OTA update system

WO2026163340A1PCT designated stage Publication Date: 2026-08-06MITSUBISHI ELECTRIC MOBILITY CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
MITSUBISHI ELECTRIC MOBILITY CORP
Filing Date
2025-01-30
Publication Date
2026-08-06

Smart Images

  • Figure JP2025003034_06082026_PF_FP_ABST
    Figure JP2025003034_06082026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is an Over the Air (OTA) update system that can roll back an on-board system to a pre-update state if: an update of a slave processing device includes an update that hinders the interconnection between a master processing device before the update and the slave processing device after the update; the update of the slave processing device succeeds; and the update of the master processing device fails. In a case where the update of the slave processing device succeeds and the update of the master processing device fails, if the update of the slave processing device includes a change that hinders the interconnection between the master processing device before the update and the slave processing device after the update, the OTA update system executes connection software, which is for the master processing device and for restoring the interconnection, to connect to the slave processing device, and returns the slave processing device to the pre-update state.
Need to check novelty before this filing date? Find Prior Art

Description

OTA Update System

[0001] This disclosure relates to an OTA update system.

[0002] Patent Document 1 discloses a system in which, in an OTA (Over The Air) update, when a master processing device connected to each slave processing device via a bus determines a system abnormality, the master processing device causes the slave processing device updated to a new program to execute a rollback using the old program transmitted from the master processing device.

[0003] Japanese Unexamined Patent Application Publication No. 2020-27630

[0004] However, in the technology of Patent Document 1, when the update of the slave processing device includes an update that causes a problem in the interconnection between the master processing device before the update and the slave processing device after the update, and when the update of the slave processing device is successful but the update of the master processing device fails, the master processing device cannot give a rollback command to the slave processing device, and the in-vehicle system cannot be rolled back to the state before the update.

[0005] Therefore, an object of the present disclosure is to provide an OTA update system that can roll back an in-vehicle system to the state before the update when the update of the slave processing device includes an update that causes a problem in the interconnection between the master processing device before the update and the slave processing device after the update, and when the update of the slave processing device is successful but the update of the master processing device fails.

[0006] The first OTA update system according to this disclosure comprises: an OTA server that transmits update data to an in-vehicle system via wireless communication; and an in-vehicle system having a plurality of processing units that update the software of one or more of the processing units to be updated based on the update data received from the OTA server, wherein the in-vehicle system comprises a master processing unit and one or more slave processing units as a plurality of processing units, the master processing unit stores the update data received from the OTA server in a storage device, transmits the update data for the slave processing units included in the update data to the slave processing units, monitors the updates of the slave processing units, and, after the updates of the slave processing units are successful, updates the master processing unit using the update data for the master processing unit included in the update data. If the update of the slave processing unit is successful but the update of the master processing unit fails, and the update of the slave processing unit includes changes that interfere with the interconnection between the master processing unit before the update and the slave processing unit after the update, the connection software for the master processing unit is executed to restore the interconnection and connect to the slave processing unit, thereby returning the slave processing unit to its state before the update.

[0007] The second OTA update system according to this disclosure comprises: an OTA server that transmits update data to an in-vehicle system via wireless communication; and an in-vehicle system having a plurality of processing units that update the software of one or more of the processing units to be updated based on the update data received from the OTA server, wherein the in-vehicle system comprises a master processing unit and one or more slave processing units as a plurality of processing units, the master processing unit stores the update data received from the OTA server in a storage device, transmits the update data for the slave processing units included in the update data to the slave processing units, monitors the updates of the slave processing units, updates the master processing unit using the update data for the master processing unit included in the update data after the updates of the slave processing units are successful, and transmits the update status of the master processing unit and the slave processing units to the OTA server. If the update of the slave processing unit is successful and the update of the master processing unit fails, and the update of the slave processing unit includes changes that interfere with the interconnection between the master processing unit before the update and the slave processing unit after the update, the OTA server will cause the master processing unit to run connection software for the master processing unit to restore the interconnection, connect to the slave processing unit, and return the slave processing unit to its state before the update.

[0008] According to the first OTA update system described in this disclosure, if the update of the slave processing unit includes an update that disrupts the interconnection between the master processing unit before the update and the slave processing unit after the update, and the update of the slave processing unit is successful but the update of the master processing unit fails, the master processing unit can autonomously execute connection software for the master processing unit to restore the interconnection and connect to the slave processing unit, thereby returning the slave processing unit to its state before the update and rolling back the in-vehicle system to its state before the update.

[0009] According to the second OTA update system described in this disclosure, if the update of a slave processing unit includes an update that disrupts the interconnection between the master processing unit before the update and the slave processing unit after the update, and the update of the slave processing unit is successful but the update of the master processing unit fails, the OTA server can cause the master processing unit to run connection software for the master processing unit that restores the interconnection, connect to the slave processing unit, and return the slave processing unit to its state before the update, thereby rolling back the in-vehicle system to its state before the update.

[0010] This is a schematic diagram of the OTA update system according to Embodiment 1. This diagram illustrates the schematic hardware configuration of the OTA server according to Embodiment 1. This diagram illustrates the schematic hardware configuration of the master processing unit according to Embodiment 1. This diagram illustrates the schematic hardware configuration of the slave processing unit according to Embodiment 1. This is a flowchart for explaining the processing of the OTA update system according to Embodiment 1. This diagram illustrates the management data of the master processing unit according to Embodiment 1. This is a flowchart for explaining the processing of the OTA update system according to Embodiment 2. This is a flowchart for explaining the processing of the OTA update system according to Embodiment 3.

[0011] 1. Embodiment 1 The OTA update system 1 according to Embodiment 1 will be described with reference to the drawings. Figure 1 shows a schematic configuration diagram of the OTA update system 1. The OTA update system 1 comprises an OTA server 10 and an in-vehicle system 30. The OTA update system 1 is composed of multiple in-vehicle systems 30 that are the target of service provision by the OTA server 10, but in the embodiment described below, one in-vehicle system 30 will be described as representative.

[0012] The OTA server 10 transmits update data to the in-vehicle system 30 to be updated via wireless communication. The in-vehicle system 30 has multiple processing units 31, and updates the software of the processing units 31 to be updated based on the update data received from the OTA server 10.

[0013] 1-1. OTA Server 10 The OTA server 10 transmits update data to the in-vehicle system via wireless communication. In OTA (Over The Air), the transmission and reception of update data are performed wirelessly. The update data includes software programs.

[0014] As shown in Figure 1, the OTA server 10 includes functional units such as an update management unit 11, an update data storage unit 13, and an update data transmission unit 12. The OTA server 10 is connected to a communication network such as the Internet, to which the in-vehicle system 30 is connected via wireless communication.

[0015] As shown in Figure 2, the OTA server 10 includes a processing unit 70, a storage device 71, and a communication device 72. The processing unit 70 can be a CPU (Central Processing Unit), various ICs (Integrated Circuits), FPGAs (Field Programmable Gate Arrays), GPUs (Graphics Processing Units), or various AI (Artificial Intelligence) chips. The storage device 71 can be a combination of various volatile and non-volatile memories. The communication device 72 is connected to a communication network such as the Internet and communicates with each in-vehicle system 30. Each function of the OTA server 10 is realized through the cooperation of the various hardware components, including the processing unit 70, storage device 71, and communication device 72. Each function is realized when the processing unit 70 executes a program stored in the storage device 71. Various data, such as update data, are stored in the non-volatile storage device 71.

[0016] The update management unit 11 manages multiple in-vehicle systems 30 that are subject to service provision, determines which in-vehicle systems 30 require updating, and transmits update data to the in-vehicle systems 30 via the update data transmission unit 12 (communication device 72).

[0017] The update management unit 11 stores and manages management data such as the types and specifications of the multiple processing units 31 that constitute each in-vehicle system 30, and the update status (version information, etc.) of the software of each processing unit 31 in the storage device 71. When new update data is added, or when an update inquiry is received from an in-vehicle system 30, the update management unit 11 refers to the management data, determines the in-vehicle system 30 to be updated, and determines the content of the update data to be transmitted. The update management unit 11 then reads the determined update data from the update data storage unit 13 (storage device 71) and transmits it to the in-vehicle system 30 to be updated via the update data transmission unit 12 (communication device 72).

[0018] The update data storage unit 13 stores multiple update data corresponding to the type and update status of the in-vehicle system 30. The update data storage unit 13 is composed of a storage device 71. Each update data includes update data such as software (programs) for each processing unit 31 of the in-vehicle system 30. In this embodiment, as will be described later, if the update data for the slave processing unit 50 includes changes that would hinder the interconnection between the master processing unit 40 before the update and the slave processing unit 50 after the update, the update data includes connection software for the master processing unit, which will be described later. The update data transmission unit 12 (communication device 72) transmits the update data, which includes the connection software for the master processing unit, to the in-vehicle system 30.

[0019] 1-2. In-vehicle system 30 The in-vehicle system 30 has a plurality of processing units 31, and updates the software of the processing unit 31 to be updated based on update data received from the OTA server 10.

[0020] As shown in Figure 1, the in-vehicle system 30 comprises a master processing unit 40 and one or more slave processing units 50 as a plurality of processing units 31. The in-vehicle system 30 also includes a wireless communication device 33. The master processing unit 40, each slave processing unit 50, and the wireless communication device 33 are connected via one or more in-vehicle networks 32 and relay devices (e.g., gateway devices) using various communication protocols. Communication protocols such as CAN (Controller Area Network), CAN FD (Flexible Data Rate), UDS (Unified Diagnostic Services), FlexRay, LIN (Local Interconnect Network), and Ethernet can be used. Wireless communication may also be performed using Wi-Fi, BLE (Bluetooth Low Energy), etc.

[0021] The in-vehicle system 30 is equipped with a wireless communication device 33. The wireless communication device 33 communicates wirelessly with a base station using cellular wireless communication standards such as 4G and 5G. The base station is connected to a communication network such as the Internet to which the OTA server 10 is connected. The wireless communication device 33 may also communicate wirelessly with communication spots using Wi-Fi or Bluetooth. The master processing device 40 communicates wirelessly with the OTA server 10 via the wireless communication device 33.

[0022] The master processing unit 40 includes functional units such as an update management unit 41, an update execution unit 42, and an update data storage unit 43. The master processing unit 40 also has functional units that perform processes other than updates, but their description is omitted.

[0023] As shown in Figure 3, the master processing unit 40 includes an arithmetic processing unit 80, a storage device 81, and a communication device 82, etc. In addition to these, the master processing unit 40 may also include various hardware such as input / output devices to realize various functions. Various arithmetic processing units such as a CPU, various ICs, FPGAs, GPUs, and various AI chips can be used as the arithmetic processing unit 80. Various volatile and non-volatile memories can be used as the storage device 81. The communication device 82 is connected to the in-vehicle network 32 and communicates with each slave processing unit 50 and wireless communication device 33, etc. Each function of the master processing unit 40 is realized by the cooperation of each hardware, such as the arithmetic processing unit 80, the storage device 81, and the communication device 82. Each function is realized when the arithmetic processing unit 80 executes a program stored in the storage device 81. Various data are stored in the non-volatile storage device 81.

[0024] The slave processing unit 50 includes functional units such as an update execution unit 51 and an update data storage unit 52. The slave processing unit 50 also has functional units that perform processes other than updates, but their description is omitted.

[0025] As shown in Figure 4, the slave processing unit 50 includes an arithmetic processing unit 90, a storage device 91, and a communication device 92, etc. In addition to these, the slave processing unit 50 may also include various hardware such as input / output devices to realize various functions. Various arithmetic processing units such as a CPU, various ICs, FPGAs, GPUs, and various AI chips can be used as the arithmetic processing unit 90. Various volatile and non-volatile memories can be used as the storage device 91. The communication device 92 is connected to the in-vehicle network 32 and communicates with the master processing unit 40, each slave processing unit 50, and the wireless communication device 33, etc. Each function of the slave processing unit 50 is realized by the cooperation of each hardware, such as the arithmetic processing unit 90, the storage device 91, and the communication device 92. Each function is realized when the arithmetic processing unit 90 executes a program stored in the storage device 91. Various data are stored in the non-volatile storage device 91.

[0026] 1-3. The processing of the OTA update system 1 will be explained with reference to the flowchart in processing diagram 5 of the OTA update system 1. As described above, the explanation will be representative of one of the multiple in-vehicle systems 30 that require updating among the services provided by the OTA server 10.

[0027] In step S01, as described above, the OTA server 10 (update data transmission unit 12) sends update data to the in-vehicle system 30 when it determines that the in-vehicle system 30 needs to be updated. The update data includes update data (in this example, update software (program)) for one or more processing units 31 (master processing unit 40, one or more slave processing units 50) that the in-vehicle system 30 has to be updated.

[0028] This section describes a case where the update data includes update data for the master processing unit 40 and update data for one slave processing unit 50, and the update to the slave processing unit 50 includes changes that would interfere with the interconnection between the master processing unit 40 before the update and the slave processing unit 50 after the update. Therefore, the update data includes connection software for the master processing unit.

[0029] In step S02, the master processing unit 40 (update data storage unit 43) stores the update data received from the OTA server 10 via wireless communication in the storage device 81. The storage device 81 also stores old update data for rollback.

[0030] In step S03, the master processing unit 40 (update management unit 41) transmits the update data for the slave processing unit included in the update data to the slave processing unit 50 and monitors the update of the slave processing unit 50.

[0031] In step S04, the slave processing unit 50 (update data storage unit 52) ​​stores the update data for the slave processing unit received from the master processing unit 40 in the storage device 91. The storage device 91 may also store old update data for rollback and use it during rollback, or the master processing unit 40 may transmit old update data for rollback during rollback. Then, the slave processing unit 50 (update execution unit 51) uses the update data for the slave processing unit stored in the storage device 91 to perform a software update.

[0032] The slave processing unit 50 (update execution unit 51) determines whether the software update was successful or unsuccessful. If the update is unsuccessful, it transmits the failure to the master processing unit 40 (update management unit 41) and proceeds to step S05. If the update is successful, it transmits the success to the master processing unit 40 (update management unit 41) and proceeds to step S07.

[0033] In step S05, the slave processing unit 50 (update execution unit 51) uses the old update data stored in the storage device 91 or the old update data transmitted from the master processing unit 40 to perform a rollback, restoring the software of the slave processing unit 50 to its state before the update. When the rollback is complete, the slave processing unit 50 (update execution unit 51) notifies the master processing unit 40 (update management unit 41) of the completion of the rollback and proceeds to step S06.

[0034] In step S06, the master processing unit 40 (update management unit 41) is unable to update the slave processing unit 50, and therefore cancels the update of the entire in-vehicle system 30, including the master processing unit 40. Subsequently, the master processing unit 40 (update management unit 41) communicates the failure of the in-vehicle system 30 update to the OTA server 10 (update management unit 11). Alternatively, the master processing unit 40 (update management unit 41) may return to step S03 and re-execute the update process a predetermined number of times.

[0035] In step S07, the master processing unit 40 (update execution unit 42) determines that the update of the slave processing unit 50 was successful and updates the software of the master processing unit 40 using the update data for the master processing unit included in the update data. If multiple slave processing units 50 are to be updated, the process in step S07 is performed only if the update of all slave processing units 50 is successful. If the update of one or more slave processing units 50 fails, the process in step S05 is performed, and all slave processing units 50 are rolled back. The master processing unit 40 (update execution unit 42) determines whether the software update was successful or not. If the update failed, it proceeds to step S08. If the update was successful, it communicates the success of the update of the in-vehicle system 30 to the OTA server 10 (update management unit 11).

[0036] In step S08, the master processing unit 40 (update execution unit 42) uses the old update data stored in the storage device 81 to perform a rollback, restoring the software of the master processing unit 40 to its state before the update. If the rollback is completed, the process proceeds to step S09.

[0037] The master processing unit 40 (update management unit 41) stores and manages the respective update status of the master processing unit 40 and the slave processing unit 50 (update failure or success, rollback completion or failure, see Figure 6) in the storage device 81 of the master processing unit 40.

[0038] In step S09, the master processing unit 40 (update management unit 41) determines whether the update of the slave processing unit 50 includes any changes that would hinder the interconnection between the master processing unit 40 before the update and the slave processing unit 50 after the update (hereinafter also referred to as interconnection-hindering changes). If there are no interconnection-hindering changes, the process proceeds to step S10; if there are interconnection-hindering changes, the process proceeds to step S11.

[0039] In step S10, the master processing unit 40 (update management unit 41) instructs the slave processing unit 50 (update execution unit 51) to perform a rollback of the slave processing unit 50. Then, the process proceeds to step S05, where the rollback of the slave processing unit 50 is performed.

[0040] In step S11, the master processing device 40 (update management unit 41) executes connection software for the master processing device to restore the interconnection, connects to the slave processing device 50, and causes the slave processing device 50 to return to the state before the update. The master processing device 40 (update management unit 41) transmits a rollback command to the slave processing device 50.

[0041] After that, the process proceeds to step S05, and the slave processing device 50 (update execution unit 51) uses the old update data stored in the storage device 91 or the old update data transmitted from the master processing device 40 to execute a rollback to return the software of the slave processing device 50 to the state before the update.

[0042] Regarding the rollback of the plurality of slave processing devices 50, if the interconnection failure change is included, the master processing device 40 (update management unit 41) executes connection software for the master processing device to eliminate the interconnection failure between the master processing device 40 before the update and the slave processing device 50 after the update for each of the plurality of slave processing devices 50 and connects to the slave processing device 50.

[0043] In step S05, when the rollback is completed, the slave processing device 50 (update execution unit 51) transmits the completion of the rollback to the master processing device 40 (update management unit 41). The master processing device 40 (update management unit 41) ends the execution of the connection software for the master processing device. In step S06, when the rollback of all the processing devices 31 is completed, the master processing device 40 (update management unit 41) transmits the failure of the update of the in-vehicle system 30 to the OTA server 10 (update management unit 11). Note that the master processing device 40 (update management unit 41) may return to step S03 and re-execute the update process a predetermined number of times.

[0044] <Interconnection Failure Change and Connection Software for Master Processing Device> The interconnection failure change includes one or more of those due to the change of the mutual communication settings and those due to the change of the mutual command exchange content.

[0045] Changes to mutual communication settings may occur when the communication protocol of the slave processing unit 50 is changed due to an update, resulting in a mismatch between the communication protocol of the master processing unit 40 and the communication protocol of the slave processing unit 50. For example, if the communication protocol of the slave processing unit 50 is changed from CAN to CAN FD, and the communication protocol of the master processing unit 40 remains CAN, this can cause problems with interconnection and prevent the slave processing unit 50 from being rolled back.

[0046] In this case, the connection software for the master processing unit is software that converts or changes the communication protocol of the master processing unit 40 to the same communication protocol as the slave processing unit 50, so that the master processing unit 40 can communicate with the slave processing unit 50 using the same communication protocol as the slave processing unit 50.

[0047] Alternatively, changes to the mutual communication settings may result in an update that alters the communication data ID of the slave processing unit 50, causing the communication data ID of the master processing unit 40 and the communication data ID of the slave processing unit 50 to no longer correspond. For example, the SID (Service Identifier) ​​of the UDS (Unified Diagnostic Services), which is the communication protocol of the slave processing unit 50, may change, causing it to no longer correspond to the SID of the UDS of the master processing unit 40 in its pre-update state, thus hindering interconnection. The SID is a code used to identify a specific diagnostic service and is used as part of the UDS message. Each SID indicates a specific diagnostic function or operation, such as reading or clearing error codes or reprogramming the processing unit 31. For example, if the SIDs for reprogramming no longer correspond to each other, the slave processing unit 50 will no longer be able to perform a rollback.

[0048] In this case, the connection software for the master processing device is software that converts or changes the communication data ID of the master processing device 40 to the same communication data ID as that of the slave processing device 50. The master processing device 40 can communicate the information of the communication data ID using the same communication data ID as that of the slave processing device 50. For example, the master processing device 40 transmits a reprogramming (rollback) command to the slave processing device 50 using the same reprogramming SID as that of the slave processing device 50.

[0049] Alternatively, when changing the mutual communication settings, there may be a case where the network settings of the slave processing device 50 are changed by an update, and the network settings of the master processing device 40 and the network settings of the slave processing device 50 do not match. For example, the setting of the VLAN (Virtual Local Area Network) of Ethernet, which is the communication protocol of the slave processing device 50, is changed and does not match the setting of the VLAN of Ethernet of the master processing device 40 in the state before the update, causing an obstacle to the interconnection and making it impossible to perform a rollback of the slave processing device 50.

[0050] In this case, the connection software for the master processing device is software that changes the network settings of the master processing device 40 to the same network settings as those of the slave processing device 50. The master processing device 40 can communicate with the slave processing device 50 using the same network settings as those of the slave processing device 50. For example, the master processing device 40 can communicate with the slave processing device 50 using the same VLAN setting of Ethernet as that of the slave processing device 50.

[0051] Changes in the mutual command exchange content can occur when the command exchange content of the slave processing unit 50 changes due to an update, causing the command exchange content of the master processing unit 40 and the slave processing unit 50 to no longer match. For example, if the slave processing unit 50 was set to start automatically before the update, but after the update the slave processing unit 50 is set to start only when a start command is received from the master processing unit 40, the start command will not be transmitted from the master processing unit 40 in its pre-update state, resulting in the slave processing unit 50 not starting and making it impossible to roll back the slave processing unit 50.

[0052] In this case, the connection software for the master processing unit is software that changes the content of the commands exchanged between the master processing unit 40 and the slave processing unit 50 to be the same as the content of the commands exchanged between the master processing unit 40 and the slave processing unit 50, so that the master processing unit 40 can communicate with the slave processing unit 50 using the same content of commands exchanged between the master processing unit 40 and the slave processing unit 50. For example, the master processing unit 40 transmits a start command to the slave processing unit 50, starts the slave processing unit 50, and becomes able to communicate with the slave processing unit 50.

[0053] 2. Embodiment 2 Next, the OTA update system 1 according to Embodiment 2 will be described. The same components as in Embodiment 1 will not be described. The basic configuration of the OTA update system 1 according to this embodiment is the same as in Embodiment 1, but it differs from Embodiment 1 in that the OTA server 10 (update management unit 11) manages the execution of the connection software for the master processing unit.

[0054] Referring to the flowchart in Figure 7, the processing of the OTA update system 1 according to Embodiment 2 will be explained. As described above, we will explain in representative terms one of the multiple in-vehicle systems 30 that require updating among the multiple in-vehicle systems 30 that are the target of the OTA server 10's service provision.

[0055] Steps S22 to S27 are the same as steps S02 to S07 of Embodiment 1, so their explanation will be omitted.

[0056] Similar to Embodiment 1, in step S21, if the OTA server 10 (update data transmission unit 12) determines that the in-vehicle system 30 needs to be updated, it transmits update data to the in-vehicle system 30.

[0057] In this embodiment, the update data includes update data for the master processing unit 40 and update data for one slave processing unit 50, but does not include connection software for the master processing unit.

[0058] In step S28, the master processing unit 40 (update execution unit 42) uses the old update data stored in the storage device 81 to perform a rollback, restoring the software of the master processing unit 40 to its state before the update. When the rollback of the master processing unit 40 is complete, the master processing unit 40 (update management unit 41) notifies the OTA server 10 (update management unit 11) of the completion of the rollback of the master processing unit 40, and proceeds to step S29.

[0059] The master processing unit 40 (update management unit 41) stores and manages the respective update statuses of the master processing unit 40 and the slave processing unit 50 (update failure or success, rollback completion or failure, see Figure 6) in the storage device 81 of the master processing unit 40. The master processing unit 40 (update management unit 41) sequentially transmits the respective update statuses of the master processing unit 40 and the slave processing unit 50 to the OTA server 10 (update management unit 11). The OTA server 10 (update management unit 11) may sequentially read the respective update statuses of the master processing unit 40 and the slave processing unit 50 from the storage device 81 of the master processing unit 40.

[0060] In step S29, the OTA server 10 (update management unit 11) determines whether the update of the slave processing unit 50 was successful and the update of the master processing unit 40 failed, and whether the update of the slave processing unit 50 includes any changes that would hinder the interconnection between the master processing unit 40 before the update and the slave processing unit 50 after the update (interconnection-hindering changes). If there are no interconnection-hindering changes, the process proceeds to step S30; if there are interconnection-hindering changes, the process proceeds to step S31.

[0061] In step S30, the OTA server 10 (update management unit 11) instructs the slave processing unit 50 (update execution unit 51) to perform a rollback of the slave processing unit 50 via the master processing unit 40 (update management unit 41). Then, the process proceeds to step S25, where the rollback of the slave processing unit 50 is executed.

[0062] In step S31, the OTA server 10 (update management unit 11 and update data transmission unit 12) reads the update status and update data for the master processing unit corresponding to the master processing unit 40 and the slave processing unit 50 from the storage device 71 and transmits it to the master processing unit 40. That is, the OTA server 10 transmits the connection software for the master processing unit to the master processing unit 40 when it is needed. The OTA server 10 (update management unit 11) causes the master processing unit 40 (update management unit 41) to execute the connection software for the master processing unit, connect to the slave processing unit 50, and return the slave processing unit 50 to its state before the update. The OTA server 10 (update management unit 11) transmits a rollback command to the slave processing unit 50 via the master processing unit 40 (update management unit 41).

[0063] Subsequently, the process proceeds to step S25, where the slave processing unit 50 (update execution unit 51) uses the old update data stored in the storage device 91 to perform a rollback, restoring the software of the slave processing unit 50 to its state before the update.

[0064] Furthermore, if the rollback of multiple slave processing units 50 involves changes that disrupt interconnection, the OTA server 10 reads connection software for the master processing unit from the storage device 71 to resolve the interconnection issues between the master processing unit 40 before the update and the slave processing unit 50 after the update, sends it to the master processing unit 40, and has it execute it.

[0065] In step S25, the slave processing unit 50 (update execution unit 51) communicates the completion of the rollback to the master processing unit 40 (update management unit 41) when the rollback is complete. The master processing unit 40 (update management unit 41) terminates the execution of the connection software for the master processing unit. In step S26, the master processing unit 40 (update management unit 41) communicates the failure of the update of the in-vehicle system 30 to the OTA server 10 (update management unit 11) when the rollback of all processing units 31 is complete. The master processing unit 40 (update management unit 41) may return to step S23 and re-execute the update process a predetermined number of times.

[0066] 3. Embodiment 3 Next, the OTA update system 1 according to Embodiment 3 will be described. The same components as in Embodiment 1 will not be described. The basic configuration of the OTA update system 1 according to this embodiment is the same as in Embodiment 1, but it differs from Embodiment 1 in that the master processing unit 40 (update management unit 41) reads the connection software for the master processing unit from the storage device 71 of the OTA server 10 when necessary.

[0067] Referring to the flowchart in Figure 8, the processing of the OTA update system 1 according to Embodiment 2 will be explained. As described above, we will explain in representative terms one of the multiple in-vehicle systems 30 that require updating among the multiple in-vehicle systems 30 that are the target of the OTA server 10's service provision.

[0068] Steps S42 to S47 are the same as steps S02 to S07 of Embodiment 1, so their explanation will be omitted.

[0069] Similar to Embodiment 1, in step S41, if the OTA server 10 (update data transmission unit 12) determines that the in-vehicle system 30 needs to be updated, it transmits update data to the in-vehicle system 30.

[0070] In this embodiment, the update data includes update data for the master processing unit 40 and update data for one slave processing unit 50, but does not include connection software for the master processing unit.

[0071] In step S48, the master processing unit 40 (update execution unit 42) uses the old update data stored in the storage device 81 to perform a rollback, restoring the software of the master processing unit 40 to its state before the update. If the rollback is completed, the process proceeds to step S49.

[0072] The master processing unit 40 (update management unit 41) stores and manages the respective update status of the master processing unit 40 and the slave processing unit 50 (update failure or success, rollback completion or failure, see Figure 6) in the storage device 81 of the master processing unit 40.

[0073] In step S49, the master processing unit 40 (update management unit 41) determines whether the update of the slave processing unit 50 includes changes that would hinder the interconnection between the master processing unit 40 before the update and the slave processing unit 50 after the update (interconnection-hindering changes). If there are no interconnection-hindering changes, the process proceeds to step S50; if there are interconnection-hindering changes, the process proceeds to step S51.

[0074] In step S50, the master processing unit 40 (update management unit 41) instructs the slave processing unit 50 (update execution unit 51) to perform a rollback of the slave processing unit 50. Then, the process proceeds to step S45, where the rollback of the slave processing unit 50 is performed.

[0075] In step S51, the master processing unit 40 (update management unit 41) reads (downloads) the connection software for the master processing unit corresponding to the update status and update data of the master processing unit 40 and the slave processing unit 50 from the storage device 71 of the OTA server 10. That is, the master processing unit 40 (update management unit 41) reads the connection software for the master processing unit from the storage device 71 of the OTA server 10 when it is needed. The master processing unit 40 (update management unit 41) executes the read master processing unit connection software to connect to the slave processing unit 50 and causes the slave processing unit 50 to return to its state before the update. The master processing unit 40 (update management unit 41) transmits a rollback command to the slave processing unit 50.

[0076] Subsequently, the process proceeds to step S45, where the slave processing unit 50 (update execution unit 51) uses the old update data stored in the storage device 91 or the old update data transmitted from the master processing unit 40 to perform a rollback, restoring the software of the slave processing unit 50 to its state before the update.

[0077] Furthermore, if the rollback of multiple slave processing units 50 involves changes that cause interconnection problems, the master processing unit 40 (update management unit 41) reads connection software for the master processing unit from the storage device 71 of the OTA server 10 and executes it for each of the multiple slave processing units 50 to resolve the interconnection problems between the master processing unit 40 before the update and the slave processing unit 50 after the update.

[0078] In step S45, the slave processing unit 50 (update execution unit 51) communicates the completion of the rollback to the master processing unit 40 (update management unit 41) when the rollback is complete. The master processing unit 40 (update management unit 41) terminates the execution of the connection software for the master processing unit. In step S46, the master processing unit 40 (update management unit 41) communicates the failure of the update of the in-vehicle system 30 to the OTA server 10 (update management unit 11) when the rollback of all processing units 31 is complete. Alternatively, the master processing unit 40 (update management unit 41) may return to step S43 and re-execute the update process a predetermined number of times.

[0079] While this disclosure describes various exemplary embodiments and examples, the various features, aspects, and functions described in one or more embodiments are not limited to the application of a particular embodiment, but are applicable individually or in various combinations to the embodiments. Accordingly, countless variations not illustrated herein are conceivable within the scope of the art disclosed herein. For example, these include modifying, adding or omitting at least one component, or extracting at least one component and combining it with a component from another embodiment.

[0080] 1: OTA update system, 10: OTA server, 40: master processing unit, 50: slave processing unit

Claims

1. An OTA update system comprising: an OTA server that transmits update data to an in-vehicle system via wireless communication; and an in-vehicle system having a plurality of processing units, which updates the software of one or more of the processing units to be updated based on the update data received from the OTA server, wherein the in-vehicle system comprises a master processing unit and one or more slave processing units as a plurality of processing units, the master processing unit stores the update data received from the OTA server in a storage device, transmits the update data for the slave processing units included in the update data to the slave processing units, monitors the updates of the slave processing units, and, after the updates of the slave processing units are successful, updates the master processing unit using the update data for the master processing unit included in the update data. An OTA update system that, in the event that the update of the slave processing unit is successful and the update of the master processing unit fails, and the update of the slave processing unit includes changes that interfere with the interconnection between the master processing unit before the update and the slave processing unit after the update, executes connection software for the master processing unit to restore the interconnection, connects to the slave processing unit, and returns the slave processing unit to its state before the update.

2. An OTA update system comprising: an OTA server that transmits update data to an in-vehicle system via wireless communication; and an in-vehicle system having a plurality of processing units, which updates the software of one or more of the processing units to be updated based on the update data received from the OTA server, wherein the in-vehicle system comprises a master processing unit and one or more slave processing units as a plurality of processing units, the master processing unit stores the update data received from the OTA server in a storage device, transmits the update data for the slave processing units included in the update data to the slave processing units, monitors the updates of the slave processing units, updates the master processing unit using the update data for the master processing unit included in the update data after the updates of the slave processing units are successful, and transmits the update status of the master processing unit and the slave processing units to the OTA server. The OTA server is an OTA update system that, in the event that the update of the slave processing unit is successful and the update of the master processing unit fails, and the update of the slave processing unit includes changes that interfere with the interconnection between the master processing unit before the update and the slave processing unit after the update, causes the master processing unit to run connection software for the master processing unit that restores the interconnection, connects to the slave processing unit, and returns the slave processing unit to its state before the update.

3. The OTA update system according to claim 1, wherein the OTA server transmits the update data which includes connection software for the master processing unit, or the master processing unit reads the connection software for the master processing unit from the OTA server when the master processing unit requires it.

4. The OTA update system according to claim 2, wherein the OTA server transmits connection software for the master processing device to the master processing device when connection software for the master processing device is required.

5. The OTA update system according to any one of claims 1 to 4, wherein the changes that impede the interconnection include one or more of the changes caused by changes in the mutual communication settings and the changes caused by changes in the mutual command exchange content.