Vehicle system and software update method for entry control device
Patent Information
- Application Number
- PCT/JP2025/012956
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2026-10-01
Smart Images

Figure JP2025012956_01102026_PF_FP_ABST
Abstract
Description
Vehicle System and Software Update Method for Entry Control Device
[0001] The present invention relates to a vehicle system and a software update method for an entry control device.
[0002] In recent years, efforts have been activated to provide access to sustainable transport systems that also take into account vulnerable people such as the elderly, people with disabilities, and children among road users. To achieve this goal, research and development are being focused on further improving traffic safety and convenience through development related to the getting on and off performance of vehicles.
[0003] Patent Document 1 discloses a technique in which when a moving object around a vehicle is detected in an image captured in a low-resolution mode by an on-vehicle imaging device operating in a low-resolution mode and a high-resolution mode, a face image of the moving object is acquired in the high-resolution mode and authentication processing is performed. Patent Document 2 discloses a technique in which OTA (Over The Air) software update processing for an on-vehicle device using an update program received via wireless communication from outside the vehicle is performed in a parking lot based on permission of a vehicle user.
[0004] International Publication No. 2019 / 003826 Japanese Unexamined Patent Publication No. 2021-149701
[0005] By the way, regarding the getting on and off performance of vehicles, while ensuring improvement of getting on and off performance through software update of an entry control device that automatically performs locking and unlocking of vehicle doors, it is a problem to prevent the security of the vehicle from being lowered due to the inability to automatically lock the vehicle door during execution of the software update.
[0006] In order to solve the above problem, the present application aims to prevent the security of the vehicle from being lowered due to the inability to automatically lock the vehicle door during execution of software update of an entry control device that automatically performs locking and unlocking of vehicle doors. Furthermore, it contributes to the development of sustainable transport systems.
[0007] One aspect of the present invention is a vehicle system comprising: an entry control device that automatically locks and unlocks vehicle doors; an update management unit that receives update data provided wirelessly from outside the vehicle and instructs an electronic control device in the vehicle to perform a software update using the update data; and a detection unit that detects a person or animal inside the vehicle using a sensor provided inside the vehicle's interior, wherein the update management unit locks the vehicle doors when no person or animal is detected inside the vehicle's interior, and then instructs the entry control device to perform a software update using the update data. Another aspect of the present invention is a software update method for an entry control device, which automatically locks and unlocks the doors of a vehicle, by updating the software of the entry control device using update data provided wirelessly from outside the vehicle, the method comprising: a detection step in which a computer detects the presence or absence of a person or animal inside the vehicle using a sensor provided inside the vehicle; and an update instruction step in which, when no person or animal is detected inside the vehicle, the computer locks the doors of the vehicle and then instructs the entry control device to perform a software update using the update data.
[0008] According to the present invention, since the entry control device, which automatically locks and unlocks the vehicle doors when a person or animal is detected inside the vehicle, performs a software update, the security of the vehicle can be maintained at a high level while the update is being performed.
[0009] Figure 1 is a diagram showing an example of the configuration of a vehicle equipped with a vehicle system according to one embodiment of the present invention. Figure 2 is a diagram showing the overall configuration of the vehicle system. Figure 3 is a diagram illustrating the detection operation of a person approaching the vehicle. Figure 4 is a flowchart showing the operation procedure in the vehicle system. Figure 5 is a flowchart showing the operation procedure in the vehicle system.
[0010] Embodiments of the present invention will be described below with reference to the drawings. [1. Overall configuration of the vehicle system] Figure 1 is a diagram showing the configuration of a vehicle 2 on which the vehicle system 1 of this embodiment is installed. Figure 2 is a diagram showing the overall configuration of the vehicle system 1.
[0011] The vehicle system 1 includes an entry control device 3 and an update management device 4 mounted on the vehicle 2. The entry control device 3 automatically locks and unlocks the vehicle doors of the vehicle 2. The update management device 4 receives update data provided wirelessly from outside the vehicle 2 and manages the execution of over-the-air (OTA) software updates using the update data for the on-board electronic control devices, including the entry control device 3.
[0012] The vehicle system 1 may include, in addition to the entry control device 3 and the update management device 4, all or part of the other devices and equipment shown in Figure 2.
[0013] In this embodiment, vehicle 2 is, for example, an electric vehicle, and it moves by operating a drive unit 14, which is a motor, using a battery 13 provided in vehicle 2. Vehicle 2 may also be, for example, a shared car that can be used by multiple people in turns.
[0014] Vehicle 2 is equipped with a communication device 12. The communication device 12 is equipped with a transceiver for short-range communication such as Bluetooth® with an electronic key 5 used to use vehicle 2. The electronic key 5 may be, for example, a smart key such as an FOB key, or a mobile terminal 5a such as a smartphone of the subject P (or user) on which key information used to use vehicle 2 is stored. Here, the electronic key 5 corresponds to the vehicle key in this disclosure.
[0015] The communication device 12 also includes transceivers for communicating with external devices via an external communication network NW of the vehicle 2. The external devices include a mobile terminal 5a and an OTA server 22.
[0016] The OTA server 22 manages software updates for the on-board electronic control units of multiple pre-registered vehicles. New update data is registered to the OTA server 22 from the manufacturer of each vehicle. If new update data for updating the software of the electronic control unit installed in vehicle 2 is registered, the OTA server 22 sends the update data to vehicle 2 upon request from vehicle 2.
[0017] Vehicle 2 includes an object sensor 7 that detects objects around Vehicle 2, and a first camera 8 and a second camera 9 that capture images of the area around Vehicle 2.
[0018] The object sensor 7 is, for example, a distance measuring sensor capable of detecting surrounding objects and measuring the distance to those objects, and in this embodiment, it is a millimeter-wave radar. The object sensor 7 is not limited to radar; it can be any distance measuring sensor capable of object detection and distance measurement. Such sensors may include, for example, LiDAR or sonar, in addition to radar.
[0019] The first camera 8 and the second camera 9 are, for example, composed of CCD (Charge Coupled Device) cameras with different pixel counts. The second camera 9 has a higher resolution and consumes more power than the first camera 8.
[0020] In this embodiment, the vehicle 2 is equipped with an object sensor 7, a first camera 8, and a second camera 9. The right side of the vehicle 2 is equipped with an object sensor 7a that detects objects located to the right of the vehicle 2, and a first camera 8a and a second camera 9a that photograph the right side of the vehicle 2. The left side of the vehicle 2 is equipped with an object sensor 7b that detects objects located to the left of the vehicle 2, and a first camera 8b and a second camera 9b that photograph the left side of the vehicle 2. The rear of the vehicle 2 is equipped with an object sensor 7c that detects objects located behind the vehicle 2, and a first camera 8c and a second camera 9c that photograph the rear of the vehicle 2.
[0021] In Figure 2, to avoid diagrammatic complexity and facilitate understanding, the object sensor 7 is represented by a single rectangle. However, please understand that the object sensor 7 shown in Figure 2 includes the object sensors 7a, 7b, and 7c shown in Figure 1. Similarly, please understand that the first camera 8 shown in Figure 2 includes the first cameras 8a, 8b, and 8c shown in Figure 1, and the second camera 9 shown in Figure 2 includes the second cameras 9a, 9b, and 9c shown in Figure 1.
[0022] Vehicle 2 also includes an external control device 10 for an external person to instruct vehicle 2 to lock or unlock the vehicle door 6, and a door control device 11 for locking and unlocking the door lock of the vehicle door 6. The external control device 10 may be a touch sensor and / or touch switch provided on the door handle of the vehicle door 6 or on the pillar surrounding the vehicle door 6.
[0023] The door control device 11 controls the actuator that locks and unlocks the door lock of the vehicle door 6 and the actuator that opens and closes the vehicle door 6, thereby automatically operating the locking, unlocking, and opening / closing operations of the vehicle door 6. The door control device 11 controls the locking, unlocking, and opening / closing operations of the vehicle door 6 based on instructions from the entry control device 3 and the update management device 4, which will be described later.
[0024] Furthermore, the door control device 11 has the function of locking and unlocking the vehicle doors 6 in response to instructions transmitted wirelessly from the electronic key 5 of the vehicle 2. When the door control device 11 receives an operation request for the vehicle doors 6 from the electronic key 5 via the communication device 12, it executes the operation specified in the operation request. For example, when the door control device 11 receives an unlocking request or a locking request for the vehicle doors 6 from the electronic key 5, it unlocks or locks the vehicle doors 6 specified in those requests. Also, when the door control device 11 receives an opening operation request or a closing operation request for the vehicle doors 6 from the electronic key 5, it automatically opens or closes the vehicle doors 6 specified in those requests.
[0025] In this embodiment, the vehicle 2 includes external operating devices 10 and door control devices 11 provided on the vehicle doors 6: an external operating device 10a and door control device 11a provided on the driver's side door 6a on the right front of the vehicle 2, and an external operating device 10b and door control device 11b provided on the right rear passenger door 6b on the right rear of the vehicle 2. The vehicle 2 also includes an external operating device 10c and door control device 11c provided on the passenger side door 6c on the left front of the vehicle 2, and an external operating device 10d and door control device 11d provided on the left rear passenger door 6d on the left rear of the vehicle 2. The vehicle 2 further includes an external operating device 10e and door control device 11e provided on the back door (tailgate door) 6e of the vehicle 2.
[0026] In Figure 2, to avoid complexity in the illustration and to facilitate understanding, the vehicle door 6, external control unit 10, and door control device 11 are each represented by a single rectangle. The vehicle door 6 shown in Figure 2 should be understood to include the driver's side door 6a, the right rear passenger door 6b, the passenger side door 6c, the left rear passenger door 6d, and the back door 6e. Furthermore, the external control unit 10 and door control device 11 shown in Figure 2 should be understood to represent the external control units 10a, 10b, 10c, 10d, and 10e, and the door control devices 11a, 11b, 11c, 11d, and 11e, respectively.
[0027] Vehicle 2 also includes a drive control device 15 that controls the operation of the drive unit 14, and a power control device 16 that controls the supply of power to electrical equipment such as an air conditioner and audio equipment (not shown) mounted on vehicle 2.
[0028] Vehicle 2 is equipped with a start switch 17. The start switch 17 instructs the drive control device 15 and the power control device 16 to start operation. For example, if a user of vehicle 2 presses the start switch 17 while pressing the accelerator pedal (not shown), the start switch 17 instructs the power control device 16 and the drive control device 15 to start operation. Also, if the start switch 17 is pressed without pressing the accelerator pedal, the start switch 17 instructs the power control device 16 to start operation without instructing the drive control device 15 to start operation. Furthermore, if the start switch 17 is pressed after the power control device 16 and the drive control device 15 have started operation, they will stop their respective operations.
[0029] When the drive control device 15 is given an instruction to start operation by the start switch 17, it performs preparatory operations for operating the drive unit 14. These preparatory operations may include, for example, checking and initializing the status of the inverter (not shown), battery 13, and drive unit 14 provided in the drive control device 15, as well as starting the cooling system (not shown) for the drive unit 14 and the inverter, in accordance with the prior art. After the preparatory operations are completed, the drive control device 15 controls the operation of the drive unit 14 to drive the vehicle 2 in accordance with driving operations performed by a control device such as an accelerator pedal (not shown), in accordance with the prior art.
[0030] Vehicle 2 may be equipped with an interior camera 18 for imaging the interior of the vehicle. The interior camera 18 may be positioned at the front of the vehicle interior and may capture images of the interior, including the face of the driver seated in the cockpit of vehicle 2.
[0031] Vehicle 2 is equipped with a cabin sensor 19 that detects people and animals inside the vehicle. The cabin sensor 19 may be, for example, a human presence sensor, an interior radar, an ultrasonic sensor, or a combination of several of these sensors installed on the ceiling of the vehicle. Alternatively, an interior camera 18 may be used as the cabin sensor 19.
[0032] Vehicle 2 is equipped with a display device 20 located in the center of an instrument panel (not shown) inside the passenger compartment. The display device 20 is a touch panel that provides various information and functions, such as a route guidance map and an audio settings screen.
[0033] The devices shown in Figure 2 are connected to each other via an in-vehicle communication cable 21, enabling them to communicate with one another. For example, these devices can communicate via the communication cable 21 using CAN communication standards or Ethernet® communication.
[0034] The entry control device 3 authenticates the subject P, who is any person attempting to enter vehicle 2. If authentication is successful, it automatically unlocks the vehicle door 6, allowing subject P to use vehicle 2.
[0035] The update management device 4 receives update data from the OTA server 22 via wireless communication through the communication network NW, and instructs the electronic control unit installed in the vehicle 2 to perform a software update using the update data. The electronic control unit includes the entry control unit 3.
[0036] Software updates for electronic control devices using update data are performed according to prior art, for example, as follows. In the following description, it is assumed that the electronic control device of vehicle 2 not only stores the current software in memory, but also has an area in that memory for storing the new version of the software provided by the update management device 4.
[0037] First, the update management device 4 downloads update data from the OTA server 22. At predetermined timings, such as when the vehicle 2's start switch 17 is turned on, the update management device 4 queries the OTA server 22 to see if new update data has been registered for any of the vehicle 2's electronic control devices. The OTA server 22 replies to the update management device 4 with information on whether or not there is update data for the vehicle 2's electronic control devices.
[0038] When the update management device 4 receives the above reply from the OTA server 22 indicating that new update data is available, it requests the OTA server 22 to send the update data. In response, the OTA server 22 sends the update data to the vehicle 2. The update data may include information about which electronic control device the update data pertains to. The update management device 4 receives the update data sent from the OTA server 22 and downloads it to the second memory 41 provided in the update management device 4.
[0039] Next, the update management device 4 installs the new software included in the update data downloaded from the OTA server 22 into the corresponding electronic control unit. That is, the update management device 4 obtains the new software from the update data and transmits the obtained new software to the corresponding electronic control unit. The electronic control unit saves the new software in its memory according to the installation instructions from the update management device 4. Note that the above download and installation can also be performed while the vehicle 2 is in motion.
[0040] Next, when the start switch 17 of the vehicle 2 is turned off, the update management device 4 inquires with the user of the vehicle 2 whether or not to perform a software update of the electronic control unit. This inquiry may be transmitted to the display device 20 installed in the vehicle 2 or to the user's mobile terminal 5a.
[0041] When the user responds to the above inquiry with permission to perform the software update, the update management device 4 sends an activation instruction to the electronic control unit on which the new software is installed, instructing it to switch from the current software to the new software. Upon receiving the activation instruction, the electronic control unit executes the new software installed in its memory, performs initial setup and checks such as self-diagnosis, and then automatically performs a hardware reset. As a result, the software update of the electronic control unit is completed, and the next time the start switch 17 is turned on, the electronic control unit will operate with the new software as the current software.
[0042] Furthermore, if the electronic control unit does not have sufficient storage capacity to store the new software in addition to the currently used software, the update management device 4 may make the above inquiry to the user before the installation, and perform the installation on the electronic control unit only after receiving a response granting permission to run the software. The electronic control unit may then run the new software after the installation to perform a software update.
[0043] In this embodiment, in particular, when the update management device 4 is ready to update the software of the entry control device 3, it determines whether or not there is a person or animal inside the vehicle compartment, and, on the condition that there is no person or animal inside the vehicle compartment, it instructs the door control device 11 to automatically lock the vehicle door 6, and then gives the entry control device 3 an instruction to execute the software update (for example, an actuation instruction).
[0044] Accordingly, in the vehicle system 1, software updating of the entry control device 3 that automatically performs locking and unlocking of the vehicle doors 6 is performed by automatically locking the vehicle doors 6 in advance when no person or animal is detected in the vehicle interior. Therefore, during execution of the software updating of the entry control device 3, access to the vehicle interior from outside the vehicle by a person who is not a user of the vehicle 2 is suppressed. Further, since there is no person in the vehicle interior, an occupant does not manually unlock the lock of the vehicle door 6 from inside the vehicle interior. Therefore, in the vehicle system 1, the security of the vehicle 2 is maintained in a high state during execution of the software updating of the entry control device 3.
[0045] Hereinafter, the configurations of the entry control device 3 and the update management device 4, and the operation of the vehicle system 1 will be described. In the following description, software update refers to software updating using update data received from the OTA server 22, unless otherwise specified.
[0046] [2. Configuration of Entry Control Device] The configuration of the entry control device 3 will be described. The entry control device 3 automatically performs locking and unlocking of the vehicle doors 6. In the present embodiment, the entry control device 3 authenticates a subject P who is a person attempting to enter the vehicle 2, and when authentication is successful, automatically unlocks the door lock of the vehicle door 6, allowing the subject P to use the vehicle 2. The authentication is performed, for example, by collating a face image acquired for the subject P with a face image of a registered user pre-stored as authentication data in a storage device.
[0047] In the following description, "subject" refers to a person targeted for authentication by the entry control device 3. Further, "user" refers to a person who is a registered user pre-registered as a person having legitimate authority to use the vehicle 2, and who actually uses the vehicle 2. The subject P becomes a user when authenticated by the entry control device 3 and becomes allowed to use the vehicle 2.
[0048] The entry control device 3 is a computer including a first processor 30 and a first memory 31. The first memory 31 is constituted of, for example, a volatile and / or non-volatile semiconductor memory or the like. The first memory 31 stores authentication data 32 including face images of each of one or more registered users who are registered in advance as persons having legitimate authority to use the vehicle 2. The first memory 31 also stores active software 33 currently executed by the first processor 30, and update control software 34. In the present embodiment, the first memory 31 is further assumed to have a storage capacity capable of storing new version software received from the update management unit 44.
[0049] The first processor 30 is, for example, an arithmetic processing device such as a CPU. The first processor 30 may have a configuration including a ROM in which programs are written, a RAM for temporary storage of data, and the like. The first processor 30 includes, as functional elements or functional units, an approach detection unit 35, a detail acquisition unit 36, an intention determination unit 37, an authentication unit 38, and a door control unit 39.
[0050] These functional elements included in the first processor 30 are realized, for example, when the first processor 30 executes the active software 33 stored in the first memory 31.
[0051] The approach detection unit 35 uses the object sensor 7 and the first camera 8 to detect a target person P approaching the vehicle 2. The approach detection unit 35 operates, for example, as shown in FIG. 3. FIG. 3 is an explanatory diagram for explaining the operation of the approach detection unit 35. First, the approach detection unit 35 uses the object sensor 7 to determine whether an actual object has entered the detection range of the object sensor 7 (in FIG. 3, as an example, the range of a distance D1 from the vehicle 2). The actual object can be any object including living things and inanimate objects. When an actual object enters the detection range of the object sensor 7, the approach detection unit 35 activates the first camera 8 close to the object sensor 7 that has detected the actual object.
[0052] The proximity detection unit 35 continuously acquires first images of the area around the vehicle 2 at predetermined time intervals using the activated first camera 8. The proximity detection unit 35 performs image recognition processing on the first images captured by the first camera 8 to determine whether the object is a person or not. If the object is a person, the proximity detection unit 35 determines from the first images continuously captured by the first camera 8 whether that person is approaching the vehicle 2. If the person is approaching the vehicle 2, the proximity detection unit 35 determines that the person is the subject P. As a result, the system detects the subject P approaching the vehicle 2. When the proximity detection unit 35 detects the subject P, it notifies the detailed acquisition unit 36 of this fact. In Figure 3, as an example, by the time the proximity detection unit 35 determines that the object detected by the object sensor 7 is a person approaching the vehicle 2, the person has reached a position at a distance D2 from the vehicle 2. This distance D2 is determined, for example, by the speed at which a person approaches vehicle 2 and the time required for the proximity detection unit 35 to recognize the person and the direction of movement.
[0053] The detail acquisition unit 36 acquires a second image, which is an image of the subject P approaching the vehicle 2. The detail acquisition unit 36 also extracts and acquires the face image of the subject P from the second image each time it takes a second image of the subject P.
[0054] Specifically, when the proximity detection unit 35 detects a subject P, the detail acquisition unit 36 activates the second camera 9, which is closest to the first camera 8 used to detect the subject P. As mentioned above, the second camera 9 has a higher resolution and consumes more power than the first camera 8.
[0055] The detailed image acquisition unit 36 uses the activated second camera 9 to continuously capture high-definition second images of the subject P at predetermined time intervals. Each time the detailed image acquisition unit 36 captures a second image of the subject P, it extracts the subject P's face image from the second image and acquires multiple face images of the subject P captured at predetermined time intervals. Each time the detailed image acquisition unit 36 captures a second image of the subject P, it sends the captured image of the subject P and the extracted face image to the intent determination unit 37 and the authentication unit 38.
[0056] The intention determination unit 37 determines whether or not the subject P intends to board the vehicle 2 based on the movement of the subject P recognized from a plurality of second images captured at predetermined time intervals. For example, the intention determination unit 37 may determine that the subject P intends to board the vehicle 2 when the subject P is approaching one of the vehicle doors 6 of the vehicle 2, when the subject P is standing in front of one of the vehicle doors 6 of the vehicle 2, or when the subject P is reaching for the door handle of one of the vehicle doors 6. In Figure 3, as an example, by the time the intention determination unit 37 determines the subject P's intention to board, the subject P has moved to a position at a distance D3 from the vehicle 2. This distance D3 is determined by the subject P's speed and the time it takes for the intention determination unit 37 to process the determination. The intention determination unit 37 notifies the authentication unit 38 of the result of the determination regarding whether or not the subject P intends to board the vehicle 2.
[0057] The authentication unit 38 authenticates that the subject P is a registered user with the right to use the vehicle 2, based on the facial image of the subject P acquired by the detailed acquisition unit 36. The authentication unit 38, for example, compares the facial image of the subject P acquired by the detailed acquisition unit 36 with the facial image included in the authentication data 32 of the registered user recorded in the first memory 31. Based on the acquired facial image of the subject P, the authentication unit 38 authenticates that the subject P is a registered user.
[0058] As described above, the detail acquisition unit 36 sends the captured image of subject P and the facial image to the authentication unit 38 each time it captures a second image of subject P. Therefore, the authentication unit 38 can authenticate subject P in parallel with the acquisition of the second image by the detail acquisition unit 36. For example, in the example shown in Figure 3, the authentication unit 38 may operate to complete the authentication of subject P at a distance D3 where the intention determination unit 37 completes its determination of whether or not subject P intends to ride.
[0059] The authentication unit 38 may also authenticate the subject P in response to an operation on an external control device 10 located outside the vehicle 2, near the vehicle door 6. In this case, since it is clear that the subject P has the intention to board the vehicle, the authentication unit 38 can perform the authentication operation for the subject P without waiting for a determination from the intention determination unit 37. If the second camera 9 is not activated before the operation of the external control device 10, the authentication unit 38 may instruct the detail acquisition unit 36 to acquire a second image of the subject P using the second camera 9 and to extract the face image of the subject P.
[0060] The authentication unit 38 also activates the interior camera 18 when it has authenticated that the subject P is a registered user. The authentication unit 38 then identifies the person who sits in the driver's seat as the driver and performs driver authentication to determine whether the driver is a registered user. Driver authentication can also be performed by comparing the driver's facial image acquired by the interior camera 18 with the registered user authentication data 32 recorded in the first memory 31, similar to the authentication of the subject P described above. Alternatively, driver authentication may be performed using other known authentication technologies such as fingerprint authentication or voice authentication. When driver authentication is successful, the authentication unit 38 transmits permission to operate to the drive control device 15.
[0061] The door control unit 39, on the condition that the authentication unit 38 has successfully authenticated the subject P, instructs the door control device 11 of the vehicle 2 to perform automatic door unlocking and automatic door opening operations for the vehicle door 6 closest to the subject P. The vehicle door 6 closest to the subject P can be identified, for example, from the second image most recently acquired by the detail acquisition unit 36 and notified to the door control unit 39.
[0062] In this embodiment, the entry control device 3, in particular, executes the update control software 34 via the first processor 30 in accordance with instructions from the update management device 4 to perform a software update. Specifically, when the first processor 30 receives an instruction to install the new version of the software from the update management device 4, it executes the update control software 34 and stores the new version of the software transmitted from the update management device 4 in the first memory 31. Furthermore, when the first processor 30 receives an activation instruction from the update management device 4, it executes the update control software 34, runs the installed new version of the software, performs initial setup, and performs a software update. After that, the new version of the software is executed by the first processor 30 as the active software 33.
[0063] Furthermore, if the first memory 31 does not have storage capacity to store the new version software in addition to the current software 33, the first processor 30 may, upon receiving an installation instruction for the new version software from the update management device 4, execute the update control software 34 to store the new version software transmitted from the update management device 4 in the first memory 31, and then execute the stored new version software to perform initial setup and update the software.
[0064] [3. Configuration of the Update Management Device] The update management device 4 receives update data from the OTA server 22 via wireless communication over the communication network NW and instructs the electronic control device installed in the vehicle 2 to perform a software update. The electronic control device includes the entry control device 3.
[0065] The update management device 4 is a computer comprising a second processor 40 and a second memory 41. The second memory 41 is composed of, for example, a volatile and / or non-volatile semiconductor memory. The update management program 42 executed by the second processor 40 is stored in the second memory 41. Update data downloaded from the OTA server 22 is also temporarily stored in the second memory 41.
[0066] The second processor 40 is, for example, an arithmetic processing unit such as a CPU. The second processor 40 may have a configuration that includes a ROM on which a program is written, a RAM for temporary data storage, etc. The second processor 40 includes a detection unit 43 and an update management unit 44 as functional elements or functional units.
[0067] These functional elements provided by the second processor 40 are realized, for example, by the second processor 40 executing an update management program 42 stored in the second memory 41.
[0068] The detection unit 43 detects people or animals inside the vehicle using a cabin sensor 19 installed inside the vehicle 2.
[0069] The update management unit 44 receives update data from the OTA server 22 via wireless communication from outside the vehicle 2 and instructs the electronic control unit installed in the vehicle 2 to perform a software update. The electronic control unit includes the entry control unit 3.
[0070] In this embodiment, the update management unit 44 instructs the entry control device 3 to perform a software update only when no person or animal is detected inside the vehicle and after instructing the door control device 11 to lock the vehicle door 6. This prevents unauthorized persons from accessing the vehicle interior from outside the vehicle while the entry control device 3 is performing a software update, and also prevents occupants from manually unlocking the vehicle door 6 from inside the vehicle. Therefore, the vehicle system 1 maintains a high level of security for the vehicle 2 while the entry control device 3 is performing a software update.
[0071] Alternatively, the update management unit 44 may prohibit the entry control device 3 from performing a software update using update data when it detects a person or animal inside the vehicle. This prevents inconveniences such as the inability to automatically lock the vehicle doors 6 when a person inside the vehicle exits, if the entry control device 3 is unable to lock or unlock the vehicle doors 6 due to the execution of a software update.
[0072] Here, the instruction to execute a software update to the entry control device 3 may be an activation instruction to the entry control device 3 after the new version of the software included in the update data has been installed on the entry control device 3.
[0073] Alternatively, if the first memory 31 in the entry control device 3 does not have sufficient storage capacity to simultaneously store the current software 33 and the new software, the instruction to the entry control device 3 to perform a software update may be an instruction to install the new software included in the update data. In this case, the entry control device 3 can update the software by installing the new software, then executing the new software and performing initial setup, etc.
[0074] The update management unit 44 may also notify the user of the vehicle 2 to inquire whether or not to perform the software update before instructing the entry control device 3 to perform the software update. After the update management unit 44 has made the notification, or after receiving a response from the user granting permission to perform the software update, it may instruct the detection unit 43 to perform a person or animal detection operation inside the vehicle. This ensures that the detection operation is started only when it is necessary to detect a person or animal inside the vehicle, thereby suppressing the waste of power in the vehicle 2 due to unnecessary detection operations.
[0075] The update management unit 44 may also instruct the entry control device 3 to execute a software update when the cabin sensor 19 detects the presence of a person or animal inside the vehicle, provided that predetermined permission conditions are met. This allows for the execution of important software updates, such as those related to the safety and security of the vehicle 2, to be included in the permission conditions in advance. This ensures that updates are promptly executed even when a person or animal is detected inside the vehicle, thereby achieving higher safety and security for the vehicle 2.
[0076] Specifically, the above permission conditions may include the requirement that the update data pertains to a software update predetermined as an important update. This allows important updates to be performed promptly, thereby improving vehicle safety and convenience. Here, information on whether or not the update data pertains to an important update can be included, for example, in the update data downloaded from the OTA server 22.
[0077] Alternatively, the permission conditions may include receiving permission from the user of vehicle 2 to perform a software update for the entry control device 3. This improves the convenience of the vehicle, as the software update can be performed based on the user's choice, even when there are people or animals inside the vehicle.
[0078] The update management unit 44 may prohibit the door control device 11 from unlocking the vehicle door 6 based on instructions from the electronic key 5 while the entry control device 3 is performing a software update. This further enhances the security of the vehicle 2 while the entry control device 3 is performing a software update.
[0079] The update management unit 44 also, when the cabin sensor 19 detects a person or animal inside the vehicle and instructs the entry control device 3 to perform a software update because the above permission conditions are met, permits power supply to the electrical equipment other than the drive unit 14, even while the entry control device 3 is performing the software update, as long as the presence of a person or animal inside the vehicle is detected. Specifically, the update management unit 44 grants permission to operate the power control device 16, which manages the power supply to the electrical equipment other than the drive unit 14. As a result, even while the software update is being performed, the user can comfortably use the onboard electrical equipment such as the air conditioner and audio system by operating the start switch 17 inside the vehicle.
[0080] The update management unit 44 also, when the cabin sensor 19 detects a person or animal inside the vehicle and instructs the entry control device 3 to perform a software update because the above permission conditions are met, prohibits the supply of power to the vehicle's drive unit 14 while the entry control device 3 is performing the software update. Specifically, the update management unit 44 prohibits the supply of power to the drive unit 14 by issuing an instruction to the drive control device 15, which controls the operation of the drive unit 14, to prohibit operation. This prevents a user waiting inside the vehicle for the entry control device 3 to complete the software update from accidentally starting the vehicle, thereby ensuring the safety of the vehicle.
[0081] [3. Operation of the Vehicle System] Next, the procedure for the operation of the vehicle system 1 will be described. Figures 4 and 5 are flowcharts showing the procedure for updating the software of the entry control device 3 that the vehicle system 1 performs. The process shown in Figures 4 and 5 starts when the start switch 17 of the vehicle 2 is turned off, after the update management unit 44 of the update management device 4 has installed the new software included in the update data downloaded from the OTA server 22 to the entry control device 3, but before the activation of the new software has been performed. Even after the start switch 17 of the vehicle 2 is turned off, power will be supplied to the entry control device 3 and the update management device 4, as well as to the devices shown in Figure 2, such as the door control device 11, communication device 12, cabin sensor 19, and display device 20, which are necessary for the operation of the entry control device 3 and the update management device 4.
[0082] Referring to Figure 4, when processing begins, the update management unit 44 of the update management device 4 first inquires with the user of the vehicle 2 whether or not to perform a software update on the entry control device 3 (S100). This inquiry can be made by displaying a message on the display device 20 provided in the vehicle 2 and on the user's mobile terminal 5a. In response, the user can input an instruction to allow or refuse the software update to the display device 20 or mobile terminal 5a and send either instruction to the update management device 4.
[0083] Next, the update management unit 44 determines whether it has received permission from the user to perform the update from the in-vehicle device within a predetermined time from the above inquiry (S102). In this embodiment, the in-vehicle device is a display device 20 which is a touch panel. If permission is received from the in-vehicle device, it is assumed that there is an occupant inside the vehicle 2. Therefore, when permission to perform the update is received from the in-vehicle device (S102, YES), the update management unit 44 determines whether any of the vehicle doors 6 have been opened, closed, and locked (S104). This allows for the determination of whether the person inside the vehicle has exited. The open / closed state and the locking / unlocking state of the vehicle doors 6 can be detected by a door open / close sensor and a lock sensor (not shown) provided on the vehicle doors 6.
[0084] Then, when any of the vehicle doors 6 are opened, closed, and locked (S104, YES), the update management unit 44 instructs the detection unit 43 to detect a person or animal (hereinafter referred to as "person, etc.") inside the vehicle and determines whether or not a person, etc. has been detected (S140). This allows the update management unit 44 to confirm that there are no people, etc. inside the vehicle. If no people, etc. are detected inside the vehicle (S140, NO), the update management unit 44 instructs all door control devices 11 to lock all vehicle doors 6 (S142). The update management unit 44 also instructs the entry control device 3 to perform a software update (S144). In this embodiment, the update management unit 44 gives the entry control device 3 an activation instruction as an instruction to perform a software update. As a result, the entry control device 3 executes the new version of the software installed in the first memory 31 and performs initial settings, etc., to update the software.
[0085] Next, the update management unit 44 prohibits all door control devices 11 from performing door unlocking operations based on instructions from the electronic key 5 (S146). This prevents subsequent boarding by users using the electronic key 5. The update management unit 44 then moves the process to step S136 in Figure 5.
[0086] Referring to Figure 5, the update management unit 44 then determines whether the software update operation for all electronic control devices that are the target of this software update, including the entry control device 3, has been completed (S136). If the software update operation for any of the electronic control devices has not been completed (S136, NO), the update management unit 44 returns to step S136 and repeats the process.
[0087] On the other hand, when the software update operation of all electronic control devices is completed (S136, YES), the update management unit 44 authorizes all door control devices 11 to unlock the vehicle doors 6 in response to instructions from the electronic key 5 (S130), and then terminates this process.
[0088] Referring to Figure 4, if in step S102 permission to perform the update is not received from the in-vehicle equipment by the user (S102, NO), the update management unit 44 determines whether or not permission to perform the software update has been received from the user's mobile terminal 5a within a predetermined time from the inquiry in step S100 (S150). If permission to perform the update is not received from the user's mobile terminal 5a either (S150, NO), the update management unit 44 terminates this process (transitions to "END" in Figure 5). In this case, since the new software installed on the entry control device 3 has not yet been actuated, the process will start again from step S100 when the start switch 17 is turned off next.
[0089] On the other hand, when permission to perform the update is received from the user's mobile terminal 5a (S150, YES), the update management unit 44 moves to step S140. When permission to perform the update is received from the mobile terminal 5a, there is a high probability that the user is operating the mobile terminal 5a outside the vehicle, and a low probability that there are people inside the vehicle. For this reason, the update management unit 44 moves to step S140 to determine whether or not there are people inside the vehicle, without performing step S104 to determine the possibility of people getting out of the vehicle.
[0090] On the other hand, if in step S104 none of the vehicle doors 6 are opened or closed and locked (S104, NO), or if a person or the like is detected inside the vehicle in step S140 (S140, NO), the update management unit 44 determines whether a predetermined time has elapsed since receiving permission from the in-vehicle equipment in step S102 (S106). That is, after receiving permission to perform the update from the in-vehicle equipment, the update management unit 44 determines whether a predetermined time has elapsed without a person getting out of the vehicle 2. If the predetermined time has not yet elapsed since receiving permission to perform the update from the in-vehicle equipment (S106, NO), the update management unit 44 returns to step S104 and repeats the process.
[0091] On the other hand, if a predetermined time has elapsed since receiving permission to perform the update from the in-vehicle equipment (S106, YES), it is determined whether the update data received from the OTA server 22 regarding the software update of the entry control device 3 is related to an important update for the entry control device 3 (S108). If the update data is related to an important update for the entry control device 3 (S108, YES), the process moves to step S114 in Figure 5.
[0092] On the other hand, if the update data is not related to an important update for the entry control device 3 (S108, NO), the update management unit 44 asks the user whether it is permissible to perform a software update for the entry control device 3 while there are people inside the vehicle (S110). This inquiry can be made by displaying a message on the display device 20 provided in the vehicle 2 and the user's mobile terminal 5a, similar to step S100. In response, the user can input an instruction to the display device 20 or mobile terminal 5a to permit or refuse the execution of the software update while there are people inside the vehicle (i.e., in the presence of people), and send either instruction to the update management device 4.
[0093] Then, if the update management unit 44 does not receive permission from the display device 20 or mobile terminal 5a to perform the software update in the presence of a person, etc., within a predetermined time from the inquiry in step S110 (S112, NO), the update management unit 44 terminates this process (it moves to "END" in Figure 5). In this case, since the new software installed on the entry control device 3 has not yet been actuated, the process will start again from step S100 when the start switch 17 is turned off next.
[0094] On the other hand, if permission to perform the software update in the presence of a person or other person is received in step S112 (S112, YES), the update management unit 44 moves to step S114 in Figure 5.
[0095] Referring to Figure 5, in step S114, the update management unit 44 instructs all door control devices 11 to lock all vehicle doors 6 (S114). The update management unit 44 also instructs the entry control device 3 to perform a software update (S116). In this embodiment, the update management unit 44 gives the entry control device 3 an activation instruction as an instruction to perform a software update. As a result, the entry control device 3 executes the new software installed in the first memory 31 and performs initial settings, etc., to update the software.
[0096] Next, the update management unit 44 grants permission for operation to the power control device 16 (S118) and instructs the drive control device 15 to prohibit operation (S120). This improves the comfort of people inside the vehicle and ensures the safety of the vehicle 2. The update management unit 44 also prohibits all door control devices 11 from unlocking the doors based on instructions from the electronic key 5 (S122). This prevents new people from boarding the vehicle while the software of the entry control device 3 is being updated.
[0097] Next, the update management unit 44 instructs the detection unit 43 to detect people or other objects inside the vehicle and determines whether or not people or other objects have been detected (S124). This allows the update management unit 44 to determine whether or not people or other objects have left the vehicle after the software update operation started in step S116.
[0098] If no people or other objects are detected inside the vehicle (S124, YES), the update management unit 44 instructs the power control device 16 to stop operation (S132) and all door control devices 11 to lock all vehicle doors 6 (S134). Next, the update management unit 44 determines whether the software update operation of all electronic control devices that are the target of this software update, including the entry control device 3, has been completed (S136). If the software update operation of any electronic control device has not been completed (S136, NO), the update management unit 44 returns to step S136 and repeats the process, waiting for the software update operation of all electronic control devices to be completed.
[0099] On the other hand, when the software update operation of all electronic control devices is completed (S136, YES), the update management unit 44 authorizes all door control devices 11 to unlock the vehicle doors 6 in response to instructions from the electronic key 5 (S130), and then terminates this process.
[0100] On the other hand, if the system continues to detect the presence of a person or other object inside the vehicle in step S124 (S124, YES), the update management unit 44 determines whether the software update operation for all electronic control devices that are the target of this software update, including the entry control device 3, has been completed (S126). If the software update operation for any of the electronic control devices has not been completed (S126, NO), the update management unit 44 returns to step S124 and repeats the process.
[0101] On the other hand, when the software update operation of all electronic control devices is completed (S126, YES), the update management unit 44 instructs the power control device 16 to turn off the power to the electrical devices (S128), and permits all door control devices 11 to unlock the vehicle doors 6 in response to the instruction from the electronic key 5 (S130), thereby ending this process.
[0102] Step S140 in Figure 4 and step S124 in Figure 5 correspond to the detection step in this disclosure. Steps S142 and S144 in Figure 4 correspond to the update instruction step in this disclosure.
[0103] It should be noted that the present invention is not limited to the configuration of the embodiments described above, and can be implemented in various forms without departing from the spirit of the invention.
[0104] [5. Configurations Supported by the Above Embodiments] The above embodiments support the following configurations.
[0105] (Configuration 1) A vehicle system comprising: an entry control device that automatically locks and unlocks the vehicle doors; an update management unit that receives update data provided wirelessly from outside the vehicle and instructs an electronic control device in the vehicle to perform a software update using the update data; and a detection unit that detects a person or animal inside the vehicle using a sensor installed inside the vehicle's interior, wherein the update management unit locks the vehicle doors when no person or animal is detected inside the vehicle, and then, based on the detection result of the detection unit, instructs the entry control device to perform a software update using the update data. According to Configuration 1, since the software update of the entry control device that automatically locks and unlocks the vehicle doors is performed by locking the vehicle doors when no person or animal is detected inside the vehicle, during the execution of the software update, it is prevented for persons who are not users of the vehicle to access the interior from outside the vehicle, and it is also not possible for an occupant to manually unlock the vehicle doors from inside the vehicle. Therefore, in Configuration 1, the security of the vehicle is maintained at a high level while the software update of the entry control device is being performed.
[0106] (Configuration 2) The vehicle system according to Configuration 1 or 2, wherein the update management unit, when it detects a person or animal inside the vehicle, prohibits the entry control device from executing a software update using the update data. According to Configuration 2, when the entry control device is unable to lock or unlock the vehicle doors due to the execution of a software update, it is possible to prevent inconveniences such as the inability to automatically lock the vehicle doors when a person inside the vehicle exits the vehicle.
[0107] (Configuration 3) The vehicle system according to Configuration 1 or 2, comprising a door control device having a function to lock and unlock the vehicle doors by wireless communication instructions from the vehicle key of the vehicle, wherein the update management unit prohibits the door control device from unlocking the vehicle doors by instructions from the vehicle key while the entry control device is performing a software update using the update data. According to Configuration 3, the security of the vehicle is improved while the entry control device is performing a software update.
[0108] (Configuration 4) The vehicle system according to any one of Configurations 1 to 3, wherein the update management unit, even when the sensor detects the presence of a person or animal in the vehicle compartment, instructs the entry control device to execute a software update using the update data if predetermined permission conditions are met. According to Configuration 4, for example, important software updates related to vehicle safety and security can be included in the permission conditions in advance, so that the update can be executed quickly regardless of the presence of a person or other object in the vehicle compartment, thereby achieving high safety and security for the vehicle.
[0109] (Configuration 5) The vehicle system as described in Configuration 4, wherein the permission conditions include that the update data pertains to a software update predetermined as relating to an important update, and that permission to perform a software update for the entry control device has been received from the user of the vehicle. According to Configuration 5, important updates related to the safety and security of the vehicle can be performed promptly, and software updates can be performed based on the user's choice even when people are present in the vehicle cabin, thereby improving the safety and convenience of the vehicle.
[0110] (Configuration 6) The vehicle system according to Configuration 4 or 5, wherein when the update management unit detects a person or animal in the vehicle interior by the sensor and instructs the entry control device to perform a software update because the permission conditions are met, the system permits the supply of power to the electrical equipment, excluding the drive unit, installed in the vehicle, while the entry control device is performing a software update and the presence of a person or animal in the vehicle interior is detected. According to Configuration 6, electrical equipment such as air conditioners and audio equipment can be used even while the entry control device is performing a software update, thereby improving convenience for people waiting in the vehicle interior.
[0111] (Configuration 7) The vehicle system according to any one of Configurations 4 to 6, wherein when the update management unit detects a person or animal in the vehicle interior by the sensor and instructs the entry control device to perform a software update because the permission conditions are met, it prohibits the supply of power to the vehicle's drive system while the entry control device is performing the software update. According to Configuration 7, it is possible to ensure the safety of the vehicle by preventing a user waiting in the vehicle interior for the completion of the software update of the entry control device from accidentally starting the vehicle to drive.
[0112] (Configuration 8) The vehicle system according to any one of Configurations 1 to 7, wherein the update management unit notifies the user of the vehicle to inquire whether or not to perform a software update using the update data for the entry control device, and after the notification is made, or after the user has given permission to perform the execution, the detection unit starts detecting people or animals inside the vehicle. According to Configuration 8, the detection operation is started when it becomes necessary to detect people or the like inside the vehicle, so the waste of power in the vehicle 2 due to unnecessary detection operations can be suppressed.
[0113] (Configuration 9) A software update method for an entry control device, which automatically locks and unlocks the doors of a vehicle, wherein the software of the entry control device is updated by update data provided wirelessly from outside the vehicle, the method comprising: a detection step in which a computer detects the presence or absence of a person or animal inside the vehicle using a sensor provided inside the vehicle's interior; and an update instruction step in which, when no person or animal is detected inside the vehicle's interior, the computer locks the doors of the vehicle and then instructs the entry control device to perform a software update using the update data. Configuration 9 provides the same effects as Configuration 1.
[0114] 1...Vehicle system, 2...Vehicle, 3...Entry control device, 4...Update management device, 5...Electronic key, 5a...Mobile terminal, 6...Vehicle door, 6a...Driver's door, 6b...Right rear door, 6c...Passenger door, 6d...Left rear door, 6e...Back door, 7, 7a, 7b, 7c...Object sensors, 8, 8a, 8b, 8c...First camera, 9, 9a, 9b, 9c...Second camera, 10, 10a, 10b, 10c, 10d, 10e...External control device, 11, 11a, 11b, 11c, 11d, 11e...Door control device, 12...Communication device, 13...Battery, 14...Drive unit, 15...Drive control device, 16...Power control device ,17...Start switch, 18...Indoor camera, 19...Cabin sensor, 20...Display device, 21...Communication cable, 22...OTA server, 30...First processor, 31...First memory, 32...Authentication data, 33...Current software, 34...Update control software, 35...Proximity detection unit, 36...Detail acquisition unit, 37...Intention determination unit, 38...Authentication unit, 39...Door control unit, 40...Second processor, 41...Second memory, 42...Update management program, 43...Detection unit, 44...Update management unit, 61...Second current software, 62...Second detection unit, 63...Second authentication unit, NW...Communication network, P...Target person.
Claims
1. A vehicle system comprising: an entry control device that automatically locks and unlocks the vehicle doors; an update management unit that receives update data provided wirelessly from outside the vehicle and instructs an electronic control device in the vehicle to perform a software update using the update data; and a detection unit that detects a person or animal inside the vehicle using a sensor installed inside the vehicle's interior, wherein the update management unit locks the vehicle doors and then instructs the entry control device to perform a software update using the update data when no person or animal is detected inside the vehicle's interior.
2. The vehicle system according to claim 1, wherein the update management unit, when it detects a person or animal inside the vehicle, prohibits the entry control device from executing a software update using the update data.
3. The vehicle system according to claim 1, comprising a door control device having a function to lock and unlock the vehicle door in response to instructions from the vehicle key via wireless communication of the vehicle, wherein the update management unit prohibits the door control device from unlocking the vehicle door in response to instructions from the vehicle key while the entry control device is performing a software update using the update data.
4. The vehicle system according to claim 1, wherein the update management unit, when it detects the presence of a person or animal in the vehicle interior using the sensor, instructs the entry control device to perform a software update using the update data if the predetermined permission conditions are met.
5. The vehicle system according to claim 4, wherein the permission conditions include that the update data pertains to a software update predetermined as relating to an important update, and that permission to perform a software update for the entry control device has been received from the user of the vehicle.
6. The vehicle system according to claim 4, wherein when the update management unit detects a person or animal in the vehicle interior by the sensor and instructs the entry control device to perform a software update because the permission conditions are met, the entry control device permits the supply of power to the electrical equipment excluding the drive unit mounted on the vehicle while the entry control device is performing a software update and the presence of a person or animal in the vehicle interior is detected.
7. The vehicle system according to claim 4, wherein when the update management unit detects a person or animal in the vehicle interior by the sensor and instructs the entry control device to perform a software update because the permission conditions are met, it prohibits the supply of power to the vehicle's drive system while the entry control device is performing the software update.
8. The vehicle system according to any one of claims 1 to 7, wherein the update management unit notifies the user of the vehicle to inquire whether or not to perform a software update using the update data for the entry control device, and after the notification has been made, or after receiving a response from the user granting permission to perform the execution, the detection unit causes the detection unit to start detecting a person or animal inside the vehicle.
9. A software update method for an entry control device, which automatically locks and unlocks the doors of a vehicle, wherein the software of the entry control device is updated using update data provided wirelessly from outside the vehicle, the method comprising: a detection step in which a computer detects the presence or absence of a person or animal inside the vehicle using a sensor provided inside the vehicle's interior; and an update instruction step in which, when no person or animal is detected inside the vehicle's interior, the computer locks the doors of the vehicle and then instructs the entry control device to perform a software update using the update data.