WO2020184255A1 - 車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム - Google Patents

車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム Download PDF

Info

Publication number
WO2020184255A1
WO2020184255A1 PCT/JP2020/008683 JP2020008683W WO2020184255A1 WO 2020184255 A1 WO2020184255 A1 WO 2020184255A1 JP 2020008683 W JP2020008683 W JP 2020008683W WO 2020184255 A1 WO2020184255 A1 WO 2020184255A1
Authority
WO
WIPO (PCT)
Prior art keywords
vehicle
update
program
person
storage unit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2020/008683
Other languages
English (en)
French (fr)
Inventor
好邦 下村
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Sumitomo Wiring Systems Ltd
Original Assignee
Sumitomo Wiring Systems Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sumitomo Wiring Systems Ltd filed Critical Sumitomo Wiring Systems Ltd
Priority to CN202080015434.2A priority Critical patent/CN113454693B/zh
Priority to US17/435,617 priority patent/US11954476B2/en
Publication of WO2020184255A1 publication Critical patent/WO2020184255A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/65Updates
    • BPERFORMING OPERATIONS; TRANSPORTING
    • B60VEHICLES IN GENERAL
    • B60RVEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
    • B60R16/00Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for
    • B60R16/02Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for electric constitutive elements
    • B60R16/023Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for electric constitutive elements for transmission of signals between vehicle parts or subsystems
    • B60R16/0231Circuits relating to the driving or the functioning of the vehicle
    • GPHYSICS
    • G08SIGNALLING
    • G08GTRAFFIC CONTROL SYSTEMS
    • G08G1/00Traffic control systems for road vehicles
    • G08G1/16Anti-collision systems

Definitions

  • the present disclosure relates to an in-vehicle update device, an update processing system, an update processing method, and a computer program.
  • This application claims priority based on Japanese Application No. 2019-042788 filed on March 8, 2019, and incorporates all the contents described in the Japanese application.
  • a vehicle is equipped with in-vehicle devices such as a plurality of ECUs (Electronic Control Units), and the plurality of ECUs are connected via a communication line such as a CAN (Controller Area Network) bus to transmit and receive information to each other.
  • a communication line such as a CAN (Controller Area Network) bus to transmit and receive information to each other.
  • Each ECU reads and executes a program stored in a storage unit such as a flash memory or an EEPROM (Electrically Erasable Programmable Read Only Memory) by a processing device such as a CPU (Central Processing Unit), thereby controlling a vehicle and the like. Is being processed.
  • the program stored in the storage unit of the ECU needs to be updated with a new program when, for example, it becomes necessary to add a function, correct a defect, or upgrade the version. In this case, the update program is transmitted to the ECU that is the target of the update process via the communication line.
  • Patent Document 1 proposes a vehicle device capable of notifying a user of whether or not to drive when updating a program in response to a request from a terminal that can be operated by a vehicle user.
  • the in-vehicle update device of the present disclosure has a first in-vehicle device having a storage unit that stores a program rewritably, and a sensor that detects a person existing in the vicinity of the vehicle, and determines the presence or absence of a person present in the vicinity of the vehicle.
  • the communication unit that communicates with the second in-vehicle device that transmits the detection result shown, and the update program for updating the program stored in the storage unit are acquired from the outside, and the acquired update program is used.
  • the storage unit includes a processing unit that executes an update process of the program stored in the storage unit, and the processing unit determines that no person exists in the vicinity of the vehicle based on the detection result received by the communication unit.
  • the update program executes the update process of the program stored in the storage unit.
  • the update processing method of the present disclosure is an update processing method for executing update processing of a program stored in the storage unit of the first vehicle-mounted device, and is an update program for updating the program stored in the storage unit.
  • the step of determining whether or not there is a person in the vicinity of the vehicle, and when it is determined that there is no person in the vicinity of the vehicle the storage unit uses the acquired update program. It includes a step of executing the update process of the program to be stored.
  • the computer program of the present disclosure is a computer program for causing a computer to execute an update process of a program stored in a storage unit of the first vehicle-mounted device, and the computer detects a person existing in the vicinity of the vehicle. Whether there is a person around the vehicle based on the step of communicating with a second in-vehicle device having a sensor and transmitting a detection result indicating the presence or absence of a person existing around the vehicle and the received detection result. The step of determining whether or not, and when it is determined that there is no person in the vicinity of the vehicle, the update process of the program stored in the storage unit by the update program acquired from the outside for updating the program is performed. To execute the step to be executed.
  • the present application can be realized not only as an update processing apparatus provided with such a characteristic processing unit, but also as an update processing method in which the characteristic processing is a step, as described above, or such a step.
  • it can be realized as a semiconductor integrated circuit that realizes a part or all of the update processing device, or can be realized as another system including the update processing device.
  • Patent Document 1 does not consider an unforeseen situation that poses a danger to people around the vehicle.
  • the object of the present disclosure is to execute the program update process of the in-vehicle device after confirming that there is at least no person in the vicinity of the vehicle, and if there is a person in the vicinity of the vehicle, the program update process can be restricted.
  • the purpose of the present invention is to provide an apparatus, an update processing system, an update processing method, and a computer program.
  • the in-vehicle update device has a first in-vehicle device having a storage unit that stores a program rewritably, and a sensor that detects a person existing in the vicinity of the vehicle, and exists in the vicinity of the vehicle.
  • the communication unit that communicates with the second in-vehicle device that transmits the detection result indicating the presence or absence of a person, and the update program for updating the program stored in the storage unit are acquired from the outside and the acquired update.
  • the program includes a processing unit that executes an update process of the program stored in the storage unit, and the processing unit does not have a person around the vehicle based on the detection result received by the communication unit. When it is determined, the update process of the program stored in the storage unit is executed by the update program.
  • the processing unit externally acquires an update program for updating the program stored in the storage unit of the first vehicle-mounted device.
  • the processing unit executes the update processing of the program stored in the storage unit by using the acquired update program
  • the detection result is information indicating the presence or absence of a person existing around the vehicle.
  • the processing unit determines whether or not there is a person in the vicinity of the vehicle based on the received detection result, and if it is determined that there is no person in the vicinity of the vehicle, the processing unit executes the update process of the above program. That is, when there is no person around the vehicle, the processing unit does not execute the update processing of the program stored in the storage unit. Therefore, even if the vehicle behaves unexpectedly due to a defect in the program update process, there are no people around the vehicle, so even if an unexpected situation related to the program update occurs, human damage is avoided. be able to.
  • the communication unit has a sensor that detects a person in the vehicle, and communicates with a third in-vehicle device that transmits an in-vehicle detection result indicating the presence or absence of a person in the vehicle.
  • a program stored by the storage unit in the update program when it is determined that there are no people around the vehicle or in the vehicle based on the detection result received by the communication unit and the in-vehicle detection result.
  • the configuration that executes the update process of is preferable.
  • the processing unit when the processing unit executes the update processing of the program stored in the storage unit, the processing unit receives the in-vehicle detection result transmitted from the third vehicle-mounted device in the communication unit.
  • the in-vehicle detection result is information indicating the presence or absence of a person present in the vehicle.
  • the processing unit determines whether or not there is a person in the vicinity of the vehicle and in the vehicle, and when it is determined that there is no person in the vicinity of the vehicle and in the vehicle, the processing unit of the above program Execute the update process. That is, when there is no person around the vehicle or in the vehicle, the processing unit does not execute the update processing of the program stored in the storage unit. Therefore, even if the vehicle behaves unexpectedly due to a defect in the program update process, there are no people around or inside the vehicle, so even if an unexpected situation related to the program update occurs, human damage will occur. It can be avoided.
  • the processing unit executes the update processing of the program stored in the storage unit by the update program when a predetermined time has elapsed after confirming that no person exists.
  • the processing unit executes the update processing of the program stored in the storage unit after a lapse of a predetermined time after confirming that no person exists around the vehicle. Therefore, it is possible to more reliably detect that there is no person around the vehicle and avoid human damage caused by an unexpected situation related to the program update.
  • the processing unit determines that a person exists in the vicinity of the vehicle during the update process of the program, the processing unit stops the update process of the program by the first in-vehicle device, and the person again comes around the vehicle.
  • a predetermined time has elapsed since it was determined that the program does not exist, it is preferable to restart the update process of the program.
  • the processing unit suspends the update process when a person existing around the vehicle is detected during the program update process.
  • the processing unit restarts the update process of the program. Therefore, the update process can be advanced in a state where no person is present around the vehicle, and human damage caused by an unexpected situation related to the program update can be avoided.
  • the processing unit stops the update processing of the program stored in the storage unit when the door of the vehicle is unlocked.
  • the processing unit suspends the update process when the door is unlocked during the program update process. If the door is unlocked by remote control, a person may approach the vehicle. Therefore, the update process can be stopped even when there is a possibility that a person exists in the vicinity of the vehicle, and human damage caused by an unexpected situation related to the program update can be avoided.
  • the processing unit locks the vehicle door after a predetermined time has elapsed after confirming that there are no people around the vehicle. Therefore, it is possible to prevent a person from entering the vehicle during the program update and operating the vehicle, and it is possible to more reliably avoid human damage caused by an unexpected situation related to the program update.
  • the update program is applied regardless of the presence or absence of a person present in the vicinity of the vehicle.
  • the configuration for executing the update process of the program stored in the storage unit is preferable.
  • the program update process is managed by a maintenance worker having specialized knowledge, so that the processing unit is the vehicle. It is possible to execute the update process of the program stored in the storage unit regardless of the presence or absence of people in the vicinity. Therefore, it is possible to prevent the program update process from being interrupted unnecessarily, and the maintenance worker can efficiently perform the maintenance work of the vehicle.
  • the detection result includes the result of detecting a person existing in the vicinity of the vehicle with an in-vehicle camera or a radar that images the vicinity of the vehicle.
  • In this embodiment it is possible to confirm that there is no person around the vehicle by using an in-vehicle camera or radar, and to execute the update process of the program stored in the storage unit.
  • the system can be configured at low cost.
  • In-vehicle cameras also include cameras that capture images outside visible light, such as infrared cameras. Radar irradiates radio waves or ultrasonic waves, detects reflected waves from an object, and detects a person. Radars include millimeter wave radars, ultrasonic sensors, infrared sensors, laser scanners and the like.
  • the update processing system includes an in-vehicle update device according to any one of aspects (1) to (8) and a first in-vehicle device having the storage unit that stores the program in a rewritable manner.
  • a second in-vehicle device having a sensor for detecting a person present in the vicinity of the vehicle and transmitting the detection result indicating the presence or absence of a person present in the vicinity of the vehicle.
  • the update processing method is an update processing method for executing the update processing of the program stored in the storage unit of the first vehicle-mounted device, in order to update the program stored in the storage unit.
  • Communication with a second in-vehicle device that has a step of acquiring the update program from the outside and a sensor that detects a person existing around the vehicle and transmits a detection result indicating the presence or absence of a person existing around the vehicle.
  • the step to be performed the step of determining whether or not there is a person in the vicinity of the vehicle based on the received detection result, and when it is determined that there is no person in the vicinity of the vehicle, the acquired update program is used.
  • the program includes a step of executing an update process of the program stored in the storage unit.
  • the computer program according to this aspect is a computer program for causing a computer to execute an update process of a program stored in a storage unit of the first vehicle-mounted device, and exists in the computer around the vehicle.
  • the program stored in the storage unit by an update program acquired from the outside for updating the program when it is determined that there is no person in the vicinity of the vehicle and the step of determining whether or not the computer exists. To execute the step to execute the update process of.
  • the computer can function as the update processing device according to the aspect (1), and even if the vehicle performs an unexpected operation due to a defect in the program update processing of the in-vehicle device, the vehicle Since there are no people in the vicinity, it is possible to avoid human damage even if an unexpected situation related to program update occurs.
  • FIG. 1 is a schematic diagram showing the configuration of the update processing system 100 according to the present embodiment
  • FIG. 2 is a schematic diagram showing the configuration of the update processing system 100 and the gateway (vehicle-mounted update device) 1 according to the present embodiment.
  • the update processing system 100 according to the present embodiment includes a plurality of ECUs 2 mounted on the vehicle C, one wireless communication device 3, and one gateway 1.
  • Each ECU 2 is connected to any of the communication lines 1a, 1b or 1c, and can perform communication via the connected communication lines 1a, 1b or 1c.
  • the drive ECU (first in-vehicle device) 21 is connected to the communication line 1a
  • the peripheral detection ECU (second in-vehicle device) 22, the stop detection ECU 23, and the seating detection ECU (seat detection ECU) are connected to the communication line 1b.
  • the third vehicle-mounted device) 24a and the grip detection ECU (third vehicle-mounted device) 24b are connected, and the locking / unlocking ECU 25 is connected to the communication line 1c. In the present embodiment, these are collectively referred to as ECU 2.
  • the gateway 1 relays communication between communication lines 1a, 1b, and 1c, whereby the plurality of ECUs 2 can communicate via communication lines 1a, 1b, 1c and gateway 1.
  • the drive ECU 21 is, for example, an ECU 2 that controls the operation of the engine of the vehicle C.
  • the configuration of the drive ECU 21 will be described later.
  • the peripheral detection ECU 22 is connected to an in-vehicle camera 22a that images the surroundings of the vehicle, an ultrasonic sensor 22b for detecting an object existing around the vehicle, a millimeter wave radar 22c, and a laser radar (LIDAR: light detection and ranging) 22d.
  • LIDAR light detection and ranging
  • the in-vehicle camera 22a either a monocular camera or a stereo camera can be used.
  • the in-vehicle camera 22a may be one that images the person A with visible light, or may be one that images the person A with infrared rays.
  • the peripheral detection ECU 22 is a person existing around the vehicle based on the image captured by the in-vehicle camera 22a, the detection data of the ultrasonic sensor 22b, the millimeter wave radar 22c, the laser radar 22d (LIDAR), and the like.
  • Detect A The person A includes not only a pedestrian but also a person A riding a motorcycle.
  • the person A may be identified by using, for example, a trained model learned by deep learning. Deep learning is a type of machine learning that classifies images and detection results of each sensor and radar into predetermined classes.
  • the peripheral detection ECU 22 learns a large amount of object images of stationary obstacles other than the person A existing around the vehicle, object images of the person A, objects of buildings existing around the vehicle, objects such as the vehicle C, and the like.
  • the weighting coefficient that associates the feature such as A with the class corresponding to each feature is stored as a learning result.
  • the peripheral detection ECU 22 identifies the class to which the detection target belongs by inputting the acquired image data and the detection result of each sensor into the trained model. By specifying the class, whether or not the detection target is person A is specified.
  • the peripheral detection ECU 22 transmits an out-of-vehicle detection result indicating whether or not a person A is present around the vehicle to the gateway 1.
  • the gateway 1 receives the vehicle outside detection result transmitted from the peripheral detection ECU 22, and can determine whether or not a person A exists in the vicinity of the vehicle based on the received vehicle outside detection result.
  • the vehicle stop detection ECU 23 is connected to, for example, a vehicle speed sensor, a position switch that outputs a signal according to the position of the shift lever of the vehicle C, an ignition switch, and the like.
  • the vehicle speed sensor is, for example, a wheel speed sensor, and outputs a pulse signal according to the rotation speed of the wheels.
  • the vehicle stop detection ECU 23 determines whether or not the vehicle C is stopped based on the signals output from the vehicle speed sensor, the position switch, the ignition switch, etc., and transmits the vehicle stop detection result indicating whether or not the vehicle C is stopped as a gateway. Output to 1.
  • the gateway 1 receives the stop detection result transmitted from the stop detection ECU 23, and can determine whether or not the vehicle C is stopped based on the received stop detection result.
  • the seating detection ECU 24a has a pressure sensor, a weight sensor, etc. embedded in the seat of the vehicle C, detects whether or not a occupant is sitting in the seat, and transmits the in-vehicle detection result to the gateway 1.
  • the gateway 1 receives the in-vehicle detection result transmitted from the seating detection ECU 24a, and can determine whether or not a person A is present in the vehicle based on the received in-vehicle detection result.
  • the grip detection ECU 24b has a touch sensor provided on the steering wheel.
  • the touch sensor is, for example, a capacitance sensor, and the grip detection ECU 24b determines whether or not the driver is gripping the steering wheel based on the signal of the touch sensor.
  • the grip detection ECU 24b transmits an in-vehicle detection result indicating whether or not the steering wheel is gripped to the gateway 1.
  • the gateway 1 receives the in-vehicle detection result transmitted from the seating detection ECU 24a, and can determine whether or not a person A is present in the vehicle based on the received in-vehicle detection result.
  • the locking / unlocking ECU 25 is connected to an actuator that drives a locking / unlocking device (not shown) that locks / unlocks the vehicle door.
  • a locking / unlocking device (not shown) that locks / unlocks the vehicle door.
  • the locking / unlocking ECU 25 drives the locking / unlocking device to lock or unlock the vehicle door.
  • a signal instructing the locking / unlocking of the door is transmitted from the legitimate portable device and the signal is received
  • the locking / unlocking ECU 25 drives the locking / unlocking device to lock or unlock the vehicle door.
  • another ECU 2 executes detection of the operation state of the request switch, wireless communication processing with the portable device, position detection of the portable device, authentication processing of the portable device, and the like.
  • the locking / unlocking ECU 25 may receive from the other ECU 2 the operation state of the request switch, the position detection result of the portable device, the authentication result, the signal for instructing the locking / unlocking wirelessly transmitted from the portable device, and the like. Further, the lock / unlock ECU 25 can transmit information indicating the lock / unlock state of the door to the gateway 1 via the communication line 1c. The gateway 1 can recognize the locked / unlocked state of the door by receiving the information transmitted from the locking / unlocking ECU 25.
  • the wireless communication device 3 is connected to the gateway 1 via the communication line 1d.
  • the gateway 1 can communicate with the server device 9 installed outside the vehicle C via the wireless communication device 3.
  • the wireless communication device 3 can communicate with the server device 9 installed outside the vehicle C by performing wireless communication such as a mobile phone communication network or a wireless LAN (Local Area Network).
  • the wireless communication device 3 can relay the communication between the gateway 1 and the server device 9, transmits the data given from the gateway 1 to the server device 9, and transmits the data received from the server device 9 to the gateway 1. give.
  • the server device 9 manages and stores a program executed by the ECU 2 mounted on the vehicle C. In response to an inquiry from the vehicle C, the server device 9 notifies whether or not an update of a program or the like stored in each ECU 2 is necessary, and if the update is necessary, the server device 9 provides a program for update to the vehicle. Performs the process of delivering to C.
  • the gateway 1 can communicate with the server device 9, acquire an update program for updating the program 21d to be described later stored in the ECU 2, and transmit the acquired update program to the ECU 2.
  • a connector 4 for connecting an external device by wire is provided at an appropriate position in the vehicle C.
  • the gateway 1 is connected to the connector 4 by the communication line 1e.
  • the diagnostic tool 5 is detachably connected to the connector 4 via, for example, a communication cable.
  • the gateway 1 can communicate with the diagnostic tool 5 via the communication line 1e, the connector 4, and the communication cable.
  • the diagnostic tool 5 is, for example, a device provided in a dealer or a maintenance shop of the vehicle C, and is a device for an operator to inspect a defect of the vehicle C or change a setting.
  • the diagnostic tool 5 is a portable device having, for example, an operation unit and a display unit. After the operator connects the communication cable of the diagnostic tool 5 to the connector 4 of the vehicle C and undergoes an appropriate authentication process or the like, the diagnostic tool 5 and the gateway 1 of the vehicle C can communicate with each other.
  • the gateway 1 periodically communicates with the server device 9 via the wireless communication device 3 to confirm whether or not the program stored in the ECU 2 has been updated.
  • the gateway 1 acquires the update program from the server device 9 and stores it in its own storage unit 12.
  • the gateway 1 performs the update process of the ECU 2 by transmitting the update program to the ECU 2 to be updated via the communication lines 1a, 1b, and 1c.
  • the ECU 2 receives the update program transmitted from the gateway 1 and stores it in its own 21b, and after receiving all the update programs, changes the program to be executed by itself to the stored update program. Update the program.
  • an example of mainly updating the program of the drive ECU 21 will be described.
  • the gateway 1 includes a processing unit (processor) 11, a storage unit (storage) 12, and first to fifth communication units (transceivers) 13a to 13d.
  • the processing unit 11 is configured by using, for example, an arithmetic processing unit such as a CPU (Central Processing Unit) or an MPU (Micro-Processing Unit), and variously by reading and executing a computer program 12a stored in the storage unit 12. Performs arithmetic processing.
  • the processing unit 11 performs processing for relaying data transmission / reception between communication lines 1a to 1e of the in-vehicle network, and arithmetic processing necessary for updating the ECU 2.
  • the storage unit 12 is configured by using a non-volatile memory element such as a flash memory or an EEPROM (Electrically Erasable Programmable Read Only Memory).
  • the storage unit 12 stores various programs executed by the processing unit 11 and various data required for processing by the processing unit 11.
  • the storage unit 12 stores the computer program 12a executed by the processing unit 11.
  • the computer program 12a may be written in the storage unit 12 at the manufacturing stage of the gateway 1, for example, and the gateway 1 may acquire what is distributed by the remote server device 9 or the like by communication, for example.
  • the gateway 1 may read out what is recorded on the recording medium 101 such as a memory card or an optical disk and store it in the storage unit 12, or the writing device reads out what is recorded on the recording medium 101 and stores the gateway 1. It may be written in the storage unit 12.
  • the computer program 12a may be provided in the form of distribution via the network, or may be provided in the form of being recorded on the recording medium 101.
  • the gateway 1 includes a first communication unit 13a, a second communication unit 13b, a third communication unit 13c, a fourth communication unit 13d, and a fifth communication unit 13e.
  • the first communication unit 13a, the second communication unit 13b, the third communication unit 13c, the fourth communication unit 13d, and the fifth communication unit 13e are connected to the communication lines 1a to 1e constituting the in-vehicle network, respectively, and have a predetermined communication protocol. Data is transmitted and received to and from the ECU 2, the server device 9, and the diagnostic tool 5 according to the above.
  • the first to fifth communication units 13a to 13d transmit and receive data based on the communication standard of CAN, but the communication standard may be anything other than CAN.
  • the first to fifth communication units 13a to 13d transmit information by converting the data given from the processing unit 11 into an electric signal and outputting it to the communication lines 1a to 1e, and the potentials of the communication lines 1a to 1e. Data is received by sampling and acquiring the data, and the received data is given to the processing unit 11.
  • the four first to fifth communication units 13a to 13d included in the gateway 1 may communicate according to different communication protocols.
  • FIG. 3 is a schematic view showing the configuration of the drive ECU 21.
  • the drive ECU 21 includes a control unit (processor) 21a, a storage unit 21b (storage) 21b, an ECU communication unit (transceiver) 21c, and the like.
  • Various sensors, actuators, and the like are connected to the control unit 21a according to the function of the ECU 2.
  • the control unit 21a is configured by using an arithmetic processing unit such as a CPU or an MPU, and performs various arithmetic processing by reading and executing the program 21d stored in the storage unit 21b.
  • the contents of the program 21d stored in the storage unit 21b are different for each ECU 2.
  • the storage unit 21b is configured by using a non-volatile memory element such as a flash memory or EEPROM.
  • the storage unit 21b stores the program 21d executed by the control unit 21a and the data necessary for executing the program 21d.
  • the earliest program 21d may be written in the storage unit 21b at the manufacturing stage of the drive ECU 21, for example, and the drive ECU 21 reads out what is recorded on a recording medium such as a memory card or an optical disk and stores it in the storage unit 21b.
  • a recording medium such as a memory card or an optical disk and stores it in the storage unit 21b.
  • what is recorded on the recording medium may be read by the writing device and written in the storage unit 21b of the drive ECU 21.
  • the drive ECU 21 after the drive ECU 21 is mounted on the vehicle C, the drive ECU 21 receives an update program transmitted from the gateway 1 via the communication line 1a, and the drive ECU 21 receives the received update program.
  • the program 21d of the storage unit 21b is updated.
  • the storage unit 21b of the drive ECU 21 is provided with two areas for storing the program 21d. Both of the two regions have a sufficient storage capacity for storing the program 21d.
  • the control unit 21a reads the program 21d from one area of the storage unit 21b and performs processing, and the update program received from the gateway 1 is stored in the other area of the storage unit 21b. After completing all reception of the update program from the gateway 1, the drive ECU 21 updates the program 21d by switching the area in which the control unit 21a reads the program 21d.
  • the ECU communication unit 21c is connected to the communication line 1a constituting the in-vehicle network, and transmits / receives data according to, for example, the CAN communication protocol.
  • the ECU communication unit 21c transmits the data by converting the data given from the control unit 21a into an electric signal and outputting it to the communication line 1a, and collects the data by sampling the potential of the communication line 1a. Receive and give the received data to the control unit 21a.
  • FIGS. 6, 7A and 7B, and 8A, 8B and 8C are explanatory views showing the program update method.
  • the processing unit 11 of the gateway 1 determines whether or not an update request has been received from the server device 9 (step S11). If it is determined that the update request has not been received (step S11: NO), the processing unit 11 waits until the update request is received.
  • step S11 When it is determined that the update request has been received (step S11: YES), the processing unit 11 receives the update program transmitted from the server device 9 that is the source of the update request, so that the update program used for the update process is received. (Step S12).
  • the processing unit 11 determines whether or not the diagnostic tool 5 is connected to the fifth communication unit 13e or the connector 4 of the gateway 1 (step S13). As shown in FIG. 6, when it is determined that the diagnostic tool 5 is connected (step S13: YES), the processing unit 11 does not execute the process of detecting the presence or absence of the person A existing inside or outside the vehicle. Using the update program acquired in step S12, the update process of the program 21d stored in the storage unit 21b of the ECU 2 is executed (step S14). When the notification of the completion of the update process of the program 21d is received from the ECU 2, the processing unit 11 finishes the program update process.
  • the processing unit 11 receives the outside detection result transmitted from the peripheral detection ECU 22 by the second communication unit 13b (step S15).
  • the processing unit 11 receives the in-vehicle detection result transmitted from the seating detection ECU 24a and the grip detection ECU 24b in the second communication unit 13b (step S16).
  • the processing unit 11 determines whether or not a person A exists in the vicinity of the vehicle and in the vehicle based on the in-vehicle detection result and the out-of-vehicle detection result received in steps S15 and S16 (step S17). As shown in FIG.
  • step S17 when it is determined that the person A exists around the vehicle and inside the vehicle (step S17: YES), the processing unit 11 returns the process to step S15 and continues monitoring around the vehicle and inside the vehicle. That is, the processing unit 11 waits without executing the program update process.
  • step S17 When it is determined that there is no person A around the vehicle and in the vehicle (step S17: NO), the absence time of the person A around the vehicle and in the vehicle, that is, a predetermined time after it is determined that the person A does not exist around the vehicle and in the vehicle. Is determined (step S18). When it is determined that the absence time of the person A is within a predetermined time (step S18: NO), the processing unit 11 returns the processing to step S15 and continues monitoring around the vehicle and inside the vehicle.
  • step S18 when it is determined that a predetermined time has elapsed since it was determined that the person A does not exist around the vehicle and in the vehicle (step S18: YES), the processing unit 11 orders the door of the vehicle C to be locked.
  • the signal is transmitted to the locking / unlocking ECU 25 by the third communication unit 13c (step S19).
  • the door of vehicle C is locked by transmitting the lock command signal.
  • the processing unit 11 starts the update processing of the program 21d stored in the storage unit 21b of the drive ECU 21 by using the update program acquired in step S12 (step S20).
  • the processing unit 11 receives the vehicle exterior detection result transmitted from the peripheral detection ECU 22 by the second communication unit 13b (step S21), and the vehicle interior detection transmitted from the seating detection ECU 24a and the grip detection ECU 24b. The result is received by the second communication unit 13b (step S22). The processing unit 11 determines whether or not a person A exists in the vicinity of the vehicle and in the vehicle based on the outside detection result and the in-vehicle detection result received in steps S21 and S22 (step S23).
  • step S24 communication is performed with the locking / unlocking ECU 25 to determine whether or not the unlocking operation has been performed.
  • the processing unit 11 communicates with the ECU 2 and determines whether or not the update process of the program 21d is completed (step S25).
  • the ECU 2 is configured to give a completion signal to the gateway 1 when the update of the program 21d is completed, and the processing unit 11 completes the update depending on whether or not the completion signal transmitted from the ECU 2 is received. It can be determined whether or not. As shown in FIG.
  • step S25: NO when it is determined that there is no person A around the vehicle or in the vehicle and the update of the program 21d is not completed (step S25: NO), the processing unit 11 returns the processing to step S21 and programs. While continuing the update process, the monitoring of the person A around the vehicle and in the vehicle is continued. When it is determined that the update process of the program 21d is completed (step S25: YES), the processing unit 11 ends the process.
  • the processing unit 11 suspends the update processing of the program 21d (step S26). Specifically, the processing unit 11 transmits a pause command signal instructing the suspension of the update to the drive ECU 21. The drive ECU 21 that has received the pause command signal suspends the update process of the program 21d.
  • the processing unit 11 receives the vehicle exterior detection result transmitted from the peripheral detection ECU 22 by the second communication unit 13b (step S27), and the second communication the vehicle interior detection result transmitted from the seating detection ECU 24a and the grip detection ECU 24b. Received by unit 13b (step S28). The processing unit 11 determines whether or not a person A exists in the vicinity of the vehicle and in the vehicle based on the outside detection result and the in-vehicle detection result received in steps S27 and S28 (step S29).
  • step S29 When it is determined that the person A exists around the vehicle and inside the vehicle (step S29: YES), the processing unit 11 returns the processing to step S27 and continues monitoring around the vehicle and inside the vehicle.
  • step S29: NO When it is determined that there is no person A around the vehicle and in the vehicle (step S29: NO), the absence time of the person A around the vehicle and in the vehicle, that is, a predetermined time after it is determined that the person A does not exist around the vehicle and in the vehicle. Is determined (step S30). When it is determined that the absence time of the person A is within a predetermined time (step S30: NO), the processing unit 11 returns the processing to step S27 and continues monitoring around the vehicle and inside the vehicle.
  • step S30 When it is determined that a predetermined time has elapsed since it is determined that the person A does not exist around the vehicle or in the vehicle (step S30: YES), the processing unit 11 sends a lock command signal to the door of the vehicle C to the third communication unit 13c. Is transmitted to the locking / unlocking ECU 25 (step S31), the update process of the program 21d is restarted (step S32) as shown in FIG. 8C, and the process is returned to step S21. Specifically, the processing unit 11 transmits a restart command signal instructing the restart of the update process to the drive ECU 21. The drive ECU 21 that has received the restart command signal restarts the update process of the program 21d.
  • the gateway 1, the update processing method, and the computer program 12a according to the embodiment configured in this way, the program update of the in-vehicle device is performed after confirming that there is no person A around the vehicle and in the vehicle.
  • the program update process can be restricted.
  • the processing unit 11 executes the update process of the program 21d stored in the storage unit 21b after a lapse of a predetermined time after confirming that the person A does not exist around the vehicle. Therefore, it is possible to more reliably detect that the person A does not exist in the vicinity of the vehicle and avoid human damage caused by an unexpected situation related to the program update.
  • the processing unit 11 when the processing unit 11 detects a person A existing around the vehicle during the update processing of the program 21d, the processing unit 11 suspends the update processing and determines that the person A no longer exists again. After confirming, the update process of the program 21d is restarted. Therefore, the update process can be advanced in a state where the person A does not exist around the vehicle, and human damage caused by an unexpected situation related to the program update can be avoided.
  • the processing unit 11 suspends the update process when the door is unlocked during the update process of the program 21d. If the door is unlocked by remote control, the person A may approach the vehicle. Therefore, the update process can be stopped even when there is a possibility that the person A is present around the vehicle, and the human damage caused by the unexpected situation related to the program update can be avoided.
  • the processing unit 11 locks the door of the vehicle after a predetermined time has elapsed after confirming that there is no person A around the vehicle. Therefore, it is possible to prevent the person A from entering the vehicle during the program update and operating the vehicle, and it is possible to more reliably avoid the human damage caused by the unexpected situation related to the program update.
  • the update process of the program 21d is managed by a maintenance worker having specialized knowledge, so that the processing unit 11 is in the vicinity of the vehicle. Regardless of the presence or absence of the person A, the update process of the program 21d stored in the storage unit 21b can be executed. Therefore, it is possible to prevent the program update process from being interrupted unnecessarily, and the maintenance worker can efficiently perform the maintenance work of the vehicle.
  • the processing unit 11 can confirm that the person A does not exist in the vicinity of the vehicle by the in-vehicle camera 22a, and can execute the update process of the program 21d stored in the storage unit 21b.
  • the system can be configured at low cost.
  • the processing unit 11 confirms that there is no person A around the vehicle by the ultrasonic sensor 22b, the millimeter wave radar 22c, and the laser radar 22d in addition to the in-vehicle camera 22a. Therefore, it is possible to more reliably detect the person A around the vehicle and more reliably avoid human damage caused by an unexpected situation related to the program update.
  • the millimeter wave radar 22c is used, the person A can be detected regardless of the weather.
  • the laser radar 22d is used, the person A can be detected more accurately than other radars.
  • the repro master update processing device
  • the repro master may be configured separately from the gateway 1.
  • the program of the ECU 2 may be configured.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Automation & Control Theory (AREA)
  • Mechanical Engineering (AREA)
  • Stored Programmes (AREA)
  • Traffic Control Systems (AREA)

Abstract

車載更新装置は、プログラムを書き換え可能に記憶した記憶部を有する第1の車載装置と、車両周辺に存在する人を検知するセンサを有し、車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置とそれぞれ通信を行う通信部と、記憶部が記憶したプログラムを更新するための更新用プログラムを外部から取得し、取得した更新用プログラムにて記憶部が記憶するプログラムの更新処理を実行する処理部とを備え、処理部は、通信部にて受信した検知結果に基づき、車両周辺に人が存在しないと判定した場合、更新用プログラムにて記憶部が記憶するプログラムの更新処理を実行する。

Description

車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム
 本開示は、車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラムに関する。
 本出願は、2019年3月8日出願の日本出願第2019-042788号に基づく優先権を主張し、前記日本出願に記載された全ての記載内容を援用するものである。
 従来、車両には複数のECU(Electronic Control Unit)などの車載装置が搭載され、複数のECUがCAN(Controller Area Network)バスなどの通信線を介して接続されて相互に情報の送受信を行うことが可能とされている。各ECUは、フラッシュメモリ又はEEPROM(Electrically Erasable Programmable Read Only Memory)等の記憶部に記憶されたプログラムをCPU(Central Processing Unit)などの処理装置が読み出して実行することにより、車両の制御などの種々の処理を行っている。ECUの記憶部に記憶されたプログラムは、例えば機能追加、不具合の修正又はバージョンアップ等の必要が生じた際には、新たなプログラムに書き換える更新処理を行う必要がある。この場合、更新処理の対象となるECUに対して、通信線を介して更新用のプログラムを送信することが行われている。
 特許文献1においては、車両のユーザにより操作可能な端末からの要求に応じてプログラムを更新する際、ユーザに運転可否を報知することができる車両用装置が提案されている。
特開2017-220091号公報
 本開示の車載更新装置は、プログラムを書き換え可能に記憶した記憶部を有する第1の車載装置と、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置とそれぞれ通信を行う通信部と、前記記憶部が記憶した前記プログラムを更新するための更新用プログラムを外部から取得し、取得した前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する処理部とを備え、前記処理部は、前記通信部にて受信した前記検知結果に基づき、前記車両周辺に人が存在しないと判定した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する。
 本開示の更新処理方法は、第1の車載装置が有する記憶部が記憶したプログラムの更新処理を実行する更新処理方法であって、前記記憶部が記憶した前記プログラムを更新するための更新用プログラムを外部から取得するステップと、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置と通信を行うステップと、受信した前記検知結果に基づき、前記車両周辺に人が存在するか否かを判定するステップと、前記車両周辺に人が存在しないと判定した場合、取得した前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行するステップとを備える。
 本開示のコンピュータプログラムは、コンピュータに、第1の車載装置が有する記憶部が記憶したプログラムの更新処理を実行させるためのコンピュータプログラムであって、前記コンピュータに、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置と通信を行うステップと、受信した前記検知結果に基づき、前記車両周辺に人が存在するか否かを判定するステップと、前記車両周辺に人が存在しないと判定した場合、前記プログラムを更新するための、外部から取得した更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行するステップとを実行させる。
 なお、本願は、このような特徴的な処理部を備える更新処理装置として実現することができるだけでなく、上記の通り、かかる特徴的な処理をステップとする更新処理方法として実現したり、かかるステップをコンピュータに実行させるためのプログラムとして実現したりすることができる。また、更新処理装置の一部又は全部を実現する半導体集積回路として実現したり、更新処理装置を含むその他のシステムとして実現したりすることができる。
本実施形態に係る更新処理システムの構成を示す模式図である。 本実施形態に係る更新処理システム及びゲートウェイの構成を示す模式図である。 駆動ECUの構成を示す模式図である。 プログラム更新処理の手順を示すフローチャートである。 プログラム更新処理の手順を示すフローチャートである。 プログラム更新方法を示す説明図である。 プログラム更新方法を示す説明図である。 プログラム更新方法を示す説明図である。 プログラム更新方法を示す説明図である。 プログラム更新方法を示す説明図である。 プログラム更新方法を示す説明図である。
[本開示が解決しようとする課題]
 車載装置のプログラム更新によって車両が予期せぬ動作をし、車両周辺の人に危険が及ぶ可能性があるという技術的問題があった。特許文献1においては、車両周辺の人に危険が及ぶ不測の事態については考慮されていない。
 本開示の目的は、少なくとも車両周辺に人が存在しないことを確認した上で車載装置のプログラム更新処理を実行し、車両周辺に人が存在する場合、プログラム更新処理を制限することができる車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラムを提供することにある。
[本開示の効果]
 本開示によれば、少なくとも車両周辺に人が存在しないことを確認した上で車載装置のプログラム更新処理を実行し、車両周辺に人が存在する場合、プログラム更新処理を制限することができる車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラムを提供することができる。
[本開示の実施形態の説明]
 最初に本開示の実施態様を列記して説明する。また、以下に記載する実施形態の少なくとも一部を任意に組み合わせてもよい。
(1)本態様に係る車載更新装置は、プログラムを書き換え可能に記憶した記憶部を有する第1の車載装置と、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置とそれぞれ通信を行う通信部と、前記記憶部が記憶した前記プログラムを更新するための更新用プログラムを外部から取得し、取得した前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する処理部とを備え、前記処理部は、前記通信部にて受信した前記検知結果に基づき、前記車両周辺に人が存在しないと判定した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する。
 本態様にあっては、処理部は、第1の車載装置の記憶部が記憶するプログラムを更新するための更新プログラムを外部から取得する。処理部は、取得した更新プログラムを用いて、上記記憶部が記憶するプログラムの更新処理を実行する際、第2の車載装置から送信された検知結果を通信部にて受信する。検知結果は、車両周辺に存在する人の有無を示す情報である。処理部は、受信した検知結果に基づいて、車両周辺に人が存在するか否かを判定し、車両周辺に人が存在しないと判定した場合に、上記プログラムの更新処理を実行する。つまり、車両周辺に人が存在しない場合、処理部は上記記憶部が記憶するプログラムの更新処理を実行しない。
 従って、プログラム更新処理の不具合によって車両が予期せぬ動作を行った場合であっても、車両周辺に人が存在しないため、プログラム更新に係る不測の事態が発生しても人的被害を回避することができる。
(2)前記通信部は、車内の人を検知するセンサを有し、前記車内の人の有無を示す車内検知結果を送信する第3の車載装置と通信を行うようにしてあり、前記処理部は、前記通信部にて受信した前記検知結果及び前記車内検知結果に基づき、前記車両周辺及び前記車内に人が存在しないと判定した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する構成が好ましい。
 本態様にあっては、処理部は、上記記憶部が記憶するプログラムの更新処理を実行する際、第3の車載装置から送信された車内検知結果を通信部にて受信する。車内検知結果は、車内に存在する人の有無を示す情報である。処理部は、受信した検知結果及び車内検知結果に基づいて、車両周辺及び車内に人が存在するか否かを判定し、車両周辺及び車内に人が存在しないと判定した場合に、上記プログラムの更新処理を実行する。つまり、車両周辺及び車内に人が存在しない場合、処理部は上記記憶部が記憶するプログラムの更新処理を実行しない。
 従って、プログラム更新処理の不具合によって車両が予期せぬ動作を行った場合であっても、車両周辺及び車内に人が存在しないため、プログラム更新に係る不測の事態が発生しても人的被害を回避することができる。
(3)前記処理部は、人が存在しないことを確認してから所定時間が経過した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する構成が好ましい。
 本態様にあっては、処理部は、車両周辺に人が存在しないことを確認してから所定時間経過後に上記記憶部が記憶するプログラムの更新処理を実行する。従って、車両周辺に人が存在しないことをより確実に検知し、プログラム更新に係る不測の事態に起因する人的被害を回避することができる。
(4)前記処理部は、前記プログラムの更新処理中、前記車両周辺に人が存在すると判定した場合、前記第1の車載装置による前記プログラムの更新処理を停止し、再び前記車両周辺に人が存在しないと判定されてから所定時間が経過した場合、前記プログラムの更新処理を再開させる構成が好ましい。
 本態様にあっては、処理部は、プログラムの更新処理中に、車両周辺に存在する人が検知された場合、更新処理を一時停止する。処理部は、再び人が存在しないと判定されてから所定時間が経過した場合、上記プログラムの更新処理を再開させる。従って、車両周辺に人が存在しない状態で更新処理を進行させることができ、プログラム更新に係る不測の事態に起因する人的被害を回避することができる。
(5)前記処理部は、車両のドアの解錠操作が行われた場合、前記記憶部が記憶する前記プログラムの更新処理を停止させる構成が好ましい。
 本態様にあっては、処理部は、プログラムの更新処理中に、ドアの解錠操作が行われた場合、更新処理を一時停止する。遠隔操作にてドアの解錠操作が行われた場合、車両に人が接近する可能性がある。従って、車両周辺に人が存在する可能性がある場合も更新処理を停止させることができ、プログラム更新に係る不測の事態に起因する人的被害を回避することができる。
(6)前記車両周辺に存在する人が検知されず、所定時間が経過した場合、車両のドアの施錠を指示する施錠命令信号を前記通信部に送信させる構成が好ましい。
 本態様にあっては、処理部は、車両周辺に人が存在しないことを確認してから所定時間経過後に車両のドアを施錠する。従って、プログラム更新中の車内に人が入って、車両が操作させることを防ぐことができ、プログラム更新に係る不測の事態に起因する人的被害をより確実に回避することができる。
(7)車両の保守に係る通信装置が、自装置及び前記第1の車載装置が接続された車内ネットワークに接続された場合、前記車両周辺に存在する人の有無に拘わらず前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する構成が好ましい。
 本態様にあっては、車両の保守に係る通信装置が車内ネットワークに接続された場合、専門知識を有する保守作業者によってプログラムの更新処理が管理されている状況にあるため、処理部は、車両周辺の人の有無にかかわらす、記憶部が記憶するプログラムの更新処理を実行することができる。従って、不必要にプログラム更新処理が中断されることを防ぎ、保守作業者は効率的に車両の保守作業を行うことができる。
(8)前記検知結果は、前記車両周辺を撮像する車載カメラ又はレーダにて前記車両周辺に存在する人を検知した結果を含む構成が好ましい。
 本態様にあっては、車載カメラ又はレーダにて車両周辺に人が存在しないことを確認し、上記記憶部が記憶するプログラムの更新処理を実行することができる。
 車載カメラを利用することによって、低コストでシステムを構成することができる。車載カメラには赤外線カメラ等、可視光外で撮像するカメラも含まれる。
 レーダは、電波又は超音波を照射し、対象物からの反射波を検出して人を検知する。レーダには、ミリ波レーダ、超音波センサ、赤外線センサ、レーザースキャナー等が含まれる。
(9)本態様に係る更新処理システムは、態様(1)から態様(8)のいずれか一つの車載更新装置と、前記プログラムを書き換え可能に記憶した前記記憶部を有する第1の車載装置と、前記車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す前記検知結果を送信する第2の車載装置とを備える。
 本態様にあっては、態様(1)同様、車載装置のプログラム更新処理の不具合によって車両が予期せぬ動作を行った場合であっても、車両周辺に人が存在しないため、プログラム更新に係る不測の事態が発生しても人的被害を回避することができる。
(10)本態様に係る更新処理方法は、第1の車載装置が有する記憶部が記憶したプログラムの更新処理を実行する更新処理方法であって、前記記憶部が記憶した前記プログラムを更新するための更新用プログラムを外部から取得するステップと、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置と通信を行うステップと、受信した前記検知結果に基づき、前記車両周辺に人が存在するか否かを判定するステップと、前記車両周辺に人が存在しないと判定した場合、取得した前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行するステップとを備える。
 本態様にあっては、態様(1)同様、車載装置のプログラム更新処理の不具合によって車両が予期せぬ動作を行った場合であっても、車両周辺に人が存在しないため、プログラム更新に係る不測の事態が発生しても人的被害を回避することができる。
(11)本態様に係るコンピュータプログラムは、コンピュータに、第1の車載装置が有する記憶部が記憶したプログラムの更新処理を実行させるためのコンピュータプログラムであって、前記コンピュータに、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置と通信を行うステップと、受信した前記検知結果に基づき、前記車両周辺に人が存在するか否かを判定するステップと、前記車両周辺に人が存在しないと判定した場合、前記プログラムを更新するための、外部から取得した更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行するステップとを実行させる。
 本態様にあっては、コンピュータを態様(1)に係る更新処理装置として機能させることができ、車載装置のプログラム更新処理の不具合によって車両が予期せぬ動作を行った場合であっても、車両周辺に人が存在しないため、プログラム更新に係る不測の事態が発生しても人的被害を回避することができる。
[本開示の実施形態の詳細]
 本開示の実施形態に係る給電制御装置及び給電制御方法の具体例を、以下に図面を参照しつつ説明する。なお、本開示はこれらの例示に限定されるものではなく、請求の範囲によって示され、請求の範囲と均等の意味及び範囲内でのすべての変更が含まれることが意図される。
 以下、本開示をその実施形態を示す図面に基づいて具体的に説明する。
 図1は、本実施形態に係る更新処理システム100の構成を示す模式図、図2は、本実施形態に係る更新処理システム100及びゲートウェイ(車載更新装置)1の構成を示す模式図である。本実施の形態に係る更新処理システム100は、車両Cに搭載された複数のECU2と、1つの無線通信装置3と、1つのゲートウェイ1とを備える。
 各ECU2は、通信線1a、1b又は1cのいずれかに接続されており、接続された通信線1a、1b又は1cを介した通信を行うことができる。図2に示す例においては、通信線1aに駆動ECU(第1の車載装置)21が接続され、通信線1bに周辺検知ECU(第2の車載装置)22、停車検知ECU23、着座検知ECU(第3の車載装置)24a、把持検知ECU(第3の車載装置)24bが接続され、通信線1cに施解錠ECU25が接続されている。本実施形態では、これらを総括して適宜ECU2と呼ぶ。ゲートウェイ1は通信線1a、1b、1c間の通信を中継し、これにより複数のECU2は通信線1a、1b、1c及びゲートウェイ1を介して通信を行うことができる。
 駆動ECU21は、例えば車両Cのエンジンの動作を制御するECU2である。駆動ECU21の構成は後述する。
 周辺検知ECU22は、車両周辺を撮像する車載カメラ22a、車両周辺に存在する物体を検知するための超音波センサ22b、ミリ波レーダ22c、レーザレーダ(LIDAR:light detection and ranging)22dに接続されている。車載カメラ22aは、単眼カメラ、ステレオカメラのいずれも利用することができる。また、車載カメラ22aは、可視光にて人Aを撮像するものであっても良いし、赤外線にて人Aを撮像するものであっても良い。本実施形態に係る周辺検知ECU22は、車載カメラ22aにて撮像された画像、超音波センサ22b、ミリ波レーダ22c、レーザレーダ22d(LIDAR)等の検出データに基づいて、車両周辺に存在する人Aを検知する。人Aには、歩行者のみならず、二輪車に乗っている人A等も含まれる。人Aの識別は、例えばディープラーニングによって学習された学習済モデルを用いて行えば良い。ディープラーニングは、機械学習の一種であり、画像及び各センサ、レーダの検出結果を所定のクラスに分類するものである。周辺検知ECU22は、車両周辺に存在する人A以外の静止障害物のオブジェクト画像、人Aのオブジェクト画像、車両周辺に存在する建物、車両C等の物体のオブジェクト画像等を大量に学習し、人A等の特徴と、各特徴に対応するクラスとを関連付ける重み係数を学習結果として記憶している。周辺検知ECU22は、取得した画像データ及び各センサの検出結果を学習済モデルに入力することによって、検出対象が属するクラスを特定する。クラスの特定によって、検出対象が人Aであるか否かが特定される。周辺検知ECU22は、車両周辺に人Aが存在するか否かを示す車外検知結果をゲートウェイ1へ送信する。ゲートウェイ1は、周辺検知ECU22から送信された車外検知結果を受信し、受信した車外検知結果に基づいて、車両周辺に人Aが存在するか否かを判定することができる。
 停車検知ECU23は、例えば、車速センサ、車両Cのシフトレバーの位置に応じた信号を出力するポジションスイッチ、イグニッションスイッチ等に接続されている。車速センサは、例えば車輪速センサであり、車輪の回転速度に応じたパルス信号を出力する。停車検知ECU23は、車速センサ、ポジションスイッチ、イグニッションスイッチ等が出力する信号に基づいて車両Cが停車しているか否かを判定し、車両Cが停止しているか否かを示す停車検知結果をゲートウェイ1へ出力する。ゲートウェイ1は、停車検知ECU23から送信された停車検知結果を受信し、受信した停車検知結果に基づいて、車両Cが停止しているか否かを判定することができる。
 着座検知ECU24aは、車両Cの座席に埋め込まれた感圧センサ、重量センサ等を有し、当該座席に乗員が座っているか否かを検出し、車内検知結果をゲートウェイ1へ送信する。ゲートウェイ1は着座検知ECU24aから送信される車内検知結果を受信し、受信した車内検知結果に基づいて、車両に人Aが存在するか否かを判定することができる。
 把持検知ECU24bは、ステアリングホイールに設けられたタッチセンサを有する。タッチセンサは例えば静電容量センサであり、把持検知ECU24bは、タッチセンサの信号に基づいて、運転者がステアリングホイールを把持しているか否かを判定する。把持検知ECU24bは、ステアリングホイールが把持されているか否かを示した車内検知結果をゲートウェイ1へ送信する。ゲートウェイ1は着座検知ECU24aから送信される車内検知結果を受信し、受信した車内検知結果に基づいて、車両に人Aが存在するか否かを判定することができる。
 施解錠ECU25は、車両ドアの施錠及び解錠を行う図示しない施解錠装置を駆動するアクチュエータに接続されている。車両ドアのリクエストスイッチが操作され、正規の携帯機がドア付近にある場合、施解錠ECU25は、施解錠装置を駆動させ、車両ドアを施錠又は解錠する。また、正規の携帯機からドアの施解錠を指示する信号が送信され、当該信号を受信した場合、施解錠ECU25は、施解錠装置を駆動させ、車両ドアを施錠又は解錠する。なお、リクエストスイッチの操作状態の検知、携帯機との間の無線通信処理、携帯機の位置検出、携帯機の認証処理等は他のECU2が実行すると良い。施解錠ECU25は、当該他のECU2から、リクエストスイッチの操作状態、携帯機の位置検出結果、認証結果、携帯機から無線送信された施解錠を指示する信号等を受信すれば良い。
 また、施解錠ECU25は、ドアの施解錠状態を示す情報を、通信線1cを介してゲートウェイ1へ送信することができる。ゲートウェイ1は、施解錠ECU25から送信される当該情報を受信することによって、ドアの施解錠状態を認識することができる。
 本実施の形態に係る更新処理システム100では、ゲートウェイ1に通信線1dを介して無線通信装置3が接続されている。ゲートウェイ1は、無線通信装置3を介して車両Cの外部に設置されたサーバ装置9との通信を行うことができる。
 無線通信装置3は、例えば携帯電話通信網又は無線LAN(Local Area Network)等の無線通信を行うことによって、車両Cの外部に設置されたサーバ装置9との間で通信を行うことができる。無線通信装置3は、ゲートウェイ1及びサーバ装置9の間の通信を中継することができ、ゲートウェイ1から与えられたデータをサーバ装置9へ送信すると共に、サーバ装置9から受信したデータをゲートウェイ1へ与える。
 サーバ装置9は、車両Cに搭載されるECU2にて実行されるプログラムを管理及び記憶している。サーバ装置9は、車両Cからの問合わせに応じて、各ECU2が記憶するプログラムなどの更新が必要であるか否かを通知すると共に、更新が必要である場合には更新用のプログラムを車両Cへ配信する処理を行う。ゲートウェイ1は、サーバ装置9と通信を行い、ECU2が記憶する後述のプログラム21dを更新するための更新プログラムを取得し、取得した更新プログラムをECU2へ送信することができる。
 車両Cの適所には外部の機器を有線で接続するためのコネクタ4が設けられている。ゲートウェイ1は通信線1eにてコネクタ4に接続されている。コネクタ4には、例えば通信ケーブルを介してダイアグツール5が着脱可能に接続される。これによりゲートウェイ1は、通信線1e、コネクタ4及び通信ケーブルを介してダイアグツール5との通信を行うことができる。
 ダイアグツール5は、例えば車両Cのディーラ又は整備工場等に備えられる装置であり、車両Cの不具合の検査又は設定変更等を作業者が行うための装置である。ダイアグツール5は、例えば操作部及び表示部等を有する可搬型の装置である。作業者がダイアグツール5の通信ケーブルを車両Cのコネクタ4に接続し、適宜の認証処理などを経た後で、ダイアグツール5及び車両Cのゲートウェイ1が通信可能となる。
 本実施の形態に係る更新処理システム100では、ゲートウェイ1が無線通信装置3を介して定期的にサーバ装置9との通信を行い、ECU2が記憶しているプログラムの更新の有無を確認する。更新がある場合、ゲートウェイ1は、更新用プログラムをサーバ装置9から取得して自身の記憶部12に記憶する。更新用プログラムの取得が完了した後、ゲートウェイ1は、通信線1a、1b、1cを介して更新対象のECU2へ更新用プログラムを送信することによって、ECU2の更新処理を行う。ECU2は、ゲートウェイ1から送信された更新用プログラムを受信して自身の21bに蓄積し、更新用プログラムを全て受信し終えた後に自身の実行するプログラムを蓄積した更新用プログラムに変更することによって、プログラムの更新を行う。以下、本実施形態では、主に駆動ECU21のプログラムを更新する例を説明する。
 本実施の形態に係るゲートウェイ1は、図2に示すように、処理部(プロセッサ)11、記憶部(ストレージ)12及び第1~第5通信部(トランシーバ)13a~13d等を備える。処理部11は、例えばCPU(Central Processing Unit)又はMPU(Micro-Processing Unit)等の演算処理装置を用いて構成され、記憶部12に記憶されたコンピュータプログラム12aを読み出して実行することにより、種々の演算処理を行う。本実施の形態において処理部11は、車内ネットワークの通信線1a~1e間のデータ送受信を中継する処理、及び、ECU2の更新処理等に必要な演算処理を行う。
 記憶部12は、フラッシュメモリ又はEEPROM(Electrically Erasable Programmable Read Only Memory)等の不揮発性のメモリ素子を用いて構成されている。記憶部12は、処理部11が実行する各種のプログラム、及び、処理部11の処理に必要な各種のデータを記憶する。本実施の形態において記憶部12は、処理部11が実行するコンピュータプログラム12aを記憶している。なおコンピュータプログラム12aは、例えばゲートウェイ1の製造段階において記憶部12に書き込まれてもよく、また例えば遠隔のサーバ装置9などが配信するものをゲートウェイ1が通信にて取得してもよく、また例えばメモリカード又は光ディスク等の記録媒体101に記録されたものをゲートウェイ1が読み出して記憶部12に記憶してもよく、また例えば記録媒体101に記録されたものを書込装置が読み出してゲートウェイ1の記憶部12に書き込んでもよい。コンピュータプログラム12aは、ネットワークを介した配信の態様で提供されてもよく、記録媒体101に記録された態様で提供されてもよい。
 ゲートウェイ1は、第1通信部13a、第2通信部13b、第3通信部13c、第4通信部13d及び第5通信部13eを備える。第1通信部13a、第2通信部13b、第3通信部13c、第4通信部13d及び第5通信部13eは、車内ネットワークを構成する通信線1a~1eにそれぞれ接続され、所定の通信プロトコルに従ってECU2、サーバ装置9、ダイアグツール5とデータの送受信を行う。本実施の形態において、第1~第5通信部13a~13dはCANの通信規格に基づくデータの送受信を行うものとするが、通信規格はCAN以外のどのようなものであってもよい。第1~第5通信部13a~13dは、処理部11から与えられたデータを電気信号に変換して通信線1a~1eへ出力することによって情報を送信すると共に、通信線1a~1eの電位をサンプリングして取得することによりデータを受信し、受信したデータを処理部11へ与える。なおゲートウェイ1が備える4つの第1~第5通信部13a~13dは、それぞれ異なる通信プロトコルに従って通信を行うものであってもよい。
 図3は、駆動ECU21の構成を示す模式図である。なお本図においては、車両Cに搭載された複数のECU2のうち、駆動ECU21の構成を図示しているが、他のECU2についても同様の構成である。駆動ECU21は、制御部(プロセッサ)21a、記憶部21b(ストレージ)21b及びECU通信部(トランシーバ)21c等を備える。制御部21aには、ECU2の機能に応じて、各種センサ、アクチュエータ等が接続されている。制御部21aは、例えばCPU又はMPU等の演算処理装置を用いて構成され、記憶部21bに記憶されたプログラム21dを読み出して実行することにより、種々の演算処理を行う。なお記憶部21bに記憶されるプログラム21dは、ECU2毎にその内容が異なっている。
 記憶部21bは、フラッシュメモリ又はEEPROM等の不揮発性のメモリ素子を用いて構成されている。記憶部21bは、制御部21aが実行するプログラム21dと、このプログラム21dの実行に必要なデータとを記憶する。最初期のプログラム21dは、例えば駆動ECU21の製造段階において記憶部21bに書き込まれてもよく、また例えばメモリカード又は光ディスク等の記録媒体に記録されたものを駆動ECU21が読み出して記憶部21bに記憶してもよく、また例えば記録媒体に記録されたものを書込装置が読み出して駆動ECU21の記憶部21bに書き込んでもよい。ただし本実施の形態においては、駆動ECU21が車両Cに搭載された後、ゲートウェイ1から通信線1aを介して送信された更新用プログラムを駆動ECU21が受信し、受信した更新用プログラムにより駆動ECU21が記憶部21bのプログラム21dを更新する。
 本実施の形態において駆動ECU21の記憶部21bは、プログラム21dを記憶するための2つの領域が設けられている。2つの領域は、いずれもプログラム21dを記憶する十分な記憶容量を有している。制御部21aは記憶部21bの一方の領域からプログラム21dを読み出して処理を行い、ゲートウェイ1から受信した更新用プログラムが記憶部21bの他方の領域に記憶される。駆動ECU21は、ゲートウェイ1から更新用プログラムの全ての受信を完了した後、制御部21aがプログラム21dを読み出す領域を切り替えることによって、プログラム21dの更新を行う。
 ECU通信部21cは、車内ネットワークを構成する通信線1aに接続され、例えばCANの通信プロトコルに従ってデータの送受信を行う。ECU通信部21cは、制御部21aから与えられたデータを電気信号に変換して通信線1aへ出力することによってデータを送信すると共に、通信線1aの電位をサンプリングして取得することによりデータを受信し、受信したデータを制御部21aへ与える。
 図4及び図5は、プログラム更新処理の手順を示すフローチャート、図6、図7A及び図7B、並びに図8A、図8B及び図8Cは、プログラム更新方法を示す説明図である。
 ゲートウェイ1の処理部11は、サーバ装置9から更新要求を受信したか否かを判定する(ステップS11)。更新要求を受信していないと判定した場合(ステップS11:NO)、処理部11は、更新要求を受信するまで待機する。
 更新要求を受信したと判定した場合(ステップS11:YES)、処理部11は、更新要求の送信元のサーバ装置9から送信される更新用プログラムを受信することにより、更新処理に用いる更新用プログラムを取得する(ステップS12)。
 処理部11は、ゲートウェイ1の第5通信部13eないしコネクタ4にダイアグツール5が接続されているか否かを判定する(ステップS13)。図6に示すように、ダイアグツール5が接続されていると判定した場合(ステップS13:YES)、処理部11は、車内外に存在する人Aの有無を検知する処理を実行することなく、ステップS12で取得した更新用プログラムを用いて、ECU2の記憶部21bが記憶するプログラム21dの更新処理を実行する(ステップS14)。プログラム21dの更新処理完了の通知をECU2から受信すると、処理部11はプログラム更新処理を終える。
 ダイアグツール5が接続されていないと判定した場合(ステップS13:NO)、処理部11は、周辺検知ECU22から送信される車外検知結果を第2通信部13bにて受信する(ステップS15)。処理部11は、着座検知ECU24a、把持検知ECU24bから送信される車内検知結果を第2通信部13bにて受信する(ステップS16)。処理部11は、ステップS15及びステップS16で受信した車内検知結果及び車外検知結果に基づいて、車両周辺及び車内に人Aが存在するか否かを判定する(ステップS17)。図7Aに示すように、車両周辺及び車内に人Aが存在すると判定した場合(ステップS17:YES)、処理部11は処理をステップS15へ戻し、車両周辺及び車内の監視を継続する。つまり、処理部11は、プログラム更新処理を実行することなく、待機する。
 車両周辺及び車内に人Aが存在しないと判定した場合(ステップS17:NO)、車両周辺及び車内における人Aの不在時間、即ち車両周辺及び車内に人Aが存在しないと判定されてから所定時間が経過したか否かを判定する(ステップS18)。人Aの不在時間が所定時間以内であると判定した場合(ステップS18:NO)、処理部11は処理をステップS15へ戻し、車両周辺及び車内の監視を継続する。
 図7Bに示すように、車両周辺及び車内に人Aが存在しないと判定されてから所定時間が経過したと判定した場合(ステップS18:YES)、処理部11は、車両Cのドアの施錠命令信号を第3通信部13cにて施解錠ECU25へ送信する(ステップS19)。施錠命令信号の送信により、車両Cのドアは施錠される。次いで処理部11は、ステップS12で取得した更新用プログラムを用いて、駆動ECU21の記憶部21bが記憶するプログラム21dの更新処理を開始する(ステップS20)。
 更新処理を開始した後、処理部11は、周辺検知ECU22から送信される車外検知結果を第2通信部13bにて受信し(ステップS21)、着座検知ECU24a、把持検知ECU24bから送信される車内検知結果を第2通信部13bにて受信する(ステップS22)。処理部11は、ステップS21及びステップS22で受信した車外検知結果及び車内検知結果に基づいて、車両周辺及び車内に人Aが存在するか否かを判定する(ステップS23)。
 車両周辺及び車内に人Aが存在しないと判定した場合(ステップS23:NO)、施解錠ECU25と通信を行い、解錠操作が行われたか否かを判定する(ステップS24)。解錠操作が行われていないと判定した場合(ステップS24:NO)、処理部11は、ECU2と通信を行い、プログラム21dの更新処理が完了したか否かを判定する(ステップS25)。例えば、ECU2は、プログラム21dの更新が完了した場合、ゲートウェイ1に完了信号するように構成されており、処理部11はECU2から送信された完了信号を受信したか否かによって、更新が完了したか否かを判定することができる。図8Aに示すように、車両周辺及び車内に人Aがおらず、プログラム21dの更新が完了していないと判定した場合(ステップS25:NO)、処理部11は処理をステップS21へ戻し、プログラム更新処理を継続しながら車両周辺及び車内の人Aの監視を継続する。プログラム21dの更新処理が完了したと判定した場合(ステップS25:YES)、処理部11は処理を終える。
 図8Bに示すように、プログラム更新中において、車両周辺及び車内に人Aが存在すると判定した場合(ステップS23:YES)、又はドアの解錠操作が行われたと判定した場合(ステップS24:YES)、処理部11はプログラム21dの更新処理を一時停止させる(ステップS26)。具体的には、処理部11は、更新の一時停止を指示する一時停止命令信号を駆動ECU21へ送信する。一時停止命令信号を受信した駆動ECU21は、プログラム21dの更新処理を一時停止させる。
 次いで、処理部11は、周辺検知ECU22から送信される車外検知結果を第2通信部13bにて受信し(ステップS27)、着座検知ECU24a、把持検知ECU24bから送信される車内検知結果を第2通信部13bにて受信する(ステップS28)。処理部11は、ステップS27及びステップS28で受信した車外検知結果及び車内検知結果に基づいて、車両周辺及び車内に人Aが存在するか否かを判定する(ステップS29)。
 車両周辺及び車内に人Aが存在すると判定した場合(ステップS29:YES)、処理部11は処理をステップS27へ戻し、車両周辺及び車内の監視を継続する。
 車両周辺及び車内に人Aが存在しないと判定した場合(ステップS29:NO)、車両周辺及び車内における人Aの不在時間、即ち車両周辺及び車内に人Aが存在しないと判定されてから所定時間が経過したか否かを判定する(ステップS30)。人Aの不在時間が所定時間以内であると判定した場合(ステップS30:NO)、処理部11は処理をステップS27へ戻し、車両周辺及び車内の監視を継続する。
 車両周辺及び車内に人Aが存在しないと判定されてから所定時間が経過したと判定した場合(ステップS30:YES)、処理部11は、車両Cのドアの施錠命令信号を第3通信部13cにて施解錠ECU25へ送信し(ステップS31)、図8Cに示すように、プログラム21dの更新処理を再開させ(ステップS32)、処理をステップS21へ戻す。具体的には、処理部11は、更新処理の再開を指示する再開命令信号を駆動ECU21へ送信する。再開命令信号を受信した駆動ECU21は、プログラム21dの更新処理を再開させる。
 このように構成された実施形態に係る更新処理システム100、ゲートウェイ1、更新処理方法、コンピュータプログラム12aによれば、車両周辺及び車内に人Aが存在しないことを確認した上で車載装置のプログラム更新処理を実行し、車両周辺及び車内に人Aが存在する場合、プログラム更新処理を制限することができる。
 本実施形態によれば、処理部11は、車両周辺に人Aが存在しないことを確認してから所定時間経過後に記憶部21bが記憶するプログラム21dの更新処理を実行する。従って、車両周辺に人Aが存在しないことをより確実に検知し、プログラム更新に係る不測の事態に起因する人的被害を回避することができる。
 本実施形態によれば、処理部11は、プログラム21dの更新処理中に、車両周辺に存在する人Aが検知された場合、更新処理を一時停止し、再び人Aが存在しなくなったことを確認した上でプログラム21dの更新処理を再開させる。従って、車両周辺に人Aが存在しない状態で更新処理を進行させることができ、プログラム更新に係る不測の事態に起因する人的被害を回避することができる。
 本実施形態によれば、処理部11は、プログラム21dの更新処理中に、ドアの解錠操作が行われた場合、更新処理を一時停止する。遠隔操作にてドアの解錠操作が行われた場合、車両に人Aが接近する可能性がある。従って、車両周辺に人Aが存在する可能性がある場合も更新処理を停止させることができ、プログラム更新に係る不測の事態に起因する人的被害を回避することができる。
 本実施形態によれば、処理部11は、車両周辺に人Aが存在しないことを確認してから所定時間経過後に車両のドアを施錠する。従って、プログラム更新中に車内に人Aが入って、車両が操作させることを防ぐことができ、プログラム更新に係る不測の事態に起因する人的被害をより確実に回避することができる。
 本実施形態によれば、ダイアグツール5が車内ネットワークに接続された場合、専門知識を有する保守作業者によってプログラム21dの更新処理が管理されている状況にあるため、処理部11は、車両周辺の人Aの有無にかかわらす、記憶部21bが記憶するプログラム21dの更新処理を実行することができる。従って、不必要にプログラム更新処理が中断されることを防ぎ、保守作業者は効率的に車両の保守作業を行うことができる。
 本実施形態によれば、処理部11は、車載カメラ22aにて車両周辺に人Aが存在しないことを確認し、記憶部21bが記憶するプログラム21dの更新処理を実行することができる。車載カメラ22aを利用することによって、低コストでシステムを構成することができる。
 また、処理部11は、車載カメラ22aに加え、超音波センサ22b、ミリ波レーダ22c、レーザレーダ22dにて車両周辺に人Aが存在しないことを確認する。従って、より確実に車両周辺の人Aを検知し、プログラム更新に係る不測の事態に起因する人的被害をより確実に回避することができる。特に、ミリ波レーダ22cを用いれば、天候に左右されることなく、人Aを検知することができる。レーザレーダ22dを用いれば、他のレーダに比べてより精度良く人Aを検知することができる。
 なお、本実施形態では、ECU2のプログラム更新処理を制御するリプロマスタ(更新処理装置)をゲートウェイ1として構成する例を説明したが、リプロマスタをゲートウェイ1と別体で構成しても良い。また、ECU2のプログラムを構成する例を説明したが、車内ネットワークに有線接続又は無線接続される任意のリプロスレーブのプログラムを構成するように構成しても良い。
1 ゲートウェイ
1a,1b,1c,1d,1e 通信線
2 ECU
3 無線通信装置
4 コネクタ
5 ダイアグツール
9 サーバ装置
11 処理部
12 記憶部
13a 第1通信部
13b 第2通信部
13c 第3通信部
13d 第4通信部
13e 第5通信部
21 駆動ECU
22 施解錠ECU
23 周辺検知ECU
24a 着座検知ECU
24b 把持検知ECU
25 施解錠ECU
21a 制御部
21b 記憶部
21c ECU通信部
22a 車載カメラ
22b 超音波センサ
22c ミリ波レーダ
22d レーザレーダ
100 更新処理システム
C 車両
A 人
 

Claims (11)

  1.  プログラムを書き換え可能に記憶した記憶部を有する第1の車載装置と、車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置とそれぞれ通信を行う通信部と、
     前記記憶部が記憶した前記プログラムを更新するための更新用プログラムを外部から取得し、取得した前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する処理部と
     を備え、
     前記処理部は、
     前記通信部にて受信した前記検知結果に基づき、前記車両周辺に人が存在しないと判定した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する
     車載更新装置。
  2.  前記通信部は、
     車内の人を検知するセンサを有し、前記車内の人の有無を示す車内検知結果を送信する第3の車載装置と通信を行うようにしてあり、
     前記処理部は、
     前記通信部にて受信した前記検知結果及び前記車内検知結果に基づき、前記車両周辺及び前記車内に人が存在しないと判定した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する
     請求項1に記載の車載更新装置。
  3.  前記処理部は、
     人が存在しないことを確認してから所定時間が経過した場合、前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する
     請求項1又は請求項2に記載の車載更新装置。
  4.  前記処理部は、
     前記プログラムの更新処理中、前記車両周辺に人が存在すると判定した場合、前記第1の車載装置による前記プログラムの更新処理を停止し、再び前記車両周辺に人が存在しないと判定されてから所定時間が経過した場合、前記プログラムの更新処理を再開させる
     請求項1から請求項3のいずれか1項に記載の車載更新装置。
  5.  前記処理部は、
     車両のドアの解錠操作が行われた場合、前記記憶部が記憶する前記プログラムの更新処理を停止させる
     請求項1から請求項4のいずれか1項に記載の車載更新装置。
  6.  前記車両周辺に存在する人が検知されず、所定時間が経過した場合、車両のドアの施錠を指示する施錠命令信号を前記通信部に送信させる
     請求項1から請求項5のいずれか1項に記載の車載更新装置。
  7.  車両の保守に係る通信装置が、自装置及び前記第1の車載装置が接続された車内ネットワークに接続された場合、前記車両周辺に存在する人の有無に拘わらず前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行する
     請求項1から請求項6のいずれか1項に記載の車載更新装置。
  8.  前記検知結果は、
     前記車両周辺を撮像する車載カメラ又はレーダにて前記車両周辺に存在する人を検知した結果を含む
     請求項1から請求項4のいずれか1項に記載の車載更新装置。
  9.  請求項1から請求項8のいずれか1項に記載の車載更新装置と、
     前記プログラムを書き換え可能に記憶した前記記憶部を有する第1の車載装置と、
     前記車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す前記検知結果を送信する第2の車載装置と
     を備える更新処理システム。
  10.  第1の車載装置が有する記憶部が記憶したプログラムの更新処理を実行する更新処理方法であって、
     前記記憶部が記憶した前記プログラムを更新するための更新用プログラムを外部から取得するステップと、
     車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置と通信を行うステップと、
     受信した前記検知結果に基づき、前記車両周辺に人が存在するか否かを判定するステップと、
     前記車両周辺に人が存在しないと判定した場合、取得した前記更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行するステップと
     を備える更新処理方法。
  11.  コンピュータに、第1の車載装置が有する記憶部が記憶したプログラムの更新処理を実行させるためのコンピュータプログラムであって、
     前記コンピュータに、
     車両周辺に存在する人を検知するセンサを有し、該車両周辺に存在する人の有無を示す検知結果を送信する第2の車載装置と通信を行うステップと、
     受信した前記検知結果に基づき、前記車両周辺に人が存在するか否かを判定するステップと、
     前記車両周辺に人が存在しないと判定した場合、前記プログラムを更新するための、外部から取得した更新用プログラムにて前記記憶部が記憶する前記プログラムの更新処理を実行するステップと
     を実行させるためのコンピュータプログラム。
     
PCT/JP2020/008683 2019-03-08 2020-03-02 車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム Ceased WO2020184255A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202080015434.2A CN113454693B (zh) 2019-03-08 2020-03-02 车载更新装置、更新处理系统、更新处理方法及计算机程序
US17/435,617 US11954476B2 (en) 2019-03-08 2020-03-02 On-board update apparatus, update processing system, update processing method, and computer program

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2019042788A JP7218623B2 (ja) 2019-03-08 2019-03-08 車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム
JP2019-042788 2019-03-08

Publications (1)

Publication Number Publication Date
WO2020184255A1 true WO2020184255A1 (ja) 2020-09-17

Family

ID=72354322

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2020/008683 Ceased WO2020184255A1 (ja) 2019-03-08 2020-03-02 車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム

Country Status (4)

Country Link
US (1) US11954476B2 (ja)
JP (1) JP7218623B2 (ja)
CN (1) CN113454693B (ja)
WO (1) WO2020184255A1 (ja)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4375802A4 (en) * 2021-07-23 2024-10-02 Huawei Technologies Co., Ltd. METHOD AND APPARATUS FOR OVER-THE-AIR (OTA) UPGRADING

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR3101716B1 (fr) * 2019-10-04 2021-12-03 Safran Electronics & Defense Système et procédé de mise à jour de données à distance pour des dispositifs informatiques compris dans un aéronef
JP7782206B2 (ja) * 2021-10-28 2025-12-09 マツダ株式会社 グリッドコンピューティングの管理方法及びグリッドコンピューティングシステム
JP7782207B2 (ja) * 2021-10-28 2025-12-09 マツダ株式会社 グリッドコンピューティングの管理方法及び管理システム
JP7687190B2 (ja) * 2021-10-28 2025-06-03 マツダ株式会社 グリッドコンピューティングの管理方法及びグリッドコンピューティングシステム
CN116483411A (zh) * 2023-06-25 2023-07-25 广汽埃安新能源汽车股份有限公司 整车软件在线升级方法、装置、电子设备和存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2004127106A (ja) * 2002-10-04 2004-04-22 Konica Minolta Holdings Inc 情報処理装置、画像形成装置及びプログラム更新方法
JP2017220091A (ja) * 2016-06-09 2017-12-14 株式会社デンソー 車両用装置
JP2018060323A (ja) * 2016-10-04 2018-04-12 株式会社オートネットワーク技術研究所 車載更新システム、車載更新装置、車載機器及び更新方法

Family Cites Families (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH05106376A (ja) * 1991-10-17 1993-04-27 Nissan Motor Co Ltd キーレスエントリーシステム
JP4599952B2 (ja) * 2004-09-15 2010-12-15 株式会社デンソー プログラム書き換えシステム及び車両コンピュータシステム
JP5120381B2 (ja) * 2007-10-10 2013-01-16 トヨタ自動車株式会社 車両の制御装置および制御方法
EP2590103B1 (en) * 2010-06-29 2019-07-24 Toyota Jidosha Kabushiki Kaisha Control device
JP5609702B2 (ja) * 2011-02-17 2014-10-22 株式会社デンソー 車載制御装置のプログラム更新システム
US10241509B1 (en) * 2014-11-13 2019-03-26 State Farm Mutual Automobile Insurance Company Autonomous vehicle control assessment and selection
JP6561811B2 (ja) * 2015-12-09 2019-08-21 株式会社オートネットワーク技術研究所 車載通信装置、車載通信システム及び車両特定処理禁止方法
US9984571B2 (en) * 2016-03-14 2018-05-29 GM Global Technology Operations LLC Three-body vehicle-based object tracking and notification systems
JP2017215889A (ja) * 2016-06-02 2017-12-07 住友電気工業株式会社 制御装置、プログラム更新方法、およびコンピュータプログラム
JP2018076040A (ja) * 2016-11-11 2018-05-17 株式会社オートネットワーク技術研究所 車載更新システム、車載更新装置及びゲートウェイ
JP6958308B2 (ja) * 2017-12-11 2021-11-02 株式会社オートネットワーク技術研究所 車載更新装置、プログラム及び、プログラム又はデータの更新方法

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2004127106A (ja) * 2002-10-04 2004-04-22 Konica Minolta Holdings Inc 情報処理装置、画像形成装置及びプログラム更新方法
JP2017220091A (ja) * 2016-06-09 2017-12-14 株式会社デンソー 車両用装置
JP2018060323A (ja) * 2016-10-04 2018-04-12 株式会社オートネットワーク技術研究所 車載更新システム、車載更新装置、車載機器及び更新方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4375802A4 (en) * 2021-07-23 2024-10-02 Huawei Technologies Co., Ltd. METHOD AND APPARATUS FOR OVER-THE-AIR (OTA) UPGRADING

Also Published As

Publication number Publication date
CN113454693B (zh) 2023-06-02
US11954476B2 (en) 2024-04-09
JP2020144784A (ja) 2020-09-10
JP7218623B2 (ja) 2023-02-07
CN113454693A (zh) 2021-09-28
US20220156056A1 (en) 2022-05-19

Similar Documents

Publication Publication Date Title
JP7218623B2 (ja) 車載更新装置、更新処理システム、更新処理方法及びコンピュータプログラム
JP6756225B2 (ja) 車載更新システム、車載更新装置及び更新方法
US10414376B1 (en) Systems and methods for vehicle lock/unlock alerts
US20200086850A1 (en) Park-assist based on vehicle door open positions
CN107650905A (zh) 带有乘客探测的车辆远程停车辅助
US11987207B2 (en) Vehicles and vehicle systems for operating powered running boards in an alarm deterrent mode
CN105379163A (zh) 使用控制单元远程控制用于控制车辆操纵的系统的方法
JP2020166541A (ja) 事故責任特定方法、運行支援方法、事故責任特定装置及びコンピュータプログラム
CN106985744A (zh) 用于操作车门的系统和方法
JP2008265491A (ja) 遠隔エンジン制御システム
JP6853724B2 (ja) 情報システム、車載機器、第一キー、解錠方法、およびプログラム
CN107010051B (zh) 用于确定当前手动还是自动驾驶机动车的方法和设备
JP7369516B2 (ja) 記録装置、記録システム、記録方法および記録プログラム
CN112389320A (zh) 车辆用显示装置、车辆控制系统、车辆控制方法以及存储介质
JP7439810B2 (ja) サーバ、情報処理システムおよび情報処理方法
JP7600956B2 (ja) サーバ、情報処理システムおよび情報処理方法
JP7399185B2 (ja) 安全なテレオペレート運転のためのシステム
CN116238417A (zh) 无人自主学习泊车外后视镜控制方法、电子设备及存储介质
US20210078643A1 (en) Removable interior for reconfigurable vehicles
JP7761021B2 (ja) 移動体管理装置、移動体管理システム、および遠隔制御機能の無効化方法
JP4434084B2 (ja) 遠隔操作装置、及び遠隔操作システム
KR20230056582A (ko) 차량, 자동 주차 시스템 및 자동 주차 방법
DE102022116430A1 (de) Fahrzeugnachrichtenübermittlung
JP7211189B2 (ja) 更新処理システム及び更新処理方法
JP2019514242A (ja) 動力車両のための電子駐車支援装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20768249

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20768249

Country of ref document: EP

Kind code of ref document: A1