Control device and program storage method

The control device and method address fragmentation in ECUs by moving and converting programs to create contiguous storage, enhancing storage efficiency and reducing fragmentation while maintaining system performance.

WO2026115698A1PCT designated stage Publication Date: 2026-06-04NISSAN MOTOR CO LTD

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NISSAN MOTOR CO LTD
Filing Date
2024-11-29
Publication Date
2026-06-04

Smart Images

  • Figure JP2024042277_04062026_PF_FP_ABST
    Figure JP2024042277_04062026_PF_FP_ABST
Patent Text Reader

Abstract

A program acquisition unit (110) acquires a target program, which is an update program or a program to be newly added. If there is no continuous storable area capable of storing the target program in a program storage area (141), a movement control unit (120) secures a storable area by moving a program stored in the program storage area (141) within the program storage area (141). A program storage unit (130) stores the target program in the storable area. In a case of securing a storable area, if a first program, which is one of existing programs stored in the program storage area (141) and has a given size, cannot be moved to an adjacent unused area, the movement control unit (120) compresses the size of the first program by converting the first program into a second program with which only an input / output function can be implemented, and moves the second program to the unused area.
Need to check novelty before this filing date? Find Prior Art

Description

Control Device and Program Storage Method

[0001] The present invention relates to a control device and a program storage method.

[0002] A vehicle is equipped with an ECU (Electronic Control Unit) which is a control device. Each function of the ECU is realized by a processor included in the ECU executing a software program (hereinafter referred to as a program) stored in a program storage area. Patent Document 1 discloses a technique of downloading an update program from a server and updating the program of the ECU mounted on the vehicle.

[0003] Japanese Unexamined Patent Application Publication No. 2017 - 149323

[0004] When updates and additions of each program stored in the program storage area of the ECU are repeated, the program storage area becomes fragmented, where the used areas are arranged discontinuously with small - sized unused areas in between, and it becomes impossible to secure a large continuous unused area. In a fragmented program storage area, since a sufficient - sized continuous unused area cannot be secured, newly added programs are often stored by being divided into multiple unused areas. When the processor executes a program stored in a divided manner, it may take time for scanning, etc., which may reduce the performance of the ECU. Also, there are programs for which divided storage is not allowed.

[0005] The present invention has been made in view of the above circumstances, and an object thereof is to provide a control device and a program storage method capable of delaying the progress of fragmentation of the program storage area.

[0006] To achieve the above objective, the control device according to the present invention comprises a program acquisition unit, a move control unit, and a program storage unit. The program acquisition unit acquires a target program, which is either an update program or a newly added program. If there is no contiguous storage area in the program storage area where the target program can be stored, the move control unit secures a storage area by moving an existing program stored in the program storage area within the program storage area. The program storage unit stores the target program in the storage area secured by the move control unit. Furthermore, when the move control unit secures a storage area, if it cannot move a first program, which is one of the existing programs stored in the program storage area, to an adjacent unused area while maintaining its original size, it converts the first program into a second program that can only implement input / output functions to compress its size before moving it to the unused area.

[0007] This invention, when allocating storage space for a target program, if a first program, which is one of the existing programs stored in the program storage area, cannot be moved to an adjacent unused area while maintaining its original size, the first program is converted into a second program capable of implementing only input / output functions to compress its size before being moved to the unused area. This makes it easier to allocate storage space for the target program, thereby slowing down the progression of program storage area fragmentation.

[0008] This is a block diagram of a system equipped with an ECU according to an embodiment of the present invention. This is a hardware configuration diagram of an ECU according to an embodiment of the present invention. This is a diagram (1) for specifically explaining the movement of a program within the program storage area. This is a diagram (2) for specifically explaining the movement of a program within the program storage area. This is a flowchart of the program storage process according to an embodiment of the present invention. This is a diagram (1) showing an example of the configuration of the program storage area. This is a diagram (2) showing an example of the configuration of the program storage area. This is a diagram (3) showing an example of the configuration of the program storage area. This is a diagram (4) showing an example of the configuration of the program storage area.

[0009] Hereinafter, an ECU 100 according to an embodiment of the present invention will be described with reference to the drawings. In each drawing, the same or equivalent parts are denoted by the same reference numerals.

[0010] As shown in Figure 1, the ECU 100 according to an embodiment of the present invention is mounted on a vehicle 10. The ECU 100 is a vehicle control device for driver assistance that has multiple functions to assist in driving the vehicle 10. For example, the ECU 100 has functions to assist in driving, such as emergency braking (FEB), rear emergency braking (RAEB), lane departure prevention (LDP), rear side collision prevention (BSI), autonomous driving (AD), parking assistance (APA), preceding vehicle departure notification (LCDN), and exit safety assistance (OSE). These functions of the ECU 100 are independent of each other, and a program for realizing each function is stored in the program storage area 141. The ECU 100 controls in-vehicle components such as the engine, brakes, steering, and car navigation system by executing each program stored in the program storage area 141. In this way, the ECU 100 realizes each of the driver assistance functions.

[0011] Furthermore, the ECU 100 is connected to the data center 30 wirelessly via the communication device 20, enabling communication. This allows the ECU 100 to obtain update programs from the data center 30 via OTA (Over The Air) and update each program stored in the program storage area 141 to the latest version. The ECU 100 can also obtain new programs from the data center 30 via OTA (Over The Air) and store (install) them in the program storage area 141.

[0012] Next, the hardware configuration of the ECU 100 will be described. The ECU 100 is, for example, a microcomputer. As shown in Figure 2, the ECU 100 comprises a processor 11, RAM (Random Access Memory) 12, ROM (Read Only Memory) 13, flash memory 14, and a communication interface (indicated as communication I / F in the figure) 15, all connected to each other via a bus 16.

[0013] The processor 11 comprises, for example, one or more CPUs (Central Processing Units) and their peripheral circuits, and performs various arithmetic operations. The processor 11 executes a control program 131 stored in the ROM 13, thereby performing program storage operations, such as updating programs stored in the program storage area 141 of the flash memory 14 or adding new programs to the program storage area 141. Details of the program storage operations will be described later. The processor 11 also implements various functions to support the operation of the vehicle 10 by executing each program stored in the program storage area 141. The processor 11 may further include arithmetic circuits such as a logic unit and a numerical unit.

[0014] The RAM 12 functions as the work memory for the processor 11. The ROM 13 stores the control program 131 described above. The control program 131 may also be stored in the flash memory 14.

[0015] The flash memory 14 is a non-volatile semiconductor memory. The flash memory 14 has a program storage area 141. The program storage area 141 stores programs corresponding to each function for assisting the operation of the vehicle 10, which are executed by the processor 11. In addition, the flash memory 14 stores various data used for processing by the processor 11 in areas other than the program storage area 141. Alternatively, storage such as an HDD (Hard Disk Drive) or SSD (Solid State Drive) may be provided in or outside the ECU 100, and this storage may be used as the program storage area 141.

[0016] The communication interface 15 includes an interface circuit for connecting the ECU 100 to an in-vehicle network compliant with standards such as CAN (Controller Area Network). The communication interface 15 receives signals from in-vehicle components such as brakes and engines, and the navigation system, and passes them to the processor 11. The communication interface 15 also receives update programs and newly added programs from the data center 30 via the communication device 20 and passes them to the processor 11.

[0017] Furthermore, the communication interface 15 transmits control signals generated by the processor 11 to the in-vehicle components. The control signals received from the communication interface 15 control in-vehicle components such as the engine and brakes, thereby realizing the various driver assistance functions of the ECU 100.

[0018] For example, the ECU 100 implements the functions shown in Figure 1 by having the processor 11 execute the control program 131 stored in the ROM 13. That is, the ECU 100 implements the functions of the program acquisition unit 110, the movement control unit 120, and the program storage unit 130. These units are functionally configured for updating or adding programs stored in the program storage area 141 via OTA. The configuration related to the driving assistance functions, which are the original functions of the ECU 100, and other functional configurations are omitted in Figure 1.

[0019] The program acquisition unit 110 acquires an update program or a newly added program from the data center 30 via the communication device 20. In the following description, the program acquired by the program acquisition unit 110 will be referred to as the target program. The processing executed by the program acquisition unit 110 is an example of the processing in the program acquisition step of the present invention.

[0020] If there is no contiguous unused area (storable area) in the program storage area 141 where the target program can be stored, the movement control unit 120 attempts to secure a storable area by moving an existing program stored in the program storage area 141 within the program storage area 141. Specifically, the movement control unit 120 secures a storable area by repeatedly executing a process to move programs stored adjacent to unused areas in the program storage area 141, starting with the largest programs, to the smallest unused area that can be moved within the program storage area 141. The process executed by the movement control unit 120 is an example of the process of the movement control step of the present invention.

[0021] Here, a program stored in the program storage area 141 is subject to a constraint: even if there is an adjacent unused area, if the size of that unused area is smaller than the size of the program, the program cannot be moved to that unused area while maintaining its original size. For example, as shown in Figure 3, program α stored in the program storage area 141 cannot be moved to an adjacent unused area X that is smaller than program α while maintaining its original size. This is because such a move would require the complete erasure of program α during the move, rendering program α's functions unexecutable during that time, preventing other functions from accessing program α's functions, and causing the system to terminate with an error.

[0022] Therefore, when allocating storage space, if it is not possible to move a program to an adjacent unused area while maintaining its original size, the move control unit 120 first stubs the program. Stubbing means converting the program into a format in which only the input / output functions of the program's original functions are implemented. By stubbing, the size of the program is compressed. Also, while the program is stubbed, the input / output functions of the program are maintained at a minimum level, so other functions can refer to or call the functions of the stubbed program. Therefore, the system is maintained normally even while the program is stubbed. As a result, the move control unit 120 can successfully move the stubbed program to an adjacent unused area. After the move is complete, the move control unit 120 converts the stubbed program back to the original program. In this way, the move control unit 120 can move programs that cannot be moved to an adjacent unused area while maintaining their original size.

[0023] Here, we will explain the program movement described above using Figure 4. As explained in Figure 3, it is not possible to move program α to the adjacent unused area X while maintaining its original size. Therefore, the movement control unit 120 compresses program α by stubbing it. As a result, the size of the stubbed program α becomes smaller than the unused area X. Therefore, the movement control unit 120 can move the stubbed program α to the unused area X. After the movement is complete, the movement control unit 120 destubs program α back to its original state. In this way, program α can be moved by shifting it to the adjacent unused area X, making it possible to secure a larger unused area Y on the opposite side adjacent to program α.

[0024] Returning to Figure 1, the program storage unit 130 stores the target program in a storable area within the program storage region 141. If there are multiple storable areas, the program storage unit 130 stores the target program in the smallest of these storable areas. Furthermore, if the program storage unit 130 cannot secure a storable area within the program storage region 141, it divides the target program into multiple unused areas and stores them there. The processing executed by the program storage unit 130 is an example of the processing of the program storage step of the present invention.

[0025] Next, the operation of the program storage process executed by the ECU 100 configured as described above will be explained with reference to the flowchart in Figure 5. For example, when the program acquisition unit 110 of the ECU 100 acquires an update program for updating a program stored in the program storage area 141, or a program to be newly added to the program storage area 141 (hereinafter, both will be collectively referred to as the target program), via OTA from the data center 30 through the communication device 20, the program storage process is started.

[0026] First, the program storage unit 130 extracts a contiguous unused area from the program storage area 141 (step S101). If the target program is an update program, the program storage unit 130 determines that the area in the program storage area 141 where the program to be updated is stored is unused and extracts a contiguous unused area. This is because when a program is updated, the program to be updated is deleted, and the area where this program was stored becomes unused.

[0027] Here, the process of step S101 will be explained using a specific example. For example, suppose that programs A to E are stored in the program storage area 141, as shown in Figure 6A. And the target program is the program to be newly added. In this case, the program storage unit 130 extracts two areas as consecutive unused areas: area a between program B and program C, and area b between program C and program D.

[0028] On the other hand, the target program is a program for updating program C. In this case, the program storage unit 130 determines that the storage area for program C to be updated is unused and extracts a continuous unused area. That is, in this case, the program storage unit 130 extracts a single area by connecting the storage area for program C and the adjacent areas a and b as a continuous unused area.

[0029] Returning to Figure 5, the program storage unit 120 then determines whether there is a storage area (storable area) in the extracted unused area that is larger than or equal to the size of the target program (step S102). If there is a storage area (step S102; Yes), the program storage unit 120 stores the target program in that storage area (step S103). If there are multiple storage areas, the program storage unit 120 stores the target program in the smallest storage area among them. This ensures that the target program is stored in an unused area that is as close to the required size as possible.

[0030] On the other hand, if there is no available storage area (step S102; No), the movement control unit 120 extracts a program stored in a location adjacent to the unused area extracted in step S101 (step S104). Then, from the extracted programs, the movement control unit 120 selects the largest program that has not yet been selected (step S105). In the following description, the program selected in step S105 will be referred to as the selected program.

[0031] Then, the movement control unit 120 determines whether or not there is an unused area in the program storage area 141 that can move the selected program (i.e., an unused area larger than the selected program) (step S106).

[0032] If there is such unused area (step S106; Yes), the move control unit 120 moves the selected program to the smallest unused area among these unused areas (step S107). In order to prevent fragmentation as much as possible, the move control unit 120 stores the selected program from the beginning of the unused area at the destination. Then the process moves to step S113.

[0033] On the other hand, if there is no such unused area (step S106; No), the movement control unit 120 determines whether it is possible to stub the selection program based on the type of function of the selection program (step S108). For example, the movement control unit 120 assumes that the vehicle 10 is currently traveling on a highway. In this case, if the function of the selection program is a function that is not used while traveling on a highway, such as parking assistance (APA) or exit safety assistance (OSE), the movement control unit 120 can determine that it is possible to stub the selection program.

[0034] If it is determined that the selected program cannot be stubbed (step S108; No), the process moves to step S114. On the other hand, if it is determined that the selected program can be stubbed (step S108; Yes), the movement control unit 120 determines whether the selected program can be moved to an adjacent unused area by stubging it (step S109). Specifically, the movement control unit 120 estimates the size of the selected program after stubging, and if the estimated size is less than or equal to the adjacent unused area, it determines that it can be moved, and if the estimated size is larger than the adjacent unused area, it determines that it cannot be moved.

[0035] If it is determined that the selected program cannot be moved to an adjacent unused area even after stubbing (step S109; No), the process returns to step S114. On the other hand, if it is determined that the selected program can be moved to an adjacent unused area by stubbing (step S109; Yes), the move control unit 120 stubbles and compresses the selected program (step S110).

[0036] Then, the movement control unit 120 moves the stubbed selection program to an adjacent unused area (step S111). In order to prevent fragmentation as much as possible, the movement control unit 120 stores the selection program from the beginning of the adjacent unused area.

[0037] Then, after the movement in step S111 is completed, the movement control unit 120 de-stubs the selected program and returns it to a state where it can perform its original function (step S112). Then the process moves to step S113. Alternatively, the process may be moved to step S113 without performing step S112. Doing so can shorten the processing time for the program storage process. In this case, after the program storage process is completed, it is necessary to de-stub the stubbed program as a separate process. Also, if step S113 is not executed, it is necessary to reserve free space adjacent to the selected program in the program storage area 141 for future de-stubping.

[0038] In step S113, the move control unit 120 determines again whether there is a storage area for the target program in the program storage area 141 after the selected program has been moved.

[0039] If there is a storable area (step S113; Yes), the movement control unit 120 stores the target program in the storable area (step S103), and the program storage process ends. On the other hand, if there is no storable area (step S113; No), the process moves to step S114.

[0040] In step S114, the movement control unit 120 determines whether all the programs extracted in step S104 were selected in step S105. If there are any unselected programs (step S114; No), the process returns to step S105.

[0041] On the other hand, if all extracted programs are selected (step S114; Yes), it means that the programs in the program storage area 141 could not be moved, or even if the programs in the program storage area 141 were moved, it would not be possible to secure storage space for the target programs. Therefore, the program storage unit 130 determines whether or not the target programs can be stored by dividing them into multiple unused areas (step S115). If there is almost no unused space, or if the target program is not permitted to be stored in division, it is determined that it cannot be divided (step S115; No), and the program storage area 141 is not updated, and the program storage process ends. At this time, the ECU 100 may output an error message indicating that the target programs could not be stored via the communication device 20 to the smartphone of the vehicle owner 10 that has been registered in advance, or to an in-vehicle device (e.g., a speaker). The ECU 100 may also include a message in this error message prompting the deletion of unnecessary functions in order to secure capacity in the program storage area 141.

[0042] On the other hand, if it is determined that the program can be divided and stored (step S115; Yes), the program storage unit 120 divides the target program into multiple unused areas and stores them (step S116). There are various methods for how to divide the target program. For example, the program storage unit 130 may divide and store the target program so that unused areas are used as efficiently as possible. Alternatively, the program storage unit 130 may divide and store the target program so that the number of divisions is kept to a minimum. This completes the program storage process.

[0043] Next, I will explain the program storage process described above with a specific example. Figure 6A shows the program storage area 141 where programs A to E are stored. Currently, programs A to E are all programs that can be stubbed. Let's assume that a program storage process is executed to newly store program F (the target program), which has a size of 500 MB, in this program storage area 141.

[0044] In this case, first, in step S101 of the program storage process, the program storage unit 130 extracts unused areas a and b. Since both of these unused areas a and b are smaller than 500 MB, the program F cannot be stored. Therefore, in step S102, it is determined as No. Then, in step S104, the movement control unit 120 extracts programs B, C, and D adjacent to the unused areas a and b. And in step S105, the movement control unit 120 selects the program C with the largest size among them. Here, since the size of the program C is larger than the areas a and b, the movement control unit 120 determines that there is no unused area where it can be moved (step S106; No). Subsequently, since the program C can be stubbed (step S108; Yes), in step S109, the movement control unit 120 stubs the program C to compress its size. And in step S111, the movement control unit 120 moves the stubbed program C to the beginning of the adjacent unused area a. As a result, the program storage area 141 becomes the state shown in FIG. 6B.

[0045] After that, in step S112, the movement control unit 120 unstubs the program C to return it to its original size. As a result, the program storage area 141 becomes the state shown in FIG. 6C. That is, it means that the program C could be moved so as to be shifted to the adjacent unused area a. And thereby, since the unused area b to the right of the program C can be expanded to 600 MB, the movement control unit 120 determines that there is an area for storing the target program F with a size of 500 MB (step S113; Yes). Then, in step S103, the movement control unit 120 stores the target program F in the unused area b as shown in FIG. 6D. Thus, the program storage process ends.

[0046] Thus, when the ECU 100, which is a control device according to this embodiment, attempts to store a target program in the program storage area 141, if there is no available storage area that is a continuous unused area, the program stored in the program storage area 141 is moved to an unused area within the program storage area 141, thereby securing an available storage area. As a result, the target program can be stored in the program storage area 141 without being split, so it is possible to slow down the progress of fragmentation of the program storage area 141 when storing the target program.

[0047] Also, when the ECU 100 according to this embodiment secures an available storage area for the target program, if a first program, which is one of the existing programs stored in the program storage area 141, cannot be moved as it is to an adjacent unused area while maintaining its size, the first program is stubbed out and converted into a second program that can only realize input / output functions to compress the size. Then, the ECU 100 moves the stubbed-out program to this unused area. Thereby, the degree of freedom of movement of the existing programs stored in the program storage area 141 can be improved, and it becomes easier to secure an available storage area for the target program. Therefore, an effect of further slowing down the progress of fragmentation of the program storage area 141 when storing the target program can be expected.

[0048] Also, the ECU 100 according to this embodiment returns to the original functional program after stubbing out and moving the program. Therefore, the time during which the original function of the program is lost can be made very short.

[0049] Also, the ECU 100 according to this embodiment does not execute stubbing for a program that is determined to be in a situation where it cannot be stubbed out based on the function of the program. Thereby, it is possible to prevent a situation where a malfunction occurs in the system due to stubbing.

[0050] Furthermore, the ECU 100 according to this embodiment moves the program stored in the program storage area 141 to the smallest unused area within the available unused areas. This makes it possible to move the existing program to the most efficient location within the program storage area 141, thereby making it easier to secure more storage space for the target program.

[0051] (Variations) This invention is not limited to the above embodiments, and various modifications and applications are possible. For example, parts of the above embodiments can be omitted or replaced, or arbitrary configurations can be added. Also, the hardware configuration, functional configuration, flowchart, etc. shown in the above embodiments are examples and can be changed as appropriate.

[0052] For example, in the program storage process of the above embodiment, an attempt was made to secure storable space by extracting programs adjacent to unused areas in the program storage area 141 (step S104), selecting the extracted programs in order, and repeatedly moving the selected programs to the unused areas (steps S105 to S114). However, various methods can be used to move programs within the program storage area 141 to secure storable space. For example, storable space may be secured by moving each program stored in the program storage area 141 so that they are packed in address order without any gaps between programs. The method of stubing and moving programs as described above can also be used when moving programs in this way.

[0053] For example, in the above embodiment, during the program storage process, if there is no available storage space in the program storage area 141, a process is uniformly performed to move the programs stored in the program storage area 141 to secure available storage space. However, if the target program is a program related to a specific function that requires high responsiveness, such as emergency braking (FEB) or rear emergency braking (RAEB), the process of moving the existing program is executed, and if the program is related to any other function, it is not necessary to move the existing program. By doing so, the movement of programs in the program storage area 141 is suppressed, and thus the degradation of the flash memory 14 can be suppressed.

[0054] In the above embodiment, the ECU 100 is not limited to a driver assistance system ECU, but may also be a multimedia system ECU, a power supply system ECU, etc. A multimedia system ECU is a general term for an ECU that controls the multimedia system of the vehicle 10. Examples of multimedia system ECUs include a navigation control ECU that controls the navigation system of the vehicle 10, and an audio control ECU that controls the audio equipment of the vehicle 10. A power supply system ECU is a general term for an ECU that controls the power supply system of the vehicle 10. Examples of power supply system ECUs include a power supply control ECU that controls the ACC (accessory) power and IG (ignition) power installed in the vehicle 10. Furthermore, the present invention is also applicable in a configuration in which the vehicle 10 is equipped with multiple types of such ECUs and each of these ECUs shares the program storage area 141.

[0055] Furthermore, the present invention is applicable to control devices other than the ECU 100, which is a control device for the vehicle 10. For example, the present invention is applicable to control devices for industrial robots and machine tools that operate by executing programs corresponding to each function. In addition, the program storage method of the present invention can be applied when storing the programs for each function in the program storage area 141 of the flash memory 14 during the manufacturing stage of the ECU 100.

[0056] Furthermore, in the above embodiment, an example was described in which the processor 11 of the ECU 100 executes the control program 131 to realize the functions of the program acquisition unit 110, the movement control unit 120, and the program storage unit 130. However, the processor 11 may also be configured with dedicated hardware to realize each function.

[0057] Furthermore, the control program 131 for executing the operations of the above embodiment may be stored in a recording medium such as a computer-readable CD-ROM (Compact Disc Read-Only Memory), DVD (Digital Versatile Disc), MO (Magneto Optical Disc), or memory card and distributed, and the program can be installed in a computer to realize each function, thereby configuring the program acquisition unit 110, the movement control unit 120, and the program storage unit 130 of the ECU 100. In cases where the functions of the program acquisition unit 110, the movement control unit 120, and the program storage unit 130 are realized through a division of labor between the OS (Operating System) and the application, or through cooperation between the OS and the application, only the parts other than the OS may be stored in the recording medium.

[0058] The present invention allows for various embodiments and modifications without departing from the broad spirit and scope of the invention. Furthermore, the embodiments described above are for illustrative purposes only and do not limit the scope of the invention. In other words, the scope of the invention is indicated by the claims, not by the embodiments. Various modifications made within the scope of the claims and the equivalent significance of disclosure are considered to be within the scope of the invention.

[0059] 10 Vehicle, 20 Communication device, 30 Data center, 100 ECU, 11 Processor, 12 RAM, 13 ROM, 131 Control program, 14 Flash memory, 141 Program storage area, 15 Communication interface, 16 Bus, 110 Program acquisition unit, 120 Movement control unit, 130 Program storage unit.

Claims

1. A control device that realizes corresponding functions by executing each program stored in a program storage area, comprising: a program acquisition unit that acquires a target program which is an update program or a newly added program; a move control unit that secures a storable area by moving an existing program stored in the program storage area within the program storage area when there is no contiguous storable area in the program storage area where the target program can be stored; and a program storage unit that stores the target program in the storable area secured by the move control unit, wherein when the move control unit secures the storable area, if it is not possible to move a first program which is one of the existing programs stored in the program storage area to an adjacent unused area while maintaining its original size, the move control unit converts the first program into a second program which is capable of realizing only input / output functions to compress its size, and then moves it to the unused area.

2. The control device according to claim 1, wherein the movement control unit moves the second program to an adjacent unused area and then returns the second program to the first program.

3. The control device according to claim 1 or 2, wherein the movement control unit determines, based on the function of the first program, that it is not possible to convert the first program to the second program, and the movement control unit does not convert the first program to the second program.

4. The control device according to claim 1 or 2, wherein the control device is a vehicle control device.

5. A method for storing a program in a program storage area by a computer, comprising: a program acquisition step in which the computer acquires a target program which is an update program or a newly added program; a move control step in which, if there is no contiguous storable area in the program storage area in which the target program can be stored, an existing program stored in the program storage area is moved within the program storage area to secure the storable area; and a program storage step in which the target program is stored in the storable area, wherein in the move control step, when securing the storable area, if a first program which is one of the existing programs stored in the program storage area cannot be moved to an adjacent unused area while maintaining its original size, the first program is converted into a second program which can only implement input / output functions to compress its size, and then moved to the unused area.