Wireless communication device, wireless communication system, and wireless communication method
The wireless communication device and system address communication stability and safety issues in wireless BMS systems by performing a test after OTA updates and automatically rolling back to the previous firmware if the test fails, ensuring continuous operation and safety.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NUVOTON TECH CORP JAPAN
- Filing Date
- 2025-11-25
- Publication Date
- 2026-06-04
AI Technical Summary
Wireless BMS systems face challenges in maintaining communication stability and safety during OTA updates, which can lead to system failures and potential hazards such as battery explosions or fires due to overcharging or high temperatures, necessitating fail-safe mechanisms to ensure continuous operation.
A wireless communication device and system that performs a wireless communication test after switching to new firmware during OTA updates, automatically rolling back to the previous firmware if the test fails, ensuring continuous operation and preventing system shutdowns.
Enables reliable OTA updates in wireless BMS systems by automatically reverting to the previous firmware if communication issues arise, preventing system failures and ensuring safety, thus avoiding manual recovery procedures and potential hazards.
Smart Images

Figure JP2025040952_04062026_PF_FP_ABST
Abstract
Description
Wireless communication device, wireless communication system, and wireless communication method
[0001] The present disclosure relates to a wireless communication device, a wireless communication system, and a wireless communication method.
[0002] There is a demand for introducing a software update function for an ECU (Electronic Control Unit) mounted on a vehicle. In recent years, software updates by OTA (Over The Air) have been prevalent. OTA means transmitting and receiving data via a wireless communication path, and by utilizing OTA, it becomes possible to update software and firmware without going through a wired connection path.
[0003] U.S. Patent Application Publication No. 2022 / 082627
[0004] By the way, when a problem occurs in an OTA update for an ECU (an example of an information processing device) mounted on a vehicle, etc., the ECU, etc. may malfunction, and there is a risk that the object on which the ECU is mounted cannot continue to operate. When the object is a vehicle, for example, the vehicle may come to an emergency stop.
[0005] Therefore, the present disclosure provides a wireless communication device, a wireless communication system, and a wireless communication method in which an information processing device can continue to operate even when a problem occurs in an OTA update.
[0006] A wireless communication device according to one aspect of the present disclosure is a wireless communication device provided by one of the master device and the slave device in a wireless communication system in which a master device having a battery control circuit for controlling a battery and a slave device having a battery monitoring circuit for monitoring the battery communicate wirelessly, the device comprising: a memory unit capable of storing a first firmware being applied and a second firmware acquired by wireless communication; a wireless communication test control unit that performs a wireless communication test between the wireless communication device provided by the other of the master device and the slave device; and an OTA (Over The Air) unit that controls the firmware to be applied, wherein the wireless communication test control unit performs the wireless communication test after the firmware to be applied has been switched from the first firmware to the second firmware by the OTA unit, and if the wireless communication test is not passed, the OTA unit reapplies the first firmware.
[0007] A wireless communication system according to one aspect of this disclosure comprises the master device and the slave device described above.
[0008] A wireless communication method according to one aspect of the present disclosure is a wireless communication method performed by a wireless communication device provided by one of the master device and the slave device in a wireless communication system in which a master device having a battery control circuit for controlling a battery and a slave device having a battery monitoring circuit for monitoring the battery communicate wirelessly, wherein after the firmware to be applied is switched from a first firmware currently being applied to a second firmware obtained by wireless communication, a wireless communication test is performed between the wireless communication device provided by the other of the master device and the slave device, and if the wireless communication test is not passed, the first firmware is reapplied.
[0009] According to one aspect of this disclosure, it is possible to realize a wireless communication device, etc., that can continue to operate even if a problem occurs during an OTA update.
[0010] Figure 1 is a schematic diagram showing a vehicle equipped with a wireless BMS according to Embodiment 1. Figure 2 is an external view showing the wireless BMS according to Embodiment 1. Figure 3 is a diagram showing the functional configuration of the wireless BMS according to Embodiment 1. Figure 4 is a diagram showing the configuration of the memory unit according to Embodiment 1. Figure 5 is a diagram showing an example of a test flag according to Embodiment 1. Figure 6 is a diagram showing the configuration of the security module according to Embodiment 1. Figure 7A is the first diagram showing an overview of the OTA update according to Embodiment 1. Figure 7B is the second diagram showing an overview of the OTA update according to Embodiment 1. Figure 7C is the third diagram showing an overview of the OTA update according to Embodiment 1. Figure 8 is a flowchart showing the operation of the master device during OTA download according to Embodiment 1. Figure 9 is a flowchart showing the operation of the master device during OTA update according to Embodiment 1. Figure 10A is the first diagram for explaining the wireless communication test according to Embodiment 1. Figure 10B is the second diagram for explaining the wireless communication test according to Embodiment 1. Figure 11 is a flowchart showing the operation of the master device during OTA download according to Embodiment 1 when performing an OTA update on a slave device. Figure 12 is a flowchart showing the operation of the slave device according to Embodiment 1 during OTA download. Figure 13 is a flowchart showing the operation of the slave device according to Embodiment 1 during OTA update. Figure 14 is a flowchart showing the operation of the master device according to Embodiment 1 when the OTA update of the slave device is completed. Figure 15 is a diagram showing the functional configuration of the wireless BMS according to Embodiment 2. Figure 16A is a diagram showing the configuration of the first memory unit according to Embodiment 2. Figure 16B is a diagram showing the configuration of the second memory unit according to Embodiment 2. Figure 16C is a diagram showing the configuration of the third memory unit according to Embodiment 2. Figure 17 is a diagram showing the functional configuration of the wireless BMS according to Embodiment 3. Figure 18 is a flowchart showing the operation of the master device according to Embodiment 3 during OTA update. Figure 19 is a flowchart showing the operation of the slave device according to Embodiment 3 during OTA update.
[0011] (Background to this disclosure) A Battery Management System (BMS) is a device that manages the state of batteries, including lithium-ion batteries. By preventing overcharging and over-discharging of batteries and detecting abnormalities, BMS enables efficient and safe operation. It is an essential technology, especially for electric vehicles that use a large number of lithium-ion batteries.
[0012] In recent years, wireless BMS (Battery Management System) has been attracting attention. A wireless BMS is a device that wirelessly connects the Battery Management Unit (BMU), which controls the entire system, to the battery monitoring circuit, which acquires battery voltage information. Compared to conventional BMS, which mainly uses wired connections, wireless BMS can be expected to reduce costs by eliminating the need for cables and connectors. However, there are concerns about increased complexity in communication stability due to wireless connectivity and an increased risk of cyberattacks.
[0013] A software update function is essential to solve the above problems. In automobiles, the international standard ISO 24089 for automotive software updates has been established, requiring the introduction of a software update function for the ECU. This disclosure assumes software updates via OTA (On-Track Update).
[0014] In a wireless BMS, the BMU and battery monitoring circuit are connected by a wireless communication circuit, and problems associated with OTA updates can potentially disrupt this wireless communication path. In this case, battery voltage information cannot be obtained via the battery monitoring circuit, potentially leading to a dangerous situation where the battery could explode or catch fire. Furthermore, firmware updates are performed frequently, and there is a possibility that firmware with a defect in the wireless communication function may be applied during these updates. OTA updates refer to updating the software using OTA technology.
[0015] Therefore, wireless BMS systems are desirable to have fail-safe mechanisms to address situations where wireless communication fails. In particular, since batteries can ignite due to overcharging or high temperatures, and there are concerns that this could endanger the safety of road users, a function to prevent system failure is essential.
[0016] Therefore, the inventors of this application diligently studied wireless communication devices, etc., that would allow the ECU to continue operating even if a problem occurs during an OTA update, and have devised the wireless communication devices, etc., described below. Specifically, the inventors of this application have devised a wireless communication device that performs a wireless communication test during an OTA update, and if the wireless communication test is unsuccessful, determines that there is a defect in the new firmware and spontaneously rolls back to restore the system.
[0017] This eliminates the need for manual recovery procedures even if problems occur during OTA updates, allowing the system to recover automatically. Such a wireless communication device makes it possible to realize a wireless BMS that can reliably perform OTA updates. Furthermore, when the wireless communication device is installed in a vehicle, it can prevent the in-vehicle system from shutting down due to malfunctions.
[0018] Furthermore, an ECU is a device that controls electronic equipment, and is not limited to ECUs installed in vehicles (on-board ECUs); it may also be an ECU installed in electronic equipment other than vehicles. In the following sections, we will explain examples where the ECU is an on-board ECU.
[0019] The embodiments and other details will be described below with reference to the drawings.
[0020] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, arrangement positions of components, connection configurations, steps, and step order shown in the following embodiments are examples only and are not intended to limit this disclosure. Furthermore, any components in the following embodiments that are not described in an independent claim will be described as optional components.
[0021] Furthermore, each figure is a schematic diagram and not necessarily a strictly accurate representation. Therefore, for example, the scale may not necessarily match in each figure. Also, in each figure, substantially identical components are given the same reference numerals, and redundant explanations are omitted or simplified. In addition, for convenience, some of the figures include English translations for reference. The English translations may not necessarily match the Japanese translations in the specification.
[0022] Furthermore, in this specification, terms indicating relationships between elements such as "identical" and "same," as well as numerical values and numerical ranges, do not represent only strict meanings, but also include substantially equivalent ranges, such as differences of a few percent (or about 10%).
[0023] Furthermore, the term "on top of (for example, on a battery module)" applies not only when two components are spaced apart and another component is present between them, but also when two components are placed in contact with each other.
[0024] Furthermore, in this specification, ordinal numbers such as "first," "second," etc., do not mean the number or order of components unless otherwise specified, but are used to avoid confusion and to distinguish similar components.
[0025] (Embodiment 1) The wireless communication device and the like according to this embodiment will be described below with reference to Figures 1 to 14.
[0026] [1-1. Configuration of Wireless BMS] First, the configuration of the wireless BMS having the wireless communication device according to this embodiment will be described with reference to Figures 1 to 6. Figure 1 is a schematic diagram showing a vehicle 1 equipped with the wireless BMS 5 according to this embodiment. The wireless BMS 5 is an example of a wireless communication system. Note that the wireless communication system is not limited to the wireless BMS 5.
[0027] As shown in Figure 1, the wireless BMS 5 is positioned below the seat 2 of the vehicle 1. Specifically, the wireless BMS 5 is positioned in the space (enclosed space) between the seat 2 and the chassis 3. This space is a narrow space. In other words, the wireless BMS 5 is positioned and used within a narrow space.
[0028] Within this confined space, a battery pack containing multiple batteries 11a, a master device 200 for managing the battery pack, and multiple slave devices 100 for monitoring the battery pack are arranged. Wireless communication is conducted between the master device 200 and each of the slave devices 100, forming a transmission path L within the confined space. The master device 200 is connected to the battery pack via a junction box 4. The junction box 4 is also referred to as a control box.
[0029] Vehicle 1 is, for example, an electric vehicle. Vehicle 1 is, for example, an electric vehicle (EV), but is not limited to this, and may also be an electric railway, etc.
[0030] Figure 2 is an external view showing the wireless BMS 5 according to this embodiment.
[0031] The Wireless BMS 5 is a system for managing battery packs. For example, the Wireless BMS 5 manages the State of Charge (SOC), State of Health (SOH), and State of Power (SOP) of the battery packs. The Wireless BMS 5 also monitors for abnormalities in the battery packs.
[0032] The wireless BMS 5 comprises a master device 200 for managing battery packs and a plurality of slave devices 100 for monitoring battery packs. As will be described in detail later, the wireless BMS 5 is a wireless communication system in which the master device 200 and the slave devices 100 communicate wirelessly. The wireless BMS 5 may also further include battery packs. For example, a battery pack is composed of a plurality of battery modules 11 connected in series or parallel. A battery module 11 is also called a battery pack and is composed of one or more batteries 11a housed in a battery case. A battery 11a is also called a battery cell. For example, a lithium-ion battery is given as an example of a battery 11a, but it is not limited to this. For example, a slave device 100 may be placed on each of the plurality of battery modules 11.
[0033] The slave device 100 includes a unit that monitors the battery 11a of the battery module 11. The battery 11a (or battery pack) is an example of an object that the slave device 100 monitors.
[0034] The master device 200, together with the slave devices 100, constitutes a BMS and acquires data such as the voltage value of each battery 11a from each slave device 100.
[0035] Figure 3 shows the functional configuration of the wireless BMS 5 according to this embodiment.
[0036] As shown in Figure 3, the wireless BMS 5 is configured to include a slave device 100, a master device 200, and a battery 11a. The number of slave devices 100 included in the wireless BMS 5 is not particularly limited, as long as it is one or more. Both the slave device 100 and the master device 200 are configured to include an ECU. The ECU is an example of an information processing device.
[0037] The slave device 100 is a device on the battery 11a side in the wireless BMS 5, and includes a wireless communication circuit 101 and a battery monitoring circuit (BMIC: Battery Management IC) 111.
[0038] The wireless communication circuit 101 controls the wireless communication function of the slave device 100. The wireless communication circuit 101 comprises an MCU (Micro Controller Unit) 102, a wireless communication unit 109, and an antenna 110. The wireless communication circuit 101 is an example of a wireless communication device.
[0039] The MCU 102 is a circuit that plays a host role in controlling communication in the wireless communication circuit 101, and comprises a core unit 103, a memory unit 104, a security module 105, an OTA unit 106, a wireless communication test control unit 107, and a timer unit 108. Each component of the MCU 102 is the same as the components of the MCU 203 which will be described later, and will be described later using the MCU 203.
[0040] The wireless communication unit 109 is a communication unit for wireless communication with the master device 200. In the test mode described later, the wireless communication unit 109 performs wireless communication tests. In the normal mode, the wireless communication unit 109 wirelessly transmits necessary information to the master device 200.
[0041] The wireless communication unit 109 includes an analog circuit that converts a baseband signal and a modulated signal from one to the other, and a digital circuit that generates and reads packets.
[0042] Antenna 110 is a wireless communication antenna mounted on the slave device 100. These antennas may also be antennas for short-range wireless communication. In this embodiment, antenna 110 is an antenna for short-range wireless communication.
[0043] The wireless communication protocols for short-range wireless communication include, but are not limited to, at least one of the Bluetooth protocol (Bluetooth) and the IEEE 802.15.4 protocol; for example, Wi-Fi® and ZigBee® may also be included. Furthermore, Bluetooth may also be referred to as BLE (Bluetooth Low Energy).
[0044] The battery monitoring circuit 111 is a circuit that measures the voltage of the battery 11a. A plurality of battery monitoring circuits 111 are mounted in the wireless BMS 5, and upon receiving a voltage acquisition command from the BMU 201, they acquire the voltage information of the batteries 11a under their respective management. Further, when the battery 11a enters a high-temperature or low-temperature state exceeding the threshold value or an unexpected high-voltage state, the battery monitoring circuit 111 transmits an alarm signal to the BMU 201. Thereby, the BMU 201 can detect an abnormality. The batteries 11a are connected in series or in parallel to form the battery module 11. Also, the wireless communication circuit 101 may have at least some functions of the battery monitoring circuit 111, or the wireless communication circuit 202 may have all the functions of the BMU 201 in a lump.
[0045] The master device 200 is a device on the upper layer side of the slave device 100 in the wireless BMS 5, and includes a BMU 201 and a wireless communication circuit 202.
[0046] The BMU 201 is in charge of the command system in the wireless BMS 5. The BMU 201 manages the state of the battery 11a by transmitting various commands and calculating the data received from the slave device 100. The BMU 201 is an example of a battery control circuit.
[0047] The wireless communication circuit 202 controls the wireless communication function of the master device 200. The wireless communication circuit 202 includes an MCU 203, a wireless communication unit 210, and an antenna 211. The wireless communication circuit 202 is an example of a wireless communication device.
[0048] The MCU 203 is a circuit having a host role of controlling communication in the wireless communication circuit 202, and includes a core unit 204, a memory unit 205, a security module 206, an OTA unit 207, a wireless communication test control unit 208, and a timer unit 209.
[0049] The core unit 204 is a control circuit that manages the entire wireless communication circuit 202. The core unit 204 is, for example, a microcontroller that performs processing related to wireless communication.
[0050] The memory unit 205 is a storage device having a memory area (storage area) for storing various types of data. In this embodiment, the memory unit 205 stores at least data related to OTA updates. The memory unit 205 can store, for example, multiple firmware files.
[0051] Figure 4 shows the configuration of the memory unit 205 according to this embodiment.
[0052] As shown in Figure 4, the memory unit 205 includes memory areas, a control unit 304, and an interface unit 305.
[0053] Each memory area stores the active firmware 300, the inactive firmware 301, the boot loader 302, and the configuration file 303. For example, the active firmware 300, the inactive firmware 301, the boot loader 302, and the configuration file 303 are all stored in the same memory (i.e., on a single semiconductor chip). This makes information management easier.
[0054] Active firmware 300 refers to the firmware in an active state, that is, the firmware currently applied. When an object equipped with the Wireless BMS 5 is sold, the active firmware 300 is the initially configured firmware and is stored in the memory unit 205. Furthermore, this memory area is a dedicated area for storing firmware, and the storage of other information may be prohibited. Active firmware 300 is an example of a first firmware.
[0055] Inactive firmware 301 refers to firmware that is inactive, that is, firmware that is not currently applied. Inactive firmware 301 is firmware that is subject to update but has not undergone the wireless communication test described later, or firmware that has been used in the past (old firmware). Note that inactive firmware 301 is not stored when an object equipped with the wireless BMS5 is sold. Furthermore, this memory area is a dedicated area for storing firmware, and it may be prohibited to store other information there. When inactive firmware 301 is firmware for update, it is an example of a second firmware.
[0056] Thus, the memory unit 205 can store the active firmware 300 currently being applied and the inactive firmware 301 that is to be updated. For example, the memory unit 205 has a capacity that can store the active firmware 300 and the inactive firmware 301 simultaneously. Furthermore, hereafter, the memory area in which the active firmware 300 is stored will also be referred to as the active firmware area, and the memory area in which the inactive firmware 301 is stored, or the memory area in which the inactive firmware 301 is planned to be stored, will also be referred to as the inactive firmware area. Note that the active firmware 300 may be stored in the inactive firmware area when the object equipped with the wireless BMS 5 is sold.
[0057] The bootloader 302 reads and executes the firmware configured in the configuration file 303 during startup.
[0058] The configuration file 303 contains various settings related to firmware updates. For example, the configuration file 303 includes test flags used in wireless communication testing as a bootloader configuration file. Also, for example, the configuration file 303 contains information that identifies the currently active firmware. This firmware identification information is updated each time the firmware is updated.
[0059] The control unit 304 is a control device that controls each process of the memory unit 205. For example, when performing an OTA update, the control unit 304 stores the newly received firmware as inactive firmware 301 in the memory area while the active firmware 300 is operating. The control unit 304 may also copy one firmware to another memory area. The new firmware is, for example, the firmware to be updated, and is also referred to as update firmware.
[0060] The interface unit 305 is a communication interface for the memory unit 205 to communicate with external circuits, etc.
[0061] The method for switching the applicable firmware is to deactivate the active firmware 300 and activate the inactive firmware 301. Active means that it is set as the firmware that the bootloader 302 will load, and inactive means that it is not the firmware that the bootloader 302 will load. In this case, the deactivated active firmware 300 is prohibited from being deleted at least until the wireless communication test described later is successful.
[0062] Figure 5 shows an example of a test flag according to this embodiment. The switching between "0" and "1" of the test flag is performed by the OTA unit 207. The specific switching of the test flag will be described later.
[0063] As shown in Figure 5, the test flag indicates whether the wireless communication test function and rollback function are enabled or disabled. Figure 5 shows an example where the wireless communication test function and rollback function are disabled when the test flag is "0", and enabled when the test flag is "1".
[0064] This ensures that wireless communication tests and rollbacks are only performed when the test flag is set to "1". In other words, setting the test flag to "0" prevents wireless communication tests and rollbacks from being performed unnecessarily.
[0065] Referring again to Figure 4, the active firmware 300 and the inactive firmware 301 operate exclusively based on the boot loader 302 and the configuration file 303.
[0066] Thus, the memory unit 205 saves both the new and old firmware simultaneously during OTA updates, with the aim of enabling a quick rollback to the proven old firmware without requiring data transmission or reception with the higher-level system if a problem occurs with the new firmware.
[0067] In Figure 4, the memory unit 205 stores two firmware files, but the number of firmware files can be two or more. However, there is only one active firmware file 300, and the others are treated as inactive firmware files 301.
[0068] Referring again to Figure 3, the security module 206 includes various modules that perform encryption or authentication functions, and performs tasks such as transferring firmware from the higher-level ECU to the master device 200 and transmitting new firmware from the master device 200 to the slave device 100. For example, when transmitting firmware from the master device 200 to the slave device 100, the security module 206 may perform a process to guarantee integrity and authenticity by adding a hash value, signature data, etc., to the new firmware so that it can detect if it receives malicious firmware. Note that the security module 206 only needs to perform a process to guarantee at least one of integrity and authenticity.
[0069] Figure 6 shows the configuration of the security module 206 according to this embodiment. Note that the configuration shown in Figure 6 is just one example and does not restrict the type of module to be installed, the key length, etc.
[0070] As shown in Figure 6, the security module 206 includes a first encryption circuit 400, a second encryption circuit 401, a third encryption circuit 402, a calculation circuit 403, a random number generator 404, a control unit 405, and an interface unit 406.
[0071] The first encryption circuit 400 to the third encryption circuit 402 encrypt data using different encryption methods.
[0072] The first encryption circuit 400 performs encryption using, for example, AES (Advanced Encryption Standard) encryption, which uses an encryption key of a predetermined number of bits. In this embodiment, AES-128 with a key length of 128 bits is used, but the key length is not limited to this and may be 192 bits, 256 bits, or the like.
[0073] The second encryption circuit 401 performs encryption using, for example, elliptic curve cryptography (ECC). In this embodiment, ECC-256 with a key length of 256 bits is used, but the key length is not limited to this and may be other than 256 bits.
[0074] The third encryption circuit 402 performs encryption using, for example, a public-key cryptography scheme. The third encryption circuit 402 performs encryption using, for example, RSA (Rivest-Shamir-Adleman) encryption. In this embodiment, the third encryption circuit 402 uses RSA-3072 with a key length of 3072 bits, but the key length is not limited to this and may be 2048 bits, 4096 bits, etc.
[0075] The calculation circuit 403 calculates a hash value from the input data (transmitted data) for the receiving device to verify data tampering. The calculation circuit 403 may, for example, calculate a fixed-length hash value from data of any length. In this embodiment, the calculation circuit 403 calculates the hash value using a hash function (SHA-512 (Secure Hash Algorithm 512-bit)) that calculates a 512-bit hash value from data of any length.
[0076] The random number generator 404 generates random numbers for encrypting the input data. For example, the input data may be pseudo-encrypted using random numbers and logical operations. The random number generator 404 is, for example, a hardware random number generator that generates random numbers using random physical phenomena, but it may also be configured to generate random numbers (e.g., pseudo-random numbers) using a random number generation algorithm (software).
[0077] The control unit 405 is a control device that controls each process of the security module 206. The control unit 405 may, for example, cause any of the first encryption circuit 400 to the third encryption circuit 402 to perform encryption of transmitted data and decryption of received data. Furthermore, if the control unit 405 changes the encryption circuit used for encryption, it may transmit the public key corresponding to the secret key of the changed encryption circuit to the slave device 100 via the wireless communication unit 210 and the antenna 211.
[0078] The interface unit 406 is a communication interface for the security module 206 to communicate with external circuits, etc.
[0079] Furthermore, the number of encryption circuits in the security module 206 is not limited to three; it may be one or more. Also, encryption methods other than the three methods described above may be used. Additionally, the security module 206 may be capable of generating new encryption keys (for example, a set of private and public keys) for communication.
[0080] Referring again to Figure 3, the OTA unit 207 controls the OTA update. It can also be said that the OTA unit 207 controls the firmware to be applied.
[0081] Specifically, the OTA unit 207 sets test flags and executes the rollback function. The OTA unit 207 also determines whether or not to perform a rollback based on the results of the wireless communication test. For example, the OTA unit 207 determines whether or not to perform a rollback based on the measurement time of the timer unit 209.
[0082] The wireless communication test control unit 208 controls and determines the wireless communication test after the OTA update. The wireless communication test control unit 208 determines whether the master device 200 and the slave device 100 can communicate wirelessly using the new firmware (for example, whether the wireless communication test is successful or not). The wireless communication test control unit 208 of the master device 200 performs a wireless communication test with the wireless communication circuit 101 provided in the slave device 100.
[0083] The timer unit 209 measures the time related to the wireless communication test. For example, in a wireless communication test, the timer unit 209 measures the elapsed time from the start of the test. It can also be said that the timer unit 209 measures whether or not the time limit for the wireless communication test has been reached.
[0084] The wireless communication unit 210 is a communication unit for wireless communication with the slave device 100. In the test mode described later, the wireless communication unit 210 performs wireless communication tests. In the normal mode, the wireless communication unit 210 wirelessly transmits necessary information to the slave device 100. The configuration of the wireless communication unit 210 is the same as that of the wireless communication unit 109.
[0085] Antenna 211 is a wireless communication antenna mounted on the master device 200. These antennas may also be antennas for short-range wireless communication. In this embodiment, antenna 211 is an antenna for short-range wireless communication.
[0086] The slave device 100 and the master device 200 can transmit and receive data wirelessly via antennas 110 and 211. The master device 200, for example, transmits a voltage acquisition command sent from the BMU 201 to the slave device 100 via the wireless communication circuit 202. The slave device 100 receives data transmitted from the master device 200 via the wireless communication circuit 101, and the battery monitoring circuit 111 acquires voltage information of the battery 11a according to the command, and then sends it back to the BMU 201 via the wireless communication path. As a result, the BMU 201 can manage the battery status of the battery 11a, such as SOC, SOH, and SOP.
[0087] [1-2. Overview of OTA Update] Next, an overview of the OTA update in the wireless BMS 5 configured as described above will be explained with reference to Figures 7A to 7C. Figures 7A to 7C are diagrams showing the overview of the OTA update according to this embodiment.
[0088] Figure 7A shows an example where the currently applied firmware is version 2.0, and the firmware that is not currently applied is the older version, version 1.0. In other words, Figure 7A shows an example where version 2.0 firmware is set to active in configuration file 303, and the boot loader 302 is loading version 2.0 firmware. The check mark indicates that it is set to active in configuration file 303. Version 2.0 firmware is an example of the first firmware.
[0089] Here, we will explain what happens after the master device 200 receives the new firmware to be updated from the higher-level ECU. The new firmware is assumed to be version 3.0.
[0090] Figure 7B shows an example where the currently applied firmware is version 2.0, and the firmware that is not currently applied is the newer version, version 3.0. Figure 7B shows the state in which version 3.0 firmware is stored as inactive firmware 301. Version 3.0 firmware is an example of the second firmware.
[0091] At this point, the OTA unit 207 activates firmware version 3.0 of the configuration file 303, and a restart is performed. At this time, the test flag is set to "1".
[0092] Figure 7C shows an example where, after a reboot, version 3.0 firmware is set to active in configuration file 303 (see checkmark), and the boot loader 302 loads version 3.0 firmware after a reboot.
[0093] In this state, a wireless communication test is performed. It is determined whether the master device 200 and the slave device 100 can communicate wirelessly with the version 3.0 firmware applied. If it is determined that wireless communication is possible (test successful), the version 3.0 firmware is continued to be applied. On the other hand, if it is determined that wireless communication is not possible (test failed), a rollback to version 2.0 firmware is performed. Specifically, the OTA unit 207 switches to the active version 2.0 firmware in the configuration file 303 and restarts. As a result, after the restart, the boot loader 302 loads the version 2.0 firmware. In other words, it returns to the state shown in Figure 7B.
[0094] For example, if there is a bug in the firmware, communication between the master device 200 and the slave device 100 may fail, so the inability to establish a wireless connection becomes a criterion for deciding whether to roll back.
[0095] [1-3. Operation of Wireless BMS] Next, the operation of the wireless BMS 5 configured as described above will be explained with reference to Figures 8 to 14. Figure 8 is a flowchart showing the operation (wireless communication method) of the master device 200 according to this embodiment during OTA download.
[0096] As shown in Figure 8, the wireless communication circuit 202 of the master device 200 receives update firmware (new firmware) from the BMU 201 (S101). The update firmware may be downloaded via the BMU 201, for example. The update firmware is an example of second firmware.
[0097] Next, the core unit 204 of the wireless communication circuit 202 outputs the update firmware received in step S101 to the security module 206 (S102).
[0098] Next, the security module 206 determines the hash value of the acquired update firmware to verify the integrity of the received data (i.e., the update firmware) (S103). The security module 206 determines whether the update firmware has been tampered with or whether there is any data loss. In addition, if the received data includes a signature in step S103, the security module 206 may further verify the authenticity of the received data based on the signature.
[0099] Next, if the hash values do not match (No in S104), for example, if there is a possibility that the update firmware has been tampered with, the security module 206 determines that the update firmware is inappropriate and discards it (S105). For example, the security module 206 deletes the update firmware. If the hash values match (Yes in S104), for example, if the update firmware has not been tampered with, the security module 206 proceeds to step S106 (OTA update process) shown in Figure 9.
[0100] Figure 9 is a flowchart showing the operation (wireless communication method) of the master device 200 according to this embodiment during an OTA update.
[0101] The OTA unit 207 writes the update firmware to the inactive firmware area of the memory unit 205 (S106) and writes the test mode flag (test flag) to the boot loader configuration file (configuration file 303) of the memory unit 205 (S107). It can also be said that the OTA unit 207 records the test flag in the boot loader configuration file 303 when the update firmware is applied. Here, the OTA unit 207 writes the test mode flag to "1". As a result, the operating mode of the wireless communication circuit 202 transitions from normal mode to test mode. The OTA unit 207 also changes the read destination in the configuration file 303 to the inactive firmware 301 (here, the update firmware received in step S101). In other words, the OTA unit 207 activates the update firmware. In this way, the OTA unit 207 can enable the execution of wireless communication tests and the execution of rollback functions according to the value of the test flag.
[0102] The normal mode is a mode in which the slave device 100 and the master device 200 communicate commands and data related to battery monitoring, and in this mode, the wireless communication function and the rollback function are restricted (for example, prohibited). The test mode is a mode for determining whether the slave device 100 and the master device 200 may switch to the update firmware (for example, whether the update firmware contains defects), and in this mode, the wireless communication function and the rollback function are not restricted. In the test mode, communication of commands and data related to battery monitoring between the slave device 100 and the master device 200 may be restricted.
[0103] Furthermore, the operation mode of the wireless communication circuit 202 may or may not be transmitted to the slave device 100 when it transitions from normal mode to test mode.
[0104] Next, the boot loader 302 changes the load destination to the memory area of the inactive firmware 301 based on the configuration file 303 and restarts in test mode (S108). As a result, the master device 200 operates in test mode only during the first startup, for example, when an updated firmware is applied.
[0105] Next, the OTA unit 207 determines whether the startup (restart) was successful (S109). If it determines that the startup was successful (Yes in S109), it starts the wireless communication test (S110). In this way, the wireless communication test is performed after the firmware being applied has been switched from the old firmware to the updated firmware. The wireless communication test will be described later with reference to Figures 10A and 10B.
[0106] In the wireless communication test, the timer unit 209 starts measuring time (S111), and the wireless communication unit 210 establishes a wireless connection to the slave device 100 (S112). The wireless communication unit 210 only needs to establish a wireless connection to at least one of the multiple slave devices 100 that are wirelessly connected and communicating. For example, the wireless communication unit 210 may establish a wireless connection to any one or more of the multiple slave devices 100 that are wirelessly connected and communicating, or it may establish a wireless connection to all of the slave devices 100 that are wirelessly connected and communicating.
[0107] Next, the OTA unit 207 determines whether or not a wireless connection was successfully established within a certain period of time (S113). The OTA unit 207 determines whether or not a wireless connection with the slave device 100 was successfully established before the measured time measured by the timer unit 209 elapsed. The certain period of time may be predetermined and stored in the memory unit 205. The certain period of time may be a few milliseconds, a few seconds, or several tens of seconds.
[0108] Next, if the OTA unit 207 determines that a wireless connection has been successfully established within a certain period of time (Yes in S113), it deletes the test mode flag from the configuration file 303 stored in the memory unit 205 in order to terminate the test mode and transition to normal mode (S114). Deleting the test mode flag may involve deleting the value of the test mode flag or setting the value of the test mode flag to "0". This makes it possible to disable the execution of the wireless communication test and the rollback function depending on the value of the test flag (in this case, based on the value of the test mode flag being "0" or the test mode flag not existing).
[0109] Next, the OTA unit 207 performs a restart in normal mode (S115) and outputs an update completion notification to the BMU 201 (S116). Note that the order of steps S115 and S116 may be reversed. In other words, the test mode may include the process up to outputting the update completion notification.
[0110] Furthermore, if the OTA unit 207 determines that the startup (restart) has failed (No in S109), or if it determines that the wireless connection has not been successfully established within a certain period of time (No in S113), it returns to step S108 and executes the processes from step S108 onwards again.
[0111] When step S108 is executed again, the memory unit 205 stores the update firmware as active firmware 300 and the old firmware before the update as inactive firmware 301. Therefore, when step S108 is executed again, the old firmware becomes active and the update firmware becomes inactive. In other words, the old firmware is reapplied. The old firmware here (for example, the firmware used before the update firmware) is an example of the first firmware.
[0112] Then, with the old firmware applied, a wireless communication test is performed (S110). It can also be said that the OTA unit 207 performs the wireless communication test after the first firmware has been reapplied and while the reapplied first firmware is active. Note that the wireless communication test with the old firmware applied may be omitted.
[0113] Thus, in step S108, which is executed after step S113 is determined to be No, a process is performed to revert from the new firmware to the previously used firmware (in this case, the old firmware).
[0114] This allows the system to automatically switch to the old firmware via a rollback function if the wireless communication test fails. Therefore, even if problems occur during the OTA update, the master device 200 can communicate with the slave device 100 using the old firmware. In other words, the master device 200 can continue to operate without human intervention even if problems occur during the OTA update.
[0115] Furthermore, while the processes in steps S106 to S116 are being executed in the master device 200, the slave device 100 does not need to execute the processes in steps S212 to S224 shown in Figure 13, which will be described later. In other words, the OTA update process may be executed by only one of the master device 200 or the slave device 100 (i.e., exclusively).
[0116] Here, the wireless communication test will be explained with reference to Figures 10A and 10B. Figures 10A and 10B are diagrams illustrating the wireless communication test according to this embodiment. Using Figure 10A, an example of a successful wireless communication test between the master device 200 and the slave device 100 during an OTA update will be explained, and using Figure 10B, an example of a failed wireless communication test will be explained. Note that the test flag is set to "1".
[0117] As shown in Figure 10A, the wireless communication test is started in the initial state. The initial state is, for example, a state in which the update firmware is set to active, a restart is successful, and the wireless communication test has not been started. When the wireless communication test is started, the timer unit 209 starts measuring time (S111), and the wireless communication unit 210 establishes a wireless connection with the slave device 100 (S112). Specifically, the wireless communication unit 109 transmits an advertisement packet. The wireless communication unit 109 may transmit advertisement packets at predetermined time intervals until it receives a connection request from the wireless communication unit 210 of the master device 200. When the wireless communication unit 210 receives an advertisement packet from the wireless communication unit 109, it transmits a connection establishment request to the slave device 100 requesting the establishment of a connection.
[0118] When the wireless communication unit 109 receives a connection establishment request from the wireless communication unit 210, it transmits a connection establishment response, which is a response to the connection establishment request, to the slave device 100. This establishes a connection, and the master device 200 and the slave device 100 become able to communicate. The OTA unit 207 determines that the wireless communication test is successful if a connection is established within a certain time (Yes in S113). In this way, after the timer unit 209 starts measuring time, if the slave device 100 responds to the connection request packet from the master device 200 and establishes a connection, the wireless communication test is determined to be successful.
[0119] Then, the OTA unit 207 sets the test flag to "0" (S114) and restarts (S115). This is intended to restrict the test function and rollback function during normal use (normal mode). For example, if the rollback condition is "when the master and slave cannot establish a wireless connection within a certain period of time during a wireless communication test," the OTA unit 207 determines that there is an abnormality in the update firmware applied to the active firmware 300 and executes a process to revert to the old firmware stored in the inactive firmware 301.
[0120] However, even during normal use, the wireless connection between the master device 200 and the slave device 100 may be disrupted due to congestion in the surrounding radio wave environment. If the rollback function is not restricted, a rollback will be performed in such cases, but this is only temporary due to congestion in the surrounding radio wave environment and deviates from the original purpose of "when it is determined that there is an abnormality in the firmware." Therefore, a test flag is necessary to restrict the rollback function, along with the test function. After the wireless communication test is successful, the test flag is reset as described above.
[0121] As shown in Figure 10B, the wireless communication unit 109 has not received a connection establishment request from the wireless communication unit 210 within a certain period of time after sending the advertisement packet. In this case, the OTA unit 207 determines that the wireless communication test has failed because a connection has not been established within a certain period of time (No in S113), returns to step S108, applies the old firmware (a rollback is performed), and a restart is performed. If the master device 200 is unresponsive, the wireless communication test is determined to have failed. A failure in the wireless communication test means that there is some kind of abnormality in the wireless communication function (for example, some kind of abnormality in the update firmware).
[0122] Next, the operation when the slave device 100 is updated via OTA will be explained with reference to Figures 11 to 14. Figure 11 is a flowchart showing the operation (wireless communication method) of the master device 200 during OTA download when performing an OTA update of the slave device 100 according to this embodiment. Steps S201 to S205 shown in Figure 11 are the same as steps S101 to S105 shown in Figure 8, so their explanation will be omitted.
[0123] As shown in Figure 11, if the hash values match (Yes in S204), for example, if the update firmware has not been tampered with, the security module 206 encrypts the update firmware, assigns an authentication tag (S206), and transmits the update firmware to the slave device 100 via the wireless communication unit 210 (S207). In step S207, the update firmware is transmitted to each of the slave devices 100 whose firmware is to be updated. The authentication tag includes at least one of a hash value and a signature, and in this embodiment, it includes both a hash value and a signature.
[0124] Figure 12 is a flowchart showing the operation (wireless communication method) of the slave device 100 during OTA download according to this embodiment. The operation shown in Figure 12 is performed, for example, on each of the slave devices 100 whose firmware is to be updated.
[0125] As shown in Figure 12, the slave device 100 receives update firmware from the master device 200 via the wireless communication unit 109 (S208). The update firmware is an example of the second firmware.
[0126] Next, the core unit 103 of the wireless communication circuit 101 outputs the update firmware received in step S201 to the security module 105 (S209).
[0127] Next, the security module 105 decrypts the acquired update firmware and verifies the authentication tag (S210). In verifying the authentication tag, for example, it is determined whether the hash value contained in the authentication tag matches the hash value calculated using the decrypted update firmware. This allows the integrity of the update firmware to be confirmed. In addition, in step S210, the security module 105 may further confirm the authenticity of the update firmware by using a signature or the like to confirm that the update firmware is firmware transmitted from the master device 200.
[0128] Next, if the verification is successful (for example, if the hash values match), the security module 105 outputs the update firmware to the OTA unit 106 (S211).
[0129] Figure 13 is a flowchart showing the operation (wireless communication method) of the slave device 100 according to this embodiment during an OTA update. Steps S212 to S222 shown in Figure 13 are the same as steps S106 to S116 shown in Figure 9, so their explanation is omitted.
[0130] In step S218, the wireless communication unit 109 establishes a wireless connection to the master device 200. In step S222, the OTA unit 106 outputs an update completion notification to the security module 105. The main component of each process shown in Figure 13 is the wireless communication circuit 101.
[0131] Note that the old firmware (for example, the firmware used before the update firmware) that becomes active in step S214, which is executed after step S219 shown in Figure 13 is determined to be No, is an example of the first firmware.
[0132] As shown in Figure 13, the security module 105 encrypts the update completion notification, assigns an authentication tag to it (S223), and wirelessly transmits the update completion notification with the authentication tag to the master device 200 via the wireless communication unit 109 (S224).
[0133] Figure 14 is a flowchart showing the operation (wireless communication method) of the master device 200 according to this embodiment when the OTA update of the slave device 100 is completed.
[0134] As shown in Figure 14, when the wireless communication circuit 202 (for example, the core unit 204) of the master device 200 receives an update completion notification from the slave device 100 via the wireless communication unit 210, it outputs the received update completion notification to the security module 206 (S225).
[0135] Next, the security module 206 decrypts the update completion notification and verifies the authentication tag (S226). In verifying the authentication tag, for example, it is determined whether the hash value contained in the authentication tag matches the hash value calculated using the decrypted update completion notification.
[0136] Next, if the verification is successful (for example, if the hash values match), the security module 206 outputs an update completion notification to the OTA unit 207 (S227).
[0137] Next, the OTA unit 207 outputs an update completion notification to the BMU 201 (S228). This allows the BMU 201 to notify the higher-level ECU that the firmware update has been completed in the slave device 100.
[0138] Furthermore, when an OTA update is performed on two or more slave devices 100, the OTA update process (for example, the process shown in Figure 13) may be executed simultaneously on the two or more slave devices 100. This can shorten the time required for the OTA update of the slave devices 100. Alternatively, the OTA update process may be executed sequentially on each of the two or more slave devices 100. This can prevent the simultaneous execution of a rollback process on two or more slave devices 100 if there is a problem with the update firmware. For example, it can reduce the amount of processing required for the rollback process executed on the slave devices 100 within a certain period.
[0139] (Embodiment 2) The wireless BMS according to this embodiment will be described below with reference to Figures 15 to 16C. In the following description, the differences from Embodiment 1 will be the main focus, and the same or similar content as in Embodiment 1 will be omitted or simplified.
[0140] [2-1. Configuration of Wireless BMS] The configuration of a wireless BMS having a wireless communication device according to this embodiment will be described with reference to Figures 15 to 16C. Figure 15 is a diagram showing the functional configuration of the wireless BMS 5 according to this embodiment. The wireless BMS 5 according to this embodiment differs from the wireless BMS 5 according to Embodiment 1 in that the wireless communication circuit has multiple memory units. In this embodiment, a wireless BMS 5 capable of continuing to operate as a wireless communication circuit even if one memory unit (one semiconductor chip) is damaged or subjected to a cyberattack will be described.
[0141] As shown in Figure 15, the wireless BMS 5 comprises a slave device 100a and a master device 200a.
[0142] The slave device 100a includes a wireless communication circuit 101a, which includes an MCU 102a. The MCU 102a has a memory section comprising a first memory section 104a, a second memory section 104b, and a third memory section 104c. The first memory section 104a, the second memory section 104b, and the third memory section 104c are implemented using different semiconductor chips.
[0143] The master device 200a includes a wireless communication circuit 202a, which includes an MCU 203a. The MCU 203a has a memory section comprising a first memory section 205a, a second memory section 205b, and a third memory section 205c. The first memory section 205a, the second memory section 205b, and the third memory section 205c are implemented using different semiconductor chips.
[0144] Here, the configuration of each memory section will be explained with reference to Figures 16A to 16C. Note that the first memory section 104a to the third memory section 104c and the first memory section 205a to the third memory section 205c have similar configurations, so the configuration of the first memory section 205a to the third memory section 205c will be explained, and the configuration of the first memory section 104a to the third memory section 104c will be omitted.
[0145] Figure 16A shows the configuration of the first memory unit 205a according to this embodiment. Figure 16B shows the configuration of the second memory unit 205b according to this embodiment. Figure 16C shows the configuration of the third memory unit 205c according to this embodiment.
[0146] As shown in Figure 16A, the first memory unit 205a has a memory area in which the active firmware 700 is stored, a control unit 701, and an interface unit 702. In other words, the first memory unit 205a stores the active firmware 700. The active firmware 700 is an example of the first firmware.
[0147] The first memory unit 205a has a memory area for storing one firmware (in this case, the active firmware 700).
[0148] The control unit 701 is a control device that controls each process of the first memory unit 205a. The control unit 701 performs, for example, writing firmware to be stored in the memory area. The control unit 701 may control the writing process so that only one firmware file is stored.
[0149] The interface unit 702 is a communication interface for the first memory unit 205a to communicate with external circuits, etc.
[0150] As shown in Figure 16B, the second memory unit 205b has a memory area where the inactive firmware 703 is stored, a control unit 704, and an interface unit 705. In other words, the second memory unit 205b stores the inactive firmware 703. If the inactive firmware 703 is update firmware, the inactive firmware 703 is an example of the second firmware.
[0151] The second memory unit 205b has a memory area capable of storing one firmware (in this case, an inactive firmware 703).
[0152] The control unit 704 is a control device that controls each process of the second memory unit 205b. The control unit 704 performs, for example, writing firmware to be stored in the memory area. The control unit 704 may control the writing process so that only one firmware file is stored.
[0153] The interface unit 705 is a communication interface for the second memory unit 205b to communicate with external circuits, etc.
[0154] As shown in Figure 16C, the third memory unit 205c has a memory area where the boot loader 706 is stored, a memory area where the configuration file 707 is stored, a control unit 708, and an interface unit 709. Thus, the third memory unit 205c has a memory area for storing information other than firmware.
[0155] The control unit 708 is a control device that controls each process of the third memory unit 205c. The control unit 708 may, for example, control the updating of information in the configuration file 303.
[0156] The interface unit 709 is a communication interface for the third memory unit 205c to communicate with external circuits, etc.
[0157] Thus, in this embodiment, the active firmware 700, the inactive firmware 703, the boot loader 706, and the configuration file 707 are stored in different memory units (different semiconductor chips). This allows the system to operate using the firmware stored in another memory unit (recovery is possible using another memory unit) even if, for example, one of the memory units storing the firmware is damaged or subjected to a cyberattack, thereby improving the availability and security performance of the wireless communication circuit. For example, failure of the wireless BMS 5 can be avoided. Furthermore, the advantages of the wireless communication circuit storing multiple firmwares can be better utilized.
[0158] In the above example, a wireless communication circuit has three memory units, but the number of memory units is not limited to three; it can be two or more. For example, a wireless communication circuit may have four or more memory units. In the case of two memory units, the boot loader 706 and the configuration file 707 may be stored in the two memory units in any way.
[0159] The first memory section 205a only needs to store at least the active firmware 700, and may also store inactive firmware 703. The second memory section 205b only needs to be capable of storing at least the inactive firmware 703, and may also store the active firmware 700.
[0160] Furthermore, if the second memory unit 205b fails while the second firmware for updating is being applied, the OTA unit 207 may switch the firmware to be applied to the firmware stored in the first memory unit 205a (in this case, the first firmware). The failure of the second memory unit 205b may be detected, for example, by a known memory diagnostic tool.
[0161] (Embodiment 3) The wireless BMS according to this embodiment will be described below with reference to Figures 17 to 19. In the following description, the differences from Embodiment 1 will be the main focus, and the same or similar content as in Embodiment 1 will be omitted or simplified.
[0162] [3-1. Configuration of Wireless BMS] The configuration of a wireless BMS having a wireless communication device according to this embodiment will be described with reference to Figure 17. Figure 17 is a diagram showing the functional configuration of the wireless BMS 5 according to this embodiment. The wireless BMS 5 according to this embodiment differs from the wireless BMS 5 according to Embodiment 1 in that, if the wireless communication test is successful, it has a redundancy determination unit to overwrite the storage area of the old firmware with new firmware (update firmware) and ensure redundancy of two identical new firmwares. In the following, an example in which the wireless communication circuit has one memory unit will be described, but as shown in Embodiment 2, it may have multiple memory units.
[0163] As shown in Figure 17, the wireless BMS 5 comprises a slave device 100b and a master device 200b.
[0164] The slave device 100b includes a wireless communication circuit 101b, which includes an MCU 102b. In addition to the MCU 102, the MCU 102b has a redundancy determination unit 112.
[0165] If the OTA unit 106 succeeds in the wireless communication test, it overwrites the memory area of the old firmware with the new firmware (the firmware that succeeded in the wireless communication test). As a result, two identical firmwares are stored in one memory unit 104. In the example in Figure 17, the two data sets of the new firmware are stored in different memory areas within one memory unit 104.
[0166] The redundancy determination unit 112 determines the redundancy of the two firmwares stored in the memory unit 104. For example, the redundancy determination unit 112 performs error detection based on whether the firmware written to the two memory areas matches.
[0167] The master device 200b includes a wireless communication circuit 202b, which includes an MCU 203b. In addition to the MCU 203, the MCU 203b has a redundancy determination unit 212.
[0168] If the OTA unit 207 succeeds in the wireless communication test, it overwrites the memory area of the old firmware with the new firmware (the firmware that succeeded in the wireless communication test). As a result, two identical firmwares are stored in one memory unit 205. In the example in Figure 17, the two data sets of the new firmware are stored in different memory areas within one memory unit 205.
[0169] The redundancy determination unit 212 determines the redundancy of the two firmwares stored in the memory unit 205. For example, the redundancy determination unit 212 performs error detection based on whether the firmwares written to the two memory areas match. The redundancy determination unit 212 may perform error detection based on whether the hash values of the two firmwares match, or by bit comparison of the two firmwares, or by other methods.
[0170] [3-2. Operation of Wireless BMS] Next, the operation of the wireless BMS 5 configured as described above will be explained with reference to Figures 18 and 19. Figure 18 is a flowchart showing the operation (wireless communication method) of the master device 200b according to this embodiment during OTA update.
[0171] As shown in Figure 18, the operation of the master device 200b includes the addition of step S121 compared to the operation shown in Figure 9.
[0172] After the wireless communication test is successful (Yes in S113), the OTA unit 207 writes the same firmware as the active firmware area (the firmware currently set to be active) to the inactive firmware area of the memory unit 205 (S121). In other words, the OTA unit 207 overwrites the memory area where the inactive firmware 301 is stored with the active firmware 300. As a result, two identical firmwares are stored in one memory unit 205 (one semiconductor chip), so after the operation of the new firmware is guaranteed, the new firmware can be duplicated to provide redundancy.
[0173] The redundancy determination unit 212 can detect errors such as firmware corruption or tampering by determining whether the two firmwares stored in the memory unit 205 are identical. Matching the two firmwares is performed, for example, by verifying and comparing the checksums or hash values of the active and inactive firmwares when the firmware is loaded, but is not limited to this.
[0174] Figure 19 is a flowchart showing the operation (wireless communication method) of the slave device 100 according to this embodiment during an OTA update.
[0175] As shown in Figure 19, the operation of the slave device 100 includes the addition of step S231 compared to the operation shown in Figure 13.
[0176] After the wireless communication test is successful (Yes in S219), the OTA unit 106 writes the same firmware as the active firmware area (the firmware currently set to be active) to the inactive firmware area of the memory unit 104 (S231). The process in step S231 is the same as the process in step S121 shown in Figure 18.
[0177] The redundancy determination unit 112 can detect errors such as firmware corruption or tampering by determining whether the two firmwares stored in the memory unit 104 are identical. The detection method used by the redundancy determination unit 112 to detect errors is the same as that used by the redundancy determination unit 212.
[0178] Error detection is performed by at least one of the redundancy determination units 112 and 212, which is expected to improve the overall stability of the wireless BMS 5.
[0179] (Other Embodiments) Although one or more embodiments of wireless BMS etc. have been described above based on Embodiments 1 to 3 (Embodiments etc.), this disclosure is not limited to these embodiments etc. Without departing from the spirit of this disclosure, various modifications that a person skilled in the art can conceive of may be applied to these embodiments, and forms constructed by combining components from different embodiments may also be included in this disclosure.
[0180] For example, the above embodiments describe an example in which both the master device and the slave device included in the wireless BMS have a rollback function, but the invention is not limited to this. For example, one of the master device and the slave device (for example, at least one) may have a rollback function.
[0181] Furthermore, although the multiple memory units in the above embodiment 2 are different semiconductor chips, at least two of them may be realized by a semiconductor package in which two or more semiconductor chips are packaged.
[0182] Furthermore, although the above embodiments describe a case where the wireless communication device updates its firmware, the technology of this disclosure is also applicable to cases where the software is updated, for example.
[0183] Furthermore, in the above embodiments, each component may be implemented by being composed of dedicated hardware or by executing a software program suitable for each component. Each component may also be implemented by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0184] Furthermore, the order in which each step in the flowchart is performed is illustrative for the purpose of specifically illustrating this disclosure, and may be in a different order. Also, some of the above steps may be performed simultaneously (in parallel) with other steps, and some of the above steps may not be performed.
[0185] Furthermore, the division of functional blocks in the block diagram is just one example; multiple functional blocks can be implemented as a single functional block, a single functional block can be divided into multiple parts, or some functions can be moved to other functional blocks. In addition, the functions of multiple functional blocks with similar functions can be processed in parallel or time-sharing by a single piece of hardware or software.
[0186] Furthermore, the master device and slave device according to the above embodiments may be implemented as a single device or as multiple devices. When at least one of the master device and slave device is implemented as multiple devices, the components of the circuit of at least one of them may be distributed among the multiple devices in any way. When at least one of the circuits is implemented as multiple devices, the method of communication between the multiple devices is not particularly limited and may be wireless communication or wired communication. In addition, wireless communication and wired communication may be combined between the devices.
[0187] Furthermore, each component described in the above embodiments may be implemented as software, or typically as an integrated circuit (LSI). These may be individually integrated onto a single chip, or some or all of them may be integrated onto a single chip. Here, we refer to it as an LSI, but depending on the degree of integration, it may also be called an IC, system LSI, super LSI, or ultra LSI. Moreover, the method of integrated circuit implementation is not limited to LSIs; it may also be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After LSI manufacturing, a programmable FPGA (Field Programmable Gate Array) or a reconfigurable processor that can reconfigure the connections or settings of circuit cells inside the LSI may be used. Furthermore, if an integrated circuit implementation technology that replaces LSIs emerges due to advances in semiconductor technology or other derived technologies, it is natural that the components may be integrated using that technology.
[0188] A system LSI is a highly functional LSI manufactured by integrating multiple processing units onto a single chip. Specifically, it is a computer system composed of a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), and other components. The ROM stores the computer program. The system LSI achieves its function by having the microprocessor operate according to the computer program.
[0189] Furthermore, one aspect of this disclosure may be a computer program that causes a computer to perform characteristic steps included in the wireless communication method shown in Figures 8, 9, 11 to 14, 18, and 19.
[0190] Furthermore, for example, the program may be a program to be executed by a computer. Also, in one aspect of this disclosure, such a program may be recorded on a computer-readable non-temporary recording medium. For example, such a program may be recorded on a recording medium and distributed or made available. For example, by installing the distributed program on a device having another processor and having that processor execute the program, it becomes possible to have that device perform the above-mentioned processes.
[0191] (Note) Based on the above description of embodiments, the following technologies are disclosed.
[0192] (Technical 1) A wireless communication system in which a master device having a battery control circuit for controlling a battery and a slave device having a battery monitoring circuit for monitoring the battery communicate wirelessly, wherein one of the master device and the slave device has a wireless communication device comprising: a memory unit capable of storing a first firmware being applied and a second firmware acquired by wireless communication; a wireless communication test control unit that performs a wireless communication test between the wireless communication device of the other of the master device and the slave device; and an OTA unit that controls the firmware to be applied, wherein the wireless communication test control unit performs the wireless communication test after the firmware to be applied is switched from the first firmware to the second firmware by the OTA unit, and the OTA unit reapplies the first firmware if the wireless communication test is not passed.
[0193] This means that if a wireless communication test with the second firmware, which is the target of the update, fails, a rollback is performed and the first firmware is reapplied. In other words, even if a wireless communication test with the second firmware fails, wireless communication can be continued by reapplying the first firmware. Therefore, even if a problem occurs during OTA update, it is possible to realize a wireless communication device in which at least one of the master device and slave device, as information processing devices, can continue to operate.
[0194] (Technology 2) The wireless communication device of Technology 1 further includes a security module that verifies at least one of the integrity and authenticity of the downloaded second firmware, and the OTA unit switches the firmware to be applied from the first firmware to the second firmware in order to perform the wireless communication test after at least one of the integrity and authenticity has been verified.
[0195] This ensures that wireless communication tests are performed using a second firmware version whose integrity and authenticity have been verified. In other words, a second firmware version that has been tampered with is not applied in the first place, preventing it from reaching the wireless communication test stage. Therefore, since the application of a tampered second firmware version can be suppressed, it is possible to realize a wireless communication device in which at least one of the master and slave devices can continue to operate even if a problem occurs during OTA updates.
[0196] (Technology 3) The memory unit records a test flag in the boot loader configuration file when the second firmware is applied, and the OTA unit enables the execution of the wireless communication test and the execution of the rollback function according to the value of the test flag, and is a wireless communication device according to Technology 1 or 2.
[0197] This allows you to switch between performing wireless communication tests and rollback functions using a test flag.
[0198] (Technical 4) The OTA unit is a wireless communication device according to Technical 3, which after the second firmware is applied, instructs the wireless communication test control unit to perform the wireless communication test, and further includes a timer unit for measuring the time related to the wireless communication test.
[0199] This allows the timer unit to determine whether a certain amount of time has elapsed, making it easy to determine whether a wireless connection was successful based on whether a wireless connection was established within that time.
[0200] (Technical 5) The OTA unit is a wireless communication device according to Technical 3 or 4, which, if the wireless communication test is successful within a certain period of time, deletes the test flag stored in the memory unit and, depending on the value of the test flag, disables the execution of the wireless communication test and the execution of the rollback function.
[0201] This prevents wireless communication tests and rollback functions from being executed at times other than OTA updates. For example, it prevents rollback from being triggered if the connection is lost due to poor radio wave conditions during normal mode.
[0202] (Technical 6) The memory unit has a first memory unit and a second memory unit, each composed of different semiconductor chips, the first firmware is stored in the first memory unit, and the second firmware is stored in the second memory unit, and this is a wireless communication device according to any of Technical 1 to 5.
[0203] This makes it possible to realize a wireless communication device in which, even if one memory unit fails, at least one of the memory units of the master device and the slave device can continue to operate in both test mode and normal mode by using the firmware stored in the other memory unit.
[0204] (Technical 7) The OTA unit is a wireless communication device according to Technical 6 that, if the second memory unit fails while the second firmware is being applied, switches the firmware to be applied to the firmware stored in the first memory unit.
[0205] This makes it possible to realize a wireless communication device in which at least one of the master device and the slave device can continue to operate even in normal mode by using the first firmware stored in the first memory unit, even if the second memory unit fails.
[0206] (Technical 8) The OTA unit is a wireless communication device according to any of Technical 3 to 5, which writes the second firmware to an inactive firmware area in the memory unit if the wireless communication test with the second firmware applied is successful.
[0207] This allows the second firmware, which has successfully passed the wireless connection test, to be stored in both the active firmware area and the inactive firmware area. Therefore, even if the active firmware area is subjected to a cyberattack, at least one of the master device and the slave device can continue to operate using the second firmware in the inactive firmware area.
[0208] (Technical 9) Furthermore, the wireless communication device of Technical 8 is equipped with a redundancy determination unit that performs error detection based on the second firmware stored in a plurality of storage areas of the memory unit.
[0209] This allows for error detection using a second firmware stored in multiple memory areas, thereby improving the security performance of the wireless communication device.
[0210] (Technical 10) The wireless communication test control unit is a wireless communication device according to any of Technical 1 to 9 that applies the first firmware and performs the wireless communication test when the first firmware is reapplied.
[0211] This makes it possible to prevent the wireless connection between the master device and the wireless communication device of the other slave device from being disconnected in the event of a rollback.
[0212] (Technical 11) A wireless communication device provided by the master device, which is any of the wireless communication devices described in Technical 1 to 10.
[0213] This allows at least one of the master and slave devices to continue operating even if the wireless communication device on the master device experiences problems during an OTA update.
[0214] (Technical 12) A wireless communication device provided by the slave device, the second firmware is a wireless communication device according to any of Technical 1 to 11, which is acquired via the master device.
[0215] This allows at least one of the master and slave devices to continue operating even if the wireless communication device of the slave device experiences problems during an OTA update.
[0216] (Technical 13) The battery, the master device, and the slave device are mounted on a vehicle, and each of the master device and the slave device is a wireless communication device according to any of Technical 1 to 12, which is implemented by an on-board ECU (Electronic Control Unit).
[0217] This allows the in-vehicle ECU to continue operating as an information processing device even if a problem occurs with the wireless communication device of the vehicle's ECU during an OTA update.
[0218] (Technical 14) A wireless communication system comprising the master device and the slave device according to any of Technical 1 to 13.
[0219] This produces the same effect as the wireless communication device described above.
[0220] (Technical 15) A wireless communication method performed by a wireless communication device of one of the master device and the slave device in a wireless communication system in which a master device having a battery control circuit for controlling a battery and a slave device having a battery monitoring circuit for monitoring the battery communicate wirelessly, wherein after the firmware to be applied is switched from a first firmware that is currently being applied to a second firmware obtained by wireless communication, a wireless communication test is performed between the wireless communication device of the other of the master device and the slave device, and if the wireless communication test is not passed, the first firmware is reapplied.
[0221] This produces the same effect as the wireless communication device described above.
[0222] These general or specific embodiments may be implemented using a system, method, integrated circuit, computer program, or a non-temporary recording medium such as a computer-readable CD-ROM, or any combination of a system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored on the recording medium or supplied to the recording medium via a wide-area communication network, including the Internet.
[0223] This disclosure is useful for wireless communication devices that constitute a wireless BMS mounted on vehicles and the like.
[0224] 1 Vehicle 2 Seats 3 Chassis 4 Connection Box 5 Wireless BMS 11 Battery Module 11a Battery 100, 100a, 100b Slave Device 101, 101a, 101b, 202, 202a, 202b Wireless Communication Circuit (Wireless Communication Device) 102, 102a, 102b, 203, 203a, 203b MCU 103, 204 Core Unit 104, 205 Memory Unit 104a, 205a First Memory Unit 104b, 205b Second Memory Unit 104c, 205c Third Memory Unit 105, 206 Security Module 106, 207 OTA Unit 107, 208 Wireless Communication Test Control Unit 108, 209 Timer Unit 109, 210 Wireless Communication Unit 110, 211 Antenna 111 Battery monitoring circuit 112, 212 Redundancy determination unit 200, 200a, 200b Master device 201 BMU (Battery control unit) 300, 700 Active firmware 301, 703 Inactive firmware 302, 706 Boot loader 303, 707 Configuration file 304, 405, 701, 704, 708 Control unit 305, 406, 702, 705, 709 Interface unit 400 First encryption circuit 401 Second encryption circuit 402 Third encryption circuit 403 Calculation circuit 404 Random number generator
Claims
1. A wireless communication system in which a master device having a battery control circuit for controlling a battery and a slave device having a battery monitoring circuit for monitoring the battery communicate wirelessly, wherein one of the master device and the slave device comprises a wireless communication device comprising: a memory unit capable of storing a first firmware being applied and a second firmware acquired by wireless communication; a wireless communication test control unit that performs a wireless communication test with the wireless communication device of the other of the master device and the slave device; and an OTA (Over The Air) unit that controls the firmware to be applied, wherein the wireless communication test control unit performs the wireless communication test after the firmware to be applied has been switched from the first firmware to the second firmware by the OTA unit, and the OTA unit reapplies the first firmware if the wireless communication test is not passed.
2. The wireless communication device according to claim 1, further comprising a security module that verifies at least one of the integrity and authenticity of the downloaded second firmware, wherein the OTA unit switches the firmware to be applied from the first firmware to the second firmware in order to perform the wireless communication test after at least one of the integrity and authenticity has been verified.
3. The wireless communication device according to claim 1 or 2, wherein the memory unit records a test flag in the boot loader configuration file when the second firmware is applied, and the OTA unit enables the execution of the wireless communication test and the execution of the rollback function according to the value of the test flag.
4. The wireless communication device according to claim 3, wherein the OTA unit instructs the wireless communication test control unit to perform the wireless communication test after the second firmware has been applied, and further comprises a timer unit for measuring the time related to the wireless communication test.
5. The wireless communication device according to claim 3, wherein if the wireless communication test is successful within a certain period of time, the OTA unit deletes the test flag stored in the memory unit, and disables the execution of the wireless communication test and the execution of the rollback function according to the value of the test flag.
6. The wireless communication device according to claim 1 or 2, wherein the memory unit comprises a first memory unit and a second memory unit composed of different semiconductor chips, the first firmware is stored in the first memory unit, and the second firmware is stored in the second memory unit.
7. The wireless communication device according to claim 6, wherein if the second memory unit fails while the second firmware is being applied, the OTA unit switches the firmware to be applied to the firmware stored in the first memory unit.
8. The wireless communication device according to claim 3, wherein the OTA unit writes the second firmware to an inactive firmware area in the memory unit if the wireless communication test with the second firmware applied is successful.
9. The wireless communication device according to claim 8, further comprising a redundancy determination unit that performs error detection based on the second firmware stored in a plurality of storage areas of the memory unit.
10. The wireless communication device according to claim 1 or 2, wherein the wireless communication test control unit applies the first firmware and performs the wireless communication test when the first firmware is reapplied.
11. The wireless communication device according to claim 1 or 2, which is a wireless communication device provided by the master device.
12. The wireless communication device according to claim 1 or 2, wherein the slave device is equipped with a wireless communication device, and the second firmware is obtained via the master device.
13. The wireless communication device according to claim 1 or 2, wherein the battery, the master device and the slave device are mounted on a vehicle, and each of the master device and the slave device is implemented by an on-board ECU (Electronic Control Unit).
14. A wireless communication system comprising the master device and the slave device according to claim 1 or 2.
15. A wireless communication method performed by a wireless communication device provided by one of the master device and the slave device in a wireless communication system in which a master device having a battery control circuit for controlling a battery and a slave device having a battery monitoring circuit for monitoring the battery communicate wirelessly, wherein after the firmware to be applied is switched from a first firmware currently being applied to a second firmware obtained by wireless communication, a wireless communication test is performed between the wireless communication device provided by the other of the master device and the slave device, and if the wireless communication test is not passed, the first firmware is reapplied.