Software updating system and software updating method

The software update system for vehicle ECUs allows selective updating based on user choice and situational awareness, addressing the need to maintain security functions during OTA updates, thus enhancing crime prevention and user control.

WO2026004919A1PCT designated stage Publication Date: 2026-01-02DENSO CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/022884
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-28
Filing Date
2025-06-25
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Conventional software update technologies for vehicle electronic control units (ECUs) via OTA (Over the Air) often require stopping security functions while the vehicle is parked, posing a risk to crime prevention.

Method used

A software update system and method that allows users to selectively choose whether to update software based on the situation, considering the impact on running applications and user presence, using a software determination unit and selection presentation unit to present options for updating software that cannot be stopped while parked.

Benefits of technology

Enables users to appropriately choose when to update software depending on the situation, ensuring security functions remain active when needed, thereby enhancing crime prevention and user control during OTA updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025022884_02012026_PF_FP_ABST
    Figure JP2025022884_02012026_PF_FP_ABST
Patent Text Reader

Abstract

A software updating system (1) updates software for a vehicle electronic control unit (11) installed in a vehicle (3), using update data acquired from outside the vehicle. In the software updating system (1), when updating software to be updated, it is determined whether parked-state software that is being executed when in a parked state cannot be updated unless execution of the software to be updated is stopped. When the software to be updated cannot be updated unless execution of the parked-state software is stopped, a user is provided with a presentation enabling selection of whether or not to update the software to be updated.
Need to check novelty before this filing date? Find Prior Art

Description

Software update system and software update method CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This international application claims the benefit of Japanese Patent Application No. 2024-105629, filed with the Japan Patent Office on June 28, 2024, the entire disclosure of which is incorporated herein by reference.

[0002] The present disclosure relates to a technology for updating software in an electronic control unit mounted on a vehicle.

[0003] In recent years, a technology for updating software in an electronic control unit mounted on a vehicle, in which software update data is transmitted wirelessly from a center or the like, has become known, as described in, for example, Patent Document 1. This technology for updating software wirelessly (i.e., remote software update technology) is called an OTA update, but hereinafter may be referred to simply as OTA. OTA is an abbreviation for Over the Air.

[0004] Japanese Patent Application Laid-Open No. 2021-128362

[0005] As a result of detailed investigation by the inventors, the following problems were found in the conventional techniques.

[0006] While the vehicle is parked, security functions are often turned on for crime prevention purposes, but when updating software wirelessly (i.e., performing OTA) as described above, there is a concern that the security functions may be stopped. In other words, when updating software related to the security functions while the vehicle is parked, it is necessary to stop the security functions, which is undesirable from the viewpoint of crime prevention, etc.

[0007] Thus, when attempting to implement OTA when software is running while the vehicle is parked, it is important to consider the associated problems, but this consideration has not been given enough thought.

[0008] The present disclosure aims to provide a technology that allows a user to appropriately select whether or not to update software depending on the situation when attempting to update software via OTA or the like while the vehicle is parked.

[0009] One aspect of the present disclosure relates to a software update system for updating software of an electronic control unit (ECU) mounted on a vehicle using update data acquired from outside the vehicle, the software update system including a software determination unit and a selection presentation unit.

[0010] The software determination unit is configured to determine, when updating software, whether the software to be updated is software that cannot be updated unless the execution of parked software that is being executed while the vehicle is parked is stopped.

[0011] The selection presentation unit is configured to present the user with the option of whether or not to update the software to be updated when the software to be updated cannot be updated unless the execution of the software while the vehicle is parked is stopped.

[0012] With this configuration, in the present disclosure, when updating software to be updated while the vehicle is parked (for example, when attempting to perform OTA), it is possible to select whether or not to update the software to be updated appropriately depending on the situation (for example, depending on the type of software currently in operation, etc.).

[0013] In other words, in the present disclosure, when updating software using update data obtained from outside the vehicle, if the parked software is software that cannot be updated unless the software execution is stopped, the user is presented with a choice as to whether or not to update the software to be updated. Therefore, the user can decide whether or not to update the software to be updated based on the presented content.

[0014] For example, when the user is near the vehicle and does not need to activate the security function, the software can be updated while parked by permitting the software update while parked. On the other hand, when the user is away from the vehicle and needs to activate the security function, the software update while parked can be prohibited to ensure security.

[0015] b) Another aspect of the present disclosure relates to a software update method for updating software of an electronic control unit mounted on a vehicle using update data acquired from outside the vehicle.

[0016] In this software update method, when updating software using update data obtained from outside the vehicle, if the parked software being executed while the vehicle is parked is software that cannot be updated unless the execution of the software is stopped, the user is presented with a choice as to whether or not to update the software to be updated.

[0017] With this configuration, in the present disclosure, when updating software to be updated while the vehicle is parked (for example, when attempting to perform OTA), it is possible to select whether or not to update the software to be updated appropriately depending on the situation (for example, depending on the type of software currently in operation, etc.).

[0018] The above and other objects, features, and advantages of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings.

[0014] Fig. 1 is a block diagram showing the configuration of a software update system according to a first embodiment.

[0015] Fig. 2 is an explanatory diagram functionally showing a vehicle ECU according to the first embodiment.

[0016] Fig. 3 is an explanatory diagram functionally showing a vehicle equipped with a plurality of vehicle ECUs according to the first embodiment.

[0017] Fig. 4 is a flowchart showing the processing of the software update system according to the first embodiment.

[0018] Fig. 5 is an explanatory diagram showing the configuration relating to operation on the vehicle side of a software update system according to a second embodiment.

[0019] Fig. 6 is an explanatory diagram showing the configuration relating to operation on the smartphone side of the software update system according to the second embodiment.

[0020] Fig. 7 is an explanatory diagram showing the configuration of pre-setting on the vehicle side of a software update system according to a third embodiment.

[0021] Fig. 8 is an explanatory diagram showing the configuration of pre-setting on the smartphone side of the software update system according to the third embodiment.

[0022] Fig. 9 is an explanatory diagram showing another configuration of pre-setting on the smartphone side of the software update system according to the third embodiment.

[0019] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the drawings.

[0020] 1. First Embodiment In the first embodiment, a technique for updating software in an electronic control unit while the vehicle is parked will be described based on software update data wirelessly transmitted from a center.

[0021] [1-1. Overall Configuration] As shown in FIG. 1, the software update system 1 of the first embodiment includes an in-vehicle device 5 mounted on a vehicle (e.g., an automobile) 3, a center 7 capable of wirelessly communicating with the in-vehicle device 5, and a smartphone 9 that is an information terminal capable of communicating with the in-vehicle device 5 and / or the center 7.

[0022] [1-2. Configuration of Each Unit] Each unit of the software update system 1 will be described below.

[0023] 1, the in-vehicle device 5 includes a vehicle ECU 11 and an OTA ECU 13, as well as a vehicle communication unit 15, a vehicle display unit 17, and a sensor unit 19. ECU stands for Electronic Control Unit, and OTA stands for Over the Air.

[0024] <Vehicle ECU> The vehicle ECU 11 is an electronic control device that controls the operation of the vehicle 3 , and includes a vehicle control unit 21 and a vehicle storage unit 23 .

[0025] The vehicle control unit 21 is a device that performs various calculation processes related to the operation of the vehicle ECU 11, and is mainly composed of, for example, a well-known microcomputer (hereinafter referred to as a microcomputer) having a CPU, RAM, ROM, etc.

[0026] The various functions of the vehicle control unit 21 are realized by the CPU executing a program stored in a non-transitory storage medium. In this example, for example, a ROM corresponds to the non-transitory storage medium storing the program. Furthermore, by executing this program, a method corresponding to the program is performed.

[0027] The vehicle control unit 21 may include one or more microcomputers. Furthermore, the method for realizing the various functions of the vehicle control unit 21 is not limited to software; some or all of the functions may be realized using one or more pieces of hardware. For example, if the functions are realized by electronic circuits that are hardware, the electronic circuits may be digital circuits including multiple logic circuits, analog circuits, or a combination of these.

[0028] The vehicle storage unit 23 may be a known non-volatile memory, such as a flash memory or an EEPROM that can rewrite various data.

[0029] <OTA ECU> The OTA ECU 13 is an electronic control device that receives software update data wirelessly transmitted from the center 7 and performs control to update the software of various ECUs such as the vehicle ECU 11. That is, the OTA ECU 13 is an electronic control device that performs control to implement OTA, and includes an OTA control unit 25 and an OTA storage unit 27.

[0030] The OTA control unit 25 is a device that performs various calculation processes related to the operation of the OTA ECU 13, and is mainly composed of a well-known microcomputer having a CPU, RAM, ROM, etc., for example.

[0031] The various functions of the OTA control unit 25 are realized by the CPU executing a program stored in a non-transitory physical recording medium. Note that the OTA control unit 25 is basically the same as the vehicle control unit 21, and therefore a description thereof will be omitted.

[0032] The OTA storage unit 27 may be a known non-volatile memory, such as a flash memory or an EEPROM that is rewritable for various data. The OTA storage unit 27 may store update data for software downloaded from the center 7. If the vehicle storage unit 23 has an area for storing update data for software downloaded from the center 7, the update data may be stored in that area.

[0033] Although the OTA ECU 13 and the vehicle ECU 11 are described as separate ECUs here, the vehicle ECU 11 may have the functions of the OTA ECU 13 .

[0034] <Vehicle Communication Unit> The vehicle communication unit 15 is a communication device capable of communicating with the center 7 and the smartphone 9 .

[0035] The vehicle communication unit 15 can receive software update data transmitted from the center 7 via communication between the vehicle 3 and a network, for example, V2N communication (i.e., V2N communication). V2N is an abbreviation for Vehicle to Cellular Network.

[0036] The vehicle communication unit 15 is also capable of communicating with the smartphone 9 via, for example, Bluetooth (registered trademark) or Bluetooth Low Energy.

[0037] <Vehicle Display Unit> Examples of the vehicle display unit 17 include a display, etc. Furthermore, if the display has a touch panel function, the display may be provided with a vehicle operation unit 29 that can be manually operated by the user.

[0038] <Sensor Unit> Examples of the sensor unit 19 include a shift position sensor 31 that detects the position of the shift lever (e.g., the parking position, etc.), an in-vehicle camera 33 that takes images of the interior of the vehicle (i.e., the interior of the vehicle), and a seat sensor 35 that detects the seat in which a person is seated.

[0039] [1-2-2. Configuration of Smartphone Side] As shown in FIG. 1 , an information terminal, for example, a smartphone 9, includes a smartphone control unit 43, a smartphone storage unit 45, a smartphone communication unit 39, and a smartphone display unit 41.

[0040] <Smartphone Control Unit> The smartphone control unit 43 is a device that performs various calculation processes related to the operation of the smartphone 9, and is mainly configured with, for example, a well-known microcomputer having a CPU, RAM, ROM, and the like.

[0041] The various functions of the smartphone control unit 43 are realized by the CPU executing a program stored in a non-transient physical recording medium. Note that the smartphone control unit 43 is basically the same as the vehicle control unit 21, etc., and therefore a description thereof will be omitted.

[0042] <Smartphone Storage Unit> The smartphone storage unit 45 may be a well-known non-volatile memory, such as a flash memory or an EEPROM that is capable of rewriting various types of data.

[0043] <Smartphone Communication Unit> The smartphone communication unit 39 is a communication device capable of communicating with the center 7 and the vehicle 3 (i.e., the vehicle communication unit 15).

[0044] The smartphone communication unit 39 can communicate with the center 7 by wireless communication via a well-known base station. The smartphone communication unit 39 can also communicate with the vehicle communication unit 15 by the above-mentioned Bluetooth, Bluetooth Low Energy, or the like.

[0045] <Smartphone Display Unit> Examples of the smartphone display unit 41 include a display, etc. Furthermore, if the display has a touch panel function, the display can be provided with a smartphone operation unit 47 that can be manually operated by the user.

[0046] [1-2-3. Center Configuration] The center 7 is configured by a server (i.e., a center server) capable of processing and storing known data.

[0047] The center 7 can communicate with the vehicle communication unit 15 of the vehicle 3 by the above-mentioned V2N communication or the like. That is, the center 7 can wirelessly transmit software update data to the vehicle 3. Also, well-known wireless communication is possible between the center 7 and the smartphone 9.

[0048] [1-3. Functional Configuration] Next, the functional configuration of the vehicle ECU 11 will be described.

[0049] 2, the vehicle ECU 11 includes a physical hardware configuration, an OS configuration, and an APP configuration. The OS stands for Operating System, and the APP stands for Application Software. As is well known, the OS is basic software, and the APP is application software that runs on the OS.

[0050] Here, for example, a case will be described in which an OS and an APP are stored in the vehicle storage unit 23. In the first embodiment, although both the APP and the OS can be updated, the following description will focus on updating the APP.

[0051] The above-mentioned APPs include APPs that operate while the vehicle is parked and APPs that do not operate while the vehicle is parked. APPs that operate while the vehicle is parked include a security APP that operates to prevent crime while the vehicle is parked, a charging APP that operates when charging the battery while the vehicle is parked, and an APP that prevents small children from being left behind in the vehicle (i.e., an APP for detecting whether a small child has been left behind).

[0052] 3 shows an example in which a plurality of ECU-A11a and ECU-B11b are mounted on a vehicle 3 as the vehicle ECU 11. Note that the configuration other than the ECU-A11a and ECU-B11b (e.g., the OTA ECU 13, the vehicle communication unit 15, the vehicle display unit 17, the sensor unit 19, etc.) is the same as the configuration shown in FIG.

[0053] [1-4. Control Processing] Next, a control processing executed on the vehicle 3 side (for example, the OTA ECU 13, etc.) in the first embodiment will be described.

[0054] Here, the case where the predetermined software that runs while the vehicle is parked is taken as an example where the predetermined software is application software (hereinafter referred to as application) that runs on an OS. Specifically, examples of applications (i.e., apps) include a security application that runs for crime prevention purposes while the vehicle is parked, and a charging application that runs when charging the battery while the vehicle is parked.

[0055] As shown in the flowchart of FIG. 4, in step (hereinafter, S) 100, if the center 7 notifies the in-vehicle device 5 (e.g., the OTA ECU 13) of an OTA campaign (i.e., a notification that a software update is available), the process proceeds to S110.

[0056] In S110, the in-vehicle device 5 downloads software (i.e., SW) update data transmitted from the center 7. Here, the method of downloading the update data may require user approval for execution of the download or may not require user approval. The downloaded update data is stored in, for example, the OTA storage unit 27 or the vehicle storage unit 23.

[0057] In the next step S120, it is determined whether the vehicle 3 is parked. For example, it is determined whether the position of the shift lever is in the parking position based on a signal from the shift position sensor 31. If the determination here is affirmative, the process proceeds to step S130, whereas if the determination here is negative, the process is temporarily terminated.

[0058] In S130, since the vehicle is parked, it is determined whether predetermined software (i.e., predetermined software set to run while the vehicle is parked) is actually running. If the determination here is affirmative, the process proceeds to S150, whereas if the determination here is negative, the process proceeds to S140. Examples of the predetermined software include the security application and charging application described above.

[0059] In S140, since the predetermined application is not running, a sequence for executing a normal OTA (i.e., an OTA sequence) is executed, and this process is temporarily terminated. In other words, since there is no problem in executing an OTA while the vehicle is parked, the downloaded update data (i.e., an update application) is installed according to the normal update procedure, and the updated application is made executable.

[0060] On the other hand, in S150, it is determined whether an application running while the vehicle is parked (i.e., an active app) is an application that will be stopped if OTA is performed. If the determination here is affirmative, the process proceeds to S160, whereas if the determination here is negative, the process proceeds to S140. Examples of applications that will be stopped if OTA is performed include the above-mentioned security application and charging application.

[0061] In S160, it is determined whether a priority is set in advance between the execution of an application that runs while the vehicle is parked and the execution of OTA. If the determination here is affirmative, the process proceeds to S170, whereas if the determination here is negative, the process proceeds to S190.

[0062] In S170, it is determined whether or not OTA is set to be prioritized. If the determination here is affirmative, the process proceeds to S180, whereas if the determination here is negative, the process proceeds to S230.

[0063] In S180, since OTA is set to be prioritized, the above-described OTA sequence is executed, and the process ends for the time being.

[0064] On the other hand, in S230, since the setting is not set to prioritize OTA, the OTA is not performed, and the operation of the application running during parking continues, and this process is temporarily terminated.

[0065] In S190, which is determined if a negative determination is made in S160, the process proceeds to S200 to determine whether a person (e.g., a user) is present in the vehicle cabin. If a positive determination is made here, the process proceeds to S200, whereas if a negative determination is made here, the process proceeds to S210. For example, using an image captured by the in-vehicle camera 33, it is possible to determine whether a person is present in the vehicle cabin (e.g., whether a person is in the driver's seat) through well-known image analysis. The seat sensor 35 can also determine whether a person is seated in a seat (e.g., the driver's seat) (i.e., whether a person is present in the vehicle cabin).

[0066] In S200, since there is a person in the vehicle, a selection screen is displayed on the vehicle display unit 17 (i.e., the display) to allow the user to select whether to stop the running application and perform OTA, and the process proceeds to S220. For example, the vehicle display unit 17 may display a message asking, "Do you want to stop the running application and update the application?", along with "Yes" and "No" selection buttons displayed near the message. At this time, the type of the running application (for example, that it is a security application) may also be displayed.

[0067] These selection buttons are on the vehicle operation unit 29 which functions as a touch panel, so by touching any of the selection buttons, it is possible to select whether or not to stop the running application and perform OTA.

[0068] On the other hand, in S210, since there is no one in the vehicle cabin, a selection screen is displayed on the smartphone display unit 41 (i.e., display) of the smartphone 9, similar to S200, allowing the user to select whether to stop the running application and perform OTA, and the process proceeds to S210. For example, the smartphone display unit 41 displays a message asking, "Do you want to stop the running application and update the application?", and displays selection buttons for "Yes" and "No" near the display. These selection buttons are the smartphone operation unit 47, which functions as a touch panel.

[0069] In S220, it is determined whether the user has consented to the implementation of OTA, and if the determination here is affirmative, the process proceeds to S240, whereas if the determination here is negative, the process proceeds to S230. In other words, it is determined whether the user has consented to the implementation of OTA by operation of the vehicle operation unit 29 of the vehicle 3 or operation of the smartphone operation unit 47 of the smartphone 9.

[0070] In S240, since the user has consented to the implementation of OTA, the above-described OTA sequence is implemented to update the running application, and then this process is temporarily terminated. When this update is performed, the operation of the running application is stopped, but the application may be operated after the update.

[0071] <Other Control Processes> Applications that run while the vehicle is parked include the security application and charging application described above, as well as an application for detecting whether a child has been left behind.

[0072] This application for detecting child abandonment can be set to be executed with priority over OTA. Therefore, if the application running while the vehicle is parked is the application for detecting child abandonment, OTA will not be executed and the application for detecting child abandonment can continue to be executed.

[0073] Alternatively, even if the application running while the vehicle is parked is an application for detecting an infant being left behind, if there is no one in the vehicle, as described above, the smartphone 9 may present the user with a prompt as to whether or not to perform OTA, allowing the user to select. Alternatively, even if the application running while the vehicle is parked is an application for detecting an infant being left behind, if there is no one in the vehicle, OTA may be performed as is.

[0074] [1-6. Effects] According to the first embodiment, the following effects can be obtained.

[0075] (1a) In the first embodiment, when updating software via OTA while the vehicle is parked, if the software to be updated cannot be updated unless the execution of software running while the vehicle is parked (i.e., parked software) is stopped, the user is presented with a choice as to whether or not to update the software to be updated. With this configuration, when attempting to perform OTA while the vehicle is parked, the user can appropriately choose whether or not to perform OTA depending on the situation (e.g., depending on the type of software running, etc.).

[0076] In other words, when updating software via OTA, if the software to be updated cannot be updated unless the execution of the parked software is stopped, the user is presented with a choice of whether or not to update the software to be updated. Therefore, the user can decide whether or not to update the software to be updated based on the presented content.

[0077] For example, when the user is near the vehicle 3 and there is no need to activate the security function, etc., the OTA can be performed by permitting the execution of the OTA. On the other hand, when the user is away from the vehicle 3 and there is a need to activate the security function, etc., the OTA can be prohibited from being executed, thereby ensuring crime prevention, etc.

[0078] (1b) In the first embodiment, it is possible to determine whether the vehicle 3 is parked based on, for example, the position of the shift lever. In other words, it is possible to determine that the vehicle 3 is parked when the position of the shift lever is in the “parking” position.

[0079] (1c) In the first embodiment, while the vehicle is parked, it can be determined whether software that can be executed while the vehicle is parked (for example, a security application) is actually being executed.

[0080] (1d) In the first embodiment, the vehicle display unit 17 and the vehicle operation unit 29 can be used to present the user with the option of whether or not to update the software to be updated via OTA.

[0081] (1e) In the first embodiment, the smartphone display unit 41 and the smartphone operation unit 47 can be used to present the user with the option of whether to update the software to be updated via OTA. In this case, the smartphone 9 can transmit and receive information required for implementing or not implementing OTA via the center 7.

[0082] (1f) In the first embodiment, it is possible to determine whether or not there is a person in the vehicle cabin based on signals from the in-vehicle camera 33 and the seat sensor 35. Therefore, when there is a person in the vehicle cabin, it is possible to select whether or not to perform OTA using the in-vehicle device 5, and when there is no person in the vehicle cabin, it is possible to select whether or not to perform OTA using the smartphone 9.

[0083] [1-7. Correspondence] Next, the relationship between the present disclosure and the first embodiment will be described.

[0084] The software update system corresponds to the software update system 1, the vehicle corresponds to the vehicle 3, the electronic control unit corresponds to the vehicle ECU 11 etc., the soft judgment unit corresponds to the processing of S150, the selection presentation unit corresponds to the processing of S210 and S220, the parking judgment unit corresponds to the processing of S120, the execution judgment unit corresponds to the processing of S130, and the priority judgment unit corresponds to the processing of S160.

[0085] [2. Second Embodiment] The second embodiment has the same basic configuration as the first embodiment, and therefore the following mainly describes the differences from the first embodiment. Note that the same reference numerals as those in the first embodiment indicate the same configuration, and reference is made to the preceding description.

[0086] In the second embodiment, a case where the OS is updated will be described.

[0087] In the second embodiment, a software update system 1 similar to that of the first embodiment is used, as shown in Figures 5 and 6. Note that in Figures 5 and 6, some of the configurations similar to those of the first embodiment are omitted.

[0088] <When an In-Vehicle Device is Used> Here, an example will be described in which the vehicle display unit 17 and the vehicle operation unit 29 of the in-vehicle device 5 are used when the user is inside the vehicle.

[0089] As shown in FIG. 5, when updating the OS of the vehicle ECU 11, for example, when updating the OS of a security application that runs while the vehicle is parked, the security application needs to be stopped while the vehicle is parked.

[0090] Therefore, similar to the first embodiment, a selection screen that allows the user to select whether to stop running applications and perform OTA of the OS is displayed on the vehicle display unit 17. That is, the vehicle display unit 17 displays a message saying "Do you want to stop running applications and update the basic software?", and displays "Yes" and "No" on the vehicle operation unit 29 (i.e., selection buttons) near the display.

[0091] This allows the user to select whether or not to perform an OTA OS update using the selection button.

[0092] <When a Smartphone is Used> Here, an example will be described in which the smartphone display unit 41 and the smartphone operation unit 47 of the smartphone 9 are used when the user is not in the vehicle cabin. Note that the case in which the smartphone 9 is used is similar to the case in which the in-vehicle device 5 described above is used, and therefore will be briefly described.

[0093] As shown in Figure 6, when updating the OS of the vehicle ECU 11, a selection screen is displayed on the smartphone display unit 41 of the smartphone 9, allowing the user to select whether to stop running applications and perform OTA, as in the first embodiment.

[0094] More specifically, when updating the OS of the vehicle ECU 11, the in-vehicle device 5 notifies the center 7 that the OS will be updated, and the center 7 then notifies the smartphone 9 that the OS will be updated. In response to this notification, the smartphone 9 displays on the smartphone display unit 41 a message asking, "Do you want to stop running applications and update the basic software?", and displays selection buttons for "Yes" and "No" near the message.

[0095] This allows the user to select whether or not to perform an OTA OS update using the selection button on the smartphone 9.

[0096] The selected content is then notified from the smartphone 9 to the in-vehicle device 5 via the center 7, and the in-vehicle device 5 can perform processing corresponding to whether or not to implement OTA of the OS based on the notified content (i.e., the selection result).

[0097] The second embodiment has the same effects as the first embodiment.

[0098] [3. Third Embodiment] The third embodiment has the same basic configuration as the first embodiment, and therefore the following mainly describes the differences from the first embodiment. Note that the same reference numerals as those in the first embodiment indicate the same configuration, and reference is made to the preceding description.

[0099] In the third embodiment, an example will be described in which it is previously set which of "execution of software while parked" and "execution of software update via OTA" is to be given priority.

[0100] In the third embodiment, a software update system 1 similar to that of the first embodiment is used, as shown in Figures 7 to 9. Note that in Figures 7 to 9, some of the configurations similar to those of the first embodiment are omitted.

[0101] <Using an In-Vehicle Device> Here, a case where advance setting is performed using the vehicle operation unit 29 of the in-vehicle device 5 will be described.

[0102] 7 , when updating an application or OS of the vehicle ECU 11, it is possible to set in advance whether to prioritize "operation of the application or OS running while the vehicle is parked" or "updating the application or OS via OTA" using the vehicle operation unit 29. Note that this example shows a case where an application or OS cannot be updated via OTA unless the operation of the application or OS running while the vehicle is parked is stopped (the same applies hereinafter).

[0103] For example, a menu of various operations is displayed on the vehicle display unit 17 by the user operating the vehicle operation unit 29. When the user selects a pre-setting item from the menu, the vehicle display unit 17 displays, for example, "Please set whether to prioritize application operation or application update while parked." Along with this, selection buttons for "Give priority to application operation" and "Give priority to application update" are displayed near the display. Note that instead of the "application," the OS may be included in the display, for example, by displaying "Please set whether to prioritize software operation or software update while parked," along with selection buttons for "Give priority to software operation" and "Give priority to software update" (the same applies hereinafter).

[0104] This allows the user to set in advance, by using the selection button, whether to prioritize "application operation" or "application update (i.e., OTA implementation)." The result of this setting can be stored, for example, in the OTA storage unit 27 of the OTA ECU 13.

[0105] Therefore, in the subsequent processing, processing corresponding to whether or not to implement OTA can be performed according to the contents previously set as described above.

[0106] <Using a Smartphone (Part 1)> Here, an example will be described in which the smartphone operation unit 47 of the smartphone 9 is used to perform presetting via the center 7.

[0107] As shown in Figure 8, when updating an application or OS of the vehicle ECU 11, it is possible to use the smartphone 9 to set in advance whether to prioritize "operation of the application or OS running while the vehicle is parked" or "updating the application or OS via OTA."

[0108] For example, a menu of various operations is displayed on the smartphone display unit 41 by the user operating the smartphone operation unit 47. When the user selects a pre-setting item from the menu, for example, "Please set whether to prioritize application operation or application updates while parked," is displayed on the smartphone display unit 41. At the same time, selection buttons for "Prioritize application operation" and "Prioritize application updates" are displayed near the display.

[0109] This allows the user to use the selection button to set in advance whether to prioritize "application operation" or "application update (i.e., OTA implementation)."

[0110] In detail, the selection result using the selection button is notified to the in-vehicle device 5 from the smartphone 9 via the center 7, and the notification content (i.e., the selection result) can be stored, for example, in the OTA memory unit 27 of the OTA ECU 13.

[0111] Therefore, in the subsequent processing, processing corresponding to whether or not to implement OTA can be performed according to the contents previously set as described above.

[0112] <Using a Smartphone (Part 2)> Here, another example of presetting using the smartphone operation unit 47 of the smartphone 9 and using Bluetooth or Bluetooth Low Energy will be described.

[0113] That is, a case will be described in which communication via Bluetooth or Bluetooth Low Energy (hereinafter referred to as specific wireless communication) is possible between the smartphone and the in-vehicle device 5.

[0114] As shown in Figure 9, when updating an application or OS of the vehicle ECU 11, it is possible to set in advance using the smartphone 9 (i.e., using specific wireless communication) whether to prioritize "operation of the application or OS running while the vehicle is parked" or "updating the application or OS via OTA."

[0115] For example, a menu of various operations is displayed on the smartphone display unit 41 by the user operating the smartphone operation unit 47. When the user selects a pre-setting item from the menu, for example, "Please set whether to prioritize application operation or application updates while parked," is displayed on the smartphone display unit 41. At the same time, selection buttons for "Prioritize application operation" and "Prioritize application updates" are displayed near the display.

[0116] This allows the user to use the selection button to set in advance whether to prioritize "application operation" or "application update (i.e., OTA implementation)."

[0117] In detail, the selection result by the selection button is notified from the smartphone 9 to the in-vehicle device 5 using specific wireless communication, and the notification content (i.e., the selection result) can be stored, for example, in the OTA memory unit 27 of the OTA ECU 13.

[0118] Therefore, in the subsequent processing, processing corresponding to whether or not to implement OTA can be performed according to the contents previously set as described above.

[0119] In addition, if the smartphone 9 is able to communicate with the in-vehicle device 5 via specific wireless communication, it may notify the in-vehicle device 5 of the selection result via the specific wireless communication, while if the smartphone 9 is unable to communicate with the in-vehicle device 5 via specific wireless communication, it may notify the in-vehicle device 5 of the selection result using the center 7.

[0120] The third embodiment has the same effects as the first embodiment. Furthermore, in the third embodiment, it is possible to set in advance whether to "prioritize the operation of applications, etc." or "prioritize the implementation of OTA," which has the advantage of reducing the effort required for the user to make a selection when responding to OTA, and the advantage of reducing the burden of processing when making the above-mentioned selection in the software update system 1 (for example, displaying a selection screen and processing after the selection).

[0121] [4. Other Embodiments] Although the embodiments of the present disclosure have been described above, it goes without saying that the present disclosure is not limited to the above-described embodiments and can take on various forms.

[0122] (4a) In the present disclosure, the control process is performed when the vehicle is parked. A determination condition for determining that the vehicle is parked may be that the position of the shift lever is in a position indicating parking (e.g., PARKING).

[0123] Another condition for determining whether the vehicle is parked is that the power is off, such as when the ignition switch is off or the power switch is off.

[0124] The power switch is a switch that switches on and off the driving power supplied from the battery in at least a vehicle that is driven by electricity, such as a well-known hybrid electric vehicle (HEV), plug-in hybrid electric vehicle (PHEV), battery electric vehicle (BEV), or fuel cell electric vehicle (FCEV).

[0125] When the ignition switch or power switch is off, the vehicle engine or the vehicle drive motor will not operate even if the accelerator is operated, but power is supplied to the device that updates the software and operates the APP so that the control processing (i.e., software update) of the present disclosure and the APP that operates while parked can operate.

[0126] (4b) In the above embodiment, an example of updating software via OTA (i.e., wirelessly) was described. However, the present disclosure can be applied to cases where software is updated using an update device that is connected to the vehicle via a wired connection, or where software is updated using a memory card such as an SD card.

[0127] (4c) The operations of the software update system described in this disclosure may be realized by a special purpose computer provided by configuring a processor and memory programmed to perform one or more functions embodied in a computer program.

[0128] Alternatively, the operations of the software update system described in this disclosure may be implemented by a special purpose computer provided by configuring a processor with one or more dedicated hardware logic circuits.

[0129] Alternatively, the operations of the software update system described in this disclosure may be implemented by one or more special-purpose computers configured by a combination of a processor and memory programmed to perform one or more functions and a processor configured with one or more hardware logic circuits.

[0130] The computer program may also be stored as instructions for execution by a computer on a computer-readable non-transitory storage medium. The means for realizing the functionality of the software update system need not necessarily include software, and all of the functionality may be realized using one or more pieces of hardware.

[0131] (4d) In addition to the software update system described above, the present disclosure can also be realized in various forms, such as a configuration that includes the software update system as a component, a program for causing the computer of the software update system to function, a non-transitory tangible recording medium such as a semiconductor memory on which this program is recorded, and a software update method.

[0132] (4e) Multiple functions possessed by one component in each of the above embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Furthermore, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, part of the configuration of each of the above embodiments may be omitted. Furthermore, at least part of the configuration of each of the above embodiments may be added to or substituted for the configuration of another embodiment. [Technical Ideas Disclosed in the Present Specification] [Item 1] A software update system (1) that updates software of an electronic control unit (11) mounted on a vehicle (3) using update data acquired from outside the vehicle, the software update system comprising: a software determination unit (S150) configured to determine, when updating the software, whether the software to be updated is software that cannot be updated unless execution of parked software that is running while the vehicle is parked is stopped; and a selection presentation unit (S210, S220) configured to present to a user the option of whether or not to update the software to be updated, if the software to be updated is software that cannot be updated unless execution of the parked software is stopped.

[0133] [Item 2] The software update system according to Item 1, further comprising: a parking determination unit (S120) configured to determine whether the vehicle is parked.

[0134] [Item 3] The software update system according to item 1 or 2, further comprising: an execution determination unit (S130) configured to determine whether the parking software is actually being executed while the vehicle is parked.

[0135] [Item 4] The software update system according to any one of items 1 to 3, wherein the software update system is configured to allow a user to set in advance which of the executions of the parked software and the update of the software to be updated is to be prioritized in the vehicle.

[0136] [Item 5] A software update system according to any one of items 1 to 4, further comprising: a priority determination unit (S160) that determines whether or not a setting has been made in advance as to which of the executions of the parked software and the update of the software to be updated is to be prioritized; and the selection presentation unit is configured not to present to the user whether or not to update the software to be updated when the priority determination unit makes a positive determination.

[0137] [Item 6] The software update system according to any one of items 1 to 5, further comprising: a software update system configured to determine whether or not there is a person in the vehicle cabin; and, when there is a person in the vehicle cabin, the selection presentation unit presents a prompt to the user in the vehicle to select whether or not to update the software to be updated.

[0138] [Item 7] The software update system according to any one of items 1 to 6, wherein the selection presentation unit is configured to present to the user a choice of whether or not to update the software to be updated in an information terminal (9) capable of communicating with the vehicle or an information terminal (9) capable of communicating with a server (7) capable of communicating with the vehicle.

[0139] [Item 8] A software update system according to any one of items 1 to 7, configured such that it is possible to set in advance which of the executions of the parked software and the update of the software to be updated is to be prioritized in an information terminal (9) capable of communicating with the vehicle or an information terminal (9) capable of communicating with a server (7) capable of communicating with the vehicle.

[0140] [Item 9] A software update method for updating software of an electronic control unit (11) mounted on a vehicle (3) using update data acquired from outside the vehicle, wherein, when updating the software, if the software to be updated cannot be updated unless execution of parked software that is running while the vehicle is parked is stopped, the software update method presents a user with the option of whether or not to update the software to be updated.

Claims

1. A software update system (1) that updates software of an electronic control unit (11) mounted on a vehicle (3) using update data obtained from outside the vehicle, the software update system comprising: a software determination unit (S150) configured to determine, when updating the software, whether the software to be updated is software that cannot be updated unless execution of parked software that is running while the vehicle is parked is stopped; and a selection presentation unit (S210, S220) configured to present a selection to a user on whether or not to update the software to be updated if the software to be updated is software that cannot be updated unless execution of the parked software is stopped.

2. A software update system according to claim 1, comprising: a parking determination unit (S120) configured to determine whether the vehicle is parked or not.

3. A software update system according to claim 1, comprising: an execution determination unit (S130) configured to determine whether the parking software is actually being executed while the vehicle is parked.

4. A software update system as described in claim 1, configured to enable the vehicle to set in advance which of the executions to prioritize: execution of the parked software or execution of the update of the software to be updated.

5. A software update system as described in claim 1, comprising a priority determination unit (S160) that determines whether or not a setting has been made in advance as to which of the executions of the parked software and the update of the software to be updated is to be given priority, and the selection presentation unit is configured not to present to the user whether or not to update the software to be updated if the priority determination unit makes a positive determination.

6. A software update system as described in claim 1, configured to determine whether or not there is a person in the vehicle cabin, and when there is a person in the vehicle cabin, configured to present to the user, via the selection presentation unit in the vehicle, the option of whether or not to update the software to be updated.

7. A software update system as described in claim 1, wherein the selection presentation unit is configured to present the user with the option of whether or not to update the software to be updated in an information terminal (9) capable of communicating with the vehicle or an information terminal (9) capable of communicating with a server (7) capable of communicating with the vehicle.

8. A software update system as described in claim 1, configured so that it is possible to set in advance which of the executions to prioritize between the execution of the parked software and the execution of the update of the software to be updated is to be prioritized in an information terminal (9) capable of communicating with the vehicle or an information terminal (9) capable of communicating with a server (7) capable of communicating with the vehicle.

9. A software update method for updating software of an electronic control unit (11) mounted on a vehicle (3) using update data obtained from outside the vehicle, wherein, when updating the software, if the software to be updated cannot be updated unless execution of parked software running while the vehicle is parked is stopped, the method presents the user with the option of whether or not to update the software to be updated.

Citation Information

Patent Citations

  • Program rewriting system

    JP2006082648A

  • Controller, method for control, and computer program

    JP2019036140A

  • Server, software update system, software update method and program

    JP2024032412A