only OTA reprogramming immediately before the completion inspection has been performed, the OTA master 14 sends an initialization instruction notice to the DCM 4 instructing the initialization of the SSID for OTA reprogramming immediately before the completion inspection. If only yard OTA reprogramming has been performed, the OTA master 14 sends an initialization instruction notice to the DCM 4 instructing the initialization of the SSID for yard OTA reprogramming. If both OTA reproducibility immediately before completion inspection and yard OTA reproducibility are being performed, the OTA master 14 transmits an initialization instruction notice to the DCM 4 to instruct initialization of the SSID for OTA reproducibility immediately before completion inspection and the SSID for yard OTA reproducibility. If the IVI system ECU is configured to hold a connection information list, the OTA master 14 transmits the initialization instruction notice to the IVI system ECU.

[0057] For example, when the OTA master 14 determines that an initialization success notification has been received from the DCM 4 before a certain time has elapsed since the initialization instruction notification was sent to the DCM 4 (A13: YES), it confirms that the initialization of either the SSID for OTA repro just before completion inspection or the SSID for OTA repro in the yard has been successful in the connection information list stored in the DCM 4, and terminates the connection information initialization determination process.

[0058] On the other hand, if the OTA master 14 determines that a certain time has passed since the OTA master 14 transmitted the initialization instruction notification to the DCM 4 without receiving an initialization success notification from the DCM 4 (A13: NO), the OTA master 14 compares the number of retransmissions of the initialization instruction notification with a preset upper limit and determines whether the number of retransmissions of the initialization instruction notification has reached the upper limit (A14). If the OTA master 14 determines that the number of retransmissions of the initialization instruction notification has not reached the upper limit (A14: NO), the OTA master 14 increments the number of retransmissions by "1" (A15), returns to step A12, and repeats step A12 and subsequent steps.

[0059] When the OTA master 14 determines that the number of retransmissions of the initialization instruction notification has reached the upper limit (A14: YES), it confirms that initialization of either the SSID for OTA re-progression just before completion inspection or the SSID for yard OTA re-progression has failed in the connection information list stored in the DCM 4, stores initialization failure information indicating that initialization of either the SSID for OTA re-progression just before completion inspection or the SSID for yard OTA re-progression has failed as history (A16), and ends the connection information initialization determination process. The OTA master 14 is not limited to a configuration in which it stores the initialization failure information, and any device mounted on the vehicle may be configured to store the initialization failure information.

[0060] The storage destination where the OTA master 14 stores the initialization failure information may be, for example, the non-volatile memory of the CGW 5 if the OTA master 14 is configured to be provided in the CGW 5, or the non-volatile memory of any of the DCM 4, the first relay 6, the second relay 7, and the third relay 8. More generally, the storage destination where the OTA master 14 stores the initialization failure information may be any device mounted on the vehicle. For example, the OTA master 14 issues a write instruction for the initialization failure information to a component (e.g., software) responsible for writing data to the storage destination non-volatile memory. Alternatively, for example, the DCM 4 or an IVI-based ECU may store the initialization failure information as its own diagnostic information.

[0061] (2) Initialization Instruction Notification Reception Determination Process Performed by DCM 4 (See FIG. 6) When the DCM 4 starts the initialization instruction notification reception determination process, it determines whether an initialization instruction notification has been received from the OTA master 14 (B1). If the DCM 4 determines that an initialization instruction notification has been received from the OTA master 14 (B1: YES), it initializes either the SSID for OTA re-progression immediately before completion inspection or the SSID for yard OTA re-progression (B2). That is, if the DCM 4 determines that an initialization instruction notification instructing initialization of the SSID for OTA re-progression immediately before completion inspection has been received, it initializes the SSID for OTA re-progression immediately before completion inspection. If the DCM 4 determines that an initialization instruction notification instructing initialization of the SSID for yard OTA re-progression has been received, it initializes the SSID for yard OTA re-progression. If DCM4 determines that an initialization instruction notification instructing initialization of both the SSID for OTA re-progression just before completion inspection and the SSID for yard OTA re-progression has been received, it initializes both the SSID for OTA re-progression just before completion inspection and the SSID for yard OTA re-progression.

[0062] The DCM 4 determines whether initialization of either the SSID for OTA repro just before completion inspection or the SSID for yard OTA repro was successful (B3). If it determines that initialization was successful (B3: YES), it sends an initialization success notification to the OTA master 14 (B4) and ends the initialization instruction notification reception determination process. If the DCM 4 determines that initialization was unsuccessful (B3: NO), it returns to step B1 and repeats step B1 and subsequent steps. Note that if the OTA master 14 is configured to send an initialization retry notification to the DCM 4, the DCM 4 may return to step B2 and repeat step B2 and subsequent steps on the condition that it has received the initialization retry notification from the OTA master 14.

[0063] As shown in FIG. 7 , if the OTA reprocessing from version 1 to version 2 is either OTA reprocessing just before final inspection or yard OTA reprocessing, the OTA reprocessing from version 2 to version 3 is also either OTA reprocessing just before final inspection or yard OTA reprocessing, and the OTA reprocessing from version 3 to version 4 is neither OTA reprocessing just before final inspection nor yard OTA reprocessing, then when the OTA reprocessing from version 2 to version 3 is completed, either the SSID for OTA reprocessing just before final inspection or the SSID for OTA reprocessing at the yard is initialized.

[0064] The above describes an example of a configuration in which the OTA master 14 retransmits an initialization instruction notification when it determines that a certain amount of time has passed since it transmitted an initialization instruction notification to the DCM 4 without receiving an initialization success notification from the DCM 4. However, the DCM 4 may be configured to be able to transmit an initialization failure notification, and may retransmit the initialization instruction notification when it determines that it has received an initialization failure notification from the DCM 4. Furthermore, the DCM 4 may detect an initialization failure and internally retry initialization of either the SSID for OTA repro just before completion inspection or the SSID for OTA repro in the yard. In this case, an upper limit may be set for the number of retries.

[0065] For example, if the OTA master 14 is provided in the CGW 5, the CGW 5 may be configured as a connection information holding device that holds connection information and initializes the connection information when an instruction to initialize the connection information is received. More generally, a specific ECU may have the functions of the OTA master 14 and the functions of the DCM 4 and the IVI ECU. As shown in Figure 8, for example, the specific ECU 41 includes a first functional unit 42 that executes software that performs the functions of the OTA master 14 and the DCM 4 and the IVI ECU.

[0066] The OTA master 14, which is executed by the software of the first functional unit 42, has a wide range of responsibilities as described above. Specifically, when the first functional unit 42 completes OTA before the vehicle is released to the market, it outputs an initialization instruction notice to the second functional unit 43. When the first functional unit 42 determines that the second functional unit 43 has failed to initialize the SSID or password, it retries outputting the initialization instruction notice to the second functional unit 43. When the first functional unit 42 determines that the number of retries to output the initialization instruction notice to the second functional unit 43 has reached an upper limit, it stores initialization failure information indicating that the initialization of the SSID or password has failed. The first functional unit 42 may store the initialization failure information in a storage area other than its own.

[0067] The DCM 4 and the IVI-based ECUs executed by the software of the second functional unit 43 have a wide range of responsibilities, as described above. Specifically, upon receiving an initialization instruction notification from the first functional unit 42, the second functional unit 43 initializes the SSID and password used for OTA before the vehicle was released to the market. The second functional unit 43 stores the SSID and password used for OTA and the SSID and password used for purposes other than OTA, and upon receiving an initialization instruction notification from the first functional unit 42, initializes the SSID and password used for OTA but does not initialize the SSID and password used for purposes other than OTA. Alternatively, as a method for initializing the SSID and password, the second functional unit 43 may be configured to output an initialization failure notification to the first functional unit 42, and upon determining that the initialization failure notification from the second functional unit 43 has been received, the first functional unit 42 may retry outputting the initialization instruction notification. Furthermore, the second functional unit 43 may detect an initialization failure and internally retry initialization of the SSID and password used for OTA. In this case, an upper limit may be set for the number of retries.

[0068] As described above, according to the embodiment, the following advantageous effects can be obtained. When the OTA master 14 confirms the completion of the OTA before the vehicle is released to the market, it transmits an initialization instruction notification to the DCM 4, and when the DCM 4 receives the initialization instruction notification from the OTA master 14, it initializes the SSID used in the OTA before the vehicle is released to the market. By initializing the SSID used in the OTA before the vehicle is released to the market, it is possible to prevent problems from occurring due to the SSID being left unused.

[0069] The present disclosure includes the following disclosures in addition to what is set forth in the claims: [1] A master device (14) that performs processing related to software update via a wireless line with wireless equipment before a vehicle is released to the market, wherein, when the software update before the vehicle is released to the market is completed, the master device instructs a connection information holding device that holds the connection information to initialize connection information used to connect the wireless line.

[0070] [2] A master device as described in [1] that instructs the connection information holding device to initialize the connection information upon completion of the software update by identifying the type of software update as a software update before the vehicle is released to the market.

[0071] [3] The master device according to [1] or [2], wherein, upon identifying a failure in the initialization of the connection information in the connection information holding device, the master device retries issuing an instruction to initialize the connection information to the connection information holding device.

[0072] [4] The master device according to [3], wherein when it determines that the number of retries of the instruction to initialize the connection information to the connection information holding device has reached an upper limit, it stores initialization failure information indicating that the initialization of the connection information has failed.

[0073] [5] The master device according to any one of [1] to [4], which instructs the connection information holding device to initialize at least one of an SSID and a password as the connection information.

[0074] [6] A connection information holding device (4) that holds connection information used by a master device that performs processing related to software updates with wireless equipment via a wireless line, wherein the connection information holding device initializes the connection information when instructed to do so by the master device.

[0075] [7] A connection information holding device according to [6], which holds connection information used by the master device and connection information used for purposes other than software update processing, and when an instruction to initialize the connection information is given by the master device, initializes the connection information used by the master device, but does not initialize the connection information used for purposes other than software update processing.

[0076] [8] The connection information holding device according to [6] or [7], which is an in-vehicle communication device or an in-vehicle infotainment system device.

[0077] Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and modifications within the scope of equivalents. In addition, various combinations and forms, as well as other combinations and forms including only one element, more than one element, or less than one element, are also within the scope and spirit of the present disclosure.

[0078] The control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the control unit and the method described herein may be implemented by a special-purpose computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit and the method described herein may be implemented by one or more special-purpose computers configured by combining a processor and memory programmed to perform one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible storage medium.

Claims

1. A master device (14) that performs software update processing via a wireless line with wireless equipment before a vehicle is released to the market, and when the software update before the vehicle is released to the market is completed, the master device instructs a connection information holding device that holds the connection information to initialize the connection information used to connect the wireless line.

2. A master device as described in claim 1, which instructs the connection information holding device to initialize the connection information when the type of software update is identified as a software update performed before the vehicle is released to the market and the software update is completed.

3. The master device according to claim 1, wherein, when a failure in the initialization of the connection information in the connection information holding device is identified, the master device retries issuing an instruction to the connection information holding device to initialize the connection information.

4. A master device as described in claim 3, which, when it determines that the number of retries to instruct the connection information holding device to initialize the connection information has reached an upper limit, stores initialization failure information indicating that initialization of the connection information has failed.

5. The master device according to claim 1, which instructs the connection information holding device to initialize at least one of an SSID and a password as the connection information.

6. A connection information holding device (4) that holds connection information used by a master device that performs software update processing with wireless equipment via a wireless line, wherein the connection information holding device initializes the connection information when instructed to do so by the master device.

7. A connection information holding device as described in claim 6, which holds connection information used by the master device and connection information used for purposes other than software update processing, and when instructed by the master device to initialize the connection information, initializes the connection information used by the master device but does not initialize the connection information used for purposes other than software update processing.

8. The connection information holding device according to claim 6, which is an in-vehicle communication device or an in-vehicle infotainment system device.

9. A vehicle system (3) comprising a master device (14) that performs processing related to software updates via a wireless line between the vehicle and wireless equipment before the vehicle is released to the market, and a connection information holding device (4) that holds connection information used by the master device, wherein, when the master device completes the software update before the vehicle is released to the market, the master device instructs the connection information holding device to initialize the connection information used to connect the wireless line, and the connection information holding device initializes the connection information when instructed to do so by the master device.

10. An electronic control device (41) comprising a first functional unit (42) that performs processing related to software updates via a wireless line between the vehicle and wireless equipment before the vehicle is released to the market, and a second functional unit (43) that holds connection information used by the first functional unit, wherein, upon completing the software update before the vehicle is released to the market, the first functional unit instructs the second functional unit to initialize the connection information used to connect the wireless line, and the second functional unit initializes the connection information when instructed to do so by the first functional unit.

11. A connection information initialization instruction method in a master device (14) that performs processing related to software updates via a wireless line with wireless equipment before a vehicle is released to the market, the method including, when the software update before the vehicle is released to the market is completed, instructing a connection information holding device that holds the connection information to initialize the connection information used to connect the wireless line.

12. A connection information initialization instruction program that causes a master device (14) that performs processing related to software updates via a wireless line with wireless equipment before a vehicle is released to the market to execute an initialization instruction procedure that instructs a connection information holding device that holds the connection information to initialize the connection information used to connect the wireless line when the software update before the vehicle is released to the market is completed.

Citation Information

Patent Citations

  • Software upgrading method and electronic equipment

    CN117270917A

  • Information processing unit, control method of the same, program, and recording medium

    JP2017038236A

  • Information distribution system and vehicle-mounted device

    WO2019012821A1

  • Vehicle electronic control system, vehicle master device, rewriting instruction method by writing back config information, and rewriting instruction program by writing back config information

    WO2021039795A1